{"id":42,"name":"aiohttp","ecosystem":"pip","repository_url":"https://github.com/aio-libs/aiohttp","issues_count":8246,"created_at":"2025-06-06T15:01:32.460Z","updated_at":"2025-06-06T15:01:32.460Z","purl":"pkg:pypi/aiohttp","metadata":{"id":2634417,"name":"aiohttp","ecosystem":"pypi","description":"Async http client/server framework (asyncio)","homepage":"https://github.com/aio-libs/aiohttp","licenses":"Apache-2.0","normalized_licenses":["Apache-2.0"],"repository_url":"https://github.com/aio-libs/aiohttp","keywords_array":[],"namespace":null,"versions_count":295,"first_release_published_at":"2013-10-25T18:17:03.000Z","latest_release_published_at":"2025-06-04T10:03:12.000Z","latest_release_number":"3.12.8","last_synced_at":"2025-06-04T10:31:29.624Z","created_at":"2022-04-10T09:59:16.808Z","updated_at":"2025-06-04T10:31:32.647Z","registry_url":"https://pypi.org/project/aiohttp/","install_command":"pip install aiohttp --index-url https://pypi.org/simple","documentation_url":"https://aiohttp.readthedocs.io/","metadata":{"funding":null,"documentation":null,"classifiers":["Development Status :: 5 - Production/Stable","Framework :: AsyncIO","Intended Audience :: Developers","Operating System :: MacOS :: MacOS X","Operating System :: Microsoft :: Windows","Operating System :: POSIX","Programming Language :: Python","Programming Language :: Python :: 3","Programming Language :: Python :: 3.10","Programming Language :: Python :: 3.11","Programming Language :: Python :: 3.12","Programming Language :: Python :: 3.13","Programming Language :: Python :: 3.9","Topic :: Internet :: WWW/HTTP"],"normalized_name":"aiohttp"},"repo_metadata":{"uuid":"13258039","full_name":"aio-libs/aiohttp","owner":"aio-libs","description":"Asynchronous HTTP client/server framework for asyncio and Python","archived":false,"fork":false,"pushed_at":"2024-01-05T23:58:08.000Z","size":25234,"stargazers_count":14254,"open_issues_count":502,"forks_count":1993,"subscribers_count":222,"default_branch":"master","last_synced_at":"2024-01-06T13:57:47.413Z","etag":null,"topics":["aiohttp","async","asyncio","hacktoberfest","http","http-client","http-server","python"],"latest_commit_sha":null,"homepage":"https://docs.aiohttp.org","language":"Python","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"other","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/aio-libs.png","metadata":{"files":{"readme":"README.rst","changelog":"CHANGES.rst","contributing":"CONTRIBUTING.rst","funding":".github/FUNDING.yml","license":"LICENSE.txt","code_of_conduct":"CODE_OF_CONDUCT.md","threat_model":null,"audit":null,"citation":null,"codeowners":".github/CODEOWNERS","security":null,"support":null,"governance":null,"roadmap":null,"authors":null},"funding":{"github":["asvetlov","webknjaz","Dreamsorcerer"]}},"created_at":"2013-10-01T23:04:01.000Z","updated_at":"2024-01-06T13:14:39.000Z","dependencies_parsed_at":"2023-10-16T12:27:57.134Z","dependency_job_id":"a7e1b4ec-0c01-46fc-abdd-02044ead9c38","html_url":"https://github.com/aio-libs/aiohttp","commit_stats":{"total_commits":8438,"total_committers":721,"mean_commits":"11.703190013869625","dds":0.5483526902109505,"last_synced_commit":"85f7b98976bd7808ea1497af1a7e5299968da982"},"previous_names":[],"tags_count":244,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/aio-libs","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/refs/heads/master","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":179484934,"owners_count":10822668,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"},"owner_record":{"login":"aio-libs","name":"aio-libs","uuid":"7049303","kind":"organization","description":"The set of asyncio-based libraries built with high quality","email":null,"website":"https://github.com/aio-libs/.github/discussions","location":null,"twitter":null,"company":null,"icon_url":"https://avatars.githubusercontent.com/u/7049303?v=4","repositories_count":66,"last_synced_at":"2023-04-09T09:48:08.904Z","metadata":{"has_sponsors_listing":false},"html_url":"https://github.com/aio-libs","created_at":"2022-11-02T16:23:24.182Z","updated_at":"2023-04-09T09:48:09.011Z","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/aio-libs","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/aio-libs/repositories"},"tags":[{"name":"v3.9.1","sha":"6333c026422c6b0fe57ff63cde4104e2d00f47f4","kind":"tag","published_at":"2023-11-26T16:34:43.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.9.1","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.9.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.9.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.9.1/manifests"},{"name":"v3.9.0","sha":"45b2c2c5773f0ee0d35fce8ff5716c78e91d9135","kind":"tag","published_at":"2023-11-18T01:42:23.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.9.0","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.9.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.9.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.9.0/manifests"},{"name":"v3.9.0rc0","sha":"5d59d3d6ac073a7db5e5d2234e03a67da5dec48a","kind":"tag","published_at":"2023-11-14T15:07:57.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.9.0rc0","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.9.0rc0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.9.0rc0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.9.0rc0/manifests"},{"name":"v3.9.0b1","sha":"987dccf77320331f72897445fcd692ed229170f1","kind":"tag","published_at":"2023-11-03T15:20:09.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.9.0b1","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.9.0b1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.9.0b1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.9.0b1/manifests"},{"name":"v3.9.0b0","sha":"9764df24685cec07aee5ff3dace92e7547b2023f","kind":"tag","published_at":"2023-10-07T19:49:25.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.9.0b0","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.9.0b0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.9.0b0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.9.0b0/manifests"},{"name":"v3.8.6","sha":"996de2629ef6b4c2934a7c04dfd49d0950d4c43b","kind":"tag","published_at":"2023-10-07T12:42:01.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.8.6","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.8.6","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.8.6","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.8.6/manifests"},{"name":"v3.8.5","sha":"9c13a52c21c23dfdb49ed89418d28a5b116d0681","kind":"tag","published_at":"2023-07-19T14:33:40.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.8.5","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.8.5","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.8.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.8.5/manifests"},{"name":"v3.8.4","sha":"33953f110e97eecc707e1402daa8d543f38a189b","kind":"tag","published_at":"2023-02-12T17:20:55.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.8.4","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.8.4","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.8.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.8.4/manifests"},{"name":"v3.8.3","sha":"30b7a4e99677b4014dda2372504343bb05fc983e","kind":"tag","published_at":"2022-09-21T12:40:24.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.8.3","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.8.3","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.8.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.8.3/manifests"},{"name":"v3.8.2","sha":"99c8d0d7706153970bc1cbace8bdf4ab137783c7","kind":"tag","published_at":"2022-09-20T22:42:13.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.8.2","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.8.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.8.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.8.2/manifests"},{"name":"v3.8.2a0","sha":"6b3b379cc9fae73306b769caf3991665cacb262e","kind":"tag","published_at":"2022-09-20T01:08:18.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.8.2a0","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.8.2a0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.8.2a0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.8.2a0/manifests"},{"name":"v3.8.1","sha":"cc6dc0c49f5d002485f9a3cdf9bc3127a3ac1388","kind":"tag","published_at":"2021-11-14T19:50:38.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.8.1","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.8.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.8.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.8.1/manifests"},{"name":"v3.8.0","sha":"208a4eb6dbf5373d9f5a9f18efac839a6448eadc","kind":"tag","published_at":"2021-10-31T20:11:06.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.8.0","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.8.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.8.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.8.0/manifests"},{"name":"v3.8.0b0","sha":"6b5dc205444407adc7cd6e7ac7e99ba0d4b986f0","kind":"tag","published_at":"2021-10-31T18:34:01.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.8.0b0","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.8.0b0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.8.0b0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.8.0b0/manifests"},{"name":"v3.8.0a7","sha":"610744127eac51fc7b1f5f5d04ef3ddee2ef79cc","kind":"tag","published_at":"2021-10-30T14:08:40.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.8.0a7","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.8.0a7","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.8.0a7","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.8.0a7/manifests"},{"name":"v3.8.0a6","sha":"51137bdabc75d073be8bcb05397fb91b154ca63a","kind":"tag","published_at":"2021-10-30T11:53:25.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.8.0a6","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.8.0a6","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.8.0a6","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.8.0a6/manifests"},{"name":"v3.8.0a5","sha":"32c027f8b18de69a3873341f89414f31a46352d0","kind":"tag","published_at":"2021-10-30T09:03:03.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.8.0a5","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.8.0a5","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.8.0a5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.8.0a5/manifests"},{"name":"v3.8.0a4","sha":"1fbe14363a22cfbef5bcb792bcc7381e894b8593","kind":"tag","published_at":"2021-10-29T17:18:52.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.8.0a4","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.8.0a4","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.8.0a4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.8.0a4/manifests"},{"name":"v3.8.0a3","sha":"6fe533ed5523b5c7974fafa29da937e9bc947194","kind":"tag","published_at":"2021-10-29T15:51:08.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.8.0a3","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.8.0a3","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.8.0a3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.8.0a3/manifests"},{"name":"v3.8.0a2","sha":"0615842c2b0e402a9eae72f760089c99bb34d97b","kind":"tag","published_at":"2021-10-29T14:14:33.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.8.0a2","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.8.0a2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.8.0a2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.8.0a2/manifests"},{"name":"v3.8.0a1","sha":"dc4e0d46e38909793c94ab2687cb7d46f7d111b5","kind":"tag","published_at":"2021-10-29T12:41:08.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.8.0a1","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.8.0a1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.8.0a1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.8.0a1/manifests"},{"name":"v3.8.0a0","sha":"c61ea13c16f01e5f7d366e02ef1e0bdbc035c9da","kind":"tag","published_at":"2021-10-29T12:18:01.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.8.0a0","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.8.0a0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.8.0a0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.8.0a0/manifests"},{"name":"v3.7.4.post0","sha":"184274d9b28bbfa06ac60e48bf286a761c6a6cb0","kind":"tag","published_at":"2021-03-06T20:47:27.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.7.4.post0","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.7.4.post0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.7.4.post0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.7.4.post0/manifests"},{"name":"v3.7.4","sha":"0a26acc1de9e1b0244456b7881ec16ba8bb64fc3","kind":"tag","published_at":"2021-02-25T17:30:12.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.7.4","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.7.4","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.7.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.7.4/manifests"},{"name":"v3.7.3","sha":"2f655a59d0daedfa2a794996c4355b576c98ecc8","kind":"tag","published_at":"2020-11-18T17:32:09.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.7.3","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.7.3","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.7.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.7.3/manifests"},{"name":"v3.7.2","sha":"ac294fdded8366b4f8612591bc914e58b4225451","kind":"tag","published_at":"2020-10-27T08:07:29.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.7.2","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.7.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.7.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.7.2/manifests"},{"name":"v3.7.1","sha":"fa8adadc1a84333434431778d3da59d7dbed8161","kind":"tag","published_at":"2020-10-25T07:30:00.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.7.1","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.7.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.7.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.7.1/manifests"},{"name":"v3.7.0","sha":"cac3cd2450953f5749eda4b5615d982d855ebfb9","kind":"tag","published_at":"2020-10-24T08:09:01.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.7.0","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.7.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.7.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.7.0/manifests"},{"name":"v3.7.0b1","sha":"1a4118b20ec12f2b9a57e00af7a66bf0d730f91d","kind":"tag","published_at":"2020-10-22T14:15:01.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.7.0b1","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.7.0b1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.7.0b1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.7.0b1/manifests"},{"name":"v3.7.0b0","sha":"093ebf9e0752611b90a2a76ccb6e704a29f14f8d","kind":"tag","published_at":"2020-10-21T18:54:04.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.7.0b0","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.7.0b0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.7.0b0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.7.0b0/manifests"},{"name":"v3.6.3","sha":"19405036da709906b3349298569c4ae8696d436b","kind":"tag","published_at":"2020-10-12T10:36:15.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.6.3","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.6.3","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.6.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.6.3/manifests"},{"name":"v3.6.2","sha":"6a5ab96bd9cb404b4abfd5160fe8f34a29d941e5","kind":"tag","published_at":"2019-10-09T16:22:53.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.6.2","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.6.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.6.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.6.2/manifests"},{"name":"v3.6.2a2","sha":"3da9a534441640ecfe1f93d691a5200308ec9088","kind":"tag","published_at":"2019-10-09T14:58:00.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.6.2a2","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.6.2a2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.6.2a2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.6.2a2/manifests"},{"name":"v3.6.2a1","sha":"d10927c116843509d68ade998e38f710dfb6d4df","kind":"tag","published_at":"2019-10-09T14:52:02.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.6.2a1","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.6.2a1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.6.2a1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.6.2a1/manifests"},{"name":"v3.6.2a0","sha":"ac302cd4e6d8395715b6a918989dc5c458c6d20c","kind":"tag","published_at":"2019-10-09T13:54:53.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.6.2a0","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.6.2a0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.6.2a0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.6.2a0/manifests"},{"name":"v4.0.0a1","sha":"0ed22240769d11dc382ca1430538f8be180316df","kind":"tag","published_at":"2019-10-09T10:51:38.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v4.0.0a1","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v4.0.0a1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v4.0.0a1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v4.0.0a1/manifests"},{"name":"v3.6.1","sha":"37e5d61298703234b968b28f01bafa3434d920dd","kind":"tag","published_at":"2019-09-19T16:27:04.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.6.1","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.6.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.6.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.6.1/manifests"},{"name":"v3.6.1b4","sha":"aa281c66f0be78aa52cfe974fcca6d3472e91062","kind":"tag","published_at":"2019-09-17T18:09:09.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.6.1b4","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.6.1b4","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.6.1b4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.6.1b4/manifests"},{"name":"v3.6.1b3","sha":"3e0691c81ca83377e1f2ce412c7c0579163d23ac","kind":"tag","published_at":"2019-09-15T11:46:00.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.6.1b3","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.6.1b3","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.6.1b3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.6.1b3/manifests"},{"name":"v3.6.0","sha":"b33540cafa432503baa517d0fd76abf67b647598","kind":"tag","published_at":"2019-09-06T13:50:55.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.6.0","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.6.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.6.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.6.0/manifests"},{"name":"v3.6.0b0","sha":"0464f8af86283a64cc5911ee3a798a36aaceddd5","kind":"tag","published_at":"2019-09-05T11:19:50.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.6.0b0","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.6.0b0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.6.0b0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.6.0b0/manifests"},{"name":"v3.6.0a12","sha":"57c8c78b65f4f31a127ea2c43d62b41e324023fb","kind":"tag","published_at":"2019-08-29T16:49:19.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.6.0a12","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.6.0a12","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.6.0a12","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.6.0a12/manifests"},{"name":"v3.6.0a11","sha":"3ffec8821bfe42eb6ea3829be5bef894ac4b497f","kind":"tag","published_at":"2019-08-29T12:53:53.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.6.0a11","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.6.0a11","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.6.0a11","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.6.0a11/manifests"},{"name":"v3.6.0a10","sha":"570686cb555c6f2bcdb1764a58c2f61fb7670a71","kind":"tag","published_at":"2019-08-29T12:11:10.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.6.0a10","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.6.0a10","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.6.0a10","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.6.0a10/manifests"},{"name":"v3.6.0a9","sha":"50a91b1a72ae7c00e51e9ed9bdb02f6672d02934","kind":"tag","published_at":"2019-08-29T10:52:45.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.6.0a9","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.6.0a9","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.6.0a9","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.6.0a9/manifests"},{"name":"v3.6.0a8","sha":"3addd81f197da94e9eb2257df27ffaa34e259391","kind":"tag","published_at":"2019-08-20T22:06:36.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.6.0a8","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.6.0a8","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.6.0a8","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.6.0a8/manifests"},{"name":"v3.6.0a7","sha":"745f720c74278c6e05931286396f93f05eeea228","kind":"tag","published_at":"2019-08-20T20:25:08.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.6.0a7","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.6.0a7","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.6.0a7","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.6.0a7/manifests"},{"name":"v3.6.0a6","sha":"4c713f00bcdb4e3b70cef0c3658becf1f0940649","kind":"tag","published_at":"2019-08-20T18:39:59.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.6.0a6","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.6.0a6","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.6.0a6","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.6.0a6/manifests"},{"name":"v3.6.0a5","sha":"29adf1e8811802934cd60e047ef1386fc7685692","kind":"tag","published_at":"2019-08-20T17:18:31.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.6.0a5","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.6.0a5","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.6.0a5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.6.0a5/manifests"},{"name":"v3.6.0a4","sha":"f8d1d98b577d44fb36e0ebfc71a484c607442a0b","kind":"tag","published_at":"2019-08-20T16:34:34.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.6.0a4","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.6.0a4","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.6.0a4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.6.0a4/manifests"},{"name":"v3.6.0a3","sha":"44e507638f76ea2c2b7fd02329b20f42ad92d60d","kind":"tag","published_at":"2019-08-19T16:22:27.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.6.0a3","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.6.0a3","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.6.0a3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.6.0a3/manifests"},{"name":"v3.6.0a2","sha":"152dc7c8fb55436d203c9e1a4f78f948cb75f8bc","kind":"tag","published_at":"2019-08-19T13:12:39.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.6.0a2","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.6.0a2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.6.0a2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.6.0a2/manifests"},{"name":"v3.6.0a1","sha":"9d290a7ec61f89c09a5cd227c006962ca201078b","kind":"tag","published_at":"2019-08-12T12:47:16.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.6.0a1","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.6.0a1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.6.0a1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.6.0a1/manifests"},{"name":"v3.6.0a0","sha":"36da9da494df85426d86a755ade45501da3a8c71","kind":"tag","published_at":"2019-08-12T11:10:14.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.6.0a0","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.6.0a0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.6.0a0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.6.0a0/manifests"},{"name":"v3.5.4","sha":"f6f647eb828fa738610d61481f11fa51e42599e9","kind":"tag","published_at":"2019-01-12T10:13:19.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.5.4","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.5.4","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.5.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.5.4/manifests"},{"name":"v3.5.3","sha":"99335f4224c5fa74a43490835c63dc19b914b458","kind":"tag","published_at":"2019-01-10T21:04:39.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.5.3","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.5.3","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.5.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.5.3/manifests"},{"name":"v4.0.0a0","sha":"d487af9a62aac62b752cd4e412a9cf1c0c6b214d","kind":"tag","published_at":"2019-01-09T00:34:53.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v4.0.0a0","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v4.0.0a0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v4.0.0a0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v4.0.0a0/manifests"},{"name":"v3.5.2","sha":"8c8375f26a5bbfb8c0f56541aec860b10d99ffc5","kind":"tag","published_at":"2019-01-08T10:24:12.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.5.2","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.5.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.5.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.5.2/manifests"},{"name":"v3.5.1","sha":"e29785191158fb7503be5cf9a43f7f7c3119eb76","kind":"tag","published_at":"2018-12-24T20:58:34.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.5.1","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.5.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.5.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.5.1/manifests"},{"name":"v3.5.0","sha":"e13ed991117a8a7aa0cdd2e4f496787e58e1b744","kind":"tag","published_at":"2018-12-22T21:51:58.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.5.0","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.5.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.5.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.5.0/manifests"},{"name":"v3.5.0b3","sha":"e1e81e831f7872270e1f172283a3d775edb755ff","kind":"tag","published_at":"2018-12-22T09:03:49.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.5.0b3","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.5.0b3","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.5.0b3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.5.0b3/manifests"},{"name":"v3.5.0b2","sha":"ccc02f5fb016135ee60445d024c7123a13db6518","kind":"tag","published_at":"2018-12-21T12:04:20.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.5.0b2","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.5.0b2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.5.0b2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.5.0b2/manifests"},{"name":"v3.5.0b1","sha":"9708dc5788484239eae6b2aad2d4473e62d8f12d","kind":"tag","published_at":"2018-12-20T21:33:52.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.5.0b1","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.5.0b1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.5.0b1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.5.0b1/manifests"},{"name":"v3.5.0a1","sha":"ffaef545a99d67c12b2000d07ce43d885a0cbf1a","kind":"tag","published_at":"2018-11-20T09:35:29.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.5.0a1","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.5.0a1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.5.0a1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.5.0a1/manifests"},{"name":"v3.4.4","sha":"fd335f2d597208e95bc86732cf93edbc8fa379ef","kind":"tag","published_at":"2018-09-05T07:16:23.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.4.4","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.4.4","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.4.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.4.4/manifests"},{"name":"v3.4.3","sha":"c74c945889c7e49ab9a5d5a2beba0faa2327b0da","kind":"tag","published_at":"2018-09-04T13:26:33.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.4.3","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.4.3","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.4.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.4.3/manifests"},{"name":"v3.4.2","sha":"3ddd91c2c89e5a31380b169bd5a26c8d641b2fc5","kind":"tag","published_at":"2018-09-01T19:03:41.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.4.2","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.4.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.4.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.4.2/manifests"},{"name":"v3.4.1","sha":"06438b0b31192ad720f26767f41845ab280d972d","kind":"tag","published_at":"2018-08-28T20:30:09.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.4.1","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.4.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.4.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.4.1/manifests"},{"name":"v3.4.0","sha":"1e2f51c2548cd90266c80867b68714fd32b3fd04","kind":"tag","published_at":"2018-08-25T11:20:16.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.4.0","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.4.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.4.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.4.0/manifests"},{"name":"v3.4.0b2","sha":"37ef00ae03bc96e4222a8f9fae58e64d538ae80a","kind":"tag","published_at":"2018-08-24T18:56:26.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.4.0b2","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.4.0b2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.4.0b2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.4.0b2/manifests"},{"name":"v3.4.0b1","sha":"bf2fc0c9e854a27949177759a7fc92a70ff1d56c","kind":"tag","published_at":"2018-08-24T14:17:56.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.4.0b1","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.4.0b1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.4.0b1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.4.0b1/manifests"},{"name":"v3.4.0a3","sha":"99914c87e986fcfc3107c0acdfa33fd8801b46f8","kind":"tag","published_at":"2018-08-20T20:09:25.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.4.0a3","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.4.0a3","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.4.0a3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.4.0a3/manifests"},{"name":"v3.4.0a2","sha":"86479c3ecd34a9e475fd37a80293659439e1397f","kind":"tag","published_at":"2018-08-19T13:35:21.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.4.0a2","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.4.0a2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.4.0a2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.4.0a2/manifests"},{"name":"v3.4.0a1","sha":"01a98e639cd4bea8c7cd6bd07f384206457f1823","kind":"tag","published_at":"2018-08-19T12:04:01.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.4.0a1","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.4.0a1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.4.0a1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.4.0a1/manifests"},{"name":"v3.4.0a0","sha":"bb78691e70e9519459017d66e5c110ccaa176541","kind":"tag","published_at":"2018-08-11T11:45:00.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.4.0a0","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.4.0a0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.4.0a0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.4.0a0/manifests"},{"name":"v3.3.2","sha":"99b2bd1c2c5c534dceb3b363a535b78a80f31138","kind":"tag","published_at":"2018-06-13T08:49:55.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.3.2","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.3.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.3.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.3.2/manifests"},{"name":"v3.3.2a0","sha":"601b1e04b929f295fc2350eee3d6dd6cb7f2369d","kind":"tag","published_at":"2018-06-12T11:23:24.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.3.2a0","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.3.2a0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.3.2a0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.3.2a0/manifests"},{"name":"v3.3.1","sha":"6177b05f35bfea458f97ef7262937c921839cc10","kind":"tag","published_at":"2018-06-05T20:58:32.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.3.1","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.3.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.3.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.3.1/manifests"},{"name":"v3.3.1b1","sha":"6177b05f35bfea458f97ef7262937c921839cc10","kind":"tag","published_at":"2018-06-05T19:45:31.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.3.1b1","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.3.1b1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.3.1b1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.3.1b1/manifests"},{"name":"3.3.0a0","sha":"870b613145dae11b5e678e1e60fb1df1ad8bac3f","kind":"commit","published_at":"2018-06-02T10:56:35.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/3.3.0a0","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/3.3.0a0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/3.3.0a0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/3.3.0a0/manifests"},{"name":"v3.3.0","sha":"efec306dc421f68c9d0f4d225ef7e272e0114ffa","kind":"tag","published_at":"2018-06-01T08:58:23.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.3.0","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.3.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.3.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.3.0/manifests"},{"name":"v3.2.1","sha":"ed7e4aba16d948b02a47e1d55ae82a978e3279db","kind":"tag","published_at":"2018-05-10T08:49:47.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.2.1","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.2.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.2.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.2.1/manifests"},{"name":"v3.2.0","sha":"fd7998860d709bf8e7943770bdfd4c9f8b371e8f","kind":"tag","published_at":"2018-05-06T21:01:15.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.2.0","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.2.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.2.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.2.0/manifests"},{"name":"v3.1.3","sha":"77f5633ce02da71c6879d3b25b5fbe8b240647c6","kind":"tag","published_at":"2018-04-13T09:59:35.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.1.3","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.1.3","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.1.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.1.3/manifests"},{"name":"v3.1.2","sha":"ae2dbcb6ea208275b67eecda025b8f55c603e79b","kind":"tag","published_at":"2018-04-05T20:22:24.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.1.2","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.1.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.1.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.1.2/manifests"},{"name":"v3.1.1","sha":"b02206ad7f20a3b97b1710801ebf4ca17de477a8","kind":"tag","published_at":"2018-03-27T13:08:24.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.1.1","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.1.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.1.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.1.1/manifests"},{"name":"v3.1.0","sha":"77623f823f738966142802a57dde6c0b832333b6","kind":"tag","published_at":"2018-03-21T13:53:00.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.1.0","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.1.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.1.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.1.0/manifests"},{"name":"v3.0.9","sha":"1e882849a0bd889673b1b13934df3e2ae5ffb97f","kind":"tag","published_at":"2018-03-14T12:35:45.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.0.9","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.0.9","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.0.9","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.0.9/manifests"},{"name":"v3.0.8","sha":"c4058a4e1ddc0883f11ef28a0b25ce1292a1800e","kind":"tag","published_at":"2018-03-13T08:49:23.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.0.8","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.0.8","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.0.8","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.0.8/manifests"},{"name":"v3.0.7","sha":"5d687407112f1b11c1cd5960d32cc2f83ab48203","kind":"tag","published_at":"2018-03-08T16:19:11.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.0.7","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.0.7","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.0.7","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.0.7/manifests"},{"name":"v3.0.6","sha":"e0c11106aa49af2852c9718f81063770f7a334d8","kind":"tag","published_at":"2018-03-04T23:09:10.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.0.6","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.0.6","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.0.6","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.0.6/manifests"},{"name":"v3.0.5","sha":"3587121ece581a8fd68b278245aa82875f9acbd7","kind":"tag","published_at":"2018-02-27T16:26:40.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.0.5","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.0.5","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.0.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.0.5/manifests"},{"name":"v3.0.4","sha":"5d5e9fd78034cabddc6b392fb454367f5d91f4bf","kind":"tag","published_at":"2018-02-26T13:11:06.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.0.4","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.0.4","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.0.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.0.4/manifests"},{"name":"v3.0.3","sha":"36179d178440d1fccf743ca73f051416a6659b78","kind":"tag","published_at":"2018-02-25T15:43:52.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.0.3","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.0.3","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.0.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.0.3/manifests"},{"name":"v3.0.2","sha":"66858fc999f0cf318c286285a0e27435075a83bb","kind":"tag","published_at":"2018-02-23T09:30:29.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.0.2","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.0.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.0.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.0.2/manifests"},{"name":"v3.0.1","sha":"c3ec2423bbdea845c18aea27a402b6a8a18905a3","kind":"tag","published_at":"2018-02-12T12:33:27.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.0.1","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.0.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.0.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.0.1/manifests"},{"name":"v3.0.0","sha":"5cf72cf5b2444a8fad1ae7db6ca5b76e2a092e27","kind":"tag","published_at":"2018-02-12T09:01:16.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.0.0","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.0.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.0.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.0.0/manifests"},{"name":"v3.0.0b4","sha":"af560adec4a44077a5232ac6d4656086a33d2d1f","kind":"tag","published_at":"2018-02-09T15:04:28.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.0.0b4","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.0.0b4","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.0.0b4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.0.0b4/manifests"},{"name":"v3.0.0b3","sha":"e5d4ee9bc1f87c6d655ae30d577f33e8dc227b64","kind":"tag","published_at":"2018-02-08T21:08:21.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.0.0b3","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.0.0b3","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.0.0b3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.0.0b3/manifests"},{"name":"v3.0.0b2","sha":"b3887d202890fdea84ceda758f3e3050b9c0fff3","kind":"tag","published_at":"2018-02-08T15:27:50.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.0.0b2","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.0.0b2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.0.0b2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.0.0b2/manifests"},{"name":"v3.0.0b1","sha":"ee86e5ece03233d81682b0c3d9f8bb9cd7cb94ee","kind":"tag","published_at":"2018-02-08T13:40:14.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.0.0b1","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.0.0b1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.0.0b1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.0.0b1/manifests"},{"name":"v3.0.0b0","sha":"cfce39093ce185eb5050eae330bbe82cad71f17f","kind":"tag","published_at":"2018-02-08T10:52:38.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v3.0.0b0","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v3.0.0b0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.0.0b0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v3.0.0b0/manifests"},{"name":"v2.3.10","sha":"3dfad7a30a3049ed1b7cbbfd908aa4fa30bc6501","kind":"tag","published_at":"2018-02-02T10:24:32.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v2.3.10","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v2.3.10","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v2.3.10","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v2.3.10/manifests"},{"name":"v2.3.9","sha":"06ed15ecb2a4700a08f4f2ff4b03bd751ca979f6","kind":"tag","published_at":"2018-01-17T08:44:37.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v2.3.9","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v2.3.9","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v2.3.9","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v2.3.9/manifests"},{"name":"v2.3.8","sha":"ed6166744285ac31a0ac8305830c2b4cf31f7a42","kind":"tag","published_at":"2018-01-15T22:20:19.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v2.3.8","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v2.3.8","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v2.3.8","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v2.3.8/manifests"},{"name":"v2.3.7","sha":"aaa7d546ba9f361eed3bf533cce730135b02edbe","kind":"tag","published_at":"2017-12-27T09:05:18.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v2.3.7","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v2.3.7","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v2.3.7","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v2.3.7/manifests"},{"name":"v2.3.6","sha":"9fd8048a5871b474e33ba550fa76d9e3afa47f8c","kind":"tag","published_at":"2017-12-04T17:40:54.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v2.3.6","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v2.3.6","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v2.3.6","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v2.3.6/manifests"},{"name":"v2.3.5","sha":"07afeb76e9782ea730d6379fc68d94cb3a18cece","kind":"tag","published_at":"2017-11-29T23:47:31.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v2.3.5","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v2.3.5","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v2.3.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v2.3.5/manifests"},{"name":"v2.3.4","sha":"5577631c9c952c78b29d452d96ffef6235899a09","kind":"tag","published_at":"2017-11-29T13:59:07.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v2.3.4","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v2.3.4","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v2.3.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v2.3.4/manifests"},{"name":"v2.3.3","sha":"ec4db9223fa78130555d56d24a747b1e2b5cfcdb","kind":"tag","published_at":"2017-11-17T09:39:41.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v2.3.3","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v2.3.3","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v2.3.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v2.3.3/manifests"},{"name":"v2.3.2","sha":"e740a1d64b919470c5edbf616e751ec6d283f75f","kind":"tag","published_at":"2017-11-01T15:11:36.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v2.3.2","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v2.3.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v2.3.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v2.3.2/manifests"},{"name":"v2.3.2b3","sha":"7dea13fe4787551a8461af39fbc2444b205cdc95","kind":"tag","published_at":"2017-11-01T11:14:06.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v2.3.2b3","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v2.3.2b3","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v2.3.2b3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v2.3.2b3/manifests"},{"name":"v2.3.2b2","sha":"84863a8cf9f8df5595ddb189d680774776d16cfb","kind":"tag","published_at":"2017-11-01T10:50:29.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v2.3.2b2","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v2.3.2b2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v2.3.2b2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v2.3.2b2/manifests"},{"name":"v2.3.2b1","sha":"c3edcd08cc0af46efc898244013cb083dab1ea45","kind":"tag","published_at":"2017-11-01T10:01:35.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v2.3.2b1","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v2.3.2b1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v2.3.2b1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v2.3.2b1/manifests"},{"name":"v2.3.1","sha":"0f43d52211d893e87fd7ebd2f880c4a44815a2ae","kind":"tag","published_at":"2017-10-19T01:14:46.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v2.3.1","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v2.3.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v2.3.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v2.3.1/manifests"},{"name":"v2.3.1a1","sha":"1ddf2f698049455af165e009999e068d63c4b529","kind":"tag","published_at":"2017-10-18T14:24:57.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v2.3.1a1","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v2.3.1a1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v2.3.1a1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v2.3.1a1/manifests"},{"name":"v2.3.0","sha":"a631eb2b8122d735989e3a90a36af4ad8129016f","kind":"tag","published_at":"2017-10-18T06:33:50.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v2.3.0","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v2.3.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v2.3.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v2.3.0/manifests"},{"name":"v2.3.0a4","sha":"fb812d1108300fa2e017e138f148e961db65deaf","kind":"tag","published_at":"2017-10-17T19:06:27.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v2.3.0a4","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v2.3.0a4","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v2.3.0a4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v2.3.0a4/manifests"},{"name":"v2.3.0a3","sha":"52981afca0cc007ac02484f63d2c1208244749db","kind":"tag","published_at":"2017-10-17T14:28:08.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v2.3.0a3","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v2.3.0a3","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v2.3.0a3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v2.3.0a3/manifests"},{"name":"v2.3.0a2","sha":"0f2225461ac157d12aee46da27057b9f680baa15","kind":"tag","published_at":"2017-10-17T13:37:04.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v2.3.0a2","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v2.3.0a2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v2.3.0a2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v2.3.0a2/manifests"},{"name":"v2.3.0a1","sha":"e9574da09ddd571791fa862bcaa3da266cf546ce","kind":"tag","published_at":"2017-10-17T09:26:41.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v2.3.0a1","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v2.3.0a1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v2.3.0a1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v2.3.0a1/manifests"},{"name":"v2.2.5","sha":"cc2a522f5d9505e29abe3c35366e6afc94199358","kind":"tag","published_at":"2017-08-03T14:01:02.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v2.2.5","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v2.2.5","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v2.2.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v2.2.5/manifests"},{"name":"v2.2.4","sha":"2c2172a13b0d04c5be206d204a66ab37d473369f","kind":"tag","published_at":"2017-08-02T19:21:34.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v2.2.4","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v2.2.4","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v2.2.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v2.2.4/manifests"},{"name":"v2.2.3","sha":"c02e119413c0023c1e6c93c34004799c68fbe92b","kind":"tag","published_at":"2017-07-04T14:58:21.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v2.2.3","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v2.2.3","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v2.2.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v2.2.3/manifests"},{"name":"v2.2.2","sha":"7183dc873de32622aa11cd9b5a64756e20338621","kind":"tag","published_at":"2017-07-03T08:16:17.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v2.2.2","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v2.2.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v2.2.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v2.2.2/manifests"},{"name":"v2.2.1","sha":"580d8b1d21fba209c92642a0fab76e6c8cd7a4f0","kind":"tag","published_at":"2017-07-02T17:56:52.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v2.2.1","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v2.2.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v2.2.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v2.2.1/manifests"},{"name":"v2.2.0","sha":"6e818f330002252e4056a534da851663b42b8955","kind":"tag","published_at":"2017-06-20T11:38:29.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v2.2.0","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v2.2.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v2.2.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v2.2.0/manifests"},{"name":"v2.1.0","sha":"482dbfd658d13b71b99e0a7b5947b155b891d3a5","kind":"tag","published_at":"2017-05-26T14:29:24.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v2.1.0","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v2.1.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v2.1.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v2.1.0/manifests"},{"name":"2.0.7","sha":"b81f4fe2e3b1aa18b68e7ed1b4e22b564afac9e0","kind":"commit","published_at":"2017-04-12T22:22:06.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/2.0.7","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/2.0.7","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/2.0.7","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/2.0.7/manifests"},{"name":"2.0.6","sha":"6f5da457185cce9be71c6ea9a14fcd9fde487ca0","kind":"commit","published_at":"2017-04-06T14:53:01.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/2.0.6","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/2.0.6","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/2.0.6","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/2.0.6/manifests"},{"name":"2.0.5","sha":"ed88699cbb458eb3f5320584d80562f1e365c8d9","kind":"commit","published_at":"2017-03-29T17:33:57.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/2.0.5","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/2.0.5","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/2.0.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/2.0.5/manifests"},{"name":"2.0.4","sha":"a6d8b518e877aacaf5f74cc0fa4ca9dca0f502ce","kind":"commit","published_at":"2017-03-27T18:41:43.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/2.0.4","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/2.0.4","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/2.0.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/2.0.4/manifests"},{"name":"2.0.3-1","sha":"4f1a8a18bfd4e2c63628eaacf48e296f2400bf6a","kind":"commit","published_at":"2017-03-24T21:24:24.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/2.0.3-1","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/2.0.3-1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/2.0.3-1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/2.0.3-1/manifests"},{"name":"2.0.3","sha":"268c31012ed5fdf583772ff1fa87c098cdc7dd26","kind":"commit","published_at":"2017-03-24T16:34:04.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/2.0.3","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/2.0.3","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/2.0.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/2.0.3/manifests"},{"name":"2.0.2","sha":"20ef6f57e5ee1743293eaf38474b01221e347e16","kind":"commit","published_at":"2017-03-21T22:11:35.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/2.0.2","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/2.0.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/2.0.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/2.0.2/manifests"},{"name":"2.0.1","sha":"65e571c8c46a65c3d2a05c2f14aee2b4577207c5","kind":"commit","published_at":"2017-03-21T14:59:11.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/2.0.1","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/2.0.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/2.0.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/2.0.1/manifests"},{"name":"2.0.0","sha":"9673cf44f399eda0221e59c7f7023be03b632dd5","kind":"commit","published_at":"2017-03-20T17:12:02.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/2.0.0","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/2.0.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/2.0.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/2.0.0/manifests"},{"name":"1.3.5","sha":"d561806ad4c869093eaa56ac8d1959f4768694ae","kind":"commit","published_at":"2017-03-16T14:55:40.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/1.3.5","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/1.3.5","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/1.3.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/1.3.5/manifests"},{"name":"2.0.0rc1","sha":"06b0491c01feaefb6a61558042fd5c7975a34258","kind":"commit","published_at":"2017-03-15T17:28:10.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/2.0.0rc1","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/2.0.0rc1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/2.0.0rc1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/2.0.0rc1/manifests"},{"name":"1.3.4","sha":"8482f002293fd0ce87c9883009ec02c5e9d0912c","kind":"commit","published_at":"2017-03-15T02:05:36.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/1.3.4","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/1.3.4","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/1.3.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/1.3.4/manifests"},{"name":"1.3.3","sha":"3fec89a45107ccd920b4ab9efb7e960c81f80f97","kind":"commit","published_at":"2017-02-20T02:03:46.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/1.3.3","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/1.3.3","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/1.3.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/1.3.3/manifests"},{"name":"1.3.2","sha":"e53ce5132173fed3c296afa71ded4dc2d9918004","kind":"commit","published_at":"2017-02-16T19:11:49.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/1.3.2","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/1.3.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/1.3.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/1.3.2/manifests"},{"name":"1.3.1","sha":"55e1228c4c9616d90531db42a83533d9d0f464ac","kind":"commit","published_at":"2017-02-09T14:27:58.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/1.3.1","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/1.3.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/1.3.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/1.3.1/manifests"},{"name":"1.3.0","sha":"e166cafd4c91570a631400582293706e72d08964","kind":"commit","published_at":"2017-02-08T18:08:36.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/1.3.0","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/1.3.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/1.3.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/1.3.0/manifests"},{"name":"v1.2.0","sha":"4eef48a800a39c8ba42addc0d2fcbafb1b8badee","kind":"tag","published_at":"2016-12-17T04:01:52.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v1.2.0","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v1.2.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v1.2.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v1.2.0/manifests"},{"name":"v1.1.6","sha":"5412d9e79e6178cf6ec5a13cefdb4a06fa47028b","kind":"tag","published_at":"2016-11-28T17:57:13.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v1.1.6","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v1.1.6","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v1.1.6","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v1.1.6/manifests"},{"name":"v1.1.5","sha":"dd53bee67a344659c5b3432315d2207aad313a72","kind":"tag","published_at":"2016-11-16T18:12:32.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v1.1.5","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v1.1.5","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v1.1.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v1.1.5/manifests"},{"name":"v1.1.4","sha":"5060def635dea624ec2344a0ec89b62a990066e5","kind":"tag","published_at":"2016-11-14T17:14:58.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v1.1.4","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v1.1.4","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v1.1.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v1.1.4/manifests"},{"name":"v1.1.3","sha":"a9f97149b59b5a537e845ce87c4182f81c9d1f55","kind":"tag","published_at":"2016-11-10T20:57:38.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v1.1.3","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v1.1.3","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v1.1.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v1.1.3/manifests"},{"name":"v1.1.2","sha":"994f4afcff1066bd6256f55cbdbe93bcb4348c2a","kind":"tag","published_at":"2016-11-08T15:50:24.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v1.1.2","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v1.1.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v1.1.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v1.1.2/manifests"},{"name":"v1.1.1","sha":"ab1aed2335aef606778036cd7a6b1b8dba8386da","kind":"tag","published_at":"2016-11-04T08:55:02.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v1.1.1","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v1.1.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v1.1.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v1.1.1/manifests"},{"name":"v1.1.0","sha":"0218f8f477253485f8d9f3d70fdd47266092474e","kind":"tag","published_at":"2016-11-03T20:49:08.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v1.1.0","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v1.1.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v1.1.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v1.1.0/manifests"},{"name":"v1.0.5","sha":"01ca6947fd59d972935f74bd803c04f7a07ebb3d","kind":"tag","published_at":"2016-10-11T17:14:54.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v1.0.5","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v1.0.5","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v1.0.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v1.0.5/manifests"},{"name":"v1.0.4","sha":"294f9c29747d6cde17a32d9f9d0133028e322617","kind":"tag","published_at":"2016-10-04T16:05:49.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v1.0.4","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v1.0.4","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v1.0.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v1.0.4/manifests"},{"name":"v1.0.2","sha":"a5c24f8dca7607d96bc30d800177003dec647612","kind":"tag","published_at":"2016-09-22T09:15:02.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v1.0.2","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v1.0.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v1.0.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v1.0.2/manifests"},{"name":"v1.0.1","sha":"0922176fc8a93e45373d4c6f6ba77c406e3a750a","kind":"tag","published_at":"2016-09-16T19:15:20.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v1.0.1","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v1.0.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v1.0.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v1.0.1/manifests"},{"name":"v1.0.0","sha":"728bc35211b6ce3680643f182ba9367c31bbee0f","kind":"tag","published_at":"2016-09-16T12:31:40.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v1.0.0","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v1.0.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v1.0.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v1.0.0/manifests"},{"name":"v0.22.5","sha":"c9660ab6b8a84d8b9ab219de83367822908c43ad","kind":"tag","published_at":"2016-08-02T17:56:49.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v0.22.5","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v0.22.5","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.22.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.22.5/manifests"},{"name":"v0.22.4","sha":"70d971bf3fb7d48f9f9a921fbd27605a139055c5","kind":"tag","published_at":"2016-07-28T11:21:14.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v0.22.4","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v0.22.4","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.22.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.22.4/manifests"},{"name":"v0.22.3","sha":"a6102d8876880dc1c56faa076e4df5bc518b437e","kind":"tag","published_at":"2016-07-26T19:55:02.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v0.22.3","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v0.22.3","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.22.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.22.3/manifests"},{"name":"v0.22.2","sha":"f9c27f048f6e09634bdfc78780fcc1f3e5ce87a6","kind":"tag","published_at":"2016-07-23T13:06:42.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v0.22.2","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v0.22.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.22.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.22.2/manifests"},{"name":"v0.22.1","sha":"2cb70cc8de372b0cbab56cea913018a4b98efccf","kind":"tag","published_at":"2016-07-16T11:28:08.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v0.22.1","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v0.22.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.22.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.22.1/manifests"},{"name":"v0.22.0","sha":"e65d3f8e43c8da6f375adc356a1117202196ab0c","kind":"tag","published_at":"2016-07-15T08:26:05.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v0.22.0","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v0.22.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.22.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.22.0/manifests"},{"name":"v0.22.0b6","sha":"83cb1bccd0cc845f07a460821b3ad7bf301d67b5","kind":"tag","published_at":"2016-07-14T13:02:36.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v0.22.0b6","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v0.22.0b6","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.22.0b6","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.22.0b6/manifests"},{"name":"v0.22.0b5","sha":"fb37ccb3dacbbc84ba082adcc9f0865eccb18e63","kind":"tag","published_at":"2016-07-14T12:49:04.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v0.22.0b5","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v0.22.0b5","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.22.0b5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.22.0b5/manifests"},{"name":"v0.22.0b4","sha":"895c2385f7570e0f17d4cf10e161b84941e29632","kind":"tag","published_at":"2016-07-14T12:15:30.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v0.22.0b4","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v0.22.0b4","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.22.0b4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.22.0b4/manifests"},{"name":"v0.22.0b3","sha":"fef7190e5cf34e140028604dfd9645637619a18c","kind":"tag","published_at":"2016-07-14T12:04:12.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v0.22.0b3","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v0.22.0b3","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.22.0b3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.22.0b3/manifests"},{"name":"v0.22.0b2","sha":"4d73b6becf74efba8ef3cf3d0e52ce158f52f10d","kind":"tag","published_at":"2016-07-14T11:49:21.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v0.22.0b2","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v0.22.0b2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.22.0b2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.22.0b2/manifests"},{"name":"v0.22.0b1","sha":"56d4f23d7a596b9d39075195620ca6639adff711","kind":"tag","published_at":"2016-07-14T11:32:01.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v0.22.0b1","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v0.22.0b1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.22.0b1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.22.0b1/manifests"},{"name":"v0.22.0b0","sha":"4ba11ea5f2b758be53a3fdd56fd5f204ef411544","kind":"tag","published_at":"2016-07-14T11:06:35.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v0.22.0b0","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v0.22.0b0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.22.0b0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.22.0b0/manifests"},{"name":"4v0.21.6","sha":"8ca24a4d35318f202a1ac1c1de658188b298364b","kind":"commit","published_at":"2016-05-05T11:27:04.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/4v0.21.6","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/4v0.21.6","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/4v0.21.6","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/4v0.21.6/manifests"},{"name":"v0.21.6","sha":"87a2c329823214aba5016023f8b19ad723dd70ca","kind":"tag","published_at":"2016-05-05T11:01:08.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v0.21.6","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v0.21.6","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.21.6","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.21.6/manifests"},{"name":"v0.21.5","sha":"b54248c6258317e94873751b9834a9d401198c71","kind":"tag","published_at":"2016-03-22T05:45:22.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v0.21.5","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v0.21.5","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.21.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.21.5/manifests"},{"name":"v0.21.4","sha":"a39bb382598e2a82a52e2198fdb16822a987f9f6","kind":"tag","published_at":"2016-03-13T11:10:33.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v0.21.4","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v0.21.4","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.21.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.21.4/manifests"},{"name":"v0.21.3","sha":"02187eea5e296a7b01a517960597c9b4fd7887c7","kind":"tag","published_at":"2016-03-12T17:21:02.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v0.21.3","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v0.21.3","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.21.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.21.3/manifests"},{"name":"v0.21.2","sha":"47cc7393d517f5c8fa979a7776fa95c0d128a149","kind":"tag","published_at":"2016-02-16T14:53:20.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v0.21.2","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v0.21.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.21.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.21.2/manifests"},{"name":"v0.21.1","sha":"96b982c9fd0e04f144c6bec6c5c668513ea9c816","kind":"tag","published_at":"2016-02-10T18:36:07.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v0.21.1","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v0.21.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.21.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.21.1/manifests"},{"name":"v0.21.0","sha":"822e90933c760fc911a5a841e8d66aa3ffa86472","kind":"tag","published_at":"2016-02-04T11:13:46.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v0.21.0","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v0.21.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.21.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.21.0/manifests"},{"name":"v0.21.0a2","sha":"72d5d352b41add6a146354b9ae9a4da4ae25b0f7","kind":"tag","published_at":"2016-01-08T02:04:05.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v0.21.0a2","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v0.21.0a2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.21.0a2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.21.0a2/manifests"},{"name":"v0.21.0a1","sha":"bf1a5428938c03ff16f381bb059e4f05f864f604","kind":"tag","published_at":"2016-01-08T02:02:19.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v0.21.0a1","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v0.21.0a1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.21.0a1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.21.0a1/manifests"},{"name":"v0.21.0a0","sha":"9680447c6cf2ad13d10066e6d1d80cd4af54e766","kind":"tag","published_at":"2016-01-08T01:32:07.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v0.21.0a0","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v0.21.0a0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.21.0a0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.21.0a0/manifests"},{"name":"v0.20.2","sha":"c7ff5da1b1b5ddcbd9a3673d4da2f0886627e03d","kind":"tag","published_at":"2016-01-07T21:43:17.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v0.20.2","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v0.20.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.20.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.20.2/manifests"},{"name":"v0.20.1","sha":"f8eed38dfb8a2de1c5e019c98cd03949cc9bc43d","kind":"tag","published_at":"2015-12-30T15:46:26.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v0.20.1","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v0.20.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.20.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.20.1/manifests"},{"name":"v0.20.0","sha":"53c06b05ef9a57d561905f856abe621e05577e15","kind":"tag","published_at":"2015-12-28T05:31:31.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v0.20.0","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v0.20.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.20.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.20.0/manifests"},{"name":"v0.19.0","sha":"a339ffef74cb8991720b9c204f9088e35fb3db99","kind":"tag","published_at":"2015-11-25T15:46:55.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v0.19.0","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v0.19.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.19.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.19.0/manifests"},{"name":"v0.18.4","sha":"8dd0a220d0e723aea5d99e610f3c0a0daca3f47a","kind":"tag","published_at":"2015-11-13T15:46:58.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v0.18.4","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v0.18.4","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.18.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.18.4/manifests"},{"name":"v0.18.3","sha":"3e68ce9289573c15e8982d77b9b0d9553ae442bb","kind":"tag","published_at":"2015-10-25T12:33:25.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v0.18.3","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v0.18.3","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.18.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.18.3/manifests"},{"name":"v0.18.2","sha":"4ae656a931349bd61c38bf27b27091cdb8ac13ff","kind":"tag","published_at":"2015-10-22T18:30:45.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v0.18.2","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v0.18.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.18.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.18.2/manifests"},{"name":"v0.18.1","sha":"5202ff3b673b3c94f500efbb396aaf3da33c3958","kind":"tag","published_at":"2015-10-20T16:35:34.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v0.18.1","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v0.18.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.18.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.18.1/manifests"},{"name":"v0.18.0","sha":"e85557e07e2d7e615192f531653c706c5cd13d0f","kind":"tag","published_at":"2015-10-19T08:10:46.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v0.18.0","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v0.18.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.18.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.18.0/manifests"},{"name":"v0.17.4","sha":"aaaa34b8907cd503c6c621187532216eb2a56d44","kind":"tag","published_at":"2015-09-29T10:48:27.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v0.17.4","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v0.17.4","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.17.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.17.4/manifests"},{"name":"v0.17.3","sha":"f5b6e7487caa0f9c00c01b7f018ceb6e5e76f234","kind":"tag","published_at":"2015-08-28T17:30:09.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v0.17.3","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v0.17.3","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.17.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.17.3/manifests"},{"name":"v0.17.2","sha":"0df8ba8f1612bbc5f7889d1b354e4165f8e7b2b1","kind":"tag","published_at":"2015-08-11T14:59:02.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v0.17.2","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v0.17.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.17.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.17.2/manifests"},{"name":"v0.17.1","sha":"9895f63e70a607fff009480618ec7d448fa95ef6","kind":"tag","published_at":"2015-08-10T23:07:48.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v0.17.1","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v0.17.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.17.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.17.1/manifests"},{"name":"v0.17.0","sha":"af78d314784f05f111208671f8efa6a1704518ee","kind":"tag","published_at":"2015-08-04T18:33:05.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v0.17.0","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v0.17.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.17.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.17.0/manifests"},{"name":"v0.16.6","sha":"951b81dcf8dd75ead2f373bbfbc01e92c6a11b03","kind":"tag","published_at":"2015-07-15T17:40:44.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v0.16.6","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v0.16.6","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.16.6","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.16.6/manifests"},{"name":"v0.16.5","sha":"843f0fd37af9be8241c86d77b8522a55474e6044","kind":"tag","published_at":"2015-06-13T13:57:31.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v0.16.5","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v0.16.5","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.16.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.16.5/manifests"},{"name":"v0.16.4","sha":"55dc13b026d0190ca971111ff8eec9c79f14ae20","kind":"tag","published_at":"2015-06-13T06:11:10.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v0.16.4","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v0.16.4","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.16.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.16.4/manifests"},{"name":"v0.16.3","sha":"5bdcce72dbdc43f2db6157604abeda8dd5af9872","kind":"tag","published_at":"2015-05-30T19:28:12.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v0.16.3","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v0.16.3","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.16.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.16.3/manifests"},{"name":"v0.16.2","sha":"376449b1d0511d763466e7d955c0fd0479aa51ae","kind":"tag","published_at":"2015-05-27T21:25:44.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v0.16.2","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v0.16.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.16.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.16.2/manifests"},{"name":"v0.16.1","sha":"badd4ce5be2289bb7bf2a6538d6bc607d33ae66a","kind":"tag","published_at":"2015-05-27T12:06:57.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v0.16.1","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v0.16.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.16.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.16.1/manifests"},{"name":"v0.16.0","sha":"3b3577aa699913662e36f29c53292d193eac2e7a","kind":"tag","published_at":"2015-05-26T17:19:14.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v0.16.0","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v0.16.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.16.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.16.0/manifests"},{"name":"v0.15.3","sha":"449e5988a8e06c8c1f51f46daedcf0372ab1fd07","kind":"tag","published_at":"2015-04-22T16:55:21.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v0.15.3","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v0.15.3","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.15.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.15.3/manifests"},{"name":"0.15.2","sha":"f1dcf0767c18ae0a2a1a921c45b731a12e40d465","kind":"commit","published_at":"2015-04-19T03:52:08.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/0.15.2","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/0.15.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/0.15.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/0.15.2/manifests"},{"name":"v0.15.2","sha":"6c796658ee144f8b1bdeb41e424623a5f2dd9f32","kind":"tag","published_at":"2015-04-19T03:51:07.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v0.15.2","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v0.15.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.15.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.15.2/manifests"},{"name":"v0.15.1","sha":"8bf7f187e15734645ddc529778534497bcfd4d8c","kind":"tag","published_at":"2015-03-31T23:14:39.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v0.15.1","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v0.15.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.15.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.15.1/manifests"},{"name":"v0.15.0","sha":"7ec6d39a7a3c545910f4a1d623d36172d0e4c72a","kind":"tag","published_at":"2015-03-27T16:05:00.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v0.15.0","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v0.15.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.15.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.15.0/manifests"},{"name":"v0.14.4","sha":"947c1a248bca1c34e826338d661aec93b4034f4d","kind":"tag","published_at":"2015-01-29T19:25:46.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v0.14.4","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v0.14.4","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.14.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.14.4/manifests"},{"name":"v0.14.3","sha":"ee35cfe4714cd1b13655958b4625e1570719e9d5","kind":"tag","published_at":"2015-01-28T12:41:02.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v0.14.3","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v0.14.3","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.14.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.14.3/manifests"},{"name":"v0.14.2","sha":"2d60f48c807116d2dd4ba23e8c63e4a90e07209a","kind":"tag","published_at":"2015-01-23T07:39:20.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v0.14.2","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v0.14.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.14.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.14.2/manifests"},{"name":"v0.14.1","sha":"08026b3974aa6e2682c77f0dd651675f3b0a101c","kind":"tag","published_at":"2015-01-15T20:55:03.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v0.14.1","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v0.14.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.14.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.14.1/manifests"},{"name":"v0.14.0","sha":"5aa55e7cea431ee675e5b73444c3e096eb2afbae","kind":"tag","published_at":"2015-01-15T20:43:05.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v0.14.0","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v0.14.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.14.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.14.0/manifests"},{"name":"v0.13.1","sha":"26163e70903072f4560d4e1bb0460b3da1f0c9df","kind":"tag","published_at":"2014-12-31T11:30:10.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v0.13.1","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v0.13.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.13.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.13.1/manifests"},{"name":"v0.13.0","sha":"7b95cab3bd110c7855a0db345fa5840a8211e2cd","kind":"tag","published_at":"2014-12-29T18:31:01.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v0.13.0","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v0.13.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.13.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.13.0/manifests"},{"name":"v0.12.0","sha":"f8826af316292e3092fe88fe468fd3936a4cd65f","kind":"tag","published_at":"2014-12-12T19:53:00.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v0.12.0","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v0.12.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.12.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.12.0/manifests"},{"name":"v0.11.0","sha":"3bc3c84a8cf1f52f780d51e1effd2a3ccba983a3","kind":"tag","published_at":"2014-11-29T16:34:19.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v0.11.0","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v0.11.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.11.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.11.0/manifests"},{"name":"v0.10.2","sha":"0813710e44b911e40809131521e108cdb8451c7b","kind":"tag","published_at":"2014-11-19T16:49:48.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v0.10.2","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v0.10.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.10.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.10.2/manifests"},{"name":"v0.10.1","sha":"4b863d30a39c2052c1ab72a21ec8b498fdf45a32","kind":"tag","published_at":"2014-11-17T13:03:03.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v0.10.1","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v0.10.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.10.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.10.1/manifests"},{"name":"v0.10.0","sha":"9c111cf28235b3bb5beea3fcc869e124d7549888","kind":"tag","published_at":"2014-11-13T12:46:51.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v0.10.0","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v0.10.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.10.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.10.0/manifests"},{"name":"v0.9.3","sha":"ad314e2120fe247f620d2a0d566a7e81273f8fe8","kind":"tag","published_at":"2014-10-30T12:52:06.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v0.9.3","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v0.9.3","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.9.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.9.3/manifests"},{"name":"v0.9.2","sha":"5f2b2c0d9f4c9ba97d29057b833edd110d2d22b1","kind":"tag","published_at":"2014-10-16T17:48:59.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v0.9.2","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v0.9.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.9.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.9.2/manifests"},{"name":"v0.9.1","sha":"8a44398aca58baeab809da9cbaeca8e616b3556d","kind":"tag","published_at":"2014-08-30T16:15:00.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v0.9.1","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v0.9.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.9.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.9.1/manifests"},{"name":"v0.9.0","sha":"76a348fd62cb2c8ac95b471194d51e31ee1e8679","kind":"tag","published_at":"2014-07-08T19:00:38.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v0.9.0","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v0.9.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.9.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.9.0/manifests"},{"name":"v0.8.4","sha":"4aa8a341e8eb78f298bd9651c0f22f1c25ff3ca6","kind":"tag","published_at":"2014-07-04T14:53:52.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v0.8.4","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v0.8.4","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.8.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.8.4/manifests"},{"name":"v0.8.3","sha":"b89c281a96135d4dd91a2297b2547e876614118b","kind":"tag","published_at":"2014-07-04T04:07:16.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v0.8.3","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v0.8.3","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.8.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.8.3/manifests"},{"name":"0.8.2","sha":"f2ddf9381420e7b94350dcaa0750b92e6414c259","kind":"tag","published_at":"2014-06-22T23:20:34.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/0.8.2","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/0.8.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/0.8.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/0.8.2/manifests"},{"name":"v0.8.1","sha":"1d41f138d15cf8d8fcdd9066eaf80a3717749dfe","kind":"tag","published_at":"2014-06-19T02:28:42.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v0.8.1","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v0.8.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.8.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.8.1/manifests"},{"name":"v0.8.0","sha":"f23546f92e206803248750f4f553002dfc82e2b8","kind":"tag","published_at":"2014-06-09T06:52:36.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v0.8.0","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v0.8.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.8.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.8.0/manifests"},{"name":"v0.7.3","sha":"5d7faef132d8fe510952ae739ed342f3ce482c8c","kind":"tag","published_at":"2014-05-19T20:21:45.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v0.7.3","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v0.7.3","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.7.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.7.3/manifests"},{"name":"v0.7.2","sha":"e4d7e76cc03952b6d207cc0e0681746e08bbf201","kind":"tag","published_at":"2014-05-14T10:52:16.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v0.7.2","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v0.7.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.7.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.7.2/manifests"},{"name":"v0.7.1","sha":"7ad75945e316f1fdbb23ae33d9b029e12bdd9ae1","kind":"tag","published_at":"2014-04-28T01:54:36.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v0.7.1","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v0.7.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.7.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.7.1/manifests"},{"name":"v0.7.0","sha":"48899a742cec9269c844a3940d9b6f2d669de001","kind":"tag","published_at":"2014-04-16T17:10:47.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v0.7.0","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v0.7.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.7.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.7.0/manifests"},{"name":"v.0.6.5","sha":"4bf945c2ad60bb61283f7d04eebae13205bc13d4","kind":"tag","published_at":"2014-03-29T15:41:26.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v.0.6.5","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v.0.6.5","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v.0.6.5","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v.0.6.5/manifests"},{"name":"v0.6.4","sha":"246474c4fc551de929d3384874973dba6121b354","kind":"tag","published_at":"2014-02-28T02:07:45.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v0.6.4","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v0.6.4","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.6.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.6.4/manifests"},{"name":"v0.6.3","sha":"066faba0eaa17c8a8ce9ed1cd4017b88f7da5344","kind":"tag","published_at":"2014-02-28T01:35:52.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v0.6.3","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v0.6.3","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.6.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.6.3/manifests"},{"name":"v0.6.2","sha":"9fe5dda985e66b3f65572c4b340ca8c3274099b7","kind":"tag","published_at":"2014-02-18T19:37:04.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v0.6.2","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v0.6.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.6.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.6.2/manifests"},{"name":"v0.6.1","sha":"37de40a4d402455e5b161be150a9a4f8c5166c73","kind":"tag","published_at":"2014-02-18T07:07:01.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v0.6.1","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v0.6.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.6.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.6.1/manifests"},{"name":"v0.5.0","sha":"5ac9f5a92461af2ae20b1057c549545f0d0461e2","kind":"tag","published_at":"2014-01-29T17:28:51.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v0.5.0","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v0.5.0","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.5.0","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.5.0/manifests"},{"name":"v0.4.2","sha":"5152e785dfa703e8c831f247b77eaee9c490d5a8","kind":"tag","published_at":"2013-11-14T21:53:12.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v0.4.2","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v0.4.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.4.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.4.2/manifests"},{"name":"v0.4.1","sha":"0f5c26a6a83e7626053f47bbef12857a243b109a","kind":"tag","published_at":"2013-11-12T19:36:47.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v0.4.1","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v0.4.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.4.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.4.1/manifests"},{"name":"v0.4","sha":"89b64a2455412e85e602549dccb152b206ea1d16","kind":"tag","published_at":"2013-11-07T05:42:55.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v0.4","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v0.4","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.4","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.4/manifests"},{"name":"v0.3","sha":"654218c3dc3788b8bbc71dfa973273dd55bb71b4","kind":"tag","published_at":"2013-11-04T19:01:36.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v0.3","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v0.3","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.3","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.3/manifests"},{"name":"v0.2","sha":"e5f4f88741c9d6e5ba9fc13a688fcb6657a495de","kind":"tag","published_at":"2013-10-25T18:27:39.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v0.2","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v0.2","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.2","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.2/manifests"},{"name":"v0.1","sha":"39170ed6beadbfb014646367fc3d3dc7617259cc","kind":"tag","published_at":"2013-10-25T18:17:14.000Z","download_url":"https://codeload.github.com/aio-libs/aiohttp/tar.gz/v0.1","html_url":"https://github.com/aio-libs/aiohttp/releases/tag/v0.1","dependencies_parsed_at":null,"dependency_job_id":null,"tag_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.1","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/aio-libs%2Faiohttp/tags/v0.1/manifests"}]},"repo_metadata_updated_at":"2024-01-06T13:58:01.699Z","dependent_packages_count":5267,"downloads":240311681,"downloads_period":"last-month","dependent_repos_count":66431,"rankings":{"downloads":0.009904494989976285,"dependent_repos_count":0.021459739144948614,"dependent_packages_count":0.004401997773322793,"stargazers_count":0.32538100207810977,"forks_count":0.5863827867213737,"docker_downloads_count":0.038700897090462885,"average":0.16437181963303235},"purl":"pkg:pypi/aiohttp","advisories":[{"uuid":"GSA_kwCzR0hTQS1nZncyLTRqdmgtd2dmZ84AA3K1","url":"https://github.com/advisories/GHSA-gfw2-4jvh-wgfg","title":"AIOHTTP has problems in HTTP parser (the python one, not llhttp)","description":"# Summary\nThe HTTP parser in AIOHTTP has numerous problems with header parsing, which could lead to request smuggling.\nThis parser is only used when `AIOHTTP_NO_EXTENSIONS` is enabled (or not using a prebuilt wheel).\n \n# Details\n\n## Bug 1: Bad parsing of `Content-Length` values\n\n### Description\nRFC 9110 says this:\n\u003e `Content-Length = 1*DIGIT`\n\nAIOHTTP does not enforce this rule, presumably because of an incorrect usage of the builtin `int` constructor. Because the `int` constructor accepts `+` and `-` prefixes, and digit-separating underscores, using `int` to parse CL values leads AIOHTTP to significant misinterpretation.\n\n### Examples\n```\nGET / HTTP/1.1\\r\\n\nContent-Length: -0\\r\\n\n\\r\\n\nX\n```\n```\nGET / HTTP/1.1\\r\\n\nContent-Length: +0_1\\r\\n\n\\r\\n\nX\n```\n\n### Suggested action\nVerify that a `Content-Length` value consists only of ASCII digits before parsing, as the standard requires.\n\n## Bug 2: Improper handling of NUL, CR, and LF in header values\n\n### Description\nRFC 9110 says this:\n\u003e Field values containing CR, LF, or NUL characters are invalid and dangerous, due to the varying ways that implementations might parse and interpret those characters; a recipient of CR, LF, or NUL within a field value MUST either reject the message or replace each of those characters with SP before further processing or forwarding of that message.\n\nAIOHTTP's HTTP parser does not enforce this rule, and will happily process header values containing these three forbidden characters without replacing them with SP.\n### Examples\n```\nGET / HTTP/1.1\\r\\n\nHeader: v\\x00alue\\r\\n\n\\r\\n\n```\n```\nGET / HTTP/1.1\\r\\n\nHeader: v\\ralue\\r\\n\n\\r\\n\n```\n```\nGET / HTTP/1.1\\r\\n\nHeader: v\\nalue\\r\\n\n\\r\\n\n```\n### Suggested action\nReject all messages with NUL, CR, or LF in a header value. The translation to space thing, while technically allowed, does not seem like a good idea to me.\n\n## Bug 3: Improper stripping of whitespace before colon in HTTP headers\n\n### Description\nRFC 9112 says this:\n\u003e No whitespace is allowed between the field name and colon. In the past, differences in the handling of such whitespace have led to security vulnerabilities in request routing and response handling. A server MUST reject, with a response status code of 400 (Bad Request), any received request message that contains whitespace between a header field name and colon.\n\nAIOHTTP does not enforce this rule, and will simply strip any whitespace before the colon in an HTTP header.\n\n### Example\n```\nGET / HTTP/1.1\\r\\n\nContent-Length : 1\\r\\n\n\\r\\n\nX\n```\n\n### Suggested action\nReject all messages with whitespace before a colon in a header field, as the standard requires.\n\n# PoC\nExample requests are embedded in the previous section. To reproduce these bugs, start an AIOHTTP server without llhttp (i.e. `AIOHTTP_NO_EXTENSIONS=1`) and send the requests given in the previous section. (e.g. by `printf`ing into `nc`)\n\n# Impact\nEach of these bugs can be used for request smuggling.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2023-11-14T22:20:59.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":6.9,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N","references":["https://github.com/aio-libs/aiohttp/security/advisories/GHSA-gfw2-4jvh-wgfg","https://nvd.nist.gov/vuln/detail/CVE-2023-47627","https://github.com/aio-libs/aiohttp/commit/d5c12ba890557a575c313bb3017910d7616fce3d","https://github.com/aio-libs/aiohttp/releases/tag/v3.8.6","https://github.com/pypa/advisory-database/tree/main/vulns/aiohttp/PYSEC-2023-246.yaml","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FUSJVQ7OQ55RWL4XAX2F5EZ73N4ZSH6U","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VDKQ6HM3KNDU4OQI476ZWT4O7DMSIT35","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WQYQL6WV535EEKSNH7KRARLLMOW5WXDM","https://github.com/advisories/GHSA-gfw2-4jvh-wgfg"],"source_kind":"github","identifiers":["GHSA-gfw2-4jvh-wgfg","CVE-2023-47627"],"repository_url":"https://github.com/aio-libs/aiohttp","blast_radius":33.274358451125195,"packages":[{"versions":[{"first_patched_version":"3.8.6","vulnerable_version_range":"\u003c 3.8.6"}],"ecosystem":"pypi","package_name":"aiohttp"}],"created_at":"2023-11-14T23:05:49.180Z","updated_at":"2024-09-04T20:01:59.000Z","epss_percentage":0.00181,"epss_percentile":0.40444},{"uuid":"GSA_kwCzR0hTQS03Z3B3LTh3bWMtcG04Z84AA7Ls","url":"https://github.com/advisories/GHSA-7gpw-8wmc-pm8g","title":"aiohttp Cross-site Scripting vulnerability on index pages for static file handling","description":"### Summary\n\nA XSS vulnerability exists on index pages for static file handling.\n\n### Details\n\nWhen using `web.static(..., show_index=True)`, the resulting index pages do not escape file names.\n\nIf users can upload files with arbitrary filenames to the static directory, the server is vulnerable to XSS attacks.\n\n### Workaround\n\nWe have always recommended using a reverse proxy server (e.g. nginx) for serving static files. Users following the recommendation are unaffected.\n\nOther users can disable `show_index` if unable to upgrade.\n\n-----\n\nPatch: https://github.com/aio-libs/aiohttp/pull/8319/files","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2024-04-18T13:45:21.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://github.com/aio-libs/aiohttp/security/advisories/GHSA-7gpw-8wmc-pm8g","https://github.com/aio-libs/aiohttp/pull/8319/files","https://github.com/aio-libs/aiohttp/commit/28335525d1eac015a7e7584137678cbb6ff19397","https://nvd.nist.gov/vuln/detail/CVE-2024-27306","https://github.com/aio-libs/aiohttp/pull/8319","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2EXRGTN2WG7VZLUZ7WOXU5GQJKCPPHKP","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NWEI6NIHZ3G7DURDZVMRK7ZEFC2BTD3U","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZIVBMPEY7WWOFMC3CWXFBRQPFECV4SW3","https://github.com/advisories/GHSA-7gpw-8wmc-pm8g"],"source_kind":"github","identifiers":["GHSA-7gpw-8wmc-pm8g","CVE-2024-27306"],"repository_url":"https://github.com/aio-libs/aiohttp","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"3.9.4","vulnerable_version_range":"\u003c 3.9.4"}],"ecosystem":"pypi","package_name":"aiohttp"}],"created_at":"2024-04-18T14:04:56.118Z","updated_at":"2024-05-02T03:30:33.000Z","epss_percentage":0.00304,"epss_percentile":0.52918},{"uuid":"GSA_kwCzR0hTQS1xM3F4LWM2ZzItN3B3Ms4AA3Yd","url":"https://github.com/advisories/GHSA-q3qx-c6g2-7pw2","title":"aiohttp's ClientSession is vulnerable to CRLF injection via version","description":"### Summary\nImproper validation make it possible for an attacker to modify the HTTP request (e.g. to insert a new header) or even create a new HTTP request if the attacker controls the HTTP version.\n\n### Details\nThe vulnerability only occurs if the attacker can control the HTTP version of the request (including its type).\nFor example if an unvalidated JSON value is used as a version and the attacker is then able to pass an array as the `version` parameter.\nFurthermore, the vulnerability only occurs when the `Connection` header is passed to the `headers` parameter.\n\nAt this point, the library will use the parsed value to create the request. If a list is passed, then it bypasses validation and it is possible to perform CRLF injection.\n\n### PoC\nThe POC below shows an example of providing an unvalidated array as a version:\nhttps://gist.github.com/jnovikov/184afb593d9c2114d77f508e0ccd508e\n\n### Impact\nCRLF injection leading to Request Smuggling.\n\n### Workaround\nIf these specific conditions are met and you are unable to upgrade, then validate the user input to the `version` parameter to ensure it is a `str`.\n\nPatch: https://github.com/aio-libs/aiohttp/pull/7835/files","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2023-11-27T23:17:42.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":6.9,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N","references":["https://github.com/aio-libs/aiohttp/security/advisories/GHSA-q3qx-c6g2-7pw2","https://gist.github.com/jnovikov/184afb593d9c2114d77f508e0ccd508e","https://nvd.nist.gov/vuln/detail/CVE-2023-49081","https://github.com/aio-libs/aiohttp/pull/7835/files","https://github.com/aio-libs/aiohttp/commit/1e86b777e61cf4eefc7d92fa57fa19dcc676013b","https://github.com/pypa/advisory-database/tree/main/vulns/aiohttp/PYSEC-2023-250.yaml","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TY5SI6NK5243DEEDQUFKQKW5GQNKQUMA","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WSYWMP64ZFCTC3VO6RY6EC6VSSMV6I3A","https://github.com/advisories/GHSA-q3qx-c6g2-7pw2"],"source_kind":"github","identifiers":["GHSA-q3qx-c6g2-7pw2","CVE-2023-49081"],"repository_url":"https://github.com/aio-libs/aiohttp","blast_radius":33.274358451125195,"packages":[{"versions":[{"first_patched_version":"3.9.0","vulnerable_version_range":"\u003c 3.9.0"}],"ecosystem":"pypi","package_name":"aiohttp"}],"created_at":"2023-11-28T00:05:56.832Z","updated_at":"2024-09-04T18:56:36.000Z","epss_percentage":0.00242,"epss_percentile":0.47552},{"uuid":"GSA_kwCzR0hTQS1wamp3LXFoZzgtcDJwOc4AA3Yb","url":"https://github.com/advisories/GHSA-pjjw-qhg8-p2p9","title":"aiohttp has vulnerable dependency that is vulnerable to request smuggling","description":"### Summary\nllhttp 8.1.1 is vulnerable to two request smuggling vulnerabilities.\nDetails have not been disclosed yet, so refer to llhttp for future information.\nThe issue is resolved by using llhttp 9+ (which is included in aiohttp 3.8.6+).","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2023-11-27T23:15:38.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://github.com/aio-libs/aiohttp/security/advisories/GHSA-pjjw-qhg8-p2p9","https://github.com/aio-libs/aiohttp/commit/996de2629ef6b4c2934a7c04dfd49d0950d4c43b","https://github.com/aio-libs/aiohttp/commit/bcc416e533796d04fb8124ef1e7686b1f338767a","https://github.com/advisories/GHSA-pjjw-qhg8-p2p9"],"source_kind":"github","identifiers":["GHSA-pjjw-qhg8-p2p9"],"repository_url":"https://github.com/aio-libs/aiohttp","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"3.8.6","vulnerable_version_range":"\u003c 3.8.6"}],"ecosystem":"pypi","package_name":"aiohttp"}],"created_at":"2023-11-28T00:05:56.873Z","updated_at":"2023-11-27T23:15:39.000Z","epss_percentage":null,"epss_percentile":null},{"uuid":"MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXY2d3AtNG02Zi1nY2pn","url":"https://github.com/advisories/GHSA-v6wp-4m6f-gcjg","title":"`aiohttp` Open Redirect vulnerability (`normalize_path_middleware` middleware)","description":"### Impact\n\nOpen redirect vulnerability — a maliciously crafted link to an aiohttp-based web-server could redirect the browser to a different website.\n\nIt is caused by a bug in the `aiohttp.web_middlewares.normalize_path_middleware` middleware.\n\n### Patches\n\nThis security problem has been fixed in v3.7.4. Upgrade your dependency as follows:\n[`pip install aiohttp \u003e= 3.7.4`]\n\n### Workarounds\n\nIf upgrading is not an option for you, a workaround can be to avoid using `aiohttp.web_middlewares.normalize_path_middleware` in your applications.\n\n### References\n\n* [aiohttp @ PyPI]\n* [GHSA-v6wp-4m6f-gcjg]\n* [OWASP page on open redirects]\n\n### For more information\n\nIf you have any questions or comments about this advisory:\n* Open an issue in the [aiohttp repo](https://github.com/aio-libs/aiohttp/issues/new/choose)\n* Email us at wk+aio-libs-security@sydorenko.org.ua and/or andrew.svetlov+aio-libs-security@gmail.com\n\nCredit: [Jelmer Vernooĳ] and [Beast Glatisant].\n\n[aiohttp @ PyPI]: https://pypi.org/p/aiohttp\n[`pip install aiohttp \u003e= 3.7.4`]: https://pypi.org/project/aiohttp/3.7.4/\n[GHSA-v6wp-4m6f-gcjg]: https://github.com/aio-libs/aiohttp/security/advisories/GHSA-v6wp-4m6f-gcjg\n[OWASP page on open redirects]:\nhttps://cheatsheetseries.owasp.org/cheatsheets/Unvalidated_Redirects_and_Forwards_Cheat_Sheet.html\n\n[Jelmer Vernooĳ]: https://jelmer.uk\n[Beast Glatisant]: https://github.com/g147","origin":"UNSPECIFIED","severity":"LOW","published_at":"2021-02-26T02:11:57.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":2.3,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N","references":["https://github.com/aio-libs/aiohttp/security/advisories/GHSA-v6wp-4m6f-gcjg","https://github.com/aio-libs/aiohttp/commit/2545222a3853e31ace15d87ae0e2effb7da0c96b","https://github.com/aio-libs/aiohttp/blob/master/CHANGES.rst#374-2021-02-25","https://nvd.nist.gov/vuln/detail/CVE-2021-21330","https://www.debian.org/security/2021/dsa-4864","https://security.gentoo.org/glsa/202208-19","https://github.com/pypa/advisory-database/tree/main/vulns/aiohttp/PYSEC-2021-76.yaml","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FU7ENI54JNEK3PHEFGCE46DGMFNTVU6L","https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JN3V7CZJRT4QFCVXB6LDPCJH7NAOFCA5","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FU7ENI54JNEK3PHEFGCE46DGMFNTVU6L","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JN3V7CZJRT4QFCVXB6LDPCJH7NAOFCA5","https://pypi.org/project/aiohttp","https://github.com/advisories/GHSA-v6wp-4m6f-gcjg"],"source_kind":"github","identifiers":["GHSA-v6wp-4m6f-gcjg","CVE-2021-21330"],"repository_url":"https://github.com/aio-libs/aiohttp","blast_radius":11.091452817041729,"packages":[{"versions":[{"first_patched_version":"3.7.4","vulnerable_version_range":"\u003c 3.7.4"}],"ecosystem":"pypi","package_name":"aiohttp"}],"created_at":"2022-12-21T16:12:45.984Z","updated_at":"2024-09-03T21:02:50.000Z","epss_percentage":0.00554,"epss_percentile":0.66714},{"uuid":"GSA_kwCzR0hTQS1yd3FyLWMzNDgtbTV3cs4AAs7f","url":"https://github.com/advisories/GHSA-rwqr-c348-m5wr","title":"Withdrawn: Denial of Service in aiohttp","description":"## Withdrawn\nThis advisory has been withdrawn because the maintainers of aiohttp and multiple third parties disputed the validity of the issue. There is not sufficient evidence for the claims in the original report.\n\n## Original Description\naiohttp v3.8.1 was discovered to contain an invalid IPv6 URL which can lead to a Denial of Service (DoS).","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2022-06-24T00:00:31.000Z","withdrawn_at":"2022-06-28T16:39:06.000Z","classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2022-33124","https://github.com/aio-libs/aiohttp/issues/6772","https://github.com/advisories/GHSA-rwqr-c348-m5wr"],"source_kind":"github","identifiers":["GHSA-rwqr-c348-m5wr","CVE-2022-33124"],"repository_url":"https://github.com/aio-libs/aiohttp","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":null,"vulnerable_version_range":"\u003c= 3.8.1"}],"ecosystem":"pypi","package_name":"aiohttp"}],"created_at":"2022-12-21T16:12:16.941Z","updated_at":"2023-01-27T05:05:18.000Z","epss_percentage":0.00046,"epss_percentile":0.13755},{"uuid":"GSA_kwCzR0hTQS1qd2h4LXhjZzYtOHhoas4AA-ge","url":"https://github.com/advisories/GHSA-jwhx-xcg6-8xhj","title":"In aiohttp, compressed files as symlinks are not protected from path traversal","description":"### Summary\nStatic routes which contain files with compressed variants (`.gz` or `.br` extension) were vulnerable to path traversal outside the root directory if those variants are symbolic links.\n\n### Details\nThe server protects static routes from path traversal outside the root directory when `follow_symlinks=False` (default).  It does this by resolving the requested URL to an absolute path and then checking that path relative to the root.  However, these checks are not performed when looking for compressed variants in the `FileResponse` class, and symbolic links are then automatically followed when performing `Path.stat()` and `Path.open()` to send the file.\n\n### Impact\nServers with static routes that contain compressed variants as symbolic links, pointing outside the root directory, or that permit users to upload or create such links, are impacted.\n\n----\n\nPatch: https://github.com/aio-libs/aiohttp/pull/8653/files","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2024-08-09T16:49:58.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":6.3,"cvss_vector":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N","references":["https://github.com/aio-libs/aiohttp/security/advisories/GHSA-jwhx-xcg6-8xhj","https://github.com/aio-libs/aiohttp/pull/8653","https://github.com/aio-libs/aiohttp/commit/ce2e9758814527589b10759a20783fb03b98339f","https://nvd.nist.gov/vuln/detail/CVE-2024-42367","https://github.com/aio-libs/aiohttp/blob/e0ff5246e1d29b7710ab1a2bbc972b48169f1c05/aiohttp/web_fileresponse.py#L177","https://github.com/aio-libs/aiohttp/blob/e0ff5246e1d29b7710ab1a2bbc972b48169f1c05/aiohttp/web_urldispatcher.py#L674","https://github.com/advisories/GHSA-jwhx-xcg6-8xhj"],"source_kind":"github","identifiers":["GHSA-jwhx-xcg6-8xhj","CVE-2024-42367"],"repository_url":"https://github.com/aio-libs/aiohttp","blast_radius":30.380935977114305,"packages":[{"versions":[{"first_patched_version":"3.10.2","vulnerable_version_range":"\u003c 3.10.2"}],"ecosystem":"pypi","package_name":"aiohttp"}],"created_at":"2024-08-09T17:05:27.275Z","updated_at":"2024-08-12T16:02:22.000Z","epss_percentage":0.00187,"epss_percentile":0.41062},{"uuid":"GSA_kwCzR0hTQS0yN21mLWdocW0tajNqOM4ABBeT","url":"https://github.com/advisories/GHSA-27mf-ghqm-j3j8","title":"aiohttp has a memory leak when middleware is enabled when requesting a resource with a non-allowed method","description":"### Summary\n\nA memory leak can occur when a request produces a `MatchInfoError`. This was caused by adding an entry to a cache on each request, due to the building of each `MatchInfoError` producing a unique cache entry.\n\n### Impact\n\nIf the user is making use of any middlewares with `aiohttp.web` then it is advisable to upgrade immediately.\n\nAn attacker may be able to exhaust the memory resources of a server by sending a substantial number (100,000s to millions) of such requests.\n\n-----\n\nPatch: https://github.com/aio-libs/aiohttp/commit/bc15db61615079d1b6327ba42c682f758fa96936","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2024-11-18T21:02:17.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":6.9,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N","references":["https://github.com/aio-libs/aiohttp/security/advisories/GHSA-27mf-ghqm-j3j8","https://github.com/aio-libs/aiohttp/commit/bc15db61615079d1b6327ba42c682f758fa96936","https://nvd.nist.gov/vuln/detail/CVE-2024-52303","https://github.com/advisories/GHSA-27mf-ghqm-j3j8"],"source_kind":"github","identifiers":["GHSA-27mf-ghqm-j3j8","CVE-2024-52303"],"repository_url":"https://github.com/aio-libs/aiohttp","blast_radius":33.274358451125195,"packages":[{"versions":[{"first_patched_version":"3.10.11","vulnerable_version_range":"\u003e= 3.10.6, \u003c 3.10.11"}],"ecosystem":"pypi","package_name":"aiohttp"}],"created_at":"2024-11-18T22:06:44.967Z","updated_at":"2024-11-19T20:48:53.000Z","epss_percentage":0.00088,"epss_percentile":0.26583},{"uuid":"GSA_kwCzR0hTQS01aDg2LThtdjItanE5Zs4AA47u","url":"https://github.com/advisories/GHSA-5h86-8mv2-jq9f","title":"aiohttp is vulnerable to directory traversal","description":"### Summary\nImproperly configuring static resource resolution in aiohttp when used as a web server can result in the unauthorized reading of arbitrary files on the system.\n\n### Details\nWhen using aiohttp as a web server and configuring static routes, it is necessary to specify the root path for static files. Additionally, the option 'follow_symlinks' can be used to determine whether to follow symbolic links outside the static root directory. When 'follow_symlinks' is set to True, there is no validation to check if a given file path is within the root directory.This can lead to directory traversal vulnerabilities, resulting in unauthorized access to arbitrary files on the system, even when symlinks are not present.\n\ni.e. An application is only vulnerable with setup code like:\n```\napp.router.add_routes([\n    web.static(\"/static\", \"static/\", follow_symlinks=True),  # Remove follow_symlinks to avoid the vulnerability\n])\n```\n\n### Impact\nThis is a directory traversal vulnerability with CWE ID 22. When using aiohttp as a web server and enabling static resource resolution with `follow_symlinks` set to True, it can lead to this vulnerability. This vulnerability has been present since the introduction of the `follow_symlinks` parameter.\n\n### Workaround\nEven if upgrading to a patched version of aiohttp, we recommend following these steps regardless.\n\nIf using `follow_symlinks=True` outside of a restricted local development environment, disable the option immediately. This option is NOT needed to follow symlinks which point to a location _within_ the static root directory, it is _only_ intended to allow a symlink to break out of the static directory. Even with this CVE fixed, there is still a substantial risk of misconfiguration when using this option on a server that accepts requests from remote users.\n\nAdditionally, aiohttp has always recommended using a reverse proxy server (such as nginx) to handle static resources and _not_ to use these static resources in aiohttp for production environments. Doing so also protects against this vulnerability, and is why we expect the number of affected users to be very low.\n\n-----\n\nPatch: https://github.com/aio-libs/aiohttp/pull/8079/files","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2024-01-29T22:31:03.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":8.2,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N","references":["https://github.com/aio-libs/aiohttp/security/advisories/GHSA-5h86-8mv2-jq9f","https://github.com/aio-libs/aiohttp/pull/8079/files","https://github.com/aio-libs/aiohttp/commit/1c335944d6a8b1298baf179b7c0b3069f10c514b","https://nvd.nist.gov/vuln/detail/CVE-2024-23334","https://github.com/aio-libs/aiohttp/pull/8079","https://github.com/pypa/advisory-database/tree/main/vulns/aiohttp/PYSEC-2024-24.yaml","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ICUOCFGTB25WUT336BZ4UNYLSZOUVKBD","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XXWVZIVAYWEBHNRIILZVB3R3SDQNNAA7","https://github.com/advisories/GHSA-5h86-8mv2-jq9f"],"source_kind":"github","identifiers":["GHSA-5h86-8mv2-jq9f","CVE-2024-23334"],"repository_url":"https://github.com/aio-libs/aiohttp","blast_radius":39.543440478148774,"packages":[{"versions":[{"first_patched_version":"3.9.2","vulnerable_version_range":"\u003e= 1.0.5, \u003c 3.9.2"}],"ecosystem":"pypi","package_name":"aiohttp"}],"created_at":"2024-01-29T23:04:50.951Z","updated_at":"2025-05-16T01:11:13.057Z","epss_percentage":0.93264,"epss_percentile":0.99793},{"uuid":"GSA_kwCzR0hTQS14eDlwLXh4dmgtN2c4as4AA3Hw","url":"https://github.com/advisories/GHSA-xx9p-xxvh-7g8j","title":"Aiohttp has inconsistent interpretation of `Content-Length` vs. `Transfer-Encoding` differing in C and Python fallbacks","description":"### Impact\n\nAiohttp has a security vulnerability regarding the inconsistent interpretation of the http protocol. As we know that HTTP/1.1 is persistent, if we have both Content-Length(CL) and Transfer-Encoding(TE) it can lead to incorrect interpretation of two entities that parse the HTTP and we can poison other sockets with this incorrect interpretation.\n\nA possible Proof-of-Concept (POC) would be a configuration with a reverse proxy(frontend) that accepts both CL and TE headers and aiohttp as backend. As aiohttp parses anything with chunked, we can pass a chunked123 as TE, the frontend entity will ignore this header and will parse Content-Length. I can give a Dockerfile with the configuration if you want.\n\nThe impact of this vulnerability is that it is possible to bypass any proxy rule, poisoning sockets to other users like passing Authentication Headers, also if it is present an Open Redirect (just like CVE-2021-21330) we can combine it to redirect random users to our website and log the request.\n\n\n### References\n\n- https://github.com/aio-libs/aiohttp/commit/f016f0680e4ace6742b03a70cb0382ce86abe371","origin":"UNSPECIFIED","severity":"LOW","published_at":"2023-11-14T20:36:25.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":2.3,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N","references":["https://github.com/aio-libs/aiohttp/security/advisories/GHSA-xx9p-xxvh-7g8j","https://github.com/aio-libs/aiohttp/commit/f016f0680e4ace6742b03a70cb0382ce86abe371","https://github.com/aio-libs/aiohttp/releases/tag/v3.8.0","https://nvd.nist.gov/vuln/detail/CVE-2023-47641","https://github.com/pypa/advisory-database/tree/main/vulns/aiohttp/PYSEC-2023-247.yaml","https://github.com/advisories/GHSA-xx9p-xxvh-7g8j"],"source_kind":"github","identifiers":["GHSA-xx9p-xxvh-7g8j","CVE-2023-47641"],"repository_url":"https://github.com/aio-libs/aiohttp","blast_radius":11.091452817041729,"packages":[{"versions":[{"first_patched_version":"3.8.0","vulnerable_version_range":"\u003c 3.8.0"}],"ecosystem":"pypi","package_name":"aiohttp"}],"created_at":"2023-11-14T21:06:02.757Z","updated_at":"2024-09-04T20:00:53.000Z","epss_percentage":0.00151,"epss_percentile":0.36794},{"uuid":"GSA_kwCzR0hTQS00NWM0LTh3eDUtcXc2d84AA00K","url":"https://github.com/advisories/GHSA-45c4-8wx5-qw6w","title":"aiohttp.web.Application vulnerable to HTTP request smuggling via llhttp HTTP request parser","description":"### Impact\n\naiohttp v3.8.4 and earlier are [bundled with llhttp v6.0.6](https://github.com/aio-libs/aiohttp/blob/v3.8.4/.gitmodules) which is vulnerable to CVE-2023-30589. The vulnerable code is used by aiohttp for its HTTP request parser when available which is the default case when installing from a wheel.\n\nThis vulnerability only affects users of aiohttp as an HTTP server (ie `aiohttp.Application`), you are not affected by this vulnerability if you are using aiohttp as an HTTP client library (ie `aiohttp.ClientSession`).\n\n### Reproducer\n\n```python\nfrom aiohttp import web\n\nasync def example(request: web.Request):\n    headers = dict(request.headers)\n    body = await request.content.read()\n    return web.Response(text=f\"headers: {headers} body: {body}\")\n\napp = web.Application()\napp.add_routes([web.post('/', example)])\nweb.run_app(app)\n```\n\nSending a crafted HTTP request will cause the server to misinterpret one of the HTTP header values leading to HTTP request smuggling.\n\n```console\n$ printf \"POST / HTTP/1.1\\r\\nHost: localhost:8080\\r\\nX-Abc: \\rxTransfer-Encoding: chunked\\r\\n\\r\\n1\\r\\nA\\r\\n0\\r\\n\\r\\n\" \\\n  | nc localhost 8080\n\nExpected output:\n  headers: {'Host': 'localhost:8080', 'X-Abc': '\\rxTransfer-Encoding: chunked'} body: b''\n\nActual output (note that 'Transfer-Encoding: chunked' is an HTTP header now and body is treated differently)\n  headers: {'Host': 'localhost:8080', 'X-Abc': '', 'Transfer-Encoding': 'chunked'} body: b'A'\n```\n\n### Patches\n\nUpgrade to the latest version of aiohttp to resolve this vulnerability. It has been fixed in v3.8.5: [`pip install aiohttp \u003e= 3.8.5`](https://pypi.org/project/aiohttp/3.8.5/)\n\n### Workarounds\n\nIf you aren't able to upgrade you can reinstall aiohttp using `AIOHTTP_NO_EXTENSIONS=1` as an environment variable to disable the llhttp HTTP request parser implementation. The pure Python implementation isn't vulnerable to request smuggling:\n\n```console\n$ python -m pip uninstall --yes aiohttp\n$ AIOHTTP_NO_EXTENSIONS=1 python -m pip install --no-binary=aiohttp --no-cache aiohttp\n```\n\n### References\n\n* https://nvd.nist.gov/vuln/detail/CVE-2023-30589\n* https://hackerone.com/reports/2001873\n","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2023-07-20T14:52:00.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":6.9,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N","references":["https://github.com/aio-libs/aiohttp/security/advisories/GHSA-45c4-8wx5-qw6w","https://nvd.nist.gov/vuln/detail/CVE-2023-37276","https://github.com/aio-libs/aiohttp/commit/9337fb3f2ab2b5f38d7e98a194bde6f7e3d16c40","https://github.com/aio-libs/aiohttp/commit/9c13a52c21c23dfdb49ed89418d28a5b116d0681","https://hackerone.com/reports/2001873","https://github.com/aio-libs/aiohttp/blob/v3.8.4/.gitmodules","https://github.com/aio-libs/aiohttp","https://github.com/pypa/advisory-database/tree/main/vulns/aiohttp/PYSEC-2023-120.yaml","https://github.com/advisories/GHSA-45c4-8wx5-qw6w"],"source_kind":"github","identifiers":["GHSA-45c4-8wx5-qw6w","CVE-2023-37276"],"repository_url":"https://github.com/aio-libs/aiohttp","blast_radius":33.274358451125195,"packages":[{"versions":[{"first_patched_version":"3.8.5","vulnerable_version_range":"\u003c= 3.8.4"}],"ecosystem":"pypi","package_name":"aiohttp"}],"created_at":"2023-07-20T15:05:11.590Z","updated_at":"2024-09-03T21:33:37.000Z","epss_percentage":0.05842,"epss_percentile":0.89979},{"uuid":"GSA_kwCzR0hTQS04NDk1LTRnM2cteDdwcs4ABBeU","url":"https://github.com/advisories/GHSA-8495-4g3g-x7pr","title":"aiohttp allows request smuggling due to incorrect parsing of chunk extensions","description":"### Summary\nThe Python parser parses newlines in chunk extensions incorrectly which can lead to request smuggling vulnerabilities under certain conditions.\n\n### Impact\nIf a pure Python version of aiohttp is installed (i.e. without the usual C extensions) or `AIOHTTP_NO_EXTENSIONS` is enabled, then an attacker may be able to execute a request smuggling attack to bypass certain firewalls or proxy protections.\n\n-----\n\nPatch: https://github.com/aio-libs/aiohttp/commit/259edc369075de63e6f3a4eaade058c62af0df71","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2024-11-18T21:02:32.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":6.3,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","references":["https://github.com/aio-libs/aiohttp/security/advisories/GHSA-8495-4g3g-x7pr","https://github.com/aio-libs/aiohttp/commit/259edc369075de63e6f3a4eaade058c62af0df71","https://nvd.nist.gov/vuln/detail/CVE-2024-52304","https://github.com/advisories/GHSA-8495-4g3g-x7pr"],"source_kind":"github","identifiers":["GHSA-8495-4g3g-x7pr","CVE-2024-52304"],"repository_url":"https://github.com/aio-libs/aiohttp","blast_radius":30.380935977114305,"packages":[{"versions":[{"first_patched_version":"3.10.11","vulnerable_version_range":"\u003c= 3.10.10"}],"ecosystem":"pypi","package_name":"aiohttp"}],"created_at":"2024-11-18T22:06:44.743Z","updated_at":"2024-11-19T20:49:41.000Z","epss_percentage":0.00153,"epss_percentile":0.37108},{"uuid":"GSA_kwCzR0hTQS04cXB3LXhxeGotaDRyMs4AA47q","url":"https://github.com/advisories/GHSA-8qpw-xqxj-h4r2","title":"aiohttp's HTTP parser (the python one, not llhttp) still overly lenient about separators","description":"### Summary\nSecurity-sensitive parts of the *Python HTTP parser* retained minor differences in allowable character sets, that must trigger error handling to robustly match frame boundaries of proxies in order to protect against injection of additional requests. Additionally, validation could trigger exceptions that were not handled consistently with processing of other malformed input.\n\n### Details\nThese problems are rooted in pattern matching protocol elements, previously improved by PR #3235 and GHSA-gfw2-4jvh-wgfg:\n\n1. The expression `HTTP/(\\d).(\\d)` lacked another backslash to clarify that the separator should be a literal dot, not just *any* Unicode code point (result: `HTTP/(\\d)\\.(\\d)`).\n\n2. The HTTP version was permitting Unicode digits, where only ASCII digits are standards-compliant.\n\n3. Distinct regular expressions for validating HTTP Method and Header field names were used - though both should (at least) apply the common restrictions of rfc9110 `token`.\n\n### PoC\n`GET / HTTP/1ö1`\n`GET / HTTP/1.𝟙`\n`GET/: HTTP/1.1`\n`Content-Encoding?: chunked`\n\n### Impact\nPrimarily concerns running an aiohttp server without llhttp:\n 1. **behind a proxy**: Being more lenient than internet standards require could, depending on deployment environment, assist in request smuggling.\n 2. **directly accessible** or exposed behind proxies relaying malformed input: the unhandled exception could cause excessive resource consumption on the application server and/or its logging facilities.\n\n-----\n\nPatch: https://github.com/aio-libs/aiohttp/pull/8074/files","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2024-01-29T22:30:07.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":6.9,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N","references":["https://github.com/aio-libs/aiohttp/security/advisories/GHSA-8qpw-xqxj-h4r2","https://github.com/aio-libs/aiohttp/security/advisories/GHSA-gfw2-4jvh-wgfg","https://github.com/aio-libs/aiohttp/pull/3235","https://github.com/aio-libs/aiohttp/pull/8074/files","https://github.com/aio-libs/aiohttp/commit/33ccdfb0a12690af5bb49bda2319ec0907fa7827","https://nvd.nist.gov/vuln/detail/CVE-2024-23829","https://github.com/aio-libs/aiohttp/pull/8074","https://github.com/pypa/advisory-database/tree/main/vulns/aiohttp/PYSEC-2024-26.yaml","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ICUOCFGTB25WUT336BZ4UNYLSZOUVKBD","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XXWVZIVAYWEBHNRIILZVB3R3SDQNNAA7","https://github.com/advisories/GHSA-8qpw-xqxj-h4r2"],"source_kind":"github","identifiers":["GHSA-8qpw-xqxj-h4r2","CVE-2024-23829"],"repository_url":"https://github.com/aio-libs/aiohttp","blast_radius":33.274358451125195,"packages":[{"versions":[{"first_patched_version":"3.9.2","vulnerable_version_range":"\u003c 3.9.2"}],"ecosystem":"pypi","package_name":"aiohttp"}],"created_at":"2024-01-29T23:04:51.121Z","updated_at":"2024-09-04T19:51:23.000Z","epss_percentage":0.0023,"epss_percentile":0.45872},{"uuid":"GSA_kwCzR0hTQS1xdnJ3LXY5cnYtNXJqeM4AA3Yc","url":"https://github.com/advisories/GHSA-qvrw-v9rv-5rjx","title":"aiohttp's ClientSession is vulnerable to CRLF injection via method","description":"### Summary\nImproper validation makes it possible for an attacker to modify the HTTP request (e.g. insert a new header) or even create a new HTTP request if the attacker controls the HTTP method.\n\n### Details\nThe vulnerability occurs only if the attacker can control the HTTP method (GET, POST etc.) of the request.\n\nPrevious releases performed no validation on the provided value. If an attacker controls the HTTP method it will be used as is and can lead to HTTP request smuggling.\n\n### PoC\nA minimal example can be found here:\nhttps://gist.github.com/jnovikov/7f411ae9fe6a9a7804cf162a3bdbb44b\n\n### Impact\nIf the attacker can control the HTTP version of the request it will be able to modify the request (request smuggling).\n\n### Workaround\nIf unable to upgrade and using user-provided values for the request method, perform manual validation of the user value (e.g. by restricting it to a few known values like GET, POST etc.).\n\nPatch: https://github.com/aio-libs/aiohttp/pull/7806/files","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2023-11-27T23:17:24.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":6.9,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N","references":["https://github.com/aio-libs/aiohttp/security/advisories/GHSA-qvrw-v9rv-5rjx","https://gist.github.com/jnovikov/7f411ae9fe6a9a7804cf162a3bdbb44b","https://nvd.nist.gov/vuln/detail/CVE-2023-49082","https://github.com/aio-libs/aiohttp/pull/7806/files","https://github.com/aio-libs/aiohttp/commit/e4ae01c2077d2cfa116aa82e4ff6866857f7c466","https://github.com/pypa/advisory-database/tree/main/vulns/aiohttp/PYSEC-2023-251.yaml","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TY5SI6NK5243DEEDQUFKQKW5GQNKQUMA","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WSYWMP64ZFCTC3VO6RY6EC6VSSMV6I3A","https://github.com/advisories/GHSA-qvrw-v9rv-5rjx"],"source_kind":"github","identifiers":["GHSA-qvrw-v9rv-5rjx","CVE-2023-49082"],"repository_url":"https://github.com/aio-libs/aiohttp","blast_radius":33.274358451125195,"packages":[{"versions":[{"first_patched_version":"3.9.0","vulnerable_version_range":"\u003c 3.9.0"}],"ecosystem":"pypi","package_name":"aiohttp"}],"created_at":"2023-11-28T00:05:56.856Z","updated_at":"2024-09-03T21:38:57.000Z","epss_percentage":0.00159,"epss_percentile":0.37995},{"uuid":"GSA_kwCzR0hTQS01bTk4LXFnZzktd2g4NM4AA7vP","url":"https://github.com/advisories/GHSA-5m98-qgg9-wh84","title":"aiohttp vulnerable to Denial of Service when trying to parse malformed POST requests","description":"### Summary\nAn attacker can send a specially crafted POST (multipart/form-data) request. When the aiohttp server processes it, the server will enter an infinite loop and be unable to process any further requests.\n\n### Impact\nAn attacker can stop the application from serving requests after sending a single request.\n\n-------\n\nFor anyone needing to patch older versions of aiohttp, the minimum diff needed to resolve the issue is (located in `_read_chunk_from_length()`):\n\n```diff\ndiff --git a/aiohttp/multipart.py b/aiohttp/multipart.py\nindex 227be605c..71fc2654a 100644\n--- a/aiohttp/multipart.py\n+++ b/aiohttp/multipart.py\n@@ -338,6 +338,8 @@ class BodyPartReader:\n         assert self._length is not None, \"Content-Length required for chunked read\"\n         chunk_size = min(size, self._length - self._read_bytes)\n         chunk = await self._content.read(chunk_size)\n+        if self._content.at_eof():\n+            self._at_eof = True\n         return chunk\n \n     async def _read_chunk_from_stream(self, size: int) -\u003e bytes:\n```\n\nThis does however introduce some very minor issues with handling form data. So, if possible, it would be recommended to also backport the changes in:\nhttps://github.com/aio-libs/aiohttp/commit/cebe526b9c34dc3a3da9140409db63014bc4cf19\nhttps://github.com/aio-libs/aiohttp/commit/7eecdff163ccf029fbb1ddc9de4169d4aaeb6597\nhttps://github.com/aio-libs/aiohttp/commit/f21c6f2ca512a026ce7f0f6c6311f62d6a638866","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2024-05-03T17:29:54.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://github.com/aio-libs/aiohttp/security/advisories/GHSA-5m98-qgg9-wh84","https://nvd.nist.gov/vuln/detail/CVE-2024-30251","https://github.com/aio-libs/aiohttp/commit/7eecdff163ccf029fbb1ddc9de4169d4aaeb6597","https://github.com/aio-libs/aiohttp/commit/cebe526b9c34dc3a3da9140409db63014bc4cf19","https://github.com/aio-libs/aiohttp/commit/f21c6f2ca512a026ce7f0f6c6311f62d6a638866","http://www.openwall.com/lists/oss-security/2024/05/02/4","https://github.com/advisories/GHSA-5m98-qgg9-wh84"],"source_kind":"github","identifiers":["GHSA-5m98-qgg9-wh84","CVE-2024-30251"],"repository_url":"https://github.com/aio-libs/aiohttp","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"3.9.4","vulnerable_version_range":"\u003c 3.9.4"}],"ecosystem":"pypi","package_name":"aiohttp"}],"created_at":"2024-05-03T18:05:28.471Z","updated_at":"2024-05-03T17:30:09.000Z","epss_percentage":0.00288,"epss_percentile":0.51702}],"docker_usage_url":"https://docker.ecosyste.ms/usage/pypi/aiohttp","docker_dependents_count":7069,"docker_downloads_count":2314349642,"usage_url":"https://repos.ecosyste.ms/usage/pypi/aiohttp","dependent_repositories_url":"https://repos.ecosyste.ms/api/v1/usage/pypi/aiohttp/dependencies","status":null,"funding_links":["https://github.com/sponsors/asvetlov","https://github.com/sponsors/webknjaz","https://github.com/sponsors/Dreamsorcerer"],"critical":true,"versions_url":"https://packages.ecosyste.ms/api/v1/registries/pypi.org/packages/aiohttp/versions","version_numbers_url":"https://packages.ecosyste.ms/api/v1/registries/pypi.org/packages/aiohttp/version_numbers","dependent_packages_url":"https://packages.ecosyste.ms/api/v1/registries/pypi.org/packages/aiohttp/dependent_packages","related_packages_url":"https://packages.ecosyste.ms/api/v1/registries/pypi.org/packages/aiohttp/related_packages","maintainers":[{"uuid":"Andrew.Svetlov","login":"Andrew.Svetlov","name":null,"email":null,"url":null,"packages_count":75,"html_url":"https://pypi.org/user/Andrew.Svetlov/","role":null,"created_at":"2022-11-15T00:45:45.335Z","updated_at":"2022-11-15T00:45:45.335Z","packages_url":"https://packages.ecosyste.ms/api/v1/registries/pypi.org/maintainers/Andrew.Svetlov/packages"},{"uuid":"fafhrd","login":"fafhrd","name":null,"email":null,"url":null,"packages_count":20,"html_url":"https://pypi.org/user/fafhrd/","role":null,"created_at":"2022-11-15T00:45:45.365Z","updated_at":"2022-11-15T00:45:45.365Z","packages_url":"https://packages.ecosyste.ms/api/v1/registries/pypi.org/maintainers/fafhrd/packages"},{"uuid":"webknjaz","login":"webknjaz","name":null,"email":null,"url":null,"packages_count":39,"html_url":"https://pypi.org/user/webknjaz/","role":null,"created_at":"2022-11-15T00:45:45.384Z","updated_at":"2022-11-15T00:45:45.384Z","packages_url":"https://packages.ecosyste.ms/api/v1/registries/pypi.org/maintainers/webknjaz/packages"}],"registry":{"name":"pypi.org","url":"https://pypi.org","ecosystem":"pypi","default":true,"packages_count":689698,"maintainers_count":292475,"namespaces_count":0,"keywords_count":228396,"github":"pypi","metadata":{"funded_packages_count":48936},"icon_url":"https://github.com/pypi.png","created_at":"2022-04-04T15:19:23.364Z","updated_at":"2025-06-04T05:22:32.052Z","packages_url":"https://packages.ecosyste.ms/api/v1/registries/pypi.org/packages","maintainers_url":"https://packages.ecosyste.ms/api/v1/registries/pypi.org/maintainers","namespaces_url":"https://packages.ecosyste.ms/api/v1/registries/pypi.org/namespaces"}},"unique_repositories_count":3889,"unique_repositories_count_past_30_days":100,"recent_issues":[{"uuid":"5576671790","node_id":"PR_kwDOTw8DQM8AAAABFCOc6w","number":18,"state":"open","title":"Bump the minor-update group across 1 directory with 194 updates","user":"dependabot[bot]","labels":["dependencies"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-25T01:12:52.000Z","updated_at":"2026-09-25T01:13:02.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","group_name":"minor-update","update_count":194,"packages":[{"name":"tblib","old_version":"3.1.0","new_version":"3.2.2","repository_url":"https://github.com/ionelmc/python-tblib"},{"name":"regex","old_version":"2026.2.28","new_version":"2026.9.10","repository_url":"https://github.com/mrabarnett/mrab-regex"},{"name":"requests","old_version":"2.32.3","new_version":"2.34.2","repository_url":"https://github.com/psf/requests"},{"name":"tqdm","old_version":"4.67.3","new_version":"4.70.1","repository_url":"https://github.com/tqdm/tqdm"},{"name":"transformers","old_version":"5.14.1","new_version":"5.17.0","repository_url":"https://github.com/huggingface/transformers"},{"name":"huggingface-hub","old_version":"1.26.0","new_version":"1.32.0","repository_url":"https://github.com/huggingface/huggingface_hub"},{"name":"tokenizers","old_version":"0.22.2","new_version":"0.23.2","repository_url":"https://github.com/huggingface/tokenizers"},{"name":"fastapi","old_version":"0.136.3","new_version":"0.141.1","repository_url":"https://github.com/fastapi/fastapi"},{"name":"starlette","old_version":"1.3.1","new_version":"1.6.0","repository_url":"https://github.com/Kludex/starlette"},{"name":"aiohttp","old_version":"3.13.3","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"pydantic","old_version":"2.12.0","new_version":"2.13.5","repository_url":"https://github.com/pydantic/pydantic"},{"name":"prometheus-client","old_version":"0.22.0","new_version":"0.26.0","repository_url":"https://github.com/prometheus/client_python"},{"name":"prometheus-fastapi-instrumentator","old_version":"8.0.2","new_version":"8.1.0","repository_url":"https://github.com/trallnag/prometheus-fastapi-instrumentator"},{"name":"tiktoken","old_version":"0.12.0","new_version":"0.14.0","repository_url":"https://github.com/openai/tiktoken"},{"name":"lark","old_version":"1.2.2","new_version":"1.3.1","repository_url":"https://github.com/lark-parser/lark"},{"name":"typing-extensions","old_version":"4.15.0","new_version":"4.16.0","repository_url":"https://github.com/python/typing_extensions"},{"name":"jsonschema","old_version":"4.23.0","new_version":"4.26.0","repository_url":"https://github.com/python-jsonschema/jsonschema"},{"name":"pyzmq","old_version":"27.1.0","new_version":"27.2.0","repository_url":"https://github.com/zeromq/pyzmq"},{"name":"watchfiles","old_version":"1.2.0","new_version":"1.3.0","repository_url":"https://github.com/samuelcolvin/watchfiles"},{"name":"python-json-logger","old_version":"4.1.0","new_version":"4.2.0","repository_url":"https://github.com/nhairs/python-json-logger"},{"name":"pybase64","old_version":"1.4.3","new_version":"1.5.0","repository_url":"https://github.com/mayeut/pybase64"},{"name":"opentelemetry-sdk","old_version":"1.35.0","new_version":"1.44.0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"opentelemetry-api","old_version":"1.35.0","new_version":"1.44.0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"opentelemetry-exporter-otlp","old_version":"1.35.0","new_version":"1.44.0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"opentelemetry-semantic-conventions-ai","old_version":"0.4.13","new_version":"0.5.1"},{"name":"numba","old_version":"0.65.0","new_version":"0.67.0","repository_url":"https://github.com/numba/numba"},{"name":"torchcodec","old_version":"0.14.0+cu130","new_version":"0.16.0","repository_url":"https://github.com/pytorch/torchcodec"},{"name":"absl-py","old_version":"2.1.0","new_version":"2.5.0","repository_url":"https://github.com/abseil/abseil-py"},{"name":"accelerate","old_version":"1.13.0","new_version":"1.15.0","repository_url":"https://github.com/huggingface/accelerate"},{"name":"aiohappyeyeballs","old_version":"2.6.1","new_version":"2.7.1","repository_url":"https://github.com/aio-libs/aiohappyeyeballs"},{"name":"alembic","old_version":"1.16.4","new_version":"1.20.0","repository_url":"https://github.com/sqlalchemy/alembic"},{"name":"annotated-types","old_version":"0.7.0","new_version":"0.8.0","repository_url":"https://github.com/annotated-types/annotated-types"},{"name":"anyio","old_version":"4.14.1","new_version":"4.15.1","repository_url":"https://github.com/agronholm/anyio"},{"name":"arctic-inference","old_version":"0.1.1","new_version":"0.3.0"},{"name":"argcomplete","old_version":"3.5.1","new_version":"3.7.2","repository_url":"https://github.com/kislyuk/argcomplete"},{"name":"audioread","old_version":"3.0.1","new_version":"3.1.0","repository_url":"https://github.com/beetbox/audioread"},{"name":"azure-core","old_version":"1.38.2","new_version":"1.41.0","repository_url":"https://github.com/Azure/azure-sdk-for-python"},{"name":"azure-storage-blob","old_version":"12.28.0","new_version":"12.30.2","repository_url":"https://github.com/Azure/azure-sdk-for-python"},{"name":"bitsandbytes","old_version":"0.49.2","new_version":"0.50.2","repository_url":"https://github.com/bitsandbytes-foundation/bitsandbytes"},{"name":"blobfile","old_version":"3.0.0","new_version":"3.3.0","repository_url":"https://github.com/blobfile/blobfile"},{"name":"bm25s","old_version":"0.2.13","new_version":"0.3.11","repository_url":"https://github.com/xhluca/bm25s"},{"name":"boto3","old_version":"1.35.57","new_version":"1.43.99","repository_url":"https://github.com/boto/boto3"},{"name":"botocore","old_version":"1.35.57","new_version":"1.43.99","repository_url":"https://github.com/boto/botocore"},{"name":"cffi","old_version":"2.0.0","new_version":"2.1.1","repository_url":"https://github.com/python-cffi/cffi"},{"name":"charset-normalizer","old_version":"3.4.0","new_version":"3.5.1","repository_url":"https://github.com/jawah/charset_normalizer"},{"name":"click","old_version":"8.4.2","new_version":"8.5.0","repository_url":"https://github.com/pallets/click"},{"name":"cohere","old_version":"7.0.8","new_version":"7.1.1","repository_url":"https://github.com/cohere-ai/cohere-python"},{"name":"cohere-melody","old_version":"0.9.0","new_version":"0.15.0","repository_url":"https://github.com/cohere-ai/melody"},{"name":"colorlog","old_version":"6.10.1","new_version":"6.12.0","repository_url":"https://github.com/borntyping/python-colorlog"},{"name":"coverage","old_version":"7.10.6","new_version":"7.16.1","repository_url":"https://github.com/coveragepy/coveragepy"},{"name":"cramjam","old_version":"2.9.0","new_version":"2.11.0","repository_url":"https://github.com/milesgranger/pyrus-cramjam"},{"name":"cuda-bindings","old_version":"13.0.3","new_version":"13.4.2","repository_url":"https://github.com/NVIDIA/cuda-python"},{"name":"cuda-pathfinder","old_version":"1.3.3","new_version":"1.8.2","repository_url":"https://github.com/NVIDIA/cuda-python"},{"name":"cuda-toolkit","old_version":"13.0.3.0","new_version":"13.4.2"},{"name":"datamodel-code-generator","old_version":"0.26.3","new_version":"0.82.0","repository_url":"https://github.com/datamodel-code-generator/datamodel-code-generator"},{"name":"dataproperty","old_version":"1.0.1","new_version":"1.1.1","repository_url":"https://github.com/thombashi/DataProperty"},{"name":"decorator","old_version":"5.1.1","new_version":"5.3.1","repository_url":"https://github.com/micheles/decorator"},{"name":"detect-installer","old_version":"0.1.0","new_version":"0.2.1"},{"name":"dill","old_version":"0.3.8","new_version":"0.4.1","repository_url":"https://github.com/uqfoundation/dill"},{"name":"distlib","old_version":"0.3.9","new_version":"0.4.3","repository_url":"https://github.com/pypa/distlib"},{"name":"dnspython","old_version":"2.7.0","new_version":"2.8.0","repository_url":"https://github.com/rthalley/dnspython"},{"name":"docker","old_version":"7.1.0","new_version":"7.2.0","repository_url":"https://github.com/docker/docker-py"},{"name":"einx","old_version":"0.3.0","new_version":"0.4.3","repository_url":"https://github.com/fferflo/einx"},{"name":"email-validator","old_version":"2.2.0","new_version":"2.3.0","repository_url":"https://github.com/JoshData/python-email-validator"},{"name":"fastapi-cloud-cli","old_version":"0.21.0","new_version":"0.26.0","repository_url":"https://github.com/fastapilabs/fastapi-cloud-cli"},{"name":"fastar","old_version":"0.11.0","new_version":"0.12.0","repository_url":"https://github.com/DoctorJohn/fastar"},{"name":"fastsafetensors","old_version":"0.3.2","new_version":"0.4.0","repository_url":"https://github.com/foundation-model-stack/fastsafetensors"},{"name":"fonttools","old_version":"4.55.0","new_version":"4.65.0","repository_url":"https://github.com/fonttools/fonttools"},{"name":"frozenlist","old_version":"1.5.0","new_version":"1.8.0","repository_url":"https://github.com/aio-libs/frozenlist"},{"name":"genson","old_version":"1.3.0","new_version":"1.4.0","repository_url":"https://github.com/wolverdude/genson"},{"name":"google-api-core","old_version":"2.24.2","new_version":"2.38.0","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"google-auth","old_version":"2.40.2","new_version":"2.58.0","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"google-cloud-core","old_version":"2.4.3","new_version":"2.7.0","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"google-cloud-storage","old_version":"3.4.0","new_version":"3.14.1","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"google-crc32c","old_version":"1.7.1","new_version":"1.8.0","repository_url":"https://github.com/googleapis/python-crc32c"},{"name":"google-resumable-media","old_version":"2.7.2","new_version":"2.10.2","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"googleapis-common-protos","old_version":"1.70.0","new_version":"1.75.3","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"greenlet","old_version":"3.2.3","new_version":"3.5.6","repository_url":"https://github.com/python-greenlet/greenlet"},{"name":"grpcio","old_version":"1.78.0","new_version":"1.84.0","repository_url":"https://github.com/grpc/grpc"},{"name":"grpcio-reflection","old_version":"1.78.0","new_version":"1.84.0"},{"name":"h11","old_version":"0.14.0","new_version":"0.16.0","repository_url":"https://github.com/python-hyper/h11"},{"name":"h2","old_version":"4.3.0","new_version":"4.4.1","repository_url":"https://github.com/python-hyper/h2"},{"name":"hf-xet","old_version":"1.5.1","new_version":"1.6.0","repository_url":"https://github.com/huggingface/xet-core"},{"name":"hiredis","old_version":"3.0.0","new_version":"3.4.1","repository_url":"https://github.com/redis/hiredis-py"},{"name":"hpack","old_version":"4.1.0","new_version":"4.2.0","repository_url":"https://github.com/python-hyper/hpack"},{"name":"httpx","old_version":"0.27.2","new_version":"0.28.1","repository_url":"https://github.com/encode/httpx"},{"name":"humanize","old_version":"4.11.0","new_version":"4.16.0","repository_url":"https://github.com/python-humanize/humanize"},{"name":"hypothesis","old_version":"6.131.0","new_version":"6.168.0","repository_url":"https://github.com/HypothesisWorks/hypothesis"},{"name":"idna","old_version":"3.10","new_version":"3.20","repository_url":"https://github.com/kjd/idna"},{"name":"iniconfig","old_version":"2.0.0","new_version":"2.3.0","repository_url":"https://github.com/pytest-dev/iniconfig"},{"name":"instanttensor","old_version":"0.1.9","new_version":"0.2.0","repository_url":"https://github.com/scitix/InstantTensor"},{"name":"jiter","old_version":"0.15.0","new_version":"0.17.0","repository_url":"https://github.com/pydantic/jiter"},{"name":"jmespath","old_version":"1.0.1","new_version":"1.1.0","repository_url":"https://github.com/jmespath/jmespath.py"},{"name":"joblib","old_version":"1.4.2","new_version":"1.6.0","repository_url":"https://github.com/joblib/joblib"},{"name":"jsonschema-rs","old_version":"0.46.5","new_version":"0.57.1","repository_url":"https://github.com/Stranger6667/jsonschema"},{"name":"kiwisolver","old_version":"1.4.7","new_version":"1.5.1","repository_url":"https://github.com/nucleic/kiwi"},{"name":"lazy-loader","old_version":"0.4","new_version":"0.6","repository_url":"https://github.com/scientific-python/lazy-loader"},{"name":"llguidance","old_version":"1.7.6","new_version":"1.8.0","repository_url":"https://github.com/microsoft/llguidance"},{"name":"llvmlite","old_version":"0.47.0","new_version":"0.49.0","repository_url":"https://github.com/numba/llvmlite"},{"name":"mako","old_version":"1.3.10","new_version":"1.4.1","repository_url":"https://github.com/sqlalchemy/mako"},{"name":"matplotlib","old_version":"3.9.2","new_version":"3.10.9","repository_url":"https://github.com/matplotlib/matplotlib"},{"name":"mpmath","old_version":"1.3.0","new_version":"1.4.1","repository_url":"https://github.com/mpmath/mpmath"},{"name":"msal","old_version":"1.34.0","new_version":"1.39.0","repository_url":"https://github.com/AzureAD/microsoft-authentication-library-for-python"},{"name":"msgpack","old_version":"1.1.0","new_version":"1.2.2","repository_url":"https://github.com/msgpack/msgpack-python"},{"name":"mteb","old_version":"2.8.3","new_version":"2.21.6","repository_url":"https://github.com/embeddings-benchmark/mteb"},{"name":"multidict","old_version":"6.1.0","new_version":"6.9.1","repository_url":"https://github.com/aio-libs/multidict"},{"name":"mypy-extensions","old_version":"1.0.0","new_version":"1.1.0","repository_url":"https://github.com/python/mypy_extensions"},{"name":"networkx","old_version":"3.2.1","new_version":"3.4.2","repository_url":"https://github.com/networkx/networkx"},{"name":"nltk","old_version":"3.9.1","new_version":"3.10.3","repository_url":"https://github.com/nltk/nltk"},{"name":"nvidia-cublas","old_version":"13.1.1.3","new_version":"13.8.0.4"},{"name":"nvidia-cuda-cupti","old_version":"13.0.85","new_version":"13.4.92"},{"name":"nvidia-cuda-nvrtc","old_version":"13.0.88","new_version":"13.4.92"},{"name":"nvidia-cuda-runtime","old_version":"13.0.96","new_version":"13.4.92"},{"name":"nvidia-cudnn-cu13","old_version":"9.20.0.48","new_version":"9.26.0.51"},{"name":"nvidia-cufft","old_version":"12.0.0.61","new_version":"12.4.0.43"},{"name":"nvidia-cufile","old_version":"1.15.1.6","new_version":"1.19.1.55"},{"name":"nvidia-cusolver","old_version":"12.0.4.66","new_version":"12.3.4.7"},{"name":"nvidia-cusparse","old_version":"12.6.3.3","new_version":"12.8.6.72"},{"name":"nvidia-cusparselt-cu13","old_version":"0.8.1","new_version":"0.9.1"},{"name":"nvidia-nccl-cu13","old_version":"2.29.7","new_version":"2.31.2"},{"name":"nvidia-nvjitlink","old_version":"13.0.88","new_version":"13.4.92"},{"name":"nvidia-nvshmem-cu13","old_version":"3.4.5","new_version":"3.7.2"},{"name":"nvidia-nvtx","old_version":"13.0.85","new_version":"13.4.92"},{"name":"opentelemetry-exporter-otlp-proto-common","old_version":"1.35.0","new_version":"1.44.0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"opentelemetry-exporter-otlp-proto-grpc","old_version":"1.35.0","new_version":"1.44.0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"opentelemetry-exporter-otlp-proto-http","old_version":"1.35.0","new_version":"1.44.0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"opentelemetry-exporter-prometheus","old_version":"0.56b0","new_version":"0.65b0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"opentelemetry-proto","old_version":"1.35.0","new_version":"1.44.0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"opentelemetry-semantic-conventions","old_version":"0.56b0","new_version":"0.65b0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"orjson","old_version":"3.11.5","new_version":"3.12.0","repository_url":"https://github.com/ijl/orjson"},{"name":"pathvalidate","old_version":"3.2.1","new_version":"3.3.1","repository_url":"https://github.com/thombashi/pathvalidate"},{"name":"peft","old_version":"0.19.1","new_version":"0.21.0","repository_url":"https://github.com/huggingface/peft"},{"name":"perceptron","old_version":"0.1.4","new_version":"0.3.5","repository_url":"https://github.com/perceptron-ai-inc/perceptron"},{"name":"platformdirs","old_version":"4.3.6","new_version":"4.11.11","repository_url":"https://github.com/tox-dev/platformdirs"},{"name":"pluggy","old_version":"1.5.0","new_version":"1.6.0","repository_url":"https://github.com/pytest-dev/pluggy"},{"name":"polars","old_version":"1.29.0","new_version":"1.44.2","repository_url":"https://github.com/pola-rs/polars"},{"name":"pooch","old_version":"1.8.2","new_version":"1.9.0","repository_url":"https://github.com/fatiando/pooch"},{"name":"propcache","old_version":"0.2.0","new_version":"0.5.4","repository_url":"https://github.com/aio-libs/propcache"},{"name":"proto-plus","old_version":"1.26.1","new_version":"1.28.4","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"pycryptodomex","old_version":"3.22.0","new_version":"3.23.0","repository_url":"https://github.com/Legrandin/pycryptodome"},{"name":"pydantic-core","old_version":"2.41.1","new_version":"2.49.0","repository_url":"https://github.com/pydantic/pydantic"},{"name":"pydantic-extra-types","old_version":"2.10.5","new_version":"2.11.1","repository_url":"https://github.com/pydantic/pydantic-extra-types"},{"name":"pydantic-settings","old_version":"2.14.2","new_version":"2.15.0","repository_url":"https://github.com/pydantic/pydantic-settings"},{"name":"pygments","old_version":"2.18.0","new_version":"2.21.0","repository_url":"https://github.com/pygments/pygments"},{"name":"pyjwt","old_version":"2.11.0","new_version":"2.14.0","repository_url":"https://github.com/jpadilla/pyjwt"},{"name":"pyparsing","old_version":"3.2.0","new_version":"3.3.3","repository_url":"https://github.com/pyparsing/pyparsing"},{"name":"pyrate-limiter","old_version":"4.4.0","new_version":"4.5.0","repository_url":"https://github.com/vutran1710/PyrateLimiter"},{"name":"pystemmer","old_version":"3.0.0","new_version":"3.1.0","repository_url":"https://github.com/snowballstem/pystemmer"},{"name":"pytest-forked","old_version":"1.6.0","new_version":"1.7.5","repository_url":"https://github.com/pytest-dev/pytest-forked"},{"name":"pytest-mock","old_version":"3.14.0","new_version":"3.15.1","repository_url":"https://github.com/pytest-dev/pytest-mock"},{"name":"pytest-timeout","old_version":"2.3.1","new_version":"2.4.0","repository_url":"https://github.com/pytest-dev/pytest-timeout"},{"name":"python-rapidjson","old_version":"1.20","new_version":"1.25","repository_url":"https://github.com/python-rapidjson/python-rapidjson"},{"name":"rapidfuzz","old_version":"3.12.1","new_version":"3.14.5","repository_url":"https://github.com/rapidfuzz/RapidFuzz"},{"name":"referencing","old_version":"0.35.1","new_version":"0.37.0","repository_url":"https://github.com/python-jsonschema/referencing"},{"name":"responses","old_version":"0.25.3","new_version":"0.26.3","repository_url":"https://github.com/getsentry/responses"},{"name":"rignore","old_version":"0.7.6","new_version":"0.8.1"},{"name":"runai-model-streamer","old_version":"0.15.7","new_version":"0.16.1"},{"name":"runai-model-streamer-azure","old_version":"0.15.7","new_version":"0.16.1"},{"name":"runai-model-streamer-gcs","old_version":"0.15.7","new_version":"0.16.1"},{"name":"runai-model-streamer-s3","old_version":"0.15.7","new_version":"0.16.1"},{"name":"s3transfer","old_version":"0.10.3","new_version":"0.19.2","repository_url":"https://github.com/boto/s3transfer"},{"name":"sacrebleu","old_version":"2.4.3","new_version":"2.6.0","repository_url":"https://github.com/mjpost/sacrebleu"},{"name":"schemathesis","old_version":"4.21.6","new_version":"4.27.5","repository_url":"https://github.com/schemathesis/schemathesis"},{"name":"scikit-learn","old_version":"1.5.2","new_version":"1.7.2","repository_url":"https://github.com/scikit-learn/scikit-learn"},{"name":"scipy","old_version":"1.13.1","new_version":"1.15.3","repository_url":"https://github.com/scipy/scipy"},{"name":"sentry-sdk","old_version":"2.63.0","new_version":"2.69.2","repository_url":"https://github.com/getsentry/sentry-python"},{"name":"six","old_version":"1.16.0","new_version":"1.17.0","repository_url":"https://github.com/benjaminp/six"},{"name":"soundfile","old_version":"0.12.1","new_version":"0.14.0","repository_url":"https://github.com/bastibe/python-soundfile"},{"name":"statsmodels","old_version":"0.14.4","new_version":"0.15.0","repository_url":"https://github.com/statsmodels/statsmodels"},{"name":"sympy","old_version":"1.13.3","new_version":"1.14.0","repository_url":"https://github.com/sympy/sympy"},{"name":"tabulate","old_version":"0.9.0","new_version":"0.10.0","repository_url":"https://github.com/astanin/python-tabulate"},{"name":"tensorizer","old_version":"2.10.1","new_version":"2.12.1","repository_url":"https://github.com/coreweave/tensorizer"},{"name":"termcolor","old_version":"3.1.0","new_version":"3.3.0","repository_url":"https://github.com/termcolor/termcolor"},{"name":"threadpoolctl","old_version":"3.5.0","new_version":"3.7.0","repository_url":"https://github.com/joblib/threadpoolctl"},{"name":"triton","old_version":"3.7.1","new_version":"3.8.0","repository_url":"https://github.com/triton-lang/triton"},{"name":"tritonclient","old_version":"2.64.0","new_version":"2.71.0","repository_url":"https://github.com/triton-inference-server/client"},{"name":"typer","old_version":"0.26.8","new_version":"0.27.2","repository_url":"https://github.com/fastapi/typer"},{"name":"urllib3","old_version":"2.2.3","new_version":"2.8.0","repository_url":"https://github.com/urllib3/urllib3"},{"name":"uvicorn","old_version":"0.35.0","new_version":"0.53.0","repository_url":"https://github.com/Kludex/uvicorn"},{"name":"vector-quantize-pytorch","old_version":"1.21.2","new_version":"1.31.4","repository_url":"https://github.com/lucidrains/vector-quantizer-pytorch"},{"name":"wcwidth","old_version":"0.2.13","new_version":"0.8.4","repository_url":"https://github.com/jquast/wcwidth"},{"name":"yarl","old_version":"1.17.1","new_version":"1.25.1","repository_url":"https://github.com/aio-libs/yarl"},{"name":"conch-triton-kernels","old_version":"1.2.1","new_version":"1.3","repository_url":"https://github.com/stackav-oss/conch"},{"name":"tpu-inference","old_version":"0.26.0","new_version":"0.29.0","repository_url":"https://github.com/vllm-project/tpu-inference"},{"name":"pynvvideocodec","old_version":"2.0.4","new_version":"2.2.3"},{"name":"flashinfer-python","old_version":"0.6.15.post1","new_version":"0.7.0","repository_url":"https://github.com/flashinfer-ai/flashinfer"},{"name":"flashinfer-cubin","old_version":"0.6.15.post1","new_version":"0.7.0","repository_url":"https://github.com/flashinfer-ai/flashinfer"},{"name":"nvidia-cutlass-dsl","old_version":"4.6.0","new_version":"4.8.0","repository_url":"https://github.com/NVIDIA/cutlass"},{"name":"tokenspeed-mla","old_version":"0.1.8","new_version":"0.2.10","repository_url":"https://github.com/lightseekorg/tokenspeed"},{"name":"auto-round-lib","old_version":"0.14.2","new_version":"0.15.0","repository_url":"https://github.com/intel/auto-round"},{"name":"griffelib","old_version":"2.0.2","new_version":"2.3.0"},{"name":"mkdocs-git-revision-date-localized-plugin","old_version":"1.5.1","new_version":"1.6.0","repository_url":"https://github.com/timvink/mkdocs-git-revision-date-localized-plugin"},{"name":"ruff","old_version":"0.15.12","new_version":"0.16.8","repository_url":"https://github.com/astral-sh/ruff"},{"name":"zentorch","old_version":"2.11.0.0","new_version":"2.14.0.0","repository_url":"https://github.com/amd/ZenDNN-pytorch-plugin"}],"path":null,"ecosystem":"pip"},"body":"\u003e [!WARNING]\n\u003e Cooldown could not be applied because no publication date was available from the registry.\n\u003e\n\nBumps the minor-update group with 194 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [tblib](https://github.com/ionelmc/python-tblib) | `3.1.0` | `3.2.2` |\n| [regex](https://github.com/mrabarnett/mrab-regex) | `2026.2.28` | `2026.9.10` |\n| [requests](https://github.com/psf/requests) | `2.32.3` | `2.34.2` |\n| [tqdm](https://github.com/tqdm/tqdm) | `4.67.3` | `4.70.1` |\n| [transformers](https://github.com/huggingface/transformers) | `5.14.1` | `5.17.0` |\n| [huggingface-hub](https://github.com/huggingface/huggingface_hub) | `1.26.0` | `1.32.0` |\n| [tokenizers](https://github.com/huggingface/tokenizers) | `0.22.2` | `0.23.2` |\n| [fastapi](https://github.com/fastapi/fastapi) | `0.136.3` | `0.141.1` |\n| [starlette](https://github.com/Kludex/starlette) | `1.3.1` | `1.6.0` |\n| [aiohttp](https://github.com/aio-libs/aiohttp) | `3.13.3` | `3.14.3` |\n| [pydantic](https://github.com/pydantic/pydantic) | `2.12.0` | `2.13.5` |\n| [prometheus-client](https://github.com/prometheus/client_python) | `0.22.0` | `0.26.0` |\n| [prometheus-fastapi-instrumentator](https://github.com/trallnag/prometheus-fastapi-instrumentator) | `8.0.2` | `8.1.0` |\n| [tiktoken](https://github.com/openai/tiktoken) | `0.12.0` | `0.14.0` |\n| [lark](https://github.com/lark-parser/lark) | `1.2.2` | `1.3.1` |\n| [typing-extensions](https://github.com/python/typing_extensions) | `4.15.0` | `4.16.0` |\n| [jsonschema](https://github.com/python-jsonschema/jsonschema) | `4.23.0` | `4.26.0` |\n| [pyzmq](https://github.com/zeromq/pyzmq) | `27.1.0` | `27.2.0` |\n| [watchfiles](https://github.com/samuelcolvin/watchfiles) | `1.2.0` | `1.3.0` |\n| [python-json-logger](https://github.com/nhairs/python-json-logger) | `4.1.0` | `4.2.0` |\n| [pybase64](https://github.com/mayeut/pybase64) | `1.4.3` | `1.5.0` |\n| [opentelemetry-sdk](https://github.com/open-telemetry/opentelemetry-python) | `1.35.0` | `1.44.0` |\n| [opentelemetry-api](https://github.com/open-telemetry/opentelemetry-python) | `1.35.0` | `1.44.0` |\n| [opentelemetry-exporter-otlp](https://github.com/open-telemetry/opentelemetry-python) | `1.35.0` | `1.44.0` |\n| opentelemetry-semantic-conventions-ai | `0.4.13` | `0.5.1` |\n| [numba](https://github.com/numba/numba) | `0.65.0` | `0.67.0` |\n| [torchcodec](https://github.com/pytorch/torchcodec) | `0.14.0+cu130` | `0.16.0` |\n| [absl-py](https://github.com/abseil/abseil-py) | `2.1.0` | `2.5.0` |\n| [accelerate](https://github.com/huggingface/accelerate) | `1.13.0` | `1.15.0` |\n| [aiohappyeyeballs](https://github.com/aio-libs/aiohappyeyeballs) | `2.6.1` | `2.7.1` |\n| [alembic](https://github.com/sqlalchemy/alembic) | `1.16.4` | `1.20.0` |\n| [annotated-types](https://github.com/annotated-types/annotated-types) | `0.7.0` | `0.8.0` |\n| [anyio](https://github.com/agronholm/anyio) | `4.14.1` | `4.15.1` |\n| arctic-inference | `0.1.1` | `0.3.0` |\n| [argcomplete](https://github.com/kislyuk/argcomplete) | `3.5.1` | `3.7.2` |\n| [audioread](https://github.com/beetbox/audioread) | `3.0.1` | `3.1.0` |\n| [azure-core](https://github.com/Azure/azure-sdk-for-python) | `1.38.2` | `1.41.0` |\n| [azure-storage-blob](https://github.com/Azure/azure-sdk-for-python) | `12.28.0` | `12.30.2` |\n| [bitsandbytes](https://github.com/bitsandbytes-foundation/bitsandbytes) | `0.49.2` | `0.50.2` |\n| [blobfile](https://github.com/blobfile/blobfile) | `3.0.0` | `3.3.0` |\n| [bm25s](https://github.com/xhluca/bm25s) | `0.2.13` | `0.3.11` |\n| [boto3](https://github.com/boto/boto3) | `1.35.57` | `1.43.99` |\n| [botocore](https://github.com/boto/botocore) | `1.35.57` | `1.43.99` |\n| [cffi](https://github.com/python-cffi/cffi) | `2.0.0` | `2.1.1` |\n| [charset-normalizer](https://github.com/jawah/charset_normalizer) | `3.4.0` | `3.5.1` |\n| [click](https://github.com/pallets/click) | `8.4.2` | `8.5.0` |\n| [cohere](https://github.com/cohere-ai/cohere-python) | `7.0.8` | `7.1.1` |\n| [cohere-melody](https://github.com/cohere-ai/melody) | `0.9.0` | `0.15.0` |\n| [colorlog](https://github.com/borntyping/python-colorlog) | `6.10.1` | `6.12.0` |\n| [coverage](https://github.com/coveragepy/coveragepy) | `7.10.6` | `7.16.1` |\n| [cramjam](https://github.com/milesgranger/pyrus-cramjam) | `2.9.0` | `2.11.0` |\n| [cuda-bindings](https://github.com/NVIDIA/cuda-python) | `13.0.3` | `13.4.2` |\n| [cuda-pathfinder](https://github.com/NVIDIA/cuda-python) | `1.3.3` | `1.8.2` |\n| [cuda-toolkit](https://developer.nvidia.com/cuda-toolkit) | `13.0.3.0` | `13.4.2` |\n| [datamodel-code-generator](https://github.com/datamodel-code-generator/datamodel-code-generator) | `0.26.3` | `0.82.0` |\n| [dataproperty](https://github.com/thombashi/DataProperty) | `1.0.1` | `1.1.1` |\n| [decorator](https://github.com/micheles/decorator) | `5.1.1` | `5.3.1` |\n| detect-installer | `0.1.0` | `0.2.1` |\n| [dill](https://github.com/uqfoundation/dill) | `0.3.8` | `0.4.1` |\n| [distlib](https://github.com/pypa/distlib) | `0.3.9` | `0.4.3` |\n| [dnspython](https://github.com/rthalley/dnspython) | `2.7.0` | `2.8.0` |\n| [docker](https://github.com/docker/docker-py) | `7.1.0` | `7.2.0` |\n| [einx](https://github.com/fferflo/einx) | `0.3.0` | `0.4.3` |\n| [email-validator](https://github.com/JoshData/python-email-validator) | `2.2.0` | `2.3.0` |\n| [fastapi-cloud-cli](https://github.com/fastapilabs/fastapi-cloud-cli) | `0.21.0` | `0.26.0` |\n| [fastar](https://github.com/DoctorJohn/fastar) | `0.11.0` | `0.12.0` |\n| [fastsafetensors](https://github.com/foundation-model-stack/fastsafetensors) | `0.3.2` | `0.4.0` |\n| [fonttools](https://github.com/fonttools/fonttools) | `4.55.0` | `4.65.0` |\n| [frozenlist](https://github.com/aio-libs/frozenlist) | `1.5.0` | `1.8.0` |\n| [genson](https://github.com/wolverdude/genson) | `1.3.0` | `1.4.0` |\n| [google-api-core](https://github.com/googleapis/google-cloud-python) | `2.24.2` | `2.38.0` |\n| [google-auth](https://github.com/googleapis/google-cloud-python) | `2.40.2` | `2.58.0` |\n| [google-cloud-core](https://github.com/googleapis/google-cloud-python) | `2.4.3` | `2.7.0` |\n| [google-cloud-storage](https://github.com/googleapis/google-cloud-python) | `3.4.0` | `3.14.1` |\n| [google-crc32c](https://github.com/googleapis/python-crc32c) | `1.7.1` | `1.8.0` |\n| [google-resumable-media](https://github.com/googleapis/google-cloud-python) | `2.7.2` | `2.10.2` |\n| [googleapis-common-protos](https://github.com/googleapis/google-cloud-python) | `1.70.0` | `1.75.3` |\n| [greenlet](https://github.com/python-greenlet/greenlet) | `3.2.3` | `3.5.6` |\n| [grpcio](https://github.com/grpc/grpc) | `1.78.0` | `1.84.0` |\n| [grpcio-reflection](https://grpc.io) | `1.78.0` | `1.84.0` |\n| [h11](https://github.com/python-hyper/h11) | `0.14.0` | `0.16.0` |\n| [h2](https://github.com/python-hyper/h2) | `4.3.0` | `4.4.1` |\n| [hf-xet](https://github.com/huggingface/xet-core) | `1.5.1` | `1.6.0` |\n| [hiredis](https://github.com/redis/hiredis-py) | `3.0.0` | `3.4.1` |\n| [hpack](https://github.com/python-hyper/hpack) | `4.1.0` | `4.2.0` |\n| [httpx](https://github.com/encode/httpx) | `0.27.2` | `0.28.1` |\n| [humanize](https://github.com/python-humanize/humanize) | `4.11.0` | `4.16.0` |\n| [hypothesis](https://github.com/HypothesisWorks/hypothesis) | `6.131.0` | `6.168.0` |\n| [idna](https://github.com/kjd/idna) | `3.10` | `3.20` |\n| [iniconfig](https://github.com/pytest-dev/iniconfig) | `2.0.0` | `2.3.0` |\n| [instanttensor](https://github.com/scitix/InstantTensor) | `0.1.9` | `0.2.0` |\n| [jiter](https://github.com/pydantic/jiter) | `0.15.0` | `0.17.0` |\n| [jmespath](https://github.com/jmespath/jmespath.py) | `1.0.1` | `1.1.0` |\n| [joblib](https://github.com/joblib/joblib) | `1.4.2` | `1.6.0` |\n| [jsonschema-rs](https://github.com/Stranger6667/jsonschema) | `0.46.5` | `0.57.1` |\n| [kiwisolver](https://github.com/nucleic/kiwi) | `1.4.7` | `1.5.1` |\n| [lazy-loader](https://github.com/scientific-python/lazy-loader) | `0.4` | `0.6` |\n| [llguidance](https://github.com/microsoft/llguidance) | `1.7.6` | `1.8.0` |\n| [llvmlite](https://github.com/numba/llvmlite) | `0.47.0` | `0.49.0` |\n| [mako](https://github.com/sqlalchemy/mako) | `1.3.10` | `1.4.1` |\n| [matplotlib](https://github.com/matplotlib/matplotlib) | `3.9.2` | `3.10.9` |\n| [mpmath](https://github.com/mpmath/mpmath) | `1.3.0` | `1.4.1` |\n| [msal](https://github.com/AzureAD/microsoft-authentication-library-for-python) | `1.34.0` | `1.39.0` |\n| [msgpack](https://github.com/msgpack/msgpack-python) | `1.1.0` | `1.2.2` |\n| [mteb](https://github.com/embeddings-benchmark/mteb) | `2.8.3` | `2.21.6` |\n| [multidict](https://github.com/aio-libs/multidict) | `6.1.0` | `6.9.1` |\n| [mypy-extensions](https://github.com/python/mypy_extensions) | `1.0.0` | `1.1.0` |\n| [networkx](https://github.com/networkx/networkx) | `3.2.1` | `3.4.2` |\n| [nltk](https://github.com/nltk/nltk) | `3.9.1` | `3.10.3` |\n| [nvidia-cublas](https://developer.nvidia.com/cuda-zone) | `13.1.1.3` | `13.8.0.4` |\n| [nvidia-cuda-cupti](https://developer.nvidia.com/cuda-zone) | `13.0.85` | `13.4.92` |\n| [nvidia-cuda-nvrtc](https://developer.nvidia.com/cuda-zone) | `13.0.88` | `13.4.92` |\n| [nvidia-cuda-runtime](https://developer.nvidia.com/cuda-zone) | `13.0.96` | `13.4.92` |\n| [nvidia-cudnn-cu13](https://developer.nvidia.com/cuda-zone) | `9.20.0.48` | `9.26.0.51` |\n| [nvidia-cufft](https://developer.nvidia.com/cuda-zone) | `12.0.0.61` | `12.4.0.43` |\n| [nvidia-cufile](https://developer.nvidia.com/cuda-zone) | `1.15.1.6` | `1.19.1.55` |\n| [nvidia-cusolver](https://developer.nvidia.com/cuda-zone) | `12.0.4.66` | `12.3.4.7` |\n| [nvidia-cusparse](https://developer.nvidia.com/cuda-zone) | `12.6.3.3` | `12.8.6.72` |\n| [nvidia-cusparselt-cu13](https://developer.nvidia.com/cusparselt) | `0.8.1` | `0.9.1` |\n| [nvidia-nccl-cu13](https://developer.nvidia.com/cuda-zone) | `2.29.7` | `2.31.2` |\n| [nvidia-nvjitlink](https://developer.nvidia.com/cuda-zone) | `13.0.88` | `13.4.92` |\n| [nvidia-nvshmem-cu13](https://developer.nvidia.com/cuda-zone) | `3.4.5` | `3.7.2` |\n| [nvidia-nvtx](https://developer.nvidia.com/cuda-zone) | `13.0.85` | `13.4.92` |\n| [opentelemetry-exporter-otlp-proto-common](https://github.com/open-telemetry/opentelemetry-python) | `1.35.0` | `1.44.0` |\n| [opentelemetry-exporter-otlp-proto-grpc](https://github.com/open-telemetry/opentelemetry-python) | `1.35.0` | `1.44.0` |\n| [opentelemetry-exporter-otlp-proto-http](https://github.com/open-telemetry/opentelemetry-python) | `1.35.0` | `1.44.0` |\n| [opentelemetry-exporter-prometheus](https://github.com/open-telemetry/opentelemetry-python) | `0.56b0` | `0.65b0` |\n| [opentelemetry-proto](https://github.com/open-telemetry/opentelemetry-python) | `1.35.0` | `1.44.0` |\n| [opentelemetry-semantic-conventions](https://github.com/open-telemetry/opentelemetry-python) | `0.56b0` | `0.65b0` |\n| [orjson](https://github.com/ijl/orjson) | `3.11.5` | `3.12.0` |\n| [pathvalidate](https://github.com/thombashi/pathvalidate) | `3.2.1` | `3.3.1` |\n| [peft](https://github.com/huggingface/peft) | `0.19.1` | `0.21.0` |\n| [perceptron](https://github.com/perceptron-ai-inc/perceptron) | `0.1.4` | `0.3.5` |\n| [platformdirs](https://github.com/tox-dev/platformdirs) | `4.3.6` | `4.11.11` |\n| [pluggy](https://github.com/pytest-dev/pluggy) | `1.5.0` | `1.6.0` |\n| [polars](https://github.com/pola-rs/polars) | `1.29.0` | `1.44.2` |\n| [pooch](https://github.com/fatiando/pooch) | `1.8.2` | `1.9.0` |\n| [propcache](https://github.com/aio-libs/propcache) | `0.2.0` | `0.5.4` |\n| [proto-plus](https://github.com/googleapis/google-cloud-python) | `1.26.1` | `1.28.4` |\n| [pycryptodomex](https://github.com/Legrandin/pycryptodome) | `3.22.0` | `3.23.0` |\n| [pydantic-core](https://github.com/pydantic/pydantic) | `2.41.1` | `2.49.0` |\n| [pydantic-extra-types](https://github.com/pydantic/pydantic-extra-types) | `2.10.5` | `2.11.1` |\n| [pydantic-settings](https://github.com/pydantic/pydantic-settings) | `2.14.2` | `2.15.0` |\n| [pygments](https://github.com/pygments/pygments) | `2.18.0` | `2.21.0` |\n| [pyjwt](https://github.com/jpadilla/pyjwt) | `2.11.0` | `2.14.0` |\n| [pyparsing](https://github.com/pyparsing/pyparsing) | `3.2.0` | `3.3.3` |\n| [pyrate-limiter](https://github.com/vutran1710/PyrateLimiter) | `4.4.0` | `4.5.0` |\n| [pystemmer](https://github.com/snowballstem/pystemmer) | `3.0.0` | `3.1.0` |\n| [pytest-forked](https://github.com/pytest-dev/pytest-forked) | `1.6.0` | `1.7.5` |\n| [pytest-mock](https://github.com/pytest-dev/pytest-mock) | `3.14.0` | `3.15.1` |\n| [pytest-timeout](https://github.com/pytest-dev/pytest-timeout) | `2.3.1` | `2.4.0` |\n| [python-rapidjson](https://github.com/python-rapidjson/python-rapidjson) | `1.20` | `1.25` |\n| [rapidfuzz](https://github.com/rapidfuzz/RapidFuzz) | `3.12.1` | `3.14.5` |\n| [referencing](https://github.com/python-jsonschema/referencing) | `0.35.1` | `0.37.0` |\n| [responses](https://github.com/getsentry/responses) | `0.25.3` | `0.26.3` |\n| rignore | `0.7.6` | `0.8.1` |\n| runai-model-streamer | `0.15.7` | `0.16.1` |\n| runai-model-streamer-azure | `0.15.7` | `0.16.1` |\n| runai-model-streamer-gcs | `0.15.7` | `0.16.1` |\n| runai-model-streamer-s3 | `0.15.7` | `0.16.1` |\n| [s3transfer](https://github.com/boto/s3transfer) | `0.10.3` | `0.19.2` |\n| [sacrebleu](https://github.com/mjpost/sacrebleu) | `2.4.3` | `2.6.0` |\n| [schemathesis](https://github.com/schemathesis/schemathesis) | `4.21.6` | `4.27.5` |\n| [scikit-learn](https://github.com/scikit-learn/scikit-learn) | `1.5.2` | `1.7.2` |\n| [scipy](https://github.com/scipy/scipy) | `1.13.1` | `1.15.3` |\n| [sentry-sdk](https://github.com/getsentry/sentry-python) | `2.63.0` | `2.69.2` |\n| [six](https://github.com/benjaminp/six) | `1.16.0` | `1.17.0` |\n| [soundfile](https://github.com/bastibe/python-soundfile) | `0.12.1` | `0.14.0` |\n| [statsmodels](https://github.com/statsmodels/statsmodels) | `0.14.4` | `0.15.0` |\n| [sympy](https://github.com/sympy/sympy) | `1.13.3` | `1.14.0` |\n| [tabulate](https://github.com/astanin/python-tabulate) | `0.9.0` | `0.10.0` |\n| [tensorizer](https://github.com/coreweave/tensorizer) | `2.10.1` | `2.12.1` |\n| [termcolor](https://github.com/termcolor/termcolor) | `3.1.0` | `3.3.0` |\n| [threadpoolctl](https://github.com/joblib/threadpoolctl) | `3.5.0` | `3.7.0` |\n| [triton](https://github.com/triton-lang/triton) | `3.7.1` | `3.8.0` |\n| [tritonclient](https://github.com/triton-inference-server/client) | `2.64.0` | `2.71.0` |\n| [typer](https://github.com/fastapi/typer) | `0.26.8` | `0.27.2` |\n| [urllib3](https://github.com/urllib3/urllib3) | `2.2.3` | `2.8.0` |\n| [uvicorn](https://github.com/Kludex/uvicorn) | `0.35.0` | `0.53.0` |\n| [vector-quantize-pytorch](https://github.com/lucidrains/vector-quantizer-pytorch) | `1.21.2` | `1.31.4` |\n| [wcwidth](https://github.com/jquast/wcwidth) | `0.2.13` | `0.8.4` |\n| [yarl](https://github.com/aio-libs/yarl) | `1.17.1` | `1.25.1` |\n| [conch-triton-kernels](https://github.com/stackav-oss/conch) | `1.2.1` | `1.3` |\n| [tpu-inference](https://github.com/vllm-project/tpu-inference) | `0.26.0` | `0.29.0` |\n| pynvvideocodec | `2.0.4` | `2.2.3` |\n| [flashinfer-python](https://github.com/flashinfer-ai/flashinfer) | `0.6.15.post1` | `0.7.0` |\n| [flashinfer-cubin](https://github.com/flashinfer-ai/flashinfer) | `0.6.15.post1` | `0.7.0` |\n| [nvidia-cutlass-dsl](https://github.com/NVIDIA/cutlass) | `4.6.0` | `4.8.0` |\n| [tokenspeed-mla](https://github.com/lightseekorg/tokenspeed) | `0.1.8` | `0.2.10` |\n| [auto-round-lib](https://github.com/intel/auto-round) | `0.14.2` | `0.15.0` |\n| griffelib | `2.0.2` | `2.3.0` |\n| [mkdocs-git-revision-date-localized-plugin](https://github.com/timvink/mkdocs-git-revision-date-localized-plugin) | `1.5.1` | `1.6.0` |\n| [ruff](https://github.com/astral-sh/ruff) | `0.15.12` | `0.16.8` |\n| [zentorch](https://github.com/amd/ZenDNN-pytorch-plugin) | `2.11.0.0` | `2.14.0.0` |\n\n\nUpdates `tblib` from 3.1.0 to 3.2.2\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/ionelmc/python-tblib/blob/master/CHANGELOG.rst\"\u003etblib's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e3.2.2 (2025-11-12)\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003e\n* Fixed regression occurring with ``TimeoutError`` exceptions. They should be represented now exactly as the original when unpickling.\n  Contributed by Jacob Tomlinson in `[#85](https://github.com/ionelmc/python-tblib/issues/85) \u0026lt;https://github.com/ionelmc/python-tblib/pull/85\u0026gt;`_.\n\u003cp\u003e3.2.1 (2025-10-31)\n\u003c/code\u003e\u003c/pre\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eFixed regression occurring with \u003ccode\u003eExceptionGroup\u003c/code\u003e exceptions. That exception type is now handled specifically in the new \u003ccode\u003eunpickle_exception_with_attrs\u003c/code\u003e function (just like \u003ccode\u003eOSError\u003c/code\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e3.2.0 (2025-10-21)\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003e\n* Changed ``tblib.pickling_support.install`` to support exceptions with ``__init__`` that does match the default\n  ``BaseException.__reduce__`` (as it expects the positional arguments to ``__init__`` to match the ``args`` attribute).\n\u003cp\u003eSpecial handling for OSError (and subclasses) is also included. The errno, strerror, winerror, filename and filename2 attributes will be added in the reduce structure (if set).\u003c/p\u003e\n\u003cp\u003eThis will support exception subclasses that do this without defining a custom \u003ccode\u003e__reduce__\u003c/code\u003e:\u003c/p\u003e\n\u003cp\u003e.. code-block:: python\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003edef __init__(self):\n    super().__init__('mistery argument')\n\ndef __init__(self, mistery_argument):\n    super().__init__()\n    self.mistery_argument = mistery_argument\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eTests and POC contributed by Oldřich Jedlička in \u003ccode\u003e[#73](https://github.com/ionelmc/python-tblib/issues/73) \u0026amp;lt;https://github.com/ionelmc/python-tblib/pull/73\u0026amp;gt;\u003c/code\u003e_.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eFixed some doctest and coverage config. Contributed by Colin Watson in \u003ccode\u003e[#79](https://github.com/ionelmc/python-tblib/issues/79) \u0026amp;lt;https://github.com/ionelmc/python-tblib/pull/79\u0026amp;gt;\u003c/code\u003e_.\n\u003c/code\u003e\u003c/pre\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/d88606aab343749dfeccf16a813f63cbe2dae11e\"\u003e\u003ccode\u003ed88606a\u003c/code\u003e\u003c/a\u003e Bump version: 3.2.1 → 3.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/530f8743f1ed322f220621d8491e660636065279\"\u003e\u003ccode\u003e530f874\u003c/code\u003e\u003c/a\u003e Add test for timeouterror regression. Ref \u003ca href=\"https://redirect.github.com/ionelmc/python-tblib/issues/85\"\u003e#85\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/9c8f2ca0e7c061cc423207986af6f06aaa76cfee\"\u003e\u003ccode\u003e9c8f2ca\u003c/code\u003e\u003c/a\u003e Update changelog.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/df6185d4b942a37d48a0e082b885380b8c5cc5ad\"\u003e\u003ccode\u003edf6185d\u003c/code\u003e\u003c/a\u003e Handle optional OSError attributes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/b197023aa86b831834393fdd89c6439fe2ffaf0c\"\u003e\u003ccode\u003eb197023\u003c/code\u003e\u003c/a\u003e Bump version: 3.2.0 → 3.2.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/d71e1edc9da5a86e326406ea4372cce5c075b4f4\"\u003e\u003ccode\u003ed71e1ed\u003c/code\u003e\u003c/a\u003e Update changelog.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/74ec64570acb0d6ce708c695ab98d52d08f8b066\"\u003e\u003ccode\u003e74ec645\u003c/code\u003e\u003c/a\u003e Specifically handle ExceptionGroup in the new unpickle_exception_with_attrs. ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/580d57921a6e93660bf47771f70c0bfbe70e9c97\"\u003e\u003ccode\u003e580d579\u003c/code\u003e\u003c/a\u003e Ooops, forgot to update these.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/ebc83e93b6342950cb93cf296991fb99ce4aa13a\"\u003e\u003ccode\u003eebc83e9\u003c/code\u003e\u003c/a\u003e Bump version: 3.1.0 → 3.2.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/abec37d4526fb86f95c7567644f1fd6c2cec4215\"\u003e\u003ccode\u003eabec37d\u003c/code\u003e\u003c/a\u003e Update changelog and add one more test.\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/ionelmc/python-tblib/compare/v3.1.0...v3.2.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `regex` from 2026.2.28 to 2026.9.10\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/mrabarnett/mrab-regex/blob/hg/changelog.txt\"\u003eregex's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003eVersion: 2026.9.19\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eGit issue 619: `Match.expand()` segfaults after `detach_string()` when the template references a group\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.9.10\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eFixed version.\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.9.9\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003ePR [#615](https://github.com/mrabarnett/mrab-regex/issues/615): Fix Python API error propagation in match helpers\n\u003cp\u003ePR \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/616\"\u003e#616\u003c/a\u003e: Preserve Python Exceptions in Input Decoding and String Detachment\u003c/p\u003e\n\u003cp\u003ePR \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/617\"\u003e#617\u003c/a\u003e: Prevent Invalid Pointer Use and Exception State Corruption in Byte String Joining\u003c/p\u003e\n\u003cp\u003ePR \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/618\"\u003e#618\u003c/a\u003e: Propagate Allocation and Internal Errors During Pattern Compilation and Scanner Execution\n\u003c/code\u003e\u003c/pre\u003e\u003c/p\u003e\n\u003cp\u003eVersion: 2026.9.3\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eNew version of cibuildwheel no longer supports building for free-threaded Python 3.13.\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.9.2\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eNew version of cibuildwheel no longer needs nor supports cpython-freethreading option.\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.9.1\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eUpdated cibuildwheel.\nSupport Python 3.15.\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.8.31\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eFixed version.\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.8.30\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eGit issue 611: Heap out-of-bounds write at compile time\nGit issue 612: count_one() size underflow through the stale required-string cache\nGit issue 613: (*SKIP) inside an atomic group, plus an equality-only scan stop\nGit issue 614: build_GROUP() does not propagate the match direction\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.8.12\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eSupport Python 3.15.\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.7.19\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eGit issue 607: SIGSEGV: NULL pointer dereference in `basic_match()` when `(?R)`/`(?0)` recursion is used inside a fuzzy-matching quantifier\nGit issue 608: SIGSEGV: out-of-bounds read in `bytes1_char_at()` with `DOTALL` + a fuzzy constraint + `(?r)` reverse-direction matching\n\u003c/code\u003e\u003c/pre\u003e\n\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/7dd71c15c4fb5c94206bed1763abd4c2bd2f1b33\"\u003e\u003ccode\u003e7dd71c1\u003c/code\u003e\u003c/a\u003e Fixed version.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/59124d62299e212931786aa74ead15388abaf376\"\u003e\u003ccode\u003e59124d6\u003c/code\u003e\u003c/a\u003e PR \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/615\"\u003e#615\u003c/a\u003e: Fix Python API error propagation in match helpers\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/25e15218bd44ca26677e3c28709e94a0ca0d9b8e\"\u003e\u003ccode\u003e25e1521\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/618\"\u003e#618\u003c/a\u003e from dynapx/fix-compiler-error-propagation\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/3ad78cfb73850c2f1178d19553fa14661f73d9cb\"\u003e\u003ccode\u003e3ad78cf\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/616\"\u003e#616\u003c/a\u003e from dynapx/fix-detach-string-error-propagation\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/f54253c332574bd5a9d96d3ec9d62b5db954dac7\"\u003e\u003ccode\u003ef54253c\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/615\"\u003e#615\u003c/a\u003e from dynapx/fix-python-api-error-propagation\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/c44224476cd6a6e53be0e458dfdcf3b81d76e426\"\u003e\u003ccode\u003ec442244\u003c/code\u003e\u003c/a\u003e Propagate scanner internal errors\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/68837e7af862250cd08fa49ff584a2bbff246e0f\"\u003e\u003ccode\u003e68837e7\u003c/code\u003e\u003c/a\u003e Propagate node stack allocation failures\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/f1df5387982d526cc9475fddcc8d1043b02ffc9a\"\u003e\u003ccode\u003ef1df538\u003c/code\u003e\u003c/a\u003e Propagate check stack allocation failures\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/d8873b119a49cde8d2613253827bf973261bb2bc\"\u003e\u003ccode\u003ed8873b1\u003c/code\u003e\u003c/a\u003e Preserve Python exceptions in input decoding\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/910784fb8039c445a68e84a261119a96031c811c\"\u003e\u003ccode\u003e910784f\u003c/code\u003e\u003c/a\u003e Propagate detach_string slicing errors\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/mrabarnett/mrab-regex/compare/2026.2.28...2026.9.10\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `requests` from 2.32.3 to 2.34.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/psf/requests/releases\"\u003erequests's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.34.2\u003c/h2\u003e\n\u003ch2\u003e2.34.2 (2026-05-14)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMoved \u003ccode\u003eheaders\u003c/code\u003e input type back to \u003ccode\u003eMapping\u003c/code\u003e to avoid invariance issues with \u003ccode\u003eMutableMapping\u003c/code\u003e and inferred dict types. Users calling \u003ccode\u003eRequest.headers.update()\u003c/code\u003e may need to narrow typing in their code. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7441\"\u003e#7441\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/psf/requests/blob/main/HISTORY.md#2342-2026-05-14\"\u003ehttps://github.com/psf/requests/blob/main/HISTORY.md#2342-2026-05-14\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.34.1\u003c/h2\u003e\n\u003ch2\u003e2.34.1 (2026-05-13)\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eBugfixes\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eWidened \u003ccode\u003ejson\u003c/code\u003e input type from \u003ccode\u003edict\u003c/code\u003e and \u003ccode\u003elist\u003c/code\u003e to \u003ccode\u003eMapping\u003c/code\u003e\nand \u003ccode\u003eSequence\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7436\"\u003e#7436\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eChanged \u003ccode\u003eheaders\u003c/code\u003e input type to MutableMapping and removed \u003ccode\u003eNone\u003c/code\u003e from\n\u003ccode\u003eRequest.headers\u003c/code\u003e typing to improve handling for users. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7431\"\u003e#7431\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eResponse.reason\u003c/code\u003e moved from \u003ccode\u003estr | None\u003c/code\u003e to \u003ccode\u003estr\u003c/code\u003e to improve handling\nfor users. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7437\"\u003e#7437\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed a bug where some bodies with custom \u003ccode\u003e__getattr__\u003c/code\u003e implementations\nweren't being properly detected as Iterables. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7433\"\u003e#7433\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/k223kim\"\u003e\u003ccode\u003e@​k223kim\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/psf/requests/pull/7433\"\u003epsf/requests#7433\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/psf/requests/blob/main/HISTORY.md#2341-2026-05-13\"\u003ehttps://github.com/psf/requests/blob/main/HISTORY.md#2341-2026-05-13\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.34.0\u003c/h2\u003e\n\u003ch2\u003e2.34.0 (2026-05-11)\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eAnnouncements\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eRequests 2.34.0 introduces inline types, replacing those provided by\ntypeshed. Public API types should be fully compatible with mypy, pyright,\nand ty. \u003cstrong\u003eWe believe types are comprehensive but if you find issues, please\nreport them to the \u003ca href=\"https://redirect.github.com/psf/requests/issues/7271\"\u003epinned tracking issue\u003c/a\u003e.\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eSpecial thanks to \u003ca href=\"https://github.com/bastimeyer\"\u003e\u003ccode\u003e@​bastimeyer\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/cthoyt\"\u003e\u003ccode\u003e@​cthoyt\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/edgarrmondragon\"\u003e\u003ccode\u003e@​edgarrmondragon\u003c/code\u003e\u003c/a\u003e, and \u003ca href=\"https://github.com/srittau\"\u003e\u003ccode\u003e@​srittau\u003c/code\u003e\u003c/a\u003e for\nhelping review and test the types ahead of the release. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7272\"\u003e#7272\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eImprovements\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eDigest Auth hashing algorithms have added \u003ccode\u003eusedforsecurity=False\u003c/code\u003e to clarify\nsecurity considerations. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7310\"\u003e#7310\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests added support for Python 3.15 based on beta1. Downstream projects\nshould be able to start testing prior to its release in October. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7422\"\u003e#7422\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests added support for Python 3.14t. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7419\"\u003e#7419\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eBugfixes\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eResponse.history\u003c/code\u003e no longer contains a reference to itself, preventing\naccidental looping when traversing the history list. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7328\"\u003e#7328\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests no longer performs greedy matching on no_proxy domains. The\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/psf/requests/blob/main/HISTORY.md\"\u003erequests's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e2.34.2 (2026-05-14)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMoved \u003ccode\u003eheaders\u003c/code\u003e input type back to \u003ccode\u003eMapping\u003c/code\u003e to avoid invariance issues\nwith \u003ccode\u003eMutableMapping\u003c/code\u003e and inferred dict types. Users calling\n\u003ccode\u003eRequest.headers.update()\u003c/code\u003e may need to narrow typing in their code. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7441\"\u003e#7441\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.34.1 (2026-05-13)\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eBugfixes\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eWidened \u003ccode\u003ejson\u003c/code\u003e input type from \u003ccode\u003edict\u003c/code\u003e and \u003ccode\u003elist\u003c/code\u003e to \u003ccode\u003eMapping\u003c/code\u003e\nand \u003ccode\u003eSequence\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7436\"\u003e#7436\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eChanged \u003ccode\u003eheaders\u003c/code\u003e input type to MutableMapping and removed \u003ccode\u003eNone\u003c/code\u003e from\n\u003ccode\u003eRequest.headers\u003c/code\u003e typing to improve handling for users. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7431\"\u003e#7431\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eResponse.reason\u003c/code\u003e moved from \u003ccode\u003estr | None\u003c/code\u003e to \u003ccode\u003estr\u003c/code\u003e to improve handling\nfor users. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7437\"\u003e#7437\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed a bug where some bodies with custom \u003ccode\u003e__getattr__\u003c/code\u003e implementations\nweren't being properly detected as Iterables. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7433\"\u003e#7433\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.34.0 (2026-05-11)\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eAnnouncements\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eRequests 2.34.0 introduces inline types, replacing those provided by\ntypeshed. Public API types should be fully compatible with mypy, pyright,\nand ty. We believe types are comprehensive but if you find issues, please\nreport them to the pinned tracking issue.\u003c/p\u003e\n\u003cp\u003eSpecial thanks to \u003ca href=\"https://github.com/bastimeyer\"\u003e\u003ccode\u003e@​bastimeyer\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/cthoyt\"\u003e\u003ccode\u003e@​cthoyt\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/edgarrmondragon\"\u003e\u003ccode\u003e@​edgarrmondragon\u003c/code\u003e\u003c/a\u003e, and \u003ca href=\"https://github.com/srittau\"\u003e\u003ccode\u003e@​srittau\u003c/code\u003e\u003c/a\u003e for\nhelping review and test the types ahead of the release. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7272\"\u003e#7272\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eImprovements\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eDigest Auth hashing algorithms have added \u003ccode\u003eusedforsecurity=False\u003c/code\u003e to clarify\nsecurity considerations. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7310\"\u003e#7310\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests added support for Python 3.15 based on beta1. Downstream projects\nshould be able to start testing prior to its release in October. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7422\"\u003e#7422\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests added support for Python 3.14t. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7419\"\u003e#7419\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eBugfixes\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eResponse.history\u003c/code\u003e no longer contains a reference to itself, preventing\naccidental looping when traversing the history list. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7328\"\u003e#7328\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests no longer performs greedy matching on no_proxy domains. The\nproxy_bypass implementation has been updated with CPython's fix from\nbpo-39057. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7427\"\u003e#7427\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests no longer incorrectly strips duplicate leading slashes in\nURI paths. This should address user issues with specific presigned\nURLs. Note the full fix requires urllib3 2.7.0+. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7315\"\u003e#7315\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/6e83187b8feb273ed4c6cdab5efd8d54901dfab3\"\u003e\u003ccode\u003e6e83187\u003c/code\u003e\u003c/a\u003e v2.34.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/84d10f0be83e8f6aeca8a05230c52216431c4d0b\"\u003e\u003ccode\u003e84d10f0\u003c/code\u003e\u003c/a\u003e Move Request.headers back to Mapping (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7441\"\u003e#7441\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/b7b549b54571d03950b16afd2d01bc6ff0348224\"\u003e\u003ccode\u003eb7b549b\u003c/code\u003e\u003c/a\u003e v2.34.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/e511bc72777a94c45d004e010c597925092e1efe\"\u003e\u003ccode\u003ee511bc7\u003c/code\u003e\u003c/a\u003e Fix mutability issues with headers input types (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7431\"\u003e#7431\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/5691f596134c2feb121e595c77a0178921fcce61\"\u003e\u003ccode\u003e5691f59\u003c/code\u003e\u003c/a\u003e Update JsonType containers to read-based collections (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7436\"\u003e#7436\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/2144213c307691710c9d665700860fc4993c3035\"\u003e\u003ccode\u003e2144213\u003c/code\u003e\u003c/a\u003e Constrain Response.reason to str (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7437\"\u003e#7437\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/6404f345e562d962abe6700a1c357ec1e7e18232\"\u003e\u003ccode\u003e6404f34\u003c/code\u003e\u003c/a\u003e Fix \u003ccode\u003eprepare_body\u003c/code\u003e stream detection for \u003ccode\u003e__getattr__\u003c/code\u003e-based file wrappers (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7\"\u003e#7\u003c/a\u003e...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/0b401c76b6e80a4eecf3c690085b2553f6e261ca\"\u003e\u003ccode\u003e0b401c7\u003c/code\u003e\u003c/a\u003e v2.34.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/86b378d3f60f828daa13ca50aa82e287ff7b66b4\"\u003e\u003ccode\u003e86b378d\u003c/code\u003e\u003c/a\u003e Align Session.get parameters with requests.get (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7429\"\u003e#7429\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/a4f9a5999bdb9bf2d6e7c8aa973b28cacb17134f\"\u003e\u003ccode\u003ea4f9a59\u003c/code\u003e\u003c/a\u003e Port bpo-39057 to Requests (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7427\"\u003e#7427\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/psf/requests/compare/v2.32.3...v2.34.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `tqdm` from 4.67.3 to 4.70.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/tqdm/tqdm/releases\"\u003etqdm's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003etqdm v4.70.1 stable\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003econtrib.concurrent\u003c/code\u003e: fix no-len iterables (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1830\"\u003e#1830\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1828\"\u003e#1828\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003etests: major overhaul (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1819\"\u003e#1819\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eupdate AI policy in PR template\u003c/li\u003e\n\u003cli\u003emisc lint \u0026amp; tidy\u003c/li\u003e\n\u003cli\u003eCI: bump workflow actions \u0026amp; pre-commit hooks\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003etqdm v4.70.0 stable\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003econtrib.concurrent\u003c/code\u003e: major improvements\n\u003cul\u003e\n\u003cli\u003esupport \u003ccode\u003eprocess_map(mp_context, max_tasks_per_child)\u003c/code\u003e, \u003ccode\u003ethread_map(thread_name_prefix)\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1265\"\u003e#1265\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix \u003ccode\u003etotal\u003c/code\u003e based on shortest iterable length (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1473\"\u003e#1473\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003euse default \u003ccode\u003emax_workers\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1543\"\u003e#1543\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1530\"\u003e#1530\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1518\"\u003e#1518\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003esupport \u003ccode\u003etimeout\u003c/code\u003e, \u003ccode\u003ebuffersize\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1576\"\u003e#1576\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eimprove ETA (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1708\"\u003e#1708\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1161\"\u003e#1161\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eupdate \u003ccode\u003eas_completed\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1709\"\u003e#1709\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1565\"\u003e#1565\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eadd \u003ccode\u003etqdm.concurrent.intepreter_map\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1777\"\u003e#1777\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003easyncio\u003c/code\u003e: support iterables with only \u003ccode\u003e__aiter__\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1714\"\u003e#1714\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1686\"\u003e#1686\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003esupport \u003ccode\u003ereset(float(\u0026quot;inf\u0026quot;))\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1783\"\u003e#1783\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1781\"\u003e#1781\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/651\"\u003e#651\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eframework: test \u0026amp; reduce wheel size (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1782\"\u003e#1782\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003etqdm v4.69.1 stable\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003econtrib.logging\u003c/code\u003e: preserve filters (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1775\"\u003e#1775\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1581\"\u003e#1581\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003erich\u003c/code\u003e: misc fixes (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1773\"\u003e#1773\u003c/a\u003e)\n\u003cul\u003e\n\u003cli\u003esupport generators (without \u003ccode\u003elen\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1391\"\u003e#1391\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix potential \u003ccode\u003eAttributeError\u003c/code\u003e on exit (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1674\"\u003e#1674\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003efix \u003ccode\u003etotal=float('inf')\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1781\"\u003e#1781\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/651\"\u003e#651\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix potential \u003ccode\u003eAttributeError\u003c/code\u003e on exit (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1778\"\u003e#1778\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1668\"\u003e#1668\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1537\"\u003e#1537\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/261\"\u003e#261\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix minor docs typos (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1780\"\u003e#1780\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1746\"\u003e#1746\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003etqdm v4.69.0 stable\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eadd \u003ccode\u003etqdm.asyncio.gather(..., return_exceptions=False)\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1776\"\u003e#1776\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1671\"\u003e#1671\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1286\"\u003e#1286\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003emisc minor framework updates\n\u003cul\u003e\n\u003cli\u003ebump workflow actions \u0026amp; pre-commit hooks\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003etqdm v4.68.4 stable\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003etrim to \u003ccode\u003encols\u003c/code\u003e even when \u003ccode\u003e'{bar}' not in bar_format\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1717\"\u003e#1717\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1767\"\u003e#1767\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1658\"\u003e#1658\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix \u003ccode\u003etqdm.write\u003c/code\u003e when \u003ccode\u003estdout=None\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1768\"\u003e#1768\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1654\"\u003e#1654\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003etqdm v4.68.3 stable\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eutils\u003c/code\u003e: delay \u003ccode\u003eos.get_terminal_size\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1763\"\u003e#1763\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1760\"\u003e#1760\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eautonotebook\u003c/code\u003e: support QtConsole, Spyder, JupyterLite (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1763\"\u003e#1763\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1628\"\u003e#1628\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1559\"\u003e#1559\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1283\"\u003e#1283\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1098\"\u003e#1098\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/512\"\u003e#512\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eminor docs updates\n\u003cul\u003e\n\u003cli\u003efix typo (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1762\"\u003e#1762\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003euse \u003ccode\u003egit-fame\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003emisc minor framework updates\n\u003cul\u003e\n\u003cli\u003efix \u0026amp; update CI build\u003c/li\u003e\n\u003cli\u003epre-commit: add docs \u0026amp; metadata generation\u003c/li\u003e\n\u003cli\u003emove \u003ccode\u003etox.ini\u003c/code\u003e -\u0026gt; \u003ccode\u003epyproject.toml\u003c/code\u003e, move \u003ccode\u003etox-gh-actions\u003c/code\u003e -\u0026gt; \u003ccode\u003etox-gh\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eadd Python 3.14, drop 3.7 support\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/9cf5a12b1f955468a17f0ba3c59092b23e4258ac\"\u003e\u003ccode\u003e9cf5a12\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1830\"\u003e#1830\u003c/a\u003e from eaubin/master\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/24b9e1e08a097f1c30f2d235b63f9eb25ba47974\"\u003e\u003ccode\u003e24b9e1e\u003c/code\u003e\u003c/a\u003e misc tidy\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/2a9e4e82ddba07c5dd6d126e23a4745b76ea49c8\"\u003e\u003ccode\u003e2a9e4e8\u003c/code\u003e\u003c/a\u003e contrib.concurrent: fix no-len iterables\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/8d6ff8de5a9066de77d0a9df3e80a022a3dcf146\"\u003e\u003ccode\u003e8d6ff8d\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1819\"\u003e#1819\u003c/a\u003e from tqdm/devel\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/bed379609c2c8300671c784c8f85a185c8cf6fb3\"\u003e\u003ccode\u003ebed3796\u003c/code\u003e\u003c/a\u003e tests: major overhaul\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/4d3d3194d5467e0701bc0f4b836a735273ef0868\"\u003e\u003ccode\u003e4d3d319\u003c/code\u003e\u003c/a\u003e AI policy\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/5dcb022b55553b60ed2131b64aa5bf1e65470df1\"\u003e\u003ccode\u003e5dcb022\u003c/code\u003e\u003c/a\u003e minor syntax update\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/309effe4244bf45427c5add7f1bcf33f98a7b421\"\u003e\u003ccode\u003e309effe\u003c/code\u003e\u003c/a\u003e tests: pre-commit coverage\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/604193aa03b5f5c0ad5f3d441951f0fbb515f1e4\"\u003e\u003ccode\u003e604193a\u003c/code\u003e\u003c/a\u003e tests: slight tidy\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/17f1cac07c89943eb0e6082875b3821205308d4f\"\u003e\u003ccode\u003e17f1cac\u003c/code\u003e\u003c/a\u003e CI: bump workflow actions\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/tqdm/tqdm/compare/v4.67.3...v4.70.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `transformers` from 5.14.1 to 5.17.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/huggingface/transformers/releases\"\u003etransformers's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eRelease 5.17.0\u003c/h2\u003e\n\u003ch1\u003eRelease v5.17.0\u003c/h1\u003e\n\u003ch2\u003eNew Model additions\u003c/h2\u003e\n\u003ch3\u003eHYV4\u003c/h3\u003e\n\n\u003cp\u003eHy4-Preview is a 780B-parameter mixture-of-experts language model that activates 49B parameters per\ntoken. Each MoE layer holds 256 routed experts plus one always-active shared expert and routes every\ntoken to 8 of them. The context window is 1M tokens.\u003c/p\u003e\n\u003cp\u003eThe architecture combines four features:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eMulti-head Latent Attention (MLA)\u003c/strong\u003e compresses keys and values into a low-rank latent\n(\u003ccode\u003ekv_lora_rank\u003c/code\u003e) that \u003ccode\u003ekv_b_proj\u003c/code\u003e expands back to one key/value per query head.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eDeepSeek Sparse Attention (DSA)\u003c/strong\u003e selects \u003ccode\u003eindex_topk\u003c/code\u003e keys per query with a lightweight indexer.\nFollowing \u003ca href=\"https://huggingface.co/papers/2603.12201\"\u003eIndexShare\u003c/a\u003e, only the layers marked \u003ccode\u003e\u0026quot;full\u0026quot;\u003c/code\u003e\nin \u003ccode\u003eindexer_types\u003c/code\u003e run an indexer; \u003ccode\u003e\u0026quot;shared\u0026quot;\u003c/code\u003e layers reuse the previous full layer's selection.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eGated MLA with learnable attention sinks\u003c/strong\u003e, where each head owns a sink logit that participates\nin the softmax and contributes no value, as in \u003ca href=\"https://github.com/huggingface/transformers/blob/HEAD/gpt_oss\"\u003eGPT-OSS\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eIndependent Hyper-Connections (iHC)\u003c/strong\u003e replace the plain residual path with \u003ccode\u003ehc_mult\u003c/code\u003e parallel\nresidual streams that are collapsed before, and redistributed after, every sublayer.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThe implementation does not execute the multi-token prediction (MTP) layers. Released checkpoints\nkeep those weights so that other runtimes can use them for speculative decoding; they are ignored\nat load time.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/hy_v4\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAdd h4 (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48473\"\u003e#48473\u003c/a\u003e) by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/transformers/pull/48473\"\u003e#48473\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eVibeVoice\u003c/h3\u003e\n\n\u003cp\u003e\u003ca href=\"https://huggingface.co/papers/2508.19205\"\u003eVibeVoice\u003c/a\u003e is a novel framework for synthesizing high-fidelity, long-form speech with multiple speakers by employing a next-token diffusion approach within a Large Language Model (LLM) structure. It's designed to capture the authentic conversational \u0026quot;vibe\u0026quot; and is particularly suited for generating audio content like podcasts and multi-participant audiobooks.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/vibevoice\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eImplement VibeVoice  (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/40546\"\u003e#40546\u003c/a\u003e) by \u003ca href=\"https://github.com/pengzhiliang\"\u003e\u003ccode\u003e@​pengzhiliang\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/transformers/pull/40546\"\u003e#40546\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eNeoMME\u003c/h3\u003e\n\u003cp\u003eNeoMME is a family of efficient 260M and 800M parameter multimodal-native multilingual foundation encoders from H Company. It processes multilingual text tokens and raw image patches in a single bidirectional Transformer encoder, without a separately pretrained vision tower or causal language model.\u003c/p\u003e\n\u003cp\u003eNeoMME-Retriever is a model fine-tuned from the NeoMME backbone for visual document retrieval with joint late-interaction and dense objectives. It takes text queries and documents (text or page screenshots) and produces multi-vector embeddings for MeanMaxSim scoring (late-interaction) and mean-pooled embeddings for cosine similarity (dense).\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/neomme\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/856157a2f3e9594954310df18fdccc31ffddebe9\"\u003e\u003ccode\u003e856157a\u003c/code\u003e\u003c/a\u003e v5.17.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/5b7dcb0d36c242d8d85920a81c564ef3a86ca6dd\"\u003e\u003ccode\u003e5b7dcb0\u003c/code\u003e\u003c/a\u003e MRoPE continued (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48594\"\u003e#48594\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/50bbcc630ed1675d15d2def3877c88d6c2630415\"\u003e\u003ccode\u003e50bbcc6\u003c/code\u003e\u003c/a\u003e [fix] Update stale expected strings in HunYuanVL integration tests (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48646\"\u003e#48646\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/e8bcd79c4c77a529bc34d6e19f7d718164b7fa6a\"\u003e\u003ccode\u003ee8bcd79\u003c/code\u003e\u003c/a\u003e [Quantizaiton]support 5/6/7 bits in AutoRound (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48481\"\u003e#48481\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/3283d5f78ed6836d39430c8190a6e0500be78698\"\u003e\u003ccode\u003e3283d5f\u003c/code\u003e\u003c/a\u003e [fix] Update stale golden values and fix expected_logits shape in FlavaForPre...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/5f47b5aad791b69dff597b903614fb2bef8b88a1\"\u003e\u003ccode\u003e5f47b5a\u003c/code\u003e\u003c/a\u003e [tests] Fix integration test golden values broken by fast image processor def...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/fc501343edfccdc840eb8594a6cafa8185c2de53\"\u003e\u003ccode\u003efc50134\u003c/code\u003e\u003c/a\u003e Add Fun-ASR-Nano model (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46180\"\u003e#46180\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/d9fe823d1cedbba33dd0aeef08f773abe971688e\"\u003e\u003ccode\u003ed9fe823\u003c/code\u003e\u003c/a\u003e Fix YOLOS device mismatch with device_map=\u0026quot;auto\u0026quot; (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46886\"\u003e#46886\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/cbc1651a032b923da7f4b44b3d0e6f68e6ba6b55\"\u003e\u003ccode\u003ecbc1651\u003c/code\u003e\u003c/a\u003e [\u003ccode\u003eGenerate\u003c/code\u003e] Avoid unconditionally downloading remote hub file (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48620\"\u003e#48620\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/bd05a4b2baf8b37b8f64c0c2c70d2628583f7c2a\"\u003e\u003ccode\u003ebd05a4b\u003c/code\u003e\u003c/a\u003e Honor \u003ccode\u003eshift_labels\u003c/code\u003e in decoder-only LLM/VLM losses (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48493\"\u003e#48493\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/huggingface/transformers/compare/v5.14.1...v5.17.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `huggingface-hub` from 1.26.0 to 1.32.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/huggingface/huggingface_hub/releases\"\u003ehuggingface-hub's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e[v1.32.0] Shared blob store, sandbox security hardening and faster imports\u003c/h2\u003e\n\u003ch2\u003e:open_file_folder: [Cache] Shared blob store: deduplicate Xet files across repos\u003c/h2\u003e\n\u003cp\u003eThe cache now deduplicates Xet files across repos. A Xet file downloaded through \u003ccode\u003ehf_xet\u003c/code\u003e is stored once at \u003ccode\u003e\u0026lt;CACHE_DIR\u0026gt;/blobs/\u0026lt;prefix\u0026gt;/\u0026lt;xet_hash\u0026gt;\u003c/code\u003e and every repo that needs it gets a relative symlink instead of a download: no bytes are transferred and no extra space is used, even across different repos — or after the repo that first downloaded the file was deleted. The per-repo snapshot layout is unchanged, older clients keep reading and downloading normally, and any failure to share silently falls back to regular repo-local storage. Set \u003ccode\u003eHF_HUB_DISABLE_SHARED_BLOBS=1\u003c/code\u003e to opt out entirely. Shared files carry a \u003ccode\u003e\u0026lt;xet_hash\u0026gt;.refs\u003c/code\u003e manifest listing the repo blobs referencing them, which \u003ccode\u003ehf cache rm\u003c/code\u003e consults on deletion and \u003ccode\u003ehf cache prune\u003c/code\u003e sweeps to reclaim payloads that no cached repo uses anymore.\u003c/p\u003e\n\u003cp\u003e📚 \u003cstrong\u003eDocumentation:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/huggingface_hub/main/en/guides/manage-cache\"\u003eManage your cache\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e[Cache] Add cross-repo shared blob store by \u003ca href=\"https://github.com/hanouticelina\"\u003e\u003ccode\u003e@​hanouticelina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4498\"\u003e#4498\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e:computer: [Jobs] Ship config inside UV scripts\u003c/h2\u003e\n\u003cp\u003eA UV script that only runs correctly on a specific runtime can now carry that runtime with it. An optional \u003ccode\u003e[tool.hf-jobs]\u003c/code\u003e table in the script's PEP 723 header accepts \u003ccode\u003eimage\u003c/code\u003e, \u003ccode\u003eflavor\u003c/code\u003e, \u003ccode\u003epython\u003c/code\u003e, \u003ccode\u003etimeout\u003c/code\u003e, \u003ccode\u003ename\u003c/code\u003e, \u003ccode\u003enamespace\u003c/code\u003e, \u003ccode\u003eenv\u003c/code\u003e, \u003ccode\u003esecrets\u003c/code\u003e, \u003ccode\u003elabels\u003c/code\u003e, \u003ccode\u003evolumes\u003c/code\u003e, \u003ccode\u003enetwork_group\u003c/code\u003e and \u003ccode\u003enetwork_aliases\u003c/code\u003e, and \u003ccode\u003ehf jobs uv run\u003c/code\u003e reads it at submit time. CLI flags always win, and \u003ccode\u003eenv\u003c/code\u003e/\u003ccode\u003esecrets\u003c/code\u003e/\u003ccode\u003elabels\u003c/code\u003e/\u003ccode\u003evolumes\u003c/code\u003e merge entry by entry instead of being replaced, so \u003ccode\u003e-e\u003c/code\u003e/\u003ccode\u003e-v\u003c/code\u003e add to what the script declares. Typos and unknown keys are rejected with the list of valid options, secrets are passed by name only (values come from your environment), and every run prints a config summary with script-sourced values marked and secrets redacted. Note that the table is read by the CLI only: \u003ccode\u003erun_uv_job()\u003c/code\u003e and \u003ccode\u003ecreate_scheduled_uv_job()\u003c/code\u003e ignore it.\u003c/p\u003e\n\u003cpre lang=\"python\"\u003e\u003ccode\u003e# /// script\r\n# requires-python = \u0026quot;\u0026gt;=3.11\u0026quot;\r\n# dependencies = [\u0026quot;vllm\u0026quot;, \u0026quot;datasets\u0026quot;]\r\n#\r\n# [tool.hf-jobs]\r\n# image   = \u0026quot;vllm/vllm-openai:unlimited-ocr\u0026quot;\r\n# flavor  = \u0026quot;l4x1\u0026quot;\r\n# python  = \u0026quot;/usr/bin/python3\u0026quot;\r\n# secrets = [\u0026quot;HF_TOKEN\u0026quot;]\r\n# ///\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003e📚 \u003cstrong\u003eDocumentation:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/huggingface_hub/main/en/guides/jobs\"\u003eRun and manage Jobs\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e[CLI] Read a UV script's \u003ccode\u003e[tool.hf-jobs]\u003c/code\u003e launch config (opus-generated) by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4598\"\u003e#4598\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🛡️ [Sandbox] security hardening\u003c/h2\u003e\n\u003cp\u003eAn internal security review of the Sandbox API resulted in a 9-PR hardening series. Pooled sandboxes now use their own per-sandbox capability token instead of the host-wide credential, pool hosts are fully validated (initiator, namespace, image, flavor, command, URL) before any credential is sent to them, the \u003ccode\u003esbx-server\u003c/code\u003e binary is pinned by digest and verified before being run as PID 1, and the local pool cache is bound to the endpoint, credential and namespace that wrote it. Secret values no longer end up in \u003ccode\u003eargv\u003c/code\u003e when using \u003ccode\u003ehf sandbox exec --secrets\u003c/code\u003e, background processes are addressed by their server-assigned id (so \u003ccode\u003ekill()\u003c/code\u003e actually stops them and reports honestly), transfers and command output are bounded to avoid unbounded memory usage in the client, and pool ownership is decided per host so a \u003ccode\u003ewith SandboxPool(...)\u003c/code\u003e block never again tears down a colleague's discovered host. The security documentation was also rewritten to state precisely what the sandbox contract is — and what it is not — including a new \u0026quot;Known limitations\u0026quot; section.\u003c/p\u003e\n\u003cp\u003e📚 \u003cstrong\u003eDocumentation:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/huggingface_hub/main/en/guides/sandbox\"\u003eSandboxes\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e[sandbox audit] Make the sandbox security contract match the implementation by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4831\"\u003e#4831\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[sandbox audit] Use each pooled sandbox's own capability token by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4832\"\u003e#4832\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[sandbox audit] Validate a pool host before sending it a credential by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4834\"\u003e#4834\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[sandbox audit] Bind the sandbox pool cache to the endpoint, credential and namespace that wrote it by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4838\"\u003e#4838\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[sandbox audit] Bound what a transfer or a command's output costs the client by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4839\"\u003e#4839\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[sandbox audit] Decide host teardown per host, and report it honestly by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4840\"\u003e#4840\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[sandbox audit] Address background processes by their server-assigned id by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4836\"\u003e#4836\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[sandbox audit] Pin the sandbox server binary by digest and verify it before running it by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4837\"\u003e#4837\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[sandbox audit] Keep secret values out of argv in the CLI and fix the env/secrets docs by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4835\"\u003e#4835\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🔒 Security hardening for serialization and validation\u003c/h2\u003e\n\u003cp\u003eThree changes make the library safer against malicious or malformed inputs, with a stricter behavior worth noting. Torch checkpoint deserialization was hardened across 11 reported vulnerabilities: \u003ccode\u003eload_state_dict_from_file\u003c/code\u003e now defaults to \u003ccode\u003esafe=True\u003c/code\u003e (always using the safetensors loader), the pickle path defaults to \u003ccode\u003eweights_only=True\u003c/code\u003e, and unsafe combinations raise explicit errors instead of silently falling through. Path validation now rejects \u003ccode\u003e..\u003c/code\u003e segments anywhere in \u003ccode\u003epath_in_repo\u003c/code\u003e (previously only a leading one was caught), so uploads like \u003ccode\u003e\u0026quot;a/../../etc/passwd\u0026quot;\u003c/code\u003e are refused. Finally, \u003ccode\u003erepo_id\u003c/code\u003e validation is restricted to ASCII word characters as documented, so non-ASCII ids like \u003ccode\u003ecafé\u003c/code\u003e are rejected client-side instead of failing later on the Hub.\u003c/p\u003e\n\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/8814aabc81298df547bece9e71e4e88d3e513928\"\u003e\u003ccode\u003e8814aab\u003c/code\u003e\u003c/a\u003e Release: v1.32.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/445770606fa5ca80765a8e7a3d6e8cfaacaf7919\"\u003e\u003ccode\u003e4457706\u003c/code\u003e\u003c/a\u003e Release: v1.32.0.rc0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/b064a14629f9cdf3622e3fcac52c4f0e4e58c6b6\"\u003e\u003ccode\u003eb064a14\u003c/code\u003e\u003c/a\u003e [Download] Send X-HF-Download-Counter header on download calls (\u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4613\"\u003e#4613\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/79dd41ed6dec58314dad130fe7b8b578c8a1737d\"\u003e\u003ccode\u003e79dd41e\u003c/code\u003e\u003c/a\u003e [Docs] Fix hf discussions info options that do not exist (\u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4886\"\u003e#4886\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/d7b62c7becb6ba75667ab2c5b32d9338bcd5a4d4\"\u003e\u003ccode\u003ed7b62c7\u003c/code\u003e\u003c/a\u003e [CLI] Fix card data serialization (\u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4882\"\u003e#4882\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/f94ea55533a6fc796f191723823217fe75dfd462\"\u003e\u003ccode\u003ef94ea55\u003c/code\u003e\u003c/a\u003e [Buckets] Send mtime when copying files (\u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4920\"\u003e#4920\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/6e3d21f5d5a663468e58b37e6b94871e97534c24\"\u003e\u003ccode\u003e6e3d21f\u003c/code\u003e\u003c/a\u003e [Cache] Add cross-repo shared blob store (\u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4498\"\u003e#4498\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/5a9cdda63f231a1b57a05eab88dc4357c790ba87\"\u003e\u003ccode\u003e5a9cdda\u003c/code\u003e\u003c/a\u003e [Core] Speed up package imports (\u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4914\"\u003e#4914\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/2075fd68e69297eed60e1b058ef9b67b742b505d\"\u003e\u003ccode\u003e2075fd6\u003c/code\u003e\u003c/a\u003e [Cache] Support kernel repos in \u003ccode\u003ehf cache\u003c/code\u003e commands (\u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4905\"\u003e#4905\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/af6b41ece7448c5d7531699376c6f5974a2d24cc\"\u003e\u003ccode\u003eaf6b41e\u003c/code\u003e\u003c/a\u003e [Core] Reject path traversal via embedded \u0026quot;..\u0026quot; segments in path_in_repo (\u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4884\"\u003e#4884\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/huggingface/huggingface_hub/compare/v1.26.0...v1.32.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `tokenizers` from 0.22.2 to 0.23.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/huggingface/tokenizers/releases\"\u003etokenizers's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev0.23.2\u003c/h2\u003e\n\u003cp\u003eThis is the last v0 release, we are moving to v1!!\u003c/p\u003e\n\u003cp\u003eMore details coming soon 👀\u003c/p\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate daachorse from 1.0.1 to 3.0.0 by \u003ca href=\"https://github.com/musicinmybrain\"\u003e\u003ccode\u003e@​musicinmybrain\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2050\"\u003ehuggingface/tokenizers#2050\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eCi test fixes by \u003ca href=\"https://github.com/sebpop\"\u003e\u003ccode\u003e@​sebpop\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2079\"\u003ehuggingface/tokenizers#2079\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAvoid full vocab clone in get_vocab_size() by \u003ca href=\"https://github.com/eunseo9311\"\u003e\u003ccode\u003e@​eunseo9311\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2074\"\u003ehuggingface/tokenizers#2074\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: pin benchmark jobs to a larger dedicated runner by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2084\"\u003ehuggingface/tokenizers#2084\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: target benchmark runners by group, not nonexistent label by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2090\"\u003ehuggingface/tokenizers#2090\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBindings: acquire model read-lock once per call instead of per pre-token by \u003ca href=\"https://github.com/sebpop\"\u003e\u003ccode\u003e@​sebpop\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2072\"\u003ehuggingface/tokenizers#2072\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: split audit in a separate job by \u003ca href=\"https://github.com/SBrandeis\"\u003e\u003ccode\u003e@​SBrandeis\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2103\"\u003ehuggingface/tokenizers#2103\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: install libcairo on benchmark runners by \u003ca href=\"https://github.com/SBrandeis\"\u003e\u003ccode\u003e@​SBrandeis\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2100\"\u003ehuggingface/tokenizers#2100\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(ci): enable npm's trusted publisher for releases by \u003ca href=\"https://github.com/McPatate\"\u003e\u003ccode\u003e@​McPatate\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2111\"\u003ehuggingface/tokenizers#2111\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: bump pyo3 to version 0.29 by \u003ca href=\"https://github.com/SBrandeis\"\u003e\u003ccode\u003e@​SBrandeis\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2115\"\u003ehuggingface/tokenizers#2115\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eperf: add benchmarks for the \u003ccode\u003edecode\u003c/code\u003e API by \u003ca href=\"https://github.com/SBrandeis\"\u003e\u003ccode\u003e@​SBrandeis\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2099\"\u003ehuggingface/tokenizers#2099\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: cache HF test data and authenticate Hub downloads to avoid rate limits by \u003ca href=\"https://github.com/SBrandeis\"\u003e\u003ccode\u003e@​SBrandeis\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2102\"\u003ehuggingface/tokenizers#2102\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eImplementing Parity-aware BPE by \u003ca href=\"https://github.com/cimeister\"\u003e\u003ccode\u003e@​cimeister\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/1974\"\u003ehuggingface/tokenizers#1974\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eMake doc builds faster by \u003ca href=\"https://github.com/mishig25\"\u003e\u003ccode\u003e@​mishig25\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2158\"\u003ehuggingface/tokenizers#2158\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(deps-dev): bump websocket-driver from 0.7.4 to 0.7.5 in /tokenizers/examples/unstable_wasm/www by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2208\"\u003ehuggingface/tokenizers#2208\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(deps-dev): bump shell-quote from 1.8.3 to 1.10.0 in /tokenizers/examples/unstable_wasm/www by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2244\"\u003ehuggingface/tokenizers#2244\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: remove stale examples (kills 50% of dependabot traffic) by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2285\"\u003ehuggingface/tokenizers#2285\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(node): drop 8 unused devDependencies by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2286\"\u003ehuggingface/tokenizers#2286\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: pin every action to one SHA, drop stale audit suppressions by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2291\"\u003ehuggingface/tokenizers#2291\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(node): take node security alerts from 33 to 0 by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2287\"\u003ehuggi...\n\n_Description has been truncated_","html_url":"https://github.com/kuoihao/vllm-tle/pull/18","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/kuoihao%2Fvllm-tle/issues/18","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/18/packages"},{"uuid":"5575687922","node_id":"PR_kwDOTfTeHs8AAAABFBcojQ","number":5,"state":"open","title":"Bump the pip group across 1 directory with 7 updates","user":"dependabot[bot]","labels":["dependencies","python"],"assignees":[],"locked":false,"comments_count":6,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-24T23:06:29.000Z","updated_at":"2026-09-24T23:06:40.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","group_name":"pip","update_count":7,"packages":[{"name":"anthropic","old_version":"0.86.0","new_version":"0.87.0","repository_url":"https://github.com/anthropics/anthropic-sdk-python"},{"name":"pyjwt","old_version":"2.12.1","new_version":"2.13.0","repository_url":"https://github.com/jpadilla/pyjwt"},{"name":"mcp","old_version":"1.26.0","new_version":"1.28.1","repository_url":"https://github.com/modelcontextprotocol/python-sdk"},{"name":"aiohttp","old_version":"3.10.10","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"anyio","old_version":"4.13.0","new_version":"4.14.2","repository_url":"https://github.com/agronholm/anyio"},{"name":"idna","old_version":"3.11","new_version":"3.15","repository_url":"https://github.com/kjd/idna"},{"name":"urllib3","old_version":"2.6.3","new_version":"2.7.0","repository_url":"https://github.com/urllib3/urllib3"}],"path":null,"ecosystem":"pip"},"body":"Bumps the pip group with 7 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [anthropic](https://github.com/anthropics/anthropic-sdk-python) | `0.86.0` | `0.87.0` |\n| [pyjwt](https://github.com/jpadilla/pyjwt) | `2.12.1` | `2.13.0` |\n| [mcp](https://github.com/modelcontextprotocol/python-sdk) | `1.26.0` | `1.28.1` |\n| [aiohttp](https://github.com/aio-libs/aiohttp) | `3.10.10` | `3.14.3` |\n| [anyio](https://github.com/agronholm/anyio) | `4.13.0` | `4.14.2` |\n| [idna](https://github.com/kjd/idna) | `3.11` | `3.15` |\n| [urllib3](https://github.com/urllib3/urllib3) | `2.6.3` | `2.7.0` |\n\n\nUpdates `anthropic` from 0.86.0 to 0.87.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/anthropics/anthropic-sdk-python/releases\"\u003eanthropic's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev0.87.0\u003c/h2\u003e\n\u003ch2\u003e0.87.0 (2026-03-31)\u003c/h2\u003e\n\u003cp\u003eFull Changelog: \u003ca href=\"https://github.com/anthropics/anthropic-sdk-python/compare/v0.86.0...v0.87.0\"\u003ev0.86.0...v0.87.0\u003c/a\u003e\u003c/p\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eclient:\u003c/strong\u003e add error type field to APIStatusError (\u003ca href=\"https://redirect.github.com/anthropics/anthropic-sdk-python/issues/1587\"\u003e#1587\u003c/a\u003e) (\u003ca href=\"https://github.com/anthropics/anthropic-sdk-python/commit/dd563c031c2a0be75ccb6175246685abd5806d7d\"\u003edd563c0\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003einternal:\u003c/strong\u003e implement indices array format for query and form serialization (\u003ca href=\"https://github.com/anthropics/anthropic-sdk-python/commit/11a624467bd44175bc602f0135ff354895bdebdd\"\u003e11a6244\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ehonor \u003cstrong\u003eapi_exclude\u003c/strong\u003e in async transform path (\u003ca href=\"https://redirect.github.com/anthropics/anthropic-sdk-python/issues/1612\"\u003e#1612\u003c/a\u003e) (\u003ca href=\"https://github.com/anthropics/anthropic-sdk-python/commit/8172232a8bb19e0d0bf10df1c3c21ed492784585\"\u003e8172232\u003c/a\u003e), closes \u003ca href=\"https://redirect.github.com/anthropics/anthropic-sdk-python/issues/1610\"\u003e#1610\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ememory:\u003c/strong\u003e return resolved path from async _validate_path (\u003ca href=\"https://github.com/anthropics/anthropic-sdk-python/commit/7b0add32bd5fc59ad0fa277ef6982ee1df1eed7a\"\u003e7b0add3\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ememory:\u003c/strong\u003e use restrictive file mode for memory files (\u003ca href=\"https://github.com/anthropics/anthropic-sdk-python/commit/47ba5b8f5f74beb1e1babef249754e1312b9dddf\"\u003e47ba5b8\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003esanitize endpoint path params (\u003ca href=\"https://github.com/anthropics/anthropic-sdk-python/commit/98f60e42039392a133d83c8673d659f514c15a35\"\u003e98f60e4\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003etransform schema:\u003c/strong\u003e support enums (\u003ca href=\"https://redirect.github.com/anthropics/anthropic-sdk-python/issues/1275\"\u003e#1275\u003c/a\u003e) (\u003ca href=\"https://github.com/anthropics/anthropic-sdk-python/commit/5c088ab1d162b1c1a18f566688b31bfbd7610825\"\u003e5c088ab\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eChores\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eci:\u003c/strong\u003e run builds on CI even if only spec metadata changed (\u003ca href=\"https://github.com/anthropics/anthropic-sdk-python/commit/194c05029403cef820897c3c6b2c26d4df0736f7\"\u003e194c050\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eci:\u003c/strong\u003e skip lint on metadata-only changes (\u003ca href=\"https://github.com/anthropics/anthropic-sdk-python/commit/03e2ab9e95ec452d7d519e0b419c8881f3ae3a08\"\u003e03e2ab9\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003einternal:\u003c/strong\u003e update gitignore (\u003ca href=\"https://github.com/anthropics/anthropic-sdk-python/commit/94ede14b443c78b51931c185d1cd44f4ef201eae\"\u003e94ede14\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003etests:\u003c/strong\u003e bump steady to v0.19.4 (\u003ca href=\"https://github.com/anthropics/anthropic-sdk-python/commit/2d6d58fa0101930c8f5cd9e9a94e7e988055f371\"\u003e2d6d58f\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003etests:\u003c/strong\u003e bump steady to v0.19.5 (\u003ca href=\"https://github.com/anthropics/anthropic-sdk-python/commit/8fb439afeadaf608cbf7d4630d01735f97227e3e\"\u003e8fb439a\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003etests:\u003c/strong\u003e bump steady to v0.19.6 (\u003ca href=\"https://github.com/anthropics/anthropic-sdk-python/commit/76da5fdd03b7ffc65a8b58b9f2a0df3e03c587c9\"\u003e76da5fd\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003etests:\u003c/strong\u003e bump steady to v0.19.7 (\u003ca href=\"https://github.com/anthropics/anthropic-sdk-python/commit/bfa40e5c5bed65da0f3f664082e58e85c26b9c66\"\u003ebfa40e5\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003etests:\u003c/strong\u003e bump steady to v0.20.1 (\u003ca href=\"https://github.com/anthropics/anthropic-sdk-python/commit/4fd9446332ae114072dac968134e6451c62138bb\"\u003e4fd9446\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/anthropics/anthropic-sdk-python/blob/main/CHANGELOG.md\"\u003eanthropic's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e0.87.0 (2026-03-31)\u003c/h2\u003e\n\u003cp\u003eFull Changelog: \u003ca href=\"https://github.com/anthropics/anthropic-sdk-python/compare/v0.86.0...v0.87.0\"\u003ev0.86.0...v0.87.0\u003c/a\u003e\u003c/p\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eclient:\u003c/strong\u003e add error type field to APIStatusError (\u003ca href=\"https://redirect.github.com/anthropics/anthropic-sdk-python/issues/1587\"\u003e#1587\u003c/a\u003e) (\u003ca href=\"https://github.com/anthropics/anthropic-sdk-python/commit/dd563c031c2a0be75ccb6175246685abd5806d7d\"\u003edd563c0\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003einternal:\u003c/strong\u003e implement indices array format for query and form serialization (\u003ca href=\"https://github.com/anthropics/anthropic-sdk-python/commit/11a624467bd44175bc602f0135ff354895bdebdd\"\u003e11a6244\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ehonor \u003cstrong\u003eapi_exclude\u003c/strong\u003e in async transform path (\u003ca href=\"https://redirect.github.com/anthropics/anthropic-sdk-python/issues/1612\"\u003e#1612\u003c/a\u003e) (\u003ca href=\"https://github.com/anthropics/anthropic-sdk-python/commit/8172232a8bb19e0d0bf10df1c3c21ed492784585\"\u003e8172232\u003c/a\u003e), closes \u003ca href=\"https://redirect.github.com/anthropics/anthropic-sdk-python/issues/1610\"\u003e#1610\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ememory:\u003c/strong\u003e return resolved path from async _validate_path (\u003ca href=\"https://github.com/anthropics/anthropic-sdk-python/commit/7b0add32bd5fc59ad0fa277ef6982ee1df1eed7a\"\u003e7b0add3\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ememory:\u003c/strong\u003e use restrictive file mode for memory files (\u003ca href=\"https://github.com/anthropics/anthropic-sdk-python/commit/47ba5b8f5f74beb1e1babef249754e1312b9dddf\"\u003e47ba5b8\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003esanitize endpoint path params (\u003ca href=\"https://github.com/anthropics/anthropic-sdk-python/commit/98f60e42039392a133d83c8673d659f514c15a35\"\u003e98f60e4\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003etransform schema:\u003c/strong\u003e support enums (\u003ca href=\"https://redirect.github.com/anthropics/anthropic-sdk-python/issues/1275\"\u003e#1275\u003c/a\u003e) (\u003ca href=\"https://github.com/anthropics/anthropic-sdk-python/commit/5c088ab1d162b1c1a18f566688b31bfbd7610825\"\u003e5c088ab\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eChores\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eci:\u003c/strong\u003e run builds on CI even if only spec metadata changed (\u003ca href=\"https://github.com/anthropics/anthropic-sdk-python/commit/194c05029403cef820897c3c6b2c26d4df0736f7\"\u003e194c050\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eci:\u003c/strong\u003e skip lint on metadata-only changes (\u003ca href=\"https://github.com/anthropics/anthropic-sdk-python/commit/03e2ab9e95ec452d7d519e0b419c8881f3ae3a08\"\u003e03e2ab9\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003einternal:\u003c/strong\u003e update gitignore (\u003ca href=\"https://github.com/anthropics/anthropic-sdk-python/commit/94ede14b443c78b51931c185d1cd44f4ef201eae\"\u003e94ede14\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003etests:\u003c/strong\u003e bump steady to v0.19.4 (\u003ca href=\"https://github.com/anthropics/anthropic-sdk-python/commit/2d6d58fa0101930c8f5cd9e9a94e7e988055f371\"\u003e2d6d58f\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003etests:\u003c/strong\u003e bump steady to v0.19.5 (\u003ca href=\"https://github.com/anthropics/anthropic-sdk-python/commit/8fb439afeadaf608cbf7d4630d01735f97227e3e\"\u003e8fb439a\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003etests:\u003c/strong\u003e bump steady to v0.19.6 (\u003ca href=\"https://github.com/anthropics/anthropic-sdk-python/commit/76da5fdd03b7ffc65a8b58b9f2a0df3e03c587c9\"\u003e76da5fd\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003etests:\u003c/strong\u003e bump steady to v0.19.7 (\u003ca href=\"https://github.com/anthropics/anthropic-sdk-python/commit/bfa40e5c5bed65da0f3f664082e58e85c26b9c66\"\u003ebfa40e5\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003etests:\u003c/strong\u003e bump steady to v0.20.1 (\u003ca href=\"https://github.com/anthropics/anthropic-sdk-python/commit/4fd9446332ae114072dac968134e6451c62138bb\"\u003e4fd9446\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/anthropics/anthropic-sdk-python/commit/ab0c4460a170183ff036e2a3dad320ac4ac2c76d\"\u003e\u003ccode\u003eab0c446\u003c/code\u003e\u003c/a\u003e release: 0.87.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/anthropics/anthropic-sdk-python/commit/6599043eee6e86dce16953fcd1fd828052052be6\"\u003e\u003ccode\u003e6599043\u003c/code\u003e\u003c/a\u003e fix(memory): return resolved path from async _validate_path\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/anthropics/anthropic-sdk-python/commit/715030ceb4d6dd8d3546e999c680e29532bf1255\"\u003e\u003ccode\u003e715030c\u003c/code\u003e\u003c/a\u003e fix(memory): use restrictive file mode for memory files\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/anthropics/anthropic-sdk-python/commit/6cdbc5f37105e464704d911ef590b88c7e5ae427\"\u003e\u003ccode\u003e6cdbc5f\u003c/code\u003e\u003c/a\u003e chore(tests): bump steady to v0.20.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/anthropics/anthropic-sdk-python/commit/4beda3cc966b49166387aa9275cec8f88b004154\"\u003e\u003ccode\u003e4beda3c\u003c/code\u003e\u003c/a\u003e Add output-300k-2026-03-24 beta header\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/anthropics/anthropic-sdk-python/commit/3b77b826ce402881bcb2a43092e758368fccc99a\"\u003e\u003ccode\u003e3b77b82\u003c/code\u003e\u003c/a\u003e chore(ci): run builds on CI even if only spec metadata changed\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/anthropics/anthropic-sdk-python/commit/764ddbab9bcd6c4e076bf2618d4930e5b39cfb7c\"\u003e\u003ccode\u003e764ddba\u003c/code\u003e\u003c/a\u003e feat(internal): implement indices array format for query and form serialization\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/anthropics/anthropic-sdk-python/commit/8a06a905bb89bf8126e552d951270fe90869bc1d\"\u003e\u003ccode\u003e8a06a90\u003c/code\u003e\u003c/a\u003e codegen metadata\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/anthropics/anthropic-sdk-python/commit/7f8cf3c4c0c7a601847538364f6eccf00e72a2c4\"\u003e\u003ccode\u003e7f8cf3c\u003c/code\u003e\u003c/a\u003e chore(tests): bump steady to v0.19.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/anthropics/anthropic-sdk-python/commit/0eba0dd8f9590254b91eaadb79e44b792d56d85b\"\u003e\u003ccode\u003e0eba0dd\u003c/code\u003e\u003c/a\u003e chore(ci): skip lint on metadata-only changes\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/anthropics/anthropic-sdk-python/compare/v0.86.0...v0.87.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `pyjwt` from 2.12.1 to 2.13.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/jpadilla/pyjwt/releases\"\u003epyjwt's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e2.13.0\u003c/h2\u003e\n\u003ch1\u003ePyJWT 2.13.0 — Security Release\u003c/h1\u003e\n\u003cp\u003eThis release bundles five security fixes plus three additional hardening / spec-compliance changes. We recommend all users upgrade.\u003c/p\u003e\n\u003ch2\u003eSecurity\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/security/advisories/GHSA-xgmm-8j9v-c9wx\"\u003e\u003ccode\u003eGHSA-xgmm-8j9v-c9wx\u003c/code\u003e\u003c/a\u003e — JWK JSON accepted as HMAC secret (algorithm confusion).\u003c/strong\u003e \u003ccode\u003eHMACAlgorithm.prepare_key\u003c/code\u003e previously rejected PEM- and SSH-formatted asymmetric keys but did not catch a JWK passed as a raw JSON string. In a verifier configured with both symmetric and asymmetric algorithms in \u003ccode\u003ealgorithms=[…]\u003c/code\u003e and a raw-JSON JWK as the key, an attacker could forge HS256 tokens using the JWK text as the HMAC secret. The guard has been extended to reject any JWK-shaped JSON. \u003cem\u003eReported by \u003ca href=\"https://github.com/aradona91\"\u003e\u003ccode\u003e@​aradona91\u003c/code\u003e\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/security/advisories/GHSA-jq35-7prp-9v3f\"\u003e\u003ccode\u003eGHSA-jq35-7prp-9v3f\u003c/code\u003e\u003c/a\u003e — Algorithm allow-list bypass with \u003ccode\u003ePyJWK\u003c/code\u003e / \u003ccode\u003ePyJWKClient\u003c/code\u003e.\u003c/strong\u003e When verifying with a \u003ccode\u003ePyJWK\u003c/code\u003e, the caller's \u003ccode\u003ealgorithms=[…]\u003c/code\u003e allow-list was checked against the token header \u003ccode\u003ealg\u003c/code\u003e as a string only; actual verification used the algorithm bound to the \u003ccode\u003ePyJWK\u003c/code\u003e. An attacker who controlled a registered JWKS key could sign with one algorithm and advertise another on the header. PyJWT now requires the token header \u003ccode\u003ealg\u003c/code\u003e to match the \u003ccode\u003ePyJWK\u003c/code\u003e's algorithm before verification. \u003cem\u003eReported by \u003ca href=\"https://github.com/sushi-gif\"\u003e\u003ccode\u003e@​sushi-gif\u003c/code\u003e\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/security/advisories/GHSA-w7vc-732c-9m39\"\u003e\u003ccode\u003eGHSA-w7vc-732c-9m39\u003c/code\u003e\u003c/a\u003e — DoS via base64 decode of unused payload segment when \u003ccode\u003eb64=false\u003c/code\u003e.\u003c/strong\u003e For detached-payload JWS (\u003ccode\u003eb64=false\u003c/code\u003e), the compact-form payload segment was base64-decoded before being discarded in favor of the caller-supplied \u003ccode\u003edetached_payload\u003c/code\u003e. An attacker could inflate the unused segment to force CPU + memory cost without holding a valid signature. The segment is now required to be empty per RFC 7515 Appendix F, and is no longer decoded. \u003cem\u003eReported by \u003ca href=\"https://github.com/thesmartshadow\"\u003e\u003ccode\u003e@​thesmartshadow\u003c/code\u003e\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/security/advisories/GHSA-993g-76c3-p5m4\"\u003e\u003ccode\u003eGHSA-993g-76c3-p5m4\u003c/code\u003e\u003c/a\u003e — \u003ccode\u003ePyJWKClient\u003c/code\u003e accepts non-HTTP(S) URIs.\u003c/strong\u003e \u003ccode\u003ePyJWKClient.fetch_data\u003c/code\u003e passed its URI to \u003ccode\u003eurllib.request.urlopen\u003c/code\u003e, which by default also handles \u003ccode\u003efile://\u003c/code\u003e, \u003ccode\u003eftp://\u003c/code\u003e, and \u003ccode\u003edata:\u003c/code\u003e schemes. An application that fed an attacker-influenced URI into \u003ccode\u003ePyJWKClient\u003c/code\u003e could be coerced into reading local files or reaching other unintended schemes. \u003ccode\u003ePyJWKClient\u003c/code\u003e now rejects any URI whose scheme isn't \u003ccode\u003ehttp\u003c/code\u003e or \u003ccode\u003ehttps\u003c/code\u003e. \u003cem\u003eReported by \u003ca href=\"https://github.com/KEIJOT\"\u003e\u003ccode\u003e@​KEIJOT\u003c/code\u003e\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/security/advisories/GHSA-fhv5-28vv-h8m8\"\u003e\u003ccode\u003eGHSA-fhv5-28vv-h8m8\u003c/code\u003e\u003c/a\u003e — \u003ccode\u003ePyJWKClient\u003c/code\u003e cache wiped on fetch error.\u003c/strong\u003e A \u003ccode\u003efinally\u003c/code\u003e-block \u003ccode\u003eput(jwk_set=None)\u003c/code\u003e cleared the JWK Set cache whenever a fetch raised, turning a transient JWKS-endpoint outage into application-wide auth failure. The cache write was moved into the success path; transient errors no longer evict valid cached keys. \u003cem\u003eReported by \u003ca href=\"https://github.com/eddieran\"\u003e\u003ccode\u003e@​eddieran\u003c/code\u003e\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eFixed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eReject empty HMAC keys outright in \u003ccode\u003eHMACAlgorithm.prepare_key\u003c/code\u003e with \u003ccode\u003eInvalidKeyError\u003c/code\u003e instead of accepting them with only a warning. Defends against the \u003ccode\u003eos.getenv(\u0026quot;JWT_SECRET\u0026quot;, \u0026quot;\u0026quot;)\u003c/code\u003e footgun. \u003cem\u003eThanks to \u003ca href=\"https://github.com/SnailSploit\"\u003e\u003ccode\u003e@​SnailSploit\u003c/code\u003e\u003c/a\u003e and \u003ca href=\"https://github.com/spartan8806\"\u003e\u003ccode\u003e@​spartan8806\u003c/code\u003e\u003c/a\u003e for the reports.\u003c/em\u003e\u003c/li\u003e\n\u003cli\u003eForward per-call \u003ccode\u003eoptions\u003c/code\u003e (including \u003ccode\u003eenforce_minimum_key_length\u003c/code\u003e) from \u003ccode\u003ePyJWT.decode\u003c/code\u003e through to \u003ccode\u003ePyJWS._verify_signature\u003c/code\u003e. The option was previously silently dropped between the two layers, so it only took effect when set on the \u003ccode\u003ePyJWT\u003c/code\u003e instance. \u003cem\u003eThanks to \u003ca href=\"https://github.com/WLUB\"\u003e\u003ccode\u003e@​WLUB\u003c/code\u003e\u003c/a\u003e for the report.\u003c/em\u003e\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eRFC 7797 §3 compliance for \u003ccode\u003eb64=false\u003c/code\u003e:\u003c/strong\u003e the encoder now auto-adds \u003ccode\u003e\u0026quot;b64\u0026quot;\u003c/code\u003e to \u003ccode\u003ecrit\u003c/code\u003e, and the decoder rejects tokens that set \u003ccode\u003eb64=false\u003c/code\u003e without listing it in \u003ccode\u003ecrit\u003c/code\u003e. \u003cem\u003eThanks to \u003ca href=\"https://github.com/MachineLearning-Nerd\"\u003e\u003ccode\u003e@​MachineLearning-Nerd\u003c/code\u003e\u003c/a\u003e for the report.\u003c/em\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eChanged\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMigrate the \u003ccode\u003edev\u003c/code\u003e, \u003ccode\u003edocs\u003c/code\u003e, and \u003ccode\u003etests\u003c/code\u003e package extras to dependency groups, by \u003ca href=\"https://github.com/kurtmckee\"\u003e\u003ccode\u003e@​kurtmckee\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/jpadilla/pyjwt/pull/1152\"\u003e#1152\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eUpgrade notes\u003c/h2\u003e\n\u003cp\u003eMost fixes are invisible to correctly-configured callers. A few behavioral changes you may encounter:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eEmpty HMAC keys now raise.\u003c/strong\u003e If your app passed \u003ccode\u003e\u0026quot;\u0026quot;\u003c/code\u003e or \u003ccode\u003eb\u0026quot;\u0026quot;\u003c/code\u003e as a secret (often via a missing env var, e.g. \u003ccode\u003eos.getenv(\u0026quot;JWT_SECRET\u0026quot;, \u0026quot;\u0026quot;)\u003c/code\u003e), \u003ccode\u003eencode\u003c/code\u003e/\u003ccode\u003edecode\u003c/code\u003e will now raise \u003ccode\u003eInvalidKeyError\u003c/code\u003e. This is the intended behavior — fix the configuration.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ccode\u003ePyJWK\u003c/code\u003e decoding now requires the token's \u003ccode\u003ealg\u003c/code\u003e to match the JWK's algorithm.\u003c/strong\u003e Previously a mismatch was silently honored if the header \u003ccode\u003ealg\u003c/code\u003e appeared in the allow-list. Tokens that relied on this mismatch will now fail with \u003ccode\u003eInvalidAlgorithmError\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ccode\u003ePyJWKClient\u003c/code\u003e now rejects non-HTTP(S) URIs at construction time.\u003c/strong\u003e Tests or dev environments that fetched JWKS from \u003ccode\u003efile://\u003c/code\u003e URIs need to switch to a local HTTP server or load the JWKS by other means (e.g. construct \u003ccode\u003ePyJWKSet.from_dict(...)\u003c/code\u003e directly).\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ccode\u003eb64=false\u003c/code\u003e tokens are now strictly RFC 7515 / 7797 compliant.\u003c/strong\u003e Tokens with a non-empty compact-form payload segment, or that omit \u003ccode\u003e\u0026quot;b64\u0026quot;\u003c/code\u003e from \u003ccode\u003ecrit\u003c/code\u003e, will be rejected. PyJWT-produced tokens always satisfy both invariants, so round-trips through PyJWT are unaffected.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ccode\u003eenforce_minimum_key_length\u003c/code\u003e set per-call now takes effect.\u003c/strong\u003e Callers who passed \u003ccode\u003eoptions={\u0026quot;enforce_minimum_key_length\u0026quot;: True}\u003c/code\u003e to \u003ccode\u003ejwt.decode()\u003c/code\u003e previously got no enforcement; they will now get \u003ccode\u003eInvalidKeyError\u003c/code\u003e on undersized keys, as documented.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull changelog:\u003c/strong\u003e \u003ca href=\"https://github.com/jpadilla/pyjwt/compare/2.12.1...2.13.0\"\u003ehttps://github.com/jpadilla/pyjwt/compare/2.12.1...2.13.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/jpadilla/pyjwt/blob/master/CHANGELOG.rst\"\u003epyjwt's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ccode\u003ev2.13.0 \u0026lt;https://github.com/jpadilla/pyjwt/compare/2.12.1...2.13.0\u0026gt;\u003c/code\u003e__\u003c/h2\u003e\n\u003cp\u003eSecurity\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003e\n- Reject JWK JSON documents passed as raw HMAC secrets in\n  ``HMACAlgorithm.prepare_key`` to close an algorithm-confusion gap that\n  the existing PEM/SSH guard did not cover. Reported by @aradona91 in\n  `GHSA-xgmm-8j9v-c9wx \u0026lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-xgmm-8j9v-c9wx\u0026gt;`__.\n- Bind the JWT header ``alg`` to ``PyJWK.algorithm_name`` during\n  verification so the caller's ``algorithms=[...]`` allow-list cannot be\n  bypassed when decoding with a ``PyJWK`` / ``PyJWKClient`` key. Reported\n  by @sushi-gif in `GHSA-jq35-7prp-9v3f \u0026lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-jq35-7prp-9v3f\u0026gt;`__.\n- Reject non-``http(s)`` URI schemes in ``PyJWKClient`` so attacker-\n  influenced URIs cannot read local files or reach unintended schemes via\n  urllib's default ``file://`` / ``ftp://`` / ``data:`` handlers. Reported\n  by @KEIJOT in `GHSA-993g-76c3-p5m4 \u0026lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-993g-76c3-p5m4\u0026gt;`__.\n- Preserve the cached JWK Set on fetch errors in ``PyJWKClient.fetch_data``.\n  The previous ``finally``-block ``put(None)`` pattern cleared the cache\n  on any transient outage, turning one bad JWKS request into application-\n  wide auth failure. Reported by @eddieran in `GHSA-fhv5-28vv-h8m8 \u0026lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-fhv5-28vv-h8m8\u0026gt;`__.\n- Skip the unconditional base64 decode of the compact-form payload segment\n  when ``b64=false`` is set in the protected header, and require that\n  segment to be empty (RFC 7515 Appendix F detached form). Closes an\n  unauthenticated DoS amplifier. Reported by @thesmartshadow in\n  `GHSA-w7vc-732c-9m39 \u0026lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-w7vc-732c-9m39\u0026gt;`__.\n\u003cp\u003eFixed\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003e\n- Reject empty HMAC keys outright in ``HMACAlgorithm.prepare_key`` with\n  ``InvalidKeyError`` instead of accepting them with only a warning.\n  Thanks to @SnailSploit and @spartan8806 for independently flagging the\n  footgun.\n- Forward per-call ``options`` (including ``enforce_minimum_key_length``)\n  from ``PyJWT.decode`` through to ``PyJWS._verify_signature`` so the\n  option actually takes effect when set at the call site rather than only\n  on the ``PyJWT`` instance. Thanks to @WLUB for the report.\n- RFC 7797 §3 compliance for ``b64=false``: the encoder now auto-adds\n  ``\u0026amp;quot;b64\u0026amp;quot;`` to the ``crit`` header parameter, and the decoder rejects\n  tokens that set ``b64=false`` without listing it in ``crit``. Thanks to\n  @MachineLearning-Nerd for the report.\n\nChanged\n\u003c/code\u003e\u003c/pre\u003e\n\u003cul\u003e\n\u003cli\u003eMigrate the \u003ccode\u003edev\u003c/code\u003e, \u003ccode\u003edocs\u003c/code\u003e, and \u003ccode\u003etests\u003c/code\u003e package extras to dependency groups by \u003ca href=\"https://github.com/kurtmckee\"\u003e\u003ccode\u003e@​kurtmckee\u003c/code\u003e\u003c/a\u003e in \u003ccode\u003e[#1152](https://github.com/jpadilla/pyjwt/issues/1152) \u0026amp;lt;https://github.com/jpadilla/pyjwt/pull/1152\u0026amp;gt;\u003c/code\u003e__\n\u003c/code\u003e\u003c/pre\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/7144e4534c34810f4525dc4578a32addd8212cff\"\u003e\u003ccode\u003e7144e45\u003c/code\u003e\u003c/a\u003e Apply ruff format\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/d2f4bec4963897c0ef96ef64a875894f2c8542ab\"\u003e\u003ccode\u003ed2f4bec\u003c/code\u003e\u003c/a\u003e Restore \u003ccode\u003ecast()\u003c/code\u003e calls with cross-version \u003ccode\u003etype: ignore\u003c/code\u003e for \u003ccode\u003eprepare_key\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/22f478cebddd8294259c30f037ecb92b0b348774\"\u003e\u003ccode\u003e22f478c\u003c/code\u003e\u003c/a\u003e Remove redundant casts in \u003ccode\u003eRSAAlgorithm.prepare_key\u003c/code\u003e and `ECAlgorithm.prepare...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/95791b1759b8aa4f2203575d344d5c78564cdc81\"\u003e\u003ccode\u003e95791b1\u003c/code\u003e\u003c/a\u003e Bundle security fixes and hardening into 2.13.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/dcc27a9d3182a2349c30b160758785c6ce7a6508\"\u003e\u003ccode\u003edcc27a9\u003c/code\u003e\u003c/a\u003e [pre-commit.ci] pre-commit autoupdate (\u003ca href=\"https://redirect.github.com/jpadilla/pyjwt/issues/1155\"\u003e#1155\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/9d08a9a1896845ed8eaf88e6f6ac61e5800c3e7a\"\u003e\u003ccode\u003e9d08a9a\u003c/code\u003e\u003c/a\u003e [pre-commit.ci] pre-commit autoupdate (\u003ca href=\"https://redirect.github.com/jpadilla/pyjwt/issues/1146\"\u003e#1146\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/b87c10014d4109f0214fea188d00faaaf8a80e64\"\u003e\u003ccode\u003eb87c100\u003c/code\u003e\u003c/a\u003e Bump codecov/codecov-action from 5 to 6 (\u003ca href=\"https://redirect.github.com/jpadilla/pyjwt/issues/1154\"\u003e#1154\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/40e3147eb5f790d8d041772e5fc00728a176c812\"\u003e\u003ccode\u003e40e3147\u003c/code\u003e\u003c/a\u003e Migrate development extras to dependency groups (\u003ca href=\"https://redirect.github.com/jpadilla/pyjwt/issues/1152\"\u003e#1152\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/jpadilla/pyjwt/compare/2.12.1...2.13.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `mcp` from 1.26.0 to 1.28.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/modelcontextprotocol/python-sdk/releases\"\u003emcp's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.28.1\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e[v1.x] Buffer per-request StreamableHTTP streams; store priming event before dispatch by \u003ca href=\"https://github.com/maxisbey\"\u003e\u003ccode\u003e@​maxisbey\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/modelcontextprotocol/python-sdk/pull/2948\"\u003emodelcontextprotocol/python-sdk#2948\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[v1.x] Set Development Status classifier to Production/Stable by \u003ca href=\"https://github.com/maxisbey\"\u003e\u003ccode\u003e@​maxisbey\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/modelcontextprotocol/python-sdk/pull/2976\"\u003emodelcontextprotocol/python-sdk#2976\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[v1.x] Support TransportSecuritySettings in the WebSocket server transport by \u003ca href=\"https://github.com/maxisbey\"\u003e\u003ccode\u003e@​maxisbey\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/modelcontextprotocol/python-sdk/pull/2992\"\u003emodelcontextprotocol/python-sdk#2992\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/modelcontextprotocol/python-sdk/compare/v1.28.0...v1.28.1\"\u003ehttps://github.com/modelcontextprotocol/python-sdk/compare/v1.28.0...v1.28.1\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.28.0\u003c/h2\u003e\n\u003ch2\u003eDeprecations\u003c/h2\u003e\n\u003cp\u003eTwo API surfaces now emit \u003ccode\u003eDeprecationWarning\u003c/code\u003e ahead of their removal in v2. Nothing is removed in 1.x, and the warnings fire only when the deprecated API is \u003cem\u003ecalled\u003c/em\u003e - importing the modules stays silent.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eWebSocket transport\u003c/strong\u003e - \u003ccode\u003emcp.client.websocket.websocket_client\u003c/code\u003e and \u003ccode\u003emcp.server.websocket.websocket_server\u003c/code\u003e\u003ccode\u003emodelcontextprotocol/typescript-sdk#1783\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eExperimental tasks API\u003c/strong\u003e - \u003ccode\u003eClientSession.experimental\u003c/code\u003e, \u003ccode\u003eServer.experimental\u003c/code\u003e, \u003ccode\u003eServerSession.experimental\u003c/code\u003e, and the \u003ccode\u003eexperimental_task_handlers=\u003c/code\u003e kwarg on \u003ccode\u003eClientSession\u003c/code\u003e. Tasks (SEP-1686) were removed from the MCP specification and are expected to return as a separate MCP extension.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eIf your test suite runs with \u003ccode\u003efilterwarnings = [\u0026quot;error\u0026quot;]\u003c/code\u003e and exercises these paths, add a scoped ignore such as \u003ccode\u003eignore:The experimental tasks API is deprecated:DeprecationWarning\u003c/code\u003e or \u003ccode\u003eignore:The WebSocket .* transport is deprecated:DeprecationWarning\u003c/code\u003e.\u003c/p\u003e\n\u003cp\u003eSee \u003ca href=\"https://redirect.github.com/modelcontextprotocol/python-sdk/issues/2828\"\u003e#2828\u003c/a\u003e for full details.\u003c/p\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e[v1.x] Support Python 3.14 by \u003ca href=\"https://github.com/maxisbey\"\u003e\u003ccode\u003e@​maxisbey\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/modelcontextprotocol/python-sdk/pull/2769\"\u003emodelcontextprotocol/python-sdk#2769\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: omit null optional fields from task result payloads by \u003ca href=\"https://github.com/liuzemei\"\u003e\u003ccode\u003e@​liuzemei\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/modelcontextprotocol/python-sdk/pull/2809\"\u003emodelcontextprotocol/python-sdk#2809\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[v1.x] Deprecate the WebSocket transport and the experimental tasks entry points by \u003ca href=\"https://github.com/maxisbey\"\u003e\u003ccode\u003e@​maxisbey\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/modelcontextprotocol/python-sdk/pull/2828\"\u003emodelcontextprotocol/python-sdk#2828\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[v1.x] Add a v2 status banner to the README by \u003ca href=\"https://github.com/maxisbey\"\u003e\u003ccode\u003e@​maxisbey\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/modelcontextprotocol/python-sdk/pull/2835\"\u003emodelcontextprotocol/python-sdk#2835\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[v1.x] Deflake the child process cleanup tests by \u003ca href=\"https://github.com/maxisbey\"\u003e\u003ccode\u003e@​maxisbey\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/modelcontextprotocol/python-sdk/pull/2839\"\u003emodelcontextprotocol/python-sdk#2839\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/liuzemei\"\u003e\u003ccode\u003e@​liuzemei\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/modelcontextprotocol/python-sdk/pull/2809\"\u003emodelcontextprotocol/python-sdk#2809\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/modelcontextprotocol/python-sdk/compare/v1.27.2...v1.28.0\"\u003ehttps://github.com/modelcontextprotocol/python-sdk/compare/v1.27.2...v1.28.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.27.2\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e[v1.x] ci: deploy docs to py.sdk.modelcontextprotocol.io via Pages artifact by \u003ca href=\"https://github.com/maxisbey\"\u003e\u003ccode\u003e@​maxisbey\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/modelcontextprotocol/python-sdk/pull/2635\"\u003emodelcontextprotocol/python-sdk#2635\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[v1.x] Add subject and claims to AccessToken by \u003ca href=\"https://github.com/maxisbey\"\u003e\u003ccode\u003e@​maxisbey\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/modelcontextprotocol/python-sdk/pull/2690\"\u003emodelcontextprotocol/python-sdk#2690\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[v1.x] Bind transport sessions to the authenticated principal by \u003ca href=\"https://github.com/maxisbey\"\u003e\u003ccode\u003e@​maxisbey\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/modelcontextprotocol/python-sdk/pull/2719\"\u003emodelcontextprotocol/python-sdk#2719\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[v1.x] Scope experimental tasks to the session that created them by \u003ca href=\"https://github.com/maxisbey\"\u003e\u003ccode\u003e@​maxisbey\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/modelcontextprotocol/python-sdk/pull/2720\"\u003emodelcontextprotocol/python-sdk#2720\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/modelcontextprotocol/python-sdk/compare/v1.27.1...v1.27.2\"\u003ehttps://github.com/modelcontextprotocol/python-sdk/compare/v1.27.1...v1.27.2\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.27.1\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e[v1.x] fix: catch PydanticUserError when generating output schema (pydantic 2.13 compat) by \u003ca href=\"https://github.com/maxisbey\"\u003e\u003ccode\u003e@​maxisbey\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/modelcontextprotocol/python-sdk/pull/2435\"\u003emodelcontextprotocol/python-sdk#2435\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[v1.x] fix(auth): coerce empty-string optional URL fields to None in OAuthClientMetadata by \u003ca href=\"https://github.com/felixweinberger\"\u003e\u003ccode\u003e@​felixweinberger\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/modelcontextprotocol/python-sdk/pull/2405\"\u003emodelcontextprotocol/python-sdk#2405\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[v1.x] build: restrict httpx to \u0026lt;1.0.0 by \u003ca href=\"https://github.com/maxisbey\"\u003e\u003ccode\u003e@​maxisbey\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/modelcontextprotocol/python-sdk/pull/2559\"\u003emodelcontextprotocol/python-sdk#2559\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/modelcontextprotocol/python-sdk/commit/777b8d06710c140e3606b0d4598e2aa48546c266\"\u003e\u003ccode\u003e777b8d0\u003c/code\u003e\u003c/a\u003e [v1.x] Support TransportSecuritySettings in the WebSocket server transport (#...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/modelcontextprotocol/python-sdk/commit/47204674fb26185c2cf45f065831f27b8e5d5c65\"\u003e\u003ccode\u003e4720467\u003c/code\u003e\u003c/a\u003e [v1.x] Set Development Status classifier to Production/Stable (\u003ca href=\"https://redirect.github.com/modelcontextprotocol/python-sdk/issues/2976\"\u003e#2976\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/modelcontextprotocol/python-sdk/commit/6df3d734265eb49bf758a5e5eb420937337184e9\"\u003e\u003ccode\u003e6df3d73\u003c/code\u003e\u003c/a\u003e [v1.x] Buffer per-request StreamableHTTP streams; store priming event before ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/modelcontextprotocol/python-sdk/commit/32d32908feb7b15eddeb46872774bf95869cc5f0\"\u003e\u003ccode\u003e32d3290\u003c/code\u003e\u003c/a\u003e [v1.x] Pass a list to parametrize in test_docs_examples (pytest 9.1.0 compat)...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/modelcontextprotocol/python-sdk/commit/0dca751056dc87d04893d53af129fd00b56a18da\"\u003e\u003ccode\u003e0dca751\u003c/code\u003e\u003c/a\u003e [v1.x] Deflake the child process cleanup tests (\u003ca href=\"https://redirect.github.com/modelcontextprotocol/python-sdk/issues/2839\"\u003e#2839\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/modelcontextprotocol/python-sdk/commit/52258a95645c66fccbe925289c3382712b9bc68a\"\u003e\u003ccode\u003e52258a9\u003c/code\u003e\u003c/a\u003e [v1.x] Add a v2 status banner to the README (\u003ca href=\"https://redirect.github.com/modelcontextprotocol/python-sdk/issues/2835\"\u003e#2835\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/modelcontextprotocol/python-sdk/commit/b8f491724c45dbf89d6569364b58d6e8d25d7e42\"\u003e\u003ccode\u003eb8f4917\u003c/code\u003e\u003c/a\u003e [v1.x] Deprecate the WebSocket transport and the experimental tasks entry poi...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/modelcontextprotocol/python-sdk/commit/2309e5ef974062748e0268c396eba73cfdb6f5e3\"\u003e\u003ccode\u003e2309e5e\u003c/code\u003e\u003c/a\u003e fix: omit null optional fields from task result payloads (\u003ca href=\"https://redirect.github.com/modelcontextprotocol/python-sdk/issues/2809\"\u003e#2809\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/modelcontextprotocol/python-sdk/commit/494eb11d36b4238226cc0551da6015e1c73f7f3b\"\u003e\u003ccode\u003e494eb11\u003c/code\u003e\u003c/a\u003e [v1.x] Support Python 3.14 (\u003ca href=\"https://redirect.github.com/modelcontextprotocol/python-sdk/issues/2769\"\u003e#2769\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/modelcontextprotocol/python-sdk/commit/62137874ff26dd74d2fea80ff528a7fd9ca7a5e7\"\u003e\u003ccode\u003e6213787\u003c/code\u003e\u003c/a\u003e [v1.x] Scope experimental tasks to the session that created them (\u003ca href=\"https://redirect.github.com/modelcontextprotocol/python-sdk/issues/2720\"\u003e#2720\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/modelcontextprotocol/python-sdk/compare/v1.26.0...v1.28.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `aiohttp` from 3.10.10 to 3.14.3\nUpdates `anyio` from 4.13.0 to 4.14.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/agronholm/anyio/releases\"\u003eanyio's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e4.14.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eChanged \u003ccode\u003eByteReceiveStream.receive()\u003c/code\u003e implementations to raise a \u003ccode\u003eValueError\u003c/code\u003e when \u003ccode\u003emax_bytes\u003c/code\u003e is not a positive integer (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1191\"\u003e#1191\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eCapacityLimiter.total_tokens\u003c/code\u003e rejecting \u003ccode\u003efloat(\u0026quot;inf\u0026quot;)\u003c/code\u003e when the limiter was instantiated outside of an event loop. The adapter setter checked for infinity by identity (\u003ccode\u003evalue is math.inf\u003c/code\u003e), so only the exact \u003ccode\u003emath.inf\u003c/code\u003e singleton was accepted, while every backend setter (using \u003ccode\u003emath.isinf()\u003c/code\u003e) accepts any positive infinity (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1189\"\u003e#1189\u003c/a\u003e; PR by \u003ca href=\"https://github.com/greymoth-jp\"\u003e\u003ccode\u003e@​greymoth-jp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eto_process.run_sync()\u003c/code\u003e deadlocking when the worker function writes enough data to \u003ccode\u003esys.stderr\u003c/code\u003e to fill the (undrained) pipe buffer. The worker process now redirects \u003ccode\u003esys.stderr\u003c/code\u003e to \u003ccode\u003eos.devnull\u003c/code\u003e as well, matching the documented behavior\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eTLSStream.wrap()\u003c/code\u003e matching an internationalized (unicode) host name against the peer certificate using IDNA 2003 (via the standard library) instead of IDNA 2008, which could cause the host name to be matched against the wrong certificate (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1208\"\u003e#1208\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eanyio.open_process()\u003c/code\u003e (and \u003ccode\u003erun_process()\u003c/code\u003e) ignoring the \u003ccode\u003eextra_groups\u003c/code\u003e argument, as it mistakenly passed the value of the \u003ccode\u003egroup\u003c/code\u003e argument instead (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1209\"\u003e#1209\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eCapacityLimiter.acquire_nowait()\u003c/code\u003e and \u003ccode\u003eCapacityLimiter.acquire_nowait_on_behalf_of()\u003c/code\u003e raising \u003ccode\u003etrio.WouldBlock\u003c/code\u003e instead of \u003ccode\u003eanyio.WouldBlock\u003c/code\u003e on the \u003ccode\u003etrio\u003c/code\u003e backend when there are no tokens available (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1218\"\u003e#1218\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eCapacityLimiter\u003c/code\u003e on the asyncio backend over-granting tokens (\u003ccode\u003eborrowed_tokens\u003c/code\u003e exceeding \u003ccode\u003etotal_tokens\u003c/code\u003e and \u003ccode\u003eavailable_tokens\u003c/code\u003e going negative) when a non-blocking acquire was made in the window between a token being released and the notified waiter resuming. The freed token is now reserved for the woken waiter right away, so the non-blocking acquire correctly raises \u003ccode\u003eWouldBlock\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1170\"\u003e#1170\u003c/a\u003e; PR by \u003ca href=\"https://github.com/gaoflow\"\u003e\u003ccode\u003e@​gaoflow\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed unnecessary CPU spin when delivering cancellation from \u003ccode\u003eCancelScope\u003c/code\u003e on asyncio under certain conditions, including improper cancel scope nesting (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1111\"\u003e#1111\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.14.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed teardown of higher-scoped async fixtures failing on asyncio with \u003ccode\u003eRuntimeError: Attempted to exit cancel scope in a different task than it was entered in\u003c/code\u003e when an async test raise an outcome exception (e.g., \u003ccode\u003epytest.skip()\u003c/code\u003e, \u003ccode\u003epytest.xfail()\u003c/code\u003e, or \u003ccode\u003epytest.fail()\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1179\"\u003e#1179\u003c/a\u003e; PR by \u003ca href=\"https://github.com/EmmanuelNiyonshuti\"\u003e\u003ccode\u003e@​EmmanuelNiyonshuti\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eCapacityLimiter.total_tokens\u003c/code\u003e rejecting a value of \u003ccode\u003e0\u003c/code\u003e when the limiter was instantiated outside of an event loop, contradicting the documented behavior of allowing 0 total tokens (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1183\"\u003e#1183\u003c/a\u003e; PR by \u003ca href=\"https://github.com/nyxst4ck\"\u003e\u003ccode\u003e@​nyxst4ck\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.14.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eAdded support for Python 3.15\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAdded an asynchronous implementation of the \u003ccode\u003eitertools\u003c/code\u003e module (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/998\"\u003e#998\u003c/a\u003e; PR by \u003ca href=\"https://github.com/11kkw\"\u003e\u003ccode\u003e@​11kkw\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAdded the \u003ccode\u003elocal_port\u003c/code\u003e parameter to \u003ccode\u003econnect_tcp()\u003c/code\u003e to allow binding to a specific local port before connecting (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1067\"\u003e#1067\u003c/a\u003e; PR by \u003ca href=\"https://github.com/nullwiz\"\u003e\u003ccode\u003e@​nullwiz\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAdded support for custom capacity limiters in async path and file I/O functions and classes\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAdded the \u003ccode\u003ecreate_task()\u003c/code\u003e task group method for easier asyncio migration (returns a \u003ccode\u003eTaskHandle\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1098\"\u003e#1098\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eChanged \u003ccode\u003eTaskGroup.start_soon()\u003c/code\u003e to return a \u003ccode\u003eTaskHandle\u003c/code\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAdded an option for \u003ccode\u003eTaskGroup.start()\u003c/code\u003e to return a \u003ccode\u003eTaskHandle\u003c/code\u003e (which then contains the start value in the \u003ccode\u003estart_value\u003c/code\u003e property)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAdded the \u003ccode\u003ecancel()\u003c/code\u003e convenience method to \u003ccode\u003eTaskGroup\u003c/code\u003e as a shortcut for cancelling the task group's cancel scope\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eImproved the error message when a known backend is not installed to suggest the install command (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1115\"\u003e#1115\u003c/a\u003e; PR by \u003ca href=\"https://github.com/EmmanuelNiyonshuti\"\u003e\u003ccode\u003e@​EmmanuelNiyonshuti\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eImproved \u003ccode\u003eanyio.Path\u003c/code\u003e to preserve subclass types by returning \u003ccode\u003eSelf\u003c/code\u003e in methods that return path objects (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1130\"\u003e#1130\u003c/a\u003e; PR by \u003ca href=\"https://github.com/EmmanuelNiyonshuti\"\u003e\u003ccode\u003e@​EmmanuelNiyonshuti\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eChanged the parameter type annotation in \u003ccode\u003eanyio.Path.write_bytes()\u003c/code\u003e to accept any \u003ccode\u003eReadableBuffer\u003c/code\u003e, thus allowing it to accept \u003ccode\u003ebytearray\u003c/code\u003e and \u003ccode\u003ememoryview\u003c/code\u003e to match \u003ccode\u003epathlib.Path.write_bytes()\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1135\"\u003e#1135\u003c/a\u003e; PR by \u003ca href=\"https://github.com/SAY-5\"\u003e\u003ccode\u003e@​SAY-5\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eChanged several type annotations to only accept callables returning coroutine-like objects instead of arbitrary awaitables:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eTaskGroup.start_soon()\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eTaskGroup.start()\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eanyio.from_thread.run()\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThis reverts an earlier change from v3.7.0 which was made in error. (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1153\"\u003e#1153\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eChanged \u003ccode\u003eanyio.run\u003c/code\u003e to support callables returning arbitrary awaitables at runtime on all backends. Previously, this only worked on asyncio (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1171\"\u003e#1171\u003c/a\u003e; PR by \u003ca href=\"https://github.com/gschaffner\"\u003e\u003ccode\u003e@​gschaffner\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eChanged several classes (and their subclasses) to have \u003ccode\u003e__slots__\u003c/code\u003e (with \u003ccode\u003e__weakref__\u003c/code\u003e):\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eanyio.CancelScope\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/c384f99687c64c59ed8a11c3a0f11a2d57daff71\"\u003e\u003ccode\u003ec384f99\u003c/code\u003e\u003c/a\u003e Bumped up the version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/dbba29d1ade7936f18fb71ba24aa92978673482a\"\u003e\u003ccode\u003edbba29d\u003c/code\u003e\u003c/a\u003e Fixed 100% CPU spin on cancel scope misuse (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1217\"\u003e#1217\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/6bbc6c33caabc13af5bc4256f745027cf8d5d7b8\"\u003e\u003ccode\u003e6bbc6c3\u003c/code\u003e\u003c/a\u003e Fix CapacityLimiter over-granting tokens on asyncio (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1172\"\u003e#1172\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/6f82b2537cbbe98f3df3f295499056ab7de0b15b\"\u003e\u003ccode\u003e6f82b25\u003c/code\u003e\u003c/a\u003e Refactored TestTLSStream.test_receive_invalid_max_bytes() to be less flaky\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/be24b0414f67f604bcbdd5ea3bcc56ab920d872e\"\u003e\u003ccode\u003ebe24b04\u003c/code\u003e\u003c/a\u003e Relaxed timeouts to fix test flakiness\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/81135065749b4f60c06619b9caaf0a11871c1ddf\"\u003e\u003ccode\u003e8113506\u003c/code\u003e\u003c/a\u003e Fix test flakiness caused by slow callback duration logging\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/1e988b617b69588e33fecb75e36a9837245f562f\"\u003e\u003ccode\u003e1e988b6\u003c/code\u003e\u003c/a\u003e Fixed CapacityLimiter raising trio.WouldBlock instead of anyio.WouldBlock (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1\"\u003e#1\u003c/a\u003e...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/44713f345cd29dd4e7d76553c134543a1296cc62\"\u003e\u003ccode\u003e44713f3\u003c/code\u003e\u003c/a\u003e Pin setup-uv to a commit sha across downstream jobs (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1213\"\u003e#1213\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/f1b7301c8264b0d2e8d24a5788fd29e93dea4040\"\u003e\u003ccode\u003ef1b7301\u003c/code\u003e\u003c/a\u003e Fixed stderr writes in a worker subprocess causing a deadlock (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1207\"\u003e#1207\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/212be93c2cf2c841e753e95e5e2c543ee7feca90\"\u003e\u003ccode\u003e212be93\u003c/code\u003e\u003c/a\u003e Fix flaky test_tcp_listener_same_port using a hardcoded port (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1206\"\u003e#1206\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/agronholm/anyio/compare/4.13.0...4.14.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `idna` from 3.11 to 3.15\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/kjd/idna/blob/master/HISTORY.md\"\u003eidna's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e3.15 (2026-05-12)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eEnforce DNS-length cap on individual labels early in \u003ccode\u003echeck_label\u003c/code\u003e,\nshort-circuiting contextual-rule processing for oversized input\nwhile staying compatible with UTS 46 usage.\u003c/li\u003e\n\u003cli\u003eTidy core helpers: hoist bidi category sets to module-level\nfrozensets (avoiding per-codepoint list construction), simplify\nlength checks, and reuse the shared \u003ccode\u003e_unicode_dots_re\u003c/code\u003e from\n\u003ccode\u003eidna.core\u003c/code\u003e in the codec module.\u003c/li\u003e\n\u003cli\u003eUse \u003ccode\u003eraise ... from err\u003c/code\u003e for proper exception chaining and\nswitch internal string formatting to f-strings.\u003c/li\u003e\n\u003cli\u003eAllow \u003ccode\u003eflit_core\u003c/code\u003e 4.x in the build backend.\u003c/li\u003e\n\u003cli\u003eExpand the ruff lint set (flake8-bugbear, flake8-simplify,\npyupgrade, perflint) and apply the surfaced fixes; pin lint CI\nto Python 3.14.\u003c/li\u003e\n\u003cli\u003eAdd Dependabot configuration for GitHub Actions.\u003c/li\u003e\n\u003cli\u003eConvert README and HISTORY from reStructuredText to Markdown.\u003c/li\u003e\n\u003cli\u003eReference CVE-2026-45409 for the 3.14 advisory in place of the\ninitial GHSA identifier.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThanks to Felix Yan, Stan Ulbrych, and metsw24-max for\ncontributions to this release.\u003c/p\u003e\n\u003ch2\u003e3.14 (2026-05-10)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRemoved opportunity to process long inputs into quadratic\ntime by rejecting oversize inputs up-front. Closes a bypass\nof the CVE-2024-3651 mitigation. [CVE-2026-45409]\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThanks to Stan Ulbrych for reporting the issue.\u003c/p\u003e\n\u003ch2\u003e3.13 (2026-04-22)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eCorrect classification error for codepoint U+A7F1\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.12 (2026-04-21)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate to Unicode 17.0.0.\u003c/li\u003e\n\u003cli\u003eIssue a deprecation warning for the transitional argument.\u003c/li\u003e\n\u003cli\u003eAdded lazy-loading to provide some performance improvements.\u003c/li\u003e\n\u003cli\u003eRemoved vestiges of code related to Python 2 support, including\nsegmentation of data structures specific to Jython.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThanks to Rodrigo Nogueira for contributions to this release.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kjd/idna/commit/af30a092e158181d0b35ac66dfa813788126bdd8\"\u003e\u003ccode\u003eaf30a09\u003c/code\u003e\u003c/a\u003e Release 3.15\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kjd/idna/commit/30314d4628744ca14cf2b5820564e5127a9f86f2\"\u003e\u003ccode\u003e30314d4\u003c/code\u003e\u003c/a\u003e Pre-release 3.15rc0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kjd/idna/commit/05d4b219aa9eddc47371fcbd2000f0301016f3e9\"\u003e\u003ccode\u003e05d4b21\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/kjd/idna/issues/237\"\u003e#237\u003c/a\u003e from kjd/convert-docs-to-markdown\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kjd/idna/commit/2987fdba1962bbb2358399e0084ba062b98a0bee\"\u003e\u003ccode\u003e2987fdb\u003c/code\u003e\u003c/a\u003e Convert README and HISTORY from reStructuredText to Markdown\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kjd/idna/commit/59fa8002d514bf4a5ce7b58f67b9ec587d53fa9c\"\u003e\u003ccode\u003e59fa800\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/kjd/idna/issues/236\"\u003e#236\u003c/a\u003e from kjd/dependabot/github_actions/actions-f3e34333ea\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kjd/idna/commit/def69834ced5d4b3c50439d8b99c4c856ec19ca2\"\u003e\u003ccode\u003edef6983\u003c/code\u003e\u003c/a\u003e Merge branch 'master' into dependabot/github_actions/actions-f3e34333ea\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kjd/idna/commit/bbd8004a797185d8c56bb555cd5c88fde05e0631\"\u003e\u003ccode\u003ebbd8004\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/kjd/idna/issues/234\"\u003e#234\u003c/a\u003e from StanFromIreland/patch-1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kjd/idna/commit/edd07c05024344a6ccb517414ccb36683aee99fc\"\u003e\u003ccode\u003eedd07c0\u003c/code\u003e\u003c/a\u003e Bump github/codeql-action from 3.35.2 to 4.35.2 in the actions group\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kjd/idna/commit/5557db030c11bdec50d62aa5f631d705d33ba123\"\u003e\u003ccode\u003e5557db0\u003c/code\u003e\u003c/a\u003e Merge branch 'master' into patch-1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kjd/idna/commit/f11746cf4981d25123ef7830d3ee60f07de8ae3d\"\u003e\u003ccode\u003ef11746c\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/kjd/idna/issues/235\"\u003e#235\u003c/a\u003e from StanFromIreland/patch-2\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/kjd/idna/compare/v3.11...v3.15\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `urllib3` from 2.6.3 to 2.7.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/urllib3/urllib3/releases\"\u003eurllib3's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e2.7.0\u003c/h2\u003e\n\u003ch2\u003e🚀 urllib3 is fundraising for HTTP/2 support\u003c/h2\u003e\n\u003cp\u003e\u003ca href=\"https://sethmlarson.dev/urllib3-is-fundraising-for-http2-support\"\u003eurllib3 is raising ~$40,000 USD\u003c/a\u003e to release HTTP/2 support and ensure long-term sustainable maintenance of the project after a sharp decline in financial support. If your company or organization uses Python and would benefit from HTTP/2 support in Requests, pip, cloud SDKs, and thousands of other projects \u003ca href=\"https://opencollective.com/urllib3\"\u003eplease consider contributing financially\u003c/a\u003e to ensure HTTP/2 support is developed sustainably and maintained for the long-haul.\u003c/p\u003e\n\u003cp\u003eThank you for your support.\u003c/p\u003e\n\u003ch2\u003eSecurity\u003c/h2\u003e\n\u003cp\u003eAddressed high-severity security issues. Impact was limited to specific use cases detailed in the accompanying advisories; overall user exposure was estimated to be marginal.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eDecompression-bomb safeguards of the streaming API were bypassed:\u003c/p\u003e\n\u003col\u003e\n\u003cli\u003eWhen \u003ccode\u003eHTTPResponse.drain_conn()\u003c/code\u003e was called after the response had been read and decompressed partially. (Reported by \u003ca href=\"https://github.com/Cycloctane\"\u003e\u003ccode\u003e@​Cycloctane\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eDuring the second \u003ccode\u003eHTTPResponse.read(amt=N)\u003c/code\u003e or \u003ccode\u003eHTTPResponse.stream(amt=N)\u003c/code\u003e call when the response was decompressed using the official \u003ca href=\"https://pypi.org/project/brotli/\"\u003eBrotli\u003c/a\u003e library. (Reported by \u003ca href=\"https://github.com/kimkou2024\"\u003e\u003ccode\u003e@​kimkou2024\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ol\u003e\n\u003cp\u003eSee GHSA-mf9v-mfxr-j63j for details.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eHTTP pools created using \u003ccode\u003eProxyManager.connection_from_url\u003c/code\u003e did not strip sensitive headers specified in \u003ccode\u003eRetry.remove_headers_on_redirect\u003c/code\u003e when redirecting to a different host. (GHSA-qccp-gfcp-xxvc reported by \u003ca href=\"https://github.com/christos-spearbit\"\u003e\u003ccode\u003e@​christos-spearbit\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eDeprecations and Removals\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUsed \u003ccode\u003eFutureWarning\u003c/code\u003e instead of \u003ccode\u003eDeprecationWarning\u003c/code\u003e for better visibility of existing deprecation notices. Rescheduled the removal of deprecated features to version 3.0. (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/3763\"\u003eurllib3/urllib3#3763\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRemoved support for end-of-life Python 3.9. (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/3720\"\u003eurllib3/urllib3#3720\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRemoved support for end-of-life PyPy3.10. (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/4979\"\u003eurllib3/urllib3#4979\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eBumped the minimum supported pyOpenSSL version to 19.0.0. (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/3777\"\u003eurllib3/urllib3#3777\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eBugfixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed a bug where \u003ccode\u003eHTTPResponse.read(amt=None)\u003c/code\u003e was ignoring decompressed data buffered from previous partial reads. (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/3636\"\u003eurllib3/urllib3#3636\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed a bug where \u003ccode\u003eHTTPResponse.read()\u003c/code\u003e could cache only part of the response after a partial read when \u003ccode\u003ecache_content=True\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/4967\"\u003eurllib3/urllib3#4967\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eHTTPResponse.stream()\u003c/code\u003e and \u003ccode\u003eHTTPResponse.read_chunked()\u003c/code\u003e to handle \u003ccode\u003eamt=0\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/3793\"\u003eurllib3/urllib3#3793\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eUpdated \u003ccode\u003e_TYPE_BODY\u003c/code\u003e type alias to include missing \u003ccode\u003eIterable[str]\u003c/code\u003e, matching the documented and runtime behavior of chunked request bodies. (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/3798\"\u003eurllib3/urllib3#3798\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eLocationParseError\u003c/code\u003e when paths resembling schemeless URIs were passed to \u003ccode\u003eHTTPConnectionPool.urlopen()\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/3352\"\u003eurllib3/urllib3#3352\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eBaseHTTPResponse.readinto()\u003c/code\u003e type annotation to accept \u003ccode\u003ememoryview\u003c/code\u003e in addition to \u003ccode\u003ebytearray\u003c/code\u003e, matching the \u003ccode\u003eio.RawIOBase.readinto\u003c/code\u003e contract and enabling use with \u003ccode\u003eio.BufferedReader\u003c/code\u003e without type errors. (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/3764\"\u003eurllib3/urllib3#3764\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/urllib3/urllib3/blob/main/CHANGES.rst\"\u003eurllib3's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003e2.7.0 (2026-05-07)\u003c/h1\u003e\n\u003ch2\u003eSecurity\u003c/h2\u003e\n\u003cp\u003eAddressed high-severity security issues.\nImpact was limited to specific use cases detailed in the accompanying\nadvisories; overall user exposure was estimated to be marginal.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eDecompression-bomb safeguards of the streaming API were bypassed:\u003c/p\u003e\n\u003col\u003e\n\u003cli\u003eWhen \u003ccode\u003eHTTPResponse.drain_conn()\u003c/code\u003e was called after the response had been\nread and decompressed partially.\u003c/li\u003e\n\u003cli\u003eDuring the second \u003ccode\u003eHTTPResponse.read(amt=N)\u003c/code\u003e or\n\u003ccode\u003eHTTPResponse.stream(amt=N)\u003c/code\u003e call when the response was decompressed\nusing the official \u003ccode\u003eBrotli \u0026lt;https://pypi.org/project/brotli/\u0026gt;\u003c/code\u003e__ library.\u003c/li\u003e\n\u003c/ol\u003e\n\u003cp\u003eSee \u003ccode\u003eGHSA-mf9v-mfxr-j63j \u0026lt;https://github.com/urllib3/urllib3/security/advisories/GHSA-mf9v-mfxr-j63j\u0026gt;\u003c/code\u003e__\nfor details.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eHTTP pools created using \u003ccode\u003eProxyManager.connection_from_url\u003c/code\u003e did not strip\nsensitive headers specified in \u003ccode\u003eRetry.remove_headers_on_redirect\u003c/code\u003e when\nredirecting to a different host.\n(\u003ccode\u003eGHSA-qccp-gfcp-xxvc \u0026lt;https://github.com/urllib3/urllib3/security/advisories/GHSA-qccp-gfcp-xxvc\u0026gt;\u003c/code\u003e__)\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eDeprecations and Removals\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUsed \u003ccode\u003eFutureWarning\u003c/code\u003e instead of \u003ccode\u003eDeprecationWarning\u003c/code\u003e for better\nvisibility of existing deprecation notices. Rescheduled the removal of\ndeprecated features to version 3.0.\n(\u003ccode\u003e[#3763](https://github.com/urllib3/urllib3/issues/3763) \u0026lt;https://github.com/urllib3/urllib3/issues/3763\u0026gt;\u003c/code\u003e__)\u003c/li\u003e\n\u003cli\u003eRemoved support for end-of-life Python 3.9.\n(\u003ccode\u003e[#3720](https://github.com/urllib3/urllib3/issues/3720) \u0026lt;https://github.com/urllib3/urllib3/issues/3720\u0026gt;\u003c/code\u003e__)\u003c/li\u003e\n\u003cli\u003eRemoved support for end-of-life PyPy3.10.\n(\u003ccode\u003e[#4979](https://github.com/urllib3/urllib3/issues/4979) \u0026lt;https://github.com/urllib3/urllib3/issues/4979\u0026gt;\u003c/code\u003e__)\u003c/li\u003e\n\u003cli\u003eBumped the minimum supported pyOpenSSL version to 19.0.0.\n(\u003ccode\u003e[#3777](https://github.com/urllib3/urllib3/issues/3777) \u0026lt;https://github.com/urllib3/urllib3/issues/3777\u0026gt;\u003c/code\u003e__)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eBugfixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed a bug where \u003ccode\u003eHTTPResponse.read(amt=None)\u003c/code\u003e was ignoring decompressed\ndata buffered from previous partial reads.\n(\u003ccode\u003e[#3636](https://github.com/urllib3/urllib3/issues/3636) \u0026lt;https://github.com/urllib3/urllib3/issues/3636\u0026gt;\u003c/code\u003e__)\u003c/li\u003e\n\u003cli\u003eFixed a bug where \u003ccode\u003eHTTPResponse.read()\u003c/code\u003e could cache only part of the\nresponse after a partial read when \u003ccode\u003ecache_content=True\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/urllib3/urllib3/commit/9a950b92d999f906b6020bb2d1076ee56cddd5d2\"\u003e\u003ccode\u003e9a950b9\u003c/code\u003e\u003c/a\u003e Release 2.7.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/urllib3/urllib3/commit/5ec0de499b9166ca71c65ab04f2a7e4eb0d66fcc\"\u003e\u003ccode\u003e5ec0de4\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/urllib3/urllib3/commit/2bdcc44d1e163fb5cc48a8662425e35e15adfe6a\"\u003e\u003ccode\u003e2bdcc44\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/urllib3/urllib3/commit/f45b0df09d8620ac6ed0491eb9362c8c87b7bc2c\"\u003e\u003ccode\u003ef45b0df\u003c/code\u003e\u003c/a\u003e Fix a misleading example for \u003ccode\u003eProxyManager\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/4970\"\u003e#4970\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/urllib3/urllib3/commit/577193ca029872384f82c133449e0935f6d8a64b\"\u003e\u003ccode\u003e577193c\u003c/code\u003e\u003c/a\u003e Switch to nightly PyPy3.11 in CI for now (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/4984\"\u003e#4984\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/urllib3/urllib3/commit/e90af45bb006c3a452a3a21644a2681523f5c7fc\"\u003e\u003ccode\u003ee90af45\u003c/code\u003e\u003c/a\u003e Avoid infinite loop in \u003ccode\u003eHTTPResponse.read_chunked\u003c/code\u003e when \u003ccode\u003eamt=0\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/4974\"\u003e#4974\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/urllib3/urllib3/commit/67ed74fdaec6659a6534621ec8e3aaaa6f976210\"\u003e\u003ccode\u003e67ed74f\u003c/code\u003e\u003c/a\u003e Bump dev dependencies (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/4972\"\u003e#4972\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/urllib3/urllib3/commit/3abd481097b54d87b574ac7ea593c3f40938a84d\"\u003e\u003ccode\u003e3abd481\u003c/code\u003e\u003c/a\u003e Upgrade mypy to version 1.20.2 (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/4978\"\u003e#4978\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/urllib3/urllib3/commit/2b8725dfcac4f21d4d93cc0cc3a64a33af08f890\"\u003e\u003ccode\u003e2b8725d\u003c/code\u003e\u003c/a\u003e Drop support for EOL PyPy3.10 (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/4979\"\u003e#4979\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/urllib3/urllib3/commit/2944b2a0a6c573f5548a39cfd17196f98ee21b33\"\u003e\u003ccode\u003e2944b2a\u003c/code\u003e\u003c/a\u003e Upgrade \u003ccode\u003esetup-chrome\u003c/code\u003e and \u003ccode\u003esetup-firefox\u003c/code\u003e to fix warnings (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/4973\"\u003e#4973\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/urllib3/urllib3/compare/2.6.3...2.7.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/timerloggedout-spec/hermes-agent_fork/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/timerloggedout-spec/hermes-agent_fork/pull/5","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/timerloggedout-spec%2Fhermes-agent_fork/issues/5","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/5/packages"},{"uuid":"5570060544","node_id":"PR_kwDOTg5ijc8AAAABE877pw","number":20,"state":"open","title":"Bump the minor-update group across 1 directory with 173 updates","user":"dependabot[bot]","labels":["dependencies"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-24T14:42:10.000Z","updated_at":"2026-09-24T14:42:23.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","group_name":"minor-update","update_count":173,"packages":[{"name":"tblib","old_version":"3.1.0","new_version":"3.2.2","repository_url":"https://github.com/ionelmc/python-tblib"},{"name":"regex","old_version":"2026.2.28","new_version":"2026.9.10","repository_url":"https://github.com/mrabarnett/mrab-regex"},{"name":"requests","old_version":"2.32.3","new_version":"2.34.2","repository_url":"https://github.com/psf/requests"},{"name":"tqdm","old_version":"4.67.3","new_version":"4.70.1","repository_url":"https://github.com/tqdm/tqdm"},{"name":"transformers","old_version":"5.5.3","new_version":"5.17.0","repository_url":"https://github.com/huggingface/transformers"},{"name":"tokenizers","old_version":"0.22.2","new_version":"0.23.2","repository_url":"https://github.com/huggingface/tokenizers"},{"name":"safetensors","old_version":"0.7.0","new_version":"0.8.0","repository_url":"https://github.com/huggingface/safetensors"},{"name":"fastapi","old_version":"0.136.3","new_version":"0.141.1","repository_url":"https://github.com/fastapi/fastapi"},{"name":"starlette","old_version":"1.3.1","new_version":"1.6.0","repository_url":"https://github.com/Kludex/starlette"},{"name":"aiohttp","old_version":"3.13.3","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"pydantic","old_version":"2.12.0","new_version":"2.13.5","repository_url":"https://github.com/pydantic/pydantic"},{"name":"prometheus-client","old_version":"0.22.0","new_version":"0.26.0","repository_url":"https://github.com/prometheus/client_python"},{"name":"tiktoken","old_version":"0.12.0","new_version":"0.14.0","repository_url":"https://github.com/openai/tiktoken"},{"name":"lark","old_version":"1.2.2","new_version":"1.3.1","repository_url":"https://github.com/lark-parser/lark"},{"name":"typing-extensions","old_version":"4.15.0","new_version":"4.16.0","repository_url":"https://github.com/python/typing_extensions"},{"name":"jsonschema","old_version":"4.23.0","new_version":"4.26.0","repository_url":"https://github.com/python-jsonschema/jsonschema"},{"name":"opentelemetry-sdk","old_version":"1.35.0","new_version":"1.44.0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"opentelemetry-api","old_version":"1.35.0","new_version":"1.44.0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"numba","old_version":"0.65.0","new_version":"0.67.0","repository_url":"https://github.com/numba/numba"},{"name":"absl-py","old_version":"2.1.0","new_version":"2.5.0","repository_url":"https://github.com/abseil/abseil-py"},{"name":"accelerate","old_version":"1.13.0","new_version":"1.15.0","repository_url":"https://github.com/huggingface/accelerate"},{"name":"aiohappyeyeballs","old_version":"2.6.1","new_version":"2.7.1","repository_url":"https://github.com/aio-libs/aiohappyeyeballs"},{"name":"alembic","old_version":"1.16.4","new_version":"1.20.0","repository_url":"https://github.com/sqlalchemy/alembic"},{"name":"annotated-types","old_version":"0.7.0","new_version":"0.8.0","repository_url":"https://github.com/annotated-types/annotated-types"},{"name":"anyio","old_version":"4.6.2.post1","new_version":"4.15.1","repository_url":"https://github.com/agronholm/anyio"},{"name":"arctic-inference","old_version":"0.1.1","new_version":"0.3.0"},{"name":"argcomplete","old_version":"3.5.1","new_version":"3.7.2","repository_url":"https://github.com/kislyuk/argcomplete"},{"name":"audioread","old_version":"3.0.1","new_version":"3.1.0","repository_url":"https://github.com/beetbox/audioread"},{"name":"azure-core","old_version":"1.38.2","new_version":"1.41.0","repository_url":"https://github.com/Azure/azure-sdk-for-python"},{"name":"azure-storage-blob","old_version":"12.28.0","new_version":"12.30.2","repository_url":"https://github.com/Azure/azure-sdk-for-python"},{"name":"bitsandbytes","old_version":"0.49.2","new_version":"0.50.2","repository_url":"https://github.com/bitsandbytes-foundation/bitsandbytes"},{"name":"blobfile","old_version":"3.0.0","new_version":"3.3.0","repository_url":"https://github.com/blobfile/blobfile"},{"name":"bm25s","old_version":"0.2.13","new_version":"0.3.11","repository_url":"https://github.com/xhluca/bm25s"},{"name":"boto3","old_version":"1.35.57","new_version":"1.43.98","repository_url":"https://github.com/boto/boto3"},{"name":"botocore","old_version":"1.35.57","new_version":"1.43.98","repository_url":"https://github.com/boto/botocore"},{"name":"cffi","old_version":"2.0.0","new_version":"2.1.1","repository_url":"https://github.com/python-cffi/cffi"},{"name":"charset-normalizer","old_version":"3.4.0","new_version":"3.5.1","repository_url":"https://github.com/jawah/charset_normalizer"},{"name":"click","old_version":"8.1.7","new_version":"8.5.0","repository_url":"https://github.com/pallets/click"},{"name":"cohere-melody","old_version":"0.9.0","new_version":"0.15.0","repository_url":"https://github.com/cohere-ai/melody"},{"name":"colorlog","old_version":"6.10.1","new_version":"6.12.0","repository_url":"https://github.com/borntyping/python-colorlog"},{"name":"coverage","old_version":"7.10.6","new_version":"7.16.1","repository_url":"https://github.com/coveragepy/coveragepy"},{"name":"cramjam","old_version":"2.9.0","new_version":"2.11.0","repository_url":"https://github.com/milesgranger/pyrus-cramjam"},{"name":"cuda-bindings","old_version":"13.0.3","new_version":"13.4.2","repository_url":"https://github.com/NVIDIA/cuda-python"},{"name":"cuda-pathfinder","old_version":"1.3.3","new_version":"1.8.2","repository_url":"https://github.com/NVIDIA/cuda-python"},{"name":"cuda-toolkit","old_version":"13.0.2","new_version":"13.4.2"},{"name":"datamodel-code-generator","old_version":"0.26.3","new_version":"0.82.0","repository_url":"https://github.com/datamodel-code-generator/datamodel-code-generator"},{"name":"dataproperty","old_version":"1.0.1","new_version":"1.1.1","repository_url":"https://github.com/thombashi/DataProperty"},{"name":"decorator","old_version":"5.1.1","new_version":"5.3.1","repository_url":"https://github.com/micheles/decorator"},{"name":"dill","old_version":"0.3.8","new_version":"0.4.1","repository_url":"https://github.com/uqfoundation/dill"},{"name":"distlib","old_version":"0.3.9","new_version":"0.4.3","repository_url":"https://github.com/pypa/distlib"},{"name":"dnspython","old_version":"2.7.0","new_version":"2.8.0","repository_url":"https://github.com/rthalley/dnspython"},{"name":"docker","old_version":"7.1.0","new_version":"7.2.0","repository_url":"https://github.com/docker/docker-py"},{"name":"einx","old_version":"0.3.0","new_version":"0.4.3","repository_url":"https://github.com/fferflo/einx"},{"name":"email-validator","old_version":"2.2.0","new_version":"2.3.0","repository_url":"https://github.com/JoshData/python-email-validator"},{"name":"fastsafetensors","old_version":"0.3.2","new_version":"0.4.0","repository_url":"https://github.com/foundation-model-stack/fastsafetensors"},{"name":"fonttools","old_version":"4.55.0","new_version":"4.65.0","repository_url":"https://github.com/fonttools/fonttools"},{"name":"frozenlist","old_version":"1.5.0","new_version":"1.8.0","repository_url":"https://github.com/aio-libs/frozenlist"},{"name":"genson","old_version":"1.3.0","new_version":"1.4.0","repository_url":"https://github.com/wolverdude/genson"},{"name":"google-api-core","old_version":"2.24.2","new_version":"2.38.0","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"google-auth","old_version":"2.40.2","new_version":"2.58.0","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"google-cloud-core","old_version":"2.4.3","new_version":"2.7.0","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"google-cloud-storage","old_version":"3.4.0","new_version":"3.14.1","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"google-crc32c","old_version":"1.7.1","new_version":"1.8.0","repository_url":"https://github.com/googleapis/python-crc32c"},{"name":"google-resumable-media","old_version":"2.7.2","new_version":"2.10.2","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"googleapis-common-protos","old_version":"1.70.0","new_version":"1.75.3","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"greenlet","old_version":"3.2.3","new_version":"3.5.6","repository_url":"https://github.com/python-greenlet/greenlet"},{"name":"grpcio","old_version":"1.78.0","new_version":"1.84.0","repository_url":"https://github.com/grpc/grpc"},{"name":"grpcio-reflection","old_version":"1.78.0","new_version":"1.84.0"},{"name":"h11","old_version":"0.14.0","new_version":"0.16.0","repository_url":"https://github.com/python-hyper/h11"},{"name":"h2","old_version":"4.3.0","new_version":"4.4.1","repository_url":"https://github.com/python-hyper/h2"},{"name":"hf-xet","old_version":"1.4.3","new_version":"1.6.0","repository_url":"https://github.com/huggingface/xet-core"},{"name":"hiredis","old_version":"3.0.0","new_version":"3.4.1","repository_url":"https://github.com/redis/hiredis-py"},{"name":"hpack","old_version":"4.1.0","new_version":"4.2.0","repository_url":"https://github.com/python-hyper/hpack"},{"name":"httpx","old_version":"0.27.2","new_version":"0.28.1","repository_url":"https://github.com/encode/httpx"},{"name":"huggingface-hub","old_version":"1.10.2","new_version":"1.32.0","repository_url":"https://github.com/huggingface/huggingface_hub"},{"name":"humanize","old_version":"4.11.0","new_version":"4.16.0","repository_url":"https://github.com/python-humanize/humanize"},{"name":"hypothesis","old_version":"6.131.0","new_version":"6.168.0","repository_url":"https://github.com/HypothesisWorks/hypothesis"},{"name":"idna","old_version":"3.10","new_version":"3.20","repository_url":"https://github.com/kjd/idna"},{"name":"iniconfig","old_version":"2.0.0","new_version":"2.3.0","repository_url":"https://github.com/pytest-dev/iniconfig"},{"name":"instanttensor","old_version":"0.1.5","new_version":"0.2.0","repository_url":"https://github.com/scitix/InstantTensor"},{"name":"jmespath","old_version":"1.0.1","new_version":"1.1.0","repository_url":"https://github.com/jmespath/jmespath.py"},{"name":"joblib","old_version":"1.4.2","new_version":"1.6.0","repository_url":"https://github.com/joblib/joblib"},{"name":"jsonschema-rs","old_version":"0.46.5","new_version":"0.56.0","repository_url":"https://github.com/Stranger6667/jsonschema"},{"name":"kiwisolver","old_version":"1.4.7","new_version":"1.5.1","repository_url":"https://github.com/nucleic/kiwi"},{"name":"lazy-loader","old_version":"0.4","new_version":"0.5","repository_url":"https://github.com/scientific-python/lazy-loader"},{"name":"llvmlite","old_version":"0.47.0","new_version":"0.49.0","repository_url":"https://github.com/numba/llvmlite"},{"name":"mako","old_version":"1.3.10","new_version":"1.4.1","repository_url":"https://github.com/sqlalchemy/mako"},{"name":"matplotlib","old_version":"3.9.2","new_version":"3.10.9","repository_url":"https://github.com/matplotlib/matplotlib"},{"name":"mpmath","old_version":"1.3.0","new_version":"1.4.1","repository_url":"https://github.com/mpmath/mpmath"},{"name":"msal","old_version":"1.34.0","new_version":"1.39.0","repository_url":"https://github.com/AzureAD/microsoft-authentication-library-for-python"},{"name":"msgpack","old_version":"1.1.0","new_version":"1.2.2","repository_url":"https://github.com/msgpack/msgpack-python"},{"name":"mteb","old_version":"2.8.3","new_version":"2.21.4","repository_url":"https://github.com/embeddings-benchmark/mteb"},{"name":"multidict","old_version":"6.1.0","new_version":"6.9.0","repository_url":"https://github.com/aio-libs/multidict"},{"name":"mypy-extensions","old_version":"1.0.0","new_version":"1.1.0","repository_url":"https://github.com/python/mypy_extensions"},{"name":"networkx","old_version":"3.2.1","new_version":"3.4.2","repository_url":"https://github.com/networkx/networkx"},{"name":"nltk","old_version":"3.9.1","new_version":"3.10.3","repository_url":"https://github.com/nltk/nltk"},{"name":"nvidia-cublas","old_version":"13.1.0.3","new_version":"13.8.0.4"},{"name":"nvidia-cuda-cupti","old_version":"13.0.85","new_version":"13.4.92"},{"name":"nvidia-cuda-nvrtc","old_version":"13.0.88","new_version":"13.4.92"},{"name":"nvidia-cuda-runtime","old_version":"13.0.96","new_version":"13.4.92"},{"name":"nvidia-cudnn-cu13","old_version":"9.19.0.56","new_version":"9.26.0.51"},{"name":"nvidia-cufft","old_version":"12.0.0.61","new_version":"12.4.0.43"},{"name":"nvidia-cufile","old_version":"1.15.1.6","new_version":"1.19.1.55"},{"name":"nvidia-cusolver","old_version":"12.0.4.66","new_version":"12.3.4.7"},{"name":"nvidia-cusparse","old_version":"12.6.3.3","new_version":"12.8.6.72"},{"name":"nvidia-cusparselt-cu13","old_version":"0.8.0","new_version":"0.9.1"},{"name":"nvidia-nccl-cu13","old_version":"2.28.9","new_version":"2.31.2"},{"name":"nvidia-nvjitlink","old_version":"13.0.88","new_version":"13.4.92"},{"name":"nvidia-nvshmem-cu13","old_version":"3.4.5","new_version":"3.7.2"},{"name":"nvidia-nvtx","old_version":"13.0.85","new_version":"13.4.92"},{"name":"opentelemetry-exporter-prometheus","old_version":"0.56b0","new_version":"0.65b0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"opentelemetry-proto","old_version":"1.35.0","new_version":"1.44.0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"opentelemetry-semantic-conventions","old_version":"0.56b0","new_version":"0.65b0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"orjson","old_version":"3.11.5","new_version":"3.12.0","repository_url":"https://github.com/ijl/orjson"},{"name":"pathvalidate","old_version":"3.2.1","new_version":"3.3.1","repository_url":"https://github.com/thombashi/pathvalidate"},{"name":"peft","old_version":"0.18.1","new_version":"0.21.0","repository_url":"https://github.com/huggingface/peft"},{"name":"perceptron","old_version":"0.1.4","new_version":"0.3.5","repository_url":"https://github.com/perceptron-ai-inc/perceptron"},{"name":"platformdirs","old_version":"4.3.6","new_version":"4.11.11","repository_url":"https://github.com/tox-dev/platformdirs"},{"name":"pluggy","old_version":"1.5.0","new_version":"1.6.0","repository_url":"https://github.com/pytest-dev/pluggy"},{"name":"polars","old_version":"1.29.0","new_version":"1.44.2","repository_url":"https://github.com/pola-rs/polars"},{"name":"pooch","old_version":"1.8.2","new_version":"1.9.0","repository_url":"https://github.com/fatiando/pooch"},{"name":"propcache","old_version":"0.2.0","new_version":"0.5.4","repository_url":"https://github.com/aio-libs/propcache"},{"name":"proto-plus","old_version":"1.26.1","new_version":"1.28.4","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"pycryptodomex","old_version":"3.22.0","new_version":"3.23.0","repository_url":"https://github.com/Legrandin/pycryptodome"},{"name":"pydantic-core","old_version":"2.41.1","new_version":"2.49.0","repository_url":"https://github.com/pydantic/pydantic"},{"name":"pydantic-extra-types","old_version":"2.10.5","new_version":"2.11.1","repository_url":"https://github.com/pydantic/pydantic-extra-types"},{"name":"pygments","old_version":"2.18.0","new_version":"2.21.0","repository_url":"https://github.com/pygments/pygments"},{"name":"pyjwt","old_version":"2.11.0","new_version":"2.14.0","repository_url":"https://github.com/jpadilla/pyjwt"},{"name":"pyparsing","old_version":"3.2.0","new_version":"3.3.3","repository_url":"https://github.com/pyparsing/pyparsing"},{"name":"pyrate-limiter","old_version":"4.4.0","new_version":"4.5.0","repository_url":"https://github.com/vutran1710/PyrateLimiter"},{"name":"pystemmer","old_version":"3.0.0","new_version":"3.1.0","repository_url":"https://github.com/snowballstem/pystemmer"},{"name":"pytest-forked","old_version":"1.6.0","new_version":"1.7.5","repository_url":"https://github.com/pytest-dev/pytest-forked"},{"name":"pytest-mock","old_version":"3.14.0","new_version":"3.15.1","repository_url":"https://github.com/pytest-dev/pytest-mock"},{"name":"pytest-timeout","old_version":"2.3.1","new_version":"2.4.0","repository_url":"https://github.com/pytest-dev/pytest-timeout"},{"name":"python-rapidjson","old_version":"1.20","new_version":"1.25","repository_url":"https://github.com/python-rapidjson/python-rapidjson"},{"name":"rapidfuzz","old_version":"3.12.1","new_version":"3.14.5","repository_url":"https://github.com/rapidfuzz/RapidFuzz"},{"name":"referencing","old_version":"0.35.1","new_version":"0.37.0","repository_url":"https://github.com/python-jsonschema/referencing"},{"name":"responses","old_version":"0.25.3","new_version":"0.26.3","repository_url":"https://github.com/getsentry/responses"},{"name":"runai-model-streamer","old_version":"0.15.7","new_version":"0.16.1"},{"name":"runai-model-streamer-azure","old_version":"0.15.7","new_version":"0.16.1"},{"name":"runai-model-streamer-gcs","old_version":"0.15.7","new_version":"0.16.1"},{"name":"runai-model-streamer-s3","old_version":"0.15.7","new_version":"0.16.1"},{"name":"s3transfer","old_version":"0.10.3","new_version":"0.19.2","repository_url":"https://github.com/boto/s3transfer"},{"name":"sacrebleu","old_version":"2.4.3","new_version":"2.6.0","repository_url":"https://github.com/mjpost/sacrebleu"},{"name":"schemathesis","old_version":"4.21.6","new_version":"4.27.5","repository_url":"https://github.com/schemathesis/schemathesis"},{"name":"scikit-learn","old_version":"1.5.2","new_version":"1.7.2","repository_url":"https://github.com/scikit-learn/scikit-learn"},{"name":"scipy","old_version":"1.13.1","new_version":"1.15.3","repository_url":"https://github.com/scipy/scipy"},{"name":"six","old_version":"1.16.0","new_version":"1.17.0","repository_url":"https://github.com/benjaminp/six"},{"name":"soundfile","old_version":"0.12.1","new_version":"0.14.0","repository_url":"https://github.com/bastibe/python-soundfile"},{"name":"statsmodels","old_version":"0.14.4","new_version":"0.15.0","repository_url":"https://github.com/statsmodels/statsmodels"},{"name":"sympy","old_version":"1.13.3","new_version":"1.14.0","repository_url":"https://github.com/sympy/sympy"},{"name":"tabulate","old_version":"0.9.0","new_version":"0.10.0","repository_url":"https://github.com/astanin/python-tabulate"},{"name":"tensorizer","old_version":"2.10.1","new_version":"2.12.1","repository_url":"https://github.com/coreweave/tensorizer"},{"name":"termcolor","old_version":"3.1.0","new_version":"3.3.0","repository_url":"https://github.com/termcolor/termcolor"},{"name":"threadpoolctl","old_version":"3.5.0","new_version":"3.7.0","repository_url":"https://github.com/joblib/threadpoolctl"},{"name":"triton","old_version":"3.6.0","new_version":"3.8.0","repository_url":"https://github.com/triton-lang/triton"},{"name":"tritonclient","old_version":"2.64.0","new_version":"2.71.0","repository_url":"https://github.com/triton-inference-server/client"},{"name":"typer","old_version":"0.15.2","new_version":"0.27.2","repository_url":"https://github.com/fastapi/typer"},{"name":"urllib3","old_version":"2.2.3","new_version":"2.8.0","repository_url":"https://github.com/urllib3/urllib3"},{"name":"uvicorn","old_version":"0.35.0","new_version":"0.53.0","repository_url":"https://github.com/Kludex/uvicorn"},{"name":"vector-quantize-pytorch","old_version":"1.21.2","new_version":"1.31.4","repository_url":"https://github.com/lucidrains/vector-quantizer-pytorch"},{"name":"wcwidth","old_version":"0.2.13","new_version":"0.8.4","repository_url":"https://github.com/jquast/wcwidth"},{"name":"yarl","old_version":"1.17.1","new_version":"1.25.1","repository_url":"https://github.com/aio-libs/yarl"},{"name":"conch-triton-kernels","old_version":"1.2.1","new_version":"1.3","repository_url":"https://github.com/stackav-oss/conch"},{"name":"tpu-inference","old_version":"0.23.0","new_version":"0.29.0","repository_url":"https://github.com/vllm-project/tpu-inference"},{"name":"pynvvideocodec","old_version":"2.0.4","new_version":"2.2.3"},{"name":"nvidia-cutlass-dsl","old_version":"4.5.2","new_version":"4.8.0","repository_url":"https://github.com/NVIDIA/cutlass"},{"name":"tokenspeed-mla","old_version":"0.1.2","new_version":"0.2.10","repository_url":"https://github.com/lightseekorg/tokenspeed"},{"name":"griffelib","old_version":"2.0.2","new_version":"2.3.0"},{"name":"mkdocs-git-revision-date-localized-plugin","old_version":"1.5.1","new_version":"1.6.0","repository_url":"https://github.com/timvink/mkdocs-git-revision-date-localized-plugin"},{"name":"ruff","old_version":"0.15.12","new_version":"0.16.8","repository_url":"https://github.com/astral-sh/ruff"},{"name":"zentorch","old_version":"2.11.0.0","new_version":"2.14.0.0","repository_url":"https://github.com/amd/ZenDNN-pytorch-plugin"},{"name":"helion","old_version":"1.1.0","new_version":"1.4.0","repository_url":"https://github.com/pytorch/helion"}],"path":null,"ecosystem":"pip"},"body":"Bumps the minor-update group with 173 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [tblib](https://github.com/ionelmc/python-tblib) | `3.1.0` | `3.2.2` |\n| [regex](https://github.com/mrabarnett/mrab-regex) | `2026.2.28` | `2026.9.10` |\n| [requests](https://github.com/psf/requests) | `2.32.3` | `2.34.2` |\n| [tqdm](https://github.com/tqdm/tqdm) | `4.67.3` | `4.70.1` |\n| [transformers](https://github.com/huggingface/transformers) | `5.5.3` | `5.17.0` |\n| [tokenizers](https://github.com/huggingface/tokenizers) | `0.22.2` | `0.23.2` |\n| [safetensors](https://github.com/huggingface/safetensors) | `0.7.0` | `0.8.0` |\n| [fastapi](https://github.com/fastapi/fastapi) | `0.136.3` | `0.141.1` |\n| [starlette](https://github.com/Kludex/starlette) | `1.3.1` | `1.6.0` |\n| [aiohttp](https://github.com/aio-libs/aiohttp) | `3.13.3` | `3.14.3` |\n| [pydantic](https://github.com/pydantic/pydantic) | `2.12.0` | `2.13.5` |\n| [prometheus-client](https://github.com/prometheus/client_python) | `0.22.0` | `0.26.0` |\n| [tiktoken](https://github.com/openai/tiktoken) | `0.12.0` | `0.14.0` |\n| [lark](https://github.com/lark-parser/lark) | `1.2.2` | `1.3.1` |\n| [typing-extensions](https://github.com/python/typing_extensions) | `4.15.0` | `4.16.0` |\n| [jsonschema](https://github.com/python-jsonschema/jsonschema) | `4.23.0` | `4.26.0` |\n| [opentelemetry-sdk](https://github.com/open-telemetry/opentelemetry-python) | `1.35.0` | `1.44.0` |\n| [opentelemetry-api](https://github.com/open-telemetry/opentelemetry-python) | `1.35.0` | `1.44.0` |\n| [numba](https://github.com/numba/numba) | `0.65.0` | `0.67.0` |\n| [absl-py](https://github.com/abseil/abseil-py) | `2.1.0` | `2.5.0` |\n| [accelerate](https://github.com/huggingface/accelerate) | `1.13.0` | `1.15.0` |\n| [aiohappyeyeballs](https://github.com/aio-libs/aiohappyeyeballs) | `2.6.1` | `2.7.1` |\n| [alembic](https://github.com/sqlalchemy/alembic) | `1.16.4` | `1.20.0` |\n| [annotated-types](https://github.com/annotated-types/annotated-types) | `0.7.0` | `0.8.0` |\n| [anyio](https://github.com/agronholm/anyio) | `4.6.2.post1` | `4.15.1` |\n| arctic-inference | `0.1.1` | `0.3.0` |\n| [argcomplete](https://github.com/kislyuk/argcomplete) | `3.5.1` | `3.7.2` |\n| [audioread](https://github.com/beetbox/audioread) | `3.0.1` | `3.1.0` |\n| [azure-core](https://github.com/Azure/azure-sdk-for-python) | `1.38.2` | `1.41.0` |\n| [azure-storage-blob](https://github.com/Azure/azure-sdk-for-python) | `12.28.0` | `12.30.2` |\n| [bitsandbytes](https://github.com/bitsandbytes-foundation/bitsandbytes) | `0.49.2` | `0.50.2` |\n| [blobfile](https://github.com/blobfile/blobfile) | `3.0.0` | `3.3.0` |\n| [bm25s](https://github.com/xhluca/bm25s) | `0.2.13` | `0.3.11` |\n| [boto3](https://github.com/boto/boto3) | `1.35.57` | `1.43.98` |\n| [botocore](https://github.com/boto/botocore) | `1.35.57` | `1.43.98` |\n| [cffi](https://github.com/python-cffi/cffi) | `2.0.0` | `2.1.1` |\n| [charset-normalizer](https://github.com/jawah/charset_normalizer) | `3.4.0` | `3.5.1` |\n| [click](https://github.com/pallets/click) | `8.1.7` | `8.5.0` |\n| [cohere-melody](https://github.com/cohere-ai/melody) | `0.9.0` | `0.15.0` |\n| [colorlog](https://github.com/borntyping/python-colorlog) | `6.10.1` | `6.12.0` |\n| [coverage](https://github.com/coveragepy/coveragepy) | `7.10.6` | `7.16.1` |\n| [cramjam](https://github.com/milesgranger/pyrus-cramjam) | `2.9.0` | `2.11.0` |\n| [cuda-bindings](https://github.com/NVIDIA/cuda-python) | `13.0.3` | `13.4.2` |\n| [cuda-pathfinder](https://github.com/NVIDIA/cuda-python) | `1.3.3` | `1.8.2` |\n| [cuda-toolkit](https://developer.nvidia.com/cuda-toolkit) | `13.0.2` | `13.4.2` |\n| [datamodel-code-generator](https://github.com/datamodel-code-generator/datamodel-code-generator) | `0.26.3` | `0.82.0` |\n| [dataproperty](https://github.com/thombashi/DataProperty) | `1.0.1` | `1.1.1` |\n| [decorator](https://github.com/micheles/decorator) | `5.1.1` | `5.3.1` |\n| [dill](https://github.com/uqfoundation/dill) | `0.3.8` | `0.4.1` |\n| [distlib](https://github.com/pypa/distlib) | `0.3.9` | `0.4.3` |\n| [dnspython](https://github.com/rthalley/dnspython) | `2.7.0` | `2.8.0` |\n| [docker](https://github.com/docker/docker-py) | `7.1.0` | `7.2.0` |\n| [einx](https://github.com/fferflo/einx) | `0.3.0` | `0.4.3` |\n| [email-validator](https://github.com/JoshData/python-email-validator) | `2.2.0` | `2.3.0` |\n| [fastsafetensors](https://github.com/foundation-model-stack/fastsafetensors) | `0.3.2` | `0.4.0` |\n| [fonttools](https://github.com/fonttools/fonttools) | `4.55.0` | `4.65.0` |\n| [frozenlist](https://github.com/aio-libs/frozenlist) | `1.5.0` | `1.8.0` |\n| [genson](https://github.com/wolverdude/genson) | `1.3.0` | `1.4.0` |\n| [google-api-core](https://github.com/googleapis/google-cloud-python) | `2.24.2` | `2.38.0` |\n| [google-auth](https://github.com/googleapis/google-cloud-python) | `2.40.2` | `2.58.0` |\n| [google-cloud-core](https://github.com/googleapis/google-cloud-python) | `2.4.3` | `2.7.0` |\n| [google-cloud-storage](https://github.com/googleapis/google-cloud-python) | `3.4.0` | `3.14.1` |\n| [google-crc32c](https://github.com/googleapis/python-crc32c) | `1.7.1` | `1.8.0` |\n| [google-resumable-media](https://github.com/googleapis/google-cloud-python) | `2.7.2` | `2.10.2` |\n| [googleapis-common-protos](https://github.com/googleapis/google-cloud-python) | `1.70.0` | `1.75.3` |\n| [greenlet](https://github.com/python-greenlet/greenlet) | `3.2.3` | `3.5.6` |\n| [grpcio](https://github.com/grpc/grpc) | `1.78.0` | `1.84.0` |\n| [grpcio-reflection](https://grpc.io) | `1.78.0` | `1.84.0` |\n| [h11](https://github.com/python-hyper/h11) | `0.14.0` | `0.16.0` |\n| [h2](https://github.com/python-hyper/h2) | `4.3.0` | `4.4.1` |\n| [hf-xet](https://github.com/huggingface/xet-core) | `1.4.3` | `1.6.0` |\n| [hiredis](https://github.com/redis/hiredis-py) | `3.0.0` | `3.4.1` |\n| [hpack](https://github.com/python-hyper/hpack) | `4.1.0` | `4.2.0` |\n| [httpx](https://github.com/encode/httpx) | `0.27.2` | `0.28.1` |\n| [huggingface-hub](https://github.com/huggingface/huggingface_hub) | `1.10.2` | `1.32.0` |\n| [humanize](https://github.com/python-humanize/humanize) | `4.11.0` | `4.16.0` |\n| [hypothesis](https://github.com/HypothesisWorks/hypothesis) | `6.131.0` | `6.168.0` |\n| [idna](https://github.com/kjd/idna) | `3.10` | `3.20` |\n| [iniconfig](https://github.com/pytest-dev/iniconfig) | `2.0.0` | `2.3.0` |\n| [instanttensor](https://github.com/scitix/InstantTensor) | `0.1.5` | `0.2.0` |\n| [jmespath](https://github.com/jmespath/jmespath.py) | `1.0.1` | `1.1.0` |\n| [joblib](https://github.com/joblib/joblib) | `1.4.2` | `1.6.0` |\n| [jsonschema-rs](https://github.com/Stranger6667/jsonschema) | `0.46.5` | `0.56.0` |\n| [kiwisolver](https://github.com/nucleic/kiwi) | `1.4.7` | `1.5.1` |\n| [lazy-loader](https://github.com/scientific-python/lazy-loader) | `0.4` | `0.5` |\n| [llvmlite](https://github.com/numba/llvmlite) | `0.47.0` | `0.49.0` |\n| [mako](https://github.com/sqlalchemy/mako) | `1.3.10` | `1.4.1` |\n| [matplotlib](https://github.com/matplotlib/matplotlib) | `3.9.2` | `3.10.9` |\n| [mpmath](https://github.com/mpmath/mpmath) | `1.3.0` | `1.4.1` |\n| [msal](https://github.com/AzureAD/microsoft-authentication-library-for-python) | `1.34.0` | `1.39.0` |\n| [msgpack](https://github.com/msgpack/msgpack-python) | `1.1.0` | `1.2.2` |\n| [mteb](https://github.com/embeddings-benchmark/mteb) | `2.8.3` | `2.21.4` |\n| [multidict](https://github.com/aio-libs/multidict) | `6.1.0` | `6.9.0` |\n| [mypy-extensions](https://github.com/python/mypy_extensions) | `1.0.0` | `1.1.0` |\n| [networkx](https://github.com/networkx/networkx) | `3.2.1` | `3.4.2` |\n| [nltk](https://github.com/nltk/nltk) | `3.9.1` | `3.10.3` |\n| [nvidia-cublas](https://developer.nvidia.com/cuda-zone) | `13.1.0.3` | `13.8.0.4` |\n| [nvidia-cuda-cupti](https://developer.nvidia.com/cuda-zone) | `13.0.85` | `13.4.92` |\n| [nvidia-cuda-nvrtc](https://developer.nvidia.com/cuda-zone) | `13.0.88` | `13.4.92` |\n| [nvidia-cuda-runtime](https://developer.nvidia.com/cuda-zone) | `13.0.96` | `13.4.92` |\n| [nvidia-cudnn-cu13](https://developer.nvidia.com/cuda-zone) | `9.19.0.56` | `9.26.0.51` |\n| [nvidia-cufft](https://developer.nvidia.com/cuda-zone) | `12.0.0.61` | `12.4.0.43` |\n| [nvidia-cufile](https://developer.nvidia.com/cuda-zone) | `1.15.1.6` | `1.19.1.55` |\n| [nvidia-cusolver](https://developer.nvidia.com/cuda-zone) | `12.0.4.66` | `12.3.4.7` |\n| [nvidia-cusparse](https://developer.nvidia.com/cuda-zone) | `12.6.3.3` | `12.8.6.72` |\n| [nvidia-cusparselt-cu13](https://developer.nvidia.com/cusparselt) | `0.8.0` | `0.9.1` |\n| [nvidia-nccl-cu13](https://developer.nvidia.com/cuda-zone) | `2.28.9` | `2.31.2` |\n| [nvidia-nvjitlink](https://developer.nvidia.com/cuda-zone) | `13.0.88` | `13.4.92` |\n| [nvidia-nvshmem-cu13](https://developer.nvidia.com/cuda-zone) | `3.4.5` | `3.7.2` |\n| [nvidia-nvtx](https://developer.nvidia.com/cuda-zone) | `13.0.85` | `13.4.92` |\n| [opentelemetry-exporter-prometheus](https://github.com/open-telemetry/opentelemetry-python) | `0.56b0` | `0.65b0` |\n| [opentelemetry-proto](https://github.com/open-telemetry/opentelemetry-python) | `1.35.0` | `1.44.0` |\n| [opentelemetry-semantic-conventions](https://github.com/open-telemetry/opentelemetry-python) | `0.56b0` | `0.65b0` |\n| [orjson](https://github.com/ijl/orjson) | `3.11.5` | `3.12.0` |\n| [pathvalidate](https://github.com/thombashi/pathvalidate) | `3.2.1` | `3.3.1` |\n| [peft](https://github.com/huggingface/peft) | `0.18.1` | `0.21.0` |\n| [perceptron](https://github.com/perceptron-ai-inc/perceptron) | `0.1.4` | `0.3.5` |\n| [platformdirs](https://github.com/tox-dev/platformdirs) | `4.3.6` | `4.11.11` |\n| [pluggy](https://github.com/pytest-dev/pluggy) | `1.5.0` | `1.6.0` |\n| [polars](https://github.com/pola-rs/polars) | `1.29.0` | `1.44.2` |\n| [pooch](https://github.com/fatiando/pooch) | `1.8.2` | `1.9.0` |\n| [propcache](https://github.com/aio-libs/propcache) | `0.2.0` | `0.5.4` |\n| [proto-plus](https://github.com/googleapis/google-cloud-python) | `1.26.1` | `1.28.4` |\n| [pycryptodomex](https://github.com/Legrandin/pycryptodome) | `3.22.0` | `3.23.0` |\n| [pydantic-core](https://github.com/pydantic/pydantic) | `2.41.1` | `2.49.0` |\n| [pydantic-extra-types](https://github.com/pydantic/pydantic-extra-types) | `2.10.5` | `2.11.1` |\n| [pygments](https://github.com/pygments/pygments) | `2.18.0` | `2.21.0` |\n| [pyjwt](https://github.com/jpadilla/pyjwt) | `2.11.0` | `2.14.0` |\n| [pyparsing](https://github.com/pyparsing/pyparsing) | `3.2.0` | `3.3.3` |\n| [pyrate-limiter](https://github.com/vutran1710/PyrateLimiter) | `4.4.0` | `4.5.0` |\n| [pystemmer](https://github.com/snowballstem/pystemmer) | `3.0.0` | `3.1.0` |\n| [pytest-forked](https://github.com/pytest-dev/pytest-forked) | `1.6.0` | `1.7.5` |\n| [pytest-mock](https://github.com/pytest-dev/pytest-mock) | `3.14.0` | `3.15.1` |\n| [pytest-timeout](https://github.com/pytest-dev/pytest-timeout) | `2.3.1` | `2.4.0` |\n| [python-rapidjson](https://github.com/python-rapidjson/python-rapidjson) | `1.20` | `1.25` |\n| [rapidfuzz](https://github.com/rapidfuzz/RapidFuzz) | `3.12.1` | `3.14.5` |\n| [referencing](https://github.com/python-jsonschema/referencing) | `0.35.1` | `0.37.0` |\n| [responses](https://github.com/getsentry/responses) | `0.25.3` | `0.26.3` |\n| runai-model-streamer | `0.15.7` | `0.16.1` |\n| runai-model-streamer-azure | `0.15.7` | `0.16.1` |\n| runai-model-streamer-gcs | `0.15.7` | `0.16.1` |\n| runai-model-streamer-s3 | `0.15.7` | `0.16.1` |\n| [s3transfer](https://github.com/boto/s3transfer) | `0.10.3` | `0.19.2` |\n| [sacrebleu](https://github.com/mjpost/sacrebleu) | `2.4.3` | `2.6.0` |\n| [schemathesis](https://github.com/schemathesis/schemathesis) | `4.21.6` | `4.27.5` |\n| [scikit-learn](https://github.com/scikit-learn/scikit-learn) | `1.5.2` | `1.7.2` |\n| [scipy](https://github.com/scipy/scipy) | `1.13.1` | `1.15.3` |\n| [six](https://github.com/benjaminp/six) | `1.16.0` | `1.17.0` |\n| [soundfile](https://github.com/bastibe/python-soundfile) | `0.12.1` | `0.14.0` |\n| [statsmodels](https://github.com/statsmodels/statsmodels) | `0.14.4` | `0.15.0` |\n| [sympy](https://github.com/sympy/sympy) | `1.13.3` | `1.14.0` |\n| [tabulate](https://github.com/astanin/python-tabulate) | `0.9.0` | `0.10.0` |\n| [tensorizer](https://github.com/coreweave/tensorizer) | `2.10.1` | `2.12.1` |\n| [termcolor](https://github.com/termcolor/termcolor) | `3.1.0` | `3.3.0` |\n| [threadpoolctl](https://github.com/joblib/threadpoolctl) | `3.5.0` | `3.7.0` |\n| [triton](https://github.com/triton-lang/triton) | `3.6.0` | `3.8.0` |\n| [tritonclient](https://github.com/triton-inference-server/client) | `2.64.0` | `2.71.0` |\n| [typer](https://github.com/fastapi/typer) | `0.15.2` | `0.27.2` |\n| [urllib3](https://github.com/urllib3/urllib3) | `2.2.3` | `2.8.0` |\n| [uvicorn](https://github.com/Kludex/uvicorn) | `0.35.0` | `0.53.0` |\n| [vector-quantize-pytorch](https://github.com/lucidrains/vector-quantizer-pytorch) | `1.21.2` | `1.31.4` |\n| [wcwidth](https://github.com/jquast/wcwidth) | `0.2.13` | `0.8.4` |\n| [yarl](https://github.com/aio-libs/yarl) | `1.17.1` | `1.25.1` |\n| [conch-triton-kernels](https://github.com/stackav-oss/conch) | `1.2.1` | `1.3` |\n| [tpu-inference](https://github.com/vllm-project/tpu-inference) | `0.23.0` | `0.29.0` |\n| pynvvideocodec | `2.0.4` | `2.2.3` |\n| [nvidia-cutlass-dsl](https://github.com/NVIDIA/cutlass) | `4.5.2` | `4.8.0` |\n| [tokenspeed-mla](https://github.com/lightseekorg/tokenspeed) | `0.1.2` | `0.2.10` |\n| griffelib | `2.0.2` | `2.3.0` |\n| [mkdocs-git-revision-date-localized-plugin](https://github.com/timvink/mkdocs-git-revision-date-localized-plugin) | `1.5.1` | `1.6.0` |\n| [ruff](https://github.com/astral-sh/ruff) | `0.15.12` | `0.16.8` |\n| [zentorch](https://github.com/amd/ZenDNN-pytorch-plugin) | `2.11.0.0` | `2.14.0.0` |\n| [helion](https://github.com/pytorch/helion) | `1.1.0` | `1.4.0` |\n\n\nUpdates `tblib` from 3.1.0 to 3.2.2\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/ionelmc/python-tblib/blob/master/CHANGELOG.rst\"\u003etblib's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e3.2.2 (2025-11-12)\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003e\n* Fixed regression occurring with ``TimeoutError`` exceptions. They should be represented now exactly as the original when unpickling.\n  Contributed by Jacob Tomlinson in `[#85](https://github.com/ionelmc/python-tblib/issues/85) \u0026lt;https://github.com/ionelmc/python-tblib/pull/85\u0026gt;`_.\n\u003cp\u003e3.2.1 (2025-10-31)\n\u003c/code\u003e\u003c/pre\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eFixed regression occurring with \u003ccode\u003eExceptionGroup\u003c/code\u003e exceptions. That exception type is now handled specifically in the new \u003ccode\u003eunpickle_exception_with_attrs\u003c/code\u003e function (just like \u003ccode\u003eOSError\u003c/code\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e3.2.0 (2025-10-21)\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003e\n* Changed ``tblib.pickling_support.install`` to support exceptions with ``__init__`` that does match the default\n  ``BaseException.__reduce__`` (as it expects the positional arguments to ``__init__`` to match the ``args`` attribute).\n\u003cp\u003eSpecial handling for OSError (and subclasses) is also included. The errno, strerror, winerror, filename and filename2 attributes will be added in the reduce structure (if set).\u003c/p\u003e\n\u003cp\u003eThis will support exception subclasses that do this without defining a custom \u003ccode\u003e__reduce__\u003c/code\u003e:\u003c/p\u003e\n\u003cp\u003e.. code-block:: python\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003edef __init__(self):\n    super().__init__('mistery argument')\n\ndef __init__(self, mistery_argument):\n    super().__init__()\n    self.mistery_argument = mistery_argument\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eTests and POC contributed by Oldřich Jedlička in \u003ccode\u003e[#73](https://github.com/ionelmc/python-tblib/issues/73) \u0026amp;lt;https://github.com/ionelmc/python-tblib/pull/73\u0026amp;gt;\u003c/code\u003e_.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eFixed some doctest and coverage config. Contributed by Colin Watson in \u003ccode\u003e[#79](https://github.com/ionelmc/python-tblib/issues/79) \u0026amp;lt;https://github.com/ionelmc/python-tblib/pull/79\u0026amp;gt;\u003c/code\u003e_.\n\u003c/code\u003e\u003c/pre\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/d88606aab343749dfeccf16a813f63cbe2dae11e\"\u003e\u003ccode\u003ed88606a\u003c/code\u003e\u003c/a\u003e Bump version: 3.2.1 → 3.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/530f8743f1ed322f220621d8491e660636065279\"\u003e\u003ccode\u003e530f874\u003c/code\u003e\u003c/a\u003e Add test for timeouterror regression. Ref \u003ca href=\"https://redirect.github.com/ionelmc/python-tblib/issues/85\"\u003e#85\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/9c8f2ca0e7c061cc423207986af6f06aaa76cfee\"\u003e\u003ccode\u003e9c8f2ca\u003c/code\u003e\u003c/a\u003e Update changelog.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/df6185d4b942a37d48a0e082b885380b8c5cc5ad\"\u003e\u003ccode\u003edf6185d\u003c/code\u003e\u003c/a\u003e Handle optional OSError attributes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/b197023aa86b831834393fdd89c6439fe2ffaf0c\"\u003e\u003ccode\u003eb197023\u003c/code\u003e\u003c/a\u003e Bump version: 3.2.0 → 3.2.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/d71e1edc9da5a86e326406ea4372cce5c075b4f4\"\u003e\u003ccode\u003ed71e1ed\u003c/code\u003e\u003c/a\u003e Update changelog.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/74ec64570acb0d6ce708c695ab98d52d08f8b066\"\u003e\u003ccode\u003e74ec645\u003c/code\u003e\u003c/a\u003e Specifically handle ExceptionGroup in the new unpickle_exception_with_attrs. ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/580d57921a6e93660bf47771f70c0bfbe70e9c97\"\u003e\u003ccode\u003e580d579\u003c/code\u003e\u003c/a\u003e Ooops, forgot to update these.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/ebc83e93b6342950cb93cf296991fb99ce4aa13a\"\u003e\u003ccode\u003eebc83e9\u003c/code\u003e\u003c/a\u003e Bump version: 3.1.0 → 3.2.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/abec37d4526fb86f95c7567644f1fd6c2cec4215\"\u003e\u003ccode\u003eabec37d\u003c/code\u003e\u003c/a\u003e Update changelog and add one more test.\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/ionelmc/python-tblib/compare/v3.1.0...v3.2.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `regex` from 2026.2.28 to 2026.9.10\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/mrabarnett/mrab-regex/blob/hg/changelog.txt\"\u003eregex's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003eVersion: 2026.9.19\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eGit issue 619: `Match.expand()` segfaults after `detach_string()` when the template references a group\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.9.10\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eFixed version.\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.9.9\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003ePR [#615](https://github.com/mrabarnett/mrab-regex/issues/615): Fix Python API error propagation in match helpers\n\u003cp\u003ePR \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/616\"\u003e#616\u003c/a\u003e: Preserve Python Exceptions in Input Decoding and String Detachment\u003c/p\u003e\n\u003cp\u003ePR \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/617\"\u003e#617\u003c/a\u003e: Prevent Invalid Pointer Use and Exception State Corruption in Byte String Joining\u003c/p\u003e\n\u003cp\u003ePR \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/618\"\u003e#618\u003c/a\u003e: Propagate Allocation and Internal Errors During Pattern Compilation and Scanner Execution\n\u003c/code\u003e\u003c/pre\u003e\u003c/p\u003e\n\u003cp\u003eVersion: 2026.9.3\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eNew version of cibuildwheel no longer supports building for free-threaded Python 3.13.\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.9.2\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eNew version of cibuildwheel no longer needs nor supports cpython-freethreading option.\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.9.1\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eUpdated cibuildwheel.\nSupport Python 3.15.\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.8.31\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eFixed version.\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.8.30\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eGit issue 611: Heap out-of-bounds write at compile time\nGit issue 612: count_one() size underflow through the stale required-string cache\nGit issue 613: (*SKIP) inside an atomic group, plus an equality-only scan stop\nGit issue 614: build_GROUP() does not propagate the match direction\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.8.12\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eSupport Python 3.15.\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.7.19\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eGit issue 607: SIGSEGV: NULL pointer dereference in `basic_match()` when `(?R)`/`(?0)` recursion is used inside a fuzzy-matching quantifier\nGit issue 608: SIGSEGV: out-of-bounds read in `bytes1_char_at()` with `DOTALL` + a fuzzy constraint + `(?r)` reverse-direction matching\n\u003c/code\u003e\u003c/pre\u003e\n\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/7dd71c15c4fb5c94206bed1763abd4c2bd2f1b33\"\u003e\u003ccode\u003e7dd71c1\u003c/code\u003e\u003c/a\u003e Fixed version.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/59124d62299e212931786aa74ead15388abaf376\"\u003e\u003ccode\u003e59124d6\u003c/code\u003e\u003c/a\u003e PR \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/615\"\u003e#615\u003c/a\u003e: Fix Python API error propagation in match helpers\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/25e15218bd44ca26677e3c28709e94a0ca0d9b8e\"\u003e\u003ccode\u003e25e1521\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/618\"\u003e#618\u003c/a\u003e from dynapx/fix-compiler-error-propagation\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/3ad78cfb73850c2f1178d19553fa14661f73d9cb\"\u003e\u003ccode\u003e3ad78cf\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/616\"\u003e#616\u003c/a\u003e from dynapx/fix-detach-string-error-propagation\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/f54253c332574bd5a9d96d3ec9d62b5db954dac7\"\u003e\u003ccode\u003ef54253c\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/615\"\u003e#615\u003c/a\u003e from dynapx/fix-python-api-error-propagation\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/c44224476cd6a6e53be0e458dfdcf3b81d76e426\"\u003e\u003ccode\u003ec442244\u003c/code\u003e\u003c/a\u003e Propagate scanner internal errors\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/68837e7af862250cd08fa49ff584a2bbff246e0f\"\u003e\u003ccode\u003e68837e7\u003c/code\u003e\u003c/a\u003e Propagate node stack allocation failures\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/f1df5387982d526cc9475fddcc8d1043b02ffc9a\"\u003e\u003ccode\u003ef1df538\u003c/code\u003e\u003c/a\u003e Propagate check stack allocation failures\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/d8873b119a49cde8d2613253827bf973261bb2bc\"\u003e\u003ccode\u003ed8873b1\u003c/code\u003e\u003c/a\u003e Preserve Python exceptions in input decoding\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/910784fb8039c445a68e84a261119a96031c811c\"\u003e\u003ccode\u003e910784f\u003c/code\u003e\u003c/a\u003e Propagate detach_string slicing errors\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/mrabarnett/mrab-regex/compare/2026.2.28...2026.9.10\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `requests` from 2.32.3 to 2.34.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/psf/requests/releases\"\u003erequests's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.34.2\u003c/h2\u003e\n\u003ch2\u003e2.34.2 (2026-05-14)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMoved \u003ccode\u003eheaders\u003c/code\u003e input type back to \u003ccode\u003eMapping\u003c/code\u003e to avoid invariance issues with \u003ccode\u003eMutableMapping\u003c/code\u003e and inferred dict types. Users calling \u003ccode\u003eRequest.headers.update()\u003c/code\u003e may need to narrow typing in their code. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7441\"\u003e#7441\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/psf/requests/blob/main/HISTORY.md#2342-2026-05-14\"\u003ehttps://github.com/psf/requests/blob/main/HISTORY.md#2342-2026-05-14\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.34.1\u003c/h2\u003e\n\u003ch2\u003e2.34.1 (2026-05-13)\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eBugfixes\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eWidened \u003ccode\u003ejson\u003c/code\u003e input type from \u003ccode\u003edict\u003c/code\u003e and \u003ccode\u003elist\u003c/code\u003e to \u003ccode\u003eMapping\u003c/code\u003e\nand \u003ccode\u003eSequence\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7436\"\u003e#7436\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eChanged \u003ccode\u003eheaders\u003c/code\u003e input type to MutableMapping and removed \u003ccode\u003eNone\u003c/code\u003e from\n\u003ccode\u003eRequest.headers\u003c/code\u003e typing to improve handling for users. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7431\"\u003e#7431\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eResponse.reason\u003c/code\u003e moved from \u003ccode\u003estr | None\u003c/code\u003e to \u003ccode\u003estr\u003c/code\u003e to improve handling\nfor users. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7437\"\u003e#7437\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed a bug where some bodies with custom \u003ccode\u003e__getattr__\u003c/code\u003e implementations\nweren't being properly detected as Iterables. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7433\"\u003e#7433\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/k223kim\"\u003e\u003ccode\u003e@​k223kim\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/psf/requests/pull/7433\"\u003epsf/requests#7433\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/psf/requests/blob/main/HISTORY.md#2341-2026-05-13\"\u003ehttps://github.com/psf/requests/blob/main/HISTORY.md#2341-2026-05-13\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.34.0\u003c/h2\u003e\n\u003ch2\u003e2.34.0 (2026-05-11)\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eAnnouncements\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eRequests 2.34.0 introduces inline types, replacing those provided by\ntypeshed. Public API types should be fully compatible with mypy, pyright,\nand ty. \u003cstrong\u003eWe believe types are comprehensive but if you find issues, please\nreport them to the \u003ca href=\"https://redirect.github.com/psf/requests/issues/7271\"\u003epinned tracking issue\u003c/a\u003e.\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eSpecial thanks to \u003ca href=\"https://github.com/bastimeyer\"\u003e\u003ccode\u003e@​bastimeyer\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/cthoyt\"\u003e\u003ccode\u003e@​cthoyt\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/edgarrmondragon\"\u003e\u003ccode\u003e@​edgarrmondragon\u003c/code\u003e\u003c/a\u003e, and \u003ca href=\"https://github.com/srittau\"\u003e\u003ccode\u003e@​srittau\u003c/code\u003e\u003c/a\u003e for\nhelping review and test the types ahead of the release. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7272\"\u003e#7272\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eImprovements\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eDigest Auth hashing algorithms have added \u003ccode\u003eusedforsecurity=False\u003c/code\u003e to clarify\nsecurity considerations. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7310\"\u003e#7310\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests added support for Python 3.15 based on beta1. Downstream projects\nshould be able to start testing prior to its release in October. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7422\"\u003e#7422\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests added support for Python 3.14t. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7419\"\u003e#7419\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eBugfixes\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eResponse.history\u003c/code\u003e no longer contains a reference to itself, preventing\naccidental looping when traversing the history list. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7328\"\u003e#7328\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests no longer performs greedy matching on no_proxy domains. The\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/psf/requests/blob/main/HISTORY.md\"\u003erequests's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e2.34.2 (2026-05-14)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMoved \u003ccode\u003eheaders\u003c/code\u003e input type back to \u003ccode\u003eMapping\u003c/code\u003e to avoid invariance issues\nwith \u003ccode\u003eMutableMapping\u003c/code\u003e and inferred dict types. Users calling\n\u003ccode\u003eRequest.headers.update()\u003c/code\u003e may need to narrow typing in their code. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7441\"\u003e#7441\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.34.1 (2026-05-13)\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eBugfixes\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eWidened \u003ccode\u003ejson\u003c/code\u003e input type from \u003ccode\u003edict\u003c/code\u003e and \u003ccode\u003elist\u003c/code\u003e to \u003ccode\u003eMapping\u003c/code\u003e\nand \u003ccode\u003eSequence\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7436\"\u003e#7436\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eChanged \u003ccode\u003eheaders\u003c/code\u003e input type to MutableMapping and removed \u003ccode\u003eNone\u003c/code\u003e from\n\u003ccode\u003eRequest.headers\u003c/code\u003e typing to improve handling for users. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7431\"\u003e#7431\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eResponse.reason\u003c/code\u003e moved from \u003ccode\u003estr | None\u003c/code\u003e to \u003ccode\u003estr\u003c/code\u003e to improve handling\nfor users. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7437\"\u003e#7437\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed a bug where some bodies with custom \u003ccode\u003e__getattr__\u003c/code\u003e implementations\nweren't being properly detected as Iterables. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7433\"\u003e#7433\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.34.0 (2026-05-11)\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eAnnouncements\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eRequests 2.34.0 introduces inline types, replacing those provided by\ntypeshed. Public API types should be fully compatible with mypy, pyright,\nand ty. We believe types are comprehensive but if you find issues, please\nreport them to the pinned tracking issue.\u003c/p\u003e\n\u003cp\u003eSpecial thanks to \u003ca href=\"https://github.com/bastimeyer\"\u003e\u003ccode\u003e@​bastimeyer\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/cthoyt\"\u003e\u003ccode\u003e@​cthoyt\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/edgarrmondragon\"\u003e\u003ccode\u003e@​edgarrmondragon\u003c/code\u003e\u003c/a\u003e, and \u003ca href=\"https://github.com/srittau\"\u003e\u003ccode\u003e@​srittau\u003c/code\u003e\u003c/a\u003e for\nhelping review and test the types ahead of the release. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7272\"\u003e#7272\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eImprovements\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eDigest Auth hashing algorithms have added \u003ccode\u003eusedforsecurity=False\u003c/code\u003e to clarify\nsecurity considerations. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7310\"\u003e#7310\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests added support for Python 3.15 based on beta1. Downstream projects\nshould be able to start testing prior to its release in October. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7422\"\u003e#7422\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests added support for Python 3.14t. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7419\"\u003e#7419\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eBugfixes\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eResponse.history\u003c/code\u003e no longer contains a reference to itself, preventing\naccidental looping when traversing the history list. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7328\"\u003e#7328\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests no longer performs greedy matching on no_proxy domains. The\nproxy_bypass implementation has been updated with CPython's fix from\nbpo-39057. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7427\"\u003e#7427\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests no longer incorrectly strips duplicate leading slashes in\nURI paths. This should address user issues with specific presigned\nURLs. Note the full fix requires urllib3 2.7.0+. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7315\"\u003e#7315\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/6e83187b8feb273ed4c6cdab5efd8d54901dfab3\"\u003e\u003ccode\u003e6e83187\u003c/code\u003e\u003c/a\u003e v2.34.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/84d10f0be83e8f6aeca8a05230c52216431c4d0b\"\u003e\u003ccode\u003e84d10f0\u003c/code\u003e\u003c/a\u003e Move Request.headers back to Mapping (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7441\"\u003e#7441\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/b7b549b54571d03950b16afd2d01bc6ff0348224\"\u003e\u003ccode\u003eb7b549b\u003c/code\u003e\u003c/a\u003e v2.34.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/e511bc72777a94c45d004e010c597925092e1efe\"\u003e\u003ccode\u003ee511bc7\u003c/code\u003e\u003c/a\u003e Fix mutability issues with headers input types (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7431\"\u003e#7431\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/5691f596134c2feb121e595c77a0178921fcce61\"\u003e\u003ccode\u003e5691f59\u003c/code\u003e\u003c/a\u003e Update JsonType containers to read-based collections (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7436\"\u003e#7436\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/2144213c307691710c9d665700860fc4993c3035\"\u003e\u003ccode\u003e2144213\u003c/code\u003e\u003c/a\u003e Constrain Response.reason to str (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7437\"\u003e#7437\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/6404f345e562d962abe6700a1c357ec1e7e18232\"\u003e\u003ccode\u003e6404f34\u003c/code\u003e\u003c/a\u003e Fix \u003ccode\u003eprepare_body\u003c/code\u003e stream detection for \u003ccode\u003e__getattr__\u003c/code\u003e-based file wrappers (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7\"\u003e#7\u003c/a\u003e...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/0b401c76b6e80a4eecf3c690085b2553f6e261ca\"\u003e\u003ccode\u003e0b401c7\u003c/code\u003e\u003c/a\u003e v2.34.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/86b378d3f60f828daa13ca50aa82e287ff7b66b4\"\u003e\u003ccode\u003e86b378d\u003c/code\u003e\u003c/a\u003e Align Session.get parameters with requests.get (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7429\"\u003e#7429\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/a4f9a5999bdb9bf2d6e7c8aa973b28cacb17134f\"\u003e\u003ccode\u003ea4f9a59\u003c/code\u003e\u003c/a\u003e Port bpo-39057 to Requests (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7427\"\u003e#7427\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/psf/requests/compare/v2.32.3...v2.34.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `tqdm` from 4.67.3 to 4.70.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/tqdm/tqdm/releases\"\u003etqdm's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003etqdm v4.70.1 stable\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003econtrib.concurrent\u003c/code\u003e: fix no-len iterables (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1830\"\u003e#1830\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1828\"\u003e#1828\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003etests: major overhaul (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1819\"\u003e#1819\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eupdate AI policy in PR template\u003c/li\u003e\n\u003cli\u003emisc lint \u0026amp; tidy\u003c/li\u003e\n\u003cli\u003eCI: bump workflow actions \u0026amp; pre-commit hooks\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003etqdm v4.70.0 stable\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003econtrib.concurrent\u003c/code\u003e: major improvements\n\u003cul\u003e\n\u003cli\u003esupport \u003ccode\u003eprocess_map(mp_context, max_tasks_per_child)\u003c/code\u003e, \u003ccode\u003ethread_map(thread_name_prefix)\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1265\"\u003e#1265\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix \u003ccode\u003etotal\u003c/code\u003e based on shortest iterable length (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1473\"\u003e#1473\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003euse default \u003ccode\u003emax_workers\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1543\"\u003e#1543\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1530\"\u003e#1530\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1518\"\u003e#1518\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003esupport \u003ccode\u003etimeout\u003c/code\u003e, \u003ccode\u003ebuffersize\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1576\"\u003e#1576\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eimprove ETA (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1708\"\u003e#1708\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1161\"\u003e#1161\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eupdate \u003ccode\u003eas_completed\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1709\"\u003e#1709\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1565\"\u003e#1565\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eadd \u003ccode\u003etqdm.concurrent.intepreter_map\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1777\"\u003e#1777\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003easyncio\u003c/code\u003e: support iterables with only \u003ccode\u003e__aiter__\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1714\"\u003e#1714\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1686\"\u003e#1686\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003esupport \u003ccode\u003ereset(float(\u0026quot;inf\u0026quot;))\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1783\"\u003e#1783\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1781\"\u003e#1781\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/651\"\u003e#651\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eframework: test \u0026amp; reduce wheel size (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1782\"\u003e#1782\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003etqdm v4.69.1 stable\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003econtrib.logging\u003c/code\u003e: preserve filters (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1775\"\u003e#1775\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1581\"\u003e#1581\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003erich\u003c/code\u003e: misc fixes (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1773\"\u003e#1773\u003c/a\u003e)\n\u003cul\u003e\n\u003cli\u003esupport generators (without \u003ccode\u003elen\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1391\"\u003e#1391\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix potential \u003ccode\u003eAttributeError\u003c/code\u003e on exit (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1674\"\u003e#1674\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003efix \u003ccode\u003etotal=float('inf')\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1781\"\u003e#1781\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/651\"\u003e#651\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix potential \u003ccode\u003eAttributeError\u003c/code\u003e on exit (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1778\"\u003e#1778\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1668\"\u003e#1668\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1537\"\u003e#1537\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/261\"\u003e#261\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix minor docs typos (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1780\"\u003e#1780\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1746\"\u003e#1746\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003etqdm v4.69.0 stable\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eadd \u003ccode\u003etqdm.asyncio.gather(..., return_exceptions=False)\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1776\"\u003e#1776\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1671\"\u003e#1671\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1286\"\u003e#1286\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003emisc minor framework updates\n\u003cul\u003e\n\u003cli\u003ebump workflow actions \u0026amp; pre-commit hooks\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003etqdm v4.68.4 stable\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003etrim to \u003ccode\u003encols\u003c/code\u003e even when \u003ccode\u003e'{bar}' not in bar_format\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1717\"\u003e#1717\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1767\"\u003e#1767\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1658\"\u003e#1658\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix \u003ccode\u003etqdm.write\u003c/code\u003e when \u003ccode\u003estdout=None\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1768\"\u003e#1768\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1654\"\u003e#1654\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003etqdm v4.68.3 stable\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eutils\u003c/code\u003e: delay \u003ccode\u003eos.get_terminal_size\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1763\"\u003e#1763\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1760\"\u003e#1760\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eautonotebook\u003c/code\u003e: support QtConsole, Spyder, JupyterLite (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1763\"\u003e#1763\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1628\"\u003e#1628\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1559\"\u003e#1559\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1283\"\u003e#1283\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1098\"\u003e#1098\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/512\"\u003e#512\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eminor docs updates\n\u003cul\u003e\n\u003cli\u003efix typo (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1762\"\u003e#1762\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003euse \u003ccode\u003egit-fame\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003emisc minor framework updates\n\u003cul\u003e\n\u003cli\u003efix \u0026amp; update CI build\u003c/li\u003e\n\u003cli\u003epre-commit: add docs \u0026amp; metadata generation\u003c/li\u003e\n\u003cli\u003emove \u003ccode\u003etox.ini\u003c/code\u003e -\u0026gt; \u003ccode\u003epyproject.toml\u003c/code\u003e, move \u003ccode\u003etox-gh-actions\u003c/code\u003e -\u0026gt; \u003ccode\u003etox-gh\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eadd Python 3.14, drop 3.7 support\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/9cf5a12b1f955468a17f0ba3c59092b23e4258ac\"\u003e\u003ccode\u003e9cf5a12\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1830\"\u003e#1830\u003c/a\u003e from eaubin/master\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/24b9e1e08a097f1c30f2d235b63f9eb25ba47974\"\u003e\u003ccode\u003e24b9e1e\u003c/code\u003e\u003c/a\u003e misc tidy\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/2a9e4e82ddba07c5dd6d126e23a4745b76ea49c8\"\u003e\u003ccode\u003e2a9e4e8\u003c/code\u003e\u003c/a\u003e contrib.concurrent: fix no-len iterables\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/8d6ff8de5a9066de77d0a9df3e80a022a3dcf146\"\u003e\u003ccode\u003e8d6ff8d\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1819\"\u003e#1819\u003c/a\u003e from tqdm/devel\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/bed379609c2c8300671c784c8f85a185c8cf6fb3\"\u003e\u003ccode\u003ebed3796\u003c/code\u003e\u003c/a\u003e tests: major overhaul\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/4d3d3194d5467e0701bc0f4b836a735273ef0868\"\u003e\u003ccode\u003e4d3d319\u003c/code\u003e\u003c/a\u003e AI policy\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/5dcb022b55553b60ed2131b64aa5bf1e65470df1\"\u003e\u003ccode\u003e5dcb022\u003c/code\u003e\u003c/a\u003e minor syntax update\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/309effe4244bf45427c5add7f1bcf33f98a7b421\"\u003e\u003ccode\u003e309effe\u003c/code\u003e\u003c/a\u003e tests: pre-commit coverage\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/604193aa03b5f5c0ad5f3d441951f0fbb515f1e4\"\u003e\u003ccode\u003e604193a\u003c/code\u003e\u003c/a\u003e tests: slight tidy\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/17f1cac07c89943eb0e6082875b3821205308d4f\"\u003e\u003ccode\u003e17f1cac\u003c/code\u003e\u003c/a\u003e CI: bump workflow actions\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/tqdm/tqdm/compare/v4.67.3...v4.70.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `transformers` from 5.5.3 to 5.17.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/huggingface/transformers/releases\"\u003etransformers's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eRelease 5.17.0\u003c/h2\u003e\n\u003ch1\u003eRelease v5.17.0\u003c/h1\u003e\n\u003ch2\u003eNew Model additions\u003c/h2\u003e\n\u003ch3\u003eHYV4\u003c/h3\u003e\n\n\u003cp\u003eHy4-Preview is a 780B-parameter mixture-of-experts language model that activates 49B parameters per\ntoken. Each MoE layer holds 256 routed experts plus one always-active shared expert and routes every\ntoken to 8 of them. The context window is 1M tokens.\u003c/p\u003e\n\u003cp\u003eThe architecture combines four features:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eMulti-head Latent Attention (MLA)\u003c/strong\u003e compresses keys and values into a low-rank latent\n(\u003ccode\u003ekv_lora_rank\u003c/code\u003e) that \u003ccode\u003ekv_b_proj\u003c/code\u003e expands back to one key/value per query head.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eDeepSeek Sparse Attention (DSA)\u003c/strong\u003e selects \u003ccode\u003eindex_topk\u003c/code\u003e keys per query with a lightweight indexer.\nFollowing \u003ca href=\"https://huggingface.co/papers/2603.12201\"\u003eIndexShare\u003c/a\u003e, only the layers marked \u003ccode\u003e\u0026quot;full\u0026quot;\u003c/code\u003e\nin \u003ccode\u003eindexer_types\u003c/code\u003e run an indexer; \u003ccode\u003e\u0026quot;shared\u0026quot;\u003c/code\u003e layers reuse the previous full layer's selection.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eGated MLA with learnable attention sinks\u003c/strong\u003e, where each head owns a sink logit that participates\nin the softmax and contributes no value, as in \u003ca href=\"https://github.com/huggingface/transformers/blob/HEAD/gpt_oss\"\u003eGPT-OSS\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eIndependent Hyper-Connections (iHC)\u003c/strong\u003e replace the plain residual path with \u003ccode\u003ehc_mult\u003c/code\u003e parallel\nresidual streams that are collapsed before, and redistributed after, every sublayer.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThe implementation does not execute the multi-token prediction (MTP) layers. Released checkpoints\nkeep those weights so that other runtimes can use them for speculative decoding; they are ignored\nat load time.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/hy_v4\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAdd h4 (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48473\"\u003e#48473\u003c/a\u003e) by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/transformers/pull/48473\"\u003e#48473\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eVibeVoice\u003c/h3\u003e\n\n\u003cp\u003e\u003ca href=\"https://huggingface.co/papers/2508.19205\"\u003eVibeVoice\u003c/a\u003e is a novel framework for synthesizing high-fidelity, long-form speech with multiple speakers by employing a next-token diffusion approach within a Large Language Model (LLM) structure. It's designed to capture the authentic conversational \u0026quot;vibe\u0026quot; and is particularly suited for generating audio content like podcasts and multi-participant audiobooks.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/vibevoice\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eImplement VibeVoice  (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/40546\"\u003e#40546\u003c/a\u003e) by \u003ca href=\"https://github.com/pengzhiliang\"\u003e\u003ccode\u003e@​pengzhiliang\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/transformers/pull/40546\"\u003e#40546\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eNeoMME\u003c/h3\u003e\n\u003cp\u003eNeoMME is a family of efficient 260M and 800M parameter multimodal-native multilingual foundation encoders from H Company. It processes multilingual text tokens and raw image patches in a single bidirectional Transformer encoder, without a separately pretrained vision tower or causal language model.\u003c/p\u003e\n\u003cp\u003eNeoMME-Retriever is a model fine-tuned from the NeoMME backbone for visual document retrieval with joint late-interaction and dense objectives. It takes text queries and documents (text or page screenshots) and produces multi-vector embeddings for MeanMaxSim scoring (late-interaction) and mean-pooled embeddings for cosine similarity (dense).\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/neomme\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/856157a2f3e9594954310df18fdccc31ffddebe9\"\u003e\u003ccode\u003e856157a\u003c/code\u003e\u003c/a\u003e v5.17.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/5b7dcb0d36c242d8d85920a81c564ef3a86ca6dd\"\u003e\u003ccode\u003e5b7dcb0\u003c/code\u003e\u003c/a\u003e MRoPE continued (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48594\"\u003e#48594\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/50bbcc630ed1675d15d2def3877c88d6c2630415\"\u003e\u003ccode\u003e50bbcc6\u003c/code\u003e\u003c/a\u003e [fix] Update stale expected strings in HunYuanVL integration tests (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48646\"\u003e#48646\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/e8bcd79c4c77a529bc34d6e19f7d718164b7fa6a\"\u003e\u003ccode\u003ee8bcd79\u003c/code\u003e\u003c/a\u003e [Quantizaiton]support 5/6/7 bits in AutoRound (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48481\"\u003e#48481\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/3283d5f78ed6836d39430c8190a6e0500be78698\"\u003e\u003ccode\u003e3283d5f\u003c/code\u003e\u003c/a\u003e [fix] Update stale golden values and fix expected_logits shape in FlavaForPre...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/5f47b5aad791b69dff597b903614fb2bef8b88a1\"\u003e\u003ccode\u003e5f47b5a\u003c/code\u003e\u003c/a\u003e [tests] Fix integration test golden values broken by fast image processor def...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/fc501343edfccdc840eb8594a6cafa8185c2de53\"\u003e\u003ccode\u003efc50134\u003c/code\u003e\u003c/a\u003e Add Fun-ASR-Nano model (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46180\"\u003e#46180\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/d9fe823d1cedbba33dd0aeef08f773abe971688e\"\u003e\u003ccode\u003ed9fe823\u003c/code\u003e\u003c/a\u003e Fix YOLOS device mismatch with device_map=\u0026quot;auto\u0026quot; (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46886\"\u003e#46886\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/cbc1651a032b923da7f4b44b3d0e6f68e6ba6b55\"\u003e\u003ccode\u003ecbc1651\u003c/code\u003e\u003c/a\u003e [\u003ccode\u003eGenerate\u003c/code\u003e] Avoid unconditionally downloading remote hub file (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48620\"\u003e#48620\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/bd05a4b2baf8b37b8f64c0c2c70d2628583f7c2a\"\u003e\u003ccode\u003ebd05a4b\u003c/code\u003e\u003c/a\u003e Honor \u003ccode\u003eshift_labels\u003c/code\u003e in decoder-only LLM/VLM losses (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48493\"\u003e#48493\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/huggingface/transformers/compare/v5.5.3...v5.17.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `tokenizers` from 0.22.2 to 0.23.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/huggingface/tokenizers/releases\"\u003etokenizers's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev0.23.2\u003c/h2\u003e\n\u003cp\u003eThis is the last v0 release, we are moving to v1!!\u003c/p\u003e\n\u003cp\u003eMore details coming soon 👀\u003c/p\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate daachorse from 1.0.1 to 3.0.0 by \u003ca href=\"https://github.com/musicinmybrain\"\u003e\u003ccode\u003e@​musicinmybrain\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2050\"\u003ehuggingface/tokenizers#2050\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eCi test fixes by \u003ca href=\"https://github.com/sebpop\"\u003e\u003ccode\u003e@​sebpop\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2079\"\u003ehuggingface/tokenizers#2079\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAvoid full vocab clone in get_vocab_size() by \u003ca href=\"https://github.com/eunseo9311\"\u003e\u003ccode\u003e@​eunseo9311\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2074\"\u003ehuggingface/tokenizers#2074\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: pin benchmark jobs to a larger dedicated runner by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2084\"\u003ehuggingface/tokenizers#2084\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: target benchmark runners by group, not nonexistent label by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2090\"\u003ehuggingface/tokenizers#2090\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBindings: acquire model read-lock once per call instead of per pre-token by \u003ca href=\"https://github.com/sebpop\"\u003e\u003ccode\u003e@​sebpop\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2072\"\u003ehuggingface/tokenizers#2072\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: split audit in a separate job by \u003ca href=\"https://github.com/SBrandeis\"\u003e\u003ccode\u003e@​SBrandeis\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2103\"\u003ehuggingface/tokenizers#2103\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: install libcairo on benchmark runners by \u003ca href=\"https://github.com/SBrandeis\"\u003e\u003ccode\u003e@​SBrandeis\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2100\"\u003ehuggingface/tokenizers#2100\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(ci): enable npm's trusted publisher for releases by \u003ca href=\"https://github.com/McPatate\"\u003e\u003ccode\u003e@​McPatate\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2111\"\u003ehuggingface/tokenizers#2111\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: bump pyo3 to version 0.29 by \u003ca href=\"https://github.com/SBrandeis\"\u003e\u003ccode\u003e@​SBrandeis\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2115\"\u003ehuggingface/tokenizers#2115\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eperf: add benchmarks for the \u003ccode\u003edecode\u003c/code\u003e API by \u003ca href=\"https://github.com/SBrandeis\"\u003e\u003ccode\u003e@​SBrandeis\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2099\"\u003ehuggingface/tokenizers#2099\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: cache HF test data and authenticate Hub downloads to avoid rate limits by \u003ca href=\"https://github.com/SBrandeis\"\u003e\u003ccode\u003e@​SBrandeis\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2102\"\u003ehuggingface/tokenizers#2102\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eImplementing Parity-aware BPE by \u003ca href=\"https://github.com/cimeister\"\u003e\u003ccode\u003e@​cimeister\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/1974\"\u003ehuggingface/tokenizers#1974\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eMake doc builds faster by \u003ca href=\"https://github.com/mishig25\"\u003e\u003ccode\u003e@​mishig25\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2158\"\u003ehuggingface/tokenizers#2158\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(deps-dev): bump websocket-driver from 0.7.4 to 0.7.5 in /tokenizers/examples/unstable_wasm/www by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2208\"\u003ehuggingface/tokenizers#2208\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(deps-dev): bump shell-quote from 1.8.3 to 1.10.0 in /tokenizers/examples/unstable_wasm/www by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2244\"\u003ehuggingface/tokenizers#2244\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: remove stale examples (kills 50% of dependabot traffic) by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2285\"\u003ehuggingface/tokenizers#2285\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(node): drop 8 unused devDependencies by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2286\"\u003ehuggingface/tokenizers#2286\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: pin every action to one SHA, drop stale audit suppressions by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2291\"\u003ehuggingface/tokenizers#2291\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(node): take node security alerts from 33 to 0 by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2287\"\u003ehuggingface/tokenizers#2287\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(python): pin the ruff rule set so a ruff release can't redden main by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2292\"\u003ehuggingface/tokenizers#2292\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd a ParityBpeTrainer example and list it in the trainers API docs by \u003ca href=\"https://github.com/cimeister\"\u003e\u003ccode\u003e@​cimeister\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2217\"\u003ehuggingface/tokenizers#2217\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eunseo9311\"\u003e\u003ccode\u003e@​eunseo9311\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2074\"\u003ehuggingface/tokenizers#2074\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cimeister\"\u003e\u003ccode\u003e@​cimeister\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/1974\"\u003ehuggingface/tokenizers#1974\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/huggingface/tokenizers/compare/v0.23.1...v0.23.2\"\u003ehttps://github.com/huggingface/tokenizers/compare/v0.23.1...v0.23.2\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eRelease v0.23.1\u003c/h2\u003e\n\u003ch2\u003eTL;DR\u003c/h2\u003e\n\u003cp\u003e\u003ccode\u003etokenizers 0.23.1\u003c/code\u003e is the first proper stable release in the \u003ccode\u003e0.23\u003c/code\u003e line — \u003ccode\u003e0.23.0\u003c/code\u003e only ever shipped as \u003ccode\u003erc0\u003c/code\u003e because the release pipeline itself was broken (Node side hadn't shipped multi-platform binaries since 2023, Python side was on \u003ccode\u003epyo3 0.27\u003c/code\u003e without free-threaded support). \u003ccode\u003e0.23.1\u003c/code\u003e is the version where everything actually goes out the door together: full Node multi-platform wheels for the first time in years, Python 3.14 (regular \u003cstrong\u003eand\u003c/strong\u003e free-threaded \u003ccode\u003e3.14t\u003c/code\u003e), full type hints for every Python class, and a stack of measurable perf wins on the BPE / added-vocab hot paths.\u003c/p\u003e\n\u003cp\u003eThere is no functional \u003ccode\u003e0.23.0\u003c/code\u003e published — we tag \u003ccode\u003e0.23.1\u003c/code\u003e directly so users don't accidentally pull a never-shipped version.\u003c/p\u003e\n\u003chr /\u003e\n\u003ch2\u003e🚨 Breaking changes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eDrop Python 3.9\u003c/strong\u003e (\u003ca href=\"https://redirect.github.com/huggingface/tokenizers/issues/1952\"\u003e#1952\u003c/a\u003e) — \u003ccode\u003erequires-python = \u0026quot;\u0026gt;=3.10\u0026quot;\u003c/code\u003e; 3.9 users stay on \u003ccode\u003e0.22.x\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ccode\u003eadd_tokens\u003c/code\u003e normalizes \u003ccode\u003econtent\u003c/code\u003e at insertion\u003c/strong\u003e (\u003ca href=\"https://redirect.github.com/huggingface/tokenizers/issues/1995\"\u003e#1995\u003c/a\u003e) — re-saved \u003ccode\u003etokenizer.json\u003c/code\u003e may differ in the \u003ccode\u003eadded_tokens\u003c/code\u003e block. Existing files load unchanged.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eType stubs are precise\u003c/strong\u003e (\u003ca href=\"https://redirect.github.com/huggingface/tokenizers/issues/1928\"\u003e#1928\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/issues/1997\"\u003e#1997\u003c/a\u003e) — methods that returned \u003ccode\u003eAny\u003c/code\u003e now return real types; \u003ccode\u003emypy --strict\u003c/code\u003e may surface previously-hidden errors. Stub layout also moved from \u003ccode\u003etokenizers/\u0026lt;sub\u0026gt;/__init__.pyi\u003c/code\u003e to \u003ccode\u003etokenizers/\u0026lt;sub\u0026gt;.pyi\u003c/code\u003e. This breaks the surface of some of the processors like \u003ccode\u003eRobertaProcessign\u003c/code\u003e's \u003ccode\u003e__init__\u003c/code\u003e .\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e3.14t-only\u003c/strong\u003e: setters/getters return \u003ccode\u003ePyResult\u0026lt;T\u0026gt;\u003c/code\u003e because of \u003ccode\u003eArc\u0026lt;RwLock\u0026lt;Tokenizer\u0026gt;\u0026gt;\u003c/code\u003e; a poisoned lock surfaces as \u003ccode\u003ePyException\u003c/code\u003e instead of a panic.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/tokenizers/commit/88a4498ad4ea1a9487b0a9b0ff881383fd5a06a3\"\u003e\u003ccode\u003e88a4498\u003c/code\u003e\u003c/a\u003e add lock\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/tokenizers/commit/e4ea65f27057e593656ff1335b95afe2e552b88d\"\u003e\u003ccode\u003ee4ea65f\u003c/code\u003e\u003c/a\u003e real release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/tokenizers/commit/7c5964b4afae7b710d254eacd5a9fa180ba2cfef\"\u003e\u003ccode\u003e7c5964b\u003c/code\u003e\u003c/a\u003e add lock\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/tokenizers/commit/bc405ad60991a0639f8b09b40f13f91c38e50e87\"\u003e\u003ccode\u003ebc405ad\u003c/code\u003e\u003c/a\u003e push rc0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/tokenizers/commit/d5827816baedcbf1cb5b452dea8048150b6872df\"\u003e\u003ccode\u003ed582781\u003c/code\u003e\u003c/a\u003e Add a ParityBpeTrainer example and list it in the trainers API docs (\u003ca href=\"https://redirect.github.com/huggingface/tokenizers/issues/2217\"\u003e#2217\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/tokenizers/commit/447890f84deab25794ccfdee2a877901b6893569\"\u003e\u003ccode\u003e447890f\u003c/code\u003e\u003c/a\u003e fix(python): pin the ruff rule set so a ruff release can't redden main (\u003ca href=\"https://redirect.github.com/huggingface/tokenizers/issues/2292\"\u003e#2292\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/tokenizers/commit/68b3ab7788b58408f37a3dc73eeabf2417d14c22\"\u003e\u003ccode\u003e68b3ab7\u003c/code\u003e\u003c/a\u003e chore(node): take node security alerts from 33 to 0 (\u003ca href=\"https://redirect.github.com/huggingface/tokenizers/issues/2287\"\u003e#2287\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/tokenizers/commit/74ef81f64e6d1cd4979c56d7d75f3ce21ba11992\"\u003e\u003ccode\u003e74ef81f\u003c/code\u003e\u003c/a\u003e ci: pin every action to one SHA, drop stale audit suppressions (\u003ca href=\"https://redirect.github.com/huggingface/tokenizers/issues/2291\"\u003e#2291\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/tokenizers/commit/b26727f1a92cdf727cd965fc1c467a7c77c63aae\"\u003e\u003ccode\u003eb26727f\u003c/code\u003e\u003c/a\u003e chore(node): drop 8 unused devDependencies (\u003ca href=\"https://redirect.github.com/huggingface/tokenizers/issues/2286\"\u003e#2286\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/tokenizers/commit/7c7cfd838fb79e76aaba6b0931898073a784fb2a\"\u003e\u003ccode\u003e7c7cfd8\u003c/code\u003e\u003c/a\u003e chore: remove stale examples (kills 50% of dependabot traffic) (\u003ca href=\"https://redirect.github.com/huggingface/tokenizers/issues/2285\"\u003e#2285\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/huggingface/tokenizers/compare/v0.22.2...v0.23.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `safetensors` from 0.7.0 to 0.8.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/huggingface/safetensors/releases\"\u003esafetensors's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev0.8.0\u003c/h2\u003e\n\u003ch2\u003eNews\u003c/h2\u003e\n\u003cp\u003esafetensors joins the PyTorch foundation!\u003c/p\u003e\n\n\u003cp\u003eRead more on that: \u003ca href=\"https://huggingface.co/blog/safetensors-joins-pytorch-foundation\"\u003ehttps://huggingface.co/blog/safetensors-joins-pytorch-foundation\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eWhat's changed\u003c/h2\u003e\n\u003cp\u003eSafetensors 0.8.0 brings direct to Metal loading on Apple Silicon, GIL-free serialization, broader hardware and dtype coverage, and a stronger Python API.\u003c/p\u003e\n\u003ch3\u003eBreaking\u003c/h3\u003e\n\u003cp\u003eThe \u003ccode\u003eserialize\u003c/code\u003e and \u003ccode\u003eserialize_file\u003c/code\u003e functions now release the GIL during writes, enabling true multithreaded saves from Python. Their input contract has also changed: tensor metadata is now passed via a \u003ccode\u003eTensorSpec\u003c/code\u003e class (exported from safetensors) instead of plain dicts, making API more explicit and robust to misinputs. This is a breaking change for anyone calling the low-level \u003ccode\u003eserialize\u003c/code\u003e / \u003ccode\u003eserialize_file\u003c/code\u003e API directly; the high-level wrappers (\u003ccode\u003esafetensors.torch\u003c/code\u003e, \u003ccode\u003esafetensors.numpy\u003c/code\u003e, \u003ccode\u003esafetensors.paddle\u003c/code\u003e) are updated internally and their public API is unchanged.\u003c/p\u003e\n\u003cp\u003eThe minimum supported Python version is now 3.10 (was 3.9). Python 3.9 reached end-of-life in October 2025.\u003c/p\u003e\n\u003cp\u003e\u003ccode\u003eTensorIndexer::Narrow\u003c/code\u003e now carries a \u003ccode\u003estep: NonZeroUsize\u003c/code\u003e parameter, so a slice is now \u003ccode\u003estart:stop:step\u003c/code\u003e. This is a fix as this silent error was hidden behind the \u003ccode\u003eStorage::Torch\u003c/code\u003e variant which offloaded slicing logic to torch directly.\u003c/p\u003e\n\u003ch3\u003eCI\u003c/h3\u003e\n\u003cp\u003eOn the platform side, this release adds Windows ARM64 wheel builds, riscv64 Linux wheels, and CI has been hardened with pinned GitHub Actions SHAs.\u003c/p\u003e\n\u003cp\u003eAlso dropped the anaconda CI we had as there's already an automatic tracker via conda-forge.\u003c/p\u003e\n\u003ch3\u003eNew features\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eDirect MPS load on Apple Silicon: tensors are directly loaded in an \u003ccode\u003eMTLBuffer\u003c/code\u003e and handed to the frameworks that support it (only torch atm) via DLPack, skipping needless copies.\u003c/li\u003e\n\u003cli\u003eNew \u003ccode\u003ebackend\u003c/code\u003e parameter introduced, for the addition of the \u003ccode\u003epread\u003c/code\u003e backend. We now support loading files via \u003ccode\u003epread(2)\u003c/code\u003e syscall instead of just mmap. Useful for specific archs/platforms.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eget_slice\u003c/code\u003e now handles ellipsis \u003ccode\u003e[...]\u003c/code\u003e and strided slices \u003ccode\u003e[:, ::8]\u003c/code\u003e wherever safetensors does the slicing itself (\u003ccode\u003epread\u003c/code\u003e for any framework, MPS, and \u003ccode\u003emmap\u003c/code\u003e outside torch/paddle), which silently dropped the step or rejected \u003ccode\u003e...\u003c/code\u003e before.\u003c/li\u003e\n\u003cli\u003eMUSA device support for MooreThreads GPUs.\u003c/li\u003e\n\u003cli\u003eNew dtype support includes \u003ccode\u003efloat8_e4m3fnuz\u003c/code\u003e and \u003ccode\u003efloat8_e5m2fnuz\u003c/code\u003e (AMD FNUZ FP8 formats).\u003c/li\u003e\n\u003cli\u003eThe reader is now explicitly lenient about leading whitespace in the JSON header, which keeps the door open for future page-aligned writes.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eImprovements/perf\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFile writes on macOS now use \u003ccode\u003eF_NOCACHE\u003c/code\u003e for direct I/O, yielding roughly 30% faster \u003ccode\u003esave_file\u003c/code\u003e on Apple Silicon.\u003c/li\u003e\n\u003cli\u003eThe packaging dependency has been dropped from the \u003ccode\u003e[torch]\u003c/code\u003e extra, replaced by a simple \u003ccode\u003ehasattr\u003c/code\u003e probe for efficiency.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd arm64 windows support by \u003ca href=\"https://github.com/finnagin\"\u003e\u003ccode\u003e@​finnagin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/safetensors/safetensors/pull/678\"\u003esafetensors/safetensors#678\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(backend): support musa backend for MooreThreads GPU by \u003ca href=\"https://github.com/caizhi-mt\"\u003e\u003ccode\u003e@​caizhi-mt\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/safetensors/safetensors/pull/671\"\u003esafetensors/safetensors#671\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eadd gil free serialize_file(serialize_file_threadable) by \u003ca href=\"https://github.com/TomQunChao\"\u003e\u003ccode\u003e@​TomQunChao\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/safetensors/safetensors/pull/679\"\u003esafetensors/safetensors#679\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003erefactor: remove outdated comment by \u003ca href=\"https://github.com/McPatate\"\u003e\u003ccode\u003e@​McPatate\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/safetensors/safetensors/pull/685\"\u003esafetensors/safetensors#685\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat: add direct io write fast path on macos by \u003ca href=\"https://github.com/McPatate\"\u003e\u003ccode\u003e@​McPatate\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/safetensors/safetensors/pull/687\"\u003esafetensors/safetensors#687\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: keep dropped reference to tensor moved from gpu to cpu by \u003ca href=\"https://github.com/McPatate\"\u003e\u003ccode\u003e@​McPatate\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/safetensors/safetensors/pull/689\"\u003esafetensors/safetensors#689\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat: bump torch to \u003ccode\u003e2.4\u003c/code\u003e by \u003ca href=\"https://github.com/McPatate\"\u003e\u003ccode\u003e@​McPatate\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/safetensors/safetensors/pull/710\"\u003esafetensors/safetensors#710\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eContribution guide security by \u003ca href=\"https://github.com/LysandreJik\"\u003e\u003ccode\u003e@​LysandreJik\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/safetensors/safetensors/pull/712\"\u003esafetensors/safetensors#712\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/safetensors/safetensors/blob/main/RELEASE.md\"\u003esafetensors's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e0.8.0-dev.0 → 0.8.0\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003e\nUpdate lockfiles again:\n\u003cpre lang=\"bash\"\u003e\u003ccode\u003ecargo check\ncd bindings/python \u0026amp;amp;\u0026amp;amp; uv lock\n\u0026lt;/code\u0026gt;\u0026lt;/pre\u0026gt;\n\u0026lt;p\u0026gt;Commit:\u0026lt;/p\u0026gt;\n\u0026lt;pre\u0026gt;\u0026lt;code\u0026gt;Set version to 0.8.0\n\u0026lt;/code\u0026gt;\u0026lt;/pre\u0026gt;\n\u0026lt;p\u0026gt;The Python version is not set in \u0026lt;code\u0026gt;pyproject.toml\u0026lt;/code\u0026gt; directly — maturin reads it from \u0026lt;code\u0026gt;bindings/python/Cargo.toml\u0026lt;/code\u0026gt; at build time.\u0026lt;/p\u0026gt;\n\u0026lt;h3\u0026gt;4. Create the release on GitHub\u0026lt;/h3\u0026gt;\n\u0026lt;p\u0026gt;Go to the \u0026lt;a href=\u0026quot;https://github.com/huggingface/safetensors/releases\u0026quot;\u0026gt;GitHub Releases page\u0026lt;/a\u0026gt; and draft a new release:\u0026lt;/p\u0026gt;\n\u0026lt;ul\u0026gt;\n\u0026lt;li\u0026gt;\u0026lt;strong\u0026gt;Choose the release branch\u0026lt;/strong\u0026gt; (e.g. \u0026lt;code\u0026gt;git_v0.8.0\u0026lt;/code\u0026gt;)\u0026lt;/li\u0026gt;\n\u0026lt;li\u0026gt;\u0026lt;strong\u0026gt;Create a new tag\u0026lt;/strong\u0026gt; on publish: \u0026lt;code\u0026gt;v0.8.0\u0026lt;/code\u0026gt;\u0026lt;/li\u0026gt;\n\u0026lt;li\u0026gt;\u0026lt;strong\u0026gt;Generate release notes\u0026lt;/strong\u0026gt; from the previous tag (e.g. \u0026lt;code\u0026gt;v0.7.0\u0026lt;/code\u0026gt;)\u0026lt;/li\u0026gt;\n\u0026lt;li\u0026gt;Add any notable highlights at the top of the generated notes\u0026lt;/li\u0026gt;\n\u0026lt;/ul\u0026gt;\n\u0026lt;p\u0026gt;Structure for manual notes:\u0026lt;/p\u0026gt;\n\u0026lt;pre lang=\u0026quot;markdown\u0026quot;\u0026gt;...\n\n_Description has been truncated_","html_url":"https://github.com/KASW-UI/cpu-vllm/pull/20","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/KASW-UI%2Fcpu-vllm/issues/20","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/20/packages"},{"uuid":"5560786429","node_id":"PR_kwDOUUQI988AAAABE1thtw","number":2,"state":"closed","title":"chore(deps): Bump aiohttp from 3.13.5 to 3.14.3","user":"dependabot[bot]","labels":["dependencies","python:uv"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":"2026-09-25T22:44:18.000Z","author_association":null,"state_reason":null,"created_at":"2026-09-23T23:26:38.000Z","updated_at":"2026-09-25T22:44:22.000Z","time_to_close":170260,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps): Bump","packages":[{"name":"aiohttp","old_version":"3.13.5","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"}],"path":null,"ecosystem":"pip"},"body":"Bumps [aiohttp](https://github.com/aio-libs/aiohttp) from 3.13.5 to 3.14.3.","html_url":"https://github.com/CitrateNetwork/citrate-sdk-python/pull/2","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/CitrateNetwork%2Fcitrate-sdk-python/issues/2","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/2/packages"},{"uuid":"5536027477","node_id":"PR_kwDONC03Hc8AAAABEiBuuw","number":4260,"state":"open","title":"build(deps): bump the python group with 85 updates","user":"dependabot[bot]","labels":["backport:skip","dependencies","python:uv","first-time-contributor"],"assignees":[],"locked":false,"comments_count":3,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-22T06:23:30.000Z","updated_at":"2026-09-22T06:33:34.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"build(deps): bump","group_name":"python","update_count":85,"packages":[{"name":"pin-pink","old_version":"4.3.0","new_version":"4.4.0","repository_url":"https://github.com/stephane-caron/pink"},{"name":"reactivex","old_version":"4.1.0","new_version":"5.1.0","repository_url":"https://github.com/ReactiveX/RxPY"},{"name":"pydantic","old_version":"2.12.5","new_version":"2.13.5","repository_url":"https://github.com/pydantic/pydantic"},{"name":"python-dotenv","old_version":"1.2.2","new_version":"1.2.3","repository_url":"https://github.com/theskumar/python-dotenv"},{"name":"packaging","old_version":"25.0","new_version":"26.3","repository_url":"https://github.com/pypa/packaging"},{"name":"filelock","old_version":"3.23.0","new_version":"3.32.6","repository_url":"https://github.com/tox-dev/py-filelock"},{"name":"plum-dispatch","old_version":"2.5.7","new_version":"2.10.1","repository_url":"https://github.com/beartype/plum"},{"name":"gitpython","old_version":"3.1.52","new_version":"3.1.62","repository_url":"https://github.com/gitpython-developers/GitPython"},{"name":"structlog","old_version":"25.5.0","new_version":"26.1.0","repository_url":"https://github.com/hynek/structlog"},{"name":"opencv-contrib-python","old_version":"4.13.0.92","new_version":"5.0.0.93","repository_url":"https://github.com/opencv/opencv-python"},{"name":"pydantic-settings","old_version":"2.12.0","new_version":"2.15.0","repository_url":"https://github.com/pydantic/pydantic-settings"},{"name":"textual","old_version":"3.7.1","new_version":"8.2.8","repository_url":"https://github.com/Textualize/textual"},{"name":"terminaltexteffects","old_version":"0.12.2","new_version":"0.15.0","repository_url":"https://github.com/ChrisBuilds/terminaltexteffects"},{"name":"typer","old_version":"0.23.1","new_version":"0.27.2","repository_url":"https://github.com/fastapi/typer"},{"name":"ipython","old_version":"8.38.0","new_version":"8.39.0","repository_url":"https://github.com/ipython/ipython"},{"name":"plotext","old_version":"5.3.2","new_version":"6.1.0","repository_url":"https://github.com/piccolomo/plotext"},{"name":"numba","old_version":"0.63.1","new_version":"0.67.0","repository_url":"https://github.com/numba/numba"},{"name":"llvmlite","old_version":"0.46.0","new_version":"0.49.0","repository_url":"https://github.com/numba/llvmlite"},{"name":"rerun-sdk","old_version":"0.32.0","new_version":"0.37.2","repository_url":"https://github.com/rerun-io/rerun"},{"name":"protobuf","old_version":"6.33.5","new_version":"7.36.1","repository_url":"https://github.com/protocolbuffers/protobuf"},{"name":"cryptography","old_version":"46.0.5","new_version":"50.0.1","repository_url":"https://github.com/pyca/cryptography"},{"name":"websocket-client","old_version":"1.9.0","new_version":"1.9.2","repository_url":"https://github.com/websocket-client/websocket-client"},{"name":"ipykernel","old_version":"7.2.0","new_version":"7.3.0","repository_url":"https://github.com/ipython/ipykernel"},{"name":"open-clip-torch","old_version":"3.2.0","new_version":"3.3.0","repository_url":"https://github.com/mlfoundations/open_clip"},{"name":"gdown","old_version":"6.0.0","new_version":"6.2.0","repository_url":"https://github.com/wkentaro/gdown"},{"name":"tensorboard","old_version":"2.20.0","new_version":"2.21.0","repository_url":"https://github.com/tensorflow/tensorboard"},{"name":"portal","old_version":"3.7.4","new_version":"3.8.1","repository_url":"https://github.com/danijar/portal"},{"name":"bosdyn-client","old_version":"5.1.4","new_version":"5.2.0","repository_url":"https://github.com/boston-dynamics/spot-sdk"},{"name":"bosdyn-api","old_version":"5.1.4","new_version":"5.2.0","repository_url":"https://github.com/boston-dynamics/spot-sdk"},{"name":"bosdyn-core","old_version":"5.1.4","new_version":"5.2.0","repository_url":"https://github.com/boston-dynamics/spot-sdk"},{"name":"pyarrow","old_version":"23.0.0","new_version":"25.0.1","repository_url":"https://github.com/apache/arrow"},{"name":"langchain-core","old_version":"1.3.3","new_version":"1.6.3","repository_url":"https://github.com/langchain-ai/langchain"},{"name":"langchain-openai","old_version":"1.1.6","new_version":"1.6.2","repository_url":"https://github.com/langchain-ai/langchain"},{"name":"langchain-huggingface","old_version":"1.2.0","new_version":"1.2.2","repository_url":"https://github.com/langchain-ai/langchain"},{"name":"langchain-ollama","old_version":"1.0.1","new_version":"1.1.0","repository_url":"https://github.com/langchain-ai/langchain"},{"name":"ollama","old_version":"0.6.1","new_version":"0.6.2","repository_url":"https://github.com/ollama/ollama-python"},{"name":"openai","old_version":"2.21.0","new_version":"3.14.0","repository_url":"https://github.com/openai/openai-python"},{"name":"sounddevice","old_version":"0.5.5","new_version":"0.5.6","repository_url":"https://github.com/spatialaudio/python-sounddevice"},{"name":"fastapi","old_version":"0.129.0","new_version":"0.141.1","repository_url":"https://github.com/fastapi/fastapi"},{"name":"python-socketio","old_version":"5.16.1","new_version":"5.17.0","repository_url":"https://github.com/sponsors/miguelgrinberg"},{"name":"python-multipart","old_version":"0.0.27","new_version":"0.0.32","repository_url":"https://github.com/Kludex/python-multipart"},{"name":"sse-starlette","old_version":"3.2.0","new_version":"3.4.11","repository_url":"https://github.com/sysid/sse-starlette"},{"name":"uvicorn","old_version":"0.40.0","new_version":"0.53.0","repository_url":"https://github.com/Kludex/uvicorn"},{"name":"soundfile","old_version":"0.13.1","new_version":"0.14.0","repository_url":"https://github.com/bastibe/python-soundfile"},{"name":"timm","old_version":"1.0.24","new_version":"1.0.29","repository_url":"https://github.com/huggingface/pytorch-image-models"},{"name":"pillow","old_version":"12.2.0","new_version":"12.3.0","repository_url":"https://github.com/python-pillow/Pillow"},{"name":"lap","old_version":"0.5.12","new_version":"0.5.13","repository_url":"https://github.com/gatagat/lap"},{"name":"transformers","old_version":"4.53.3","new_version":"5.17.0"},{"name":"moondream","old_version":"0.2.0","new_version":"2.3.0","repository_url":"https://github.com/vikhyat/moondream"},{"name":"omegaconf","old_version":"2.3.0","new_version":"2.3.1","repository_url":"https://github.com/omry/omegaconf"},{"name":"hydra-core","old_version":"1.3.2","new_version":"1.3.7","repository_url":"https://github.com/facebookresearch/hydra"},{"name":"unitree-webrtc-connect","old_version":"2.1.2","new_version":"2.2.0","repository_url":"https://github.com/legion1581/unitree_webrtc_connect"},{"name":"cyclonedds","old_version":"0.10.5","new_version":"11.0.1","repository_url":"https://github.com/eclipse-cyclonedds/cyclonedds-python"},{"name":"mcap","old_version":"1.3.1","new_version":"1.4.0","repository_url":"https://github.com/foxglove/mcap"},{"name":"piper-sdk","old_version":"0.6.1","new_version":"0.6.2","repository_url":"https://github.com/agilexrobotics/piper_sdk"},{"name":"xarm-python-sdk","old_version":"1.17.3","new_version":"1.18.4","repository_url":"https://github.com/xArm-Developer/xArm-Python-SDK"},{"name":"roboplan","old_version":"0.6.0","new_version":"0.6.1","repository_url":"https://github.com/open-planning/roboplan"},{"name":"matplotlib","old_version":"3.10.8","new_version":"3.10.9","repository_url":"https://github.com/matplotlib/matplotlib"},{"name":"cupy-cuda12x","old_version":"13.6.0","new_version":"14.2.0","repository_url":"https://github.com/cupy/cupy"},{"name":"mujoco","old_version":"3.10.0","new_version":"3.13.0","repository_url":"https://github.com/google-deepmind/mujoco"},{"name":"gtsam-extended","old_version":"4.3a1.post1","new_version":"4.3a2.post202608240418"},{"name":"aiortc","old_version":"1.14.0","new_version":"1.15.0","repository_url":"https://github.com/aiortc/aiortc"},{"name":"aiohttp","old_version":"3.14.1","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"reportlab","old_version":"4.5.0","new_version":"5.0.1"},{"name":"manifold3d","old_version":"3.5.1","new_version":"3.5.3","repository_url":"https://github.com/elalish/manifold"},{"name":"coacd","old_version":"1.0.11","new_version":"1.0.14","repository_url":"https://github.com/SarahWeiii/CoACD"},{"name":"usd-core","old_version":"26.5","new_version":"26.8","repository_url":"https://github.com/PixarAnimationStudios/OpenUSD"},{"name":"ruff","old_version":"0.14.3","new_version":"0.16.7","repository_url":"https://github.com/astral-sh/ruff"},{"name":"pytest","old_version":"8.3.5","new_version":"9.1.1","repository_url":"https://github.com/pytest-dev/pytest"},{"name":"pytest-mock","old_version":"3.15.0","new_version":"3.15.1","repository_url":"https://github.com/pytest-dev/pytest-mock"},{"name":"pytest-env","old_version":"1.1.5","new_version":"1.7.1","repository_url":"https://github.com/pytest-dev/pytest-env"},{"name":"pytest-rerunfailures","old_version":"16.4","new_version":"16.6.1","repository_url":"https://github.com/pytest-dev/pytest-rerunfailures"},{"name":"coverage","old_version":"7.13.4","new_version":"7.16.1","repository_url":"https://github.com/coveragepy/coveragepy"},{"name":"pre-commit","old_version":"4.2.0","new_version":"4.6.2","repository_url":"https://github.com/pre-commit/pre-commit"},{"name":"py-spy","old_version":"0.4.1","new_version":"0.4.2","repository_url":"https://github.com/benfred/py-spy"},{"name":"maturin","old_version":"1.13.3","new_version":"1.15.0","repository_url":"https://github.com/pyo3/maturin"},{"name":"python-lsp-server","old_version":"1.14.0","new_version":"1.15.0"},{"name":"python-lsp-ruff","old_version":"2.3.0","new_version":"2.3.4","repository_url":"https://github.com/python-lsp/python-lsp-ruff"},{"name":"playwright","old_version":"1.61.0","new_version":"1.62.0","repository_url":"https://github.com/microsoft/playwright-python"},{"name":"mypy","old_version":"1.19.0","new_version":"2.3.1","repository_url":"https://github.com/python/mypy"},{"name":"types-pyyaml","old_version":"6.0.12.20250915","new_version":"6.0.12.20260906","repository_url":"https://github.com/python/typeshed"},{"name":"types-reportlab","old_version":"4.5.0.20260509","new_version":"5.0.0.20260911","repository_url":"https://github.com/python/typeshed"},{"name":"types-requests","old_version":"2.32.4.20260107","new_version":"2.33.0.20260906","repository_url":"https://github.com/python/typeshed"},{"name":"pybind11","old_version":"3.0.4","new_version":"3.1.0","repository_url":"https://github.com/pybind/pybind11"},{"name":"optuna","old_version":"4.9.0","new_version":"5.0.0","repository_url":"https://github.com/optuna/optuna"}],"path":null,"ecosystem":"pip"},"body":"Bumps the python group with 85 updates:\n\n| Package | From | To |\n| --- | --- | --- |\n| [pin-pink](https://github.com/stephane-caron/pink) | `4.3.0` | `4.4.0` |\n| [reactivex](https://github.com/ReactiveX/RxPY) | `4.1.0` | `5.1.0` |\n| [pydantic](https://github.com/pydantic/pydantic) | `2.12.5` | `2.13.5` |\n| [python-dotenv](https://github.com/theskumar/python-dotenv) | `1.2.2` | `1.2.3` |\n| [packaging](https://github.com/pypa/packaging) | `25.0` | `26.3` |\n| [filelock](https://github.com/tox-dev/py-filelock) | `3.23.0` | `3.32.6` |\n| [plum-dispatch](https://github.com/beartype/plum) | `2.5.7` | `2.10.1` |\n| [gitpython](https://github.com/gitpython-developers/GitPython) | `3.1.52` | `3.1.62` |\n| [structlog](https://github.com/hynek/structlog) | `25.5.0` | `26.1.0` |\n| [opencv-contrib-python](https://github.com/opencv/opencv-python) | `4.13.0.92` | `5.0.0.93` |\n| [pydantic-settings](https://github.com/pydantic/pydantic-settings) | `2.12.0` | `2.15.0` |\n| [textual](https://github.com/Textualize/textual) | `3.7.1` | `8.2.8` |\n| [terminaltexteffects](https://github.com/ChrisBuilds/terminaltexteffects) | `0.12.2` | `0.15.0` |\n| [typer](https://github.com/fastapi/typer) | `0.23.1` | `0.27.2` |\n| [ipython](https://github.com/ipython/ipython) | `8.38.0` | `8.39.0` |\n| [plotext](https://github.com/piccolomo/plotext) | `5.3.2` | `6.1.0` |\n| [numba](https://github.com/numba/numba) | `0.63.1` | `0.67.0` |\n| [llvmlite](https://github.com/numba/llvmlite) | `0.46.0` | `0.49.0` |\n| [rerun-sdk](https://github.com/rerun-io/rerun) | `0.32.0` | `0.37.2` |\n| [protobuf](https://github.com/protocolbuffers/protobuf) | `6.33.5` | `7.36.1` |\n| [cryptography](https://github.com/pyca/cryptography) | `46.0.5` | `50.0.1` |\n| [websocket-client](https://github.com/websocket-client/websocket-client) | `1.9.0` | `1.9.2` |\n| [ipykernel](https://github.com/ipython/ipykernel) | `7.2.0` | `7.3.0` |\n| [open-clip-torch](https://github.com/mlfoundations/open_clip) | `3.2.0` | `3.3.0` |\n| [gdown](https://github.com/wkentaro/gdown) | `6.0.0` | `6.2.0` |\n| [tensorboard](https://github.com/tensorflow/tensorboard) | `2.20.0` | `2.21.0` |\n| [portal](https://github.com/danijar/portal) | `3.7.4` | `3.8.1` |\n| [bosdyn-client](https://github.com/boston-dynamics/spot-sdk) | `5.1.4` | `5.2.0` |\n| [bosdyn-api](https://github.com/boston-dynamics/spot-sdk) | `5.1.4` | `5.2.0` |\n| [bosdyn-core](https://github.com/boston-dynamics/spot-sdk) | `5.1.4` | `5.2.0` |\n| [pyarrow](https://github.com/apache/arrow) | `23.0.0` | `25.0.1` |\n| [langchain-core](https://github.com/langchain-ai/langchain) | `1.3.3` | `1.6.3` |\n| [langchain-openai](https://github.com/langchain-ai/langchain) | `1.1.6` | `1.6.2` |\n| [langchain-huggingface](https://github.com/langchain-ai/langchain) | `1.2.0` | `1.2.2` |\n| [langchain-ollama](https://github.com/langchain-ai/langchain) | `1.0.1` | `1.1.0` |\n| [ollama](https://github.com/ollama/ollama-python) | `0.6.1` | `0.6.2` |\n| [openai](https://github.com/openai/openai-python) | `2.21.0` | `3.14.0` |\n| [sounddevice](https://github.com/spatialaudio/python-sounddevice) | `0.5.5` | `0.5.6` |\n| [fastapi](https://github.com/fastapi/fastapi) | `0.129.0` | `0.141.1` |\n| [python-socketio](https://github.com/sponsors/miguelgrinberg) | `5.16.1` | `5.17.0` |\n| [python-multipart](https://github.com/Kludex/python-multipart) | `0.0.27` | `0.0.32` |\n| [sse-starlette](https://github.com/sysid/sse-starlette) | `3.2.0` | `3.4.11` |\n| [uvicorn](https://github.com/Kludex/uvicorn) | `0.40.0` | `0.53.0` |\n| [soundfile](https://github.com/bastibe/python-soundfile) | `0.13.1` | `0.14.0` |\n| [timm](https://github.com/huggingface/pytorch-image-models) | `1.0.24` | `1.0.29` |\n| [pillow](https://github.com/python-pillow/Pillow) | `12.2.0` | `12.3.0` |\n| [lap](https://github.com/gatagat/lap) | `0.5.12` | `0.5.13` |\n| [transformers[torch]](https://github.com/huggingface/transformers) | `4.53.3` | `5.17.0` |\n| [moondream](https://github.com/vikhyat/moondream) | `0.2.0` | `2.3.0` |\n| [omegaconf](https://github.com/omry/omegaconf) | `2.3.0` | `2.3.1` |\n| [hydra-core](https://github.com/facebookresearch/hydra) | `1.3.2` | `1.3.7` |\n| [unitree-webrtc-connect](https://github.com/legion1581/unitree_webrtc_connect) | `2.1.2` | `2.2.0` |\n| [cyclonedds](https://github.com/eclipse-cyclonedds/cyclonedds-python) | `0.10.5` | `11.0.1` |\n| [mcap](https://github.com/foxglove/mcap) | `1.3.1` | `1.4.0` |\n| [piper-sdk](https://github.com/agilexrobotics/piper_sdk) | `0.6.1` | `0.6.2` |\n| [xarm-python-sdk](https://github.com/xArm-Developer/xArm-Python-SDK) | `1.17.3` | `1.18.4` |\n| [roboplan](https://github.com/open-planning/roboplan) | `0.6.0` | `0.6.1` |\n| [matplotlib](https://github.com/matplotlib/matplotlib) | `3.10.8` | `3.10.9` |\n| [cupy-cuda12x](https://github.com/cupy/cupy) | `13.6.0` | `14.2.0` |\n| [mujoco](https://github.com/google-deepmind/mujoco) | `3.10.0` | `3.13.0` |\n| [gtsam-extended](https://gtsam.org/) | `4.3a1.post1` | `4.3a2.post202608240418` |\n| [aiortc](https://github.com/aiortc/aiortc) | `1.14.0` | `1.15.0` |\n| [aiohttp](https://github.com/aio-libs/aiohttp) | `3.14.1` | `3.14.3` |\n| [reportlab](https://www.reportlab.com/) | `4.5.0` | `5.0.1` |\n| [manifold3d](https://github.com/elalish/manifold) | `3.5.1` | `3.5.3` |\n| [coacd](https://github.com/SarahWeiii/CoACD) | `1.0.11` | `1.0.14` |\n| [usd-core](https://github.com/PixarAnimationStudios/OpenUSD) | `26.5` | `26.8` |\n| [ruff](https://github.com/astral-sh/ruff) | `0.14.3` | `0.16.7` |\n| [pytest](https://github.com/pytest-dev/pytest) | `8.3.5` | `9.1.1` |\n| [pytest-mock](https://github.com/pytest-dev/pytest-mock) | `3.15.0` | `3.15.1` |\n| [pytest-env](https://github.com/pytest-dev/pytest-env) | `1.1.5` | `1.7.1` |\n| [pytest-rerunfailures](https://github.com/pytest-dev/pytest-rerunfailures) | `16.4` | `16.6.1` |\n| [coverage](https://github.com/coveragepy/coveragepy) | `7.13.4` | `7.16.1` |\n| [pre-commit](https://github.com/pre-commit/pre-commit) | `4.2.0` | `4.6.2` |\n| [py-spy](https://github.com/benfred/py-spy) | `0.4.1` | `0.4.2` |\n| [maturin](https://github.com/pyo3/maturin) | `1.13.3` | `1.15.0` |\n| [python-lsp-server[all]](https://github.com/python-lsp/python-lsp-server) | `1.14.0` | `1.15.0` |\n| [python-lsp-ruff](https://github.com/python-lsp/python-lsp-ruff) | `2.3.0` | `2.3.4` |\n| [playwright](https://github.com/microsoft/playwright-python) | `1.61.0` | `1.62.0` |\n| [mypy](https://github.com/python/mypy) | `1.19.0` | `2.3.1` |\n| [types-pyyaml](https://github.com/python/typeshed) | `6.0.12.20250915` | `6.0.12.20260906` |\n| [types-reportlab](https://github.com/python/typeshed) | `4.5.0.20260509` | `5.0.0.20260911` |\n| [types-requests](https://github.com/python/typeshed) | `2.32.4.20260107` | `2.33.0.20260906` |\n| [pybind11](https://github.com/pybind/pybind11) | `3.0.4` | `3.1.0` |\n| [optuna](https://github.com/optuna/optuna) | `4.9.0` | `5.0.0` |\n\nUpdates `pin-pink` from 4.3.0 to 4.4.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/stephane-caron/pink/releases\"\u003epin-pink's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.4.0\u003c/h2\u003e\n\u003cp\u003eThis release allows custom boundaries in velocity limits, allowing bounds on joints that can't have a limit from their URDF model (such as continuous joints).\u003c/p\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eLimit: Allow custom boundaries in \u003ccode\u003eVelocityLimit\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003edocs: Document assumption that we start from a feasible configuration\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pink-kinematics/pink/blob/main/CHANGELOG.md\"\u003epin-pink's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e[4.4.0] - 2026-09-09\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eLimit: Allow custom boundaries in \u003ccode\u003eVelocityLimit\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003edocs: Document assumption that we start from a feasible configuration\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pink-kinematics/pink/commit/c14d0ae62f4fb744bbe84e35f9e16f1b680b20c0\"\u003e\u003ccode\u003ec14d0ae\u003c/code\u003e\u003c/a\u003e Release v4.4.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pink-kinematics/pink/commit/5c890570ee42d397f03d1cf8e1b8f4a9797bde97\"\u003e\u003ccode\u003e5c89057\u003c/code\u003e\u003c/a\u003e doc: Add context to configuration limit\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pink-kinematics/pink/commit/7df4f5a323c423b591ff3c35c7e66df40ff9c197\"\u003e\u003ccode\u003e7df4f5a\u003c/code\u003e\u003c/a\u003e Update link to CBF note\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pink-kinematics/pink/commit/bfd30c7aec222b66fb36629c20439bedb223d161\"\u003e\u003ccode\u003ebfd30c7\u003c/code\u003e\u003c/a\u003e lint: Apply pylint recos in FrameTask\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pink-kinematics/pink/commit/e71a42bd424680b039b782de1392b0b7ec2307d9\"\u003e\u003ccode\u003ee71a42b\u003c/code\u003e\u003c/a\u003e lint: Fix pylint recos in ManipulabilityTask\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pink-kinematics/pink/commit/a7ac5aa23b591fc203fbdc636d88c1a9b410375c\"\u003e\u003ccode\u003ea7ac5aa\u003c/code\u003e\u003c/a\u003e pixi: Group linting tasks, add format task\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pink-kinematics/pink/commit/771c0e0a5d80107771525321927eebb28fbc3400\"\u003e\u003ccode\u003e771c0e0\u003c/code\u003e\u003c/a\u003e lint: Fix two pylint errors\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pink-kinematics/pink/commit/f568e80536549a3b7f627468eb29526d3404c85b\"\u003e\u003ccode\u003ef568e80\u003c/code\u003e\u003c/a\u003e Update type of velocity_limit attribute\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pink-kinematics/pink/commit/232c9c0b76db644c212c1e9caa33bda345cb4dd2\"\u003e\u003ccode\u003e232c9c0\u003c/code\u003e\u003c/a\u003e minor: Removed comes before Fixed in Keep a Changelog\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pink-kinematics/pink/commit/3b60614b5f25ed8c1ed0f1fc596ec19133665035\"\u003e\u003ccode\u003e3b60614\u003c/code\u003e\u003c/a\u003e Update the changelog\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/stephane-caron/pink/compare/v4.3.0...v4.4.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `reactivex` from 4.1.0 to 5.1.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/ReactiveX/RxPY/releases\"\u003ereactivex's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev5.1.0\u003c/h2\u003e\n\u003cp\u003eSee \u003ca href=\"https://github.com/ReactiveX/RxPY/blob/master/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003ch2\u003ev5.0.0\u003c/h2\u003e\n\u003cp\u003eSee \u003ca href=\"https://github.com/ReactiveX/RxPY/blob/master/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003ch2\u003ev5.0.0rc2\u003c/h2\u003e\n\u003cp\u003eSee \u003ca href=\"https://github.com/ReactiveX/RxPY/blob/master/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003ch2\u003ev5.0.0a2\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix title header by \u003ca href=\"https://github.com/dbrattli\"\u003e\u003ccode\u003e@​dbrattli\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/pull/744\"\u003eReactiveX/RxPY#744\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/ReactiveX/RxPY/compare/v5.0.0a1...v5.0.0a2\"\u003ehttps://github.com/ReactiveX/RxPY/compare/v5.0.0a1...v5.0.0a2\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev5.0.0a1\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eGive run a scheduler parameter by \u003ca href=\"https://github.com/rmahfoud\"\u003e\u003ccode\u003e@​rmahfoud\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/pull/731\"\u003eReactiveX/RxPY#731\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAvoid use of asyncio.get_event_loop (3.14) by \u003ca href=\"https://github.com/traylenator\"\u003e\u003ccode\u003e@​traylenator\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/pull/728\"\u003eReactiveX/RxPY#728\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eMigrate to uv by \u003ca href=\"https://github.com/dbrattli\"\u003e\u003ccode\u003e@​dbrattli\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/pull/738\"\u003eReactiveX/RxPY#738\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eMigrate to ruff by \u003ca href=\"https://github.com/dbrattli\"\u003e\u003ccode\u003e@​dbrattli\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/pull/739\"\u003eReactiveX/RxPY#739\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpgrade pyright by \u003ca href=\"https://github.com/dbrattli\"\u003e\u003ccode\u003e@​dbrattli\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/pull/740\"\u003eReactiveX/RxPY#740\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix subscribe_on not forwarding scheduler to the source  by \u003ca href=\"https://github.com/jcafhe\"\u003e\u003ccode\u003e@​jcafhe\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/pull/726\"\u003eReactiveX/RxPY#726\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpgrade deps by \u003ca href=\"https://github.com/dbrattli\"\u003e\u003ccode\u003e@​dbrattli\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/pull/741\"\u003eReactiveX/RxPY#741\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eClarify what you can do with the .subscribe Disposable by \u003ca href=\"https://github.com/tmewett\"\u003e\u003ccode\u003e@​tmewett\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/pull/686\"\u003eReactiveX/RxPY#686\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRxPY v5 by \u003ca href=\"https://github.com/dbrattli\"\u003e\u003ccode\u003e@​dbrattli\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/pull/743\"\u003eReactiveX/RxPY#743\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/rmahfoud\"\u003e\u003ccode\u003e@​rmahfoud\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/pull/731\"\u003eReactiveX/RxPY#731\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tmewett\"\u003e\u003ccode\u003e@​tmewett\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/pull/686\"\u003eReactiveX/RxPY#686\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/ReactiveX/RxPY/compare/v4.1.0...v5.0.0a1\"\u003ehttps://github.com/ReactiveX/RxPY/compare/v4.1.0...v5.0.0a1\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/ReactiveX/RxPY/blob/master/CHANGELOG.md\"\u003ereactivex's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e5.1.0 - 2026-07-27\u003c/h2\u003e\n\u003ch3\u003e🚀 Features\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cem\u003e(operators)\u003c/em\u003e Add tap as an alias for do_action (\u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/issues/804\"\u003e#804\u003c/a\u003e) (\u003ca href=\"https://github.com/ReactiveX/RxPY/commit/95c54ac3652aed2bf78035c9846cb5867ee58172\"\u003e95c54ac3\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e🐞 Bug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cem\u003e(gtk)\u003c/em\u003e Call gi.require_version before importing gi.repository (\u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/issues/749\"\u003e#749\u003c/a\u003e) (\u003ca href=\"https://github.com/ReactiveX/RxPY/commit/2b9e3f338246acb7b0037c2a2d9b0882a980ce62\"\u003e2b9e3f33\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cem\u003e(operators)\u003c/em\u003e Accept concurrent.futures.Future wherever futures are accepted (\u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/issues/806\"\u003e#806\u003c/a\u003e) (\u003ca href=\"https://github.com/ReactiveX/RxPY/commit/19da6ac1487e97bb973fcc4dafc69cee4a1e12a7\"\u003e19da6ac1\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cem\u003e(scheduler)\u003c/em\u003e Use wall clock time for now() in event loop schedulers (\u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/issues/809\"\u003e#809\u003c/a\u003e) (\u003ca href=\"https://github.com/ReactiveX/RxPY/commit/361951c7237ae100f33f81e89144935adb281509\"\u003e361951c7\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003c!-- raw HTML omitted --\u003e\u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://github.com/ReactiveX/RxPY/compare/10ccc0a3deba0d004a8f9b6079802ffdb73d1edd..b286407307ace6670f6f0072a8438bc912165d43\"\u003eView changes on Github\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e\u003c!-- raw HTML omitted --\u003e\u003c/p\u003e\n\u003ch2\u003e5.0.0 - 2026-07-20\u003c/h2\u003e\n\u003ch3\u003e🐞 Bug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cem\u003e(scripts)\u003c/em\u003e Keep uv.lock in sync and scope the version sed to [project] (\u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/issues/802\"\u003e#802\u003c/a\u003e) (\u003ca href=\"https://github.com/ReactiveX/RxPY/commit/10ccc0a3deba0d004a8f9b6079802ffdb73d1edd\"\u003e10ccc0a3\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003c!-- raw HTML omitted --\u003e\u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://github.com/ReactiveX/RxPY/compare/915311e3e002b933f2eb4d59c9eac1cab327ff78..10ccc0a3deba0d004a8f9b6079802ffdb73d1edd\"\u003eView changes on Github\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e\u003c!-- raw HTML omitted --\u003e\u003c/p\u003e\n\u003ch2\u003e5.0.0-rc.2 - 2026-07-20\u003c/h2\u003e\n\u003ch3\u003e🐞 Bug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cem\u003e(operators)\u003c/em\u003e Reset retry budget per subscription to fix retry+repeat (\u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/issues/765\"\u003e#765\u003c/a\u003e) (\u003ca href=\"https://github.com/ReactiveX/RxPY/commit/c3f19d5e83403f70d44331daf0b5a86d410f76d4\"\u003ec3f19d5e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003c!-- raw HTML omitted --\u003e\u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://github.com/ReactiveX/RxPY/compare/2975deb528c9eec73c76cf8bb53fc8780f31de45..915311e3e002b933f2eb4d59c9eac1cab327ff78\"\u003eView changes on Github\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e\u003c!-- raw HTML omitted --\u003e\u003c/p\u003e\n\u003ch2\u003e5.0.0-rc.1 - 2026-04-20\u003c/h2\u003e\n\u003cp\u003e\u003c!-- raw HTML omitted --\u003e\u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://github.com/ReactiveX/RxPY/compare/8b59bc7394f1b6a8a78e2fc4b5efe200d4f47f89..2975deb528c9eec73c76cf8bb53fc8780f31de45\"\u003eView changes on Github\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e\u003c!-- raw HTML omitted --\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eTyping: Added \u003ccode\u003eAction\u003c/code\u003e and \u003ccode\u003eStartableFactory\u003c/code\u003e to \u003ccode\u003ereactivex.typing.__all__\u003c/code\u003e,\nmaking them part of the explicit public API surface.\u003c/li\u003e\n\u003cli\u003eDocs: Added missing docstring to \u003ccode\u003eon_error_resume_next\u003c/code\u003e operator.\u003c/li\u003e\n\u003cli\u003eOperators: Fixed scheduler forwarding in \u003ccode\u003epairwise\u003c/code\u003e, \u003ccode\u003eto_marbles\u003c/code\u003e, and\n\u003ccode\u003edelay_with_mapper\u003c/code\u003e (subscription-delay path). These operators now pass the\n\u003ccode\u003escheduler\u003c/code\u003e argument through to \u003ccode\u003esource.subscribe(...)\u003c/code\u003e and, in the case of\n\u003ccode\u003edelay_with_mapper\u003c/code\u003e, to the subscription-delay observable, consistent with\nall other pipeable operators. Closes \u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/issues/480\"\u003e#480\u003c/a\u003e (partial — the operators listed\nin the issue that were not yet fixed).\u003c/li\u003e\n\u003cli\u003eCI: Skip \u003ccode\u003etests/test_scheduler/test_mainloop/test_tkinterscheduler.py\u003c/code\u003e on\nPyPy (all platforms). The module creates a Tk root at import time; PyPy's\n\u003ccode\u003e_tkinter\u003c/code\u003e finalizer calls \u003ccode\u003ethreading.notify_all\u003c/code\u003e during interpreter\nshutdown and aborts the xdist worker, failing whichever unrelated test\nwas running. Previously guarded only on macOS+PyPy.\u003c/li\u003e\n\u003cli\u003eFix: \u003ccode\u003ereactivex.timer(duetime, period)\u003c/code\u003e now correctly resets the initial\ndelay on each resubscription (e.g. via \u003ccode\u003erepeat()\u003c/code\u003e). Previously `nonlocal\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ReactiveX/RxPY/commit/bbfecfbf83605f2bb2beb8b887dfe5b5fb322a67\"\u003e\u003ccode\u003ebbfecfb\u003c/code\u003e\u003c/a\u003e chore: release reactivex@5.1.0 (\u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/issues/805\"\u003e#805\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ReactiveX/RxPY/commit/b286407307ace6670f6f0072a8438bc912165d43\"\u003e\u003ccode\u003eb286407\u003c/code\u003e\u003c/a\u003e docs: correct and expand the GIL free-threading note (\u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/issues/811\"\u003e#811\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ReactiveX/RxPY/commit/93a4f0417fe5d1d187dbd2d0dfdf2ef3b481c45c\"\u003e\u003ccode\u003e93a4f04\u003c/code\u003e\u003c/a\u003e docs: explain how to parallelize work within a single stream (\u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/issues/810\"\u003e#810\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ReactiveX/RxPY/commit/2271867415d4beaed62e6f0441fd3312e47079aa\"\u003e\u003ccode\u003e2271867\u003c/code\u003e\u003c/a\u003e Revise GIL section for Python 3.13 updates (\u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/issues/742\"\u003e#742\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ReactiveX/RxPY/commit/361951c7237ae100f33f81e89144935adb281509\"\u003e\u003ccode\u003e361951c\u003c/code\u003e\u003c/a\u003e fix(scheduler): use wall clock time for now() in event loop schedulers (\u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/issues/809\"\u003e#809\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ReactiveX/RxPY/commit/b809222be63e235f439f65794dd1d4291556d072\"\u003e\u003ccode\u003eb809222\u003c/code\u003e\u003c/a\u003e docs: read version from pyproject instead of git tags (\u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/issues/808\"\u003e#808\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ReactiveX/RxPY/commit/19e808000610335b4f6d0e0c739b59372b8b5a5f\"\u003e\u003ccode\u003e19e8080\u003c/code\u003e\u003c/a\u003e ci(deps): bump the github-actions group with 2 updates (\u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/issues/807\"\u003e#807\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ReactiveX/RxPY/commit/dd9b8ec0185ade72dcb3aac983cd495f21ca0a6d\"\u003e\u003ccode\u003edd9b8ec\u003c/code\u003e\u003c/a\u003e refactor(combine-latest): simplify logic by removing redundant loops … (\u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/issues/736\"\u003e#736\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ReactiveX/RxPY/commit/19da6ac1487e97bb973fcc4dafc69cee4a1e12a7\"\u003e\u003ccode\u003e19da6ac\u003c/code\u003e\u003c/a\u003e fix(operators): accept concurrent.futures.Future wherever futures are accepte...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ReactiveX/RxPY/commit/2b9e3f338246acb7b0037c2a2d9b0882a980ce62\"\u003e\u003ccode\u003e2b9e3f3\u003c/code\u003e\u003c/a\u003e fix(gtk): call gi.require_version before importing gi.repository (\u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/issues/749\"\u003e#749\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/ReactiveX/RxPY/compare/v4.1.0...v5.1.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `pydantic` from 2.12.5 to 2.13.5\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pydantic/pydantic/releases\"\u003epydantic's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.13.5 (2026-08-28)\u003c/h2\u003e\n\u003ch3\u003eWhat's Changed\u003c/h3\u003e\n\u003ch4\u003eFixes\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eAllow reuse of validators when plugins are set by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13535\"\u003e#13535\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix missing GC traversal on some \u003ccode\u003epydantic-core\u003c/code\u003e struct fields by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13624\"\u003e#13624\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix missing GC traversal in \u003ccode\u003epydantic-core\u003c/code\u003e for \u003ccode\u003eGeneralFieldsSerializer\u003c/code\u003e by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13629\"\u003e#13629\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eCount validated model fields once in smart unions by \u003ca href=\"https://github.com/tamird\"\u003e\u003ccode\u003e@​tamird\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13731\"\u003e#13731\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev2.13.4 2026-05-06\u003c/h2\u003e\n\u003ch2\u003ev2.13.4 (2026-05-06)\u003c/h2\u003e\n\u003ch3\u003eWhat's Changed\u003c/h3\u003e\n\u003ch4\u003ePackaging\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eBump libc from 0.2.155 to 0.2.185 by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13109\"\u003e#13109\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdapt \u003ccode\u003epydantic-core\u003c/code\u003e linker flags on macOS by \u003ca href=\"https://github.com/washingtoneg\"\u003e\u003ccode\u003e@​washingtoneg\u003c/code\u003e\u003c/a\u003e and \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13147\"\u003e#13147\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003eFixes\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve \u003ccode\u003eRootModel\u003c/code\u003e core metadata by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13129\"\u003e#13129\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/pydantic/pydantic/compare/v2.13.3...v2.13.4\"\u003ehttps://github.com/pydantic/pydantic/compare/v2.13.3...v2.13.4\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.13.3 2026-04-20\u003c/h2\u003e\n\u003ch2\u003ev2.13.3 (2026-04-20)\u003c/h2\u003e\n\u003ch3\u003eWhat's Changed\u003c/h3\u003e\n\u003ch4\u003eFixes\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eHandle \u003ccode\u003eAttributeError\u003c/code\u003e subclasses with \u003ccode\u003efrom_attributes\u003c/code\u003e by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13096\"\u003e#13096\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/pydantic/pydantic/compare/v2.13.2...v2.13.3\"\u003ehttps://github.com/pydantic/pydantic/compare/v2.13.2...v2.13.3\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.13.2 2026-04-17\u003c/h2\u003e\n\u003ch2\u003ev2.13.2 (2026-04-17)\u003c/h2\u003e\n\u003ch3\u003eWhat's Changed\u003c/h3\u003e\n\u003ch4\u003eFixes\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eFix \u003ccode\u003eValidationInfo.field_name\u003c/code\u003e missing with \u003ccode\u003emodel_validate_json()\u003c/code\u003e by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13084\"\u003e#13084\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/pydantic/pydantic/compare/v2.13.1...v2.13.2\"\u003ehttps://github.com/pydantic/pydantic/compare/v2.13.1...v2.13.2\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.13.1 2026-04-15\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pydantic/pydantic/blob/v2.13.5/HISTORY.md\"\u003epydantic's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.13.5 (2026-08-28)\u003c/h2\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/pydantic/pydantic/releases/tag/v2.13.5\"\u003eGitHub release\u003c/a\u003e\u003c/p\u003e\n\u003ch3\u003eWhat's Changed\u003c/h3\u003e\n\u003ch4\u003eFixes\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eAllow reuse of validators when plugins are set by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13535\"\u003e#13535\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix missing GC traversal on some \u003ccode\u003epydantic-core\u003c/code\u003e struct fields by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13624\"\u003e#13624\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix missing GC traversal in \u003ccode\u003epydantic-core\u003c/code\u003e for \u003ccode\u003eGeneralFieldsSerializer\u003c/code\u003e by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13629\"\u003e#13629\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eCount validated model fields once in smart unions by \u003ca href=\"https://github.com/tamird\"\u003e\u003ccode\u003e@​tamird\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13731\"\u003e#13731\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev2.13.4 (2026-05-06)\u003c/h2\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/pydantic/pydantic/releases/tag/v2.13.4\"\u003eGitHub release\u003c/a\u003e\u003c/p\u003e\n\u003ch3\u003eWhat's Changed\u003c/h3\u003e\n\u003ch4\u003ePackaging\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eBump libc from 0.2.155 to 0.2.185 by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13109\"\u003e#13109\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdapt \u003ccode\u003epydantic-core\u003c/code\u003e linker flags on macOS by \u003ca href=\"https://github.com/washingtoneg\"\u003e\u003ccode\u003e@​washingtoneg\u003c/code\u003e\u003c/a\u003e and \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13147\"\u003e#13147\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003eFixes\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve \u003ccode\u003eRootModel\u003c/code\u003e core metadata by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13129\"\u003e#13129\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev2.13.3 (2026-04-20)\u003c/h2\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/pydantic/pydantic/releases/tag/v2.13.3\"\u003eGitHub release\u003c/a\u003e\u003c/p\u003e\n\u003ch3\u003eWhat's Changed\u003c/h3\u003e\n\u003ch4\u003eFixes\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eHandle \u003ccode\u003eAttributeError\u003c/code\u003e subclasses with \u003ccode\u003efrom_attributes\u003c/code\u003e by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13096\"\u003e#13096\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev2.13.2 (2026-04-17)\u003c/h2\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/pydantic/pydantic/releases/tag/v2.13.2\"\u003eGitHub release\u003c/a\u003e\u003c/p\u003e\n\u003ch3\u003eWhat's Changed\u003c/h3\u003e\n\u003ch4\u003eFixes\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eFix \u003ccode\u003eValidationInfo.field_name\u003c/code\u003e missing with \u003ccode\u003emodel_validate_json()\u003c/code\u003e by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13084\"\u003e#13084\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev2.13.1 (2026-04-15)\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/001dea020e0809844e5b17666432c9135a976f46\"\u003e\u003ccode\u003e001dea0\u003c/code\u003e\u003c/a\u003e Bump \u003ccode\u003epypa/gh-action-pypi-publish\u003c/code\u003e action to v1.14.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/558379fee957fad25858e33596146c72d5674843\"\u003e\u003ccode\u003e558379f\u003c/code\u003e\u003c/a\u003e Bump twine to v7.0.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/2cfd5d3d2ae721ea882c045f83b7f7a4003aab01\"\u003e\u003ccode\u003e2cfd5d3\u003c/code\u003e\u003c/a\u003e Do not check for docs build\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/a735bee5c64e1fe50785c376adaf1275e752b8ac\"\u003e\u003ccode\u003ea735bee\u003c/code\u003e\u003c/a\u003e Fix more Clippy lints\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/7eed4a16b87afaced4d0eafae230453de3410d64\"\u003e\u003ccode\u003e7eed4a1\u003c/code\u003e\u003c/a\u003e Fix Clippy 0.1.95 warnings\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/b353bbb20a4989b4c033e2be2b4a40d36178b16a\"\u003e\u003ccode\u003eb353bbb\u003c/code\u003e\u003c/a\u003e Prepare release v2.13.5\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/63d2cccd6e760da6bbc7fe81a53cb2bde3768f5e\"\u003e\u003ccode\u003e63d2ccc\u003c/code\u003e\u003c/a\u003e Count validated model fields once in smart unions\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/a53ec2ed342fda4e6aa3684399d04ea57be9a6e4\"\u003e\u003ccode\u003ea53ec2e\u003c/code\u003e\u003c/a\u003e Speed up PyPy CI tests\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/d65e0f96e890ca82f4b66a15d5b3bd65af2c661c\"\u003e\u003ccode\u003ed65e0f9\u003c/code\u003e\u003c/a\u003e Workaround circular import error in Mypy\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/47a6dbf8ad6216211bd0df6ec5c2c6c6ed905b72\"\u003e\u003ccode\u003e47a6dbf\u003c/code\u003e\u003c/a\u003e Fix missing GC traversal in \u003ccode\u003epydantic-core\u003c/code\u003e for \u003ccode\u003eGeneralFieldsSerializer\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/pydantic/pydantic/compare/v2.12.5...v2.13.5\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `python-dotenv` from 1.2.2 to 1.2.3\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/theskumar/python-dotenv/releases\"\u003epython-dotenv's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.2.3\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eStrip a leading UTF-8 BOM from \u003ccode\u003e.env\u003c/code\u003e file contents so the first variable is no longer silently lost when the file is saved with BOM (e.g. by some JetBrains IDEs on Windows) by [\u003ca href=\"https://github.com/h1whelan\"\u003e\u003ccode\u003e@​h1whelan\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/640\"\u003e#640\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eset_key\u003c/code\u003e now escapes backslashes, so values containing them (Windows paths, regular expressions) survive a write/read round-trip. Quoted values ending in an escaped backslash are no longer mis-parsed as an escaped quote, which used to swallow the following lines by [\u003ca href=\"https://github.com/dchaudhari7177\"\u003e\u003ccode\u003e@​dchaudhari7177\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/680\"\u003e#680\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003edotenv run\u003c/code\u003e now prints a friendly error instead of a traceback when no command is given by [\u003ca href=\"https://github.com/bbc2\"\u003e\u003ccode\u003e@​bbc2\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/606\"\u003e#606\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eCache the parsed result for empty \u003ccode\u003e.env\u003c/code\u003e files so repeated \u003ccode\u003edotenv_values\u003c/code\u003e/\u003ccode\u003eload_dotenv\u003c/code\u003e calls no longer re-read the file by [\u003ca href=\"https://github.com/ReinerBRO\"\u003e\u003ccode\u003e@​ReinerBRO\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/638\"\u003e#638\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/theskumar/python-dotenv/blob/main/CHANGELOG.md\"\u003epython-dotenv's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e[1.2.3] - 2026-08-16\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eStrip a leading UTF-8 BOM from \u003ccode\u003e.env\u003c/code\u003e file contents so the first variable is no longer silently lost when the file is saved with BOM (e.g. by some JetBrains IDEs on Windows) by [\u003ca href=\"https://github.com/h1whelan\"\u003e\u003ccode\u003e@​h1whelan\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/640\"\u003e#640\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eset_key\u003c/code\u003e now escapes backslashes, so values containing them (Windows paths, regular expressions) survive a write/read round-trip. Quoted values ending in an escaped backslash are no longer mis-parsed as an escaped quote, which used to swallow the following lines by [\u003ca href=\"https://github.com/dchaudhari7177\"\u003e\u003ccode\u003e@​dchaudhari7177\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/680\"\u003e#680\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003edotenv run\u003c/code\u003e now prints a friendly error instead of a traceback when no command is given by [\u003ca href=\"https://github.com/bbc2\"\u003e\u003ccode\u003e@​bbc2\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/606\"\u003e#606\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eCache the parsed result for empty \u003ccode\u003e.env\u003c/code\u003e files so repeated \u003ccode\u003edotenv_values\u003c/code\u003e/\u003ccode\u003eload_dotenv\u003c/code\u003e calls no longer re-read the file by [\u003ca href=\"https://github.com/ReinerBRO\"\u003e\u003ccode\u003e@​ReinerBRO\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/638\"\u003e#638\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/49515afee2d50c33cad9419b3800b3a0dc93fc59\"\u003e\u003ccode\u003e49515af\u003c/code\u003e\u003c/a\u003e Bump version: 1.2.2 → 1.2.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/8ac846ff2760b65470e769d7eed33e540f0934e1\"\u003e\u003ccode\u003e8ac846f\u003c/code\u003e\u003c/a\u003e chore: add release runbook (RELEASING.md) and make release target\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/bb31c944fb4b40e8dea59587f525840c38326166\"\u003e\u003ccode\u003ebb31c94\u003c/code\u003e\u003c/a\u003e docs: add 1.2.3 release notes (\u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/606\"\u003e#606\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/638\"\u003e#638\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/680\"\u003e#680\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/f7b18d9c72d1abcc2ad4023424b84f5bee30d266\"\u003e\u003ccode\u003ef7b18d9\u003c/code\u003e\u003c/a\u003e fix: round-trip backslashes through set_key (\u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/680\"\u003e#680\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/751f8c148222e58aa173c83c4e5e6cfccb2cc124\"\u003e\u003ccode\u003e751f8c1\u003c/code\u003e\u003c/a\u003e ci(deps): bump actions/checkout from 6.0.2 to 6.0.3 in the github-actions gro...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/f1937b68f338d7ebd7754da377ca08b2f0df8dbb\"\u003e\u003ccode\u003ef1937b6\u003c/code\u003e\u003c/a\u003e chore(deps): update mkdocs-include-markdown-plugin requirement from \u0026gt;=6.0.0 t...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/45b93720dd5e9e127d0be3971a04855d34e464d8\"\u003e\u003ccode\u003e45b9372\u003c/code\u003e\u003c/a\u003e chore(deps): update pytest requirement from \u0026gt;=3.9 to \u0026gt;=9.0.3 (\u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/653\"\u003e#653\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/72896e9244d2a1ff8d5e1934d3df8a35c813799a\"\u003e\u003ccode\u003e72896e9\u003c/code\u003e\u003c/a\u003e docs: fix broken mkdocs link in CONTRIBUTING.md (\u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/636\"\u003e#636\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/72754a16a4743e4c92edf87ce59ba0e4ff78758d\"\u003e\u003ccode\u003e72754a1\u003c/code\u003e\u003c/a\u003e ci(deps): bump peaceiris/actions-gh-pages from 4.0.0 to 4.1.0 in the github-a...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/078325e92558330e9addc661b789c7b6123fa73c\"\u003e\u003ccode\u003e078325e\u003c/code\u003e\u003c/a\u003e ci(security): harden CI/CD supply chain with SHA pinning and least-privilege ...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/theskumar/python-dotenv/compare/v1.2.2...v1.2.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `packaging` from 25.0 to 26.3\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pypa/packaging/releases\"\u003epackaging's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e26.3\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdd a public \u003ccode\u003eVersionRange\u003c/code\u003e API and \u003ccode\u003eSpecifierSet.to_range()\u003c/code\u003e, representing the versions a specifier set accepts as an interval set that supports intersection, union, difference, complement, set relations, membership tests, and filtering. \u003ccode\u003eVersionRange.to_specifier_set()\u003c/code\u003e converts a range back to a \u003ccode\u003eSpecifierSet\u003c/code\u003e where a PEP 440 form exists. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1267\"\u003e#1267\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1270\"\u003e#1270\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1298\"\u003e#1298\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ePEP 808: accept \u003ccode\u003eMetadata-Version: 2.6\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1194\"\u003e#1194\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdd a \u003ccode\u003elimit\u003c/code\u003e argument to \u003ccode\u003eparse_tag()\u003c/code\u003e for compressed tag sets. (\u003ca href=\"https://redirect.github.com/pypa/packaging/issues/1220\"\u003e#1220\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdd a \u003ccode\u003eprefer_sdist_predicate\u003c/code\u003e argument to \u003ccode\u003ePylock.select()\u003c/code\u003e to prefer source distributions over wheels for selected packages. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1334\"\u003e#1334\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003epure_python_tags()\u003c/code\u003e to generate the pure-Python tags for a Python version without touching the running platform. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1346\"\u003e#1346\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003eSpecifierSet.is_subset()\u003c/code\u003e, \u003ccode\u003eSpecifierSet.is_superset()\u003c/code\u003e, and \u003ccode\u003eSpecifierSet.is_disjoint()\u003c/code\u003e, which compare the versions two specifier sets accept. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1313\"\u003e#1313\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBehavior adaptations\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eDrop support for Python 3.8; packaging now requires Python 3.9 or later. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1157\"\u003e#1157\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ePrefer native \u003ccode\u003elinux_*\u003c/code\u003e platform tags over \u003ccode\u003emanylinux\u003c/code\u003e and \u003ccode\u003emusllinux\u003c/code\u003e tags on Linux. (\u003ca href=\"https://redirect.github.com/pypa/packaging/issues/160\"\u003e#160\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixes for versions and specifiers\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eRaise \u003ccode\u003eInvalidVersion\u003c/code\u003e instead of \u003ccode\u003eTypeError\u003c/code\u003e when \u003ccode\u003eVersion\u003c/code\u003e is given a non-string. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1319\"\u003e#1319\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRaise \u003ccode\u003eInvalidVersion\u003c/code\u003e for non-string pre-release letters passed to \u003ccode\u003eVersion.from_parts\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1241\"\u003e#1241\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix an \u003ccode\u003eAttributeError\u003c/code\u003e when hashing internally trimmed versions. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1242\"\u003e#1242\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix \u003ccode\u003eSpecifierSet.is_unsatisfiable\u003c/code\u003e for post-release boundary intersections. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1257\"\u003e#1257\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixes for requirements and markers\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eMake \u003ccode\u003eRequirement.__hash__\u003c/code\u003e consistent with \u003ccode\u003e__eq__\u003c/code\u003e for trailing-zero-equivalent specifiers (e.g. \u003ccode\u003efoo==1.0.0\u003c/code\u003e and \u003ccode\u003efoo==1.0.0.0\u003c/code\u003e), so equal requirements hash equal and deduplicate in sets and dicts. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1232\"\u003e#1232\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eNormalize requested extra names before comparing or hashing requirements. (\u003ca href=\"https://redirect.github.com/pypa/packaging/issues/644\"\u003e#644\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ePreserve a \u003ccode\u003eRequirement\u003c/code\u003e's specifier \u003ccode\u003eprereleases\u003c/code\u003e override across a pickle round trip. (\u003ca href=\"https://redirect.github.com/pypa/packaging/issues/1204\"\u003e#1204\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRaise \u003ccode\u003eInvalidRequirement\u003c/code\u003e instead of \u003ccode\u003eInvalidSpecifier\u003c/code\u003e when a requirement contains an invalid specifier. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1332\"\u003e#1332\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eClarify the error for post-release prefix wildcards like \u003ccode\u003e==1.0.post1.*\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1299\"\u003e#1299\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ePreserve quoting semantics when serializing marker values, so round-tripped markers parse back to the same marker. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1213\"\u003e#1213\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eKeep the parentheses of a nested group when serializing markers. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1316\"\u003e#1316\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eNormalize \u003ccode\u003eextra\u003c/code\u003e and \u003ccode\u003edependency_groups\u003c/code\u003e values in nested markers at parse time. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1246\"\u003e#1246\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1310\"\u003e#1310\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRaise \u003ccode\u003eUndefinedComparison\u003c/code\u003e when a set-valued variable like \u003ccode\u003eextras\u003c/code\u003e is used outside the membership form. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1265\"\u003e#1265\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRaise \u003ccode\u003eUndefinedEnvironmentName\u003c/code\u003e (a \u003ccode\u003eKeyError\u003c/code\u003e subclass) for missing environment keys during marker evaluation. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1276\"\u003e#1276\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eWrap malformed string literal errors in \u003ccode\u003eInvalidMarker\u003c/code\u003e / \u003ccode\u003eInvalidRequirement\u003c/code\u003e instead of leaking a low-level error. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1249\"\u003e#1249\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eReject requirements and markers with a trailing line break. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1345\"\u003e#1345\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixes for metadata and licenses\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eCollect all \u003ccode\u003efrom_email\u003c/code\u003e validation errors into one \u003ccode\u003eExceptionGroup\u003c/code\u003e instead of raising the first. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1268\"\u003e#1268\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAccept the UTF-8 charset case-insensitively in email payloads. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1330\"\u003e#1330\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eReject malformed \u003ccode\u003eDescription-Content-Type\u003c/code\u003e values. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1329\"\u003e#1329\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eDon't rewrite user values that contain \u003ccode\u003e{field}\u003c/code\u003e placeholders in error messages. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1327\"\u003e#1327\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRoute multipart email payloads to \u003ccode\u003eunparsed\u003c/code\u003e instead of asserting. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1247\"\u003e#1247\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eMake \u003ccode\u003eInvalidMetadata\u003c/code\u003e and \u003ccode\u003eCyclicDependencyGroup\u003c/code\u003e picklable. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1328\"\u003e#1328\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFold every line boundary \u003ccode\u003estr.splitlines\u003c/code\u003e recognizes when writing a header with \u003ccode\u003eRFC822Message\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1356\"\u003e#1356\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pypa/packaging/blob/main/CHANGELOG.rst\"\u003epackaging's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e26.3 - 2026-08-03\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003e\nFeatures:\n\u003cul\u003e\n\u003cli\u003eAdd a public :class:\u003ccode\u003e~packaging.ranges.VersionRange\u003c/code\u003e API and\u003cbr /\u003e\n:meth:\u003ccode\u003eSpecifierSet.to_range() \u0026amp;lt;packaging.specifiers.SpecifierSet.to_range\u0026amp;gt;\u003c/code\u003e,\u003cbr /\u003e\nrepresenting the versions a specifier set accepts as an interval set that\u003cbr /\u003e\nsupports intersection, union, difference, complement, set relations,\u003cbr /\u003e\nmembership tests, and filtering.\u003cbr /\u003e\n:meth:\u003ccode\u003e~packaging.ranges.VersionRange.to_specifier_set\u003c/code\u003e converts a range back\u003cbr /\u003e\nto a :class:\u003ccode\u003e~packaging.specifiers.SpecifierSet\u003c/code\u003e where a PEP 440 form exists.\u003cbr /\u003e\n(:pull:\u003ccode\u003e1267\u003c/code\u003e, :pull:\u003ccode\u003e1270\u003c/code\u003e, :pull:\u003ccode\u003e1298\u003c/code\u003e)\u003c/li\u003e\n\u003cli\u003ePEP 808: accept \u003ccode\u003eMetadata-Version: 2.6\u003c/code\u003e. (:pull:\u003ccode\u003e1194\u003c/code\u003e)\u003c/li\u003e\n\u003cli\u003eAdd a \u003ccode\u003elimit\u003c/code\u003e argument to \u003ccode\u003eparse_tag()\u003c/code\u003e for compressed tag sets.\u003cbr /\u003e\n(:issue:\u003ccode\u003e1220\u003c/code\u003e)\u003c/li\u003e\n\u003cli\u003eAdd a \u003ccode\u003eprefer_sdist_predicate\u003c/code\u003e argument to \u003ccode\u003ePylock.select()\u003c/code\u003e to prefer\u003cbr /\u003e\nsource distributions over wheels for selected packages. (:pull:\u003ccode\u003e1334\u003c/code\u003e)\u003c/li\u003e\n\u003cli\u003eAdd :func:\u003ccode\u003e~packaging.tags.pure_python_tags\u003c/code\u003e to generate the pure-Python\u003cbr /\u003e\ntags for a Python version without touching the running platform.\u003cbr /\u003e\n(:pull:\u003ccode\u003e1346\u003c/code\u003e)\u003c/li\u003e\n\u003cli\u003eAdd :meth:\u003ccode\u003eSpecifierSet.is_subset() \u0026amp;lt;packaging.specifiers.SpecifierSet.is_subset\u0026amp;gt;\u003c/code\u003e, :meth:\u003ccode\u003e~packaging.specifiers.SpecifierSet.is_superset\u003c/code\u003e,\u003cbr /\u003e\nand :meth:\u003ccode\u003e~packaging.specifiers.SpecifierSet.is_disjoint\u003c/code\u003e, which compare the\u003cbr /\u003e\nversions two specifier sets accept. (:pull:\u003ccode\u003e1313\u003c/code\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eBehavior adaptations:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eDrop support for Python 3.8; packaging now requires Python 3.9 or later.\u003cbr /\u003e\n(:pull:\u003ccode\u003e1157\u003c/code\u003e)\u003c/li\u003e\n\u003cli\u003ePrefer native \u003ccode\u003elinux_*\u003c/code\u003e platform tags over \u003ccode\u003emanylinux\u003c/code\u003e and \u003ccode\u003emusllinux\u003c/code\u003e\u003cbr /\u003e\ntags on Linux. (:issue:\u003ccode\u003e160\u003c/code\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eFixes for versions and specifiers:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eRaise \u003ccode\u003eInvalidVersion\u003c/code\u003e instead of \u003ccode\u003eTypeError\u003c/code\u003e when \u003ccode\u003eVersion\u003c/code\u003e is given a\u003cbr /\u003e\nnon-string. (:pull:\u003ccode\u003e1319\u003c/code\u003e)\u003c/li\u003e\n\u003cli\u003eRaise \u003ccode\u003eInvalidVersion\u003c/code\u003e for non-string pre-release letters passed to\u003cbr /\u003e\n\u003ccode\u003eVersion.from_parts\u003c/code\u003e. (:pull:\u003ccode\u003e1241\u003c/code\u003e)\u003c/li\u003e\n\u003cli\u003eFix an \u003ccode\u003eAttributeError\u003c/code\u003e when hashing internally trimmed versions.\u003cbr /\u003e\n(:pull:\u003ccode\u003e1242\u003c/code\u003e)\u003c/li\u003e\n\u003cli\u003eFix \u003ccode\u003eSpecifierSet.is_unsatisfiable\u003c/code\u003e for post-release boundary\u003cbr /\u003e\nintersections. (:pull:\u003ccode\u003e1257\u003c/code\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eFixes for requirements and markers:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eMake \u003ccode\u003eRequirement.__hash__\u003c/code\u003e consistent with \u003ccode\u003e__eq__\u003c/code\u003e for\u003cbr /\u003e\ntrailing-zero-equivalent specifiers (e.g. \u003ccode\u003efoo==1.0.0\u003c/code\u003e and\u003cbr /\u003e\n\u003ccode\u003efoo==1.0.0.0\u003c/code\u003e), so equal requirements hash equal and deduplicate in\u003cbr /\u003e\nsets and dicts. (:pull:\u003ccode\u003e1232\u003c/code\u003e)\u003cbr /\u003e\n\u0026lt;/tr\u0026gt;\u0026lt;/table\u0026gt;\u003cbr /\u003e\n\u003c/code\u003e\u003c/pre\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/packaging/commit/929fd4b1410ac7ef61ef3f45b2f5d7e87711a9b5\"\u003e\u003ccode\u003e929fd4b\u003c/code\u003e\u003c/a\u003e Bump for release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/packaging/commit/f300ebf0c155e1f7ea6d62fba11dba4bac3d1944\"\u003e\u003ccode\u003ef300ebf\u003c/code\u003e\u003c/a\u003e chore(deps): bump the pre-commit group with 5 updates (\u003ca href=\"https://redirect.github.com/pypa/packaging/issues/1357\"\u003e#1357\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/packaging/commit/f91d97566a966177ad7ea5a7c703b12a7273e3b1\"\u003e\u003ccode\u003ef91d975\u003c/code\u003e\u003c/a\u003e ci(downstream): bump hatchling to 1.31.0 and fix its pytest rootdir (\u003ca href=\"https://redirect.github.com/pypa/packaging/issues/1361\"\u003e#1361\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/packaging/commit/b1a7124fe3d40c3302c029e9eb01ac3fc3496a54\"\u003e\u003ccode\u003eb1a7124\u003c/code\u003e\u003c/a\u003e chore(deps): bump the github-actions group with 7 updates (\u003ca href=\"https://redirect.github.com/pypa/packaging/issues/1358\"\u003e#1358\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/packaging/commit/2d873eb6002021a8c007c933fbdab58b37a5079b\"\u003e\u003ccode\u003e2d873eb\u003c/code\u003e\u003c/a\u003e fix(metadata): fold every line boundary when writing headers (\u003ca href=\"https://redirect.github.com/pypa/packaging/issues/1356\"\u003e#1356\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/packaging/commit/413d006fadf5b9b14d78ad444201d8189bff8c64\"\u003e\u003ccode\u003e413d006\u003c/code\u003e\u003c/a\u003e docs: changelog for 26.3 (\u003ca href=\"https://redirect.github.com/pypa/packaging/issues/1343\"\u003e#1343\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/packaging/commit/4eb0753dba8fcaaac8eb75463374e448f0931558\"\u003e\u003ccode\u003e4eb0753\u003c/code\u003e\u003c/a\u003e docs(metadata): explain selective field validation (\u003ca href=\"https://redirect.github.com/pypa/packaging/issues/1342\"\u003e#1342\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/packaging/commit/77e9ed42b6db9c5c011a5148047a356ebe42692a\"\u003e\u003ccode\u003e77e9ed4\u003c/code\u003e\u003c/a\u003e feat(tags): add pure Python tag generator (\u003ca href=\"https://redirect.github.com/pypa/packaging/issues/1346\"\u003e#1346\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/packaging/commit/7cea5e88671ed14016e9ab3dd08eab064f596564\"\u003e\u003ccode\u003e7cea5e8\u003c/code\u003e\u003c/a\u003e ci: drop 3.13t on Windows (3.13.14t may fail to build, run takes 9 minutes) (...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/packaging/commit/45a8b3402db5ff82158f2d0eabaf8447aa7a50bf\"\u003e\u003ccode\u003e45a8b34\u003c/code\u003e\u003c/a\u003e docs: add missing versionadded/versionchanged directives (\u003ca href=\"https://redirect.github.com/pypa/packaging/issues/1344\"\u003e#1344\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/pypa/packaging/compare/25.0...26.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `filelock` from 3.23.0 to 3.32.6\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/tox-dev/py-filelock/releases\"\u003efilelock's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e3.32.6\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e🐛 fix(lease): reject a duration no marker can carry by \u003ca href=\"https://github.com/lprnmns\"\u003e\u003ccode\u003e@​lprnmns\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/723\"\u003etox-dev/filelock#723\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e🐛 fix(soft-rw): reject non-finite timing options by \u003ca href=\"https://github.com/lprnmns\"\u003e\u003ccode\u003e@​lprnmns\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/724\"\u003etox-dev/filelock#724\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: preserve exception notes when copying and pickling by \u003ca href=\"https://github.com/jackwalkerlabs\"\u003e\u003ccode\u003e@​jackwalkerlabs\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/729\"\u003etox-dev/filelock#729\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etest(soft-rw): reuse existing test module by \u003ca href=\"https://github.com/gaborbernat\"\u003e\u003ccode\u003e@​gaborbernat\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/730\"\u003etox-dev/filelock#730\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: respect ACL write access when the owner write bit is absent by \u003ca href=\"https://github.com/jackwalkerlabs\"\u003e\u003ccode\u003e@​jackwalkerlabs\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/728\"\u003etox-dev/filelock#728\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix SoftReadWriteLock state lock timeout by \u003ca href=\"https://github.com/Sohel2309\"\u003e\u003ccode\u003e@​Sohel2309\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/726\"\u003etox-dev/filelock#726\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jackwalkerlabs\"\u003e\u003ccode\u003e@​jackwalkerlabs\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/729\"\u003etox-dev/filelock#729\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Sohel2309\"\u003e\u003ccode\u003e@​Sohel2309\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/726\"\u003etox-dev/filelock#726\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/tox-dev/filelock/compare/3.32.5...3.32.6\"\u003ehttps://github.com/tox-dev/filelock/compare/3.32.5...3.32.6\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003e3.32.5\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e🧪 test(fork): report where a stalled fork stops by \u003ca href=\"https://github.com/gaborbernat\"\u003e\u003ccode\u003e@​gaborbernat\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/715\"\u003etox-dev/filelock#715\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e📝 docs: say that mode is read-only in the thread-local section by \u003ca href=\"https://github.com/Gares95\"\u003e\u003ccode\u003e@​Gares95\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/716\"\u003etox-dev/filelock#716\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e🐛 fix(lease): clear token after failed acquire by \u003ca href=\"https://github.com/lprnmns\"\u003e\u003ccode\u003e@​lprnmns\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/721\"\u003etox-dev/filelock#721\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lprnmns\"\u003e\u003ccode\u003e@​lprnmns\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/721\"\u003etox-dev/filelock#721\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/tox-dev/filelock/compare/3.32.4...3.32.5\"\u003ehttps://github.com/tox-dev/filelock/compare/3.32.4...3.32.5\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003e3.32.4\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e🐛 fix: retry transient denials on open and claim read by \u003ca href=\"https://github.com/gaborbernat\"\u003e\u003ccode\u003e@​gaborbernat\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/705\"\u003etox-dev/filelock#705\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e🧪 test: deflake six scheduled-run failures by \u003ca href=\"https://github.com/gaborbernat\"\u003e\u003ccode\u003e@​gaborbernat\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/704\"\u003etox-dev/filelock#704\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e🧪 test: cover a reclaimed private record for real by \u003ca href=\"https://github.com/gaborbernat\"\u003e\u003ccode\u003e@​gaborbernat\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/706\"\u003etox-dev/filelock#706\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e🧪 test(fork): fork once the event loop has closed by \u003ca href=\"https://github.com/gaborbernat\"\u003e\u003ccode\u003e@​gaborbernat\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/714\"\u003etox-dev/filelock#714\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e🔧 chore: batch dependency updates weekly on Tuesday by \u003ca href=\"https://github.com/gaborbernat\"\u003e\u003ccode\u003e@​gaborbernat\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/713\"\u003etox-dev/filelock#713\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eescape the hostname every marker publishes by \u003ca href=\"https://github.com/dxbjavid\"\u003e\u003ccode\u003e@​dxbjavid\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/709\"\u003etox-dev/filelock#709\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/tox-dev/filelock/compare/3.32.3...3.32.4\"\u003ehttps://github.com/tox-dev/filelock/compare/3.32.3...3.32.4\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003e3.32.3\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e🧪 test(strict): deflake close-fault injections on graalpy by \u003ca href=\"https://github.com/gaborbernat\"\u003e\u003ccode\u003e@​gaborbernat\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/697\"\u003etox-dev/filelock#697\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e📄 docs: publish llms.txt from the docs build by \u003ca href=\"https://github.com/gaborbernat\"\u003e\u003ccode\u003e@​gaborbernat\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/700\"\u003etox-dev/filelock#700\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/tox-dev/filelock/blob/main/docs/changelog.rst\"\u003efilelock's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e###########\nChangelog\n###########\u003c/p\u003e\n\u003cp\u003e.. towncrier-draft-entries:: Unreleased\u003c/p\u003e\n\u003cp\u003e.. towncrier release notes start\u003c/p\u003e\n\u003chr /\u003e\n\u003cp\u003e4.0.1 (2026-09-19)\u003c/p\u003e\n\u003chr /\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003epoll_interval\u003c/code\u003e is now validated at construction, on the setter, and on \u003ccode\u003eacquire()\u003c/code\u003e: a negative, non-finite, or\nnon-numeric value raises :class:\u003ccode\u003eValueError\u003c/code\u003e/:class:\u003ccode\u003eTypeError\u003c/code\u003e immediately instead of failing inside \u003ccode\u003etime.sleep\u003c/code\u003e. :pr:\u003ccode\u003e739\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr /\u003e\n\u003cp\u003e4.0.0 (2026-09-17)\u003c/p\u003e\n\u003chr /\u003e\n\u003cul\u003e\n\u003cli\u003eThe :class:\u003ccode\u003e~filelock.SoftReadWriteLock\u003c/code\u003e on-disk protocol is a generation log under \u003ccode\u003e\u0026lt;path\u0026gt;.rw\u003c/code\u003e, and a process\nrunning an earlier release does not see it: an old and a new participant on one lock path do not exclude each\nother. Stop every participant, upgrade them all, then restart them; the new code ignores leftover \u003ccode\u003e.state\u003c/code\u003e,\n\u003ccode\u003e.write\u003c/code\u003e and \u003ccode\u003e.readers/\u003c/code\u003e files, and you can delete them. The filesystem must provide no-replace hard links, as\nit must for :class:\u003ccode\u003e~filelock.StrictSoftFileLock\u003c/code\u003e, so a runtime without \u003ccode\u003eos.link\u003c/code\u003e raises\n:class:\u003ccode\u003e~filelock.SoftFileLockProtocolError\u003c/code\u003e on acquire. Constructing a singleton again with a different\n\u003ccode\u003eon_compromise\u003c/code\u003e, or with \u003ccode\u003epoll_interval\u003c/code\u003e at or above \u003ccode\u003estale_threshold\u003c/code\u003e, now raises :class:\u003ccode\u003eValueError\u003c/code\u003e. :pr:\u003ccode\u003e735\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e:class:\u003ccode\u003e~filelock.SoftReadWriteLock\u003c/code\u003e exposes :attr:\u003ccode\u003e~filelock.SoftReadWriteLock.generation\u003c/code\u003e as a fencing token for\nthe protected resource and reports a lost hold through \u003ccode\u003eon_compromise\u003c/code\u003e and\n:attr:\u003ccode\u003e~filelock.SoftReadWriteLock.compromise\u003c/code\u003e. :pr:\u003ccode\u003e735\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e:class:\u003ccode\u003e~filelock.SoftReadWriteLock\u003c/code\u003e no longer deadlocks when a holder dies on another host mid-transition, and\n\u003ccode\u003erelease()\u003c/code\u003e no longer waits on a mutex a dead host left behind (:pr:\u003ccode\u003e725\u003c/code\u003e, :pr:\u003ccode\u003e735\u003c/code\u003e). The state mutex is gone.\nEach transition is one atomic snapshot commit, and liveness is a heartbeat nonce read on the observer's own clock\nrather than an \u003ccode\u003emtime\u003c/code\u003e read against another host's. :pr:\u003ccode\u003e735\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr /\u003e\n\u003cp\u003e3.32.7 (2026-09-16)\u003c/p\u003e\n\u003chr /\u003e\n\u003cul\u003e\n\u003cli\u003eValidate final-symlink refusal by error number so the test works across libc implementations. :pr:\u003ccode\u003e737\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eDocument that :meth:\u003ccode\u003e~filelock.BaseFileLock.acquire\u003c/code\u003e reads \u003ccode\u003eblocking=None\u003c/code\u003e as the lock's \u003ccode\u003eblocking\u003c/code\u003e attribute and\nraises :class:\u003ccode\u003e~filelock.Timeout\u003c/code\u003e after one attempt when \u003ccode\u003eblocking=False\u003c/code\u003e. :pr:\u003ccode\u003e733\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr /\u003e\n\u003cp\u003e3.32.6 (2026-09-08)\u003c/p\u003e\n\u003chr /\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eSoftFileLease\u003c/code\u003e and \u003ccode\u003eAsyncSoftFileLease\u003c/code\u003e now reject a boolean or non-finite \u003ccode\u003elease_duration\u003c/code\u003e, which used to\npublish an owner record their own \u003ccode\u003eowner\u003c/code\u003e property reads back as malformed. :pr:\u003ccode\u003e723\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eReject non-finite heartbeat, stale, and polling intervals in \u003ccode\u003eSoftReadWriteLock\u003c/code\u003e and \u003ccode\u003eAsyncSoftReadWriteLock\u003c/code\u003e,\nincluding cached singleton construction and overflow in the default stale threshold. :pr:\u003ccode\u003e724\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tox-dev/filelock/commit/4efd93e0482e8095a0b6949fb337206e7f67495d\"\u003e\u003ccode\u003e4efd93e\u003c/code\u003e\u003c/a\u003e Release 3.32.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tox-dev/filelock/commit/7b7b7a8b9b10acf826cca246441297468039b0c1\"\u003e\u003ccode\u003e7b7b7a8\u003c/code\u003e\u003c/a\u003e Fix SoftReadWriteLock state lock timeout (\u003ca href=\"https://redirect.github.com/tox-dev/py-filelock/issues/726\"\u003e#726\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tox-dev/filelock/commit/f2f7b8696426c518b6828ea10e755c0ba2a4ffe2\"\u003e\u003ccode\u003ef2f7b86\u003c/code\u003e\u003c/a\u003e fix: respect ACL write access when the owner write bit is absent (\u003ca href=\"https://redirect.github.com/tox-dev/py-filelock/issues/728\"\u003e#728\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tox-dev/filelock/commit/e947a694fb0da6676c4861c8bfef3650e5656153\"\u003e\u003ccode\u003ee947a69\u003c/code\u003e\u003c/a\u003e test(soft-rw): reuse existing test module (\u003ca href=\"https://redirect.github.com/tox-dev/py-filelock/issues/730\"\u003e#730\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tox-dev/filelock/commit/da3ae2bca0035fb9e5269257e6f393360866cf88\"\u003e\u003ccode\u003eda3ae2b\u003c/code\u003e\u003c/a\u003e fix: preserve exception notes when copying and pickling (\u003ca href=\"https://redirect.github.com/tox-dev/py-filelock/issues/729\"\u003e#729\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tox-dev/filelock/commit/ae9cb5b2d66d6a79edd76b292fa7320c11468812\"\u003e\u003ccode\u003eae9cb5b\u003c/code\u003e\u003c/a\u003e 🐛 fix(soft-rw): reject non-finite timing options (\u003ca href=\"https://redirect.github.com/tox-dev/py-filelock/issues/724\"\u003e#724\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tox-dev/filelock/commit/d00f9bbd709fbe92a99a38cb1e32b6690813e5a8\"\u003e\u003ccode\u003ed00f9bb\u003c/code\u003e\u003c/a\u003e [pre-commit.ci] pre-commit autoupdate (\u003ca href=\"https://redirect.github.com/tox-dev/py-filelock/issues/727\"\u003e#727\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tox-dev/filelock/commit/82f66d7b0aaa83755f8d71d0b0da88408b58ec4a\"\u003e\u003ccode\u003e82f66d7\u003c/code\u003e\u003c/a\u003e 🐛 fix(lease): reject a duration no marker can carry (\u003ca href=\"https://redirect.github.com/tox-dev/py-filelock/issues/723\"\u003e#723\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tox-dev/filelock/commit/1d9e9e7e43a1089c57d7c6f20d6a2268235a4745\"\u003e\u003ccode\u003e1d9e9e7\u003c/code\u003e\u003c/a\u003e [pre-commit.ci] pre-commit autoupdate (\u003ca href=\"https://redirect.github.com/tox-dev/py-filelock/issues/722\"\u003e#722\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tox-dev/filelock/commit/1585dfef9355a5c77d4a9498cc34d3a98056fdb9\"\u003e\u003ccode\u003e1585dfe\u003c/code\u003e\u003c/a\u003e Release 3.32.5\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/tox-dev/py-filelock/compare/3.23.0...3.32.6\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `plum-dispatch` from 2.5.7 to 2.10.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/beartype/plum/releases\"\u003eplum-dispatch's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.10.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eOptimise \u003ccode\u003e_wrap_type_hint\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/310\"\u003e#310\u003c/a\u003e by \u003ca href=\"https://github.com/nstarman\"\u003e\u003ccode\u003e@​nstarman\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eBuild macOS arm64 mypyc wheels (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/320\"\u003e#320\u003c/a\u003e by \u003ca href=\"https://github.com/nstarman\"\u003e\u003ccode\u003e@​nstarman\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFix \u003ca href=\"https://redirect.github.com/beartype/plum/issues/317\"\u003e#317\u003c/a\u003e and \u003ca href=\"https://redirect.github.com/beartype/plum/issues/318\"\u003e#318\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/319\"\u003e#319\u003c/a\u003e by \u003ca href=\"https://github.com/nstarman\"\u003e\u003ccode\u003e@​nstarman\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev2.10.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eCompile more things with \u003ccode\u003emypyc\u003c/code\u003e for faster dispatch (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/287\"\u003e#287\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/beartype/plum/issues/288\"\u003e#288\u003c/a\u003e, and \u003ca href=\"https://redirect.github.com/beartype/plum/issues/289\"\u003e#289\u003c/a\u003e by \u003ca href=\"https://github.com/nstarman\"\u003e\u003ccode\u003e@​nstarman\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eMake concurrent dispatch resolution thread safe (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/281\"\u003e#281\u003c/a\u003e by \u003ca href=\"https://github.com/nstarman\"\u003e\u003ccode\u003e@​nstarman\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFix support for \u003ccode\u003ebeartype\u0026gt;=0.23\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/296\"\u003e#296\u003c/a\u003e by \u003ca href=\"https://github.com/nstarman\"\u003e\u003ccode\u003e@​nstarman\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eImprove typing (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/268\"\u003e#268\u003c/a\u003e by \u003ca href=\"https://github.com/nstarman\"\u003e\u003ccode\u003e@​nstarman\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eRemove \u003ccode\u003eVal\u003c/code\u003e, which was deprecated in v0.5.0 in favour of \u003ccode\u003etyping.Literal\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/269\"\u003e#269\u003c/a\u003e by \u003ca href=\"https://github.com/nstarman\"\u003e\u003ccode\u003e@​nstarman\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev2.9.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSupport union aliases in Python 3.14 and later (\u003ca href=\"https://github.com/nstarman\"\u003e\u003ccode\u003e@​nstarman\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev2.8.0\u003c/h2\u003e\n\u003cp\u003eStarting this release, Plum will be available on PyPI as both \u003ccode\u003eplum-dispatch\u003c/code\u003e and \u003ccode\u003eplum\u003c/code\u003e.\u003c/p\u003e\n\u003ch2\u003ev2.7.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd \u003ccode\u003efaithful\u003c/code\u003e keyword to \u003ccode\u003eModuleType\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev2.7.0\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eNote:\u003c/strong\u003e All imports should now go through \u003ccode\u003eplum\u003c/code\u003e directly! That is, not \u003ccode\u003eplum.signature.Signature\u003c/code\u003e, but \u003ccode\u003eplum.Signature\u003c/code\u003e. Please do open an issue if this release breaks something that shouldn't break.\u003c/p\u003e\n\u003cp\u003eChanges:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eSignificantly improve typing of the internals (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/179\"\u003e#179\u003c/a\u003e and \u003ca href=\"https://redirect.github.com/beartype/plum/issues/242\"\u003e#242\u003c/a\u003e by \u003ca href=\"https://github.com/nstarman\"\u003e\u003ccode\u003e@​nstarman\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eSwitch to \u003ccode\u003euv\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/218\"\u003e#218\u003c/a\u003e by \u003ca href=\"https://github.com/nstarman\"\u003e\u003ccode\u003e@​nstarman\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eMake modules private for public/private separation (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/241\"\u003e#241\u003c/a\u003e by \u003ca href=\"https://github.com/nstarman\"\u003e\u003ccode\u003e@​nstarman\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eSwitch to \u003ccode\u003esrc\u003c/code\u003e layout (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/249\"\u003e#249\u003c/a\u003e by \u003ca href=\"https://github.com/nstarman\"\u003e\u003ccode\u003e@​nstarman\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eImprove config (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/248\"\u003e#248\u003c/a\u003e by \u003ca href=\"https://github.com/nstarman\"\u003e\u003ccode\u003e@​nstarman\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eEnable \u003ccode\u003emypyc\u003c/code\u003e builds for better performance (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/247\"\u003e#247\u003c/a\u003e by \u003ca href=\"https://github.com/nstarman\"\u003e\u003ccode\u003e@​nstarman\u003c/code\u003e\u003c/a\u003e)!\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev2.6.1\u003c/h2\u003e\n\u003cp\u003eThis release features numerous very helpful contributions and improvements by \u003ca href=\"https://github.com/nstarman\"\u003e\u003ccode\u003e@​nstarman\u003c/code\u003e\u003c/a\u003e!\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUse dependency groups (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/195\"\u003e#195\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eTreat \u003ccode\u003etyping_extensions\u003c/code\u003e as standard library and make more use of it (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/226\"\u003e#226\u003c/a\u003e and \u003ca href=\"https://redirect.github.com/beartype/plum/issues/232\"\u003e#232\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eComplete deprecation cycles (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/230\"\u003e#230\u003c/a\u003e and \u003ca href=\"https://redirect.github.com/beartype/plum/issues/236\"\u003e#236\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eTurn various arguments into positional-only (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/229\"\u003e#229\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eRemove unnecessary path manipulation (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/233\"\u003e#233\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eRework tests with a \u003ccode\u003edispatch\u003c/code\u003e fixture (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/234\"\u003e#234\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eAvoid using a deprecated NumPy module (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/231\"\u003e#231\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eDrops support for Python 3.9 (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/228\"\u003e#228\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eImport exports from \u003ccode\u003emethods.py\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/237\"\u003e#237\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixes an incorrect \u003ccode\u003eoverload\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/238\"\u003e#238\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eUse \u003ccode\u003enox\u003c/code\u003e for testing (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/235\"\u003e#235\u003c/a\u003e and \u003ca href=\"https://redirect.github.com/beartype/plum/issues/240\"\u003e#240\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/beartype/plum/issues/228\"\u003e#228\u003c/a\u003e also fixes an important bug to do with the handling of unions (CC \u003ca href=\"https://github.com/davidwyld\"\u003e\u003ccode\u003e@​davidwyld\u003c/code\u003e\u003c/a\u003e).\u003c/p\u003e\n\u003ch2\u003ev2.6.0\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/beartype/plum/commit/c835c8cf5ebea4f00ee304a647e026739034e63b\"\u003e\u003ccode\u003ec835c8c\u003c/code\u003e\u003c/a\u003e fix(mypyc): keep \u003ccode\u003eFunction\u003c/code\u003e weak-referenceable on the compiled wheels (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/319\"\u003e#319\u003c...\n\n_Description has been truncated_","html_url":"https://github.com/dimensionalOS/dimos/pull/4260","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/dimensionalOS%2Fdimos/issues/4260","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/4260/packages"},{"uuid":"5534319114","node_id":"PR_kwDOS8i2VM8AAAABEgrTaA","number":119,"state":"open","title":"Bump the minor-update group with 191 updates","user":"dependabot[bot]","labels":["dependencies"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-22T01:41:11.000Z","updated_at":"2026-09-22T01:41:25.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","group_name":"minor-update","update_count":191,"packages":[{"name":"regex","old_version":"2026.2.28","new_version":"2026.9.10","repository_url":"https://github.com/mrabarnett/mrab-regex"},{"name":"requests","old_version":"2.32.3","new_version":"2.34.2","repository_url":"https://github.com/psf/requests"},{"name":"tqdm","old_version":"4.67.3","new_version":"4.70.1","repository_url":"https://github.com/tqdm/tqdm"},{"name":"transformers","old_version":"5.15.0","new_version":"5.17.0","repository_url":"https://github.com/huggingface/transformers"},{"name":"huggingface-hub","old_version":"1.28.0","new_version":"1.32.0","repository_url":"https://github.com/huggingface/huggingface_hub"},{"name":"tokenizers","old_version":"0.22.2","new_version":"0.23.2","repository_url":"https://github.com/huggingface/tokenizers"},{"name":"fastapi","old_version":"0.136.3","new_version":"0.141.1","repository_url":"https://github.com/fastapi/fastapi"},{"name":"starlette","old_version":"1.3.1","new_version":"1.6.0","repository_url":"https://github.com/Kludex/starlette"},{"name":"aiohttp","old_version":"3.13.3","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"pydantic","old_version":"2.12.0","new_version":"2.13.5","repository_url":"https://github.com/pydantic/pydantic"},{"name":"prometheus-client","old_version":"0.22.0","new_version":"0.26.0","repository_url":"https://github.com/prometheus/client_python"},{"name":"prometheus-fastapi-instrumentator","old_version":"8.0.2","new_version":"8.1.0","repository_url":"https://github.com/trallnag/prometheus-fastapi-instrumentator"},{"name":"tiktoken","old_version":"0.12.0","new_version":"0.14.0","repository_url":"https://github.com/openai/tiktoken"},{"name":"lark","old_version":"1.2.2","new_version":"1.3.1","repository_url":"https://github.com/lark-parser/lark"},{"name":"typing-extensions","old_version":"4.15.0","new_version":"4.16.0","repository_url":"https://github.com/python/typing_extensions"},{"name":"jsonschema","old_version":"4.23.0","new_version":"4.26.0","repository_url":"https://github.com/python-jsonschema/jsonschema"},{"name":"pyzmq","old_version":"27.1.0","new_version":"27.2.0","repository_url":"https://github.com/zeromq/pyzmq"},{"name":"python-json-logger","old_version":"4.1.0","new_version":"4.2.0","repository_url":"https://github.com/nhairs/python-json-logger"},{"name":"pybase64","old_version":"1.4.3","new_version":"1.5.0","repository_url":"https://github.com/mayeut/pybase64"},{"name":"mcp","old_version":"2.1.1","new_version":"2.2.0","repository_url":"https://github.com/modelcontextprotocol/python-sdk"},{"name":"opentelemetry-sdk","old_version":"1.35.0","new_version":"1.44.0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"opentelemetry-api","old_version":"1.35.0","new_version":"1.44.0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"opentelemetry-exporter-otlp","old_version":"1.35.0","new_version":"1.44.0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"opentelemetry-semantic-conventions-ai","old_version":"0.4.13","new_version":"0.5.1"},{"name":"triton","old_version":"3.7.1","new_version":"3.8.0","repository_url":"https://github.com/triton-lang/triton"},{"name":"numba","old_version":"0.65.0","new_version":"0.67.0","repository_url":"https://github.com/numba/numba"},{"name":"torchcodec","old_version":"0.14.0+cu130","new_version":"0.16.0","repository_url":"https://github.com/pytorch/torchcodec"},{"name":"tpu-inference","old_version":"0.28.0","new_version":"0.29.0","repository_url":"https://github.com/vllm-project/tpu-inference"},{"name":"pynvvideocodec","old_version":"2.0.4","new_version":"2.2.3"},{"name":"fastsafetensors","old_version":"0.3.3","new_version":"0.4.0","repository_url":"https://github.com/foundation-model-stack/fastsafetensors"},{"name":"instanttensor","old_version":"0.1.9","new_version":"0.2.0","repository_url":"https://github.com/scitix/InstantTensor"},{"name":"nvidia-cutlass-dsl","old_version":"4.6.2","new_version":"4.7.1","repository_url":"https://github.com/NVIDIA/cutlass"},{"name":"tokenspeed-mla","old_version":"0.1.8","new_version":"0.2.9","repository_url":"https://github.com/lightseekorg/tokenspeed"},{"name":"absl-py","old_version":"2.1.0","new_version":"2.5.0","repository_url":"https://github.com/abseil/abseil-py"},{"name":"accelerate","old_version":"1.13.0","new_version":"1.15.0","repository_url":"https://github.com/huggingface/accelerate"},{"name":"aiohappyeyeballs","old_version":"2.6.1","new_version":"2.7.1","repository_url":"https://github.com/aio-libs/aiohappyeyeballs"},{"name":"alembic","old_version":"1.16.4","new_version":"1.20.0","repository_url":"https://github.com/sqlalchemy/alembic"},{"name":"annotated-types","old_version":"0.7.0","new_version":"0.8.0","repository_url":"https://github.com/annotated-types/annotated-types"},{"name":"anyio","old_version":"4.14.1","new_version":"4.15.1","repository_url":"https://github.com/agronholm/anyio"},{"name":"arctic-inference","old_version":"0.1.1","new_version":"0.3.0"},{"name":"argcomplete","old_version":"3.5.1","new_version":"3.7.2","repository_url":"https://github.com/kislyuk/argcomplete"},{"name":"audioread","old_version":"3.0.1","new_version":"3.1.0","repository_url":"https://github.com/beetbox/audioread"},{"name":"azure-core","old_version":"1.38.2","new_version":"1.41.0","repository_url":"https://github.com/Azure/azure-sdk-for-python"},{"name":"azure-storage-blob","old_version":"12.28.0","new_version":"12.30.2","repository_url":"https://github.com/Azure/azure-sdk-for-python"},{"name":"blobfile","old_version":"3.0.0","new_version":"3.3.0","repository_url":"https://github.com/blobfile/blobfile"},{"name":"bm25s","old_version":"0.2.13","new_version":"0.3.11","repository_url":"https://github.com/xhluca/bm25s"},{"name":"boto3","old_version":"1.35.57","new_version":"1.43.98","repository_url":"https://github.com/boto/boto3"},{"name":"botocore","old_version":"1.35.57","new_version":"1.43.98","repository_url":"https://github.com/boto/botocore"},{"name":"cffi","old_version":"2.0.0","new_version":"2.1.1","repository_url":"https://github.com/python-cffi/cffi"},{"name":"charset-normalizer","old_version":"3.4.0","new_version":"3.5.1","repository_url":"https://github.com/jawah/charset_normalizer"},{"name":"click","old_version":"8.4.2","new_version":"8.5.0","repository_url":"https://github.com/pallets/click"},{"name":"cohere","old_version":"7.0.8","new_version":"7.1.1","repository_url":"https://github.com/cohere-ai/cohere-python"},{"name":"cohere-melody","old_version":"0.11.1","new_version":"0.15.0","repository_url":"https://github.com/cohere-ai/melody"},{"name":"colorlog","old_version":"6.10.1","new_version":"6.12.0","repository_url":"https://github.com/borntyping/python-colorlog"},{"name":"coverage","old_version":"7.10.6","new_version":"7.16.1","repository_url":"https://github.com/coveragepy/coveragepy"},{"name":"cramjam","old_version":"2.9.0","new_version":"2.11.0","repository_url":"https://github.com/milesgranger/pyrus-cramjam"},{"name":"cuda-bindings","old_version":"13.0.3","new_version":"13.4.2","repository_url":"https://github.com/NVIDIA/cuda-python"},{"name":"cuda-pathfinder","old_version":"1.3.3","new_version":"1.8.2","repository_url":"https://github.com/NVIDIA/cuda-python"},{"name":"cuda-toolkit","old_version":"13.0.3.0","new_version":"13.4.2"},{"name":"datamodel-code-generator","old_version":"0.26.3","new_version":"0.82.0","repository_url":"https://github.com/datamodel-code-generator/datamodel-code-generator"},{"name":"dataproperty","old_version":"1.0.1","new_version":"1.1.1","repository_url":"https://github.com/thombashi/DataProperty"},{"name":"decorator","old_version":"5.1.1","new_version":"5.3.1","repository_url":"https://github.com/micheles/decorator"},{"name":"detect-installer","old_version":"0.1.0","new_version":"0.2.1"},{"name":"dill","old_version":"0.3.8","new_version":"0.4.1","repository_url":"https://github.com/uqfoundation/dill"},{"name":"distlib","old_version":"0.3.9","new_version":"0.4.3","repository_url":"https://github.com/pypa/distlib"},{"name":"dnspython","old_version":"2.7.0","new_version":"2.8.0","repository_url":"https://github.com/rthalley/dnspython"},{"name":"docker","old_version":"7.1.0","new_version":"7.2.0","repository_url":"https://github.com/docker/docker-py"},{"name":"einx","old_version":"0.3.0","new_version":"0.4.3","repository_url":"https://github.com/fferflo/einx"},{"name":"email-validator","old_version":"2.2.0","new_version":"2.3.0","repository_url":"https://github.com/JoshData/python-email-validator"},{"name":"fastapi-cloud-cli","old_version":"0.21.0","new_version":"0.26.0","repository_url":"https://github.com/fastapilabs/fastapi-cloud-cli"},{"name":"fastar","old_version":"0.11.0","new_version":"0.12.0","repository_url":"https://github.com/DoctorJohn/fastar"},{"name":"fonttools","old_version":"4.55.0","new_version":"4.65.0","repository_url":"https://github.com/fonttools/fonttools"},{"name":"frozenlist","old_version":"1.5.0","new_version":"1.8.0","repository_url":"https://github.com/aio-libs/frozenlist"},{"name":"genson","old_version":"1.3.0","new_version":"1.4.0","repository_url":"https://github.com/wolverdude/genson"},{"name":"google-api-core","old_version":"2.24.2","new_version":"2.38.0","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"google-auth","old_version":"2.40.2","new_version":"2.58.0","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"google-cloud-core","old_version":"2.4.3","new_version":"2.7.0","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"google-cloud-storage","old_version":"3.4.0","new_version":"3.14.1","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"google-crc32c","old_version":"1.7.1","new_version":"1.8.0","repository_url":"https://github.com/googleapis/python-crc32c"},{"name":"google-resumable-media","old_version":"2.7.2","new_version":"2.10.2","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"googleapis-common-protos","old_version":"1.70.0","new_version":"1.75.3","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"greenlet","old_version":"3.2.3","new_version":"3.5.6","repository_url":"https://github.com/python-greenlet/greenlet"},{"name":"grpcio","old_version":"1.78.0","new_version":"1.84.0","repository_url":"https://github.com/grpc/grpc"},{"name":"grpcio-reflection","old_version":"1.78.0","new_version":"1.84.0"},{"name":"h2","old_version":"4.3.0","new_version":"4.4.1","repository_url":"https://github.com/python-hyper/h2"},{"name":"hiredis","old_version":"3.0.0","new_version":"3.4.1","repository_url":"https://github.com/redis/hiredis-py"},{"name":"hpack","old_version":"4.1.0","new_version":"4.2.0","repository_url":"https://github.com/python-hyper/hpack"},{"name":"httpcore2","old_version":"2.12.0","new_version":"2.13.0","repository_url":"https://github.com/pydantic/httpx2"},{"name":"httpx","old_version":"0.27.2","new_version":"0.28.1","repository_url":"https://github.com/encode/httpx"},{"name":"httpx2","old_version":"2.12.0","new_version":"2.13.0","repository_url":"https://github.com/pydantic/httpx2"},{"name":"humanize","old_version":"4.11.0","new_version":"4.16.0","repository_url":"https://github.com/python-humanize/humanize"},{"name":"hypothesis","old_version":"6.131.0","new_version":"6.168.0","repository_url":"https://github.com/HypothesisWorks/hypothesis"},{"name":"idna","old_version":"3.19","new_version":"3.20","repository_url":"https://github.com/kjd/idna"},{"name":"iniconfig","old_version":"2.0.0","new_version":"2.3.0","repository_url":"https://github.com/pytest-dev/iniconfig"},{"name":"jiter","old_version":"0.15.0","new_version":"0.17.0","repository_url":"https://github.com/pydantic/jiter"},{"name":"jmespath","old_version":"1.0.1","new_version":"1.1.0","repository_url":"https://github.com/jmespath/jmespath.py"},{"name":"joblib","old_version":"1.4.2","new_version":"1.6.0","repository_url":"https://github.com/joblib/joblib"},{"name":"jsonschema-rs","old_version":"0.46.5","new_version":"0.56.0","repository_url":"https://github.com/Stranger6667/jsonschema"},{"name":"kiwisolver","old_version":"1.4.7","new_version":"1.5.1","repository_url":"https://github.com/nucleic/kiwi"},{"name":"lazy-loader","old_version":"0.4","new_version":"0.5","repository_url":"https://github.com/scientific-python/lazy-loader"},{"name":"llguidance","old_version":"1.7.6","new_version":"1.8.0","repository_url":"https://github.com/microsoft/llguidance"},{"name":"llvmlite","old_version":"0.47.0","new_version":"0.49.0","repository_url":"https://github.com/numba/llvmlite"},{"name":"mako","old_version":"1.3.10","new_version":"1.4.1","repository_url":"https://github.com/sqlalchemy/mako"},{"name":"matplotlib","old_version":"3.9.2","new_version":"3.10.9","repository_url":"https://github.com/matplotlib/matplotlib"},{"name":"mcp-types","old_version":"2.1.1","new_version":"2.2.0","repository_url":"https://github.com/modelcontextprotocol/python-sdk"},{"name":"mpmath","old_version":"1.3.0","new_version":"1.4.1","repository_url":"https://github.com/mpmath/mpmath"},{"name":"msal","old_version":"1.34.0","new_version":"1.39.0","repository_url":"https://github.com/AzureAD/microsoft-authentication-library-for-python"},{"name":"msgpack","old_version":"1.1.0","new_version":"1.2.2","repository_url":"https://github.com/msgpack/msgpack-python"},{"name":"mteb","old_version":"2.8.3","new_version":"2.21.0","repository_url":"https://github.com/embeddings-benchmark/mteb"},{"name":"multidict","old_version":"6.1.0","new_version":"6.9.0","repository_url":"https://github.com/aio-libs/multidict"},{"name":"mypy-extensions","old_version":"1.0.0","new_version":"1.1.0","repository_url":"https://github.com/python/mypy_extensions"},{"name":"networkx","old_version":"3.2.1","new_version":"3.4.2","repository_url":"https://github.com/networkx/networkx"},{"name":"nltk","old_version":"3.9.1","new_version":"3.10.3","repository_url":"https://github.com/nltk/nltk"},{"name":"nvidia-cublas","old_version":"13.1.1.3","new_version":"13.8.0.4"},{"name":"nvidia-cuda-cupti","old_version":"13.0.85","new_version":"13.4.92"},{"name":"nvidia-cuda-nvrtc","old_version":"13.0.88","new_version":"13.4.92"},{"name":"nvidia-cuda-runtime","old_version":"13.0.96","new_version":"13.4.92"},{"name":"nvidia-cudnn-cu13","old_version":"9.20.0.48","new_version":"9.26.0.51"},{"name":"nvidia-cufft","old_version":"12.0.0.61","new_version":"12.4.0.43"},{"name":"nvidia-cufile","old_version":"1.15.1.6","new_version":"1.19.1.55"},{"name":"nvidia-cusolver","old_version":"12.0.4.66","new_version":"12.3.4.7"},{"name":"nvidia-cusparse","old_version":"12.6.3.3","new_version":"12.8.6.72"},{"name":"nvidia-cusparselt-cu13","old_version":"0.8.1","new_version":"0.9.1"},{"name":"nvidia-nccl-cu13","old_version":"2.29.7","new_version":"2.31.2"},{"name":"nvidia-nvjitlink","old_version":"13.0.88","new_version":"13.4.92"},{"name":"nvidia-nvshmem-cu13","old_version":"3.4.5","new_version":"3.7.2"},{"name":"nvidia-nvtx","old_version":"13.0.85","new_version":"13.4.92"},{"name":"opentelemetry-exporter-otlp-proto-common","old_version":"1.35.0","new_version":"1.44.0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"opentelemetry-exporter-otlp-proto-grpc","old_version":"1.35.0","new_version":"1.44.0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"opentelemetry-exporter-otlp-proto-http","old_version":"1.35.0","new_version":"1.44.0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"opentelemetry-exporter-prometheus","old_version":"0.56b0","new_version":"0.65b0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"opentelemetry-proto","old_version":"1.35.0","new_version":"1.44.0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"opentelemetry-semantic-conventions","old_version":"0.56b0","new_version":"0.65b0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"orjson","old_version":"3.11.5","new_version":"3.12.0","repository_url":"https://github.com/ijl/orjson"},{"name":"pathvalidate","old_version":"3.2.1","new_version":"3.3.1","repository_url":"https://github.com/thombashi/pathvalidate"},{"name":"peft","old_version":"0.19.1","new_version":"0.21.0","repository_url":"https://github.com/huggingface/peft"},{"name":"perceptron","old_version":"0.1.4","new_version":"0.3.5","repository_url":"https://github.com/perceptron-ai-inc/perceptron"},{"name":"platformdirs","old_version":"4.3.6","new_version":"4.11.10","repository_url":"https://github.com/tox-dev/platformdirs"},{"name":"pluggy","old_version":"1.5.0","new_version":"1.6.0","repository_url":"https://github.com/pytest-dev/pluggy"},{"name":"polars","old_version":"1.29.0","new_version":"1.44.2","repository_url":"https://github.com/pola-rs/polars"},{"name":"pooch","old_version":"1.8.2","new_version":"1.9.0","repository_url":"https://github.com/fatiando/pooch"},{"name":"propcache","old_version":"0.2.0","new_version":"0.5.4","repository_url":"https://github.com/aio-libs/propcache"},{"name":"proto-plus","old_version":"1.26.1","new_version":"1.28.4","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"pycryptodomex","old_version":"3.22.0","new_version":"3.23.0","repository_url":"https://github.com/Legrandin/pycryptodome"},{"name":"pydantic-core","old_version":"2.41.1","new_version":"2.49.0","repository_url":"https://github.com/pydantic/pydantic"},{"name":"pydantic-extra-types","old_version":"2.10.5","new_version":"2.11.1","repository_url":"https://github.com/pydantic/pydantic-extra-types"},{"name":"pydantic-settings","old_version":"2.14.2","new_version":"2.15.0","repository_url":"https://github.com/pydantic/pydantic-settings"},{"name":"pygments","old_version":"2.18.0","new_version":"2.21.0","repository_url":"https://github.com/pygments/pygments"},{"name":"pyjwt","old_version":"2.11.0","new_version":"2.14.0","repository_url":"https://github.com/jpadilla/pyjwt"},{"name":"pyparsing","old_version":"3.2.0","new_version":"3.3.2","repository_url":"https://github.com/pyparsing/pyparsing"},{"name":"pyrate-limiter","old_version":"4.4.0","new_version":"4.5.0","repository_url":"https://github.com/vutran1710/PyrateLimiter"},{"name":"pystemmer","old_version":"3.0.0","new_version":"3.1.0","repository_url":"https://github.com/snowballstem/pystemmer"},{"name":"pytest-forked","old_version":"1.6.0","new_version":"1.7.5","repository_url":"https://github.com/pytest-dev/pytest-forked"},{"name":"pytest-mock","old_version":"3.14.0","new_version":"3.15.1","repository_url":"https://github.com/pytest-dev/pytest-mock"},{"name":"pytest-timeout","old_version":"2.3.1","new_version":"2.4.0","repository_url":"https://github.com/pytest-dev/pytest-timeout"},{"name":"python-rapidjson","old_version":"1.20","new_version":"1.25","repository_url":"https://github.com/python-rapidjson/python-rapidjson"},{"name":"rapidfuzz","old_version":"3.12.1","new_version":"3.14.5","repository_url":"https://github.com/rapidfuzz/RapidFuzz"},{"name":"referencing","old_version":"0.35.1","new_version":"0.37.0","repository_url":"https://github.com/python-jsonschema/referencing"},{"name":"responses","old_version":"0.25.3","new_version":"0.26.3","repository_url":"https://github.com/getsentry/responses"},{"name":"rignore","old_version":"0.7.6","new_version":"0.8.1"},{"name":"runai-model-streamer","old_version":"0.15.7","new_version":"0.16.1"},{"name":"runai-model-streamer-azure","old_version":"0.15.7","new_version":"0.16.1"},{"name":"runai-model-streamer-gcs","old_version":"0.15.7","new_version":"0.16.1"},{"name":"runai-model-streamer-s3","old_version":"0.15.7","new_version":"0.16.1"},{"name":"s3transfer","old_version":"0.10.3","new_version":"0.19.2","repository_url":"https://github.com/boto/s3transfer"},{"name":"sacrebleu","old_version":"2.4.3","new_version":"2.6.0","repository_url":"https://github.com/mjpost/sacrebleu"},{"name":"schemathesis","old_version":"4.21.6","new_version":"4.27.4","repository_url":"https://github.com/schemathesis/schemathesis"},{"name":"scikit-learn","old_version":"1.5.2","new_version":"1.7.2","repository_url":"https://github.com/scikit-learn/scikit-learn"},{"name":"scipy","old_version":"1.13.1","new_version":"1.15.3","repository_url":"https://github.com/scipy/scipy"},{"name":"sentry-sdk","old_version":"2.63.0","new_version":"2.69.2","repository_url":"https://github.com/getsentry/sentry-python"},{"name":"six","old_version":"1.16.0","new_version":"1.17.0","repository_url":"https://github.com/benjaminp/six"},{"name":"soundfile","old_version":"0.12.1","new_version":"0.14.0","repository_url":"https://github.com/bastibe/python-soundfile"},{"name":"statsmodels","old_version":"0.14.4","new_version":"0.15.0","repository_url":"https://github.com/statsmodels/statsmodels"},{"name":"sympy","old_version":"1.13.3","new_version":"1.14.0","repository_url":"https://github.com/sympy/sympy"},{"name":"tabulate","old_version":"0.9.0","new_version":"0.10.0","repository_url":"https://github.com/astanin/python-tabulate"},{"name":"tblib","old_version":"3.1.0","new_version":"3.2.2","repository_url":"https://github.com/ionelmc/python-tblib"},{"name":"tensorizer","old_version":"2.10.1","new_version":"2.12.1","repository_url":"https://github.com/coreweave/tensorizer"},{"name":"termcolor","old_version":"3.1.0","new_version":"3.3.0","repository_url":"https://github.com/termcolor/termcolor"},{"name":"threadpoolctl","old_version":"3.5.0","new_version":"3.7.0","repository_url":"https://github.com/joblib/threadpoolctl"},{"name":"tritonclient","old_version":"2.64.0","new_version":"2.71.0","repository_url":"https://github.com/triton-inference-server/client"},{"name":"typer","old_version":"0.26.8","new_version":"0.27.2","repository_url":"https://github.com/fastapi/typer"},{"name":"urllib3","old_version":"2.2.3","new_version":"2.8.0","repository_url":"https://github.com/urllib3/urllib3"},{"name":"uvicorn","old_version":"0.35.0","new_version":"0.53.0","repository_url":"https://github.com/Kludex/uvicorn"},{"name":"vector-quantize-pytorch","old_version":"1.21.2","new_version":"1.31.4","repository_url":"https://github.com/lucidrains/vector-quantizer-pytorch"},{"name":"wcwidth","old_version":"0.2.13","new_version":"0.8.4","repository_url":"https://github.com/jquast/wcwidth"},{"name":"yarl","old_version":"1.17.1","new_version":"1.25.1","repository_url":"https://github.com/aio-libs/yarl"},{"name":"conch-triton-kernels","old_version":"1.2.1","new_version":"1.3","repository_url":"https://github.com/stackav-oss/conch"},{"name":"griffelib","old_version":"2.0.2","new_version":"2.3.0"},{"name":"mkdocs-git-revision-date-localized-plugin","old_version":"1.5.1","new_version":"1.6.0","repository_url":"https://github.com/timvink/mkdocs-git-revision-date-localized-plugin"},{"name":"ruff","old_version":"0.15.12","new_version":"0.16.8","repository_url":"https://github.com/astral-sh/ruff"},{"name":"zentorch","old_version":"2.13.0.0","new_version":"2.14.0.0","repository_url":"https://github.com/amd/ZenDNN-pytorch-plugin"}],"path":null,"ecosystem":"pip"},"body":"Bumps the minor-update group with 191 updates:\n\n| Package | From | To |\n| --- | --- | --- |\n| [regex](https://github.com/mrabarnett/mrab-regex) | `2026.2.28` | `2026.9.10` |\n| [requests](https://github.com/psf/requests) | `2.32.3` | `2.34.2` |\n| [tqdm](https://github.com/tqdm/tqdm) | `4.67.3` | `4.70.1` |\n| [transformers](https://github.com/huggingface/transformers) | `5.15.0` | `5.17.0` |\n| [huggingface-hub](https://github.com/huggingface/huggingface_hub) | `1.28.0` | `1.32.0` |\n| [tokenizers](https://github.com/huggingface/tokenizers) | `0.22.2` | `0.23.2` |\n| [fastapi](https://github.com/fastapi/fastapi) | `0.136.3` | `0.141.1` |\n| [starlette](https://github.com/Kludex/starlette) | `1.3.1` | `1.6.0` |\n| [aiohttp](https://github.com/aio-libs/aiohttp) | `3.13.3` | `3.14.3` |\n| [pydantic](https://github.com/pydantic/pydantic) | `2.12.0` | `2.13.5` |\n| [prometheus-client](https://github.com/prometheus/client_python) | `0.22.0` | `0.26.0` |\n| [prometheus-fastapi-instrumentator](https://github.com/trallnag/prometheus-fastapi-instrumentator) | `8.0.2` | `8.1.0` |\n| [tiktoken](https://github.com/openai/tiktoken) | `0.12.0` | `0.14.0` |\n| [lark](https://github.com/lark-parser/lark) | `1.2.2` | `1.3.1` |\n| [typing-extensions](https://github.com/python/typing_extensions) | `4.15.0` | `4.16.0` |\n| [jsonschema](https://github.com/python-jsonschema/jsonschema) | `4.23.0` | `4.26.0` |\n| [pyzmq](https://github.com/zeromq/pyzmq) | `27.1.0` | `27.2.0` |\n| [python-json-logger](https://github.com/nhairs/python-json-logger) | `4.1.0` | `4.2.0` |\n| [pybase64](https://github.com/mayeut/pybase64) | `1.4.3` | `1.5.0` |\n| [mcp](https://github.com/modelcontextprotocol/python-sdk) | `2.1.1` | `2.2.0` |\n| [opentelemetry-sdk](https://github.com/open-telemetry/opentelemetry-python) | `1.35.0` | `1.44.0` |\n| [opentelemetry-api](https://github.com/open-telemetry/opentelemetry-python) | `1.35.0` | `1.44.0` |\n| [opentelemetry-exporter-otlp](https://github.com/open-telemetry/opentelemetry-python) | `1.35.0` | `1.44.0` |\n| opentelemetry-semantic-conventions-ai | `0.4.13` | `0.5.1` |\n| [triton](https://github.com/triton-lang/triton) | `3.7.1` | `3.8.0` |\n| [numba](https://github.com/numba/numba) | `0.65.0` | `0.67.0` |\n| [torchcodec](https://github.com/pytorch/torchcodec) | `0.14.0+cu130` | `0.16.0` |\n| [tpu-inference](https://github.com/vllm-project/tpu-inference) | `0.28.0` | `0.29.0` |\n| pynvvideocodec | `2.0.4` | `2.2.3` |\n| [fastsafetensors](https://github.com/foundation-model-stack/fastsafetensors) | `0.3.3` | `0.4.0` |\n| [instanttensor](https://github.com/scitix/InstantTensor) | `0.1.9` | `0.2.0` |\n| [nvidia-cutlass-dsl](https://github.com/NVIDIA/cutlass) | `4.6.2` | `4.7.1` |\n| [tokenspeed-mla](https://github.com/lightseekorg/tokenspeed) | `0.1.8` | `0.2.9` |\n| [absl-py](https://github.com/abseil/abseil-py) | `2.1.0` | `2.5.0` |\n| [accelerate](https://github.com/huggingface/accelerate) | `1.13.0` | `1.15.0` |\n| [aiohappyeyeballs](https://github.com/aio-libs/aiohappyeyeballs) | `2.6.1` | `2.7.1` |\n| [alembic](https://github.com/sqlalchemy/alembic) | `1.16.4` | `1.20.0` |\n| [annotated-types](https://github.com/annotated-types/annotated-types) | `0.7.0` | `0.8.0` |\n| [anyio](https://github.com/agronholm/anyio) | `4.14.1` | `4.15.1` |\n| arctic-inference | `0.1.1` | `0.3.0` |\n| [argcomplete](https://github.com/kislyuk/argcomplete) | `3.5.1` | `3.7.2` |\n| [audioread](https://github.com/beetbox/audioread) | `3.0.1` | `3.1.0` |\n| [azure-core](https://github.com/Azure/azure-sdk-for-python) | `1.38.2` | `1.41.0` |\n| [azure-storage-blob](https://github.com/Azure/azure-sdk-for-python) | `12.28.0` | `12.30.2` |\n| [blobfile](https://github.com/blobfile/blobfile) | `3.0.0` | `3.3.0` |\n| [bm25s](https://github.com/xhluca/bm25s) | `0.2.13` | `0.3.11` |\n| [boto3](https://github.com/boto/boto3) | `1.35.57` | `1.43.98` |\n| [botocore](https://github.com/boto/botocore) | `1.35.57` | `1.43.98` |\n| [cffi](https://github.com/python-cffi/cffi) | `2.0.0` | `2.1.1` |\n| [charset-normalizer](https://github.com/jawah/charset_normalizer) | `3.4.0` | `3.5.1` |\n| [click](https://github.com/pallets/click) | `8.4.2` | `8.5.0` |\n| [cohere](https://github.com/cohere-ai/cohere-python) | `7.0.8` | `7.1.1` |\n| [cohere-melody](https://github.com/cohere-ai/melody) | `0.11.1` | `0.15.0` |\n| [colorlog](https://github.com/borntyping/python-colorlog) | `6.10.1` | `6.12.0` |\n| [coverage](https://github.com/coveragepy/coveragepy) | `7.10.6` | `7.16.1` |\n| [cramjam](https://github.com/milesgranger/pyrus-cramjam) | `2.9.0` | `2.11.0` |\n| [cuda-bindings](https://github.com/NVIDIA/cuda-python) | `13.0.3` | `13.4.2` |\n| [cuda-pathfinder](https://github.com/NVIDIA/cuda-python) | `1.3.3` | `1.8.2` |\n| [cuda-toolkit](https://developer.nvidia.com/cuda-toolkit) | `13.0.3.0` | `13.4.2` |\n| [datamodel-code-generator](https://github.com/datamodel-code-generator/datamodel-code-generator) | `0.26.3` | `0.82.0` |\n| [dataproperty](https://github.com/thombashi/DataProperty) | `1.0.1` | `1.1.1` |\n| [decorator](https://github.com/micheles/decorator) | `5.1.1` | `5.3.1` |\n| detect-installer | `0.1.0` | `0.2.1` |\n| [dill](https://github.com/uqfoundation/dill) | `0.3.8` | `0.4.1` |\n| [distlib](https://github.com/pypa/distlib) | `0.3.9` | `0.4.3` |\n| [dnspython](https://github.com/rthalley/dnspython) | `2.7.0` | `2.8.0` |\n| [docker](https://github.com/docker/docker-py) | `7.1.0` | `7.2.0` |\n| [einx](https://github.com/fferflo/einx) | `0.3.0` | `0.4.3` |\n| [email-validator](https://github.com/JoshData/python-email-validator) | `2.2.0` | `2.3.0` |\n| [fastapi-cloud-cli](https://github.com/fastapilabs/fastapi-cloud-cli) | `0.21.0` | `0.26.0` |\n| [fastar](https://github.com/DoctorJohn/fastar) | `0.11.0` | `0.12.0` |\n| [fonttools](https://github.com/fonttools/fonttools) | `4.55.0` | `4.65.0` |\n| [frozenlist](https://github.com/aio-libs/frozenlist) | `1.5.0` | `1.8.0` |\n| [genson](https://github.com/wolverdude/genson) | `1.3.0` | `1.4.0` |\n| [google-api-core](https://github.com/googleapis/google-cloud-python) | `2.24.2` | `2.38.0` |\n| [google-auth](https://github.com/googleapis/google-cloud-python) | `2.40.2` | `2.58.0` |\n| [google-cloud-core](https://github.com/googleapis/google-cloud-python) | `2.4.3` | `2.7.0` |\n| [google-cloud-storage](https://github.com/googleapis/google-cloud-python) | `3.4.0` | `3.14.1` |\n| [google-crc32c](https://github.com/googleapis/python-crc32c) | `1.7.1` | `1.8.0` |\n| [google-resumable-media](https://github.com/googleapis/google-cloud-python) | `2.7.2` | `2.10.2` |\n| [googleapis-common-protos](https://github.com/googleapis/google-cloud-python) | `1.70.0` | `1.75.3` |\n| [greenlet](https://github.com/python-greenlet/greenlet) | `3.2.3` | `3.5.6` |\n| [grpcio](https://github.com/grpc/grpc) | `1.78.0` | `1.84.0` |\n| [grpcio-reflection](https://grpc.io) | `1.78.0` | `1.84.0` |\n| [h2](https://github.com/python-hyper/h2) | `4.3.0` | `4.4.1` |\n| [hiredis](https://github.com/redis/hiredis-py) | `3.0.0` | `3.4.1` |\n| [hpack](https://github.com/python-hyper/hpack) | `4.1.0` | `4.2.0` |\n| [httpcore2](https://github.com/pydantic/httpx2) | `2.12.0` | `2.13.0` |\n| [httpx](https://github.com/encode/httpx) | `0.27.2` | `0.28.1` |\n| [httpx2](https://github.com/pydantic/httpx2) | `2.12.0` | `2.13.0` |\n| [humanize](https://github.com/python-humanize/humanize) | `4.11.0` | `4.16.0` |\n| [hypothesis](https://github.com/HypothesisWorks/hypothesis) | `6.131.0` | `6.168.0` |\n| [idna](https://github.com/kjd/idna) | `3.19` | `3.20` |\n| [iniconfig](https://github.com/pytest-dev/iniconfig) | `2.0.0` | `2.3.0` |\n| [jiter](https://github.com/pydantic/jiter) | `0.15.0` | `0.17.0` |\n| [jmespath](https://github.com/jmespath/jmespath.py) | `1.0.1` | `1.1.0` |\n| [joblib](https://github.com/joblib/joblib) | `1.4.2` | `1.6.0` |\n| [jsonschema-rs](https://github.com/Stranger6667/jsonschema) | `0.46.5` | `0.56.0` |\n| [kiwisolver](https://github.com/nucleic/kiwi) | `1.4.7` | `1.5.1` |\n| [lazy-loader](https://github.com/scientific-python/lazy-loader) | `0.4` | `0.5` |\n| [llguidance](https://github.com/microsoft/llguidance) | `1.7.6` | `1.8.0` |\n| [llvmlite](https://github.com/numba/llvmlite) | `0.47.0` | `0.49.0` |\n| [mako](https://github.com/sqlalchemy/mako) | `1.3.10` | `1.4.1` |\n| [matplotlib](https://github.com/matplotlib/matplotlib) | `3.9.2` | `3.10.9` |\n| [mcp-types](https://github.com/modelcontextprotocol/python-sdk) | `2.1.1` | `2.2.0` |\n| [mpmath](https://github.com/mpmath/mpmath) | `1.3.0` | `1.4.1` |\n| [msal](https://github.com/AzureAD/microsoft-authentication-library-for-python) | `1.34.0` | `1.39.0` |\n| [msgpack](https://github.com/msgpack/msgpack-python) | `1.1.0` | `1.2.2` |\n| [mteb](https://github.com/embeddings-benchmark/mteb) | `2.8.3` | `2.21.0` |\n| [multidict](https://github.com/aio-libs/multidict) | `6.1.0` | `6.9.0` |\n| [mypy-extensions](https://github.com/python/mypy_extensions) | `1.0.0` | `1.1.0` |\n| [networkx](https://github.com/networkx/networkx) | `3.2.1` | `3.4.2` |\n| [nltk](https://github.com/nltk/nltk) | `3.9.1` | `3.10.3` |\n| [nvidia-cublas](https://developer.nvidia.com/cuda-zone) | `13.1.1.3` | `13.8.0.4` |\n| [nvidia-cuda-cupti](https://developer.nvidia.com/cuda-zone) | `13.0.85` | `13.4.92` |\n| [nvidia-cuda-nvrtc](https://developer.nvidia.com/cuda-zone) | `13.0.88` | `13.4.92` |\n| [nvidia-cuda-runtime](https://developer.nvidia.com/cuda-zone) | `13.0.96` | `13.4.92` |\n| [nvidia-cudnn-cu13](https://developer.nvidia.com/cuda-zone) | `9.20.0.48` | `9.26.0.51` |\n| [nvidia-cufft](https://developer.nvidia.com/cuda-zone) | `12.0.0.61` | `12.4.0.43` |\n| [nvidia-cufile](https://developer.nvidia.com/cuda-zone) | `1.15.1.6` | `1.19.1.55` |\n| [nvidia-cusolver](https://developer.nvidia.com/cuda-zone) | `12.0.4.66` | `12.3.4.7` |\n| [nvidia-cusparse](https://developer.nvidia.com/cuda-zone) | `12.6.3.3` | `12.8.6.72` |\n| [nvidia-cusparselt-cu13](https://developer.nvidia.com/cusparselt) | `0.8.1` | `0.9.1` |\n| [nvidia-nccl-cu13](https://developer.nvidia.com/cuda-zone) | `2.29.7` | `2.31.2` |\n| [nvidia-nvjitlink](https://developer.nvidia.com/cuda-zone) | `13.0.88` | `13.4.92` |\n| [nvidia-nvshmem-cu13](https://developer.nvidia.com/cuda-zone) | `3.4.5` | `3.7.2` |\n| [nvidia-nvtx](https://developer.nvidia.com/cuda-zone) | `13.0.85` | `13.4.92` |\n| [opentelemetry-exporter-otlp-proto-common](https://github.com/open-telemetry/opentelemetry-python) | `1.35.0` | `1.44.0` |\n| [opentelemetry-exporter-otlp-proto-grpc](https://github.com/open-telemetry/opentelemetry-python) | `1.35.0` | `1.44.0` |\n| [opentelemetry-exporter-otlp-proto-http](https://github.com/open-telemetry/opentelemetry-python) | `1.35.0` | `1.44.0` |\n| [opentelemetry-exporter-prometheus](https://github.com/open-telemetry/opentelemetry-python) | `0.56b0` | `0.65b0` |\n| [opentelemetry-proto](https://github.com/open-telemetry/opentelemetry-python) | `1.35.0` | `1.44.0` |\n| [opentelemetry-semantic-conventions](https://github.com/open-telemetry/opentelemetry-python) | `0.56b0` | `0.65b0` |\n| [orjson](https://github.com/ijl/orjson) | `3.11.5` | `3.12.0` |\n| [pathvalidate](https://github.com/thombashi/pathvalidate) | `3.2.1` | `3.3.1` |\n| [peft](https://github.com/huggingface/peft) | `0.19.1` | `0.21.0` |\n| [perceptron](https://github.com/perceptron-ai-inc/perceptron) | `0.1.4` | `0.3.5` |\n| [platformdirs](https://github.com/tox-dev/platformdirs) | `4.3.6` | `4.11.10` |\n| [pluggy](https://github.com/pytest-dev/pluggy) | `1.5.0` | `1.6.0` |\n| [polars](https://github.com/pola-rs/polars) | `1.29.0` | `1.44.2` |\n| [pooch](https://github.com/fatiando/pooch) | `1.8.2` | `1.9.0` |\n| [propcache](https://github.com/aio-libs/propcache) | `0.2.0` | `0.5.4` |\n| [proto-plus](https://github.com/googleapis/google-cloud-python) | `1.26.1` | `1.28.4` |\n| [pycryptodomex](https://github.com/Legrandin/pycryptodome) | `3.22.0` | `3.23.0` |\n| [pydantic-core](https://github.com/pydantic/pydantic) | `2.41.1` | `2.49.0` |\n| [pydantic-extra-types](https://github.com/pydantic/pydantic-extra-types) | `2.10.5` | `2.11.1` |\n| [pydantic-settings](https://github.com/pydantic/pydantic-settings) | `2.14.2` | `2.15.0` |\n| [pygments](https://github.com/pygments/pygments) | `2.18.0` | `2.21.0` |\n| [pyjwt](https://github.com/jpadilla/pyjwt) | `2.11.0` | `2.14.0` |\n| [pyparsing](https://github.com/pyparsing/pyparsing) | `3.2.0` | `3.3.2` |\n| [pyrate-limiter](https://github.com/vutran1710/PyrateLimiter) | `4.4.0` | `4.5.0` |\n| [pystemmer](https://github.com/snowballstem/pystemmer) | `3.0.0` | `3.1.0` |\n| [pytest-forked](https://github.com/pytest-dev/pytest-forked) | `1.6.0` | `1.7.5` |\n| [pytest-mock](https://github.com/pytest-dev/pytest-mock) | `3.14.0` | `3.15.1` |\n| [pytest-timeout](https://github.com/pytest-dev/pytest-timeout) | `2.3.1` | `2.4.0` |\n| [python-rapidjson](https://github.com/python-rapidjson/python-rapidjson) | `1.20` | `1.25` |\n| [rapidfuzz](https://github.com/rapidfuzz/RapidFuzz) | `3.12.1` | `3.14.5` |\n| [referencing](https://github.com/python-jsonschema/referencing) | `0.35.1` | `0.37.0` |\n| [responses](https://github.com/getsentry/responses) | `0.25.3` | `0.26.3` |\n| rignore | `0.7.6` | `0.8.1` |\n| runai-model-streamer | `0.15.7` | `0.16.1` |\n| runai-model-streamer-azure | `0.15.7` | `0.16.1` |\n| runai-model-streamer-gcs | `0.15.7` | `0.16.1` |\n| runai-model-streamer-s3 | `0.15.7` | `0.16.1` |\n| [s3transfer](https://github.com/boto/s3transfer) | `0.10.3` | `0.19.2` |\n| [sacrebleu](https://github.com/mjpost/sacrebleu) | `2.4.3` | `2.6.0` |\n| [schemathesis](https://github.com/schemathesis/schemathesis) | `4.21.6` | `4.27.4` |\n| [scikit-learn](https://github.com/scikit-learn/scikit-learn) | `1.5.2` | `1.7.2` |\n| [scipy](https://github.com/scipy/scipy) | `1.13.1` | `1.15.3` |\n| [sentry-sdk](https://github.com/getsentry/sentry-python) | `2.63.0` | `2.69.2` |\n| [six](https://github.com/benjaminp/six) | `1.16.0` | `1.17.0` |\n| [soundfile](https://github.com/bastibe/python-soundfile) | `0.12.1` | `0.14.0` |\n| [statsmodels](https://github.com/statsmodels/statsmodels) | `0.14.4` | `0.15.0` |\n| [sympy](https://github.com/sympy/sympy) | `1.13.3` | `1.14.0` |\n| [tabulate](https://github.com/astanin/python-tabulate) | `0.9.0` | `0.10.0` |\n| [tblib](https://github.com/ionelmc/python-tblib) | `3.1.0` | `3.2.2` |\n| [tensorizer](https://github.com/coreweave/tensorizer) | `2.10.1` | `2.12.1` |\n| [termcolor](https://github.com/termcolor/termcolor) | `3.1.0` | `3.3.0` |\n| [threadpoolctl](https://github.com/joblib/threadpoolctl) | `3.5.0` | `3.7.0` |\n| [tritonclient](https://github.com/triton-inference-server/client) | `2.64.0` | `2.71.0` |\n| [typer](https://github.com/fastapi/typer) | `0.26.8` | `0.27.2` |\n| [urllib3](https://github.com/urllib3/urllib3) | `2.2.3` | `2.8.0` |\n| [uvicorn](https://github.com/Kludex/uvicorn) | `0.35.0` | `0.53.0` |\n| [vector-quantize-pytorch](https://github.com/lucidrains/vector-quantizer-pytorch) | `1.21.2` | `1.31.4` |\n| [wcwidth](https://github.com/jquast/wcwidth) | `0.2.13` | `0.8.4` |\n| [yarl](https://github.com/aio-libs/yarl) | `1.17.1` | `1.25.1` |\n| [conch-triton-kernels](https://github.com/stackav-oss/conch) | `1.2.1` | `1.3` |\n| griffelib | `2.0.2` | `2.3.0` |\n| [mkdocs-git-revision-date-localized-plugin](https://github.com/timvink/mkdocs-git-revision-date-localized-plugin) | `1.5.1` | `1.6.0` |\n| [ruff](https://github.com/astral-sh/ruff) | `0.15.12` | `0.16.8` |\n| [zentorch](https://github.com/amd/ZenDNN-pytorch-plugin) | `2.13.0.0` | `2.14.0.0` |\n\nUpdates `regex` from 2026.2.28 to 2026.9.10\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/mrabarnett/mrab-regex/blob/hg/changelog.txt\"\u003eregex's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003eVersion: 2026.9.19\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eGit issue 619: `Match.expand()` segfaults after `detach_string()` when the template references a group\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.9.10\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eFixed version.\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.9.9\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003ePR [#615](https://github.com/mrabarnett/mrab-regex/issues/615): Fix Python API error propagation in match helpers\n\u003cp\u003ePR \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/616\"\u003e#616\u003c/a\u003e: Preserve Python Exceptions in Input Decoding and String Detachment\u003c/p\u003e\n\u003cp\u003ePR \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/617\"\u003e#617\u003c/a\u003e: Prevent Invalid Pointer Use and Exception State Corruption in Byte String Joining\u003c/p\u003e\n\u003cp\u003ePR \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/618\"\u003e#618\u003c/a\u003e: Propagate Allocation and Internal Errors During Pattern Compilation and Scanner Execution\n\u003c/code\u003e\u003c/pre\u003e\u003c/p\u003e\n\u003cp\u003eVersion: 2026.9.3\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eNew version of cibuildwheel no longer supports building for free-threaded Python 3.13.\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.9.2\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eNew version of cibuildwheel no longer needs nor supports cpython-freethreading option.\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.9.1\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eUpdated cibuildwheel.\nSupport Python 3.15.\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.8.31\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eFixed version.\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.8.30\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eGit issue 611: Heap out-of-bounds write at compile time\nGit issue 612: count_one() size underflow through the stale required-string cache\nGit issue 613: (*SKIP) inside an atomic group, plus an equality-only scan stop\nGit issue 614: build_GROUP() does not propagate the match direction\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.8.12\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eSupport Python 3.15.\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.7.19\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eGit issue 607: SIGSEGV: NULL pointer dereference in `basic_match()` when `(?R)`/`(?0)` recursion is used inside a fuzzy-matching quantifier\nGit issue 608: SIGSEGV: out-of-bounds read in `bytes1_char_at()` with `DOTALL` + a fuzzy constraint + `(?r)` reverse-direction matching\n\u003c/code\u003e\u003c/pre\u003e\n\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/7dd71c15c4fb5c94206bed1763abd4c2bd2f1b33\"\u003e\u003ccode\u003e7dd71c1\u003c/code\u003e\u003c/a\u003e Fixed version.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/59124d62299e212931786aa74ead15388abaf376\"\u003e\u003ccode\u003e59124d6\u003c/code\u003e\u003c/a\u003e PR \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/615\"\u003e#615\u003c/a\u003e: Fix Python API error propagation in match helpers\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/25e15218bd44ca26677e3c28709e94a0ca0d9b8e\"\u003e\u003ccode\u003e25e1521\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/618\"\u003e#618\u003c/a\u003e from dynapx/fix-compiler-error-propagation\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/3ad78cfb73850c2f1178d19553fa14661f73d9cb\"\u003e\u003ccode\u003e3ad78cf\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/616\"\u003e#616\u003c/a\u003e from dynapx/fix-detach-string-error-propagation\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/f54253c332574bd5a9d96d3ec9d62b5db954dac7\"\u003e\u003ccode\u003ef54253c\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/615\"\u003e#615\u003c/a\u003e from dynapx/fix-python-api-error-propagation\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/c44224476cd6a6e53be0e458dfdcf3b81d76e426\"\u003e\u003ccode\u003ec442244\u003c/code\u003e\u003c/a\u003e Propagate scanner internal errors\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/68837e7af862250cd08fa49ff584a2bbff246e0f\"\u003e\u003ccode\u003e68837e7\u003c/code\u003e\u003c/a\u003e Propagate node stack allocation failures\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/f1df5387982d526cc9475fddcc8d1043b02ffc9a\"\u003e\u003ccode\u003ef1df538\u003c/code\u003e\u003c/a\u003e Propagate check stack allocation failures\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/d8873b119a49cde8d2613253827bf973261bb2bc\"\u003e\u003ccode\u003ed8873b1\u003c/code\u003e\u003c/a\u003e Preserve Python exceptions in input decoding\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/910784fb8039c445a68e84a261119a96031c811c\"\u003e\u003ccode\u003e910784f\u003c/code\u003e\u003c/a\u003e Propagate detach_string slicing errors\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/mrabarnett/mrab-regex/compare/2026.2.28...2026.9.10\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `requests` from 2.32.3 to 2.34.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/psf/requests/releases\"\u003erequests's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.34.2\u003c/h2\u003e\n\u003ch2\u003e2.34.2 (2026-05-14)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMoved \u003ccode\u003eheaders\u003c/code\u003e input type back to \u003ccode\u003eMapping\u003c/code\u003e to avoid invariance issues with \u003ccode\u003eMutableMapping\u003c/code\u003e and inferred dict types. Users calling \u003ccode\u003eRequest.headers.update()\u003c/code\u003e may need to narrow typing in their code. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7441\"\u003e#7441\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/psf/requests/blob/main/HISTORY.md#2342-2026-05-14\"\u003ehttps://github.com/psf/requests/blob/main/HISTORY.md#2342-2026-05-14\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.34.1\u003c/h2\u003e\n\u003ch2\u003e2.34.1 (2026-05-13)\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eBugfixes\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eWidened \u003ccode\u003ejson\u003c/code\u003e input type from \u003ccode\u003edict\u003c/code\u003e and \u003ccode\u003elist\u003c/code\u003e to \u003ccode\u003eMapping\u003c/code\u003e\nand \u003ccode\u003eSequence\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7436\"\u003e#7436\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eChanged \u003ccode\u003eheaders\u003c/code\u003e input type to MutableMapping and removed \u003ccode\u003eNone\u003c/code\u003e from\n\u003ccode\u003eRequest.headers\u003c/code\u003e typing to improve handling for users. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7431\"\u003e#7431\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eResponse.reason\u003c/code\u003e moved from \u003ccode\u003estr | None\u003c/code\u003e to \u003ccode\u003estr\u003c/code\u003e to improve handling\nfor users. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7437\"\u003e#7437\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed a bug where some bodies with custom \u003ccode\u003e__getattr__\u003c/code\u003e implementations\nweren't being properly detected as Iterables. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7433\"\u003e#7433\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/k223kim\"\u003e\u003ccode\u003e@​k223kim\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/psf/requests/pull/7433\"\u003epsf/requests#7433\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/psf/requests/blob/main/HISTORY.md#2341-2026-05-13\"\u003ehttps://github.com/psf/requests/blob/main/HISTORY.md#2341-2026-05-13\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.34.0\u003c/h2\u003e\n\u003ch2\u003e2.34.0 (2026-05-11)\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eAnnouncements\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eRequests 2.34.0 introduces inline types, replacing those provided by\ntypeshed. Public API types should be fully compatible with mypy, pyright,\nand ty. \u003cstrong\u003eWe believe types are comprehensive but if you find issues, please\nreport them to the \u003ca href=\"https://redirect.github.com/psf/requests/issues/7271\"\u003epinned tracking issue\u003c/a\u003e.\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eSpecial thanks to \u003ca href=\"https://github.com/bastimeyer\"\u003e\u003ccode\u003e@​bastimeyer\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/cthoyt\"\u003e\u003ccode\u003e@​cthoyt\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/edgarrmondragon\"\u003e\u003ccode\u003e@​edgarrmondragon\u003c/code\u003e\u003c/a\u003e, and \u003ca href=\"https://github.com/srittau\"\u003e\u003ccode\u003e@​srittau\u003c/code\u003e\u003c/a\u003e for\nhelping review and test the types ahead of the release. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7272\"\u003e#7272\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eImprovements\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eDigest Auth hashing algorithms have added \u003ccode\u003eusedforsecurity=False\u003c/code\u003e to clarify\nsecurity considerations. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7310\"\u003e#7310\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests added support for Python 3.15 based on beta1. Downstream projects\nshould be able to start testing prior to its release in October. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7422\"\u003e#7422\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests added support for Python 3.14t. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7419\"\u003e#7419\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eBugfixes\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eResponse.history\u003c/code\u003e no longer contains a reference to itself, preventing\naccidental looping when traversing the history list. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7328\"\u003e#7328\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests no longer performs greedy matching on no_proxy domains. The\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/psf/requests/blob/main/HISTORY.md\"\u003erequests's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e2.34.2 (2026-05-14)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMoved \u003ccode\u003eheaders\u003c/code\u003e input type back to \u003ccode\u003eMapping\u003c/code\u003e to avoid invariance issues\nwith \u003ccode\u003eMutableMapping\u003c/code\u003e and inferred dict types. Users calling\n\u003ccode\u003eRequest.headers.update()\u003c/code\u003e may need to narrow typing in their code. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7441\"\u003e#7441\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.34.1 (2026-05-13)\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eBugfixes\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eWidened \u003ccode\u003ejson\u003c/code\u003e input type from \u003ccode\u003edict\u003c/code\u003e and \u003ccode\u003elist\u003c/code\u003e to \u003ccode\u003eMapping\u003c/code\u003e\nand \u003ccode\u003eSequence\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7436\"\u003e#7436\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eChanged \u003ccode\u003eheaders\u003c/code\u003e input type to MutableMapping and removed \u003ccode\u003eNone\u003c/code\u003e from\n\u003ccode\u003eRequest.headers\u003c/code\u003e typing to improve handling for users. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7431\"\u003e#7431\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eResponse.reason\u003c/code\u003e moved from \u003ccode\u003estr | None\u003c/code\u003e to \u003ccode\u003estr\u003c/code\u003e to improve handling\nfor users. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7437\"\u003e#7437\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed a bug where some bodies with custom \u003ccode\u003e__getattr__\u003c/code\u003e implementations\nweren't being properly detected as Iterables. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7433\"\u003e#7433\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.34.0 (2026-05-11)\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eAnnouncements\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eRequests 2.34.0 introduces inline types, replacing those provided by\ntypeshed. Public API types should be fully compatible with mypy, pyright,\nand ty. We believe types are comprehensive but if you find issues, please\nreport them to the pinned tracking issue.\u003c/p\u003e\n\u003cp\u003eSpecial thanks to \u003ca href=\"https://github.com/bastimeyer\"\u003e\u003ccode\u003e@​bastimeyer\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/cthoyt\"\u003e\u003ccode\u003e@​cthoyt\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/edgarrmondragon\"\u003e\u003ccode\u003e@​edgarrmondragon\u003c/code\u003e\u003c/a\u003e, and \u003ca href=\"https://github.com/srittau\"\u003e\u003ccode\u003e@​srittau\u003c/code\u003e\u003c/a\u003e for\nhelping review and test the types ahead of the release. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7272\"\u003e#7272\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eImprovements\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eDigest Auth hashing algorithms have added \u003ccode\u003eusedforsecurity=False\u003c/code\u003e to clarify\nsecurity considerations. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7310\"\u003e#7310\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests added support for Python 3.15 based on beta1. Downstream projects\nshould be able to start testing prior to its release in October. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7422\"\u003e#7422\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests added support for Python 3.14t. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7419\"\u003e#7419\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eBugfixes\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eResponse.history\u003c/code\u003e no longer contains a reference to itself, preventing\naccidental looping when traversing the history list. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7328\"\u003e#7328\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests no longer performs greedy matching on no_proxy domains. The\nproxy_bypass implementation has been updated with CPython's fix from\nbpo-39057. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7427\"\u003e#7427\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests no longer incorrectly strips duplicate leading slashes in\nURI paths. This should address user issues with specific presigned\nURLs. Note the full fix requires urllib3 2.7.0+. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7315\"\u003e#7315\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/6e83187b8feb273ed4c6cdab5efd8d54901dfab3\"\u003e\u003ccode\u003e6e83187\u003c/code\u003e\u003c/a\u003e v2.34.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/84d10f0be83e8f6aeca8a05230c52216431c4d0b\"\u003e\u003ccode\u003e84d10f0\u003c/code\u003e\u003c/a\u003e Move Request.headers back to Mapping (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7441\"\u003e#7441\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/b7b549b54571d03950b16afd2d01bc6ff0348224\"\u003e\u003ccode\u003eb7b549b\u003c/code\u003e\u003c/a\u003e v2.34.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/e511bc72777a94c45d004e010c597925092e1efe\"\u003e\u003ccode\u003ee511bc7\u003c/code\u003e\u003c/a\u003e Fix mutability issues with headers input types (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7431\"\u003e#7431\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/5691f596134c2feb121e595c77a0178921fcce61\"\u003e\u003ccode\u003e5691f59\u003c/code\u003e\u003c/a\u003e Update JsonType containers to read-based collections (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7436\"\u003e#7436\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/2144213c307691710c9d665700860fc4993c3035\"\u003e\u003ccode\u003e2144213\u003c/code\u003e\u003c/a\u003e Constrain Response.reason to str (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7437\"\u003e#7437\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/6404f345e562d962abe6700a1c357ec1e7e18232\"\u003e\u003ccode\u003e6404f34\u003c/code\u003e\u003c/a\u003e Fix \u003ccode\u003eprepare_body\u003c/code\u003e stream detection for \u003ccode\u003e__getattr__\u003c/code\u003e-based file wrappers (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7\"\u003e#7\u003c/a\u003e...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/0b401c76b6e80a4eecf3c690085b2553f6e261ca\"\u003e\u003ccode\u003e0b401c7\u003c/code\u003e\u003c/a\u003e v2.34.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/86b378d3f60f828daa13ca50aa82e287ff7b66b4\"\u003e\u003ccode\u003e86b378d\u003c/code\u003e\u003c/a\u003e Align Session.get parameters with requests.get (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7429\"\u003e#7429\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/a4f9a5999bdb9bf2d6e7c8aa973b28cacb17134f\"\u003e\u003ccode\u003ea4f9a59\u003c/code\u003e\u003c/a\u003e Port bpo-39057 to Requests (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7427\"\u003e#7427\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/psf/requests/compare/v2.32.3...v2.34.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `tqdm` from 4.67.3 to 4.70.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/tqdm/tqdm/releases\"\u003etqdm's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003etqdm v4.70.1 stable\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003econtrib.concurrent\u003c/code\u003e: fix no-len iterables (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1830\"\u003e#1830\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1828\"\u003e#1828\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003etests: major overhaul (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1819\"\u003e#1819\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eupdate AI policy in PR template\u003c/li\u003e\n\u003cli\u003emisc lint \u0026amp; tidy\u003c/li\u003e\n\u003cli\u003eCI: bump workflow actions \u0026amp; pre-commit hooks\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003etqdm v4.70.0 stable\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003econtrib.concurrent\u003c/code\u003e: major improvements\n\u003cul\u003e\n\u003cli\u003esupport \u003ccode\u003eprocess_map(mp_context, max_tasks_per_child)\u003c/code\u003e, \u003ccode\u003ethread_map(thread_name_prefix)\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1265\"\u003e#1265\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix \u003ccode\u003etotal\u003c/code\u003e based on shortest iterable length (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1473\"\u003e#1473\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003euse default \u003ccode\u003emax_workers\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1543\"\u003e#1543\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1530\"\u003e#1530\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1518\"\u003e#1518\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003esupport \u003ccode\u003etimeout\u003c/code\u003e, \u003ccode\u003ebuffersize\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1576\"\u003e#1576\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eimprove ETA (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1708\"\u003e#1708\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1161\"\u003e#1161\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eupdate \u003ccode\u003eas_completed\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1709\"\u003e#1709\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1565\"\u003e#1565\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eadd \u003ccode\u003etqdm.concurrent.intepreter_map\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1777\"\u003e#1777\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003easyncio\u003c/code\u003e: support iterables with only \u003ccode\u003e__aiter__\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1714\"\u003e#1714\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1686\"\u003e#1686\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003esupport \u003ccode\u003ereset(float(\u0026quot;inf\u0026quot;))\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1783\"\u003e#1783\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1781\"\u003e#1781\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/651\"\u003e#651\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eframework: test \u0026amp; reduce wheel size (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1782\"\u003e#1782\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003etqdm v4.69.1 stable\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003econtrib.logging\u003c/code\u003e: preserve filters (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1775\"\u003e#1775\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1581\"\u003e#1581\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003erich\u003c/code\u003e: misc fixes (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1773\"\u003e#1773\u003c/a\u003e)\n\u003cul\u003e\n\u003cli\u003esupport generators (without \u003ccode\u003elen\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1391\"\u003e#1391\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix potential \u003ccode\u003eAttributeError\u003c/code\u003e on exit (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1674\"\u003e#1674\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003efix \u003ccode\u003etotal=float('inf')\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1781\"\u003e#1781\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/651\"\u003e#651\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix potential \u003ccode\u003eAttributeError\u003c/code\u003e on exit (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1778\"\u003e#1778\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1668\"\u003e#1668\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1537\"\u003e#1537\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/261\"\u003e#261\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix minor docs typos (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1780\"\u003e#1780\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1746\"\u003e#1746\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003etqdm v4.69.0 stable\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eadd \u003ccode\u003etqdm.asyncio.gather(..., return_exceptions=False)\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1776\"\u003e#1776\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1671\"\u003e#1671\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1286\"\u003e#1286\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003emisc minor framework updates\n\u003cul\u003e\n\u003cli\u003ebump workflow actions \u0026amp; pre-commit hooks\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003etqdm v4.68.4 stable\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003etrim to \u003ccode\u003encols\u003c/code\u003e even when \u003ccode\u003e'{bar}' not in bar_format\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1717\"\u003e#1717\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1767\"\u003e#1767\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1658\"\u003e#1658\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix \u003ccode\u003etqdm.write\u003c/code\u003e when \u003ccode\u003estdout=None\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1768\"\u003e#1768\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1654\"\u003e#1654\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003etqdm v4.68.3 stable\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eutils\u003c/code\u003e: delay \u003ccode\u003eos.get_terminal_size\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1763\"\u003e#1763\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1760\"\u003e#1760\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eautonotebook\u003c/code\u003e: support QtConsole, Spyder, JupyterLite (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1763\"\u003e#1763\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1628\"\u003e#1628\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1559\"\u003e#1559\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1283\"\u003e#1283\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1098\"\u003e#1098\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/512\"\u003e#512\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eminor docs updates\n\u003cul\u003e\n\u003cli\u003efix typo (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1762\"\u003e#1762\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003euse \u003ccode\u003egit-fame\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003emisc minor framework updates\n\u003cul\u003e\n\u003cli\u003efix \u0026amp; update CI build\u003c/li\u003e\n\u003cli\u003epre-commit: add docs \u0026amp; metadata generation\u003c/li\u003e\n\u003cli\u003emove \u003ccode\u003etox.ini\u003c/code\u003e -\u0026gt; \u003ccode\u003epyproject.toml\u003c/code\u003e, move \u003ccode\u003etox-gh-actions\u003c/code\u003e -\u0026gt; \u003ccode\u003etox-gh\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eadd Python 3.14, drop 3.7 support\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/9cf5a12b1f955468a17f0ba3c59092b23e4258ac\"\u003e\u003ccode\u003e9cf5a12\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1830\"\u003e#1830\u003c/a\u003e from eaubin/master\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/24b9e1e08a097f1c30f2d235b63f9eb25ba47974\"\u003e\u003ccode\u003e24b9e1e\u003c/code\u003e\u003c/a\u003e misc tidy\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/2a9e4e82ddba07c5dd6d126e23a4745b76ea49c8\"\u003e\u003ccode\u003e2a9e4e8\u003c/code\u003e\u003c/a\u003e contrib.concurrent: fix no-len iterables\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/8d6ff8de5a9066de77d0a9df3e80a022a3dcf146\"\u003e\u003ccode\u003e8d6ff8d\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1819\"\u003e#1819\u003c/a\u003e from tqdm/devel\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/bed379609c2c8300671c784c8f85a185c8cf6fb3\"\u003e\u003ccode\u003ebed3796\u003c/code\u003e\u003c/a\u003e tests: major overhaul\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/4d3d3194d5467e0701bc0f4b836a735273ef0868\"\u003e\u003ccode\u003e4d3d319\u003c/code\u003e\u003c/a\u003e AI policy\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/5dcb022b55553b60ed2131b64aa5bf1e65470df1\"\u003e\u003ccode\u003e5dcb022\u003c/code\u003e\u003c/a\u003e minor syntax update\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/309effe4244bf45427c5add7f1bcf33f98a7b421\"\u003e\u003ccode\u003e309effe\u003c/code\u003e\u003c/a\u003e tests: pre-commit coverage\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/604193aa03b5f5c0ad5f3d441951f0fbb515f1e4\"\u003e\u003ccode\u003e604193a\u003c/code\u003e\u003c/a\u003e tests: slight tidy\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/17f1cac07c89943eb0e6082875b3821205308d4f\"\u003e\u003ccode\u003e17f1cac\u003c/code\u003e\u003c/a\u003e CI: bump workflow actions\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/tqdm/tqdm/compare/v4.67.3...v4.70.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `transformers` from 5.15.0 to 5.17.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/huggingface/transformers/releases\"\u003etransformers's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eRelease 5.17.0\u003c/h2\u003e\n\u003ch1\u003eRelease v5.17.0\u003c/h1\u003e\n\u003ch2\u003eNew Model additions\u003c/h2\u003e\n\u003ch3\u003eHYV4\u003c/h3\u003e\n\n\u003cp\u003eHy4-Preview is a 780B-parameter mixture-of-experts language model that activates 49B parameters per\ntoken. Each MoE layer holds 256 routed experts plus one always-active shared expert and routes every\ntoken to 8 of them. The context window is 1M tokens.\u003c/p\u003e\n\u003cp\u003eThe architecture combines four features:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eMulti-head Latent Attention (MLA)\u003c/strong\u003e compresses keys and values into a low-rank latent\n(\u003ccode\u003ekv_lora_rank\u003c/code\u003e) that \u003ccode\u003ekv_b_proj\u003c/code\u003e expands back to one key/value per query head.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eDeepSeek Sparse Attention (DSA)\u003c/strong\u003e selects \u003ccode\u003eindex_topk\u003c/code\u003e keys per query with a lightweight indexer.\nFollowing \u003ca href=\"https://huggingface.co/papers/2603.12201\"\u003eIndexShare\u003c/a\u003e, only the layers marked \u003ccode\u003e\u0026quot;full\u0026quot;\u003c/code\u003e\nin \u003ccode\u003eindexer_types\u003c/code\u003e run an indexer; \u003ccode\u003e\u0026quot;shared\u0026quot;\u003c/code\u003e layers reuse the previous full layer's selection.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eGated MLA with learnable attention sinks\u003c/strong\u003e, where each head owns a sink logit that participates\nin the softmax and contributes no value, as in \u003ca href=\"https://github.com/huggingface/transformers/blob/HEAD/gpt_oss\"\u003eGPT-OSS\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eIndependent Hyper-Connections (iHC)\u003c/strong\u003e replace the plain residual path with \u003ccode\u003ehc_mult\u003c/code\u003e parallel\nresidual streams that are collapsed before, and redistributed after, every sublayer.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThe implementation does not execute the multi-token prediction (MTP) layers. Released checkpoints\nkeep those weights so that other runtimes can use them for speculative decoding; they are ignored\nat load time.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/hy_v4\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAdd h4 (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48473\"\u003e#48473\u003c/a\u003e) by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/transformers/pull/48473\"\u003e#48473\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eVibeVoice\u003c/h3\u003e\n\n\u003cp\u003e\u003ca href=\"https://huggingface.co/papers/2508.19205\"\u003eVibeVoice\u003c/a\u003e is a novel framework for synthesizing high-fidelity, long-form speech with multiple speakers by employing a next-token diffusion approach within a Large Language Model (LLM) structure. It's designed to capture the authentic conversational \u0026quot;vibe\u0026quot; and is particularly suited for generating audio content like podcasts and multi-participant audiobooks.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/vibevoice\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eImplement VibeVoice  (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/40546\"\u003e#40546\u003c/a\u003e) by \u003ca href=\"https://github.com/pengzhiliang\"\u003e\u003ccode\u003e@​pengzhiliang\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/transformers/pull/40546\"\u003e#40546\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eNeoMME\u003c/h3\u003e\n\u003cp\u003eNeoMME is a family of efficient 260M and 800M parameter multimodal-native multilingual foundation encoders from H Company. It processes multilingual text tokens and raw image patches in a single bidirectional Transformer encoder, without a separately pretrained vision tower or causal language model.\u003c/p\u003e\n\u003cp\u003eNeoMME-Retriever is a model fine-tuned from the NeoMME backbone for visual document retrieval with joint late-interaction and dense objectives. It takes text queries and documents (text or page screenshots) and produces multi-vector embeddings for MeanMaxSim scoring (late-interaction) and mean-pooled embeddings for cosine similarity (dense).\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/neomme\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/856157a2f3e9594954310df18fdccc31ffddebe9\"\u003e\u003ccode\u003e856157a\u003c/code\u003e\u003c/a\u003e v5.17.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/5b7dcb0d36c242d8d85920a81c564ef3a86ca6dd\"\u003e\u003ccode\u003e5b7dcb0\u003c/code\u003e\u003c/a\u003e MRoPE continued (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48594\"\u003e#48594\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/50bbcc630ed1675d15d2def3877c88d6c2630415\"\u003e\u003ccode\u003e50bbcc6\u003c/code\u003e\u003c/a\u003e [fix] Update stale expected strings in HunYuanVL integration tests (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48646\"\u003e#48646\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/e8bcd79c4c77a529bc34d6e19f7d718164b7fa6a\"\u003e\u003ccode\u003ee8bcd79\u003c/code\u003e\u003c/a\u003e [Quantizaiton]support 5/6/7 bits in AutoRound (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48481\"\u003e#48481\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/3283d5f78ed6836d39430c8190a6e0500be78698\"\u003e\u003ccode\u003e3283d5f\u003c/code\u003e\u003c/a\u003e [fix] Update stale golden values and fix expected_logits shape in FlavaForPre...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/5f47b5aad791b69dff597b903614fb2bef8b88a1\"\u003e\u003ccode\u003e5f47b5a\u003c/code\u003e\u003c/a\u003e [tests] Fix integration test golden values broken by fast image processor def...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/fc501343edfccdc840eb8594a6cafa8185c2de53\"\u003e\u003ccode\u003efc50134\u003c/code\u003e\u003c/a\u003e Add Fun-ASR-Nano model (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46180\"\u003e#46180\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/d9fe823d1cedbba33dd0aeef08f773abe971688e\"\u003e\u003ccode\u003ed9fe823\u003c/code\u003e\u003c/a\u003e Fix YOLOS device mismatch with device_map=\u0026quot;auto\u0026quot; (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46886\"\u003e#46886\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/cbc1651a032b923da7f4b44b3d0e6f68e6ba6b55\"\u003e\u003ccode\u003ecbc1651\u003c/code\u003e\u003c/a\u003e [\u003ccode\u003eGenerate\u003c/code\u003e] Avoid unconditionally downloading remote hub file (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48620\"\u003e#48620\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/bd05a4b2baf8b37b8f64c0c2c70d2628583f7c2a\"\u003e\u003ccode\u003ebd05a4b\u003c/code\u003e\u003c/a\u003e Honor \u003ccode\u003eshift_labels\u003c/code\u003e in decoder-only LLM/VLM losses (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48493\"\u003e#48493\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/huggingface/transformers/compare/v5.15.0...v5.17.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `huggingface-hub` from 1.28.0 to 1.32.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/huggingface/huggingface_hub/releases\"\u003ehuggingface-hub's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e[v1.32.0] Shared blob store, sandbox security hardening and faster imports\u003c/h2\u003e\n\u003ch2\u003e:open_file_folder: [Cache] Shared blob store: deduplicate Xet files across repos\u003c/h2\u003e\n\u003cp\u003eThe cache now deduplicates Xet files across repos. A Xet file downloaded through \u003ccode\u003ehf_xet\u003c/code\u003e is stored once at \u003ccode\u003e\u0026lt;CACHE_DIR\u0026gt;/blobs/\u0026lt;prefix\u0026gt;/\u0026lt;xet_hash\u0026gt;\u003c/code\u003e and every repo that needs it gets a relative symlink instead of a download: no bytes are transferred and no extra space is used, even across different repos — or after the repo that first downloaded the file was deleted. The per-repo snapshot layout is unchanged, older clients keep reading and downloading normally, and any failure to share silently falls back to regular repo-local storage. Set \u003ccode\u003eHF_HUB_DISABLE_SHARED_BLOBS=1\u003c/code\u003e to opt out entirely. Shared files carry a \u003ccode\u003e\u0026lt;xet_hash\u0026gt;.refs\u003c/code\u003e manifest listing the repo blobs referencing them, which \u003ccode\u003ehf cache rm\u003c/code\u003e consults on deletion and \u003ccode\u003ehf cache prune\u003c/code\u003e sweeps to reclaim payloads that no cached repo uses anymore.\u003c/p\u003e\n\u003cp\u003e📚 \u003cstrong\u003eDocumentation:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/huggingface_hub/main/en/guides/manage-cache\"\u003eManage your cache\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e[Cache] Add cross-repo shared blob store by \u003ca href=\"https://github.com/hanouticelina\"\u003e\u003ccode\u003e@​hanouticelina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4498\"\u003e#4498\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e:computer: [Jobs] Ship config inside UV scripts\u003c/h2\u003e\n\u003cp\u003eA UV script that only runs correctly on a specific runtime can now carry that runtime with it. An optional \u003ccode\u003e[tool.hf-jobs]\u003c/code\u003e table in the script's PEP 723 header accepts \u003ccode\u003eimage\u003c/code\u003e, \u003ccode\u003eflavor\u003c/code\u003e, \u003ccode\u003epython\u003c/code\u003e, \u003ccode\u003etimeout\u003c/code\u003e, \u003ccode\u003ename\u003c/code\u003e, \u003ccode\u003enamespace\u003c/code\u003e, \u003ccode\u003eenv\u003c/code\u003e, \u003ccode\u003esecrets\u003c/code\u003e, \u003ccode\u003elabels\u003c/code\u003e, \u003ccode\u003evolumes\u003c/code\u003e, \u003ccode\u003enetwork_group\u003c/code\u003e and \u003ccode\u003enetwork_aliases\u003c/code\u003e, and \u003ccode\u003ehf jobs uv run\u003c/code\u003e reads it at submit time. CLI flags always win, and \u003ccode\u003eenv\u003c/code\u003e/\u003ccode\u003esecrets\u003c/code\u003e/\u003ccode\u003elabels\u003c/code\u003e/\u003ccode\u003evolumes\u003c/code\u003e merge entry by entry instead of being replaced, so \u003ccode\u003e-e\u003c/code\u003e/\u003ccode\u003e-v\u003c/code\u003e add to what the script declares. Typos and unknown keys are rejected with the list of valid options, secrets are passed by name only (values come from your environment), and every run prints a config summary with script-sourced values marked and secrets redacted. Note that the table is read by the CLI only: \u003ccode\u003erun_uv_job()\u003c/code\u003e and \u003ccode\u003ecreate_scheduled_uv_job()\u003c/code\u003e ignore it.\u003c/p\u003e\n\u003cpre lang=\"python\"\u003e\u003ccode\u003e# /// script\r\n# requires-python = \u0026quot;\u0026gt;=3.11\u0026quot;\r\n# dependencies = [\u0026quot;vllm\u0026quot;, \u0026quot;datasets\u0026quot;]\r\n#\r\n# [tool.hf-jobs]\r\n# image   = \u0026quot;vllm/vllm-openai:unlimited-ocr\u0026quot;\r\n# flavor  = \u0026quot;l4x1\u0026quot;\r\n# python  = \u0026quot;/usr/bin/python3\u0026quot;\r\n# secrets = [\u0026quot;HF_TOKEN\u0026quot;]\r\n# ///\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003e📚 \u003cstrong\u003eDocumentation:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/huggingface_hub/main/en/guides/jobs\"\u003eRun and manage Jobs\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e[CLI] Read a UV script's \u003ccode\u003e[tool.hf-jobs]\u003c/code\u003e launch config (opus-generated) by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4598\"\u003e#4598\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🛡️ [Sandbox] security hardening\u003c/h2\u003e\n\u003cp\u003eAn internal security review of the Sandbox API resulted in a 9-PR hardening series. Pooled sandboxes now use their own per-sandbox capability token instead of the host-wide credential, pool hosts are fully validated (initiator, namespace, image, flavor, command, URL) before any credential is sent to them, the \u003ccode\u003esbx-server\u003c/code\u003e binary is pinned by digest and verified before being run as PID 1, and the local pool cache is bound to the endpoint, credential and namespace that wrote it. Secret values no longer end up in \u003ccode\u003eargv\u003c/code\u003e when using \u003ccode\u003ehf sandbox exec --secrets\u003c/code\u003e, background processes are addressed by their server-assigned id (so \u003ccode\u003ekill()\u003c/code\u003e actually stops them and reports honestly), transfers and command output are bounded to avoid unbounded memory usage in the client, and pool ownership is decided per host so a \u003ccode\u003ewith SandboxPool(...)\u003c/code\u003e block never again tears down a colleague's discovered host. The security documentation was also rewritten to state precisely what the sandbox contract is — and what it is not — including a new \u0026quot;Known limitations\u0026quot; section.\u003c/p\u003e\n\u003cp\u003e📚 \u003cstrong\u003eDocumentation:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/huggingface_hub/main/en/guides/sandbox\"\u003eSandboxes\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e[sandbox audit] Make the sandbox security contract match the implementation by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4831\"\u003e#4831\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[sandbox audit] Use each pooled sandbox's own capability token by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4832\"\u003e#4832\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[sandbox audit] Validate a pool host before sending it a credential by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4834\"\u003e#4834\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[sandbox audit] Bind the sandbox pool cache to the endpoint, credential and namespace that wrote it by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4838\"\u003e#4838\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[sandbox audit] Bound what a transfer or a command's output costs the client by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4839\"\u003e#4839\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[sandbox audit] Decide host teardown per host, and report it honestly by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4840\"\u003e#4840\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[sandbox audit] Address background processes by their server-assigned id by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4836\"\u003e#4836\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[sandbox audit] Pin the sandbox server binary by digest and verify it before running it by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4837\"\u003e#4837\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[sandbox audit] Keep secret values out of argv in the CLI and fix the env/secrets docs by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4835\"\u003e#4835\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🔒 Security hardening for serialization and validation\u003c/h2\u003e\n\u003cp\u003eThree changes make the library safer against malicious or malformed inputs, with a stricter behavior worth noting. Torch checkpoint deserialization was hardened across 11 reported vulnerabilities: \u003ccode\u003eload_state_dict_from_file\u003c/code\u003e now defaults to \u003ccode\u003esafe=True\u003c/code\u003e (always using the safetensors loader), the pickle path defaults to \u003ccode\u003eweights_only=True\u003c/code\u003e, and unsafe combinations raise explicit errors instead of silently falling through. Path validation now rejects \u003ccode\u003e..\u003c/code\u003e segments anywhere in \u003ccode\u003epath_in_repo\u003c/code\u003e (previously only a leading one was caught), so uploads like \u003ccode\u003e\u0026quot;a/../../etc/passwd\u0026quot;\u003c/code\u003e are refused. Finally, \u003ccode\u003erepo_id\u003c/code\u003e validation is restricted to ASCII word characters as documented, so non-ASCII ids like \u003ccode\u003ecafé\u003c/code\u003e are rejected client-side instead of failing later on the Hub.\u003c/p\u003e\n\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/8814aabc81298df547bece9e71e4e88d3e513928\"\u003e\u003ccode\u003e8814aab\u003c/code\u003e\u003c/a\u003e Release: v1.32.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/445770606fa5ca80765a8e7a3d6e8cfaacaf7919\"\u003e\u003ccode\u003e4457706\u003c/code\u003e\u003c/a\u003e Release: v1.32.0.rc0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/b064a14629f9cdf3622e3fcac52c4f0e4e58c6b6\"\u003e\u003ccode\u003eb064a14\u003c/code\u003e\u003c/a\u003e [Download] Send X-HF-Download-Counter header on download calls (\u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4613\"\u003e#4613\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/79dd41ed6dec58314dad130fe7b8b578c8a1737d\"\u003e\u003ccode\u003e79dd41e\u003c/code\u003e\u003c/a\u003e [Docs] Fix hf discussions info options that do not exist (\u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4886\"\u003e#4886\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/d7b62c7becb6ba75667ab2c5b32d9338bcd5a4d4\"\u003e\u003ccode\u003ed7b62c7\u003c/code\u003e\u003c/a\u003e [CLI] Fix card data serialization (\u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4882\"\u003e#4882\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/f94ea55533a6fc796f191723823217fe75dfd462\"\u003e\u003ccode\u003ef94ea55\u003c/code\u003e\u003c/a\u003e [Buckets] Send mtime when copying files (\u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4920\"\u003e#4920\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/6e3d21f5d5a663468e58b37e6b94871e97534c24\"\u003e\u003ccode\u003e6e3d21f\u003c/code\u003e\u003c/a\u003e [Cache] Add cross-repo shared blob store (\u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4498\"\u003e#4498\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/5a9cdda63f231a1b57a05eab88dc4357c790ba87\"\u003e\u003ccode\u003e5a9cdda\u003c/code\u003e\u003c/a\u003e [Core] Speed up package imports (\u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4914\"\u003e#4914\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/2075fd68e69297eed60e1b058ef9b67b742b505d\"\u003e\u003ccode\u003e2075fd6\u003c/code\u003e\u003c/a\u003e [Cache] Support kernel repos in \u003ccode\u003ehf cache\u003c/code\u003e commands (\u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4905\"\u003e#4905\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/af6b41ece7448c5d7531699376c6f5974a2d24cc\"\u003e\u003ccode\u003eaf6b41e\u003c/code\u003e\u003c/a\u003e [Core] Reject path traversal via embedded \u0026quot;..\u0026quot; segments in path_in_repo (\u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4884\"\u003e#4884\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/huggingface/huggingface_hub/compare/v1.28.0...v1.32.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `tokenizers` from 0.22.2 to 0.23.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/huggingface/tokenizers/releases\"\u003etokenizers's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev0.23.2\u003c/h2\u003e\n\u003cp\u003eThis is the last v0 release, we are moving to v1!!\u003c/p\u003e\n\u003cp\u003eMore details coming soon 👀\u003c/p\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate daachorse from 1.0.1 to 3.0.0 by \u003ca href=\"https://github.com/musicinmybrain\"\u003e\u003ccode\u003e@​musicinmybrain\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2050\"\u003ehuggingface/tokenizers#2050\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eCi test fixes by \u003ca href=\"https://github.com/sebpop\"\u003e\u003ccode\u003e@​sebpop\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2079\"\u003ehuggingface/tokenizers#2079\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAvoid full vocab clone in get_vocab_size() by \u003ca href=\"https://github.com/eunseo9311\"\u003e\u003ccode\u003e@​eunseo9311\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2074\"\u003ehuggingface/tokenizers#2074\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: pin benchmark jobs to a larger dedicated runner by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2084\"\u003ehuggingface/tokenizers#2084\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: target benchmark runners by group, not nonexistent label by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2090\"\u003ehuggingface/tokenizers#2090\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBindings: acquire model read-lock once per call instead of per pre-token by \u003ca href=\"https://github.com/sebpop\"\u003e\u003ccode\u003e@​sebpop\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2072\"\u003ehuggingface/tokenizers#2072\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: split audit in a separate job by \u003ca href=\"https://github.com/SBrandeis\"\u003e\u003ccode\u003e@​SBrandeis\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2103\"\u003ehuggingface/tokenizers#2103\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: install libcairo on benchmark runners by \u003ca href=\"https://github.com/SBrandeis\"\u003e\u003ccode\u003e@​SBrandeis\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2100\"\u003ehuggingface/tokenizers#2100\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(ci): enable npm's trusted publisher for releases by \u003ca href=\"https://github.com/McPatate\"\u003e\u003ccode\u003e@​McPatate\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2111\"\u003ehuggingface/tokenizers#2111\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: bump pyo3 to version 0.29 by \u003ca href=\"https://github.com/SBrandeis\"\u003e\u003ccode\u003e@​SBrandeis\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2115\"\u003ehuggingface/tokenizers#2115\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eperf: add benchmarks for the \u003ccode\u003edecode\u003c/code\u003e API by \u003ca href=\"https://github.com/SBrandeis\"\u003e\u003ccode\u003e@​SBrandeis\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2099\"\u003ehuggingface/tokenizers#2099\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: cache HF test data and authenticate Hub downloads to avoid rate limits by \u003ca href=\"https://github.com/SBrandeis\"\u003e\u003ccode\u003e@​SBrandeis\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2102\"\u003ehuggingface/tokenizers#2102\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eImplementing Parity-aware BPE by \u003ca href=\"https://github.com/cimeister\"\u003e\u003ccode\u003e@​cimeister\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/1974\"\u003ehuggingface/tokenizers#1974\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eMake doc builds faster by \u003ca href=\"https://github.com/mishig25\"\u003e\u003ccode\u003e@​mishig25\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2158\"\u003ehuggingface/tokenizers#2158\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(deps-dev): bump websocket-driver from 0.7.4 to 0.7.5 in /tokenizers/examples/unstable_wasm/www by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2208\"\u003ehuggingface/tokenizers#2208\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(deps-dev): bump shell-quote from 1.8.3 to 1.10.0 in /tokenizers/examples/unstable_wasm/www by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2244\"\u003ehuggingface/tokenizers#2244\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: remove stale examples (kills 50% of dependabot traffic) by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2285\"\u003ehuggingface/tokenizers#2285\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(node): drop 8 unused devDependencies by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2286\"\u003ehuggingface/tokenizers#2286\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: pin every action to one SHA, drop stale audit suppressions by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2291\"\u003ehuggingface/tokenizers#2291\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(node): take node security alerts from 33 to 0 by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2287\"\u003ehuggingface/tokenizers#2287\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(python): pin the ruff rule set so a ruff release can't redden main by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2292\"\u003ehuggingface/tokenizers#2292\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd a ParityBpeTrainer example and list it in the trainers API docs by \u003ca href=\"https://github.com/cimeister\"\u003e\u003ccode\u003e@​cimeister\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2217\"\u003ehuggingface/tokenizers#2217\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eunseo9311\"\u003e\u003ccode\u003e@​eunseo9311\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2074\"\u003ehuggingface/tokenizers#2074\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cimeister\"\u003e\u003ccode\u003e@​cimeister\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/1974\"\u003ehuggingface/tokenizers#1974\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/huggingface/tokenizers/compare/v0.23.1...v0.23.2\"\u003ehttps://github.com/huggingface/tokenizers/compare/v0.23.1...v0.23.2\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eRelease v0.23.1\u003c/h2\u003e\n\u003ch2\u003eTL;DR\u003c/h2\u003e\n\u003cp\u003e\u003ccode\u003etokenizers 0.23.1\u003c/code\u003e is the first proper stable release in the \u003ccode\u003e0.23\u003c/code\u003e line — \u003ccode\u003e0.23.0\u003c/code\u003e only ever shipped as \u003ccode\u003erc0\u003c/code\u003e because the release pipeline itself was broken (Node side hadn't shipped multi-platform binaries since 2023, Python side was on \u003ccode\u003epyo3 0.27\u003c/code\u003e without free-threaded support). \u003ccode\u003e0.23.1\u003c/code\u003e is the version where everything actually goes out the door together: full Node multi-platform wheels for the first time in years, Python 3.14 (regular \u003cstrong\u003eand\u003c/strong\u003e free-threaded \u003ccode\u003e3.14t\u003c/code\u003e), full type hints for every Python class, and a stack of measurable perf wins on the BPE / added-vocab hot paths.\u003c/p\u003e\n\u003cp\u003eThere is no functional \u003ccode\u003e0.23.0\u003c/code\u003e published — we tag \u003ccode\u003e0.23.1\u003c/code\u003e directly so users don't accidentally pull a never-shipped version.\u003c/p\u003e\n\u003chr /\u003e\n\u003ch2\u003e🚨 Breaking changes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eDrop Python 3.9\u003c/strong\u003e (\u003ca href=\"https://redirect.github.com/huggingface/tokenizers/issues/1952\"\u003e#1952\u003c/a\u003e) — \u003ccode\u003erequires-python = \u0026quot;\u0026gt;=3.10\u0026quot;\u003c/code\u003e; 3.9 users stay on \u003ccode\u003e0.22.x\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ccode\u003eadd_tokens\u003c/code\u003e normalizes \u003ccode\u003econtent\u003c/code\u003e at insertion\u003c/strong\u003e (\u003ca href=\"https://redirect.github.com/huggingface/tokenizers/issues/1995\"\u003e#1995\u003c/a\u003e) — re-saved \u003ccode\u003etokenizer.json\u003c/code\u003e may differ in the \u003ccode\u003eadded_tokens\u003c/code\u003e block. Existing files load unchanged.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eType stubs are precise\u003c/strong\u003e (\u003ca href=\"https://redirect.github.com/huggingface/tokenizers/issues/1928\"\u003e#1928\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/issues/1997\"\u003e#1997\u003c/a\u003e) — methods that returned \u003ccode\u003eAny\u003c/code\u003e now return real types; \u003ccode\u003emypy --strict\u003c/code\u003e may surface previously-hidden errors. Stub layout also moved from \u003ccode\u003etokenizers/\u0026lt;sub\u0026gt;/__init__.pyi\u003c/code\u003e to \u003ccode\u003etokenizers/\u0026lt;sub\u0026gt;.pyi\u003c/code\u003e. This breaks the surface of some of the processors like \u003ccode\u003eRobertaProcessign\u003c/code\u003e's \u003ccode\u003e__init__\u003c/code\u003e .\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e3.14t-only\u003c/strong\u003e: setters/getters return \u003ccode\u003ePyResult\u0026lt;T\u0026gt;\u003c/code\u003e because of \u003ccode\u003eArc\u0026lt;RwLock\u0026lt;Tokenizer\u0026gt;\u0026gt;\u003c/code\u003e; a poisoned lock surfaces as \u003ccode\u003ePyException\u003c/code\u003e instead of a panic.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/tokenizers/commit/88a4498ad4ea1a9487b0a9b0ff881383fd5a06a3\"\u003e\u003ccode\u003e88a4498\u003c/code\u003e\u003c/a\u003e add lock\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/tokenizers/commit/e4ea65f27057e593656ff1335b95afe2e552b88d\"\u003e\u003ccode\u003ee4ea65f\u003c/code\u003e\u003c/a\u003e real release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/tokenizers/commit/7c5964b4afae7b710d254eacd5a9fa180ba2cfef\"\u003e\u003ccode\u003e7c5964b\u003c/code\u003e\u003c/a\u003e add lock\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/tokenizers/commit/bc405ad60991a0639f8b09b40f13f91c38e50e87\"\u003e\u003ccode\u003ebc405ad\u003c/code\u003e\u003c/a\u003e push rc0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/tokenizers/commit/d5827816baedcbf1cb5b452dea8048150b6872df\"\u003e\u003ccode\u003ed582781\u003c/code\u003e\u003c/a\u003e Add a ParityBpeTrainer example and list it in the trainers API docs (\u003ca href=\"https://redirect.github.com/huggingface/tokenizers/iss...\n\n_Description has been truncated_","html_url":"https://github.com/yhfgyyf/vllm-deepseek-v4-sm89/pull/119","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/yhfgyyf%2Fvllm-deepseek-v4-sm89/issues/119","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/119/packages"},{"uuid":"5516302428","node_id":"PR_kwDOQeYl_s8AAAABESeotw","number":586,"state":"open","title":"chore(deps): bump the python-runtime group with 7 updates","user":"dependabot[bot]","labels":[],"assignees":[],"locked":false,"comments_count":3,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-20T06:49:46.000Z","updated_at":"2026-09-20T06:49:52.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps): bump","group_name":"python-runtime","update_count":7,"packages":[{"name":"xrpl-py","old_version":"5.0.0","new_version":"5.2.0","repository_url":"https://github.com/XRPLF/xrpl-py"},{"name":"numpy","old_version":"2.2.6","new_version":"2.5.3","repository_url":"https://github.com/numpy/numpy"},{"name":"opencv-python","old_version":"4.13.0.92","new_version":"5.0.0.93","repository_url":"https://github.com/opencv/opencv-python"},{"name":"pillow","old_version":"12.2.0","new_version":"12.3.0","repository_url":"https://github.com/python-pillow/Pillow"},{"name":"python-dotenv","old_version":"0.21.1","new_version":"1.2.3","repository_url":"https://github.com/theskumar/python-dotenv"},{"name":"aiohttp","old_version":"3.14.1","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"cryptography","old_version":"50.0.0","new_version":"50.0.1","repository_url":"https://github.com/pyca/cryptography"}],"path":null,"ecosystem":"pip"},"body":"Bumps the python-runtime group with 7 updates:\n\n| Package | From | To |\n| --- | --- | --- |\n| [xrpl-py](https://github.com/XRPLF/xrpl-py) | `5.0.0` | `5.2.0` |\n| [numpy](https://github.com/numpy/numpy) | `2.2.6` | `2.5.3` |\n| [opencv-python](https://github.com/opencv/opencv-python) | `4.13.0.92` | `5.0.0.93` |\n| [pillow](https://github.com/python-pillow/Pillow) | `12.2.0` | `12.3.0` |\n| [python-dotenv](https://github.com/theskumar/python-dotenv) | `0.21.1` | `1.2.3` |\n| [aiohttp](https://github.com/aio-libs/aiohttp) | `3.14.1` | `3.14.3` |\n| [cryptography](https://github.com/pyca/cryptography) | `50.0.0` | `50.0.1` |\n\nUpdates `xrpl-py` from 5.0.0 to 5.2.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/XRPLF/xrpl-py/releases\"\u003exrpl-py's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev5.2.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003echore(coderabbit): reduce review noise and load .ai-review/instructions.md by \u003ca href=\"https://github.com/arshjafri-ripple\"\u003e\u003ccode\u003e@​arshjafri-ripple\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/XRPLF/xrpl-py/pull/1024\"\u003eXRPLF/xrpl-py#1024\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: remove integration test requirement for beta releases by \u003ca href=\"https://github.com/pdp2121\"\u003e\u003ccode\u003e@​pdp2121\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/XRPLF/xrpl-py/pull/1039\"\u003eXRPLF/xrpl-py#1039\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSupport \u003ccode\u003efixCleanup3_4_0\u003c/code\u003e signing prefixes (\u003ccode\u003eSponsor\u003c/code\u003e) by \u003ca href=\"https://github.com/pdp2121\"\u003e\u003ccode\u003e@​pdp2121\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/XRPLF/xrpl-py/pull/1036\"\u003eXRPLF/xrpl-py#1036\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat: Support LendingProtocolV1_1 by \u003ca href=\"https://github.com/pdp2121\"\u003e\u003ccode\u003e@​pdp2121\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/XRPLF/xrpl-py/pull/1034\"\u003eXRPLF/xrpl-py#1034\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/XRPLF/xrpl-py/compare/v5.1.0...v5.2.0\"\u003ehttps://github.com/XRPLF/xrpl-py/compare/v5.1.0...v5.2.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev5.2.0b0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSet dependabot version update frequency to quarterly by \u003ca href=\"https://github.com/Patel-Raj11\"\u003e\u003ccode\u003e@​Patel-Raj11\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/XRPLF/xrpl-py/pull/898\"\u003eXRPLF/xrpl-py#898\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRelease pipeline by \u003ca href=\"https://github.com/shichengripple001\"\u003e\u003ccode\u003e@​shichengripple001\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/XRPLF/xrpl-py/pull/876\"\u003eXRPLF/xrpl-py#876\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix number serialization by \u003ca href=\"https://github.com/ckeshava\"\u003e\u003ccode\u003e@​ckeshava\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/XRPLF/xrpl-py/pull/900\"\u003eXRPLF/xrpl-py#900\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdates to the Lending-Protocol transactions by \u003ca href=\"https://github.com/ckeshava\"\u003e\u003ccode\u003e@​ckeshava\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/XRPLF/xrpl-py/pull/901\"\u003eXRPLF/xrpl-py#901\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003erefactor: improve int32 integration by \u003ca href=\"https://github.com/mvadari\"\u003e\u003ccode\u003e@​mvadari\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/XRPLF/xrpl-py/pull/902\"\u003eXRPLF/xrpl-py#902\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix \u003ccode\u003eRequest.from_xrpl\u003c/code\u003e by aliasing it to \u003ccode\u003eRequest.from_dict\u003c/code\u003e by \u003ca href=\"https://github.com/mvadari\"\u003e\u003ccode\u003e@​mvadari\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/XRPLF/xrpl-py/pull/892\"\u003eXRPLF/xrpl-py#892\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRelease 4.5.0: release-4.5.0 → main by \u003ca href=\"https://github.com/github-actions\"\u003e\u003ccode\u003e@​github-actions\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/XRPLF/xrpl-py/pull/904\"\u003eXRPLF/xrpl-py#904\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd pull request types to unit test workflow by \u003ca href=\"https://github.com/shichengripple001\"\u003e\u003ccode\u003e@​shichengripple001\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/XRPLF/xrpl-py/pull/911\"\u003eXRPLF/xrpl-py#911\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eDrop support for Python 3.8 by \u003ca href=\"https://github.com/kuan121\"\u003e\u003ccode\u003e@​kuan121\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/XRPLF/xrpl-py/pull/917\"\u003eXRPLF/xrpl-py#917\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(deps): bump aquasecurity/trivy-action from 0.33.1 to 0.34.0 in /.github/workflows by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/XRPLF/xrpl-py/pull/912\"\u003eXRPLF/xrpl-py#912\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: incorrect SField definitions for Lending Protocols and DynamicMPTs by \u003ca href=\"https://github.com/pdp2121\"\u003e\u003ccode\u003e@​pdp2121\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/XRPLF/xrpl-py/pull/918\"\u003eXRPLF/xrpl-py#918\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eupdate trivy-action version by \u003ca href=\"https://github.com/Patel-Raj11\"\u003e\u003ccode\u003e@​Patel-Raj11\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/XRPLF/xrpl-py/pull/922\"\u003eXRPLF/xrpl-py#922\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix _calculate_precision by \u003ca href=\"https://github.com/Patel-Raj11\"\u003e\u003ccode\u003e@​Patel-Raj11\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/XRPLF/xrpl-py/pull/924\"\u003eXRPLF/xrpl-py#924\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eDrop python 3.9 support by \u003ca href=\"https://github.com/Patel-Raj11\"\u003e\u003ccode\u003e@​Patel-Raj11\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/XRPLF/xrpl-py/pull/940\"\u003eXRPLF/xrpl-py#940\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate default algorithm in\u003ccode\u003eWallet\u003c/code\u003e class (breaking change) by \u003ca href=\"https://github.com/ckeshava\"\u003e\u003ccode\u003e@​ckeshava\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/XRPLF/xrpl-py/pull/942\"\u003eXRPLF/xrpl-py#942\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(deps): quarterly batch dependency upgrade 2026-Q2 by \u003ca href=\"https://github.com/Patel-Raj11\"\u003e\u003ccode\u003e@​Patel-Raj11\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/XRPLF/xrpl-py/pull/995\"\u003eXRPLF/xrpl-py#995\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eCollection of bug-fixes by \u003ca href=\"https://github.com/ckeshava\"\u003e\u003ccode\u003e@​ckeshava\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/XRPLF/xrpl-py/pull/993\"\u003eXRPLF/xrpl-py#993\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: docker path for integration test by \u003ca href=\"https://github.com/pdp2121\"\u003e\u003ccode\u003e@​pdp2121\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/XRPLF/xrpl-py/pull/1003\"\u003eXRPLF/xrpl-py#1003\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: preserve significant trailing zeros in \u003ccode\u003eAmount.to_json\u003c/code\u003e for IOU values by \u003ca href=\"https://github.com/ckeshava\"\u003e\u003ccode\u003e@​ckeshava\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/XRPLF/xrpl-py/pull/1001\"\u003eXRPLF/xrpl-py#1001\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(wallet): infer signing algorithm from seed prefix in Wallet.from_seed / Wallet.from_secret by \u003ca href=\"https://github.com/ckeshava\"\u003e\u003ccode\u003e@​ckeshava\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/XRPLF/xrpl-py/pull/999\"\u003eXRPLF/xrpl-py#999\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRelease 5.0.0: release-5.0.0 → main by \u003ca href=\"https://github.com/github-actions\"\u003e\u003ccode\u003e@​github-actions\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/XRPLF/xrpl-py/pull/1004\"\u003eXRPLF/xrpl-py#1004\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat: Batch (XLS-56) V1_1 signing support by \u003ca href=\"https://github.com/Patel-Raj11\"\u003e\u003ccode\u003e@​Patel-Raj11\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/XRPLF/xrpl-py/pull/1015\"\u003eXRPLF/xrpl-py#1015\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: support private xrpld images via committed config file by \u003ca href=\"https://github.com/rrmanukyan\"\u003e\u003ccode\u003e@​rrmanukyan\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/XRPLF/xrpl-py/pull/1019\"\u003eXRPLF/xrpl-py#1019\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: Handle signing fields correctly in definitions generation by \u003ca href=\"https://github.com/mvadari\"\u003e\u003ccode\u003e@​mvadari\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/XRPLF/xrpl-py/pull/1021\"\u003eXRPLF/xrpl-py#1021\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSupport for Dynamic MPT (XLS-94d) by \u003ca href=\"https://github.com/kuan121\"\u003e\u003ccode\u003e@​kuan121\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/XRPLF/xrpl-py/pull/877\"\u003eXRPLF/xrpl-py#877\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eExpand team required-reviewers into individual member logins for Slack notifications by \u003ca href=\"https://github.com/github-actions\"\u003e\u003ccode\u003e@​github-actions\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/XRPLF/xrpl-py/pull/1029\"\u003eXRPLF/xrpl-py#1029\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSupport XLS-68 Sponsored Fees and Reserves by \u003ca href=\"https://github.com/kuan121\"\u003e\u003ccode\u003e@​kuan121\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/XRPLF/xrpl-py/pull/1020\"\u003eXRPLF/xrpl-py#1020\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat: ConfidentialMPT Support by \u003ca href=\"https://github.com/pdp2121\"\u003e\u003ccode\u003e@​pdp2121\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/XRPLF/xrpl-py/pull/919\"\u003eXRPLF/xrpl-py#919\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRelease 5.1.0: release-5.1.0 → main by \u003ca href=\"https://github.com/github-actions\"\u003e\u003ccode\u003e@​github-actions\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/XRPLF/xrpl-py/pull/1032\"\u003eXRPLF/xrpl-py#1032\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(coderabbit): reduce review noise and load .ai-review/instructions.md by \u003ca href=\"https://github.com/arshjafri-ripple\"\u003e\u003ccode\u003e@​arshjafri-ripple\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/XRPLF/xrpl-py/pull/1024\"\u003eXRPLF/xrpl-py#1024\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/shichengripple001\"\u003e\u003ccode\u003e@​shichengripple001\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/XRPLF/xrpl-py/pull/876\"\u003eXRPLF/xrpl-py#876\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github-actions\"\u003e\u003ccode\u003e@​github-actions\u003c/code\u003e\u003c/a\u003e[bot] made their first contribution in \u003ca href=\"https://redirect.github.com/XRPLF/xrpl-py/pull/904\"\u003eXRPLF/xrpl-py#904\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kuan121\"\u003e\u003ccode\u003e@​kuan121\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/XRPLF/xrpl-py/pull/917\"\u003eXRPLF/xrpl-py#917\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/rrmanukyan\"\u003e\u003ccode\u003e@​rrmanukyan\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/XRPLF/xrpl-py/pull/1019\"\u003eXRPLF/xrpl-py#1019\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/arshjafri-ripple\"\u003e\u003ccode\u003e@​arshjafri-ripple\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/XRPLF/xrpl-py/pull/1024\"\u003eXRPLF/xrpl-py#1024\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/XRPLF/xrpl-py/compare/v4.4.0...v5.2.0b0\"\u003ehttps://github.com/XRPLF/xrpl-py/compare/v4.4.0...v5.2.0b0\u003c/a\u003e\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/XRPLF/xrpl-py/blob/v5.2.0/CHANGELOG.md\"\u003exrpl-py's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e[[5.2.0]]\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eSupport for the \u003ccode\u003eLendingProtocolV1_1\u003c/code\u003e amendment.\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003eencode_for_signing_counterparty\u003c/code\u003e / \u003ccode\u003eencode_for_multisigning_counterparty\u003c/code\u003e and \u003ccode\u003eencode_for_signing_sponsor\u003c/code\u003e / \u003ccode\u003eencode_for_multisigning_sponsor\u003c/code\u003e for the role-specific signing prefixes introduced by \u003ccode\u003efixCleanup3_4_0\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eSupport the \u003ccode\u003efixCleanup3_4_0\u003c/code\u003e signing prefixes.\u003c/li\u003e\n\u003cli\u003eRegenerate \u003ccode\u003edefinitions.json\u003c/code\u003e from rippled 3.4.0: adds new fields (e.g. \u003ccode\u003eVaultKind\u003c/code\u003e, \u003ccode\u003eSubscriptionDate\u003c/code\u003e, \u003ccode\u003eRedemptionDate\u003c/code\u003e) and removes Hook/Emit field definitions, as Hooks is no longer supported.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e[[5.1.0]]\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eSupport for \u003ccode\u003eConfidential MPT\u003c/code\u003e (XLS-0096). The optional native cryptography (proof generation and balance decryption) is provided by the separate \u003ccode\u003exrpl.ext.confidential\u003c/code\u003e extension.\u003c/li\u003e\n\u003cli\u003eAdded support for the Sponsored Fees and Reserves (XLS-68)\u003c/li\u003e\n\u003cli\u003eSupport for \u003ccode\u003eDynamic Multi-Purpose Tokens\u003c/code\u003e (XLS-94)\u003c/li\u003e\n\u003cli\u003eAdd support for Batch (XLS-56) \u003ccode\u003eBatchV1_1\u003c/code\u003e signing.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eRemoved\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eDrop support for the older \u003ccode\u003eBatch\u003c/code\u003e signing format (never live on any network, so no existing signatures are affected).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/XRPLF/xrpl-py/commit/a553301e2c4caaf0bf808fc48d18e5271a5c7d28\"\u003e\u003ccode\u003ea553301\u003c/code\u003e\u003c/a\u003e bump packages\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/XRPLF/xrpl-py/commit/634ab7a4c5c18c547a9336fcaa8320a15ccca4ce\"\u003e\u003ccode\u003e634ab7a\u003c/code\u003e\u003c/a\u003e feat: Support LendingProtocolV1_1 (\u003ca href=\"https://redirect.github.com/XRPLF/xrpl-py/issues/1034\"\u003e#1034\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/XRPLF/xrpl-py/commit/28836d0a7346e92adce877eeb02721fff218fb89\"\u003e\u003ccode\u003e28836d0\u003c/code\u003e\u003c/a\u003e Support \u003ccode\u003efixCleanup3_4_0\u003c/code\u003e signing prefixes (\u003ccode\u003eSponsor\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/XRPLF/xrpl-py/issues/1036\"\u003e#1036\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/XRPLF/xrpl-py/commit/a29bdba371fabdf08aafda1dbbb15c8bfbfcc4a8\"\u003e\u003ccode\u003ea29bdba\u003c/code\u003e\u003c/a\u003e ci: remove integration test requirement for beta releases (\u003ca href=\"https://redirect.github.com/XRPLF/xrpl-py/issues/1039\"\u003e#1039\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/XRPLF/xrpl-py/commit/10ed82ee1f25c8bef0bf3bbc08d2708d6dde2a0f\"\u003e\u003ccode\u003e10ed82e\u003c/code\u003e\u003c/a\u003e chore(coderabbit): reduce review noise and load .ai-review/instructions.md (#...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/XRPLF/xrpl-py/commit/ad08b5b79ee221fd32ca610bf72e6e0dcfb7c894\"\u003e\u003ccode\u003ead08b5b\u003c/code\u003e\u003c/a\u003e Release 5.1.0: release-5.1.0 → main (\u003ca href=\"https://redirect.github.com/XRPLF/xrpl-py/issues/1032\"\u003e#1032\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/XRPLF/xrpl-py/commit/d80063149a70c5478d5f3fe5fef1b2bdd81bf67c\"\u003e\u003ccode\u003ed800631\u003c/code\u003e\u003c/a\u003e feat: ConfidentialMPT Support (\u003ca href=\"https://redirect.github.com/XRPLF/xrpl-py/issues/919\"\u003e#919\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/XRPLF/xrpl-py/commit/e648619de0961b13dc6f7548f4973bf5345b888e\"\u003e\u003ccode\u003ee648619\u003c/code\u003e\u003c/a\u003e Support XLS-68 Sponsored Fees and Reserves (\u003ca href=\"https://redirect.github.com/XRPLF/xrpl-py/issues/1020\"\u003e#1020\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/XRPLF/xrpl-py/commit/524f230c6581a99d876137a4d8121391df691a30\"\u003e\u003ccode\u003e524f230\u003c/code\u003e\u003c/a\u003e Expand team required-reviewers into individual member logins for Slack notifi...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/XRPLF/xrpl-py/commit/cddeb632e611348550edc4c9c03eb90ae562789a\"\u003e\u003ccode\u003ecddeb63\u003c/code\u003e\u003c/a\u003e Support for Dynamic MPT (XLS-94d) (\u003ca href=\"https://redirect.github.com/XRPLF/xrpl-py/issues/877\"\u003e#877\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/XRPLF/xrpl-py/compare/v5.0.0...v5.2.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `numpy` from 2.2.6 to 2.5.3\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/numpy/numpy/releases\"\u003enumpy's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.5.3 (Sep 6, 2026)\u003c/h2\u003e\n\u003ch1\u003eNumPy 2.5.3 Release Notes\u003c/h1\u003e\n\u003cp\u003eThe NumPy 2.5.3 is a patch release that fixes bugs discovered after the 2.5.2\nrelease. Apart from the usual bug and maintenance work, there are a number of\nStringDType related fixes for problems discovered during the ongoing string\nwork in the main branch.\u003c/p\u003e\n\u003cp\u003eThis release supports Python versions 3.12-3.15\u003c/p\u003e\n\u003ch2\u003eChanges\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eCasting a fixed-width byte string array (\u003ccode\u003enp.bytes_\u003c/code\u003e) to \u003ccode\u003eStringDType\u003c/code\u003e\nnow raises \u003ccode\u003eTypeError\u003c/code\u003e when the bytes are not valid UTF-8. Previously the\ninvalid bytes were stored as-is and later caused undefined behavior in\nstring operations.\u003c/p\u003e\n\u003cp\u003e(\u003ca href=\"https://redirect.github.com/numpy/numpy/pull/32296\"\u003egh-32296\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ccode\u003eMaskedArray._fill_value\u003c/code\u003e would become stale when ufuncs that change dtype\nleft the result holding a fill_value typed for the old dtype. The mismatch\nwas silent until something later called \u003ccode\u003e_check_fill_value\u003c/code\u003e, such as\n\u003ccode\u003e.view()\u003c/code\u003e, and then a \u003ccode\u003eTypeError\u003c/code\u003e would be raised. Now, when the copied\nfill_value is no longer valid for the new dtype, fall back to the\ndefault fill_value for that dtype instead of propagating the stale value.\nThis may raise a \u003ccode\u003eComplexWarning\u003c/code\u003e if the fill_value is complex and the\nnew dtype is real.\u003c/p\u003e\n\u003cp\u003e(\u003ca href=\"https://redirect.github.com/numpy/numpy/pull/32423\"\u003egh-32423\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eContributors\u003c/h2\u003e\n\u003cp\u003eA total of 9 people contributed to this release. People with a \u0026quot;+\u0026quot; by their\nnames contributed a patch for the first time.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eCharles Harris\u003c/li\u003e\n\u003cli\u003eIason Krommydas\u003c/li\u003e\n\u003cli\u003eJames Davies +\u003c/li\u003e\n\u003cli\u003eJoren Hammudoglu\u003c/li\u003e\n\u003cli\u003eMaanas Arora\u003c/li\u003e\n\u003cli\u003eMatti Picus\u003c/li\u003e\n\u003cli\u003eNathan Goldbaum\u003c/li\u003e\n\u003cli\u003eShikhar Goel +\u003c/li\u003e\n\u003cli\u003eYeonho Kim +\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ePull requests merged\u003c/h2\u003e\n\u003cp\u003eA total of 27 pull requests were merged for this release.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/numpy/numpy/pull/32235\"\u003e#32235\u003c/a\u003e: MAINT: Prepare 2.5.x for further development\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/numpy/numpy/blob/main/doc/RELEASE_WALKTHROUGH.rst\"\u003enumpy's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003eThis is a walkthrough of the NumPy 2.4.0 release on Linux, which will be the\nfirst feature release using the \u003ccode\u003enumpy/numpy-release \u0026lt;https://github.com/numpy/numpy-release\u0026gt;\u003c/code\u003e__ repository.\u003c/p\u003e\n\u003cp\u003eThe commands can be copied into the command line, but be sure to replace 2.4.0\nwith the correct version. This should be read together with the\n:ref:\u003ccode\u003egeneral release guide \u0026lt;prepare_release\u0026gt;\u003c/code\u003e.\u003c/p\u003e\n\u003ch1\u003eFacility preparation\u003c/h1\u003e\n\u003cp\u003eBefore beginning to make a release, use the \u003ccode\u003erequirements/*_requirements.txt\u003c/code\u003e files to\nensure that you have the needed software. Most software can be installed with\npip, but some will require apt-get, dnf, or whatever your system uses for\nsoftware. You will also need a GitHub personal access token (PAT) to push the\ndocumentation. There are a few ways to streamline things:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eGit can be set up to use a keyring to store your GitHub personal access token.\nSearch online for the details.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch1\u003ePrior to release\u003c/h1\u003e\n\u003ch2\u003eAdd/drop Python versions\u003c/h2\u003e\n\u003cp\u003eWhen adding or dropping Python versions, multiple config and CI files need to\nbe edited in addition to changing the minimum version in \u003ccode\u003epyproject.toml\u003c/code\u003e.\nMake these changes in an ordinary PR against main and backport if necessary.\nWe currently release wheels for new Python versions after the first Python RC\nonce manylinux and cibuildwheel support that new Python version.\u003c/p\u003e\n\u003ch2\u003eBackport pull requests\u003c/h2\u003e\n\u003cp\u003eChanges that have been marked for this release must be backported to the\nmaintenance/2.4.x branch.\u003c/p\u003e\n\u003ch2\u003eUpdate 2.4.0 milestones\u003c/h2\u003e\n\u003cp\u003eLook at the issues/prs with 2.4.0 milestones and either push them off to a\nlater version, or maybe remove the milestone. You may need to add a milestone.\u003c/p\u003e\n\u003ch2\u003eCheck the numpy-release repo\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/numpy/numpy/commit/dd88c0c19b54ad9ed3533224221285bf0873249a\"\u003e\u003ccode\u003edd88c0c\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/numpy/numpy/issues/32511\"\u003e#32511\u003c/a\u003e from charris/prepare-2.5.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/numpy/numpy/commit/edcac6acc392f4010933ee83e8a4769a7cfe92c5\"\u003e\u003ccode\u003eedcac6a\u003c/code\u003e\u003c/a\u003e REL: Prepare for the NumPy 2.5.3 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/numpy/numpy/commit/fd4d908aff89773ead13f7c6a0ab31153f14439e\"\u003e\u003ccode\u003efd4d908\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/numpy/numpy/issues/32509\"\u003e#32509\u003c/a\u003e from charris/backport-32496\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/numpy/numpy/commit/65bb1da13d0ee784be84d173b86784f0d64bdaca\"\u003e\u003ccode\u003e65bb1da\u003c/code\u003e\u003c/a\u003e BUG: fix crash in ufunc.resolve_dtypes with a Python scalar type (\u003ca href=\"https://redirect.github.com/numpy/numpy/issues/32496\"\u003e#32496\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/numpy/numpy/commit/294956e85dfaea149aada1278c2ed6be0f6f28c8\"\u003e\u003ccode\u003e294956e\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/numpy/numpy/issues/32506\"\u003e#32506\u003c/a\u003e from charris/backport-32503\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/numpy/numpy/commit/26428d9a3f5ab4f604b326347e3a9c6dcc00c1cb\"\u003e\u003ccode\u003e26428d9\u003c/code\u003e\u003c/a\u003e DOC: fix scipy docs links in intersphinx mapping (\u003ca href=\"https://redirect.github.com/numpy/numpy/issues/32507\"\u003e#32507\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/numpy/numpy/commit/5fab1cbc6aa9e119d9f931243a56c6fbca989476\"\u003e\u003ccode\u003e5fab1cb\u003c/code\u003e\u003c/a\u003e DOC: use static scipy doc site for intershpinx (\u003ca href=\"https://redirect.github.com/numpy/numpy/issues/32503\"\u003e#32503\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/numpy/numpy/commit/7beed2f7e9a24e493a04ff7e2eb1db0d7f9c50e6\"\u003e\u003ccode\u003e7beed2f\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/numpy/numpy/issues/32481\"\u003e#32481\u003c/a\u003e from ngoldbaum/stringdtype-backport\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/numpy/numpy/commit/8972f70798a2ba1bb4557157982fd6001906f993\"\u003e\u003ccode\u003e8972f70\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/numpy/numpy/issues/32478\"\u003e#32478\u003c/a\u003e from charris/backport-32466\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/numpy/numpy/commit/ab1b58902a868d4151ef3cf8dbeb91d8a1924fa4\"\u003e\u003ccode\u003eab1b589\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/numpy/numpy/issues/32477\"\u003e#32477\u003c/a\u003e from charris/backport-32423\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/numpy/numpy/compare/v2.2.6...v2.5.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `opencv-python` from 4.13.0.92 to 5.0.0.93\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/opencv/opencv-python/releases\"\u003eopencv-python's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e5.0.0.93\u003c/h2\u003e\n\u003cp\u003eOpenCV 5.0.0 released!\u003c/p\u003e\n\u003cp\u003eOpenCV 5.0.0 overview: \u003ca href=\"https://opencv.org/opencv-5\"\u003ehttps://opencv.org/opencv-5\u003c/a\u003e\nOpenCV 4.x -\u0026gt; 5.x migration guide: \u003ca href=\"https://github.com/opencv/opencv/wiki/OpenCV-4-to-5-migration\"\u003ehttps://github.com/opencv/opencv/wiki/OpenCV-4-to-5-migration\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/opencv/opencv-python/commits\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `pillow` from 12.2.0 to 12.3.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/python-pillow/Pillow/releases\"\u003epillow's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e12.3.0\u003c/h2\u003e\n\u003cp\u003e\u003ca href=\"https://pillow.readthedocs.io/en/stable/releasenotes/12.3.0.html\"\u003ehttps://pillow.readthedocs.io/en/stable/releasenotes/12.3.0.html\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eRemovals\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRemove non-image ImageCms modes \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9697\"\u003e#9697\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eDocumentation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd release notes for SBOM and performance improvements \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9747\"\u003e#9747\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdd security release notes \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9741\"\u003e#9741\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdd release notes for Python 3.15 beta wheels \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9696\"\u003e#9696\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eImageFont can also be used with ImageText \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9597\"\u003e#9597\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdditional guidelines for security reports \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9659\"\u003e#9659\u003c/a\u003e [\u003ca href=\"https://github.com/wiredfool\"\u003e\u003ccode\u003e@​wiredfool\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eFixed typo \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9636\"\u003e#9636\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdded CVEs to 12.2.0 release notes \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9591\"\u003e#9591\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eRevise development support information in README \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9583\"\u003e#9583\u003c/a\u003e [\u003ca href=\"https://github.com/aclark4life\"\u003e\u003ccode\u003e@​aclark4life\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdd INCIDENT_RESPONSE.md \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9555\"\u003e#9555\u003c/a\u003e [\u003ca href=\"https://github.com/aclark4life\"\u003e\u003ccode\u003e@​aclark4life\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdd STRIDE threat model to security docs \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9562\"\u003e#9562\u003c/a\u003e [\u003ca href=\"https://github.com/aclark4life\"\u003e\u003ccode\u003e@​aclark4life\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdd CVEs to 12.2.0 release notes \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9556\"\u003e#9556\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate README with revised security policy \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9553\"\u003e#9553\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate security policy \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9552\"\u003e#9552\u003c/a\u003e [\u003ca href=\"https://github.com/aclark4life\"\u003e\u003ccode\u003e@​aclark4life\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate macOS tested Python versions \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9534\"\u003e#9534\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eDependencies\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate dependency harfbuzz to v14.2.1 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9720\"\u003e#9720\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency mypy to v2 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9653\"\u003e#9653\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency cibuildwheel to v4 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9665\"\u003e#9665\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate github-actions \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9655\"\u003e#9655\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency libavif to v1.4.2 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9652\"\u003e#9652\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency lcms2 to v2.19.1 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9651\"\u003e#9651\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency check-jsonschema to v0.37.2 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9650\"\u003e#9650\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate google/oss-fuzz digest to d872252 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9614\"\u003e#9614\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency lcms2 to v2.19 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9609\"\u003e#9609\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency libpng to v1.6.58 - autoclosed \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9608\"\u003e#9608\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency harfbuzz to v14 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9610\"\u003e#9610\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency mypy to v1.20.2 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9599\"\u003e#9599\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate github-actions \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9611\"\u003e#9611\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency cibuildwheel to v3.4.1 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9607\"\u003e#9607\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eMove dependency versions to single JSON and enable Renovate \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9559\"\u003e#9559\u003c/a\u003e [\u003ca href=\"https://github.com/hugovk\"\u003e\u003ccode\u003e@​hugovk\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdated raqm to 0.10.5 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9557\"\u003e#9557\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency cibuildwheel to v3.4.0 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9532\"\u003e#9532\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eTesting\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRemove matrix.os from benchmark \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9735\"\u003e#9735\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eRemove references to libavif patch \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9734\"\u003e#9734\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdd benchmark tests \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9654\"\u003e#9654\u003c/a\u003e [\u003ca href=\"https://github.com/akx\"\u003e\u003ccode\u003e@​akx\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUse reshape() instead of setting NumPy array shape directly \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9728\"\u003e#9728\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/bb1d8e8ab8d29048624d96e3ee53cecf7c13d13d\"\u003e\u003ccode\u003ebb1d8e8\u003c/code\u003e\u003c/a\u003e 12.3.0 version bump\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/e63fc481dc2e07e21d5403deafb8f1ed98a513af\"\u003e\u003ccode\u003ee63fc48\u003c/code\u003e\u003c/a\u003e Add release notes for SBOM and performance improvements (\u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9747\"\u003e#9747\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/13b701bbab291eec4bc87ea17ba06c94e5fe3054\"\u003e\u003ccode\u003e13b701b\u003c/code\u003e\u003c/a\u003e Add release notes for \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9679\"\u003e#9679\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/5564ca72fcd59d040e270af5dcf17a0d7161c364\"\u003e\u003ccode\u003e5564ca7\u003c/code\u003e\u003c/a\u003e List methods\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/a0920fd384f800b5d0ba3dd29ecdeae4f1d4043b\"\u003e\u003ccode\u003ea0920fd\u003c/code\u003e\u003c/a\u003e Speed up ImageChops operations (\u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9738\"\u003e#9738\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/07e9a6cd5336dc6cf8cae9165cd70cdd2b3e42fc\"\u003e\u003ccode\u003e07e9a6c\u003c/code\u003e\u003c/a\u003e Speed up \u003ccode\u003eImage.filter()\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9736\"\u003e#9736\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/a94578cf9649ea13e426cf7fb2b71b39ffc0dd50\"\u003e\u003ccode\u003ea94578c\u003c/code\u003e\u003c/a\u003e Speed up \u003ccode\u003eImage.getchannel()\u003c/code\u003e, \u003ccode\u003eImage.merge()\u003c/code\u003e, \u003ccode\u003eImage.putalpha()\u003c/code\u003e and `Image...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/53e02c43c919d149b2a154a5180079f9df18fbbb\"\u003e\u003ccode\u003e53e02c4\u003c/code\u003e\u003c/a\u003e Speed up \u003ccode\u003eImage.fill()\u003c/code\u003e, \u003ccode\u003eImage.linear_gradient()\u003c/code\u003e and `Image.radial_gradient...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/af037475be8634ba739744243164ba9e2c8346a6\"\u003e\u003ccode\u003eaf03747\u003c/code\u003e\u003c/a\u003e Speed up \u003ccode\u003eImage.resample()\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9739\"\u003e#9739\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/5c9ca56c3e5fba52b647809fbb0986c87e73a571\"\u003e\u003ccode\u003e5c9ca56\u003c/code\u003e\u003c/a\u003e Speed up \u003ccode\u003ealpha_composite\u003c/code\u003e, \u003ccode\u003ematrix\u003c/code\u003e, \u003ccode\u003enegative\u003c/code\u003e, \u003ccode\u003equantize\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9740\"\u003e#9740\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/python-pillow/Pillow/compare/12.2.0...12.3.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `python-dotenv` from 0.21.1 to 1.2.3\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/theskumar/python-dotenv/releases\"\u003epython-dotenv's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.2.3\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eStrip a leading UTF-8 BOM from \u003ccode\u003e.env\u003c/code\u003e file contents so the first variable is no longer silently lost when the file is saved with BOM (e.g. by some JetBrains IDEs on Windows) by [\u003ca href=\"https://github.com/h1whelan\"\u003e\u003ccode\u003e@​h1whelan\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/640\"\u003e#640\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eset_key\u003c/code\u003e now escapes backslashes, so values containing them (Windows paths, regular expressions) survive a write/read round-trip. Quoted values ending in an escaped backslash are no longer mis-parsed as an escaped quote, which used to swallow the following lines by [\u003ca href=\"https://github.com/dchaudhari7177\"\u003e\u003ccode\u003e@​dchaudhari7177\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/680\"\u003e#680\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003edotenv run\u003c/code\u003e now prints a friendly error instead of a traceback when no command is given by [\u003ca href=\"https://github.com/bbc2\"\u003e\u003ccode\u003e@​bbc2\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/606\"\u003e#606\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eCache the parsed result for empty \u003ccode\u003e.env\u003c/code\u003e files so repeated \u003ccode\u003edotenv_values\u003c/code\u003e/\u003ccode\u003eload_dotenv\u003c/code\u003e calls no longer re-read the file by [\u003ca href=\"https://github.com/ReinerBRO\"\u003e\u003ccode\u003e@​ReinerBRO\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/638\"\u003e#638\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev1.2.2\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eSupport for Python 3.14, including the free-threaded (3.14t) build. (#)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eThe \u003ccode\u003edotenv run\u003c/code\u003e command now forwards flags directly to the specified command by \u003ca href=\"https://github.com/bbc2\"\u003e\u003ccode\u003e@​bbc2\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/pull/607\"\u003etheskumar/python-dotenv#607\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eImproved documentation clarity regarding override behavior and the reference page.\u003c/li\u003e\n\u003cli\u003eUpdated PyPy support to version 3.11.\u003c/li\u003e\n\u003cli\u003eDocumentation for FIFO file support.\u003c/li\u003e\n\u003cli\u003eSupport for Python 3.9.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eImproved \u003ccode\u003eset_key\u003c/code\u003e and \u003ccode\u003eunset_key\u003c/code\u003e behavior when interacting with symlinks by \u003ca href=\"https://github.com/bbc2\"\u003e\u003ccode\u003e@​bbc2\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://github.com/theskumar/python-dotenv/commit/790c5c02991100aa1bf41ee5330aca75edc51311\"\u003e#790c5\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eCorrected the license specifier and added missing Python 3.14 classifiers in package metadata by \u003ca href=\"https://github.com/JYOuyang\"\u003e\u003ccode\u003e@​JYOuyang\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/pull/590\"\u003etheskumar/python-dotenv#590\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBreaking Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ccode\u003edotenv.set_key\u003c/code\u003e and \u003ccode\u003edotenv.unset_key\u003c/code\u003e used to follow symlinks in some\nsituations. This is no longer the case. For that behavior to be restored in\nall cases, \u003ccode\u003efollow_symlinks=True\u003c/code\u003e should be used.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eIn the CLI, \u003ccode\u003eset\u003c/code\u003e and \u003ccode\u003eunset\u003c/code\u003e used to follow symlinks in some situations. This\nis no longer the case.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ccode\u003edotenv.set_key\u003c/code\u003e, \u003ccode\u003edotenv.unset_key\u003c/code\u003e and the CLI commands \u003ccode\u003eset\u003c/code\u003e and \u003ccode\u003eunset\u003c/code\u003e\nused to reset the file mode of the modified .env file to \u003ccode\u003e0o600\u003c/code\u003e in some\nsituations. This is no longer the case: The original mode of the file is now\npreserved. Is the file needed to be created or wasn't a regular file, mode\n\u003ccode\u003e0o600\u003c/code\u003e is used.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMisc\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eskip 000 permission tests for root user by \u003ca href=\"https://github.com/burnout-projects\"\u003e\u003ccode\u003e@​burnout-projects\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/pull/561\"\u003etheskumar/python-dotenv#561\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump actions/checkout from 5 to 6 in the github-actions group by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/pull/593\"\u003etheskumar/python-dotenv#593\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd Windows testing to CI by \u003ca href=\"https://github.com/bbc2\"\u003e\u003ccode\u003e@​bbc2\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/pull/604\"\u003etheskumar/python-dotenv#604\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eImprove workflow efficiency with best practices by \u003ca href=\"https://github.com/theskumar\"\u003e\u003ccode\u003e@​theskumar\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/pull/609\"\u003etheskumar/python-dotenv#609\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRemove the use of \u003ccode\u003esh\u003c/code\u003e in tests by \u003ca href=\"https://github.com/bbc2\"\u003e\u003ccode\u003e@​bbc2\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/pull/612\"\u003etheskumar/python-dotenv#612\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/theskumar/python-dotenv/blob/main/CHANGELOG.md\"\u003epython-dotenv's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e[1.2.3] - 2026-08-16\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eStrip a leading UTF-8 BOM from \u003ccode\u003e.env\u003c/code\u003e file contents so the first variable is no longer silently lost when the file is saved with BOM (e.g. by some JetBrains IDEs on Windows) by [\u003ca href=\"https://github.com/h1whelan\"\u003e\u003ccode\u003e@​h1whelan\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/640\"\u003e#640\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eset_key\u003c/code\u003e now escapes backslashes, so values containing them (Windows paths, regular expressions) survive a write/read round-trip. Quoted values ending in an escaped backslash are no longer mis-parsed as an escaped quote, which used to swallow the following lines by [\u003ca href=\"https://github.com/dchaudhari7177\"\u003e\u003ccode\u003e@​dchaudhari7177\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/680\"\u003e#680\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003edotenv run\u003c/code\u003e now prints a friendly error instead of a traceback when no command is given by [\u003ca href=\"https://github.com/bbc2\"\u003e\u003ccode\u003e@​bbc2\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/606\"\u003e#606\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eCache the parsed result for empty \u003ccode\u003e.env\u003c/code\u003e files so repeated \u003ccode\u003edotenv_values\u003c/code\u003e/\u003ccode\u003eload_dotenv\u003c/code\u003e calls no longer re-read the file by [\u003ca href=\"https://github.com/ReinerBRO\"\u003e\u003ccode\u003e@​ReinerBRO\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/638\"\u003e#638\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e[1.2.2] - 2026-03-01\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eSupport for Python 3.14, including the free-threaded (3.14t) build. (\u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/588\"\u003e#588\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eThe \u003ccode\u003edotenv run\u003c/code\u003e command now forwards flags directly to the specified command by [\u003ca href=\"https://github.com/bbc2\"\u003e\u003ccode\u003e@​bbc2\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/607\"\u003e#607\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eImproved documentation clarity regarding override behavior and the reference page.\u003c/li\u003e\n\u003cli\u003eUpdated PyPy support to version 3.11.\u003c/li\u003e\n\u003cli\u003eDocumentation for FIFO file support.\u003c/li\u003e\n\u003cli\u003eDropped Support for Python 3.9.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eImproved \u003ccode\u003eset_key\u003c/code\u003e and \u003ccode\u003eunset_key\u003c/code\u003e behavior when interacting with symlinks by [\u003ca href=\"https://github.com/bbc2\"\u003e\u003ccode\u003e@​bbc2\u003c/code\u003e\u003c/a\u003e] in [790c5c0]\u003c/li\u003e\n\u003cli\u003eCorrected the license specifier and added missing Python 3.14 classifiers in package metadata by [\u003ca href=\"https://github.com/JYOuyang\"\u003e\u003ccode\u003e@​JYOuyang\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/590\"\u003e#590\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBreaking Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ccode\u003edotenv.set_key\u003c/code\u003e and \u003ccode\u003edotenv.unset_key\u003c/code\u003e used to follow symlinks in some\nsituations. This is no longer the case. For that behavior to be restored in\nall cases, \u003ccode\u003efollow_symlinks=True\u003c/code\u003e should be used.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eIn the CLI, \u003ccode\u003eset\u003c/code\u003e and \u003ccode\u003eunset\u003c/code\u003e used to follow symlinks in some situations. This\nis no longer the case.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ccode\u003edotenv.set_key\u003c/code\u003e, \u003ccode\u003edotenv.unset_key\u003c/code\u003e and the CLI commands \u003ccode\u003eset\u003c/code\u003e and \u003ccode\u003eunset\u003c/code\u003e\nused to reset the file mode of the modified .env file to \u003ccode\u003e0o600\u003c/code\u003e in some\nsituations. This is no longer the case: The original mode of the file is now\npreserved. Is the file needed to be created or wasn't a regular file, mode\n\u003ccode\u003e0o600\u003c/code\u003e is used.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e[1.2.1] - 2025-10-26\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMove more config to \u003ccode\u003epyproject.toml\u003c/code\u003e, removed \u003ccode\u003esetup.cfg\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eAdd support for reading \u003ccode\u003e.env\u003c/code\u003e from FIFOs (Unix) by [\u003ca href=\"https://github.com/sidharth-sudhir\"\u003e\u003ccode\u003e@​sidharth-sudhir\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/586\"\u003e#586\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e[1.2.0] - 2025-10-26\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/49515afee2d50c33cad9419b3800b3a0dc93fc59\"\u003e\u003ccode\u003e49515af\u003c/code\u003e\u003c/a\u003e Bump version: 1.2.2 → 1.2.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/8ac846ff2760b65470e769d7eed33e540f0934e1\"\u003e\u003ccode\u003e8ac846f\u003c/code\u003e\u003c/a\u003e chore: add release runbook (RELEASING.md) and make release target\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/bb31c944fb4b40e8dea59587f525840c38326166\"\u003e\u003ccode\u003ebb31c94\u003c/code\u003e\u003c/a\u003e docs: add 1.2.3 release notes (\u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/606\"\u003e#606\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/638\"\u003e#638\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/680\"\u003e#680\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/f7b18d9c72d1abcc2ad4023424b84f5bee30d266\"\u003e\u003ccode\u003ef7b18d9\u003c/code\u003e\u003c/a\u003e fix: round-trip backslashes through set_key (\u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/680\"\u003e#680\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/751f8c148222e58aa173c83c4e5e6cfccb2cc124\"\u003e\u003ccode\u003e751f8c1\u003c/code\u003e\u003c/a\u003e ci(deps): bump actions/checkout from 6.0.2 to 6.0.3 in the github-actions gro...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/f1937b68f338d7ebd7754da377ca08b2f0df8dbb\"\u003e\u003ccode\u003ef1937b6\u003c/code\u003e\u003c/a\u003e chore(deps): update mkdocs-include-markdown-plugin requirement from \u0026gt;=6.0.0 t...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/45b93720dd5e9e127d0be3971a04855d34e464d8\"\u003e\u003ccode\u003e45b9372\u003c/code\u003e\u003c/a\u003e chore(deps): update pytest requirement from \u0026gt;=3.9 to \u0026gt;=9.0.3 (\u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/653\"\u003e#653\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/72896e9244d2a1ff8d5e1934d3df8a35c813799a\"\u003e\u003ccode\u003e72896e9\u003c/code\u003e\u003c/a\u003e docs: fix broken mkdocs link in CONTRIBUTING.md (\u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/636\"\u003e#636\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/72754a16a4743e4c92edf87ce59ba0e4ff78758d\"\u003e\u003ccode\u003e72754a1\u003c/code\u003e\u003c/a\u003e ci(deps): bump peaceiris/actions-gh-pages from 4.0.0 to 4.1.0 in the github-a...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/078325e92558330e9addc661b789c7b6123fa73c\"\u003e\u003ccode\u003e078325e\u003c/code\u003e\u003c/a\u003e ci(security): harden CI/CD supply chain with SHA pinning and least-privilege ...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/theskumar/python-dotenv/compare/v0.21.1...v1.2.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `aiohttp` from 3.14.1 to 3.14.3\nUpdates `cryptography` from 50.0.0 to 50.0.1\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst\"\u003ecryptography's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e50.0.1 - 2026-08-25\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003e\n* Updated Windows, macOS, and Linux wheels to be compiled with OpenSSL 4.0.2.\n\u003cp\u003e.. _v50-0-0:\u003cbr /\u003e\n\u003c/code\u003e\u003c/pre\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/ffde75a2b594822c740a2e4748b56c00548302bf\"\u003e\u003ccode\u003effde75a\u003c/code\u003e\u003c/a\u003e bump for 50.0.1 + changelog (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15520\"\u003e#15520\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/pyca/cryptography/compare/50.0.0...50.0.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\n\n\n\u003c/details\u003e","html_url":"https://github.com/Team-Hamsa/LFG/pull/586","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/Team-Hamsa%2FLFG/issues/586","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/586/packages"},{"uuid":"5513101412","node_id":"PR_kwDOT_waCs8AAAABEP-mQw","number":89,"state":"open","title":"build(deps): bump the pip-minor-patch group in /services/ai-orchestrator-service with 70 updates","user":"dependabot[bot]","labels":[],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-19T19:44:57.000Z","updated_at":"2026-09-19T19:44:58.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"build(deps): bump","group_name":"pip-minor-patch","update_count":70,"packages":[{"name":"aiohttp","old_version":"3.14.1","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"annotated-doc","old_version":"0.0.4","new_version":"0.0.5","repository_url":"https://github.com/fastapi/annotated-doc"},{"name":"annotated-types","old_version":"0.7.0","new_version":"0.8.0","repository_url":"https://github.com/annotated-types/annotated-types"},{"name":"anyio","old_version":"4.14.2","new_version":"4.15.1","repository_url":"https://github.com/agronholm/anyio"},{"name":"build","old_version":"1.5.0","new_version":"1.6.1","repository_url":"https://github.com/pypa/build"},{"name":"certifi","old_version":"2026.6.17","new_version":"2026.7.22","repository_url":"https://github.com/certifi/python-certifi"},{"name":"cffi","old_version":"2.1.0","new_version":"2.1.1","repository_url":"https://github.com/python-cffi/cffi"},{"name":"charset-normalizer","old_version":"3.4.9","new_version":"3.5.1","repository_url":"https://github.com/jawah/charset_normalizer"},{"name":"click","old_version":"8.4.2","new_version":"8.5.0","repository_url":"https://github.com/pallets/click"},{"name":"cloudpathlib","old_version":"0.24.0","new_version":"0.25.0","repository_url":"https://github.com/drivendataorg/cloudpathlib"},{"name":"contourpy","old_version":"1.3.3","new_version":"1.4.0","repository_url":"https://github.com/contourpy/contourpy"},{"name":"durationpy","old_version":"0.10","new_version":"0.11","repository_url":"https://github.com/icholy/durationpy"},{"name":"fastapi","old_version":"0.139.2","new_version":"0.141.1","repository_url":"https://github.com/fastapi/fastapi"},{"name":"filelock","old_version":"3.30.2","new_version":"3.32.7","repository_url":"https://github.com/tox-dev/py-filelock"},{"name":"fonttools","old_version":"4.63.0","new_version":"4.65.0","repository_url":"https://github.com/fonttools/fonttools"},{"name":"fsspec","old_version":"2026.6.0","new_version":"2026.7.0","repository_url":"https://github.com/fsspec/filesystem_spec"},{"name":"google-auth","old_version":"2.55.2","new_version":"2.58.0","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"google-genai","old_version":"2.12.0","new_version":"2.23.0","repository_url":"https://github.com/googleapis/python-genai"},{"name":"googleapis-common-protos","old_version":"1.75.0","new_version":"1.75.3","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"grpcio","old_version":"1.82.1","new_version":"1.84.0","repository_url":"https://github.com/grpc/grpc"},{"name":"hf-xet","old_version":"1.5.2","new_version":"1.6.0","repository_url":"https://github.com/huggingface/xet-core"},{"name":"huggingface-hub","old_version":"1.23.0","new_version":"1.31.0","repository_url":"https://github.com/huggingface/huggingface_hub"},{"name":"idna","old_version":"3.18","new_version":"3.19","repository_url":"https://github.com/kjd/idna"},{"name":"jiter","old_version":"0.16.0","new_version":"0.17.0","repository_url":"https://github.com/pydantic/jiter"},{"name":"joblib","old_version":"1.5.3","new_version":"1.6.0","repository_url":"https://github.com/joblib/joblib"},{"name":"kiwisolver","old_version":"1.5.0","new_version":"1.5.1","repository_url":"https://github.com/nucleic/kiwi"},{"name":"langchain","old_version":"1.3.14","new_version":"1.4.1","repository_url":"https://github.com/langchain-ai/langchain"},{"name":"langchain-core","old_version":"1.4.9","new_version":"1.6.3","repository_url":"https://github.com/langchain-ai/langchain"},{"name":"langchain-google-genai","old_version":"4.2.7","new_version":"4.4.0","repository_url":"https://github.com/langchain-ai/langchain-google"},{"name":"langchain-protocol","old_version":"0.0.18","new_version":"0.0.19","repository_url":"https://github.com/langchain-ai/agent-protocol"},{"name":"langgraph","old_version":"1.2.9","new_version":"1.2.11","repository_url":"https://github.com/langchain-ai/langgraph"},{"name":"langgraph-checkpoint","old_version":"4.1.1","new_version":"4.2.0","repository_url":"https://github.com/langchain-ai/langgraph"},{"name":"langgraph-sdk","old_version":"0.4.2","new_version":"0.4.4","repository_url":"https://github.com/langchain-ai/langgraph"},{"name":"langsmith","old_version":"0.10.5","new_version":"0.12.6","repository_url":"https://github.com/langchain-ai/langsmith-sdk"},{"name":"mmh3","old_version":"5.2.1","new_version":"5.3.0","repository_url":"https://github.com/hajimes/mmh3"},{"name":"mpmath","old_version":"1.3.0","new_version":"1.4.1","repository_url":"https://github.com/mpmath/mpmath"},{"name":"multidict","old_version":"6.7.1","new_version":"6.8.0","repository_url":"https://github.com/aio-libs/multidict"},{"name":"narwhals","old_version":"2.24.0","new_version":"2.26.0","repository_url":"https://github.com/narwhals-dev/narwhals"},{"name":"numpy","old_version":"2.5.1","new_version":"2.5.3","repository_url":"https://github.com/numpy/numpy"},{"name":"onnxruntime","old_version":"1.27.0","new_version":"1.30.0","repository_url":"https://github.com/microsoft/onnxruntime"},{"name":"orjson","old_version":"3.11.9","new_version":"3.12.0","repository_url":"https://github.com/ijl/orjson"},{"name":"packaging","old_version":"26.2","new_version":"26.3","repository_url":"https://github.com/pypa/packaging"},{"name":"pandas","old_version":"3.0.3","new_version":"3.0.5","repository_url":"https://github.com/pandas-dev/pandas"},{"name":"propcache","old_version":"0.5.2","new_version":"0.5.4","repository_url":"https://github.com/aio-libs/propcache"},{"name":"protobuf","old_version":"7.35.1","new_version":"7.36.1","repository_url":"https://github.com/protocolbuffers/protobuf"},{"name":"pybase64","old_version":"1.4.3","new_version":"1.5.0","repository_url":"https://github.com/mayeut/pybase64"},{"name":"pydantic","old_version":"2.13.4","new_version":"2.13.5","repository_url":"https://github.com/pydantic/pydantic"},{"name":"pydantic-settings","old_version":"2.14.2","new_version":"2.15.0","repository_url":"https://github.com/pydantic/pydantic-settings"},{"name":"pydantic-core","old_version":"2.46.4","new_version":"2.49.0","repository_url":"https://github.com/pydantic/pydantic"},{"name":"pygments","old_version":"2.20.0","new_version":"2.21.0","repository_url":"https://github.com/pygments/pygments"},{"name":"pyproject-hooks","old_version":"1.2.0","new_version":"1.3.3","repository_url":"https://github.com/pypa/pyproject-hooks"},{"name":"python-dotenv","old_version":"1.2.2","new_version":"1.2.3","repository_url":"https://github.com/theskumar/python-dotenv"},{"name":"regex","old_version":"2026.7.10","new_version":"2026.9.10","repository_url":"https://github.com/mrabarnett/mrab-regex"},{"name":"scikit-learn","old_version":"1.9.0","new_version":"1.9.1","repository_url":"https://github.com/scikit-learn/scikit-learn"},{"name":"scipy","old_version":"1.18.0","new_version":"1.18.1","repository_url":"https://github.com/scipy/scipy"},{"name":"smart-open","old_version":"8.0.0","new_version":"8.0.1","repository_url":"https://github.com/piskvorky/smart_open"},{"name":"starlette","old_version":"1.3.1","new_version":"1.6.0","repository_url":"https://github.com/Kludex/starlette"},{"name":"threadpoolctl","old_version":"3.6.0","new_version":"3.7.0","repository_url":"https://github.com/joblib/threadpoolctl"},{"name":"tokenizers","old_version":"0.22.2","new_version":"0.23.2","repository_url":"https://github.com/huggingface/tokenizers"},{"name":"torch","old_version":"2.13.0","new_version":"2.14.0","repository_url":"https://github.com/pytorch/pytorch"},{"name":"tqdm","old_version":"4.68.4","new_version":"4.70.1","repository_url":"https://github.com/tqdm/tqdm"},{"name":"transformers","old_version":"5.14.1","new_version":"5.17.0","repository_url":"https://github.com/huggingface/transformers"},{"name":"typer","old_version":"0.26.8","new_version":"0.27.2","repository_url":"https://github.com/fastapi/typer"},{"name":"typing-inspection","old_version":"0.4.2","new_version":"0.4.4","repository_url":"https://github.com/pydantic/typing-inspection"},{"name":"tzdata","old_version":"2026.3","new_version":"2026.4","repository_url":"https://github.com/python/tzdata"},{"name":"urllib3","old_version":"2.7.0","new_version":"2.8.0","repository_url":"https://github.com/urllib3/urllib3"},{"name":"uvicorn","old_version":"0.51.0","new_version":"0.53.0","repository_url":"https://github.com/Kludex/uvicorn"},{"name":"websocket-client","old_version":"1.9.0","new_version":"1.9.2","repository_url":"https://github.com/websocket-client/websocket-client"},{"name":"wrapt","old_version":"2.2.2","new_version":"2.4.1","repository_url":"https://github.com/GrahamDumpleton/wrapt"},{"name":"yarl","old_version":"1.24.2","new_version":"1.25.1","repository_url":"https://github.com/aio-libs/yarl"}],"path":"/services/ai-orchestrator-service","ecosystem":"pip"},"body":"Bumps the pip-minor-patch group in /services/ai-orchestrator-service with 70 updates:\n\n| Package | From | To |\n| --- | --- | --- |\n| [aiohttp](https://github.com/aio-libs/aiohttp) | `3.14.1` | `3.14.3` |\n| [annotated-doc](https://github.com/fastapi/annotated-doc) | `0.0.4` | `0.0.5` |\n| [annotated-types](https://github.com/annotated-types/annotated-types) | `0.7.0` | `0.8.0` |\n| [anyio](https://github.com/agronholm/anyio) | `4.14.2` | `4.15.1` |\n| [build](https://github.com/pypa/build) | `1.5.0` | `1.6.1` |\n| [certifi](https://github.com/certifi/python-certifi) | `2026.6.17` | `2026.7.22` |\n| [cffi](https://github.com/python-cffi/cffi) | `2.1.0` | `2.1.1` |\n| [charset-normalizer](https://github.com/jawah/charset_normalizer) | `3.4.9` | `3.5.1` |\n| [click](https://github.com/pallets/click) | `8.4.2` | `8.5.0` |\n| [cloudpathlib](https://github.com/drivendataorg/cloudpathlib) | `0.24.0` | `0.25.0` |\n| [contourpy](https://github.com/contourpy/contourpy) | `1.3.3` | `1.4.0` |\n| [durationpy](https://github.com/icholy/durationpy) | `0.10` | `0.11` |\n| [fastapi](https://github.com/fastapi/fastapi) | `0.139.2` | `0.141.1` |\n| [filelock](https://github.com/tox-dev/py-filelock) | `3.30.2` | `3.32.7` |\n| [fonttools](https://github.com/fonttools/fonttools) | `4.63.0` | `4.65.0` |\n| [fsspec](https://github.com/fsspec/filesystem_spec) | `2026.6.0` | `2026.7.0` |\n| [google-auth](https://github.com/googleapis/google-cloud-python) | `2.55.2` | `2.58.0` |\n| [google-genai](https://github.com/googleapis/python-genai) | `2.12.0` | `2.23.0` |\n| [googleapis-common-protos](https://github.com/googleapis/google-cloud-python) | `1.75.0` | `1.75.3` |\n| [grpcio](https://github.com/grpc/grpc) | `1.82.1` | `1.84.0` |\n| [hf-xet](https://github.com/huggingface/xet-core) | `1.5.2` | `1.6.0` |\n| [huggingface-hub](https://github.com/huggingface/huggingface_hub) | `1.23.0` | `1.31.0` |\n| [idna](https://github.com/kjd/idna) | `3.18` | `3.19` |\n| [jiter](https://github.com/pydantic/jiter) | `0.16.0` | `0.17.0` |\n| [joblib](https://github.com/joblib/joblib) | `1.5.3` | `1.6.0` |\n| [kiwisolver](https://github.com/nucleic/kiwi) | `1.5.0` | `1.5.1` |\n| [langchain](https://github.com/langchain-ai/langchain) | `1.3.14` | `1.4.1` |\n| [langchain-core](https://github.com/langchain-ai/langchain) | `1.4.9` | `1.6.3` |\n| [langchain-google-genai](https://github.com/langchain-ai/langchain-google) | `4.2.7` | `4.4.0` |\n| [langchain-protocol](https://github.com/langchain-ai/agent-protocol) | `0.0.18` | `0.0.19` |\n| [langgraph](https://github.com/langchain-ai/langgraph) | `1.2.9` | `1.2.11` |\n| [langgraph-checkpoint](https://github.com/langchain-ai/langgraph) | `4.1.1` | `4.2.0` |\n| [langgraph-sdk](https://github.com/langchain-ai/langgraph) | `0.4.2` | `0.4.4` |\n| [langsmith](https://github.com/langchain-ai/langsmith-sdk) | `0.10.5` | `0.12.6` |\n| [mmh3](https://github.com/hajimes/mmh3) | `5.2.1` | `5.3.0` |\n| [mpmath](https://github.com/mpmath/mpmath) | `1.3.0` | `1.4.1` |\n| [multidict](https://github.com/aio-libs/multidict) | `6.7.1` | `6.8.0` |\n| [narwhals](https://github.com/narwhals-dev/narwhals) | `2.24.0` | `2.26.0` |\n| [numpy](https://github.com/numpy/numpy) | `2.5.1` | `2.5.3` |\n| [onnxruntime](https://github.com/microsoft/onnxruntime) | `1.27.0` | `1.30.0` |\n| [orjson](https://github.com/ijl/orjson) | `3.11.9` | `3.12.0` |\n| [packaging](https://github.com/pypa/packaging) | `26.2` | `26.3` |\n| [pandas](https://github.com/pandas-dev/pandas) | `3.0.3` | `3.0.5` |\n| [propcache](https://github.com/aio-libs/propcache) | `0.5.2` | `0.5.4` |\n| [protobuf](https://github.com/protocolbuffers/protobuf) | `7.35.1` | `7.36.1` |\n| [pybase64](https://github.com/mayeut/pybase64) | `1.4.3` | `1.5.0` |\n| [pydantic](https://github.com/pydantic/pydantic) | `2.13.4` | `2.13.5` |\n| [pydantic-settings](https://github.com/pydantic/pydantic-settings) | `2.14.2` | `2.15.0` |\n| [pydantic-core](https://github.com/pydantic/pydantic) | `2.46.4` | `2.49.0` |\n| [pygments](https://github.com/pygments/pygments) | `2.20.0` | `2.21.0` |\n| [pyproject-hooks](https://github.com/pypa/pyproject-hooks) | `1.2.0` | `1.3.3` |\n| [python-dotenv](https://github.com/theskumar/python-dotenv) | `1.2.2` | `1.2.3` |\n| [regex](https://github.com/mrabarnett/mrab-regex) | `2026.7.10` | `2026.9.10` |\n| [scikit-learn](https://github.com/scikit-learn/scikit-learn) | `1.9.0` | `1.9.1` |\n| [scipy](https://github.com/scipy/scipy) | `1.18.0` | `1.18.1` |\n| [smart-open](https://github.com/piskvorky/smart_open) | `8.0.0` | `8.0.1` |\n| [starlette](https://github.com/Kludex/starlette) | `1.3.1` | `1.6.0` |\n| [threadpoolctl](https://github.com/joblib/threadpoolctl) | `3.6.0` | `3.7.0` |\n| [tokenizers](https://github.com/huggingface/tokenizers) | `0.22.2` | `0.23.2` |\n| [torch](https://github.com/pytorch/pytorch) | `2.13.0` | `2.14.0` |\n| [tqdm](https://github.com/tqdm/tqdm) | `4.68.4` | `4.70.1` |\n| [transformers](https://github.com/huggingface/transformers) | `5.14.1` | `5.17.0` |\n| [typer](https://github.com/fastapi/typer) | `0.26.8` | `0.27.2` |\n| [typing-inspection](https://github.com/pydantic/typing-inspection) | `0.4.2` | `0.4.4` |\n| [tzdata](https://github.com/python/tzdata) | `2026.3` | `2026.4` |\n| [urllib3](https://github.com/urllib3/urllib3) | `2.7.0` | `2.8.0` |\n| [uvicorn](https://github.com/Kludex/uvicorn) | `0.51.0` | `0.53.0` |\n| [websocket-client](https://github.com/websocket-client/websocket-client) | `1.9.0` | `1.9.2` |\n| [wrapt](https://github.com/GrahamDumpleton/wrapt) | `2.2.2` | `2.4.1` |\n| [yarl](https://github.com/aio-libs/yarl) | `1.24.2` | `1.25.1` |\n\nUpdates `aiohttp` from 3.14.1 to 3.14.3\nUpdates `annotated-doc` from 0.0.4 to 0.0.5\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/fastapi/annotated-doc/releases\"\u003eannotated-doc's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e0.0.5\u003c/h2\u003e\n\u003ch3\u003eBreaking Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e➖ Drop support for Python 3.8. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/36\"\u003e#36\u003c/a\u003e by \u003ca href=\"https://github.com/svlandeg\"\u003e\u003ccode\u003e@​svlandeg\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eUpgrades\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e⬆ Bump ruff from 0.14.3 to 0.14.10. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/31\"\u003e#31\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDocs\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e📝 Update security policy. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/63\"\u003e#63\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eInternal\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e⬆️ Upgrade latest-changes to 0.7.1. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/92\"\u003e#92\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump the github-actions group across 1 directory with 3 updates. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/91\"\u003e#91\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump the python-packages group across 1 directory with 3 updates. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/90\"\u003e#90\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump pre-commit hooks. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/89\"\u003e#89\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e👷 Add GH workflow to bump pre-commit hook versions. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/81\"\u003e#81\u003c/a\u003e by \u003ca href=\"https://github.com/YuriiMotov\"\u003e\u003ccode\u003e@​YuriiMotov\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e🔧 Set Dependabot schedule interval to \u0026quot;monthly\u0026quot;. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/82\"\u003e#82\u003c/a\u003e by \u003ca href=\"https://github.com/YuriiMotov\"\u003e\u003ccode\u003e@​YuriiMotov\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e👷 Fix latest-changes checkout target. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/85\"\u003e#85\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆️ Update issue-manager to 0.8.1. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/84\"\u003e#84\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆️ Update latest-changes to 0.6.1. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/83\"\u003e#83\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump the python-packages group across 1 directory with 3 updates. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/72\"\u003e#72\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump the github-actions group across 1 directory with 3 updates. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/80\"\u003e#80\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump \u003ca href=\"https://github.com/crate-ci/typos\"\u003ehttps://github.com/crate-ci/typos\u003c/a\u003e from v1.46.0 to 1.47.2 in the pre-commit group across 1 directory. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/76\"\u003e#76\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e👷 Simplify pull request workflow triggers. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/79\"\u003e#79\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e👷 Update issue-manager to 0.7.1. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/78\"\u003e#78\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆️ Update issue-manager to 0.7.0. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/77\"\u003e#77\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e🔒️ Update zizmor workflow security checks. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/75\"\u003e#75\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e👷 Fix alls-green test dependency. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/74\"\u003e#74\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e👷 Add pre-commit hook to catch typos. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/68\"\u003e#68\u003c/a\u003e by \u003ca href=\"https://github.com/YuriiMotov\"\u003e\u003ccode\u003e@​YuriiMotov\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump the python-packages group with 3 updates. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/70\"\u003e#70\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump the github-actions group with 2 updates. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/71\"\u003e#71\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e👷 Automate release preparation. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/69\"\u003e#69\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e👷 Configure Dependabot to group updates and update weekly. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/62\"\u003e#62\u003c/a\u003e by \u003ca href=\"https://github.com/YuriiMotov\"\u003e\u003ccode\u003e@​YuriiMotov\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e🔥 Remove config files now in central GitHub repo. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/65\"\u003e#65\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e👷 Fix branch name in \u003ccode\u003eguard-dependencies.yml\u003c/code\u003e. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/61\"\u003e#61\u003c/a\u003e by \u003ca href=\"https://github.com/svlandeg\"\u003e\u003ccode\u003e@​svlandeg\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e🔒️ Only allow team members to modify dependencies. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/60\"\u003e#60\u003c/a\u003e by \u003ca href=\"https://github.com/svlandeg\"\u003e\u003ccode\u003e@​svlandeg\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump ty from 0.0.33 to 0.0.34. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/58\"\u003e#58\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump prek from 0.3.11 to 0.3.13. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/59\"\u003e#59\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e🔒️ Add zizmor and fix audit findings. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/50\"\u003e#50\u003c/a\u003e by \u003ca href=\"https://github.com/YuriiMotov\"\u003e\u003ccode\u003e@​YuriiMotov\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆️ Bump the lower bound of \u003ccode\u003ety\u003c/code\u003e to 0.0.25. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/57\"\u003e#57\u003c/a\u003e by \u003ca href=\"https://github.com/svlandeg\"\u003e\u003ccode\u003e@​svlandeg\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e👷 Configure \u003ccode\u003ety\u003c/code\u003e to exit with error code on warnings. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/56\"\u003e#56\u003c/a\u003e by \u003ca href=\"https://github.com/svlandeg\"\u003e\u003ccode\u003e@​svlandeg\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump actions/add-to-project from 1.0.2 to 2.0.0. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/54\"\u003e#54\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump actions/labeler from 6.0.1 to 6.1.0. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/55\"\u003e#55\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump ruff from 0.15.8 to 0.15.12. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/51\"\u003e#51\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump prek from 0.3.8 to 0.3.11. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/53\"\u003e#53\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump ty from 0.0.27 to 0.0.33. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/52\"\u003e#52\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/fastapi/annotated-doc/blob/main/release-notes.md\"\u003eannotated-doc's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e0.0.5 (2026-07-28)\u003c/h2\u003e\n\u003ch3\u003eBreaking Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e➖ Drop support for Python 3.8. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/36\"\u003e#36\u003c/a\u003e by \u003ca href=\"https://github.com/svlandeg\"\u003e\u003ccode\u003e@​svlandeg\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eUpgrades\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e⬆ Bump ruff from 0.14.3 to 0.14.10. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/31\"\u003e#31\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDocs\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e📝 Update security policy. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/63\"\u003e#63\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eInternal\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e⬆️ Upgrade latest-changes to 0.7.1. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/92\"\u003e#92\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump the github-actions group across 1 directory with 3 updates. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/91\"\u003e#91\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump the python-packages group across 1 directory with 3 updates. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/90\"\u003e#90\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump pre-commit hooks. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/89\"\u003e#89\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e👷 Add GH workflow to bump pre-commit hook versions. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/81\"\u003e#81\u003c/a\u003e by \u003ca href=\"https://github.com/YuriiMotov\"\u003e\u003ccode\u003e@​YuriiMotov\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e🔧 Set Dependabot schedule interval to \u0026quot;monthly\u0026quot;. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/82\"\u003e#82\u003c/a\u003e by \u003ca href=\"https://github.com/YuriiMotov\"\u003e\u003ccode\u003e@​YuriiMotov\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e👷 Fix latest-changes checkout target. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/85\"\u003e#85\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆️ Update issue-manager to 0.8.1. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/84\"\u003e#84\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆️ Update latest-changes to 0.6.1. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/83\"\u003e#83\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump the python-packages group across 1 directory with 3 updates. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/72\"\u003e#72\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump the github-actions group across 1 directory with 3 updates. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/80\"\u003e#80\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump \u003ca href=\"https://github.com/crate-ci/typos\"\u003ehttps://github.com/crate-ci/typos\u003c/a\u003e from v1.46.0 to 1.47.2 in the pre-commit group across 1 directory. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/76\"\u003e#76\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e👷 Simplify pull request workflow triggers. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/79\"\u003e#79\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e👷 Update issue-manager to 0.7.1. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/78\"\u003e#78\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆️ Update issue-manager to 0.7.0. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/77\"\u003e#77\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e🔒️ Update zizmor workflow security checks. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/75\"\u003e#75\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e👷 Fix alls-green test dependency. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/74\"\u003e#74\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e👷 Add pre-commit hook to catch typos. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/68\"\u003e#68\u003c/a\u003e by \u003ca href=\"https://github.com/YuriiMotov\"\u003e\u003ccode\u003e@​YuriiMotov\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump the python-packages group with 3 updates. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/70\"\u003e#70\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump the github-actions group with 2 updates. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/71\"\u003e#71\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e👷 Automate release preparation. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/69\"\u003e#69\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e👷 Configure Dependabot to group updates and update weekly. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/62\"\u003e#62\u003c/a\u003e by \u003ca href=\"https://github.com/YuriiMotov\"\u003e\u003ccode\u003e@​YuriiMotov\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e🔥 Remove config files now in central GitHub repo. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/65\"\u003e#65\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e👷 Fix branch name in \u003ccode\u003eguard-dependencies.yml\u003c/code\u003e. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/61\"\u003e#61\u003c/a\u003e by \u003ca href=\"https://github.com/svlandeg\"\u003e\u003ccode\u003e@​svlandeg\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e🔒️ Only allow team members to modify dependencies. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/60\"\u003e#60\u003c/a\u003e by \u003ca href=\"https://github.com/svlandeg\"\u003e\u003ccode\u003e@​svlandeg\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump ty from 0.0.33 to 0.0.34. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/58\"\u003e#58\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump prek from 0.3.11 to 0.3.13. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/59\"\u003e#59\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e🔒️ Add zizmor and fix audit findings. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/50\"\u003e#50\u003c/a\u003e by \u003ca href=\"https://github.com/YuriiMotov\"\u003e\u003ccode\u003e@​YuriiMotov\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆️ Bump the lower bound of \u003ccode\u003ety\u003c/code\u003e to 0.0.25. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/57\"\u003e#57\u003c/a\u003e by \u003ca href=\"https://github.com/svlandeg\"\u003e\u003ccode\u003e@​svlandeg\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e👷 Configure \u003ccode\u003ety\u003c/code\u003e to exit with error code on warnings. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/56\"\u003e#56\u003c/a\u003e by \u003ca href=\"https://github.com/svlandeg\"\u003e\u003ccode\u003e@​svlandeg\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump actions/add-to-project from 1.0.2 to 2.0.0. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/54\"\u003e#54\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump actions/labeler from 6.0.1 to 6.1.0. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/55\"\u003e#55\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump ruff from 0.15.8 to 0.15.12. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/51\"\u003e#51\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump prek from 0.3.8 to 0.3.11. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/53\"\u003e#53\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastapi/annotated-doc/commit/ef48d6ad51d226f772fd9c5284f55199afe4007c\"\u003e\u003ccode\u003eef48d6a\u003c/code\u003e\u003c/a\u003e 🔖 Release version 0.0.5 (\u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/issues/93\"\u003e#93\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastapi/annotated-doc/commit/c628000835a26f6bc8c776f90bcbcf95211f233b\"\u003e\u003ccode\u003ec628000\u003c/code\u003e\u003c/a\u003e 📝 Update release notes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastapi/annotated-doc/commit/e0b4579d2ad8d62a304c9f30a1c2c084f0d372e5\"\u003e\u003ccode\u003ee0b4579\u003c/code\u003e\u003c/a\u003e ➖ Drop support for Python 3.8 (\u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/issues/36\"\u003e#36\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastapi/annotated-doc/commit/ef956b4e9f2c0e2bead1cba7a6888e1ed8c2c237\"\u003e\u003ccode\u003eef956b4\u003c/code\u003e\u003c/a\u003e 📝 Update release notes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastapi/annotated-doc/commit/84bf1e5402c5e0cfd1462c5d3c8bae22fb717bd8\"\u003e\u003ccode\u003e84bf1e5\u003c/code\u003e\u003c/a\u003e ⬆️ Upgrade latest-changes to 0.7.1 (\u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/issues/92\"\u003e#92\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastapi/annotated-doc/commit/cf773e138b1dc5608ce0f0d11e1939c410ef6228\"\u003e\u003ccode\u003ecf773e1\u003c/code\u003e\u003c/a\u003e 📝 Update release notes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastapi/annotated-doc/commit/1375d6eb8147cb2352d080ef09f356dfc18e0d29\"\u003e\u003ccode\u003e1375d6e\u003c/code\u003e\u003c/a\u003e ⬆ Bump the github-actions group across 1 directory with 3 updates (\u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/issues/91\"\u003e#91\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastapi/annotated-doc/commit/cd373656cbf40e5fd4cc28680ca5e05bf12709cb\"\u003e\u003ccode\u003ecd37365\u003c/code\u003e\u003c/a\u003e 📝 Update release notes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastapi/annotated-doc/commit/f9f3b695cbacc4ffc37d9cebff6e05bd1751f68a\"\u003e\u003ccode\u003ef9f3b69\u003c/code\u003e\u003c/a\u003e ⬆ Bump the python-packages group across 1 directory with 3 updates (\u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/issues/90\"\u003e#90\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastapi/annotated-doc/commit/842084457f0a7739fb91d2a4ea602b2bc4e15767\"\u003e\u003ccode\u003e8420844\u003c/code\u003e\u003c/a\u003e 📝 Update release notes\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/fastapi/annotated-doc/compare/0.0.4...0.0.5\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `annotated-types` from 0.7.0 to 0.8.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/annotated-types/annotated-types/releases\"\u003eannotated-types's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev0.8.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRename DocInfo to Doc by \u003ca href=\"https://github.com/zen-xu\"\u003e\u003ccode\u003e@​zen-xu\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/pull/80\"\u003eannotated-types/annotated-types#80\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd support for Python 3.13 by \u003ca href=\"https://github.com/hugovk\"\u003e\u003ccode\u003e@​hugovk\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/pull/83\"\u003eannotated-types/annotated-types#83\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix docstring of \u003ccode\u003eTimezone\u003c/code\u003e by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/pull/84\"\u003eannotated-types/annotated-types#84\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate license-files to be PEP-639 compliant (\u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/issues/85\"\u003e#85\u003c/a\u003e) by \u003ca href=\"https://github.com/shoeffner\"\u003e\u003ccode\u003e@​shoeffner\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/pull/86\"\u003eannotated-types/annotated-types#86\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: typo in README.md by \u003ca href=\"https://github.com/camiloaz\"\u003e\u003ccode\u003e@​camiloaz\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/pull/87\"\u003eannotated-types/annotated-types#87\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eadd CI for PyPy3.11 and fix test (issue 71) by \u003ca href=\"https://github.com/mattip\"\u003e\u003ccode\u003e@​mattip\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/pull/88\"\u003eannotated-types/annotated-types#88\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix string predicate names in doc by \u003ca href=\"https://github.com/leogermond\"\u003e\u003ccode\u003e@​leogermond\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/pull/90\"\u003eannotated-types/annotated-types#90\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd SPDX license expression by \u003ca href=\"https://github.com/wichert\"\u003e\u003ccode\u003e@​wichert\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/pull/92\"\u003eannotated-types/annotated-types#92\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdded Python 3.14 to the test matrix by \u003ca href=\"https://github.com/imtoopunkforyou\"\u003e\u003ccode\u003e@​imtoopunkforyou\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/pull/96\"\u003eannotated-types/annotated-types#96\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd support for Python 3.14 and drop EOL 3.8-3.9 by \u003ca href=\"https://github.com/hugovk\"\u003e\u003ccode\u003e@​hugovk\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/pull/97\"\u003eannotated-types/annotated-types#97\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix typo in \u003ccode\u003eLen\u003c/code\u003e docstring by \u003ca href=\"https://github.com/Dutcho\"\u003e\u003ccode\u003e@​Dutcho\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/pull/100\"\u003eannotated-types/annotated-types#100\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePrepare for 0.8.0 release by \u003ca href=\"https://github.com/adriangb\"\u003e\u003ccode\u003e@​adriangb\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/pull/103\"\u003eannotated-types/annotated-types#103\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/zen-xu\"\u003e\u003ccode\u003e@​zen-xu\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/pull/80\"\u003eannotated-types/annotated-types#80\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hugovk\"\u003e\u003ccode\u003e@​hugovk\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/pull/83\"\u003eannotated-types/annotated-types#83\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/shoeffner\"\u003e\u003ccode\u003e@​shoeffner\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/pull/86\"\u003eannotated-types/annotated-types#86\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/camiloaz\"\u003e\u003ccode\u003e@​camiloaz\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/pull/87\"\u003eannotated-types/annotated-types#87\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mattip\"\u003e\u003ccode\u003e@​mattip\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/pull/88\"\u003eannotated-types/annotated-types#88\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/leogermond\"\u003e\u003ccode\u003e@​leogermond\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/pull/90\"\u003eannotated-types/annotated-types#90\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/wichert\"\u003e\u003ccode\u003e@​wichert\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/pull/92\"\u003eannotated-types/annotated-types#92\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/imtoopunkforyou\"\u003e\u003ccode\u003e@​imtoopunkforyou\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/pull/96\"\u003eannotated-types/annotated-types#96\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Dutcho\"\u003e\u003ccode\u003e@​Dutcho\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/pull/100\"\u003eannotated-types/annotated-types#100\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/annotated-types/annotated-types/compare/v0.7.0...v0.8.0\"\u003ehttps://github.com/annotated-types/annotated-types/compare/v0.7.0...v0.8.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/annotated-types/annotated-types/commit/9eb96680138269811a39d838d720abc3dce33954\"\u003e\u003ccode\u003e9eb9668\u003c/code\u003e\u003c/a\u003e Prepare for 0.8.0 release (\u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/issues/103\"\u003e#103\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/annotated-types/annotated-types/commit/10b77644f88b385357653730a1ab23748ca3ae2e\"\u003e\u003ccode\u003e10b7764\u003c/code\u003e\u003c/a\u003e Fix typo in \u003ccode\u003eLen\u003c/code\u003e docstring (\u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/issues/100\"\u003e#100\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/annotated-types/annotated-types/commit/955f7576d616feb6e9407c74498517787c38afd4\"\u003e\u003ccode\u003e955f757\u003c/code\u003e\u003c/a\u003e Add support for Python 3.14 and drop EOL 3.8-3.9 (\u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/issues/97\"\u003e#97\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/annotated-types/annotated-types/commit/bd280fea7983550d266f993d868b8dd7ff822bf1\"\u003e\u003ccode\u003ebd280fe\u003c/code\u003e\u003c/a\u003e Added Python 3.14 to the test matrix (\u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/issues/96\"\u003e#96\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/annotated-types/annotated-types/commit/a471bb757663452459893e6f593118ec21eb1b9e\"\u003e\u003ccode\u003ea471bb7\u003c/code\u003e\u003c/a\u003e Add SPDX license expression (\u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/issues/92\"\u003e#92\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/annotated-types/annotated-types/commit/eab91d9a8c0d3f73661fc4b0794a1fe76c94fa84\"\u003e\u003ccode\u003eeab91d9\u003c/code\u003e\u003c/a\u003e Fix string predicate names in doc (\u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/issues/90\"\u003e#90\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/annotated-types/annotated-types/commit/03ad9c3c7b4d4dfe9e33c09075a3a2766c0820e1\"\u003e\u003ccode\u003e03ad9c3\u003c/code\u003e\u003c/a\u003e add CI for PyPy3.11 and fix test (issue 71) (\u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/issues/88\"\u003e#88\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/annotated-types/annotated-types/commit/5ae60437f0ab493cedd27311bc6ce6d2188e8d8b\"\u003e\u003ccode\u003e5ae6043\u003c/code\u003e\u003c/a\u003e fix: typo in README.md (\u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/issues/87\"\u003e#87\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/annotated-types/annotated-types/commit/b60ad7bff90019c7de3547df1c8e3586eb328423\"\u003e\u003ccode\u003eb60ad7b\u003c/code\u003e\u003c/a\u003e Update license-files to be PEP-639 compliant (\u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/issues/85\"\u003e#85\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/issues/86\"\u003e#86\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/annotated-types/annotated-types/commit/3fbeb6d129760ae48d7a0372fb9301764acc95ae\"\u003e\u003ccode\u003e3fbeb6d\u003c/code\u003e\u003c/a\u003e Fix docstring of \u003ccode\u003eTimezone\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/issues/84\"\u003e#84\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/annotated-types/annotated-types/compare/v0.7.0...v0.8.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `anyio` from 4.14.2 to 4.15.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/agronholm/anyio/releases\"\u003eanyio's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e4.15.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImplemented a compatibility fix for supporting direct access of \u003ccode\u003eanyio.*\u003c/code\u003e submodules from the main package even when those submodules were not directly imported first (\u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1311\"\u003e#1311\u003c/a\u003e \u0026lt;\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1311%5C%3E\"\u003eagronholm/anyio#1311\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.15.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eAdded support for the newer keyword-only arguments on \u003ccode\u003eanyio.Path\u003c/code\u003e methods to match the standard library \u003ccode\u003epathlib.Path\u003c/code\u003e:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003efollow_symlinks\u003c/code\u003e on \u003ccode\u003eexists()\u003c/code\u003e (Python 3.12+)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003efollow_symlinks\u003c/code\u003e on \u003ccode\u003eis_dir()\u003c/code\u003e (Python 3.13+)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003efollow_symlinks\u003c/code\u003e on \u003ccode\u003eis_file()\u003c/code\u003e (Python 3.13+)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003efollow_symlinks\u003c/code\u003e on \u003ccode\u003eowner()\u003c/code\u003e (Python 3.13+)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003efollow_symlinks\u003c/code\u003e on \u003ccode\u003egroup()\u003c/code\u003e (Python 3.13+)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003enewline\u003c/code\u003e on \u003ccode\u003eread_text()\u003c/code\u003e (Python 3.13+)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e(\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1286\"\u003e#1286\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1293\"\u003e#1293\u003c/a\u003e; PR by \u003ca href=\"https://github.com/jaideeppyne\"\u003e\u003ccode\u003e@​jaideeppyne\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAdded \u003ccode\u003eamap\u003c/code\u003e, \u003ccode\u003egather\u003c/code\u003e, and \u003ccode\u003eas_completed\u003c/code\u003e utility functions to simplify common patterns (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1173\"\u003e#1173\u003c/a\u003e; PR by \u003ca href=\"https://github.com/Graeme22\"\u003e\u003ccode\u003e@​Graeme22\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAdded \u003ccode\u003e--anyio-mode\u003c/code\u003e command-line option as an alternative to the \u003ccode\u003eanyio_mode\u003c/code\u003e ini setting, and fix the pytest plugin's auto mode detection to recognize the mode when set via either mechanism(e.g: \u003ccode\u003epytest_asyncio\u003c/code\u003e). (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1242\"\u003e#1242\u003c/a\u003e; PR by \u003ca href=\"https://github.com/EmmanuelNiyonshuti\"\u003e\u003ccode\u003e@​EmmanuelNiyonshuti\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAdded the \u003ccode\u003eanyio.Future\u003c/code\u003e synchronization primitive which behaves similar to \u003ccode\u003easyncio.Future\u003c/code\u003e, allowing tasks to wait for a value (or exception) from another task (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1146\"\u003e#1146\u003c/a\u003e; PR by \u003ca href=\"https://github.com/Vizonex\"\u003e\u003ccode\u003e@​Vizonex\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAdded guidance for managing multiple memory object stream producers and consumers with cloned streams (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/330\"\u003e#330\u003c/a\u003e; PR by \u003ca href=\"https://github.com/nightcityblade\"\u003e\u003ccode\u003e@​nightcityblade\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAdded \u003ccode\u003eStapledObjectStream.send_nowait()\u003c/code\u003e that delegates to the underlying \u003ccode\u003eObjectSendStream\u003c/code\u003e, if it implements it (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1241\"\u003e#1241\u003c/a\u003e; PR by \u003ca href=\"https://github.com/davidbrochart\"\u003e\u003ccode\u003e@​davidbrochart\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAdded the \u003ccode\u003emove_on_at()\u003c/code\u003e and \u003ccode\u003efail_at()\u003c/code\u003e functions to complement \u003ccode\u003emove_on_after()\u003c/code\u003e and \u003ccode\u003efail_after()\u003c/code\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eChanged the default name for a task spawned with \u003ccode\u003eTaskGroup.create_task(func())\u003c/code\u003e to match the default task name for the analogous task spawned with \u003ccode\u003eTaskGroup.start_soon(func)\u003c/code\u003e or \u003ccode\u003eTaskGroup.start(func)\u003c/code\u003e in more situations. Previously, the default name of a \u003ccode\u003eTaskGroup.create_task\u003c/code\u003e task never included the module name. (The default name for a task spawned with \u003ccode\u003eTaskGroup.start_soon\u003c/code\u003e or \u003ccode\u003eTaskGroup.start\u003c/code\u003e typically includes the module name.) (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1234\"\u003e#1234\u003c/a\u003e; PR by \u003ca href=\"https://github.com/gschaffner\"\u003e\u003ccode\u003e@​gschaffner\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eChanged the \u003ccode\u003eanyio\u003c/code\u003e and \u003ccode\u003eanyio.abc\u003c/code\u003e modules to lazily (much like \u003ccode\u003e810\u003c/code\u003e) import the necessary submodules. This is done by parsing the AST of the module and building a lookup table from the \u003ccode\u003eif TYPE_CHECKING:\u003c/code\u003e block. A fallback mode has been provided for installations where the source code is unavailable (e.g. PyInstaller). (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1169\"\u003e#1169\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed free-threading compatibility issues arising from the fact that on Python 3.14 free-threading builds, newly created threads inherit the current context by default, causing AnyIO to behave erroneously in relation to \u003ccode\u003estart_blocking_portal()\u003c/code\u003e and \u003ccode\u003eanyio.to_thread.run_sync()\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1224\"\u003e#1224\u003c/a\u003e; PR by \u003ca href=\"https://github.com/EmmanuelNiyonshuti\"\u003e\u003ccode\u003e@​EmmanuelNiyonshuti\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed \u003ccode\u003eSpooledTemporaryFile.readinto()\u003c/code\u003e and \u003ccode\u003ereadinto1()\u003c/code\u003e reading twice before rollover, so the destination buffer was overwritten by the second read and the file position advanced twice, silently losing data (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1215\"\u003e#1215\u003c/a\u003e; PR by \u003ca href=\"https://github.com/c-tonneslan\"\u003e\u003ccode\u003e@​c-tonneslan\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAdded a \u003ccode\u003ereason\u003c/code\u003e parameter to \u003ccode\u003efail_after\u003c/code\u003e (and the new \u003ccode\u003efail_at\u003c/code\u003e) allowing for added exception context when raising \u003ccode\u003eTimeoutError\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1227\"\u003e#1227\u003c/a\u003e; PR by \u003ca href=\"https://github.com/Graeme22\"\u003e\u003ccode\u003e@​Graeme22\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed the default \u003ccode\u003eTaskHandle.name\u003c/code\u003e missing part of the task name for tasks started with \u003ccode\u003eTaskGroup.start\u003c/code\u003e on Trio (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1231\"\u003e#1231\u003c/a\u003e; PR by \u003ca href=\"https://github.com/gschaffner\"\u003e\u003ccode\u003e@​gschaffner\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed \u003ccode\u003eanyio.run\u003c/code\u003e leaking, or at least, delaying collection of loop and root_task due to the root task being cached in a \u003ccode\u003eRunVar\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1203\"\u003e#1203\u003c/a\u003e; PR by \u003ca href=\"https://github.com/tapetersen\"\u003e\u003ccode\u003e@​tapetersen\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed \u003ccode\u003eanyio.Path.with_stem()\u003c/code\u003e silently producing a wrong path (e.g. \u003ccode\u003ePath(\u0026quot;.txt\u0026quot;)\u003c/code\u003e) instead of raising \u003ccode\u003eValueError\u003c/code\u003e when given an empty stem on a path with a non-empty suffix, unlike \u003ccode\u003epathlib.PurePath.with_stem\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1200\"\u003e#1200\u003c/a\u003e; PR by \u003ca href=\"https://github.com/Sanjays2402\"\u003e\u003ccode\u003e@​Sanjays2402\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed \u003ccode\u003eUNIXSocketStream.aclose()\u003c/code\u003e raising \u003ccode\u003easyncio.InvalidStateError\u003c/code\u003e when a concurrent receive or send operation had just been cancelled on the asyncio backend (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1267\"\u003e#1267\u003c/a\u003e; PR by \u003ca href=\"https://github.com/alloutflo\"\u003e\u003ccode\u003e@​alloutflo\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed the pytest plugin importing the deprecated \u003ccode\u003e_pytest.python.CallSpec2\u003c/code\u003e alias, which triggers \u003ccode\u003ePytestRemovedIn10Warning\u003c/code\u003e on \u003ccode\u003epytest\u0026gt;=9.2\u003c/code\u003e and crashes pytest at startup when \u003ccode\u003efilterwarnings = error\u003c/code\u003e is configured (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1271\"\u003e#1271\u003c/a\u003e; PR by \u003ca href=\"https://github.com/matthewfeickert\"\u003e\u003ccode\u003e@​matthewfeickert\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed an asyncio worker thread race that could raise \u003ccode\u003eRuntimeError\u003c/code\u003e when the event loop closed between checking its state and scheduling the worker result (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1265\"\u003e#1265\u003c/a\u003e; PR by \u003ca href=\"https://github.com/hansu650\"\u003e\u003ccode\u003e@​hansu650\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed \u003ccode\u003eCapacityLimiter\u003c/code\u003e on the asyncio backend over-granting tokens when \u003ccode\u003etotal_tokens\u003c/code\u003e was raised while the limiter was over-subscribed (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1223\"\u003e#1223\u003c/a\u003e; PR by \u003ca href=\"https://github.com/zelinewang\"\u003e\u003ccode\u003e@​zelinewang\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/ffcd1542cd6d127980205f90a0100078849dd703\"\u003e\u003ccode\u003effcd154\u003c/code\u003e\u003c/a\u003e Bumped up the version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/0ecf5ed98d294242509b043ebd1a0843e52d892f\"\u003e\u003ccode\u003e0ecf5ed\u003c/code\u003e\u003c/a\u003e Added a workaround for third party code accessing unimported submodules (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1309\"\u003e#1309\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/928366259543412a2deb1e2ba09ea45ffa92ef4f\"\u003e\u003ccode\u003e9283662\u003c/code\u003e\u003c/a\u003e Bumped up the version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/d137692a90f76e4f71605e32ea5ca94cab3a539d\"\u003e\u003ccode\u003ed137692\u003c/code\u003e\u003c/a\u003e Improved the instructions for AI agents\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/033fc52b8fa8e90c5d0ef24b10b3860e974a6265\"\u003e\u003ccode\u003e033fc52\u003c/code\u003e\u003c/a\u003e Shield TemporaryDirectory cleanup from cancellation (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1304\"\u003e#1304\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/942e9a6552cc10b5aaa779d84bfc8e2c3d5fcffc\"\u003e\u003ccode\u003e942e9a6\u003c/code\u003e\u003c/a\u003e [pre-commit.ci] pre-commit autoupdate (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1305\"\u003e#1305\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/b825c3be7cb4ca1a8000b8065d4e147843deb704\"\u003e\u003ccode\u003eb825c3b\u003c/code\u003e\u003c/a\u003e Fixed pyproject.toml changes not triggering the test suite\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/9727dc504681e2986b5bc285de9571fb467539af\"\u003e\u003ccode\u003e9727dc5\u003c/code\u003e\u003c/a\u003e Fixed start inconsistencies between trio and asyncio (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1198\"\u003e#1198\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/b05fe6d160a640355c201363cab286a7d2581da8\"\u003e\u003ccode\u003eb05fe6d\u003c/code\u003e\u003c/a\u003e Fixed wrong type in move_on_after (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1297\"\u003e#1297\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/44d0c93cc20079acbf38ba4dbed5ab9df323f153\"\u003e\u003ccode\u003e44d0c93\u003c/code\u003e\u003c/a\u003e Fixed asyncio task group coroutine cleanup (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1275\"\u003e#1275\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/agronholm/anyio/compare/4.14.2...4.15.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `build` from 1.5.0 to 1.6.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pypa/build/releases\"\u003ebuild's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e1.6.1\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003echore[v1]: prepare for v1.6.1 by \u003ca href=\"https://github.com/henryiii\"\u003e\u003ccode\u003e@​henryiii\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1181\"\u003epypa/build#1181\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/pypa/build/compare/1.6.0...1.6.1\"\u003ehttps://github.com/pypa/build/compare/1.6.0...1.6.1\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003e1.6.0\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eReplace prettier with mdformat and yamlfmt by \u003ca href=\"https://github.com/gaborbernat\"\u003e\u003ccode\u003e@​gaborbernat\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1133\"\u003epypa/build#1133\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eLet yamlfmt format the workflows by \u003ca href=\"https://github.com/gaborbernat\"\u003e\u003ccode\u003e@​gaborbernat\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1134\"\u003epypa/build#1134\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e🐛 fix(release): semver auto bump, changelog reflow, and roll back 1.5.1 by \u003ca href=\"https://github.com/gaborbernat\"\u003e\u003ccode\u003e@​gaborbernat\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1132\"\u003epypa/build#1132\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: hash verification in --dependency-constraints-txt could be silently skipped by \u003ca href=\"https://github.com/manfred-kaiser\"\u003e\u003ccode\u003e@​manfred-kaiser\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1140\"\u003epypa/build#1140\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e🐛 fix(ci): bump build-and-inspect-python-package to v3.0.1 by \u003ca href=\"https://github.com/gaborbernat\"\u003e\u003ccode\u003e@​gaborbernat\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1147\"\u003epypa/build#1147\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e🐛 fix(ci): pin coverage core to ctrace so test contexts record by \u003ca href=\"https://github.com/gaborbernat\"\u003e\u003ccode\u003e@​gaborbernat\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1148\"\u003epypa/build#1148\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: run mypy on more parts of the code by \u003ca href=\"https://github.com/henryiii\"\u003e\u003ccode\u003e@​henryiii\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1151\"\u003epypa/build#1151\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: turn up strictness on mypy by \u003ca href=\"https://github.com/henryiii\"\u003e\u003ccode\u003e@​henryiii\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1153\"\u003epypa/build#1153\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: faster mypy, fix merge error by \u003ca href=\"https://github.com/henryiii\"\u003e\u003ccode\u003e@​henryiii\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1156\"\u003epypa/build#1156\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e🐛 fix(ci): rerun integration tests on transient network errors by \u003ca href=\"https://github.com/gaborbernat\"\u003e\u003ccode\u003e@​gaborbernat\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1150\"\u003epypa/build#1150\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: clean up unused casts in tests by \u003ca href=\"https://github.com/henryiii\"\u003e\u003ccode\u003e@​henryiii\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1154\"\u003epypa/build#1154\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003erefactor(typing): apply review feedback from \u003ca href=\"https://redirect.github.com/pypa/build/issues/1093\"\u003e#1093\u003c/a\u003e by \u003ca href=\"https://github.com/henryiii\"\u003e\u003ccode\u003e@​henryiii\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1155\"\u003epypa/build#1155\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: Generator is more accurate than Iterator by \u003ca href=\"https://github.com/henryiii\"\u003e\u003ccode\u003e@​henryiii\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1152\"\u003epypa/build#1152\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etests: mark test_main_sdist_input_end_to_end with pytest.mark.network by \u003ca href=\"https://github.com/frenzymadness\"\u003e\u003ccode\u003e@​frenzymadness\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1144\"\u003epypa/build#1144\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRevert \u0026quot;⚠️ feat(util): deprecate project_wheel_metadata\u0026quot; by \u003ca href=\"https://github.com/henryiii\"\u003e\u003ccode\u003e@​henryiii\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1158\"\u003epypa/build#1158\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etests: download integration sources once per run by \u003ca href=\"https://github.com/henryiii\"\u003e\u003ccode\u003e@​henryiii\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1157\"\u003epypa/build#1157\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUse stdlib \u003ccode\u003eimportlib.metadata\u003c/code\u003e for typing by \u003ca href=\"https://github.com/layday\"\u003e\u003ccode\u003e@​layday\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1162\"\u003epypa/build#1162\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eDrop redundant \u003ccode\u003eexc_info\u003c/code\u003e parameter from backend exception wrapper by \u003ca href=\"https://github.com/layday\"\u003e\u003ccode\u003e@​layday\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1161\"\u003epypa/build#1161\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eDrop a few PyPy-specific test skips by \u003ca href=\"https://github.com/layday\"\u003e\u003ccode\u003e@​layday\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1164\"\u003epypa/build#1164\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e🔧 chore: batch dependency updates weekly on Tuesday by \u003ca href=\"https://github.com/gaborbernat\"\u003e\u003ccode\u003e@​gaborbernat\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1165\"\u003epypa/build#1165\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e👷 ci: use app token for releases by \u003ca href=\"https://github.com/gaborbernat\"\u003e\u003ccode\u003e@​gaborbernat\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1169\"\u003epypa/build#1169\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/manfred-kaiser\"\u003e\u003ccode\u003e@​manfred-kaiser\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1140\"\u003epypa/build#1140\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/frenzymadness\"\u003e\u003ccode\u003e@​frenzymadness\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1144\"\u003epypa/build#1144\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/pypa/build/compare/1.5.1...1.6.0\"\u003ehttps://github.com/pypa/build/compare/1.5.1...1.6.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003e1.5.1\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e✨ feat(cli): accept sdist tarball as srcdir argument by \u003ca href=\"https://github.com/gaborbernat\"\u003e\u003ccode\u003e@​gaborbernat\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1057\"\u003epypa/build#1057\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: drop 3.9 branches for version_info checks by \u003ca href=\"https://github.com/henryiii\"\u003e\u003ccode\u003e@​henryiii\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1059\"\u003epypa/build#1059\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etests: skip test_uv_install_strips_pythonpath with missing uv by \u003ca href=\"https://github.com/mtelka\"\u003e\u003ccode\u003e@​mtelka\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1063\"\u003epypa/build#1063\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: remove myself from codeowners by \u003ca href=\"https://github.com/FFY00\"\u003e\u003ccode\u003e@​FFY00\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1066\"\u003epypa/build#1066\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003erefactor: safe_extractall to use pathlib.Path by \u003ca href=\"https://github.com/henryiii\"\u003e\u003ccode\u003e@​henryiii\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1060\"\u003epypa/build#1060\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pypa/build/blob/main/CHANGELOG.rst\"\u003ebuild's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e####################\n1.6.1 (2026-09-10)\n####################\u003c/p\u003e\n\u003chr /\u003e\n\u003cp\u003eBugfixes\u003c/p\u003e\n\u003chr /\u003e\n\u003cul\u003e\n\u003cli\u003eAvoid trying to detect symlinks on Windows, regression in 1.6.0 - by :user:\u003ccode\u003ehenryiii\u003c/code\u003e (:issue:\u003ccode\u003e1175\u003c/code\u003e) (:issue:\u003ccode\u003e1175\u003c/code\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr /\u003e\n\u003cp\u003eDocumentation\u003c/p\u003e\n\u003chr /\u003e\n\u003cul\u003e\n\u003cli\u003eFix doubled backslashes in the Windows pip config path (\u003ccode\u003e%APPDATA%\\pip\\pip.ini\u003c/code\u003e) in the docs - by :user:\u003ccode\u003earoh3006\u003c/code\u003e\n(:issue:\u003ccode\u003e1149\u003c/code\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr /\u003e\n\u003cp\u003eMiscellaneous\u003c/p\u003e\n\u003chr /\u003e\n\u003cul\u003e\n\u003cli\u003e:issue:\u003ccode\u003e1168\u003c/code\u003e, :issue:\u003ccode\u003e1170\u003c/code\u003e, :issue:\u003ccode\u003e1178\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e####################\n1.6.0 (2026-08-27)\n####################\u003c/p\u003e\n\u003chr /\u003e\n\u003cp\u003eFeatures\u003c/p\u003e\n\u003chr /\u003e\n\u003cul\u003e\n\u003cli\u003eAdd \u003ccode\u003e--report=PATH\u003c/code\u003e to write a machine-readable JSON report of built artifacts; \u003ccode\u003e--metadata\u003c/code\u003e now also accepts\n\u003ccode\u003e.whl\u003c/code\u003e files - by :user:\u003ccode\u003egaborbernat\u003c/code\u003e (:issue:\u003ccode\u003e198\u003c/code\u003e)\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003esrcdir\u003c/code\u003e argument now accepts \u003ccode\u003e.tar.gz\u003c/code\u003e source distributions, extracting and building from them - by\n:user:\u003ccode\u003egaborbernat\u003c/code\u003e (:issue:\u003ccode\u003e311\u003c/code\u003e)\u003c/li\u003e\n\u003cli\u003eThe \u0026quot;Unmet dependencies\u0026quot; error from \u003ccode\u003e--no-isolation\u003c/code\u003e builds now shows the wanted version, found version, and\ninterpreter - by :user:\u003ccode\u003egaborbernat\u003c/code\u003e (:issue:\u003ccode\u003e504\u003c/code\u003e)\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003e--sdist-extract-dir\u003c/code\u003e to extract the intermediate sdist into a persistent directory, enabling compiler cache\nreuse across rebuilds - by :user:\u003ccode\u003egaborbernat\u003c/code\u003e (:issue:\u003ccode\u003e614\u003c/code\u003e)\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003e--env-dir\u003c/code\u003e to place the isolated build environment at a fixed path, enabling compiler cache reuse across builds\n\u003cul\u003e\n\u003cli\u003eby :user:\u003ccode\u003egaborbernat\u003c/code\u003e (:issue:\u003ccode\u003e655\u003c/code\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003ePrint a summary of resolved dependency versions (\u003ccode\u003ename==version\u003c/code\u003e) after installing them in isolated builds - by\n:user:\u003ccode\u003egaborbernat\u003c/code\u003e (:issue:\u003ccode\u003e959\u003c/code\u003e)\u003c/li\u003e\n\u003cli\u003eOn build failure, print a tip pointing to \u003ccode\u003e--env-dir\u003c/code\u003e and \u003ccode\u003e--sdist-extract-dir\u003c/code\u003e for debugging and link to the\n\u0026quot;Debug a failed build\u0026quot; how-to - reported by :user:\u003ccode\u003edimpase\u003c/code\u003e, implemented by :user:\u003ccode\u003egaborbernat\u003c/code\u003e (:issue:\u003ccode\u003e966\u003c/code\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr /\u003e\n\u003cp\u003eBugfixes\u003c/p\u003e\n\u003chr /\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/build/commit/89cccef40df9011f03bec18cf52c53d1096ed6ee\"\u003e\u003ccode\u003e89cccef\u003c/code\u003e\u003c/a\u003e chore: prepare for 1.6.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/build/commit/a6f707a75fc8548d7707645e97c7903197387849\"\u003e\u003ccode\u003ea6f707a\u003c/code\u003e\u003c/a\u003e ci: support releases from v* branches (\u003ca href=\"https://redirect.github.com/pypa/build/issues/1178\"\u003e#1178\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/build/commit/77851610de5d3894fa8a88e06e0232901cf93758\"\u003e\u003ccode\u003e7785161\u003c/code\u003e\u003c/a\u003e docs: fix doubled backslashes in Windows pip config path (\u003ca href=\"https://redirect.github.com/pypa/build/issues/1149\"\u003e#1149\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/build/commit/244b250c3219070eebb29764f7709262d48afd41\"\u003e\u003ccode\u003e244b250\u003c/code\u003e\u003c/a\u003e fix: always use copies for the isolated venv on Windows (\u003ca href=\"https://redirect.github.com/pypa/build/issues/1176\"\u003e#1176\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/build/commit/c93ca6f6d252e4d8df7fda4a61f8f9ed8a55a411\"\u003e\u003ccode\u003ec93ca6f\u003c/code\u003e\u003c/a\u003e build(deps): bump re-actors/alls-green from 1.2.2 to 1.3.0 in the github-acti...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/build/commit/e02ffd32241aec2e306d90869417c1e900c0adb4\"\u003e\u003ccode\u003ee02ffd3\u003c/code\u003e\u003c/a\u003e pre-commit: bump repositories (\u003ca href=\"https://redirect.github.com/pypa/build/issues/1173\"\u003e#1173\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/build/commit/aad39a800e3d81bf907018ebe2fab135717da59b\"\u003e\u003ccode\u003eaad39a8\u003c/code\u003e\u003c/a\u003e docs: fix changelog page heading levels and sidebar (\u003ca href=\"https://redirect.github.com/pypa/build/issues/1171\"\u003e#1171\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/build/commit/5c3fd46b5c38c7caea5dd95ce365971104a734aa\"\u003e\u003ccode\u003e5c3fd46\u003c/code\u003e\u003c/a\u003e docs: use PyPI ref directly (\u003ca href=\"https://redirect.github.com/pypa/build/issues/1172\"\u003e#1172\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/build/commit/1c5bd6c21cbd33c1816978d45219d48fb4c2b269\"\u003e\u003ccode\u003e1c5bd6c\u003c/code\u003e\u003c/a\u003e 🐛 fix(release): format generated changelog (\u003ca href=\"https://redirect.github.com/pypa/build/issues/1170\"\u003e#1170\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/build/commit/7f0cc7ed19969558c7daeaa3652ce2ffc81599c1\"\u003e\u003ccode\u003e7f0cc7e\u003c/code\u003e\u003c/a\u003e 🔧 build(type): replace mypy with pyrefly (\u003ca href=\"https://redirect.github.com/pypa/build/issues/1168\"\u003e#1168\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/pypa/build/compare/1.5.0...1.6.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `certifi` from 2026.6.17 to 2026.7.22\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/certifi/python-certifi/commit/f4bc676bc101fe2235846e37044e8c693d6cbaf4\"\u003e\u003ccode\u003ef4bc676\u003c/code\u003e\u003c/a\u003e 2026.07.22 (\u003ca href=\"https://redirect.github.com/certifi/python-certifi/issues/428\"\u003e#428\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/certifi/python-certifi/commit/4c91f9c5f9b4676d40d2930025ba04d80dd536f6\"\u003e\u003ccode\u003e4c91f9c\u003c/code\u003e\u003c/a\u003e Bump actions/setup-python from 6.3.0 to 7.0.0 (\u003ca href=\"https://redirect.github.com/certifi/python-certifi/issues/427\"\u003e#427\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/certifi/python-certifi/commit/01a66c5cf32eadb8f03a0504c24cb44f6d581248\"\u003e\u003ccode\u003e01a66c5\u003c/code\u003e\u003c/a\u003e Bump actions/checkout from 7.0.0 to 7.0.1 (\u003ca href=\"https://redirect.github.com/certifi/python-certifi/issues/426\"\u003e#426\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/certifi/python-certifi/commit/eb355f41cb71f71012ecf1a4d27a57d0ee2b1337\"\u003e\u003ccode\u003eeb355f4\u003c/code\u003e\u003c/a\u003e Bump pypa/gh-action-pypi-publish from 1.14.0 to 1.14.1 (\u003ca href=\"https://redirect.github.com/certifi/python-certifi/issues/425\"\u003e#425\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/certifi/python-certifi/commit/474e6fc996d55b91632248da0bade702504e62dc\"\u003e\u003ccode\u003e474e6fc\u003c/code\u003e\u003c/a\u003e Include tests in the source distribution (\u003ca href=\"https://redirect.github.com/certifi/python-certifi/issues/424\"\u003e#424\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/certifi/python-certifi/commit/a31ef39bb5906af7dc9729890f7e4e04e75afdae\"\u003e\u003ccode\u003ea31ef39\u003c/code\u003e\u003c/a\u003e Bump actions/setup-python from 6.2.0 to 6.3.0 (\u003ca href=\"https://redirect.github.com/certifi/python-certifi/issues/420\"\u003e#420\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/certifi/python-certifi/commit/98eb2c76a9c7a8519912023dca00f762bbcd59af\"\u003e\u003ccode\u003e98eb2c7\u003c/code\u003e\u003c/a\u003e Bump actions/checkout from 6.0.3 to 7.0.0 (\u003ca href=\"https://redirect.github.com/certifi/python-certifi/issues/419\"\u003e#419\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/certifi/python-certifi/compare/2026.06.17...2026.07.22\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `cffi` from 2.1.0 to 2.1.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/python-cffi/cffi/releases\"\u003ecffi's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.1.1\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMinimize internal Python API usage for interpreter and thread state sampling where possible. Avoids breaking ABI change in Python \u0026gt;= 3.15.0b4 (\u003ca href=\"https://redirect.github.com/python-cffi/cffi/pull/269\"\u003epython-cffi/cffi#269\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/python-cffi/cffi/compare/v2.1.0...v2.1.1\"\u003ehttps://github.com/python-cffi/cffi/compare/v2.1.0...v2.1.1\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-cffi/cffi/commit/fd33e7700f0ebafe6f30bd5053f13327221b77a2\"\u003e\u003ccode\u003efd33e77\u003c/code\u003e\u003c/a\u003e New release 2.1.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-cffi/cffi/commit/56a7876b8cd3b2d8148233a90e0121d74cd83852\"\u003e\u003ccode\u003e56a7876\u003c/code\u003e\u003c/a\u003e Use PyGILState_Ensure to avoid accessing CPython internals (\u003ca href=\"https://redirect.github.com/python-cffi/cffi/issues/269\"\u003e#269\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/python-cffi/cffi/issues/270\"\u003e#270\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/python-cffi/cffi/compare/v2.1.0...v2.1.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `charset-normalizer` from 3.4.9 to 3.5.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/jawah/charset_normalizer/releases\"\u003echarset-normalizer's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eVersion 3.5.1\u003c/h2\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/Ousret/charset_normalizer/compare/3.5.0...3.5.1\"\u003e3.5.1\u003c/a\u003e (2026-08-15)\u003c/h2\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eRaised upper bound of setuptools to v84 (\u003ca href=\"https://redirect.github.com/jawah/charset_normalizer/issues/794\"\u003e#794\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eCache performance access optimization for our CharInfo struct (prebuilt only).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eNo longer decoding large content when the noise detector output give a high entropy.\nOnly impacted large content input \u0026gt;1M bytes.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eVersion 3.5.0\u003c/h2\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/Ousret/charset_normalizer/compare/3.4.9...3.5.0\"\u003e3.5.0\u003c/a\u003e (2026-08-12)\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eExplicit support for Python 3.15\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eComparing a CharsetMatch to a non-alias encoding strings (\u003ca href=\"https://redirect.github.com/jawah/charset_normalizer/issues/773\"\u003e#773\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eReturn 0.0 CharsetMatch.multi_byte_usage for empty payloads instead of crashing (\u003ca href=\"https://redirect.github.com/jawah/charset_normalizer/issues/774\"\u003e#774\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eA file with both a charset declaration and BOM/SIG did not verify first the BOM/SIG charset.\u003c/li\u003e\n\u003cli\u003eiso2022* cases misdetected due to a flaw in our multibyte chunking logic.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eReplaced the optional mypyc build with Cython extensions while retaining the\npure Python fallback. The previous engine (mypyc) started to hit rough limit around\nthe optimization of our noise/coherence detector while Cython allows us to\nsteer the engine toward the right generated optimized sources.\nThis change SHOULD not impact bundler (e.g. Pyinstaller) as the module are\nimmediately discoverable (i.e. not hidden import like mypyc did).\nMoreover, a long wished distribution is the abi3 wheels, this will allow us\nto no longer rush each year when a new Python interpreter is released.\nWe still distribute the interpreter specific wheels for faster performance.\u003c/li\u003e\n\u003cli\u003eApplied micro-optimization on several utils.\u003c/li\u003e\n\u003cli\u003eCharsetMatches no longer sort on each match insertion.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMisc\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eRemoved an old performance optimization attempt in apy.py (success_fast_tracked+payload_result_cache).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/jawah/charset_normalizer/blob/master/CHANGELOG.md\"\u003echarset-normalizer's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/Ousret/charset_normalizer/compare/3.5.0...3.5.1\"\u003e3.5.1\u003c/a\u003e (2026-08-15)\u003c/h2\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eRaised upper bound of setuptools to v84 (\u003ca href=\"https://redirect.github.com/jawah/charset_normalizer/issues/794\"\u003e#794\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eCache performance access optimization for our CharInfo struct (prebuilt only).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eNo longer decoding large content when the noise detector output give a high entropy.\nOnly impacted large content input \u0026gt;1M bytes.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/Ousret/charset_normalizer/compare/3.4.9...3.5.0\"\u003e3.5.0\u003c/a\u003e (2026-08-12)\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eExplicit support for Python 3.15\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eComparing a CharsetMatch to a non-alias encoding strings (\u003ca href=\"https://redirect.github.com/jawah/charset_normalizer/issues/773\"\u003e#773\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eReturn 0.0 CharsetMatch.multi_byte_usage for empty payloads instead of crashing (\u003ca href=\"https://redirect.github.com/jawah/charset_normalizer/issues/774\"\u003e#774\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eA file with both a charset declaration and BOM/SIG did not verify first the BOM/SIG charset.\u003c/li\u003e\n\u003cli\u003eiso2022* cases misdetected due to a flaw in our multibyte chunking logic.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eReplaced the optional mypyc build with Cython extensions while retaining the\npure Python fallback. The previous engine (mypyc) started to hit rough limit around\nthe optimization of our noise/coherence detector while Cython allows us to\nsteer the engine toward the right generated optimized sources.\nThis change SHOULD not impact bundler (e.g. Pyinstaller) as the module are\nimmediately discoverable (i.e. not hidden import like mypyc did).\nMoreover, a long wished distribution is the abi3 wheels, this will allow us\nto no longer rush each year when a new Python interpreter is released.\nWe still distribute the interpreter specific wheels for faster performance.\u003c/li\u003e\n\u003cli\u003eApplied micro-optimization on several utils.\u003c/li\u003e\n\u003cli\u003eCharsetMatches no longer sort on each match insertion.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMisc\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eRemoved an old performance optimization attempt in apy.py (success_fast_tracked+payload_result_cache).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jawah/charset_normalizer/commit/e239bdc5cc1eb1f0db08d4046ad531f805dbea71\"\u003e\u003ccode\u003ee239bdc\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/jawah/charset_normalizer/issues/795\"\u003e#795\u003c/a\u003e from jawah/release-3.5.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jawah/charset_normalizer/commit/648ad776db64a00aa7efd70a94656ac43784abb3\"\u003e\u003ccode\u003e648ad77\u003c/code\u003e\u003c/a\u003e docs: update faq\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jawah/charset_normalizer/commit/fab27492c39baa61aca12826022e266781108570\"\u003e\u003ccode\u003efab2749\u003c/code\u003e\u003c/a\u003e docs: write changelog for 3.5.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jawah/charset_normalizer/commit/7d32774e75d16cccd3d22c758a77fca135952787\"\u003e\u003ccode\u003e7d32774\u003c/code\u003e\u003c/a\u003e chore: bump version to 3.5.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jawah/charset_normalizer/commit/9a69f609f254ba4bfe9d0cbf375728e43360cdf2\"\u003e\u003ccode\u003e9a69f60\u003c/code\u003e\u003c/a\u003e docs: update data/info\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jawah/charset_normalizer/commit/5dcc6dd81a8a0a4bd525f8d6f508da8285caf402\"\u003e\u003ccode\u003e5dcc6dd\u003c/code\u003e\u003c/a\u003e perf: charinfo cache access optimization in cython\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jawah/charset_normalizer/commit/ea3b4479270762be1228562c590e5a212727f208\"\u003e\u003ccode\u003eea3b447\u003c/code\u003e\u003c/a\u003e fix: do not validate-decode large payload when md says it's noise\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jawah/char...\n\n_Description has been truncated_","html_url":"https://github.com/RanugaVW/Clario-multiAgent-triage-micro-services/pull/89","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/RanugaVW%2FClario-multiAgent-triage-micro-services/issues/89","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/89/packages"},{"uuid":"5507547597","node_id":"PR_kwDOUTCdd88AAAABELl5rw","number":2,"state":"open","title":"chore(deps): bump the uv group across 2 directories with 15 updates","user":"dependabot[bot]","labels":["dependencies","python:uv"],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-19T03:51:06.000Z","updated_at":"2026-09-19T03:51:56.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps): bump","group_name":"uv","update_count":15,"packages":[{"name":"aiohttp","old_version":"3.13.3","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"cryptography","old_version":"46.0.5","new_version":"50.0.0","repository_url":"https://github.com/pyca/cryptography"},{"name":"h2","old_version":"4.4.0","new_version":"4.4.1","repository_url":"https://github.com/python-hyper/h2"},{"name":"httpcore2","old_version":"2.9.0","new_version":"2.10.0","repository_url":"https://github.com/pydantic/httpx2"},{"name":"httpx2","old_version":"2.9.0","new_version":"2.10.0","repository_url":"https://github.com/pydantic/httpx2"},{"name":"pyjwt","old_version":"2.10.1","new_version":"2.13.0","repository_url":"https://github.com/jpadilla/pyjwt"},{"name":"python-dotenv","old_version":"1.1.0","new_version":"1.2.2","repository_url":"https://github.com/theskumar/python-dotenv"},{"name":"requests","old_version":"2.32.5","new_version":"2.33.0","repository_url":"https://github.com/psf/requests"},{"name":"urllib3","old_version":"2.6.3","new_version":"2.7.0","repository_url":"https://github.com/urllib3/urllib3"}],"path":null,"ecosystem":"pip"},"body":"Bumps the uv group with 9 updates in the /examples/python directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [aiohttp](https://github.com/aio-libs/aiohttp) | `3.13.3` | `3.14.3` |\n| [cryptography](https://github.com/pyca/cryptography) | `46.0.5` | `50.0.0` |\n| [h2](https://github.com/python-hyper/h2) | `4.4.0` | `4.4.1` |\n| [httpcore2](https://github.com/pydantic/httpx2) | `2.9.0` | `2.10.0` |\n| [httpx2](https://github.com/pydantic/httpx2) | `2.9.0` | `2.10.0` |\n| [pyjwt](https://github.com/jpadilla/pyjwt) | `2.10.1` | `2.13.0` |\n| [python-dotenv](https://github.com/theskumar/python-dotenv) | `1.1.0` | `1.2.2` |\n| [requests](https://github.com/psf/requests) | `2.32.5` | `2.33.0` |\n| [urllib3](https://github.com/urllib3/urllib3) | `2.6.3` | `2.7.0` |\n\nBumps the uv group with 12 updates in the /python directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [web3](https://github.com/ApeWorX/web3.py) | `7.6.0` | `7.15.0` |\n| [aiohttp](https://github.com/aio-libs/aiohttp) | `3.13.3` | `3.14.3` |\n| [anyio](https://github.com/agronholm/anyio) | `4.9.0` | `4.14.2` |\n| [cryptography](https://github.com/pyca/cryptography) | `46.0.5` | `50.0.0` |\n| [idna](https://github.com/kjd/idna) | `3.10` | `3.15` |\n| [pygments](https://github.com/pygments/pygments) | `2.19.1` | `2.20.0` |\n| [pyjwt](https://github.com/jpadilla/pyjwt) | `2.10.1` | `2.13.0` |\n| [python-dotenv](https://github.com/theskumar/python-dotenv) | `1.1.0` | `1.2.2` |\n| [requests](https://github.com/psf/requests) | `2.32.5` | `2.33.0` |\n| [starlette](https://github.com/Kludex/starlette) | `0.52.1` | `1.3.1` |\n| [urllib3](https://github.com/urllib3/urllib3) | `2.6.3` | `2.7.0` |\n| [pytest](https://github.com/pytest-dev/pytest) | `8.3.5` | `9.0.3` |\n\n\nUpdates `aiohttp` from 3.13.3 to 3.14.3\nUpdates `cryptography` from 46.0.5 to 50.0.0\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst\"\u003ecryptography's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e50.0.0 - 2026-07-31\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003e\n* **SECURITY ISSUE**:\n  :func:`~cryptography.hazmat.primitives.serialization.pkcs7.pkcs7_decrypt_der`\n  and its PEM and S/MIME variants no longer expose distinguishable errors or\n  timing when unwrapping a ``RecipientInfo``'s ``encryptedKey``, which could\n  act as a Bleichenbacher oracle for callers that decrypt untrusted messages.\n  A random key is now substituted on failure, as described in :rfc:`3218`.\n  Credit to **@X1AOxiang** for reporting the issue. **CVE-2026-69247**\n* Deprecated Diffie-Hellman key exchange over finite fields (FFDH).\n  Everything FFDH is deprecated, including the types in\n  ``cryptography.hazmat.primitives.asymmetric.dh`` and loading FFDH keys or\n  parameters with the key loading APIs. Users should migrate to a more\n  modern key exchange algorithm.\n* Added ``xof()`` class methods to\n  :class:`~cryptography.hazmat.primitives.hashes.SHAKE128` and\n  :class:`~cryptography.hazmat.primitives.hashes.SHAKE256` for constructing\n  algorithm instances configured for use with\n  :class:`~cryptography.hazmat.primitives.hashes.XOFHash`.\n* The :mod:`X.509 verification \u0026lt;cryptography.x509.verification\u0026gt;` APIs are now\n  considered stable and are subject to our API stability policy.\n* Added the :doc:`/cobblestone` recipe, an implementation of the\n  Cobblestone-128 and Cobblestone-256 instantiations of the `C2SP\n  chunked-encryption specification\n  \u0026lt;https://c2sp.org/chunked-encryption\u0026gt;`_ for streaming authenticated\n  encryption of large messages.\n* Parsing a Signed Certificate Timestamp list now rejects encodings that\n  carry trailing bytes after the list or after an individual SCT, instead of\n  silently ignoring them.\n* Added support for using :class:`~cryptography.x509.Name` as a field type in\n  the :doc:`/hazmat/asn1/index` module.\n* Loading a public key or an EC private key now rejects DER where the\n  ``subjectPublicKey`` (or EC ``publicKey``) ``BIT STRING`` declares a non-zero\n  number of unused bits, instead of silently ignoring it.\n* Parsing a CRL entry's ``InvalidityDate`` extension now rejects a\n  ``GeneralizedTime`` that carries fractional seconds or another non-DER form,\n  matching the strict encoding already required for every other X.509 time\n  field.\n* :func:`~cryptography.x509.ocsp.load_der_ocsp_request` and\n  :func:`~cryptography.x509.ocsp.load_der_ocsp_response` now reject a request\n  or response whose ``version`` field is not ``v1``, the only version defined\n  by RFC 6960, matching the version validation already performed when loading\n  certificates, CSRs and CRLs.\n* :class:`~cryptography.hazmat.primitives.hashes.XOFHash` is now supported\n  when building against AWS-LC.\n* HMAC (and therefore PBKDF2-HMAC) with SHA-3 hashes is now supported when\n  building against AWS-LC.\n* Diffie-Hellman (:doc:`/hazmat/primitives/asymmetric/dh`) is now supported\n  when building against AWS-LC.\n\u0026lt;/tr\u0026gt;\u0026lt;/table\u0026gt; \n\u003c/code\u003e\u003c/pre\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/dcb7050b807b00392fa9fe2eac7cb362fcf355cc\"\u003e\u003ccode\u003edcb7050\u003c/code\u003e\u003c/a\u003e Prepare for 50.0.0 release (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15372\"\u003e#15372\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/53fccd93413a8d7f07d6d8999681f27b75cffa3f\"\u003e\u003ccode\u003e53fccd9\u003c/code\u003e\u003c/a\u003e Don't leak how PKCS#7 encryptedKey decryption failed (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15369\"\u003e#15369\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/d472f978470fbefa521b86d98b2ecccbbb4d1dd8\"\u003e\u003ccode\u003ed472f97\u003c/code\u003e\u003c/a\u003e Add \u003ccode\u003efrom __future__ import annotations\u003c/code\u003e to all src/ Python files (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15371\"\u003e#15371\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/908773d53829fb1466c6db364b31321c3cd8eb9a\"\u003e\u003ccode\u003e908773d\u003c/code\u003e\u003c/a\u003e Bump downstream dependencies in CI (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15368\"\u003e#15368\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/2cc07cc948948211899bcb0cddd1fddf86e95812\"\u003e\u003ccode\u003e2cc07cc\u003c/code\u003e\u003c/a\u003e Bump BoringSSL, OpenSSL, AWS-LC in CI (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15367\"\u003e#15367\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/c94ede9f040fa44942f7139772603419000acf66\"\u003e\u003ccode\u003ec94ede9\u003c/code\u003e\u003c/a\u003e chore(deps): bump ruff from 0.16.0 to 0.16.1 (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15366\"\u003e#15366\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/67a8308dc9ea4cce6056e0f1438f903c208c3f35\"\u003e\u003ccode\u003e67a8308\u003c/code\u003e\u003c/a\u003e chore(deps): bump virtualenv from 21.7.0 to 21.7.1 (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15365\"\u003e#15365\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/95018ffcdbbc510fd92fc872e3a3e80aa6e58596\"\u003e\u003ccode\u003e95018ff\u003c/code\u003e\u003c/a\u003e Release the GIL in one-shot AEAD encrypt/decrypt (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15361\"\u003e#15361\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/6954733eaf55a0074abf88f06f7242dfca3a5d02\"\u003e\u003ccode\u003e6954733\u003c/code\u003e\u003c/a\u003e Release the GIL during DH and DSA parameter generation (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15364\"\u003e#15364\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/6893b94c33e948f6240082461424cfb5da2dacc6\"\u003e\u003ccode\u003e6893b94\u003c/code\u003e\u003c/a\u003e Import _serialization instead of serialization in x509/extensions (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15363\"\u003e#15363\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/pyca/cryptography/compare/46.0.5...50.0.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `h2` from 4.4.0 to 4.4.1\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/python-hyper/h2/blob/master/CHANGELOG.rst\"\u003eh2's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e4.4.1 (2026-08-03)\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eBugfixes\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003ePerformance improvement: remove consumed frames in-place from data buffer.\u003c/li\u003e\n\u003cli\u003eReject duplicate Host headers in request headers. Thanks to Sunand Mohan for the report.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-hyper/h2/commit/bc239af1d1b85bc70482804f30a0e0e587d90a08\"\u003e\u003ccode\u003ebc239af\u003c/code\u003e\u003c/a\u003e v4.4.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-hyper/h2/commit/92b925ed1b1817c82db32893503f74f47fcf4452\"\u003e\u003ccode\u003e92b925e\u003c/code\u003e\u003c/a\u003e add test for duplicate host headers\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-hyper/h2/commit/292a40829feefda98c8509dcdbbb4a57af9bd6a6\"\u003e\u003ccode\u003e292a408\u003c/code\u003e\u003c/a\u003e reject duplicate Host headers in request headers\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-hyper/h2/commit/04d3b87cbc1db020d28c7cfb44fe194558efbdde\"\u003e\u003ccode\u003e04d3b87\u003c/code\u003e\u003c/a\u003e update changelog\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-hyper/h2/commit/439b970d0fa19891fa81068907de97dfa3a07c3a\"\u003e\u003ccode\u003e439b970\u003c/code\u003e\u003c/a\u003e prepare for next release cycle\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-hyper/h2/commit/9a7ff7430df669fa8e90b6121f3cc1ed64d1115a\"\u003e\u003ccode\u003e9a7ff74\u003c/code\u003e\u003c/a\u003e performance: remove consumed frames in place from data buffer (\u003ca href=\"https://redirect.github.com/python-hyper/h2/issues/1321\"\u003e#1321\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/python-hyper/h2/compare/v4.4.0...v4.4.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `httpcore2` from 2.9.0 to 2.10.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pydantic/httpx2/releases\"\u003ehttpcore2's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.10.0\u003c/h2\u003e\n\u003ch2\u003eHighlights\u003c/h2\u003e\n\u003ch3\u003e🚀 Performance and memory improvements\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eSending large HTTP/2 request bodies no longer copies the body quadratically - sending a 256 MiB body went from ~36s to under 0.1s (\u003ca href=\"https://redirect.github.com/pydantic/httpx2/pull/1127\"\u003epydantic/httpx2#1127\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eSSE parsing is up to 35x faster on highly fragmented streams (\u003ca href=\"https://redirect.github.com/pydantic/httpx2/pull/1117\"\u003epydantic/httpx2#1117\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eCookie extraction is now skipped for responses without a \u003ccode\u003eSet-Cookie\u003c/code\u003e header, making typical requests roughly 8% faster (\u003ca href=\"https://redirect.github.com/pydantic/httpx2/pull/1107\"\u003epydantic/httpx2#1107\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e🕸️ WebAssembly / Emscripten support\u003c/h3\u003e\n\u003cp\u003e\u003ccode\u003ehttpx2\u003c/code\u003e now runs on Pyodide / Emscripten, using a JavaScript \u003ccode\u003efetch\u003c/code\u003e-based transport defined in \u003ccode\u003ehttpx2-jsfetch\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/pydantic/httpx2/pull/1119\"\u003epydantic/httpx2#1119\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/pydantic/httpx2/pull/1114\"\u003epydantic/httpx2#1114\u003c/a\u003e). Thanks \u003ca href=\"https://github.com/hoodmane\"\u003e\u003ccode\u003e@​hoodmane\u003c/code\u003e\u003c/a\u003e!\u003c/p\u003e\n\u003ch2\u003ehttpx2\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdd support for running on WebAssembly / Emscripten via Pyodide by \u003ca href=\"https://github.com/hoodmane\"\u003e\u003ccode\u003e@​hoodmane\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/httpx2/pull/1119\"\u003epydantic/httpx2#1119\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003emax_event_size\u003c/code\u003e to cap SSE event buffering by \u003ca href=\"https://github.com/Kludex\"\u003e\u003ccode\u003e@​Kludex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/httpx2/pull/1071\"\u003epydantic/httpx2#1071\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd RFC 9110 status code constants by \u003ca href=\"https://github.com/mbeijen\"\u003e\u003ccode\u003e@​mbeijen\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/httpx2/pull/1069\"\u003epydantic/httpx2#1069\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd support for Python 3.15 by \u003ca href=\"https://github.com/hugovk\"\u003e\u003ccode\u003e@​hugovk\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/httpx2/pull/1090\"\u003epydantic/httpx2#1090\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eImprove SSE chunk buffering performance by \u003ca href=\"https://github.com/Kludex\"\u003e\u003ccode\u003e@​Kludex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/httpx2/pull/1117\"\u003epydantic/httpx2#1117\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSkip cookie extraction without \u003ccode\u003eSet-Cookie\u003c/code\u003e by \u003ca href=\"https://github.com/Kludex\"\u003e\u003ccode\u003e@​Kludex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/httpx2/pull/1107\"\u003epydantic/httpx2#1107\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eReturn \u003ccode\u003estr | None\u003c/code\u003e instead of \u003ccode\u003eAny\u003c/code\u003e from \u003ccode\u003eHeaders.get\u003c/code\u003e by \u003ca href=\"https://github.com/ItsDrike\"\u003e\u003ccode\u003e@​ItsDrike\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/httpx2/pull/1121\"\u003epydantic/httpx2#1121\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eEnforce WebSocket max message size across fragments by \u003ca href=\"https://github.com/Kludex\"\u003e\u003ccode\u003e@​Kludex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/httpx2/pull/1085\"\u003epydantic/httpx2#1085\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eIgnore unsolicited and duplicate Pong frames by \u003ca href=\"https://github.com/Kludex\"\u003e\u003ccode\u003e@​Kludex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/httpx2/pull/1122\"\u003epydantic/httpx2#1122\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ehttpcore2\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdd support for Python 3.15 by \u003ca href=\"https://github.com/hugovk\"\u003e\u003ccode\u003e@​hugovk\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/httpx2/pull/1090\"\u003epydantic/httpx2#1090\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAvoid quadratic copying when sending large HTTP/2 request bodies by \u003ca href=\"https://github.com/Kludex\"\u003e\u003ccode\u003e@​Kludex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/httpx2/pull/1127\"\u003epydantic/httpx2#1127\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ePropagate the original exception instead of raising \u003ccode\u003eKeyError\u003c/code\u003e when an HTTP/2 stream fails by \u003ca href=\"https://github.com/yhay81\"\u003e\u003ccode\u003e@​yhay81\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/httpx2/pull/1093\"\u003epydantic/httpx2#1093\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eStart TLS for the \u003ccode\u003ewss\u003c/code\u003e scheme in SOCKS5 proxy connections by \u003ca href=\"https://github.com/Kludex\"\u003e\u003ccode\u003e@​Kludex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/httpx2/pull/1104\"\u003epydantic/httpx2#1104\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🙏 New Contributors\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/httpx2/commit/a966320e75477b8c55ee78fdb8f57ead6a574cb0\"\u003e\u003ccode\u003ea966320\u003c/code\u003e\u003c/a\u003e Version 2.10.0 (\u003ca href=\"https://redirect.github.com/pydantic/httpx2/issues/1129\"\u003e#1129\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/httpx2/commit/586f968f5510aa4d3b7edd1f1b039684c42945ee\"\u003e\u003ccode\u003e586f968\u003c/code\u003e\u003c/a\u003e Avoid quadratic copying when sending large HTTP/2 request bodies (\u003ca href=\"https://redirect.github.com/pydantic/httpx2/issues/1127\"\u003e#1127\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/httpx2/commit/dee1d1ace3021404d0aa255957821eda97c94c43\"\u003e\u003ccode\u003edee1d1a\u003c/code\u003e\u003c/a\u003e Return \u003ccode\u003estr | None\u003c/code\u003e instead of \u003ccode\u003eAny\u003c/code\u003e from \u003ccode\u003eHeaders.get\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/pydantic/httpx2/issues/1121\"\u003e#1121\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/httpx2/commit/dec24ad57d1d337de7de23c011eb566a145e7b40\"\u003e\u003ccode\u003edec24ad\u003c/code\u003e\u003c/a\u003e Use \u003ccode\u003ehttpx2-jsfetch\u003c/code\u003e on Emscripten (\u003ca href=\"https://redirect.github.com/pydantic/httpx2/issues/1119\"\u003e#1119\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/httpx2/commit/454b8b2197f62d699ff3ad762917643926b4da77\"\u003e\u003ccode\u003e454b8b2\u003c/code\u003e\u003c/a\u003e Ignore unsolicited and duplicate Pong frames (\u003ca href=\"https://redirect.github.com/pydantic/httpx2/issues/1122\"\u003e#1122\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/httpx2/commit/cbfc0e04ef6507da29ccbb3b9c2e5b23dd693414\"\u003e\u003ccode\u003ecbfc0e0\u003c/code\u003e\u003c/a\u003e Improve SSE chunk buffering performance (\u003ca href=\"https://redirect.github.com/pydantic/httpx2/issues/1117\"\u003e#1117\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/httpx2/commit/ad141d876c7d3c3f58555cbb0a178ec2c1f15b51\"\u003e\u003ccode\u003ead141d8\u003c/code\u003e\u003c/a\u003e Refactor SSE parser coordination (\u003ca href=\"https://redirect.github.com/pydantic/httpx2/issues/1118\"\u003e#1118\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/httpx2/commit/e0b01245e42d2091034ee9455cbb068bc0d6c0c6\"\u003e\u003ccode\u003ee0b0124\u003c/code\u003e\u003c/a\u003e Make \u003ccode\u003e_client\u003c/code\u003e depend on the \u003ccode\u003e_transports\u003c/code\u003e package instead of its submodules ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/httpx2/commit/e52f963c62f397f225c8d29573aedbe5ae613906\"\u003e\u003ccode\u003ee52f963\u003c/code\u003e\u003c/a\u003e Skip dependencies not needed on Emscripten (\u003ca href=\"https://redirect.github.com/pydantic/httpx2/issues/1114\"\u003e#1114\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/httpx2/commit/5d9eedc98186c612d0e426df417f78f6ec21e9ca\"\u003e\u003ccode\u003e5d9eedc\u003c/code\u003e\u003c/a\u003e Add \u003ccode\u003emax_event_size\u003c/code\u003e to cap SSE event buffering (\u003ca href=\"https://redirect.github.com/pydantic/httpx2/issues/1071\"\u003e#1071\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/pydantic/httpx2/compare/v2.9.0...v2.10.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `httpx2` from 2.9.0 to 2.10.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pydantic/httpx2/releases\"\u003ehttpx2's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.10.0\u003c/h2\u003e\n\u003ch2\u003eHighlights\u003c/h2\u003e\n\u003ch3\u003e🚀 Performance and memory improvements\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eSending large HTTP/2 request bodies no longer copies the body quadratically - sending a 256 MiB body went from ~36s to under 0.1s (\u003ca href=\"https://redirect.github.com/pydantic/httpx2/pull/1127\"\u003epydantic/httpx2#1127\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eSSE parsing is up to 35x faster on highly fragmented streams (\u003ca href=\"https://redirect.github.com/pydantic/httpx2/pull/1117\"\u003epydantic/httpx2#1117\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eCookie extraction is now skipped for responses without a \u003ccode\u003eSet-Cookie\u003c/code\u003e header, making typical requests roughly 8% faster (\u003ca href=\"https://redirect.github.com/pydantic/httpx2/pull/1107\"\u003epydantic/httpx2#1107\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e🕸️ WebAssembly / Emscripten support\u003c/h3\u003e\n\u003cp\u003e\u003ccode\u003ehttpx2\u003c/code\u003e now runs on Pyodide / Emscripten, using a JavaScript \u003ccode\u003efetch\u003c/code\u003e-based transport defined in \u003ccode\u003ehttpx2-jsfetch\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/pydantic/httpx2/pull/1119\"\u003epydantic/httpx2#1119\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/pydantic/httpx2/pull/1114\"\u003epydantic/httpx2#1114\u003c/a\u003e). Thanks \u003ca href=\"https://github.com/hoodmane\"\u003e\u003ccode\u003e@​hoodmane\u003c/code\u003e\u003c/a\u003e!\u003c/p\u003e\n\u003ch2\u003ehttpx2\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdd support for running on WebAssembly / Emscripten via Pyodide by \u003ca href=\"https://github.com/hoodmane\"\u003e\u003ccode\u003e@​hoodmane\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/httpx2/pull/1119\"\u003epydantic/httpx2#1119\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003emax_event_size\u003c/code\u003e to cap SSE event buffering by \u003ca href=\"https://github.com/Kludex\"\u003e\u003ccode\u003e@​Kludex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/httpx2/pull/1071\"\u003epydantic/httpx2#1071\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd RFC 9110 status code constants by \u003ca href=\"https://github.com/mbeijen\"\u003e\u003ccode\u003e@​mbeijen\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/httpx2/pull/1069\"\u003epydantic/httpx2#1069\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd support for Python 3.15 by \u003ca href=\"https://github.com/hugovk\"\u003e\u003ccode\u003e@​hugovk\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/httpx2/pull/1090\"\u003epydantic/httpx2#1090\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eImprove SSE chunk buffering performance by \u003ca href=\"https://github.com/Kludex\"\u003e\u003ccode\u003e@​Kludex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/httpx2/pull/1117\"\u003epydantic/httpx2#1117\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSkip cookie extraction without \u003ccode\u003eSet-Cookie\u003c/code\u003e by \u003ca href=\"https://github.com/Kludex\"\u003e\u003ccode\u003e@​Kludex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/httpx2/pull/1107\"\u003epydantic/httpx2#1107\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eReturn \u003ccode\u003estr | None\u003c/code\u003e instead of \u003ccode\u003eAny\u003c/code\u003e from \u003ccode\u003eHeaders.get\u003c/code\u003e by \u003ca href=\"https://github.com/ItsDrike\"\u003e\u003ccode\u003e@​ItsDrike\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/httpx2/pull/1121\"\u003epydantic/httpx2#1121\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eEnforce WebSocket max message size across fragments by \u003ca href=\"https://github.com/Kludex\"\u003e\u003ccode\u003e@​Kludex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/httpx2/pull/1085\"\u003epydantic/httpx2#1085\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eIgnore unsolicited and duplicate Pong frames by \u003ca href=\"https://github.com/Kludex\"\u003e\u003ccode\u003e@​Kludex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/httpx2/pull/1122\"\u003epydantic/httpx2#1122\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ehttpcore2\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdd support for Python 3.15 by \u003ca href=\"https://github.com/hugovk\"\u003e\u003ccode\u003e@​hugovk\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/httpx2/pull/1090\"\u003epydantic/httpx2#1090\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAvoid quadratic copying when sending large HTTP/2 request bodies by \u003ca href=\"https://github.com/Kludex\"\u003e\u003ccode\u003e@​Kludex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/httpx2/pull/1127\"\u003epydantic/httpx2#1127\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ePropagate the original exception instead of raising \u003ccode\u003eKeyError\u003c/code\u003e when an HTTP/2 stream fails by \u003ca href=\"https://github.com/yhay81\"\u003e\u003ccode\u003e@​yhay81\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/httpx2/pull/1093\"\u003epydantic/httpx2#1093\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eStart TLS for the \u003ccode\u003ewss\u003c/code\u003e scheme in SOCKS5 proxy connections by \u003ca href=\"https://github.com/Kludex\"\u003e\u003ccode\u003e@​Kludex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/httpx2/pull/1104\"\u003epydantic/httpx2#1104\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🙏 New Contributors\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pydantic/httpx2/blob/main/src/httpx2/CHANGELOG.md\"\u003ehttpx2's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e2.10.0 (August 9th, 2026)\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdd support for running on WebAssembly / Emscripten via Pyodide, using a JavaScript\n\u003ccode\u003efetch\u003c/code\u003e-based transport defined in \u003ccode\u003ehttpx2-jsfetch\u003c/code\u003e.\n(\u003ca href=\"https://redirect.github.com/pydantic/httpx2/pull/1119\"\u003e#1119\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003emax_event_size\u003c/code\u003e to cap SSE event buffering. (\u003ca href=\"https://redirect.github.com/pydantic/httpx2/pull/1071\"\u003e#1071\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdd RFC 9110 status code constants. (\u003ca href=\"https://redirect.github.com/pydantic/httpx2/pull/1069\"\u003e#1069\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdd support for Python 3.15. (\u003ca href=\"https://redirect.github.com/pydantic/httpx2/pull/1090\"\u003e#1090\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eImprove SSE chunk buffering performance. (\u003ca href=\"https://redirect.github.com/pydantic/httpx2/pull/1117\"\u003e#1117\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSkip cookie extraction for responses without \u003ccode\u003eSet-Cookie\u003c/code\u003e headers. (\u003ca href=\"https://redirect.github.com/pydantic/httpx2/pull/1107\"\u003e#1107\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eReturn \u003ccode\u003estr | None\u003c/code\u003e instead of \u003ccode\u003eAny\u003c/code\u003e from \u003ccode\u003eHeaders.get\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/pydantic/httpx2/pull/1121\"\u003e#1121\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eEnforce the WebSocket max message size across fragmented messages. (\u003ca href=\"https://redirect.github.com/pydantic/httpx2/pull/1085\"\u003e#1085\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eIgnore unsolicited and duplicate WebSocket Pong frames. (\u003ca href=\"https://redirect.github.com/pydantic/httpx2/pull/1122\"\u003e#1122\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.9.1 (July 24th, 2026)\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAlias \u003ccode\u003ehttpcore\u003c/code\u003e imports to \u003ccode\u003ehttpcore2\u003c/code\u003e in \u003ccode\u003ealias_httpx()\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/pydantic/httpx2/pull/1082\"\u003e#1082\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/httpx2/commit/a966320e75477b8c55ee78fdb8f57ead6a574cb0\"\u003e\u003ccode\u003ea966320\u003c/code\u003e\u003c/a\u003e Version 2.10.0 (\u003ca href=\"https://redirect.github.com/pydantic/httpx2/issues/1129\"\u003e#1129\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/httpx2/commit/dee1d1ace3021404d0aa255957821eda97c94c43\"\u003e\u003ccode\u003edee1d1a\u003c/code\u003e\u003c/a\u003e Return \u003ccode\u003estr | None\u003c/code\u003e instead of \u003ccode\u003eAny\u003c/code\u003e from \u003ccode\u003eHeaders.get\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/pydantic/httpx2/issues/1121\"\u003e#1121\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/httpx2/commit/dec24ad57d1d337de7de23c011eb566a145e7b40\"\u003e\u003ccode\u003edec24ad\u003c/code\u003e\u003c/a\u003e Use \u003ccode\u003ehttpx2-jsfetch\u003c/code\u003e on Emscripten (\u003ca href=\"https://redirect.github.com/pydantic/httpx2/issues/1119\"\u003e#1119\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/httpx2/commit/454b8b2197f62d699ff3ad762917643926b4da77\"\u003e\u003ccode\u003e454b8b2\u003c/code\u003e\u003c/a\u003e Ignore unsolicited and duplicate Pong frames (\u003ca href=\"https://redirect.github.com/pydantic/httpx2/issues/1122\"\u003e#1122\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/httpx2/commit/cbfc0e04ef6507da29ccbb3b9c2e5b23dd693414\"\u003e\u003ccode\u003ecbfc0e0\u003c/code\u003e\u003c/a\u003e Improve SSE chunk buffering performance (\u003ca href=\"https://redirect.github.com/pydantic/httpx2/issues/1117\"\u003e#1117\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/httpx2/commit/ad141d876c7d3c3f58555cbb0a178ec2c1f15b51\"\u003e\u003ccode\u003ead141d8\u003c/code\u003e\u003c/a\u003e Refactor SSE parser coordination (\u003ca href=\"https://redirect.github.com/pydantic/httpx2/issues/1118\"\u003e#1118\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/httpx2/commit/e0b01245e42d2091034ee9455cbb068bc0d6c0c6\"\u003e\u003ccode\u003ee0b0124\u003c/code\u003e\u003c/a\u003e Make \u003ccode\u003e_client\u003c/code\u003e depend on the \u003ccode\u003e_transports\u003c/code\u003e package instead of its submodules ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/httpx2/commit/e52f963c62f397f225c8d29573aedbe5ae613906\"\u003e\u003ccode\u003ee52f963\u003c/code\u003e\u003c/a\u003e Skip dependencies not needed on Emscripten (\u003ca href=\"https://redirect.github.com/pydantic/httpx2/issues/1114\"\u003e#1114\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/httpx2/commit/5d9eedc98186c612d0e426df417f78f6ec21e9ca\"\u003e\u003ccode\u003e5d9eedc\u003c/code\u003e\u003c/a\u003e Add \u003ccode\u003emax_event_size\u003c/code\u003e to cap SSE event buffering (\u003ca href=\"https://redirect.github.com/pydantic/httpx2/issues/1071\"\u003e#1071\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/httpx2/commit/55fad715eb24b3b1c6bbf96757bcb49a03e121de\"\u003e\u003ccode\u003e55fad71\u003c/code\u003e\u003c/a\u003e Bump the python-packages group across 1 directory with 15 updates (\u003ca href=\"https://redirect.github.com/pydantic/httpx2/issues/1112\"\u003e#1112\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/pydantic/httpx2/compare/v2.9.0...v2.10.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `pyjwt` from 2.10.1 to 2.13.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/jpadilla/pyjwt/releases\"\u003epyjwt's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e2.13.0\u003c/h2\u003e\n\u003ch1\u003ePyJWT 2.13.0 — Security Release\u003c/h1\u003e\n\u003cp\u003eThis release bundles five security fixes plus three additional hardening / spec-compliance changes. We recommend all users upgrade.\u003c/p\u003e\n\u003ch2\u003eSecurity\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/security/advisories/GHSA-xgmm-8j9v-c9wx\"\u003e\u003ccode\u003eGHSA-xgmm-8j9v-c9wx\u003c/code\u003e\u003c/a\u003e — JWK JSON accepted as HMAC secret (algorithm confusion).\u003c/strong\u003e \u003ccode\u003eHMACAlgorithm.prepare_key\u003c/code\u003e previously rejected PEM- and SSH-formatted asymmetric keys but did not catch a JWK passed as a raw JSON string. In a verifier configured with both symmetric and asymmetric algorithms in \u003ccode\u003ealgorithms=[…]\u003c/code\u003e and a raw-JSON JWK as the key, an attacker could forge HS256 tokens using the JWK text as the HMAC secret. The guard has been extended to reject any JWK-shaped JSON. \u003cem\u003eReported by \u003ca href=\"https://github.com/aradona91\"\u003e\u003ccode\u003e@​aradona91\u003c/code\u003e\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/security/advisories/GHSA-jq35-7prp-9v3f\"\u003e\u003ccode\u003eGHSA-jq35-7prp-9v3f\u003c/code\u003e\u003c/a\u003e — Algorithm allow-list bypass with \u003ccode\u003ePyJWK\u003c/code\u003e / \u003ccode\u003ePyJWKClient\u003c/code\u003e.\u003c/strong\u003e When verifying with a \u003ccode\u003ePyJWK\u003c/code\u003e, the caller's \u003ccode\u003ealgorithms=[…]\u003c/code\u003e allow-list was checked against the token header \u003ccode\u003ealg\u003c/code\u003e as a string only; actual verification used the algorithm bound to the \u003ccode\u003ePyJWK\u003c/code\u003e. An attacker who controlled a registered JWKS key could sign with one algorithm and advertise another on the header. PyJWT now requires the token header \u003ccode\u003ealg\u003c/code\u003e to match the \u003ccode\u003ePyJWK\u003c/code\u003e's algorithm before verification. \u003cem\u003eReported by \u003ca href=\"https://github.com/sushi-gif\"\u003e\u003ccode\u003e@​sushi-gif\u003c/code\u003e\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/security/advisories/GHSA-w7vc-732c-9m39\"\u003e\u003ccode\u003eGHSA-w7vc-732c-9m39\u003c/code\u003e\u003c/a\u003e — DoS via base64 decode of unused payload segment when \u003ccode\u003eb64=false\u003c/code\u003e.\u003c/strong\u003e For detached-payload JWS (\u003ccode\u003eb64=false\u003c/code\u003e), the compact-form payload segment was base64-decoded before being discarded in favor of the caller-supplied \u003ccode\u003edetached_payload\u003c/code\u003e. An attacker could inflate the unused segment to force CPU + memory cost without holding a valid signature. The segment is now required to be empty per RFC 7515 Appendix F, and is no longer decoded. \u003cem\u003eReported by \u003ca href=\"https://github.com/thesmartshadow\"\u003e\u003ccode\u003e@​thesmartshadow\u003c/code\u003e\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/security/advisories/GHSA-993g-76c3-p5m4\"\u003e\u003ccode\u003eGHSA-993g-76c3-p5m4\u003c/code\u003e\u003c/a\u003e — \u003ccode\u003ePyJWKClient\u003c/code\u003e accepts non-HTTP(S) URIs.\u003c/strong\u003e \u003ccode\u003ePyJWKClient.fetch_data\u003c/code\u003e passed its URI to \u003ccode\u003eurllib.request.urlopen\u003c/code\u003e, which by default also handles \u003ccode\u003efile://\u003c/code\u003e, \u003ccode\u003eftp://\u003c/code\u003e, and \u003ccode\u003edata:\u003c/code\u003e schemes. An application that fed an attacker-influenced URI into \u003ccode\u003ePyJWKClient\u003c/code\u003e could be coerced into reading local files or reaching other unintended schemes. \u003ccode\u003ePyJWKClient\u003c/code\u003e now rejects any URI whose scheme isn't \u003ccode\u003ehttp\u003c/code\u003e or \u003ccode\u003ehttps\u003c/code\u003e. \u003cem\u003eReported by \u003ca href=\"https://github.com/KEIJOT\"\u003e\u003ccode\u003e@​KEIJOT\u003c/code\u003e\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/security/advisories/GHSA-fhv5-28vv-h8m8\"\u003e\u003ccode\u003eGHSA-fhv5-28vv-h8m8\u003c/code\u003e\u003c/a\u003e — \u003ccode\u003ePyJWKClient\u003c/code\u003e cache wiped on fetch error.\u003c/strong\u003e A \u003ccode\u003efinally\u003c/code\u003e-block \u003ccode\u003eput(jwk_set=None)\u003c/code\u003e cleared the JWK Set cache whenever a fetch raised, turning a transient JWKS-endpoint outage into application-wide auth failure. The cache write was moved into the success path; transient errors no longer evict valid cached keys. \u003cem\u003eReported by \u003ca href=\"https://github.com/eddieran\"\u003e\u003ccode\u003e@​eddieran\u003c/code\u003e\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eFixed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eReject empty HMAC keys outright in \u003ccode\u003eHMACAlgorithm.prepare_key\u003c/code\u003e with \u003ccode\u003eInvalidKeyError\u003c/code\u003e instead of accepting them with only a warning. Defends against the \u003ccode\u003eos.getenv(\u0026quot;JWT_SECRET\u0026quot;, \u0026quot;\u0026quot;)\u003c/code\u003e footgun. \u003cem\u003eThanks to \u003ca href=\"https://github.com/SnailSploit\"\u003e\u003ccode\u003e@​SnailSploit\u003c/code\u003e\u003c/a\u003e and \u003ca href=\"https://github.com/spartan8806\"\u003e\u003ccode\u003e@​spartan8806\u003c/code\u003e\u003c/a\u003e for the reports.\u003c/em\u003e\u003c/li\u003e\n\u003cli\u003eForward per-call \u003ccode\u003eoptions\u003c/code\u003e (including \u003ccode\u003eenforce_minimum_key_length\u003c/code\u003e) from \u003ccode\u003ePyJWT.decode\u003c/code\u003e through to \u003ccode\u003ePyJWS._verify_signature\u003c/code\u003e. The option was previously silently dropped between the two layers, so it only took effect when set on the \u003ccode\u003ePyJWT\u003c/code\u003e instance. \u003cem\u003eThanks to \u003ca href=\"https://github.com/WLUB\"\u003e\u003ccode\u003e@​WLUB\u003c/code\u003e\u003c/a\u003e for the report.\u003c/em\u003e\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eRFC 7797 §3 compliance for \u003ccode\u003eb64=false\u003c/code\u003e:\u003c/strong\u003e the encoder now auto-adds \u003ccode\u003e\u0026quot;b64\u0026quot;\u003c/code\u003e to \u003ccode\u003ecrit\u003c/code\u003e, and the decoder rejects tokens that set \u003ccode\u003eb64=false\u003c/code\u003e without listing it in \u003ccode\u003ecrit\u003c/code\u003e. \u003cem\u003eThanks to \u003ca href=\"https://github.com/MachineLearning-Nerd\"\u003e\u003ccode\u003e@​MachineLearning-Nerd\u003c/code\u003e\u003c/a\u003e for the report.\u003c/em\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eChanged\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMigrate the \u003ccode\u003edev\u003c/code\u003e, \u003ccode\u003edocs\u003c/code\u003e, and \u003ccode\u003etests\u003c/code\u003e package extras to dependency groups, by \u003ca href=\"https://github.com/kurtmckee\"\u003e\u003ccode\u003e@​kurtmckee\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/jpadilla/pyjwt/pull/1152\"\u003e#1152\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eUpgrade notes\u003c/h2\u003e\n\u003cp\u003eMost fixes are invisible to correctly-configured callers. A few behavioral changes you may encounter:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eEmpty HMAC keys now raise.\u003c/strong\u003e If your app passed \u003ccode\u003e\u0026quot;\u0026quot;\u003c/code\u003e or \u003ccode\u003eb\u0026quot;\u0026quot;\u003c/code\u003e as a secret (often via a missing env var, e.g. \u003ccode\u003eos.getenv(\u0026quot;JWT_SECRET\u0026quot;, \u0026quot;\u0026quot;)\u003c/code\u003e), \u003ccode\u003eencode\u003c/code\u003e/\u003ccode\u003edecode\u003c/code\u003e will now raise \u003ccode\u003eInvalidKeyError\u003c/code\u003e. This is the intended behavior — fix the configuration.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ccode\u003ePyJWK\u003c/code\u003e decoding now requires the token's \u003ccode\u003ealg\u003c/code\u003e to match the JWK's algorithm.\u003c/strong\u003e Previously a mismatch was silently honored if the header \u003ccode\u003ealg\u003c/code\u003e appeared in the allow-list. Tokens that relied on this mismatch will now fail with \u003ccode\u003eInvalidAlgorithmError\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ccode\u003ePyJWKClient\u003c/code\u003e now rejects non-HTTP(S) URIs at construction time.\u003c/strong\u003e Tests or dev environments that fetched JWKS from \u003ccode\u003efile://\u003c/code\u003e URIs need to switch to a local HTTP server or load the JWKS by other means (e.g. construct \u003ccode\u003ePyJWKSet.from_dict(...)\u003c/code\u003e directly).\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ccode\u003eb64=false\u003c/code\u003e tokens are now strictly RFC 7515 / 7797 compliant.\u003c/strong\u003e Tokens with a non-empty compact-form payload segment, or that omit \u003ccode\u003e\u0026quot;b64\u0026quot;\u003c/code\u003e from \u003ccode\u003ecrit\u003c/code\u003e, will be rejected. PyJWT-produced tokens always satisfy both invariants, so round-trips through PyJWT are unaffected.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ccode\u003eenforce_minimum_key_length\u003c/code\u003e set per-call now takes effect.\u003c/strong\u003e Callers who passed \u003ccode\u003eoptions={\u0026quot;enforce_minimum_key_length\u0026quot;: True}\u003c/code\u003e to \u003ccode\u003ejwt.decode()\u003c/code\u003e previously got no enforcement; they will now get \u003ccode\u003eInvalidKeyError\u003c/code\u003e on undersized keys, as documented.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull changelog:\u003c/strong\u003e \u003ca href=\"https://github.com/jpadilla/pyjwt/compare/2.12.1...2.13.0\"\u003ehttps://github.com/jpadilla/pyjwt/compare/2.12.1...2.13.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003e2.12.1\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd typing_extensions dependency for Python \u0026lt; 3.11 by \u003ca href=\"https://github.com/jpadilla\"\u003e\u003ccode\u003e@​jpadilla\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/jpadilla/pyjwt/pull/1151\"\u003ejpadilla/pyjwt#1151\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/jpadilla/pyjwt/compare/2.12.0...2.12.1\"\u003ehttps://github.com/jpadilla/pyjwt/compare/2.12.0...2.12.1\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003e2.12.0\u003c/h2\u003e\n\u003ch2\u003eSecurity\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eValidate the crit (Critical) Header Parameter defined in RFC 7515 §4.1.11. by \u003ca href=\"https://github.com/dmbs335\"\u003e\u003ccode\u003e@​dmbs335\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://github.com/jpadilla/pyjwt/security/advisories/GHSA-752w-5fwx-jx9f\"\u003eGHSA-752w-5fwx-jx9f\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/jpadilla/pyjwt/blob/master/CHANGELOG.rst\"\u003epyjwt's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ccode\u003ev2.13.0 \u0026lt;https://github.com/jpadilla/pyjwt/compare/2.12.1...2.13.0\u0026gt;\u003c/code\u003e__\u003c/h2\u003e\n\u003cp\u003eSecurity\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003e\n- Reject JWK JSON documents passed as raw HMAC secrets in\n  ``HMACAlgorithm.prepare_key`` to close an algorithm-confusion gap that\n  the existing PEM/SSH guard did not cover. Reported by @aradona91 in\n  `GHSA-xgmm-8j9v-c9wx \u0026lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-xgmm-8j9v-c9wx\u0026gt;`__.\n- Bind the JWT header ``alg`` to ``PyJWK.algorithm_name`` during\n  verification so the caller's ``algorithms=[...]`` allow-list cannot be\n  bypassed when decoding with a ``PyJWK`` / ``PyJWKClient`` key. Reported\n  by @sushi-gif in `GHSA-jq35-7prp-9v3f \u0026lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-jq35-7prp-9v3f\u0026gt;`__.\n- Reject non-``http(s)`` URI schemes in ``PyJWKClient`` so attacker-\n  influenced URIs cannot read local files or reach unintended schemes via\n  urllib's default ``file://`` / ``ftp://`` / ``data:`` handlers. Reported\n  by @KEIJOT in `GHSA-993g-76c3-p5m4 \u0026lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-993g-76c3-p5m4\u0026gt;`__.\n- Preserve the cached JWK Set on fetch errors in ``PyJWKClient.fetch_data``.\n  The previous ``finally``-block ``put(None)`` pattern cleared the cache\n  on any transient outage, turning one bad JWKS request into application-\n  wide auth failure. Reported by @eddieran in `GHSA-fhv5-28vv-h8m8 \u0026lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-fhv5-28vv-h8m8\u0026gt;`__.\n- Skip the unconditional base64 decode of the compact-form payload segment\n  when ``b64=false`` is set in the protected header, and require that\n  segment to be empty (RFC 7515 Appendix F detached form). Closes an\n  unauthenticated DoS amplifier. Reported by @thesmartshadow in\n  `GHSA-w7vc-732c-9m39 \u0026lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-w7vc-732c-9m39\u0026gt;`__.\n\u003cp\u003eFixed\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003e\n- Reject empty HMAC keys outright in ``HMACAlgorithm.prepare_key`` with\n  ``InvalidKeyError`` instead of accepting them with only a warning.\n  Thanks to @SnailSploit and @spartan8806 for independently flagging the\n  footgun.\n- Forward per-call ``options`` (including ``enforce_minimum_key_length``)\n  from ``PyJWT.decode`` through to ``PyJWS._verify_signature`` so the\n  option actually takes effect when set at the call site rather than only\n  on the ``PyJWT`` instance. Thanks to @WLUB for the report.\n- RFC 7797 §3 compliance for ``b64=false``: the encoder now auto-adds\n  ``\u0026amp;quot;b64\u0026amp;quot;`` to the ``crit`` header parameter, and the decoder rejects\n  tokens that set ``b64=false`` without listing it in ``crit``. Thanks to\n  @MachineLearning-Nerd for the report.\n\nChanged\n\u003c/code\u003e\u003c/pre\u003e\n\u003cul\u003e\n\u003cli\u003eMigrate the \u003ccode\u003edev\u003c/code\u003e, \u003ccode\u003edocs\u003c/code\u003e, and \u003ccode\u003etests\u003c/code\u003e package extras to dependency groups by \u003ca href=\"https://github.com/kurtmckee\"\u003e\u003ccode\u003e@​kurtmckee\u003c/code\u003e\u003c/a\u003e in \u003ccode\u003e[#1152](https://github.com/jpadilla/pyjwt/issues/1152) \u0026amp;lt;https://github.com/jpadilla/pyjwt/pull/1152\u0026amp;gt;\u003c/code\u003e__\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003ccode\u003ev2.12.1 \u0026amp;lt;https://github.com/jpadilla/pyjwt/compare/2.12.0...2.12.1\u0026amp;gt;\u003c/code\u003e__\n\u0026lt;/tr\u0026gt;\u0026lt;/table\u0026gt;\n\u003c/code\u003e\u003c/pre\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/7144e4534c34810f4525dc4578a32addd8212cff\"\u003e\u003ccode\u003e7144e45\u003c/code\u003e\u003c/a\u003e Apply ruff format\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/d2f4bec4963897c0ef96ef64a875894f2c8542ab\"\u003e\u003ccode\u003ed2f4bec\u003c/code\u003e\u003c/a\u003e Restore \u003ccode\u003ecast()\u003c/code\u003e calls with cross-version \u003ccode\u003etype: ignore\u003c/code\u003e for \u003ccode\u003eprepare_key\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/22f478cebddd8294259c30f037ecb92b0b348774\"\u003e\u003ccode\u003e22f478c\u003c/code\u003e\u003c/a\u003e Remove redundant casts in \u003ccode\u003eRSAAlgorithm.prepare_key\u003c/code\u003e and `ECAlgorithm.prepare...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/95791b1759b8aa4f2203575d344d5c78564cdc81\"\u003e\u003ccode\u003e95791b1\u003c/code\u003e\u003c/a\u003e Bundle security fixes and hardening into 2.13.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/dcc27a9d3182a2349c30b160758785c6ce7a6508\"\u003e\u003ccode\u003edcc27a9\u003c/code\u003e\u003c/a\u003e [pre-commit.ci] pre-commit autoupdate (\u003ca href=\"https://redirect.github.com/jpadilla/pyjwt/issues/1155\"\u003e#1155\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/9d08a9a1896845ed8eaf88e6f6ac61e5800c3e7a\"\u003e\u003ccode\u003e9d08a9a\u003c/code\u003e\u003c/a\u003e [pre-commit.ci] pre-commit autoupdate (\u003ca href=\"https://redirect.github.com/jpadilla/pyjwt/issues/1146\"\u003e#1146\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/b87c10014d4109f0214fea188d00faaaf8a80e64\"\u003e\u003ccode\u003eb87c100\u003c/code\u003e\u003c/a\u003e Bump codecov/codecov-action from 5 to 6 (\u003ca href=\"https://redirect.github.com/jpadilla/pyjwt/issues/1154\"\u003e#1154\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/40e3147eb5f790d8d041772e5fc00728a176c812\"\u003e\u003ccode\u003e40e3147\u003c/code\u003e\u003c/a\u003e Migrate development extras to dependency groups (\u003ca href=\"https://redirect.github.com/jpadilla/pyjwt/issues/1152\"\u003e#1152\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/a4e1a3d1218b01c5806420b8f16d9308ac4adc30\"\u003e\u003ccode\u003ea4e1a3d\u003c/code\u003e\u003c/a\u003e Add typing_extensions dependency for Python \u0026lt; 3.11 (\u003ca href=\"https://redirect.github.com/jpadilla/pyjwt/issues/1151\"\u003e#1151\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/bd9700cca7f9258fadcc429c1034e508025931f2\"\u003e\u003ccode\u003ebd9700c\u003c/code\u003e\u003c/a\u003e Use PyJWK algorithm when encoding without explicit algorithm (\u003ca href=\"https://redirect.github.com/jpadilla/pyjwt/issues/1148\"\u003e#1148\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/jpadilla/pyjwt/compare/2.10.1...2.13.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `python-dotenv` from 1.1.0 to 1.2.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/theskumar/python-dotenv/releases\"\u003epython-dotenv's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.2.2\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eSupport for Python 3.14, including the free-threaded (3.14t) build. (#)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eThe \u003ccode\u003edotenv run\u003c/code\u003e command now forwards flags directly to the specified command by \u003ca href=\"https://github.com/bbc2\"\u003e\u003ccode\u003e@​bbc2\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/pull/607\"\u003etheskumar/python-dotenv#607\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eImproved documentation clarity regarding override behavior and the reference page.\u003c/li\u003e\n\u003cli\u003eUpdated PyPy support to version 3.11.\u003c/li\u003e\n\u003cli\u003eDocumentation for FIFO file support.\u003c/li\u003e\n\u003cli\u003eSupport for Python 3.9.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eImproved \u003ccode\u003eset_key\u003c/code\u003e and \u003ccode\u003eunset_key\u003c/code\u003e behavior when interacting with symlinks by \u003ca href=\"https://github.com/bbc2\"\u003e\u003ccode\u003e@​bbc2\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://github.com/theskumar/python-dotenv/commit/790c5c02991100aa1bf41ee5330aca75edc51311\"\u003e#790c5\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eCorrected the license specifier and added missing Python 3.14 classifiers in package metadata by \u003ca href=\"https://github.com/JYOuyang\"\u003e\u003ccode\u003e@​JYOuyang\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/pull/590\"\u003etheskumar/python-dotenv#590\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBreaking Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ccode\u003edotenv.set_key\u003c/code\u003e and \u003ccode\u003edotenv.unset_key\u003c/code\u003e used to follow symlinks in some\nsituations. This is no longer the case. For that behavior to be restored in\nall cases, \u003ccode\u003efollow_symlinks=True\u003c/code\u003e should be used.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eIn the CLI, \u003ccode\u003eset\u003c/code\u003e and \u003ccode\u003eunset\u003c/code\u003e used to follow symlinks in some situations. This\nis no longer the case.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ccode\u003edotenv.set_key\u003c/code\u003e, \u003ccode\u003edotenv.unset_key\u003c/code\u003e and the CLI commands \u003ccode\u003eset\u003c/code\u003e and \u003ccode\u003eunset\u003c/code\u003e\nused to reset the file mode of the modified .env file to \u003ccode\u003e0o600\u003c/code\u003e in some\nsituations. This is no longer the case: The original mode of the file is now\npreserved. Is the file needed to be created or wasn't a regular file, mode\n\u003ccode\u003e0o600\u003c/code\u003e is used.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMisc\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eskip 000 permission tests for root user by \u003ca href=\"https://github.com/burnout-projects\"\u003e\u003ccode\u003e@​burnout-projects\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/pull/561\"\u003etheskumar/python-dotenv#561\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump actions/checkout from 5 to 6 in the github-actions group by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/pull/593\"\u003etheskumar/python-dotenv#593\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd Windows testing to CI by \u003ca href=\"https://github.com/bbc2\"\u003e\u003ccode\u003e@​bbc2\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/pull/604\"\u003etheskumar/python-dotenv#604\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eImprove workflow efficiency with best practices by \u003ca href=\"https://github.com/theskumar\"\u003e\u003ccode\u003e@​theskumar\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/pull/609\"\u003etheskumar/python-dotenv#609\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRemove the use of \u003ccode\u003esh\u003c/code\u003e in tests by \u003ca href=\"https://github.com/bbc2\"\u003e\u003ccode\u003e@​bbc2\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/pull/612\"\u003etheskumar/python-dotenv#612\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/JYOuyang\"\u003e\u003ccode\u003e@​JYOuyang\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/pull/590\"\u003etheskumar/python-dotenv#590\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/burnout-projects\"\u003e\u003ccode\u003e@​burnout-projects\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/pull/561\"\u003etheskumar/python-dotenv#561\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cpackham-atlnz\"\u003e\u003ccode\u003e@​cpackham-atlnz\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/pull/597\"\u003etheskumar/python-dotenv#597\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/theskumar/python-dotenv/compare/v1.2.1...v1.2.2\"\u003ehttps://github.com/theskumar/python-dotenv/compare/v1.2.1...v1.2.2\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.2.1\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/theskumar/python-dotenv/blob/main/CHANGELOG.md\"\u003epython-dotenv's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e[1.2.2] - 2026-03-01\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eSupport for Python 3.14, including the free-threaded (3.14t) build. (\u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/588\"\u003e#588\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eThe \u003ccode\u003edotenv run\u003c/code\u003e command now forwards flags directly to the specified command by [\u003ca href=\"https://github.com/bbc2\"\u003e\u003ccode\u003e@​bbc2\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/607\"\u003e#607\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eImproved documentation clarity regarding override behavior and the reference page.\u003c/li\u003e\n\u003cli\u003eUpdated PyPy support to version 3.11.\u003c/li\u003e\n\u003cli\u003eDocumentation for FIFO file support.\u003c/li\u003e\n\u003cli\u003eDropped Support for Python 3.9.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eImproved \u003ccode\u003eset_key\u003c/code\u003e and \u003ccode\u003eunset_key\u003c/code\u003e behavior when interacting with symlinks by [\u003ca href=\"https://github.com/bbc2\"\u003e\u003ccode\u003e@​bbc2\u003c/code\u003e\u003c/a\u003e] in [790c5c0]\u003c/li\u003e\n\u003cli\u003eCorrected the license specifier and added missing Python 3.14 classifiers in package metadata by [\u003ca href=\"https://github.com/JYOuyang\"\u003e\u003ccode\u003e@​JYOuyang\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/590\"\u003e#590\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBreaking Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ccode\u003edotenv.set_key\u003c/code\u003e and \u003ccode\u003edotenv.unset_key\u003c/code\u003e used to follow symlinks in some\nsituations. This is no longer the case. For that behavior to be restored in\nall cases, \u003ccode\u003efollow_symlinks=True\u003c/code\u003e should be used.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eIn the CLI, \u003ccode\u003eset\u003c/code\u003e and \u003ccode\u003eunset\u003c/code\u003e used to follow symlinks in some situations. This\nis no longer the case.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ccode\u003edotenv.set_key\u003c/code\u003e, \u003ccode\u003edotenv.unset_key\u003c/code\u003e and the CLI commands \u003ccode\u003eset\u003c/code\u003e and \u003ccode\u003eunset\u003c/code\u003e\nused to reset the file mode of the modified .env file to \u003ccode\u003e0o600\u003c/code\u003e in some\nsituations. This is no longer the case: The original mode of the file is now\npreserved. Is the file needed to be created or wasn't a regular file, mode\n\u003ccode\u003e0o600\u003c/code\u003e is used.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e[1.2.1] - 2025-10-26\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMove more config to \u003ccode\u003epyproject.toml\u003c/code\u003e, removed \u003ccode\u003esetup.cfg\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eAdd support for reading \u003ccode\u003e.env\u003c/code\u003e from FIFOs (Unix) by [\u003ca href=\"https://github.com/sidharth-sudhir\"\u003e\u003ccode\u003e@​sidharth-sudhir\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/586\"\u003e#586\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e[1.2.0] - 2025-10-26\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade build system to use PEP 517 \u0026amp; PEP 518 to use \u003ccode\u003ebuild\u003c/code\u003e and \u003ccode\u003epyproject.toml\u003c/code\u003e by [\u003ca href=\"https://github.com/EpicWink\"\u003e\u003ccode\u003e@​EpicWink\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/583\"\u003e#583\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd support for Python 3.14 by [\u003ca href=\"https://github.com/23f3001135\"\u003e\u003ccode\u003e@​23f3001135\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/579\"\u003e#579\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd support for disabling of \u003ccode\u003eload_dotenv()\u003c/code\u003e using \u003ccode\u003ePYTHON_DOTENV_DISABLED\u003c/code\u003e env var. by [\u003ca href=\"https://github.com/matthewfranglen\"\u003e\u003ccode\u003e@​matthewfranglen\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/569\"\u003e#569\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e[1.1.1] - 2025-06-24\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eCLI: Ensure \u003ccode\u003efind_dotenv\u003c/code\u003e work reliably on python 3.13 by [\u003ca href=\"https://github.com/theskumar\"\u003e\u003ccode\u003e@​theskumar\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/563\"\u003e#563\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/36004e0e34be7665ff2b11a8a4005144f76f176d\"\u003e\u003ccode\u003e36004e0\u003c/code\u003e\u003c/a\u003e Bump version: 1.2.1 → 1.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/eb202520e5933c9daf42501e1e42fdb0144002c8\"\u003e\u003ccode\u003eeb20252\u003c/code\u003e\u003c/a\u003e docs: update changelog for v1.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/790c5c02991100aa1bf41ee5330aca75edc51311\"\u003e\u003ccode\u003e790c5c0\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/43340da220fb4ca4f95357bbe21a3c7f8f1278b1\"\u003e\u003ccode\u003e43340da\u003c/code\u003e\u003c/a\u003e Remove the use of \u003ccode\u003esh\u003c/code\u003e in tests (\u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/612\"\u003e#612\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/09d7cee32459e7abdcb5c9d8122a552589c06a9c\"\u003e\u003ccode\u003e09d7cee\u003c/code\u003e\u003c/a\u003e docs: clarify override behavior and document FIFO support (\u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/610\"\u003e#610\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/c8de2887c00198c22842c5ae5e92d1747467363c\"\u003e\u003ccode\u003ec8de288\u003c/code\u003e\u003c/a\u003e ci: improve workflow efficiency with best practices (\u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/609\"\u003e#609\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/7bd9e3dbfedc0983ad7d56d5570013035242bdf4\"\u003e\u003ccode\u003e7bd9e3d\u003c/code\u003e\u003c/a\u003e Add Windows testing to CI (\u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/604\"\u003e#604\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/1baaf04f336072e0ee324d5df9563ec767f14f81\"\u003e\u003ccode\u003e1baaf04\u003c/code\u003e\u003c/a\u003e Drop Python 3.9 support and update to PyPy 3.11 (\u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/608\"\u003e#608\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/4a22cf8993804aeede0c20b75bb1a29d3a99e9dc\"\u003e\u003ccode\u003e4a22cf8\u003c/code\u003e\u003c/a\u003e ci: enable testing on Python 3.14t (free-threaded) (\u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/588\"\u003e#588\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/e2e8e776b42e382ae38b44d3982dd649e7507dd4\"\u003e\u003ccode\u003ee2e8e77\u003c/code\u003e\u003c/a\u003e Fix license specifier (\u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/597\"\u003e#597\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/theskumar/python-dotenv/compare/v1.1.0...v1.2.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `requests` from 2.32.5 to 2.33.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/psf/requests/releases\"\u003erequests's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.33.0\u003c/h2\u003e\n\u003ch2\u003e2.33.0 (2026-03-25)\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eAnnouncements\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e📣 Requests is adding inline types. If you have a typed code base that uses Requests, please take a look at \u003ca href=\"https://redirect.github.com/psf/requests/issues/7271\"\u003e#7271\u003c/a\u003e. Give it a try, and report any gaps or feedback you may have in the issue. 📣\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eSecurity\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eCVE-2026-25645 \u003ccode\u003erequests.utils.extract_zipped_paths\u003c/code\u003e now extracts contents to a non-deterministic location to prevent malicious file replacement. This does not affect default usage of Requests, only applications calling the utility function directly.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eImprovements\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eMigrated to a PEP 517 build system using setuptools. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7012\"\u003e#7012\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eBugfixes\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eFixed an issue where an empty netrc entry could cause malformed authentication to be applied to Requests on Python 3.11+. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7205\"\u003e#7205\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eDeprecations\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eDropped support for Python 3.9 following its end of support. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7196\"\u003e#7196\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eDocumentation\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eVarious typo fixes and doc improvements.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/M0d3v1\"\u003e\u003ccode\u003e@​M0d3v1\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/psf/requests/pull/6865\"\u003epsf/requests#6865\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/aminvakil\"\u003e\u003ccode\u003e@​aminvakil\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/psf/requests/pull/7220\"\u003epsf/requests#7220\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/E8Price\"\u003e\u003ccode\u003e@​E8Price\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/psf/requests/pull/6960\"\u003epsf/requests#6960\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mitre88\"\u003e\u003ccode\u003e@​mitre88\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/psf/requests/pull/7244\"\u003epsf/requests#7244\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/magsen\"\u003e\u003ccode\u003e@​magsen\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/psf/requests/pull/6553\"\u003epsf/requests#6553\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Rohan5commit\"\u003e\u003ccode\u003e@​Rohan5commit\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/psf/requests/pull/7227\"\u003epsf/requests#7227\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/psf/requests/blob/main/HISTORY.md#2330-2026-03-25\"\u003ehttps://github.com/psf/requests/blob/main/HISTORY.md#2330-2026-03-25\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/psf/requests/blob/main/HISTORY.md\"\u003erequests's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e2.33.0 (2026-03-25)\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eAnnouncements\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e📣 Requests is adding inline types. If you have a typed code base that\nuses Requests, please take a look at \u003ca href=\"https://redirect.github.com/psf/requests/issues/7271\"\u003e#7271\u003c/a\u003e. Give it a try, and report\nany gaps or feedback you may have in the issue. 📣\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eSecurity\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eCVE-2026-25645 \u003ccode\u003erequests.utils.extract_zipped_paths\u003c/code\u003e now extracts\ncontents to a non-deterministic location to prevent malicious file\nreplacement. This does not affect default usage of Requests, only\napplications calling the utility function directly.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eImprovements\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eMigrated to a PEP 517 build system using setuptools. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7012\"\u003e#7012\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eBugfixes\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eFixed an issue where an empty netrc entry could cause\nmalformed authentication to be applied to Requests on\nPython 3.11+. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7205\"\u003e#7205\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eDeprecations\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eDropped support for Python 3.9 following its end of support. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7196\"\u003e#7196\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eDocumentation\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eVarious typo fixes and doc improvements.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/bc04dfd6dad4cb02cd92f5daa81eb562d280a761\"\u003e\u003ccode\u003ebc04dfd\u003c/code\u003e\u003c/a\u003e v2.33.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/66d21cb07bd6255b1280291c4fafb71803cdb3b7\"\u003e\u003ccode\u003e66d21cb\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/8b9bc8fc0f63be84602387913c4b689f19efd028\"\u003e\u003ccode\u003e8b9bc8f\u003c/code\u003e\u003c/a\u003e Move badges to top of README (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7293\"\u003e#7293\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/e331a288f369973f5de0ec8901c94cae4fa87286\"\u003e\u003ccode\u003ee331a28\u003c/code\u003e\u003c/a\u003e Remove unused extraction call (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7292\"\u003e#7292\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/753fd08c5eacce0aa0df73fe47e49525c67e0a29\"\u003e\u003ccode\u003e753fd08\u003c/code\u003e\u003c/a\u003e docs: fix FAQ grammar in httplib2 example\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/774a0b837a194ee885d4fdd9ca947900cc3daf71\"\u003e\u003ccode\u003e774a0b8\u003c/code\u003e\u003c/a\u003e docs(socks): same block as other sections\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/9c72a41bec8597f948c9d8caa5dc3f12273b3303\"\u003e\u003ccode\u003e9c72a41\u003c/code\u003e\u003c/a\u003e Bump github/codeql-action from 4.33.0 to 4.34.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/ebf71906798ec82f34e07d3168f8b8aecaf8a3be\"\u003e\u003ccode\u003eebf7190\u003c/code\u003e\u003c/a\u003e Bump github/codeql-action from 4.32.0 to 4.33.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/0e4ae38f0c93d4f92a96c774bd52c069d12a4798\"\u003e\u003ccode\u003e0e4ae38\u003c/code\u003e\u003c/a\u003e docs: exclude Response.is_permanent_redirect from API docs (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7244\"\u003e#7244\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/d568f47278492e630cc990a259047c67991d007a\"\u003e\u003ccode\u003ed568f47\u003c/code\u003e\u003c/a\u003e docs: clarify Quickstart POST example (\u003ca href=\"https://redirect.github.com/psf/requests/issues/6960\"\u003e#6960\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/psf/requests/compare/v2.32.5...v2.33.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `urllib3` from 2.6.3 to 2.7.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/urllib3/urllib3/releases\"\u003eurllib3's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e2.7.0\u003c/h2\u003e\n\u003ch2\u003e🚀 urllib3 is fundraising for HTTP/2 support\u003c/h2\u003e\n\u003cp\u003e\u003ca href=\"https://sethmlarson.dev/urllib3-is-fundraising-for-http2-support\"\u003eurllib3 is raising ~$40,000 USD\u003c/a\u003e to release HTTP/2 support and ensure long-term sustainable maintenance of the project after a sharp decline in financial support. If your company or organization uses Python and would benefit from HTTP/2 support in Requests, pip, cloud SDKs, and thousands of other projects \u003ca href=\"https://opencollective.com/urllib3\"\u003eplease consider contributing financially\u003c/a\u003e to ensure HTTP/2 support is developed sustainably and maintained for the long-haul.\u003c/p\u003e\n\u003cp\u003eThank you for your support.\u003c/p\u003e\n\u003ch2\u003eSecurity\u003c/h2\u003e\n\u003cp\u003eAddressed high-severity security issues. Impact was limited to specific use cases detailed in the accompanying advisories; overall user exposure was estimated to be marginal.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eDecompression-bomb safeguards of the streaming API were bypassed:\u003c/p\u003e\n\u003col\u003e\n\u003cli\u003eWhen \u003ccode\u003eHTTPResponse.drain_conn()\u003c/code\u003e was called after the response had been read and decompressed partially. (Reported by \u003ca href=\"https://github.com/Cycloctane\"\u003e\u003ccode\u003e@​Cycloctane\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eDuring the second \u003ccode\u003eHTTPResponse.read(amt=N)\u003c/code\u003e or \u003ccode\u003eHTTPResponse.stream(amt=N)\u003c/code\u003e call when the response was decompressed using the official \u003ca href=\"https://pypi.org/project/brotli/\"\u003eBrotli\u003c/a\u003e library. (Reported by \u003ca href=\"https://github.com/kimkou2024\"\u003e\u003ccode\u003e@​kimkou2024\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ol\u003e\n\u003cp\u003eSee GHSA-mf9v-mfxr-j63j for details.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eHTTP pools created using \u003ccode\u003eProxyManager.connection_from_url\u003c/code\u003e did not strip sensitive headers specified in \u003ccode\u003eRetry.remove_headers_on_redirect\u003c/code\u003e when redirecting to a different host. (GHSA-qccp-gfcp-xxvc reported by \u003ca href=\"https://github.com/christos-spearbit\"\u003e\u003ccode\u003e@​christos-spearbit\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eDeprecations and Removals\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUsed \u003ccode\u003eFutureWarning\u003c/code\u003e instead of \u003ccode\u003eDeprecationWarning\u003c/code\u003e for better visibility of existing deprecation notices. Rescheduled the removal of deprecated features to version 3.0. (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/3763\"\u003eurllib3/urllib3#3763\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRemoved support for end-of-life Python 3.9. (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/3720\"\u003eurllib3/urllib3#3720\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRemoved support for end-of-life PyPy3.10. (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/4979\"\u003eurllib3/urllib3#4979\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eBumped the minimum supported pyOpenSSL version to 19.0.0. (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/3777\"\u003eurllib3/urllib3#3777\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eBugfixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed a bug where \u003ccode\u003eHTTPResponse.read(amt=None)\u003c/code\u003e was ignoring decompressed data buffered from previous partial reads. (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/3636\"\u003eurllib3/urllib3#3636\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed a bug where \u003ccode\u003eHTTPResponse.read()\u003c/code\u003e could cache only part of the response after a partial read when \u003ccode\u003ecache_content=True\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/4967\"\u003eurllib3/urllib3#4967\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eHTTPResponse.stream()\u003c/code\u003e and \u003ccode\u003eHTTPResponse.read_chunked()\u003c/code\u003e to handle \u003ccode\u003eamt=0\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/3793\"\u003eurllib3/urllib3#3793\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eUpdated \u003ccode\u003e_TYPE_BODY\u003c/code\u003e type alias to include missing \u003ccode\u003eIterable[str]\u003c/code\u003e, matching the documented and runtime behavior of chunked request bodies. (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/3798\"\u003eurllib3/urllib3#3798\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eLocationParseError\u003c/code\u003e when paths resembling schemeless URIs were passed to \u003ccode\u003eHTTPConnectionPool.urlopen()\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/3352\"\u003eurllib3/urllib3#3352\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eBaseHTTPResponse.readinto()\u003c/code\u003e type annotation to accept \u003ccode\u003ememoryview\u003c/code\u003e in addition to \u003ccode\u003ebytearray\u003c/code\u003e, matching the \u003ccode\u003eio.RawIOBase.readinto\u003c/code\u003e contract and enabling use with \u003ccode\u003eio.BufferedReader\u003c/code\u003e without type errors. (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/3764\"\u003eurllib3/urllib3#3764\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/urllib3/urllib3/blob/main/CHANGES.rst\"\u003eurllib3's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003e2.7.0 (2026-05-07)\u003c/h1\u003e\n\u003ch2\u003eSecurity\u003c/h2\u003e\n\u003cp\u003eAddressed high-severity security issues.\nImpact was limited to specific use cases detailed in the accompanying\nadvisories; overall user exposure was estimated to be marginal.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eDecompression-bomb safeguards of the streaming API were bypassed:\u003c/p\u003e\n\u003col\u003e\n\u003cli\u003eWhen \u003ccode\u003eHTTPResponse.drain_conn()\u003c/code\u003e was called after the response had been\nread and decompressed partially.\u003c/li\u003e\n\u003cli\u003eDuring the second \u003ccode\u003eHTTPResponse.read(amt=N)\u003c/code\u003e or\n\u003ccode\u003eHTTPResponse.stream(amt=N)\u003c/code\u003e call when the response was decompressed\nusing the official \u003ccode\u003eBrotli \u0026lt;https://pypi.org/project/brotli/\u0026gt;\u003c/code\u003e__ library.\u003c/li\u003e\n\u003c/ol\u003e\n\u003cp\u003eSee \u003ccode\u003eGHSA-mf9v-mfxr-j63j \u0026lt;https://github.com/urllib3/urllib3/security/advisories/GHSA-mf9v-mfxr-j63j\u0026gt;\u003c/code\u003e__\nfor details.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eHTTP pools created using \u003ccode\u003eProxyManager.connection_from_url\u003c/code\u003e did not strip\nsensitive headers specified in \u003ccode\u003eRetry.remove_headers_on_redirect\u003c/code\u003e when\nredirecting to a different host.\n(\u003ccode\u003eGHSA-qccp-gfcp-xxvc \u0026lt;https://github.com/urllib3/urllib3/security/advisories/GHSA-qccp-gfcp-xxvc\u0026gt;\u003c/code\u003e__)\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eDeprecations and Removals\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUsed \u003ccode\u003eFutureWarning\u003c/code\u003e instead of \u003ccode\u003eDeprecationWarning\u003c/code\u003e for better\nvisibility of existing deprecation notices. Rescheduled the removal of\ndeprecated features to version 3.0.\n(\u003ccode\u003e[#3763](https://github.com/urllib3/urllib3/issues/3763) \u0026lt;https://github.com/urllib3/urllib3/issues/3763\u0026gt;\u003c/code\u003e__)\u003c/li\u003e\n\u003cli\u003eRemoved support for end-of-life Python 3.9.\n(\u003ccode\u003e[#3720](https://github.com/urllib3/urllib3/issues/3720) \u0026lt;https://github.com/urllib3/urllib3/issues/3720\u0026gt;\u003c/code\u003e__)\u003c/li\u003e\n\u003cli\u003eRemoved support for end-of-life PyPy3.10.\n(\u003ccode\u003e[#4979](https://github.com/urllib3/urllib3/issues/4979) \u0026lt;https://github.com/urllib3/urllib3/issues/4979\u0026gt;\u003c/code\u003e__)\u003c/li\u003e\n\u003cli\u003eBumped the minimum supported pyOpenSSL version to 19.0.0.\n(\u003ccode\u003e[#3777](https://github.com/urllib3/urllib3/issues/3777) \u0026lt;https://github.com/urllib3/urllib3/issues/3777\u0026gt;\u003c/code\u003e__)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eBugfixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed a bug where \u003ccode\u003eHTTPResponse.read(amt=None)\u003c/code\u003e was ignoring decompressed\ndata buffered from previous partial reads.\n(\u003ccode\u003e[#3636](https://github.com/urllib3/urllib3/issues/3636) \u0026lt;https://github.com/urllib3/urllib3/issues/3636\u0026gt;\u003c/code\u003e__)\u003c/li\u003e\n\u003cli\u003eFixed a bug where \u003ccode\u003eHTTPResponse.read()\u003c/code\u003e could cache only part of the\nresponse after a partial read when \u003ccode\u003ecache_content=True\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/urllib3/urllib3/commit/9a950b92d999f906b6020bb2d1076ee56cddd5d2\"\u003e\u003ccode\u003e9a950b9\u003c/code\u003e\u003c/a\u003e Release 2.7.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/urllib3/urllib3/commit/5ec0de499b9166ca71c65ab04f2a7e4eb0d66fcc\"\u003e\u003ccode\u003e5ec0de4\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/urllib3/urllib3/commit/2bdcc44d1e163fb5cc48a8662425e35e15adfe6a\"\u003e\u003ccode\u003e2bdcc44\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/urllib3/urllib3/commit/f45b0df09d8620ac6ed0491eb9362c8c87b7bc2c\"\u003e\u003ccode\u003ef45b0...\n\n_Description has been truncated_","html_url":"https://github.com/dabelstech-creator/cdp-sdk/pull/2","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/dabelstech-creator%2Fcdp-sdk/issues/2","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/2/packages"},{"uuid":"5506554398","node_id":"PR_kwDOURkMPc8AAAABEKy_IQ","number":2,"state":"open","title":"build(deps): bump the pip group across 1 directory with 3 updates","user":"dependabot[bot]","labels":["dependencies","python"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-19T00:45:27.000Z","updated_at":"2026-09-19T00:45:34.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"build(deps): bump","group_name":"pip","update_count":3,"packages":[{"name":"pillow","old_version":"12.2.0","new_version":"12.3.0","repository_url":"https://github.com/python-pillow/Pillow"},{"name":"aiohttp","old_version":"3.14.1","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"anyio","old_version":"4.13.0","new_version":"4.14.2","repository_url":"https://github.com/agronholm/anyio"}],"path":null,"ecosystem":"pip"},"body":"Bumps the pip group with 3 updates in the /examples/wine-recommender directory: [pillow](https://github.com/python-pillow/Pillow), [aiohttp](https://github.com/aio-libs/aiohttp) and [anyio](https://github.com/agronholm/anyio).\n\nUpdates `pillow` from 12.2.0 to 12.3.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/python-pillow/Pillow/releases\"\u003epillow's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e12.3.0\u003c/h2\u003e\n\u003cp\u003e\u003ca href=\"https://pillow.readthedocs.io/en/stable/releasenotes/12.3.0.html\"\u003ehttps://pillow.readthedocs.io/en/stable/releasenotes/12.3.0.html\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eRemovals\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRemove non-image ImageCms modes \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9697\"\u003e#9697\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eDocumentation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd release notes for SBOM and performance improvements \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9747\"\u003e#9747\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdd security release notes \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9741\"\u003e#9741\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdd release notes for Python 3.15 beta wheels \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9696\"\u003e#9696\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eImageFont can also be used with ImageText \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9597\"\u003e#9597\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdditional guidelines for security reports \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9659\"\u003e#9659\u003c/a\u003e [\u003ca href=\"https://github.com/wiredfool\"\u003e\u003ccode\u003e@​wiredfool\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eFixed typo \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9636\"\u003e#9636\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdded CVEs to 12.2.0 release notes \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9591\"\u003e#9591\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eRevise development support information in README \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9583\"\u003e#9583\u003c/a\u003e [\u003ca href=\"https://github.com/aclark4life\"\u003e\u003ccode\u003e@​aclark4life\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdd INCIDENT_RESPONSE.md \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9555\"\u003e#9555\u003c/a\u003e [\u003ca href=\"https://github.com/aclark4life\"\u003e\u003ccode\u003e@​aclark4life\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdd STRIDE threat model to security docs \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9562\"\u003e#9562\u003c/a\u003e [\u003ca href=\"https://github.com/aclark4life\"\u003e\u003ccode\u003e@​aclark4life\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdd CVEs to 12.2.0 release notes \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9556\"\u003e#9556\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate README with revised security policy \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9553\"\u003e#9553\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate security policy \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9552\"\u003e#9552\u003c/a\u003e [\u003ca href=\"https://github.com/aclark4life\"\u003e\u003ccode\u003e@​aclark4life\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate macOS tested Python versions \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9534\"\u003e#9534\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eDependencies\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate dependency harfbuzz to v14.2.1 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9720\"\u003e#9720\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency mypy to v2 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9653\"\u003e#9653\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency cibuildwheel to v4 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9665\"\u003e#9665\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate github-actions \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9655\"\u003e#9655\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency libavif to v1.4.2 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9652\"\u003e#9652\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency lcms2 to v2.19.1 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9651\"\u003e#9651\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency check-jsonschema to v0.37.2 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9650\"\u003e#9650\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate google/oss-fuzz digest to d872252 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9614\"\u003e#9614\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency lcms2 to v2.19 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9609\"\u003e#9609\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency libpng to v1.6.58 - autoclosed \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9608\"\u003e#9608\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency harfbuzz to v14 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9610\"\u003e#9610\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency mypy to v1.20.2 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9599\"\u003e#9599\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate github-actions \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9611\"\u003e#9611\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency cibuildwheel to v3.4.1 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9607\"\u003e#9607\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eMove dependency versions to single JSON and enable Renovate \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9559\"\u003e#9559\u003c/a\u003e [\u003ca href=\"https://github.com/hugovk\"\u003e\u003ccode\u003e@​hugovk\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdated raqm to 0.10.5 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9557\"\u003e#9557\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency cibuildwheel to v3.4.0 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9532\"\u003e#9532\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eTesting\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRemove matrix.os from benchmark \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9735\"\u003e#9735\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eRemove references to libavif patch \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9734\"\u003e#9734\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdd benchmark tests \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9654\"\u003e#9654\u003c/a\u003e [\u003ca href=\"https://github.com/akx\"\u003e\u003ccode\u003e@​akx\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUse reshape() instead of setting NumPy array shape directly \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9728\"\u003e#9728\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/bb1d8e8ab8d29048624d96e3ee53cecf7c13d13d\"\u003e\u003ccode\u003ebb1d8e8\u003c/code\u003e\u003c/a\u003e 12.3.0 version bump\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/e63fc481dc2e07e21d5403deafb8f1ed98a513af\"\u003e\u003ccode\u003ee63fc48\u003c/code\u003e\u003c/a\u003e Add release notes for SBOM and performance improvements (\u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9747\"\u003e#9747\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/13b701bbab291eec4bc87ea17ba06c94e5fe3054\"\u003e\u003ccode\u003e13b701b\u003c/code\u003e\u003c/a\u003e Add release notes for \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9679\"\u003e#9679\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/5564ca72fcd59d040e270af5dcf17a0d7161c364\"\u003e\u003ccode\u003e5564ca7\u003c/code\u003e\u003c/a\u003e List methods\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/a0920fd384f800b5d0ba3dd29ecdeae4f1d4043b\"\u003e\u003ccode\u003ea0920fd\u003c/code\u003e\u003c/a\u003e Speed up ImageChops operations (\u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9738\"\u003e#9738\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/07e9a6cd5336dc6cf8cae9165cd70cdd2b3e42fc\"\u003e\u003ccode\u003e07e9a6c\u003c/code\u003e\u003c/a\u003e Speed up \u003ccode\u003eImage.filter()\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9736\"\u003e#9736\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/a94578cf9649ea13e426cf7fb2b71b39ffc0dd50\"\u003e\u003ccode\u003ea94578c\u003c/code\u003e\u003c/a\u003e Speed up \u003ccode\u003eImage.getchannel()\u003c/code\u003e, \u003ccode\u003eImage.merge()\u003c/code\u003e, \u003ccode\u003eImage.putalpha()\u003c/code\u003e and `Image...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/53e02c43c919d149b2a154a5180079f9df18fbbb\"\u003e\u003ccode\u003e53e02c4\u003c/code\u003e\u003c/a\u003e Speed up \u003ccode\u003eImage.fill()\u003c/code\u003e, \u003ccode\u003eImage.linear_gradient()\u003c/code\u003e and `Image.radial_gradient...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/af037475be8634ba739744243164ba9e2c8346a6\"\u003e\u003ccode\u003eaf03747\u003c/code\u003e\u003c/a\u003e Speed up \u003ccode\u003eImage.resample()\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9739\"\u003e#9739\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/5c9ca56c3e5fba52b647809fbb0986c87e73a571\"\u003e\u003ccode\u003e5c9ca56\u003c/code\u003e\u003c/a\u003e Speed up \u003ccode\u003ealpha_composite\u003c/code\u003e, \u003ccode\u003ematrix\u003c/code\u003e, \u003ccode\u003enegative\u003c/code\u003e, \u003ccode\u003equantize\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9740\"\u003e#9740\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/python-pillow/Pillow/compare/12.2.0...12.3.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `aiohttp` from 3.14.1 to 3.14.3\nUpdates `anyio` from 4.13.0 to 4.14.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/agronholm/anyio/releases\"\u003eanyio's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e4.14.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eChanged \u003ccode\u003eByteReceiveStream.receive()\u003c/code\u003e implementations to raise a \u003ccode\u003eValueError\u003c/code\u003e when \u003ccode\u003emax_bytes\u003c/code\u003e is not a positive integer (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1191\"\u003e#1191\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eCapacityLimiter.total_tokens\u003c/code\u003e rejecting \u003ccode\u003efloat(\u0026quot;inf\u0026quot;)\u003c/code\u003e when the limiter was instantiated outside of an event loop. The adapter setter checked for infinity by identity (\u003ccode\u003evalue is math.inf\u003c/code\u003e), so only the exact \u003ccode\u003emath.inf\u003c/code\u003e singleton was accepted, while every backend setter (using \u003ccode\u003emath.isinf()\u003c/code\u003e) accepts any positive infinity (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1189\"\u003e#1189\u003c/a\u003e; PR by \u003ca href=\"https://github.com/greymoth-jp\"\u003e\u003ccode\u003e@​greymoth-jp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eto_process.run_sync()\u003c/code\u003e deadlocking when the worker function writes enough data to \u003ccode\u003esys.stderr\u003c/code\u003e to fill the (undrained) pipe buffer. The worker process now redirects \u003ccode\u003esys.stderr\u003c/code\u003e to \u003ccode\u003eos.devnull\u003c/code\u003e as well, matching the documented behavior\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eTLSStream.wrap()\u003c/code\u003e matching an internationalized (unicode) host name against the peer certificate using IDNA 2003 (via the standard library) instead of IDNA 2008, which could cause the host name to be matched against the wrong certificate (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1208\"\u003e#1208\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eanyio.open_process()\u003c/code\u003e (and \u003ccode\u003erun_process()\u003c/code\u003e) ignoring the \u003ccode\u003eextra_groups\u003c/code\u003e argument, as it mistakenly passed the value of the \u003ccode\u003egroup\u003c/code\u003e argument instead (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1209\"\u003e#1209\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eCapacityLimiter.acquire_nowait()\u003c/code\u003e and \u003ccode\u003eCapacityLimiter.acquire_nowait_on_behalf_of()\u003c/code\u003e raising \u003ccode\u003etrio.WouldBlock\u003c/code\u003e instead of \u003ccode\u003eanyio.WouldBlock\u003c/code\u003e on the \u003ccode\u003etrio\u003c/code\u003e backend when there are no tokens available (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1218\"\u003e#1218\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eCapacityLimiter\u003c/code\u003e on the asyncio backend over-granting tokens (\u003ccode\u003eborrowed_tokens\u003c/code\u003e exceeding \u003ccode\u003etotal_tokens\u003c/code\u003e and \u003ccode\u003eavailable_tokens\u003c/code\u003e going negative) when a non-blocking acquire was made in the window between a token being released and the notified waiter resuming. The freed token is now reserved for the woken waiter right away, so the non-blocking acquire correctly raises \u003ccode\u003eWouldBlock\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1170\"\u003e#1170\u003c/a\u003e; PR by \u003ca href=\"https://github.com/gaoflow\"\u003e\u003ccode\u003e@​gaoflow\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed unnecessary CPU spin when delivering cancellation from \u003ccode\u003eCancelScope\u003c/code\u003e on asyncio under certain conditions, including improper cancel scope nesting (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1111\"\u003e#1111\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.14.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed teardown of higher-scoped async fixtures failing on asyncio with \u003ccode\u003eRuntimeError: Attempted to exit cancel scope in a different task than it was entered in\u003c/code\u003e when an async test raise an outcome exception (e.g., \u003ccode\u003epytest.skip()\u003c/code\u003e, \u003ccode\u003epytest.xfail()\u003c/code\u003e, or \u003ccode\u003epytest.fail()\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1179\"\u003e#1179\u003c/a\u003e; PR by \u003ca href=\"https://github.com/EmmanuelNiyonshuti\"\u003e\u003ccode\u003e@​EmmanuelNiyonshuti\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eCapacityLimiter.total_tokens\u003c/code\u003e rejecting a value of \u003ccode\u003e0\u003c/code\u003e when the limiter was instantiated outside of an event loop, contradicting the documented behavior of allowing 0 total tokens (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1183\"\u003e#1183\u003c/a\u003e; PR by \u003ca href=\"https://github.com/nyxst4ck\"\u003e\u003ccode\u003e@​nyxst4ck\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.14.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eAdded support for Python 3.15\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAdded an asynchronous implementation of the \u003ccode\u003eitertools\u003c/code\u003e module (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/998\"\u003e#998\u003c/a\u003e; PR by \u003ca href=\"https://github.com/11kkw\"\u003e\u003ccode\u003e@​11kkw\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAdded the \u003ccode\u003elocal_port\u003c/code\u003e parameter to \u003ccode\u003econnect_tcp()\u003c/code\u003e to allow binding to a specific local port before connecting (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1067\"\u003e#1067\u003c/a\u003e; PR by \u003ca href=\"https://github.com/nullwiz\"\u003e\u003ccode\u003e@​nullwiz\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAdded support for custom capacity limiters in async path and file I/O functions and classes\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAdded the \u003ccode\u003ecreate_task()\u003c/code\u003e task group method for easier asyncio migration (returns a \u003ccode\u003eTaskHandle\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1098\"\u003e#1098\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eChanged \u003ccode\u003eTaskGroup.start_soon()\u003c/code\u003e to return a \u003ccode\u003eTaskHandle\u003c/code\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAdded an option for \u003ccode\u003eTaskGroup.start()\u003c/code\u003e to return a \u003ccode\u003eTaskHandle\u003c/code\u003e (which then contains the start value in the \u003ccode\u003estart_value\u003c/code\u003e property)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAdded the \u003ccode\u003ecancel()\u003c/code\u003e convenience method to \u003ccode\u003eTaskGroup\u003c/code\u003e as a shortcut for cancelling the task group's cancel scope\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eImproved the error message when a known backend is not installed to suggest the install command (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1115\"\u003e#1115\u003c/a\u003e; PR by \u003ca href=\"https://github.com/EmmanuelNiyonshuti\"\u003e\u003ccode\u003e@​EmmanuelNiyonshuti\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eImproved \u003ccode\u003eanyio.Path\u003c/code\u003e to preserve subclass types by returning \u003ccode\u003eSelf\u003c/code\u003e in methods that return path objects (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1130\"\u003e#1130\u003c/a\u003e; PR by \u003ca href=\"https://github.com/EmmanuelNiyonshuti\"\u003e\u003ccode\u003e@​EmmanuelNiyonshuti\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eChanged the parameter type annotation in \u003ccode\u003eanyio.Path.write_bytes()\u003c/code\u003e to accept any \u003ccode\u003eReadableBuffer\u003c/code\u003e, thus allowing it to accept \u003ccode\u003ebytearray\u003c/code\u003e and \u003ccode\u003ememoryview\u003c/code\u003e to match \u003ccode\u003epathlib.Path.write_bytes()\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1135\"\u003e#1135\u003c/a\u003e; PR by \u003ca href=\"https://github.com/SAY-5\"\u003e\u003ccode\u003e@​SAY-5\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eChanged several type annotations to only accept callables returning coroutine-like objects instead of arbitrary awaitables:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eTaskGroup.start_soon()\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eTaskGroup.start()\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eanyio.from_thread.run()\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThis reverts an earlier change from v3.7.0 which was made in error. (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1153\"\u003e#1153\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eChanged \u003ccode\u003eanyio.run\u003c/code\u003e to support callables returning arbitrary awaitables at runtime on all backends. Previously, this only worked on asyncio (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1171\"\u003e#1171\u003c/a\u003e; PR by \u003ca href=\"https://github.com/gschaffner\"\u003e\u003ccode\u003e@​gschaffner\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eChanged several classes (and their subclasses) to have \u003ccode\u003e__slots__\u003c/code\u003e (with \u003ccode\u003e__weakref__\u003c/code\u003e):\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eanyio.CancelScope\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/c384f99687c64c59ed8a11c3a0f11a2d57daff71\"\u003e\u003ccode\u003ec384f99\u003c/code\u003e\u003c/a\u003e Bumped up the version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/dbba29d1ade7936f18fb71ba24aa92978673482a\"\u003e\u003ccode\u003edbba29d\u003c/code\u003e\u003c/a\u003e Fixed 100% CPU spin on cancel scope misuse (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1217\"\u003e#1217\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/6bbc6c33caabc13af5bc4256f745027cf8d5d7b8\"\u003e\u003ccode\u003e6bbc6c3\u003c/code\u003e\u003c/a\u003e Fix CapacityLimiter over-granting tokens on asyncio (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1172\"\u003e#1172\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/6f82b2537cbbe98f3df3f295499056ab7de0b15b\"\u003e\u003ccode\u003e6f82b25\u003c/code\u003e\u003c/a\u003e Refactored TestTLSStream.test_receive_invalid_max_bytes() to be less flaky\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/be24b0414f67f604bcbdd5ea3bcc56ab920d872e\"\u003e\u003ccode\u003ebe24b04\u003c/code\u003e\u003c/a\u003e Relaxed timeouts to fix test flakiness\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/81135065749b4f60c06619b9caaf0a11871c1ddf\"\u003e\u003ccode\u003e8113506\u003c/code\u003e\u003c/a\u003e Fix test flakiness caused by slow callback duration logging\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/1e988b617b69588e33fecb75e36a9837245f562f\"\u003e\u003ccode\u003e1e988b6\u003c/code\u003e\u003c/a\u003e Fixed CapacityLimiter raising trio.WouldBlock instead of anyio.WouldBlock (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1\"\u003e#1\u003c/a\u003e...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/44713f345cd29dd4e7d76553c134543a1296cc62\"\u003e\u003ccode\u003e44713f3\u003c/code\u003e\u003c/a\u003e Pin setup-uv to a commit sha across downstream jobs (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1213\"\u003e#1213\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/f1b7301c8264b0d2e8d24a5788fd29e93dea4040\"\u003e\u003ccode\u003ef1b7301\u003c/code\u003e\u003c/a\u003e Fixed stderr writes in a worker subprocess causing a deadlock (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1207\"\u003e#1207\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/212be93c2cf2c841e753e95e5e2c543ee7feca90\"\u003e\u003ccode\u003e212be93\u003c/code\u003e\u003c/a\u003e Fix flaky test_tcp_listener_same_port using a hardcoded port (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1206\"\u003e#1206\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/agronholm/anyio/compare/4.13.0...4.14.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/dabelstech-creator/sie/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/dabelstech-creator/sie/pull/2","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/dabelstech-creator%2Fsie/issues/2","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/2/packages"},{"uuid":"5497591666","node_id":"PR_kwDONPLcn88AAAABEDfUKA","number":57,"state":"closed","title":"build(deps): bump aiohttp from 3.14.1 to 3.14.3 in the pip group across 1 directory","user":"dependabot[bot]","labels":["invalid","dependencies","python"],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":"2026-09-18T08:47:20.000Z","author_association":null,"state_reason":null,"created_at":"2026-09-18T08:47:08.000Z","updated_at":"2026-09-18T08:47:29.000Z","time_to_close":12,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"build(deps)","packages":[{"name":"aiohttp","old_version":"3.14.1","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"}],"path":"the pip group across 1 directory","ecosystem":"pip"},"body":"Bumps the pip group with 1 update in the / directory: [aiohttp](https://github.com/aio-libs/aiohttp).\n\nUpdates `aiohttp` from 3.14.1 to 3.14.3\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=aiohttp\u0026package-manager=pip\u0026previous-version=3.14.1\u0026new-version=3.14.3)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/Jackie264/iptv-api/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/Jackie264/iptv-api/pull/57","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/Jackie264%2Fiptv-api/issues/57","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/57/packages"},{"uuid":"5495148202","node_id":"PR_kwDOT1KaUM8AAAABEBip8g","number":16,"state":"closed","title":"build(deps): bump the pip group across 33 directories with 3 updates","user":"dependabot[bot]","labels":["dependencies","python"],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":"2026-09-18T03:04:26.000Z","author_association":null,"state_reason":null,"created_at":"2026-09-18T03:02:53.000Z","updated_at":"2026-09-18T03:04:28.000Z","time_to_close":93,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"build(deps): bump","group_name":"pip","update_count":3,"packages":[{"name":"aiohttp","old_version":"3.14.1","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"soupsieve","old_version":"2.8.4","new_version":"2.9","repository_url":"https://github.com/facelessuser/soupsieve"},{"name":"aiohttp","old_version":"3.14.1","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"soupsieve","old_version":"2.8.4","new_version":"2.9","repository_url":"https://github.com/facelessuser/soupsieve"},{"name":"tornado","old_version":"6.5.7","new_version":"6.5.8","repository_url":"https://github.com/tornadoweb/tornado"},{"name":"aiohttp","old_version":"3.14.1","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"aiohttp","old_version":"3.14.1","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"aiohttp","old_version":"3.14.1","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"aiohttp","old_version":"3.14.1","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"aiohttp","old_version":"3.14.1","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"aiohttp","old_version":"3.14.1","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"aiohttp","old_version":"3.14.1","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"aiohttp","old_version":"3.14.1","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"aiohttp","old_version":"3.14.1","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"aiohttp","old_version":"3.14.1","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"aiohttp","old_version":"3.14.1","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"soupsieve","old_version":"2.8.4","new_version":"2.9","repository_url":"https://github.com/facelessuser/soupsieve"},{"name":"aiohttp","old_version":"3.14.1","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"aiohttp","old_version":"3.14.1","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"soupsieve","old_version":"2.8.4","new_version":"2.9","repository_url":"https://github.com/facelessuser/soupsieve"},{"name":"aiohttp","old_version":"3.14.1","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"aiohttp","old_version":"3.14.1","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"aiohttp","old_version":"3.14.1","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"aiohttp","old_version":"3.14.1","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"aiohttp","old_version":"3.14.1","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"aiohttp","old_version":"3.14.1","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"aiohttp","old_version":"3.14.1","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"aiohttp","old_version":"3.14.1","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"aiohttp","old_version":"3.14.1","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"soupsieve","old_version":"2.8.4","new_version":"2.9","repository_url":"https://github.com/facelessuser/soupsieve"},{"name":"aiohttp","old_version":"3.14.1","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"aiohttp","old_version":"3.14.1","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"aiohttp","old_version":"3.14.1","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"aiohttp","old_version":"3.14.1","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"aiohttp","old_version":"3.14.1","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"aiohttp","old_version":"3.14.1","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"aiohttp","old_version":"3.14.1","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"aiohttp","old_version":"3.14.1","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"soupsieve","old_version":"2.8.4","new_version":"2.9","repository_url":"https://github.com/facelessuser/soupsieve"}],"path":null,"ecosystem":"pip"},"body":"Bumps the pip group with 2 updates in the /cli directory: [aiohttp](https://github.com/aio-libs/aiohttp) and [soupsieve](https://github.com/facelessuser/soupsieve).\nBumps the pip group with 2 updates in the /openbb_platform directory: [aiohttp](https://github.com/aio-libs/aiohttp) and [soupsieve](https://github.com/facelessuser/soupsieve).\nBumps the pip group with 1 update in the /openbb_platform/extensions/devtools directory: [tornado](https://github.com/tornadoweb/tornado).\nBumps the pip group with 1 update in the /openbb_platform/providers/biztoc directory: [aiohttp](https://github.com/aio-libs/aiohttp).\nBumps the pip group with 1 update in the /openbb_platform/providers/bls directory: [aiohttp](https://github.com/aio-libs/aiohttp).\nBumps the pip group with 1 update in the /openbb_platform/providers/cboe directory: [aiohttp](https://github.com/aio-libs/aiohttp).\nBumps the pip group with 1 update in the /openbb_platform/providers/cftc directory: [aiohttp](https://github.com/aio-libs/aiohttp).\nBumps the pip group with 1 update in the /openbb_platform/providers/congress_gov directory: [aiohttp](https://github.com/aio-libs/aiohttp).\nBumps the pip group with 1 update in the /openbb_platform/providers/deribit directory: [aiohttp](https://github.com/aio-libs/aiohttp).\nBumps the pip group with 1 update in the /openbb_platform/providers/ecb directory: [aiohttp](https://github.com/aio-libs/aiohttp).\nBumps the pip group with 1 update in the /openbb_platform/providers/econdb directory: [aiohttp](https://github.com/aio-libs/aiohttp).\nBumps the pip group with 1 update in the /openbb_platform/providers/eia directory: [aiohttp](https://github.com/aio-libs/aiohttp).\nBumps the pip group with 1 update in the /openbb_platform/providers/famafrench directory: [aiohttp](https://github.com/aio-libs/aiohttp).\nBumps the pip group with 2 updates in the /openbb_platform/providers/federal_reserve directory: [aiohttp](https://github.com/aio-libs/aiohttp) and [soupsieve](https://github.com/facelessuser/soupsieve).\nBumps the pip group with 1 update in the /openbb_platform/providers/finra directory: [aiohttp](https://github.com/aio-libs/aiohttp).\nBumps the pip group with 2 updates in the /openbb_platform/providers/finviz directory: [aiohttp](https://github.com/aio-libs/aiohttp) and [soupsieve](https://github.com/facelessuser/soupsieve).\nBumps the pip group with 1 update in the /openbb_platform/providers/fmp directory: [aiohttp](https://github.com/aio-libs/aiohttp).\nBumps the pip group with 1 update in the /openbb_platform/providers/fred directory: [aiohttp](https://github.com/aio-libs/aiohttp).\nBumps the pip group with 1 update in the /openbb_platform/providers/government_us directory: [aiohttp](https://github.com/aio-libs/aiohttp).\nBumps the pip group with 1 update in the /openbb_platform/providers/imf directory: [aiohttp](https://github.com/aio-libs/aiohttp).\nBumps the pip group with 1 update in the /openbb_platform/providers/intrinio directory: [aiohttp](https://github.com/aio-libs/aiohttp).\nBumps the pip group with 1 update in the /openbb_platform/providers/multpl directory: [aiohttp](https://github.com/aio-libs/aiohttp).\nBumps the pip group with 1 update in the /openbb_platform/providers/nasdaq directory: [aiohttp](https://github.com/aio-libs/aiohttp).\nBumps the pip group with 1 update in the /openbb_platform/providers/oecd directory: [aiohttp](https://github.com/aio-libs/aiohttp).\nBumps the pip group with 2 updates in the /openbb_platform/providers/sec directory: [aiohttp](https://github.com/aio-libs/aiohttp) and [soupsieve](https://github.com/facelessuser/soupsieve).\nBumps the pip group with 1 update in the /openbb_platform/providers/seeking_alpha directory: [aiohttp](https://github.com/aio-libs/aiohttp).\nBumps the pip group with 1 update in the /openbb_platform/providers/stockgrid directory: [aiohttp](https://github.com/aio-libs/aiohttp).\nBumps the pip group with 1 update in the /openbb_platform/providers/tiingo directory: [aiohttp](https://github.com/aio-libs/aiohttp).\nBumps the pip group with 1 update in the /openbb_platform/providers/tmx directory: [aiohttp](https://github.com/aio-libs/aiohttp).\nBumps the pip group with 1 update in the /openbb_platform/providers/tradier directory: [aiohttp](https://github.com/aio-libs/aiohttp).\nBumps the pip group with 1 update in the /openbb_platform/providers/tradingeconomics directory: [aiohttp](https://github.com/aio-libs/aiohttp).\nBumps the pip group with 1 update in the /openbb_platform/providers/wsj directory: [aiohttp](https://github.com/aio-libs/aiohttp).\nBumps the pip group with 2 updates in the /openbb_platform/providers/yfinance directory: [aiohttp](https://github.com/aio-libs/aiohttp) and [soupsieve](https://github.com/facelessuser/soupsieve).\n\nUpdates `aiohttp` from 3.14.1 to 3.14.3\nUpdates `soupsieve` from 2.8.4 to 2.9\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/facelessuser/soupsieve/releases\"\u003esoupsieve's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e2.9\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eNEW\u003c/strong\u003e: Drop Python 3.9 support.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eNEW\u003c/strong\u003e: Lazy compile selector patterns to improve initial import speed.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eFIX\u003c/strong\u003e: Correct \u003ccode\u003e:nth-child\u003c/code\u003e/\u003ccode\u003e:nth-of-type\u003c/code\u003e (and \u003ccode\u003e-last-\u003c/code\u003e variants) for \u003ccode\u003eAn+B\u003c/code\u003e values whose sequence steps onto\nindex 0 or onto the last child (e.g. \u003ccode\u003e:nth-child(2n-2)\u003c/code\u003e, \u003ccode\u003e:nth-child(n-1)\u003c/code\u003e, \u003ccode\u003e:nth-child(n+5)\u003c/code\u003e), which previously\nmatched the wrong elements or nothing at all (\u003ca href=\"https://github.com/gaoflow\"\u003e\u003ccode\u003e@​gaoflow\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eFIX\u003c/strong\u003e: More efficient CSS ID matching (\u003ca href=\"https://github.com/kaimandalic\"\u003e\u003ccode\u003e@​kaimandalic\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eFIX\u003c/strong\u003e: Fix inefficient trimming of comments and white space (\u003ca href=\"https://github.com/kaimandalic\"\u003e\u003ccode\u003e@​kaimandalic\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/8763f914472fc83652babda708bed5c8ef287004\"\u003e\u003ccode\u003e8763f91\u003c/code\u003e\u003c/a\u003e Format changelog message\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/cf198fcddc9230f06ed39f974eba0ce076b85cda\"\u003e\u003ccode\u003ecf198fc\u003c/code\u003e\u003c/a\u003e Fix inefficient trimming of comments and white space\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/ce44e4996e6632871c18cdd7a7fb641be8ef34ef\"\u003e\u003ccode\u003ece44e49\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/751c57b2c7e978e206b94b7dba17f8e2af392e19\"\u003e\u003ccode\u003e751c57b\u003c/code\u003e\u003c/a\u003e Fix :nth-child/:nth-of-type matching for An+B index boundaries (\u003ca href=\"https://redirect.github.com/facelessuser/soupsieve/issues/297\"\u003e#297\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/08e9ede4dcfafef860155319ef5eb9708e75d10b\"\u003e\u003ccode\u003e08e9ede\u003c/code\u003e\u003c/a\u003e Drop Python 3.9\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/d6e68303a6c3e0e410530939b92955ba24a07a81\"\u003e\u003ccode\u003ed6e6830\u003c/code\u003e\u003c/a\u003e Rework selector mapping\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/d2d1581fe275f89cb2e792589fed770aeb9e99b3\"\u003e\u003ccode\u003ed2d1581\u003c/code\u003e\u003c/a\u003e Utilize property for accessing lazy regular expression pattern\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/b8701dec25c84a3910fd9a03222a3804fa119a1d\"\u003e\u003ccode\u003eb8701de\u003c/code\u003e\u003c/a\u003e Build patterns and regexes lazily in css_parser (\u003ca href=\"https://redirect.github.com/facelessuser/soupsieve/issues/296\"\u003e#296\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/facelessuser/soupsieve/compare/2.8.4...2.9\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `aiohttp` from 3.14.1 to 3.14.3\nUpdates `soupsieve` from 2.8.4 to 2.9\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/facelessuser/soupsieve/releases\"\u003esoupsieve's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e2.9\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eNEW\u003c/strong\u003e: Drop Python 3.9 support.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eNEW\u003c/strong\u003e: Lazy compile selector patterns to improve initial import speed.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eFIX\u003c/strong\u003e: Correct \u003ccode\u003e:nth-child\u003c/code\u003e/\u003ccode\u003e:nth-of-type\u003c/code\u003e (and \u003ccode\u003e-last-\u003c/code\u003e variants) for \u003ccode\u003eAn+B\u003c/code\u003e values whose sequence steps onto\nindex 0 or onto the last child (e.g. \u003ccode\u003e:nth-child(2n-2)\u003c/code\u003e, \u003ccode\u003e:nth-child(n-1)\u003c/code\u003e, \u003ccode\u003e:nth-child(n+5)\u003c/code\u003e), which previously\nmatched the wrong elements or nothing at all (\u003ca href=\"https://github.com/gaoflow\"\u003e\u003ccode\u003e@​gaoflow\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eFIX\u003c/strong\u003e: More efficient CSS ID matching (\u003ca href=\"https://github.com/kaimandalic\"\u003e\u003ccode\u003e@​kaimandalic\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eFIX\u003c/strong\u003e: Fix inefficient trimming of comments and white space (\u003ca href=\"https://github.com/kaimandalic\"\u003e\u003ccode\u003e@​kaimandalic\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/8763f914472fc83652babda708bed5c8ef287004\"\u003e\u003ccode\u003e8763f91\u003c/code\u003e\u003c/a\u003e Format changelog message\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/cf198fcddc9230f06ed39f974eba0ce076b85cda\"\u003e\u003ccode\u003ecf198fc\u003c/code\u003e\u003c/a\u003e Fix inefficient trimming of comments and white space\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/ce44e4996e6632871c18cdd7a7fb641be8ef34ef\"\u003e\u003ccode\u003ece44e49\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/751c57b2c7e978e206b94b7dba17f8e2af392e19\"\u003e\u003ccode\u003e751c57b\u003c/code\u003e\u003c/a\u003e Fix :nth-child/:nth-of-type matching for An+B index boundaries (\u003ca href=\"https://redirect.github.com/facelessuser/soupsieve/issues/297\"\u003e#297\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/08e9ede4dcfafef860155319ef5eb9708e75d10b\"\u003e\u003ccode\u003e08e9ede\u003c/code\u003e\u003c/a\u003e Drop Python 3.9\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/d6e68303a6c3e0e410530939b92955ba24a07a81\"\u003e\u003ccode\u003ed6e6830\u003c/code\u003e\u003c/a\u003e Rework selector mapping\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/d2d1581fe275f89cb2e792589fed770aeb9e99b3\"\u003e\u003ccode\u003ed2d1581\u003c/code\u003e\u003c/a\u003e Utilize property for accessing lazy regular expression pattern\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/b8701dec25c84a3910fd9a03222a3804fa119a1d\"\u003e\u003ccode\u003eb8701de\u003c/code\u003e\u003c/a\u003e Build patterns and regexes lazily in css_parser (\u003ca href=\"https://redirect.github.com/facelessuser/soupsieve/issues/296\"\u003e#296\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/facelessuser/soupsieve/compare/2.8.4...2.9\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `tornado` from 6.5.7 to 6.5.8\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/tornadoweb/tornado/blob/master/docs/releases.rst\"\u003etornado's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003eRelease notes\u003c/h1\u003e\n\u003cp\u003e.. toctree::\n:maxdepth: 2\u003c/p\u003e\n\u003cp\u003ereleases/v6.5.10\nreleases/v6.5.9\nreleases/v6.5.8\nreleases/v6.5.7\nreleases/v6.5.6\nreleases/v6.5.5\nreleases/v6.5.4\nreleases/v6.5.3\nreleases/v6.5.2\nreleases/v6.5.1\nreleases/v6.5.0\nreleases/v6.4.2\nreleases/v6.4.1\nreleases/v6.4.0\nreleases/v6.3.3\nreleases/v6.3.2\nreleases/v6.3.1\nreleases/v6.3.0\nreleases/v6.2.0\nreleases/v6.1.0\nreleases/v6.0.4\nreleases/v6.0.3\nreleases/v6.0.2\nreleases/v6.0.1\nreleases/v6.0.0\nreleases/v5.1.1\nreleases/v5.1.0\nreleases/v5.0.2\nreleases/v5.0.1\nreleases/v5.0.0\nreleases/v4.5.3\nreleases/v4.5.2\nreleases/v4.5.1\nreleases/v4.5.0\nreleases/v4.4.3\nreleases/v4.4.2\nreleases/v4.4.1\nreleases/v4.4.0\nreleases/v4.3.0\nreleases/v4.2.1\nreleases/v4.2.0\nreleases/v4.1.0\nreleases/v4.0.2\nreleases/v4.0.1\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tornadoweb/tornado/commit/a55abe3e3bf59994f29b2f7084c46341f0d4f6a7\"\u003e\u003ccode\u003ea55abe3\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/tornadoweb/tornado/issues/3704\"\u003e#3704\u003c/a\u003e from bdarnell/security-6.5.8\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tornadoweb/tornado/commit/fc794885f0ccf9c33f3a66d890abcc237dd50b3c\"\u003e\u003ccode\u003efc79488\u003c/code\u003e\u003c/a\u003e docs: add additional credit to release notes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tornadoweb/tornado/commit/7b017630d3139ca0d1ebdf6ac3b3ffe7725a7129\"\u003e\u003ccode\u003e7b01763\u003c/code\u003e\u003c/a\u003e Fix test_strip_headers_on_redirect's URL-embedded-credentials cases\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tornadoweb/tornado/commit/d72fff8d7b9b8f6aa68505847e5483d600e3184c\"\u003e\u003ccode\u003ed72fff8\u003c/code\u003e\u003c/a\u003e release notes and version bump for 6.5.8\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tornadoweb/tornado/commit/b168818f8aae39808b981878fb358cbe02a6238e\"\u003e\u003ccode\u003eb168818\u003c/code\u003e\u003c/a\u003e auth: Formally deprecated OpenIDMixin\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tornadoweb/tornado/commit/da284767eae8e1f0484f123b8c3225f6465b09c7\"\u003e\u003ccode\u003eda28476\u003c/code\u003e\u003c/a\u003e web: Also check for semicolons in deprecated mixed-case cookie args\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tornadoweb/tornado/commit/8d6363ed7b69d5f0da806efe34d256627a2191de\"\u003e\u003ccode\u003e8d6363e\u003c/code\u003e\u003c/a\u003e httputil: Enforce a new limit on the number of arguments in a request\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tornadoweb/tornado/commit/de85b3f87446e323e881bbaa3d5a74f4b76e5f05\"\u003e\u003ccode\u003ede85b3f\u003c/code\u003e\u003c/a\u003e httputil: Apply multipart max_parts limit earlier\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/tornadoweb/tornado/compare/v6.5.7...v6.5.8\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `aiohttp` from 3.14.1 to 3.14.3\nUpdates `aiohttp` from 3.14.1 to 3.14.3\nUpdates `aiohttp` from 3.14.1 to 3.14.3\nUpdates `aiohttp` from 3.14.1 to 3.14.3\nUpdates `aiohttp` from 3.14.1 to 3.14.3\nUpdates `aiohttp` from 3.14.1 to 3.14.3\nUpdates `aiohttp` from 3.14.1 to 3.14.3\nUpdates `aiohttp` from 3.14.1 to 3.14.3\nUpdates `aiohttp` from 3.14.1 to 3.14.3\nUpdates `aiohttp` from 3.14.1 to 3.14.3\nUpdates `aiohttp` from 3.14.1 to 3.14.3\nUpdates `soupsieve` from 2.8.4 to 2.9\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/facelessuser/soupsieve/releases\"\u003esoupsieve's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e2.9\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eNEW\u003c/strong\u003e: Drop Python 3.9 support.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eNEW\u003c/strong\u003e: Lazy compile selector patterns to improve initial import speed.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eFIX\u003c/strong\u003e: Correct \u003ccode\u003e:nth-child\u003c/code\u003e/\u003ccode\u003e:nth-of-type\u003c/code\u003e (and \u003ccode\u003e-last-\u003c/code\u003e variants) for \u003ccode\u003eAn+B\u003c/code\u003e values whose sequence steps onto\nindex 0 or onto the last child (e.g. \u003ccode\u003e:nth-child(2n-2)\u003c/code\u003e, \u003ccode\u003e:nth-child(n-1)\u003c/code\u003e, \u003ccode\u003e:nth-child(n+5)\u003c/code\u003e), which previously\nmatched the wrong elements or nothing at all (\u003ca href=\"https://github.com/gaoflow\"\u003e\u003ccode\u003e@​gaoflow\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eFIX\u003c/strong\u003e: More efficient CSS ID matching (\u003ca href=\"https://github.com/kaimandalic\"\u003e\u003ccode\u003e@​kaimandalic\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eFIX\u003c/strong\u003e: Fix inefficient trimming of comments and white space (\u003ca href=\"https://github.com/kaimandalic\"\u003e\u003ccode\u003e@​kaimandalic\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/8763f914472fc83652babda708bed5c8ef287004\"\u003e\u003ccode\u003e8763f91\u003c/code\u003e\u003c/a\u003e Format changelog message\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/cf198fcddc9230f06ed39f974eba0ce076b85cda\"\u003e\u003ccode\u003ecf198fc\u003c/code\u003e\u003c/a\u003e Fix inefficient trimming of comments and white space\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/ce44e4996e6632871c18cdd7a7fb641be8ef34ef\"\u003e\u003ccode\u003ece44e49\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/751c57b2c7e978e206b94b7dba17f8e2af392e19\"\u003e\u003ccode\u003e751c57b\u003c/code\u003e\u003c/a\u003e Fix :nth-child/:nth-of-type matching for An+B index boundaries (\u003ca href=\"https://redirect.github.com/facelessuser/soupsieve/issues/297\"\u003e#297\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/08e9ede4dcfafef860155319ef5eb9708e75d10b\"\u003e\u003ccode\u003e08e9ede\u003c/code\u003e\u003c/a\u003e Drop Python 3.9\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/d6e68303a6c3e0e410530939b92955ba24a07a81\"\u003e\u003ccode\u003ed6e6830\u003c/code\u003e\u003c/a\u003e Rework selector mapping\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/d2d1581fe275f89cb2e792589fed770aeb9e99b3\"\u003e\u003ccode\u003ed2d1581\u003c/code\u003e\u003c/a\u003e Utilize property for accessing lazy regular expression pattern\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/b8701dec25c84a3910fd9a03222a3804fa119a1d\"\u003e\u003ccode\u003eb8701de\u003c/code\u003e\u003c/a\u003e Build patterns and regexes lazily in css_parser (\u003ca href=\"https://redirect.github.com/facelessuser/soupsieve/issues/296\"\u003e#296\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/facelessuser/soupsieve/compare/2.8.4...2.9\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `aiohttp` from 3.14.1 to 3.14.3\nUpdates `aiohttp` from 3.14.1 to 3.14.3\nUpdates `soupsieve` from 2.8.4 to 2.9\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/facelessuser/soupsieve/releases\"\u003esoupsieve's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e2.9\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eNEW\u003c/strong\u003e: Drop Python 3.9 support.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eNEW\u003c/strong\u003e: Lazy compile selector patterns to improve initial import speed.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eFIX\u003c/strong\u003e: Correct \u003ccode\u003e:nth-child\u003c/code\u003e/\u003ccode\u003e:nth-of-type\u003c/code\u003e (and \u003ccode\u003e-last-\u003c/code\u003e variants) for \u003ccode\u003eAn+B\u003c/code\u003e values whose sequence steps onto\nindex 0 or onto the last child (e.g. \u003ccode\u003e:nth-child(2n-2)\u003c/code\u003e, \u003ccode\u003e:nth-child(n-1)\u003c/code\u003e, \u003ccode\u003e:nth-child(n+5)\u003c/code\u003e), which previously\nmatched the wrong elements or nothing at all (\u003ca href=\"https://github.com/gaoflow\"\u003e\u003ccode\u003e@​gaoflow\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eFIX\u003c/strong\u003e: More efficient CSS ID matching (\u003ca href=\"https://github.com/kaimandalic\"\u003e\u003ccode\u003e@​kaimandalic\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eFIX\u003c/strong\u003e: Fix inefficient trimming of comments and white space (\u003ca href=\"https://github.com/kaimandalic\"\u003e\u003ccode\u003e@​kaimandalic\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/8763f914472fc83652babda708bed5c8ef287004\"\u003e\u003ccode\u003e8763f91\u003c/code\u003e\u003c/a\u003e Format changelog message\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/cf198fcddc9230f06ed39f974eba0ce076b85cda\"\u003e\u003ccode\u003ecf198fc\u003c/code\u003e\u003c/a\u003e Fix inefficient trimming of comments and white space\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/ce44e4996e6632871c18cdd7a7fb641be8ef34ef\"\u003e\u003ccode\u003ece44e49\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/751c57b2c7e978e206b94b7dba17f8e2af392e19\"\u003e\u003ccode\u003e751c57b\u003c/code\u003e\u003c/a\u003e Fix :nth-child/:nth-of-type matching for An+B index boundaries (\u003ca href=\"https://redirect.github.com/facelessuser/soupsieve/issues/297\"\u003e#297\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/08e9ede4dcfafef860155319ef5eb9708e75d10b\"\u003e\u003ccode\u003e08e9ede\u003c/code\u003e\u003c/a\u003e Drop Python 3.9\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/d6e68303a6c3e0e410530939b92955ba24a07a81\"\u003e\u003ccode\u003ed6e6830\u003c/code\u003e\u003c/a\u003e Rework selector mapping\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/d2d1581fe275f89cb2e792589fed770aeb9e99b3\"\u003e\u003ccode\u003ed2d1581\u003c/code\u003e\u003c/a\u003e Utilize property for accessing lazy regular expression pattern\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/b8701dec25c84a3910fd9a03222a3804fa119a1d\"\u003e\u003ccode\u003eb8701de\u003c/code\u003e\u003c/a\u003e Build patterns and regexes lazily in css_parser (\u003ca href=\"https://redirect.github.com/facelessuser/soupsieve/issues/296\"\u003e#296\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/facelessuser/soupsieve/compare/2.8.4...2.9\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `aiohttp` from 3.14.1 to 3.14.3\nUpdates `aiohttp` from 3.14.1 to 3.14.3\nUpdates `aiohttp` from 3.14.1 to 3.14.3\nUpdates `aiohttp` from 3.14.1 to 3.14.3\nUpdates `aiohttp` from 3.14.1 to 3.14.3\nUpdates `aiohttp` from 3.14.1 to 3.14.3\nUpdates `aiohttp` from 3.14.1 to 3.14.3\nUpdates `aiohttp` from 3.14.1 to 3.14.3\nUpdates `aiohttp` from 3.14.1 to 3.14.3\nUpdates `soupsieve` from 2.8.4 to 2.9\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/facelessuser/soupsieve/releases\"\u003esoupsieve's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e2.9\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eNEW\u003c/strong\u003e: Drop Python 3.9 support.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eNEW\u003c/strong\u003e: Lazy compile selector patterns to improve initial import speed.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eFIX\u003c/strong\u003e: Correct \u003ccode\u003e:nth-child\u003c/code\u003e/\u003ccode\u003e:nth-of-type\u003c/code\u003e (and \u003ccode\u003e-last-\u003c/code\u003e variants) for \u003ccode\u003eAn+B\u003c/code\u003e values whose sequence steps onto\nindex 0 or onto the last child (e.g. \u003ccode\u003e:nth-child(2n-2)\u003c/code\u003e, \u003ccode\u003e:nth-child(n-1)\u003c/code\u003e, \u003ccode\u003e:nth-child(n+5)\u003c/code\u003e), which previously\nmatched the wrong elements or nothing at all (\u003ca href=\"https://github.com/gaoflow\"\u003e\u003ccode\u003e@​gaoflow\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eFIX\u003c/strong\u003e: More efficient CSS ID matching (\u003ca href=\"https://github.com/kaimandalic\"\u003e\u003ccode\u003e@​kaimandalic\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eFIX\u003c/strong\u003e: Fix inefficient trimming of comments and white space (\u003ca href=\"https://github.com/kaimandalic\"\u003e\u003ccode\u003e@​kaimandalic\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/8763f914472fc83652babda708bed5c8ef287004\"\u003e\u003ccode\u003e8763f91\u003c/code\u003e\u003c/a\u003e Format changelog message\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/cf198fcddc9230f06ed39f974eba0ce076b85cda\"\u003e\u003ccode\u003ecf198fc\u003c/code\u003e\u003c/a\u003e Fix inefficient trimming of comments and white space\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/ce44e4996e6632871c18cdd7a7fb641be8ef34ef\"\u003e\u003ccode\u003ece44e49\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/751c57b2c7e978e206b94b7dba17f8e2af392e19\"\u003e\u003ccode\u003e751c57b\u003c/code\u003e\u003c/a\u003e Fix :nth-child/:nth-of-type matching for An+B index boundaries (\u003ca href=\"https://redirect.github.com/facelessuser/soupsieve/issues/297\"\u003e#297\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/08e9ede4dcfafef860155319ef5eb9708e75d10b\"\u003e\u003ccode\u003e08e9ede\u003c/code\u003e\u003c/a\u003e Drop Python 3.9\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/d6e68303a6c3e0e410530939b92955ba24a07a81\"\u003e\u003ccode\u003ed6e6830\u003c/code\u003e\u003c/a\u003e Rework selector mapping\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/d2d1581fe275f89cb2e792589fed770aeb9e99b3\"\u003e\u003ccode\u003ed2d1581\u003c/code\u003e\u003c/a\u003e Utilize property for accessing lazy regular expression pattern\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/b8701dec25c84a3910fd9a03222a3804fa119a1d\"\u003e\u003ccode\u003eb8701de\u003c/code\u003e\u003c/a\u003e Build patterns and regexes lazily in css_parser (\u003ca href=\"https://redirect.github.com/facelessuser/soupsieve/issues/296\"\u003e#296\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/facelessuser/soupsieve/compare/2.8.4...2.9\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `aiohttp` from 3.14.1 to 3.14.3\nUpdates `aiohttp` from 3.14.1 to 3.14.3\nUpdates `aiohttp` from 3.14.1 to 3.14.3\nUpdates `aiohttp` from 3.14.1 to 3.14.3\nUpdates `aiohttp` from 3.14.1 to 3.14.3\nUpdates `aiohttp` from 3.14.1 to 3.14.3\nUpdates `aiohttp` from 3.14.1 to 3.14.3\nUpdates `aiohttp` from 3.14.1 to 3.14.3\nUpdates `soupsieve` from 2.8.4 to 2.9\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/facelessuser/soupsieve/releases\"\u003esoupsieve's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e2.9\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eNEW\u003c/strong\u003e: Drop Python 3.9 support.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eNEW\u003c/strong\u003e: Lazy compile selector patterns to improve initial import speed.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eFIX\u003c/strong\u003e: Correct \u003ccode\u003e:nth-child\u003c/code\u003e/\u003ccode\u003e:nth-of-type\u003c/code\u003e (and \u003ccode\u003e-last-\u003c/code\u003e variants) for \u003ccode\u003eAn+B\u003c/code\u003e values whose sequence steps onto\nindex 0 or onto the last child (e.g. \u003ccode\u003e:nth-child(2n-2)\u003c/code\u003e, \u003ccode\u003e:nth-child(n-1)\u003c/code\u003e, \u003ccode\u003e:nth-child(n+5)\u003c/code\u003e), which previously\nmatched the wrong elements or nothing at all (\u003ca href=\"https://github.com/gaoflow\"\u003e\u003ccode\u003e@​gaoflow\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eFIX\u003c/strong\u003e: More efficient CSS ID matching (\u003ca href=\"https://github.com/kaimandalic\"\u003e\u003ccode\u003e@​kaimandalic\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eFIX\u003c/strong\u003e: Fix inefficient trimming of comments and white space (\u003ca href=\"https://github.com/kaimandalic\"\u003e\u003ccode\u003e@​kaimandalic\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/8763f914472fc83652babda708bed5c8ef287004\"\u003e\u003ccode\u003e8763f91\u003c/code\u003e\u003c/a\u003e Format changelog message\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/cf198fcddc9230f06ed39f974eba0ce076b85cda\"\u003e\u003ccode\u003ecf198fc\u003c/code\u003e\u003c/a\u003e Fix inefficient trimming of comments and white space\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/ce44e4996e6632871c18cdd7a7fb641be8ef34ef\"\u003e\u003ccode\u003ece44e49\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/751c57b2c7e978e206b94b7dba17f8e2af392e19\"\u003e\u003ccode\u003e751c57b\u003c/code\u003e\u003c/a\u003e Fix :nth-child/:nth-of-type matching for An+B index boundaries (\u003ca href=\"https://redirect.github.com/facelessuser/soupsieve/issues/297\"\u003e#297\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/08e9ede4dcfafef860155319ef5eb9708e75d10b\"\u003e\u003ccode\u003e08e9ede\u003c/code\u003e\u003c/a\u003e Drop Python 3.9\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/d6e68303a6c3e0e410530939b92955ba24a07a81\"\u003e\u003ccode\u003ed6e6830\u003c/code\u003e\u003c/a\u003e Rework selector mapping\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/d2d1581fe275f89cb2e792589fed770aeb9e99b3\"\u003e\u003ccode\u003ed2d1581\u003c/code\u003e\u003c/a\u003e Utilize property for accessing lazy regular expression pattern\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/b8701dec25c84a3910fd9a03222a3804fa119a1d\"\u003e\u003ccode\u003eb8701de\u003c/code\u003e\u003c/a\u003e Build patterns and regexes lazily in css_parser (\u003ca href=\"https://redirect.github.com/facelessuser/soupsieve/issues/296\"\u003e#296\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/facelessuser/soupsieve/compare/2.8.4...2.9\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/2233admin/openalice-data/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/2233admin/openalice-data/pull/16","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/2233admin%2Fopenalice-data/issues/16","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/16/packages"},{"uuid":"5494887783","node_id":"PR_kwDOS3o3yM8AAAABEBVZYQ","number":2,"state":"open","title":"Bump the uv group across 1 directory with 15 updates","user":"dependabot[bot]","labels":["dependencies","python:uv"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-18T02:21:41.000Z","updated_at":"2026-09-18T02:22:24.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","group_name":"uv","update_count":15,"packages":[{"name":"gitpython","old_version":"3.1.44","new_version":"3.1.59","repository_url":"https://github.com/gitpython-developers/GitPython"},{"name":"langchain","old_version":"1.2.10","new_version":"1.3.9","repository_url":"https://github.com/langchain-ai/langchain"},{"name":"langsmith","old_version":"0.7.7","new_version":"0.8.18","repository_url":"https://github.com/langchain-ai/langsmith-sdk"},{"name":"pyjwt","old_version":"2.10.1","new_version":"2.13.0","repository_url":"https://github.com/jpadilla/pyjwt"},{"name":"setuptools","old_version":"80.10.2","new_version":"83.0.0","repository_url":"https://github.com/pypa/setuptools"},{"name":"aiohttp","old_version":"3.13.3","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"langgraph-checkpoint","old_version":"4.0.0","new_version":"4.2.0","repository_url":"https://github.com/langchain-ai/langgraph"},{"name":"langgraph-sdk","old_version":"0.3.9","new_version":"0.4.4","repository_url":"https://github.com/langchain-ai/langgraph"},{"name":"msgpack","old_version":"1.1.2","new_version":"1.2.1","repository_url":"https://github.com/msgpack/msgpack-python"},{"name":"pyasn1","old_version":"0.6.2","new_version":"0.6.4","repository_url":"https://github.com/pyasn1/pyasn1"},{"name":"pydantic-settings","old_version":"2.13.1","new_version":"2.14.2","repository_url":"https://github.com/pydantic/pydantic-settings"},{"name":"python-engineio","old_version":"4.13.1","new_version":"4.13.2","repository_url":"https://github.com/miguelgrinberg/python-engineio"},{"name":"python-socketio","old_version":"5.16.1","new_version":"5.16.2","repository_url":"https://github.com/sponsors/miguelgrinberg"},{"name":"soupsieve","old_version":"2.8.3","new_version":"2.9","repository_url":"https://github.com/facelessuser/soupsieve"},{"name":"thrift","old_version":"0.22.0","new_version":"0.24.0","repository_url":"https://github.com/apache/thrift"}],"path":null,"ecosystem":"pip"},"body":"Bumps the uv group with 15 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [gitpython](https://github.com/gitpython-developers/GitPython) | `3.1.44` | `3.1.59` |\n| [langchain](https://github.com/langchain-ai/langchain) | `1.2.10` | `1.3.9` |\n| [langsmith](https://github.com/langchain-ai/langsmith-sdk) | `0.7.7` | `0.8.18` |\n| [pyjwt](https://github.com/jpadilla/pyjwt) | `2.10.1` | `2.13.0` |\n| [setuptools](https://github.com/pypa/setuptools) | `80.10.2` | `83.0.0` |\n| [aiohttp](https://github.com/aio-libs/aiohttp) | `3.13.3` | `3.14.3` |\n| [langgraph-checkpoint](https://github.com/langchain-ai/langgraph) | `4.0.0` | `4.2.0` |\n| [langgraph-sdk](https://github.com/langchain-ai/langgraph) | `0.3.9` | `0.4.4` |\n| [msgpack](https://github.com/msgpack/msgpack-python) | `1.1.2` | `1.2.1` |\n| [pyasn1](https://github.com/pyasn1/pyasn1) | `0.6.2` | `0.6.4` |\n| [pydantic-settings](https://github.com/pydantic/pydantic-settings) | `2.13.1` | `2.14.2` |\n| [python-engineio](https://github.com/miguelgrinberg/python-engineio) | `4.13.1` | `4.13.2` |\n| [python-socketio](https://github.com/sponsors/miguelgrinberg) | `5.16.1` | `5.16.2` |\n| [soupsieve](https://github.com/facelessuser/soupsieve) | `2.8.3` | `2.9` |\n| [thrift](https://github.com/apache/thrift) | `0.22.0` | `0.24.0` |\n\n\nUpdates `gitpython` from 3.1.44 to 3.1.59\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/gitpython-developers/GitPython/releases\"\u003egitpython's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e3.1.59 - Security\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eprepare changelog for upcoming release by \u003ca href=\"https://github.com/Byron\"\u003e\u003ccode\u003e@​Byron\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2207\"\u003egitpython-developers/GitPython#2207\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBlock file-reading Git options by \u003ca href=\"https://github.com/Byron\"\u003e\u003ccode\u003e@​Byron\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2208\"\u003egitpython-developers/GitPython#2208\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eindex: write blobs via git hash-object, not gitdb's odb.store by \u003ca href=\"https://github.com/caroescm\"\u003e\u003ccode\u003e@​caroescm\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2209\"\u003egitpython-developers/GitPython#2209\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBlock separate git directories during clone by \u003ca href=\"https://github.com/Byron\"\u003e\u003ccode\u003e@​Byron\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2210\"\u003egitpython-developers/GitPython#2210\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: harden config parsing boundaries by \u003ca href=\"https://github.com/Byron\"\u003e\u003ccode\u003e@​Byron\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2211\"\u003egitpython-developers/GitPython#2211\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003erepo.index.add()\u003c/code\u003e now respects worktree filters  \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2209\"\u003egitpython-developers/GitPython#2209\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/gitpython-developers/GitPython/compare/3.1.58...3.1.59\"\u003ehttps://github.com/gitpython-developers/GitPython/compare/3.1.58...3.1.59\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003e3.1.58 - Security and Fixes\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003etest: allow Python startup before timeout by \u003ca href=\"https://github.com/Byron\"\u003e\u003ccode\u003e@​Byron\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2195\"\u003egitpython-developers/GitPython#2195\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eResolve Windows hook Bash through PATH by \u003ca href=\"https://github.com/Byron\"\u003e\u003ccode\u003e@​Byron\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2199\"\u003egitpython-developers/GitPython#2199\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRevert \u0026quot;Resolve Windows hook Bash through PATH\u0026quot; by \u003ca href=\"https://github.com/Byron\"\u003e\u003ccode\u003e@​Byron\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2200\"\u003egitpython-developers/GitPython#2200\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etest: focus pytest summary on unexpected failures by \u003ca href=\"https://github.com/raisulchowdhury\"\u003e\u003ccode\u003e@​raisulchowdhury\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2203\"\u003egitpython-developers/GitPython#2203\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eValidate submodule names before filesystem operations by \u003ca href=\"https://github.com/Byron\"\u003e\u003ccode\u003e@​Byron\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2202\"\u003egitpython-developers/GitPython#2202\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eHandle invalid submodule names during recursive updates by \u003ca href=\"https://github.com/Byron\"\u003e\u003ccode\u003e@​Byron\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2205\"\u003egitpython-developers/GitPython#2205\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix Windows path handling on Python 3.13+ by \u003ca href=\"https://github.com/Byron\"\u003e\u003ccode\u003e@​Byron\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2196\"\u003egitpython-developers/GitPython#2196\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efixup 2202 by \u003ca href=\"https://github.com/Byron\"\u003e\u003ccode\u003e@​Byron\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2206\"\u003egitpython-developers/GitPython#2206\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eCorrect Windows hook Bash precedence by \u003ca href=\"https://github.com/Byron\"\u003e\u003ccode\u003e@​Byron\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2201\"\u003egitpython-developers/GitPython#2201\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eHarden config and Git option validation by \u003ca href=\"https://github.com/Byron\"\u003e\u003ccode\u003e@​Byron\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2204\"\u003egitpython-developers/GitPython#2204\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSkip tests that need symlink privileges instead of erroring by \u003ca href=\"https://github.com/Cyrus580529\"\u003e\u003ccode\u003e@​Cyrus580529\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2197\"\u003egitpython-developers/GitPython#2197\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/raisulchowdhury\"\u003e\u003ccode\u003e@​raisulchowdhury\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2203\"\u003egitpython-developers/GitPython#2203\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Cyrus580529\"\u003e\u003ccode\u003e@​Cyrus580529\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2197\"\u003egitpython-developers/GitPython#2197\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/gitpython-developers/GitPython/compare/3.1.57...3.1.58\"\u003ehttps://github.com/gitpython-developers/GitPython/compare/3.1.57...3.1.58\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003e3.1.57 - Security and Fixes\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMerge gitdb and smmap into the GitPython repository by \u003ca href=\"https://github.com/Byron\"\u003e\u003ccode\u003e@​Byron\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2179\"\u003egitpython-developers/GitPython#2179\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump actions/setup-python from 6 to 7 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2185\"\u003egitpython-developers/GitPython#2185\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump the pre-commit group with 2 updates by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2186\"\u003egitpython-developers/GitPython#2186\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump Vampire/setup-wsl from 6.0.0 to 7.0.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2124\"\u003egitpython-developers/GitPython#2124\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRender protected Traversable methods in the reference by \u003ca href=\"https://github.com/pick7\"\u003e\u003ccode\u003e@​pick7\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2192\"\u003egitpython-developers/GitPython#2192\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUse standard prefixes for parsed patch diffs by \u003ca href=\"https://github.com/pick7\"\u003e\u003ccode\u003e@​pick7\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2191\"\u003egitpython-developers/GitPython#2191\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eHonor kill_after_timeout with output streams by \u003ca href=\"https://github.com/pick7\"\u003e\u003ccode\u003e@​pick7\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2189\"\u003egitpython-developers/GitPython#2189\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRedact Authorization extra headers from command errors by \u003ca href=\"https://github.com/pick7\"\u003e\u003ccode\u003e@​pick7\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2188\"\u003egitpython-developers/GitPython#2188\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eImprove RemoteProgress parse return typing by \u003ca href=\"https://github.com/pick7\"\u003e\u003ccode\u003e@​pick7\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2187\"\u003egitpython-developers/GitPython#2187\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdopt basedpyright with a legacy baseline by \u003ca href=\"https://github.com/Byron\"\u003e\u003ccode\u003e@​Byron\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2194\"\u003egitpython-developers/GitPython#2194\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBlock unsafe Git file and URL options by \u003ca href=\"https://github.com/Byron\"\u003e\u003ccode\u003e@​Byron\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2193\"\u003egitpython-developers/GitPython#2193\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pick7\"\u003e\u003ccode\u003e@​pick7\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2192\"\u003egitpython-developers/GitPython#2192\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/gitpython-developers/GitPython/compare/3.1.56...3.1.57\"\u003ehttps://github.com/gitpython-developers/GitPython/compare/3.1.56...3.1.57\u003c/a\u003e\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gitpython-developers/GitPython/commit/66340d77aab9a7468f4aed3681d4ef1e3c0ec931\"\u003e\u003ccode\u003e66340d7\u003c/code\u003e\u003c/a\u003e prepare changelog prior to release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gitpython-developers/GitPython/commit/a5e047d0db7047c4249c0de335585470b14d50c4\"\u003e\u003ccode\u003ea5e047d\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/issues/2211\"\u003e#2211\u003c/a\u003e from gitpython-developers/config-sanitize-more\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gitpython-developers/GitPython/commit/ef7568e3b317ce617eacda39b8b54dcdff8c3b5c\"\u003e\u003ccode\u003eef7568e\u003c/code\u003e\u003c/a\u003e fix: ignore includes in submodule configuration\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gitpython-developers/GitPython/commit/4b4e47fc1224e23b0c8ee7220a7192818f2e4abb\"\u003e\u003ccode\u003e4b4e47f\u003c/code\u003e\u003c/a\u003e fix: preserve multiline config values when writing\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gitpython-developers/GitPython/commit/b473abb0f7de754392e1ec923f2fe296509013ab\"\u003e\u003ccode\u003eb473abb\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/issues/2210\"\u003e#2210\u003c/a\u003e from gitpython-developers/fix-clone-unsafe-option\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gitpython-developers/GitPython/commit/5ff52cccca770fd69c6caf0b8f281d3e45d599be\"\u003e\u003ccode\u003e5ff52cc\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/issues/2209\"\u003e#2209\u003c/a\u003e from caroescm/fix-index-add-chmod\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gitpython-developers/GitPython/commit/b68afff45af0f49e79a3e2d2162018986b37ad5d\"\u003e\u003ccode\u003eb68afff\u003c/code\u003e\u003c/a\u003e Block separate git directories during clone\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gitpython-developers/GitPython/commit/93677a00ab9dcb06cc08595fd1f88a4b4a0fa23b\"\u003e\u003ccode\u003e93677a0\u003c/code\u003e\u003c/a\u003e fix: \u003ccode\u003eindex.add()\u003c/code\u003e now supports filters (\u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/issues/2021\"\u003e#2021\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gitpython-developers/GitPython/commit/9729ed3b948f2bde09f1f188c5311e172212b67e\"\u003e\u003ccode\u003e9729ed3\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/issues/2208\"\u003e#2208\u003c/a\u003e from gitpython-developers/security-fixes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gitpython-developers/GitPython/commit/ce9d8e8d150e06ae2e2cc2efa229071cd3048a93\"\u003e\u003ccode\u003ece9d8e8\u003c/code\u003e\u003c/a\u003e prepare next release\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/gitpython-developers/GitPython/compare/3.1.44...3.1.59\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `langchain` from 1.2.10 to 1.3.9\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/langchain-ai/langchain/releases\"\u003elangchain's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003elangchain==1.3.9\u003c/h2\u003e\n\u003cp\u003eChanges since langchain==1.3.8\u003c/p\u003e\n\u003cp\u003erelease(anthropic): 1.4.6 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38105\"\u003e#38105\u003c/a\u003e)\nrelease(langchain): 1.3.9 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38104\"\u003e#38104\u003c/a\u003e)\nfix(langchain,anthropic): confine file-search results and tighten anthropic \u003ccode\u003eallowed_prefixes\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38106\"\u003e#38106\u003c/a\u003e)\u003c/p\u003e\n\u003ch2\u003elangchain==1.3.8\u003c/h2\u003e\n\u003cp\u003eChanges since langchain==1.3.7\u003c/p\u003e\n\u003cp\u003erelease(langchain): 1.3.8 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38096\"\u003e#38096\u003c/a\u003e)\nstyle(core,langchain,langchain-classic,partners): replace double backticks in docstrings (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38095\"\u003e#38095\u003c/a\u003e)\nrelease(core): 1.4.6 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38061\"\u003e#38061\u003c/a\u003e)\nchore(langchain): add overloads to \u003ccode\u003ecreate_agent\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/34309\"\u003e#34309\u003c/a\u003e)\nchore(infra): bump mypy to 2.1 and unify type-check config across the monorepo (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/36470\"\u003e#36470\u003c/a\u003e)\nfix(langchain): support async middleware decorator typing (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/34584\"\u003e#34584\u003c/a\u003e)\nfix(langchain): tighten structured output model fallbacks (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38042\"\u003e#38042\u003c/a\u003e)\nrelease(anthropic): 1.4.5 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38036\"\u003e#38036\u003c/a\u003e)\nhotfix(core): bump lockfile(s) (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38032\"\u003e#38032\u003c/a\u003e)\nrefactor(langchain): refactor \u003ccode\u003etest_create_agent_tool_validation\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/34443\"\u003e#34443\u003c/a\u003e)\u003c/p\u003e\n\u003ch2\u003elangchain==1.3.7\u003c/h2\u003e\n\u003cp\u003eChanges since langchain==1.3.6\u003c/p\u003e\n\u003cp\u003erelease(langchain): 1.3.7 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38024\"\u003e#38024\u003c/a\u003e)\nstyle(langchain): add ruff rules ARG (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/34435\"\u003e#34435\u003c/a\u003e)\nfeat(langchain): add \u003ccode\u003eProviderToolSearchMiddleware\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/37969\"\u003e#37969\u003c/a\u003e)\nchore(langchain): activate mypy \u003ccode\u003ewarn_return_any\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/34249\"\u003e#34249\u003c/a\u003e)\ntest(langchain): mark legacy trigger view for 2.0 removal (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38002\"\u003e#38002\u003c/a\u003e)\u003c/p\u003e\n\u003ch2\u003elangchain==1.3.6\u003c/h2\u003e\n\u003cp\u003eChanges since langchain==1.3.5\u003c/p\u003e\n\u003cp\u003erelease(langchain): 1.3.6 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38001\"\u003e#38001\u003c/a\u003e)\nfix(langchain): preserve summarization trigger compatibility (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38000\"\u003e#38000\u003c/a\u003e)\u003c/p\u003e\n\u003ch2\u003elangchain==1.3.5\u003c/h2\u003e\n\u003cp\u003eChanges since langchain==1.3.4\u003c/p\u003e\n\u003cp\u003erelease(langchain): 1.3.5 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/37998\"\u003e#37998\u003c/a\u003e)\nfeat(langchain): port AND-capable trigger conditions to \u003ccode\u003eSummarizationMiddleware\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/34576\"\u003e#34576\u003c/a\u003e)\nhotfix(openai): min core dep (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/37990\"\u003e#37990\u003c/a\u003e)\nfeat(openai): support \u003ccode\u003eapply_patch\u003c/code\u003e built-in tool (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/37157\"\u003e#37157\u003c/a\u003e)\nchore: bump pyarrow from 21.0.0 to 23.0.1 in /libs/langchain_v1 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/37930\"\u003e#37930\u003c/a\u003e)\nchore: bump dependencies  (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/37892\"\u003e#37892\u003c/a\u003e)\nchore: bump aiohttp from 3.13.4 to 3.14.0 in /libs/langchain_v1 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/37888\"\u003e#37888\u003c/a\u003e)\u003c/p\u003e\n\u003ch2\u003elangchain-openai==1.3.5\u003c/h2\u003e\n\u003cp\u003eChanges since langchain-openai==1.3.4\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/3bfb6a33e788aaca1626a7c09cbdbdbef6977012\"\u003e\u003ccode\u003e3bfb6a3\u003c/code\u003e\u003c/a\u003e release(langchain): 1.3.9 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38104\"\u003e#38104\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/dcaf7795a3e6590af55c3ff7bda6add6355e9ea6\"\u003e\u003ccode\u003edcaf779\u003c/code\u003e\u003c/a\u003e fix(langchain,anthropic): confine file-search results and tighten anthropic `...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/0392b6bae4bdfc0b7ed5aeb2e9e414bbb7ea643b\"\u003e\u003ccode\u003e0392b6b\u003c/code\u003e\u003c/a\u003e fix(core): fix Pydantic v1 support in tools/runnable (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/33698\"\u003e#33698\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/f6d63bc9f344b2949e91a6904d301553376b4f10\"\u003e\u003ccode\u003ef6d63bc\u003c/code\u003e\u003c/a\u003e release(langchain): 1.3.8 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38096\"\u003e#38096\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/5d20596d73789020f53c622b22c0a9893ba09606\"\u003e\u003ccode\u003e5d20596\u003c/code\u003e\u003c/a\u003e style(core,langchain,langchain-classic,partners): replace double backticks in...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/fb55c6660a2ac26038a64dac1534048294bc51ab\"\u003e\u003ccode\u003efb55c66\u003c/code\u003e\u003c/a\u003e chore: bump langsmith from 0.8.9 to 0.8.14 in /libs/partners/huggingface (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38\"\u003e#38\u003c/a\u003e...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/51daae5c139712f6f1347b5a801f672680ba1eba\"\u003e\u003ccode\u003e51daae5\u003c/code\u003e\u003c/a\u003e chore: bump langsmith from 0.8.9 to 0.8.14 in /libs/partners/chroma (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38092\"\u003e#38092\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/70e9579e433043321fb8e93a8a51770c946363d0\"\u003e\u003ccode\u003e70e9579\u003c/code\u003e\u003c/a\u003e chore: bump langsmith from 0.8.9 to 0.8.14 in /libs/partners/fireworks (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38093\"\u003e#38093\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/6c0e9af3246e3bbf98838e4b9ec563ad563dd748\"\u003e\u003ccode\u003e6c0e9af\u003c/code\u003e\u003c/a\u003e chore: bump langsmith from 0.8.9 to 0.8.14 in /libs/partners/xai (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38094\"\u003e#38094\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/222dc846e0e965a0d6764d772226590eec14b917\"\u003e\u003ccode\u003e222dc84\u003c/code\u003e\u003c/a\u003e ci(infra): clarify early PR auto-close guidance (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38090\"\u003e#38090\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/langchain-ai/langchain/compare/langchain==1.2.10...langchain==1.3.9\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `langsmith` from 0.7.7 to 0.8.18\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/langchain-ai/langsmith-sdk/releases\"\u003elangsmith's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev0.8.18\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003echore(deps-dev): bump vitest from 3.2.4 to 3.2.6 in /js by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3002\"\u003elangchain-ai/langsmith-sdk#3002\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(deps): bump pyjwt from 2.12.1 to 2.13.0 in /python by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3030\"\u003elangchain-ai/langsmith-sdk#3030\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(deps): bump python-multipart from 0.0.27 to 0.0.31 in /python by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3036\"\u003elangchain-ai/langsmith-sdk#3036\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(deps): bump aiohttp from 3.14.0 to 3.14.1 in /python by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3037\"\u003elangchain-ai/langsmith-sdk#3037\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(deps): bump cryptography from 46.0.7 to 48.0.1 in /python by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3038\"\u003elangchain-ai/langsmith-sdk#3038\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(deps): bump starlette from 1.0.1 to 1.3.1 in /python by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3039\"\u003elangchain-ai/langsmith-sdk#3039\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(deps-dev): bump langchain-anthropic from 1.4.4 to 1.4.6 in /python by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3044\"\u003elangchain-ai/langsmith-sdk#3044\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(deps): bump the npm_and_yarn group across 4 directories with 4 updates by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3046\"\u003elangchain-ai/langsmith-sdk#3046\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(deps): bump the npm_and_yarn group across 2 directories with 2 updates by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3060\"\u003elangchain-ai/langsmith-sdk#3060\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etest(python): fix integration assertions for updated attachment error message by \u003ca href=\"https://github.com/QuentinBrosse\"\u003e\u003ccode\u003e@​QuentinBrosse\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3061\"\u003elangchain-ai/langsmith-sdk#3061\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: reconcile bumpversion config and mandate release process for agents by \u003ca href=\"https://github.com/QuentinBrosse\"\u003e\u003ccode\u003e@​QuentinBrosse\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3062\"\u003elangchain-ai/langsmith-sdk#3062\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003erelease(py): 0.8.18 by \u003ca href=\"https://github.com/QuentinBrosse\"\u003e\u003ccode\u003e@​QuentinBrosse\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3063\"\u003elangchain-ai/langsmith-sdk#3063\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/langchain-ai/langsmith-sdk/compare/v0.8.17...v0.8.18\"\u003ehttps://github.com/langchain-ai/langsmith-sdk/compare/v0.8.17...v0.8.18\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev0.8.17\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efeat: expose the resources from the generated openapi client in the langsmith client by \u003ca href=\"https://github.com/sineha-mani\"\u003e\u003ccode\u003e@​sineha-mani\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3018\"\u003elangchain-ai/langsmith-sdk#3018\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(js): port \u003ccode\u003eisTracingEnabled\u003c/code\u003e utility from Python by \u003ca href=\"https://github.com/dqbd\"\u003e\u003ccode\u003e@​dqbd\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3032\"\u003elangchain-ai/langsmith-sdk#3032\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd sandbox mount support to JS SDK by \u003ca href=\"https://github.com/DanielKneipp\"\u003e\u003ccode\u003e@​DanielKneipp\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3010\"\u003elangchain-ai/langsmith-sdk#3010\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003erelease(js): bump to 0.7.9 by \u003ca href=\"https://github.com/dqbd\"\u003e\u003ccode\u003e@​dqbd\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3035\"\u003elangchain-ai/langsmith-sdk#3035\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd sandbox mount support to Python SDK by \u003ca href=\"https://github.com/DanielKneipp\"\u003e\u003ccode\u003e@​DanielKneipp\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3009\"\u003elangchain-ai/langsmith-sdk#3009\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003edocs: note that _openapi_client directories are auto-generated by \u003ca href=\"https://github.com/KiewanVillatel\"\u003e\u003ccode\u003e@​KiewanVillatel\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3034\"\u003elangchain-ai/langsmith-sdk#3034\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: update JS SDK type declarations with skipLibCheck disabled by \u003ca href=\"https://github.com/sineha-mani\"\u003e\u003ccode\u003e@​sineha-mani\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3043\"\u003elangchain-ai/langsmith-sdk#3043\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003erelease(js): 0.7.10 by \u003ca href=\"https://github.com/dqbd\"\u003e\u003ccode\u003e@​dqbd\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3045\"\u003elangchain-ai/langsmith-sdk#3045\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat: adding python async for online evals by \u003ca href=\"https://github.com/sineha-mani\"\u003e\u003ccode\u003e@​sineha-mani\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3048\"\u003elangchain-ai/langsmith-sdk#3048\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd sandbox Git mount SDK helpers by \u003ca href=\"https://github.com/DanielKneipp\"\u003e\u003ccode\u003e@​DanielKneipp\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3040\"\u003elangchain-ai/langsmith-sdk#3040\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: use insights tab in sdk report links [closes LSO-2936] by \u003ca href=\"https://github.com/eric-langchain\"\u003e\u003ccode\u003e@​eric-langchain\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3050\"\u003elangchain-ai/langsmith-sdk#3050\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(client): warn when backend version is below minimum required by \u003ca href=\"https://github.com/KiewanVillatel\"\u003e\u003ccode\u003e@​KiewanVillatel\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3041\"\u003elangchain-ai/langsmith-sdk#3041\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: bump _MIN_BACKEND_VERSION to 0.16.5rc1 by \u003ca href=\"https://github.com/langtions-bot\"\u003e\u003ccode\u003e@​langtions-bot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3053\"\u003elangchain-ai/langsmith-sdk#3053\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(sandbox): use built-in gcp auth host matching by \u003ca href=\"https://github.com/DanielKneipp\"\u003e\u003ccode\u003e@​DanielKneipp\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3055\"\u003elangchain-ai/langsmith-sdk#3055\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(python): py to 0.8.17 by \u003ca href=\"https://github.com/sineha-mani\"\u003e\u003ccode\u003e@​sineha-mani\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3056\"\u003elangchain-ai/langsmith-sdk#3056\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/sineha-mani\"\u003e\u003ccode\u003e@​sineha-mani\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3018\"\u003elangchain-ai/langsmith-sdk#3018\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eric-langchain\"\u003e\u003ccode\u003e@​eric-langchain\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3050\"\u003elangchain-ai/langsmith-sdk#3050\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/langchain-ai/langsmith-sdk/compare/v0.8.16...v0.8.17\"\u003ehttps://github.com/langchain-ai/langsmith-sdk/compare/v0.8.16...v0.8.17\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev0.8.16\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efeat(py): add sync/async conversion for Sandbox and SandboxClient [INF-0000] by \u003ca href=\"https://github.com/ramon-langchain\"\u003e\u003ccode\u003e@​ramon-langchain\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3019\"\u003elangchain-ai/langsmith-sdk#3019\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(experiments): extract keys from wrapped evaluator function by \u003ca href=\"https://github.com/shamikkarkhanis\"\u003e\u003ccode\u003e@​shamikkarkhanis\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3014\"\u003elangchain-ai/langsmith-sdk#3014\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: repoint \u003ca href=\"mailto:support@langchain.dev\"\u003esupport@langchain.dev\u003c/a\u003e mentions to the Support Portal by \u003ca href=\"https://github.com/lutan-langchain\"\u003e\u003ccode\u003e@​lutan-langchain\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3024\"\u003elangchain-ai/langsmith-sdk#3024\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(python): derive create_child run id from start_time [LSDK-220] by \u003ca href=\"https://github.com/harisaiharish\"\u003e\u003ccode\u003e@​harisaiharish\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3027\"\u003elangchain-ai/langsmith-sdk#3027\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: sync langsmith_api by \u003ca href=\"https://github.com/langtions-bot\"\u003e\u003ccode\u003e@​langtions-bot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3020\"\u003elangchain-ai/langsmith-sdk#3020\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: js to 0.7.8 and py to 0.8.16 by \u003ca href=\"https://github.com/shamikkarkhanis\"\u003e\u003ccode\u003e@​shamikkarkhanis\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3029\"\u003elangchain-ai/langsmith-sdk#3029\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langsmith-sdk/commit/31c2bf650b84a44577d8b4443298fb7e78025b8f\"\u003e\u003ccode\u003e31c2bf6\u003c/code\u003e\u003c/a\u003e release(py): 0.8.18 (\u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3063\"\u003e#3063\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langsmith-sdk/commit/8955b688689fdf47871d44013787410a42ea13fd\"\u003e\u003ccode\u003e8955b68\u003c/code\u003e\u003c/a\u003e chore: reconcile bumpversion config and mandate release process for agents (#...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langsmith-sdk/commit/411401f6ca5ff401c29772ed097c9c9ed97f994c\"\u003e\u003ccode\u003e411401f\u003c/code\u003e\u003c/a\u003e test(python): fix integration assertions for updated attachment error message...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langsmith-sdk/commit/9c5515620f9bfa2145fc65d6f4353c4c8a3e96b6\"\u003e\u003ccode\u003e9c55156\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langsmith-sdk/commit/5b2bd8db3c50d3f19e98f41288c87d9c0ac0b136\"\u003e\u003ccode\u003e5b2bd8d\u003c/code\u003e\u003c/a\u003e chore(deps): bump the npm_and_yarn group across 2 directories with 2 updates ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langsmith-sdk/commit/d8642f9099a48025d00c7283ad3cd2ce56fec775\"\u003e\u003ccode\u003ed8642f9\u003c/code\u003e\u003c/a\u003e chore(deps): bump the npm_and_yarn group across 4 directories with 4 updates ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langsmith-sdk/commit/953c2e5e25e41ecb4dba428adbac1c446c0a0071\"\u003e\u003ccode\u003e953c2e5\u003c/code\u003e\u003c/a\u003e chore(deps-dev): bump langchain-anthropic from 1.4.4 to 1.4.6 in /python (\u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3044\"\u003e#3044\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langsmith-sdk/commit/5513699e2d25c2147e02c296bc3b90f7d0923d8a\"\u003e\u003ccode\u003e5513699\u003c/code\u003e\u003c/a\u003e chore(deps): bump starlette from 1.0.1 to 1.3.1 in /python (\u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3039\"\u003e#3039\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langsmith-sdk/commit/8becdefdf422a02e03f78cf3ebb4c62c136b7cf3\"\u003e\u003ccode\u003e8becdef\u003c/code\u003e\u003c/a\u003e chore(deps): bump cryptography from 46.0.7 to 48.0.1 in /python (\u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3038\"\u003e#3038\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langsmith-sdk/commit/1a9c522febbf313bbe649ca75c39158fec048934\"\u003e\u003ccode\u003e1a9c522\u003c/code\u003e\u003c/a\u003e chore(deps): bump aiohttp from 3.14.0 to 3.14.1 in /python (\u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3037\"\u003e#3037\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/langchain-ai/langsmith-sdk/compare/v0.7.7...v0.8.18\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `pyjwt` from 2.10.1 to 2.13.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/jpadilla/pyjwt/releases\"\u003epyjwt's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e2.13.0\u003c/h2\u003e\n\u003ch1\u003ePyJWT 2.13.0 — Security Release\u003c/h1\u003e\n\u003cp\u003eThis release bundles five security fixes plus three additional hardening / spec-compliance changes. We recommend all users upgrade.\u003c/p\u003e\n\u003ch2\u003eSecurity\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/security/advisories/GHSA-xgmm-8j9v-c9wx\"\u003e\u003ccode\u003eGHSA-xgmm-8j9v-c9wx\u003c/code\u003e\u003c/a\u003e — JWK JSON accepted as HMAC secret (algorithm confusion).\u003c/strong\u003e \u003ccode\u003eHMACAlgorithm.prepare_key\u003c/code\u003e previously rejected PEM- and SSH-formatted asymmetric keys but did not catch a JWK passed as a raw JSON string. In a verifier configured with both symmetric and asymmetric algorithms in \u003ccode\u003ealgorithms=[…]\u003c/code\u003e and a raw-JSON JWK as the key, an attacker could forge HS256 tokens using the JWK text as the HMAC secret. The guard has been extended to reject any JWK-shaped JSON. \u003cem\u003eReported by \u003ca href=\"https://github.com/aradona91\"\u003e\u003ccode\u003e@​aradona91\u003c/code\u003e\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/security/advisories/GHSA-jq35-7prp-9v3f\"\u003e\u003ccode\u003eGHSA-jq35-7prp-9v3f\u003c/code\u003e\u003c/a\u003e — Algorithm allow-list bypass with \u003ccode\u003ePyJWK\u003c/code\u003e / \u003ccode\u003ePyJWKClient\u003c/code\u003e.\u003c/strong\u003e When verifying with a \u003ccode\u003ePyJWK\u003c/code\u003e, the caller's \u003ccode\u003ealgorithms=[…]\u003c/code\u003e allow-list was checked against the token header \u003ccode\u003ealg\u003c/code\u003e as a string only; actual verification used the algorithm bound to the \u003ccode\u003ePyJWK\u003c/code\u003e. An attacker who controlled a registered JWKS key could sign with one algorithm and advertise another on the header. PyJWT now requires the token header \u003ccode\u003ealg\u003c/code\u003e to match the \u003ccode\u003ePyJWK\u003c/code\u003e's algorithm before verification. \u003cem\u003eReported by \u003ca href=\"https://github.com/sushi-gif\"\u003e\u003ccode\u003e@​sushi-gif\u003c/code\u003e\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/security/advisories/GHSA-w7vc-732c-9m39\"\u003e\u003ccode\u003eGHSA-w7vc-732c-9m39\u003c/code\u003e\u003c/a\u003e — DoS via base64 decode of unused payload segment when \u003ccode\u003eb64=false\u003c/code\u003e.\u003c/strong\u003e For detached-payload JWS (\u003ccode\u003eb64=false\u003c/code\u003e), the compact-form payload segment was base64-decoded before being discarded in favor of the caller-supplied \u003ccode\u003edetached_payload\u003c/code\u003e. An attacker could inflate the unused segment to force CPU + memory cost without holding a valid signature. The segment is now required to be empty per RFC 7515 Appendix F, and is no longer decoded. \u003cem\u003eReported by \u003ca href=\"https://github.com/thesmartshadow\"\u003e\u003ccode\u003e@​thesmartshadow\u003c/code\u003e\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/security/advisories/GHSA-993g-76c3-p5m4\"\u003e\u003ccode\u003eGHSA-993g-76c3-p5m4\u003c/code\u003e\u003c/a\u003e — \u003ccode\u003ePyJWKClient\u003c/code\u003e accepts non-HTTP(S) URIs.\u003c/strong\u003e \u003ccode\u003ePyJWKClient.fetch_data\u003c/code\u003e passed its URI to \u003ccode\u003eurllib.request.urlopen\u003c/code\u003e, which by default also handles \u003ccode\u003efile://\u003c/code\u003e, \u003ccode\u003eftp://\u003c/code\u003e, and \u003ccode\u003edata:\u003c/code\u003e schemes. An application that fed an attacker-influenced URI into \u003ccode\u003ePyJWKClient\u003c/code\u003e could be coerced into reading local files or reaching other unintended schemes. \u003ccode\u003ePyJWKClient\u003c/code\u003e now rejects any URI whose scheme isn't \u003ccode\u003ehttp\u003c/code\u003e or \u003ccode\u003ehttps\u003c/code\u003e. \u003cem\u003eReported by \u003ca href=\"https://github.com/KEIJOT\"\u003e\u003ccode\u003e@​KEIJOT\u003c/code\u003e\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/security/advisories/GHSA-fhv5-28vv-h8m8\"\u003e\u003ccode\u003eGHSA-fhv5-28vv-h8m8\u003c/code\u003e\u003c/a\u003e — \u003ccode\u003ePyJWKClient\u003c/code\u003e cache wiped on fetch error.\u003c/strong\u003e A \u003ccode\u003efinally\u003c/code\u003e-block \u003ccode\u003eput(jwk_set=None)\u003c/code\u003e cleared the JWK Set cache whenever a fetch raised, turning a transient JWKS-endpoint outage into application-wide auth failure. The cache write was moved into the success path; transient errors no longer evict valid cached keys. \u003cem\u003eReported by \u003ca href=\"https://github.com/eddieran\"\u003e\u003ccode\u003e@​eddieran\u003c/code\u003e\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eFixed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eReject empty HMAC keys outright in \u003ccode\u003eHMACAlgorithm.prepare_key\u003c/code\u003e with \u003ccode\u003eInvalidKeyError\u003c/code\u003e instead of accepting them with only a warning. Defends against the \u003ccode\u003eos.getenv(\u0026quot;JWT_SECRET\u0026quot;, \u0026quot;\u0026quot;)\u003c/code\u003e footgun. \u003cem\u003eThanks to \u003ca href=\"https://github.com/SnailSploit\"\u003e\u003ccode\u003e@​SnailSploit\u003c/code\u003e\u003c/a\u003e and \u003ca href=\"https://github.com/spartan8806\"\u003e\u003ccode\u003e@​spartan8806\u003c/code\u003e\u003c/a\u003e for the reports.\u003c/em\u003e\u003c/li\u003e\n\u003cli\u003eForward per-call \u003ccode\u003eoptions\u003c/code\u003e (including \u003ccode\u003eenforce_minimum_key_length\u003c/code\u003e) from \u003ccode\u003ePyJWT.decode\u003c/code\u003e through to \u003ccode\u003ePyJWS._verify_signature\u003c/code\u003e. The option was previously silently dropped between the two layers, so it only took effect when set on the \u003ccode\u003ePyJWT\u003c/code\u003e instance. \u003cem\u003eThanks to \u003ca href=\"https://github.com/WLUB\"\u003e\u003ccode\u003e@​WLUB\u003c/code\u003e\u003c/a\u003e for the report.\u003c/em\u003e\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eRFC 7797 §3 compliance for \u003ccode\u003eb64=false\u003c/code\u003e:\u003c/strong\u003e the encoder now auto-adds \u003ccode\u003e\u0026quot;b64\u0026quot;\u003c/code\u003e to \u003ccode\u003ecrit\u003c/code\u003e, and the decoder rejects tokens that set \u003ccode\u003eb64=false\u003c/code\u003e without listing it in \u003ccode\u003ecrit\u003c/code\u003e. \u003cem\u003eThanks to \u003ca href=\"https://github.com/MachineLearning-Nerd\"\u003e\u003ccode\u003e@​MachineLearning-Nerd\u003c/code\u003e\u003c/a\u003e for the report.\u003c/em\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eChanged\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMigrate the \u003ccode\u003edev\u003c/code\u003e, \u003ccode\u003edocs\u003c/code\u003e, and \u003ccode\u003etests\u003c/code\u003e package extras to dependency groups, by \u003ca href=\"https://github.com/kurtmckee\"\u003e\u003ccode\u003e@​kurtmckee\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/jpadilla/pyjwt/pull/1152\"\u003e#1152\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eUpgrade notes\u003c/h2\u003e\n\u003cp\u003eMost fixes are invisible to correctly-configured callers. A few behavioral changes you may encounter:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eEmpty HMAC keys now raise.\u003c/strong\u003e If your app passed \u003ccode\u003e\u0026quot;\u0026quot;\u003c/code\u003e or \u003ccode\u003eb\u0026quot;\u0026quot;\u003c/code\u003e as a secret (often via a missing env var, e.g. \u003ccode\u003eos.getenv(\u0026quot;JWT_SECRET\u0026quot;, \u0026quot;\u0026quot;)\u003c/code\u003e), \u003ccode\u003eencode\u003c/code\u003e/\u003ccode\u003edecode\u003c/code\u003e will now raise \u003ccode\u003eInvalidKeyError\u003c/code\u003e. This is the intended behavior — fix the configuration.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ccode\u003ePyJWK\u003c/code\u003e decoding now requires the token's \u003ccode\u003ealg\u003c/code\u003e to match the JWK's algorithm.\u003c/strong\u003e Previously a mismatch was silently honored if the header \u003ccode\u003ealg\u003c/code\u003e appeared in the allow-list. Tokens that relied on this mismatch will now fail with \u003ccode\u003eInvalidAlgorithmError\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ccode\u003ePyJWKClient\u003c/code\u003e now rejects non-HTTP(S) URIs at construction time.\u003c/strong\u003e Tests or dev environments that fetched JWKS from \u003ccode\u003efile://\u003c/code\u003e URIs need to switch to a local HTTP server or load the JWKS by other means (e.g. construct \u003ccode\u003ePyJWKSet.from_dict(...)\u003c/code\u003e directly).\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ccode\u003eb64=false\u003c/code\u003e tokens are now strictly RFC 7515 / 7797 compliant.\u003c/strong\u003e Tokens with a non-empty compact-form payload segment, or that omit \u003ccode\u003e\u0026quot;b64\u0026quot;\u003c/code\u003e from \u003ccode\u003ecrit\u003c/code\u003e, will be rejected. PyJWT-produced tokens always satisfy both invariants, so round-trips through PyJWT are unaffected.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ccode\u003eenforce_minimum_key_length\u003c/code\u003e set per-call now takes effect.\u003c/strong\u003e Callers who passed \u003ccode\u003eoptions={\u0026quot;enforce_minimum_key_length\u0026quot;: True}\u003c/code\u003e to \u003ccode\u003ejwt.decode()\u003c/code\u003e previously got no enforcement; they will now get \u003ccode\u003eInvalidKeyError\u003c/code\u003e on undersized keys, as documented.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull changelog:\u003c/strong\u003e \u003ca href=\"https://github.com/jpadilla/pyjwt/compare/2.12.1...2.13.0\"\u003ehttps://github.com/jpadilla/pyjwt/compare/2.12.1...2.13.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003e2.12.1\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd typing_extensions dependency for Python \u0026lt; 3.11 by \u003ca href=\"https://github.com/jpadilla\"\u003e\u003ccode\u003e@​jpadilla\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/jpadilla/pyjwt/pull/1151\"\u003ejpadilla/pyjwt#1151\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/jpadilla/pyjwt/compare/2.12.0...2.12.1\"\u003ehttps://github.com/jpadilla/pyjwt/compare/2.12.0...2.12.1\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003e2.12.0\u003c/h2\u003e\n\u003ch2\u003eSecurity\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eValidate the crit (Critical) Header Parameter defined in RFC 7515 §4.1.11. by \u003ca href=\"https://github.com/dmbs335\"\u003e\u003ccode\u003e@​dmbs335\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://github.com/jpadilla/pyjwt/security/advisories/GHSA-752w-5fwx-jx9f\"\u003eGHSA-752w-5fwx-jx9f\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/jpadilla/pyjwt/blob/master/CHANGELOG.rst\"\u003epyjwt's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ccode\u003ev2.13.0 \u0026lt;https://github.com/jpadilla/pyjwt/compare/2.12.1...2.13.0\u0026gt;\u003c/code\u003e__\u003c/h2\u003e\n\u003cp\u003eSecurity\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003e\n- Reject JWK JSON documents passed as raw HMAC secrets in\n  ``HMACAlgorithm.prepare_key`` to close an algorithm-confusion gap that\n  the existing PEM/SSH guard did not cover. Reported by @aradona91 in\n  `GHSA-xgmm-8j9v-c9wx \u0026lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-xgmm-8j9v-c9wx\u0026gt;`__.\n- Bind the JWT header ``alg`` to ``PyJWK.algorithm_name`` during\n  verification so the caller's ``algorithms=[...]`` allow-list cannot be\n  bypassed when decoding with a ``PyJWK`` / ``PyJWKClient`` key. Reported\n  by @sushi-gif in `GHSA-jq35-7prp-9v3f \u0026lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-jq35-7prp-9v3f\u0026gt;`__.\n- Reject non-``http(s)`` URI schemes in ``PyJWKClient`` so attacker-\n  influenced URIs cannot read local files or reach unintended schemes via\n  urllib's default ``file://`` / ``ftp://`` / ``data:`` handlers. Reported\n  by @KEIJOT in `GHSA-993g-76c3-p5m4 \u0026lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-993g-76c3-p5m4\u0026gt;`__.\n- Preserve the cached JWK Set on fetch errors in ``PyJWKClient.fetch_data``.\n  The previous ``finally``-block ``put(None)`` pattern cleared the cache\n  on any transient outage, turning one bad JWKS request into application-\n  wide auth failure. Reported by @eddieran in `GHSA-fhv5-28vv-h8m8 \u0026lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-fhv5-28vv-h8m8\u0026gt;`__.\n- Skip the unconditional base64 decode of the compact-form payload segment\n  when ``b64=false`` is set in the protected header, and require that\n  segment to be empty (RFC 7515 Appendix F detached form). Closes an\n  unauthenticated DoS amplifier. Reported by @thesmartshadow in\n  `GHSA-w7vc-732c-9m39 \u0026lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-w7vc-732c-9m39\u0026gt;`__.\n\u003cp\u003eFixed\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003e\n- Reject empty HMAC keys outright in ``HMACAlgorithm.prepare_key`` with\n  ``InvalidKeyError`` instead of accepting them with only a warning.\n  Thanks to @SnailSploit and @spartan8806 for independently flagging the\n  footgun.\n- Forward per-call ``options`` (including ``enforce_minimum_key_length``)\n  from ``PyJWT.decode`` through to ``PyJWS._verify_signature`` so the\n  option actually takes effect when set at the call site rather than only\n  on the ``PyJWT`` instance. Thanks to @WLUB for the report.\n- RFC 7797 §3 compliance for ``b64=false``: the encoder now auto-adds\n  ``\u0026amp;quot;b64\u0026amp;quot;`` to the ``crit`` header parameter, and the decoder rejects\n  tokens that set ``b64=false`` without listing it in ``crit``. Thanks to\n  @MachineLearning-Nerd for the report.\n\nChanged\n\u003c/code\u003e\u003c/pre\u003e\n\u003cul\u003e\n\u003cli\u003eMigrate the \u003ccode\u003edev\u003c/code\u003e, \u003ccode\u003edocs\u003c/code\u003e, and \u003ccode\u003etests\u003c/code\u003e package extras to dependency groups by \u003ca href=\"https://github.com/kurtmckee\"\u003e\u003ccode\u003e@​kurtmckee\u003c/code\u003e\u003c/a\u003e in \u003ccode\u003e[#1152](https://github.com/jpadilla/pyjwt/issues/1152) \u0026amp;lt;https://github.com/jpadilla/pyjwt/pull/1152\u0026amp;gt;\u003c/code\u003e__\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003ccode\u003ev2.12.1 \u0026amp;lt;https://github.com/jpadilla/pyjwt/compare/2.12.0...2.12.1\u0026amp;gt;\u003c/code\u003e__\n\u0026lt;/tr\u0026gt;\u0026lt;/table\u0026gt;\n\u003c/code\u003e\u003c/pre\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/7144e4534c34810f4525dc4578a32addd8212cff\"\u003e\u003ccode\u003e7144e45\u003c/code\u003e\u003c/a\u003e Apply ruff format\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/d2f4bec4963897c0ef96ef64a875894f2c8542ab\"\u003e\u003ccode\u003ed2f4bec\u003c/code\u003e\u003c/a\u003e Restore \u003ccode\u003ecast()\u003c/code\u003e calls with cross-version \u003ccode\u003etype: ignore\u003c/code\u003e for \u003ccode\u003eprepare_key\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/22f478cebddd8294259c30f037ecb92b0b348774\"\u003e\u003ccode\u003e22f478c\u003c/code\u003e\u003c/a\u003e Remove redundant casts in \u003ccode\u003eRSAAlgorithm.prepare_key\u003c/code\u003e and `ECAlgorithm.prepare...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/95791b1759b8aa4f2203575d344d5c78564cdc81\"\u003e\u003ccode\u003e95791b1\u003c/code\u003e\u003c/a\u003e Bundle security fixes and hardening into 2.13.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/dcc27a9d3182a2349c30b160758785c6ce7a6508\"\u003e\u003ccode\u003edcc27a9\u003c/code\u003e\u003c/a\u003e [pre-commit.ci] pre-commit autoupdate (\u003ca href=\"https://redirect.github.com/jpadilla/pyjwt/issues/1155\"\u003e#1155\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/9d08a9a1896845ed8eaf88e6f6ac61e5800c3e7a\"\u003e\u003ccode\u003e9d08a9a\u003c/code\u003e\u003c/a\u003e [pre-commit.ci] pre-commit autoupdate (\u003ca href=\"https://redirect.github.com/jpadilla/pyjwt/issues/1146\"\u003e#1146\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/b87c10014d4109f0214fea188d00faaaf8a80e64\"\u003e\u003ccode\u003eb87c100\u003c/code\u003e\u003c/a\u003e Bump codecov/codecov-action from 5 to 6 (\u003ca href=\"https://redirect.github.com/jpadilla/pyjwt/issues/1154\"\u003e#1154\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/40e3147eb5f790d8d041772e5fc00728a176c812\"\u003e\u003ccode\u003e40e3147\u003c/code\u003e\u003c/a\u003e Migrate development extras to dependency groups (\u003ca href=\"https://redirect.github.com/jpadilla/pyjwt/issues/1152\"\u003e#1152\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/a4e1a3d1218b01c5806420b8f16d9308ac4adc30\"\u003e\u003ccode\u003ea4e1a3d\u003c/code\u003e\u003c/a\u003e Add typing_extensions dependency for Python \u0026lt; 3.11 (\u003ca href=\"https://redirect.github.com/jpadilla/pyjwt/issues/1151\"\u003e#1151\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/bd9700cca7f9258fadcc429c1034e508025931f2\"\u003e\u003ccode\u003ebd9700c\u003c/code\u003e\u003c/a\u003e Use PyJWK algorithm when encoding without explicit algorithm (\u003ca href=\"https://redirect.github.com/jpadilla/pyjwt/issues/1148\"\u003e#1148\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/jpadilla/pyjwt/compare/2.10.1...2.13.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `setuptools` from 80.10.2 to 83.0.0\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pypa/setuptools/blob/main/NEWS.rst\"\u003esetuptools's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003ev83.0.0\u003c/h1\u003e\n\u003ch2\u003eFeatures\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRequire Python 3.10 or later.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eBugfixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eMANIFEST.in\u003c/code\u003e matching (via \u003ccode\u003eFileList\u003c/code\u003e) is now insensitive to Unicode\nnormalization form. A pattern authored in one form (e.g. NFC, as typically\nsaved by editors) now matches a file whose name is stored on disk in another\n(e.g. NFD, as produced by macOS APFS/HFS+). Previously an \u003ccode\u003eexclude\u003c/code\u003e,\n\u003ccode\u003eglobal-exclude\u003c/code\u003e, \u003ccode\u003erecursive-exclude\u003c/code\u003e, or \u003ccode\u003eprune\u003c/code\u003e rule could silently\nfail to drop a non-ASCII-named file from the source distribution, publishing\nit despite the exclusion -- see GHSA-h35f-9h28-mq5c.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eDeprecations and Removals\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003epypa/distutils#334\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch1\u003ev82.0.1\u003c/h1\u003e\n\u003ch2\u003eBugfixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix the loading of \u003ccode\u003elauncher manifest.xml\u003c/code\u003e file. (\u003ca href=\"https://redirect.github.com/pypa/setuptools/issues/5047\"\u003e#5047\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eReplaced deprecated \u003ccode\u003ejson.__version__\u003c/code\u003e with fixture in tests. (\u003ca href=\"https://redirect.github.com/pypa/setuptools/issues/5186\"\u003e#5186\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eImproved Documentation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd advice about how to improve predictability when installing sdists. (\u003ca href=\"https://redirect.github.com/pypa/setuptools/issues/5168\"\u003e#5168\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eMisc\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/pypa/setuptools/issues/4941\"\u003e#4941\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/pypa/setuptools/issues/5157\"\u003e#5157\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/pypa/setuptools/issues/5169\"\u003e#5169\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/pypa/setuptools/issues/5175\"\u003e#5175\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003ev82.0.0\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/setuptools/commit/6519f728c6f23c992df81a5691ef7655184a20eb\"\u003e\u003ccode\u003e6519f72\u003c/code\u003e\u003c/a\u003e Bump version: 82.0.1 → 83.0.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/setuptools/commit/d1151b125b29a6ee1c7db860f7ee6c365d525b5f\"\u003e\u003ccode\u003ed1151b1\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/pypa/setuptools/issues/5250\"\u003e#5250\u003c/a\u003e from pypa/feature/distutils-d7633fbed\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/setuptools/commit/a2df31e6a741b0fe775969618fe6a3a3d032e900\"\u003e\u003ccode\u003ea2df31e\u003c/code\u003e\u003c/a\u003e Capture removal of dry_run parameter in changelog.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/setuptools/commit/00144dc3fb6d023fd81cdc26c380a012b084df9b\"\u003e\u003ccode\u003e00144dc\u003c/code\u003e\u003c/a\u003e Moved newsfragment to the release where it occurred.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/setuptools/commit/a4a5a2b160357be77626aa077ddd1d8ee53be50f\"\u003e\u003ccode\u003ea4a5a2b\u003c/code\u003e\u003c/a\u003e Add news fragment.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/setuptools/commit/77470c23c35031c9e37d7512694ac5ca52bfcaac\"\u003e\u003ccode\u003e77470c2\u003c/code\u003e\u003c/a\u003e Merge \u003ca href=\"https://github.com/pypa/distutils\"\u003ehttps://github.com/pypa/distutils\u003c/a\u003e into feature/distutils-d7633fbed\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/setuptools/commit/3c43897420f25a1be1afe6eaa905d056009cc736\"\u003e\u003ccode\u003e3c43897\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/pypa/setuptools/issues/5247\"\u003e#5247\u003c/a\u003e from pypa/copilot/fix-pypy-version-issue\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/setuptools/commit/bb6ea66b4bd01cb35d7c68a1bc61b96d59190269\"\u003e\u003ccode\u003ebb6ea66\u003c/code\u003e\u003c/a\u003e Bump PyPy from 3.10 to 3.11 in CI workflow\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/setuptools/commit/a2bc3aca2f55eb9b93ea633e58ba68170ce14451\"\u003e\u003ccode\u003ea2bc3ac\u003c/code\u003e\u003c/a\u003e Fix broken intersphinx reference to build's installation docs\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/setuptools/commit/2d6a739c64cfedc65e1f635af7b52340aac8d99b\"\u003e\u003ccode\u003e2d6a739\u003c/code\u003e\u003c/a\u003e Use stacked parametrize decorators instead of itertools.product\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/pypa/setuptools/compare/v80.10.2...v83.0.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `aiohttp` from 3.13.3 to 3.14.3\nUpdates `langgraph-checkpoint` from 4.0.0 to 4.2.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/langchain-ai/langgraph/releases\"\u003elanggraph-checkpoint's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003elanggraph-checkpoint==4.2.0\u003c/h2\u003e\n\u003cp\u003eChanges since checkpoint==4.1.1\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003erelease(checkpoint): 4.2.0 (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8563\"\u003e#8563\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix(checkpoint): collect writes at plain-value seed in delta channel history (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8526\"\u003e#8526\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore: enforce PLC0415 in tests for the remaining packages (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8547\"\u003e#8547\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore: enable RUF100 and clear unused noqa directives (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8546\"\u003e#8546\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore(deps): bump the minor-and-patch group in /libs/checkpoint with 4 updates (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8490\"\u003e#8490\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efeat(checkpoint,checkpoint-postgres): add opt-in omit_expired to skip expired rows on read (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8354\"\u003e#8354\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore(deps): bump the minor-and-patch group in /libs/checkpoint with 5 updates (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8248\"\u003e#8248\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore(deps): bump langsmith from 0.8.0 to 0.8.18 in /libs/checkpoint (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8173\"\u003e#8173\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003edocs: standardize package \u003ccode\u003eREADME.md\u003c/code\u003e structure (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8064\"\u003e#8064\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore: migrate Python type checking to ty (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8002\"\u003e#8002\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore(deps-dev): bump the major group in /libs/checkpoint with 2 updates (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/7967\"\u003e#7967\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore(deps): bump the minor-and-patch group in /libs/checkpoint with 3 updates (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/7960\"\u003e#7960\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003elanggraph-checkpoint==4.1.1\u003c/h2\u003e\n\u003cp\u003eChanges since checkpoint==4.1.0\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003erelease(checkpoint): 4.1.1 (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/7890\"\u003e#7890\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix(checkpoint): restrict lc:2 envelope revival to default constructor (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/7892\"\u003e#7892\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore(deps): bump idna from 3.11 to 3.15 in /libs/checkpoint (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/7860\"\u003e#7860\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore(deps): bump langsmith from 0.7.31 to 0.8.0 in /libs/checkpoint (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/7784\"\u003e#7784\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003elanggraph-checkpoint==4.1.0\u003c/h2\u003e\n\u003cp\u003eChanges since checkpoint==4.1.0a4\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003erelease: bump alpha packages to official versions (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/7775\"\u003e#7775\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore(deps): bump urllib3 from 2.6.3 to 2.7.0 in /libs/checkpoint (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/7762\"\u003e#7762\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore(deps): bump langchain-core from 1.3.2 to 1.3.3 in /libs/checkpoint (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/7752\"\u003e#7752\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efeat(checkpoint): force delta channel snapshot after max supersteps since last snapshot (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/7746\"\u003e#7746\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix(checkpoint): specify allowed_objects in Reviver (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/7743\"\u003e#7743\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore: remove keepset helper (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/7745\"\u003e#7745\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore(langgraph): add guide/conformance for delta channel checkpointer (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/7736\"\u003e#7736\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003edocs(checkpoint): mark DeltaChannel and delta-history APIs as beta (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/7732\"\u003e#7732\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore(deps): bump the minor-and-patch group across 1 directory with 3 updates (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/7670\"\u003e#7670\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore: \u0026quot;chore: minor clean up around checkpoint and delta channel\u0026quot; (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/7706\"\u003e#7706\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore: minor clean up around checkpoint and delta channel (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/7705\"\u003e#7705\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003elanggraph-checkpoint==4.1.0a4\u003c/h2\u003e\n\u003cp\u003eChanges since checkpoint==4.1.0a3\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003erelease: alpha bump (a4) for langgraph, checkpoint, checkpoint-postgres (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/7701\"\u003e#7701\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efeat: public get_writes_history saver API + delta cadence rework (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/7699\"\u003e#7699\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003elanggraph-checkpoint==4.1.0a3\u003c/h2\u003e\n\u003cp\u003eChanges since checkpoint==4.1.0a2\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003erelease: alpha bump (a3) for langgraph, checkpoint, checkpoint-postgres (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/7678\"\u003e#7678\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore(langgraph): use two phase read to avoid unnecessary data transport (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/7660\"\u003e#7660\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langgraph/commit/f55e77274dad40897ef7b2d52cc7c0b85b792247\"\u003e\u003ccode\u003ef55e772\u003c/code\u003e\u003c/a\u003e release(checkpoint): 4.2.0 (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8563\"\u003e#8563\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langgraph/commit/a90ab4435853b8a5b6f82b20220b4c76af0e46d1\"\u003e\u003ccode\u003ea90ab44\u003c/code\u003e\u003c/a\u003e fix(checkpoint): collect writes at plain-value seed in delta channel history ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langgraph/commit/ea5f9cc9fb8c4b123769daab4753af34de29b1e9\"\u003e\u003ccode\u003eea5f9cc\u003c/code\u003e\u003c/a\u003e chore: enforce PLC0415 in tests for the remaining packages (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8547\"\u003e#8547\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langgraph/commit/36a505ac65e956da09e93cc753609635a511047e\"\u003e\u003ccode\u003e36a505a\u003c/code\u003e\u003c/a\u003e test(checkpoint-postgres,checkpoint-sqlite): run the conformance suite (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8537\"\u003e#8537\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langgraph/commit/d569e18f4bd78b7652cb88c84b8dd098057e4f7d\"\u003e\u003ccode\u003ed569e18\u003c/code\u003e\u003c/a\u003e fix(checkpoint-postgres): find plain-value seeds when walking delta history (...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langgraph/commit/f22af6248c93df08b553e9a264f6367797e0fddb\"\u003e\u003ccode\u003ef22af62\u003c/code\u003e\u003c/a\u003e chore: enable RUF100 and clear unused noqa directives (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8546\"\u003e#8546\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langgraph/commit/658541c4960f329864a2523fc7d52427e8190bed\"\u003e\u003ccode\u003e658541c\u003c/code\u003e\u003c/a\u003e chore(checkpoint-postgres,checkpoint-sqlite): enable PLC0415 lint rule (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8540\"\u003e#8540\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langgraph/commit/fb3d5f0399222504e015fe959e0e79fdc6e00a65\"\u003e\u003ccode\u003efb3d5f0\u003c/code\u003e\u003c/a\u003e chore(deps): bump the minor-and-patch group in /libs/cli/js-examples with 8 u...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langgraph/commit/01521c1b1cc4c035f64b9be40f2913285128f526\"\u003e\u003ccode\u003e01521c1\u003c/code\u003e\u003c/a\u003e chore(deps): bump the minor-and-patch group in /libs/cli/js-monorepo-example ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langgraph/commit/cd62febcfae628d0930d1f7d3cb3b5919d4b800f\"\u003e\u003ccode\u003ecd62feb\u003c/code\u003e\u003c/a\u003e chore(deps): bump the minor-and-patch group in /libs/checkpoint with 4 update...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/langchain-ai/langgraph/compare/checkpoint==4.0.0...checkpoint==4.2.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `langgraph-sdk` from 0.3.9 to 0.4.4\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/langchain-ai/langgraph/releases\"\u003elanggraph-sdk's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003elanggraph-sdk==0.4.4\u003c/h2\u003e\n\u003cp\u003eChanges since sdk==0.4.3\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003erelease(sdk-py): 0.4.4 (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8738\"\u003e#8738\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eMerge commit from fork\u003c/li\u003e\n\u003cli\u003efeat: route LangSmith traces from thread streams (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8723\"\u003e#8723\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003elanggraph-sdk==0.4.3\u003c/h2\u003e\n\u003cp\u003eChanges since sdk==0.4.2\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003erelease(sdk-py): 0.4.3 (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8657\"\u003e#8657\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efeat(sdk-py): add decrypt replacement result (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8598\"\u003e#8598\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003erelease(langgraph): 1.2.11 (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8595\"\u003e#8595\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore(deps): bump the minor-and-patch group across 1 directory with 5 updates (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8532\"\u003e#8532\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003erelease(checkpoint): 4.2.0 (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8563\"\u003e#8563\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore: enforce PLC0415 in tests for the remaining packages (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8547\"\u003e#8547\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003erelease(langgraph): 1.2.10 (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8462\"\u003e#8462\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore(deps): bump websockets from 15.0.1 to 16.0 in /libs/sdk-py in the major group (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8253\"\u003e#8253\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix(sdk-py): support clearing cron end_time via update(end_time=None) (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8334\"\u003e#8334\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003erelease(langgraph): 1.2.9 (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8316\"\u003e#8316\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003erelease(langgraph): 1.2.8 (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8292\"\u003e#8292\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore(deps): bump websockets from 15.0.1 to 16.0 in /libs/langgraph in the major group (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8256\"\u003e#8256\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore(deps): bump the minor-and-patch group in /libs/sdk-py with 9 updates (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8252\"\u003e#8252\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003erelease(langgraph): 1.2.7 (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8223\"\u003e#8223\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore(deps-dev): bump starlette from 1.0.1 to 1.3.1 in /libs/sdk-py (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8104\"\u003e#8104\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore(deps): bump langsmith from 0.8.0 to 0.8.18 in /libs/sdk-py (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8174\"\u003e#8174\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003erelease(langgraph): 1.2.6 (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8139\"\u003e#8139\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003edocs: standardize package \u003ccode\u003eREADME.md\u003c/code\u003e structure (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8064\"\u003e#8064\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003erelease(langgraph): 1.2.5 (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8062\"\u003e#8062\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix(langgraph): merge \u003ccode\u003elc_versions\u003c/code\u003e config metadata (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8052\"\u003e#8052\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore(deps-dev): bump starlette from 1.0.0 to 1.0.1 in /libs/sdk-py (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8006\"\u003e#8006\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore: migrate Python type checking to ty (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8002\"\u003e#8002\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003erelease(langgraph): 1.2.4 (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/7991\"\u003e#7991\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003etest(sdk-py): add factory-graph integration test exercising the server factory path (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/7978\"\u003e#7978\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003erelease(langgraph): 1.2.3 (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/7945\"\u003e#7945\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003elanggraph-sdk==0.4.2\u003c/h2\u003e\n\u003cp\u003eChanges since sdk==0.4.1\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003erelease(sdk-py): 0.4.2 (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/7955\"\u003e#7955\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix(sdk-py): percent-encode thread_id in v3 stream transport default paths (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/7954\"\u003e#7954\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003elanggraph-sdk==0.4.1\u003c/h2\u003e\n\u003cp\u003eChanges since sdk==0.4.0\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003erelease(sdk-py): 0.4.1 (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/7944\"\u003e#7944\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efeat(sdk-py): extract stream decoders and add interleave_projections (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/7935\"\u003e#7935\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efeat(langgraph): add v3 streaming support to RemoteGraph (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/7927\"\u003e#7927\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix(sdk-py): make \u003ccode\u003etools_agent\u003c/code\u003e fake model stateless (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/7930\"\u003e#7930\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langgraph/commit/a64414c87c8db294fd3b1c5581f39f5b491ef07e\"\u003e\u003ccode\u003ea64414c\u003c/code\u003e\u003c/a\u003e langgraph: release 0.4.4 (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/4704\"\u003e#4704\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langgraph/commit/3a1c02ff3364fa68d6659282dc994e5c57fd1833\"\u003e\u003ccode\u003e3a1c02f\u003c/code\u003e\u003c/a\u003e update for consistency\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langgraph/commit/5ab2aa79bb4949ec96d593ffdd3f7fe6d1c7cc32\"\u003e\u003ccode\u003e5ab2aa7\u003c/code\u003e\u003c/a\u003e lint again\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langgraph/commit/c33e64daa6295be3fadd5c8664185fc4268b9f71\"\u003e\u003ccode\u003ec33e64d\u003c/code\u003e\u003c/a\u003e use list\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langgraph/commit/4ffae6065f1c7fe4dc00fed21ee9a584cbbb14b3\"\u003e\u003ccode\u003e4ffae60\u003c/code\u003e\u003c/a\u003e lint + update\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langgraph/commit/54ddde9d4c73a31cb921420867231542ae7faa72\"\u003e\u003ccode\u003e54ddde9\u003c/code\u003e\u003c/a\u003e update\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langgraph/commit/60c41ce69e17fff2367eb816a667dd38cf7bb58e\"\u003e\u003ccode\u003e60...\n\n_Description has been truncated_","html_url":"https://github.com/sdelmas/SREGym/pull/2","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/sdelmas%2FSREGym/issues/2","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/2/packages"},{"uuid":"5493704562","node_id":"PR_kwDONmOZWc8AAAABEAY7cg","number":3,"state":"open","title":"Bump the pip group across 1 directory with 7 updates","user":"dependabot[bot]","labels":["dependencies","python"],"assignees":[],"locked":false,"comments_count":4,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-17T23:24:37.000Z","updated_at":"2026-09-17T23:24:46.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","group_name":"pip","update_count":7,"packages":[{"name":"aiohttp","old_version":"3.8.4","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"cryptography","old_version":"41.0.1","new_version":"50.0.0","repository_url":"https://github.com/pyca/cryptography"},{"name":"httplib2","old_version":"0.22.0","new_version":"0.32.0","repository_url":"https://github.com/httplib2/httplib2"},{"name":"langchain","old_version":"0.0.189","new_version":"1.3.9","repository_url":"https://github.com/langchain-ai/langchain"},{"name":"nltk","old_version":"3.8.1","new_version":"3.10.3","repository_url":"https://github.com/nltk/nltk"},{"name":"pillow","old_version":"9.5.0","new_version":"12.3.0","repository_url":"https://github.com/python-pillow/Pillow"},{"name":"soupsieve","old_version":"2.4.1","new_version":"2.9","repository_url":"https://github.com/facelessuser/soupsieve"}],"path":null,"ecosystem":"pip"},"body":"Bumps the pip group with 7 updates in the /document-processor directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [aiohttp](https://github.com/aio-libs/aiohttp) | `3.8.4` | `3.14.3` |\n| [cryptography](https://github.com/pyca/cryptography) | `41.0.1` | `50.0.0` |\n| [httplib2](https://github.com/httplib2/httplib2) | `0.22.0` | `0.32.0` |\n| [langchain](https://github.com/langchain-ai/langchain) | `0.0.189` | `1.3.9` |\n| [nltk](https://github.com/nltk/nltk) | `3.8.1` | `3.10.3` |\n| [pillow](https://github.com/python-pillow/Pillow) | `9.5.0` | `12.3.0` |\n| [soupsieve](https://github.com/facelessuser/soupsieve) | `2.4.1` | `2.9` |\n\n\nUpdates `aiohttp` from 3.8.4 to 3.14.3\nUpdates `cryptography` from 41.0.1 to 50.0.0\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst\"\u003ecryptography's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e50.0.0 - 2026-07-31\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003e\n* **SECURITY ISSUE**:\n  :func:`~cryptography.hazmat.primitives.serialization.pkcs7.pkcs7_decrypt_der`\n  and its PEM and S/MIME variants no longer expose distinguishable errors or\n  timing when unwrapping a ``RecipientInfo``'s ``encryptedKey``, which could\n  act as a Bleichenbacher oracle for callers that decrypt untrusted messages.\n  A random key is now substituted on failure, as described in :rfc:`3218`.\n  Credit to **@X1AOxiang** for reporting the issue. **CVE-2026-69247**\n* Deprecated Diffie-Hellman key exchange over finite fields (FFDH).\n  Everything FFDH is deprecated, including the types in\n  ``cryptography.hazmat.primitives.asymmetric.dh`` and loading FFDH keys or\n  parameters with the key loading APIs. Users should migrate to a more\n  modern key exchange algorithm.\n* Added ``xof()`` class methods to\n  :class:`~cryptography.hazmat.primitives.hashes.SHAKE128` and\n  :class:`~cryptography.hazmat.primitives.hashes.SHAKE256` for constructing\n  algorithm instances configured for use with\n  :class:`~cryptography.hazmat.primitives.hashes.XOFHash`.\n* The :mod:`X.509 verification \u0026lt;cryptography.x509.verification\u0026gt;` APIs are now\n  considered stable and are subject to our API stability policy.\n* Added the :doc:`/cobblestone` recipe, an implementation of the\n  Cobblestone-128 and Cobblestone-256 instantiations of the `C2SP\n  chunked-encryption specification\n  \u0026lt;https://c2sp.org/chunked-encryption\u0026gt;`_ for streaming authenticated\n  encryption of large messages.\n* Parsing a Signed Certificate Timestamp list now rejects encodings that\n  carry trailing bytes after the list or after an individual SCT, instead of\n  silently ignoring them.\n* Added support for using :class:`~cryptography.x509.Name` as a field type in\n  the :doc:`/hazmat/asn1/index` module.\n* Loading a public key or an EC private key now rejects DER where the\n  ``subjectPublicKey`` (or EC ``publicKey``) ``BIT STRING`` declares a non-zero\n  number of unused bits, instead of silently ignoring it.\n* Parsing a CRL entry's ``InvalidityDate`` extension now rejects a\n  ``GeneralizedTime`` that carries fractional seconds or another non-DER form,\n  matching the strict encoding already required for every other X.509 time\n  field.\n* :func:`~cryptography.x509.ocsp.load_der_ocsp_request` and\n  :func:`~cryptography.x509.ocsp.load_der_ocsp_response` now reject a request\n  or response whose ``version`` field is not ``v1``, the only version defined\n  by RFC 6960, matching the version validation already performed when loading\n  certificates, CSRs and CRLs.\n* :class:`~cryptography.hazmat.primitives.hashes.XOFHash` is now supported\n  when building against AWS-LC.\n* HMAC (and therefore PBKDF2-HMAC) with SHA-3 hashes is now supported when\n  building against AWS-LC.\n* Diffie-Hellman (:doc:`/hazmat/primitives/asymmetric/dh`) is now supported\n  when building against AWS-LC.\n\u0026lt;/tr\u0026gt;\u0026lt;/table\u0026gt; \n\u003c/code\u003e\u003c/pre\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/dcb7050b807b00392fa9fe2eac7cb362fcf355cc\"\u003e\u003ccode\u003edcb7050\u003c/code\u003e\u003c/a\u003e Prepare for 50.0.0 release (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15372\"\u003e#15372\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/53fccd93413a8d7f07d6d8999681f27b75cffa3f\"\u003e\u003ccode\u003e53fccd9\u003c/code\u003e\u003c/a\u003e Don't leak how PKCS#7 encryptedKey decryption failed (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15369\"\u003e#15369\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/d472f978470fbefa521b86d98b2ecccbbb4d1dd8\"\u003e\u003ccode\u003ed472f97\u003c/code\u003e\u003c/a\u003e Add \u003ccode\u003efrom __future__ import annotations\u003c/code\u003e to all src/ Python files (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15371\"\u003e#15371\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/908773d53829fb1466c6db364b31321c3cd8eb9a\"\u003e\u003ccode\u003e908773d\u003c/code\u003e\u003c/a\u003e Bump downstream dependencies in CI (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15368\"\u003e#15368\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/2cc07cc948948211899bcb0cddd1fddf86e95812\"\u003e\u003ccode\u003e2cc07cc\u003c/code\u003e\u003c/a\u003e Bump BoringSSL, OpenSSL, AWS-LC in CI (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15367\"\u003e#15367\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/c94ede9f040fa44942f7139772603419000acf66\"\u003e\u003ccode\u003ec94ede9\u003c/code\u003e\u003c/a\u003e chore(deps): bump ruff from 0.16.0 to 0.16.1 (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15366\"\u003e#15366\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/67a8308dc9ea4cce6056e0f1438f903c208c3f35\"\u003e\u003ccode\u003e67a8308\u003c/code\u003e\u003c/a\u003e chore(deps): bump virtualenv from 21.7.0 to 21.7.1 (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15365\"\u003e#15365\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/95018ffcdbbc510fd92fc872e3a3e80aa6e58596\"\u003e\u003ccode\u003e95018ff\u003c/code\u003e\u003c/a\u003e Release the GIL in one-shot AEAD encrypt/decrypt (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15361\"\u003e#15361\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/6954733eaf55a0074abf88f06f7242dfca3a5d02\"\u003e\u003ccode\u003e6954733\u003c/code\u003e\u003c/a\u003e Release the GIL during DH and DSA parameter generation (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15364\"\u003e#15364\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/6893b94c33e948f6240082461424cfb5da2dacc6\"\u003e\u003ccode\u003e6893b94\u003c/code\u003e\u003c/a\u003e Import _serialization instead of serialization in x509/extensions (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15363\"\u003e#15363\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/pyca/cryptography/compare/41.0.1...50.0.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `httplib2` from 0.22.0 to 0.32.0\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/httplib2/httplib2/blob/master/CHANGELOG\"\u003ehttplib2's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e0.32.0\u003c/p\u003e\n\u003cp\u003ePython support 3.8+ only\u003c/p\u003e\n\u003cp\u003edecompression limited by size and ratio\u003c/p\u003e\n\u003cp\u003edecoder foundation to support more compression algorithms\u003c/p\u003e\n\u003cp\u003e0.31.2\u003c/p\u003e\n\u003cp\u003ebuild(deps): pp.DelimitedList (camel case) only available in pyparsing\u0026gt;=3.1\n\u003ca href=\"https://redirect.github.com/httplib2/httplib2/issues/255\"\u003ehttplib2/httplib2#255\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eDO NOT use 0.31.1\u003c/p\u003e\n\u003cp\u003e0.31.1\u003c/p\u003e\n\u003cp\u003eauth: use pyparsing v3 PEP8-compliant method names\n\u003ca href=\"https://redirect.github.com/httplib2/httplib2/pull/253\"\u003ehttplib2/httplib2#253\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e0.31.0\u003c/p\u003e\n\u003cp\u003ehttps: avoid costly load_verify_locations when SSL certificate validation is disabled\n\u003ca href=\"https://redirect.github.com/httplib2/httplib2/pull/249\"\u003ehttplib2/httplib2#249\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e0.30.2\u003c/p\u003e\n\u003cp\u003eNo changes in library. Fix automatic pypi release from CI.\u003c/p\u003e\n\u003cp\u003e0.30.1\u003c/p\u003e\n\u003cp\u003erestore socks proxy support, was broken in 0.30.0\n\u003ca href=\"https://redirect.github.com/httplib2/httplib2/issues/251\"\u003ehttplib2/httplib2#251\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e0.30.0\u003c/p\u003e\n\u003cp\u003eBREAKING CHANGE! Python support 3.7+ only\u003c/p\u003e\n\u003cp\u003ehttps: Do not rely on ssl.PROTOCOL_TLS, which has been deprecated in Python3.10\n\u003ca href=\"https://redirect.github.com/httplib2/httplib2/pull/243\"\u003ehttplib2/httplib2#243\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/httplib2/httplib2/commit/ba9bf505cd899f522f2bb58ca608444adf49afc1\"\u003e\u003ccode\u003eba9bf50\u003c/code\u003e\u003c/a\u003e v0.32.0 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/httplib2/httplib2/commit/87581ad6cf752fe3da2090c59058261d2d00a427\"\u003e\u003ccode\u003e87581ad\u003c/code\u003e\u003c/a\u003e decompression limited by size and ratio; require python 3.8+\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/httplib2/httplib2/commit/a99a11fba8d5fa3bb9c47827e5cbfd641dfb88d3\"\u003e\u003ccode\u003ea99a11f\u003c/code\u003e\u003c/a\u003e v0.31.2 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/httplib2/httplib2/commit/370010a12ef4b97ebeeac59f52d071de7bc3faa8\"\u003e\u003ccode\u003e370010a\u003c/code\u003e\u003c/a\u003e dep-compat: pp.DelimitedList (camel case) only available in pyparsing\u0026gt;=3.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/httplib2/httplib2/commit/6d2ea322d53a03d058cd8e63c12871cdd1127ca9\"\u003e\u003ccode\u003e6d2ea32\u003c/code\u003e\u003c/a\u003e v0.31.1 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/httplib2/httplib2/commit/d1b0ce329667f0b0047381c089e53ea1055f2fca\"\u003e\u003ccode\u003ed1b0ce3\u003c/code\u003e\u003c/a\u003e auth: use pyparsing v3 PEP8-compliant method names\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/httplib2/httplib2/commit/3288ba77ccb1924a6a79350f300ebb84140ec064\"\u003e\u003ccode\u003e3288ba7\u003c/code\u003e\u003c/a\u003e chore: harden publishing. use github attestations\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/httplib2/httplib2/commit/26cfea5d07a5817cf214d9978c856c91abf4e078\"\u003e\u003ccode\u003e26cfea5\u003c/code\u003e\u003c/a\u003e v0.31.0 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/httplib2/httplib2/commit/cbd3d21004374997167d9b8ab36b4ec211881a57\"\u003e\u003ccode\u003ecbd3d21\u003c/code\u003e\u003c/a\u003e chore: CI use trusted publishing\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/httplib2/httplib2/commit/147d7d5d00b4cd383dbdda839089237aa0c2a836\"\u003e\u003ccode\u003e147d7d5\u003c/code\u003e\u003c/a\u003e https: avoid costly load_verify_locations when SSL certificate validation is ...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/httplib2/httplib2/compare/v0.22.0...v0.32.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `langchain` from 0.0.189 to 1.3.9\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/langchain-ai/langchain/releases\"\u003elangchain's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003elangchain==1.3.9\u003c/h2\u003e\n\u003cp\u003eChanges since langchain==1.3.8\u003c/p\u003e\n\u003cp\u003erelease(anthropic): 1.4.6 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38105\"\u003e#38105\u003c/a\u003e)\nrelease(langchain): 1.3.9 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38104\"\u003e#38104\u003c/a\u003e)\nfix(langchain,anthropic): confine file-search results and tighten anthropic \u003ccode\u003eallowed_prefixes\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38106\"\u003e#38106\u003c/a\u003e)\u003c/p\u003e\n\u003ch2\u003elangchain==1.3.8\u003c/h2\u003e\n\u003cp\u003eChanges since langchain==1.3.7\u003c/p\u003e\n\u003cp\u003erelease(langchain): 1.3.8 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38096\"\u003e#38096\u003c/a\u003e)\nstyle(core,langchain,langchain-classic,partners): replace double backticks in docstrings (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38095\"\u003e#38095\u003c/a\u003e)\nrelease(core): 1.4.6 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38061\"\u003e#38061\u003c/a\u003e)\nchore(langchain): add overloads to \u003ccode\u003ecreate_agent\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/34309\"\u003e#34309\u003c/a\u003e)\nchore(infra): bump mypy to 2.1 and unify type-check config across the monorepo (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/36470\"\u003e#36470\u003c/a\u003e)\nfix(langchain): support async middleware decorator typing (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/34584\"\u003e#34584\u003c/a\u003e)\nfix(langchain): tighten structured output model fallbacks (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38042\"\u003e#38042\u003c/a\u003e)\nrelease(anthropic): 1.4.5 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38036\"\u003e#38036\u003c/a\u003e)\nhotfix(core): bump lockfile(s) (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38032\"\u003e#38032\u003c/a\u003e)\nrefactor(langchain): refactor \u003ccode\u003etest_create_agent_tool_validation\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/34443\"\u003e#34443\u003c/a\u003e)\u003c/p\u003e\n\u003ch2\u003elangchain==1.3.7\u003c/h2\u003e\n\u003cp\u003eChanges since langchain==1.3.6\u003c/p\u003e\n\u003cp\u003erelease(langchain): 1.3.7 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38024\"\u003e#38024\u003c/a\u003e)\nstyle(langchain): add ruff rules ARG (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/34435\"\u003e#34435\u003c/a\u003e)\nfeat(langchain): add \u003ccode\u003eProviderToolSearchMiddleware\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/37969\"\u003e#37969\u003c/a\u003e)\nchore(langchain): activate mypy \u003ccode\u003ewarn_return_any\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/34249\"\u003e#34249\u003c/a\u003e)\ntest(langchain): mark legacy trigger view for 2.0 removal (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38002\"\u003e#38002\u003c/a\u003e)\u003c/p\u003e\n\u003ch2\u003elangchain==1.3.6\u003c/h2\u003e\n\u003cp\u003eChanges since langchain==1.3.5\u003c/p\u003e\n\u003cp\u003erelease(langchain): 1.3.6 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38001\"\u003e#38001\u003c/a\u003e)\nfix(langchain): preserve summarization trigger compatibility (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38000\"\u003e#38000\u003c/a\u003e)\u003c/p\u003e\n\u003ch2\u003elangchain==1.3.5\u003c/h2\u003e\n\u003cp\u003eChanges since langchain==1.3.4\u003c/p\u003e\n\u003cp\u003erelease(langchain): 1.3.5 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/37998\"\u003e#37998\u003c/a\u003e)\nfeat(langchain): port AND-capable trigger conditions to \u003ccode\u003eSummarizationMiddleware\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/34576\"\u003e#34576\u003c/a\u003e)\nhotfix(openai): min core dep (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/37990\"\u003e#37990\u003c/a\u003e)\nfeat(openai): support \u003ccode\u003eapply_patch\u003c/code\u003e built-in tool (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/37157\"\u003e#37157\u003c/a\u003e)\nchore: bump pyarrow from 21.0.0 to 23.0.1 in /libs/langchain_v1 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/37930\"\u003e#37930\u003c/a\u003e)\nchore: bump dependencies  (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/37892\"\u003e#37892\u003c/a\u003e)\nchore: bump aiohttp from 3.13.4 to 3.14.0 in /libs/langchain_v1 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/37888\"\u003e#37888\u003c/a\u003e)\u003c/p\u003e\n\u003ch2\u003elangchain-openai==1.3.5\u003c/h2\u003e\n\u003cp\u003eChanges since langchain-openai==1.3.4\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/3bfb6a33e788aaca1626a7c09cbdbdbef6977012\"\u003e\u003ccode\u003e3bfb6a3\u003c/code\u003e\u003c/a\u003e release(langchain): 1.3.9 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38104\"\u003e#38104\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/dcaf7795a3e6590af55c3ff7bda6add6355e9ea6\"\u003e\u003ccode\u003edcaf779\u003c/code\u003e\u003c/a\u003e fix(langchain,anthropic): confine file-search results and tighten anthropic `...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/0392b6bae4bdfc0b7ed5aeb2e9e414bbb7ea643b\"\u003e\u003ccode\u003e0392b6b\u003c/code\u003e\u003c/a\u003e fix(core): fix Pydantic v1 support in tools/runnable (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/33698\"\u003e#33698\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/f6d63bc9f344b2949e91a6904d301553376b4f10\"\u003e\u003ccode\u003ef6d63bc\u003c/code\u003e\u003c/a\u003e release(langchain): 1.3.8 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38096\"\u003e#38096\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/5d20596d73789020f53c622b22c0a9893ba09606\"\u003e\u003ccode\u003e5d20596\u003c/code\u003e\u003c/a\u003e style(core,langchain,langchain-classic,partners): replace double backticks in...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/fb55c6660a2ac26038a64dac1534048294bc51ab\"\u003e\u003ccode\u003efb55c66\u003c/code\u003e\u003c/a\u003e chore: bump langsmith from 0.8.9 to 0.8.14 in /libs/partners/huggingface (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38\"\u003e#38\u003c/a\u003e...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/51daae5c139712f6f1347b5a801f672680ba1eba\"\u003e\u003ccode\u003e51daae5\u003c/code\u003e\u003c/a\u003e chore: bump langsmith from 0.8.9 to 0.8.14 in /libs/partners/chroma (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38092\"\u003e#38092\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/70e9579e433043321fb8e93a8a51770c946363d0\"\u003e\u003ccode\u003e70e9579\u003c/code\u003e\u003c/a\u003e chore: bump langsmith from 0.8.9 to 0.8.14 in /libs/partners/fireworks (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38093\"\u003e#38093\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/6c0e9af3246e3bbf98838e4b9ec563ad563dd748\"\u003e\u003ccode\u003e6c0e9af\u003c/code\u003e\u003c/a\u003e chore: bump langsmith from 0.8.9 to 0.8.14 in /libs/partners/xai (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38094\"\u003e#38094\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/222dc846e0e965a0d6764d772226590eec14b917\"\u003e\u003ccode\u003e222dc84\u003c/code\u003e\u003c/a\u003e ci(infra): clarify early PR auto-close guidance (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38090\"\u003e#38090\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/langchain-ai/langchain/compare/v0.0.189...langchain==1.3.9\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `nltk` from 3.8.1 to 3.10.3\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nltk/nltk/releases\"\u003enltk's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev3.10.3\u003c/h2\u003e\n\u003cp\u003eVersion 3.10.3 2026-08-12\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003edocs: wrap Chat-80 HOWTO output\u003c/li\u003e\n\u003cli\u003eSandbox Stanford JAR execution to nltk_data directories\u003c/li\u003e\n\u003cli\u003eHarden path-traversal / file-I/O sandbox: close write-side symlink TOCTOU + shared-temp squat, lock the cluster with a living audit (CWE-22/59/377)\u003c/li\u003e\n\u003cli\u003eExtend algorithmic-complexity DoS hardening: repo-wide sweep + two-string distances (CWE-407/CWE-400)\u003c/li\u003e\n\u003cli\u003eBound unbounded-work DoS in parsers and grammar transforms (CWE-407/674/835)\u003c/li\u003e\n\u003cli\u003efix(security): sandbox MaltParser's Java execution (CVE-2026-12252, CVE-2026-12841)\u003c/li\u003e\n\u003cli\u003efix(security): trust the system temp dir only when it is private (CWE-377/CWE-378)\u003c/li\u003e\n\u003cli\u003efix(security): validate corpus-reader roots against the data sandbox (CWE-73)\u003c/li\u003e\n\u003cli\u003efix(security): validate per-call java() options and replace the -XX:/-D allowlist with a minimal one (CWE-88)\u003c/li\u003e\n\u003cli\u003eAdditional security hardening (CWE-407, CWE-426, CWE-427, CWE-502, CWE-59, CWE-776, CWE-918)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThanks to the following contributors to 3.10.3: Mohammad Favas S, leduckhuong, Ziyu Lin, dougtrainer28-cmyk, Chaitanya Kadian, 0xRenSec, Arpit Jain, Jace, nguyencanhthuong, Liling Tan, medimedi, Eric Kafe.\u003c/p\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSandbox Stanford JAR execution to nltk_data directories by \u003ca href=\"https://github.com/ekaf\"\u003e\u003ccode\u003e@​ekaf\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nltk/nltk/pull/3743\"\u003enltk/nltk#3743\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003edocs: wrap Chat-80 HOWTO output by \u003ca href=\"https://github.com/medisean\"\u003e\u003ccode\u003e@​medisean\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nltk/nltk/pull/3741\"\u003enltk/nltk#3741\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: sandboxed-open guard + stabilize security tests across platforms/pythons (\u003ca href=\"https://redirect.github.com/nltk/nltk/issues/3740\"\u003e#3740\u003c/a\u003e) by \u003ca href=\"https://github.com/alvations\"\u003e\u003ccode\u003e@​alvations\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nltk/nltk/pull/3744\"\u003enltk/nltk#3744\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePrepare release 3.10.3 by \u003ca href=\"https://github.com/ekaf\"\u003e\u003ccode\u003e@​ekaf\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nltk/nltk/pull/3745\"\u003enltk/nltk#3745\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/medisean\"\u003e\u003ccode\u003e@​medisean\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/nltk/nltk/pull/3741\"\u003enltk/nltk#3741\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/nltk/nltk/compare/v3.10.2...v3.10.3\"\u003ehttps://github.com/nltk/nltk/compare/v3.10.2...v3.10.3\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.10.3-rc1\u003c/h2\u003e\n\u003cp\u003eVersion 3.10.3 2026-08-12\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003edocs: wrap Chat-80 HOWTO output\u003c/li\u003e\n\u003cli\u003eSandbox Stanford JAR execution to nltk_data directories\u003c/li\u003e\n\u003cli\u003eHarden path-traversal / file-I/O sandbox: close write-side symlink TOCTOU + shared-temp squat, lock the cluster with a living audit (CWE-22/59/377)\u003c/li\u003e\n\u003cli\u003eExtend algorithmic-complexity DoS hardening: repo-wide sweep + two-string distances (CWE-407/CWE-400)\u003c/li\u003e\n\u003cli\u003eBound unbounded-work DoS in parsers and grammar transforms (CWE-407/674/835)\u003c/li\u003e\n\u003cli\u003efix(security): sandbox MaltParser's Java execution (CVE-2026-12252, CVE-2026-12841)\u003c/li\u003e\n\u003cli\u003efix(security): trust the system temp dir only when it is private (CWE-377/CWE-378)\u003c/li\u003e\n\u003cli\u003efix(security): validate corpus-reader roots against the data sandbox (CWE-73)\u003c/li\u003e\n\u003cli\u003efix(security): validate per-call java() options and replace the -XX:/-D allowlist with a minimal one (CWE-88)\u003c/li\u003e\n\u003cli\u003eAdditional security hardening (CWE-407, CWE-426, CWE-427, CWE-502, CWE-59, CWE-776, CWE-918)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThanks to the following contributors to 3.10.3: Mohammad Favas S, leduckhuong, Ziyu Lin, dougtrainer28-cmyk, Chaitanya Kadian, 0xRenSec, Arpit Jain, Jace, nguyencanhthuong, Liling Tan, medimedi, Eric Kafe.\u003c/p\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSandbox Stanford JAR execution to nltk_data directories by \u003ca href=\"https://github.com/ekaf\"\u003e\u003ccode\u003e@​ekaf\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nltk/nltk/pull/3743\"\u003enltk/nltk#3743\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003edocs: wrap Chat-80 HOWTO output by \u003ca href=\"https://github.com/medisean\"\u003e\u003ccode\u003e@​medisean\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nltk/nltk/pull/3741\"\u003enltk/nltk#3741\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nltk/nltk/blob/develop/ChangeLog\"\u003enltk's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003eVersion 3.10.3 2026-08-12\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003edocs: wrap Chat-80 HOWTO output\u003c/li\u003e\n\u003cli\u003eSandbox Stanford JAR execution to nltk_data directories\u003c/li\u003e\n\u003cli\u003eHarden path-traversal / file-I/O sandbox: close write-side symlink TOCTOU + shared-temp squat, lock the cluster with a living audit (CWE-22/59/377)\u003c/li\u003e\n\u003cli\u003eExtend algorithmic-complexity DoS hardening: repo-wide sweep + two-string distances (CWE-407/CWE-400)\u003c/li\u003e\n\u003cli\u003eBound unbounded-work DoS in parsers and grammar transforms (CWE-407/674/835)\u003c/li\u003e\n\u003cli\u003efix(security): sandbox MaltParser's Java execution (CVE-2026-12252, CVE-2026-12841)\u003c/li\u003e\n\u003cli\u003efix(security): trust the system temp dir only when it is private (CWE-377/CWE-378)\u003c/li\u003e\n\u003cli\u003efix(security): validate corpus-reader roots against the data sandbox (CWE-73)\u003c/li\u003e\n\u003cli\u003efix(security): validate per-call java() options and replace the -XX:/-D allowlist with a minimal one (CWE-88)\u003c/li\u003e\n\u003cli\u003eAdditional security hardening (CWE-407, CWE-426, CWE-427, CWE-502, CWE-59, CWE-776, CWE-918)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThanks to the following contributors to 3.10.3: Mohammad Favas S, leduckhuong, Ziyu Lin, dougtrainer28-cmyk, Chaitanya Kadian, 0xRenSec, Arpit Jain, Jace, nguyencanhthuong, Liling Tan, medimedi, Eric Kafe.\u003c/p\u003e\n\u003cp\u003eVersion 3.10.2 2026-08-05\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eRemove inisec.py and document PYTHONSAFEPATH instead\u003c/li\u003e\n\u003cli\u003eSkip draft step in release workflow\u003c/li\u003e\n\u003cli\u003eFix symlink escape in FramenetCorpusReader (CWE-59)\u003c/li\u003e\n\u003cli\u003eGuard tempfile.gettempdir() when building pathsec allowed roots\u003c/li\u003e\n\u003cli\u003eadd tests for transitive_closure\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThanks to the following contributors to 3.10.2:\nLitesh Ghute, Eric Kafe, Evan Kiefer, tarann26 and Rav Singh Chandan\u003c/p\u003e\n\u003cp\u003eVersion 3.10.1 2026-07-29\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eExpand \u003ccode\u003e~\u003c/code\u003e in env-var paths\u003c/li\u003e\n\u003cli\u003eValidate types after WordNet app pickle deserialization\u003c/li\u003e\n\u003cli\u003eFix uncontrolled search path in HunposTagger\u003c/li\u003e\n\u003cli\u003eUse exact thirds in \u003ccode\u003emasi_distance\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eAvoid retaining bllip import exceptions\u003c/li\u003e\n\u003cli\u003eFix \u003ccode\u003eword_tokenize\u003c/code\u003e: pad opening single quote before multi-letter words.\u003c/li\u003e\n\u003cli\u003eImplement \u003ccode\u003eTree.pformat_latex_forest\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003ePrevent module hijacking in inline imports.\u003c/li\u003e\n\u003cli\u003eFix ReDoS in TweetTokenizer URL and email regexes.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThanks to the following contributors to 3.10.1:\nAbhinav, Litesh Ghute, Eric Kafe, Eryk Kaźmierczak, Selim C.,\nMuhtasim Munif Fahim, Triniti K., and Tom Y. Mitich.\u003c/p\u003e\n\u003cp\u003eVersion 3.10.0 2026-06-11\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eEnforce the stricter \u003ccode\u003enltk.pathsec\u003c/code\u003e security policy by default\u003c/li\u003e\n\u003cli\u003eDocument the new security model and migration guidance\u003c/li\u003e\n\u003cli\u003eHarden resource loading against path traversal and SSRF/DNS-rebinding\u003c/li\u003e\n\u003cli\u003eHarden downloader path handling and block XML entity expansion\u003c/li\u003e\n\u003cli\u003eClose remaining corpus-reader security edge cases\u003c/li\u003e\n\u003cli\u003eReplace unsafe \u003ccode\u003eexec()\u003c/code\u003e usage in the utility CLI\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nltk/nltk/commit/303f6e2ba8e4548a5f54fd65d86bb5c9a949f1db\"\u003e\u003ccode\u003e303f6e2\u003c/code\u003e\u003c/a\u003e Prepare release 3.10.3 (\u003ca href=\"https://redirect.github.com/nltk/nltk/issues/3745\"\u003e#3745\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nltk/nltk/commit/cf2aaacc3d99533a73e86709c1d839966ea25e17\"\u003e\u003ccode\u003ecf2aaac\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/nltk/nltk/issues/3744\"\u003e#3744\u003c/a\u003e from alvations/ci-guard-open\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nltk/nltk/commit/6cd8320cee54d4fc271610e744f71d44cb367dda\"\u003e\u003ccode\u003e6cd8320\u003c/code\u003e\u003c/a\u003e test: robustness on Python 3.14 / 3.14t CI (UnicodeDecodeError + timing flake)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nltk/nltk/commit/e965330e017d8180843c4a12b91bcfadd5d4e489\"\u003e\u003ccode\u003ee965330\u003c/code\u003e\u003c/a\u003e fix: perceptron save_to_json breaks on Windows (os.open can't fd-open a direc...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nltk/nltk/commit/df1bb4c5742c8943205e4564a7c03e1992cf4f4d\"\u003e\u003ccode\u003edf1bb4c\u003c/code\u003e\u003c/a\u003e test: make pathsec security tests platform-independent (fix Linux/Windows CI)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nltk/nltk/commit/0e5c7be3793cf826039a2048846138e58f864553\"\u003e\u003ccode\u003e0e5c7be\u003c/code\u003e\u003c/a\u003e ci: guard against un-sandboxed open() in sandbox-sensitive modules (\u003ca href=\"https://redirect.github.com/nltk/nltk/issues/3740\"\u003e#3740\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nltk/nltk/commit/50178263a0787a7850e66f3e85775338669f101a\"\u003e\u003ccode\u003e5017826\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nltk/nltk/commit/40d0f062649022f7f36afed4a2ca3980f574aae9\"\u003e\u003ccode\u003e40d0f06\u003c/code\u003e\u003c/a\u003e Triple-check hardening: perceptron TOCTOU squat, pathsec fd-leak, bcp47 entit...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nltk/nltk/commit/483c5fe650542ceaa2b45e8565f72e878834376f\"\u003e\u003ccode\u003e483c5fe\u003c/code\u003e\u003c/a\u003e Harden path-traversal / file-I/O sandbox: close write-side symlink TOCTOU + s...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nltk/nltk/commit/722778fd9ff987da3cf5ff6e442ac43fed1637b0\"\u003e\u003ccode\u003e722778f\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/nltk/nltk/compare/3.8.1...v3.10.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `pillow` from 9.5.0 to 12.3.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/python-pillow/Pillow/releases\"\u003epillow's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e12.3.0\u003c/h2\u003e\n\u003cp\u003e\u003ca href=\"https://pillow.readthedocs.io/en/stable/releasenotes/12.3.0.html\"\u003ehttps://pillow.readthedocs.io/en/stable/releasenotes/12.3.0.html\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eRemovals\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRemove non-image ImageCms modes \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9697\"\u003e#9697\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eDocumentation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd release notes for SBOM and performance improvements \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9747\"\u003e#9747\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdd security release notes \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9741\"\u003e#9741\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdd release notes for Python 3.15 beta wheels \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9696\"\u003e#9696\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eImageFont can also be used with ImageText \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9597\"\u003e#9597\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdditional guidelines for security reports \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9659\"\u003e#9659\u003c/a\u003e [\u003ca href=\"https://github.com/wiredfool\"\u003e\u003ccode\u003e@​wiredfool\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eFixed typo \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9636\"\u003e#9636\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdded CVEs to 12.2.0 release notes \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9591\"\u003e#9591\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eRevise development support information in README \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9583\"\u003e#9583\u003c/a\u003e [\u003ca href=\"https://github.com/aclark4life\"\u003e\u003ccode\u003e@​aclark4life\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdd INCIDENT_RESPONSE.md \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9555\"\u003e#9555\u003c/a\u003e [\u003ca href=\"https://github.com/aclark4life\"\u003e\u003ccode\u003e@​aclark4life\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdd STRIDE threat model to security docs \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9562\"\u003e#9562\u003c/a\u003e [\u003ca href=\"https://github.com/aclark4life\"\u003e\u003ccode\u003e@​aclark4life\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdd CVEs to 12.2.0 release notes \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9556\"\u003e#9556\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate README with revised security policy \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9553\"\u003e#9553\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate security policy \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9552\"\u003e#9552\u003c/a\u003e [\u003ca href=\"https://github.com/aclark4life\"\u003e\u003ccode\u003e@​aclark4life\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate macOS tested Python versions \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9534\"\u003e#9534\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eDependencies\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate dependency harfbuzz to v14.2.1 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9720\"\u003e#9720\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency mypy to v2 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9653\"\u003e#9653\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency cibuildwheel to v4 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9665\"\u003e#9665\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate github-actions \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9655\"\u003e#9655\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency libavif to v1.4.2 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9652\"\u003e#9652\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency lcms2 to v2.19.1 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9651\"\u003e#9651\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency check-jsonschema to v0.37.2 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9650\"\u003e#9650\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate google/oss-fuzz digest to d872252 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9614\"\u003e#9614\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency lcms2 to v2.19 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9609\"\u003e#9609\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency libpng to v1.6.58 - autoclosed \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9608\"\u003e#9608\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency harfbuzz to v14 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9610\"\u003e#9610\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency mypy to v1.20.2 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9599\"\u003e#9599\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate github-actions \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9611\"\u003e#9611\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency cibuildwheel to v3.4.1 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9607\"\u003e#9607\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eMove dependency versions to single JSON and enable Renovate \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9559\"\u003e#9559\u003c/a\u003e [\u003ca href=\"https://github.com/hugovk\"\u003e\u003ccode\u003e@​hugovk\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdated raqm to 0.10.5 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9557\"\u003e#9557\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency cibuildwheel to v3.4.0 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9532\"\u003e#9532\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eTesting\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRemove matrix.os from benchmark \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9735\"\u003e#9735\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eRemove references to libavif patch \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9734\"\u003e#9734\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdd benchmark tests \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9654\"\u003e#9654\u003c/a\u003e [\u003ca href=\"https://github.com/akx\"\u003e\u003ccode\u003e@​akx\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUse reshape() instead of setting NumPy array shape directly \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9728\"\u003e#9728\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/python-pillow/Pillow/blob/main/CHANGES.rst\"\u003epillow's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003eChangelog (Pillow)\u003c/h1\u003e\n\u003ch2\u003e11.1.0 and newer\u003c/h2\u003e\n\u003cp\u003eSee GitHub Releases:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/releases\"\u003ehttps://github.com/python-pillow/Pillow/releases\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e11.0.0 (2024-10-15)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eUpdate licence to MIT-CMU \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/8460\"\u003e#8460\u003c/a\u003e\n[hugovk]\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eConditionally define ImageCms type hint to avoid requiring core \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/8197\"\u003e#8197\u003c/a\u003e\n[radarhere]\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eSupport writing LONG8 offsets in AppendingTiffWriter \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/8417\"\u003e#8417\u003c/a\u003e\n[radarhere]\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUse ImageFile.MAXBLOCK when saving TIFF images \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/8461\"\u003e#8461\u003c/a\u003e\n[radarhere]\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eDo not close provided file handles with libtiff when saving \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/8458\"\u003e#8458\u003c/a\u003e\n[radarhere]\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eSupport ImageFilter.BuiltinFilter for I;16* images \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/8438\"\u003e#8438\u003c/a\u003e\n[radarhere]\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUse ImagingCore.ptr instead of ImagingCore.id \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/8341\"\u003e#8341\u003c/a\u003e\n[homm, radarhere, hugovk]\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUpdated EPS mode when opening images without transparency \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/8281\"\u003e#8281\u003c/a\u003e\n[Yay295, radarhere]\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUse transparency when combining P frames from APNGs \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/8443\"\u003e#8443\u003c/a\u003e\n[radarhere]\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eSupport all resampling filters when resizing I;16* images \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/8422\"\u003e#8422\u003c/a\u003e\n[radarhere]\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFree memory on early return \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/8413\"\u003e#8413\u003c/a\u003e\n[radarhere]\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eCast int before potentially exceeding INT_MAX \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/8402\"\u003e#8402\u003c/a\u003e\n[radarhere]\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/bb1d8e8ab8d29048624d96e3ee53cecf7c13d13d\"\u003e\u003ccode\u003ebb1d8e8\u003c/code\u003e\u003c/a\u003e 12.3.0 version bump\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/e63fc481dc2e07e21d5403deafb8f1ed98a513af\"\u003e\u003ccode\u003ee63fc48\u003c/code\u003e\u003c/a\u003e Add release notes for SBOM and performance improvements (\u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9747\"\u003e#9747\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/13b701bbab291eec4bc87ea17ba06c94e5fe3054\"\u003e\u003ccode\u003e13b701b\u003c/code\u003e\u003c/a\u003e Add release notes for \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9679\"\u003e#9679\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/5564ca72fcd59d040e270af5dcf17a0d7161c364\"\u003e\u003ccode\u003e5564ca7\u003c/code\u003e\u003c/a\u003e List methods\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/a0920fd384f800b5d0ba3dd29ecdeae4f1d4043b\"\u003e\u003ccode\u003ea0920fd\u003c/code\u003e\u003c/a\u003e Speed up ImageChops operations (\u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9738\"\u003e#9738\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/07e9a6cd5336dc6cf8cae9165cd70cdd2b3e42fc\"\u003e\u003ccode\u003e07e9a6c\u003c/code\u003e\u003c/a\u003e Speed up \u003ccode\u003eImage.filter()\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9736\"\u003e#9736\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/a94578cf9649ea13e426cf7fb2b71b39ffc0dd50\"\u003e\u003ccode\u003ea94578c\u003c/code\u003e\u003c/a\u003e Speed up \u003ccode\u003eImage.getchannel()\u003c/code\u003e, \u003ccode\u003eImage.merge()\u003c/code\u003e, \u003ccode\u003eImage.putalpha()\u003c/code\u003e and `Image...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/53e02c43c919d149b2a154a5180079f9df18fbbb\"\u003e\u003ccode\u003e53e02c4\u003c/code\u003e\u003c/a\u003e Speed up \u003ccode\u003eImage.fill()\u003c/code\u003e, \u003ccode\u003eImage.linear_gradient()\u003c/code\u003e and `Image.radial_gradient...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/af037475be8634ba739744243164ba9e2c8346a6\"\u003e\u003ccode\u003eaf03747\u003c/code\u003e\u003c/a\u003e Speed up \u003ccode\u003eImage.resample()\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9739\"\u003e#9739\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/5c9ca56c3e5fba52b647809fbb0986c87e73a571\"\u003e\u003ccode\u003e5c9ca56\u003c/code\u003e\u003c/a\u003e Speed up \u003ccode\u003ealpha_composite\u003c/code\u003e, \u003ccode\u003ematrix\u003c/code\u003e, \u003ccode\u003enegative\u003c/code\u003e, \u003ccode\u003equantize\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9740\"\u003e#9740\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/python-pillow/Pillow/compare/9.5.0...12.3.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `soupsieve` from 2.4.1 to 2.9\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/facelessuser/soupsieve/releases\"\u003esoupsieve's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e2.9\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eNEW\u003c/strong\u003e: Drop Python 3.9 support.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eNEW\u003c/strong\u003e: Lazy compile selector patterns to improve initial import speed.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eFIX\u003c/strong\u003e: Correct \u003ccode\u003e:nth-child\u003c/code\u003e/\u003ccode\u003e:nth-of-type\u003c/code\u003e (and \u003ccode\u003e-last-\u003c/code\u003e variants) for \u003ccode\u003eAn+B\u003c/code\u003e values whose sequence steps onto\nindex 0 or onto the last child (e.g. \u003ccode\u003e:nth-child(2n-2)\u003c/code\u003e, \u003ccode\u003e:nth-child(n-1)\u003c/code\u003e, \u003ccode\u003e:nth-child(n+5)\u003c/code\u003e), which previously\nmatched the wrong elements or nothing at all (\u003ca href=\"https://github.com/gaoflow\"\u003e\u003ccode\u003e@​gaoflow\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eFIX\u003c/strong\u003e: More efficient CSS ID matching (\u003ca href=\"https://github.com/kaimandalic\"\u003e\u003ccode\u003e@​kaimandalic\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eFIX\u003c/strong\u003e: Fix inefficient trimming of comments and white space (\u003ca href=\"https://github.com/kaimandalic\"\u003e\u003ccode\u003e@​kaimandalic\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.8.4\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eFIX\u003c/strong\u003e: Fix another inefficient attribute pattern (\u003ca href=\"https://github.com/mauriceng98\"\u003e\u003ccode\u003e@​mauriceng98\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eFIX\u003c/strong\u003e: Limit total number of selectors processed in a pattern to prevent massive selector requests (\u003ca href=\"https://github.com/mauriceng98\"\u003e\u003ccode\u003e@​mauriceng98\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.8.3\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eFIX\u003c/strong\u003e: Fix inefficient attribute pattern.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.8.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eFIX\u003c/strong\u003e: Ensure custom selectors or namespace dictionaries reject non-string keys (\u003ca href=\"https://github.com/mundanevision20\"\u003e\u003ccode\u003e@​mundanevision20\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eFIX\u003c/strong\u003e: Fix handling of \u003ccode\u003e:in-range\u003c/code\u003e and \u003ccode\u003e:out-of-range\u003c/code\u003e with end of year weeks (\u003ca href=\"https://github.com/mundanevision20\"\u003e\u003ccode\u003e@​mundanevision20\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eFIX\u003c/strong\u003e: Fix a potential infinite loop in the pretty printing debug function (\u003ca href=\"https://github.com/mundanevision20\"\u003e\u003ccode\u003e@​mundanevision20\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.8.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eFIX\u003c/strong\u003e: Changes in tests to accommodate latest Python HTML parser changes.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.8\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eNEW\u003c/strong\u003e: Drop support for Python 3.8.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eNEW\u003c/strong\u003e: Add support for Python 3.14.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eNEW\u003c/strong\u003e: Deploy with PyPI's \u0026quot;Trusted Publisher\u0026quot;.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.7\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eNEW\u003c/strong\u003e: Add \u003ccode\u003e:open\u003c/code\u003e pseudo selector.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eNEW\u003c/strong\u003e: Add \u003ccode\u003e:muted\u003c/code\u003e pseudo selector.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eNEW\u003c/strong\u003e: Recognize the following pseudo selectors: \u003ccode\u003e:autofill\u003c/code\u003e, \u003ccode\u003e:buffering\u003c/code\u003e, \u003ccode\u003e:fullscreen\u003c/code\u003e, \u003ccode\u003e:picture-in-picture\u003c/code\u003e,\n\u003ccode\u003e:popover-open\u003c/code\u003e, \u003ccode\u003e:seeking\u003c/code\u003e, \u003ccode\u003e:stalled\u003c/code\u003e, and \u003ccode\u003e:volume-locked\u003c/code\u003e. These selectors, while recognized, will not match any\nelement as they require a live environment to check element states and browser states. This just prevents Soup Sieve\nfrom failing when any of these selectors are specified.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eNEW\u003c/strong\u003e: A number of existing pseudo-classes are no longer noted as experimental.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eFIX\u003c/strong\u003e: Typing fixes.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.6\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eNEW\u003c/strong\u003e: Add official support for Python 3.13.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eNEW\u003c/strong\u003e: Add support for \u003ccode\u003e\u0026amp;\u003c/code\u003e as scoping root per the CSS Nesting Module, Level 1. When \u003ccode\u003e\u0026amp;\u003c/code\u003e is used outside the\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/8763f914472fc83652babda708bed5c8ef287004\"\u003e\u003ccode\u003e8763f91\u003c/code\u003e\u003c/a\u003e Format changelog message\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/cf198fcddc9230f06ed39f974eba0ce076b85cda\"\u003e\u003ccode\u003ecf198fc\u003c/code\u003e\u003c/a\u003e Fix inefficient trimming of comments and white space\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/ce44e4996e6632871c18cdd7a7fb641be8ef34ef\"\u003e\u003ccode\u003ece44e49\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/751c57b2c7e978e206b94b7dba17f8e2af392e19\"\u003e\u003ccode\u003e751c57b\u003c/code\u003e\u003c/a\u003e Fix :nth-child/:nth-of-type matching for An+B index boundaries (\u003ca href=\"https://redirect.github.com/facelessuser/soupsieve/issues/297\"\u003e#297\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/08e9ede4dcfafef860155319ef5eb9708e75d10b\"\u003e\u003ccode\u003e08e9ede\u003c/code\u003e\u003c/a\u003e Drop Python 3.9\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/d6e68303a6c3e0e410530939b92955ba24a07a81\"\u003e\u003ccode\u003ed6e6830\u003c/code\u003e\u003c/a\u003e Rework selector mapping\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/d2d1581fe275f89cb2e792589fed770aeb9e99b3\"\u003e\u003ccode\u003ed2d1581\u003c/code\u003e\u003c/a\u003e Utilize property for accessing lazy regular expression pattern\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/b8701dec25c84a3910fd9a03222a3804fa119a1d\"\u003e\u003ccode\u003eb8701de\u003c/code\u003e\u003c/a\u003e Build patterns and regexes lazily in css_parser (\u003ca href=\"https://redirect.github.com/facelessuser/soupsieve/issues/296\"\u003e#296\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/28108ab805818c832d9568142a99844fd95a0d39\"\u003e\u003ccode\u003e28108ab\u003c/code\u003e\u003c/a\u003e Limit excessive selectors\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/ef188721d6cc95641e99297b3a26ac17b7dfcfa7\"\u003e\u003ccode\u003eef18872\u003c/code\u003e\u003c/a\u003e Fix test for Windows\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/facelessuser/soupsieve/compare/2.4.1...2.9\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/black-da-bull/vector-admin/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/black-da-bull/vector-admin/pull/3","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/black-da-bull%2Fvector-admin/issues/3","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/3/packages"},{"uuid":"5486867022","node_id":"PR_kwDOOhhJoc8AAAABD62WHw","number":26,"state":"open","title":"Bump the pip group across 2 directories with 8 updates","user":"dependabot[bot]","labels":["dependencies","python"],"assignees":[],"locked":false,"comments_count":10,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-17T11:43:08.000Z","updated_at":"2026-09-17T11:44:07.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","group_name":"pip","update_count":8,"packages":[{"name":"setuptools","old_version":"75.3.0","new_version":"83.0.0","repository_url":"https://github.com/pypa/setuptools"},{"name":"python-multipart","old_version":"0.0.20","new_version":"0.0.31","repository_url":"https://github.com/Kludex/python-multipart"},{"name":"pyjwt","old_version":"2.10.1","new_version":"2.13.0","repository_url":"https://github.com/jpadilla/pyjwt"},{"name":"aiohttp","old_version":"3.12.14","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"gitpython","old_version":"3.1.44","new_version":"3.1.59","repository_url":"https://github.com/gitpython-developers/GitPython"},{"name":"h2","old_version":"4.3.0","new_version":"4.4.1","repository_url":"https://github.com/python-hyper/h2"},{"name":"tornado","old_version":"6.5","new_version":"6.5.8","repository_url":"https://github.com/tornadoweb/tornado"}],"path":null,"ecosystem":"pip"},"body":"Bumps the pip group with 7 updates in the /backend directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [setuptools](https://github.com/pypa/setuptools) | `75.3.0` | `83.0.0` |\n| [python-multipart](https://github.com/Kludex/python-multipart) | `0.0.20` | `0.0.31` |\n| [pyjwt](https://github.com/jpadilla/pyjwt) | `2.10.1` | `2.13.0` |\n| [aiohttp](https://github.com/aio-libs/aiohttp) | `3.12.14` | `3.14.3` |\n| [gitpython](https://github.com/gitpython-developers/GitPython) | `3.1.44` | `3.1.59` |\n| [h2](https://github.com/python-hyper/h2) | `4.3.0` | `4.4.1` |\n| [tornado](https://github.com/tornadoweb/tornado) | `6.5` | `6.5.8` |\n\nBumps the pip group with 1 update in the /backend/sandbox/docker directory: [pillow](https://github.com/python-pillow/Pillow).\n\nUpdates `setuptools` from 75.3.0 to 83.0.0\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pypa/setuptools/blob/main/NEWS.rst\"\u003esetuptools's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003ev83.0.0\u003c/h1\u003e\n\u003ch2\u003eFeatures\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRequire Python 3.10 or later.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eBugfixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eMANIFEST.in\u003c/code\u003e matching (via \u003ccode\u003eFileList\u003c/code\u003e) is now insensitive to Unicode\nnormalization form. A pattern authored in one form (e.g. NFC, as typically\nsaved by editors) now matches a file whose name is stored on disk in another\n(e.g. NFD, as produced by macOS APFS/HFS+). Previously an \u003ccode\u003eexclude\u003c/code\u003e,\n\u003ccode\u003eglobal-exclude\u003c/code\u003e, \u003ccode\u003erecursive-exclude\u003c/code\u003e, or \u003ccode\u003eprune\u003c/code\u003e rule could silently\nfail to drop a non-ASCII-named file from the source distribution, publishing\nit despite the exclusion -- see GHSA-h35f-9h28-mq5c.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eDeprecations and Removals\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003epypa/distutils#334\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch1\u003ev82.0.1\u003c/h1\u003e\n\u003ch2\u003eBugfixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix the loading of \u003ccode\u003elauncher manifest.xml\u003c/code\u003e file. (\u003ca href=\"https://redirect.github.com/pypa/setuptools/issues/5047\"\u003e#5047\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eReplaced deprecated \u003ccode\u003ejson.__version__\u003c/code\u003e with fixture in tests. (\u003ca href=\"https://redirect.github.com/pypa/setuptools/issues/5186\"\u003e#5186\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eImproved Documentation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd advice about how to improve predictability when installing sdists. (\u003ca href=\"https://redirect.github.com/pypa/setuptools/issues/5168\"\u003e#5168\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eMisc\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/pypa/setuptools/issues/4941\"\u003e#4941\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/pypa/setuptools/issues/5157\"\u003e#5157\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/pypa/setuptools/issues/5169\"\u003e#5169\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/pypa/setuptools/issues/5175\"\u003e#5175\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003ev82.0.0\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/setuptools/commit/6519f728c6f23c992df81a5691ef7655184a20eb\"\u003e\u003ccode\u003e6519f72\u003c/code\u003e\u003c/a\u003e Bump version: 82.0.1 → 83.0.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/setuptools/commit/d1151b125b29a6ee1c7db860f7ee6c365d525b5f\"\u003e\u003ccode\u003ed1151b1\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/pypa/setuptools/issues/5250\"\u003e#5250\u003c/a\u003e from pypa/feature/distutils-d7633fbed\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/setuptools/commit/a2df31e6a741b0fe775969618fe6a3a3d032e900\"\u003e\u003ccode\u003ea2df31e\u003c/code\u003e\u003c/a\u003e Capture removal of dry_run parameter in changelog.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/setuptools/commit/00144dc3fb6d023fd81cdc26c380a012b084df9b\"\u003e\u003ccode\u003e00144dc\u003c/code\u003e\u003c/a\u003e Moved newsfragment to the release where it occurred.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/setuptools/commit/a4a5a2b160357be77626aa077ddd1d8ee53be50f\"\u003e\u003ccode\u003ea4a5a2b\u003c/code\u003e\u003c/a\u003e Add news fragment.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/setuptools/commit/77470c23c35031c9e37d7512694ac5ca52bfcaac\"\u003e\u003ccode\u003e77470c2\u003c/code\u003e\u003c/a\u003e Merge \u003ca href=\"https://github.com/pypa/distutils\"\u003ehttps://github.com/pypa/distutils\u003c/a\u003e into feature/distutils-d7633fbed\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/setuptools/commit/3c43897420f25a1be1afe6eaa905d056009cc736\"\u003e\u003ccode\u003e3c43897\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/pypa/setuptools/issues/5247\"\u003e#5247\u003c/a\u003e from pypa/copilot/fix-pypy-version-issue\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/setuptools/commit/bb6ea66b4bd01cb35d7c68a1bc61b96d59190269\"\u003e\u003ccode\u003ebb6ea66\u003c/code\u003e\u003c/a\u003e Bump PyPy from 3.10 to 3.11 in CI workflow\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/setuptools/commit/a2bc3aca2f55eb9b93ea633e58ba68170ce14451\"\u003e\u003ccode\u003ea2bc3ac\u003c/code\u003e\u003c/a\u003e Fix broken intersphinx reference to build's installation docs\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/setuptools/commit/2d6a739c64cfedc65e1f635af7b52340aac8d99b\"\u003e\u003ccode\u003e2d6a739\u003c/code\u003e\u003c/a\u003e Use stacked parametrize decorators instead of itertools.product\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/pypa/setuptools/compare/v75.3.0...v83.0.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `python-multipart` from 0.0.20 to 0.0.31\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/Kludex/python-multipart/releases\"\u003epython-multipart's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eVersion 0.0.31\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSpeed up multipart header parsing and callback dispatch by \u003ca href=\"https://github.com/Kludex\"\u003e\u003ccode\u003e@​Kludex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/295\"\u003eKludex/python-multipart#295\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBound header field name size before validating by \u003ca href=\"https://github.com/Kludex\"\u003e\u003ccode\u003e@​Kludex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/296\"\u003eKludex/python-multipart#296\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eValidate Content-Length is non-negative in parse_form by \u003ca href=\"https://github.com/Kludex\"\u003e\u003ccode\u003e@​Kludex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/297\"\u003eKludex/python-multipart#297\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/Kludex/python-multipart/compare/0.0.30...0.0.31\"\u003ehttps://github.com/Kludex/python-multipart/compare/0.0.30...0.0.31\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eVersion 0.0.30\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eTreat only \u003ccode\u003e\u0026amp;\u003c/code\u003e as the urlencoded field separator by \u003ca href=\"https://github.com/Kludex\"\u003e\u003ccode\u003e@​Kludex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/290\"\u003eKludex/python-multipart#290\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eIgnore RFC 2231 extended parameters in \u003ccode\u003eparse_options_header\u003c/code\u003e by \u003ca href=\"https://github.com/Kludex\"\u003e\u003ccode\u003e@​Kludex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/291\"\u003eKludex/python-multipart#291\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/Kludex/python-multipart/compare/0.0.29...0.0.30\"\u003ehttps://github.com/Kludex/python-multipart/compare/0.0.29...0.0.30\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eVersion 0.0.29\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eHandle malformed RFC 2231 continuations in \u003ccode\u003eparse_options_header\u003c/code\u003e by \u003ca href=\"https://github.com/manunio\"\u003e\u003ccode\u003e@​manunio\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/270\"\u003eKludex/python-multipart#270\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/Kludex/python-multipart/compare/0.0.28...0.0.29\"\u003ehttps://github.com/Kludex/python-multipart/compare/0.0.28...0.0.29\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eVersion 0.0.28\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSpeed up partial-boundary tail scan via \u003ccode\u003ebytes.find\u003c/code\u003e by \u003ca href=\"https://github.com/Kludex\"\u003e\u003ccode\u003e@​Kludex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/281\"\u003eKludex/python-multipart#281\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eCap multipart boundary length at 256 bytes by \u003ca href=\"https://github.com/Kludex\"\u003e\u003ccode\u003e@​Kludex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/282\"\u003eKludex/python-multipart#282\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/Kludex/python-multipart/compare/0.0.27...0.0.28\"\u003ehttps://github.com/Kludex/python-multipart/compare/0.0.27...0.0.28\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eVersion 0.0.27\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePass parse offsets via constructors by \u003ca href=\"https://github.com/Kludex\"\u003e\u003ccode\u003e@​Kludex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/268\"\u003eKludex/python-multipart#268\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd multipart header limits by \u003ca href=\"https://github.com/Kludex\"\u003e\u003ccode\u003e@​Kludex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/267\"\u003eKludex/python-multipart#267\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/Kludex/python-multipart/compare/0.0.26...0.0.27\"\u003ehttps://github.com/Kludex/python-multipart/compare/0.0.26...0.0.27\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eVersion 0.0.26\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSkip preamble before first multipart boundary by \u003ca href=\"https://github.com/Kludex\"\u003e\u003ccode\u003e@​Kludex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/262\"\u003eKludex/python-multipart#262\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSilently discard epilogue data after the closing boundary by \u003ca href=\"https://github.com/Kludex\"\u003e\u003ccode\u003e@​Kludex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/259\"\u003eKludex/python-multipart#259\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/Kludex/python-multipart/compare/0.0.25...0.0.26\"\u003ehttps://github.com/Kludex/python-multipart/compare/0.0.25...0.0.26\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eVersion 0.0.25\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eApply Apache-2.0 properly by \u003ca href=\"https://github.com/Kludex\"\u003e\u003ccode\u003e@​Kludex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/247\"\u003eKludex/python-multipart#247\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eHandle multipart headers case-insensitively by \u003ca href=\"https://github.com/Kludex\"\u003e\u003ccode\u003e@​Kludex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/252\"\u003eKludex/python-multipart#252\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/Kludex/python-multipart/blob/main/CHANGELOG.md\"\u003epython-multipart's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e0.0.31 (2026-06-04)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSpeed up multipart header parsing and callback dispatch \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/295\"\u003e#295\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eBound header field name size before validating \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/296\"\u003e#296\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eValidate \u003ccode\u003eContent-Length\u003c/code\u003e is non-negative in \u003ccode\u003eparse_form\u003c/code\u003e \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/297\"\u003e#297\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e0.0.30 (2026-05-31)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eParse \u003ccode\u003eapplication/x-www-form-urlencoded\u003c/code\u003e bodies per the WHATWG URL standard, treating only \u003ccode\u003e\u0026amp;\u003c/code\u003e as a field separator \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/290\"\u003e#290\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eIgnore RFC 2231/5987 extended parameters (\u003ccode\u003ename*\u003c/code\u003e, \u003ccode\u003efilename*\u003c/code\u003e) in \u003ccode\u003eparse_options_header\u003c/code\u003e, keeping the plain parameter authoritative per \u003ca href=\"https://datatracker.ietf.org/doc/html/rfc7578#section-4.2\"\u003eRFC 7578 §4.2\u003c/a\u003e \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/291\"\u003e#291\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e0.0.29 (2026-05-17)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eHandle malformed RFC 2231 continuations in \u003ccode\u003eparse_options_header\u003c/code\u003e \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/270\"\u003e#270\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e0.0.28 (2026-05-10)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSpeed up partial-boundary tail scan via \u003ccode\u003ebytes.find\u003c/code\u003e \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/281\"\u003e#281\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eCap multipart boundary length at 256 bytes \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/282\"\u003e#282\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e0.0.27 (2026-04-27)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd multipart header limits \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/267\"\u003e#267\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003ePass parse offsets via constructors \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/268\"\u003e#268\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e0.0.26 (2026-04-10)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSkip preamble before the first multipart boundary more efficiently \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/262\"\u003e#262\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eSilently discard epilogue data after the closing multipart boundary \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/259\"\u003e#259\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e0.0.25 (2026-04-10)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd MIME content type info to \u003ccode\u003eFile\u003c/code\u003e \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/143\"\u003e#143\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eHandle CTE values case-insensitively \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/258\"\u003e#258\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eRemove custom \u003ccode\u003eFormParser\u003c/code\u003e classes \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/257\"\u003e#257\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003eUPLOAD_DELETE_TMP\u003c/code\u003e to \u003ccode\u003eFormParser\u003c/code\u003e config \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/254\"\u003e#254\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eEmit \u003ccode\u003efield_end\u003c/code\u003e for trailing bare field names on finalize \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/230\"\u003e#230\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eHandle multipart headers case-insensitively \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/252\"\u003e#252\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eApply Apache-2.0 properly \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/247\"\u003e#247\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e0.0.24 (2026-04-05)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eValidate \u003ccode\u003echunk_size\u003c/code\u003e in \u003ccode\u003eparse_form()\u003c/code\u003e \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/244\"\u003e#244\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e0.0.23 (2026-04-05)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRemove unused \u003ccode\u003etrust_x_headers\u003c/code\u003e parameter and \u003ccode\u003eX-File-Name\u003c/code\u003e fallback \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/196\"\u003e#196\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eReturn processed length from \u003ccode\u003eQuerystringParser._internal_write\u003c/code\u003e \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/229\"\u003e#229\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eCleanup metadata dunders from \u003ccode\u003e__init__.py\u003c/code\u003e \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/227\"\u003e#227\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/python-multipart/commit/4cffc68a165f7a6f6b7756ce006fabf07a05b7a4\"\u003e\u003ccode\u003e4cffc68\u003c/code\u003e\u003c/a\u003e Version 0.0.31 (\u003ca href=\"https://redirect.github.com/Kludex/python-multipart/issues/298\"\u003e#298\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/python-multipart/commit/c814948acf509cef7881fa75c969969b19239bbf\"\u003e\u003ccode\u003ec814948\u003c/code\u003e\u003c/a\u003e Reject negative \u003ccode\u003eContent-Length\u003c/code\u003e in \u003ccode\u003eparse_form\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/Kludex/python-multipart/issues/297\"\u003e#297\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/python-multipart/commit/6b837d47bc68826ed5cbbcb50c6c6a6093444494\"\u003e\u003ccode\u003e6b837d4\u003c/code\u003e\u003c/a\u003e Bound header field name size before validating (\u003ca href=\"https://redirect.github.com/Kludex/python-multipart/issues/296\"\u003e#296\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/python-multipart/commit/e0c4f9df2e737d1663fbbdd6563f80613a2089f9\"\u003e\u003ccode\u003ee0c4f9d\u003c/code\u003e\u003c/a\u003e Bump the github-actions group with 3 updates (\u003ca href=\"https://redirect.github.com/Kludex/python-multipart/issues/294\"\u003e#294\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/python-multipart/commit/b8a01bb683e8e8675fdb5d831b206a478c8215aa\"\u003e\u003ccode\u003eb8a01bb\u003c/code\u003e\u003c/a\u003e Bump the python-packages group with 3 updates (\u003ca href=\"https://redirect.github.com/Kludex/python-multipart/issues/293\"\u003e#293\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/python-multipart/commit/6732164f30c58e28589a1e22213d2f6b8c6bad9f\"\u003e\u003ccode\u003e6732164\u003c/code\u003e\u003c/a\u003e Speed up multipart header parsing and callback dispatch (\u003ca href=\"https://redirect.github.com/Kludex/python-multipart/issues/295\"\u003e#295\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/python-multipart/commit/9d3ead568a259f222cff6425262ff63e88d930d4\"\u003e\u003ccode\u003e9d3ead5\u003c/code\u003e\u003c/a\u003e Version 0.0.30 (\u003ca href=\"https://redirect.github.com/Kludex/python-multipart/issues/292\"\u003e#292\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/python-multipart/commit/3506c15ce99cb62faf2d5ceb3c4c1e5800cb843d\"\u003e\u003ccode\u003e3506c15\u003c/code\u003e\u003c/a\u003e Ignore RFC 2231 extended parameters in \u003ccode\u003eparse_options_header\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/Kludex/python-multipart/issues/291\"\u003e#291\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/python-multipart/commit/d69df35cd2cad9c72794c2c340db646afae957d8\"\u003e\u003ccode\u003ed69df35\u003c/code\u003e\u003c/a\u003e Treat only \u003ccode\u003e\u0026amp;\u003c/code\u003e as the urlencoded field separator (\u003ca href=\"https://redirect.github.com/Kludex/python-multipart/issues/290\"\u003e#290\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/python-multipart/commit/1e6ff9740b09fb439755f30e2b0e2ada1d297325\"\u003e\u003ccode\u003e1e6ff97\u003c/code\u003e\u003c/a\u003e Bump idna from 3.11 to 3.15 (\u003ca href=\"https://redirect.github.com/Kludex/python-multipart/issues/289\"\u003e#289\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/Kludex/python-multipart/compare/0.0.20...0.0.31\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `pyjwt` from 2.10.1 to 2.13.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/jpadilla/pyjwt/releases\"\u003epyjwt's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e2.13.0\u003c/h2\u003e\n\u003ch1\u003ePyJWT 2.13.0 — Security Release\u003c/h1\u003e\n\u003cp\u003eThis release bundles five security fixes plus three additional hardening / spec-compliance changes. We recommend all users upgrade.\u003c/p\u003e\n\u003ch2\u003eSecurity\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/security/advisories/GHSA-xgmm-8j9v-c9wx\"\u003e\u003ccode\u003eGHSA-xgmm-8j9v-c9wx\u003c/code\u003e\u003c/a\u003e — JWK JSON accepted as HMAC secret (algorithm confusion).\u003c/strong\u003e \u003ccode\u003eHMACAlgorithm.prepare_key\u003c/code\u003e previously rejected PEM- and SSH-formatted asymmetric keys but did not catch a JWK passed as a raw JSON string. In a verifier configured with both symmetric and asymmetric algorithms in \u003ccode\u003ealgorithms=[…]\u003c/code\u003e and a raw-JSON JWK as the key, an attacker could forge HS256 tokens using the JWK text as the HMAC secret. The guard has been extended to reject any JWK-shaped JSON. \u003cem\u003eReported by \u003ca href=\"https://github.com/aradona91\"\u003e\u003ccode\u003e@​aradona91\u003c/code\u003e\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/security/advisories/GHSA-jq35-7prp-9v3f\"\u003e\u003ccode\u003eGHSA-jq35-7prp-9v3f\u003c/code\u003e\u003c/a\u003e — Algorithm allow-list bypass with \u003ccode\u003ePyJWK\u003c/code\u003e / \u003ccode\u003ePyJWKClient\u003c/code\u003e.\u003c/strong\u003e When verifying with a \u003ccode\u003ePyJWK\u003c/code\u003e, the caller's \u003ccode\u003ealgorithms=[…]\u003c/code\u003e allow-list was checked against the token header \u003ccode\u003ealg\u003c/code\u003e as a string only; actual verification used the algorithm bound to the \u003ccode\u003ePyJWK\u003c/code\u003e. An attacker who controlled a registered JWKS key could sign with one algorithm and advertise another on the header. PyJWT now requires the token header \u003ccode\u003ealg\u003c/code\u003e to match the \u003ccode\u003ePyJWK\u003c/code\u003e's algorithm before verification. \u003cem\u003eReported by \u003ca href=\"https://github.com/sushi-gif\"\u003e\u003ccode\u003e@​sushi-gif\u003c/code\u003e\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/security/advisories/GHSA-w7vc-732c-9m39\"\u003e\u003ccode\u003eGHSA-w7vc-732c-9m39\u003c/code\u003e\u003c/a\u003e — DoS via base64 decode of unused payload segment when \u003ccode\u003eb64=false\u003c/code\u003e.\u003c/strong\u003e For detached-payload JWS (\u003ccode\u003eb64=false\u003c/code\u003e), the compact-form payload segment was base64-decoded before being discarded in favor of the caller-supplied \u003ccode\u003edetached_payload\u003c/code\u003e. An attacker could inflate the unused segment to force CPU + memory cost without holding a valid signature. The segment is now required to be empty per RFC 7515 Appendix F, and is no longer decoded. \u003cem\u003eReported by \u003ca href=\"https://github.com/thesmartshadow\"\u003e\u003ccode\u003e@​thesmartshadow\u003c/code\u003e\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/security/advisories/GHSA-993g-76c3-p5m4\"\u003e\u003ccode\u003eGHSA-993g-76c3-p5m4\u003c/code\u003e\u003c/a\u003e — \u003ccode\u003ePyJWKClient\u003c/code\u003e accepts non-HTTP(S) URIs.\u003c/strong\u003e \u003ccode\u003ePyJWKClient.fetch_data\u003c/code\u003e passed its URI to \u003ccode\u003eurllib.request.urlopen\u003c/code\u003e, which by default also handles \u003ccode\u003efile://\u003c/code\u003e, \u003ccode\u003eftp://\u003c/code\u003e, and \u003ccode\u003edata:\u003c/code\u003e schemes. An application that fed an attacker-influenced URI into \u003ccode\u003ePyJWKClient\u003c/code\u003e could be coerced into reading local files or reaching other unintended schemes. \u003ccode\u003ePyJWKClient\u003c/code\u003e now rejects any URI whose scheme isn't \u003ccode\u003ehttp\u003c/code\u003e or \u003ccode\u003ehttps\u003c/code\u003e. \u003cem\u003eReported by \u003ca href=\"https://github.com/KEIJOT\"\u003e\u003ccode\u003e@​KEIJOT\u003c/code\u003e\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/security/advisories/GHSA-fhv5-28vv-h8m8\"\u003e\u003ccode\u003eGHSA-fhv5-28vv-h8m8\u003c/code\u003e\u003c/a\u003e — \u003ccode\u003ePyJWKClient\u003c/code\u003e cache wiped on fetch error.\u003c/strong\u003e A \u003ccode\u003efinally\u003c/code\u003e-block \u003ccode\u003eput(jwk_set=None)\u003c/code\u003e cleared the JWK Set cache whenever a fetch raised, turning a transient JWKS-endpoint outage into application-wide auth failure. The cache write was moved into the success path; transient errors no longer evict valid cached keys. \u003cem\u003eReported by \u003ca href=\"https://github.com/eddieran\"\u003e\u003ccode\u003e@​eddieran\u003c/code\u003e\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eFixed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eReject empty HMAC keys outright in \u003ccode\u003eHMACAlgorithm.prepare_key\u003c/code\u003e with \u003ccode\u003eInvalidKeyError\u003c/code\u003e instead of accepting them with only a warning. Defends against the \u003ccode\u003eos.getenv(\u0026quot;JWT_SECRET\u0026quot;, \u0026quot;\u0026quot;)\u003c/code\u003e footgun. \u003cem\u003eThanks to \u003ca href=\"https://github.com/SnailSploit\"\u003e\u003ccode\u003e@​SnailSploit\u003c/code\u003e\u003c/a\u003e and \u003ca href=\"https://github.com/spartan8806\"\u003e\u003ccode\u003e@​spartan8806\u003c/code\u003e\u003c/a\u003e for the reports.\u003c/em\u003e\u003c/li\u003e\n\u003cli\u003eForward per-call \u003ccode\u003eoptions\u003c/code\u003e (including \u003ccode\u003eenforce_minimum_key_length\u003c/code\u003e) from \u003ccode\u003ePyJWT.decode\u003c/code\u003e through to \u003ccode\u003ePyJWS._verify_signature\u003c/code\u003e. The option was previously silently dropped between the two layers, so it only took effect when set on the \u003ccode\u003ePyJWT\u003c/code\u003e instance. \u003cem\u003eThanks to \u003ca href=\"https://github.com/WLUB\"\u003e\u003ccode\u003e@​WLUB\u003c/code\u003e\u003c/a\u003e for the report.\u003c/em\u003e\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eRFC 7797 §3 compliance for \u003ccode\u003eb64=false\u003c/code\u003e:\u003c/strong\u003e the encoder now auto-adds \u003ccode\u003e\u0026quot;b64\u0026quot;\u003c/code\u003e to \u003ccode\u003ecrit\u003c/code\u003e, and the decoder rejects tokens that set \u003ccode\u003eb64=false\u003c/code\u003e without listing it in \u003ccode\u003ecrit\u003c/code\u003e. \u003cem\u003eThanks to \u003ca href=\"https://github.com/MachineLearning-Nerd\"\u003e\u003ccode\u003e@​MachineLearning-Nerd\u003c/code\u003e\u003c/a\u003e for the report.\u003c/em\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eChanged\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMigrate the \u003ccode\u003edev\u003c/code\u003e, \u003ccode\u003edocs\u003c/code\u003e, and \u003ccode\u003etests\u003c/code\u003e package extras to dependency groups, by \u003ca href=\"https://github.com/kurtmckee\"\u003e\u003ccode\u003e@​kurtmckee\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/jpadilla/pyjwt/pull/1152\"\u003e#1152\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eUpgrade notes\u003c/h2\u003e\n\u003cp\u003eMost fixes are invisible to correctly-configured callers. A few behavioral changes you may encounter:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eEmpty HMAC keys now raise.\u003c/strong\u003e If your app passed \u003ccode\u003e\u0026quot;\u0026quot;\u003c/code\u003e or \u003ccode\u003eb\u0026quot;\u0026quot;\u003c/code\u003e as a secret (often via a missing env var, e.g. \u003ccode\u003eos.getenv(\u0026quot;JWT_SECRET\u0026quot;, \u0026quot;\u0026quot;)\u003c/code\u003e), \u003ccode\u003eencode\u003c/code\u003e/\u003ccode\u003edecode\u003c/code\u003e will now raise \u003ccode\u003eInvalidKeyError\u003c/code\u003e. This is the intended behavior — fix the configuration.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ccode\u003ePyJWK\u003c/code\u003e decoding now requires the token's \u003ccode\u003ealg\u003c/code\u003e to match the JWK's algorithm.\u003c/strong\u003e Previously a mismatch was silently honored if the header \u003ccode\u003ealg\u003c/code\u003e appeared in the allow-list. Tokens that relied on this mismatch will now fail with \u003ccode\u003eInvalidAlgorithmError\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ccode\u003ePyJWKClient\u003c/code\u003e now rejects non-HTTP(S) URIs at construction time.\u003c/strong\u003e Tests or dev environments that fetched JWKS from \u003ccode\u003efile://\u003c/code\u003e URIs need to switch to a local HTTP server or load the JWKS by other means (e.g. construct \u003ccode\u003ePyJWKSet.from_dict(...)\u003c/code\u003e directly).\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ccode\u003eb64=false\u003c/code\u003e tokens are now strictly RFC 7515 / 7797 compliant.\u003c/strong\u003e Tokens with a non-empty compact-form payload segment, or that omit \u003ccode\u003e\u0026quot;b64\u0026quot;\u003c/code\u003e from \u003ccode\u003ecrit\u003c/code\u003e, will be rejected. PyJWT-produced tokens always satisfy both invariants, so round-trips through PyJWT are unaffected.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ccode\u003eenforce_minimum_key_length\u003c/code\u003e set per-call now takes effect.\u003c/strong\u003e Callers who passed \u003ccode\u003eoptions={\u0026quot;enforce_minimum_key_length\u0026quot;: True}\u003c/code\u003e to \u003ccode\u003ejwt.decode()\u003c/code\u003e previously got no enforcement; they will now get \u003ccode\u003eInvalidKeyError\u003c/code\u003e on undersized keys, as documented.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull changelog:\u003c/strong\u003e \u003ca href=\"https://github.com/jpadilla/pyjwt/compare/2.12.1...2.13.0\"\u003ehttps://github.com/jpadilla/pyjwt/compare/2.12.1...2.13.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003e2.12.1\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd typing_extensions dependency for Python \u0026lt; 3.11 by \u003ca href=\"https://github.com/jpadilla\"\u003e\u003ccode\u003e@​jpadilla\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/jpadilla/pyjwt/pull/1151\"\u003ejpadilla/pyjwt#1151\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/jpadilla/pyjwt/compare/2.12.0...2.12.1\"\u003ehttps://github.com/jpadilla/pyjwt/compare/2.12.0...2.12.1\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003e2.12.0\u003c/h2\u003e\n\u003ch2\u003eSecurity\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eValidate the crit (Critical) Header Parameter defined in RFC 7515 §4.1.11. by \u003ca href=\"https://github.com/dmbs335\"\u003e\u003ccode\u003e@​dmbs335\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://github.com/jpadilla/pyjwt/security/advisories/GHSA-752w-5fwx-jx9f\"\u003eGHSA-752w-5fwx-jx9f\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/jpadilla/pyjwt/blob/master/CHANGELOG.rst\"\u003epyjwt's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ccode\u003ev2.13.0 \u0026lt;https://github.com/jpadilla/pyjwt/compare/2.12.1...2.13.0\u0026gt;\u003c/code\u003e__\u003c/h2\u003e\n\u003cp\u003eSecurity\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003e\n- Reject JWK JSON documents passed as raw HMAC secrets in\n  ``HMACAlgorithm.prepare_key`` to close an algorithm-confusion gap that\n  the existing PEM/SSH guard did not cover. Reported by @aradona91 in\n  `GHSA-xgmm-8j9v-c9wx \u0026lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-xgmm-8j9v-c9wx\u0026gt;`__.\n- Bind the JWT header ``alg`` to ``PyJWK.algorithm_name`` during\n  verification so the caller's ``algorithms=[...]`` allow-list cannot be\n  bypassed when decoding with a ``PyJWK`` / ``PyJWKClient`` key. Reported\n  by @sushi-gif in `GHSA-jq35-7prp-9v3f \u0026lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-jq35-7prp-9v3f\u0026gt;`__.\n- Reject non-``http(s)`` URI schemes in ``PyJWKClient`` so attacker-\n  influenced URIs cannot read local files or reach unintended schemes via\n  urllib's default ``file://`` / ``ftp://`` / ``data:`` handlers. Reported\n  by @KEIJOT in `GHSA-993g-76c3-p5m4 \u0026lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-993g-76c3-p5m4\u0026gt;`__.\n- Preserve the cached JWK Set on fetch errors in ``PyJWKClient.fetch_data``.\n  The previous ``finally``-block ``put(None)`` pattern cleared the cache\n  on any transient outage, turning one bad JWKS request into application-\n  wide auth failure. Reported by @eddieran in `GHSA-fhv5-28vv-h8m8 \u0026lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-fhv5-28vv-h8m8\u0026gt;`__.\n- Skip the unconditional base64 decode of the compact-form payload segment\n  when ``b64=false`` is set in the protected header, and require that\n  segment to be empty (RFC 7515 Appendix F detached form). Closes an\n  unauthenticated DoS amplifier. Reported by @thesmartshadow in\n  `GHSA-w7vc-732c-9m39 \u0026lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-w7vc-732c-9m39\u0026gt;`__.\n\u003cp\u003eFixed\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003e\n- Reject empty HMAC keys outright in ``HMACAlgorithm.prepare_key`` with\n  ``InvalidKeyError`` instead of accepting them with only a warning.\n  Thanks to @SnailSploit and @spartan8806 for independently flagging the\n  footgun.\n- Forward per-call ``options`` (including ``enforce_minimum_key_length``)\n  from ``PyJWT.decode`` through to ``PyJWS._verify_signature`` so the\n  option actually takes effect when set at the call site rather than only\n  on the ``PyJWT`` instance. Thanks to @WLUB for the report.\n- RFC 7797 §3 compliance for ``b64=false``: the encoder now auto-adds\n  ``\u0026amp;quot;b64\u0026amp;quot;`` to the ``crit`` header parameter, and the decoder rejects\n  tokens that set ``b64=false`` without listing it in ``crit``. Thanks to\n  @MachineLearning-Nerd for the report.\n\nChanged\n\u003c/code\u003e\u003c/pre\u003e\n\u003cul\u003e\n\u003cli\u003eMigrate the \u003ccode\u003edev\u003c/code\u003e, \u003ccode\u003edocs\u003c/code\u003e, and \u003ccode\u003etests\u003c/code\u003e package extras to dependency groups by \u003ca href=\"https://github.com/kurtmckee\"\u003e\u003ccode\u003e@​kurtmckee\u003c/code\u003e\u003c/a\u003e in \u003ccode\u003e[#1152](https://github.com/jpadilla/pyjwt/issues/1152) \u0026amp;lt;https://github.com/jpadilla/pyjwt/pull/1152\u0026amp;gt;\u003c/code\u003e__\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003ccode\u003ev2.12.1 \u0026amp;lt;https://github.com/jpadilla/pyjwt/compare/2.12.0...2.12.1\u0026amp;gt;\u003c/code\u003e__\n\u0026lt;/tr\u0026gt;\u0026lt;/table\u0026gt;\n\u003c/code\u003e\u003c/pre\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/7144e4534c34810f4525dc4578a32addd8212cff\"\u003e\u003ccode\u003e7144e45\u003c/code\u003e\u003c/a\u003e Apply ruff format\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/d2f4bec4963897c0ef96ef64a875894f2c8542ab\"\u003e\u003ccode\u003ed2f4bec\u003c/code\u003e\u003c/a\u003e Restore \u003ccode\u003ecast()\u003c/code\u003e calls with cross-version \u003ccode\u003etype: ignore\u003c/code\u003e for \u003ccode\u003eprepare_key\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/22f478cebddd8294259c30f037ecb92b0b348774\"\u003e\u003ccode\u003e22f478c\u003c/code\u003e\u003c/a\u003e Remove redundant casts in \u003ccode\u003eRSAAlgorithm.prepare_key\u003c/code\u003e and `ECAlgorithm.prepare...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/95791b1759b8aa4f2203575d344d5c78564cdc81\"\u003e\u003ccode\u003e95791b1\u003c/code\u003e\u003c/a\u003e Bundle security fixes and hardening into 2.13.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/dcc27a9d3182a2349c30b160758785c6ce7a6508\"\u003e\u003ccode\u003edcc27a9\u003c/code\u003e\u003c/a\u003e [pre-commit.ci] pre-commit autoupdate (\u003ca href=\"https://redirect.github.com/jpadilla/pyjwt/issues/1155\"\u003e#1155\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/9d08a9a1896845ed8eaf88e6f6ac61e5800c3e7a\"\u003e\u003ccode\u003e9d08a9a\u003c/code\u003e\u003c/a\u003e [pre-commit.ci] pre-commit autoupdate (\u003ca href=\"https://redirect.github.com/jpadilla/pyjwt/issues/1146\"\u003e#1146\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/b87c10014d4109f0214fea188d00faaaf8a80e64\"\u003e\u003ccode\u003eb87c100\u003c/code\u003e\u003c/a\u003e Bump codecov/codecov-action from 5 to 6 (\u003ca href=\"https://redirect.github.com/jpadilla/pyjwt/issues/1154\"\u003e#1154\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/40e3147eb5f790d8d041772e5fc00728a176c812\"\u003e\u003ccode\u003e40e3147\u003c/code\u003e\u003c/a\u003e Migrate development extras to dependency groups (\u003ca href=\"https://redirect.github.com/jpadilla/pyjwt/issues/1152\"\u003e#1152\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/a4e1a3d1218b01c5806420b8f16d9308ac4adc30\"\u003e\u003ccode\u003ea4e1a3d\u003c/code\u003e\u003c/a\u003e Add typing_extensions dependency for Python \u0026lt; 3.11 (\u003ca href=\"https://redirect.github.com/jpadilla/pyjwt/issues/1151\"\u003e#1151\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/bd9700cca7f9258fadcc429c1034e508025931f2\"\u003e\u003ccode\u003ebd9700c\u003c/code\u003e\u003c/a\u003e Use PyJWK algorithm when encoding without explicit algorithm (\u003ca href=\"https://redirect.github.com/jpadilla/pyjwt/issues/1148\"\u003e#1148\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/jpadilla/pyjwt/compare/2.10.1...2.13.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `aiohttp` from 3.12.14 to 3.14.3\nUpdates `gitpython` from 3.1.44 to 3.1.59\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/gitpython-developers/GitPython/releases\"\u003egitpython's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e3.1.59 - Security\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eprepare changelog for upcoming release by \u003ca href=\"https://github.com/Byron\"\u003e\u003ccode\u003e@​Byron\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2207\"\u003egitpython-developers/GitPython#2207\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBlock file-reading Git options by \u003ca href=\"https://github.com/Byron\"\u003e\u003ccode\u003e@​Byron\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2208\"\u003egitpython-developers/GitPython#2208\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eindex: write blobs via git hash-object, not gitdb's odb.store by \u003ca href=\"https://github.com/caroescm\"\u003e\u003ccode\u003e@​caroescm\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2209\"\u003egitpython-developers/GitPython#2209\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBlock separate git directories during clone by \u003ca href=\"https://github.com/Byron\"\u003e\u003ccode\u003e@​Byron\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2210\"\u003egitpython-developers/GitPython#2210\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: harden config parsing boundaries by \u003ca href=\"https://github.com/Byron\"\u003e\u003ccode\u003e@​Byron\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2211\"\u003egitpython-developers/GitPython#2211\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003erepo.index.add()\u003c/code\u003e now respects worktree filters  \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2209\"\u003egitpython-developers/GitPython#2209\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/gitpython-developers/GitPython/compare/3.1.58...3.1.59\"\u003ehttps://github.com/gitpython-developers/GitPython/compare/3.1.58...3.1.59\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003e3.1.58 - Security and Fixes\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003etest: allow Python startup before timeout by \u003ca href=\"https://github.com/Byron\"\u003e\u003ccode\u003e@​Byron\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2195\"\u003egitpython-developers/GitPython#2195\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eResolve Windows hook Bash through PATH by \u003ca href=\"https://github.com/Byron\"\u003e\u003ccode\u003e@​Byron\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2199\"\u003egitpython-developers/GitPython#2199\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRevert \u0026quot;Resolve Windows hook Bash through PATH\u0026quot; by \u003ca href=\"https://github.com/Byron\"\u003e\u003ccode\u003e@​Byron\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2200\"\u003egitpython-developers/GitPython#2200\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etest: focus pytest summary on unexpected failures by \u003ca href=\"https://github.com/raisulchowdhury\"\u003e\u003ccode\u003e@​raisulchowdhury\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2203\"\u003egitpython-developers/GitPython#2203\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eValidate submodule names before filesystem operations by \u003ca href=\"https://github.com/Byron\"\u003e\u003ccode\u003e@​Byron\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2202\"\u003egitpython-developers/GitPython#2202\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eHandle invalid submodule names during recursive updates by \u003ca href=\"https://github.com/Byron\"\u003e\u003ccode\u003e@​Byron\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2205\"\u003egitpython-developers/GitPython#2205\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix Windows path handling on Python 3.13+ by \u003ca href=\"https://github.com/Byron\"\u003e\u003ccode\u003e@​Byron\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2196\"\u003egitpython-developers/GitPython#2196\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efixup 2202 by \u003ca href=\"https://github.com/Byron\"\u003e\u003ccode\u003e@​Byron\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2206\"\u003egitpython-developers/GitPython#2206\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eCorrect Windows hook Bash precedence by \u003ca href=\"https://github.com/Byron\"\u003e\u003ccode\u003e@​Byron\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2201\"\u003egitpython-developers/GitPython#2201\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eHarden config and Git option validation by \u003ca href=\"https://github.com/Byron\"\u003e\u003ccode\u003e@​Byron\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2204\"\u003egitpython-developers/GitPython#2204\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSkip tests that need symlink privileges instead of erroring by \u003ca href=\"https://github.com/Cyrus580529\"\u003e\u003ccode\u003e@​Cyrus580529\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2197\"\u003egitpython-developers/GitPython#2197\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/raisulchowdhury\"\u003e\u003ccode\u003e@​raisulchowdhury\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2203\"\u003egitpython-developers/GitPython#2203\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Cyrus580529\"\u003e\u003ccode\u003e@​Cyrus580529\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2197\"\u003egitpython-developers/GitPython#2197\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/gitpython-developers/GitPython/compare/3.1.57...3.1.58\"\u003ehttps://github.com/gitpython-developers/GitPython/compare/3.1.57...3.1.58\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003e3.1.57 - Security and Fixes\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMerge gitdb and smmap into the GitPython repository by \u003ca href=\"https://github.com/Byron\"\u003e\u003ccode\u003e@​Byron\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2179\"\u003egitpython-developers/GitPython#2179\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump actions/setup-python from 6 to 7 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2185\"\u003egitpython-developers/GitPython#2185\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump the pre-commit group with 2 updates by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2186\"\u003egitpython-developers/GitPython#2186\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump Vampire/setup-wsl from 6.0.0 to 7.0.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2124\"\u003egitpython-developers/GitPython#2124\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRender protected Traversable methods in the reference by \u003ca href=\"https://github.com/pick7\"\u003e\u003ccode\u003e@​pick7\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2192\"\u003egitpython-developers/GitPython#2192\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUse standard prefixes for parsed patch diffs by \u003ca href=\"https://github.com/pick7\"\u003e\u003ccode\u003e@​pick7\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2191\"\u003egitpython-developers/GitPython#2191\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eHonor kill_after_timeout with output streams by \u003ca href=\"https://github.com/pick7\"\u003e\u003ccode\u003e@​pick7\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2189\"\u003egitpython-developers/GitPython#2189\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRedact Authorization extra headers from command errors by \u003ca href=\"https://github.com/pick7\"\u003e\u003ccode\u003e@​pick7\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2188\"\u003egitpython-developers/GitPython#2188\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eImprove RemoteProgress parse return typing by \u003ca href=\"https://github.com/pick7\"\u003e\u003ccode\u003e@​pick7\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2187\"\u003egitpython-developers/GitPython#2187\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdopt basedpyright with a legacy baseline by \u003ca href=\"https://github.com/Byron\"\u003e\u003ccode\u003e@​Byron\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2194\"\u003egitpython-developers/GitPython#2194\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBlock unsafe Git file and URL options by \u003ca href=\"https://github.com/Byron\"\u003e\u003ccode\u003e@​Byron\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2193\"\u003egitpython-developers/GitPython#2193\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pick7\"\u003e\u003ccode\u003e@​pick7\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2192\"\u003egitpython-developers/GitPython#2192\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/gitpython-developers/GitPython/compare/3.1.56...3.1.57\"\u003ehttps://github.com/gitpython-developers/GitPython/compare/3.1.56...3.1.57\u003c/a\u003e\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gitpython-developers/GitPython/commit/66340d77aab9a7468f4aed3681d4ef1e3c0ec931\"\u003e\u003ccode\u003e66340d7\u003c/code\u003e\u003c/a\u003e prepare changelog prior to release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gitpython-developers/GitPython/commit/a5e047d0db7047c4249c0de335585470b14d50c4\"\u003e\u003ccode\u003ea5e047d\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/issues/2211\"\u003e#2211\u003c/a\u003e from gitpython-developers/config-sanitize-more\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gitpython-developers/GitPython/commit/ef7568e3b317ce617eacda39b8b54dcdff8c3b5c\"\u003e\u003ccode\u003eef7568e\u003c/code\u003e\u003c/a\u003e fix: ignore includes in submodule configuration\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gitpython-developers/GitPython/commit/4b4e47fc1224e23b0c8ee7220a7192818f2e4abb\"\u003e\u003ccode\u003e4b4e47f\u003c/code\u003e\u003c/a\u003e fix: preserve multiline config values when writing\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gitpython-developers/GitPython/commit/b473abb0f7de754392e1ec923f2fe296509013ab\"\u003e\u003ccode\u003eb473abb\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/issues/2210\"\u003e#2210\u003c/a\u003e from gitpython-developers/fix-clone-unsafe-option\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gitpython-developers/GitPython/commit/5ff52cccca770fd69c6caf0b8f281d3e45d599be\"\u003e\u003ccode\u003e5ff52cc\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/issues/2209\"\u003e#2209\u003c/a\u003e from caroescm/fix-index-add-chmod\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gitpython-developers/GitPython/commit/b68afff45af0f49e79a3e2d2162018986b37ad5d\"\u003e\u003ccode\u003eb68afff\u003c/code\u003e\u003c/a\u003e Block separate git directories during clone\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gitpython-developers/GitPython/commit/93677a00ab9dcb06cc08595fd1f88a4b4a0fa23b\"\u003e\u003ccode\u003e93677a0\u003c/code\u003e\u003c/a\u003e fix: \u003ccode\u003eindex.add()\u003c/code\u003e now supports filters (\u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/issues/2021\"\u003e#2021\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gitpython-developers/GitPython/commit/9729ed3b948f2bde09f1f188c5311e172212b67e\"\u003e\u003ccode\u003e9729ed3\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/issues/2208\"\u003e#2208\u003c/a\u003e from gitpython-developers/security-fixes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gitpython-developers/GitPython/commit/ce9d8e8d150e06ae2e2cc2efa229071cd3048a93\"\u003e\u003ccode\u003ece9d8e8\u003c/code\u003e\u003c/a\u003e prepare next release\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/gitpython-developers/GitPython/compare/3.1.44...3.1.59\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `h2` from 4.3.0 to 4.4.1\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/python-hyper/h2/blob/master/CHANGELOG.rst\"\u003eh2's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e4.4.1 (2026-08-03)\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eBugfixes\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003ePerformance improvement: remove consumed frames in-place from data buffer.\u003c/li\u003e\n\u003cli\u003eReject duplicate Host headers in request headers. Thanks to Sunand Mohan for the report.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.4.0 (2026-07-23)\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eAPI Changes (Backward Incompatible)\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eSupport for Python 3.9 has been removed.\u003c/li\u003e\n\u003cli\u003eSupport for PyPy 3.9 has been removed.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eStream.end_stream()\u003c/code\u003e now raises \u003ccode\u003eNoSuchStreamError\u003c/code\u003e or \u003ccode\u003eStreamClosedError\u003c/code\u003e exceptions, instead of a generic \u003ccode\u003eKeyError\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eDuplicate \u003ccode\u003econtent-length\u003c/code\u003e headers with different values now raise \u003ccode\u003eProtocolError\u003c/code\u003e.\nPreviously, the first \u003ccode\u003econtent-length\u003c/code\u003e header was accepted and later conflicting values were ignored. Thanks to Harshal Parekh for the report.\u003c/li\u003e\n\u003cli\u003eParse \u003ccode\u003econtent-length\u003c/code\u003e headers according to RFC9110 grammar for numbers (1*DIGIT). Thanks to Arkadiusz Marta for the report.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ebackfill from v4.3.0\u003c/strong\u003e Convert emitted events into Python \u003ccode\u003edataclass\u003c/code\u003e, which introduces new constructors with required arguments.\nInstantiating these events without arguments, as previously commonly used API pattern, will no longer work.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eAPI Changes (Backward Compatible)\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eSupport for Python 3.14 has been added.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eH2Connection.receive_data\u003c/code\u003e now accepts any byte-like object that\nimplements the buffer protocol, such as \u003ccode\u003ebytes\u003c/code\u003e, \u003ccode\u003ebytearray\u003c/code\u003e, and\n\u003ccode\u003ememoryview\u003c/code\u003e. Existing \u003ccode\u003ebytes\u003c/code\u003e callers are unaffected.\u003c/li\u003e\n\u003cli\u003eAlign CONNECT pseudo-header validation with RFC 9113 s8.3 and RFC 8441 s4.\nOrdinary CONNECT now requires \u003ccode\u003e:method=CONNECT\u003c/code\u003e and \u003ccode\u003e:authority\u003c/code\u003e, and\nforbids \u003ccode\u003e:scheme\u003c/code\u003e/\u003ccode\u003e:path\u003c/code\u003e. Extended CONNECT (e.g., WebSocket) requires\n\u003ccode\u003e:scheme\u003c/code\u003e, \u003ccode\u003e:path\u003c/code\u003e, \u003ccode\u003e:authority\u003c/code\u003e plus \u003ccode\u003e:protocol\u003c/code\u003e. (PR \u003ca href=\"https://redirect.github.com/python-hyper/h2/issues/1309\"\u003e#1309\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix incorrect substring matching of secure header in \u003ccode\u003ecookie\u003c/code\u003e and \u003ccode\u003e:method\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eBugfixes\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eFix to allow sending 0 bytes on a stream even if the flow control window is negative.\u003c/li\u003e\n\u003cli\u003eReject non-zero \u003ccode\u003eSETTINGS_ENABLE_PUSH\u003c/code\u003e values received from servers.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-hyper/h2/commit/bc239af1d1b85bc70482804f30a0e0e587d90a08\"\u003e\u003ccode\u003ebc239af\u003c/code\u003e\u003c/a\u003e v4.4.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-hyper/h2/commit/92b925ed1b1817c82db32893503f74f47fcf4452\"\u003e\u003ccode\u003e92b925e\u003c/code\u003e\u003c/a\u003e add test for duplicate host headers\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-hyper/h2/commit/292a40829feefda98c8509dcdbbb4a57af9bd6a6\"\u003e\u003ccode\u003e292a408\u003c/code\u003e\u003c/a\u003e reject duplicate Host headers in request headers\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-hyper/h2/commit/04d3b87cbc1db020d28c7cfb44fe194558efbdde\"\u003e\u003ccode\u003e04d3b87\u003c/code\u003e\u003c/a\u003e update changelog\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-hyper/h2/commit/439b970d0fa19891fa81068907de97dfa3a07c3a\"\u003e\u003ccode\u003e439b970\u003c/code\u003e\u003c/a\u003e prepare for next release cycle\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-hyper/h2/commit/9a7ff7430df669fa8e90b6121f3cc1ed64d1115a\"\u003e\u003ccode\u003e9a7ff74\u003c/code\u003e\u003c/a\u003e performance: remove consumed frames in place from data buffer (\u003ca href=\"https://redirect.github.com/python-hyper/h2/issues/1321\"\u003e#1321\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-hyper/h2/commit/6cce763997eca5b826f3e435a611b7a7fc73f633\"\u003e\u003ccode\u003e6cce763\u003c/code\u003e\u003c/a\u003e v4.4.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-hyper/h2/commit/dfafda3b0cd96455b45d1785ef1ebc6968bba5cf\"\u003e\u003ccode\u003edfafda3\u003c/code\u003e\u003c/a\u003e Bump pytest from 8.4.2 to 9.0.3 (\u003ca href=\"https://redirect.github.com/python-hyper/h2/issues/1320\"\u003e#1320\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-hyper/h2/commit/b45207cedf9fabe2c77bb3c1c10f403a610599a0\"\u003e\u003ccode\u003eb45207c\u003c/code\u003e\u003c/a\u003e dependencies and packaging++\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-hyper/h2/commit/c40145f69c5473850849fe96301ac0416b1afea6\"\u003e\u003ccode\u003ec40145f\u003c/code\u003e\u003c/a\u003e parse \u003ccode\u003econtent-length\u003c/code\u003e headers according to RFC9110 grammar for numbers (1*DI...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/python-hyper/h2/compare/v4.3.0...v4.4.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `tornado` from 6.5 to 6.5.8\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/tornadoweb/tornado/blob/master/docs/releases.rst\"\u003etornado's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003eRelease notes\u003c/h1\u003e\n\u003cp\u003e.. toctree::\n:maxdepth: 2\u003c/p\u003e\n\u003cp\u003ereleases/v6.5.10\nreleases/v6.5.9\nreleases/v6.5.8\nreleases/v6.5.7\nreleases/v6.5.6\nreleases/v6.5.5\nreleases/v6.5.4\nreleases/v6.5.3\nreleases/v6.5.2\nreleases/v6.5.1\nreleases/v6.5.0\nreleases/v6.4.2\nreleases/v6.4.1\nreleases/v6.4.0\nreleases/v6.3.3\nreleases/v6.3.2\nreleases/v6.3.1\nreleases/v6.3.0\nreleases/v6.2.0\nreleases/v6.1.0\nreleases/v6.0.4\nreleases/v6.0.3\nreleases/v6.0.2\nreleases/v6.0.1\nreleases/v6.0.0\nreleases/v5.1.1\nreleases/v5.1.0\nreleases/v5.0.2\nreleases/v5.0.1\nreleases/v5.0.0\nreleases/v4.5.3\nreleases/v4.5.2\nreleases/v4.5.1\nreleases/v4.5.0\nreleases/v4.4.3\nreleases/v4.4.2\nreleases/v4.4.1\nreleases/v4.4.0\nreleases/v4.3.0\nreleases/v4.2.1\nreleases/v4.2.0\nreleases/v4.1.0\nreleases/v4.0.2\nreleases/v4.0.1\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tornadoweb/tornado/commit/a55abe3e3bf59994f29b2f7084c46341f0d4f6a7\"\u003e\u003ccode\u003ea55abe3\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/tornadoweb/tornado/issues/3704\"\u003e#3704\u003c/a\u003e from bdarnell/security-6.5.8\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tornadoweb/tornado/commit/fc794885f0ccf9c33f3a66d890abcc237dd50b3c\"\u003e\u003ccode\u003efc79488\u003c/code\u003e\u003c/a\u003e docs: add additional credit to release notes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tornadoweb/tornado/commit/7b017630d3139ca0d1ebdf6ac3b3ffe7725a7129\"\u003e\u003ccode\u003e7b01763\u003c/code\u003e\u003c/a\u003e Fix test_strip_headers_on_redirect's URL-embedded-credentials cases\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tornadoweb/tornado/commit/d72fff8d7b9b8f6aa68505847e5483d600e3184c\"\u003e\u003ccode\u003ed72fff8\u003c/code\u003e\u003c/a\u003e release notes and version bump for 6.5.8\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tornadoweb/tornado/commit/b168818f8aae39808b981878fb358cbe02a6238e\"\u003e\u003ccode\u003eb168818\u003c/code\u003e\u003c/a\u003e auth: Formally deprecated OpenIDMixin\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tornadoweb/tornado/commit/da284767eae8e1f0484f123b8c3225f6465b09c7\"\u003e\u003ccode\u003eda28476\u003c/code\u003e\u003c/a\u003e web: Also check for semicolons in deprecated mixed-case cookie args\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tornadoweb/tornado/commit/8d6363ed7b69d5f0da806efe34d256627a2191de\"\u003e\u003ccode\u003e8d6363e\u003c/code\u003e\u003c/a\u003e httputil: Enforce a new limit on the number of arguments in a request\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tornadoweb/tornado/commit/de85b3f87446e323e881bbaa3d5a74f4b76e5f05\"\u003e\u003ccode\u003ede85b3f\u003c/code\u003e\u003c/a\u003e httputil: Apply multipart max_parts limit earlier\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tornadoweb/tornado/commit/48fc2d43d1f48b8b3b0be5dcf6a7634c6f45b1c4\"\u003e\u003ccode\u003e48fc2d4\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/tornadoweb/tornado/issues/3633\"\u003e#3633\u003c/a\u003e from bdarnell/curl-reset-65\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tornadoweb/tornado/commit/4ae1ddd14245e56e9fb6fb14d4b9508301fbb841\"\u003e\u003ccode\u003e4ae1ddd\u003c/code\u003e\u003c/a\u003e Release notes and version bump for 6.5.7\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/tornadoweb/tornado/compare/v6.5.0...v6.5.8\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `pillow` from 10.3.0 to 12.3.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/python-pillow/Pillow/releases\"\u003epillow's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e12.3.0\u003c/h2\u003e\n\u003cp\u003e\u003ca href=\"https://pillow.readthedocs.io/en/stable/releasenotes/12.3.0.html\"\u003ehttps://pillow.readthedocs.io/en/stable/releasenotes/12.3.0.html\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eRemovals\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRemove non-image ImageCms modes \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9697\"\u003e#9697\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eDocumentation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd release notes for SBOM and performance improvements \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9747\"\u003e#9747\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdd security release notes \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9741\"\u003e#9741\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdd release notes for Python 3.15 beta wheels \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9696\"\u003e#9696\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eImageFont can also be used with ImageText \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9597\"\u003e#9597\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdditional guidelines for security reports \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9659\"\u003e#9659\u003c/a\u003e [\u003ca href=\"https://github.com/wiredfool\"\u003e\u003ccode\u003e@​wiredfool\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eFixed typo \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9636\"\u003e#9636\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdded CVEs to 12.2.0 release notes \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9591\"\u003e#9591\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eRevise development support information in README \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9583\"\u003e#9583\u003c/a\u003e [\u003ca href=\"https://github.com/aclark4life\"\u003e\u003ccode\u003e@​aclark4life\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdd INCIDENT_RESPONSE.md \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9555\"\u003e#9555\u003c/a\u003e [\u003ca href=\"https://github.com/aclark4life\"\u003e\u003ccode\u003e@​aclark4life\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdd STRIDE threat model to security docs \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9562\"\u003e#9562\u003c/a\u003e [\u003ca href=\"https://github.com/aclark4life\"\u003e\u003ccode\u003e@​aclark4life\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdd CVEs to 12.2.0 release notes \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9556\"\u003e#9556\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate README with revised security policy \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9553\"\u003e#9553\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate security policy \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9552\"\u003e#9552\u003c/a\u003e [\u003ca href=\"https://github.com/aclark4life\"\u003e\u003ccode\u003e@​aclark4life\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate macOS tested Python versions \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9534\"\u003e#9534\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eDependencies\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate dependency harfbuzz to v14.2.1 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9720\"\u003e#9720\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency mypy to v2 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9653\"\u003e#9653\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency cibuildwheel to v4 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9665\"\u003e#9665\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate github-actions \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9655\"\u003e#9655\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency libavif to v1.4.2 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9652\"\u003e#9652\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency lcms2 to v2.19.1 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9651\"\u003e#9651\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency check-jsonschema to v0.37.2 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9650\"\u003e#9650\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate google/oss-fuzz digest to d872252 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9614\"\u003e#9614\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency lcms2 to v2.19 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9609\"\u003e#9609\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency libpng to v1.6.58 - autoclosed \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9608\"\u003e#9608\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency harfbuzz to v14 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9610\"\u003e#9610\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency mypy to v1.20.2 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9599\"\u003e#9599\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate github-actions \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9611\"\u003e#9611\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency cibuildwheel to v3.4.1 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9607\"\u003e#9607\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eMove dependency versions to single JSON and enable Renovate \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9559\"\u003e#9559\u003c/a\u003e [\u003ca href=\"https://github.com/hugovk\"\u003e\u003ccode\u003e@​hugovk\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdated raqm to 0.10.5 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9557\"\u003e#9557\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency cibuildwheel to v3.4.0 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9532\"\u003e#9532\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eTesting\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRemove matrix.os from benchmark \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9735\"\u003e#9735\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eRemove references to libavif patch \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9734\"\u003e#9734\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdd benchmark tests \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9654\"\u003e#9654\u003c/a\u003e [\u003ca href=\"https://github.com/akx\"\u003e\u003ccode\u003e@​akx\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUse reshape() instead of setting NumPy array shape directly \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9728\"\u003e#9728\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/python-pillow/Pillow/blob/main/CHANGES.rst\"\u003epillow's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003eChangelog (Pillow)\u003c/h1\u003e\n\u003ch2\u003e11.1.0 and newer\u003c/h2\u003e\n\u003cp\u003eSee GitHub Releases:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/releases\"\u003ehttps://github.com/python-pillow/Pillow/releases\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e11.0.0 (2024-10-15)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eUpdate licence to MIT-CMU \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/8460\"\u003e#8460\u003c/a\u003e\n[hugovk]\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eConditionally define ImageCms type hint to avoid requiring core \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/8197\"\u003e#8197\u003c/a\u003e\n[radarhere]\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eSupport writing LONG8 offsets in AppendingTiffWriter \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/8417\"\u003e#8417\u003c/a\u003e\n[radarhere]\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUse ImageFile.MAXBLOCK when saving TIFF images \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/8461\"\u003e#8461\u003c/a\u003e\n[radarhere]\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eDo not close provided file handles with libtiff when saving \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/8458\"\u003e#8458\u003c/a\u003e\n[radarhere]\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eSupport ImageFilter.BuiltinFilter for I;16* images \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/8438\"\u003e#8438\u003c/a\u003e\n[radarhere]\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUse ImagingCore.ptr instead of ImagingCore.id \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/8341\"\u003e#8341\u003c/a\u003e\n[homm, radarhere, hugovk]\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUpdated EPS mode when opening images without transparency \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/8281\"\u003e#8281\u003c/a\u003e\n[Yay295, radarhere]\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUse transparency when combining P frames from APNGs \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/8443\"\u003e#8443\u003c/a\u003e\n[radarhere]\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eSupport all resampling filters when resizing I;16* images \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/8422\"\u003e#8422\u003c/a\u003e\n[radarhere]\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFree memory on early return \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/8413\"\u003e#8413\u003c/a\u003e\n[radarhere]\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eCast int before potentially exceeding INT_MAX \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/8402\"\u003e#8402\u003c/a\u003e\n[radarhere]\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/bb1d8e8ab8d29048624d96e3ee53cecf7c13d13d\"\u003e\u003ccode\u003ebb1d8e8\u003c/code\u003e\u003c/a\u003e 12.3.0 version bump\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/e63fc481dc2e07e21d5403deafb8f1ed98a513af\"\u003e\u003ccode\u003ee63fc48\u003c/code\u003e\u003c/a\u003e Add release notes for SBOM and performance improvements (\u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9747\"\u003e#9747\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/13b701bbab291eec4bc87ea17ba06c94e5fe3054\"\u003e\u003ccode\u003e13b701b\u003c/code\u003e\u003c/a\u003e Add release notes for \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9679\"\u003e#9679\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/5564ca72fcd59d040e270af5dcf17a0d7161c364\"\u003e\u003ccode\u003e5564ca7\u003c/code\u003e\u003c/a\u003e List methods\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/a0920fd384f800b5d0ba3dd29ecdeae4f1d4043b\"\u003e\u003ccode\u003ea0920fd\u003c/code\u003e\u003c/a\u003e Speed up ImageChops operations (\u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9738\"\u003e#9738\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/07e9a6cd5336dc6cf8cae9165cd70cdd2b3e42fc\"\u003e\u003ccode\u003e07e9a6c\u003c/code\u003e\u003c/a\u003e Speed up \u003ccode\u003eImage.filter()\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9736\"\u003e#9736\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/a94578cf9649ea13e426cf7fb2b71b39ffc0dd50\"\u003e\u003ccode\u003ea94578c\u003c/code\u003e\u003c/a\u003e Speed up \u003ccode\u003eImage.getchannel()\u003c/code\u003e, \u003ccode\u003eImage.merge()\u003c/code\u003e, \u003ccode\u003eImage.putalpha()\u003c/code\u003e and `Image...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/53e02c43c919d149b2a154a5180079f9df18fbbb\"\u003e\u003ccode\u003e53e02c4\u003c/code\u003e\u003c/a\u003e Speed up \u003ccode\u003eImage.fill()\u003c/code\u003e, \u003ccode\u003eImage.linear_gradient()\u003c/code\u003e and `Image.radial_gradient...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/af037475be8634ba739744243164ba9e2c8346a6\"\u003e\u003ccode\u003eaf03747\u003c/code\u003e\u003c/a\u003e Speed up \u003ccode\u003eImage.resample()\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9739\"\u003e#9739\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/5c9ca56c3e5fba52b647809fbb0986c87e73a571\"\u003e\u003ccode\u003e5c9ca56\u003c/code\u003e\u003c/a\u003e Speed up \u003ccode\u003ealpha_composite\u003c/code\u003e, \u003ccode\u003ematrix\u003c/code\u003e, \u003ccode\u003enegative\u003c/code\u003e, \u003ccode\u003equantize\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9740\"\u003e#9740\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/python-pillow/Pillow/compare/10.3.0...12.3.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/RemyLoveLogicAI/suna/network/alerts).\n\n\u003c/details\u003e\n\n\u003cdiv id='description'\u003e\n\u003ca href=\"https://bito.ai#summarystart\"\u003e\u003c/a\u003e\u003ch3\u003eSummary by Bito\u003c/h3\u003e\u003cul\u003e\u003cli\u003eUpdated aiohttp dependency from 3.12.14 to 3.14.3 in backend/poetry.lock and backend/pyproject.toml.\u003c/li\u003e\n\u003cli\u003eUpdated backend/sandbox/docker/requirements.txt to reflect dependency changes.\u003c/li\u003e\n\u003cli\u003eUpdated frontend/package.json and frontend/package-lock.json with various dependency updates.\u003c/li\u003e\n\u003cli\u003eIncreased minimum Python version requirement for aiohttp to 3.10.\u003c/li\u003e\n\u003c/ul\u003e\u003c/div\u003e\n\n\u003c!-- This is an auto-generated description by cubic. --\u003e\n---\n## Summary by cubic\nBumps 8 Python dependencies in `backend` and `backend/sandbox/docker`, pulling in security fixes for `pyjwt`, `gitpython`, and `tornado`.\n\n**Notes**\n- `pyjwt` 2.13.0 now raises `InvalidKeyError` on empty HMAC secrets and rejects non-HTTP(S) `PyJWKClient` URIs.\n- `python-multipart` 0.0.31 adds header and boundary size limits and rejects negative `Content-Length`.\n- `h2` 4.4.1 drops Python 3.9 and raises `NoSuchStreamError`/`StreamClosedError` instead of `KeyError` for closed streams.\n- `setuptools`, `aiohttp`, and `python-multipart` now require Python 3.10+, which is satisfied by `python = \"^3.11\"`.\n\n\u003csup\u003eWritten for commit 0b5994a4f371a4bc53a09cf49370ed24e8f9df1b. Summary will update on new commits.\u003c/sup\u003e\n\n\u003ca href=\"https://cubic.dev/pr/RemyLoveLogicAI/suna/pull/26?utm_source=github\" target=\"_blank\" rel=\"noopener noreferrer\" data-no-image-dialog=\"true\"\u003e\u003cpicture\u003e\u003csource media=\"(prefers-color-scheme: dark)\" srcset=\"https://www.cubic.dev/buttons/review-in-cubic-dark.svg\"\u003e\u003csource media=\"(prefers-color-scheme: light)\" srcset=\"https://www.cubic.dev/buttons/review-in-cubic-light.svg\"\u003e\u003cimg alt=\"Review in cubic\" src=\"https://www.cubic.dev/buttons/review-in-cubic-dark.svg\"\u003e\u003c/picture\u003e\u003c/a\u003e\n\n\u003c!-- End of auto-generated description by cubic. --\u003e\n\n","html_url":"https://github.com/RemyLoveLogicAI/suna/pull/26","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/RemyLoveLogicAI%2Fsuna/issues/26","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/26/packages"},{"uuid":"5486487206","node_id":"PR_kwDOLyV66M8AAAABD6imRQ","number":1,"state":"open","title":"chore(deps): bump the pip group across 1 directory with 12 updates","user":"dependabot[bot]","labels":["dependencies","python"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-17T11:04:28.000Z","updated_at":"2026-09-17T11:04:50.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps): bump","group_name":"pip","update_count":12,"packages":[{"name":"aiohttp","old_version":"3.9.5","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"cryptography","old_version":"42.0.5","new_version":"50.0.0","repository_url":"https://github.com/pyca/cryptography"},{"name":"flask","old_version":"3.0.3","new_version":"3.1.3","repository_url":"https://github.com/pallets/flask"},{"name":"httplib2","old_version":"0.22.0","new_version":"0.32.0","repository_url":"https://github.com/httplib2/httplib2"},{"name":"idna","old_version":"3.7","new_version":"3.15","repository_url":"https://github.com/kjd/idna"},{"name":"marshmallow","old_version":"3.21.1","new_version":"3.26.2","repository_url":"https://github.com/marshmallow-code/marshmallow"},{"name":"orjson","old_version":"3.10.1","new_version":"3.11.6","repository_url":"https://github.com/ijl/orjson"},{"name":"pillow","old_version":"10.3.0","new_version":"12.3.0","repository_url":"https://github.com/python-pillow/Pillow"},{"name":"pyasn1","old_version":"0.6.0","new_version":"0.6.4","repository_url":"https://github.com/pyasn1/pyasn1"},{"name":"requests","old_version":"2.31.0","new_version":"2.33.0","repository_url":"https://github.com/psf/requests"},{"name":"urllib3","old_version":"2.2.1","new_version":"2.7.0","repository_url":"https://github.com/urllib3/urllib3"},{"name":"werkzeug","old_version":"3.0.2","new_version":"3.1.8","repository_url":"https://github.com/pallets/werkzeug"}],"path":null,"ecosystem":"pip"},"body":"Bumps the pip group with 12 updates in the /src/shoppingassistantservice directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [aiohttp](https://github.com/aio-libs/aiohttp) | `3.9.5` | `3.14.3` |\n| [cryptography](https://github.com/pyca/cryptography) | `42.0.5` | `50.0.0` |\n| [flask](https://github.com/pallets/flask) | `3.0.3` | `3.1.3` |\n| [httplib2](https://github.com/httplib2/httplib2) | `0.22.0` | `0.32.0` |\n| [idna](https://github.com/kjd/idna) | `3.7` | `3.15` |\n| [marshmallow](https://github.com/marshmallow-code/marshmallow) | `3.21.1` | `3.26.2` |\n| [orjson](https://github.com/ijl/orjson) | `3.10.1` | `3.11.6` |\n| [pillow](https://github.com/python-pillow/Pillow) | `10.3.0` | `12.3.0` |\n| [pyasn1](https://github.com/pyasn1/pyasn1) | `0.6.0` | `0.6.4` |\n| [requests](https://github.com/psf/requests) | `2.31.0` | `2.33.0` |\n| [urllib3](https://github.com/urllib3/urllib3) | `2.2.1` | `2.7.0` |\n| [werkzeug](https://github.com/pallets/werkzeug) | `3.0.2` | `3.1.8` |\n\n\nUpdates `aiohttp` from 3.9.5 to 3.14.3\nUpdates `cryptography` from 42.0.5 to 50.0.0\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst\"\u003ecryptography's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e50.0.0 - 2026-07-31\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003e\n* **SECURITY ISSUE**:\n  :func:`~cryptography.hazmat.primitives.serialization.pkcs7.pkcs7_decrypt_der`\n  and its PEM and S/MIME variants no longer expose distinguishable errors or\n  timing when unwrapping a ``RecipientInfo``'s ``encryptedKey``, which could\n  act as a Bleichenbacher oracle for callers that decrypt untrusted messages.\n  A random key is now substituted on failure, as described in :rfc:`3218`.\n  Credit to **@X1AOxiang** for reporting the issue. **CVE-2026-69247**\n* Deprecated Diffie-Hellman key exchange over finite fields (FFDH).\n  Everything FFDH is deprecated, including the types in\n  ``cryptography.hazmat.primitives.asymmetric.dh`` and loading FFDH keys or\n  parameters with the key loading APIs. Users should migrate to a more\n  modern key exchange algorithm.\n* Added ``xof()`` class methods to\n  :class:`~cryptography.hazmat.primitives.hashes.SHAKE128` and\n  :class:`~cryptography.hazmat.primitives.hashes.SHAKE256` for constructing\n  algorithm instances configured for use with\n  :class:`~cryptography.hazmat.primitives.hashes.XOFHash`.\n* The :mod:`X.509 verification \u0026lt;cryptography.x509.verification\u0026gt;` APIs are now\n  considered stable and are subject to our API stability policy.\n* Added the :doc:`/cobblestone` recipe, an implementation of the\n  Cobblestone-128 and Cobblestone-256 instantiations of the `C2SP\n  chunked-encryption specification\n  \u0026lt;https://c2sp.org/chunked-encryption\u0026gt;`_ for streaming authenticated\n  encryption of large messages.\n* Parsing a Signed Certificate Timestamp list now rejects encodings that\n  carry trailing bytes after the list or after an individual SCT, instead of\n  silently ignoring them.\n* Added support for using :class:`~cryptography.x509.Name` as a field type in\n  the :doc:`/hazmat/asn1/index` module.\n* Loading a public key or an EC private key now rejects DER where the\n  ``subjectPublicKey`` (or EC ``publicKey``) ``BIT STRING`` declares a non-zero\n  number of unused bits, instead of silently ignoring it.\n* Parsing a CRL entry's ``InvalidityDate`` extension now rejects a\n  ``GeneralizedTime`` that carries fractional seconds or another non-DER form,\n  matching the strict encoding already required for every other X.509 time\n  field.\n* :func:`~cryptography.x509.ocsp.load_der_ocsp_request` and\n  :func:`~cryptography.x509.ocsp.load_der_ocsp_response` now reject a request\n  or response whose ``version`` field is not ``v1``, the only version defined\n  by RFC 6960, matching the version validation already performed when loading\n  certificates, CSRs and CRLs.\n* :class:`~cryptography.hazmat.primitives.hashes.XOFHash` is now supported\n  when building against AWS-LC.\n* HMAC (and therefore PBKDF2-HMAC) with SHA-3 hashes is now supported when\n  building against AWS-LC.\n* Diffie-Hellman (:doc:`/hazmat/primitives/asymmetric/dh`) is now supported\n  when building against AWS-LC.\n\u0026lt;/tr\u0026gt;\u0026lt;/table\u0026gt; \n\u003c/code\u003e\u003c/pre\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/dcb7050b807b00392fa9fe2eac7cb362fcf355cc\"\u003e\u003ccode\u003edcb7050\u003c/code\u003e\u003c/a\u003e Prepare for 50.0.0 release (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15372\"\u003e#15372\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/53fccd93413a8d7f07d6d8999681f27b75cffa3f\"\u003e\u003ccode\u003e53fccd9\u003c/code\u003e\u003c/a\u003e Don't leak how PKCS#7 encryptedKey decryption failed (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15369\"\u003e#15369\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/d472f978470fbefa521b86d98b2ecccbbb4d1dd8\"\u003e\u003ccode\u003ed472f97\u003c/code\u003e\u003c/a\u003e Add \u003ccode\u003efrom __future__ import annotations\u003c/code\u003e to all src/ Python files (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15371\"\u003e#15371\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/908773d53829fb1466c6db364b31321c3cd8eb9a\"\u003e\u003ccode\u003e908773d\u003c/code\u003e\u003c/a\u003e Bump downstream dependencies in CI (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15368\"\u003e#15368\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/2cc07cc948948211899bcb0cddd1fddf86e95812\"\u003e\u003ccode\u003e2cc07cc\u003c/code\u003e\u003c/a\u003e Bump BoringSSL, OpenSSL, AWS-LC in CI (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15367\"\u003e#15367\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/c94ede9f040fa44942f7139772603419000acf66\"\u003e\u003ccode\u003ec94ede9\u003c/code\u003e\u003c/a\u003e chore(deps): bump ruff from 0.16.0 to 0.16.1 (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15366\"\u003e#15366\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/67a8308dc9ea4cce6056e0f1438f903c208c3f35\"\u003e\u003ccode\u003e67a8308\u003c/code\u003e\u003c/a\u003e chore(deps): bump virtualenv from 21.7.0 to 21.7.1 (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15365\"\u003e#15365\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/95018ffcdbbc510fd92fc872e3a3e80aa6e58596\"\u003e\u003ccode\u003e95018ff\u003c/code\u003e\u003c/a\u003e Release the GIL in one-shot AEAD encrypt/decrypt (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15361\"\u003e#15361\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/6954733eaf55a0074abf88f06f7242dfca3a5d02\"\u003e\u003ccode\u003e6954733\u003c/code\u003e\u003c/a\u003e Release the GIL during DH and DSA parameter generation (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15364\"\u003e#15364\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/6893b94c33e948f6240082461424cfb5da2dacc6\"\u003e\u003ccode\u003e6893b94\u003c/code\u003e\u003c/a\u003e Import _serialization instead of serialization in x509/extensions (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15363\"\u003e#15363\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/pyca/cryptography/compare/42.0.5...50.0.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `flask` from 3.0.3 to 3.1.3\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pallets/flask/releases\"\u003eflask's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e3.1.3\u003c/h2\u003e\n\u003cp\u003eThis is the Flask 3.1.3 security fix release, which fixes a security issue but does not otherwise change behavior and should not result in breaking changes compared to the latest feature release.\u003c/p\u003e\n\u003cp\u003ePyPI: \u003ca href=\"https://pypi.org/project/Flask/3.1.3/\"\u003ehttps://pypi.org/project/Flask/3.1.3/\u003c/a\u003e\nChanges: \u003ca href=\"https://flask.palletsprojects.com/page/changes/#version-3-1-3\"\u003ehttps://flask.palletsprojects.com/page/changes/#version-3-1-3\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eThe session is marked as accessed for operations that only access the keys but not the values, such as \u003ccode\u003ein\u003c/code\u003e and \u003ccode\u003elen\u003c/code\u003e. \u003ca href=\"https://github.com/pallets/flask/security/advisories/GHSA-68rp-wp8r-4726\"\u003eGHSA-68rp-wp8r-4726\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.1.2\u003c/h2\u003e\n\u003cp\u003eThis is the Flask 3.1.2 fix release, which fixes bugs but does not otherwise change behavior and should not result in breaking changes compared to the latest feature release.\u003c/p\u003e\n\u003cp\u003ePyPI: \u003ca href=\"https://pypi.org/project/Flask/3.1.2/\"\u003ehttps://pypi.org/project/Flask/3.1.2/\u003c/a\u003e\nChanges: \u003ca href=\"https://flask.palletsprojects.com/page/changes/#version-3-1-2\"\u003ehttps://flask.palletsprojects.com/page/changes/#version-3-1-2\u003c/a\u003e\nMilestone: \u003ca href=\"https://github.com/pallets/flask/milestone/38?closed=1\"\u003ehttps://github.com/pallets/flask/milestone/38?closed=1\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003estream_with_context\u003c/code\u003e does not fail inside async views. \u003ca href=\"https://redirect.github.com/pallets/flask/issues/5774\"\u003e#5774\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eWhen using \u003ccode\u003efollow_redirects\u003c/code\u003e in the test client, the final state of \u003ccode\u003esession\u003c/code\u003e is correct. \u003ca href=\"https://redirect.github.com/pallets/flask/issues/5786\"\u003e#5786\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRelax type hint for passing bytes IO to \u003ccode\u003esend_file\u003c/code\u003e. \u003ca href=\"https://redirect.github.com/pallets/flask/issues/5776\"\u003e#5776\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.1.1\u003c/h2\u003e\n\u003cp\u003eThis is the Flask 3.1.1 fix release, which fixes bugs but does not otherwise change behavior and should not result in breaking changes compared to the latest feature release.\u003c/p\u003e\n\u003cp\u003ePyPI: \u003ca href=\"https://pypi.org/project/Flask/3.1.1/\"\u003ehttps://pypi.org/project/Flask/3.1.1/\u003c/a\u003e\nChanges: \u003ca href=\"https://flask.palletsprojects.com/en/stable/changes/#version-3-1-1\"\u003ehttps://flask.palletsprojects.com/en/stable/changes/#version-3-1-1\u003c/a\u003e\nMilestone \u003ca href=\"https://github.com/pallets/flask/milestone/36?closed=1\"\u003ehttps://github.com/pallets/flask/milestone/36?closed=1\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eFix signing key selection order when key rotation is enabled via \u003ccode\u003eSECRET_KEY_FALLBACKS\u003c/code\u003e. GHSA-4grg-w6v8-c28g\u003c/li\u003e\n\u003cli\u003eFix type hint for \u003ccode\u003ecli_runner.invoke\u003c/code\u003e. \u003ca href=\"https://redirect.github.com/pallets/flask/issues/5645\"\u003e#5645\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eflask --help\u003c/code\u003e loads the app and plugins first to make sure all commands are shown. \u003ca href=\"https://redirect.github.com/pallets/flask/issues/5673\"\u003e#5673\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eMark sans-io base class as being able to handle views that return \u003ccode\u003eAsyncIterable\u003c/code\u003e. This is not accurate for Flask, but makes typing easier for Quart. \u003ca href=\"https://redirect.github.com/pallets/flask/issues/5659\"\u003e#5659\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.1.0\u003c/h2\u003e\n\u003cp\u003eThis is the Flask 3.1.0 feature release. A feature release may include new features, remove previously deprecated code, add new deprecations, or introduce potentially breaking changes. We encourage everyone to upgrade, and to use a tool such as \u003ca href=\"https://pypi.org/project/pip-tools/\"\u003epip-tools\u003c/a\u003e to pin all dependencies and control upgrades. Test with warnings treated as errors to be able to adapt to deprecation warnings early.\u003c/p\u003e\n\u003cp\u003ePyPI: \u003ca href=\"https://pypi.org/project/Flask/3.1.0/\"\u003ehttps://pypi.org/project/Flask/3.1.0/\u003c/a\u003e\nChanges: \u003ca href=\"https://flask.palletsprojects.com/en/stable/changes/#version-3-1-0\"\u003ehttps://flask.palletsprojects.com/en/stable/changes/#version-3-1-0\u003c/a\u003e\nMilestone: \u003ca href=\"https://github.com/pallets/flask/milestone/33?closed=1\"\u003ehttps://github.com/pallets/flask/milestone/33?closed=1\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eDrop support for Python 3.8. \u003ca href=\"https://redirect.github.com/pallets/flask/issues/5623\"\u003e#5623\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate minimum dependency versions to latest feature releases. Werkzeug \u0026gt;= 3.1, ItsDangerous \u0026gt;= 2.2, Blinker \u0026gt;= 1.9. \u003ca href=\"https://redirect.github.com/pallets/flask/issues/5624\"\u003e#5624\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/pallets/flask/issues/5633\"\u003e#5633\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eProvide a configuration option to control automatic option responses. \u003ca href=\"https://redirect.github.com/pallets/flask/issues/5496\"\u003e#5496\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eFlask.open_resource\u003c/code\u003e/\u003ccode\u003eopen_instance_resource\u003c/code\u003e and \u003ccode\u003eBlueprint.open_resource\u003c/code\u003e take an \u003ccode\u003eencoding\u003c/code\u003e parameter to use when opening in text mode. It defaults to \u003ccode\u003eutf-8\u003c/code\u003e. \u003ca href=\"https://redirect.github.com/pallets/flask/issues/5504\"\u003e#5504\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eRequest.max_content_length\u003c/code\u003e can be customized per-request instead of only through the \u003ccode\u003eMAX_CONTENT_LENGTH\u003c/code\u003e config. Added \u003ccode\u003eMAX_FORM_MEMORY_SIZE\u003c/code\u003e and \u003ccode\u003eMAX_FORM_PARTS\u003c/code\u003e config. Added documentation about resource limits to the security page. \u003ca href=\"https://redirect.github.com/pallets/flask/issues/5625\"\u003e#5625\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd support for the \u003ccode\u003ePartitioned\u003c/code\u003e cookie attribute (CHIPS), with the \u003ccode\u003eSESSION_COOKIE_PARTITIONED\u003c/code\u003e config. \u003ca href=\"https://redirect.github.com/pallets/flask/issues/5472\"\u003e#5472\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e-e path\u003c/code\u003e takes precedence over default \u003ccode\u003e.env\u003c/code\u003e and \u003ccode\u003e.flaskenv\u003c/code\u003e files. \u003ccode\u003eload_dotenv\u003c/code\u003e loads default files in addition to a path unless \u003ccode\u003eload_defaults=False\u003c/code\u003e is passed. \u003ca href=\"https://redirect.github.com/pallets/flask/issues/5628\"\u003e#5628\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSupport key rotation with the \u003ccode\u003eSECRET_KEY_FALLBACKS\u003c/code\u003e config, a list of old secret keys that can still be used for unsigning. Extensions will need to add support. \u003ca href=\"https://redirect.github.com/pallets/flask/issues/5621\"\u003e#5621\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix how setting \u003ccode\u003ehost_matching=True\u003c/code\u003e or \u003ccode\u003esubdomain_matching=False\u003c/code\u003e interacts with \u003ccode\u003eSERVER_NAME\u003c/code\u003e. Setting \u003ccode\u003eSERVER_NAME\u003c/code\u003e no longer restricts requests to only that domain. \u003ca href=\"https://redirect.github.com/pallets/flask/issues/5553\"\u003e#5553\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eRequest.trusted_hosts\u003c/code\u003e is checked during routing, and can be set through the \u003ccode\u003eTRUSTED_HOSTS\u003c/code\u003e config. \u003ca href=\"https://redirect.github.com/pallets/flask/issues/5636\"\u003e#5636\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pallets/flask/blob/main/CHANGES.rst\"\u003eflask's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eVersion 3.1.3\u003c/h2\u003e\n\u003cp\u003eReleased 2026-02-18\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eThe session is marked as accessed for operations that only access the keys\nbut not the values, such as \u003ccode\u003ein\u003c/code\u003e and \u003ccode\u003elen\u003c/code\u003e. :ghsa:\u003ccode\u003e68rp-wp8r-4726\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eVersion 3.1.2\u003c/h2\u003e\n\u003cp\u003eReleased 2025-08-19\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003estream_with_context\u003c/code\u003e does not fail inside async views. :issue:\u003ccode\u003e5774\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eWhen using \u003ccode\u003efollow_redirects\u003c/code\u003e in the test client, the final state\nof \u003ccode\u003esession\u003c/code\u003e is correct. :issue:\u003ccode\u003e5786\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eRelax type hint for passing bytes IO to \u003ccode\u003esend_file\u003c/code\u003e. :issue:\u003ccode\u003e5776\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eVersion 3.1.1\u003c/h2\u003e\n\u003cp\u003eReleased 2025-05-13\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eFix signing key selection order when key rotation is enabled via\n\u003ccode\u003eSECRET_KEY_FALLBACKS\u003c/code\u003e. :ghsa:\u003ccode\u003e4grg-w6v8-c28g\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eFix type hint for \u003ccode\u003ecli_runner.invoke\u003c/code\u003e. :issue:\u003ccode\u003e5645\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eflask --help\u003c/code\u003e loads the app and plugins first to make sure all commands\nare shown. :issue:\u003ccode\u003e5673\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eMark sans-io base class as being able to handle views that return\n\u003ccode\u003eAsyncIterable\u003c/code\u003e. This is not accurate for Flask, but makes typing easier\nfor Quart. :pr:\u003ccode\u003e5659\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eVersion 3.1.0\u003c/h2\u003e\n\u003cp\u003eReleased 2024-11-13\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eDrop support for Python 3.8. :pr:\u003ccode\u003e5623\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eUpdate minimum dependency versions to latest feature releases.\nWerkzeug \u0026gt;= 3.1, ItsDangerous \u0026gt;= 2.2, Blinker \u0026gt;= 1.9. :pr:\u003ccode\u003e5624,5633\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eProvide a configuration option to control automatic option\nresponses. :pr:\u003ccode\u003e5496\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eFlask.open_resource\u003c/code\u003e/\u003ccode\u003eopen_instance_resource\u003c/code\u003e and\n\u003ccode\u003eBlueprint.open_resource\u003c/code\u003e take an \u003ccode\u003eencoding\u003c/code\u003e parameter to use when\nopening in text mode. It defaults to \u003ccode\u003eutf-8\u003c/code\u003e. :issue:\u003ccode\u003e5504\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eRequest.max_content_length\u003c/code\u003e can be customized per-request instead of only\nthrough the \u003ccode\u003eMAX_CONTENT_LENGTH\u003c/code\u003e config. Added\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pallets/flask/commit/22d924701a6ae2e4cd01e9a15bbaf3946094af65\"\u003e\u003ccode\u003e22d9247\u003c/code\u003e\u003c/a\u003e release version 3.1.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pallets/flask/commit/089cb86dd22bff589a4eafb7ab8e42dc357623b4\"\u003e\u003ccode\u003e089cb86\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pallets/flask/commit/c17f379390731543eea33a570a47bd4ef76a54fa\"\u003e\u003ccode\u003ec17f379\u003c/code\u003e\u003c/a\u003e request context tracks session access\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pallets/flask/commit/27be9338405382445a7cb01151e084559b98d602\"\u003e\u003ccode\u003e27be933\u003c/code\u003e\u003c/a\u003e start version 3.1.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pallets/flask/commit/4e652d3f68b90d50aa2301d3b7e68c3fafd9251d\"\u003e\u003ccode\u003e4e652d3\u003c/code\u003e\u003c/a\u003e Abort if the instance folder cannot be created (\u003ca href=\"https://redirect.github.com/pallets/flask/issues/5903\"\u003e#5903\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pallets/flask/commit/3d03098a97ddc6a908aa4a50c2ef7381f8297d0a\"\u003e\u003ccode\u003e3d03098\u003c/code\u003e\u003c/a\u003e Abort if the instance folder cannot be created\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pallets/flask/commit/407eb76b27884848383a37c7274654f0271e4bc4\"\u003e\u003ccode\u003e407eb76\u003c/code\u003e\u003c/a\u003e document using gevent for async (\u003ca href=\"https://redirect.github.com/pallets/flask/issues/5900\"\u003e#5900\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pallets/flask/commit/ac5664d2281533eacafd64f5cc7d5edcdaccab60\"\u003e\u003ccode\u003eac5664d\u003c/code\u003e\u003c/a\u003e document using gevent for async\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pallets/flask/commit/4f79d5b59a56bc4356a97f2e81a35f98cb18d7b3\"\u003e\u003ccode\u003e4f79d5b\u003c/code\u003e\u003c/a\u003e Increase required flit_core version to 3.11 (\u003ca href=\"https://redirect.github.com/pallets/flask/issues/5865\"\u003e#5865\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pallets/flask/commit/fe3b215d3ade4db68262dae1a3cdc464a1fc524f\"\u003e\u003ccode\u003efe3b215\u003c/code\u003e\u003c/a\u003e Increase required flit_core version to 3.11\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/pallets/flask/compare/3.0.3...3.1.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `httplib2` from 0.22.0 to 0.32.0\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/httplib2/httplib2/blob/master/CHANGELOG\"\u003ehttplib2's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e0.32.0\u003c/p\u003e\n\u003cp\u003ePython support 3.8+ only\u003c/p\u003e\n\u003cp\u003edecompression limited by size and ratio\u003c/p\u003e\n\u003cp\u003edecoder foundation to support more compression algorithms\u003c/p\u003e\n\u003cp\u003e0.31.2\u003c/p\u003e\n\u003cp\u003ebuild(deps): pp.DelimitedList (camel case) only available in pyparsing\u0026gt;=3.1\n\u003ca href=\"https://redirect.github.com/httplib2/httplib2/issues/255\"\u003ehttplib2/httplib2#255\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eDO NOT use 0.31.1\u003c/p\u003e\n\u003cp\u003e0.31.1\u003c/p\u003e\n\u003cp\u003eauth: use pyparsing v3 PEP8-compliant method names\n\u003ca href=\"https://redirect.github.com/httplib2/httplib2/pull/253\"\u003ehttplib2/httplib2#253\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e0.31.0\u003c/p\u003e\n\u003cp\u003ehttps: avoid costly load_verify_locations when SSL certificate validation is disabled\n\u003ca href=\"https://redirect.github.com/httplib2/httplib2/pull/249\"\u003ehttplib2/httplib2#249\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e0.30.2\u003c/p\u003e\n\u003cp\u003eNo changes in library. Fix automatic pypi release from CI.\u003c/p\u003e\n\u003cp\u003e0.30.1\u003c/p\u003e\n\u003cp\u003erestore socks proxy support, was broken in 0.30.0\n\u003ca href=\"https://redirect.github.com/httplib2/httplib2/issues/251\"\u003ehttplib2/httplib2#251\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e0.30.0\u003c/p\u003e\n\u003cp\u003eBREAKING CHANGE! Python support 3.7+ only\u003c/p\u003e\n\u003cp\u003ehttps: Do not rely on ssl.PROTOCOL_TLS, which has been deprecated in Python3.10\n\u003ca href=\"https://redirect.github.com/httplib2/httplib2/pull/243\"\u003ehttplib2/httplib2#243\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/httplib2/httplib2/commit/ba9bf505cd899f522f2bb58ca608444adf49afc1\"\u003e\u003ccode\u003eba9bf50\u003c/code\u003e\u003c/a\u003e v0.32.0 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/httplib2/httplib2/commit/87581ad6cf752fe3da2090c59058261d2d00a427\"\u003e\u003ccode\u003e87581ad\u003c/code\u003e\u003c/a\u003e decompression limited by size and ratio; require python 3.8+\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/httplib2/httplib2/commit/a99a11fba8d5fa3bb9c47827e5cbfd641dfb88d3\"\u003e\u003ccode\u003ea99a11f\u003c/code\u003e\u003c/a\u003e v0.31.2 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/httplib2/httplib2/commit/370010a12ef4b97ebeeac59f52d071de7bc3faa8\"\u003e\u003ccode\u003e370010a\u003c/code\u003e\u003c/a\u003e dep-compat: pp.DelimitedList (camel case) only available in pyparsing\u0026gt;=3.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/httplib2/httplib2/commit/6d2ea322d53a03d058cd8e63c12871cdd1127ca9\"\u003e\u003ccode\u003e6d2ea32\u003c/code\u003e\u003c/a\u003e v0.31.1 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/httplib2/httplib2/commit/d1b0ce329667f0b0047381c089e53ea1055f2fca\"\u003e\u003ccode\u003ed1b0ce3\u003c/code\u003e\u003c/a\u003e auth: use pyparsing v3 PEP8-compliant method names\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/httplib2/httplib2/commit/3288ba77ccb1924a6a79350f300ebb84140ec064\"\u003e\u003ccode\u003e3288ba7\u003c/code\u003e\u003c/a\u003e chore: harden publishing. use github attestations\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/httplib2/httplib2/commit/26cfea5d07a5817cf214d9978c856c91abf4e078\"\u003e\u003ccode\u003e26cfea5\u003c/code\u003e\u003c/a\u003e v0.31.0 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/httplib2/httplib2/commit/cbd3d21004374997167d9b8ab36b4ec211881a57\"\u003e\u003ccode\u003ecbd3d21\u003c/code\u003e\u003c/a\u003e chore: CI use trusted publishing\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/httplib2/httplib2/commit/147d7d5d00b4cd383dbdda839089237aa0c2a836\"\u003e\u003ccode\u003e147d7d5\u003c/code\u003e\u003c/a\u003e https: avoid costly load_verify_locations when SSL certificate validation is ...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/httplib2/httplib2/compare/v0.22.0...v0.32.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `idna` from 3.7 to 3.15\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/kjd/idna/releases\"\u003eidna's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev3.15\u003c/h2\u003e\n\u003cp\u003eNo release notes provided.\u003c/p\u003e\n\u003ch2\u003ev3.14\u003c/h2\u003e\n\u003cp\u003eNo release notes provided.\u003c/p\u003e\n\u003ch2\u003ev3.13\u003c/h2\u003e\n\u003cp\u003eNo release notes provided.\u003c/p\u003e\n\u003ch2\u003ev3.12\u003c/h2\u003e\n\u003cp\u003eNo release notes provided.\u003c/p\u003e\n\u003ch2\u003ev3.11\u003c/h2\u003e\n\u003cp\u003eNo release notes provided.\u003c/p\u003e\n\u003ch2\u003ev3.10\u003c/h2\u003e\n\u003cp\u003eNo release notes provided.\u003c/p\u003e\n\u003ch2\u003ev3.9\u003c/h2\u003e\n\u003cp\u003eNo release notes provided.\u003c/p\u003e\n\u003ch2\u003ev3.8\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix regression where IDNAError exception was not being produced for certain inputs.\u003c/li\u003e\n\u003cli\u003eAdd support for Python 3.13, drop support for Python 3.5 as it is no longer testable.\u003c/li\u003e\n\u003cli\u003eDocumentation improvements\u003c/li\u003e\n\u003cli\u003eUpdates to package testing using Github actions\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThanks to Hugo van Kemenade for contributions to this release.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/kjd/idna/compare/v3.7...v3.8\"\u003ehttps://github.com/kjd/idna/compare/v3.7...v3.8\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/kjd/idna/blob/master/HISTORY.md\"\u003eidna's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e3.15 (2026-05-12)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eEnforce DNS-length cap on individual labels early in \u003ccode\u003echeck_label\u003c/code\u003e,\nshort-circuiting contextual-rule processing for oversized input\nwhile staying compatible with UTS 46 usage.\u003c/li\u003e\n\u003cli\u003eTidy core helpers: hoist bidi category sets to module-level\nfrozensets (avoiding per-codepoint list construction), simplify\nlength checks, and reuse the shared \u003ccode\u003e_unicode_dots_re\u003c/code\u003e from\n\u003ccode\u003eidna.core\u003c/code\u003e in the codec module.\u003c/li\u003e\n\u003cli\u003eUse \u003ccode\u003eraise ... from err\u003c/code\u003e for proper exception chaining and\nswitch internal string formatting to f-strings.\u003c/li\u003e\n\u003cli\u003eAllow \u003ccode\u003eflit_core\u003c/code\u003e 4.x in the build backend.\u003c/li\u003e\n\u003cli\u003eExpand the ruff lint set (flake8-bugbear, flake8-simplify,\npyupgrade, perflint) and apply the surfaced fixes; pin lint CI\nto Python 3.14.\u003c/li\u003e\n\u003cli\u003eAdd Dependabot configuration for GitHub Actions.\u003c/li\u003e\n\u003cli\u003eConvert README and HISTORY from reStructuredText to Markdown.\u003c/li\u003e\n\u003cli\u003eReference CVE-2026-45409 for the 3.14 advisory in place of the\ninitial GHSA identifier.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThanks to Felix Yan, Stan Ulbrych, and metsw24-max for\ncontributions to this release.\u003c/p\u003e\n\u003ch2\u003e3.14 (2026-05-10)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRemoved opportunity to process long inputs into quadratic\ntime by rejecting oversize inputs up-front. Closes a bypass\nof the CVE-2024-3651 mitigation. [CVE-2026-45409]\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThanks to Stan Ulbrych for reporting the issue.\u003c/p\u003e\n\u003ch2\u003e3.13 (2026-04-22)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eCorrect classification error for codepoint U+A7F1\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.12 (2026-04-21)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate to Unicode 17.0.0.\u003c/li\u003e\n\u003cli\u003eIssue a deprecation warning for the transitional argument.\u003c/li\u003e\n\u003cli\u003eAdded lazy-loading to provide some performance improvements.\u003c/li\u003e\n\u003cli\u003eRemoved vestiges of code related to Python 2 support, including\nsegmentation of data structures specific to Jython.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThanks to Rodrigo Nogueira for contributions to this release.\u003c/p\u003e\n\u003ch2\u003e3.11 (2025-10-12)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate to Unicode 16.0.0, including significant changes to UTS46\nprocessing. As a result of Unicode ending support for it, transitional\nprocessing no longer has an effect and returns the same result.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kjd/idna/commit/af30a092e158181d0b35ac66dfa813788126bdd8\"\u003e\u003ccode\u003eaf30a09\u003c/code\u003e\u003c/a\u003e Release 3.15\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kjd/idna/commit/30314d4628744ca14cf2b5820564e5127a9f86f2\"\u003e\u003ccode\u003e30314d4\u003c/code\u003e\u003c/a\u003e Pre-release 3.15rc0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kjd/idna/commit/05d4b219aa9eddc47371fcbd2000f0301016f3e9\"\u003e\u003ccode\u003e05d4b21\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/kjd/idna/issues/237\"\u003e#237\u003c/a\u003e from kjd/convert-docs-to-markdown\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kjd/idna/commit/2987fdba1962bbb2358399e0084ba062b98a0bee\"\u003e\u003ccode\u003e2987fdb\u003c/code\u003e\u003c/a\u003e Convert README and HISTORY from reStructuredText to Markdown\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kjd/idna/commit/59fa8002d514bf4a5ce7b58f67b9ec587d53fa9c\"\u003e\u003ccode\u003e59fa800\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/kjd/idna/issues/236\"\u003e#236\u003c/a\u003e from kjd/dependabot/github_actions/actions-f3e34333ea\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kjd/idna/commit/def69834ced5d4b3c50439d8b99c4c856ec19ca2\"\u003e\u003ccode\u003edef6983\u003c/code\u003e\u003c/a\u003e Merge branch 'master' into dependabot/github_actions/actions-f3e34333ea\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kjd/idna/commit/bbd8004a797185d8c56bb555cd5c88fde05e0631\"\u003e\u003ccode\u003ebbd8004\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/kjd/idna/issues/234\"\u003e#234\u003c/a\u003e from StanFromIreland/patch-1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kjd/idna/commit/edd07c05024344a6ccb517414ccb36683aee99fc\"\u003e\u003ccode\u003eedd07c0\u003c/code\u003e\u003c/a\u003e Bump github/codeql-action from 3.35.2 to 4.35.2 in the actions group\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kjd/idna/commit/5557db030c11bdec50d62aa5f631d705d33ba123\"\u003e\u003ccode\u003e5557db0\u003c/code\u003e\u003c/a\u003e Merge branch 'master' into patch-1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kjd/idna/commit/f11746cf4981d25123ef7830d3ee60f07de8ae3d\"\u003e\u003ccode\u003ef11746c\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/kjd/idna/issues/235\"\u003e#235\u003c/a\u003e from StanFromIreland/patch-2\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/kjd/idna/compare/v3.7...v3.15\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `marshmallow` from 3.21.1 to 3.26.2\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/marshmallow-code/marshmallow/blob/dev/CHANGELOG.rst\"\u003emarshmallow's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e3.26.2 (2025-12-19)\u003c/h2\u003e\n\u003cp\u003eBug fixes:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e:cve:\u003ccode\u003e2025-68480\u003c/code\u003e: Merge error store messages without rebuilding collections.\nThanks 카푸치노 for reporting and :user:\u003ccode\u003edeckar01\u003c/code\u003e for the fix.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.26.1 (2025-02-03)\u003c/h2\u003e\n\u003cp\u003eBug fixes:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eTyping: Fix type annotations for \u003ccode\u003eclass Meta \u0026lt;marshmallow.Schema.Meta\u0026gt;\u003c/code\u003e options (:issue:\u003ccode\u003e2804\u003c/code\u003e).\nThanks :user:\u003ccode\u003elawrence-law\u003c/code\u003e for reporting.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eOther changes:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eRemove default value for the \u003ccode\u003edata\u003c/code\u003e param of \u003ccode\u003eNested._deserialize \u0026lt;marshmallow.fields.Nested._deserialize\u0026gt;\u003c/code\u003e (:issue:\u003ccode\u003e2802\u003c/code\u003e).\nThanks :user:\u003ccode\u003egbenson\u003c/code\u003e for reporting.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.26.0 (2025-01-22)\u003c/h2\u003e\n\u003cp\u003eFeatures:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eTyping: Add type annotations and improved documentation for \u003ccode\u003eclass Meta \u0026lt;marshmallow.Schema.Meta\u0026gt;\u003c/code\u003e options (:pr:\u003ccode\u003e2760\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eTyping: Improve type coverage of \u003ccode\u003emarshmallow.Schema.SchemaMeta\u003c/code\u003e (:pr:\u003ccode\u003e2761\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eTyping: \u003ccode\u003emarshmallow.Schema.loads\u003c/code\u003e parameter allows \u003ccode\u003ebytes\u003c/code\u003e and \u003ccode\u003ebytesarray\u003c/code\u003e (:pr:\u003ccode\u003e2769\u003c/code\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eBug fixes:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eRespect \u003ccode\u003edata_key\u003c/code\u003e when schema validators raise a \u003ccode\u003eValidationError \u0026lt;marshmallow.exceptions.ValidationError\u0026gt;\u003c/code\u003e\nwith a \u003ccode\u003efield_name\u003c/code\u003e argument (:issue:\u003ccode\u003e2170\u003c/code\u003e). Thanks :user:\u003ccode\u003ematejsp\u003c/code\u003e for reporting.\u003c/li\u003e\n\u003cli\u003eCorrectly handle multiple \u003ccode\u003e@post_load \u0026lt;marshmallow.post_load\u0026gt;\u003c/code\u003e methods where one method appends to\nthe data and another passes \u003ccode\u003epass_original=True\u003c/code\u003e (:issue:\u003ccode\u003e1755\u003c/code\u003e).\nThanks :user:\u003ccode\u003eghostwheel42\u003c/code\u003e for reporting.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eURL\u003c/code\u003e fields now properly validate \u003ccode\u003efile\u003c/code\u003e paths (:issue:\u003ccode\u003e2249\u003c/code\u003e).\nThanks :user:\u003ccode\u003e0xDEC0DE\u003c/code\u003e for reporting and fixing.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eDocumentation:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAdd :doc:\u003ccode\u003eupgrading guides \u0026lt;upgrading\u0026gt;\u003c/code\u003e for 3.24 and 3.26 (:pr:\u003ccode\u003e2780\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eVarious documentation improvements (:pr:\u003ccode\u003e2757\u003c/code\u003e, :pr:\u003ccode\u003e2759\u003c/code\u003e, :pr:\u003ccode\u003e2765\u003c/code\u003e, :pr:\u003ccode\u003e2774\u003c/code\u003e, :pr:\u003ccode\u003e2778\u003c/code\u003e, :pr:\u003ccode\u003e2783\u003c/code\u003e, :pr:\u003ccode\u003e2796\u003c/code\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eDeprecations:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eThe \u003ccode\u003eordered\u003c/code\u003e \u003ccode\u003eclass Meta \u0026lt;marshmallow.Schema.Meta\u0026gt;\u003c/code\u003e option is deprecated (:issue:\u003ccode\u003e2146\u003c/code\u003e, :pr:\u003ccode\u003e2762\u003c/code\u003e).\nField order is already preserved by default. Set \u003ccode\u003emarshmallow.Schema.dict_class\u003c/code\u003e to \u003ccode\u003ecollections.OrderedDict\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/marshmallow-code/marshmallow/commit/1407d5102ae020421ddc8425474e976325a9539e\"\u003e\u003ccode\u003e1407d51\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/marshmallow-code/marshmallow/issues/2878\"\u003e#2878\u003c/a\u003e from marshmallow-code/3.x-mypy-unreachable\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/marshmallow-code/marshmallow/commit/b2292f513845ccbd134bd55501a9bcbcdd18f8ac\"\u003e\u003ccode\u003eb2292f5\u003c/code\u003e\u003c/a\u003e Fix mypy errors\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/marshmallow-code/marshmallow/commit/8acd211847244fa28e0174728ff310fddf0d7fa2\"\u003e\u003ccode\u003e8acd211\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/marshmallow-code/marshmallow/issues/2877\"\u003e#2877\u003c/a\u003e from marshmallow-code/3.x-delint\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/marshmallow-code/marshmallow/commit/b4bcb4a96f16a3b94c1b52ac82a66b57bbee1d88\"\u003e\u003ccode\u003eb4bcb4a\u003c/code\u003e\u003c/a\u003e [pre-commit.ci] auto fixes from pre-commit.com hooks\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/marshmallow-code/marshmallow/commit/b78af7a0ea3102f8c2379bebe115a015e4018a62\"\u003e\u003ccode\u003eb78af7a\u003c/code\u003e\u003c/a\u003e Delint\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/marshmallow-code/marshmallow/commit/2c4451e5129411da79161add51cfc76fe852549d\"\u003e\u003ccode\u003e2c4451e\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/marshmallow-code/marshmallow/commit/86d101a1aee2fe0a521c976015d1940437493cde\"\u003e\u003ccode\u003e86d101a\u003c/code\u003e\u003c/a\u003e Bump version and update changelog\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/marshmallow-code/marshmallow/commit/489a8d421dc7955bb53b89e962d69465fbc5b6af\"\u003e\u003ccode\u003e489a8d4\u003c/code\u003e\u003c/a\u003e Only deep copy error message collections\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/marshmallow-code/marshmallow/commit/6d4a17dad54ea9711040c6aa6ba4d59267242a41\"\u003e\u003ccode\u003e6d4a17d\u003c/code\u003e\u003c/a\u003e Add test coverage for error message modification\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/marshmallow-code/marshmallow/commit/0356a3f1c307830f8ded56d823abca5611c594c9\"\u003e\u003ccode\u003e0356a3f\u003c/code\u003e\u003c/a\u003e Merge error store messages without rebuilding collections\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/marshmallow-code/marshmallow/compare/3.21.1...3.26.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `orjson` from 3.10.1 to 3.11.6\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/ijl/orjson/releases\"\u003eorjson's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e3.11.6\u003c/h2\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eorjson now includes code licensed under the Mozilla Public License 2.0 (MPL-2.0).\u003c/li\u003e\n\u003cli\u003eDrop support for Python 3.9.\u003c/li\u003e\n\u003cli\u003eABI compatibility with CPython 3.15 alpha 5.\u003c/li\u003e\n\u003cli\u003eBuild now depends on Rust 1.89 or later instead of 1.85.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFix sporadic crash serializing deeply nested \u003ccode\u003elist\u003c/code\u003e of \u003ccode\u003edict\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.11.5\u003c/h2\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eShow simple error message instead of traceback when attempting to\nbuild on unsupported Python versions.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.11.4\u003c/h2\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eABI compatibility with CPython 3.15 alpha 1.\u003c/li\u003e\n\u003cli\u003ePublish PyPI wheels for 3.14 and manylinux i686, manylinux arm7,\nmanylinux ppc64le, manylinux s390x.\u003c/li\u003e\n\u003cli\u003eBuild now requires a C compiler.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.11.3\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFix PyPI project metadata when using maturin 1.9.2 or later.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.11.2\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFix build using Rust 1.89 on amd64.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eBuild now depends on Rust 1.85 or later instead of 1.82.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.11.1\u003c/h2\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ePublish PyPI wheels for CPython 3.14.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFix \u003ccode\u003estr\u003c/code\u003e on big-endian architectures.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.11.0\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/ijl/orjson/blob/master/CHANGELOG.md\"\u003eorjson's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e3.11.6 - 2026-01-29\u003c/h2\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eorjson now includes code licensed under the Mozilla Public License 2.0 (MPL-2.0).\u003c/li\u003e\n\u003cli\u003eDrop support for Python 3.9.\u003c/li\u003e\n\u003cli\u003eABI compatibility with CPython 3.15 alpha 5.\u003c/li\u003e\n\u003cli\u003eBuild now depends on Rust 1.89 or later instead of 1.85.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFix sporadic crash serializing deeply nested \u003ccode\u003elist\u003c/code\u003e of \u003ccode\u003edict\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.11.5 - 2025-12-06\u003c/h2\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eShow simple error message instead of traceback when attempting to\nbuild on unsupported Python versions.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.11.4 - 2025-10-24\u003c/h2\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eABI compatibility with CPython 3.15 alpha 1.\u003c/li\u003e\n\u003cli\u003ePublish PyPI wheels for 3.14 and manylinux i686, manylinux arm7,\nmanylinux ppc64le, manylinux s390x.\u003c/li\u003e\n\u003cli\u003eBuild now requires a C compiler.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.11.3 - 2025-08-26\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFix PyPI project metadata when using maturin 1.9.2 or later.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.11.2 - 2025-08-12\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFix build using Rust 1.89 on amd64.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eBuild now depends on Rust 1.85 or later instead of 1.82.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ijl/orjson/commit/ec02024c3837255064f248c0d2d331319b75e9ad\"\u003e\u003ccode\u003eec02024\u003c/code\u003e\u003c/a\u003e 3.11.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ijl/orjson/commit/d58168733189f82b3fd0c058dff73e05d09202e6\"\u003e\u003ccode\u003ed581687\u003c/code\u003e\u003c/a\u003e build, clippy misc\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ijl/orjson/commit/4105b29b2275f200f6fae01349bef02ccf1bc2e2\"\u003e\u003ccode\u003e4105b29\u003c/code\u003e\u003c/a\u003e writer::num\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ijl/orjson/commit/62bb185b70785ded49c79c26f8c9781f1e6fe370\"\u003e\u003ccode\u003e62bb185\u003c/code\u003e\u003c/a\u003e Fix sporadic crash on serializing object close\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ijl/orjson/commit/d860078a973f44401265c5c4ad12a7dbe4f839ad\"\u003e\u003ccode\u003ed860078\u003c/code\u003e\u003c/a\u003e PyRef idiom refactors\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ijl/orjson/commit/343ae2f148197918aba9f8562db42c364620e4b8\"\u003e\u003ccode\u003e343ae2f\u003c/code\u003e\u003c/a\u003e Deserializer, Utf8Buffer\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ijl/orjson/commit/7835f58d1c56947d1cf7a18acdfc07a2bca9b0f2\"\u003e\u003ccode\u003e7835f58\u003c/code\u003e\u003c/a\u003e PyBytesRef and other input refactor\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ijl/orjson/commit/71e0516424ce1e11613eb1780f18e8cde83989fd\"\u003e\u003ccode\u003e71e0516\u003c/code\u003e\u003c/a\u003e PyStrRef\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ijl/orjson/commit/1096df42dc585fde837ed0c930a346f5ef7dbb94\"\u003e\u003ccode\u003e1096df4\u003c/code\u003e\u003c/a\u003e MSRV 1.89\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ijl/orjson/commit/b718e75b8ba18a707c2b44b6de14d52547573771\"\u003e\u003ccode\u003eb718e75\u003c/code\u003e\u003c/a\u003e Drop support for python3.9\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/ijl/orjson/compare/3.10.1...3.11.6\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `pillow` from 10.3.0 to 12.3.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/python-pillow/Pillow/releases\"\u003epillow's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e12.3.0\u003c/h2\u003e\n\u003cp\u003e\u003ca href=\"https://pillow.readthedocs.io/en/stable/releasenotes/12.3.0.html\"\u003ehttps://pillow.readthedocs.io/en/stable/releasenotes/12.3.0.html\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eRemovals\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRemove non-image ImageCms modes \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9697\"\u003e#9697\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eDocumentation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd release notes for SBOM and performance improvements \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9747\"\u003e#9747\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdd security release notes \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9741\"\u003e#9741\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdd release notes for Python 3.15 beta wheels \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9696\"\u003e#9696\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eImageFont can also be used with ImageText \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9597\"\u003e#9597\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdditional guidelines for security reports \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9659\"\u003e#9659\u003c/a\u003e [\u003ca href=\"https://github.com/wiredfool\"\u003e\u003ccode\u003e@​wiredfool\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eFixed typo \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9636\"\u003e#9636\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdded CVEs to 12.2.0 release notes \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9591\"\u003e#9591\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eRevise development support information in README \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9583\"\u003e#9583\u003c/a\u003e [\u003ca href=\"https://github.com/aclark4life\"\u003e\u003ccode\u003e@​aclark4life\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdd INCIDENT_RESPONSE.md \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9555\"\u003e#9555\u003c/a\u003e [\u003ca href=\"https://github.com/aclark4life\"\u003e\u003ccode\u003e@​aclark4life\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdd STRIDE threat model to security docs \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9562\"\u003e#9562\u003c/a\u003e [\u003ca href=\"https://github.com/aclark4life\"\u003e\u003ccode\u003e@​aclark4life\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdd CVEs to 12.2.0 release notes \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9556\"\u003e#9556\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate README with revised security policy \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9553\"\u003e#9553\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate security policy \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9552\"\u003e#9552\u003c/a\u003e [\u003ca href=\"https://github.com/aclark4life\"\u003e\u003ccode\u003e@​aclark4life\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate macOS tested Python versions \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9534\"\u003e#9534\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eDependencies\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate dependency harfbuzz to v14.2.1 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9720\"\u003e#9720\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency mypy to v2 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9653\"\u003e#9653\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency cibuildwheel to v4 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9665\"\u003e#9665\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate github-actions \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9655\"\u003e#9655\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency libavif to v1.4.2 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9652\"\u003e#9652\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency lcms2 to v2.19.1 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9651\"\u003e#9651\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency check-jsonschema to v0.37.2 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9650\"\u003e#9650\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate google/oss-fuzz digest to d872252 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9614\"\u003e#9614\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency lcms2 to v2.19 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9609\"\u003e#9609\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency libpng to v1.6.58 - autoclosed \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9608\"\u003e#9608\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency harfbuzz to v14 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9610\"\u003e#9610\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency mypy to v1.20.2 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9599\"\u003e#9599\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate github-actions \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9611\"\u003e#9611\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency cibuildwheel to v3.4.1 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9607\"\u003e#9607\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eMove dependency versions to single JSON and enable Renovate \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9559\"\u003e#9559\u003c/a\u003e [\u003ca href=\"https://github.com/hugovk\"\u003e\u003ccode\u003e@​hugovk\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdated raqm to 0.10.5 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9557\"\u003e#9557\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency cibuildwheel to v3.4.0 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9532\"\u003e#9532\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eTesting\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRemove matrix.os from benchmark \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9735\"\u003e#9735\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eRemove references to libavif patch \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9734\"\u003e#9734\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdd benchmark tests \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9654\"\u003e#9654\u003c/a\u003e [\u003ca href=\"https://github.com/akx\"\u003e\u003ccode\u003e@​akx\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUse reshape() instead of setting NumPy array shape directly \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9728\"\u003e#9728\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/python-pillow/Pillow/blob/main/CHANGES.rst\"\u003epillow's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003eChangelog (Pillow)\u003c/h1\u003e\n\u003ch2\u003e11.1.0 and newer\u003c/h2\u003e\n\u003cp\u003eSee GitHub Releases:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/releases\"\u003ehttps://github.com/python-pillow/Pillow/releases\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e11.0.0 (2024-10-15)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eUpdate licence to MIT-CMU \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/8460\"\u003e#8460\u003c/a\u003e\n[hugovk]\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eConditionally define ImageCms type hint to avoid requiring core \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/8197\"\u003e#8197\u003c/a\u003e\n[radarhere]\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eSupport writing LONG8 offsets in AppendingTiffWriter \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/8417\"\u003e#8417\u003c/a\u003e\n[radarhere]\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUse ImageFile.MAXBLOCK when saving TIFF images \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/8461\"\u003e#8461\u003c/a\u003e\n[radarhere]\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eDo not close provided file handles with libtiff when saving \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/8458\"\u003e#8458\u003c/a\u003e\n[radarhere]\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eSupport ImageFilter.BuiltinFilter for I;16* images \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/8438\"\u003e#8438\u003c/a\u003e\n[radarhere]\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUse ImagingCore.ptr instead of ImagingCore.id \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/8341\"\u003e#8341\u003c/a\u003e\n[homm, radarhere, hugovk]\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUpdated EPS mode when opening images without transparency \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/8281\"\u003e#8281\u003c/a\u003e\n[Yay295, radarhere]\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUse transparency when combining P frames from APNGs \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/8443\"\u003e#8443\u003c/a\u003e\n[radarhere]\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eSupport all resampling filters when resizing I;16* images \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/8422\"\u003e#8422\u003c/a\u003e\n[radarhere]\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFree memory on early return \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/8413\"\u003e#8413\u003c/a\u003e\n[radarhere]\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eCast int before potentially exceeding INT_MAX \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/8402\"\u003e#8402\u003c/a\u003e\n[radarhere]\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/bb1d8e8ab8d29048624d96e3ee53cecf7c13d13d\"\u003e\u003ccode\u003ebb1d8e8\u003c/code\u003e\u003c/a\u003e 12.3.0 version bump\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/e63fc481dc2e07e21d5403deafb8f1ed98a513af\"\u003e\u003ccode\u003ee63fc48\u003c/code\u003e\u003c/a\u003e Add release notes for SBOM and performance improvements (\u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9747\"\u003e#9747\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/13b701bbab291eec4bc87ea17ba06c94e5fe3054\"\u003e\u003ccode\u003e13b701b\u003c/code\u003e\u003c/a\u003e Add release notes for \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9679\"\u003e#9679\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/5564ca72fcd59d040e270af5dcf17a0d7161c364\"\u003e\u003ccode\u003e5564ca7\u003c/code\u003e\u003c/a\u003e List methods\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/a0920fd384f800b5d0ba3dd29ecdeae4f1d4043b\"\u003e\u003ccode\u003ea0920fd\u003c/code\u003e\u003c/a\u003e Speed up ImageChops operations (\u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9738\"\u003e#9738\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/07e9a6cd5336dc6cf8cae9165cd70cdd2b3e42fc\"\u003e\u003ccode\u003e07e9a6c\u003c/code\u003e\u003c/a\u003e Speed up \u003ccode\u003eImage.filter()\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9736\"\u003e#9736\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/a94578cf9649ea13e426cf7fb2b71b39ffc0dd50\"\u003e\u003ccode\u003ea94578c\u003c/code\u003e\u003c/a\u003e Speed up \u003ccode\u003eImage.getchannel()\u003c/code\u003e, \u003ccode\u003eImage.merge()\u003c/code\u003e, \u003ccode\u003eImage.putalpha()\u003c/code\u003e and `Image...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/53e02c43c919d149b2a154a5180079f9df18fbbb\"\u003e\u003ccode\u003e53e02c4\u003c/code\u003e\u003c/a\u003e Speed up \u003ccode\u003eImage.fill()\u003c/code\u003e, \u003ccode\u003eImage.linear_gradient()\u003c/code\u003e and `Image.radial_gradient...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/af037475be8634ba739744243164ba9e2c8346a6\"\u003e\u003ccode\u003eaf03747\u003c/code\u003e\u003c/a\u003e Speed up \u003ccode\u003eImage.resample()\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9739\"\u003e#9739\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/5c9ca56c3e5fba52b647809fbb0986c87e73a571\"\u003e\u003ccode\u003e5c9ca56\u003c/code\u003e\u003c/a\u003e Speed up \u003ccode\u003ealpha_composite\u003c/code\u003e, \u003ccode\u003ematrix\u003c/code\u003e, \u003ccode\u003enegative\u003c/code\u003e, \u003ccode\u003equantize\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9740\"\u003e#9740\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/python-pillow/Pillow/compare/10.3.0...12.3.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `pyasn1` from 0.6.0 to 0.6.4\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pyasn1/pyasn1/releases\"\u003epyasn1's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eRelease 0.6.4\u003c/h2\u003e\n\u003cp\u003eThis is a security release.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eCVE-2026-59885 (GHSA-8ppf-4f7h-5ppj): Fixed quadratic time complexity in the OBJECT IDENTIFIER and RELATIVE-OID decoders. A small crafted substrate encoding many arcs could consume excessive CPU.\u003c/li\u003e\n\u003cli\u003eCVE-2026-59884 (GHSA-m4p7-r5rc-7g4j): Limited BER long-form tag IDs to 20 octets (140 bits). Unbounded tag IDs allowed a crafted substrate to consume excessive CPU and memory.\u003c/li\u003e\n\u003cli\u003eCVE-2026-59886 (GHSA-hm4w-wwcw-mr6r): Fixed excessive memory and CPU consumption in \u003ccode\u003eReal.__float__()\u003c/code\u003e for values with large base-10 exponents.\u003c/li\u003e\n\u003cli\u003ePinned PyPI publish GitHub Action to an immutable commit.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eAll changes are noted in the \u003ca href=\"https://github.com/pyasn1/pyasn1/blob/main/CHANGES.rst\"\u003eCHANGELOG\u003c/a\u003e.\u003c/p\u003e\n\u003ch2\u003eRelease 0.6.3\u003c/h2\u003e\n\u003cp\u003eIt's a minor release.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAdded nesting depth limit to ASN.1 decoder to prevent stack overflow from deeply nested structures (CVE-2026-30922).\u003c/li\u003e\n\u003cli\u003eFixed OverflowError from oversized BER length field.\u003c/li\u003e\n\u003cli\u003eFixed DeprecationWarning stacklevel for deprecated attributes.\u003c/li\u003e\n\u003cli\u003eFixed asDateTime incorrect fractional seconds parsing.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eAll changes are noted in the \u003ca href=\"https://github.com/pyasn1/pyasn1/blob/master/CHANGES.rst\"\u003eCHANGELOG\u003c/a\u003e.\u003c/p\u003e\n\u003ch2\u003eRelease 0.6.2\u003c/h2\u003e\n\u003cp\u003eIt's a minor release.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eFixed continuation octet limits in OID/RELATIVE-OID decoder (CVE-2026-23490).\u003c/li\u003e\n\u003cli\u003eAdded support for Python 3.14.\u003c/li\u003e\n\u003cli\u003eAdded SECURITY.md policy.\u003c/li\u003e\n\u003cli\u003eMigrated to pyproject.toml packaging.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eAll changes are noted in the \u003ca href=\"https://github.com/pyasn1/pyasn1/blob/master/CHANGES.rst\"\u003eCHANGELOG\u003c/a\u003e.\u003c/p\u003e\n\u003ch2\u003eRelease 0.6.1\u003c/h2\u003e\n\u003cp\u003eIt's a minor release.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAdded support for Python 3.13.\u003c/li\u003e\n\u003cli\u003eCleaned Python 2-related code.\u003c/li\u003e\n\u003cli\u003eRemoved bdist_wheel universal flag from setup.cfg.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eAll changes are noted in the \u003ca href=\"https://github.com/pyasn1/pyasn1/blob/master/CHANGES.rst\"\u003eCHANGELOG\u003c/a\u003e.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pyasn1/pyasn1/blob/main/CHANGES.rst\"\u003epyasn1's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eRevision 0.6.4, released 08-07-2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eCVE-2026-59885 (GHSA-8ppf-4f7h-5ppj): Fixed quadratic time\ncomplexity in the OBJECT IDENTIFIER and RELATIVE-OID decoders.\nA small crafted substrate encoding many arcs could consume\nexcessive CPU. Arcs are now accumulated in linear time; decoded\nvalues are unchanged (thanks for reporting, tynus2)\u003c/li\u003e\n\u003cli\u003eCVE-2026-59884 (GHSA-m4p7-r5rc-7g4j): Limited BER long-form tag\nIDs to 20 octets (140 bits), matching the OID arc limit introduced\nin 0.6.2. Unbounded tag IDs allowed a crafted substrate to consume\nexcessive CPU and memory; longer tag IDs are now rejected with\nPyAsn1Error. Also fixed Tag and TagSet repr() failing on huge tag\n(thanks for reporting, mikeappsec)\nIDs due to the integer-to-string conversion limit (Python 3.11+)\u003c/li\u003e\n\u003cli\u003eCVE-2026-59886 (GHSA-hm4w-wwcw-mr6r): Fixed excessive memory and\nCPU consumption in Real.\u003cstrong\u003efloat\u003c/strong\u003e() for values with large base-10\nexponents. Conversion no longer materializes huge intermediate\nintegers; values too large to represent as a Python float raise\nOverflowError promptly, and prettyPrint() renders them as\n'\u003c!-- raw HTML omitted --\u003e' as before. Also fixed base-10 mantissa normalization\nto use exact integer arithmetic; mantissas larger than 2**53\ncould previously lose precision through float division\n(thanks for reporting, gvozdila)\u003c/li\u003e\n\u003cli\u003ePinned PyPI publish GitHub Action to an immutable commit\n[pr \u003ca href=\"https://redirect.github.com/pyasn1/pyasn1/issues/113\"\u003e#113\u003c/a\u003e](\u003ca href=\"https://redirect.github.com/pyasn1/pyasn1/pull/113\"\u003epyasn1/pyasn1#113\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eRevision 0.6.3, released 16-03-2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eCVE-2026-30922 (GHSA-jr27-m4p2-rc6r): Added nesting depth\nlimit to ASN.1 decoder to prevent stack overflow from deeply\nnested structures (thanks for reporting, romanticpragmatism)\u003c/li\u003e\n\u003cli\u003eFixed OverflowError from oversized BER length field\n[issue \u003ca href=\"https://redirect.github.com/pyasn1/pyasn1/issues/54\"\u003e#54\u003c/a\u003e](\u003ca href=\"https://redirect.github.com/pyasn1/pyasn1/issues/54\"\u003epyasn1/pyasn1#54\u003c/a\u003e)\n[pr \u003ca href=\"https://redirect.github.com/pyasn1/pyasn1/issues/100\"\u003e#100\u003c/a\u003e](\u003ca href=\"https://redirect.github.com/pyasn1/pyasn1/pull/100\"\u003epyasn1/pyasn1#100\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed DeprecationWarning stacklevel for deprecated attributes\n[issue \u003ca href=\"https://redirect.github.com/pyasn1/pyasn1/issues/86\"\u003e#86\u003c/a\u003e](\u003ca href=\"https://redirect.github.com/pyasn1/pyasn1/issues/86\"\u003epyasn1/pyasn1#86\u003c/a\u003e)\n[pr \u003ca href=\"https://redirect.github.com/pyasn1/pyasn1/issues/101\"\u003e#101\u003c/a\u003e](\u003ca href=\"https://redirect.github.com/pyasn1/pyasn1/pull/101\"\u003epyasn1/pyasn1#101\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed asDateTime incorrect fractional seconds parsing\n[issue \u003ca href=\"https://redirect.github.com/pyasn1/pyasn1/issues/81\"\u003e#81\u003c/a\u003e](\u003ca href=\"https://redirect.github.com/pyasn1/pyasn1/issues/81\"\u003epyasn1/pyasn1#81\u003c/a\u003e)\n[pr \u003ca href=\"https://redirect.github.com/pyasn1/pyasn1/issues/102\"\u003e#102\u003c/a\u003e](\u003ca href=\"https://redirect.github.com/pyasn1/pyasn1/pull/102\"\u003epyasn1/pyasn1#102\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eRevision 0.6.2, released 16-01-2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eCVE-2026-23490 (GHSA-63vm-454h-vhhq): Fixed continuation octet limits\nin OID/RELATIVE-OID decoder (thanks to tsigouris007)\u003c/li\u003e\n\u003cli\u003eAdded support for Python 3.14\n[pr \u003ca href=\"https://redirect.github.com/pyasn1/pyasn1/issues/97\"\u003e#97\u003c/a\u003e](\u003ca href=\"https://redirect.github.com/pyasn1/pyasn1/pull/97\"\u003epyasn1/pyasn1#97\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyasn1/pyasn1/commit/72e4803405816c371ed3b2cb4be181c47f038406\"\u003e\u003ccode\u003e72e4803\u003c/code\u003e\u003c/a\u003e Prepare release 0.6.4\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyasn1/pyasn1/commit/0c19eeb853731db1c717ff125ea001a1e558332d\"\u003e\u003ccode\u003e0c19eeb\u003c/code\u003e\u003c/a\u003e Pin PyPI publish action to immutable commit (\u003ca href=\"https://redirect.github.com/pyasn1/pyasn1/issues/113\"\u003e#113\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyasn1/pyasn1/commit/45bdb19eb7df4b3780fe9c912c63e99bffc39dd9\"\u003e\u003ccode\u003e45bdb19\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyasn1/pyasn1/commit/628e36ecbb5277a3f01572ce418ef54271b165a5\"\u003e\u003ccode\u003e628e36e\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyasn1/pyasn1/commit/e60c691cb91addb8fcefa2f537e85ede6fb1e886\"\u003e\u003ccode\u003ee60c691\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyasn1/pyasn1/commit/af65c3b92e9deeae50db4de390982dd970d87f98\"\u003e\u003ccode\u003eaf65c3b\u003c/code\u003e\u003c/a\u003e Prepare release 0.6.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyasn1/pyasn1/commit/5a49bd1fe93b5b866a1210f6bf0a3924f21572c8\"\u003e\u003ccode\u003e5a49bd1\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyasn1/pyasn1/commit/5494ba43f738e700ca9f7c7a69ec5c44908c9a9f\"\u003e\u003ccode\u003e5494ba4\u003c/code\u003e\u003c/a\u003e Fix asDateTime incorrect fractional seconds parsing (\u003ca href=\"https://redirect.github.com/pyasn1/pyasn1/issues/102\"\u003e#102\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyasn1/pyasn1/commit/71f486e6c32d0f270868aa1b2bb5ceb7d5fd5476\"\u003e\u003ccode\u003e71f486e\u003c/code\u003e\u003c/a\u003e Fix DeprecationWarning stacklevel for deprecated attributes (\u003ca href=\"https://redirect.github.com/pyasn1/pyasn1/issues/101\"\u003e#101\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyasn1/pyasn1/commit/d7cb42dcaa9a66e18f14c4609c2ed00c5b65f7e8\"\u003e\u003ccode\u003ed7cb42d\u003c/code\u003e\u003c/a\u003e Fix OverflowError from oversized BER length field (\u003ca href=\"https://redirect.github.com/pyasn1/pyasn1/issues/100\"\u003e#100\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/pyasn1/pyasn1/compare/v0.6.0...v0.6.4\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `requests` from 2.31.0 to 2.33.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/psf/requests/releases\"\u003erequests's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.33.0\u003c/h2\u003e\n\u003ch2\u003e2.33.0 (2026-03-25)\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eAnnouncements\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e📣 Requests is adding inline types. If you have a typed code base that uses Requests, please take a look at \u003ca href=\"https://redirect.github.com/psf/requests/issues/7271\"\u003e#7271\u003c/a\u003e. Give it a try, and report any gaps or feedback you may have in the issue. 📣\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eSecurity\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eCVE-2026-25645 \u003ccode\u003erequests.utils.extract_zipped_paths\u003c/code\u003e now extracts contents to a non-deterministic location to prevent malicious file replacement. This does not affect default usage of Requests, only applications calling the utility function directly.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eImprovements\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eMigrated to a PEP 517 build system using setuptools. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7012\"\u003e#7012\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eBugfixes\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eFixed an issue where an empty netrc entry could cause malformed authentication to be applied to Requests on Python 3.11+. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7205\"\u003e#7205\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eDeprecations\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eDropped support for Python 3.9 following its end of support. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7196\"\u003e#7196\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eDocumentation\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eVarious typo fixes and doc improvements.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/M0d3v1\"\u003e\u003ccode\u003e@​M0d3v1\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/psf/requests/pull/6865\"\u003epsf/requests#6865\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/aminvakil\"\u003e\u003ccode\u003e@​aminvakil\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/psf/requests/pull/7220\"\u003epsf/requests#7220\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/E8Price\"\u003e\u003ccode\u003e@​E8Price\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/psf/requests/pull/6960\"\u003epsf/requests#6960\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mitre88\"\u003e\u003ccode\u003e@​mitre88\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/psf/requests/pull/7244\"\u003epsf/requests#7244\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/magsen\"\u003e\u003ccode\u003e@​magsen\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/psf/requests/pull/6553\"\u003epsf/requests#6553\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Rohan5commit\"\u003e\u003ccode\u003e@​Rohan5commit\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/psf/requests/pull/7227\"\u003epsf/requests#7227\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/psf/requests/blob/main/HISTORY.md#2330-2026-03-25\"\u003ehttps://github.com/psf/requests/blob/main/HISTORY.md#2330-2026-03-25\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.32.5\u003c/h2\u003e\n\u003ch2\u003e2.32.5 (2025-08-18)\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eBugfixes\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eThe SSLContext caching feature originally introduced in 2.32.0 has created\na new class of issues in Requests that have had negative impact across a number\nof use cases. The Requests team has decided to revert this feature as long term\nmaintenance of it is proving to be unsustainable in its current iteration.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eDeprecations\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAdded support for Python 3.14.\u003c/li\u003e\n\u003cli\u003eDropped support for Python 3.8 following its end of support.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev2.32.4\u003c/h2\u003e\n\u003ch2\u003e2.32.4 (2025-06-10)\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/psf/requests/blob/main/HISTORY.md\"\u003erequests's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e2.33.0 (2026-03-25)\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eAnnouncements\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e📣 Requests is adding inline types. If you have a typed code base that\nuses Requests, please take a look at \u003ca href=\"https://redirect.github.com/psf/requests/issues/7271\"\u003e#7271\u003c/a\u003e. Give it a try, and report\nany gaps or feedback you may have in the issue. 📣\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eSecurity\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eCVE-2026-25645 \u003ccode\u003erequests.utils.extract_zipped_paths\u003c/code\u003e now extracts\ncontents to a non-deterministic location to prevent malicious file\nreplacement. This does not affect default usage of Requests, only\napplications calling the utility function directly.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eImprovements\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eMigrated to a PEP 517 build system using setuptools. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7012\"\u003e#7012\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eBugfixes\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eFixed an issue where an empty netrc entry could cause\nmalformed authentication to be applied to Requests on\nPython 3.11+. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7205\"\u003e#7205\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eDeprecations\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eDropped support for Python 3.9 following its end of support. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7196\"\u003e#7196\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eDocumentation\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eVarious typo fixes and doc improvements.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.32.5 (2025-08-18)\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eBugfixes\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eThe SSLContext caching feature originally introduced in 2.32.0 has created\na new class of issues in Requests that have had negative impact across a number\nof use cases. The Requests team has decided to revert this feature as long term\nmaintenance of it is proving to be unsustainable in its current iteration.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eDeprecations\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAdded support for Python 3.14.\u003c/li\u003e\n\u003cli\u003eDropped support for Python 3.8 following its end of support.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.32.4 (2025-06-10)\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eSecurity\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eCVE-2024-47081 Fixed an issue where a maliciously crafted URL and trusted\nenvironment will retrieve credentials for the wrong hostname/machine from a\nnetrc file.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/bc04dfd6dad4cb02cd92f5daa81eb562d280a761\"\u003e\u003ccode\u003ebc04dfd\u003c/code\u003e\u003c/a\u003e v2.33.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/66d21cb07bd6255b1280291c4fafb71803cdb3b7\"\u003e\u003ccode\u003e66d21cb\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/8b9bc8fc0f63be84602387913c4b689f19efd028\"\u003e\u003ccode\u003e8b9bc8f\u003c/code\u003e\u003c/a\u003e Move badges to top of README (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7293\"\u003e#7293\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/e331a288f369973f5de0ec8901c94cae4fa87286\"\u003e\u003ccode\u003ee331a28\u003c/code\u003e\u003c/a\u003e Remove unused extraction call (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7292\"\u003e#7292\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/753fd08c5eacce0aa0df73fe47e49525c67e0a29\"\u003e\u003ccode\u003e753fd08\u003c/code\u003e\u003c/a\u003e docs: fix FAQ grammar in httplib2 example\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/774a0b837a194ee885d4fdd9ca947900cc3daf71\"\u003e\u003ccode\u003e774a0b8\u003c/code\u003e\u003c/a\u003e docs(socks): same block as other sections\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/9c72a41bec8597f948c9d8caa5dc3f12273b3303\"\u003e\u003ccode\u003e9c72a41\u003c/code\u003e\u003c/a\u003e Bump github/codeql-action from 4.33.0 to 4.34.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/ebf71906798ec82f34e07d3168f8b8aecaf8a3be\"\u003e\u003ccode\u003eebf7190\u003c/code\u003e\u003c/a\u003e Bump github/codeql-action from 4.32.0 to 4.33.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/0e4ae38f0c93d4f92a96c774bd52c069d12a4798\"\u003e\u003ccode\u003e0e4ae38\u003c/code\u003e\u003c/a\u003e docs: exclude Response.is_permanent_redirect from API docs (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7244\"\u003e#7244\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/d568f47278492e630cc990a259047c67991d007a\"\u003e\u003ccode\u003ed568f47\u003c/code\u003e\u003c/a\u003e docs: clarify Quickstart POST example (\u003ca href=\"https://redirect.github.com/psf/requests/issues/6960\"\u003e#6960\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/psf/requests/compare/v2.31.0...v2.33.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `urllib3` from 2.2.1 to 2.7.0\n\u003cdetails\u003e\n\u003csumm...\n\n_Description has been truncated_","html_url":"https://github.com/rajivranjanmars/microservices-demo/pull/1","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/rajivranjanmars%2Fmicroservices-demo/issues/1","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/1/packages"},{"uuid":"5470240775","node_id":"PR_kwDOQmqEms8AAAABDtdtPg","number":200,"state":"open","title":"Bump aiohttp from 3.12.15 to 3.14.3 in /content/response_integrations/google/wiz","user":"dependabot[bot]","labels":["dependencies","python:uv","migration"],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-16T04:31:16.000Z","updated_at":"2026-09-16T04:32:16.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","packages":[{"name":"aiohttp","old_version":"3.12.15","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"}],"path":"/content/response_integrations/google/wiz","ecosystem":"pip"},"body":"Bumps [aiohttp](https://github.com/aio-libs/aiohttp) from 3.12.15 to 3.14.3.\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=aiohttp\u0026package-manager=uv\u0026previous-version=3.12.15\u0026new-version=3.14.3)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/metron-labs/content-hub/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/metron-labs/content-hub/pull/200","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/metron-labs%2Fcontent-hub/issues/200","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/200/packages"},{"uuid":"5469471709","node_id":"PR_kwDOTZpjNs8AAAABDs21bA","number":26,"state":"closed","title":"chore(deps): bump the pip-minor-patch group across 1 directory with 76 updates","user":"dependabot[bot]","labels":["dependencies","python"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":"2026-09-23T02:15:39.000Z","author_association":null,"state_reason":null,"created_at":"2026-09-16T02:22:32.000Z","updated_at":"2026-09-23T02:15:41.000Z","time_to_close":604387,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps): bump","group_name":"pip-minor-patch","update_count":76,"packages":[{"name":"langchain","old_version":"1.3.13","new_version":"1.4.0","repository_url":"https://github.com/langchain-ai/langchain"},{"name":"langchain-core","old_version":"1.4.9","new_version":"1.6.3","repository_url":"https://github.com/langchain-ai/langchain"},{"name":"langchain-openai","old_version":"1.3.5","new_version":"1.6.2","repository_url":"https://github.com/langchain-ai/langchain"},{"name":"langgraph","old_version":"1.2.9","new_version":"1.2.11","repository_url":"https://github.com/langchain-ai/langgraph"},{"name":"langgraph-checkpoint","old_version":"4.1.1","new_version":"4.2.0","repository_url":"https://github.com/langchain-ai/langgraph"},{"name":"python-dotenv","old_version":"1.2.2","new_version":"1.2.3","repository_url":"https://github.com/theskumar/python-dotenv"},{"name":"pypdfium2","old_version":"5.11.0","new_version":"5.13.0","repository_url":"https://github.com/pypdfium2-team/pypdfium2"},{"name":"duckdb","old_version":"1.5.4","new_version":"1.5.5","repository_url":"https://github.com/duckdb/duckdb-python"},{"name":"scikit-learn","old_version":"1.9.0","new_version":"1.9.1","repository_url":"https://github.com/scikit-learn/scikit-learn"},{"name":"joblib","old_version":"1.5.3","new_version":"1.6.0","repository_url":"https://github.com/joblib/joblib"},{"name":"yfinance","old_version":"1.5.1","new_version":"1.7.0","repository_url":"https://github.com/ranaroussi/yfinance"},{"name":"akshare","old_version":"1.18.64","new_version":"1.18.94","repository_url":"https://github.com/akfamily/akshare"},{"name":"ccxt","old_version":"4.5.64","new_version":"4.5.78","repository_url":"https://github.com/ccxt/ccxt"},{"name":"fastapi","old_version":"0.139.0","new_version":"0.141.1","repository_url":"https://github.com/fastapi/fastapi"},{"name":"uvicorn","old_version":"0.51.0","new_version":"0.52.4","repository_url":"https://github.com/Kludex/uvicorn"},{"name":"pydantic","old_version":"2.13.4","new_version":"2.13.5","repository_url":"https://github.com/pydantic/pydantic"},{"name":"sse-starlette","old_version":"3.4.5","new_version":"3.4.11","repository_url":"https://github.com/sysid/sse-starlette"},{"name":"ddgs","old_version":"9.14.4","new_version":"9.16.0","repository_url":"https://github.com/deedy5/ddgs"},{"name":"matplotlib","old_version":"3.11.0","new_version":"3.11.2","repository_url":"https://github.com/matplotlib/matplotlib"},{"name":"prompt-toolkit","old_version":"3.0.52","new_version":"3.0.53","repository_url":"https://github.com/prompt-toolkit/python-prompt-toolkit"},{"name":"aiohttp","old_version":"3.14.1","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"pyjwt","old_version":"2.13.0","new_version":"2.14.0","repository_url":"https://github.com/jpadilla/pyjwt"},{"name":"aiofile","old_version":"3.11.1","new_version":"3.12.3","repository_url":"https://github.com/mosquito/aiofile"},{"name":"annotated-doc","old_version":"0.0.4","new_version":"0.0.5","repository_url":"https://github.com/fastapi/annotated-doc"},{"name":"annotated-types","old_version":"0.7.0","new_version":"0.8.0","repository_url":"https://github.com/annotated-types/annotated-types"},{"name":"anyio","old_version":"4.14.2","new_version":"4.15.1","repository_url":"https://github.com/agronholm/anyio"},{"name":"authlib","old_version":"1.7.2","new_version":"1.8.0","repository_url":"https://github.com/authlib/authlib"},{"name":"cachetools","old_version":"7.1.4","new_version":"7.1.8","repository_url":"https://github.com/tkem/cachetools"},{"name":"caio","old_version":"0.10.2","new_version":"0.12.4","repository_url":"https://github.com/mosquito/caio"},{"name":"certifi","old_version":"2026.6.17","new_version":"2026.7.22","repository_url":"https://github.com/certifi/python-certifi"},{"name":"cffi","old_version":"2.1.0","new_version":"2.1.1","repository_url":"https://github.com/python-cffi/cffi"},{"name":"charset-normalizer","old_version":"3.4.9","new_version":"3.5.1","repository_url":"https://github.com/jawah/charset_normalizer"},{"name":"click","old_version":"8.4.2","new_version":"8.5.0","repository_url":"https://github.com/pallets/click"},{"name":"cssselect2","old_version":"0.9.0","new_version":"0.10.1","repository_url":"https://github.com/Kozea/cssselect2"},{"name":"curl-cffi","old_version":"0.15.0","new_version":"0.16.3","repository_url":"https://github.com/lexiforest/curl_cffi"},{"name":"cyclopts","old_version":"4.21.0","new_version":"4.25.2","repository_url":"https://github.com/BrianPugh/cyclopts"},{"name":"fonttools","old_version":"4.63.0","new_version":"4.65.0","repository_url":"https://github.com/fonttools/fonttools"},{"name":"griffelib","old_version":"2.1.0","new_version":"2.3.0"},{"name":"h2","old_version":"4.3.0","new_version":"4.4.1","repository_url":"https://github.com/python-hyper/h2"},{"name":"idna","old_version":"3.18","new_version":"3.19","repository_url":"https://github.com/kjd/idna"},{"name":"jaraco-functools","old_version":"4.5.0","new_version":"4.6.0","repository_url":"https://github.com/jaraco/jaraco.functools"},{"name":"jiter","old_version":"0.16.0","new_version":"0.17.0","repository_url":"https://github.com/pydantic/jiter"},{"name":"joserfc","old_version":"1.7.3","new_version":"1.7.5","repository_url":"https://github.com/authlib/joserfc"},{"name":"kiwisolver","old_version":"1.5.0","new_version":"1.5.1","repository_url":"https://github.com/nucleic/kiwi"},{"name":"langchain-protocol","old_version":"0.0.18","new_version":"0.0.19","repository_url":"https://github.com/langchain-ai/agent-protocol"},{"name":"langgraph-sdk","old_version":"0.4.2","new_version":"0.4.4","repository_url":"https://github.com/langchain-ai/langgraph"},{"name":"langsmith","old_version":"0.10.2","new_version":"0.12.4","repository_url":"https://github.com/langchain-ai/langsmith-sdk"},{"name":"llvmlite","old_version":"0.48.0","new_version":"0.49.0","repository_url":"https://github.com/numba/llvmlite"},{"name":"lxml","old_version":"6.1.1","new_version":"6.1.3","repository_url":"https://github.com/lxml/lxml"},{"name":"multidict","old_version":"6.7.1","new_version":"6.8.0","repository_url":"https://github.com/aio-libs/multidict"},{"name":"narwhals","old_version":"2.23.0","new_version":"2.26.0","repository_url":"https://github.com/narwhals-dev/narwhals"},{"name":"numba","old_version":"0.66.0","new_version":"0.67.0","repository_url":"https://github.com/numba/numba"},{"name":"opentelemetry-api","old_version":"1.43.0","new_version":"1.44.0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"orjson","old_version":"3.11.9","new_version":"3.12.0","repository_url":"https://github.com/ijl/orjson"},{"name":"packaging","old_version":"26.2","new_version":"26.3","repository_url":"https://github.com/pypa/packaging"},{"name":"peewee","old_version":"4.2.1","new_version":"4.5.1","repository_url":"https://github.com/coleifer/peewee"},{"name":"platformdirs","old_version":"4.10.0","new_version":"4.11.8","repository_url":"https://github.com/tox-dev/platformdirs"},{"name":"protobuf","old_version":"7.35.1","new_version":"7.36.1","repository_url":"https://github.com/protocolbuffers/protobuf"},{"name":"pydantic-core","old_version":"2.47.0","new_version":"2.49.0","repository_url":"https://github.com/pydantic/pydantic"},{"name":"pydantic-settings","old_version":"2.14.2","new_version":"2.15.0","repository_url":"https://github.com/pydantic/pydantic-settings"},{"name":"pygments","old_version":"2.20.0","new_version":"2.21.0","repository_url":"https://github.com/pygments/pygments"},{"name":"pyphen","old_version":"0.17.2","new_version":"0.18.1","repository_url":"https://github.com/Kozea/Pyphen"},{"name":"pytz","old_version":"2026.2","new_version":"2026.3.post1","repository_url":"https://github.com/stub42/pytz"},{"name":"regex","old_version":"2026.7.10","new_version":"2026.9.10","repository_url":"https://github.com/mrabarnett/mrab-regex"},{"name":"simplejson","old_version":"4.1.1","new_version":"4.1.2","repository_url":"https://github.com/simplejson/simplejson"},{"name":"soupsieve","old_version":"2.8.4","new_version":"2.9.2","repository_url":"https://github.com/facelessuser/soupsieve"},{"name":"starlette","old_version":"1.3.1","new_version":"1.6.0","repository_url":"https://github.com/Kludex/starlette"},{"name":"tiktoken","old_version":"0.13.0","new_version":"0.14.0","repository_url":"https://github.com/openai/tiktoken"},{"name":"tqdm","old_version":"4.68.4","new_version":"4.70.1","repository_url":"https://github.com/tqdm/tqdm"},{"name":"typing-inspection","old_version":"0.4.2","new_version":"0.4.4","repository_url":"https://github.com/pydantic/typing-inspection"},{"name":"tzdata","old_version":"2026.3","new_version":"2026.4","repository_url":"https://github.com/python/tzdata"},{"name":"uncalled-for","old_version":"0.3.2","new_version":"0.4.0","repository_url":"https://github.com/chrisguidry/uncalled-for"},{"name":"wcwidth","old_version":"0.8.2","new_version":"0.8.3","repository_url":"https://github.com/jquast/wcwidth"},{"name":"webencodings","old_version":"0.5.1","new_version":"0.6.1","repository_url":"https://github.com/CourtBouillon/webencodings"},{"name":"websocket-client","old_version":"1.9.0","new_version":"1.9.2","repository_url":"https://github.com/websocket-client/websocket-client"},{"name":"yarl","old_version":"1.24.2","new_version":"1.24.5","repository_url":"https://github.com/aio-libs/yarl"}],"path":null,"ecosystem":"pip"},"body":"Bumps the pip-minor-patch group with 76 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [langchain](https://github.com/langchain-ai/langchain) | `1.3.13` | `1.4.0` |\n| [langchain-core](https://github.com/langchain-ai/langchain) | `1.4.9` | `1.6.3` |\n| [langchain-openai](https://github.com/langchain-ai/langchain) | `1.3.5` | `1.6.2` |\n| [langgraph](https://github.com/langchain-ai/langgraph) | `1.2.9` | `1.2.11` |\n| [langgraph-checkpoint](https://github.com/langchain-ai/langgraph) | `4.1.1` | `4.2.0` |\n| [python-dotenv](https://github.com/theskumar/python-dotenv) | `1.2.2` | `1.2.3` |\n| [pypdfium2](https://github.com/pypdfium2-team/pypdfium2) | `5.11.0` | `5.13.0` |\n| [duckdb](https://github.com/duckdb/duckdb-python) | `1.5.4` | `1.5.5` |\n| [scikit-learn](https://github.com/scikit-learn/scikit-learn) | `1.9.0` | `1.9.1` |\n| [joblib](https://github.com/joblib/joblib) | `1.5.3` | `1.6.0` |\n| [yfinance](https://github.com/ranaroussi/yfinance) | `1.5.1` | `1.7.0` |\n| [akshare](https://github.com/akfamily/akshare) | `1.18.64` | `1.18.94` |\n| [ccxt](https://github.com/ccxt/ccxt) | `4.5.64` | `4.5.78` |\n| [fastapi](https://github.com/fastapi/fastapi) | `0.139.0` | `0.141.1` |\n| [uvicorn](https://github.com/Kludex/uvicorn) | `0.51.0` | `0.52.4` |\n| [pydantic](https://github.com/pydantic/pydantic) | `2.13.4` | `2.13.5` |\n| [sse-starlette](https://github.com/sysid/sse-starlette) | `3.4.5` | `3.4.11` |\n| [ddgs](https://github.com/deedy5/ddgs) | `9.14.4` | `9.16.0` |\n| [matplotlib](https://github.com/matplotlib/matplotlib) | `3.11.0` | `3.11.2` |\n| [prompt-toolkit](https://github.com/prompt-toolkit/python-prompt-toolkit) | `3.0.52` | `3.0.53` |\n| [aiohttp](https://github.com/aio-libs/aiohttp) | `3.14.1` | `3.14.3` |\n| [pyjwt](https://github.com/jpadilla/pyjwt) | `2.13.0` | `2.14.0` |\n| [aiofile](https://github.com/mosquito/aiofile) | `3.11.1` | `3.12.3` |\n| [annotated-doc](https://github.com/fastapi/annotated-doc) | `0.0.4` | `0.0.5` |\n| [annotated-types](https://github.com/annotated-types/annotated-types) | `0.7.0` | `0.8.0` |\n| [anyio](https://github.com/agronholm/anyio) | `4.14.2` | `4.15.1` |\n| [authlib](https://github.com/authlib/authlib) | `1.7.2` | `1.8.0` |\n| [cachetools](https://github.com/tkem/cachetools) | `7.1.4` | `7.1.8` |\n| [caio](https://github.com/mosquito/caio) | `0.10.2` | `0.12.4` |\n| [certifi](https://github.com/certifi/python-certifi) | `2026.6.17` | `2026.7.22` |\n| [cffi](https://github.com/python-cffi/cffi) | `2.1.0` | `2.1.1` |\n| [charset-normalizer](https://github.com/jawah/charset_normalizer) | `3.4.9` | `3.5.1` |\n| [click](https://github.com/pallets/click) | `8.4.2` | `8.5.0` |\n| [cssselect2](https://github.com/Kozea/cssselect2) | `0.9.0` | `0.10.1` |\n| [curl-cffi](https://github.com/lexiforest/curl_cffi) | `0.15.0` | `0.16.3` |\n| [cyclopts](https://github.com/BrianPugh/cyclopts) | `4.21.0` | `4.25.2` |\n| [fonttools](https://github.com/fonttools/fonttools) | `4.63.0` | `4.65.0` |\n| griffelib | `2.1.0` | `2.3.0` |\n| [h2](https://github.com/python-hyper/h2) | `4.3.0` | `4.4.1` |\n| [idna](https://github.com/kjd/idna) | `3.18` | `3.19` |\n| [jaraco-functools](https://github.com/jaraco/jaraco.functools) | `4.5.0` | `4.6.0` |\n| [jiter](https://github.com/pydantic/jiter) | `0.16.0` | `0.17.0` |\n| [joserfc](https://github.com/authlib/joserfc) | `1.7.3` | `1.7.5` |\n| [kiwisolver](https://github.com/nucleic/kiwi) | `1.5.0` | `1.5.1` |\n| [langchain-protocol](https://github.com/langchain-ai/agent-protocol) | `0.0.18` | `0.0.19` |\n| [langgraph-sdk](https://github.com/langchain-ai/langgraph) | `0.4.2` | `0.4.4` |\n| [langsmith](https://github.com/langchain-ai/langsmith-sdk) | `0.10.2` | `0.12.4` |\n| [llvmlite](https://github.com/numba/llvmlite) | `0.48.0` | `0.49.0` |\n| [lxml](https://github.com/lxml/lxml) | `6.1.1` | `6.1.3` |\n| [multidict](https://github.com/aio-libs/multidict) | `6.7.1` | `6.8.0` |\n| [narwhals](https://github.com/narwhals-dev/narwhals) | `2.23.0` | `2.26.0` |\n| [numba](https://github.com/numba/numba) | `0.66.0` | `0.67.0` |\n| [opentelemetry-api](https://github.com/open-telemetry/opentelemetry-python) | `1.43.0` | `1.44.0` |\n| [orjson](https://github.com/ijl/orjson) | `3.11.9` | `3.12.0` |\n| [packaging](https://github.com/pypa/packaging) | `26.2` | `26.3` |\n| [peewee](https://github.com/coleifer/peewee) | `4.2.1` | `4.5.1` |\n| [platformdirs](https://github.com/tox-dev/platformdirs) | `4.10.0` | `4.11.8` |\n| [protobuf](https://github.com/protocolbuffers/protobuf) | `7.35.1` | `7.36.1` |\n| [pydantic-core](https://github.com/pydantic/pydantic) | `2.47.0` | `2.49.0` |\n| [pydantic-settings](https://github.com/pydantic/pydantic-settings) | `2.14.2` | `2.15.0` |\n| [pygments](https://github.com/pygments/pygments) | `2.20.0` | `2.21.0` |\n| [pyphen](https://github.com/Kozea/Pyphen) | `0.17.2` | `0.18.1` |\n| [pytz](https://github.com/stub42/pytz) | `2026.2` | `2026.3.post1` |\n| [regex](https://github.com/mrabarnett/mrab-regex) | `2026.7.10` | `2026.9.10` |\n| [simplejson](https://github.com/simplejson/simplejson) | `4.1.1` | `4.1.2` |\n| [soupsieve](https://github.com/facelessuser/soupsieve) | `2.8.4` | `2.9.2` |\n| [starlette](https://github.com/Kludex/starlette) | `1.3.1` | `1.6.0` |\n| [tiktoken](https://github.com/openai/tiktoken) | `0.13.0` | `0.14.0` |\n| [tqdm](https://github.com/tqdm/tqdm) | `4.68.4` | `4.70.1` |\n| [typing-inspection](https://github.com/pydantic/typing-inspection) | `0.4.2` | `0.4.4` |\n| [tzdata](https://github.com/python/tzdata) | `2026.3` | `2026.4` |\n| [uncalled-for](https://github.com/chrisguidry/uncalled-for) | `0.3.2` | `0.4.0` |\n| [wcwidth](https://github.com/jquast/wcwidth) | `0.8.2` | `0.8.3` |\n| [webencodings](https://github.com/CourtBouillon/webencodings) | `0.5.1` | `0.6.1` |\n| [websocket-client](https://github.com/websocket-client/websocket-client) | `1.9.0` | `1.9.2` |\n| [yarl](https://github.com/aio-libs/yarl) | `1.24.2` | `1.24.5` |\n\n\nUpdates `langchain` from 1.3.13 to 1.4.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/langchain-ai/langchain/releases\"\u003elangchain's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003elangchain-perplexity==1.4.0\u003c/h2\u003e\n\u003cp\u003eChanges since langchain-perplexity==1.3.2\u003c/p\u003e\n\u003cp\u003erelease(perplexity): 1.4.0 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/37993\"\u003e#37993\u003c/a\u003e)\nfeat(perplexity): \u003ccode\u003ebind_tools\u003c/code\u003e and Responses-API tool round-trip (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/37934\"\u003e#37934\u003c/a\u003e)\nhotfix(openai): min core dep (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/37990\"\u003e#37990\u003c/a\u003e)\u003c/p\u003e\n\u003ch2\u003elangchain-openai==1.4.0\u003c/h2\u003e\n\u003cp\u003eChanges since langchain-openai==1.3.5\u003c/p\u003e\n\u003cp\u003erelease(openai): 1.4.0 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38983\"\u003e#38983\u003c/a\u003e)\nchore: bump pillow from 12.2.0 to 12.3.0 in /libs/partners/openai (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38999\"\u003e#38999\u003c/a\u003e)\nfeat(core): add \u003ccode\u003ereasoning_effort\u003c/code\u003e as a standard chat model parameter (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38887\"\u003e#38887\u003c/a\u003e)\nchore(model-profiles): refresh model profile data (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38797\"\u003e#38797\u003c/a\u003e)\u003c/p\u003e\n\u003ch2\u003elangchain==1.4.0\u003c/h2\u003e\n\u003cp\u003eChanges since langchain==1.3.18\u003c/p\u003e\n\u003cp\u003edocs(langchain): runnable \u003ccode\u003elangchain.mcp\u003c/code\u003e examples (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/39976\"\u003e#39976\u003c/a\u003e)\nfeat(langchain): \u003ccode\u003elangchain.mcp\u003c/code\u003e namespace, \u003ccode\u003eMCPAdapter\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/39939\"\u003e#39939\u003c/a\u003e)\nperf(anthropic,langchain): omit middleware trace inputs (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/40098\"\u003e#40098\u003c/a\u003e)\nfix(langchain): include model destination in agent tool routing (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38355\"\u003e#38355\u003c/a\u003e)\nchore(langchain): bump vcrpy test dependency minimum to \u003ccode\u003e\u0026gt;=8.2.0\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/39942\"\u003e#39942\u003c/a\u003e)\u003c/p\u003e\n\u003ch2\u003elangchain==1.4.0a4\u003c/h2\u003e\n\u003cp\u003eInitial release\u003c/p\u003e\n\u003cp\u003erelease(langchain): 1.4.0a4\ntest(langchain): cover mixed-era ClientGroup and group elicitation\nUpdate libs/langchain_v1/langchain/mcp/adapter.py\nfix(langchain): drive MCP elicitation via member session for fastmcp 4.0.1\nfix(sdk): use latest fastmcp and rm reentrant impl\ncr\ncr\nrefactor(langchain): inline MCP client arming into \u003ccode\u003e__init__\u003c/code\u003e\nrefactor(langchain): stamp an arm marker instead of introspecting the handler closure\nfix(langchain): gate MCP interrupt routing on the negotiated protocol era\nrefactor(langchain): drop MCP \u003ccode\u003eelicitation\u003c/code\u003e flag, derive interrupt routing from the client\nfix(sdk): add _ReentrantClientGroup\nfix(langchain): narrow \u003ccode\u003eMCPAdapter.client\u003c/code\u003e union in mcp tests for mypy\nchore(langchain): format \u003ccode\u003emcp/adapter.py\u003c/code\u003e\nrelease(langchain): 1.4.0a3\nfeat(langchain): group MCP tool metadata under an \u003ccode\u003emcp\u003c/code\u003e namespace\nrefactor(langchain): stop exporting \u003ccode\u003eMCPAdapterTarget\u003c/code\u003e from \u003ccode\u003elangchain.mcp\u003c/code\u003e\nrefactor(langchain): rename \u003ccode\u003econvert_mcp_tool_to_langchain_tool\u003c/code\u003e to \u003ccode\u003eas_langchain_tool\u003c/code\u003e\nrefactor(langchain): rename \u003ccode\u003eMCPAdapter.get_tools\u003c/code\u003e to \u003ccode\u003elist_tools\u003c/code\u003e\nfeat(langchain): expose \u003ccode\u003ecache_mode\u003c/code\u003e on \u003ccode\u003eMCPAdapter.get_tools\u003c/code\u003e\nchore(langchain): require \u003ccode\u003efastmcp\u003c/code\u003e 4.0.0\nfeat(langchain): accept a \u003ccode\u003eClientGroup\u003c/code\u003e as an \u003ccode\u003eMCPAdapter\u003c/code\u003e target\nfeat(langchain): mark the \u003ccode\u003elangchain.mcp\u003c/code\u003e namespace as beta\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/79cab2dc7f58be720cac43db3677b4c1fd971f91\"\u003e\u003ccode\u003e79cab2d\u003c/code\u003e\u003c/a\u003e release(anthropic): 1.7.1 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/40181\"\u003e#40181\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/1e6a4f0b45b60475f566f3ad49fb32ea99d22233\"\u003e\u003ccode\u003e1e6a4f0\u003c/code\u003e\u003c/a\u003e chore(model-profiles): refresh model profile data (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/40171\"\u003e#40171\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/8330dfe987988c1bcbbc5e8d9af9a67e5a1c2744\"\u003e\u003ccode\u003e8330dfe\u003c/code\u003e\u003c/a\u003e docs(langchain): runnable \u003ccode\u003elangchain.mcp\u003c/code\u003e examples (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/39976\"\u003e#39976\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/280442b54c80db2175ced4a20ab59eab86a32dc1\"\u003e\u003ccode\u003e280442b\u003c/code\u003e\u003c/a\u003e feat(langchain): \u003ccode\u003elangchain.mcp\u003c/code\u003e namespace, \u003ccode\u003eMCPAdapter\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/39939\"\u003e#39939\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/f5ee2b65f4cf2f1a9fe688bcae6ad2af966582bd\"\u003e\u003ccode\u003ef5ee2b6\u003c/code\u003e\u003c/a\u003e chore(chroma): bump Pygments security constraint (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/40162\"\u003e#40162\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/234255c1c7427b5ed6dc505abad41ddfa6c9ff8f\"\u003e\u003ccode\u003e234255c\u003c/code\u003e\u003c/a\u003e chore(model-profiles): refresh model profile data (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/40009\"\u003e#40009\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/79e0e4adbafc1fda1ca9956e184be8b8819aa7ab\"\u003e\u003ccode\u003e79e0e4a\u003c/code\u003e\u003c/a\u003e chore(deps): bump mistune from 3.3.0 to 3.3.3 in /libs/langchain (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/40149\"\u003e#40149\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/e90201b7af5cd32762744c974ca9ce3f27efc9d8\"\u003e\u003ccode\u003ee90201b\u003c/code\u003e\u003c/a\u003e chore(deps): bump mistune from 3.3.0 to 3.3.3 in /libs/core (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/40150\"\u003e#40150\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/4240248e7b08ed72e85ce0744350c33beddb0ac8\"\u003e\u003ccode\u003e4240248\u003c/code\u003e\u003c/a\u003e chore(deps): bump mistune from 3.3.0 to 3.3.3 in /libs/text-splitters (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/40148\"\u003e#40148\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/530290a9d445069d80a68cdcd4d0da768f2aa2b0\"\u003e\u003ccode\u003e530290a\u003c/code\u003e\u003c/a\u003e chore(deps): bump uv to 0.12.8 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/40092\"\u003e#40092\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/langchain-ai/langchain/compare/langchain==1.3.13...langchain==1.4.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `langchain-core` from 1.4.9 to 1.6.3\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/langchain-ai/langchain/releases\"\u003elangchain-core's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003elangchain-core==1.6.3\u003c/h2\u003e\n\u003cp\u003eChanges since langchain-core==1.6.2\u003c/p\u003e\n\u003cp\u003erelease(core): 1.6.3 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/40407\"\u003e#40407\u003c/a\u003e)\nfeat(core): Allow model name and provider tracing metadata override based on gateway response (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/40406\"\u003e#40406\u003c/a\u003e)\ntest(core): cover the deprecated \u003ccode\u003e.text()\u003c/code\u003e access path (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/40243\"\u003e#40243\u003c/a\u003e)\ndocs(core): remove stale Args/Raises entries from FileCallbackHandler._write and ChatGeneration.set_text (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/40211\"\u003e#40211\u003c/a\u003e)\u003c/p\u003e\n\u003ch2\u003elangchain-core==1.6.2\u003c/h2\u003e\n\u003cp\u003eChanges since langchain-core==1.6.1\u003c/p\u003e\n\u003cp\u003erelease(core): 1.6.2 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/40209\"\u003e#40209\u003c/a\u003e)\nfeat(openai): support async tools (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/40208\"\u003e#40208\u003c/a\u003e)\nchore(deps): bump mistune from 3.3.0 to 3.3.3 in /libs/core (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/40150\"\u003e#40150\u003c/a\u003e)\nchore(deps): bump tornado from 6.5.7 to 6.5.8 in /libs/core (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/40113\"\u003e#40113\u003c/a\u003e)\nfix(core): avoid mutation in google-genai standard content (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/40023\"\u003e#40023\u003c/a\u003e)\nfix(core): avoid mutation in bedrock converse standard content (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/40022\"\u003e#40022\u003c/a\u003e)\u003c/p\u003e\n\u003ch2\u003elangchain-core==1.6.1\u003c/h2\u003e\n\u003cp\u003eChanges since langchain-core==1.6.0\u003c/p\u003e\n\u003cp\u003erevert: release(core): 1.6.2 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/39971\"\u003e#39971\u003c/a\u003e)\nrelease(core): 1.6.2 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/39967\"\u003e#39967\u003c/a\u003e)\nfix(core): shore up indexing in genai v1 streaming content (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/39964\"\u003e#39964\u003c/a\u003e)\nfix(core): make \u003ccode\u003eStructuredTool\u003c/code\u003e JSON-serializable (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/39631\"\u003e#39631\u003c/a\u003e)\nchore(deps): bump minor and patch dependencies (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/39869\"\u003e#39869\u003c/a\u003e)\nrelease(core): 1.6.1 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/39832\"\u003e#39832\u003c/a\u003e)\nfeat(core): propagate gateway information on error path (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/39829\"\u003e#39829\u003c/a\u003e)\u003c/p\u003e\n\u003ch2\u003elangchain-core==1.6.0\u003c/h2\u003e\n\u003cp\u003eChanges since langchain-core==1.5.6\u003c/p\u003e\n\u003cp\u003erelease(core): 1.6.0 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/39760\"\u003e#39760\u003c/a\u003e)\nfix(core): resolve postponed annotations in \u003ccode\u003eStructuredTool._injected_args_keys\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/39602\"\u003e#39602\u003c/a\u003e)\nfeat(core): add standard model exception types (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/39538\"\u003e#39538\u003c/a\u003e)\nfix(core): allow deserializing \u003ccode\u003eRunnablePick\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/39753\"\u003e#39753\u003c/a\u003e)\nfix(core): make \u003ccode\u003econvert_to_openai_function\u003c/code\u003e handle callables and non-dict mappings (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/39750\"\u003e#39750\u003c/a\u003e)\nfix(core): make subprocess and temporary file tests portable on Windows (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/39664\"\u003e#39664\u003c/a\u003e)\nfix(core): fail fast when tool schemas can't resolve forward refs during serialization (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/39570\"\u003e#39570\u003c/a\u003e)\ntest(core): avoid version-dependent runnable snapshots (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/39705\"\u003e#39705\u003c/a\u003e)\nfix(core): require all nested properties for strict tool schemas (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/39306\"\u003e#39306\u003c/a\u003e)\nfix(core): remove stale sync-stream \u003ccode\u003exfail\u003c/code\u003e [closes \u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/39720\"\u003e#39720\u003c/a\u003e] (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/39723\"\u003e#39723\u003c/a\u003e)\nperf(core): Lazily import transformers (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38037\"\u003e#38037\u003c/a\u003e)\nfix(core): accept non-dict Mapping values in mustache templates (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/39680\"\u003e#39680\u003c/a\u003e)\ndocs(core): clarify \u003ccode\u003eRunnable\u003c/code\u003e pipe coercion [closes \u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/39075\"\u003e#39075\u003c/a\u003e] (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/39707\"\u003e#39707\u003c/a\u003e)\nfix(core): finalize chain-group runs on \u003ccode\u003eBaseException\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/39699\"\u003e#39699\u003c/a\u003e)\u003c/p\u003e\n\u003ch2\u003elangchain-core==1.5.6\u003c/h2\u003e\n\u003cp\u003eChanges since langchain-core==1.5.5\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/348c9dc572599947d2d7d33d6a5b8b936e92a1d4\"\u003e\u003ccode\u003e348c9dc\u003c/code\u003e\u003c/a\u003e release(core): 1.6.3 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/40407\"\u003e#40407\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/e0e1557bd6ebae13915c59d942ef2824b51a10c6\"\u003e\u003ccode\u003ee0e1557\u003c/code\u003e\u003c/a\u003e feat(core): Allow model name and provider tracing metadata override based on ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/67ee6cb63dd9ae7f3a4dfedc3095652bce15a125\"\u003e\u003ccode\u003e67ee6cb\u003c/code\u003e\u003c/a\u003e chore(model-profiles): refresh model profile data (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/40399\"\u003e#40399\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/d5d7cc56ab3932c9a10dc76b31cd5d4a778c3f2a\"\u003e\u003ccode\u003ed5d7cc5\u003c/code\u003e\u003c/a\u003e release(anthropic): 1.7.2 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/40387\"\u003e#40387\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/4436bd2b67814877a3797613de28882adcdb6edf\"\u003e\u003ccode\u003e4436bd2\u003c/code\u003e\u003c/a\u003e fix(anthropic): preserve invalid tool use blocks (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/40372\"\u003e#40372\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/443154df9db5251d73730e1de3eb63bf352e586f\"\u003e\u003ccode\u003e443154d\u003c/code\u003e\u003c/a\u003e feat(huggingface): use torch.accelerator for device-agnostic device count det...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/3539ca08d92e10b65b6f3117cfd657b16b05c865\"\u003e\u003ccode\u003e3539ca0\u003c/code\u003e\u003c/a\u003e fix(huggingface): remove retired IPEX backend (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/39649\"\u003e#39649\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/45d94fb0fa10bf8cab95dcb1e76c2bc39165535d\"\u003e\u003ccode\u003e45d94fb\u003c/code\u003e\u003c/a\u003e chore(model-profiles): refresh model profile data (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/40358\"\u003e#40358\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/60357692c76651a7cd6153496a24658fa355bdcc\"\u003e\u003ccode\u003e6035769\u003c/code\u003e\u003c/a\u003e release(openai): 1.6.2 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/40339\"\u003e#40339\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/a7b0f0ae50acebb527a25e153ff16621d37ba650\"\u003e\u003ccode\u003ea7b0f0a\u003c/code\u003e\u003c/a\u003e docs: update OpenWiki (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/40318\"\u003e#40318\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/langchain-ai/langchain/compare/langchain-core==1.4.9...langchain-core==1.6.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `langchain-openai` from 1.3.5 to 1.6.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/langchain-ai/langchain/releases\"\u003elangchain-openai's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003elangchain-openai==1.6.2\u003c/h2\u003e\n\u003cp\u003eChanges since langchain-openai==1.6.1\u003c/p\u003e\n\u003cp\u003erelease(openai): 1.6.2 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/40339\"\u003e#40339\u003c/a\u003e)\nfix(openai): add GPT-6 Astra reasoning efforts (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/40330\"\u003e#40330\u003c/a\u003e)\nchore(deps): bump httpx2 from 2.10.0 to 2.12.0 in /libs/partners/openai (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/40309\"\u003e#40309\u003c/a\u003e)\u003c/p\u003e\n\u003ch2\u003elangchain-openai==1.6.1\u003c/h2\u003e\n\u003cp\u003eChanges since langchain-openai==1.6.0\u003c/p\u003e\n\u003cp\u003efix(openai): bump \u003ccode\u003emax_completion_tokens\u003c/code\u003e in cache breakpoint integration test (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/40284\"\u003e#40284\u003c/a\u003e)\nrelease(openai): 1.6.1 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/40268\"\u003e#40268\u003c/a\u003e)\nchore(model-profiles): refresh model profile data (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/40217\"\u003e#40217\u003c/a\u003e)\nfix(openai): support Azure AD auth with OpenAI 3.8 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/40190\"\u003e#40190\u003c/a\u003e)\nfeat(openai): support async tools (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/40208\"\u003e#40208\u003c/a\u003e)\nfeat(openai): support \u003ccode\u003econfiguration_update\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/40201\"\u003e#40201\u003c/a\u003e)\nchore(model-profiles): refresh model profile data (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/40171\"\u003e#40171\u003c/a\u003e)\nfix(openai): route \u003ccode\u003egpt-5.6-sol\u003c/code\u003e to responses API (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/40133\"\u003e#40133\u003c/a\u003e)\nchore(openai): fix tests (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/39972\"\u003e#39972\u003c/a\u003e)\nfix(openai): correct \u003ccode\u003ereasoning_effort_levels\u003c/code\u003e for gpt-5 and gpt-5.1 profiles (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/39936\"\u003e#39936\u003c/a\u003e)\nchore(model-profiles): refresh model profile data (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/39954\"\u003e#39954\u003c/a\u003e)\u003c/p\u003e\n\u003ch2\u003elangchain-openai==1.6.0\u003c/h2\u003e\n\u003cp\u003eChanges since langchain-openai==1.5.2\u003c/p\u003e\n\u003cp\u003erelease(openai): 1.6.0 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/39762\"\u003e#39762\u003c/a\u003e)\nfeat(core): add standard model exception types (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/39538\"\u003e#39538\u003c/a\u003e)\nfix(openai): raise clear error on unexpected response type in \u003ccode\u003e_create_chat_result\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/39731\"\u003e#39731\u003c/a\u003e)\u003c/p\u003e\n\u003ch2\u003elangchain-openai==1.5.2\u003c/h2\u003e\n\u003cp\u003eChanges since langchain-openai==1.5.1\u003c/p\u003e\n\u003cp\u003erelease(openai): 1.5.2 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/39719\"\u003e#39719\u003c/a\u003e)\nfix(openai): preserve reasoning item boundaries (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/39278\"\u003e#39278\u003c/a\u003e)\nrelease(openai): 1.5.2a1 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/39709\"\u003e#39709\u003c/a\u003e)\nfeat(openai): extract gateway metadata from response headers when available (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/39706\"\u003e#39706\u003c/a\u003e)\nchore(openai): update snapshots (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/39657\"\u003e#39657\u003c/a\u003e)\nfix(openai): support o-series models in \u003ccode\u003eget_num_tokens_from_messages\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38710\"\u003e#38710\u003c/a\u003e)\u003c/p\u003e\n\u003ch2\u003elangchain-openai==1.5.2a1\u003c/h2\u003e\n\u003cp\u003eInitial release\u003c/p\u003e\n\u003cp\u003erelease(openai): 1.5.2a1 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/39709\"\u003e#39709\u003c/a\u003e)\nfeat(openai): extract gateway metadata from response headers when available (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/39706\"\u003e#39706\u003c/a\u003e)\nchore(openai): update snapshots (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/39657\"\u003e#39657\u003c/a\u003e)\nfix(openai): support o-series models in \u003ccode\u003eget_num_tokens_from_messages\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38710\"\u003e#38710\u003c/a\u003e)\nrelease(openai): 1.5.1 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/39653\"\u003e#39653\u003c/a\u003e)\nfix(openai): preserve streamed encrypted reasoning (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/39635\"\u003e#39635\u003c/a\u003e)\nchore(infra): support langsmith gateway in CI (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/39651\"\u003e#39651\u003c/a\u003e)\nrelease(openai): 1.5.0 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/39629\"\u003e#39629\u003c/a\u003e)\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/60357692c76651a7cd6153496a24658fa355bdcc\"\u003e\u003ccode\u003e6035769\u003c/code\u003e\u003c/a\u003e release(openai): 1.6.2 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/40339\"\u003e#40339\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/a7b0f0ae50acebb527a25e153ff16621d37ba650\"\u003e\u003ccode\u003ea7b0f0a\u003c/code\u003e\u003c/a\u003e docs: update OpenWiki (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/40318\"\u003e#40318\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/1611938f49dda48aa069d1fdce429430257488b7\"\u003e\u003ccode\u003e1611938\u003c/code\u003e\u003c/a\u003e fix(openai): add GPT-6 Astra reasoning efforts (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/40330\"\u003e#40330\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/f092c9a78b3c532ef4c01935c0d4514209ff9f96\"\u003e\u003ccode\u003ef092c9a\u003c/code\u003e\u003c/a\u003e chore(model-profiles): refresh model profile data (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/40317\"\u003e#40317\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/22f3421aeedec55962f712a34d86d9683bf6cf59\"\u003e\u003ccode\u003e22f3421\u003c/code\u003e\u003c/a\u003e docs: update OpenWiki (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/40218\"\u003e#40218\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/1c40140b3daf80c5baa7427d707ef2beb6c404b2\"\u003e\u003ccode\u003e1c40140\u003c/code\u003e\u003c/a\u003e chore(deps): bump httpx2 from 2.10.0 to 2.12.0 in /libs/partners/openai (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/40309\"\u003e#40309\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/db613a96050bc6e594fdcd618af7532264dcceb8\"\u003e\u003ccode\u003edb613a9\u003c/code\u003e\u003c/a\u003e fix(openai): bump \u003ccode\u003emax_completion_tokens\u003c/code\u003e in cache breakpoint integration tes...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/9f2eb7f46719742875ebea9e31d53e168e8b81a2\"\u003e\u003ccode\u003e9f2eb7f\u003c/code\u003e\u003c/a\u003e release(openai): 1.6.1 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/40268\"\u003e#40268\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/765eb32901fa524e1428f94a9ee91b371a63ab62\"\u003e\u003ccode\u003e765eb32\u003c/code\u003e\u003c/a\u003e chore(model-profiles): refresh model profile data (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/40277\"\u003e#40277\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/e670c7a03ba36fd1516f0185f7ec1186c89aa471\"\u003e\u003ccode\u003ee670c7a\u003c/code\u003e\u003c/a\u003e chore(model-profiles): refresh model profile data (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/40258\"\u003e#40258\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/langchain-ai/langchain/compare/langchain-openai==1.3.5...langchain-openai==1.6.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `langgraph` from 1.2.9 to 1.2.11\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/langchain-ai/langgraph/releases\"\u003elanggraph's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003elanggraph==1.2.11\u003c/h2\u003e\n\u003cp\u003eChanges since 1.2.10\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003erelease(langgraph): 1.2.11 (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8595\"\u003e#8595\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efeat(langgraph): expose \u003ccode\u003etrace_policy\u003c/code\u003e on \u003ccode\u003eadd_node\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8523\"\u003e#8523\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore(deps): bump the minor-and-patch group across 1 directory with 7 updates (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8533\"\u003e#8533\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore(deps): bump the minor-and-patch group across 1 directory with 5 updates (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8532\"\u003e#8532\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003erelease(checkpoint-postgres): 3.1.2 (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8565\"\u003e#8565\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003erelease(checkpoint): 4.2.0 (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8563\"\u003e#8563\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix(checkpoint): collect writes at plain-value seed in delta channel history (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8526\"\u003e#8526\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore: enforce PLC0415 in tests for the remaining packages (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8547\"\u003e#8547\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003etest(checkpoint-postgres,checkpoint-sqlite): run the conformance suite (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8537\"\u003e#8537\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore: enable RUF100 and clear unused noqa directives (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8546\"\u003e#8546\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore(deps-dev): bump types-requests from 2.33.0.20260518 to 2.33.0.20260712 in /libs/langgraph (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8502\"\u003e#8502\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore(deps): bump cryptography from 48.0.1 to 50.0.0 in /libs/langgraph (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8528\"\u003e#8528\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003erelease(checkpoint-sqlite): 3.1.1 (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8481\"\u003e#8481\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003erelease(checkpoint-postgres): 3.1.1 (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8480\"\u003e#8480\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003elanggraph==1.2.10\u003c/h2\u003e\n\u003cp\u003eChanges since 1.2.9\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003erelease(langgraph): 1.2.10 (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8462\"\u003e#8462\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore(deps): bump jupyterlab from 4.5.9 to 4.5.10 in /libs/langgraph (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8440\"\u003e#8440\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore(deps): bump setuptools from 80.9.0 to 83.0.0 in /libs/langgraph (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8435\"\u003e#8435\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efeat(langgraph): type v3 stream_events return and native projections (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8389\"\u003e#8389\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003erevert(langgraph): delete TracePolicy (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8403\"\u003e#8403\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efeat(langgraph): drop tags from TracePolicy (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8402\"\u003e#8402\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efeat(langgraph): expose \u003ccode\u003etrace_policy\u003c/code\u003e on \u003ccode\u003eadd_node\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8362\"\u003e#8362\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore(deps): bump mistune from 3.2.1 to 3.3.0 in /libs/langgraph (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8317\"\u003e#8317\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore(deps): bump soupsieve from 2.8.1 to 2.8.4 in /libs/langgraph (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8318\"\u003e#8318\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore(cli): allow langgraph-api versions up to 1.0.0 (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8319\"\u003e#8319\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langgraph/commit/644815f9e5bc52ad8f7a5227a456227e9c3e639b\"\u003e\u003ccode\u003e644815f\u003c/code\u003e\u003c/a\u003e release(langgraph): 1.2.11 (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8595\"\u003e#8595\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langgraph/commit/7d6b5790ba84ce38c26f27a533d8419a31103c36\"\u003e\u003ccode\u003e7d6b579\u003c/code\u003e\u003c/a\u003e feat(langgraph): expose \u003ccode\u003etrace_policy\u003c/code\u003e on \u003ccode\u003eadd_node\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8523\"\u003e#8523\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langgraph/commit/d56666f7fbf0d380ad84cdf0cbe5aa48ab0cc086\"\u003e\u003ccode\u003ed56666f\u003c/code\u003e\u003c/a\u003e chore(deps): bump the minor-and-patch group across 1 directory with 7 updates...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langgraph/commit/6a2822d3c77dad49a96718de73095f18717728be\"\u003e\u003ccode\u003e6a2822d\u003c/code\u003e\u003c/a\u003e chore(deps): bump the minor-and-patch group across 1 directory with 5 updates...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langgraph/commit/fde3068970679184b68d3d068a92c83c966a4888\"\u003e\u003ccode\u003efde3068\u003c/code\u003e\u003c/a\u003e release(checkpoint-postgres): 3.1.2 (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8565\"\u003e#8565\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langgraph/commit/f55e77274dad40897ef7b2d52cc7c0b85b792247\"\u003e\u003ccode\u003ef55e772\u003c/code\u003e\u003c/a\u003e release(checkpoint): 4.2.0 (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8563\"\u003e#8563\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langgraph/commit/a90ab4435853b8a5b6f82b20220b4c76af0e46d1\"\u003e\u003ccode\u003ea90ab44\u003c/code\u003e\u003c/a\u003e fix(checkpoint): collect writes at plain-value seed in delta channel history ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langgraph/commit/ea5f9cc9fb8c4b123769daab4753af34de29b1e9\"\u003e\u003ccode\u003eea5f9cc\u003c/code\u003e\u003c/a\u003e chore: enforce PLC0415 in tests for the remaining packages (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8547\"\u003e#8547\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langgraph/commit/36a505ac65e956da09e93cc753609635a511047e\"\u003e\u003ccode\u003e36a505a\u003c/code\u003e\u003c/a\u003e test(checkpoint-postgres,checkpoint-sqlite): run the conformance suite (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8537\"\u003e#8537\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langgraph/commit/d569e18f4bd78b7652cb88c84b8dd098057e4f7d\"\u003e\u003ccode\u003ed569e18\u003c/code\u003e\u003c/a\u003e fix(checkpoint-postgres): find plain-value seeds when walking delta history (...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/langchain-ai/langgraph/compare/1.2.9...1.2.11\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `langgraph-checkpoint` from 4.1.1 to 4.2.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/langchain-ai/langgraph/releases\"\u003elanggraph-checkpoint's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003elanggraph-checkpoint==4.2.0\u003c/h2\u003e\n\u003cp\u003eChanges since checkpoint==4.1.1\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003erelease(checkpoint): 4.2.0 (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8563\"\u003e#8563\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix(checkpoint): collect writes at plain-value seed in delta channel history (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8526\"\u003e#8526\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore: enforce PLC0415 in tests for the remaining packages (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8547\"\u003e#8547\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore: enable RUF100 and clear unused noqa directives (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8546\"\u003e#8546\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore(deps): bump the minor-and-patch group in /libs/checkpoint with 4 updates (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8490\"\u003e#8490\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efeat(checkpoint,checkpoint-postgres): add opt-in omit_expired to skip expired rows on read (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8354\"\u003e#8354\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore(deps): bump the minor-and-patch group in /libs/checkpoint with 5 updates (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8248\"\u003e#8248\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore(deps): bump langsmith from 0.8.0 to 0.8.18 in /libs/checkpoint (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8173\"\u003e#8173\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003edocs: standardize package \u003ccode\u003eREADME.md\u003c/code\u003e structure (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8064\"\u003e#8064\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore: migrate Python type checking to ty (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8002\"\u003e#8002\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore(deps-dev): bump the major group in /libs/checkpoint with 2 updates (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/7967\"\u003e#7967\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore(deps): bump the minor-and-patch group in /libs/checkpoint with 3 updates (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/7960\"\u003e#7960\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langgraph/commit/f55e77274dad40897ef7b2d52cc7c0b85b792247\"\u003e\u003ccode\u003ef55e772\u003c/code\u003e\u003c/a\u003e release(checkpoint): 4.2.0 (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8563\"\u003e#8563\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langgraph/commit/a90ab4435853b8a5b6f82b20220b4c76af0e46d1\"\u003e\u003ccode\u003ea90ab44\u003c/code\u003e\u003c/a\u003e fix(checkpoint): collect writes at plain-value seed in delta channel history ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langgraph/commit/ea5f9cc9fb8c4b123769daab4753af34de29b1e9\"\u003e\u003ccode\u003eea5f9cc\u003c/code\u003e\u003c/a\u003e chore: enforce PLC0415 in tests for the remaining packages (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8547\"\u003e#8547\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langgraph/commit/36a505ac65e956da09e93cc753609635a511047e\"\u003e\u003ccode\u003e36a505a\u003c/code\u003e\u003c/a\u003e test(checkpoint-postgres,checkpoint-sqlite): run the conformance suite (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8537\"\u003e#8537\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langgraph/commit/d569e18f4bd78b7652cb88c84b8dd098057e4f7d\"\u003e\u003ccode\u003ed569e18\u003c/code\u003e\u003c/a\u003e fix(checkpoint-postgres): find plain-value seeds when walking delta history (...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langgraph/commit/f22af6248c93df08b553e9a264f6367797e0fddb\"\u003e\u003ccode\u003ef22af62\u003c/code\u003e\u003c/a\u003e chore: enable RUF100 and clear unused noqa directives (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8546\"\u003e#8546\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langgraph/commit/658541c4960f329864a2523fc7d52427e8190bed\"\u003e\u003ccode\u003e658541c\u003c/code\u003e\u003c/a\u003e chore(checkpoint-postgres,checkpoint-sqlite): enable PLC0415 lint rule (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8540\"\u003e#8540\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langgraph/commit/fb3d5f0399222504e015fe959e0e79fdc6e00a65\"\u003e\u003ccode\u003efb3d5f0\u003c/code\u003e\u003c/a\u003e chore(deps): bump the minor-and-patch group in /libs/cli/js-examples with 8 u...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langgraph/commit/01521c1b1cc4c035f64b9be40f2913285128f526\"\u003e\u003ccode\u003e01521c1\u003c/code\u003e\u003c/a\u003e chore(deps): bump the minor-and-patch group in /libs/cli/js-monorepo-example ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langgraph/commit/cd62febcfae628d0930d1f7d3cb3b5919d4b800f\"\u003e\u003ccode\u003ecd62feb\u003c/code\u003e\u003c/a\u003e chore(deps): bump the minor-and-patch group in /libs/checkpoint with 4 update...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/langchain-ai/langgraph/compare/checkpoint==4.1.1...checkpoint==4.2.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `python-dotenv` from 1.2.2 to 1.2.3\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/theskumar/python-dotenv/releases\"\u003epython-dotenv's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.2.3\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eStrip a leading UTF-8 BOM from \u003ccode\u003e.env\u003c/code\u003e file contents so the first variable is no longer silently lost when the file is saved with BOM (e.g. by some JetBrains IDEs on Windows) by [\u003ca href=\"https://github.com/h1whelan\"\u003e\u003ccode\u003e@​h1whelan\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/640\"\u003e#640\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eset_key\u003c/code\u003e now escapes backslashes, so values containing them (Windows paths, regular expressions) survive a write/read round-trip. Quoted values ending in an escaped backslash are no longer mis-parsed as an escaped quote, which used to swallow the following lines by [\u003ca href=\"https://github.com/dchaudhari7177\"\u003e\u003ccode\u003e@​dchaudhari7177\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/680\"\u003e#680\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003edotenv run\u003c/code\u003e now prints a friendly error instead of a traceback when no command is given by [\u003ca href=\"https://github.com/bbc2\"\u003e\u003ccode\u003e@​bbc2\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/606\"\u003e#606\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eCache the parsed result for empty \u003ccode\u003e.env\u003c/code\u003e files so repeated \u003ccode\u003edotenv_values\u003c/code\u003e/\u003ccode\u003eload_dotenv\u003c/code\u003e calls no longer re-read the file by [\u003ca href=\"https://github.com/ReinerBRO\"\u003e\u003ccode\u003e@​ReinerBRO\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/638\"\u003e#638\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/theskumar/python-dotenv/blob/main/CHANGELOG.md\"\u003epython-dotenv's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e[1.2.3] - 2026-08-16\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eStrip a leading UTF-8 BOM from \u003ccode\u003e.env\u003c/code\u003e file contents so the first variable is no longer silently lost when the file is saved with BOM (e.g. by some JetBrains IDEs on Windows) by [\u003ca href=\"https://github.com/h1whelan\"\u003e\u003ccode\u003e@​h1whelan\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/640\"\u003e#640\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eset_key\u003c/code\u003e now escapes backslashes, so values containing them (Windows paths, regular expressions) survive a write/read round-trip. Quoted values ending in an escaped backslash are no longer mis-parsed as an escaped quote, which used to swallow the following lines by [\u003ca href=\"https://github.com/dchaudhari7177\"\u003e\u003ccode\u003e@​dchaudhari7177\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/680\"\u003e#680\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003edotenv run\u003c/code\u003e now prints a friendly error instead of a traceback when no command is given by [\u003ca href=\"https://github.com/bbc2\"\u003e\u003ccode\u003e@​bbc2\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/606\"\u003e#606\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eCache the parsed result for empty \u003ccode\u003e.env\u003c/code\u003e files so repeated \u003ccode\u003edotenv_values\u003c/code\u003e/\u003ccode\u003eload_dotenv\u003c/code\u003e calls no longer re-read the file by [\u003ca href=\"https://github.com/ReinerBRO\"\u003e\u003ccode\u003e@​ReinerBRO\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/638\"\u003e#638\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/49515afee2d50c33cad9419b3800b3a0dc93fc59\"\u003e\u003ccode\u003e49515af\u003c/code\u003e\u003c/a\u003e Bump version: 1.2.2 → 1.2.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/8ac846ff2760b65470e769d7eed33e540f0934e1\"\u003e\u003ccode\u003e8ac846f\u003c/code\u003e\u003c/a\u003e chore: add release runbook (RELEASING.md) and make release target\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/bb31c944fb4b40e8dea59587f525840c38326166\"\u003e\u003ccode\u003ebb31c94\u003c/code\u003e\u003c/a\u003e docs: add 1.2.3 release notes (\u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/606\"\u003e#606\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/638\"\u003e#638\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/680\"\u003e#680\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/f7b18d9c72d1abcc2ad4023424b84f5bee30d266\"\u003e\u003ccode\u003ef7b18d9\u003c/code\u003e\u003c/a\u003e fix: round-trip backslashes through set_key (\u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/680\"\u003e#680\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/751f8c148222e58aa173c83c4e5e6cfccb2cc124\"\u003e\u003ccode\u003e751f8c1\u003c/code\u003e\u003c/a\u003e ci(deps): bump actions/checkout from 6.0.2 to 6.0.3 in the github-actions gro...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/f1937b68f338d7ebd7754da377ca08b2f0df8dbb\"\u003e\u003ccode\u003ef1937b6\u003c/code\u003e\u003c/a\u003e chore(deps): update mkdocs-include-markdown-plugin requirement from \u0026gt;=6.0.0 t...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/45b93720dd5e9e127d0be3971a04855d34e464d8\"\u003e\u003ccode\u003e45b9372\u003c/code\u003e\u003c/a\u003e chore(deps): update pytest requirement from \u0026gt;=3.9 to \u0026gt;=9.0.3 (\u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/653\"\u003e#653\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/72896e9244d2a1ff8d5e1934d3df8a35c813799a\"\u003e\u003ccode\u003e72896e9\u003c/code\u003e\u003c/a\u003e docs: fix broken mkdocs link in CONTRIBUTING.md (\u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/636\"\u003e#636\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/72754a16a4743e4c92edf87ce59ba0e4ff78758d\"\u003e\u003ccode\u003e72754a1\u003c/code\u003e\u003c/a\u003e ci(deps): bump peaceiris/actions-gh-pages from 4.0.0 to 4.1.0 in the github-a...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/078325e92558330e9addc661b789c7b6123fa73c\"\u003e\u003ccode\u003e078325e\u003c/code\u003e\u003c/a\u003e ci(security): harden CI/CD supply chain with SHA pinning and least-privilege ...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/theskumar/python-dotenv/compare/v1.2.2...v1.2.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `pypdfium2` from 5.11.0 to 5.13.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pypdfium2-team/pypdfium2/releases\"\u003epypdfium2's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e5.13.0\u003c/h2\u003e\n\u003ch2\u003eRelease 5.13.0\u003c/h2\u003e\n\u003ch3\u003eSummary\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eExperimental \u003ccode\u003epyemscripten_2026_0_wasm32\u003c/code\u003e (Pyodide) build support added. \u003cem\u003eHowever, the resulting builds are flaky at runtime and subject to various types of random crashes. Freezes on shutdown have also been observed.\u003c/em\u003e\nWhile these issues persist, PyEmscripten wheels will not be uploaded to PyPI, but they are included in the release process and can be downloaded from GitHub on an experimental basis. If you can help track down and fix these issues, please reach out.\nNote: Our PyEmscripten wheels are bigger than usual, as they are built with debug symbols (a non-debug build is not considered useful at this stage).\u003c/li\u003e\n\u003cli\u003eFixed compatibility with Python 3.6 and 3.7.\n\u003cul\u003e\n\u003cli\u003eRuntime support was inadvertently broken due to a faulty cached property backport which held only one cache per class, not per instance as should have been.\nThe accidental loss of caches broke key assumptions of our autoclose logic, which relies on \u003ccode\u003ecached_property\u003c/code\u003e since 5.8.0. (Earlier versions that did not make extensive use of cached properties might work but have not been explicitly tested.)\u003c/li\u003e\n\u003cli\u003eThis release replaces both \u003ccode\u003efunctools.cached_property\u003c/code\u003e and the faulty \u003ccode\u003efunctools.lru_cache()\u003c/code\u003e based backport with our own, backward compatible \u003ccode\u003ecached_property\u003c/code\u003e implementation along with thorough documentation.\u003c/li\u003e\n\u003cli\u003eAlso, fixed setup (i.e. source installation) with Python 3.6 and its max available setup dependency versions (that is, \u003ccode\u003esetuptools\u003c/code\u003e 59). This had probably been broken for a long time. (A few non-breaking issues remain, e.g. for some reason we end up with a \u003ccode\u003epurelib\u003c/code\u003e directory, but it should be \u003ccode\u003eplatlib\u003c/code\u003e.)\u003c/li\u003e\n\u003cli\u003eBear in mind that ctypesgen continues to require Python \u003ccode\u003e\u0026gt;=3.8\u003c/code\u003e at this time (3.6 compat not being a priority in that case), but you can install with \u003ccode\u003e--no-build-isolation\u003c/code\u003e and let the reference bindings be used, or try adding ctypesgen's \u003ccode\u003esrc/\u003c/code\u003e to \u003ccode\u003ePYTHONPATH\u003c/code\u003e to bypass setup, and see how it goes.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eNote: We do not plan to (and practically cannot) keep up compatibility with outdated Python versions indefinitely.\u003c/strong\u003e In particular, setup compatibility may be dropped sooner or later in favor of contemporary Python packaging concepts, like migrating as much as possible to \u003ccode\u003epyproject.toml\u003c/code\u003e. That said, we are happy to restore compatibility at this point, and fix any \u003cem\u003eunintentional\u003c/em\u003e breakage.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eMANIFEST.in\u003c/code\u003e missing Windows spoof headers, which resulted in subtly incorrect bindings when installing from an sdist on Windows, as seen in test failures. (Release wheels have been unaffected and passed the test suite, so this issue went unnoticed for a while.)\u003c/li\u003e\n\u003cli\u003eBumped \u003ccode\u003egn-dist\u003c/code\u003e from \u003ccode\u003e2407.1\u003c/code\u003e to \u003ccode\u003e2407.3\u003c/code\u003e. Made its setup python 3.6 compatible likewise (wheels should have worked before now). Changed versioning and release process so that CI no longer needs to push to the repository (may eventually become a blueprint for pypdfium2 itself). More documentation added, including \u003ccode\u003emanylinux2014\u003c/code\u003e POC.\u003c/li\u003e\n\u003cli\u003eInternal improvements (non-exhaustive):\n\u003cul\u003e\n\u003cli\u003eProperly clean up \u003ccode\u003e*.egg-info/\u003c/code\u003e and \u003ccode\u003ebuild/\u003c/code\u003e before packaging, to avoid mad file inclusion bugs (ran into this while working on setup include rules).\u003c/li\u003e\n\u003cli\u003eMigrated from requirements files to PEP 735 dependency groups (\u003ccode\u003epyproject.toml\u003c/code\u003e).\nRecent enough \u003ccode\u003epip\u003c/code\u003e should be available to Python \u0026gt;= 3.9. For compatibility with older versions, feel free to use \u003ccode\u003e./utils/misc/install_dep_group.py\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eApplied dependency cooldowns to internal callers of \u003ccode\u003epip install\u003c/code\u003e. Always use virtual environments in CI. Use lockfiles in sensitive areas (e.g. publish jobs).\u003c/li\u003e\n\u003cli\u003eRearranged \u0026amp; improved utilities. Cleaner distinction between \u003ccode\u003esetupsrc/\u003c/code\u003e and \u003ccode\u003eutils/\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eWork around persistent i686 container network issues by downgrading host runner to \u003ccode\u003eubuntu-24.04\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eLet \u003ccode\u003esetupsrc/\u003c/code\u003e share code from \u003ccode\u003esrc/\u003c/code\u003e through a \u003ccode\u003epypdfium2_cfg._shared\u003c/code\u003e submodule that can be added to \u003ccode\u003esys.path\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBuild info\u003c/h3\u003e\n\u003cp\u003eThis release was made with the following build strategies:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003ePBIN: \u003ccode\u003e[macosx_arm64, macosx_x86_64, win_amd64, win_arm64, win32, manylinux_x86_64, manylinux_i686, manylinux_aarch64, manylinux_armv7l, manylinux_ppc64le, manylinux_mips64le, android_arm64_v8a, android_armeabi_v7a]\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eSBLD: \u003ccode\u003e[manylinux_mipsle]\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eCIBW: \u003ccode\u003e[manylinux_riscv64, manylinux_loongarch64, manylinux_s390x, musllinux_x86_64, musllinux_aarch64, musllinux_armv7l, musllinux_i686, musllinux_ppc64le, musllinux_s390x, musllinux_riscv64, musllinux_loongarch64, pyodide_wasm32]\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cblockquote\u003e\n\u003cp\u003e[!CAUTION]\nThe following builds are affected by known, major issues (e.g. endianness bugs, crashes, freezes) and are \u003cstrong\u003eNOT\u003c/strong\u003e considered ready for production use:\n\u003ccode\u003e[manylinux_s390x, musllinux_s390x, pyodide_wasm32]\u003c/code\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003ch3\u003eCommit logs\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cp\u003eCommits between \u003ca href=\"https://github.com/pypdfium2-team/pypdfium2/tree/5.12.1\"\u003e\u003ccode\u003e5.12.1\u003c/code\u003e\u003c/a\u003e and \u003ca href=\"https://github.com/pypdfium2-team/pypdfium2/tree/5.13.0\"\u003e\u003ccode\u003e5.13.0\u003c/code\u003e\u003c/a\u003e (latest commit first):\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypdfium2-team/pypdfium2/commit/a4659102e4c258ee18c661232c0f9763f6c85ad0\"\u003e\u003ccode\u003ea4659102\u003c/code\u003e\u003c/a\u003e [autorelease main] update 5.13.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypdfium2-team/pypdfium2/commit/9094de358328ae44236c5cb401a8155311e450a0\"\u003e\u003ccode\u003e9094de35\u003c/code\u003e\u003c/a\u003e continue on changelog/docs\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypdfium2-team/pypdfium2/commit/b89e367a5dec13b99ec20f0beed137146a75bbcf\"\u003e\u003ccode\u003eb89e367a\u003c/code\u003e\u003c/a\u003e git_net_additions.py: minor tweaks\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypdfium2-team/pypdfium2/commit/57157e789f2573f6d4b61e58e8c7a778674afdd1\"\u003e\u003ccode\u003e57157e78\u003c/code\u003e\u003c/a\u003e readme: don't overdo admonitions\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypdfium2-team/pypdfium2/commit/033d5ce066aba79233d4f406678bbac057ad6011\"\u003e\u003ccode\u003e033d5ce0\u003c/code\u003e\u003c/a\u003e changelog: less waffle\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypdfium2-team/pypdfium2/commit/5afbd6193eff87df05153148116a82d9f7cd7fa3\"\u003e\u003ccode\u003e5afbd619\u003c/code\u003e\u003c/a\u003e install_buildtools: use compat function for dependency group\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypdfium2-team/pypdfium2/commit/a4659102e4c258ee18c661232c0f9763f6c85ad0\"\u003e\u003ccode\u003ea465910\u003c/code\u003e\u003c/a\u003e [autorelease main] update 5.13.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypdfium2-team/pypdfium2/commit/9094de358328ae44236c5cb401a8155311e450a0\"\u003e\u003ccode\u003e9094de3\u003c/code\u003e\u003c/a\u003e continue on changelog/docs\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypdfium2-team/pypdfium2/commit/b89e367a5dec13b99ec20f0beed137146a75bbcf\"\u003e\u003ccode\u003eb89e367\u003c/code\u003e\u003c/a\u003e git_net_additions.py: minor tweaks\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypdfium2-team/pypdfium2/commit/57157e789f2573f6d4b61e58e8c7a778674afdd1\"\u003e\u003ccode\u003e57157e7\u003c/code\u003e\u003c/a\u003e readme: don't overdo admonitions\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypdfium2-team/pypdfium2/commit/033d5ce066aba79233d4f406678bbac057ad6011\"\u003e\u003ccode\u003e033d5ce\u003c/code\u003e\u003c/a\u003e changelog: less waffle\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypdfium2-team/pypdfium2/commit/5afbd6193eff87df05153148116a82d9f7cd7fa3\"\u003e\u003ccode\u003e5afbd61\u003c/code\u003e\u003c/a\u003e install_buildtools: use compat function for dependency group\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypdfium2-team/pypdfium2/commit/3282e36375fd6e139f885ff634747ab0fe643e66\"\u003e\u003ccode\u003e3282e36\u003c/code\u003e\u003c/a\u003e Add zizmor to check step\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypdfium2-team/pypdfium2/commit/07b84aaaa9c4c44429e0316c15c179b64c004d0a\"\u003e\u003ccode\u003e07b84aa\u003c/code\u003e\u003c/a\u003e Progress changelog\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypdfium2-team/pypdfium2/commit/6ec38d2aa64d59f02892ddf07f601bbdb5bbf53e\"\u003e\u003ccode\u003e6ec38d2\u003c/code\u003e\u003c/a\u003e git_net_additions: further improve fallback\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypdfium2-team/pypdfium2/commit/b5cdd7c7fcd2c01cd7744b6824f977bbbcb831c6\"\u003e\u003ccode\u003eb5cdd7c\u003c/code\u003e\u003c/a\u003e git_net_additions: fancier fallback for binary files\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/pypdfium2-team/pypdfium2/compare/5.11.0...5.13.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `duckdb` from 1.5.4 to 1.5.5\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/duckdb/duckdb-python/releases\"\u003educkdb's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.5.5 Bugfix Release\u003c/h2\u003e\n\u003cp\u003eSee \u003ca href=\"https://github.com/duckdb/duckdb/releases/tag/v1.5.5\"\u003eDuckDB's changelog\u003c/a\u003e for all changes in DuckDB.\u003c/p\u003e\n\u003ch2\u003eWhat's Changed in DuckDB-Python\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix numpy deprecations by \u003ca href=\"https://github.com/evertlammerts\"\u003e\u003ccode\u003e@​evertlammerts\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/duckdb/duckdb-python/pull/505\"\u003educkdb/duckdb-python#505\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix alias of \u003ccode\u003eDuckDBPyRelation.query\u003c/code\u003e (closes \u003ca href=\"https://redirect.github.com/duckdb/duckdb-python/issues/468\"\u003e#468\u003c/a\u003e) by \u003ca href=\"https://github.com/evertlammerts\"\u003e\u003ccode\u003e@​evertlammerts\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/duckdb/duckdb-python/pull/524\"\u003educkdb/duckdb-python#524\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/duckdb/duckdb-python/commit/b236c8194ed14c7a7c685e0534dde501cc855b3a\"\u003e\u003ccode\u003eb236c81\u003c/code\u003e\u003c/a\u003e Pin submodule to release hash\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/duckdb/duckdb-python/commit/e6a21c5b5d65d741fafd5a7389c93b8b86a7f249\"\u003e\u003ccode\u003ee6a21c5\u003c/code\u003e\u003c/a\u003e [duckdb-labs bot] Bump DuckDB submodule (\u003ca href=\"https://redirect.github.com/duckdb/duckdb-python/issues/554\"\u003e#554\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/duckdb/duckdb-python/commit/f637bf42683030cbb108268581b866f13cb75031\"\u003e\u003ccode\u003ef637bf4\u003c/code\u003e\u003c/a\u003e Bump submodule\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/duckdb/duckdb-python/commit/4c5c73c63381bd0587fd42b41093c8f0abe9f17c\"\u003e\u003ccode\u003e4c5c73c\u003c/code\u003e\u003c/a\u003e [duckdb-labs bot] Bump DuckDB submodule (\u003ca href=\"https://redirect.github.com/duckdb/duckdb-python/issues/551\"\u003e#551\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/duckdb/duckdb-python/commit/6fae28061912de88c3c0f6e6ad6b2f3fc5ee5235\"\u003e\u003ccode\u003e6fae280\u003c/code\u003e\u003c/a\u003e Bump submodule\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/duckdb/duckdb-python/commit/d8d5f0a36003c9090ea9480cdefa8f4b4122fece\"\u003e\u003ccode\u003ed8d5f0a\u003c/code\u003e\u003c/a\u003e [duckdb-labs bot] Bump DuckDB submodule (\u003ca href=\"https://redirect.github.com/duckdb/duckdb-python/issues/548\"\u003e#548\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/duckdb/duckdb-python/commit/5d85f06025e83e3d2c69813acf4b2dc02bebc415\"\u003e\u003ccode\u003e5d85f06\u003c/code\u003e\u003c/a\u003e Bump submodule\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/duckdb/duckdb-python/commit/c3cbf8d9ca87cea3dfbb89bfa2102ff4ec530f00\"\u003e\u003ccode\u003ec3cbf8d\u003c/code\u003e\u003c/a\u003e [duckdb-labs bot] Bump DuckDB submodule (\u003ca href=\"https://redirect.github.com/duckdb/duckdb-python/issues/545\"\u003e#545\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/duckdb/duckdb-python/commit/93418b65c6ca821d71d9a091fb5218ad55d8a4eb\"\u003e\u003ccode\u003e93418b6\u003c/code\u003e\u003c/a\u003e Bump submodule\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/duckdb/duckdb-python/commit/24f1915b590e1e663a14c0bff9e49bf28ebece9b\"\u003e\u003ccode\u003e24f1915\u003c/code\u003e\u003c/a\u003e [duckdb-labs bot] Bump DuckDB submodule (\u003ca href=\"https://redirect.github.com/duckdb/duckdb-python/issues/539\"\u003e#539\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/duckdb/duckdb-python/compare/v1.5.4...v1.5.5\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `scikit-learn` from 1.9.0 to 1.9.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/scikit-learn/scikit-learn/releases\"\u003escikit-learn's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eScikit-learn 1.9.1\u003c/h2\u003e\n\u003cp\u003eWe're happy to announce the 1.9.1 release.\u003c/p\u003e\n\u003cp\u003eThis release contains a few bug fixes and is the first version supporting Python 3.15.\u003c/p\u003e\n\u003cp\u003eYou can see the changelog here: \u003ca href=\"https://scikit-learn.org/stable/whats_new/v1.9.html#version-1-9-1\"\u003ehttps://scikit-learn.org/stable/whats_new/v1.9.html#version-1-9-1\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eYou can upgrade with pip as usual:\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003epip install -U scikit-learn\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eThe conda-forge builds can be installed using:\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003econda install -c conda-forge scikit-learn\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eThanks to everyone who contributed to this release !\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/scikit-learn/scikit-learn/commit/866c0f51e7560ef0303cbcc5f159df5382ea9e3f\"\u003e\u003ccode\u003e866c0f5\u003c/code\u003e\u003c/a\u003e generate changelog\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/scikit-learn/scikit-learn/commit/12f135fbffe3b3e7e294e4ef16f0b59f68e6a6b9\"\u003e\u003ccode\u003e12f135f\u003c/code\u003e\u003c/a\u003e update upper bounds\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/scikit-learn/scikit-learn/commit/43ff2f20bc5bfbe92b9cd3ec9d86214da8ee2c6e\"\u003e\u003ccode\u003e43ff2f2\u003c/code\u003e\u003c/a\u003e bump version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/scikit-learn/scikit-learn/commit/b8515241202663142b65dbe92294e96a6dc5def2\"\u003e\u003ccode\u003eb851524\u003c/code\u003e\u003c/a\u003e DOC Mark dev index as orphan (\u003ca href=\"https://redirect.github.com/scikit-learn/scikit-learn/issues/34916\"\u003e#34916\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/scikit-learn/scikit-learn/commit/01d56d48da18e7b365c4d2ebcd5d1fddaa24dd12\"\u003e\u003ccode\u003e01d56d4\u003c/code\u003e\u003c/a\u003e DOC Fix wikipedia principal eigenvector example references (\u003ca href=\"https://redirect.github.com/scikit-learn/scikit-learn/issues/34915\"\u003e#34915\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/scikit-learn/scikit-learn/commit/b86a1e227c2c424b17f8872d4094bbbc061e32c9\"\u003e\u003ccode\u003eb86a1e2\u003c/code\u003e\u003c/a\u003e :lock: :robot: CI Update lock files for array-api CI build(s) :lock: :robot: ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/scikit-learn/scikit-learn/commit/d282698440cec541f2427794b8c205fb4b1420be\"\u003e\u003ccode\u003ed282698\u003c/code\u003e\u003c/a\u003e :lock: :robot: CI Update lock files for main CI build(s) :lock: :robot: (\u003ca href=\"https://redirect.github.com/scikit-learn/scikit-learn/issues/34897\"\u003e#34897\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/scikit-learn/scikit-learn/commit/eb34279083fe9297d141efddceaf38c596a49766\"\u003e\u003ccode\u003eeb34279\u003c/code\u003e\u003c/a\u003e :lock: :robot: CI Update lock files for free-threaded CI build(s) :lock: :rob...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/scikit-learn/scikit-learn/commit/7581303c447a0daa07fa74ba8104e327c11f1dc5\"\u003e\u003ccode\u003e7581303\u003c/code\u003e\u003c/a\u003e FIX: Fix \u003ccode\u003eQuantileTransformer(ignore_implicit_zeros=True)\u003c/code\u003e sub-sampling behav...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/scikit-learn/scikit-learn/commit/ac47f4de75eacad880b77db09aa1f677f6038274\"\u003e\u003ccode\u003eac47f4d\u003c/code\u003e\u003c/a\u003e FIX: avoid EfficiencyWarning in OPTICS with metric='precomputed' (\u003ca href=\"https://redirect.github.com/scikit-learn/scikit-learn/issues/34692\"\u003e#34692\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/scikit-learn/scikit-learn/compare/1.9.0...1.9.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `joblib` from 1.5.3 to 1.6.0\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/joblib/joblib/blob/main/CHANGES.rst\"\u003ejoblib's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eRelease 1.6.0 - 2026/08/31\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eFix caching of functions whose source cannot be retrieved, such as functions\ndefined in a notebook cell. Their identity fell back to\n\u003ccode\u003estr(hash(func.__code__))\u003c/code\u003e, which is salted by \u003ccode\u003ePYTHONHASHSEED\u003c/code\u003e and so\ndiffered between processes. A worker reading the \u003ccode\u003efunc_code.py\u003c/code\u003e written by\nanother one concluded that the function had changed and wiped the whole\ncache directory for it, discarding results computed by its peers.\n\u003ccode\u003efunc_code.py\u003c/code\u003e is also no longer rewritten in place, so a reader can no\nlonger catch it half-written and draw the same conclusion.\n\u003ca href=\"https://redirect.github.com/joblib/joblib/issues/1694\"\u003ejoblib/joblib#1694\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eDrop python 3.9 support. The oldest supported Python version\nis now Python 3.10.\n\u003ca href=\"https://redirect.github.com/joblib/joblib/pull/1773\"\u003ejoblib/joblib#1773\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix \u003ccode\u003eeval_expr\u003c/code\u003e (used to evaluate the \u003ccode\u003epre_dispatch\u003c/code\u003e argument of\n\u003ccode\u003eParallel\u003c/code\u003e) to raise a \u003ccode\u003eValueError\u003c/code\u003e as documented instead of leaking a\n\u003ccode\u003eZeroDivisionError\u003c/code\u003e for expressions that divide or take a modulo by zero.\n\u003ca href=\"https://redirect.github.com/joblib/joblib/pull/1810\"\u003ejoblib/joblib#1810\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ccode\u003eMemorizedResult\u003c/code\u003e now forwards \u003ccode\u003emmap_mode\u003c/code\u003e to its store backend, so a\ncached array reconstructed from a location is memory-mapped as requested\ninstead of being loaded fully into memory.\n\u003ca href=\"https://redirect.github.com/joblib/joblib/pull/1799\"\u003ejoblib/joblib#1799\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUnvendor cloudpickle to more quickly benefit from maintenance releases\nof cloudpickle\n\u003ca href=\"https://redirect.github.com/joblib/joblib/pull/1775\"\u003ejoblib/joblib#1775\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix \u003ccode\u003eMemory.cache\u003c/code\u003e for functions with a keyword-only argument that has a\ndefault declared before a keyword-only argument without a default.\n\u003ca href=\"https://redirect.github.com/joblib/joblib/issues/1731\"\u003ejoblib/joblib#1731\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix behavior of \u003ccode\u003efilter_args\u003c/code\u003e on some precise cases.\n\u003ca href=\"https://redirect.github.com/joblib/joblib/pull/1800\"\u003ejoblib/joblib#1800\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix a concurrency error that could happen with unordered generator.\n\u003ca href=\"https://redirect.github.com/joblib/joblib/pull/1789\"\u003ejoblib/joblib#1789\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix: \u003ccode\u003edump()\u003c/code\u003e now accepts any input \u003ccode\u003eos.PathLike\u003c/code\u003e object to be consistent with\n\u003ccode\u003eload\u003c/code\u003e.\n\u003ca href=\"https://redirect.github.com/joblib/joblib/pull/1812\"\u003ejoblib/joblib#1812\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eThe documentation now uses pydata sphinx theme. Furthermore, optional dependencies\n\u003ccode\u003etest\u003c/code\u003e and \u003ccode\u003edocs\u003c/code\u003e have been added to \u003ccode\u003epyproject.toml\u003c/code\u003e.\n\u003ca href=\"https://redirect.github.com/joblib/joblib/pull/1774\"\u003ejoblib/joblib#1774\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eVendor \u003ccode\u003eloky 3.6.0\u003c/code\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/joblib/joblib/commit/cd9a6b05fc4f2b1c8202eb62c4e863484f8cc099\"\u003e\u003ccode\u003ecd9a6b0\u003c/code\u003e\u003c/a\u003e Release 1.6.0 (\u003ca href=\"https://redirect.github.com/joblib/joblib/issues/1844\"\u003e#1844\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/joblib/joblib/commit/d873f972949d78166af6c945667c53f04d41fed6\"\u003e\u003ccode\u003ed873f97\u003c/code\u003e\u003c/a\u003e MNT vendor loky 3.6.0 (\u003ca href=\"https://redirect.github.com/joblib/joblib/issues/1843\"\u003e#1843\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/joblib/joblib/commit/4ff61afd0849f18fddf5fbd137c1f02bfaed5223\"\u003e\u003ccode\u003e4ff61af\u003c/code\u003e\u003c/a\u003e Bump the github-actions group with 4 updates (\u003ca href=\"https://redirect.github.com/joblib/joblib/issues/1832\"\u003e#1832\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/joblib/joblib/commit/804f4725e1a27b1425c8aabcf7312ceb11c3a07d\"\u003e\u003ccode\u003e804f472\u003c/code\u003e\u003c/...\n\n_Description has been truncated_","html_url":"https://github.com/Vatsa1374/Vibe-trading-/pull/26","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/Vatsa1374%2FVibe-trading-/issues/26","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/26/packages"},{"uuid":"5469403115","node_id":"PR_kwDOUc0WIs8AAAABDszVZA","number":10,"state":"open","title":"chore(deps): update aiohttp requirement from \u003e=3.13.3 to \u003e=3.14.3","user":"dependabot[bot]","labels":[],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-16T02:11:59.000Z","updated_at":"2026-09-16T02:11:59.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps): update","packages":[{"name":"aiohttp","old_version":"\u003e=3.13.3","new_version":"\u003e=3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"}],"path":null,"ecosystem":"pip"},"body":"Updates the requirements on [aiohttp](https://github.com/aio-libs/aiohttp) to permit the latest version.\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\n\n\n\u003c/details\u003e","html_url":"https://github.com/01sure/Multi-Agent-Intelligent-Warehouse/pull/10","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/01sure%2FMulti-Agent-Intelligent-Warehouse/issues/10","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/10/packages"},{"uuid":"5467892353","node_id":"PR_kwDOTIfnCs8AAAABDrnK9A","number":17,"state":"open","title":"build(deps): bump the minor-and-patch group across 1 directory with 14 updates","user":"dependabot[bot]","labels":["dependencies","python:uv"],"assignees":[],"locked":false,"comments_count":8,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-15T22:10:08.000Z","updated_at":"2026-09-15T22:11:35.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"build(deps): bump","group_name":"minor-and-patch","update_count":14,"packages":[{"name":"uvicorn","old_version":"0.49.0","new_version":"0.52.4","repository_url":"https://github.com/Kludex/uvicorn"},{"name":"pydantic","old_version":"2.13.4","new_version":"2.13.5","repository_url":"https://github.com/pydantic/pydantic"},{"name":"python-dotenv","old_version":"1.2.2","new_version":"1.2.3","repository_url":"https://github.com/theskumar/python-dotenv"},{"name":"tiktoken","old_version":"0.13.0","new_version":"0.14.0","repository_url":"https://github.com/openai/tiktoken"},{"name":"pydantic-settings","old_version":"2.14.2","new_version":"2.15.0","repository_url":"https://github.com/pydantic/pydantic-settings"},{"name":"aiohttp","old_version":"3.14.1","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"reportlab","old_version":"5.0.0","new_version":"5.0.1"},{"name":"grpcio","old_version":"1.81.1","new_version":"1.83.1","repository_url":"https://github.com/grpc/grpc"},{"name":"nvidia-riva-client","old_version":"2.26.0","new_version":"2.27.0","repository_url":"https://github.com/nvidia-riva/python-clients"},{"name":"torch","old_version":"2.12.1+cu130","new_version":"2.14.0","repository_url":"https://github.com/pytorch/pytorch"},{"name":"transformers","old_version":"5.12.1","new_version":"5.17.0","repository_url":"https://github.com/huggingface/transformers"},{"name":"accelerate","old_version":"1.14.0","new_version":"1.15.0","repository_url":"https://github.com/huggingface/accelerate"},{"name":"ty","old_version":"0.0.55","new_version":"0.0.80","repository_url":"https://github.com/astral-sh/ty"},{"name":"ruff","old_version":"0.15.20","new_version":"0.16.7","repository_url":"https://github.com/astral-sh/ruff"}],"path":null,"ecosystem":"pip"},"body":"Bumps the minor-and-patch group with 14 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [uvicorn](https://github.com/Kludex/uvicorn) | `0.49.0` | `0.52.4` |\n| [pydantic](https://github.com/pydantic/pydantic) | `2.13.4` | `2.13.5` |\n| [python-dotenv](https://github.com/theskumar/python-dotenv) | `1.2.2` | `1.2.3` |\n| [tiktoken](https://github.com/openai/tiktoken) | `0.13.0` | `0.14.0` |\n| [pydantic-settings](https://github.com/pydantic/pydantic-settings) | `2.14.2` | `2.15.0` |\n| [aiohttp](https://github.com/aio-libs/aiohttp) | `3.14.1` | `3.14.3` |\n| [reportlab](https://www.reportlab.com/) | `5.0.0` | `5.0.1` |\n| [grpcio](https://github.com/grpc/grpc) | `1.81.1` | `1.83.1` |\n| [nvidia-riva-client](https://github.com/nvidia-riva/python-clients) | `2.26.0` | `2.27.0` |\n| [torch](https://github.com/pytorch/pytorch) | `2.12.1+cu130` | `2.14.0` |\n| [transformers](https://github.com/huggingface/transformers) | `5.12.1` | `5.17.0` |\n| [accelerate](https://github.com/huggingface/accelerate) | `1.14.0` | `1.15.0` |\n| [ty](https://github.com/astral-sh/ty) | `0.0.55` | `0.0.80` |\n| [ruff](https://github.com/astral-sh/ruff) | `0.15.20` | `0.16.7` |\n\n\nUpdates `uvicorn` from 0.49.0 to 0.52.4\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/Kludex/uvicorn/releases\"\u003euvicorn's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eVersion 0.52.4\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eRemove duplicate \u003ccode\u003eDate\u003c/code\u003e headers from accepted WebSocket handshakes with \u003ccode\u003ewebsockets-sansio\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/3078\"\u003e#3078\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/Kludex/uvicorn/compare/0.52.3...0.52.4\"\u003ehttps://github.com/Kludex/uvicorn/compare/0.52.3...0.52.4\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eVersion 0.52.3\u003c/h2\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate \u003ccode\u003ezttp\u003c/code\u003e to 0.0.24 and use its combined receive path, improving HTTP/1.1 request parsing performance (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3067\"\u003e#3067\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/Kludex/uvicorn/compare/0.52.2...0.52.3\"\u003ehttps://github.com/Kludex/uvicorn/compare/0.52.2...0.52.3\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eVersion 0.52.2\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate \u003ccode\u003ezttp\u003c/code\u003e to 0.0.22, fixing bodyless request receives and improving HTTP/1 request parsing performance (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3063\"\u003e#3063\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/Kludex/uvicorn/compare/0.52.1...0.52.2\"\u003ehttps://github.com/Kludex/uvicorn/compare/0.52.1...0.52.2\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eVersion 0.52.1\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eComplete the closing handshake on server-initiated WebSocket closes in the \u003ccode\u003ewebsockets-sansio\u003c/code\u003e and \u003ccode\u003ewsproto\u003c/code\u003e implementations, waiting for the client's close reply with a 10 second timeout instead of resetting the connection (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3053\"\u003e#3053\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdd missing write flow control to the \u003ccode\u003ewebsockets-sansio\u003c/code\u003e implementation, preventing data truncation on server-initiated closes with large in-flight payloads (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3048\"\u003e#3048\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eHandle connection loss while a WebSocket write is waiting on backpressure (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3050\"\u003e#3050\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRemove duplicate \u003ccode\u003eContent-Type\u003c/code\u003e and \u003ccode\u003eContent-Length\u003c/code\u003e headers from WebSocket denial responses on the \u003ccode\u003ewebsockets-sansio\u003c/code\u003e implementation, and deliver non-UTF-8 denial bodies intact (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3041\"\u003e#3041\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/Kludex/uvicorn/compare/0.52.0...0.52.1\"\u003ehttps://github.com/Kludex/uvicorn/compare/0.52.0...0.52.1\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eVersion 0.52.0\u003c/h2\u003e\n\u003cp\u003eThis release adds an experimental HTTP/1.1 implementation backed by \u003ca href=\"https://zttp.marcelotryle.com/\"\u003ezttp\u003c/a\u003e, a sans-IO HTTP parser I've been developing on the side: a core written in Zig, with bindings to Python. It has been running under a fuzzer for some weeks now, and has been through multiple rounds of security auditing.\u003c/p\u003e\n\u003cp\u003eIt is still \u003cstrong\u003eexperimental\u003c/strong\u003e, so don't put it in front of production traffic yet. Try it with \u003ccode\u003e--http zttp\u003c/code\u003e, and please send any feedback to the \u003ca href=\"https://github.com/Kludex/uvicorn/issues\"\u003eissue tracker\u003c/a\u003e.\u003c/p\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdd an experimental \u003ccode\u003ezttp\u003c/code\u003e HTTP/1.1 implementation, selectable with \u003ccode\u003e--http zttp\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/2979\"\u003e#2979\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eKeep non-ASCII WebSocket request headers intact with websockets 17.0, which encodes them with ISO-8859-1 (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3036\"\u003e#3036\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/Kludex/uvicorn/compare/0.51.0...0.52.0\"\u003ehttps://github.com/Kludex/uvicorn/compare/0.51.0...0.52.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eVersion 0.51.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRestart workers with overlap on SIGHUP for near-zero-downtime reloads by \u003ca href=\"https://github.com/Kludex\"\u003e\u003ccode\u003e@​Kludex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/3025\"\u003eKludex/uvicorn#3025\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/Kludex/uvicorn/blob/main/docs/release-notes.md\"\u003euvicorn's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e0.52.4 (August 18, 2026)\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eRemove duplicate \u003ccode\u003eDate\u003c/code\u003e headers from accepted WebSocket handshakes with \u003ccode\u003ewebsockets-sansio\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/3078\"\u003e#3078\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e0.52.3 (August 13, 2026)\u003c/h2\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate \u003ccode\u003ezttp\u003c/code\u003e to 0.0.24 and use its combined receive path, improving HTTP/1.1 request parsing performance (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3067\"\u003e#3067\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e0.52.2 (August 13, 2026)\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate \u003ccode\u003ezttp\u003c/code\u003e to 0.0.22, fixing bodyless request receives and improving HTTP/1 request parsing performance (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3063\"\u003e#3063\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e0.52.1 (August 1, 2026)\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eComplete the closing handshake on server-initiated WebSocket closes in the \u003ccode\u003ewebsockets-sansio\u003c/code\u003e and \u003ccode\u003ewsproto\u003c/code\u003e implementations, waiting for the client's close reply with a 10 second timeout instead of resetting the connection (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3053\"\u003e#3053\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdd missing write flow control to the \u003ccode\u003ewebsockets-sansio\u003c/code\u003e implementation, preventing data truncation on server-initiated closes with large in-flight payloads (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3048\"\u003e#3048\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eHandle connection loss while a WebSocket write is waiting on backpressure (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3050\"\u003e#3050\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRemove duplicate \u003ccode\u003eContent-Type\u003c/code\u003e and \u003ccode\u003eContent-Length\u003c/code\u003e headers from WebSocket denial responses on the \u003ccode\u003ewebsockets-sansio\u003c/code\u003e implementation, and deliver non-UTF-8 denial bodies intact (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3041\"\u003e#3041\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e0.52.0 (July 29, 2026)\u003c/h2\u003e\n\u003cp\u003eThis release adds an experimental HTTP/1.1 implementation backed by \u003ca href=\"https://zttp.marcelotryle.com/\"\u003ezttp\u003c/a\u003e, a sans-IO HTTP parser I've been developing on the side: a core written in Zig, with bindings to Python. It has been running under a fuzzer for some weeks now, and has been through multiple rounds of security auditing.\u003c/p\u003e\n\u003cp\u003eIt is still \u003cstrong\u003eexperimental\u003c/strong\u003e, so don't put it in front of production traffic yet. Try it with \u003ccode\u003e--http zttp\u003c/code\u003e, and please send any feedback to the \u003ca href=\"https://github.com/Kludex/uvicorn/issues\"\u003eissue tracker\u003c/a\u003e.\u003c/p\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdd an experimental \u003ccode\u003ezttp\u003c/code\u003e HTTP/1.1 implementation, selectable with \u003ccode\u003e--http zttp\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/2979\"\u003e#2979\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eKeep non-ASCII WebSocket request headers intact with websockets 17.0, which encodes them with ISO-8859-1 (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3036\"\u003e#3036\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e0.51.0 (July 8, 2026)\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eRestart workers one at a time on \u003ccode\u003eSIGHUP\u003c/code\u003e, bringing each replacement up before retiring the old worker, so reloads no longer drop requests (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3025\"\u003e#3025\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eRemoved\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eRemove \u003ccode\u003ecolorama\u003c/code\u003e from the \u003ccode\u003estandard\u003c/code\u003e extra (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3027\"\u003e#3027\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/8988c23704fc373c9206cca53ec57dd8ad7f44a5\"\u003e\u003ccode\u003e8988c23\u003c/code\u003e\u003c/a\u003e Stabilize macOS Python 3.13 signal shutdown tests (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3084\"\u003e#3084\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/898ddca9254b53c5bf7a6ee509756704caaa949f\"\u003e\u003ccode\u003e898ddca\u003c/code\u003e\u003c/a\u003e Update PyPI publish action to version 1.14.2 (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3083\"\u003e#3083\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/3869f8aac2bdd040fa3fbe564e1dad67e2637641\"\u003e\u003ccode\u003e3869f8a\u003c/code\u003e\u003c/a\u003e Restore Mermaid diagram rendering (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3080\"\u003e#3080\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/64148a9c574e1eb87d3d09b3ce4c256606f8d973\"\u003e\u003ccode\u003e64148a9\u003c/code\u003e\u003c/a\u003e Version 0.52.4 (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3079\"\u003e#3079\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/9e9e5691bd14d5c4cd66d9bd76c7730bc48461a2\"\u003e\u003ccode\u003e9e9e569\u003c/code\u003e\u003c/a\u003e docs: correct release example PR number (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3072\"\u003e#3072\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/b783dacab50b9d6767b0cf65826b2dc3aae21909\"\u003e\u003ccode\u003eb783dac\u003c/code\u003e\u003c/a\u003e Remove duplicate Date header from SansIO WebSocket handshakes (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3078\"\u003e#3078\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/27019b2a4b1fa6d68a289fcf7d738fbdc6ee4e5d\"\u003e\u003ccode\u003e27019b2\u003c/code\u003e\u003c/a\u003e chore(deps): bump the python-packages group across 1 directory with 11 update...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/1b6427311bb84a15addee688f6d41d96e33f8b0a\"\u003e\u003ccode\u003e1b64273\u003c/code\u003e\u003c/a\u003e Fix a typo in index.md (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3006\"\u003e#3006\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/a68da608147c5f79d962352dce11de8f6e32d972\"\u003e\u003ccode\u003ea68da60\u003c/code\u003e\u003c/a\u003e Version 0.52.3 (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3068\"\u003e#3068\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/6e3bb4c5c22531c16d341f2da49f2653307f412f\"\u003e\u003ccode\u003e6e3bb4c\u003c/code\u003e\u003c/a\u003e Use zttp 0.0.24 fast receive path (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3067\"\u003e#3067\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/Kludex/uvicorn/compare/0.49.0...0.52.4\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `pydantic` from 2.13.4 to 2.13.5\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pydantic/pydantic/releases\"\u003epydantic's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.13.5 (2026-08-28)\u003c/h2\u003e\n\u003ch3\u003eWhat's Changed\u003c/h3\u003e\n\u003ch4\u003eFixes\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eAllow reuse of validators when plugins are set by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13535\"\u003e#13535\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix missing GC traversal on some \u003ccode\u003epydantic-core\u003c/code\u003e struct fields by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13624\"\u003e#13624\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix missing GC traversal in \u003ccode\u003epydantic-core\u003c/code\u003e for \u003ccode\u003eGeneralFieldsSerializer\u003c/code\u003e by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13629\"\u003e#13629\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eCount validated model fields once in smart unions by \u003ca href=\"https://github.com/tamird\"\u003e\u003ccode\u003e@​tamird\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13731\"\u003e#13731\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pydantic/pydantic/blob/v2.13.5/HISTORY.md\"\u003epydantic's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.13.5 (2026-08-28)\u003c/h2\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/pydantic/pydantic/releases/tag/v2.13.5\"\u003eGitHub release\u003c/a\u003e\u003c/p\u003e\n\u003ch3\u003eWhat's Changed\u003c/h3\u003e\n\u003ch4\u003eFixes\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eAllow reuse of validators when plugins are set by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13535\"\u003e#13535\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix missing GC traversal on some \u003ccode\u003epydantic-core\u003c/code\u003e struct fields by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13624\"\u003e#13624\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix missing GC traversal in \u003ccode\u003epydantic-core\u003c/code\u003e for \u003ccode\u003eGeneralFieldsSerializer\u003c/code\u003e by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13629\"\u003e#13629\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eCount validated model fields once in smart unions by \u003ca href=\"https://github.com/tamird\"\u003e\u003ccode\u003e@​tamird\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13731\"\u003e#13731\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/001dea020e0809844e5b17666432c9135a976f46\"\u003e\u003ccode\u003e001dea0\u003c/code\u003e\u003c/a\u003e Bump \u003ccode\u003epypa/gh-action-pypi-publish\u003c/code\u003e action to v1.14.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/558379fee957fad25858e33596146c72d5674843\"\u003e\u003ccode\u003e558379f\u003c/code\u003e\u003c/a\u003e Bump twine to v7.0.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/2cfd5d3d2ae721ea882c045f83b7f7a4003aab01\"\u003e\u003ccode\u003e2cfd5d3\u003c/code\u003e\u003c/a\u003e Do not check for docs build\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/a735bee5c64e1fe50785c376adaf1275e752b8ac\"\u003e\u003ccode\u003ea735bee\u003c/code\u003e\u003c/a\u003e Fix more Clippy lints\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/7eed4a16b87afaced4d0eafae230453de3410d64\"\u003e\u003ccode\u003e7eed4a1\u003c/code\u003e\u003c/a\u003e Fix Clippy 0.1.95 warnings\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/b353bbb20a4989b4c033e2be2b4a40d36178b16a\"\u003e\u003ccode\u003eb353bbb\u003c/code\u003e\u003c/a\u003e Prepare release v2.13.5\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/63d2cccd6e760da6bbc7fe81a53cb2bde3768f5e\"\u003e\u003ccode\u003e63d2ccc\u003c/code\u003e\u003c/a\u003e Count validated model fields once in smart unions\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/a53ec2ed342fda4e6aa3684399d04ea57be9a6e4\"\u003e\u003ccode\u003ea53ec2e\u003c/code\u003e\u003c/a\u003e Speed up PyPy CI tests\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/d65e0f96e890ca82f4b66a15d5b3bd65af2c661c\"\u003e\u003ccode\u003ed65e0f9\u003c/code\u003e\u003c/a\u003e Workaround circular import error in Mypy\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/47a6dbf8ad6216211bd0df6ec5c2c6c6ed905b72\"\u003e\u003ccode\u003e47a6dbf\u003c/code\u003e\u003c/a\u003e Fix missing GC traversal in \u003ccode\u003epydantic-core\u003c/code\u003e for \u003ccode\u003eGeneralFieldsSerializer\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/pydantic/pydantic/compare/v2.13.4...v2.13.5\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `python-dotenv` from 1.2.2 to 1.2.3\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/theskumar/python-dotenv/releases\"\u003epython-dotenv's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.2.3\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eStrip a leading UTF-8 BOM from \u003ccode\u003e.env\u003c/code\u003e file contents so the first variable is no longer silently lost when the file is saved with BOM (e.g. by some JetBrains IDEs on Windows) by [\u003ca href=\"https://github.com/h1whelan\"\u003e\u003ccode\u003e@​h1whelan\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/640\"\u003e#640\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eset_key\u003c/code\u003e now escapes backslashes, so values containing them (Windows paths, regular expressions) survive a write/read round-trip. Quoted values ending in an escaped backslash are no longer mis-parsed as an escaped quote, which used to swallow the following lines by [\u003ca href=\"https://github.com/dchaudhari7177\"\u003e\u003ccode\u003e@​dchaudhari7177\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/680\"\u003e#680\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003edotenv run\u003c/code\u003e now prints a friendly error instead of a traceback when no command is given by [\u003ca href=\"https://github.com/bbc2\"\u003e\u003ccode\u003e@​bbc2\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/606\"\u003e#606\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eCache the parsed result for empty \u003ccode\u003e.env\u003c/code\u003e files so repeated \u003ccode\u003edotenv_values\u003c/code\u003e/\u003ccode\u003eload_dotenv\u003c/code\u003e calls no longer re-read the file by [\u003ca href=\"https://github.com/ReinerBRO\"\u003e\u003ccode\u003e@​ReinerBRO\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/638\"\u003e#638\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/theskumar/python-dotenv/blob/main/CHANGELOG.md\"\u003epython-dotenv's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e[1.2.3] - 2026-08-16\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eStrip a leading UTF-8 BOM from \u003ccode\u003e.env\u003c/code\u003e file contents so the first variable is no longer silently lost when the file is saved with BOM (e.g. by some JetBrains IDEs on Windows) by [\u003ca href=\"https://github.com/h1whelan\"\u003e\u003ccode\u003e@​h1whelan\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/640\"\u003e#640\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eset_key\u003c/code\u003e now escapes backslashes, so values containing them (Windows paths, regular expressions) survive a write/read round-trip. Quoted values ending in an escaped backslash are no longer mis-parsed as an escaped quote, which used to swallow the following lines by [\u003ca href=\"https://github.com/dchaudhari7177\"\u003e\u003ccode\u003e@​dchaudhari7177\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/680\"\u003e#680\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003edotenv run\u003c/code\u003e now prints a friendly error instead of a traceback when no command is given by [\u003ca href=\"https://github.com/bbc2\"\u003e\u003ccode\u003e@​bbc2\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/606\"\u003e#606\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eCache the parsed result for empty \u003ccode\u003e.env\u003c/code\u003e files so repeated \u003ccode\u003edotenv_values\u003c/code\u003e/\u003ccode\u003eload_dotenv\u003c/code\u003e calls no longer re-read the file by [\u003ca href=\"https://github.com/ReinerBRO\"\u003e\u003ccode\u003e@​ReinerBRO\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/638\"\u003e#638\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/49515afee2d50c33cad9419b3800b3a0dc93fc59\"\u003e\u003ccode\u003e49515af\u003c/code\u003e\u003c/a\u003e Bump version: 1.2.2 → 1.2.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/8ac846ff2760b65470e769d7eed33e540f0934e1\"\u003e\u003ccode\u003e8ac846f\u003c/code\u003e\u003c/a\u003e chore: add release runbook (RELEASING.md) and make release target\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/bb31c944fb4b40e8dea59587f525840c38326166\"\u003e\u003ccode\u003ebb31c94\u003c/code\u003e\u003c/a\u003e docs: add 1.2.3 release notes (\u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/606\"\u003e#606\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/638\"\u003e#638\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/680\"\u003e#680\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/f7b18d9c72d1abcc2ad4023424b84f5bee30d266\"\u003e\u003ccode\u003ef7b18d9\u003c/code\u003e\u003c/a\u003e fix: round-trip backslashes through set_key (\u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/680\"\u003e#680\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/751f8c148222e58aa173c83c4e5e6cfccb2cc124\"\u003e\u003ccode\u003e751f8c1\u003c/code\u003e\u003c/a\u003e ci(deps): bump actions/checkout from 6.0.2 to 6.0.3 in the github-actions gro...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/f1937b68f338d7ebd7754da377ca08b2f0df8dbb\"\u003e\u003ccode\u003ef1937b6\u003c/code\u003e\u003c/a\u003e chore(deps): update mkdocs-include-markdown-plugin requirement from \u0026gt;=6.0.0 t...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/45b93720dd5e9e127d0be3971a04855d34e464d8\"\u003e\u003ccode\u003e45b9372\u003c/code\u003e\u003c/a\u003e chore(deps): update pytest requirement from \u0026gt;=3.9 to \u0026gt;=9.0.3 (\u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/653\"\u003e#653\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/72896e9244d2a1ff8d5e1934d3df8a35c813799a\"\u003e\u003ccode\u003e72896e9\u003c/code\u003e\u003c/a\u003e docs: fix broken mkdocs link in CONTRIBUTING.md (\u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/636\"\u003e#636\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/72754a16a4743e4c92edf87ce59ba0e4ff78758d\"\u003e\u003ccode\u003e72754a1\u003c/code\u003e\u003c/a\u003e ci(deps): bump peaceiris/actions-gh-pages from 4.0.0 to 4.1.0 in the github-a...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/078325e92558330e9addc661b789c7b6123fa73c\"\u003e\u003ccode\u003e078325e\u003c/code\u003e\u003c/a\u003e ci(security): harden CI/CD supply chain with SHA pinning and least-privilege ...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/theskumar/python-dotenv/compare/v1.2.2...v1.2.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `tiktoken` from 0.13.0 to 0.14.0\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/openai/tiktoken/blob/main/CHANGELOG.md\"\u003etiktoken's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e[v0.14.0]\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBuild wheels for Python 3.15\u003c/li\u003e\n\u003cli\u003eSupport looking up more GPT-5 series models\u003c/li\u003e\n\u003cli\u003eUpgrade dependencies\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/openai/tiktoken/commit/4e71bbe0c078468e00fefbf94b39849389f346e5\"\u003e\u003ccode\u003e4e71bbe\u003c/code\u003e\u003c/a\u003e Release 0.14.0 (\u003ca href=\"https://redirect.github.com/openai/tiktoken/issues/597\"\u003e#597\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/openai/tiktoken/commit/212b893ba940cba53476851103d2e5c1d0020c6e\"\u003e\u003ccode\u003e212b893\u003c/code\u003e\u003c/a\u003e Fail open for GPT-5 model tokenisers (\u003ca href=\"https://redirect.github.com/openai/tiktoken/issues/596\"\u003e#596\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/openai/tiktoken/commit/4187ba33e48b7c554de02c17149ff0c5e50ddf38\"\u003e\u003ccode\u003e4187ba3\u003c/code\u003e\u003c/a\u003e Upgrade dependencies (\u003ca href=\"https://redirect.github.com/openai/tiktoken/issues/595\"\u003e#595\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/openai/tiktoken/commit/92a82552fc5d046839f83e3505a6d9b002208ac2\"\u003e\u003ccode\u003e92a8255\u003c/code\u003e\u003c/a\u003e Remove test-skip comment for macOS arm64 (\u003ca href=\"https://redirect.github.com/openai/tiktoken/issues/562\"\u003e#562\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/openai/tiktoken/commit/674f5e65caad92c2b17f944fbdc4256fea32890e\"\u003e\u003ccode\u003e674f5e6\u003c/code\u003e\u003c/a\u003e Build Python 3.15 (\u003ca href=\"https://redirect.github.com/openai/tiktoken/issues/594\"\u003e#594\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/openai/tiktoken/commit/dbea866194b3c7d496a029c8faf9ad238064a992\"\u003e\u003ccode\u003edbea866\u003c/code\u003e\u003c/a\u003e Remove deprecated freethreading build\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/openai/tiktoken/commit/f6782242d03134d18b9a551845fd7d69fd23106e\"\u003e\u003ccode\u003ef678224\u003c/code\u003e\u003c/a\u003e Update cibuildwheel\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/openai/tiktoken/commit/08a5f3b2c987ada4fc5aa1f16c643c203fa8acaa\"\u003e\u003ccode\u003e08a5f3b\u003c/code\u003e\u003c/a\u003e ci: use static artifact name for sdist build job (\u003ca href=\"https://redirect.github.com/openai/tiktoken/issues/535\"\u003e#535\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/openai/tiktoken/compare/0.13.0...0.14.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `pydantic-settings` from 2.14.2 to 2.15.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pydantic/pydantic-settings/releases\"\u003epydantic-settings's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.15.0\u003c/h2\u003e\n\u003ch2\u003eHighlights\u003c/h2\u003e\n\u003ch3\u003eBehavior changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ccode\u003ecase_sensitive\u003c/code\u003e now applies to init kwargs and config-file sources\u003c/strong\u003e (\u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/900\"\u003e#900\u003c/a\u003e). \u003ccode\u003eInitSettingsSource\u003c/code\u003e and the JSON/TOML/YAML config sources previously ignored \u003ccode\u003ecase_sensitive\u003c/code\u003e. Since it defaults to \u003ccode\u003eFalse\u003c/code\u003e, \u003cstrong\u003ecase-insensitive matching is now the default\u003c/strong\u003e for these sources — e.g. \u003ccode\u003eSettings(TeSt=...)\u003c/code\u003e now populates a \u003ccode\u003etest\u003c/code\u003e field where it previously did not. Nested keys are still matched case-sensitively.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eFields with unresolved forward references now emit a warning\u003c/strong\u003e (\u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/901\"\u003e#901\u003c/a\u003e). Settings sources can silently fail to resolve such fields; they now raise \u003ccode\u003eIncompleteFieldDefinitionWarning\u003c/code\u003e telling you to call \u003ccode\u003emodel_rebuild()\u003c/code\u003e. If you have \u003ccode\u003efilterwarnings = error\u003c/code\u003e configured, this may surface as a new failure.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eNon-JSON env values for strict fields now raise \u003ccode\u003eValidationError\u003c/code\u003e\u003c/strong\u003e (\u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/926\"\u003e#926\u003c/a\u003e) instead of a less specific error.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eNew features\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eShow environment variable names in CLI help\u003c/strong\u003e via \u003ccode\u003ecli_show_env_vars=True\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/860\"\u003e#860\u003c/a\u003e), so generated \u003ccode\u003e--help\u003c/code\u003e output doubles as configuration documentation.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ccode\u003ePYDANTIC_SETTINGS_DEBUG\u003c/code\u003e for debugging settings resolution\u003c/strong\u003e (\u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/906\"\u003e#906\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/913\"\u003e#913\u003c/a\u003e). Set it to a truthy value with \u003ccode\u003eDEBUG\u003c/code\u003e logging enabled to see each source's contribution in priority order, which source won for each value, and which \u003ccode\u003eenv_file\u003c/code\u003e/secret files were probed, loaded, or skipped — the long-standing \u0026quot;why isn't my \u003ccode\u003e.env\u003c/code\u003e being picked up?\u0026quot; question.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ccode\u003etoml_table_header\u003c/code\u003e for regular TOML files\u003c/strong\u003e (\u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/882\"\u003e#882\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/886\"\u003e#886\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/887\"\u003e#887\u003c/a\u003e), letting you root settings at a nested table in any TOML file, not just \u003ccode\u003epyproject.toml\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ccode\u003eTraversable\u003c/code\u003e support for JSON/TOML/YAML file sources\u003c/strong\u003e (\u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/902\"\u003e#902\u003c/a\u003e), so you can load config packaged inside a distribution — including files inside a zip or wheel — via \u003ccode\u003eimportlib.resources.files(...)\u003c/code\u003e without casting to \u003ccode\u003ePath\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eGCP: \u003ccode\u003eproject_id\u003c/code\u003e can come from an earlier settings source\u003c/strong\u003e (\u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/878\"\u003e#878\u003c/a\u003e), rather than only from the constructor or \u003ccode\u003eGOOGLE_CLOUD_PROJECT\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBug fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFix env vars not loading on Windows with \u003ccode\u003ecase_sensitive=True\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/894\"\u003e#894\u003c/a\u003e). Windows upper-cases \u003ccode\u003eos.environ\u003c/code\u003e keys, so fields raised \u003ccode\u003eField required\u003c/code\u003e instead of picking up their values.\u003c/li\u003e\n\u003cli\u003eRead secret files as UTF-8 instead of the platform locale encoding (\u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/917\"\u003e#917\u003c/a\u003e). On Windows code pages such as cp1252 this silently corrupted non-ASCII secrets.\u003c/li\u003e\n\u003cli\u003eFix \u003ccode\u003eAliasPath\u003c/code\u003e on nested model fields not JSON-decoding env values (\u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/898\"\u003e#898\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFix case-insensitive matching for \u003cstrong\u003eoptional\u003c/strong\u003e nested models (\u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/905\"\u003e#905\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFix dotenv extras being wrongly claimed by a complex field sharing a name prefix (\u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/912\"\u003e#912\u003c/a\u003e) — e.g. \u003ccode\u003edbx_token\u003c/code\u003e being swallowed by a \u003ccode\u003edb: dict\u003c/code\u003e field.\u003c/li\u003e\n\u003cli\u003eFix \u003ccode\u003enested_model_default_partial_update=True\u003c/code\u003e corrupting discriminated unions (\u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/876\"\u003e#876\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFix \u003ccode\u003eSecret\u003c/code\u003e subclasses crashing when loaded from the environment (\u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/920\"\u003e#920\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFix enum names not parsing through nested annotations such as \u003ccode\u003eOptional[Annotated[MyEnum, ...]]\u003c/code\u003e with \u003ccode\u003eenv_parse_enums=True\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/910\"\u003e#910\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eAn empty \u003ccode\u003eyaml_config_section\u003c/code\u003e now falls back to defaults instead of raising \u003ccode\u003eAttributeError: 'NoneType' object has no attribute 'keys'\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/914\"\u003e#914\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eNestedSecretsSettingsSource\u003c/code\u003e no longer follows symlinks pointing outside \u003ccode\u003esecrets_dir\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/889\"\u003e#889\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eGCP: skip the \u003ccode\u003elist_secrets\u003c/code\u003e call when \u003ccode\u003ecase_sensitive=True\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/862\"\u003e#862\u003c/a\u003e), lowering the required IAM permissions to just \u003ccode\u003eroles/secretmanager.secretAccessor\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eAWS: \u003ccode\u003etypes-boto3[secretsmanager]\u003c/code\u003e is no longer required at runtime (\u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/880\"\u003e#880\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDocumentation\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eDocument JSON parsing of complex env values, plus a comma-separated-values recipe (\u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/919\"\u003e#919\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eRecommend an async settings loading pattern (\u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/908\"\u003e#908\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eClarify behavior when an unprefixed value is present in a dotenv file (\u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/895\"\u003e#895\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eClarify environment variable helper descriptions (\u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/867\"\u003e#867\u003c/a\u003e) and fix assorted typos (\u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/904\"\u003e#904\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate documentation link for Pydantic settings by \u003ca href=\"https://github.com/hramezani\"\u003e\u003ccode\u003e@​hramezani\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/863\"\u003epydantic/pydantic-settings#863\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump the python-packages group with 4 updates by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/865\"\u003epydantic/pydantic-settings#865\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003edocs: clarify environment variable helper descriptions by \u003ca href=\"https://github.com/vip892766gma\"\u003e\u003ccode\u003e@​vip892766gma\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/867\"\u003epydantic/pydantic-settings#867\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump the python-packages group with 4 updates by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/870\"\u003epydantic/pydantic-settings#870\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump the python-packages group with 4 updates by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/875\"\u003epydantic/pydantic-settings#875\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSkip list_secrets call when case_sensitive=True by \u003ca href=\"https://github.com/ecerulm\"\u003e\u003ccode\u003e@​ecerulm\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/862\"\u003epydantic/pydantic-settings#862\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eGoogleSecretManagerSettingsSource: read project_id from previous sources by \u003ca href=\"https://github.com/ecerulm\"\u003e\u003ccode\u003e@​ecerulm\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/878\"\u003epydantic/pydantic-settings#878\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic-settings/commit/f725ca187bee4212e9ef799eefa3cb25be788462\"\u003e\u003ccode\u003ef725ca1\u003c/code\u003e\u003c/a\u003e Prepare release 2.15.0 (\u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/issues/930\"\u003e#930\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic-settings/commit/28f35c25fac5d61210d532c31a300d49c0b684a4\"\u003e\u003ccode\u003e28f35c2\u003c/code\u003e\u003c/a\u003e Bump the python-packages group with 4 updates (\u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/issues/929\"\u003e#929\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic-settings/commit/9056db049560897229f2603493753bae27b6479f\"\u003e\u003ccode\u003e9056db0\u003c/code\u003e\u003c/a\u003e test: move function-local imports to the top of test modules (\u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/issues/927\"\u003e#927\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic-settings/commit/f077e3ab3d9492838c7ef9275a88c95134688095\"\u003e\u003ccode\u003ef077e3a\u003c/code\u003e\u003c/a\u003e fix: raise ValidationError for non-JSON env values on strict fields (\u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/issues/926\"\u003e#926\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic-settings/commit/ae25d703c458b57f5a9a425f6ec9a28ad868f980\"\u003e\u003ccode\u003eae25d70\u003c/code\u003e\u003c/a\u003e fix: treat Secret subclasses as non-complex fields (\u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/issues/716\"\u003e#716\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/issues/920\"\u003e#920\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic-settings/commit/798dcea2a23b08a3e9b37994014e036224f6dd18\"\u003e\u003ccode\u003e798dcea\u003c/code\u003e\u003c/a\u003e Bump the python-packages group with 4 updates (\u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/issues/924\"\u003e#924\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic-settings/commit/a190041d353bda2d432ea1908de4c499ae89ee0a\"\u003e\u003ccode\u003ea190041\u003c/code\u003e\u003c/a\u003e Bump the github-actions group with 4 updates (\u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/issues/925\"\u003e#925\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic-settings/commit/5d9333282b5c85d65a457c45e4476369b9949726\"\u003e\u003ccode\u003e5d93332\u003c/code\u003e\u003c/a\u003e Bump the python-packages group with 4 updates (\u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/issues/921\"\u003e#921\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic-settings/commit/d2fdeda91157140d2ff0c05404f32a9b1218115a\"\u003e\u003ccode\u003ed2fdeda\u003c/code\u003e\u003c/a\u003e fix: read secret files as UTF-8 instead of the locale encoding (\u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/issues/917\"\u003e#917\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic-settings/commit/2256a4e60f83f2da81e7654252562fc4841aa5d4\"\u003e\u003ccode\u003e2256a4e\u003c/code\u003e\u003c/a\u003e Bump the python-packages group with 3 updates (\u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/issues/915\"\u003e#915\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/pydantic/pydantic-settings/compare/v2.14.2...v2.15.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `aiohttp` from 3.14.1 to 3.14.3\nUpdates `reportlab` from 5.0.0 to 5.0.1\n\nUpdates `grpcio` from 1.81.1 to 1.83.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/grpc/grpc/releases\"\u003egrpcio's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eRelease v1.83.1\u003c/h2\u003e\n\u003cp\u003eThis is release gRPC Core 1.83.1 (garden).\u003c/p\u003e\n\u003cp\u003eFor gRPC documentation, see \u003ca href=\"https://grpc.io/\"\u003egrpc.io\u003c/a\u003e. For previous releases, see \u003ca href=\"https://github.com/grpc/grpc/releases\"\u003eReleases\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003eThis release contains refinements, improvements, and bug fixes.\u003c/p\u003e\n\u003ch2\u003eRelease v1.83.0\u003c/h2\u003e\n\u003cp\u003eThis is release 1.83.0 (\u003ca href=\"https://github.com/grpc/grpc/blob/master/doc/g_stands_for.md\"\u003egarden\u003c/a\u003e) of gRPC Core.\u003c/p\u003e\n\u003cp\u003eFor gRPC documentation, see \u003ca href=\"https://grpc.io/\"\u003egrpc.io\u003c/a\u003e. For previous releases, see \u003ca href=\"https://github.com/grpc/grpc/releases\"\u003eReleases\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003eThis release contains refinements, improvements, and bug fixes, with highlights listed below.\u003c/p\u003e\n\u003ch2\u003eCore\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e[Security] Default to Post-Quantum Cryptography in TLS key exchange. (\u003ca href=\"https://redirect.github.com/grpc/grpc/pull/42560\"\u003e#42560\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[authz] don't pass RBAC policy by value when constructing authorization engine. (\u003ca href=\"https://redirect.github.com/grpc/grpc/pull/42636\"\u003e#42636\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eC#\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMigrate CSharp Grpc.Tools to new DotNet Version. (\u003ca href=\"https://redirect.github.com/grpc/grpc/pull/42661\"\u003e#42661\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[C#] Tools - Build: Fix protoc SIGSEGV on ARM64 by aligning max-page-size and migrating to manylinux_2_28. (\u003ca href=\"https://redirect.github.com/grpc/grpc/pull/42590\"\u003e#42590\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ePython\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e[Backport][v1.83.x][Python] grpc-status: Relax protobuf dependency lower bound to allow 6.x. (\u003ca href=\"https://redirect.github.com/grpc/grpc/pull/43001\"\u003e#43001\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[Python] Add abort_with_status to the aio ServicerContext ABC. (\u003ca href=\"https://redirect.github.com/grpc/grpc/pull/42733\"\u003e#42733\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[Python] Update lower bound for protobuf from 6.33.5 to 7.35.1. (\u003ca href=\"https://redirect.github.com/grpc/grpc/pull/42914\"\u003e#42914\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[Python] Pyright typeCheckingMode - standard. (\u003ca href=\"https://redirect.github.com/grpc/grpc/pull/42739\"\u003e#42739\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[Python] Support Python 3.15 - Upgrade bazel dep rules_python to 2.0.2. (\u003ca href=\"https://redirect.github.com/grpc/grpc/pull/42637\"\u003e#42637\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[Python] Hide internal symbols from Python's \u003ccode\u003ecygrpc\u003c/code\u003e shared object. (\u003ca href=\"https://redirect.github.com/grpc/grpc/pull/42325\"\u003e#42325\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[Python] Handle custom Interceptor exceptions in InterceptedCall APIs . (\u003ca href=\"https://redirect.github.com/grpc/grpc/pull/42593\"\u003e#42593\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eRelease v1.83.0-pre1\u003c/h2\u003e\n\u003cp\u003eThis is a prerelease of gRPC Core 1.83.0 (garden).\u003c/p\u003e\n\u003cp\u003eFor gRPC documentation, see \u003ca href=\"https://grpc.io/\"\u003egrpc.io\u003c/a\u003e. For previous releases, see \u003ca href=\"https://github.com/grpc/grpc/releases\"\u003eReleases\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003eThis prerelease contains refinements, improvements, and bug fixes.\u003c/p\u003e\n\u003ch2\u003eRelease v1.82.2\u003c/h2\u003e\n\u003cp\u003eThis is release gRPC Core 1.82.2 (glacier).\u003c/p\u003e\n\u003cp\u003eFor gRPC documentation, see \u003ca href=\"https://grpc.io/\"\u003egrpc.io\u003c/a\u003e. For previous releases, see \u003ca href=\"https://github.com/grpc/grpc/releases\"\u003eReleases\u003c/a\u003e.\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/grpc/grpc/commit/aae267021b1ac256f8b9038d0ef528c3798cc137\"\u003e\u003ccode\u003eaae2670\u003c/code\u003e\u003c/a\u003e [Backport][v1.83.x] Fix legacy_channel.cc compile error with `std::optional\u0026lt;a...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/grpc/grpc/commit/b77ea3602cccdc92071942d6d9731d99dff3d8d4\"\u003e\u003ccode\u003eb77ea36\u003c/code\u003e\u003c/a\u003e [Backport][v1.83.x] Memory optimization (\u003ca href=\"https://redirect.github.com/grpc/grpc/issues/43297\"\u003e#43297\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/grpc/grpc/commit/9dcd5aaed80912634d360915480198c3a9305942\"\u003e\u003ccode\u003e9dcd5aa\u003c/code\u003e\u003c/a\u003e [CI] Fix Python 3.15 Sanity (\u003ca href=\"https://redirect.github.com/grpc/grpc/issues/43299\"\u003e#43299\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/grpc/grpc/commit/ed8899e28f7e00214988b2dbe283dfc9b6a0b6a8\"\u003e\u003ccode\u003eed8899e\u003c/code\u003e\u003c/a\u003e [Backport][v1.83.x]  Fixing bug in GoAway and gRPC Message Compression (\u003ca href=\"https://redirect.github.com/grpc/grpc/issues/43270\"\u003e#43270\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/grpc/grpc/commit/5f8d6dff1b8c99de5ebc5cc36530a78464b20dfa\"\u003e\u003ccode\u003e5f8d6df\u003c/code\u003e\u003c/a\u003e [Release] Bump version to 1.83.1 (on v1.83.x branch) (\u003ca href=\"https://redirect.github.com/grpc/grpc/issues/43274\"\u003e#43274\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/grpc/grpc/commit/291e0be51f7a637da0d107f4f56ccfcf8ed0c37d\"\u003e\u003ccode\u003e291e0be\u003c/code\u003e\u003c/a\u003e [Backport][v1.83.x][Python] Fix the StatusCode Enums to be int (\u003ca href=\"https://redirect.github.com/grpc/grpc/issues/43252\"\u003e#43252\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/grpc/grpc/commit/05ceb5d3595e6d907ef713658ae050504d5e8965\"\u003e\u003ccode\u003e05ceb5d\u003c/code\u003e\u003c/a\u003e [CI][Backport][v1.83.x][Python] Fix PSM Interop xds-v3 Python continuous fail...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/grpc/grpc/commit/dbc73b8a0d7db0df335067b2892a16b09f0da3fa\"\u003e\u003ccode\u003edbc73b8\u003c/code\u003e\u003c/a\u003e [Backport][v1.83.x][PHP]updated workflow to preserve github folder (\u003ca href=\"https://redirect.github.com/grpc/grpc/issues/43243\"\u003e#43243\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/grpc/grpc/commit/c876f4da50f7da2f331888b88b2a7243514139fe\"\u003e\u003ccode\u003ec876f4d\u003c/code\u003e\u003c/a\u003e [Release] Bump version to 1.83.0 (on v1.83.x branch) (\u003ca href=\"https://redirect.github.com/grpc/grpc/issues/43036\"\u003e#43036\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/grpc/grpc/commit/b5c40cd49e0734dbc4078ec3fd8b9d20c2d3c5bc\"\u003e\u003ccode\u003eb5c40cd\u003c/code\u003e\u003c/a\u003e [Backport][v1.83.x][Python] grpc-status: Relax protobuf dependency lower boun...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/grpc/grpc/compare/v1.81.1...v1.83.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `nvidia-riva-client` from 2.26.0 to 2.27.0\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/nvidia-riva/python-clients/commits\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `torch` from 2.12.1+cu130 to 2.14.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pytorch/pytorch/releases\"\u003etorch's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003ePyTorch 2.14.0 Release Notes\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/blob/HEAD/#highlights\"\u003eHighlights\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/blob/HEAD/#backwards-incompatible-changes\"\u003eBackwards Incompatible Changes\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/blob/HEAD/#deprecations\"\u003eDeprecations\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/blob/HEAD/#new-features\"\u003eNew Features\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/blob/HEAD/#improvements\"\u003eImprovements\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/blob/HEAD/#bug-fixes\"\u003eBug fixes\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/blob/HEAD/#performance\"\u003ePerformance\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/blob/HEAD/#documentation\"\u003eDocumentation\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/blob/HEAD/#security\"\u003eSecurity\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/blob/HEAD/#developers\"\u003eDevelopers\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch1\u003eHighlights\u003c/h1\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cp\u003eFor more details about these highlighted features, you can look at the release blogpost. Below are the full release notes for this release.\u003c/p\u003e\n\u003ch1\u003eBackwards Incompatible Changes\u003c/h1\u003e\n\u003ch2\u003etorch.nn\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ccode\u003etorch.nn.LinearCrossEntropyOptions\u003c/code\u003e no longer accepts \u003ccode\u003eacc_policy=\u0026quot;balanced\u0026quot;\u003c/code\u003e; use \u003ccode\u003e\u0026quot;compact\u0026quot;\u003c/code\u003e instead (\u003ca href=\"https://redirect.github.com/pytorch/pytorch/issues/188283\"\u003e#188283\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eThe \u003ccode\u003e\u0026quot;balanced\u0026quot;\u003c/code\u003e policy was removed because \u003ccode\u003e\u0026quot;compact\u0026quot;\u003c/code\u003e provides the same weight-gradient accumulation precision with lower memory use on CUDA, already uses the equivalent scratch layout for mixed-precision inputs on other devices, and was never selected by \u003ccode\u003e\u0026quot;auto\u0026quot;\u003c/code\u003e. Constructing the options with \u003ccode\u003eacc_policy=\u0026quot;balanced\u0026quot;\u003c/code\u003e now raises \u003ccode\u003eValueError: invalid acc_policy: 'balanced'; expected one of 'auto', 'accurate', 'compact'\u003c/code\u003e.\u003c/p\u003e\n\u003cp\u003eBefore:\u003c/p\u003e\n\u003cpre lang=\"python\"\u003e\u003ccode\u003eoptions = torch.nn.LinearCrossEntropyOptions(acc_policy=\u0026quot;balanced\u0026quot;)\r\nloss = torch.nn.functional.linear_cross_entropy(\r\n    input, linear_weight, target, options=options\r\n)\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eAfter:\u003c/p\u003e\n\u003cpre lang=\"python\"\u003e\u003ccode\u003eoptions = torch.nn.LinearCrossEntropyOptions(acc_policy=\u0026quot;compact\u0026quot;)\r\nloss = torch.nn.functional.linear_cross_entropy(\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/pytorch/pytorch/commits/v2.14.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `transformers` from 5.12.1 to 5.17.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/huggingface/transformers/releases\"\u003etransformers's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eRelease 5.17.0\u003c/h2\u003e\n\u003ch1\u003eRelease v5.17.0\u003c/h1\u003e\n\u003ch2\u003eNew Model additions\u003c/h2\u003e\n\u003ch3\u003eHYV4\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cp\u003eHy4-Preview is a 780B-parameter mixture-of-experts language model that activates 49B parameters per\ntoken. Each MoE layer holds 256 routed experts plus one always-active shared expert and routes every\ntoken to 8 of them. The context window is 1M tokens.\u003c/p\u003e\n\u003cp\u003eThe architecture combines four features:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eMulti-head Latent Attention (MLA)\u003c/strong\u003e compresses keys and values into a low-rank latent\n(\u003ccode\u003ekv_lora_rank\u003c/code\u003e) that \u003ccode\u003ekv_b_proj\u003c/code\u003e expands back to one key/value per query head.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eDeepSeek Sparse Attention (DSA)\u003c/strong\u003e selects \u003ccode\u003eindex_topk\u003c/code\u003e keys per query with a lightweight indexer.\nFollowing \u003ca href=\"https://huggingface.co/papers/2603.12201\"\u003eIndexShare\u003c/a\u003e, only the layers marked \u003ccode\u003e\u0026quot;full\u0026quot;\u003c/code\u003e\nin \u003ccode\u003eindexer_types\u003c/code\u003e run an indexer; \u003ccode\u003e\u0026quot;shared\u0026quot;\u003c/code\u003e layers reuse the previous full layer's selection.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eGated MLA with learnable attention sinks\u003c/strong\u003e, where each head owns a sink logit that participates\nin the softmax and contributes no value, as in \u003ca href=\"https://github.com/huggingface/transformers/blob/HEAD/gpt_oss\"\u003eGPT-OSS\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eIndependent Hyper-Connections (iHC)\u003c/strong\u003e replace the plain residual path with \u003ccode\u003ehc_mult\u003c/code\u003e parallel\nresidual streams that are collapsed before, and redistributed after, every sublayer.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThe implementation does not execute the multi-token prediction (MTP) layers. Released checkpoints\nkeep those weights so that other runtimes can use them for speculative decoding; they are ignored\nat load time.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/hy_v4\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAdd h4 (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48473\"\u003e#48473\u003c/a\u003e) by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/transformers/pull/48473\"\u003e#48473\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eVibeVoice\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cp\u003e\u003ca href=\"https://huggingface.co/papers/2508.19205\"\u003eVibeVoice\u003c/a\u003e is a novel framework for synthesizing high-fidelity, long-form speech with multiple speakers by employing a next-token diffusion approach within a Large Language Model (LLM) structure. It's designed to capture the authentic conversational \u0026quot;vibe\u0026quot; and is particularly suited for generating audio content like podcasts and multi-participant audiobooks.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/vibevoice\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eImplement VibeVoice  (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/40546\"\u003e#40546\u003c/a\u003e) by \u003ca href=\"https://github.com/pengzhiliang\"\u003e\u003ccode\u003e@​pengzhiliang\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/transformers/pull/40546\"\u003e#40546\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eNeoMME\u003c/h3\u003e\n\u003cp\u003eNeoMME is a family of efficient 260M and 800M parameter multimodal-native multilingual foundation encoders from H Company. It processes multilingual text tokens and raw image patches in a single bidirectional Transformer encoder, without a separately pretrained vision tower or causal language model.\u003c/p\u003e\n\u003cp\u003eNeoMME-Retriever is a model fine-tuned from the NeoMME backbone for visual document retrieval with joint late-interaction and dense objectives. It takes text queries and documents (text or page screenshots) and produces multi-vector embeddings for MeanMaxSim scoring (late-interaction) and mean-pooled embeddings for cosine similarity (dense).\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/neomme\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/856157a2f3e9594954310df18fdccc31ffddebe9\"\u003e\u003ccode\u003e856157a\u003c/code\u003e\u003c/a\u003e v5.17.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/5b7dcb0d36c242d8d85920a81c564ef3a86ca6dd\"\u003e\u003ccode\u003e5b7dcb0\u003c/code\u003e\u003c/a\u003e MRoPE continued (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48594\"\u003e#48594\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/50bbcc630ed1675d15d2def3877c88d6c2630415\"\u003e\u003ccode\u003e50bbcc6\u003c/code\u003e\u003c/a\u003e [fix] Update stale expected strings in HunYuanVL integration tests (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48646\"\u003e#48646\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/e8bcd79c4c77a529bc34d6e19f7d718164b7fa6a\"\u003e\u003ccode\u003ee8bcd79\u003c/code\u003e\u003c/a\u003e [Quantizaiton]support 5/6/7 bits in AutoRound (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48481\"\u003e#48481\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/3283d5f78ed6836d39430c8190a6e0500be78698\"\u003e\u003ccode\u003e3283d5f\u003c/code\u003e\u003c/a\u003e [fix] Update stale golden values and fix expected_logits shape in FlavaForPre...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/5f47b5aad791b69dff597b903614fb2bef8b88a1\"\u003e\u003ccode\u003e5f47b5a\u003c/code\u003e\u003c/a\u003e [tests] Fix integration test golden values broken by fast image processor def...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/fc501343edfccdc840eb8594a6cafa8185c2de53\"\u003e\u003ccode\u003efc50134\u003c/code\u003e\u003c/a\u003e Add Fun-ASR-Nano model (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46180\"\u003e#46180\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/d9fe823d1cedbba33dd0aeef08f773abe971688e\"\u003e\u003ccode\u003ed9fe823\u003c/code\u003e\u003c/a\u003e Fix YOLOS device mismatch with device_map=\u0026quot;auto\u0026quot; (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46886\"\u003e#46886\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/cbc1651a032b923da7f4b44b3d0e6f68e6ba6b55\"\u003e\u003ccode\u003ecbc1651\u003c/code\u003e\u003c/a\u003e [\u003ccode\u003eGenerate\u003c/code\u003e] Avoid unconditionally downloading remote hub file (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48620\"\u003e#48620\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/bd05a4b2baf8b37b8f64c0c2c70d2628583f7c2a\"\u003e\u003ccode\u003ebd05a4b\u003c/code\u003e\u003c/a\u003e Honor \u003ccode\u003eshift_labels\u003c/code\u003e in decoder-only LLM/VLM losses (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48493\"\u003e#48493\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/huggingface/transformers/compare/v5.12.1...v5.17.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `accelerate` from 1.14.0 to 1.15.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/huggingface/accelerate/releases\"\u003eaccelerate's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003ev1.15.0: FSDP2 activation memory, dtensor improvements\u003c/h1\u003e\n\u003ch2\u003eFSDP2\u003c/h2\u003e\n\u003cp\u003eA large batch of FSDP2 work this release: two fixes that cut activation memory at long sequence lengths, tied-embedding support on torch \u0026gt;= 2.13, and a round of checkpointing correctness and scale fixes.\u003c/p\u003e\n\u003cp\u003eActivation checkpointing was wrapping each \u003cem\u003echild\u003c/em\u003e of the matched layer (\u003ccode\u003eself_attn\u003c/code\u003e, \u003ccode\u003emlp\u003c/code\u003e, the norms) instead of the layer itself, so every inter-child activation stayed saved for backward. It now wraps the layer.\u003c/p\u003e\n\u003cp\u003eThere's also a new FSDP2-only \u003ccode\u003eactivation_checkpointing_offload\u003c/code\u003e, which moves the remaining per-layer checkpoint inputs to pinned CPU memory. Gradients are exactly those of plain activation checkpointing:\u003c/p\u003e\n\u003cpre lang=\"yaml\"\u003e\u003ccode\u003e# fsdp2.yaml\r\nfsdp_config:\r\n  fsdp_version: 2\r\n  fsdp_auto_wrap_policy: TRANSFORMER_BASED_WRAP\r\n  fsdp_activation_checkpointing: true\r\n  fsdp_activation_checkpointing_offload: true\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003cpre lang=\"bash\"\u003e\u003ccode\u003eaccelerate launch --config_file fsdp2.yaml train.py\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003cul\u003e\n\u003cli\u003eFSDP2 activation checkpointing: wrap the matched transformer layer itself, not each of its children by \u003ca href=\"https://github.com/qgallouedec\"\u003e\u003ccode\u003e@​qgallouedec\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4172\"\u003e#4172\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd FSDP2 \u003ccode\u003eactivation_checkpointing_offload\u003c/code\u003e: offload checkpointed layer inputs to pinned CPU memory by \u003ca href=\"https://github.com/qgallouedec\"\u003e\u003ccode\u003e@​qgallouedec\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4175\"\u003e#4175\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix FSDP2 tied-embedding models on torch \u0026gt;= 2.13: put the output embedding in the same fully_shard group by \u003ca href=\"https://github.com/qgallouedec\"\u003e\u003ccode\u003e@​qgallouedec\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4171\"\u003e#4171\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix FSDP2/PEFT/\u003ccode\u003eFULL_STATE_DICT\u003c/code\u003e dropping every rank's adapter shard except rank 0 by \u003ca href=\"https://github.com/AmineDiro\"\u003e\u003ccode\u003e@​AmineDiro\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4206\"\u003e#4206\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFSDP2: per-rank torch.save/load for SHARDED_STATE_DICT to fix 2800+ NPU checkpoint timeout by \u003ca href=\"https://github.com/gygdh-001\"\u003e\u003ccode\u003e@​gygdh-001\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4105\"\u003e#4105\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix FSDP sharded checkpoint path resolution by \u003ca href=\"https://github.com/HaomingSong\"\u003e\u003ccode\u003e@​HaomingSong\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4119\"\u003e#4119\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRaise a clear error when FSDP is enabled on a mesh with no shard dimension by \u003ca href=\"https://github.com/qgallouedec\"\u003e\u003ccode\u003e@​qgallouedec\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4180\"\u003e#4180\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eDTensor\u003c/h2\u003e\n\u003cp\u003eTwo fixes for DTensor-sharded models, which you hit with FSDP2, tensor parallelism, or any N-D parallelism setup: gradient clipping no longer fails on the \u003ccode\u003eforeach\u003c/code\u003e op when plain tensors and DTensors are mixed, and \u003ccode\u003eprepare_model\u003c/code\u003e leaves an already-sharded model where it is:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eClip grad norm support for dtensors by \u003ca href=\"https://github.com/michaelbenayoun\"\u003e\u003ccode\u003e@​michaelbenayoun\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4219\"\u003e#4219\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eprepare_model: don't move DTensor-sharded models to the device by \u003ca href=\"https://github.com/qgallouedec\"\u003e\u003ccode\u003e@​qgallouedec\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4181\"\u003e#4181\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eOffloading \u0026amp; Quantization\u003c/h2\u003e\n\u003cp\u003eAn entire model can now be dispatched to disk, including tied weights — useful for tools like \u003ccode\u003ellm-compressor\u003c/code\u003e that compress large models on machines that can't hold them:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e[Offloading] Support full disk offloading by \u003ca href=\"https://github.com/kylesayrs\"\u003e\u003ccode\u003e@​kylesayrs\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4083\"\u003e#4083\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix disk offload crash on FP8 tensors by \u003ca href=\"https://github.com/shoemoney\"\u003e\u003ccode\u003e@​shoemoney\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4151\"\u003e#4151\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eTrackers\u003c/h2\u003e\n\u003cp\u003eCustom trackers can be registered by name and then selected from \u003ccode\u003elog_with=\u003c/code\u003e like any built-in one:\u003c/p\u003e\n\u003cpre lang=\"python\"\u003e\u003ccode\u003efrom accelerate import Accelerator\r\nfrom accelerate.tracking import register_tracker_class\r\n\u0026lt;/tr\u0026gt;\u0026lt;/table\u0026gt; \n\u003c/code\u003e\u003c/pre\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/accelerate/commit/6afc1e5ee217051fde702b23de2813344dc0fd33\"\u003e\u003ccode\u003e6afc1e5\u003c/code\u003e\u003c/a\u003e Release: v1.15.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/accelerate/commit/636a9343b4265db1212b04c778b8910b5cbfa713\"\u003e\u003ccode\u003e636a934\u003c/code\u003e\u003c/a\u003e Fix nightly CI: tensor parallel size detection and DeepSpeed warmup steps (\u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4\"\u003e#4\u003c/a\u003e...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/accelerate/commit/385d9fb40bdb92b0cb34775ad0ef493c171e559f\"\u003e\u003ccode\u003e385d9fb\u003c/code\u003e\u003c/a\u003e docs: fix three dead links left by the docs restructure (\u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4230\"\u003e#4230\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/accelerate/commit/c424d0b82d4ed61672bf30f1a81ce80370fd945a\"\u003e\u003ccode\u003ec424d0b\u003c/code\u003e\u003c/a\u003e docs: fix garbled sentence in CONTRIBUTING.md (\u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4231\"\u003e#4231\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/accelerate/commit/0f7e35fe7902cc6ba8dc01b146d6447900464b88\"\u003e\u003ccode\u003e0f7e35f\u003c/code\u003e\u003c/a\u003e Clip grad norm support for dtensors (\u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4219\"\u003e#4219\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/accelerate/commit/b2ac5095f04585043e21d295afe3aaaacdcc8357\"\u003e\u003ccode\u003eb2ac509\u003c/code\u003e\u003c/a\u003e Fix FSDP2/ PEFT/\u003ccode\u003eFULL_STATE_DICT\u003c/code\u003e dropping every rank's adapter shard except ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/accelerate/commit/33e8bc499254e7f3886db3f8a277d05a4ad2667e\"\u003e\u003ccode\u003e33e8bc4\u003c/code\u003e\u003c/a\u003e Fix load_accelerator_state only restoring one RNG backend (\u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4217\"\u003e#4217\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/accelerate/commit/50de3ad45f4da279819529e443ba746eb5b3b187\"\u003e\u003ccode\u003e50de3ad\u003c/code\u003e\u003c/a\u003e Treat MPS out-of-memory errors as OOM in find_executable_batch_size (\u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4227\"\u003e#4227\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/accelerate/commit/ab5fe8e507366f814fee59138eb96b9879cb05d6\"\u003e\u003ccode\u003eab5fe8e\u003c/code\u003e\u003c/a\u003e feat: add the neuron device branch in state (\u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4218\"\u003e#4218\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/accelerate/commit/9baf95be958c3fd8b2449d1463e6a89e14f61e7d\"\u003e\u003ccode\u003e9baf95b\u003c/code\u003e\u003c/a\u003e Fix MLFLOW_NESTED_RUN never being able to turn nesting off (\u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4223\"\u003e#4223\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/huggingface/accelerate/compare/v1.14.0...v1.15.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `ty` from 0.0.55 to 0.0.80\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/astral-sh/ty/releases\"\u003ety's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e0.0.80\u003c/h2\u003e\n\u003ch2\u003eRelease Notes\u003c/h2\u003e\n\u003cp\u003eReleased on 2026-09-09.\u003c/p\u003e\n\u003ch3\u003eBug fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFix \u003ccode\u003e--force-exclude\u003c/code\u003e for directories with an excluded ancestor (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28451\"\u003e#28451\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ePreserve metaclass candidates after conflicts (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28461\"\u003e#28461\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eLSP server\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eGive existing autofixes descriptive titles (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28456\"\u003e#28456\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ePrevent LSP hangs during inlay hint bursts (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28390\"\u003e#28390\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDiagnostic improvements\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve redundant-condition diagnostics with unreachable operands (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28374\"\u003e#28374\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eCore type checking\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eCheck captured receivers when calling wrapped classmethods (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28467\"\u003e#28467\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix cached classmethods on generic classes (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28207\"\u003e#28207\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix disjointness of type guards and boolean literals (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28363\"\u003e#28363\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eInfer tuple variance from the full tuple spec (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28446\"\u003e#28446\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eInfer tuple variance more precisely (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28426\"\u003e#28426\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ePreserve callable identity across specialized types (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28409\"\u003e#28409\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ePreserve callback type context through ParamSpec forwarding (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28439\"\u003e#28439\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ePreserve wrapped functions in precise \u003ccode\u003efunctools.partial\u003c/code\u003e relations (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28460\"\u003e#28460\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRespect descriptor protocol for \u003ccode\u003e__set__\u003c/code\u003e itself (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28408\"\u003e#28408\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRespect type-variable bounds in argument context (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28448\"\u003e#28448\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eUnwrap union alternatives in overload implementations (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28468\"\u003e#28468\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003ePerformance\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eDistribute \u003ccode\u003elen\u003c/code\u003e inference over unions (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28470\"\u003e#28470\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFast-path concrete literal intersections (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28348\"\u003e#28348\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMemory usage improvements\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAvoid excess capacity in multi-binding tables (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28412\"\u003e#28412\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eShare equivalent place tables within a file (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28319\"\u003e#28319\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eShare names in synthesized constructor parameters (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28398\"\u003e#28398\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eContributors\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/sharkdp\"\u003e\u003ccode\u003e@​sharkdp\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/charliermarsh\"\u003e\u003ccode\u003e@​charliermarsh\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ibraheemdev\"\u003e\u003ccode\u003e@​ibraheemdev\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/AlexWaygood\"\u003e\u003ccode\u003e@​AlexWaygood\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/astral-sh/ty/blob/main/CHANGELOG.md\"\u003ety's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e0.0.80\u003c/h2\u003e\n\u003cp\u003eReleased on 2026-09-09.\u003c/p\u003e\n\u003ch3\u003eBug fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFix \u003ccode\u003e--force-exclude\u003c/code\u003e for directories with an excluded ancestor (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28451\"\u003e#28451\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ePreserve metaclass candidates after conflicts (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28461\"\u003e#28461\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eLSP server\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eGive existing autofixes descriptive titles (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28456\"\u003e#28456\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ePrevent LSP hangs during inlay hint bursts (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28390\"\u003e#28390\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDiagnostic improvements\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve redundant-condition diagnostics with unreachable operands (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28374\"\u003e#28374\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eCore type checking\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eCheck captured receivers when calling wrapped classmethods (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28467\"\u003e#28467\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix cached classmethods on generic classes (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28207\"\u003e#28207\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix disjointness of type guards and boolean literals (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28363\"\u003e#28363\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eInfer tuple variance from the full tuple spec (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28446\"\u003e#28446\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eInfer tuple variance more precisely (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28426\"\u003e#28426\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ePreserve callable identity across specialized types (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28409\"\u003e#28409\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ePreserve callback type context through ParamSpec forwarding (\u003ca href=\"https...\n\n_Description has been truncated_","html_url":"https://github.com/kalburgimanju/ai-code-master/pull/17","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/kalburgimanju%2Fai-code-master/issues/17","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/17/packages"}],"issue_packages":[{"old_version":"3.13.3","new_version":"3.14.3","update_type":"minor","path":null,"pr_created_at":"2026-09-25T01:12:52.000Z","version_change":"3.13.3 → 3.14.3","issue":{"uuid":"5576671790","node_id":"PR_kwDOTw8DQM8AAAABFCOc6w","number":18,"state":"open","title":"Bump the minor-update group across 1 directory with 194 updates","user":"dependabot[bot]","labels":["dependencies"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-25T01:12:52.000Z","updated_at":"2026-09-25T01:13:02.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","group_name":"minor-update","update_count":194,"packages":[{"name":"tblib","old_version":"3.1.0","new_version":"3.2.2","repository_url":"https://github.com/ionelmc/python-tblib"},{"name":"regex","old_version":"2026.2.28","new_version":"2026.9.10","repository_url":"https://github.com/mrabarnett/mrab-regex"},{"name":"requests","old_version":"2.32.3","new_version":"2.34.2","repository_url":"https://github.com/psf/requests"},{"name":"tqdm","old_version":"4.67.3","new_version":"4.70.1","repository_url":"https://github.com/tqdm/tqdm"},{"name":"transformers","old_version":"5.14.1","new_version":"5.17.0","repository_url":"https://github.com/huggingface/transformers"},{"name":"huggingface-hub","old_version":"1.26.0","new_version":"1.32.0","repository_url":"https://github.com/huggingface/huggingface_hub"},{"name":"tokenizers","old_version":"0.22.2","new_version":"0.23.2","repository_url":"https://github.com/huggingface/tokenizers"},{"name":"fastapi","old_version":"0.136.3","new_version":"0.141.1","repository_url":"https://github.com/fastapi/fastapi"},{"name":"starlette","old_version":"1.3.1","new_version":"1.6.0","repository_url":"https://github.com/Kludex/starlette"},{"name":"aiohttp","old_version":"3.13.3","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"pydantic","old_version":"2.12.0","new_version":"2.13.5","repository_url":"https://github.com/pydantic/pydantic"},{"name":"prometheus-client","old_version":"0.22.0","new_version":"0.26.0","repository_url":"https://github.com/prometheus/client_python"},{"name":"prometheus-fastapi-instrumentator","old_version":"8.0.2","new_version":"8.1.0","repository_url":"https://github.com/trallnag/prometheus-fastapi-instrumentator"},{"name":"tiktoken","old_version":"0.12.0","new_version":"0.14.0","repository_url":"https://github.com/openai/tiktoken"},{"name":"lark","old_version":"1.2.2","new_version":"1.3.1","repository_url":"https://github.com/lark-parser/lark"},{"name":"typing-extensions","old_version":"4.15.0","new_version":"4.16.0","repository_url":"https://github.com/python/typing_extensions"},{"name":"jsonschema","old_version":"4.23.0","new_version":"4.26.0","repository_url":"https://github.com/python-jsonschema/jsonschema"},{"name":"pyzmq","old_version":"27.1.0","new_version":"27.2.0","repository_url":"https://github.com/zeromq/pyzmq"},{"name":"watchfiles","old_version":"1.2.0","new_version":"1.3.0","repository_url":"https://github.com/samuelcolvin/watchfiles"},{"name":"python-json-logger","old_version":"4.1.0","new_version":"4.2.0","repository_url":"https://github.com/nhairs/python-json-logger"},{"name":"pybase64","old_version":"1.4.3","new_version":"1.5.0","repository_url":"https://github.com/mayeut/pybase64"},{"name":"opentelemetry-sdk","old_version":"1.35.0","new_version":"1.44.0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"opentelemetry-api","old_version":"1.35.0","new_version":"1.44.0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"opentelemetry-exporter-otlp","old_version":"1.35.0","new_version":"1.44.0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"opentelemetry-semantic-conventions-ai","old_version":"0.4.13","new_version":"0.5.1"},{"name":"numba","old_version":"0.65.0","new_version":"0.67.0","repository_url":"https://github.com/numba/numba"},{"name":"torchcodec","old_version":"0.14.0+cu130","new_version":"0.16.0","repository_url":"https://github.com/pytorch/torchcodec"},{"name":"absl-py","old_version":"2.1.0","new_version":"2.5.0","repository_url":"https://github.com/abseil/abseil-py"},{"name":"accelerate","old_version":"1.13.0","new_version":"1.15.0","repository_url":"https://github.com/huggingface/accelerate"},{"name":"aiohappyeyeballs","old_version":"2.6.1","new_version":"2.7.1","repository_url":"https://github.com/aio-libs/aiohappyeyeballs"},{"name":"alembic","old_version":"1.16.4","new_version":"1.20.0","repository_url":"https://github.com/sqlalchemy/alembic"},{"name":"annotated-types","old_version":"0.7.0","new_version":"0.8.0","repository_url":"https://github.com/annotated-types/annotated-types"},{"name":"anyio","old_version":"4.14.1","new_version":"4.15.1","repository_url":"https://github.com/agronholm/anyio"},{"name":"arctic-inference","old_version":"0.1.1","new_version":"0.3.0"},{"name":"argcomplete","old_version":"3.5.1","new_version":"3.7.2","repository_url":"https://github.com/kislyuk/argcomplete"},{"name":"audioread","old_version":"3.0.1","new_version":"3.1.0","repository_url":"https://github.com/beetbox/audioread"},{"name":"azure-core","old_version":"1.38.2","new_version":"1.41.0","repository_url":"https://github.com/Azure/azure-sdk-for-python"},{"name":"azure-storage-blob","old_version":"12.28.0","new_version":"12.30.2","repository_url":"https://github.com/Azure/azure-sdk-for-python"},{"name":"bitsandbytes","old_version":"0.49.2","new_version":"0.50.2","repository_url":"https://github.com/bitsandbytes-foundation/bitsandbytes"},{"name":"blobfile","old_version":"3.0.0","new_version":"3.3.0","repository_url":"https://github.com/blobfile/blobfile"},{"name":"bm25s","old_version":"0.2.13","new_version":"0.3.11","repository_url":"https://github.com/xhluca/bm25s"},{"name":"boto3","old_version":"1.35.57","new_version":"1.43.99","repository_url":"https://github.com/boto/boto3"},{"name":"botocore","old_version":"1.35.57","new_version":"1.43.99","repository_url":"https://github.com/boto/botocore"},{"name":"cffi","old_version":"2.0.0","new_version":"2.1.1","repository_url":"https://github.com/python-cffi/cffi"},{"name":"charset-normalizer","old_version":"3.4.0","new_version":"3.5.1","repository_url":"https://github.com/jawah/charset_normalizer"},{"name":"click","old_version":"8.4.2","new_version":"8.5.0","repository_url":"https://github.com/pallets/click"},{"name":"cohere","old_version":"7.0.8","new_version":"7.1.1","repository_url":"https://github.com/cohere-ai/cohere-python"},{"name":"cohere-melody","old_version":"0.9.0","new_version":"0.15.0","repository_url":"https://github.com/cohere-ai/melody"},{"name":"colorlog","old_version":"6.10.1","new_version":"6.12.0","repository_url":"https://github.com/borntyping/python-colorlog"},{"name":"coverage","old_version":"7.10.6","new_version":"7.16.1","repository_url":"https://github.com/coveragepy/coveragepy"},{"name":"cramjam","old_version":"2.9.0","new_version":"2.11.0","repository_url":"https://github.com/milesgranger/pyrus-cramjam"},{"name":"cuda-bindings","old_version":"13.0.3","new_version":"13.4.2","repository_url":"https://github.com/NVIDIA/cuda-python"},{"name":"cuda-pathfinder","old_version":"1.3.3","new_version":"1.8.2","repository_url":"https://github.com/NVIDIA/cuda-python"},{"name":"cuda-toolkit","old_version":"13.0.3.0","new_version":"13.4.2"},{"name":"datamodel-code-generator","old_version":"0.26.3","new_version":"0.82.0","repository_url":"https://github.com/datamodel-code-generator/datamodel-code-generator"},{"name":"dataproperty","old_version":"1.0.1","new_version":"1.1.1","repository_url":"https://github.com/thombashi/DataProperty"},{"name":"decorator","old_version":"5.1.1","new_version":"5.3.1","repository_url":"https://github.com/micheles/decorator"},{"name":"detect-installer","old_version":"0.1.0","new_version":"0.2.1"},{"name":"dill","old_version":"0.3.8","new_version":"0.4.1","repository_url":"https://github.com/uqfoundation/dill"},{"name":"distlib","old_version":"0.3.9","new_version":"0.4.3","repository_url":"https://github.com/pypa/distlib"},{"name":"dnspython","old_version":"2.7.0","new_version":"2.8.0","repository_url":"https://github.com/rthalley/dnspython"},{"name":"docker","old_version":"7.1.0","new_version":"7.2.0","repository_url":"https://github.com/docker/docker-py"},{"name":"einx","old_version":"0.3.0","new_version":"0.4.3","repository_url":"https://github.com/fferflo/einx"},{"name":"email-validator","old_version":"2.2.0","new_version":"2.3.0","repository_url":"https://github.com/JoshData/python-email-validator"},{"name":"fastapi-cloud-cli","old_version":"0.21.0","new_version":"0.26.0","repository_url":"https://github.com/fastapilabs/fastapi-cloud-cli"},{"name":"fastar","old_version":"0.11.0","new_version":"0.12.0","repository_url":"https://github.com/DoctorJohn/fastar"},{"name":"fastsafetensors","old_version":"0.3.2","new_version":"0.4.0","repository_url":"https://github.com/foundation-model-stack/fastsafetensors"},{"name":"fonttools","old_version":"4.55.0","new_version":"4.65.0","repository_url":"https://github.com/fonttools/fonttools"},{"name":"frozenlist","old_version":"1.5.0","new_version":"1.8.0","repository_url":"https://github.com/aio-libs/frozenlist"},{"name":"genson","old_version":"1.3.0","new_version":"1.4.0","repository_url":"https://github.com/wolverdude/genson"},{"name":"google-api-core","old_version":"2.24.2","new_version":"2.38.0","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"google-auth","old_version":"2.40.2","new_version":"2.58.0","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"google-cloud-core","old_version":"2.4.3","new_version":"2.7.0","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"google-cloud-storage","old_version":"3.4.0","new_version":"3.14.1","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"google-crc32c","old_version":"1.7.1","new_version":"1.8.0","repository_url":"https://github.com/googleapis/python-crc32c"},{"name":"google-resumable-media","old_version":"2.7.2","new_version":"2.10.2","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"googleapis-common-protos","old_version":"1.70.0","new_version":"1.75.3","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"greenlet","old_version":"3.2.3","new_version":"3.5.6","repository_url":"https://github.com/python-greenlet/greenlet"},{"name":"grpcio","old_version":"1.78.0","new_version":"1.84.0","repository_url":"https://github.com/grpc/grpc"},{"name":"grpcio-reflection","old_version":"1.78.0","new_version":"1.84.0"},{"name":"h11","old_version":"0.14.0","new_version":"0.16.0","repository_url":"https://github.com/python-hyper/h11"},{"name":"h2","old_version":"4.3.0","new_version":"4.4.1","repository_url":"https://github.com/python-hyper/h2"},{"name":"hf-xet","old_version":"1.5.1","new_version":"1.6.0","repository_url":"https://github.com/huggingface/xet-core"},{"name":"hiredis","old_version":"3.0.0","new_version":"3.4.1","repository_url":"https://github.com/redis/hiredis-py"},{"name":"hpack","old_version":"4.1.0","new_version":"4.2.0","repository_url":"https://github.com/python-hyper/hpack"},{"name":"httpx","old_version":"0.27.2","new_version":"0.28.1","repository_url":"https://github.com/encode/httpx"},{"name":"humanize","old_version":"4.11.0","new_version":"4.16.0","repository_url":"https://github.com/python-humanize/humanize"},{"name":"hypothesis","old_version":"6.131.0","new_version":"6.168.0","repository_url":"https://github.com/HypothesisWorks/hypothesis"},{"name":"idna","old_version":"3.10","new_version":"3.20","repository_url":"https://github.com/kjd/idna"},{"name":"iniconfig","old_version":"2.0.0","new_version":"2.3.0","repository_url":"https://github.com/pytest-dev/iniconfig"},{"name":"instanttensor","old_version":"0.1.9","new_version":"0.2.0","repository_url":"https://github.com/scitix/InstantTensor"},{"name":"jiter","old_version":"0.15.0","new_version":"0.17.0","repository_url":"https://github.com/pydantic/jiter"},{"name":"jmespath","old_version":"1.0.1","new_version":"1.1.0","repository_url":"https://github.com/jmespath/jmespath.py"},{"name":"joblib","old_version":"1.4.2","new_version":"1.6.0","repository_url":"https://github.com/joblib/joblib"},{"name":"jsonschema-rs","old_version":"0.46.5","new_version":"0.57.1","repository_url":"https://github.com/Stranger6667/jsonschema"},{"name":"kiwisolver","old_version":"1.4.7","new_version":"1.5.1","repository_url":"https://github.com/nucleic/kiwi"},{"name":"lazy-loader","old_version":"0.4","new_version":"0.6","repository_url":"https://github.com/scientific-python/lazy-loader"},{"name":"llguidance","old_version":"1.7.6","new_version":"1.8.0","repository_url":"https://github.com/microsoft/llguidance"},{"name":"llvmlite","old_version":"0.47.0","new_version":"0.49.0","repository_url":"https://github.com/numba/llvmlite"},{"name":"mako","old_version":"1.3.10","new_version":"1.4.1","repository_url":"https://github.com/sqlalchemy/mako"},{"name":"matplotlib","old_version":"3.9.2","new_version":"3.10.9","repository_url":"https://github.com/matplotlib/matplotlib"},{"name":"mpmath","old_version":"1.3.0","new_version":"1.4.1","repository_url":"https://github.com/mpmath/mpmath"},{"name":"msal","old_version":"1.34.0","new_version":"1.39.0","repository_url":"https://github.com/AzureAD/microsoft-authentication-library-for-python"},{"name":"msgpack","old_version":"1.1.0","new_version":"1.2.2","repository_url":"https://github.com/msgpack/msgpack-python"},{"name":"mteb","old_version":"2.8.3","new_version":"2.21.6","repository_url":"https://github.com/embeddings-benchmark/mteb"},{"name":"multidict","old_version":"6.1.0","new_version":"6.9.1","repository_url":"https://github.com/aio-libs/multidict"},{"name":"mypy-extensions","old_version":"1.0.0","new_version":"1.1.0","repository_url":"https://github.com/python/mypy_extensions"},{"name":"networkx","old_version":"3.2.1","new_version":"3.4.2","repository_url":"https://github.com/networkx/networkx"},{"name":"nltk","old_version":"3.9.1","new_version":"3.10.3","repository_url":"https://github.com/nltk/nltk"},{"name":"nvidia-cublas","old_version":"13.1.1.3","new_version":"13.8.0.4"},{"name":"nvidia-cuda-cupti","old_version":"13.0.85","new_version":"13.4.92"},{"name":"nvidia-cuda-nvrtc","old_version":"13.0.88","new_version":"13.4.92"},{"name":"nvidia-cuda-runtime","old_version":"13.0.96","new_version":"13.4.92"},{"name":"nvidia-cudnn-cu13","old_version":"9.20.0.48","new_version":"9.26.0.51"},{"name":"nvidia-cufft","old_version":"12.0.0.61","new_version":"12.4.0.43"},{"name":"nvidia-cufile","old_version":"1.15.1.6","new_version":"1.19.1.55"},{"name":"nvidia-cusolver","old_version":"12.0.4.66","new_version":"12.3.4.7"},{"name":"nvidia-cusparse","old_version":"12.6.3.3","new_version":"12.8.6.72"},{"name":"nvidia-cusparselt-cu13","old_version":"0.8.1","new_version":"0.9.1"},{"name":"nvidia-nccl-cu13","old_version":"2.29.7","new_version":"2.31.2"},{"name":"nvidia-nvjitlink","old_version":"13.0.88","new_version":"13.4.92"},{"name":"nvidia-nvshmem-cu13","old_version":"3.4.5","new_version":"3.7.2"},{"name":"nvidia-nvtx","old_version":"13.0.85","new_version":"13.4.92"},{"name":"opentelemetry-exporter-otlp-proto-common","old_version":"1.35.0","new_version":"1.44.0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"opentelemetry-exporter-otlp-proto-grpc","old_version":"1.35.0","new_version":"1.44.0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"opentelemetry-exporter-otlp-proto-http","old_version":"1.35.0","new_version":"1.44.0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"opentelemetry-exporter-prometheus","old_version":"0.56b0","new_version":"0.65b0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"opentelemetry-proto","old_version":"1.35.0","new_version":"1.44.0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"opentelemetry-semantic-conventions","old_version":"0.56b0","new_version":"0.65b0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"orjson","old_version":"3.11.5","new_version":"3.12.0","repository_url":"https://github.com/ijl/orjson"},{"name":"pathvalidate","old_version":"3.2.1","new_version":"3.3.1","repository_url":"https://github.com/thombashi/pathvalidate"},{"name":"peft","old_version":"0.19.1","new_version":"0.21.0","repository_url":"https://github.com/huggingface/peft"},{"name":"perceptron","old_version":"0.1.4","new_version":"0.3.5","repository_url":"https://github.com/perceptron-ai-inc/perceptron"},{"name":"platformdirs","old_version":"4.3.6","new_version":"4.11.11","repository_url":"https://github.com/tox-dev/platformdirs"},{"name":"pluggy","old_version":"1.5.0","new_version":"1.6.0","repository_url":"https://github.com/pytest-dev/pluggy"},{"name":"polars","old_version":"1.29.0","new_version":"1.44.2","repository_url":"https://github.com/pola-rs/polars"},{"name":"pooch","old_version":"1.8.2","new_version":"1.9.0","repository_url":"https://github.com/fatiando/pooch"},{"name":"propcache","old_version":"0.2.0","new_version":"0.5.4","repository_url":"https://github.com/aio-libs/propcache"},{"name":"proto-plus","old_version":"1.26.1","new_version":"1.28.4","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"pycryptodomex","old_version":"3.22.0","new_version":"3.23.0","repository_url":"https://github.com/Legrandin/pycryptodome"},{"name":"pydantic-core","old_version":"2.41.1","new_version":"2.49.0","repository_url":"https://github.com/pydantic/pydantic"},{"name":"pydantic-extra-types","old_version":"2.10.5","new_version":"2.11.1","repository_url":"https://github.com/pydantic/pydantic-extra-types"},{"name":"pydantic-settings","old_version":"2.14.2","new_version":"2.15.0","repository_url":"https://github.com/pydantic/pydantic-settings"},{"name":"pygments","old_version":"2.18.0","new_version":"2.21.0","repository_url":"https://github.com/pygments/pygments"},{"name":"pyjwt","old_version":"2.11.0","new_version":"2.14.0","repository_url":"https://github.com/jpadilla/pyjwt"},{"name":"pyparsing","old_version":"3.2.0","new_version":"3.3.3","repository_url":"https://github.com/pyparsing/pyparsing"},{"name":"pyrate-limiter","old_version":"4.4.0","new_version":"4.5.0","repository_url":"https://github.com/vutran1710/PyrateLimiter"},{"name":"pystemmer","old_version":"3.0.0","new_version":"3.1.0","repository_url":"https://github.com/snowballstem/pystemmer"},{"name":"pytest-forked","old_version":"1.6.0","new_version":"1.7.5","repository_url":"https://github.com/pytest-dev/pytest-forked"},{"name":"pytest-mock","old_version":"3.14.0","new_version":"3.15.1","repository_url":"https://github.com/pytest-dev/pytest-mock"},{"name":"pytest-timeout","old_version":"2.3.1","new_version":"2.4.0","repository_url":"https://github.com/pytest-dev/pytest-timeout"},{"name":"python-rapidjson","old_version":"1.20","new_version":"1.25","repository_url":"https://github.com/python-rapidjson/python-rapidjson"},{"name":"rapidfuzz","old_version":"3.12.1","new_version":"3.14.5","repository_url":"https://github.com/rapidfuzz/RapidFuzz"},{"name":"referencing","old_version":"0.35.1","new_version":"0.37.0","repository_url":"https://github.com/python-jsonschema/referencing"},{"name":"responses","old_version":"0.25.3","new_version":"0.26.3","repository_url":"https://github.com/getsentry/responses"},{"name":"rignore","old_version":"0.7.6","new_version":"0.8.1"},{"name":"runai-model-streamer","old_version":"0.15.7","new_version":"0.16.1"},{"name":"runai-model-streamer-azure","old_version":"0.15.7","new_version":"0.16.1"},{"name":"runai-model-streamer-gcs","old_version":"0.15.7","new_version":"0.16.1"},{"name":"runai-model-streamer-s3","old_version":"0.15.7","new_version":"0.16.1"},{"name":"s3transfer","old_version":"0.10.3","new_version":"0.19.2","repository_url":"https://github.com/boto/s3transfer"},{"name":"sacrebleu","old_version":"2.4.3","new_version":"2.6.0","repository_url":"https://github.com/mjpost/sacrebleu"},{"name":"schemathesis","old_version":"4.21.6","new_version":"4.27.5","repository_url":"https://github.com/schemathesis/schemathesis"},{"name":"scikit-learn","old_version":"1.5.2","new_version":"1.7.2","repository_url":"https://github.com/scikit-learn/scikit-learn"},{"name":"scipy","old_version":"1.13.1","new_version":"1.15.3","repository_url":"https://github.com/scipy/scipy"},{"name":"sentry-sdk","old_version":"2.63.0","new_version":"2.69.2","repository_url":"https://github.com/getsentry/sentry-python"},{"name":"six","old_version":"1.16.0","new_version":"1.17.0","repository_url":"https://github.com/benjaminp/six"},{"name":"soundfile","old_version":"0.12.1","new_version":"0.14.0","repository_url":"https://github.com/bastibe/python-soundfile"},{"name":"statsmodels","old_version":"0.14.4","new_version":"0.15.0","repository_url":"https://github.com/statsmodels/statsmodels"},{"name":"sympy","old_version":"1.13.3","new_version":"1.14.0","repository_url":"https://github.com/sympy/sympy"},{"name":"tabulate","old_version":"0.9.0","new_version":"0.10.0","repository_url":"https://github.com/astanin/python-tabulate"},{"name":"tensorizer","old_version":"2.10.1","new_version":"2.12.1","repository_url":"https://github.com/coreweave/tensorizer"},{"name":"termcolor","old_version":"3.1.0","new_version":"3.3.0","repository_url":"https://github.com/termcolor/termcolor"},{"name":"threadpoolctl","old_version":"3.5.0","new_version":"3.7.0","repository_url":"https://github.com/joblib/threadpoolctl"},{"name":"triton","old_version":"3.7.1","new_version":"3.8.0","repository_url":"https://github.com/triton-lang/triton"},{"name":"tritonclient","old_version":"2.64.0","new_version":"2.71.0","repository_url":"https://github.com/triton-inference-server/client"},{"name":"typer","old_version":"0.26.8","new_version":"0.27.2","repository_url":"https://github.com/fastapi/typer"},{"name":"urllib3","old_version":"2.2.3","new_version":"2.8.0","repository_url":"https://github.com/urllib3/urllib3"},{"name":"uvicorn","old_version":"0.35.0","new_version":"0.53.0","repository_url":"https://github.com/Kludex/uvicorn"},{"name":"vector-quantize-pytorch","old_version":"1.21.2","new_version":"1.31.4","repository_url":"https://github.com/lucidrains/vector-quantizer-pytorch"},{"name":"wcwidth","old_version":"0.2.13","new_version":"0.8.4","repository_url":"https://github.com/jquast/wcwidth"},{"name":"yarl","old_version":"1.17.1","new_version":"1.25.1","repository_url":"https://github.com/aio-libs/yarl"},{"name":"conch-triton-kernels","old_version":"1.2.1","new_version":"1.3","repository_url":"https://github.com/stackav-oss/conch"},{"name":"tpu-inference","old_version":"0.26.0","new_version":"0.29.0","repository_url":"https://github.com/vllm-project/tpu-inference"},{"name":"pynvvideocodec","old_version":"2.0.4","new_version":"2.2.3"},{"name":"flashinfer-python","old_version":"0.6.15.post1","new_version":"0.7.0","repository_url":"https://github.com/flashinfer-ai/flashinfer"},{"name":"flashinfer-cubin","old_version":"0.6.15.post1","new_version":"0.7.0","repository_url":"https://github.com/flashinfer-ai/flashinfer"},{"name":"nvidia-cutlass-dsl","old_version":"4.6.0","new_version":"4.8.0","repository_url":"https://github.com/NVIDIA/cutlass"},{"name":"tokenspeed-mla","old_version":"0.1.8","new_version":"0.2.10","repository_url":"https://github.com/lightseekorg/tokenspeed"},{"name":"auto-round-lib","old_version":"0.14.2","new_version":"0.15.0","repository_url":"https://github.com/intel/auto-round"},{"name":"griffelib","old_version":"2.0.2","new_version":"2.3.0"},{"name":"mkdocs-git-revision-date-localized-plugin","old_version":"1.5.1","new_version":"1.6.0","repository_url":"https://github.com/timvink/mkdocs-git-revision-date-localized-plugin"},{"name":"ruff","old_version":"0.15.12","new_version":"0.16.8","repository_url":"https://github.com/astral-sh/ruff"},{"name":"zentorch","old_version":"2.11.0.0","new_version":"2.14.0.0","repository_url":"https://github.com/amd/ZenDNN-pytorch-plugin"}],"path":null,"ecosystem":"pip"},"body":"\u003e [!WARNING]\n\u003e Cooldown could not be applied because no publication date was available from the registry.\n\u003e\n\nBumps the minor-update group with 194 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [tblib](https://github.com/ionelmc/python-tblib) | `3.1.0` | `3.2.2` |\n| [regex](https://github.com/mrabarnett/mrab-regex) | `2026.2.28` | `2026.9.10` |\n| [requests](https://github.com/psf/requests) | `2.32.3` | `2.34.2` |\n| [tqdm](https://github.com/tqdm/tqdm) | `4.67.3` | `4.70.1` |\n| [transformers](https://github.com/huggingface/transformers) | `5.14.1` | `5.17.0` |\n| [huggingface-hub](https://github.com/huggingface/huggingface_hub) | `1.26.0` | `1.32.0` |\n| [tokenizers](https://github.com/huggingface/tokenizers) | `0.22.2` | `0.23.2` |\n| [fastapi](https://github.com/fastapi/fastapi) | `0.136.3` | `0.141.1` |\n| [starlette](https://github.com/Kludex/starlette) | `1.3.1` | `1.6.0` |\n| [aiohttp](https://github.com/aio-libs/aiohttp) | `3.13.3` | `3.14.3` |\n| [pydantic](https://github.com/pydantic/pydantic) | `2.12.0` | `2.13.5` |\n| [prometheus-client](https://github.com/prometheus/client_python) | `0.22.0` | `0.26.0` |\n| [prometheus-fastapi-instrumentator](https://github.com/trallnag/prometheus-fastapi-instrumentator) | `8.0.2` | `8.1.0` |\n| [tiktoken](https://github.com/openai/tiktoken) | `0.12.0` | `0.14.0` |\n| [lark](https://github.com/lark-parser/lark) | `1.2.2` | `1.3.1` |\n| [typing-extensions](https://github.com/python/typing_extensions) | `4.15.0` | `4.16.0` |\n| [jsonschema](https://github.com/python-jsonschema/jsonschema) | `4.23.0` | `4.26.0` |\n| [pyzmq](https://github.com/zeromq/pyzmq) | `27.1.0` | `27.2.0` |\n| [watchfiles](https://github.com/samuelcolvin/watchfiles) | `1.2.0` | `1.3.0` |\n| [python-json-logger](https://github.com/nhairs/python-json-logger) | `4.1.0` | `4.2.0` |\n| [pybase64](https://github.com/mayeut/pybase64) | `1.4.3` | `1.5.0` |\n| [opentelemetry-sdk](https://github.com/open-telemetry/opentelemetry-python) | `1.35.0` | `1.44.0` |\n| [opentelemetry-api](https://github.com/open-telemetry/opentelemetry-python) | `1.35.0` | `1.44.0` |\n| [opentelemetry-exporter-otlp](https://github.com/open-telemetry/opentelemetry-python) | `1.35.0` | `1.44.0` |\n| opentelemetry-semantic-conventions-ai | `0.4.13` | `0.5.1` |\n| [numba](https://github.com/numba/numba) | `0.65.0` | `0.67.0` |\n| [torchcodec](https://github.com/pytorch/torchcodec) | `0.14.0+cu130` | `0.16.0` |\n| [absl-py](https://github.com/abseil/abseil-py) | `2.1.0` | `2.5.0` |\n| [accelerate](https://github.com/huggingface/accelerate) | `1.13.0` | `1.15.0` |\n| [aiohappyeyeballs](https://github.com/aio-libs/aiohappyeyeballs) | `2.6.1` | `2.7.1` |\n| [alembic](https://github.com/sqlalchemy/alembic) | `1.16.4` | `1.20.0` |\n| [annotated-types](https://github.com/annotated-types/annotated-types) | `0.7.0` | `0.8.0` |\n| [anyio](https://github.com/agronholm/anyio) | `4.14.1` | `4.15.1` |\n| arctic-inference | `0.1.1` | `0.3.0` |\n| [argcomplete](https://github.com/kislyuk/argcomplete) | `3.5.1` | `3.7.2` |\n| [audioread](https://github.com/beetbox/audioread) | `3.0.1` | `3.1.0` |\n| [azure-core](https://github.com/Azure/azure-sdk-for-python) | `1.38.2` | `1.41.0` |\n| [azure-storage-blob](https://github.com/Azure/azure-sdk-for-python) | `12.28.0` | `12.30.2` |\n| [bitsandbytes](https://github.com/bitsandbytes-foundation/bitsandbytes) | `0.49.2` | `0.50.2` |\n| [blobfile](https://github.com/blobfile/blobfile) | `3.0.0` | `3.3.0` |\n| [bm25s](https://github.com/xhluca/bm25s) | `0.2.13` | `0.3.11` |\n| [boto3](https://github.com/boto/boto3) | `1.35.57` | `1.43.99` |\n| [botocore](https://github.com/boto/botocore) | `1.35.57` | `1.43.99` |\n| [cffi](https://github.com/python-cffi/cffi) | `2.0.0` | `2.1.1` |\n| [charset-normalizer](https://github.com/jawah/charset_normalizer) | `3.4.0` | `3.5.1` |\n| [click](https://github.com/pallets/click) | `8.4.2` | `8.5.0` |\n| [cohere](https://github.com/cohere-ai/cohere-python) | `7.0.8` | `7.1.1` |\n| [cohere-melody](https://github.com/cohere-ai/melody) | `0.9.0` | `0.15.0` |\n| [colorlog](https://github.com/borntyping/python-colorlog) | `6.10.1` | `6.12.0` |\n| [coverage](https://github.com/coveragepy/coveragepy) | `7.10.6` | `7.16.1` |\n| [cramjam](https://github.com/milesgranger/pyrus-cramjam) | `2.9.0` | `2.11.0` |\n| [cuda-bindings](https://github.com/NVIDIA/cuda-python) | `13.0.3` | `13.4.2` |\n| [cuda-pathfinder](https://github.com/NVIDIA/cuda-python) | `1.3.3` | `1.8.2` |\n| [cuda-toolkit](https://developer.nvidia.com/cuda-toolkit) | `13.0.3.0` | `13.4.2` |\n| [datamodel-code-generator](https://github.com/datamodel-code-generator/datamodel-code-generator) | `0.26.3` | `0.82.0` |\n| [dataproperty](https://github.com/thombashi/DataProperty) | `1.0.1` | `1.1.1` |\n| [decorator](https://github.com/micheles/decorator) | `5.1.1` | `5.3.1` |\n| detect-installer | `0.1.0` | `0.2.1` |\n| [dill](https://github.com/uqfoundation/dill) | `0.3.8` | `0.4.1` |\n| [distlib](https://github.com/pypa/distlib) | `0.3.9` | `0.4.3` |\n| [dnspython](https://github.com/rthalley/dnspython) | `2.7.0` | `2.8.0` |\n| [docker](https://github.com/docker/docker-py) | `7.1.0` | `7.2.0` |\n| [einx](https://github.com/fferflo/einx) | `0.3.0` | `0.4.3` |\n| [email-validator](https://github.com/JoshData/python-email-validator) | `2.2.0` | `2.3.0` |\n| [fastapi-cloud-cli](https://github.com/fastapilabs/fastapi-cloud-cli) | `0.21.0` | `0.26.0` |\n| [fastar](https://github.com/DoctorJohn/fastar) | `0.11.0` | `0.12.0` |\n| [fastsafetensors](https://github.com/foundation-model-stack/fastsafetensors) | `0.3.2` | `0.4.0` |\n| [fonttools](https://github.com/fonttools/fonttools) | `4.55.0` | `4.65.0` |\n| [frozenlist](https://github.com/aio-libs/frozenlist) | `1.5.0` | `1.8.0` |\n| [genson](https://github.com/wolverdude/genson) | `1.3.0` | `1.4.0` |\n| [google-api-core](https://github.com/googleapis/google-cloud-python) | `2.24.2` | `2.38.0` |\n| [google-auth](https://github.com/googleapis/google-cloud-python) | `2.40.2` | `2.58.0` |\n| [google-cloud-core](https://github.com/googleapis/google-cloud-python) | `2.4.3` | `2.7.0` |\n| [google-cloud-storage](https://github.com/googleapis/google-cloud-python) | `3.4.0` | `3.14.1` |\n| [google-crc32c](https://github.com/googleapis/python-crc32c) | `1.7.1` | `1.8.0` |\n| [google-resumable-media](https://github.com/googleapis/google-cloud-python) | `2.7.2` | `2.10.2` |\n| [googleapis-common-protos](https://github.com/googleapis/google-cloud-python) | `1.70.0` | `1.75.3` |\n| [greenlet](https://github.com/python-greenlet/greenlet) | `3.2.3` | `3.5.6` |\n| [grpcio](https://github.com/grpc/grpc) | `1.78.0` | `1.84.0` |\n| [grpcio-reflection](https://grpc.io) | `1.78.0` | `1.84.0` |\n| [h11](https://github.com/python-hyper/h11) | `0.14.0` | `0.16.0` |\n| [h2](https://github.com/python-hyper/h2) | `4.3.0` | `4.4.1` |\n| [hf-xet](https://github.com/huggingface/xet-core) | `1.5.1` | `1.6.0` |\n| [hiredis](https://github.com/redis/hiredis-py) | `3.0.0` | `3.4.1` |\n| [hpack](https://github.com/python-hyper/hpack) | `4.1.0` | `4.2.0` |\n| [httpx](https://github.com/encode/httpx) | `0.27.2` | `0.28.1` |\n| [humanize](https://github.com/python-humanize/humanize) | `4.11.0` | `4.16.0` |\n| [hypothesis](https://github.com/HypothesisWorks/hypothesis) | `6.131.0` | `6.168.0` |\n| [idna](https://github.com/kjd/idna) | `3.10` | `3.20` |\n| [iniconfig](https://github.com/pytest-dev/iniconfig) | `2.0.0` | `2.3.0` |\n| [instanttensor](https://github.com/scitix/InstantTensor) | `0.1.9` | `0.2.0` |\n| [jiter](https://github.com/pydantic/jiter) | `0.15.0` | `0.17.0` |\n| [jmespath](https://github.com/jmespath/jmespath.py) | `1.0.1` | `1.1.0` |\n| [joblib](https://github.com/joblib/joblib) | `1.4.2` | `1.6.0` |\n| [jsonschema-rs](https://github.com/Stranger6667/jsonschema) | `0.46.5` | `0.57.1` |\n| [kiwisolver](https://github.com/nucleic/kiwi) | `1.4.7` | `1.5.1` |\n| [lazy-loader](https://github.com/scientific-python/lazy-loader) | `0.4` | `0.6` |\n| [llguidance](https://github.com/microsoft/llguidance) | `1.7.6` | `1.8.0` |\n| [llvmlite](https://github.com/numba/llvmlite) | `0.47.0` | `0.49.0` |\n| [mako](https://github.com/sqlalchemy/mako) | `1.3.10` | `1.4.1` |\n| [matplotlib](https://github.com/matplotlib/matplotlib) | `3.9.2` | `3.10.9` |\n| [mpmath](https://github.com/mpmath/mpmath) | `1.3.0` | `1.4.1` |\n| [msal](https://github.com/AzureAD/microsoft-authentication-library-for-python) | `1.34.0` | `1.39.0` |\n| [msgpack](https://github.com/msgpack/msgpack-python) | `1.1.0` | `1.2.2` |\n| [mteb](https://github.com/embeddings-benchmark/mteb) | `2.8.3` | `2.21.6` |\n| [multidict](https://github.com/aio-libs/multidict) | `6.1.0` | `6.9.1` |\n| [mypy-extensions](https://github.com/python/mypy_extensions) | `1.0.0` | `1.1.0` |\n| [networkx](https://github.com/networkx/networkx) | `3.2.1` | `3.4.2` |\n| [nltk](https://github.com/nltk/nltk) | `3.9.1` | `3.10.3` |\n| [nvidia-cublas](https://developer.nvidia.com/cuda-zone) | `13.1.1.3` | `13.8.0.4` |\n| [nvidia-cuda-cupti](https://developer.nvidia.com/cuda-zone) | `13.0.85` | `13.4.92` |\n| [nvidia-cuda-nvrtc](https://developer.nvidia.com/cuda-zone) | `13.0.88` | `13.4.92` |\n| [nvidia-cuda-runtime](https://developer.nvidia.com/cuda-zone) | `13.0.96` | `13.4.92` |\n| [nvidia-cudnn-cu13](https://developer.nvidia.com/cuda-zone) | `9.20.0.48` | `9.26.0.51` |\n| [nvidia-cufft](https://developer.nvidia.com/cuda-zone) | `12.0.0.61` | `12.4.0.43` |\n| [nvidia-cufile](https://developer.nvidia.com/cuda-zone) | `1.15.1.6` | `1.19.1.55` |\n| [nvidia-cusolver](https://developer.nvidia.com/cuda-zone) | `12.0.4.66` | `12.3.4.7` |\n| [nvidia-cusparse](https://developer.nvidia.com/cuda-zone) | `12.6.3.3` | `12.8.6.72` |\n| [nvidia-cusparselt-cu13](https://developer.nvidia.com/cusparselt) | `0.8.1` | `0.9.1` |\n| [nvidia-nccl-cu13](https://developer.nvidia.com/cuda-zone) | `2.29.7` | `2.31.2` |\n| [nvidia-nvjitlink](https://developer.nvidia.com/cuda-zone) | `13.0.88` | `13.4.92` |\n| [nvidia-nvshmem-cu13](https://developer.nvidia.com/cuda-zone) | `3.4.5` | `3.7.2` |\n| [nvidia-nvtx](https://developer.nvidia.com/cuda-zone) | `13.0.85` | `13.4.92` |\n| [opentelemetry-exporter-otlp-proto-common](https://github.com/open-telemetry/opentelemetry-python) | `1.35.0` | `1.44.0` |\n| [opentelemetry-exporter-otlp-proto-grpc](https://github.com/open-telemetry/opentelemetry-python) | `1.35.0` | `1.44.0` |\n| [opentelemetry-exporter-otlp-proto-http](https://github.com/open-telemetry/opentelemetry-python) | `1.35.0` | `1.44.0` |\n| [opentelemetry-exporter-prometheus](https://github.com/open-telemetry/opentelemetry-python) | `0.56b0` | `0.65b0` |\n| [opentelemetry-proto](https://github.com/open-telemetry/opentelemetry-python) | `1.35.0` | `1.44.0` |\n| [opentelemetry-semantic-conventions](https://github.com/open-telemetry/opentelemetry-python) | `0.56b0` | `0.65b0` |\n| [orjson](https://github.com/ijl/orjson) | `3.11.5` | `3.12.0` |\n| [pathvalidate](https://github.com/thombashi/pathvalidate) | `3.2.1` | `3.3.1` |\n| [peft](https://github.com/huggingface/peft) | `0.19.1` | `0.21.0` |\n| [perceptron](https://github.com/perceptron-ai-inc/perceptron) | `0.1.4` | `0.3.5` |\n| [platformdirs](https://github.com/tox-dev/platformdirs) | `4.3.6` | `4.11.11` |\n| [pluggy](https://github.com/pytest-dev/pluggy) | `1.5.0` | `1.6.0` |\n| [polars](https://github.com/pola-rs/polars) | `1.29.0` | `1.44.2` |\n| [pooch](https://github.com/fatiando/pooch) | `1.8.2` | `1.9.0` |\n| [propcache](https://github.com/aio-libs/propcache) | `0.2.0` | `0.5.4` |\n| [proto-plus](https://github.com/googleapis/google-cloud-python) | `1.26.1` | `1.28.4` |\n| [pycryptodomex](https://github.com/Legrandin/pycryptodome) | `3.22.0` | `3.23.0` |\n| [pydantic-core](https://github.com/pydantic/pydantic) | `2.41.1` | `2.49.0` |\n| [pydantic-extra-types](https://github.com/pydantic/pydantic-extra-types) | `2.10.5` | `2.11.1` |\n| [pydantic-settings](https://github.com/pydantic/pydantic-settings) | `2.14.2` | `2.15.0` |\n| [pygments](https://github.com/pygments/pygments) | `2.18.0` | `2.21.0` |\n| [pyjwt](https://github.com/jpadilla/pyjwt) | `2.11.0` | `2.14.0` |\n| [pyparsing](https://github.com/pyparsing/pyparsing) | `3.2.0` | `3.3.3` |\n| [pyrate-limiter](https://github.com/vutran1710/PyrateLimiter) | `4.4.0` | `4.5.0` |\n| [pystemmer](https://github.com/snowballstem/pystemmer) | `3.0.0` | `3.1.0` |\n| [pytest-forked](https://github.com/pytest-dev/pytest-forked) | `1.6.0` | `1.7.5` |\n| [pytest-mock](https://github.com/pytest-dev/pytest-mock) | `3.14.0` | `3.15.1` |\n| [pytest-timeout](https://github.com/pytest-dev/pytest-timeout) | `2.3.1` | `2.4.0` |\n| [python-rapidjson](https://github.com/python-rapidjson/python-rapidjson) | `1.20` | `1.25` |\n| [rapidfuzz](https://github.com/rapidfuzz/RapidFuzz) | `3.12.1` | `3.14.5` |\n| [referencing](https://github.com/python-jsonschema/referencing) | `0.35.1` | `0.37.0` |\n| [responses](https://github.com/getsentry/responses) | `0.25.3` | `0.26.3` |\n| rignore | `0.7.6` | `0.8.1` |\n| runai-model-streamer | `0.15.7` | `0.16.1` |\n| runai-model-streamer-azure | `0.15.7` | `0.16.1` |\n| runai-model-streamer-gcs | `0.15.7` | `0.16.1` |\n| runai-model-streamer-s3 | `0.15.7` | `0.16.1` |\n| [s3transfer](https://github.com/boto/s3transfer) | `0.10.3` | `0.19.2` |\n| [sacrebleu](https://github.com/mjpost/sacrebleu) | `2.4.3` | `2.6.0` |\n| [schemathesis](https://github.com/schemathesis/schemathesis) | `4.21.6` | `4.27.5` |\n| [scikit-learn](https://github.com/scikit-learn/scikit-learn) | `1.5.2` | `1.7.2` |\n| [scipy](https://github.com/scipy/scipy) | `1.13.1` | `1.15.3` |\n| [sentry-sdk](https://github.com/getsentry/sentry-python) | `2.63.0` | `2.69.2` |\n| [six](https://github.com/benjaminp/six) | `1.16.0` | `1.17.0` |\n| [soundfile](https://github.com/bastibe/python-soundfile) | `0.12.1` | `0.14.0` |\n| [statsmodels](https://github.com/statsmodels/statsmodels) | `0.14.4` | `0.15.0` |\n| [sympy](https://github.com/sympy/sympy) | `1.13.3` | `1.14.0` |\n| [tabulate](https://github.com/astanin/python-tabulate) | `0.9.0` | `0.10.0` |\n| [tensorizer](https://github.com/coreweave/tensorizer) | `2.10.1` | `2.12.1` |\n| [termcolor](https://github.com/termcolor/termcolor) | `3.1.0` | `3.3.0` |\n| [threadpoolctl](https://github.com/joblib/threadpoolctl) | `3.5.0` | `3.7.0` |\n| [triton](https://github.com/triton-lang/triton) | `3.7.1` | `3.8.0` |\n| [tritonclient](https://github.com/triton-inference-server/client) | `2.64.0` | `2.71.0` |\n| [typer](https://github.com/fastapi/typer) | `0.26.8` | `0.27.2` |\n| [urllib3](https://github.com/urllib3/urllib3) | `2.2.3` | `2.8.0` |\n| [uvicorn](https://github.com/Kludex/uvicorn) | `0.35.0` | `0.53.0` |\n| [vector-quantize-pytorch](https://github.com/lucidrains/vector-quantizer-pytorch) | `1.21.2` | `1.31.4` |\n| [wcwidth](https://github.com/jquast/wcwidth) | `0.2.13` | `0.8.4` |\n| [yarl](https://github.com/aio-libs/yarl) | `1.17.1` | `1.25.1` |\n| [conch-triton-kernels](https://github.com/stackav-oss/conch) | `1.2.1` | `1.3` |\n| [tpu-inference](https://github.com/vllm-project/tpu-inference) | `0.26.0` | `0.29.0` |\n| pynvvideocodec | `2.0.4` | `2.2.3` |\n| [flashinfer-python](https://github.com/flashinfer-ai/flashinfer) | `0.6.15.post1` | `0.7.0` |\n| [flashinfer-cubin](https://github.com/flashinfer-ai/flashinfer) | `0.6.15.post1` | `0.7.0` |\n| [nvidia-cutlass-dsl](https://github.com/NVIDIA/cutlass) | `4.6.0` | `4.8.0` |\n| [tokenspeed-mla](https://github.com/lightseekorg/tokenspeed) | `0.1.8` | `0.2.10` |\n| [auto-round-lib](https://github.com/intel/auto-round) | `0.14.2` | `0.15.0` |\n| griffelib | `2.0.2` | `2.3.0` |\n| [mkdocs-git-revision-date-localized-plugin](https://github.com/timvink/mkdocs-git-revision-date-localized-plugin) | `1.5.1` | `1.6.0` |\n| [ruff](https://github.com/astral-sh/ruff) | `0.15.12` | `0.16.8` |\n| [zentorch](https://github.com/amd/ZenDNN-pytorch-plugin) | `2.11.0.0` | `2.14.0.0` |\n\n\nUpdates `tblib` from 3.1.0 to 3.2.2\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/ionelmc/python-tblib/blob/master/CHANGELOG.rst\"\u003etblib's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e3.2.2 (2025-11-12)\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003e\n* Fixed regression occurring with ``TimeoutError`` exceptions. They should be represented now exactly as the original when unpickling.\n  Contributed by Jacob Tomlinson in `[#85](https://github.com/ionelmc/python-tblib/issues/85) \u0026lt;https://github.com/ionelmc/python-tblib/pull/85\u0026gt;`_.\n\u003cp\u003e3.2.1 (2025-10-31)\n\u003c/code\u003e\u003c/pre\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eFixed regression occurring with \u003ccode\u003eExceptionGroup\u003c/code\u003e exceptions. That exception type is now handled specifically in the new \u003ccode\u003eunpickle_exception_with_attrs\u003c/code\u003e function (just like \u003ccode\u003eOSError\u003c/code\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e3.2.0 (2025-10-21)\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003e\n* Changed ``tblib.pickling_support.install`` to support exceptions with ``__init__`` that does match the default\n  ``BaseException.__reduce__`` (as it expects the positional arguments to ``__init__`` to match the ``args`` attribute).\n\u003cp\u003eSpecial handling for OSError (and subclasses) is also included. The errno, strerror, winerror, filename and filename2 attributes will be added in the reduce structure (if set).\u003c/p\u003e\n\u003cp\u003eThis will support exception subclasses that do this without defining a custom \u003ccode\u003e__reduce__\u003c/code\u003e:\u003c/p\u003e\n\u003cp\u003e.. code-block:: python\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003edef __init__(self):\n    super().__init__('mistery argument')\n\ndef __init__(self, mistery_argument):\n    super().__init__()\n    self.mistery_argument = mistery_argument\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eTests and POC contributed by Oldřich Jedlička in \u003ccode\u003e[#73](https://github.com/ionelmc/python-tblib/issues/73) \u0026amp;lt;https://github.com/ionelmc/python-tblib/pull/73\u0026amp;gt;\u003c/code\u003e_.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eFixed some doctest and coverage config. Contributed by Colin Watson in \u003ccode\u003e[#79](https://github.com/ionelmc/python-tblib/issues/79) \u0026amp;lt;https://github.com/ionelmc/python-tblib/pull/79\u0026amp;gt;\u003c/code\u003e_.\n\u003c/code\u003e\u003c/pre\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/d88606aab343749dfeccf16a813f63cbe2dae11e\"\u003e\u003ccode\u003ed88606a\u003c/code\u003e\u003c/a\u003e Bump version: 3.2.1 → 3.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/530f8743f1ed322f220621d8491e660636065279\"\u003e\u003ccode\u003e530f874\u003c/code\u003e\u003c/a\u003e Add test for timeouterror regression. Ref \u003ca href=\"https://redirect.github.com/ionelmc/python-tblib/issues/85\"\u003e#85\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/9c8f2ca0e7c061cc423207986af6f06aaa76cfee\"\u003e\u003ccode\u003e9c8f2ca\u003c/code\u003e\u003c/a\u003e Update changelog.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/df6185d4b942a37d48a0e082b885380b8c5cc5ad\"\u003e\u003ccode\u003edf6185d\u003c/code\u003e\u003c/a\u003e Handle optional OSError attributes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/b197023aa86b831834393fdd89c6439fe2ffaf0c\"\u003e\u003ccode\u003eb197023\u003c/code\u003e\u003c/a\u003e Bump version: 3.2.0 → 3.2.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/d71e1edc9da5a86e326406ea4372cce5c075b4f4\"\u003e\u003ccode\u003ed71e1ed\u003c/code\u003e\u003c/a\u003e Update changelog.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/74ec64570acb0d6ce708c695ab98d52d08f8b066\"\u003e\u003ccode\u003e74ec645\u003c/code\u003e\u003c/a\u003e Specifically handle ExceptionGroup in the new unpickle_exception_with_attrs. ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/580d57921a6e93660bf47771f70c0bfbe70e9c97\"\u003e\u003ccode\u003e580d579\u003c/code\u003e\u003c/a\u003e Ooops, forgot to update these.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/ebc83e93b6342950cb93cf296991fb99ce4aa13a\"\u003e\u003ccode\u003eebc83e9\u003c/code\u003e\u003c/a\u003e Bump version: 3.1.0 → 3.2.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/abec37d4526fb86f95c7567644f1fd6c2cec4215\"\u003e\u003ccode\u003eabec37d\u003c/code\u003e\u003c/a\u003e Update changelog and add one more test.\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/ionelmc/python-tblib/compare/v3.1.0...v3.2.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `regex` from 2026.2.28 to 2026.9.10\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/mrabarnett/mrab-regex/blob/hg/changelog.txt\"\u003eregex's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003eVersion: 2026.9.19\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eGit issue 619: `Match.expand()` segfaults after `detach_string()` when the template references a group\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.9.10\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eFixed version.\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.9.9\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003ePR [#615](https://github.com/mrabarnett/mrab-regex/issues/615): Fix Python API error propagation in match helpers\n\u003cp\u003ePR \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/616\"\u003e#616\u003c/a\u003e: Preserve Python Exceptions in Input Decoding and String Detachment\u003c/p\u003e\n\u003cp\u003ePR \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/617\"\u003e#617\u003c/a\u003e: Prevent Invalid Pointer Use and Exception State Corruption in Byte String Joining\u003c/p\u003e\n\u003cp\u003ePR \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/618\"\u003e#618\u003c/a\u003e: Propagate Allocation and Internal Errors During Pattern Compilation and Scanner Execution\n\u003c/code\u003e\u003c/pre\u003e\u003c/p\u003e\n\u003cp\u003eVersion: 2026.9.3\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eNew version of cibuildwheel no longer supports building for free-threaded Python 3.13.\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.9.2\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eNew version of cibuildwheel no longer needs nor supports cpython-freethreading option.\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.9.1\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eUpdated cibuildwheel.\nSupport Python 3.15.\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.8.31\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eFixed version.\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.8.30\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eGit issue 611: Heap out-of-bounds write at compile time\nGit issue 612: count_one() size underflow through the stale required-string cache\nGit issue 613: (*SKIP) inside an atomic group, plus an equality-only scan stop\nGit issue 614: build_GROUP() does not propagate the match direction\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.8.12\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eSupport Python 3.15.\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.7.19\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eGit issue 607: SIGSEGV: NULL pointer dereference in `basic_match()` when `(?R)`/`(?0)` recursion is used inside a fuzzy-matching quantifier\nGit issue 608: SIGSEGV: out-of-bounds read in `bytes1_char_at()` with `DOTALL` + a fuzzy constraint + `(?r)` reverse-direction matching\n\u003c/code\u003e\u003c/pre\u003e\n\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/7dd71c15c4fb5c94206bed1763abd4c2bd2f1b33\"\u003e\u003ccode\u003e7dd71c1\u003c/code\u003e\u003c/a\u003e Fixed version.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/59124d62299e212931786aa74ead15388abaf376\"\u003e\u003ccode\u003e59124d6\u003c/code\u003e\u003c/a\u003e PR \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/615\"\u003e#615\u003c/a\u003e: Fix Python API error propagation in match helpers\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/25e15218bd44ca26677e3c28709e94a0ca0d9b8e\"\u003e\u003ccode\u003e25e1521\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/618\"\u003e#618\u003c/a\u003e from dynapx/fix-compiler-error-propagation\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/3ad78cfb73850c2f1178d19553fa14661f73d9cb\"\u003e\u003ccode\u003e3ad78cf\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/616\"\u003e#616\u003c/a\u003e from dynapx/fix-detach-string-error-propagation\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/f54253c332574bd5a9d96d3ec9d62b5db954dac7\"\u003e\u003ccode\u003ef54253c\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/615\"\u003e#615\u003c/a\u003e from dynapx/fix-python-api-error-propagation\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/c44224476cd6a6e53be0e458dfdcf3b81d76e426\"\u003e\u003ccode\u003ec442244\u003c/code\u003e\u003c/a\u003e Propagate scanner internal errors\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/68837e7af862250cd08fa49ff584a2bbff246e0f\"\u003e\u003ccode\u003e68837e7\u003c/code\u003e\u003c/a\u003e Propagate node stack allocation failures\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/f1df5387982d526cc9475fddcc8d1043b02ffc9a\"\u003e\u003ccode\u003ef1df538\u003c/code\u003e\u003c/a\u003e Propagate check stack allocation failures\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/d8873b119a49cde8d2613253827bf973261bb2bc\"\u003e\u003ccode\u003ed8873b1\u003c/code\u003e\u003c/a\u003e Preserve Python exceptions in input decoding\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/910784fb8039c445a68e84a261119a96031c811c\"\u003e\u003ccode\u003e910784f\u003c/code\u003e\u003c/a\u003e Propagate detach_string slicing errors\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/mrabarnett/mrab-regex/compare/2026.2.28...2026.9.10\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `requests` from 2.32.3 to 2.34.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/psf/requests/releases\"\u003erequests's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.34.2\u003c/h2\u003e\n\u003ch2\u003e2.34.2 (2026-05-14)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMoved \u003ccode\u003eheaders\u003c/code\u003e input type back to \u003ccode\u003eMapping\u003c/code\u003e to avoid invariance issues with \u003ccode\u003eMutableMapping\u003c/code\u003e and inferred dict types. Users calling \u003ccode\u003eRequest.headers.update()\u003c/code\u003e may need to narrow typing in their code. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7441\"\u003e#7441\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/psf/requests/blob/main/HISTORY.md#2342-2026-05-14\"\u003ehttps://github.com/psf/requests/blob/main/HISTORY.md#2342-2026-05-14\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.34.1\u003c/h2\u003e\n\u003ch2\u003e2.34.1 (2026-05-13)\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eBugfixes\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eWidened \u003ccode\u003ejson\u003c/code\u003e input type from \u003ccode\u003edict\u003c/code\u003e and \u003ccode\u003elist\u003c/code\u003e to \u003ccode\u003eMapping\u003c/code\u003e\nand \u003ccode\u003eSequence\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7436\"\u003e#7436\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eChanged \u003ccode\u003eheaders\u003c/code\u003e input type to MutableMapping and removed \u003ccode\u003eNone\u003c/code\u003e from\n\u003ccode\u003eRequest.headers\u003c/code\u003e typing to improve handling for users. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7431\"\u003e#7431\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eResponse.reason\u003c/code\u003e moved from \u003ccode\u003estr | None\u003c/code\u003e to \u003ccode\u003estr\u003c/code\u003e to improve handling\nfor users. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7437\"\u003e#7437\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed a bug where some bodies with custom \u003ccode\u003e__getattr__\u003c/code\u003e implementations\nweren't being properly detected as Iterables. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7433\"\u003e#7433\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/k223kim\"\u003e\u003ccode\u003e@​k223kim\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/psf/requests/pull/7433\"\u003epsf/requests#7433\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/psf/requests/blob/main/HISTORY.md#2341-2026-05-13\"\u003ehttps://github.com/psf/requests/blob/main/HISTORY.md#2341-2026-05-13\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.34.0\u003c/h2\u003e\n\u003ch2\u003e2.34.0 (2026-05-11)\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eAnnouncements\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eRequests 2.34.0 introduces inline types, replacing those provided by\ntypeshed. Public API types should be fully compatible with mypy, pyright,\nand ty. \u003cstrong\u003eWe believe types are comprehensive but if you find issues, please\nreport them to the \u003ca href=\"https://redirect.github.com/psf/requests/issues/7271\"\u003epinned tracking issue\u003c/a\u003e.\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eSpecial thanks to \u003ca href=\"https://github.com/bastimeyer\"\u003e\u003ccode\u003e@​bastimeyer\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/cthoyt\"\u003e\u003ccode\u003e@​cthoyt\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/edgarrmondragon\"\u003e\u003ccode\u003e@​edgarrmondragon\u003c/code\u003e\u003c/a\u003e, and \u003ca href=\"https://github.com/srittau\"\u003e\u003ccode\u003e@​srittau\u003c/code\u003e\u003c/a\u003e for\nhelping review and test the types ahead of the release. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7272\"\u003e#7272\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eImprovements\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eDigest Auth hashing algorithms have added \u003ccode\u003eusedforsecurity=False\u003c/code\u003e to clarify\nsecurity considerations. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7310\"\u003e#7310\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests added support for Python 3.15 based on beta1. Downstream projects\nshould be able to start testing prior to its release in October. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7422\"\u003e#7422\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests added support for Python 3.14t. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7419\"\u003e#7419\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eBugfixes\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eResponse.history\u003c/code\u003e no longer contains a reference to itself, preventing\naccidental looping when traversing the history list. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7328\"\u003e#7328\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests no longer performs greedy matching on no_proxy domains. The\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/psf/requests/blob/main/HISTORY.md\"\u003erequests's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e2.34.2 (2026-05-14)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMoved \u003ccode\u003eheaders\u003c/code\u003e input type back to \u003ccode\u003eMapping\u003c/code\u003e to avoid invariance issues\nwith \u003ccode\u003eMutableMapping\u003c/code\u003e and inferred dict types. Users calling\n\u003ccode\u003eRequest.headers.update()\u003c/code\u003e may need to narrow typing in their code. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7441\"\u003e#7441\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.34.1 (2026-05-13)\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eBugfixes\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eWidened \u003ccode\u003ejson\u003c/code\u003e input type from \u003ccode\u003edict\u003c/code\u003e and \u003ccode\u003elist\u003c/code\u003e to \u003ccode\u003eMapping\u003c/code\u003e\nand \u003ccode\u003eSequence\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7436\"\u003e#7436\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eChanged \u003ccode\u003eheaders\u003c/code\u003e input type to MutableMapping and removed \u003ccode\u003eNone\u003c/code\u003e from\n\u003ccode\u003eRequest.headers\u003c/code\u003e typing to improve handling for users. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7431\"\u003e#7431\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eResponse.reason\u003c/code\u003e moved from \u003ccode\u003estr | None\u003c/code\u003e to \u003ccode\u003estr\u003c/code\u003e to improve handling\nfor users. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7437\"\u003e#7437\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed a bug where some bodies with custom \u003ccode\u003e__getattr__\u003c/code\u003e implementations\nweren't being properly detected as Iterables. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7433\"\u003e#7433\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.34.0 (2026-05-11)\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eAnnouncements\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eRequests 2.34.0 introduces inline types, replacing those provided by\ntypeshed. Public API types should be fully compatible with mypy, pyright,\nand ty. We believe types are comprehensive but if you find issues, please\nreport them to the pinned tracking issue.\u003c/p\u003e\n\u003cp\u003eSpecial thanks to \u003ca href=\"https://github.com/bastimeyer\"\u003e\u003ccode\u003e@​bastimeyer\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/cthoyt\"\u003e\u003ccode\u003e@​cthoyt\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/edgarrmondragon\"\u003e\u003ccode\u003e@​edgarrmondragon\u003c/code\u003e\u003c/a\u003e, and \u003ca href=\"https://github.com/srittau\"\u003e\u003ccode\u003e@​srittau\u003c/code\u003e\u003c/a\u003e for\nhelping review and test the types ahead of the release. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7272\"\u003e#7272\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eImprovements\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eDigest Auth hashing algorithms have added \u003ccode\u003eusedforsecurity=False\u003c/code\u003e to clarify\nsecurity considerations. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7310\"\u003e#7310\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests added support for Python 3.15 based on beta1. Downstream projects\nshould be able to start testing prior to its release in October. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7422\"\u003e#7422\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests added support for Python 3.14t. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7419\"\u003e#7419\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eBugfixes\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eResponse.history\u003c/code\u003e no longer contains a reference to itself, preventing\naccidental looping when traversing the history list. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7328\"\u003e#7328\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests no longer performs greedy matching on no_proxy domains. The\nproxy_bypass implementation has been updated with CPython's fix from\nbpo-39057. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7427\"\u003e#7427\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests no longer incorrectly strips duplicate leading slashes in\nURI paths. This should address user issues with specific presigned\nURLs. Note the full fix requires urllib3 2.7.0+. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7315\"\u003e#7315\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/6e83187b8feb273ed4c6cdab5efd8d54901dfab3\"\u003e\u003ccode\u003e6e83187\u003c/code\u003e\u003c/a\u003e v2.34.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/84d10f0be83e8f6aeca8a05230c52216431c4d0b\"\u003e\u003ccode\u003e84d10f0\u003c/code\u003e\u003c/a\u003e Move Request.headers back to Mapping (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7441\"\u003e#7441\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/b7b549b54571d03950b16afd2d01bc6ff0348224\"\u003e\u003ccode\u003eb7b549b\u003c/code\u003e\u003c/a\u003e v2.34.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/e511bc72777a94c45d004e010c597925092e1efe\"\u003e\u003ccode\u003ee511bc7\u003c/code\u003e\u003c/a\u003e Fix mutability issues with headers input types (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7431\"\u003e#7431\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/5691f596134c2feb121e595c77a0178921fcce61\"\u003e\u003ccode\u003e5691f59\u003c/code\u003e\u003c/a\u003e Update JsonType containers to read-based collections (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7436\"\u003e#7436\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/2144213c307691710c9d665700860fc4993c3035\"\u003e\u003ccode\u003e2144213\u003c/code\u003e\u003c/a\u003e Constrain Response.reason to str (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7437\"\u003e#7437\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/6404f345e562d962abe6700a1c357ec1e7e18232\"\u003e\u003ccode\u003e6404f34\u003c/code\u003e\u003c/a\u003e Fix \u003ccode\u003eprepare_body\u003c/code\u003e stream detection for \u003ccode\u003e__getattr__\u003c/code\u003e-based file wrappers (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7\"\u003e#7\u003c/a\u003e...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/0b401c76b6e80a4eecf3c690085b2553f6e261ca\"\u003e\u003ccode\u003e0b401c7\u003c/code\u003e\u003c/a\u003e v2.34.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/86b378d3f60f828daa13ca50aa82e287ff7b66b4\"\u003e\u003ccode\u003e86b378d\u003c/code\u003e\u003c/a\u003e Align Session.get parameters with requests.get (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7429\"\u003e#7429\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/a4f9a5999bdb9bf2d6e7c8aa973b28cacb17134f\"\u003e\u003ccode\u003ea4f9a59\u003c/code\u003e\u003c/a\u003e Port bpo-39057 to Requests (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7427\"\u003e#7427\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/psf/requests/compare/v2.32.3...v2.34.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `tqdm` from 4.67.3 to 4.70.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/tqdm/tqdm/releases\"\u003etqdm's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003etqdm v4.70.1 stable\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003econtrib.concurrent\u003c/code\u003e: fix no-len iterables (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1830\"\u003e#1830\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1828\"\u003e#1828\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003etests: major overhaul (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1819\"\u003e#1819\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eupdate AI policy in PR template\u003c/li\u003e\n\u003cli\u003emisc lint \u0026amp; tidy\u003c/li\u003e\n\u003cli\u003eCI: bump workflow actions \u0026amp; pre-commit hooks\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003etqdm v4.70.0 stable\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003econtrib.concurrent\u003c/code\u003e: major improvements\n\u003cul\u003e\n\u003cli\u003esupport \u003ccode\u003eprocess_map(mp_context, max_tasks_per_child)\u003c/code\u003e, \u003ccode\u003ethread_map(thread_name_prefix)\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1265\"\u003e#1265\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix \u003ccode\u003etotal\u003c/code\u003e based on shortest iterable length (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1473\"\u003e#1473\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003euse default \u003ccode\u003emax_workers\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1543\"\u003e#1543\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1530\"\u003e#1530\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1518\"\u003e#1518\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003esupport \u003ccode\u003etimeout\u003c/code\u003e, \u003ccode\u003ebuffersize\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1576\"\u003e#1576\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eimprove ETA (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1708\"\u003e#1708\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1161\"\u003e#1161\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eupdate \u003ccode\u003eas_completed\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1709\"\u003e#1709\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1565\"\u003e#1565\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eadd \u003ccode\u003etqdm.concurrent.intepreter_map\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1777\"\u003e#1777\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003easyncio\u003c/code\u003e: support iterables with only \u003ccode\u003e__aiter__\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1714\"\u003e#1714\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1686\"\u003e#1686\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003esupport \u003ccode\u003ereset(float(\u0026quot;inf\u0026quot;))\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1783\"\u003e#1783\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1781\"\u003e#1781\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/651\"\u003e#651\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eframework: test \u0026amp; reduce wheel size (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1782\"\u003e#1782\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003etqdm v4.69.1 stable\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003econtrib.logging\u003c/code\u003e: preserve filters (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1775\"\u003e#1775\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1581\"\u003e#1581\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003erich\u003c/code\u003e: misc fixes (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1773\"\u003e#1773\u003c/a\u003e)\n\u003cul\u003e\n\u003cli\u003esupport generators (without \u003ccode\u003elen\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1391\"\u003e#1391\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix potential \u003ccode\u003eAttributeError\u003c/code\u003e on exit (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1674\"\u003e#1674\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003efix \u003ccode\u003etotal=float('inf')\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1781\"\u003e#1781\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/651\"\u003e#651\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix potential \u003ccode\u003eAttributeError\u003c/code\u003e on exit (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1778\"\u003e#1778\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1668\"\u003e#1668\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1537\"\u003e#1537\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/261\"\u003e#261\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix minor docs typos (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1780\"\u003e#1780\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1746\"\u003e#1746\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003etqdm v4.69.0 stable\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eadd \u003ccode\u003etqdm.asyncio.gather(..., return_exceptions=False)\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1776\"\u003e#1776\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1671\"\u003e#1671\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1286\"\u003e#1286\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003emisc minor framework updates\n\u003cul\u003e\n\u003cli\u003ebump workflow actions \u0026amp; pre-commit hooks\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003etqdm v4.68.4 stable\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003etrim to \u003ccode\u003encols\u003c/code\u003e even when \u003ccode\u003e'{bar}' not in bar_format\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1717\"\u003e#1717\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1767\"\u003e#1767\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1658\"\u003e#1658\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix \u003ccode\u003etqdm.write\u003c/code\u003e when \u003ccode\u003estdout=None\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1768\"\u003e#1768\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1654\"\u003e#1654\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003etqdm v4.68.3 stable\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eutils\u003c/code\u003e: delay \u003ccode\u003eos.get_terminal_size\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1763\"\u003e#1763\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1760\"\u003e#1760\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eautonotebook\u003c/code\u003e: support QtConsole, Spyder, JupyterLite (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1763\"\u003e#1763\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1628\"\u003e#1628\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1559\"\u003e#1559\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1283\"\u003e#1283\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1098\"\u003e#1098\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/512\"\u003e#512\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eminor docs updates\n\u003cul\u003e\n\u003cli\u003efix typo (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1762\"\u003e#1762\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003euse \u003ccode\u003egit-fame\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003emisc minor framework updates\n\u003cul\u003e\n\u003cli\u003efix \u0026amp; update CI build\u003c/li\u003e\n\u003cli\u003epre-commit: add docs \u0026amp; metadata generation\u003c/li\u003e\n\u003cli\u003emove \u003ccode\u003etox.ini\u003c/code\u003e -\u0026gt; \u003ccode\u003epyproject.toml\u003c/code\u003e, move \u003ccode\u003etox-gh-actions\u003c/code\u003e -\u0026gt; \u003ccode\u003etox-gh\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eadd Python 3.14, drop 3.7 support\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/9cf5a12b1f955468a17f0ba3c59092b23e4258ac\"\u003e\u003ccode\u003e9cf5a12\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1830\"\u003e#1830\u003c/a\u003e from eaubin/master\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/24b9e1e08a097f1c30f2d235b63f9eb25ba47974\"\u003e\u003ccode\u003e24b9e1e\u003c/code\u003e\u003c/a\u003e misc tidy\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/2a9e4e82ddba07c5dd6d126e23a4745b76ea49c8\"\u003e\u003ccode\u003e2a9e4e8\u003c/code\u003e\u003c/a\u003e contrib.concurrent: fix no-len iterables\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/8d6ff8de5a9066de77d0a9df3e80a022a3dcf146\"\u003e\u003ccode\u003e8d6ff8d\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1819\"\u003e#1819\u003c/a\u003e from tqdm/devel\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/bed379609c2c8300671c784c8f85a185c8cf6fb3\"\u003e\u003ccode\u003ebed3796\u003c/code\u003e\u003c/a\u003e tests: major overhaul\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/4d3d3194d5467e0701bc0f4b836a735273ef0868\"\u003e\u003ccode\u003e4d3d319\u003c/code\u003e\u003c/a\u003e AI policy\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/5dcb022b55553b60ed2131b64aa5bf1e65470df1\"\u003e\u003ccode\u003e5dcb022\u003c/code\u003e\u003c/a\u003e minor syntax update\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/309effe4244bf45427c5add7f1bcf33f98a7b421\"\u003e\u003ccode\u003e309effe\u003c/code\u003e\u003c/a\u003e tests: pre-commit coverage\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/604193aa03b5f5c0ad5f3d441951f0fbb515f1e4\"\u003e\u003ccode\u003e604193a\u003c/code\u003e\u003c/a\u003e tests: slight tidy\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/17f1cac07c89943eb0e6082875b3821205308d4f\"\u003e\u003ccode\u003e17f1cac\u003c/code\u003e\u003c/a\u003e CI: bump workflow actions\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/tqdm/tqdm/compare/v4.67.3...v4.70.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `transformers` from 5.14.1 to 5.17.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/huggingface/transformers/releases\"\u003etransformers's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eRelease 5.17.0\u003c/h2\u003e\n\u003ch1\u003eRelease v5.17.0\u003c/h1\u003e\n\u003ch2\u003eNew Model additions\u003c/h2\u003e\n\u003ch3\u003eHYV4\u003c/h3\u003e\n\n\u003cp\u003eHy4-Preview is a 780B-parameter mixture-of-experts language model that activates 49B parameters per\ntoken. Each MoE layer holds 256 routed experts plus one always-active shared expert and routes every\ntoken to 8 of them. The context window is 1M tokens.\u003c/p\u003e\n\u003cp\u003eThe architecture combines four features:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eMulti-head Latent Attention (MLA)\u003c/strong\u003e compresses keys and values into a low-rank latent\n(\u003ccode\u003ekv_lora_rank\u003c/code\u003e) that \u003ccode\u003ekv_b_proj\u003c/code\u003e expands back to one key/value per query head.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eDeepSeek Sparse Attention (DSA)\u003c/strong\u003e selects \u003ccode\u003eindex_topk\u003c/code\u003e keys per query with a lightweight indexer.\nFollowing \u003ca href=\"https://huggingface.co/papers/2603.12201\"\u003eIndexShare\u003c/a\u003e, only the layers marked \u003ccode\u003e\u0026quot;full\u0026quot;\u003c/code\u003e\nin \u003ccode\u003eindexer_types\u003c/code\u003e run an indexer; \u003ccode\u003e\u0026quot;shared\u0026quot;\u003c/code\u003e layers reuse the previous full layer's selection.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eGated MLA with learnable attention sinks\u003c/strong\u003e, where each head owns a sink logit that participates\nin the softmax and contributes no value, as in \u003ca href=\"https://github.com/huggingface/transformers/blob/HEAD/gpt_oss\"\u003eGPT-OSS\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eIndependent Hyper-Connections (iHC)\u003c/strong\u003e replace the plain residual path with \u003ccode\u003ehc_mult\u003c/code\u003e parallel\nresidual streams that are collapsed before, and redistributed after, every sublayer.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThe implementation does not execute the multi-token prediction (MTP) layers. Released checkpoints\nkeep those weights so that other runtimes can use them for speculative decoding; they are ignored\nat load time.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/hy_v4\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAdd h4 (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48473\"\u003e#48473\u003c/a\u003e) by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/transformers/pull/48473\"\u003e#48473\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eVibeVoice\u003c/h3\u003e\n\n\u003cp\u003e\u003ca href=\"https://huggingface.co/papers/2508.19205\"\u003eVibeVoice\u003c/a\u003e is a novel framework for synthesizing high-fidelity, long-form speech with multiple speakers by employing a next-token diffusion approach within a Large Language Model (LLM) structure. It's designed to capture the authentic conversational \u0026quot;vibe\u0026quot; and is particularly suited for generating audio content like podcasts and multi-participant audiobooks.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/vibevoice\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eImplement VibeVoice  (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/40546\"\u003e#40546\u003c/a\u003e) by \u003ca href=\"https://github.com/pengzhiliang\"\u003e\u003ccode\u003e@​pengzhiliang\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/transformers/pull/40546\"\u003e#40546\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eNeoMME\u003c/h3\u003e\n\u003cp\u003eNeoMME is a family of efficient 260M and 800M parameter multimodal-native multilingual foundation encoders from H Company. It processes multilingual text tokens and raw image patches in a single bidirectional Transformer encoder, without a separately pretrained vision tower or causal language model.\u003c/p\u003e\n\u003cp\u003eNeoMME-Retriever is a model fine-tuned from the NeoMME backbone for visual document retrieval with joint late-interaction and dense objectives. It takes text queries and documents (text or page screenshots) and produces multi-vector embeddings for MeanMaxSim scoring (late-interaction) and mean-pooled embeddings for cosine similarity (dense).\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/neomme\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/856157a2f3e9594954310df18fdccc31ffddebe9\"\u003e\u003ccode\u003e856157a\u003c/code\u003e\u003c/a\u003e v5.17.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/5b7dcb0d36c242d8d85920a81c564ef3a86ca6dd\"\u003e\u003ccode\u003e5b7dcb0\u003c/code\u003e\u003c/a\u003e MRoPE continued (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48594\"\u003e#48594\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/50bbcc630ed1675d15d2def3877c88d6c2630415\"\u003e\u003ccode\u003e50bbcc6\u003c/code\u003e\u003c/a\u003e [fix] Update stale expected strings in HunYuanVL integration tests (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48646\"\u003e#48646\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/e8bcd79c4c77a529bc34d6e19f7d718164b7fa6a\"\u003e\u003ccode\u003ee8bcd79\u003c/code\u003e\u003c/a\u003e [Quantizaiton]support 5/6/7 bits in AutoRound (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48481\"\u003e#48481\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/3283d5f78ed6836d39430c8190a6e0500be78698\"\u003e\u003ccode\u003e3283d5f\u003c/code\u003e\u003c/a\u003e [fix] Update stale golden values and fix expected_logits shape in FlavaForPre...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/5f47b5aad791b69dff597b903614fb2bef8b88a1\"\u003e\u003ccode\u003e5f47b5a\u003c/code\u003e\u003c/a\u003e [tests] Fix integration test golden values broken by fast image processor def...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/fc501343edfccdc840eb8594a6cafa8185c2de53\"\u003e\u003ccode\u003efc50134\u003c/code\u003e\u003c/a\u003e Add Fun-ASR-Nano model (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46180\"\u003e#46180\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/d9fe823d1cedbba33dd0aeef08f773abe971688e\"\u003e\u003ccode\u003ed9fe823\u003c/code\u003e\u003c/a\u003e Fix YOLOS device mismatch with device_map=\u0026quot;auto\u0026quot; (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46886\"\u003e#46886\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/cbc1651a032b923da7f4b44b3d0e6f68e6ba6b55\"\u003e\u003ccode\u003ecbc1651\u003c/code\u003e\u003c/a\u003e [\u003ccode\u003eGenerate\u003c/code\u003e] Avoid unconditionally downloading remote hub file (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48620\"\u003e#48620\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/bd05a4b2baf8b37b8f64c0c2c70d2628583f7c2a\"\u003e\u003ccode\u003ebd05a4b\u003c/code\u003e\u003c/a\u003e Honor \u003ccode\u003eshift_labels\u003c/code\u003e in decoder-only LLM/VLM losses (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48493\"\u003e#48493\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/huggingface/transformers/compare/v5.14.1...v5.17.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `huggingface-hub` from 1.26.0 to 1.32.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/huggingface/huggingface_hub/releases\"\u003ehuggingface-hub's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e[v1.32.0] Shared blob store, sandbox security hardening and faster imports\u003c/h2\u003e\n\u003ch2\u003e:open_file_folder: [Cache] Shared blob store: deduplicate Xet files across repos\u003c/h2\u003e\n\u003cp\u003eThe cache now deduplicates Xet files across repos. A Xet file downloaded through \u003ccode\u003ehf_xet\u003c/code\u003e is stored once at \u003ccode\u003e\u0026lt;CACHE_DIR\u0026gt;/blobs/\u0026lt;prefix\u0026gt;/\u0026lt;xet_hash\u0026gt;\u003c/code\u003e and every repo that needs it gets a relative symlink instead of a download: no bytes are transferred and no extra space is used, even across different repos — or after the repo that first downloaded the file was deleted. The per-repo snapshot layout is unchanged, older clients keep reading and downloading normally, and any failure to share silently falls back to regular repo-local storage. Set \u003ccode\u003eHF_HUB_DISABLE_SHARED_BLOBS=1\u003c/code\u003e to opt out entirely. Shared files carry a \u003ccode\u003e\u0026lt;xet_hash\u0026gt;.refs\u003c/code\u003e manifest listing the repo blobs referencing them, which \u003ccode\u003ehf cache rm\u003c/code\u003e consults on deletion and \u003ccode\u003ehf cache prune\u003c/code\u003e sweeps to reclaim payloads that no cached repo uses anymore.\u003c/p\u003e\n\u003cp\u003e📚 \u003cstrong\u003eDocumentation:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/huggingface_hub/main/en/guides/manage-cache\"\u003eManage your cache\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e[Cache] Add cross-repo shared blob store by \u003ca href=\"https://github.com/hanouticelina\"\u003e\u003ccode\u003e@​hanouticelina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4498\"\u003e#4498\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e:computer: [Jobs] Ship config inside UV scripts\u003c/h2\u003e\n\u003cp\u003eA UV script that only runs correctly on a specific runtime can now carry that runtime with it. An optional \u003ccode\u003e[tool.hf-jobs]\u003c/code\u003e table in the script's PEP 723 header accepts \u003ccode\u003eimage\u003c/code\u003e, \u003ccode\u003eflavor\u003c/code\u003e, \u003ccode\u003epython\u003c/code\u003e, \u003ccode\u003etimeout\u003c/code\u003e, \u003ccode\u003ename\u003c/code\u003e, \u003ccode\u003enamespace\u003c/code\u003e, \u003ccode\u003eenv\u003c/code\u003e, \u003ccode\u003esecrets\u003c/code\u003e, \u003ccode\u003elabels\u003c/code\u003e, \u003ccode\u003evolumes\u003c/code\u003e, \u003ccode\u003enetwork_group\u003c/code\u003e and \u003ccode\u003enetwork_aliases\u003c/code\u003e, and \u003ccode\u003ehf jobs uv run\u003c/code\u003e reads it at submit time. CLI flags always win, and \u003ccode\u003eenv\u003c/code\u003e/\u003ccode\u003esecrets\u003c/code\u003e/\u003ccode\u003elabels\u003c/code\u003e/\u003ccode\u003evolumes\u003c/code\u003e merge entry by entry instead of being replaced, so \u003ccode\u003e-e\u003c/code\u003e/\u003ccode\u003e-v\u003c/code\u003e add to what the script declares. Typos and unknown keys are rejected with the list of valid options, secrets are passed by name only (values come from your environment), and every run prints a config summary with script-sourced values marked and secrets redacted. Note that the table is read by the CLI only: \u003ccode\u003erun_uv_job()\u003c/code\u003e and \u003ccode\u003ecreate_scheduled_uv_job()\u003c/code\u003e ignore it.\u003c/p\u003e\n\u003cpre lang=\"python\"\u003e\u003ccode\u003e# /// script\r\n# requires-python = \u0026quot;\u0026gt;=3.11\u0026quot;\r\n# dependencies = [\u0026quot;vllm\u0026quot;, \u0026quot;datasets\u0026quot;]\r\n#\r\n# [tool.hf-jobs]\r\n# image   = \u0026quot;vllm/vllm-openai:unlimited-ocr\u0026quot;\r\n# flavor  = \u0026quot;l4x1\u0026quot;\r\n# python  = \u0026quot;/usr/bin/python3\u0026quot;\r\n# secrets = [\u0026quot;HF_TOKEN\u0026quot;]\r\n# ///\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003e📚 \u003cstrong\u003eDocumentation:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/huggingface_hub/main/en/guides/jobs\"\u003eRun and manage Jobs\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e[CLI] Read a UV script's \u003ccode\u003e[tool.hf-jobs]\u003c/code\u003e launch config (opus-generated) by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4598\"\u003e#4598\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🛡️ [Sandbox] security hardening\u003c/h2\u003e\n\u003cp\u003eAn internal security review of the Sandbox API resulted in a 9-PR hardening series. Pooled sandboxes now use their own per-sandbox capability token instead of the host-wide credential, pool hosts are fully validated (initiator, namespace, image, flavor, command, URL) before any credential is sent to them, the \u003ccode\u003esbx-server\u003c/code\u003e binary is pinned by digest and verified before being run as PID 1, and the local pool cache is bound to the endpoint, credential and namespace that wrote it. Secret values no longer end up in \u003ccode\u003eargv\u003c/code\u003e when using \u003ccode\u003ehf sandbox exec --secrets\u003c/code\u003e, background processes are addressed by their server-assigned id (so \u003ccode\u003ekill()\u003c/code\u003e actually stops them and reports honestly), transfers and command output are bounded to avoid unbounded memory usage in the client, and pool ownership is decided per host so a \u003ccode\u003ewith SandboxPool(...)\u003c/code\u003e block never again tears down a colleague's discovered host. The security documentation was also rewritten to state precisely what the sandbox contract is — and what it is not — including a new \u0026quot;Known limitations\u0026quot; section.\u003c/p\u003e\n\u003cp\u003e📚 \u003cstrong\u003eDocumentation:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/huggingface_hub/main/en/guides/sandbox\"\u003eSandboxes\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e[sandbox audit] Make the sandbox security contract match the implementation by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4831\"\u003e#4831\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[sandbox audit] Use each pooled sandbox's own capability token by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4832\"\u003e#4832\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[sandbox audit] Validate a pool host before sending it a credential by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4834\"\u003e#4834\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[sandbox audit] Bind the sandbox pool cache to the endpoint, credential and namespace that wrote it by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4838\"\u003e#4838\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[sandbox audit] Bound what a transfer or a command's output costs the client by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4839\"\u003e#4839\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[sandbox audit] Decide host teardown per host, and report it honestly by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4840\"\u003e#4840\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[sandbox audit] Address background processes by their server-assigned id by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4836\"\u003e#4836\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[sandbox audit] Pin the sandbox server binary by digest and verify it before running it by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4837\"\u003e#4837\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[sandbox audit] Keep secret values out of argv in the CLI and fix the env/secrets docs by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4835\"\u003e#4835\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🔒 Security hardening for serialization and validation\u003c/h2\u003e\n\u003cp\u003eThree changes make the library safer against malicious or malformed inputs, with a stricter behavior worth noting. Torch checkpoint deserialization was hardened across 11 reported vulnerabilities: \u003ccode\u003eload_state_dict_from_file\u003c/code\u003e now defaults to \u003ccode\u003esafe=True\u003c/code\u003e (always using the safetensors loader), the pickle path defaults to \u003ccode\u003eweights_only=True\u003c/code\u003e, and unsafe combinations raise explicit errors instead of silently falling through. Path validation now rejects \u003ccode\u003e..\u003c/code\u003e segments anywhere in \u003ccode\u003epath_in_repo\u003c/code\u003e (previously only a leading one was caught), so uploads like \u003ccode\u003e\u0026quot;a/../../etc/passwd\u0026quot;\u003c/code\u003e are refused. Finally, \u003ccode\u003erepo_id\u003c/code\u003e validation is restricted to ASCII word characters as documented, so non-ASCII ids like \u003ccode\u003ecafé\u003c/code\u003e are rejected client-side instead of failing later on the Hub.\u003c/p\u003e\n\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/8814aabc81298df547bece9e71e4e88d3e513928\"\u003e\u003ccode\u003e8814aab\u003c/code\u003e\u003c/a\u003e Release: v1.32.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/445770606fa5ca80765a8e7a3d6e8cfaacaf7919\"\u003e\u003ccode\u003e4457706\u003c/code\u003e\u003c/a\u003e Release: v1.32.0.rc0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/b064a14629f9cdf3622e3fcac52c4f0e4e58c6b6\"\u003e\u003ccode\u003eb064a14\u003c/code\u003e\u003c/a\u003e [Download] Send X-HF-Download-Counter header on download calls (\u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4613\"\u003e#4613\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/79dd41ed6dec58314dad130fe7b8b578c8a1737d\"\u003e\u003ccode\u003e79dd41e\u003c/code\u003e\u003c/a\u003e [Docs] Fix hf discussions info options that do not exist (\u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4886\"\u003e#4886\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/d7b62c7becb6ba75667ab2c5b32d9338bcd5a4d4\"\u003e\u003ccode\u003ed7b62c7\u003c/code\u003e\u003c/a\u003e [CLI] Fix card data serialization (\u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4882\"\u003e#4882\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/f94ea55533a6fc796f191723823217fe75dfd462\"\u003e\u003ccode\u003ef94ea55\u003c/code\u003e\u003c/a\u003e [Buckets] Send mtime when copying files (\u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4920\"\u003e#4920\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/6e3d21f5d5a663468e58b37e6b94871e97534c24\"\u003e\u003ccode\u003e6e3d21f\u003c/code\u003e\u003c/a\u003e [Cache] Add cross-repo shared blob store (\u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4498\"\u003e#4498\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/5a9cdda63f231a1b57a05eab88dc4357c790ba87\"\u003e\u003ccode\u003e5a9cdda\u003c/code\u003e\u003c/a\u003e [Core] Speed up package imports (\u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4914\"\u003e#4914\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/2075fd68e69297eed60e1b058ef9b67b742b505d\"\u003e\u003ccode\u003e2075fd6\u003c/code\u003e\u003c/a\u003e [Cache] Support kernel repos in \u003ccode\u003ehf cache\u003c/code\u003e commands (\u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4905\"\u003e#4905\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/af6b41ece7448c5d7531699376c6f5974a2d24cc\"\u003e\u003ccode\u003eaf6b41e\u003c/code\u003e\u003c/a\u003e [Core] Reject path traversal via embedded \u0026quot;..\u0026quot; segments in path_in_repo (\u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4884\"\u003e#4884\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/huggingface/huggingface_hub/compare/v1.26.0...v1.32.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `tokenizers` from 0.22.2 to 0.23.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/huggingface/tokenizers/releases\"\u003etokenizers's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev0.23.2\u003c/h2\u003e\n\u003cp\u003eThis is the last v0 release, we are moving to v1!!\u003c/p\u003e\n\u003cp\u003eMore details coming soon 👀\u003c/p\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate daachorse from 1.0.1 to 3.0.0 by \u003ca href=\"https://github.com/musicinmybrain\"\u003e\u003ccode\u003e@​musicinmybrain\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2050\"\u003ehuggingface/tokenizers#2050\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eCi test fixes by \u003ca href=\"https://github.com/sebpop\"\u003e\u003ccode\u003e@​sebpop\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2079\"\u003ehuggingface/tokenizers#2079\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAvoid full vocab clone in get_vocab_size() by \u003ca href=\"https://github.com/eunseo9311\"\u003e\u003ccode\u003e@​eunseo9311\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2074\"\u003ehuggingface/tokenizers#2074\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: pin benchmark jobs to a larger dedicated runner by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2084\"\u003ehuggingface/tokenizers#2084\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: target benchmark runners by group, not nonexistent label by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2090\"\u003ehuggingface/tokenizers#2090\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBindings: acquire model read-lock once per call instead of per pre-token by \u003ca href=\"https://github.com/sebpop\"\u003e\u003ccode\u003e@​sebpop\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2072\"\u003ehuggingface/tokenizers#2072\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: split audit in a separate job by \u003ca href=\"https://github.com/SBrandeis\"\u003e\u003ccode\u003e@​SBrandeis\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2103\"\u003ehuggingface/tokenizers#2103\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: install libcairo on benchmark runners by \u003ca href=\"https://github.com/SBrandeis\"\u003e\u003ccode\u003e@​SBrandeis\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2100\"\u003ehuggingface/tokenizers#2100\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(ci): enable npm's trusted publisher for releases by \u003ca href=\"https://github.com/McPatate\"\u003e\u003ccode\u003e@​McPatate\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2111\"\u003ehuggingface/tokenizers#2111\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: bump pyo3 to version 0.29 by \u003ca href=\"https://github.com/SBrandeis\"\u003e\u003ccode\u003e@​SBrandeis\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2115\"\u003ehuggingface/tokenizers#2115\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eperf: add benchmarks for the \u003ccode\u003edecode\u003c/code\u003e API by \u003ca href=\"https://github.com/SBrandeis\"\u003e\u003ccode\u003e@​SBrandeis\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2099\"\u003ehuggingface/tokenizers#2099\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: cache HF test data and authenticate Hub downloads to avoid rate limits by \u003ca href=\"https://github.com/SBrandeis\"\u003e\u003ccode\u003e@​SBrandeis\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2102\"\u003ehuggingface/tokenizers#2102\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eImplementing Parity-aware BPE by \u003ca href=\"https://github.com/cimeister\"\u003e\u003ccode\u003e@​cimeister\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/1974\"\u003ehuggingface/tokenizers#1974\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eMake doc builds faster by \u003ca href=\"https://github.com/mishig25\"\u003e\u003ccode\u003e@​mishig25\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2158\"\u003ehuggingface/tokenizers#2158\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(deps-dev): bump websocket-driver from 0.7.4 to 0.7.5 in /tokenizers/examples/unstable_wasm/www by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2208\"\u003ehuggingface/tokenizers#2208\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(deps-dev): bump shell-quote from 1.8.3 to 1.10.0 in /tokenizers/examples/unstable_wasm/www by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2244\"\u003ehuggingface/tokenizers#2244\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: remove stale examples (kills 50% of dependabot traffic) by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2285\"\u003ehuggingface/tokenizers#2285\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(node): drop 8 unused devDependencies by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2286\"\u003ehuggingface/tokenizers#2286\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: pin every action to one SHA, drop stale audit suppressions by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2291\"\u003ehuggingface/tokenizers#2291\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(node): take node security alerts from 33 to 0 by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2287\"\u003ehuggi...\n\n_Description has been truncated_","html_url":"https://github.com/kuoihao/vllm-tle/pull/18","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/kuoihao%2Fvllm-tle/issues/18","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/18/packages"}},{"old_version":"3.10.10","new_version":"3.14.3","update_type":"minor","path":null,"pr_created_at":"2026-09-24T23:06:29.000Z","version_change":"3.10.10 → 3.14.3","issue":{"uuid":"5575687922","node_id":"PR_kwDOTfTeHs8AAAABFBcojQ","number":5,"state":"open","title":"Bump the pip group across 1 directory with 7 updates","user":"dependabot[bot]","labels":["dependencies","python"],"assignees":[],"locked":false,"comments_count":6,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-24T23:06:29.000Z","updated_at":"2026-09-24T23:06:40.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","group_name":"pip","update_count":7,"packages":[{"name":"anthropic","old_version":"0.86.0","new_version":"0.87.0","repository_url":"https://github.com/anthropics/anthropic-sdk-python"},{"name":"pyjwt","old_version":"2.12.1","new_version":"2.13.0","repository_url":"https://github.com/jpadilla/pyjwt"},{"name":"mcp","old_version":"1.26.0","new_version":"1.28.1","repository_url":"https://github.com/modelcontextprotocol/python-sdk"},{"name":"aiohttp","old_version":"3.10.10","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"anyio","old_version":"4.13.0","new_version":"4.14.2","repository_url":"https://github.com/agronholm/anyio"},{"name":"idna","old_version":"3.11","new_version":"3.15","repository_url":"https://github.com/kjd/idna"},{"name":"urllib3","old_version":"2.6.3","new_version":"2.7.0","repository_url":"https://github.com/urllib3/urllib3"}],"path":null,"ecosystem":"pip"},"body":"Bumps the pip group with 7 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [anthropic](https://github.com/anthropics/anthropic-sdk-python) | `0.86.0` | `0.87.0` |\n| [pyjwt](https://github.com/jpadilla/pyjwt) | `2.12.1` | `2.13.0` |\n| [mcp](https://github.com/modelcontextprotocol/python-sdk) | `1.26.0` | `1.28.1` |\n| [aiohttp](https://github.com/aio-libs/aiohttp) | `3.10.10` | `3.14.3` |\n| [anyio](https://github.com/agronholm/anyio) | `4.13.0` | `4.14.2` |\n| [idna](https://github.com/kjd/idna) | `3.11` | `3.15` |\n| [urllib3](https://github.com/urllib3/urllib3) | `2.6.3` | `2.7.0` |\n\n\nUpdates `anthropic` from 0.86.0 to 0.87.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/anthropics/anthropic-sdk-python/releases\"\u003eanthropic's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev0.87.0\u003c/h2\u003e\n\u003ch2\u003e0.87.0 (2026-03-31)\u003c/h2\u003e\n\u003cp\u003eFull Changelog: \u003ca href=\"https://github.com/anthropics/anthropic-sdk-python/compare/v0.86.0...v0.87.0\"\u003ev0.86.0...v0.87.0\u003c/a\u003e\u003c/p\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eclient:\u003c/strong\u003e add error type field to APIStatusError (\u003ca href=\"https://redirect.github.com/anthropics/anthropic-sdk-python/issues/1587\"\u003e#1587\u003c/a\u003e) (\u003ca href=\"https://github.com/anthropics/anthropic-sdk-python/commit/dd563c031c2a0be75ccb6175246685abd5806d7d\"\u003edd563c0\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003einternal:\u003c/strong\u003e implement indices array format for query and form serialization (\u003ca href=\"https://github.com/anthropics/anthropic-sdk-python/commit/11a624467bd44175bc602f0135ff354895bdebdd\"\u003e11a6244\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ehonor \u003cstrong\u003eapi_exclude\u003c/strong\u003e in async transform path (\u003ca href=\"https://redirect.github.com/anthropics/anthropic-sdk-python/issues/1612\"\u003e#1612\u003c/a\u003e) (\u003ca href=\"https://github.com/anthropics/anthropic-sdk-python/commit/8172232a8bb19e0d0bf10df1c3c21ed492784585\"\u003e8172232\u003c/a\u003e), closes \u003ca href=\"https://redirect.github.com/anthropics/anthropic-sdk-python/issues/1610\"\u003e#1610\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ememory:\u003c/strong\u003e return resolved path from async _validate_path (\u003ca href=\"https://github.com/anthropics/anthropic-sdk-python/commit/7b0add32bd5fc59ad0fa277ef6982ee1df1eed7a\"\u003e7b0add3\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ememory:\u003c/strong\u003e use restrictive file mode for memory files (\u003ca href=\"https://github.com/anthropics/anthropic-sdk-python/commit/47ba5b8f5f74beb1e1babef249754e1312b9dddf\"\u003e47ba5b8\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003esanitize endpoint path params (\u003ca href=\"https://github.com/anthropics/anthropic-sdk-python/commit/98f60e42039392a133d83c8673d659f514c15a35\"\u003e98f60e4\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003etransform schema:\u003c/strong\u003e support enums (\u003ca href=\"https://redirect.github.com/anthropics/anthropic-sdk-python/issues/1275\"\u003e#1275\u003c/a\u003e) (\u003ca href=\"https://github.com/anthropics/anthropic-sdk-python/commit/5c088ab1d162b1c1a18f566688b31bfbd7610825\"\u003e5c088ab\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eChores\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eci:\u003c/strong\u003e run builds on CI even if only spec metadata changed (\u003ca href=\"https://github.com/anthropics/anthropic-sdk-python/commit/194c05029403cef820897c3c6b2c26d4df0736f7\"\u003e194c050\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eci:\u003c/strong\u003e skip lint on metadata-only changes (\u003ca href=\"https://github.com/anthropics/anthropic-sdk-python/commit/03e2ab9e95ec452d7d519e0b419c8881f3ae3a08\"\u003e03e2ab9\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003einternal:\u003c/strong\u003e update gitignore (\u003ca href=\"https://github.com/anthropics/anthropic-sdk-python/commit/94ede14b443c78b51931c185d1cd44f4ef201eae\"\u003e94ede14\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003etests:\u003c/strong\u003e bump steady to v0.19.4 (\u003ca href=\"https://github.com/anthropics/anthropic-sdk-python/commit/2d6d58fa0101930c8f5cd9e9a94e7e988055f371\"\u003e2d6d58f\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003etests:\u003c/strong\u003e bump steady to v0.19.5 (\u003ca href=\"https://github.com/anthropics/anthropic-sdk-python/commit/8fb439afeadaf608cbf7d4630d01735f97227e3e\"\u003e8fb439a\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003etests:\u003c/strong\u003e bump steady to v0.19.6 (\u003ca href=\"https://github.com/anthropics/anthropic-sdk-python/commit/76da5fdd03b7ffc65a8b58b9f2a0df3e03c587c9\"\u003e76da5fd\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003etests:\u003c/strong\u003e bump steady to v0.19.7 (\u003ca href=\"https://github.com/anthropics/anthropic-sdk-python/commit/bfa40e5c5bed65da0f3f664082e58e85c26b9c66\"\u003ebfa40e5\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003etests:\u003c/strong\u003e bump steady to v0.20.1 (\u003ca href=\"https://github.com/anthropics/anthropic-sdk-python/commit/4fd9446332ae114072dac968134e6451c62138bb\"\u003e4fd9446\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/anthropics/anthropic-sdk-python/blob/main/CHANGELOG.md\"\u003eanthropic's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e0.87.0 (2026-03-31)\u003c/h2\u003e\n\u003cp\u003eFull Changelog: \u003ca href=\"https://github.com/anthropics/anthropic-sdk-python/compare/v0.86.0...v0.87.0\"\u003ev0.86.0...v0.87.0\u003c/a\u003e\u003c/p\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eclient:\u003c/strong\u003e add error type field to APIStatusError (\u003ca href=\"https://redirect.github.com/anthropics/anthropic-sdk-python/issues/1587\"\u003e#1587\u003c/a\u003e) (\u003ca href=\"https://github.com/anthropics/anthropic-sdk-python/commit/dd563c031c2a0be75ccb6175246685abd5806d7d\"\u003edd563c0\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003einternal:\u003c/strong\u003e implement indices array format for query and form serialization (\u003ca href=\"https://github.com/anthropics/anthropic-sdk-python/commit/11a624467bd44175bc602f0135ff354895bdebdd\"\u003e11a6244\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ehonor \u003cstrong\u003eapi_exclude\u003c/strong\u003e in async transform path (\u003ca href=\"https://redirect.github.com/anthropics/anthropic-sdk-python/issues/1612\"\u003e#1612\u003c/a\u003e) (\u003ca href=\"https://github.com/anthropics/anthropic-sdk-python/commit/8172232a8bb19e0d0bf10df1c3c21ed492784585\"\u003e8172232\u003c/a\u003e), closes \u003ca href=\"https://redirect.github.com/anthropics/anthropic-sdk-python/issues/1610\"\u003e#1610\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ememory:\u003c/strong\u003e return resolved path from async _validate_path (\u003ca href=\"https://github.com/anthropics/anthropic-sdk-python/commit/7b0add32bd5fc59ad0fa277ef6982ee1df1eed7a\"\u003e7b0add3\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ememory:\u003c/strong\u003e use restrictive file mode for memory files (\u003ca href=\"https://github.com/anthropics/anthropic-sdk-python/commit/47ba5b8f5f74beb1e1babef249754e1312b9dddf\"\u003e47ba5b8\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003esanitize endpoint path params (\u003ca href=\"https://github.com/anthropics/anthropic-sdk-python/commit/98f60e42039392a133d83c8673d659f514c15a35\"\u003e98f60e4\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003etransform schema:\u003c/strong\u003e support enums (\u003ca href=\"https://redirect.github.com/anthropics/anthropic-sdk-python/issues/1275\"\u003e#1275\u003c/a\u003e) (\u003ca href=\"https://github.com/anthropics/anthropic-sdk-python/commit/5c088ab1d162b1c1a18f566688b31bfbd7610825\"\u003e5c088ab\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eChores\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eci:\u003c/strong\u003e run builds on CI even if only spec metadata changed (\u003ca href=\"https://github.com/anthropics/anthropic-sdk-python/commit/194c05029403cef820897c3c6b2c26d4df0736f7\"\u003e194c050\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eci:\u003c/strong\u003e skip lint on metadata-only changes (\u003ca href=\"https://github.com/anthropics/anthropic-sdk-python/commit/03e2ab9e95ec452d7d519e0b419c8881f3ae3a08\"\u003e03e2ab9\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003einternal:\u003c/strong\u003e update gitignore (\u003ca href=\"https://github.com/anthropics/anthropic-sdk-python/commit/94ede14b443c78b51931c185d1cd44f4ef201eae\"\u003e94ede14\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003etests:\u003c/strong\u003e bump steady to v0.19.4 (\u003ca href=\"https://github.com/anthropics/anthropic-sdk-python/commit/2d6d58fa0101930c8f5cd9e9a94e7e988055f371\"\u003e2d6d58f\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003etests:\u003c/strong\u003e bump steady to v0.19.5 (\u003ca href=\"https://github.com/anthropics/anthropic-sdk-python/commit/8fb439afeadaf608cbf7d4630d01735f97227e3e\"\u003e8fb439a\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003etests:\u003c/strong\u003e bump steady to v0.19.6 (\u003ca href=\"https://github.com/anthropics/anthropic-sdk-python/commit/76da5fdd03b7ffc65a8b58b9f2a0df3e03c587c9\"\u003e76da5fd\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003etests:\u003c/strong\u003e bump steady to v0.19.7 (\u003ca href=\"https://github.com/anthropics/anthropic-sdk-python/commit/bfa40e5c5bed65da0f3f664082e58e85c26b9c66\"\u003ebfa40e5\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003etests:\u003c/strong\u003e bump steady to v0.20.1 (\u003ca href=\"https://github.com/anthropics/anthropic-sdk-python/commit/4fd9446332ae114072dac968134e6451c62138bb\"\u003e4fd9446\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/anthropics/anthropic-sdk-python/commit/ab0c4460a170183ff036e2a3dad320ac4ac2c76d\"\u003e\u003ccode\u003eab0c446\u003c/code\u003e\u003c/a\u003e release: 0.87.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/anthropics/anthropic-sdk-python/commit/6599043eee6e86dce16953fcd1fd828052052be6\"\u003e\u003ccode\u003e6599043\u003c/code\u003e\u003c/a\u003e fix(memory): return resolved path from async _validate_path\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/anthropics/anthropic-sdk-python/commit/715030ceb4d6dd8d3546e999c680e29532bf1255\"\u003e\u003ccode\u003e715030c\u003c/code\u003e\u003c/a\u003e fix(memory): use restrictive file mode for memory files\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/anthropics/anthropic-sdk-python/commit/6cdbc5f37105e464704d911ef590b88c7e5ae427\"\u003e\u003ccode\u003e6cdbc5f\u003c/code\u003e\u003c/a\u003e chore(tests): bump steady to v0.20.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/anthropics/anthropic-sdk-python/commit/4beda3cc966b49166387aa9275cec8f88b004154\"\u003e\u003ccode\u003e4beda3c\u003c/code\u003e\u003c/a\u003e Add output-300k-2026-03-24 beta header\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/anthropics/anthropic-sdk-python/commit/3b77b826ce402881bcb2a43092e758368fccc99a\"\u003e\u003ccode\u003e3b77b82\u003c/code\u003e\u003c/a\u003e chore(ci): run builds on CI even if only spec metadata changed\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/anthropics/anthropic-sdk-python/commit/764ddbab9bcd6c4e076bf2618d4930e5b39cfb7c\"\u003e\u003ccode\u003e764ddba\u003c/code\u003e\u003c/a\u003e feat(internal): implement indices array format for query and form serialization\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/anthropics/anthropic-sdk-python/commit/8a06a905bb89bf8126e552d951270fe90869bc1d\"\u003e\u003ccode\u003e8a06a90\u003c/code\u003e\u003c/a\u003e codegen metadata\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/anthropics/anthropic-sdk-python/commit/7f8cf3c4c0c7a601847538364f6eccf00e72a2c4\"\u003e\u003ccode\u003e7f8cf3c\u003c/code\u003e\u003c/a\u003e chore(tests): bump steady to v0.19.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/anthropics/anthropic-sdk-python/commit/0eba0dd8f9590254b91eaadb79e44b792d56d85b\"\u003e\u003ccode\u003e0eba0dd\u003c/code\u003e\u003c/a\u003e chore(ci): skip lint on metadata-only changes\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/anthropics/anthropic-sdk-python/compare/v0.86.0...v0.87.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `pyjwt` from 2.12.1 to 2.13.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/jpadilla/pyjwt/releases\"\u003epyjwt's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e2.13.0\u003c/h2\u003e\n\u003ch1\u003ePyJWT 2.13.0 — Security Release\u003c/h1\u003e\n\u003cp\u003eThis release bundles five security fixes plus three additional hardening / spec-compliance changes. We recommend all users upgrade.\u003c/p\u003e\n\u003ch2\u003eSecurity\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/security/advisories/GHSA-xgmm-8j9v-c9wx\"\u003e\u003ccode\u003eGHSA-xgmm-8j9v-c9wx\u003c/code\u003e\u003c/a\u003e — JWK JSON accepted as HMAC secret (algorithm confusion).\u003c/strong\u003e \u003ccode\u003eHMACAlgorithm.prepare_key\u003c/code\u003e previously rejected PEM- and SSH-formatted asymmetric keys but did not catch a JWK passed as a raw JSON string. In a verifier configured with both symmetric and asymmetric algorithms in \u003ccode\u003ealgorithms=[…]\u003c/code\u003e and a raw-JSON JWK as the key, an attacker could forge HS256 tokens using the JWK text as the HMAC secret. The guard has been extended to reject any JWK-shaped JSON. \u003cem\u003eReported by \u003ca href=\"https://github.com/aradona91\"\u003e\u003ccode\u003e@​aradona91\u003c/code\u003e\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/security/advisories/GHSA-jq35-7prp-9v3f\"\u003e\u003ccode\u003eGHSA-jq35-7prp-9v3f\u003c/code\u003e\u003c/a\u003e — Algorithm allow-list bypass with \u003ccode\u003ePyJWK\u003c/code\u003e / \u003ccode\u003ePyJWKClient\u003c/code\u003e.\u003c/strong\u003e When verifying with a \u003ccode\u003ePyJWK\u003c/code\u003e, the caller's \u003ccode\u003ealgorithms=[…]\u003c/code\u003e allow-list was checked against the token header \u003ccode\u003ealg\u003c/code\u003e as a string only; actual verification used the algorithm bound to the \u003ccode\u003ePyJWK\u003c/code\u003e. An attacker who controlled a registered JWKS key could sign with one algorithm and advertise another on the header. PyJWT now requires the token header \u003ccode\u003ealg\u003c/code\u003e to match the \u003ccode\u003ePyJWK\u003c/code\u003e's algorithm before verification. \u003cem\u003eReported by \u003ca href=\"https://github.com/sushi-gif\"\u003e\u003ccode\u003e@​sushi-gif\u003c/code\u003e\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/security/advisories/GHSA-w7vc-732c-9m39\"\u003e\u003ccode\u003eGHSA-w7vc-732c-9m39\u003c/code\u003e\u003c/a\u003e — DoS via base64 decode of unused payload segment when \u003ccode\u003eb64=false\u003c/code\u003e.\u003c/strong\u003e For detached-payload JWS (\u003ccode\u003eb64=false\u003c/code\u003e), the compact-form payload segment was base64-decoded before being discarded in favor of the caller-supplied \u003ccode\u003edetached_payload\u003c/code\u003e. An attacker could inflate the unused segment to force CPU + memory cost without holding a valid signature. The segment is now required to be empty per RFC 7515 Appendix F, and is no longer decoded. \u003cem\u003eReported by \u003ca href=\"https://github.com/thesmartshadow\"\u003e\u003ccode\u003e@​thesmartshadow\u003c/code\u003e\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/security/advisories/GHSA-993g-76c3-p5m4\"\u003e\u003ccode\u003eGHSA-993g-76c3-p5m4\u003c/code\u003e\u003c/a\u003e — \u003ccode\u003ePyJWKClient\u003c/code\u003e accepts non-HTTP(S) URIs.\u003c/strong\u003e \u003ccode\u003ePyJWKClient.fetch_data\u003c/code\u003e passed its URI to \u003ccode\u003eurllib.request.urlopen\u003c/code\u003e, which by default also handles \u003ccode\u003efile://\u003c/code\u003e, \u003ccode\u003eftp://\u003c/code\u003e, and \u003ccode\u003edata:\u003c/code\u003e schemes. An application that fed an attacker-influenced URI into \u003ccode\u003ePyJWKClient\u003c/code\u003e could be coerced into reading local files or reaching other unintended schemes. \u003ccode\u003ePyJWKClient\u003c/code\u003e now rejects any URI whose scheme isn't \u003ccode\u003ehttp\u003c/code\u003e or \u003ccode\u003ehttps\u003c/code\u003e. \u003cem\u003eReported by \u003ca href=\"https://github.com/KEIJOT\"\u003e\u003ccode\u003e@​KEIJOT\u003c/code\u003e\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/security/advisories/GHSA-fhv5-28vv-h8m8\"\u003e\u003ccode\u003eGHSA-fhv5-28vv-h8m8\u003c/code\u003e\u003c/a\u003e — \u003ccode\u003ePyJWKClient\u003c/code\u003e cache wiped on fetch error.\u003c/strong\u003e A \u003ccode\u003efinally\u003c/code\u003e-block \u003ccode\u003eput(jwk_set=None)\u003c/code\u003e cleared the JWK Set cache whenever a fetch raised, turning a transient JWKS-endpoint outage into application-wide auth failure. The cache write was moved into the success path; transient errors no longer evict valid cached keys. \u003cem\u003eReported by \u003ca href=\"https://github.com/eddieran\"\u003e\u003ccode\u003e@​eddieran\u003c/code\u003e\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eFixed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eReject empty HMAC keys outright in \u003ccode\u003eHMACAlgorithm.prepare_key\u003c/code\u003e with \u003ccode\u003eInvalidKeyError\u003c/code\u003e instead of accepting them with only a warning. Defends against the \u003ccode\u003eos.getenv(\u0026quot;JWT_SECRET\u0026quot;, \u0026quot;\u0026quot;)\u003c/code\u003e footgun. \u003cem\u003eThanks to \u003ca href=\"https://github.com/SnailSploit\"\u003e\u003ccode\u003e@​SnailSploit\u003c/code\u003e\u003c/a\u003e and \u003ca href=\"https://github.com/spartan8806\"\u003e\u003ccode\u003e@​spartan8806\u003c/code\u003e\u003c/a\u003e for the reports.\u003c/em\u003e\u003c/li\u003e\n\u003cli\u003eForward per-call \u003ccode\u003eoptions\u003c/code\u003e (including \u003ccode\u003eenforce_minimum_key_length\u003c/code\u003e) from \u003ccode\u003ePyJWT.decode\u003c/code\u003e through to \u003ccode\u003ePyJWS._verify_signature\u003c/code\u003e. The option was previously silently dropped between the two layers, so it only took effect when set on the \u003ccode\u003ePyJWT\u003c/code\u003e instance. \u003cem\u003eThanks to \u003ca href=\"https://github.com/WLUB\"\u003e\u003ccode\u003e@​WLUB\u003c/code\u003e\u003c/a\u003e for the report.\u003c/em\u003e\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eRFC 7797 §3 compliance for \u003ccode\u003eb64=false\u003c/code\u003e:\u003c/strong\u003e the encoder now auto-adds \u003ccode\u003e\u0026quot;b64\u0026quot;\u003c/code\u003e to \u003ccode\u003ecrit\u003c/code\u003e, and the decoder rejects tokens that set \u003ccode\u003eb64=false\u003c/code\u003e without listing it in \u003ccode\u003ecrit\u003c/code\u003e. \u003cem\u003eThanks to \u003ca href=\"https://github.com/MachineLearning-Nerd\"\u003e\u003ccode\u003e@​MachineLearning-Nerd\u003c/code\u003e\u003c/a\u003e for the report.\u003c/em\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eChanged\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMigrate the \u003ccode\u003edev\u003c/code\u003e, \u003ccode\u003edocs\u003c/code\u003e, and \u003ccode\u003etests\u003c/code\u003e package extras to dependency groups, by \u003ca href=\"https://github.com/kurtmckee\"\u003e\u003ccode\u003e@​kurtmckee\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/jpadilla/pyjwt/pull/1152\"\u003e#1152\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eUpgrade notes\u003c/h2\u003e\n\u003cp\u003eMost fixes are invisible to correctly-configured callers. A few behavioral changes you may encounter:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eEmpty HMAC keys now raise.\u003c/strong\u003e If your app passed \u003ccode\u003e\u0026quot;\u0026quot;\u003c/code\u003e or \u003ccode\u003eb\u0026quot;\u0026quot;\u003c/code\u003e as a secret (often via a missing env var, e.g. \u003ccode\u003eos.getenv(\u0026quot;JWT_SECRET\u0026quot;, \u0026quot;\u0026quot;)\u003c/code\u003e), \u003ccode\u003eencode\u003c/code\u003e/\u003ccode\u003edecode\u003c/code\u003e will now raise \u003ccode\u003eInvalidKeyError\u003c/code\u003e. This is the intended behavior — fix the configuration.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ccode\u003ePyJWK\u003c/code\u003e decoding now requires the token's \u003ccode\u003ealg\u003c/code\u003e to match the JWK's algorithm.\u003c/strong\u003e Previously a mismatch was silently honored if the header \u003ccode\u003ealg\u003c/code\u003e appeared in the allow-list. Tokens that relied on this mismatch will now fail with \u003ccode\u003eInvalidAlgorithmError\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ccode\u003ePyJWKClient\u003c/code\u003e now rejects non-HTTP(S) URIs at construction time.\u003c/strong\u003e Tests or dev environments that fetched JWKS from \u003ccode\u003efile://\u003c/code\u003e URIs need to switch to a local HTTP server or load the JWKS by other means (e.g. construct \u003ccode\u003ePyJWKSet.from_dict(...)\u003c/code\u003e directly).\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ccode\u003eb64=false\u003c/code\u003e tokens are now strictly RFC 7515 / 7797 compliant.\u003c/strong\u003e Tokens with a non-empty compact-form payload segment, or that omit \u003ccode\u003e\u0026quot;b64\u0026quot;\u003c/code\u003e from \u003ccode\u003ecrit\u003c/code\u003e, will be rejected. PyJWT-produced tokens always satisfy both invariants, so round-trips through PyJWT are unaffected.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ccode\u003eenforce_minimum_key_length\u003c/code\u003e set per-call now takes effect.\u003c/strong\u003e Callers who passed \u003ccode\u003eoptions={\u0026quot;enforce_minimum_key_length\u0026quot;: True}\u003c/code\u003e to \u003ccode\u003ejwt.decode()\u003c/code\u003e previously got no enforcement; they will now get \u003ccode\u003eInvalidKeyError\u003c/code\u003e on undersized keys, as documented.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull changelog:\u003c/strong\u003e \u003ca href=\"https://github.com/jpadilla/pyjwt/compare/2.12.1...2.13.0\"\u003ehttps://github.com/jpadilla/pyjwt/compare/2.12.1...2.13.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/jpadilla/pyjwt/blob/master/CHANGELOG.rst\"\u003epyjwt's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ccode\u003ev2.13.0 \u0026lt;https://github.com/jpadilla/pyjwt/compare/2.12.1...2.13.0\u0026gt;\u003c/code\u003e__\u003c/h2\u003e\n\u003cp\u003eSecurity\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003e\n- Reject JWK JSON documents passed as raw HMAC secrets in\n  ``HMACAlgorithm.prepare_key`` to close an algorithm-confusion gap that\n  the existing PEM/SSH guard did not cover. Reported by @aradona91 in\n  `GHSA-xgmm-8j9v-c9wx \u0026lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-xgmm-8j9v-c9wx\u0026gt;`__.\n- Bind the JWT header ``alg`` to ``PyJWK.algorithm_name`` during\n  verification so the caller's ``algorithms=[...]`` allow-list cannot be\n  bypassed when decoding with a ``PyJWK`` / ``PyJWKClient`` key. Reported\n  by @sushi-gif in `GHSA-jq35-7prp-9v3f \u0026lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-jq35-7prp-9v3f\u0026gt;`__.\n- Reject non-``http(s)`` URI schemes in ``PyJWKClient`` so attacker-\n  influenced URIs cannot read local files or reach unintended schemes via\n  urllib's default ``file://`` / ``ftp://`` / ``data:`` handlers. Reported\n  by @KEIJOT in `GHSA-993g-76c3-p5m4 \u0026lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-993g-76c3-p5m4\u0026gt;`__.\n- Preserve the cached JWK Set on fetch errors in ``PyJWKClient.fetch_data``.\n  The previous ``finally``-block ``put(None)`` pattern cleared the cache\n  on any transient outage, turning one bad JWKS request into application-\n  wide auth failure. Reported by @eddieran in `GHSA-fhv5-28vv-h8m8 \u0026lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-fhv5-28vv-h8m8\u0026gt;`__.\n- Skip the unconditional base64 decode of the compact-form payload segment\n  when ``b64=false`` is set in the protected header, and require that\n  segment to be empty (RFC 7515 Appendix F detached form). Closes an\n  unauthenticated DoS amplifier. Reported by @thesmartshadow in\n  `GHSA-w7vc-732c-9m39 \u0026lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-w7vc-732c-9m39\u0026gt;`__.\n\u003cp\u003eFixed\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003e\n- Reject empty HMAC keys outright in ``HMACAlgorithm.prepare_key`` with\n  ``InvalidKeyError`` instead of accepting them with only a warning.\n  Thanks to @SnailSploit and @spartan8806 for independently flagging the\n  footgun.\n- Forward per-call ``options`` (including ``enforce_minimum_key_length``)\n  from ``PyJWT.decode`` through to ``PyJWS._verify_signature`` so the\n  option actually takes effect when set at the call site rather than only\n  on the ``PyJWT`` instance. Thanks to @WLUB for the report.\n- RFC 7797 §3 compliance for ``b64=false``: the encoder now auto-adds\n  ``\u0026amp;quot;b64\u0026amp;quot;`` to the ``crit`` header parameter, and the decoder rejects\n  tokens that set ``b64=false`` without listing it in ``crit``. Thanks to\n  @MachineLearning-Nerd for the report.\n\nChanged\n\u003c/code\u003e\u003c/pre\u003e\n\u003cul\u003e\n\u003cli\u003eMigrate the \u003ccode\u003edev\u003c/code\u003e, \u003ccode\u003edocs\u003c/code\u003e, and \u003ccode\u003etests\u003c/code\u003e package extras to dependency groups by \u003ca href=\"https://github.com/kurtmckee\"\u003e\u003ccode\u003e@​kurtmckee\u003c/code\u003e\u003c/a\u003e in \u003ccode\u003e[#1152](https://github.com/jpadilla/pyjwt/issues/1152) \u0026amp;lt;https://github.com/jpadilla/pyjwt/pull/1152\u0026amp;gt;\u003c/code\u003e__\n\u003c/code\u003e\u003c/pre\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/7144e4534c34810f4525dc4578a32addd8212cff\"\u003e\u003ccode\u003e7144e45\u003c/code\u003e\u003c/a\u003e Apply ruff format\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/d2f4bec4963897c0ef96ef64a875894f2c8542ab\"\u003e\u003ccode\u003ed2f4bec\u003c/code\u003e\u003c/a\u003e Restore \u003ccode\u003ecast()\u003c/code\u003e calls with cross-version \u003ccode\u003etype: ignore\u003c/code\u003e for \u003ccode\u003eprepare_key\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/22f478cebddd8294259c30f037ecb92b0b348774\"\u003e\u003ccode\u003e22f478c\u003c/code\u003e\u003c/a\u003e Remove redundant casts in \u003ccode\u003eRSAAlgorithm.prepare_key\u003c/code\u003e and `ECAlgorithm.prepare...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/95791b1759b8aa4f2203575d344d5c78564cdc81\"\u003e\u003ccode\u003e95791b1\u003c/code\u003e\u003c/a\u003e Bundle security fixes and hardening into 2.13.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/dcc27a9d3182a2349c30b160758785c6ce7a6508\"\u003e\u003ccode\u003edcc27a9\u003c/code\u003e\u003c/a\u003e [pre-commit.ci] pre-commit autoupdate (\u003ca href=\"https://redirect.github.com/jpadilla/pyjwt/issues/1155\"\u003e#1155\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/9d08a9a1896845ed8eaf88e6f6ac61e5800c3e7a\"\u003e\u003ccode\u003e9d08a9a\u003c/code\u003e\u003c/a\u003e [pre-commit.ci] pre-commit autoupdate (\u003ca href=\"https://redirect.github.com/jpadilla/pyjwt/issues/1146\"\u003e#1146\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/b87c10014d4109f0214fea188d00faaaf8a80e64\"\u003e\u003ccode\u003eb87c100\u003c/code\u003e\u003c/a\u003e Bump codecov/codecov-action from 5 to 6 (\u003ca href=\"https://redirect.github.com/jpadilla/pyjwt/issues/1154\"\u003e#1154\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/40e3147eb5f790d8d041772e5fc00728a176c812\"\u003e\u003ccode\u003e40e3147\u003c/code\u003e\u003c/a\u003e Migrate development extras to dependency groups (\u003ca href=\"https://redirect.github.com/jpadilla/pyjwt/issues/1152\"\u003e#1152\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/jpadilla/pyjwt/compare/2.12.1...2.13.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `mcp` from 1.26.0 to 1.28.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/modelcontextprotocol/python-sdk/releases\"\u003emcp's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.28.1\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e[v1.x] Buffer per-request StreamableHTTP streams; store priming event before dispatch by \u003ca href=\"https://github.com/maxisbey\"\u003e\u003ccode\u003e@​maxisbey\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/modelcontextprotocol/python-sdk/pull/2948\"\u003emodelcontextprotocol/python-sdk#2948\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[v1.x] Set Development Status classifier to Production/Stable by \u003ca href=\"https://github.com/maxisbey\"\u003e\u003ccode\u003e@​maxisbey\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/modelcontextprotocol/python-sdk/pull/2976\"\u003emodelcontextprotocol/python-sdk#2976\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[v1.x] Support TransportSecuritySettings in the WebSocket server transport by \u003ca href=\"https://github.com/maxisbey\"\u003e\u003ccode\u003e@​maxisbey\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/modelcontextprotocol/python-sdk/pull/2992\"\u003emodelcontextprotocol/python-sdk#2992\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/modelcontextprotocol/python-sdk/compare/v1.28.0...v1.28.1\"\u003ehttps://github.com/modelcontextprotocol/python-sdk/compare/v1.28.0...v1.28.1\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.28.0\u003c/h2\u003e\n\u003ch2\u003eDeprecations\u003c/h2\u003e\n\u003cp\u003eTwo API surfaces now emit \u003ccode\u003eDeprecationWarning\u003c/code\u003e ahead of their removal in v2. Nothing is removed in 1.x, and the warnings fire only when the deprecated API is \u003cem\u003ecalled\u003c/em\u003e - importing the modules stays silent.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eWebSocket transport\u003c/strong\u003e - \u003ccode\u003emcp.client.websocket.websocket_client\u003c/code\u003e and \u003ccode\u003emcp.server.websocket.websocket_server\u003c/code\u003e\u003ccode\u003emodelcontextprotocol/typescript-sdk#1783\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eExperimental tasks API\u003c/strong\u003e - \u003ccode\u003eClientSession.experimental\u003c/code\u003e, \u003ccode\u003eServer.experimental\u003c/code\u003e, \u003ccode\u003eServerSession.experimental\u003c/code\u003e, and the \u003ccode\u003eexperimental_task_handlers=\u003c/code\u003e kwarg on \u003ccode\u003eClientSession\u003c/code\u003e. Tasks (SEP-1686) were removed from the MCP specification and are expected to return as a separate MCP extension.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eIf your test suite runs with \u003ccode\u003efilterwarnings = [\u0026quot;error\u0026quot;]\u003c/code\u003e and exercises these paths, add a scoped ignore such as \u003ccode\u003eignore:The experimental tasks API is deprecated:DeprecationWarning\u003c/code\u003e or \u003ccode\u003eignore:The WebSocket .* transport is deprecated:DeprecationWarning\u003c/code\u003e.\u003c/p\u003e\n\u003cp\u003eSee \u003ca href=\"https://redirect.github.com/modelcontextprotocol/python-sdk/issues/2828\"\u003e#2828\u003c/a\u003e for full details.\u003c/p\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e[v1.x] Support Python 3.14 by \u003ca href=\"https://github.com/maxisbey\"\u003e\u003ccode\u003e@​maxisbey\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/modelcontextprotocol/python-sdk/pull/2769\"\u003emodelcontextprotocol/python-sdk#2769\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: omit null optional fields from task result payloads by \u003ca href=\"https://github.com/liuzemei\"\u003e\u003ccode\u003e@​liuzemei\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/modelcontextprotocol/python-sdk/pull/2809\"\u003emodelcontextprotocol/python-sdk#2809\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[v1.x] Deprecate the WebSocket transport and the experimental tasks entry points by \u003ca href=\"https://github.com/maxisbey\"\u003e\u003ccode\u003e@​maxisbey\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/modelcontextprotocol/python-sdk/pull/2828\"\u003emodelcontextprotocol/python-sdk#2828\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[v1.x] Add a v2 status banner to the README by \u003ca href=\"https://github.com/maxisbey\"\u003e\u003ccode\u003e@​maxisbey\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/modelcontextprotocol/python-sdk/pull/2835\"\u003emodelcontextprotocol/python-sdk#2835\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[v1.x] Deflake the child process cleanup tests by \u003ca href=\"https://github.com/maxisbey\"\u003e\u003ccode\u003e@​maxisbey\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/modelcontextprotocol/python-sdk/pull/2839\"\u003emodelcontextprotocol/python-sdk#2839\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/liuzemei\"\u003e\u003ccode\u003e@​liuzemei\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/modelcontextprotocol/python-sdk/pull/2809\"\u003emodelcontextprotocol/python-sdk#2809\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/modelcontextprotocol/python-sdk/compare/v1.27.2...v1.28.0\"\u003ehttps://github.com/modelcontextprotocol/python-sdk/compare/v1.27.2...v1.28.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.27.2\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e[v1.x] ci: deploy docs to py.sdk.modelcontextprotocol.io via Pages artifact by \u003ca href=\"https://github.com/maxisbey\"\u003e\u003ccode\u003e@​maxisbey\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/modelcontextprotocol/python-sdk/pull/2635\"\u003emodelcontextprotocol/python-sdk#2635\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[v1.x] Add subject and claims to AccessToken by \u003ca href=\"https://github.com/maxisbey\"\u003e\u003ccode\u003e@​maxisbey\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/modelcontextprotocol/python-sdk/pull/2690\"\u003emodelcontextprotocol/python-sdk#2690\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[v1.x] Bind transport sessions to the authenticated principal by \u003ca href=\"https://github.com/maxisbey\"\u003e\u003ccode\u003e@​maxisbey\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/modelcontextprotocol/python-sdk/pull/2719\"\u003emodelcontextprotocol/python-sdk#2719\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[v1.x] Scope experimental tasks to the session that created them by \u003ca href=\"https://github.com/maxisbey\"\u003e\u003ccode\u003e@​maxisbey\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/modelcontextprotocol/python-sdk/pull/2720\"\u003emodelcontextprotocol/python-sdk#2720\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/modelcontextprotocol/python-sdk/compare/v1.27.1...v1.27.2\"\u003ehttps://github.com/modelcontextprotocol/python-sdk/compare/v1.27.1...v1.27.2\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.27.1\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e[v1.x] fix: catch PydanticUserError when generating output schema (pydantic 2.13 compat) by \u003ca href=\"https://github.com/maxisbey\"\u003e\u003ccode\u003e@​maxisbey\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/modelcontextprotocol/python-sdk/pull/2435\"\u003emodelcontextprotocol/python-sdk#2435\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[v1.x] fix(auth): coerce empty-string optional URL fields to None in OAuthClientMetadata by \u003ca href=\"https://github.com/felixweinberger\"\u003e\u003ccode\u003e@​felixweinberger\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/modelcontextprotocol/python-sdk/pull/2405\"\u003emodelcontextprotocol/python-sdk#2405\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[v1.x] build: restrict httpx to \u0026lt;1.0.0 by \u003ca href=\"https://github.com/maxisbey\"\u003e\u003ccode\u003e@​maxisbey\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/modelcontextprotocol/python-sdk/pull/2559\"\u003emodelcontextprotocol/python-sdk#2559\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/modelcontextprotocol/python-sdk/commit/777b8d06710c140e3606b0d4598e2aa48546c266\"\u003e\u003ccode\u003e777b8d0\u003c/code\u003e\u003c/a\u003e [v1.x] Support TransportSecuritySettings in the WebSocket server transport (#...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/modelcontextprotocol/python-sdk/commit/47204674fb26185c2cf45f065831f27b8e5d5c65\"\u003e\u003ccode\u003e4720467\u003c/code\u003e\u003c/a\u003e [v1.x] Set Development Status classifier to Production/Stable (\u003ca href=\"https://redirect.github.com/modelcontextprotocol/python-sdk/issues/2976\"\u003e#2976\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/modelcontextprotocol/python-sdk/commit/6df3d734265eb49bf758a5e5eb420937337184e9\"\u003e\u003ccode\u003e6df3d73\u003c/code\u003e\u003c/a\u003e [v1.x] Buffer per-request StreamableHTTP streams; store priming event before ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/modelcontextprotocol/python-sdk/commit/32d32908feb7b15eddeb46872774bf95869cc5f0\"\u003e\u003ccode\u003e32d3290\u003c/code\u003e\u003c/a\u003e [v1.x] Pass a list to parametrize in test_docs_examples (pytest 9.1.0 compat)...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/modelcontextprotocol/python-sdk/commit/0dca751056dc87d04893d53af129fd00b56a18da\"\u003e\u003ccode\u003e0dca751\u003c/code\u003e\u003c/a\u003e [v1.x] Deflake the child process cleanup tests (\u003ca href=\"https://redirect.github.com/modelcontextprotocol/python-sdk/issues/2839\"\u003e#2839\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/modelcontextprotocol/python-sdk/commit/52258a95645c66fccbe925289c3382712b9bc68a\"\u003e\u003ccode\u003e52258a9\u003c/code\u003e\u003c/a\u003e [v1.x] Add a v2 status banner to the README (\u003ca href=\"https://redirect.github.com/modelcontextprotocol/python-sdk/issues/2835\"\u003e#2835\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/modelcontextprotocol/python-sdk/commit/b8f491724c45dbf89d6569364b58d6e8d25d7e42\"\u003e\u003ccode\u003eb8f4917\u003c/code\u003e\u003c/a\u003e [v1.x] Deprecate the WebSocket transport and the experimental tasks entry poi...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/modelcontextprotocol/python-sdk/commit/2309e5ef974062748e0268c396eba73cfdb6f5e3\"\u003e\u003ccode\u003e2309e5e\u003c/code\u003e\u003c/a\u003e fix: omit null optional fields from task result payloads (\u003ca href=\"https://redirect.github.com/modelcontextprotocol/python-sdk/issues/2809\"\u003e#2809\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/modelcontextprotocol/python-sdk/commit/494eb11d36b4238226cc0551da6015e1c73f7f3b\"\u003e\u003ccode\u003e494eb11\u003c/code\u003e\u003c/a\u003e [v1.x] Support Python 3.14 (\u003ca href=\"https://redirect.github.com/modelcontextprotocol/python-sdk/issues/2769\"\u003e#2769\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/modelcontextprotocol/python-sdk/commit/62137874ff26dd74d2fea80ff528a7fd9ca7a5e7\"\u003e\u003ccode\u003e6213787\u003c/code\u003e\u003c/a\u003e [v1.x] Scope experimental tasks to the session that created them (\u003ca href=\"https://redirect.github.com/modelcontextprotocol/python-sdk/issues/2720\"\u003e#2720\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/modelcontextprotocol/python-sdk/compare/v1.26.0...v1.28.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `aiohttp` from 3.10.10 to 3.14.3\nUpdates `anyio` from 4.13.0 to 4.14.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/agronholm/anyio/releases\"\u003eanyio's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e4.14.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eChanged \u003ccode\u003eByteReceiveStream.receive()\u003c/code\u003e implementations to raise a \u003ccode\u003eValueError\u003c/code\u003e when \u003ccode\u003emax_bytes\u003c/code\u003e is not a positive integer (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1191\"\u003e#1191\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eCapacityLimiter.total_tokens\u003c/code\u003e rejecting \u003ccode\u003efloat(\u0026quot;inf\u0026quot;)\u003c/code\u003e when the limiter was instantiated outside of an event loop. The adapter setter checked for infinity by identity (\u003ccode\u003evalue is math.inf\u003c/code\u003e), so only the exact \u003ccode\u003emath.inf\u003c/code\u003e singleton was accepted, while every backend setter (using \u003ccode\u003emath.isinf()\u003c/code\u003e) accepts any positive infinity (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1189\"\u003e#1189\u003c/a\u003e; PR by \u003ca href=\"https://github.com/greymoth-jp\"\u003e\u003ccode\u003e@​greymoth-jp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eto_process.run_sync()\u003c/code\u003e deadlocking when the worker function writes enough data to \u003ccode\u003esys.stderr\u003c/code\u003e to fill the (undrained) pipe buffer. The worker process now redirects \u003ccode\u003esys.stderr\u003c/code\u003e to \u003ccode\u003eos.devnull\u003c/code\u003e as well, matching the documented behavior\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eTLSStream.wrap()\u003c/code\u003e matching an internationalized (unicode) host name against the peer certificate using IDNA 2003 (via the standard library) instead of IDNA 2008, which could cause the host name to be matched against the wrong certificate (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1208\"\u003e#1208\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eanyio.open_process()\u003c/code\u003e (and \u003ccode\u003erun_process()\u003c/code\u003e) ignoring the \u003ccode\u003eextra_groups\u003c/code\u003e argument, as it mistakenly passed the value of the \u003ccode\u003egroup\u003c/code\u003e argument instead (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1209\"\u003e#1209\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eCapacityLimiter.acquire_nowait()\u003c/code\u003e and \u003ccode\u003eCapacityLimiter.acquire_nowait_on_behalf_of()\u003c/code\u003e raising \u003ccode\u003etrio.WouldBlock\u003c/code\u003e instead of \u003ccode\u003eanyio.WouldBlock\u003c/code\u003e on the \u003ccode\u003etrio\u003c/code\u003e backend when there are no tokens available (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1218\"\u003e#1218\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eCapacityLimiter\u003c/code\u003e on the asyncio backend over-granting tokens (\u003ccode\u003eborrowed_tokens\u003c/code\u003e exceeding \u003ccode\u003etotal_tokens\u003c/code\u003e and \u003ccode\u003eavailable_tokens\u003c/code\u003e going negative) when a non-blocking acquire was made in the window between a token being released and the notified waiter resuming. The freed token is now reserved for the woken waiter right away, so the non-blocking acquire correctly raises \u003ccode\u003eWouldBlock\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1170\"\u003e#1170\u003c/a\u003e; PR by \u003ca href=\"https://github.com/gaoflow\"\u003e\u003ccode\u003e@​gaoflow\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed unnecessary CPU spin when delivering cancellation from \u003ccode\u003eCancelScope\u003c/code\u003e on asyncio under certain conditions, including improper cancel scope nesting (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1111\"\u003e#1111\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.14.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed teardown of higher-scoped async fixtures failing on asyncio with \u003ccode\u003eRuntimeError: Attempted to exit cancel scope in a different task than it was entered in\u003c/code\u003e when an async test raise an outcome exception (e.g., \u003ccode\u003epytest.skip()\u003c/code\u003e, \u003ccode\u003epytest.xfail()\u003c/code\u003e, or \u003ccode\u003epytest.fail()\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1179\"\u003e#1179\u003c/a\u003e; PR by \u003ca href=\"https://github.com/EmmanuelNiyonshuti\"\u003e\u003ccode\u003e@​EmmanuelNiyonshuti\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eCapacityLimiter.total_tokens\u003c/code\u003e rejecting a value of \u003ccode\u003e0\u003c/code\u003e when the limiter was instantiated outside of an event loop, contradicting the documented behavior of allowing 0 total tokens (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1183\"\u003e#1183\u003c/a\u003e; PR by \u003ca href=\"https://github.com/nyxst4ck\"\u003e\u003ccode\u003e@​nyxst4ck\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.14.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eAdded support for Python 3.15\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAdded an asynchronous implementation of the \u003ccode\u003eitertools\u003c/code\u003e module (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/998\"\u003e#998\u003c/a\u003e; PR by \u003ca href=\"https://github.com/11kkw\"\u003e\u003ccode\u003e@​11kkw\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAdded the \u003ccode\u003elocal_port\u003c/code\u003e parameter to \u003ccode\u003econnect_tcp()\u003c/code\u003e to allow binding to a specific local port before connecting (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1067\"\u003e#1067\u003c/a\u003e; PR by \u003ca href=\"https://github.com/nullwiz\"\u003e\u003ccode\u003e@​nullwiz\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAdded support for custom capacity limiters in async path and file I/O functions and classes\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAdded the \u003ccode\u003ecreate_task()\u003c/code\u003e task group method for easier asyncio migration (returns a \u003ccode\u003eTaskHandle\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1098\"\u003e#1098\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eChanged \u003ccode\u003eTaskGroup.start_soon()\u003c/code\u003e to return a \u003ccode\u003eTaskHandle\u003c/code\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAdded an option for \u003ccode\u003eTaskGroup.start()\u003c/code\u003e to return a \u003ccode\u003eTaskHandle\u003c/code\u003e (which then contains the start value in the \u003ccode\u003estart_value\u003c/code\u003e property)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAdded the \u003ccode\u003ecancel()\u003c/code\u003e convenience method to \u003ccode\u003eTaskGroup\u003c/code\u003e as a shortcut for cancelling the task group's cancel scope\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eImproved the error message when a known backend is not installed to suggest the install command (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1115\"\u003e#1115\u003c/a\u003e; PR by \u003ca href=\"https://github.com/EmmanuelNiyonshuti\"\u003e\u003ccode\u003e@​EmmanuelNiyonshuti\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eImproved \u003ccode\u003eanyio.Path\u003c/code\u003e to preserve subclass types by returning \u003ccode\u003eSelf\u003c/code\u003e in methods that return path objects (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1130\"\u003e#1130\u003c/a\u003e; PR by \u003ca href=\"https://github.com/EmmanuelNiyonshuti\"\u003e\u003ccode\u003e@​EmmanuelNiyonshuti\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eChanged the parameter type annotation in \u003ccode\u003eanyio.Path.write_bytes()\u003c/code\u003e to accept any \u003ccode\u003eReadableBuffer\u003c/code\u003e, thus allowing it to accept \u003ccode\u003ebytearray\u003c/code\u003e and \u003ccode\u003ememoryview\u003c/code\u003e to match \u003ccode\u003epathlib.Path.write_bytes()\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1135\"\u003e#1135\u003c/a\u003e; PR by \u003ca href=\"https://github.com/SAY-5\"\u003e\u003ccode\u003e@​SAY-5\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eChanged several type annotations to only accept callables returning coroutine-like objects instead of arbitrary awaitables:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eTaskGroup.start_soon()\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eTaskGroup.start()\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eanyio.from_thread.run()\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThis reverts an earlier change from v3.7.0 which was made in error. (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1153\"\u003e#1153\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eChanged \u003ccode\u003eanyio.run\u003c/code\u003e to support callables returning arbitrary awaitables at runtime on all backends. Previously, this only worked on asyncio (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1171\"\u003e#1171\u003c/a\u003e; PR by \u003ca href=\"https://github.com/gschaffner\"\u003e\u003ccode\u003e@​gschaffner\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eChanged several classes (and their subclasses) to have \u003ccode\u003e__slots__\u003c/code\u003e (with \u003ccode\u003e__weakref__\u003c/code\u003e):\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eanyio.CancelScope\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/c384f99687c64c59ed8a11c3a0f11a2d57daff71\"\u003e\u003ccode\u003ec384f99\u003c/code\u003e\u003c/a\u003e Bumped up the version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/dbba29d1ade7936f18fb71ba24aa92978673482a\"\u003e\u003ccode\u003edbba29d\u003c/code\u003e\u003c/a\u003e Fixed 100% CPU spin on cancel scope misuse (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1217\"\u003e#1217\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/6bbc6c33caabc13af5bc4256f745027cf8d5d7b8\"\u003e\u003ccode\u003e6bbc6c3\u003c/code\u003e\u003c/a\u003e Fix CapacityLimiter over-granting tokens on asyncio (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1172\"\u003e#1172\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/6f82b2537cbbe98f3df3f295499056ab7de0b15b\"\u003e\u003ccode\u003e6f82b25\u003c/code\u003e\u003c/a\u003e Refactored TestTLSStream.test_receive_invalid_max_bytes() to be less flaky\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/be24b0414f67f604bcbdd5ea3bcc56ab920d872e\"\u003e\u003ccode\u003ebe24b04\u003c/code\u003e\u003c/a\u003e Relaxed timeouts to fix test flakiness\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/81135065749b4f60c06619b9caaf0a11871c1ddf\"\u003e\u003ccode\u003e8113506\u003c/code\u003e\u003c/a\u003e Fix test flakiness caused by slow callback duration logging\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/1e988b617b69588e33fecb75e36a9837245f562f\"\u003e\u003ccode\u003e1e988b6\u003c/code\u003e\u003c/a\u003e Fixed CapacityLimiter raising trio.WouldBlock instead of anyio.WouldBlock (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1\"\u003e#1\u003c/a\u003e...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/44713f345cd29dd4e7d76553c134543a1296cc62\"\u003e\u003ccode\u003e44713f3\u003c/code\u003e\u003c/a\u003e Pin setup-uv to a commit sha across downstream jobs (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1213\"\u003e#1213\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/f1b7301c8264b0d2e8d24a5788fd29e93dea4040\"\u003e\u003ccode\u003ef1b7301\u003c/code\u003e\u003c/a\u003e Fixed stderr writes in a worker subprocess causing a deadlock (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1207\"\u003e#1207\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/212be93c2cf2c841e753e95e5e2c543ee7feca90\"\u003e\u003ccode\u003e212be93\u003c/code\u003e\u003c/a\u003e Fix flaky test_tcp_listener_same_port using a hardcoded port (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1206\"\u003e#1206\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/agronholm/anyio/compare/4.13.0...4.14.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `idna` from 3.11 to 3.15\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/kjd/idna/blob/master/HISTORY.md\"\u003eidna's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e3.15 (2026-05-12)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eEnforce DNS-length cap on individual labels early in \u003ccode\u003echeck_label\u003c/code\u003e,\nshort-circuiting contextual-rule processing for oversized input\nwhile staying compatible with UTS 46 usage.\u003c/li\u003e\n\u003cli\u003eTidy core helpers: hoist bidi category sets to module-level\nfrozensets (avoiding per-codepoint list construction), simplify\nlength checks, and reuse the shared \u003ccode\u003e_unicode_dots_re\u003c/code\u003e from\n\u003ccode\u003eidna.core\u003c/code\u003e in the codec module.\u003c/li\u003e\n\u003cli\u003eUse \u003ccode\u003eraise ... from err\u003c/code\u003e for proper exception chaining and\nswitch internal string formatting to f-strings.\u003c/li\u003e\n\u003cli\u003eAllow \u003ccode\u003eflit_core\u003c/code\u003e 4.x in the build backend.\u003c/li\u003e\n\u003cli\u003eExpand the ruff lint set (flake8-bugbear, flake8-simplify,\npyupgrade, perflint) and apply the surfaced fixes; pin lint CI\nto Python 3.14.\u003c/li\u003e\n\u003cli\u003eAdd Dependabot configuration for GitHub Actions.\u003c/li\u003e\n\u003cli\u003eConvert README and HISTORY from reStructuredText to Markdown.\u003c/li\u003e\n\u003cli\u003eReference CVE-2026-45409 for the 3.14 advisory in place of the\ninitial GHSA identifier.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThanks to Felix Yan, Stan Ulbrych, and metsw24-max for\ncontributions to this release.\u003c/p\u003e\n\u003ch2\u003e3.14 (2026-05-10)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRemoved opportunity to process long inputs into quadratic\ntime by rejecting oversize inputs up-front. Closes a bypass\nof the CVE-2024-3651 mitigation. [CVE-2026-45409]\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThanks to Stan Ulbrych for reporting the issue.\u003c/p\u003e\n\u003ch2\u003e3.13 (2026-04-22)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eCorrect classification error for codepoint U+A7F1\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.12 (2026-04-21)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate to Unicode 17.0.0.\u003c/li\u003e\n\u003cli\u003eIssue a deprecation warning for the transitional argument.\u003c/li\u003e\n\u003cli\u003eAdded lazy-loading to provide some performance improvements.\u003c/li\u003e\n\u003cli\u003eRemoved vestiges of code related to Python 2 support, including\nsegmentation of data structures specific to Jython.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThanks to Rodrigo Nogueira for contributions to this release.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kjd/idna/commit/af30a092e158181d0b35ac66dfa813788126bdd8\"\u003e\u003ccode\u003eaf30a09\u003c/code\u003e\u003c/a\u003e Release 3.15\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kjd/idna/commit/30314d4628744ca14cf2b5820564e5127a9f86f2\"\u003e\u003ccode\u003e30314d4\u003c/code\u003e\u003c/a\u003e Pre-release 3.15rc0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kjd/idna/commit/05d4b219aa9eddc47371fcbd2000f0301016f3e9\"\u003e\u003ccode\u003e05d4b21\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/kjd/idna/issues/237\"\u003e#237\u003c/a\u003e from kjd/convert-docs-to-markdown\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kjd/idna/commit/2987fdba1962bbb2358399e0084ba062b98a0bee\"\u003e\u003ccode\u003e2987fdb\u003c/code\u003e\u003c/a\u003e Convert README and HISTORY from reStructuredText to Markdown\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kjd/idna/commit/59fa8002d514bf4a5ce7b58f67b9ec587d53fa9c\"\u003e\u003ccode\u003e59fa800\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/kjd/idna/issues/236\"\u003e#236\u003c/a\u003e from kjd/dependabot/github_actions/actions-f3e34333ea\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kjd/idna/commit/def69834ced5d4b3c50439d8b99c4c856ec19ca2\"\u003e\u003ccode\u003edef6983\u003c/code\u003e\u003c/a\u003e Merge branch 'master' into dependabot/github_actions/actions-f3e34333ea\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kjd/idna/commit/bbd8004a797185d8c56bb555cd5c88fde05e0631\"\u003e\u003ccode\u003ebbd8004\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/kjd/idna/issues/234\"\u003e#234\u003c/a\u003e from StanFromIreland/patch-1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kjd/idna/commit/edd07c05024344a6ccb517414ccb36683aee99fc\"\u003e\u003ccode\u003eedd07c0\u003c/code\u003e\u003c/a\u003e Bump github/codeql-action from 3.35.2 to 4.35.2 in the actions group\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kjd/idna/commit/5557db030c11bdec50d62aa5f631d705d33ba123\"\u003e\u003ccode\u003e5557db0\u003c/code\u003e\u003c/a\u003e Merge branch 'master' into patch-1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kjd/idna/commit/f11746cf4981d25123ef7830d3ee60f07de8ae3d\"\u003e\u003ccode\u003ef11746c\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/kjd/idna/issues/235\"\u003e#235\u003c/a\u003e from StanFromIreland/patch-2\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/kjd/idna/compare/v3.11...v3.15\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `urllib3` from 2.6.3 to 2.7.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/urllib3/urllib3/releases\"\u003eurllib3's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e2.7.0\u003c/h2\u003e\n\u003ch2\u003e🚀 urllib3 is fundraising for HTTP/2 support\u003c/h2\u003e\n\u003cp\u003e\u003ca href=\"https://sethmlarson.dev/urllib3-is-fundraising-for-http2-support\"\u003eurllib3 is raising ~$40,000 USD\u003c/a\u003e to release HTTP/2 support and ensure long-term sustainable maintenance of the project after a sharp decline in financial support. If your company or organization uses Python and would benefit from HTTP/2 support in Requests, pip, cloud SDKs, and thousands of other projects \u003ca href=\"https://opencollective.com/urllib3\"\u003eplease consider contributing financially\u003c/a\u003e to ensure HTTP/2 support is developed sustainably and maintained for the long-haul.\u003c/p\u003e\n\u003cp\u003eThank you for your support.\u003c/p\u003e\n\u003ch2\u003eSecurity\u003c/h2\u003e\n\u003cp\u003eAddressed high-severity security issues. Impact was limited to specific use cases detailed in the accompanying advisories; overall user exposure was estimated to be marginal.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eDecompression-bomb safeguards of the streaming API were bypassed:\u003c/p\u003e\n\u003col\u003e\n\u003cli\u003eWhen \u003ccode\u003eHTTPResponse.drain_conn()\u003c/code\u003e was called after the response had been read and decompressed partially. (Reported by \u003ca href=\"https://github.com/Cycloctane\"\u003e\u003ccode\u003e@​Cycloctane\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eDuring the second \u003ccode\u003eHTTPResponse.read(amt=N)\u003c/code\u003e or \u003ccode\u003eHTTPResponse.stream(amt=N)\u003c/code\u003e call when the response was decompressed using the official \u003ca href=\"https://pypi.org/project/brotli/\"\u003eBrotli\u003c/a\u003e library. (Reported by \u003ca href=\"https://github.com/kimkou2024\"\u003e\u003ccode\u003e@​kimkou2024\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ol\u003e\n\u003cp\u003eSee GHSA-mf9v-mfxr-j63j for details.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eHTTP pools created using \u003ccode\u003eProxyManager.connection_from_url\u003c/code\u003e did not strip sensitive headers specified in \u003ccode\u003eRetry.remove_headers_on_redirect\u003c/code\u003e when redirecting to a different host. (GHSA-qccp-gfcp-xxvc reported by \u003ca href=\"https://github.com/christos-spearbit\"\u003e\u003ccode\u003e@​christos-spearbit\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eDeprecations and Removals\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUsed \u003ccode\u003eFutureWarning\u003c/code\u003e instead of \u003ccode\u003eDeprecationWarning\u003c/code\u003e for better visibility of existing deprecation notices. Rescheduled the removal of deprecated features to version 3.0. (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/3763\"\u003eurllib3/urllib3#3763\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRemoved support for end-of-life Python 3.9. (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/3720\"\u003eurllib3/urllib3#3720\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRemoved support for end-of-life PyPy3.10. (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/4979\"\u003eurllib3/urllib3#4979\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eBumped the minimum supported pyOpenSSL version to 19.0.0. (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/3777\"\u003eurllib3/urllib3#3777\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eBugfixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed a bug where \u003ccode\u003eHTTPResponse.read(amt=None)\u003c/code\u003e was ignoring decompressed data buffered from previous partial reads. (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/3636\"\u003eurllib3/urllib3#3636\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed a bug where \u003ccode\u003eHTTPResponse.read()\u003c/code\u003e could cache only part of the response after a partial read when \u003ccode\u003ecache_content=True\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/4967\"\u003eurllib3/urllib3#4967\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eHTTPResponse.stream()\u003c/code\u003e and \u003ccode\u003eHTTPResponse.read_chunked()\u003c/code\u003e to handle \u003ccode\u003eamt=0\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/3793\"\u003eurllib3/urllib3#3793\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eUpdated \u003ccode\u003e_TYPE_BODY\u003c/code\u003e type alias to include missing \u003ccode\u003eIterable[str]\u003c/code\u003e, matching the documented and runtime behavior of chunked request bodies. (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/3798\"\u003eurllib3/urllib3#3798\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eLocationParseError\u003c/code\u003e when paths resembling schemeless URIs were passed to \u003ccode\u003eHTTPConnectionPool.urlopen()\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/3352\"\u003eurllib3/urllib3#3352\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eBaseHTTPResponse.readinto()\u003c/code\u003e type annotation to accept \u003ccode\u003ememoryview\u003c/code\u003e in addition to \u003ccode\u003ebytearray\u003c/code\u003e, matching the \u003ccode\u003eio.RawIOBase.readinto\u003c/code\u003e contract and enabling use with \u003ccode\u003eio.BufferedReader\u003c/code\u003e without type errors. (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/3764\"\u003eurllib3/urllib3#3764\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/urllib3/urllib3/blob/main/CHANGES.rst\"\u003eurllib3's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003e2.7.0 (2026-05-07)\u003c/h1\u003e\n\u003ch2\u003eSecurity\u003c/h2\u003e\n\u003cp\u003eAddressed high-severity security issues.\nImpact was limited to specific use cases detailed in the accompanying\nadvisories; overall user exposure was estimated to be marginal.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eDecompression-bomb safeguards of the streaming API were bypassed:\u003c/p\u003e\n\u003col\u003e\n\u003cli\u003eWhen \u003ccode\u003eHTTPResponse.drain_conn()\u003c/code\u003e was called after the response had been\nread and decompressed partially.\u003c/li\u003e\n\u003cli\u003eDuring the second \u003ccode\u003eHTTPResponse.read(amt=N)\u003c/code\u003e or\n\u003ccode\u003eHTTPResponse.stream(amt=N)\u003c/code\u003e call when the response was decompressed\nusing the official \u003ccode\u003eBrotli \u0026lt;https://pypi.org/project/brotli/\u0026gt;\u003c/code\u003e__ library.\u003c/li\u003e\n\u003c/ol\u003e\n\u003cp\u003eSee \u003ccode\u003eGHSA-mf9v-mfxr-j63j \u0026lt;https://github.com/urllib3/urllib3/security/advisories/GHSA-mf9v-mfxr-j63j\u0026gt;\u003c/code\u003e__\nfor details.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eHTTP pools created using \u003ccode\u003eProxyManager.connection_from_url\u003c/code\u003e did not strip\nsensitive headers specified in \u003ccode\u003eRetry.remove_headers_on_redirect\u003c/code\u003e when\nredirecting to a different host.\n(\u003ccode\u003eGHSA-qccp-gfcp-xxvc \u0026lt;https://github.com/urllib3/urllib3/security/advisories/GHSA-qccp-gfcp-xxvc\u0026gt;\u003c/code\u003e__)\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eDeprecations and Removals\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUsed \u003ccode\u003eFutureWarning\u003c/code\u003e instead of \u003ccode\u003eDeprecationWarning\u003c/code\u003e for better\nvisibility of existing deprecation notices. Rescheduled the removal of\ndeprecated features to version 3.0.\n(\u003ccode\u003e[#3763](https://github.com/urllib3/urllib3/issues/3763) \u0026lt;https://github.com/urllib3/urllib3/issues/3763\u0026gt;\u003c/code\u003e__)\u003c/li\u003e\n\u003cli\u003eRemoved support for end-of-life Python 3.9.\n(\u003ccode\u003e[#3720](https://github.com/urllib3/urllib3/issues/3720) \u0026lt;https://github.com/urllib3/urllib3/issues/3720\u0026gt;\u003c/code\u003e__)\u003c/li\u003e\n\u003cli\u003eRemoved support for end-of-life PyPy3.10.\n(\u003ccode\u003e[#4979](https://github.com/urllib3/urllib3/issues/4979) \u0026lt;https://github.com/urllib3/urllib3/issues/4979\u0026gt;\u003c/code\u003e__)\u003c/li\u003e\n\u003cli\u003eBumped the minimum supported pyOpenSSL version to 19.0.0.\n(\u003ccode\u003e[#3777](https://github.com/urllib3/urllib3/issues/3777) \u0026lt;https://github.com/urllib3/urllib3/issues/3777\u0026gt;\u003c/code\u003e__)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eBugfixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed a bug where \u003ccode\u003eHTTPResponse.read(amt=None)\u003c/code\u003e was ignoring decompressed\ndata buffered from previous partial reads.\n(\u003ccode\u003e[#3636](https://github.com/urllib3/urllib3/issues/3636) \u0026lt;https://github.com/urllib3/urllib3/issues/3636\u0026gt;\u003c/code\u003e__)\u003c/li\u003e\n\u003cli\u003eFixed a bug where \u003ccode\u003eHTTPResponse.read()\u003c/code\u003e could cache only part of the\nresponse after a partial read when \u003ccode\u003ecache_content=True\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/urllib3/urllib3/commit/9a950b92d999f906b6020bb2d1076ee56cddd5d2\"\u003e\u003ccode\u003e9a950b9\u003c/code\u003e\u003c/a\u003e Release 2.7.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/urllib3/urllib3/commit/5ec0de499b9166ca71c65ab04f2a7e4eb0d66fcc\"\u003e\u003ccode\u003e5ec0de4\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/urllib3/urllib3/commit/2bdcc44d1e163fb5cc48a8662425e35e15adfe6a\"\u003e\u003ccode\u003e2bdcc44\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/urllib3/urllib3/commit/f45b0df09d8620ac6ed0491eb9362c8c87b7bc2c\"\u003e\u003ccode\u003ef45b0df\u003c/code\u003e\u003c/a\u003e Fix a misleading example for \u003ccode\u003eProxyManager\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/4970\"\u003e#4970\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/urllib3/urllib3/commit/577193ca029872384f82c133449e0935f6d8a64b\"\u003e\u003ccode\u003e577193c\u003c/code\u003e\u003c/a\u003e Switch to nightly PyPy3.11 in CI for now (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/4984\"\u003e#4984\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/urllib3/urllib3/commit/e90af45bb006c3a452a3a21644a2681523f5c7fc\"\u003e\u003ccode\u003ee90af45\u003c/code\u003e\u003c/a\u003e Avoid infinite loop in \u003ccode\u003eHTTPResponse.read_chunked\u003c/code\u003e when \u003ccode\u003eamt=0\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/4974\"\u003e#4974\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/urllib3/urllib3/commit/67ed74fdaec6659a6534621ec8e3aaaa6f976210\"\u003e\u003ccode\u003e67ed74f\u003c/code\u003e\u003c/a\u003e Bump dev dependencies (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/4972\"\u003e#4972\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/urllib3/urllib3/commit/3abd481097b54d87b574ac7ea593c3f40938a84d\"\u003e\u003ccode\u003e3abd481\u003c/code\u003e\u003c/a\u003e Upgrade mypy to version 1.20.2 (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/4978\"\u003e#4978\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/urllib3/urllib3/commit/2b8725dfcac4f21d4d93cc0cc3a64a33af08f890\"\u003e\u003ccode\u003e2b8725d\u003c/code\u003e\u003c/a\u003e Drop support for EOL PyPy3.10 (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/4979\"\u003e#4979\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/urllib3/urllib3/commit/2944b2a0a6c573f5548a39cfd17196f98ee21b33\"\u003e\u003ccode\u003e2944b2a\u003c/code\u003e\u003c/a\u003e Upgrade \u003ccode\u003esetup-chrome\u003c/code\u003e and \u003ccode\u003esetup-firefox\u003c/code\u003e to fix warnings (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/4973\"\u003e#4973\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/urllib3/urllib3/compare/2.6.3...2.7.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/timerloggedout-spec/hermes-agent_fork/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/timerloggedout-spec/hermes-agent_fork/pull/5","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/timerloggedout-spec%2Fhermes-agent_fork/issues/5","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/5/packages"}},{"old_version":"3.13.3","new_version":"3.14.3","update_type":"minor","path":null,"pr_created_at":"2026-09-24T14:42:10.000Z","version_change":"3.13.3 → 3.14.3","issue":{"uuid":"5570060544","node_id":"PR_kwDOTg5ijc8AAAABE877pw","number":20,"state":"open","title":"Bump the minor-update group across 1 directory with 173 updates","user":"dependabot[bot]","labels":["dependencies"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-24T14:42:10.000Z","updated_at":"2026-09-24T14:42:23.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","group_name":"minor-update","update_count":173,"packages":[{"name":"tblib","old_version":"3.1.0","new_version":"3.2.2","repository_url":"https://github.com/ionelmc/python-tblib"},{"name":"regex","old_version":"2026.2.28","new_version":"2026.9.10","repository_url":"https://github.com/mrabarnett/mrab-regex"},{"name":"requests","old_version":"2.32.3","new_version":"2.34.2","repository_url":"https://github.com/psf/requests"},{"name":"tqdm","old_version":"4.67.3","new_version":"4.70.1","repository_url":"https://github.com/tqdm/tqdm"},{"name":"transformers","old_version":"5.5.3","new_version":"5.17.0","repository_url":"https://github.com/huggingface/transformers"},{"name":"tokenizers","old_version":"0.22.2","new_version":"0.23.2","repository_url":"https://github.com/huggingface/tokenizers"},{"name":"safetensors","old_version":"0.7.0","new_version":"0.8.0","repository_url":"https://github.com/huggingface/safetensors"},{"name":"fastapi","old_version":"0.136.3","new_version":"0.141.1","repository_url":"https://github.com/fastapi/fastapi"},{"name":"starlette","old_version":"1.3.1","new_version":"1.6.0","repository_url":"https://github.com/Kludex/starlette"},{"name":"aiohttp","old_version":"3.13.3","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"pydantic","old_version":"2.12.0","new_version":"2.13.5","repository_url":"https://github.com/pydantic/pydantic"},{"name":"prometheus-client","old_version":"0.22.0","new_version":"0.26.0","repository_url":"https://github.com/prometheus/client_python"},{"name":"tiktoken","old_version":"0.12.0","new_version":"0.14.0","repository_url":"https://github.com/openai/tiktoken"},{"name":"lark","old_version":"1.2.2","new_version":"1.3.1","repository_url":"https://github.com/lark-parser/lark"},{"name":"typing-extensions","old_version":"4.15.0","new_version":"4.16.0","repository_url":"https://github.com/python/typing_extensions"},{"name":"jsonschema","old_version":"4.23.0","new_version":"4.26.0","repository_url":"https://github.com/python-jsonschema/jsonschema"},{"name":"opentelemetry-sdk","old_version":"1.35.0","new_version":"1.44.0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"opentelemetry-api","old_version":"1.35.0","new_version":"1.44.0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"numba","old_version":"0.65.0","new_version":"0.67.0","repository_url":"https://github.com/numba/numba"},{"name":"absl-py","old_version":"2.1.0","new_version":"2.5.0","repository_url":"https://github.com/abseil/abseil-py"},{"name":"accelerate","old_version":"1.13.0","new_version":"1.15.0","repository_url":"https://github.com/huggingface/accelerate"},{"name":"aiohappyeyeballs","old_version":"2.6.1","new_version":"2.7.1","repository_url":"https://github.com/aio-libs/aiohappyeyeballs"},{"name":"alembic","old_version":"1.16.4","new_version":"1.20.0","repository_url":"https://github.com/sqlalchemy/alembic"},{"name":"annotated-types","old_version":"0.7.0","new_version":"0.8.0","repository_url":"https://github.com/annotated-types/annotated-types"},{"name":"anyio","old_version":"4.6.2.post1","new_version":"4.15.1","repository_url":"https://github.com/agronholm/anyio"},{"name":"arctic-inference","old_version":"0.1.1","new_version":"0.3.0"},{"name":"argcomplete","old_version":"3.5.1","new_version":"3.7.2","repository_url":"https://github.com/kislyuk/argcomplete"},{"name":"audioread","old_version":"3.0.1","new_version":"3.1.0","repository_url":"https://github.com/beetbox/audioread"},{"name":"azure-core","old_version":"1.38.2","new_version":"1.41.0","repository_url":"https://github.com/Azure/azure-sdk-for-python"},{"name":"azure-storage-blob","old_version":"12.28.0","new_version":"12.30.2","repository_url":"https://github.com/Azure/azure-sdk-for-python"},{"name":"bitsandbytes","old_version":"0.49.2","new_version":"0.50.2","repository_url":"https://github.com/bitsandbytes-foundation/bitsandbytes"},{"name":"blobfile","old_version":"3.0.0","new_version":"3.3.0","repository_url":"https://github.com/blobfile/blobfile"},{"name":"bm25s","old_version":"0.2.13","new_version":"0.3.11","repository_url":"https://github.com/xhluca/bm25s"},{"name":"boto3","old_version":"1.35.57","new_version":"1.43.98","repository_url":"https://github.com/boto/boto3"},{"name":"botocore","old_version":"1.35.57","new_version":"1.43.98","repository_url":"https://github.com/boto/botocore"},{"name":"cffi","old_version":"2.0.0","new_version":"2.1.1","repository_url":"https://github.com/python-cffi/cffi"},{"name":"charset-normalizer","old_version":"3.4.0","new_version":"3.5.1","repository_url":"https://github.com/jawah/charset_normalizer"},{"name":"click","old_version":"8.1.7","new_version":"8.5.0","repository_url":"https://github.com/pallets/click"},{"name":"cohere-melody","old_version":"0.9.0","new_version":"0.15.0","repository_url":"https://github.com/cohere-ai/melody"},{"name":"colorlog","old_version":"6.10.1","new_version":"6.12.0","repository_url":"https://github.com/borntyping/python-colorlog"},{"name":"coverage","old_version":"7.10.6","new_version":"7.16.1","repository_url":"https://github.com/coveragepy/coveragepy"},{"name":"cramjam","old_version":"2.9.0","new_version":"2.11.0","repository_url":"https://github.com/milesgranger/pyrus-cramjam"},{"name":"cuda-bindings","old_version":"13.0.3","new_version":"13.4.2","repository_url":"https://github.com/NVIDIA/cuda-python"},{"name":"cuda-pathfinder","old_version":"1.3.3","new_version":"1.8.2","repository_url":"https://github.com/NVIDIA/cuda-python"},{"name":"cuda-toolkit","old_version":"13.0.2","new_version":"13.4.2"},{"name":"datamodel-code-generator","old_version":"0.26.3","new_version":"0.82.0","repository_url":"https://github.com/datamodel-code-generator/datamodel-code-generator"},{"name":"dataproperty","old_version":"1.0.1","new_version":"1.1.1","repository_url":"https://github.com/thombashi/DataProperty"},{"name":"decorator","old_version":"5.1.1","new_version":"5.3.1","repository_url":"https://github.com/micheles/decorator"},{"name":"dill","old_version":"0.3.8","new_version":"0.4.1","repository_url":"https://github.com/uqfoundation/dill"},{"name":"distlib","old_version":"0.3.9","new_version":"0.4.3","repository_url":"https://github.com/pypa/distlib"},{"name":"dnspython","old_version":"2.7.0","new_version":"2.8.0","repository_url":"https://github.com/rthalley/dnspython"},{"name":"docker","old_version":"7.1.0","new_version":"7.2.0","repository_url":"https://github.com/docker/docker-py"},{"name":"einx","old_version":"0.3.0","new_version":"0.4.3","repository_url":"https://github.com/fferflo/einx"},{"name":"email-validator","old_version":"2.2.0","new_version":"2.3.0","repository_url":"https://github.com/JoshData/python-email-validator"},{"name":"fastsafetensors","old_version":"0.3.2","new_version":"0.4.0","repository_url":"https://github.com/foundation-model-stack/fastsafetensors"},{"name":"fonttools","old_version":"4.55.0","new_version":"4.65.0","repository_url":"https://github.com/fonttools/fonttools"},{"name":"frozenlist","old_version":"1.5.0","new_version":"1.8.0","repository_url":"https://github.com/aio-libs/frozenlist"},{"name":"genson","old_version":"1.3.0","new_version":"1.4.0","repository_url":"https://github.com/wolverdude/genson"},{"name":"google-api-core","old_version":"2.24.2","new_version":"2.38.0","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"google-auth","old_version":"2.40.2","new_version":"2.58.0","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"google-cloud-core","old_version":"2.4.3","new_version":"2.7.0","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"google-cloud-storage","old_version":"3.4.0","new_version":"3.14.1","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"google-crc32c","old_version":"1.7.1","new_version":"1.8.0","repository_url":"https://github.com/googleapis/python-crc32c"},{"name":"google-resumable-media","old_version":"2.7.2","new_version":"2.10.2","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"googleapis-common-protos","old_version":"1.70.0","new_version":"1.75.3","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"greenlet","old_version":"3.2.3","new_version":"3.5.6","repository_url":"https://github.com/python-greenlet/greenlet"},{"name":"grpcio","old_version":"1.78.0","new_version":"1.84.0","repository_url":"https://github.com/grpc/grpc"},{"name":"grpcio-reflection","old_version":"1.78.0","new_version":"1.84.0"},{"name":"h11","old_version":"0.14.0","new_version":"0.16.0","repository_url":"https://github.com/python-hyper/h11"},{"name":"h2","old_version":"4.3.0","new_version":"4.4.1","repository_url":"https://github.com/python-hyper/h2"},{"name":"hf-xet","old_version":"1.4.3","new_version":"1.6.0","repository_url":"https://github.com/huggingface/xet-core"},{"name":"hiredis","old_version":"3.0.0","new_version":"3.4.1","repository_url":"https://github.com/redis/hiredis-py"},{"name":"hpack","old_version":"4.1.0","new_version":"4.2.0","repository_url":"https://github.com/python-hyper/hpack"},{"name":"httpx","old_version":"0.27.2","new_version":"0.28.1","repository_url":"https://github.com/encode/httpx"},{"name":"huggingface-hub","old_version":"1.10.2","new_version":"1.32.0","repository_url":"https://github.com/huggingface/huggingface_hub"},{"name":"humanize","old_version":"4.11.0","new_version":"4.16.0","repository_url":"https://github.com/python-humanize/humanize"},{"name":"hypothesis","old_version":"6.131.0","new_version":"6.168.0","repository_url":"https://github.com/HypothesisWorks/hypothesis"},{"name":"idna","old_version":"3.10","new_version":"3.20","repository_url":"https://github.com/kjd/idna"},{"name":"iniconfig","old_version":"2.0.0","new_version":"2.3.0","repository_url":"https://github.com/pytest-dev/iniconfig"},{"name":"instanttensor","old_version":"0.1.5","new_version":"0.2.0","repository_url":"https://github.com/scitix/InstantTensor"},{"name":"jmespath","old_version":"1.0.1","new_version":"1.1.0","repository_url":"https://github.com/jmespath/jmespath.py"},{"name":"joblib","old_version":"1.4.2","new_version":"1.6.0","repository_url":"https://github.com/joblib/joblib"},{"name":"jsonschema-rs","old_version":"0.46.5","new_version":"0.56.0","repository_url":"https://github.com/Stranger6667/jsonschema"},{"name":"kiwisolver","old_version":"1.4.7","new_version":"1.5.1","repository_url":"https://github.com/nucleic/kiwi"},{"name":"lazy-loader","old_version":"0.4","new_version":"0.5","repository_url":"https://github.com/scientific-python/lazy-loader"},{"name":"llvmlite","old_version":"0.47.0","new_version":"0.49.0","repository_url":"https://github.com/numba/llvmlite"},{"name":"mako","old_version":"1.3.10","new_version":"1.4.1","repository_url":"https://github.com/sqlalchemy/mako"},{"name":"matplotlib","old_version":"3.9.2","new_version":"3.10.9","repository_url":"https://github.com/matplotlib/matplotlib"},{"name":"mpmath","old_version":"1.3.0","new_version":"1.4.1","repository_url":"https://github.com/mpmath/mpmath"},{"name":"msal","old_version":"1.34.0","new_version":"1.39.0","repository_url":"https://github.com/AzureAD/microsoft-authentication-library-for-python"},{"name":"msgpack","old_version":"1.1.0","new_version":"1.2.2","repository_url":"https://github.com/msgpack/msgpack-python"},{"name":"mteb","old_version":"2.8.3","new_version":"2.21.4","repository_url":"https://github.com/embeddings-benchmark/mteb"},{"name":"multidict","old_version":"6.1.0","new_version":"6.9.0","repository_url":"https://github.com/aio-libs/multidict"},{"name":"mypy-extensions","old_version":"1.0.0","new_version":"1.1.0","repository_url":"https://github.com/python/mypy_extensions"},{"name":"networkx","old_version":"3.2.1","new_version":"3.4.2","repository_url":"https://github.com/networkx/networkx"},{"name":"nltk","old_version":"3.9.1","new_version":"3.10.3","repository_url":"https://github.com/nltk/nltk"},{"name":"nvidia-cublas","old_version":"13.1.0.3","new_version":"13.8.0.4"},{"name":"nvidia-cuda-cupti","old_version":"13.0.85","new_version":"13.4.92"},{"name":"nvidia-cuda-nvrtc","old_version":"13.0.88","new_version":"13.4.92"},{"name":"nvidia-cuda-runtime","old_version":"13.0.96","new_version":"13.4.92"},{"name":"nvidia-cudnn-cu13","old_version":"9.19.0.56","new_version":"9.26.0.51"},{"name":"nvidia-cufft","old_version":"12.0.0.61","new_version":"12.4.0.43"},{"name":"nvidia-cufile","old_version":"1.15.1.6","new_version":"1.19.1.55"},{"name":"nvidia-cusolver","old_version":"12.0.4.66","new_version":"12.3.4.7"},{"name":"nvidia-cusparse","old_version":"12.6.3.3","new_version":"12.8.6.72"},{"name":"nvidia-cusparselt-cu13","old_version":"0.8.0","new_version":"0.9.1"},{"name":"nvidia-nccl-cu13","old_version":"2.28.9","new_version":"2.31.2"},{"name":"nvidia-nvjitlink","old_version":"13.0.88","new_version":"13.4.92"},{"name":"nvidia-nvshmem-cu13","old_version":"3.4.5","new_version":"3.7.2"},{"name":"nvidia-nvtx","old_version":"13.0.85","new_version":"13.4.92"},{"name":"opentelemetry-exporter-prometheus","old_version":"0.56b0","new_version":"0.65b0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"opentelemetry-proto","old_version":"1.35.0","new_version":"1.44.0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"opentelemetry-semantic-conventions","old_version":"0.56b0","new_version":"0.65b0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"orjson","old_version":"3.11.5","new_version":"3.12.0","repository_url":"https://github.com/ijl/orjson"},{"name":"pathvalidate","old_version":"3.2.1","new_version":"3.3.1","repository_url":"https://github.com/thombashi/pathvalidate"},{"name":"peft","old_version":"0.18.1","new_version":"0.21.0","repository_url":"https://github.com/huggingface/peft"},{"name":"perceptron","old_version":"0.1.4","new_version":"0.3.5","repository_url":"https://github.com/perceptron-ai-inc/perceptron"},{"name":"platformdirs","old_version":"4.3.6","new_version":"4.11.11","repository_url":"https://github.com/tox-dev/platformdirs"},{"name":"pluggy","old_version":"1.5.0","new_version":"1.6.0","repository_url":"https://github.com/pytest-dev/pluggy"},{"name":"polars","old_version":"1.29.0","new_version":"1.44.2","repository_url":"https://github.com/pola-rs/polars"},{"name":"pooch","old_version":"1.8.2","new_version":"1.9.0","repository_url":"https://github.com/fatiando/pooch"},{"name":"propcache","old_version":"0.2.0","new_version":"0.5.4","repository_url":"https://github.com/aio-libs/propcache"},{"name":"proto-plus","old_version":"1.26.1","new_version":"1.28.4","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"pycryptodomex","old_version":"3.22.0","new_version":"3.23.0","repository_url":"https://github.com/Legrandin/pycryptodome"},{"name":"pydantic-core","old_version":"2.41.1","new_version":"2.49.0","repository_url":"https://github.com/pydantic/pydantic"},{"name":"pydantic-extra-types","old_version":"2.10.5","new_version":"2.11.1","repository_url":"https://github.com/pydantic/pydantic-extra-types"},{"name":"pygments","old_version":"2.18.0","new_version":"2.21.0","repository_url":"https://github.com/pygments/pygments"},{"name":"pyjwt","old_version":"2.11.0","new_version":"2.14.0","repository_url":"https://github.com/jpadilla/pyjwt"},{"name":"pyparsing","old_version":"3.2.0","new_version":"3.3.3","repository_url":"https://github.com/pyparsing/pyparsing"},{"name":"pyrate-limiter","old_version":"4.4.0","new_version":"4.5.0","repository_url":"https://github.com/vutran1710/PyrateLimiter"},{"name":"pystemmer","old_version":"3.0.0","new_version":"3.1.0","repository_url":"https://github.com/snowballstem/pystemmer"},{"name":"pytest-forked","old_version":"1.6.0","new_version":"1.7.5","repository_url":"https://github.com/pytest-dev/pytest-forked"},{"name":"pytest-mock","old_version":"3.14.0","new_version":"3.15.1","repository_url":"https://github.com/pytest-dev/pytest-mock"},{"name":"pytest-timeout","old_version":"2.3.1","new_version":"2.4.0","repository_url":"https://github.com/pytest-dev/pytest-timeout"},{"name":"python-rapidjson","old_version":"1.20","new_version":"1.25","repository_url":"https://github.com/python-rapidjson/python-rapidjson"},{"name":"rapidfuzz","old_version":"3.12.1","new_version":"3.14.5","repository_url":"https://github.com/rapidfuzz/RapidFuzz"},{"name":"referencing","old_version":"0.35.1","new_version":"0.37.0","repository_url":"https://github.com/python-jsonschema/referencing"},{"name":"responses","old_version":"0.25.3","new_version":"0.26.3","repository_url":"https://github.com/getsentry/responses"},{"name":"runai-model-streamer","old_version":"0.15.7","new_version":"0.16.1"},{"name":"runai-model-streamer-azure","old_version":"0.15.7","new_version":"0.16.1"},{"name":"runai-model-streamer-gcs","old_version":"0.15.7","new_version":"0.16.1"},{"name":"runai-model-streamer-s3","old_version":"0.15.7","new_version":"0.16.1"},{"name":"s3transfer","old_version":"0.10.3","new_version":"0.19.2","repository_url":"https://github.com/boto/s3transfer"},{"name":"sacrebleu","old_version":"2.4.3","new_version":"2.6.0","repository_url":"https://github.com/mjpost/sacrebleu"},{"name":"schemathesis","old_version":"4.21.6","new_version":"4.27.5","repository_url":"https://github.com/schemathesis/schemathesis"},{"name":"scikit-learn","old_version":"1.5.2","new_version":"1.7.2","repository_url":"https://github.com/scikit-learn/scikit-learn"},{"name":"scipy","old_version":"1.13.1","new_version":"1.15.3","repository_url":"https://github.com/scipy/scipy"},{"name":"six","old_version":"1.16.0","new_version":"1.17.0","repository_url":"https://github.com/benjaminp/six"},{"name":"soundfile","old_version":"0.12.1","new_version":"0.14.0","repository_url":"https://github.com/bastibe/python-soundfile"},{"name":"statsmodels","old_version":"0.14.4","new_version":"0.15.0","repository_url":"https://github.com/statsmodels/statsmodels"},{"name":"sympy","old_version":"1.13.3","new_version":"1.14.0","repository_url":"https://github.com/sympy/sympy"},{"name":"tabulate","old_version":"0.9.0","new_version":"0.10.0","repository_url":"https://github.com/astanin/python-tabulate"},{"name":"tensorizer","old_version":"2.10.1","new_version":"2.12.1","repository_url":"https://github.com/coreweave/tensorizer"},{"name":"termcolor","old_version":"3.1.0","new_version":"3.3.0","repository_url":"https://github.com/termcolor/termcolor"},{"name":"threadpoolctl","old_version":"3.5.0","new_version":"3.7.0","repository_url":"https://github.com/joblib/threadpoolctl"},{"name":"triton","old_version":"3.6.0","new_version":"3.8.0","repository_url":"https://github.com/triton-lang/triton"},{"name":"tritonclient","old_version":"2.64.0","new_version":"2.71.0","repository_url":"https://github.com/triton-inference-server/client"},{"name":"typer","old_version":"0.15.2","new_version":"0.27.2","repository_url":"https://github.com/fastapi/typer"},{"name":"urllib3","old_version":"2.2.3","new_version":"2.8.0","repository_url":"https://github.com/urllib3/urllib3"},{"name":"uvicorn","old_version":"0.35.0","new_version":"0.53.0","repository_url":"https://github.com/Kludex/uvicorn"},{"name":"vector-quantize-pytorch","old_version":"1.21.2","new_version":"1.31.4","repository_url":"https://github.com/lucidrains/vector-quantizer-pytorch"},{"name":"wcwidth","old_version":"0.2.13","new_version":"0.8.4","repository_url":"https://github.com/jquast/wcwidth"},{"name":"yarl","old_version":"1.17.1","new_version":"1.25.1","repository_url":"https://github.com/aio-libs/yarl"},{"name":"conch-triton-kernels","old_version":"1.2.1","new_version":"1.3","repository_url":"https://github.com/stackav-oss/conch"},{"name":"tpu-inference","old_version":"0.23.0","new_version":"0.29.0","repository_url":"https://github.com/vllm-project/tpu-inference"},{"name":"pynvvideocodec","old_version":"2.0.4","new_version":"2.2.3"},{"name":"nvidia-cutlass-dsl","old_version":"4.5.2","new_version":"4.8.0","repository_url":"https://github.com/NVIDIA/cutlass"},{"name":"tokenspeed-mla","old_version":"0.1.2","new_version":"0.2.10","repository_url":"https://github.com/lightseekorg/tokenspeed"},{"name":"griffelib","old_version":"2.0.2","new_version":"2.3.0"},{"name":"mkdocs-git-revision-date-localized-plugin","old_version":"1.5.1","new_version":"1.6.0","repository_url":"https://github.com/timvink/mkdocs-git-revision-date-localized-plugin"},{"name":"ruff","old_version":"0.15.12","new_version":"0.16.8","repository_url":"https://github.com/astral-sh/ruff"},{"name":"zentorch","old_version":"2.11.0.0","new_version":"2.14.0.0","repository_url":"https://github.com/amd/ZenDNN-pytorch-plugin"},{"name":"helion","old_version":"1.1.0","new_version":"1.4.0","repository_url":"https://github.com/pytorch/helion"}],"path":null,"ecosystem":"pip"},"body":"Bumps the minor-update group with 173 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [tblib](https://github.com/ionelmc/python-tblib) | `3.1.0` | `3.2.2` |\n| [regex](https://github.com/mrabarnett/mrab-regex) | `2026.2.28` | `2026.9.10` |\n| [requests](https://github.com/psf/requests) | `2.32.3` | `2.34.2` |\n| [tqdm](https://github.com/tqdm/tqdm) | `4.67.3` | `4.70.1` |\n| [transformers](https://github.com/huggingface/transformers) | `5.5.3` | `5.17.0` |\n| [tokenizers](https://github.com/huggingface/tokenizers) | `0.22.2` | `0.23.2` |\n| [safetensors](https://github.com/huggingface/safetensors) | `0.7.0` | `0.8.0` |\n| [fastapi](https://github.com/fastapi/fastapi) | `0.136.3` | `0.141.1` |\n| [starlette](https://github.com/Kludex/starlette) | `1.3.1` | `1.6.0` |\n| [aiohttp](https://github.com/aio-libs/aiohttp) | `3.13.3` | `3.14.3` |\n| [pydantic](https://github.com/pydantic/pydantic) | `2.12.0` | `2.13.5` |\n| [prometheus-client](https://github.com/prometheus/client_python) | `0.22.0` | `0.26.0` |\n| [tiktoken](https://github.com/openai/tiktoken) | `0.12.0` | `0.14.0` |\n| [lark](https://github.com/lark-parser/lark) | `1.2.2` | `1.3.1` |\n| [typing-extensions](https://github.com/python/typing_extensions) | `4.15.0` | `4.16.0` |\n| [jsonschema](https://github.com/python-jsonschema/jsonschema) | `4.23.0` | `4.26.0` |\n| [opentelemetry-sdk](https://github.com/open-telemetry/opentelemetry-python) | `1.35.0` | `1.44.0` |\n| [opentelemetry-api](https://github.com/open-telemetry/opentelemetry-python) | `1.35.0` | `1.44.0` |\n| [numba](https://github.com/numba/numba) | `0.65.0` | `0.67.0` |\n| [absl-py](https://github.com/abseil/abseil-py) | `2.1.0` | `2.5.0` |\n| [accelerate](https://github.com/huggingface/accelerate) | `1.13.0` | `1.15.0` |\n| [aiohappyeyeballs](https://github.com/aio-libs/aiohappyeyeballs) | `2.6.1` | `2.7.1` |\n| [alembic](https://github.com/sqlalchemy/alembic) | `1.16.4` | `1.20.0` |\n| [annotated-types](https://github.com/annotated-types/annotated-types) | `0.7.0` | `0.8.0` |\n| [anyio](https://github.com/agronholm/anyio) | `4.6.2.post1` | `4.15.1` |\n| arctic-inference | `0.1.1` | `0.3.0` |\n| [argcomplete](https://github.com/kislyuk/argcomplete) | `3.5.1` | `3.7.2` |\n| [audioread](https://github.com/beetbox/audioread) | `3.0.1` | `3.1.0` |\n| [azure-core](https://github.com/Azure/azure-sdk-for-python) | `1.38.2` | `1.41.0` |\n| [azure-storage-blob](https://github.com/Azure/azure-sdk-for-python) | `12.28.0` | `12.30.2` |\n| [bitsandbytes](https://github.com/bitsandbytes-foundation/bitsandbytes) | `0.49.2` | `0.50.2` |\n| [blobfile](https://github.com/blobfile/blobfile) | `3.0.0` | `3.3.0` |\n| [bm25s](https://github.com/xhluca/bm25s) | `0.2.13` | `0.3.11` |\n| [boto3](https://github.com/boto/boto3) | `1.35.57` | `1.43.98` |\n| [botocore](https://github.com/boto/botocore) | `1.35.57` | `1.43.98` |\n| [cffi](https://github.com/python-cffi/cffi) | `2.0.0` | `2.1.1` |\n| [charset-normalizer](https://github.com/jawah/charset_normalizer) | `3.4.0` | `3.5.1` |\n| [click](https://github.com/pallets/click) | `8.1.7` | `8.5.0` |\n| [cohere-melody](https://github.com/cohere-ai/melody) | `0.9.0` | `0.15.0` |\n| [colorlog](https://github.com/borntyping/python-colorlog) | `6.10.1` | `6.12.0` |\n| [coverage](https://github.com/coveragepy/coveragepy) | `7.10.6` | `7.16.1` |\n| [cramjam](https://github.com/milesgranger/pyrus-cramjam) | `2.9.0` | `2.11.0` |\n| [cuda-bindings](https://github.com/NVIDIA/cuda-python) | `13.0.3` | `13.4.2` |\n| [cuda-pathfinder](https://github.com/NVIDIA/cuda-python) | `1.3.3` | `1.8.2` |\n| [cuda-toolkit](https://developer.nvidia.com/cuda-toolkit) | `13.0.2` | `13.4.2` |\n| [datamodel-code-generator](https://github.com/datamodel-code-generator/datamodel-code-generator) | `0.26.3` | `0.82.0` |\n| [dataproperty](https://github.com/thombashi/DataProperty) | `1.0.1` | `1.1.1` |\n| [decorator](https://github.com/micheles/decorator) | `5.1.1` | `5.3.1` |\n| [dill](https://github.com/uqfoundation/dill) | `0.3.8` | `0.4.1` |\n| [distlib](https://github.com/pypa/distlib) | `0.3.9` | `0.4.3` |\n| [dnspython](https://github.com/rthalley/dnspython) | `2.7.0` | `2.8.0` |\n| [docker](https://github.com/docker/docker-py) | `7.1.0` | `7.2.0` |\n| [einx](https://github.com/fferflo/einx) | `0.3.0` | `0.4.3` |\n| [email-validator](https://github.com/JoshData/python-email-validator) | `2.2.0` | `2.3.0` |\n| [fastsafetensors](https://github.com/foundation-model-stack/fastsafetensors) | `0.3.2` | `0.4.0` |\n| [fonttools](https://github.com/fonttools/fonttools) | `4.55.0` | `4.65.0` |\n| [frozenlist](https://github.com/aio-libs/frozenlist) | `1.5.0` | `1.8.0` |\n| [genson](https://github.com/wolverdude/genson) | `1.3.0` | `1.4.0` |\n| [google-api-core](https://github.com/googleapis/google-cloud-python) | `2.24.2` | `2.38.0` |\n| [google-auth](https://github.com/googleapis/google-cloud-python) | `2.40.2` | `2.58.0` |\n| [google-cloud-core](https://github.com/googleapis/google-cloud-python) | `2.4.3` | `2.7.0` |\n| [google-cloud-storage](https://github.com/googleapis/google-cloud-python) | `3.4.0` | `3.14.1` |\n| [google-crc32c](https://github.com/googleapis/python-crc32c) | `1.7.1` | `1.8.0` |\n| [google-resumable-media](https://github.com/googleapis/google-cloud-python) | `2.7.2` | `2.10.2` |\n| [googleapis-common-protos](https://github.com/googleapis/google-cloud-python) | `1.70.0` | `1.75.3` |\n| [greenlet](https://github.com/python-greenlet/greenlet) | `3.2.3` | `3.5.6` |\n| [grpcio](https://github.com/grpc/grpc) | `1.78.0` | `1.84.0` |\n| [grpcio-reflection](https://grpc.io) | `1.78.0` | `1.84.0` |\n| [h11](https://github.com/python-hyper/h11) | `0.14.0` | `0.16.0` |\n| [h2](https://github.com/python-hyper/h2) | `4.3.0` | `4.4.1` |\n| [hf-xet](https://github.com/huggingface/xet-core) | `1.4.3` | `1.6.0` |\n| [hiredis](https://github.com/redis/hiredis-py) | `3.0.0` | `3.4.1` |\n| [hpack](https://github.com/python-hyper/hpack) | `4.1.0` | `4.2.0` |\n| [httpx](https://github.com/encode/httpx) | `0.27.2` | `0.28.1` |\n| [huggingface-hub](https://github.com/huggingface/huggingface_hub) | `1.10.2` | `1.32.0` |\n| [humanize](https://github.com/python-humanize/humanize) | `4.11.0` | `4.16.0` |\n| [hypothesis](https://github.com/HypothesisWorks/hypothesis) | `6.131.0` | `6.168.0` |\n| [idna](https://github.com/kjd/idna) | `3.10` | `3.20` |\n| [iniconfig](https://github.com/pytest-dev/iniconfig) | `2.0.0` | `2.3.0` |\n| [instanttensor](https://github.com/scitix/InstantTensor) | `0.1.5` | `0.2.0` |\n| [jmespath](https://github.com/jmespath/jmespath.py) | `1.0.1` | `1.1.0` |\n| [joblib](https://github.com/joblib/joblib) | `1.4.2` | `1.6.0` |\n| [jsonschema-rs](https://github.com/Stranger6667/jsonschema) | `0.46.5` | `0.56.0` |\n| [kiwisolver](https://github.com/nucleic/kiwi) | `1.4.7` | `1.5.1` |\n| [lazy-loader](https://github.com/scientific-python/lazy-loader) | `0.4` | `0.5` |\n| [llvmlite](https://github.com/numba/llvmlite) | `0.47.0` | `0.49.0` |\n| [mako](https://github.com/sqlalchemy/mako) | `1.3.10` | `1.4.1` |\n| [matplotlib](https://github.com/matplotlib/matplotlib) | `3.9.2` | `3.10.9` |\n| [mpmath](https://github.com/mpmath/mpmath) | `1.3.0` | `1.4.1` |\n| [msal](https://github.com/AzureAD/microsoft-authentication-library-for-python) | `1.34.0` | `1.39.0` |\n| [msgpack](https://github.com/msgpack/msgpack-python) | `1.1.0` | `1.2.2` |\n| [mteb](https://github.com/embeddings-benchmark/mteb) | `2.8.3` | `2.21.4` |\n| [multidict](https://github.com/aio-libs/multidict) | `6.1.0` | `6.9.0` |\n| [mypy-extensions](https://github.com/python/mypy_extensions) | `1.0.0` | `1.1.0` |\n| [networkx](https://github.com/networkx/networkx) | `3.2.1` | `3.4.2` |\n| [nltk](https://github.com/nltk/nltk) | `3.9.1` | `3.10.3` |\n| [nvidia-cublas](https://developer.nvidia.com/cuda-zone) | `13.1.0.3` | `13.8.0.4` |\n| [nvidia-cuda-cupti](https://developer.nvidia.com/cuda-zone) | `13.0.85` | `13.4.92` |\n| [nvidia-cuda-nvrtc](https://developer.nvidia.com/cuda-zone) | `13.0.88` | `13.4.92` |\n| [nvidia-cuda-runtime](https://developer.nvidia.com/cuda-zone) | `13.0.96` | `13.4.92` |\n| [nvidia-cudnn-cu13](https://developer.nvidia.com/cuda-zone) | `9.19.0.56` | `9.26.0.51` |\n| [nvidia-cufft](https://developer.nvidia.com/cuda-zone) | `12.0.0.61` | `12.4.0.43` |\n| [nvidia-cufile](https://developer.nvidia.com/cuda-zone) | `1.15.1.6` | `1.19.1.55` |\n| [nvidia-cusolver](https://developer.nvidia.com/cuda-zone) | `12.0.4.66` | `12.3.4.7` |\n| [nvidia-cusparse](https://developer.nvidia.com/cuda-zone) | `12.6.3.3` | `12.8.6.72` |\n| [nvidia-cusparselt-cu13](https://developer.nvidia.com/cusparselt) | `0.8.0` | `0.9.1` |\n| [nvidia-nccl-cu13](https://developer.nvidia.com/cuda-zone) | `2.28.9` | `2.31.2` |\n| [nvidia-nvjitlink](https://developer.nvidia.com/cuda-zone) | `13.0.88` | `13.4.92` |\n| [nvidia-nvshmem-cu13](https://developer.nvidia.com/cuda-zone) | `3.4.5` | `3.7.2` |\n| [nvidia-nvtx](https://developer.nvidia.com/cuda-zone) | `13.0.85` | `13.4.92` |\n| [opentelemetry-exporter-prometheus](https://github.com/open-telemetry/opentelemetry-python) | `0.56b0` | `0.65b0` |\n| [opentelemetry-proto](https://github.com/open-telemetry/opentelemetry-python) | `1.35.0` | `1.44.0` |\n| [opentelemetry-semantic-conventions](https://github.com/open-telemetry/opentelemetry-python) | `0.56b0` | `0.65b0` |\n| [orjson](https://github.com/ijl/orjson) | `3.11.5` | `3.12.0` |\n| [pathvalidate](https://github.com/thombashi/pathvalidate) | `3.2.1` | `3.3.1` |\n| [peft](https://github.com/huggingface/peft) | `0.18.1` | `0.21.0` |\n| [perceptron](https://github.com/perceptron-ai-inc/perceptron) | `0.1.4` | `0.3.5` |\n| [platformdirs](https://github.com/tox-dev/platformdirs) | `4.3.6` | `4.11.11` |\n| [pluggy](https://github.com/pytest-dev/pluggy) | `1.5.0` | `1.6.0` |\n| [polars](https://github.com/pola-rs/polars) | `1.29.0` | `1.44.2` |\n| [pooch](https://github.com/fatiando/pooch) | `1.8.2` | `1.9.0` |\n| [propcache](https://github.com/aio-libs/propcache) | `0.2.0` | `0.5.4` |\n| [proto-plus](https://github.com/googleapis/google-cloud-python) | `1.26.1` | `1.28.4` |\n| [pycryptodomex](https://github.com/Legrandin/pycryptodome) | `3.22.0` | `3.23.0` |\n| [pydantic-core](https://github.com/pydantic/pydantic) | `2.41.1` | `2.49.0` |\n| [pydantic-extra-types](https://github.com/pydantic/pydantic-extra-types) | `2.10.5` | `2.11.1` |\n| [pygments](https://github.com/pygments/pygments) | `2.18.0` | `2.21.0` |\n| [pyjwt](https://github.com/jpadilla/pyjwt) | `2.11.0` | `2.14.0` |\n| [pyparsing](https://github.com/pyparsing/pyparsing) | `3.2.0` | `3.3.3` |\n| [pyrate-limiter](https://github.com/vutran1710/PyrateLimiter) | `4.4.0` | `4.5.0` |\n| [pystemmer](https://github.com/snowballstem/pystemmer) | `3.0.0` | `3.1.0` |\n| [pytest-forked](https://github.com/pytest-dev/pytest-forked) | `1.6.0` | `1.7.5` |\n| [pytest-mock](https://github.com/pytest-dev/pytest-mock) | `3.14.0` | `3.15.1` |\n| [pytest-timeout](https://github.com/pytest-dev/pytest-timeout) | `2.3.1` | `2.4.0` |\n| [python-rapidjson](https://github.com/python-rapidjson/python-rapidjson) | `1.20` | `1.25` |\n| [rapidfuzz](https://github.com/rapidfuzz/RapidFuzz) | `3.12.1` | `3.14.5` |\n| [referencing](https://github.com/python-jsonschema/referencing) | `0.35.1` | `0.37.0` |\n| [responses](https://github.com/getsentry/responses) | `0.25.3` | `0.26.3` |\n| runai-model-streamer | `0.15.7` | `0.16.1` |\n| runai-model-streamer-azure | `0.15.7` | `0.16.1` |\n| runai-model-streamer-gcs | `0.15.7` | `0.16.1` |\n| runai-model-streamer-s3 | `0.15.7` | `0.16.1` |\n| [s3transfer](https://github.com/boto/s3transfer) | `0.10.3` | `0.19.2` |\n| [sacrebleu](https://github.com/mjpost/sacrebleu) | `2.4.3` | `2.6.0` |\n| [schemathesis](https://github.com/schemathesis/schemathesis) | `4.21.6` | `4.27.5` |\n| [scikit-learn](https://github.com/scikit-learn/scikit-learn) | `1.5.2` | `1.7.2` |\n| [scipy](https://github.com/scipy/scipy) | `1.13.1` | `1.15.3` |\n| [six](https://github.com/benjaminp/six) | `1.16.0` | `1.17.0` |\n| [soundfile](https://github.com/bastibe/python-soundfile) | `0.12.1` | `0.14.0` |\n| [statsmodels](https://github.com/statsmodels/statsmodels) | `0.14.4` | `0.15.0` |\n| [sympy](https://github.com/sympy/sympy) | `1.13.3` | `1.14.0` |\n| [tabulate](https://github.com/astanin/python-tabulate) | `0.9.0` | `0.10.0` |\n| [tensorizer](https://github.com/coreweave/tensorizer) | `2.10.1` | `2.12.1` |\n| [termcolor](https://github.com/termcolor/termcolor) | `3.1.0` | `3.3.0` |\n| [threadpoolctl](https://github.com/joblib/threadpoolctl) | `3.5.0` | `3.7.0` |\n| [triton](https://github.com/triton-lang/triton) | `3.6.0` | `3.8.0` |\n| [tritonclient](https://github.com/triton-inference-server/client) | `2.64.0` | `2.71.0` |\n| [typer](https://github.com/fastapi/typer) | `0.15.2` | `0.27.2` |\n| [urllib3](https://github.com/urllib3/urllib3) | `2.2.3` | `2.8.0` |\n| [uvicorn](https://github.com/Kludex/uvicorn) | `0.35.0` | `0.53.0` |\n| [vector-quantize-pytorch](https://github.com/lucidrains/vector-quantizer-pytorch) | `1.21.2` | `1.31.4` |\n| [wcwidth](https://github.com/jquast/wcwidth) | `0.2.13` | `0.8.4` |\n| [yarl](https://github.com/aio-libs/yarl) | `1.17.1` | `1.25.1` |\n| [conch-triton-kernels](https://github.com/stackav-oss/conch) | `1.2.1` | `1.3` |\n| [tpu-inference](https://github.com/vllm-project/tpu-inference) | `0.23.0` | `0.29.0` |\n| pynvvideocodec | `2.0.4` | `2.2.3` |\n| [nvidia-cutlass-dsl](https://github.com/NVIDIA/cutlass) | `4.5.2` | `4.8.0` |\n| [tokenspeed-mla](https://github.com/lightseekorg/tokenspeed) | `0.1.2` | `0.2.10` |\n| griffelib | `2.0.2` | `2.3.0` |\n| [mkdocs-git-revision-date-localized-plugin](https://github.com/timvink/mkdocs-git-revision-date-localized-plugin) | `1.5.1` | `1.6.0` |\n| [ruff](https://github.com/astral-sh/ruff) | `0.15.12` | `0.16.8` |\n| [zentorch](https://github.com/amd/ZenDNN-pytorch-plugin) | `2.11.0.0` | `2.14.0.0` |\n| [helion](https://github.com/pytorch/helion) | `1.1.0` | `1.4.0` |\n\n\nUpdates `tblib` from 3.1.0 to 3.2.2\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/ionelmc/python-tblib/blob/master/CHANGELOG.rst\"\u003etblib's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e3.2.2 (2025-11-12)\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003e\n* Fixed regression occurring with ``TimeoutError`` exceptions. They should be represented now exactly as the original when unpickling.\n  Contributed by Jacob Tomlinson in `[#85](https://github.com/ionelmc/python-tblib/issues/85) \u0026lt;https://github.com/ionelmc/python-tblib/pull/85\u0026gt;`_.\n\u003cp\u003e3.2.1 (2025-10-31)\n\u003c/code\u003e\u003c/pre\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eFixed regression occurring with \u003ccode\u003eExceptionGroup\u003c/code\u003e exceptions. That exception type is now handled specifically in the new \u003ccode\u003eunpickle_exception_with_attrs\u003c/code\u003e function (just like \u003ccode\u003eOSError\u003c/code\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e3.2.0 (2025-10-21)\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003e\n* Changed ``tblib.pickling_support.install`` to support exceptions with ``__init__`` that does match the default\n  ``BaseException.__reduce__`` (as it expects the positional arguments to ``__init__`` to match the ``args`` attribute).\n\u003cp\u003eSpecial handling for OSError (and subclasses) is also included. The errno, strerror, winerror, filename and filename2 attributes will be added in the reduce structure (if set).\u003c/p\u003e\n\u003cp\u003eThis will support exception subclasses that do this without defining a custom \u003ccode\u003e__reduce__\u003c/code\u003e:\u003c/p\u003e\n\u003cp\u003e.. code-block:: python\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003edef __init__(self):\n    super().__init__('mistery argument')\n\ndef __init__(self, mistery_argument):\n    super().__init__()\n    self.mistery_argument = mistery_argument\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eTests and POC contributed by Oldřich Jedlička in \u003ccode\u003e[#73](https://github.com/ionelmc/python-tblib/issues/73) \u0026amp;lt;https://github.com/ionelmc/python-tblib/pull/73\u0026amp;gt;\u003c/code\u003e_.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eFixed some doctest and coverage config. Contributed by Colin Watson in \u003ccode\u003e[#79](https://github.com/ionelmc/python-tblib/issues/79) \u0026amp;lt;https://github.com/ionelmc/python-tblib/pull/79\u0026amp;gt;\u003c/code\u003e_.\n\u003c/code\u003e\u003c/pre\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/d88606aab343749dfeccf16a813f63cbe2dae11e\"\u003e\u003ccode\u003ed88606a\u003c/code\u003e\u003c/a\u003e Bump version: 3.2.1 → 3.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/530f8743f1ed322f220621d8491e660636065279\"\u003e\u003ccode\u003e530f874\u003c/code\u003e\u003c/a\u003e Add test for timeouterror regression. Ref \u003ca href=\"https://redirect.github.com/ionelmc/python-tblib/issues/85\"\u003e#85\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/9c8f2ca0e7c061cc423207986af6f06aaa76cfee\"\u003e\u003ccode\u003e9c8f2ca\u003c/code\u003e\u003c/a\u003e Update changelog.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/df6185d4b942a37d48a0e082b885380b8c5cc5ad\"\u003e\u003ccode\u003edf6185d\u003c/code\u003e\u003c/a\u003e Handle optional OSError attributes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/b197023aa86b831834393fdd89c6439fe2ffaf0c\"\u003e\u003ccode\u003eb197023\u003c/code\u003e\u003c/a\u003e Bump version: 3.2.0 → 3.2.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/d71e1edc9da5a86e326406ea4372cce5c075b4f4\"\u003e\u003ccode\u003ed71e1ed\u003c/code\u003e\u003c/a\u003e Update changelog.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/74ec64570acb0d6ce708c695ab98d52d08f8b066\"\u003e\u003ccode\u003e74ec645\u003c/code\u003e\u003c/a\u003e Specifically handle ExceptionGroup in the new unpickle_exception_with_attrs. ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/580d57921a6e93660bf47771f70c0bfbe70e9c97\"\u003e\u003ccode\u003e580d579\u003c/code\u003e\u003c/a\u003e Ooops, forgot to update these.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/ebc83e93b6342950cb93cf296991fb99ce4aa13a\"\u003e\u003ccode\u003eebc83e9\u003c/code\u003e\u003c/a\u003e Bump version: 3.1.0 → 3.2.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ionelmc/python-tblib/commit/abec37d4526fb86f95c7567644f1fd6c2cec4215\"\u003e\u003ccode\u003eabec37d\u003c/code\u003e\u003c/a\u003e Update changelog and add one more test.\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/ionelmc/python-tblib/compare/v3.1.0...v3.2.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `regex` from 2026.2.28 to 2026.9.10\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/mrabarnett/mrab-regex/blob/hg/changelog.txt\"\u003eregex's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003eVersion: 2026.9.19\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eGit issue 619: `Match.expand()` segfaults after `detach_string()` when the template references a group\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.9.10\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eFixed version.\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.9.9\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003ePR [#615](https://github.com/mrabarnett/mrab-regex/issues/615): Fix Python API error propagation in match helpers\n\u003cp\u003ePR \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/616\"\u003e#616\u003c/a\u003e: Preserve Python Exceptions in Input Decoding and String Detachment\u003c/p\u003e\n\u003cp\u003ePR \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/617\"\u003e#617\u003c/a\u003e: Prevent Invalid Pointer Use and Exception State Corruption in Byte String Joining\u003c/p\u003e\n\u003cp\u003ePR \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/618\"\u003e#618\u003c/a\u003e: Propagate Allocation and Internal Errors During Pattern Compilation and Scanner Execution\n\u003c/code\u003e\u003c/pre\u003e\u003c/p\u003e\n\u003cp\u003eVersion: 2026.9.3\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eNew version of cibuildwheel no longer supports building for free-threaded Python 3.13.\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.9.2\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eNew version of cibuildwheel no longer needs nor supports cpython-freethreading option.\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.9.1\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eUpdated cibuildwheel.\nSupport Python 3.15.\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.8.31\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eFixed version.\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.8.30\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eGit issue 611: Heap out-of-bounds write at compile time\nGit issue 612: count_one() size underflow through the stale required-string cache\nGit issue 613: (*SKIP) inside an atomic group, plus an equality-only scan stop\nGit issue 614: build_GROUP() does not propagate the match direction\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.8.12\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eSupport Python 3.15.\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.7.19\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eGit issue 607: SIGSEGV: NULL pointer dereference in `basic_match()` when `(?R)`/`(?0)` recursion is used inside a fuzzy-matching quantifier\nGit issue 608: SIGSEGV: out-of-bounds read in `bytes1_char_at()` with `DOTALL` + a fuzzy constraint + `(?r)` reverse-direction matching\n\u003c/code\u003e\u003c/pre\u003e\n\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/7dd71c15c4fb5c94206bed1763abd4c2bd2f1b33\"\u003e\u003ccode\u003e7dd71c1\u003c/code\u003e\u003c/a\u003e Fixed version.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/59124d62299e212931786aa74ead15388abaf376\"\u003e\u003ccode\u003e59124d6\u003c/code\u003e\u003c/a\u003e PR \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/615\"\u003e#615\u003c/a\u003e: Fix Python API error propagation in match helpers\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/25e15218bd44ca26677e3c28709e94a0ca0d9b8e\"\u003e\u003ccode\u003e25e1521\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/618\"\u003e#618\u003c/a\u003e from dynapx/fix-compiler-error-propagation\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/3ad78cfb73850c2f1178d19553fa14661f73d9cb\"\u003e\u003ccode\u003e3ad78cf\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/616\"\u003e#616\u003c/a\u003e from dynapx/fix-detach-string-error-propagation\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/f54253c332574bd5a9d96d3ec9d62b5db954dac7\"\u003e\u003ccode\u003ef54253c\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/615\"\u003e#615\u003c/a\u003e from dynapx/fix-python-api-error-propagation\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/c44224476cd6a6e53be0e458dfdcf3b81d76e426\"\u003e\u003ccode\u003ec442244\u003c/code\u003e\u003c/a\u003e Propagate scanner internal errors\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/68837e7af862250cd08fa49ff584a2bbff246e0f\"\u003e\u003ccode\u003e68837e7\u003c/code\u003e\u003c/a\u003e Propagate node stack allocation failures\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/f1df5387982d526cc9475fddcc8d1043b02ffc9a\"\u003e\u003ccode\u003ef1df538\u003c/code\u003e\u003c/a\u003e Propagate check stack allocation failures\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/d8873b119a49cde8d2613253827bf973261bb2bc\"\u003e\u003ccode\u003ed8873b1\u003c/code\u003e\u003c/a\u003e Preserve Python exceptions in input decoding\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/910784fb8039c445a68e84a261119a96031c811c\"\u003e\u003ccode\u003e910784f\u003c/code\u003e\u003c/a\u003e Propagate detach_string slicing errors\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/mrabarnett/mrab-regex/compare/2026.2.28...2026.9.10\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `requests` from 2.32.3 to 2.34.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/psf/requests/releases\"\u003erequests's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.34.2\u003c/h2\u003e\n\u003ch2\u003e2.34.2 (2026-05-14)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMoved \u003ccode\u003eheaders\u003c/code\u003e input type back to \u003ccode\u003eMapping\u003c/code\u003e to avoid invariance issues with \u003ccode\u003eMutableMapping\u003c/code\u003e and inferred dict types. Users calling \u003ccode\u003eRequest.headers.update()\u003c/code\u003e may need to narrow typing in their code. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7441\"\u003e#7441\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/psf/requests/blob/main/HISTORY.md#2342-2026-05-14\"\u003ehttps://github.com/psf/requests/blob/main/HISTORY.md#2342-2026-05-14\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.34.1\u003c/h2\u003e\n\u003ch2\u003e2.34.1 (2026-05-13)\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eBugfixes\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eWidened \u003ccode\u003ejson\u003c/code\u003e input type from \u003ccode\u003edict\u003c/code\u003e and \u003ccode\u003elist\u003c/code\u003e to \u003ccode\u003eMapping\u003c/code\u003e\nand \u003ccode\u003eSequence\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7436\"\u003e#7436\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eChanged \u003ccode\u003eheaders\u003c/code\u003e input type to MutableMapping and removed \u003ccode\u003eNone\u003c/code\u003e from\n\u003ccode\u003eRequest.headers\u003c/code\u003e typing to improve handling for users. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7431\"\u003e#7431\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eResponse.reason\u003c/code\u003e moved from \u003ccode\u003estr | None\u003c/code\u003e to \u003ccode\u003estr\u003c/code\u003e to improve handling\nfor users. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7437\"\u003e#7437\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed a bug where some bodies with custom \u003ccode\u003e__getattr__\u003c/code\u003e implementations\nweren't being properly detected as Iterables. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7433\"\u003e#7433\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/k223kim\"\u003e\u003ccode\u003e@​k223kim\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/psf/requests/pull/7433\"\u003epsf/requests#7433\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/psf/requests/blob/main/HISTORY.md#2341-2026-05-13\"\u003ehttps://github.com/psf/requests/blob/main/HISTORY.md#2341-2026-05-13\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.34.0\u003c/h2\u003e\n\u003ch2\u003e2.34.0 (2026-05-11)\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eAnnouncements\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eRequests 2.34.0 introduces inline types, replacing those provided by\ntypeshed. Public API types should be fully compatible with mypy, pyright,\nand ty. \u003cstrong\u003eWe believe types are comprehensive but if you find issues, please\nreport them to the \u003ca href=\"https://redirect.github.com/psf/requests/issues/7271\"\u003epinned tracking issue\u003c/a\u003e.\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eSpecial thanks to \u003ca href=\"https://github.com/bastimeyer\"\u003e\u003ccode\u003e@​bastimeyer\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/cthoyt\"\u003e\u003ccode\u003e@​cthoyt\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/edgarrmondragon\"\u003e\u003ccode\u003e@​edgarrmondragon\u003c/code\u003e\u003c/a\u003e, and \u003ca href=\"https://github.com/srittau\"\u003e\u003ccode\u003e@​srittau\u003c/code\u003e\u003c/a\u003e for\nhelping review and test the types ahead of the release. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7272\"\u003e#7272\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eImprovements\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eDigest Auth hashing algorithms have added \u003ccode\u003eusedforsecurity=False\u003c/code\u003e to clarify\nsecurity considerations. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7310\"\u003e#7310\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests added support for Python 3.15 based on beta1. Downstream projects\nshould be able to start testing prior to its release in October. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7422\"\u003e#7422\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests added support for Python 3.14t. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7419\"\u003e#7419\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eBugfixes\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eResponse.history\u003c/code\u003e no longer contains a reference to itself, preventing\naccidental looping when traversing the history list. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7328\"\u003e#7328\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests no longer performs greedy matching on no_proxy domains. The\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/psf/requests/blob/main/HISTORY.md\"\u003erequests's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e2.34.2 (2026-05-14)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMoved \u003ccode\u003eheaders\u003c/code\u003e input type back to \u003ccode\u003eMapping\u003c/code\u003e to avoid invariance issues\nwith \u003ccode\u003eMutableMapping\u003c/code\u003e and inferred dict types. Users calling\n\u003ccode\u003eRequest.headers.update()\u003c/code\u003e may need to narrow typing in their code. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7441\"\u003e#7441\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.34.1 (2026-05-13)\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eBugfixes\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eWidened \u003ccode\u003ejson\u003c/code\u003e input type from \u003ccode\u003edict\u003c/code\u003e and \u003ccode\u003elist\u003c/code\u003e to \u003ccode\u003eMapping\u003c/code\u003e\nand \u003ccode\u003eSequence\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7436\"\u003e#7436\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eChanged \u003ccode\u003eheaders\u003c/code\u003e input type to MutableMapping and removed \u003ccode\u003eNone\u003c/code\u003e from\n\u003ccode\u003eRequest.headers\u003c/code\u003e typing to improve handling for users. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7431\"\u003e#7431\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eResponse.reason\u003c/code\u003e moved from \u003ccode\u003estr | None\u003c/code\u003e to \u003ccode\u003estr\u003c/code\u003e to improve handling\nfor users. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7437\"\u003e#7437\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed a bug where some bodies with custom \u003ccode\u003e__getattr__\u003c/code\u003e implementations\nweren't being properly detected as Iterables. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7433\"\u003e#7433\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.34.0 (2026-05-11)\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eAnnouncements\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eRequests 2.34.0 introduces inline types, replacing those provided by\ntypeshed. Public API types should be fully compatible with mypy, pyright,\nand ty. We believe types are comprehensive but if you find issues, please\nreport them to the pinned tracking issue.\u003c/p\u003e\n\u003cp\u003eSpecial thanks to \u003ca href=\"https://github.com/bastimeyer\"\u003e\u003ccode\u003e@​bastimeyer\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/cthoyt\"\u003e\u003ccode\u003e@​cthoyt\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/edgarrmondragon\"\u003e\u003ccode\u003e@​edgarrmondragon\u003c/code\u003e\u003c/a\u003e, and \u003ca href=\"https://github.com/srittau\"\u003e\u003ccode\u003e@​srittau\u003c/code\u003e\u003c/a\u003e for\nhelping review and test the types ahead of the release. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7272\"\u003e#7272\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eImprovements\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eDigest Auth hashing algorithms have added \u003ccode\u003eusedforsecurity=False\u003c/code\u003e to clarify\nsecurity considerations. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7310\"\u003e#7310\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests added support for Python 3.15 based on beta1. Downstream projects\nshould be able to start testing prior to its release in October. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7422\"\u003e#7422\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests added support for Python 3.14t. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7419\"\u003e#7419\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eBugfixes\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eResponse.history\u003c/code\u003e no longer contains a reference to itself, preventing\naccidental looping when traversing the history list. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7328\"\u003e#7328\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests no longer performs greedy matching on no_proxy domains. The\nproxy_bypass implementation has been updated with CPython's fix from\nbpo-39057. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7427\"\u003e#7427\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests no longer incorrectly strips duplicate leading slashes in\nURI paths. This should address user issues with specific presigned\nURLs. Note the full fix requires urllib3 2.7.0+. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7315\"\u003e#7315\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/6e83187b8feb273ed4c6cdab5efd8d54901dfab3\"\u003e\u003ccode\u003e6e83187\u003c/code\u003e\u003c/a\u003e v2.34.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/84d10f0be83e8f6aeca8a05230c52216431c4d0b\"\u003e\u003ccode\u003e84d10f0\u003c/code\u003e\u003c/a\u003e Move Request.headers back to Mapping (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7441\"\u003e#7441\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/b7b549b54571d03950b16afd2d01bc6ff0348224\"\u003e\u003ccode\u003eb7b549b\u003c/code\u003e\u003c/a\u003e v2.34.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/e511bc72777a94c45d004e010c597925092e1efe\"\u003e\u003ccode\u003ee511bc7\u003c/code\u003e\u003c/a\u003e Fix mutability issues with headers input types (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7431\"\u003e#7431\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/5691f596134c2feb121e595c77a0178921fcce61\"\u003e\u003ccode\u003e5691f59\u003c/code\u003e\u003c/a\u003e Update JsonType containers to read-based collections (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7436\"\u003e#7436\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/2144213c307691710c9d665700860fc4993c3035\"\u003e\u003ccode\u003e2144213\u003c/code\u003e\u003c/a\u003e Constrain Response.reason to str (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7437\"\u003e#7437\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/6404f345e562d962abe6700a1c357ec1e7e18232\"\u003e\u003ccode\u003e6404f34\u003c/code\u003e\u003c/a\u003e Fix \u003ccode\u003eprepare_body\u003c/code\u003e stream detection for \u003ccode\u003e__getattr__\u003c/code\u003e-based file wrappers (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7\"\u003e#7\u003c/a\u003e...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/0b401c76b6e80a4eecf3c690085b2553f6e261ca\"\u003e\u003ccode\u003e0b401c7\u003c/code\u003e\u003c/a\u003e v2.34.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/86b378d3f60f828daa13ca50aa82e287ff7b66b4\"\u003e\u003ccode\u003e86b378d\u003c/code\u003e\u003c/a\u003e Align Session.get parameters with requests.get (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7429\"\u003e#7429\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/a4f9a5999bdb9bf2d6e7c8aa973b28cacb17134f\"\u003e\u003ccode\u003ea4f9a59\u003c/code\u003e\u003c/a\u003e Port bpo-39057 to Requests (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7427\"\u003e#7427\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/psf/requests/compare/v2.32.3...v2.34.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `tqdm` from 4.67.3 to 4.70.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/tqdm/tqdm/releases\"\u003etqdm's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003etqdm v4.70.1 stable\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003econtrib.concurrent\u003c/code\u003e: fix no-len iterables (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1830\"\u003e#1830\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1828\"\u003e#1828\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003etests: major overhaul (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1819\"\u003e#1819\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eupdate AI policy in PR template\u003c/li\u003e\n\u003cli\u003emisc lint \u0026amp; tidy\u003c/li\u003e\n\u003cli\u003eCI: bump workflow actions \u0026amp; pre-commit hooks\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003etqdm v4.70.0 stable\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003econtrib.concurrent\u003c/code\u003e: major improvements\n\u003cul\u003e\n\u003cli\u003esupport \u003ccode\u003eprocess_map(mp_context, max_tasks_per_child)\u003c/code\u003e, \u003ccode\u003ethread_map(thread_name_prefix)\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1265\"\u003e#1265\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix \u003ccode\u003etotal\u003c/code\u003e based on shortest iterable length (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1473\"\u003e#1473\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003euse default \u003ccode\u003emax_workers\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1543\"\u003e#1543\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1530\"\u003e#1530\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1518\"\u003e#1518\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003esupport \u003ccode\u003etimeout\u003c/code\u003e, \u003ccode\u003ebuffersize\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1576\"\u003e#1576\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eimprove ETA (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1708\"\u003e#1708\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1161\"\u003e#1161\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eupdate \u003ccode\u003eas_completed\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1709\"\u003e#1709\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1565\"\u003e#1565\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eadd \u003ccode\u003etqdm.concurrent.intepreter_map\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1777\"\u003e#1777\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003easyncio\u003c/code\u003e: support iterables with only \u003ccode\u003e__aiter__\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1714\"\u003e#1714\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1686\"\u003e#1686\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003esupport \u003ccode\u003ereset(float(\u0026quot;inf\u0026quot;))\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1783\"\u003e#1783\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1781\"\u003e#1781\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/651\"\u003e#651\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eframework: test \u0026amp; reduce wheel size (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1782\"\u003e#1782\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003etqdm v4.69.1 stable\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003econtrib.logging\u003c/code\u003e: preserve filters (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1775\"\u003e#1775\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1581\"\u003e#1581\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003erich\u003c/code\u003e: misc fixes (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1773\"\u003e#1773\u003c/a\u003e)\n\u003cul\u003e\n\u003cli\u003esupport generators (without \u003ccode\u003elen\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1391\"\u003e#1391\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix potential \u003ccode\u003eAttributeError\u003c/code\u003e on exit (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1674\"\u003e#1674\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003efix \u003ccode\u003etotal=float('inf')\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1781\"\u003e#1781\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/651\"\u003e#651\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix potential \u003ccode\u003eAttributeError\u003c/code\u003e on exit (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1778\"\u003e#1778\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1668\"\u003e#1668\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1537\"\u003e#1537\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/261\"\u003e#261\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix minor docs typos (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1780\"\u003e#1780\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1746\"\u003e#1746\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003etqdm v4.69.0 stable\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eadd \u003ccode\u003etqdm.asyncio.gather(..., return_exceptions=False)\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1776\"\u003e#1776\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1671\"\u003e#1671\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1286\"\u003e#1286\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003emisc minor framework updates\n\u003cul\u003e\n\u003cli\u003ebump workflow actions \u0026amp; pre-commit hooks\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003etqdm v4.68.4 stable\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003etrim to \u003ccode\u003encols\u003c/code\u003e even when \u003ccode\u003e'{bar}' not in bar_format\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1717\"\u003e#1717\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1767\"\u003e#1767\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1658\"\u003e#1658\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix \u003ccode\u003etqdm.write\u003c/code\u003e when \u003ccode\u003estdout=None\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1768\"\u003e#1768\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1654\"\u003e#1654\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003etqdm v4.68.3 stable\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eutils\u003c/code\u003e: delay \u003ccode\u003eos.get_terminal_size\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1763\"\u003e#1763\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1760\"\u003e#1760\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eautonotebook\u003c/code\u003e: support QtConsole, Spyder, JupyterLite (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1763\"\u003e#1763\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1628\"\u003e#1628\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1559\"\u003e#1559\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1283\"\u003e#1283\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1098\"\u003e#1098\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/512\"\u003e#512\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eminor docs updates\n\u003cul\u003e\n\u003cli\u003efix typo (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1762\"\u003e#1762\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003euse \u003ccode\u003egit-fame\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003emisc minor framework updates\n\u003cul\u003e\n\u003cli\u003efix \u0026amp; update CI build\u003c/li\u003e\n\u003cli\u003epre-commit: add docs \u0026amp; metadata generation\u003c/li\u003e\n\u003cli\u003emove \u003ccode\u003etox.ini\u003c/code\u003e -\u0026gt; \u003ccode\u003epyproject.toml\u003c/code\u003e, move \u003ccode\u003etox-gh-actions\u003c/code\u003e -\u0026gt; \u003ccode\u003etox-gh\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eadd Python 3.14, drop 3.7 support\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/9cf5a12b1f955468a17f0ba3c59092b23e4258ac\"\u003e\u003ccode\u003e9cf5a12\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1830\"\u003e#1830\u003c/a\u003e from eaubin/master\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/24b9e1e08a097f1c30f2d235b63f9eb25ba47974\"\u003e\u003ccode\u003e24b9e1e\u003c/code\u003e\u003c/a\u003e misc tidy\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/2a9e4e82ddba07c5dd6d126e23a4745b76ea49c8\"\u003e\u003ccode\u003e2a9e4e8\u003c/code\u003e\u003c/a\u003e contrib.concurrent: fix no-len iterables\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/8d6ff8de5a9066de77d0a9df3e80a022a3dcf146\"\u003e\u003ccode\u003e8d6ff8d\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1819\"\u003e#1819\u003c/a\u003e from tqdm/devel\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/bed379609c2c8300671c784c8f85a185c8cf6fb3\"\u003e\u003ccode\u003ebed3796\u003c/code\u003e\u003c/a\u003e tests: major overhaul\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/4d3d3194d5467e0701bc0f4b836a735273ef0868\"\u003e\u003ccode\u003e4d3d319\u003c/code\u003e\u003c/a\u003e AI policy\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/5dcb022b55553b60ed2131b64aa5bf1e65470df1\"\u003e\u003ccode\u003e5dcb022\u003c/code\u003e\u003c/a\u003e minor syntax update\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/309effe4244bf45427c5add7f1bcf33f98a7b421\"\u003e\u003ccode\u003e309effe\u003c/code\u003e\u003c/a\u003e tests: pre-commit coverage\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/604193aa03b5f5c0ad5f3d441951f0fbb515f1e4\"\u003e\u003ccode\u003e604193a\u003c/code\u003e\u003c/a\u003e tests: slight tidy\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/17f1cac07c89943eb0e6082875b3821205308d4f\"\u003e\u003ccode\u003e17f1cac\u003c/code\u003e\u003c/a\u003e CI: bump workflow actions\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/tqdm/tqdm/compare/v4.67.3...v4.70.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `transformers` from 5.5.3 to 5.17.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/huggingface/transformers/releases\"\u003etransformers's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eRelease 5.17.0\u003c/h2\u003e\n\u003ch1\u003eRelease v5.17.0\u003c/h1\u003e\n\u003ch2\u003eNew Model additions\u003c/h2\u003e\n\u003ch3\u003eHYV4\u003c/h3\u003e\n\n\u003cp\u003eHy4-Preview is a 780B-parameter mixture-of-experts language model that activates 49B parameters per\ntoken. Each MoE layer holds 256 routed experts plus one always-active shared expert and routes every\ntoken to 8 of them. The context window is 1M tokens.\u003c/p\u003e\n\u003cp\u003eThe architecture combines four features:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eMulti-head Latent Attention (MLA)\u003c/strong\u003e compresses keys and values into a low-rank latent\n(\u003ccode\u003ekv_lora_rank\u003c/code\u003e) that \u003ccode\u003ekv_b_proj\u003c/code\u003e expands back to one key/value per query head.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eDeepSeek Sparse Attention (DSA)\u003c/strong\u003e selects \u003ccode\u003eindex_topk\u003c/code\u003e keys per query with a lightweight indexer.\nFollowing \u003ca href=\"https://huggingface.co/papers/2603.12201\"\u003eIndexShare\u003c/a\u003e, only the layers marked \u003ccode\u003e\u0026quot;full\u0026quot;\u003c/code\u003e\nin \u003ccode\u003eindexer_types\u003c/code\u003e run an indexer; \u003ccode\u003e\u0026quot;shared\u0026quot;\u003c/code\u003e layers reuse the previous full layer's selection.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eGated MLA with learnable attention sinks\u003c/strong\u003e, where each head owns a sink logit that participates\nin the softmax and contributes no value, as in \u003ca href=\"https://github.com/huggingface/transformers/blob/HEAD/gpt_oss\"\u003eGPT-OSS\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eIndependent Hyper-Connections (iHC)\u003c/strong\u003e replace the plain residual path with \u003ccode\u003ehc_mult\u003c/code\u003e parallel\nresidual streams that are collapsed before, and redistributed after, every sublayer.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThe implementation does not execute the multi-token prediction (MTP) layers. Released checkpoints\nkeep those weights so that other runtimes can use them for speculative decoding; they are ignored\nat load time.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/hy_v4\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAdd h4 (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48473\"\u003e#48473\u003c/a\u003e) by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/transformers/pull/48473\"\u003e#48473\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eVibeVoice\u003c/h3\u003e\n\n\u003cp\u003e\u003ca href=\"https://huggingface.co/papers/2508.19205\"\u003eVibeVoice\u003c/a\u003e is a novel framework for synthesizing high-fidelity, long-form speech with multiple speakers by employing a next-token diffusion approach within a Large Language Model (LLM) structure. It's designed to capture the authentic conversational \u0026quot;vibe\u0026quot; and is particularly suited for generating audio content like podcasts and multi-participant audiobooks.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/vibevoice\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eImplement VibeVoice  (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/40546\"\u003e#40546\u003c/a\u003e) by \u003ca href=\"https://github.com/pengzhiliang\"\u003e\u003ccode\u003e@​pengzhiliang\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/transformers/pull/40546\"\u003e#40546\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eNeoMME\u003c/h3\u003e\n\u003cp\u003eNeoMME is a family of efficient 260M and 800M parameter multimodal-native multilingual foundation encoders from H Company. It processes multilingual text tokens and raw image patches in a single bidirectional Transformer encoder, without a separately pretrained vision tower or causal language model.\u003c/p\u003e\n\u003cp\u003eNeoMME-Retriever is a model fine-tuned from the NeoMME backbone for visual document retrieval with joint late-interaction and dense objectives. It takes text queries and documents (text or page screenshots) and produces multi-vector embeddings for MeanMaxSim scoring (late-interaction) and mean-pooled embeddings for cosine similarity (dense).\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/neomme\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/856157a2f3e9594954310df18fdccc31ffddebe9\"\u003e\u003ccode\u003e856157a\u003c/code\u003e\u003c/a\u003e v5.17.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/5b7dcb0d36c242d8d85920a81c564ef3a86ca6dd\"\u003e\u003ccode\u003e5b7dcb0\u003c/code\u003e\u003c/a\u003e MRoPE continued (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48594\"\u003e#48594\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/50bbcc630ed1675d15d2def3877c88d6c2630415\"\u003e\u003ccode\u003e50bbcc6\u003c/code\u003e\u003c/a\u003e [fix] Update stale expected strings in HunYuanVL integration tests (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48646\"\u003e#48646\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/e8bcd79c4c77a529bc34d6e19f7d718164b7fa6a\"\u003e\u003ccode\u003ee8bcd79\u003c/code\u003e\u003c/a\u003e [Quantizaiton]support 5/6/7 bits in AutoRound (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48481\"\u003e#48481\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/3283d5f78ed6836d39430c8190a6e0500be78698\"\u003e\u003ccode\u003e3283d5f\u003c/code\u003e\u003c/a\u003e [fix] Update stale golden values and fix expected_logits shape in FlavaForPre...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/5f47b5aad791b69dff597b903614fb2bef8b88a1\"\u003e\u003ccode\u003e5f47b5a\u003c/code\u003e\u003c/a\u003e [tests] Fix integration test golden values broken by fast image processor def...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/fc501343edfccdc840eb8594a6cafa8185c2de53\"\u003e\u003ccode\u003efc50134\u003c/code\u003e\u003c/a\u003e Add Fun-ASR-Nano model (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46180\"\u003e#46180\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/d9fe823d1cedbba33dd0aeef08f773abe971688e\"\u003e\u003ccode\u003ed9fe823\u003c/code\u003e\u003c/a\u003e Fix YOLOS device mismatch with device_map=\u0026quot;auto\u0026quot; (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46886\"\u003e#46886\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/cbc1651a032b923da7f4b44b3d0e6f68e6ba6b55\"\u003e\u003ccode\u003ecbc1651\u003c/code\u003e\u003c/a\u003e [\u003ccode\u003eGenerate\u003c/code\u003e] Avoid unconditionally downloading remote hub file (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48620\"\u003e#48620\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/bd05a4b2baf8b37b8f64c0c2c70d2628583f7c2a\"\u003e\u003ccode\u003ebd05a4b\u003c/code\u003e\u003c/a\u003e Honor \u003ccode\u003eshift_labels\u003c/code\u003e in decoder-only LLM/VLM losses (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48493\"\u003e#48493\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/huggingface/transformers/compare/v5.5.3...v5.17.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `tokenizers` from 0.22.2 to 0.23.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/huggingface/tokenizers/releases\"\u003etokenizers's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev0.23.2\u003c/h2\u003e\n\u003cp\u003eThis is the last v0 release, we are moving to v1!!\u003c/p\u003e\n\u003cp\u003eMore details coming soon 👀\u003c/p\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate daachorse from 1.0.1 to 3.0.0 by \u003ca href=\"https://github.com/musicinmybrain\"\u003e\u003ccode\u003e@​musicinmybrain\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2050\"\u003ehuggingface/tokenizers#2050\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eCi test fixes by \u003ca href=\"https://github.com/sebpop\"\u003e\u003ccode\u003e@​sebpop\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2079\"\u003ehuggingface/tokenizers#2079\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAvoid full vocab clone in get_vocab_size() by \u003ca href=\"https://github.com/eunseo9311\"\u003e\u003ccode\u003e@​eunseo9311\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2074\"\u003ehuggingface/tokenizers#2074\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: pin benchmark jobs to a larger dedicated runner by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2084\"\u003ehuggingface/tokenizers#2084\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: target benchmark runners by group, not nonexistent label by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2090\"\u003ehuggingface/tokenizers#2090\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBindings: acquire model read-lock once per call instead of per pre-token by \u003ca href=\"https://github.com/sebpop\"\u003e\u003ccode\u003e@​sebpop\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2072\"\u003ehuggingface/tokenizers#2072\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: split audit in a separate job by \u003ca href=\"https://github.com/SBrandeis\"\u003e\u003ccode\u003e@​SBrandeis\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2103\"\u003ehuggingface/tokenizers#2103\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: install libcairo on benchmark runners by \u003ca href=\"https://github.com/SBrandeis\"\u003e\u003ccode\u003e@​SBrandeis\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2100\"\u003ehuggingface/tokenizers#2100\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(ci): enable npm's trusted publisher for releases by \u003ca href=\"https://github.com/McPatate\"\u003e\u003ccode\u003e@​McPatate\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2111\"\u003ehuggingface/tokenizers#2111\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: bump pyo3 to version 0.29 by \u003ca href=\"https://github.com/SBrandeis\"\u003e\u003ccode\u003e@​SBrandeis\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2115\"\u003ehuggingface/tokenizers#2115\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eperf: add benchmarks for the \u003ccode\u003edecode\u003c/code\u003e API by \u003ca href=\"https://github.com/SBrandeis\"\u003e\u003ccode\u003e@​SBrandeis\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2099\"\u003ehuggingface/tokenizers#2099\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: cache HF test data and authenticate Hub downloads to avoid rate limits by \u003ca href=\"https://github.com/SBrandeis\"\u003e\u003ccode\u003e@​SBrandeis\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2102\"\u003ehuggingface/tokenizers#2102\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eImplementing Parity-aware BPE by \u003ca href=\"https://github.com/cimeister\"\u003e\u003ccode\u003e@​cimeister\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/1974\"\u003ehuggingface/tokenizers#1974\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eMake doc builds faster by \u003ca href=\"https://github.com/mishig25\"\u003e\u003ccode\u003e@​mishig25\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2158\"\u003ehuggingface/tokenizers#2158\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(deps-dev): bump websocket-driver from 0.7.4 to 0.7.5 in /tokenizers/examples/unstable_wasm/www by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2208\"\u003ehuggingface/tokenizers#2208\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(deps-dev): bump shell-quote from 1.8.3 to 1.10.0 in /tokenizers/examples/unstable_wasm/www by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2244\"\u003ehuggingface/tokenizers#2244\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: remove stale examples (kills 50% of dependabot traffic) by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2285\"\u003ehuggingface/tokenizers#2285\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(node): drop 8 unused devDependencies by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2286\"\u003ehuggingface/tokenizers#2286\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: pin every action to one SHA, drop stale audit suppressions by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2291\"\u003ehuggingface/tokenizers#2291\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(node): take node security alerts from 33 to 0 by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2287\"\u003ehuggingface/tokenizers#2287\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(python): pin the ruff rule set so a ruff release can't redden main by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2292\"\u003ehuggingface/tokenizers#2292\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd a ParityBpeTrainer example and list it in the trainers API docs by \u003ca href=\"https://github.com/cimeister\"\u003e\u003ccode\u003e@​cimeister\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2217\"\u003ehuggingface/tokenizers#2217\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eunseo9311\"\u003e\u003ccode\u003e@​eunseo9311\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2074\"\u003ehuggingface/tokenizers#2074\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cimeister\"\u003e\u003ccode\u003e@​cimeister\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/1974\"\u003ehuggingface/tokenizers#1974\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/huggingface/tokenizers/compare/v0.23.1...v0.23.2\"\u003ehttps://github.com/huggingface/tokenizers/compare/v0.23.1...v0.23.2\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eRelease v0.23.1\u003c/h2\u003e\n\u003ch2\u003eTL;DR\u003c/h2\u003e\n\u003cp\u003e\u003ccode\u003etokenizers 0.23.1\u003c/code\u003e is the first proper stable release in the \u003ccode\u003e0.23\u003c/code\u003e line — \u003ccode\u003e0.23.0\u003c/code\u003e only ever shipped as \u003ccode\u003erc0\u003c/code\u003e because the release pipeline itself was broken (Node side hadn't shipped multi-platform binaries since 2023, Python side was on \u003ccode\u003epyo3 0.27\u003c/code\u003e without free-threaded support). \u003ccode\u003e0.23.1\u003c/code\u003e is the version where everything actually goes out the door together: full Node multi-platform wheels for the first time in years, Python 3.14 (regular \u003cstrong\u003eand\u003c/strong\u003e free-threaded \u003ccode\u003e3.14t\u003c/code\u003e), full type hints for every Python class, and a stack of measurable perf wins on the BPE / added-vocab hot paths.\u003c/p\u003e\n\u003cp\u003eThere is no functional \u003ccode\u003e0.23.0\u003c/code\u003e published — we tag \u003ccode\u003e0.23.1\u003c/code\u003e directly so users don't accidentally pull a never-shipped version.\u003c/p\u003e\n\u003chr /\u003e\n\u003ch2\u003e🚨 Breaking changes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eDrop Python 3.9\u003c/strong\u003e (\u003ca href=\"https://redirect.github.com/huggingface/tokenizers/issues/1952\"\u003e#1952\u003c/a\u003e) — \u003ccode\u003erequires-python = \u0026quot;\u0026gt;=3.10\u0026quot;\u003c/code\u003e; 3.9 users stay on \u003ccode\u003e0.22.x\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ccode\u003eadd_tokens\u003c/code\u003e normalizes \u003ccode\u003econtent\u003c/code\u003e at insertion\u003c/strong\u003e (\u003ca href=\"https://redirect.github.com/huggingface/tokenizers/issues/1995\"\u003e#1995\u003c/a\u003e) — re-saved \u003ccode\u003etokenizer.json\u003c/code\u003e may differ in the \u003ccode\u003eadded_tokens\u003c/code\u003e block. Existing files load unchanged.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eType stubs are precise\u003c/strong\u003e (\u003ca href=\"https://redirect.github.com/huggingface/tokenizers/issues/1928\"\u003e#1928\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/issues/1997\"\u003e#1997\u003c/a\u003e) — methods that returned \u003ccode\u003eAny\u003c/code\u003e now return real types; \u003ccode\u003emypy --strict\u003c/code\u003e may surface previously-hidden errors. Stub layout also moved from \u003ccode\u003etokenizers/\u0026lt;sub\u0026gt;/__init__.pyi\u003c/code\u003e to \u003ccode\u003etokenizers/\u0026lt;sub\u0026gt;.pyi\u003c/code\u003e. This breaks the surface of some of the processors like \u003ccode\u003eRobertaProcessign\u003c/code\u003e's \u003ccode\u003e__init__\u003c/code\u003e .\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e3.14t-only\u003c/strong\u003e: setters/getters return \u003ccode\u003ePyResult\u0026lt;T\u0026gt;\u003c/code\u003e because of \u003ccode\u003eArc\u0026lt;RwLock\u0026lt;Tokenizer\u0026gt;\u0026gt;\u003c/code\u003e; a poisoned lock surfaces as \u003ccode\u003ePyException\u003c/code\u003e instead of a panic.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/tokenizers/commit/88a4498ad4ea1a9487b0a9b0ff881383fd5a06a3\"\u003e\u003ccode\u003e88a4498\u003c/code\u003e\u003c/a\u003e add lock\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/tokenizers/commit/e4ea65f27057e593656ff1335b95afe2e552b88d\"\u003e\u003ccode\u003ee4ea65f\u003c/code\u003e\u003c/a\u003e real release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/tokenizers/commit/7c5964b4afae7b710d254eacd5a9fa180ba2cfef\"\u003e\u003ccode\u003e7c5964b\u003c/code\u003e\u003c/a\u003e add lock\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/tokenizers/commit/bc405ad60991a0639f8b09b40f13f91c38e50e87\"\u003e\u003ccode\u003ebc405ad\u003c/code\u003e\u003c/a\u003e push rc0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/tokenizers/commit/d5827816baedcbf1cb5b452dea8048150b6872df\"\u003e\u003ccode\u003ed582781\u003c/code\u003e\u003c/a\u003e Add a ParityBpeTrainer example and list it in the trainers API docs (\u003ca href=\"https://redirect.github.com/huggingface/tokenizers/issues/2217\"\u003e#2217\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/tokenizers/commit/447890f84deab25794ccfdee2a877901b6893569\"\u003e\u003ccode\u003e447890f\u003c/code\u003e\u003c/a\u003e fix(python): pin the ruff rule set so a ruff release can't redden main (\u003ca href=\"https://redirect.github.com/huggingface/tokenizers/issues/2292\"\u003e#2292\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/tokenizers/commit/68b3ab7788b58408f37a3dc73eeabf2417d14c22\"\u003e\u003ccode\u003e68b3ab7\u003c/code\u003e\u003c/a\u003e chore(node): take node security alerts from 33 to 0 (\u003ca href=\"https://redirect.github.com/huggingface/tokenizers/issues/2287\"\u003e#2287\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/tokenizers/commit/74ef81f64e6d1cd4979c56d7d75f3ce21ba11992\"\u003e\u003ccode\u003e74ef81f\u003c/code\u003e\u003c/a\u003e ci: pin every action to one SHA, drop stale audit suppressions (\u003ca href=\"https://redirect.github.com/huggingface/tokenizers/issues/2291\"\u003e#2291\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/tokenizers/commit/b26727f1a92cdf727cd965fc1c467a7c77c63aae\"\u003e\u003ccode\u003eb26727f\u003c/code\u003e\u003c/a\u003e chore(node): drop 8 unused devDependencies (\u003ca href=\"https://redirect.github.com/huggingface/tokenizers/issues/2286\"\u003e#2286\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/tokenizers/commit/7c7cfd838fb79e76aaba6b0931898073a784fb2a\"\u003e\u003ccode\u003e7c7cfd8\u003c/code\u003e\u003c/a\u003e chore: remove stale examples (kills 50% of dependabot traffic) (\u003ca href=\"https://redirect.github.com/huggingface/tokenizers/issues/2285\"\u003e#2285\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/huggingface/tokenizers/compare/v0.22.2...v0.23.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `safetensors` from 0.7.0 to 0.8.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/huggingface/safetensors/releases\"\u003esafetensors's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev0.8.0\u003c/h2\u003e\n\u003ch2\u003eNews\u003c/h2\u003e\n\u003cp\u003esafetensors joins the PyTorch foundation!\u003c/p\u003e\n\n\u003cp\u003eRead more on that: \u003ca href=\"https://huggingface.co/blog/safetensors-joins-pytorch-foundation\"\u003ehttps://huggingface.co/blog/safetensors-joins-pytorch-foundation\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eWhat's changed\u003c/h2\u003e\n\u003cp\u003eSafetensors 0.8.0 brings direct to Metal loading on Apple Silicon, GIL-free serialization, broader hardware and dtype coverage, and a stronger Python API.\u003c/p\u003e\n\u003ch3\u003eBreaking\u003c/h3\u003e\n\u003cp\u003eThe \u003ccode\u003eserialize\u003c/code\u003e and \u003ccode\u003eserialize_file\u003c/code\u003e functions now release the GIL during writes, enabling true multithreaded saves from Python. Their input contract has also changed: tensor metadata is now passed via a \u003ccode\u003eTensorSpec\u003c/code\u003e class (exported from safetensors) instead of plain dicts, making API more explicit and robust to misinputs. This is a breaking change for anyone calling the low-level \u003ccode\u003eserialize\u003c/code\u003e / \u003ccode\u003eserialize_file\u003c/code\u003e API directly; the high-level wrappers (\u003ccode\u003esafetensors.torch\u003c/code\u003e, \u003ccode\u003esafetensors.numpy\u003c/code\u003e, \u003ccode\u003esafetensors.paddle\u003c/code\u003e) are updated internally and their public API is unchanged.\u003c/p\u003e\n\u003cp\u003eThe minimum supported Python version is now 3.10 (was 3.9). Python 3.9 reached end-of-life in October 2025.\u003c/p\u003e\n\u003cp\u003e\u003ccode\u003eTensorIndexer::Narrow\u003c/code\u003e now carries a \u003ccode\u003estep: NonZeroUsize\u003c/code\u003e parameter, so a slice is now \u003ccode\u003estart:stop:step\u003c/code\u003e. This is a fix as this silent error was hidden behind the \u003ccode\u003eStorage::Torch\u003c/code\u003e variant which offloaded slicing logic to torch directly.\u003c/p\u003e\n\u003ch3\u003eCI\u003c/h3\u003e\n\u003cp\u003eOn the platform side, this release adds Windows ARM64 wheel builds, riscv64 Linux wheels, and CI has been hardened with pinned GitHub Actions SHAs.\u003c/p\u003e\n\u003cp\u003eAlso dropped the anaconda CI we had as there's already an automatic tracker via conda-forge.\u003c/p\u003e\n\u003ch3\u003eNew features\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eDirect MPS load on Apple Silicon: tensors are directly loaded in an \u003ccode\u003eMTLBuffer\u003c/code\u003e and handed to the frameworks that support it (only torch atm) via DLPack, skipping needless copies.\u003c/li\u003e\n\u003cli\u003eNew \u003ccode\u003ebackend\u003c/code\u003e parameter introduced, for the addition of the \u003ccode\u003epread\u003c/code\u003e backend. We now support loading files via \u003ccode\u003epread(2)\u003c/code\u003e syscall instead of just mmap. Useful for specific archs/platforms.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eget_slice\u003c/code\u003e now handles ellipsis \u003ccode\u003e[...]\u003c/code\u003e and strided slices \u003ccode\u003e[:, ::8]\u003c/code\u003e wherever safetensors does the slicing itself (\u003ccode\u003epread\u003c/code\u003e for any framework, MPS, and \u003ccode\u003emmap\u003c/code\u003e outside torch/paddle), which silently dropped the step or rejected \u003ccode\u003e...\u003c/code\u003e before.\u003c/li\u003e\n\u003cli\u003eMUSA device support for MooreThreads GPUs.\u003c/li\u003e\n\u003cli\u003eNew dtype support includes \u003ccode\u003efloat8_e4m3fnuz\u003c/code\u003e and \u003ccode\u003efloat8_e5m2fnuz\u003c/code\u003e (AMD FNUZ FP8 formats).\u003c/li\u003e\n\u003cli\u003eThe reader is now explicitly lenient about leading whitespace in the JSON header, which keeps the door open for future page-aligned writes.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eImprovements/perf\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFile writes on macOS now use \u003ccode\u003eF_NOCACHE\u003c/code\u003e for direct I/O, yielding roughly 30% faster \u003ccode\u003esave_file\u003c/code\u003e on Apple Silicon.\u003c/li\u003e\n\u003cli\u003eThe packaging dependency has been dropped from the \u003ccode\u003e[torch]\u003c/code\u003e extra, replaced by a simple \u003ccode\u003ehasattr\u003c/code\u003e probe for efficiency.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd arm64 windows support by \u003ca href=\"https://github.com/finnagin\"\u003e\u003ccode\u003e@​finnagin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/safetensors/safetensors/pull/678\"\u003esafetensors/safetensors#678\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(backend): support musa backend for MooreThreads GPU by \u003ca href=\"https://github.com/caizhi-mt\"\u003e\u003ccode\u003e@​caizhi-mt\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/safetensors/safetensors/pull/671\"\u003esafetensors/safetensors#671\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eadd gil free serialize_file(serialize_file_threadable) by \u003ca href=\"https://github.com/TomQunChao\"\u003e\u003ccode\u003e@​TomQunChao\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/safetensors/safetensors/pull/679\"\u003esafetensors/safetensors#679\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003erefactor: remove outdated comment by \u003ca href=\"https://github.com/McPatate\"\u003e\u003ccode\u003e@​McPatate\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/safetensors/safetensors/pull/685\"\u003esafetensors/safetensors#685\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat: add direct io write fast path on macos by \u003ca href=\"https://github.com/McPatate\"\u003e\u003ccode\u003e@​McPatate\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/safetensors/safetensors/pull/687\"\u003esafetensors/safetensors#687\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: keep dropped reference to tensor moved from gpu to cpu by \u003ca href=\"https://github.com/McPatate\"\u003e\u003ccode\u003e@​McPatate\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/safetensors/safetensors/pull/689\"\u003esafetensors/safetensors#689\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat: bump torch to \u003ccode\u003e2.4\u003c/code\u003e by \u003ca href=\"https://github.com/McPatate\"\u003e\u003ccode\u003e@​McPatate\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/safetensors/safetensors/pull/710\"\u003esafetensors/safetensors#710\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eContribution guide security by \u003ca href=\"https://github.com/LysandreJik\"\u003e\u003ccode\u003e@​LysandreJik\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/safetensors/safetensors/pull/712\"\u003esafetensors/safetensors#712\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/safetensors/safetensors/blob/main/RELEASE.md\"\u003esafetensors's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e0.8.0-dev.0 → 0.8.0\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003e\nUpdate lockfiles again:\n\u003cpre lang=\"bash\"\u003e\u003ccode\u003ecargo check\ncd bindings/python \u0026amp;amp;\u0026amp;amp; uv lock\n\u0026lt;/code\u0026gt;\u0026lt;/pre\u0026gt;\n\u0026lt;p\u0026gt;Commit:\u0026lt;/p\u0026gt;\n\u0026lt;pre\u0026gt;\u0026lt;code\u0026gt;Set version to 0.8.0\n\u0026lt;/code\u0026gt;\u0026lt;/pre\u0026gt;\n\u0026lt;p\u0026gt;The Python version is not set in \u0026lt;code\u0026gt;pyproject.toml\u0026lt;/code\u0026gt; directly — maturin reads it from \u0026lt;code\u0026gt;bindings/python/Cargo.toml\u0026lt;/code\u0026gt; at build time.\u0026lt;/p\u0026gt;\n\u0026lt;h3\u0026gt;4. Create the release on GitHub\u0026lt;/h3\u0026gt;\n\u0026lt;p\u0026gt;Go to the \u0026lt;a href=\u0026quot;https://github.com/huggingface/safetensors/releases\u0026quot;\u0026gt;GitHub Releases page\u0026lt;/a\u0026gt; and draft a new release:\u0026lt;/p\u0026gt;\n\u0026lt;ul\u0026gt;\n\u0026lt;li\u0026gt;\u0026lt;strong\u0026gt;Choose the release branch\u0026lt;/strong\u0026gt; (e.g. \u0026lt;code\u0026gt;git_v0.8.0\u0026lt;/code\u0026gt;)\u0026lt;/li\u0026gt;\n\u0026lt;li\u0026gt;\u0026lt;strong\u0026gt;Create a new tag\u0026lt;/strong\u0026gt; on publish: \u0026lt;code\u0026gt;v0.8.0\u0026lt;/code\u0026gt;\u0026lt;/li\u0026gt;\n\u0026lt;li\u0026gt;\u0026lt;strong\u0026gt;Generate release notes\u0026lt;/strong\u0026gt; from the previous tag (e.g. \u0026lt;code\u0026gt;v0.7.0\u0026lt;/code\u0026gt;)\u0026lt;/li\u0026gt;\n\u0026lt;li\u0026gt;Add any notable highlights at the top of the generated notes\u0026lt;/li\u0026gt;\n\u0026lt;/ul\u0026gt;\n\u0026lt;p\u0026gt;Structure for manual notes:\u0026lt;/p\u0026gt;\n\u0026lt;pre lang=\u0026quot;markdown\u0026quot;\u0026gt;...\n\n_Description has been truncated_","html_url":"https://github.com/KASW-UI/cpu-vllm/pull/20","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/KASW-UI%2Fcpu-vllm/issues/20","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/20/packages"}},{"old_version":"3.13.5","new_version":"3.14.3","update_type":"minor","path":null,"pr_created_at":"2026-09-23T23:26:38.000Z","version_change":"3.13.5 → 3.14.3","issue":{"uuid":"5560786429","node_id":"PR_kwDOUUQI988AAAABE1thtw","number":2,"state":"closed","title":"chore(deps): Bump aiohttp from 3.13.5 to 3.14.3","user":"dependabot[bot]","labels":["dependencies","python:uv"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":"2026-09-25T22:44:18.000Z","author_association":null,"state_reason":null,"created_at":"2026-09-23T23:26:38.000Z","updated_at":"2026-09-25T22:44:22.000Z","time_to_close":170260,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps): Bump","packages":[{"name":"aiohttp","old_version":"3.13.5","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"}],"path":null,"ecosystem":"pip"},"body":"Bumps [aiohttp](https://github.com/aio-libs/aiohttp) from 3.13.5 to 3.14.3.","html_url":"https://github.com/CitrateNetwork/citrate-sdk-python/pull/2","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/CitrateNetwork%2Fcitrate-sdk-python/issues/2","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/2/packages"}},{"old_version":"3.14.1","new_version":"3.14.3","update_type":"patch","path":null,"pr_created_at":"2026-09-22T06:23:30.000Z","version_change":"3.14.1 → 3.14.3","issue":{"uuid":"5536027477","node_id":"PR_kwDONC03Hc8AAAABEiBuuw","number":4260,"state":"open","title":"build(deps): bump the python group with 85 updates","user":"dependabot[bot]","labels":["backport:skip","dependencies","python:uv","first-time-contributor"],"assignees":[],"locked":false,"comments_count":3,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-22T06:23:30.000Z","updated_at":"2026-09-22T06:33:34.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"build(deps): bump","group_name":"python","update_count":85,"packages":[{"name":"pin-pink","old_version":"4.3.0","new_version":"4.4.0","repository_url":"https://github.com/stephane-caron/pink"},{"name":"reactivex","old_version":"4.1.0","new_version":"5.1.0","repository_url":"https://github.com/ReactiveX/RxPY"},{"name":"pydantic","old_version":"2.12.5","new_version":"2.13.5","repository_url":"https://github.com/pydantic/pydantic"},{"name":"python-dotenv","old_version":"1.2.2","new_version":"1.2.3","repository_url":"https://github.com/theskumar/python-dotenv"},{"name":"packaging","old_version":"25.0","new_version":"26.3","repository_url":"https://github.com/pypa/packaging"},{"name":"filelock","old_version":"3.23.0","new_version":"3.32.6","repository_url":"https://github.com/tox-dev/py-filelock"},{"name":"plum-dispatch","old_version":"2.5.7","new_version":"2.10.1","repository_url":"https://github.com/beartype/plum"},{"name":"gitpython","old_version":"3.1.52","new_version":"3.1.62","repository_url":"https://github.com/gitpython-developers/GitPython"},{"name":"structlog","old_version":"25.5.0","new_version":"26.1.0","repository_url":"https://github.com/hynek/structlog"},{"name":"opencv-contrib-python","old_version":"4.13.0.92","new_version":"5.0.0.93","repository_url":"https://github.com/opencv/opencv-python"},{"name":"pydantic-settings","old_version":"2.12.0","new_version":"2.15.0","repository_url":"https://github.com/pydantic/pydantic-settings"},{"name":"textual","old_version":"3.7.1","new_version":"8.2.8","repository_url":"https://github.com/Textualize/textual"},{"name":"terminaltexteffects","old_version":"0.12.2","new_version":"0.15.0","repository_url":"https://github.com/ChrisBuilds/terminaltexteffects"},{"name":"typer","old_version":"0.23.1","new_version":"0.27.2","repository_url":"https://github.com/fastapi/typer"},{"name":"ipython","old_version":"8.38.0","new_version":"8.39.0","repository_url":"https://github.com/ipython/ipython"},{"name":"plotext","old_version":"5.3.2","new_version":"6.1.0","repository_url":"https://github.com/piccolomo/plotext"},{"name":"numba","old_version":"0.63.1","new_version":"0.67.0","repository_url":"https://github.com/numba/numba"},{"name":"llvmlite","old_version":"0.46.0","new_version":"0.49.0","repository_url":"https://github.com/numba/llvmlite"},{"name":"rerun-sdk","old_version":"0.32.0","new_version":"0.37.2","repository_url":"https://github.com/rerun-io/rerun"},{"name":"protobuf","old_version":"6.33.5","new_version":"7.36.1","repository_url":"https://github.com/protocolbuffers/protobuf"},{"name":"cryptography","old_version":"46.0.5","new_version":"50.0.1","repository_url":"https://github.com/pyca/cryptography"},{"name":"websocket-client","old_version":"1.9.0","new_version":"1.9.2","repository_url":"https://github.com/websocket-client/websocket-client"},{"name":"ipykernel","old_version":"7.2.0","new_version":"7.3.0","repository_url":"https://github.com/ipython/ipykernel"},{"name":"open-clip-torch","old_version":"3.2.0","new_version":"3.3.0","repository_url":"https://github.com/mlfoundations/open_clip"},{"name":"gdown","old_version":"6.0.0","new_version":"6.2.0","repository_url":"https://github.com/wkentaro/gdown"},{"name":"tensorboard","old_version":"2.20.0","new_version":"2.21.0","repository_url":"https://github.com/tensorflow/tensorboard"},{"name":"portal","old_version":"3.7.4","new_version":"3.8.1","repository_url":"https://github.com/danijar/portal"},{"name":"bosdyn-client","old_version":"5.1.4","new_version":"5.2.0","repository_url":"https://github.com/boston-dynamics/spot-sdk"},{"name":"bosdyn-api","old_version":"5.1.4","new_version":"5.2.0","repository_url":"https://github.com/boston-dynamics/spot-sdk"},{"name":"bosdyn-core","old_version":"5.1.4","new_version":"5.2.0","repository_url":"https://github.com/boston-dynamics/spot-sdk"},{"name":"pyarrow","old_version":"23.0.0","new_version":"25.0.1","repository_url":"https://github.com/apache/arrow"},{"name":"langchain-core","old_version":"1.3.3","new_version":"1.6.3","repository_url":"https://github.com/langchain-ai/langchain"},{"name":"langchain-openai","old_version":"1.1.6","new_version":"1.6.2","repository_url":"https://github.com/langchain-ai/langchain"},{"name":"langchain-huggingface","old_version":"1.2.0","new_version":"1.2.2","repository_url":"https://github.com/langchain-ai/langchain"},{"name":"langchain-ollama","old_version":"1.0.1","new_version":"1.1.0","repository_url":"https://github.com/langchain-ai/langchain"},{"name":"ollama","old_version":"0.6.1","new_version":"0.6.2","repository_url":"https://github.com/ollama/ollama-python"},{"name":"openai","old_version":"2.21.0","new_version":"3.14.0","repository_url":"https://github.com/openai/openai-python"},{"name":"sounddevice","old_version":"0.5.5","new_version":"0.5.6","repository_url":"https://github.com/spatialaudio/python-sounddevice"},{"name":"fastapi","old_version":"0.129.0","new_version":"0.141.1","repository_url":"https://github.com/fastapi/fastapi"},{"name":"python-socketio","old_version":"5.16.1","new_version":"5.17.0","repository_url":"https://github.com/sponsors/miguelgrinberg"},{"name":"python-multipart","old_version":"0.0.27","new_version":"0.0.32","repository_url":"https://github.com/Kludex/python-multipart"},{"name":"sse-starlette","old_version":"3.2.0","new_version":"3.4.11","repository_url":"https://github.com/sysid/sse-starlette"},{"name":"uvicorn","old_version":"0.40.0","new_version":"0.53.0","repository_url":"https://github.com/Kludex/uvicorn"},{"name":"soundfile","old_version":"0.13.1","new_version":"0.14.0","repository_url":"https://github.com/bastibe/python-soundfile"},{"name":"timm","old_version":"1.0.24","new_version":"1.0.29","repository_url":"https://github.com/huggingface/pytorch-image-models"},{"name":"pillow","old_version":"12.2.0","new_version":"12.3.0","repository_url":"https://github.com/python-pillow/Pillow"},{"name":"lap","old_version":"0.5.12","new_version":"0.5.13","repository_url":"https://github.com/gatagat/lap"},{"name":"transformers","old_version":"4.53.3","new_version":"5.17.0"},{"name":"moondream","old_version":"0.2.0","new_version":"2.3.0","repository_url":"https://github.com/vikhyat/moondream"},{"name":"omegaconf","old_version":"2.3.0","new_version":"2.3.1","repository_url":"https://github.com/omry/omegaconf"},{"name":"hydra-core","old_version":"1.3.2","new_version":"1.3.7","repository_url":"https://github.com/facebookresearch/hydra"},{"name":"unitree-webrtc-connect","old_version":"2.1.2","new_version":"2.2.0","repository_url":"https://github.com/legion1581/unitree_webrtc_connect"},{"name":"cyclonedds","old_version":"0.10.5","new_version":"11.0.1","repository_url":"https://github.com/eclipse-cyclonedds/cyclonedds-python"},{"name":"mcap","old_version":"1.3.1","new_version":"1.4.0","repository_url":"https://github.com/foxglove/mcap"},{"name":"piper-sdk","old_version":"0.6.1","new_version":"0.6.2","repository_url":"https://github.com/agilexrobotics/piper_sdk"},{"name":"xarm-python-sdk","old_version":"1.17.3","new_version":"1.18.4","repository_url":"https://github.com/xArm-Developer/xArm-Python-SDK"},{"name":"roboplan","old_version":"0.6.0","new_version":"0.6.1","repository_url":"https://github.com/open-planning/roboplan"},{"name":"matplotlib","old_version":"3.10.8","new_version":"3.10.9","repository_url":"https://github.com/matplotlib/matplotlib"},{"name":"cupy-cuda12x","old_version":"13.6.0","new_version":"14.2.0","repository_url":"https://github.com/cupy/cupy"},{"name":"mujoco","old_version":"3.10.0","new_version":"3.13.0","repository_url":"https://github.com/google-deepmind/mujoco"},{"name":"gtsam-extended","old_version":"4.3a1.post1","new_version":"4.3a2.post202608240418"},{"name":"aiortc","old_version":"1.14.0","new_version":"1.15.0","repository_url":"https://github.com/aiortc/aiortc"},{"name":"aiohttp","old_version":"3.14.1","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"reportlab","old_version":"4.5.0","new_version":"5.0.1"},{"name":"manifold3d","old_version":"3.5.1","new_version":"3.5.3","repository_url":"https://github.com/elalish/manifold"},{"name":"coacd","old_version":"1.0.11","new_version":"1.0.14","repository_url":"https://github.com/SarahWeiii/CoACD"},{"name":"usd-core","old_version":"26.5","new_version":"26.8","repository_url":"https://github.com/PixarAnimationStudios/OpenUSD"},{"name":"ruff","old_version":"0.14.3","new_version":"0.16.7","repository_url":"https://github.com/astral-sh/ruff"},{"name":"pytest","old_version":"8.3.5","new_version":"9.1.1","repository_url":"https://github.com/pytest-dev/pytest"},{"name":"pytest-mock","old_version":"3.15.0","new_version":"3.15.1","repository_url":"https://github.com/pytest-dev/pytest-mock"},{"name":"pytest-env","old_version":"1.1.5","new_version":"1.7.1","repository_url":"https://github.com/pytest-dev/pytest-env"},{"name":"pytest-rerunfailures","old_version":"16.4","new_version":"16.6.1","repository_url":"https://github.com/pytest-dev/pytest-rerunfailures"},{"name":"coverage","old_version":"7.13.4","new_version":"7.16.1","repository_url":"https://github.com/coveragepy/coveragepy"},{"name":"pre-commit","old_version":"4.2.0","new_version":"4.6.2","repository_url":"https://github.com/pre-commit/pre-commit"},{"name":"py-spy","old_version":"0.4.1","new_version":"0.4.2","repository_url":"https://github.com/benfred/py-spy"},{"name":"maturin","old_version":"1.13.3","new_version":"1.15.0","repository_url":"https://github.com/pyo3/maturin"},{"name":"python-lsp-server","old_version":"1.14.0","new_version":"1.15.0"},{"name":"python-lsp-ruff","old_version":"2.3.0","new_version":"2.3.4","repository_url":"https://github.com/python-lsp/python-lsp-ruff"},{"name":"playwright","old_version":"1.61.0","new_version":"1.62.0","repository_url":"https://github.com/microsoft/playwright-python"},{"name":"mypy","old_version":"1.19.0","new_version":"2.3.1","repository_url":"https://github.com/python/mypy"},{"name":"types-pyyaml","old_version":"6.0.12.20250915","new_version":"6.0.12.20260906","repository_url":"https://github.com/python/typeshed"},{"name":"types-reportlab","old_version":"4.5.0.20260509","new_version":"5.0.0.20260911","repository_url":"https://github.com/python/typeshed"},{"name":"types-requests","old_version":"2.32.4.20260107","new_version":"2.33.0.20260906","repository_url":"https://github.com/python/typeshed"},{"name":"pybind11","old_version":"3.0.4","new_version":"3.1.0","repository_url":"https://github.com/pybind/pybind11"},{"name":"optuna","old_version":"4.9.0","new_version":"5.0.0","repository_url":"https://github.com/optuna/optuna"}],"path":null,"ecosystem":"pip"},"body":"Bumps the python group with 85 updates:\n\n| Package | From | To |\n| --- | --- | --- |\n| [pin-pink](https://github.com/stephane-caron/pink) | `4.3.0` | `4.4.0` |\n| [reactivex](https://github.com/ReactiveX/RxPY) | `4.1.0` | `5.1.0` |\n| [pydantic](https://github.com/pydantic/pydantic) | `2.12.5` | `2.13.5` |\n| [python-dotenv](https://github.com/theskumar/python-dotenv) | `1.2.2` | `1.2.3` |\n| [packaging](https://github.com/pypa/packaging) | `25.0` | `26.3` |\n| [filelock](https://github.com/tox-dev/py-filelock) | `3.23.0` | `3.32.6` |\n| [plum-dispatch](https://github.com/beartype/plum) | `2.5.7` | `2.10.1` |\n| [gitpython](https://github.com/gitpython-developers/GitPython) | `3.1.52` | `3.1.62` |\n| [structlog](https://github.com/hynek/structlog) | `25.5.0` | `26.1.0` |\n| [opencv-contrib-python](https://github.com/opencv/opencv-python) | `4.13.0.92` | `5.0.0.93` |\n| [pydantic-settings](https://github.com/pydantic/pydantic-settings) | `2.12.0` | `2.15.0` |\n| [textual](https://github.com/Textualize/textual) | `3.7.1` | `8.2.8` |\n| [terminaltexteffects](https://github.com/ChrisBuilds/terminaltexteffects) | `0.12.2` | `0.15.0` |\n| [typer](https://github.com/fastapi/typer) | `0.23.1` | `0.27.2` |\n| [ipython](https://github.com/ipython/ipython) | `8.38.0` | `8.39.0` |\n| [plotext](https://github.com/piccolomo/plotext) | `5.3.2` | `6.1.0` |\n| [numba](https://github.com/numba/numba) | `0.63.1` | `0.67.0` |\n| [llvmlite](https://github.com/numba/llvmlite) | `0.46.0` | `0.49.0` |\n| [rerun-sdk](https://github.com/rerun-io/rerun) | `0.32.0` | `0.37.2` |\n| [protobuf](https://github.com/protocolbuffers/protobuf) | `6.33.5` | `7.36.1` |\n| [cryptography](https://github.com/pyca/cryptography) | `46.0.5` | `50.0.1` |\n| [websocket-client](https://github.com/websocket-client/websocket-client) | `1.9.0` | `1.9.2` |\n| [ipykernel](https://github.com/ipython/ipykernel) | `7.2.0` | `7.3.0` |\n| [open-clip-torch](https://github.com/mlfoundations/open_clip) | `3.2.0` | `3.3.0` |\n| [gdown](https://github.com/wkentaro/gdown) | `6.0.0` | `6.2.0` |\n| [tensorboard](https://github.com/tensorflow/tensorboard) | `2.20.0` | `2.21.0` |\n| [portal](https://github.com/danijar/portal) | `3.7.4` | `3.8.1` |\n| [bosdyn-client](https://github.com/boston-dynamics/spot-sdk) | `5.1.4` | `5.2.0` |\n| [bosdyn-api](https://github.com/boston-dynamics/spot-sdk) | `5.1.4` | `5.2.0` |\n| [bosdyn-core](https://github.com/boston-dynamics/spot-sdk) | `5.1.4` | `5.2.0` |\n| [pyarrow](https://github.com/apache/arrow) | `23.0.0` | `25.0.1` |\n| [langchain-core](https://github.com/langchain-ai/langchain) | `1.3.3` | `1.6.3` |\n| [langchain-openai](https://github.com/langchain-ai/langchain) | `1.1.6` | `1.6.2` |\n| [langchain-huggingface](https://github.com/langchain-ai/langchain) | `1.2.0` | `1.2.2` |\n| [langchain-ollama](https://github.com/langchain-ai/langchain) | `1.0.1` | `1.1.0` |\n| [ollama](https://github.com/ollama/ollama-python) | `0.6.1` | `0.6.2` |\n| [openai](https://github.com/openai/openai-python) | `2.21.0` | `3.14.0` |\n| [sounddevice](https://github.com/spatialaudio/python-sounddevice) | `0.5.5` | `0.5.6` |\n| [fastapi](https://github.com/fastapi/fastapi) | `0.129.0` | `0.141.1` |\n| [python-socketio](https://github.com/sponsors/miguelgrinberg) | `5.16.1` | `5.17.0` |\n| [python-multipart](https://github.com/Kludex/python-multipart) | `0.0.27` | `0.0.32` |\n| [sse-starlette](https://github.com/sysid/sse-starlette) | `3.2.0` | `3.4.11` |\n| [uvicorn](https://github.com/Kludex/uvicorn) | `0.40.0` | `0.53.0` |\n| [soundfile](https://github.com/bastibe/python-soundfile) | `0.13.1` | `0.14.0` |\n| [timm](https://github.com/huggingface/pytorch-image-models) | `1.0.24` | `1.0.29` |\n| [pillow](https://github.com/python-pillow/Pillow) | `12.2.0` | `12.3.0` |\n| [lap](https://github.com/gatagat/lap) | `0.5.12` | `0.5.13` |\n| [transformers[torch]](https://github.com/huggingface/transformers) | `4.53.3` | `5.17.0` |\n| [moondream](https://github.com/vikhyat/moondream) | `0.2.0` | `2.3.0` |\n| [omegaconf](https://github.com/omry/omegaconf) | `2.3.0` | `2.3.1` |\n| [hydra-core](https://github.com/facebookresearch/hydra) | `1.3.2` | `1.3.7` |\n| [unitree-webrtc-connect](https://github.com/legion1581/unitree_webrtc_connect) | `2.1.2` | `2.2.0` |\n| [cyclonedds](https://github.com/eclipse-cyclonedds/cyclonedds-python) | `0.10.5` | `11.0.1` |\n| [mcap](https://github.com/foxglove/mcap) | `1.3.1` | `1.4.0` |\n| [piper-sdk](https://github.com/agilexrobotics/piper_sdk) | `0.6.1` | `0.6.2` |\n| [xarm-python-sdk](https://github.com/xArm-Developer/xArm-Python-SDK) | `1.17.3` | `1.18.4` |\n| [roboplan](https://github.com/open-planning/roboplan) | `0.6.0` | `0.6.1` |\n| [matplotlib](https://github.com/matplotlib/matplotlib) | `3.10.8` | `3.10.9` |\n| [cupy-cuda12x](https://github.com/cupy/cupy) | `13.6.0` | `14.2.0` |\n| [mujoco](https://github.com/google-deepmind/mujoco) | `3.10.0` | `3.13.0` |\n| [gtsam-extended](https://gtsam.org/) | `4.3a1.post1` | `4.3a2.post202608240418` |\n| [aiortc](https://github.com/aiortc/aiortc) | `1.14.0` | `1.15.0` |\n| [aiohttp](https://github.com/aio-libs/aiohttp) | `3.14.1` | `3.14.3` |\n| [reportlab](https://www.reportlab.com/) | `4.5.0` | `5.0.1` |\n| [manifold3d](https://github.com/elalish/manifold) | `3.5.1` | `3.5.3` |\n| [coacd](https://github.com/SarahWeiii/CoACD) | `1.0.11` | `1.0.14` |\n| [usd-core](https://github.com/PixarAnimationStudios/OpenUSD) | `26.5` | `26.8` |\n| [ruff](https://github.com/astral-sh/ruff) | `0.14.3` | `0.16.7` |\n| [pytest](https://github.com/pytest-dev/pytest) | `8.3.5` | `9.1.1` |\n| [pytest-mock](https://github.com/pytest-dev/pytest-mock) | `3.15.0` | `3.15.1` |\n| [pytest-env](https://github.com/pytest-dev/pytest-env) | `1.1.5` | `1.7.1` |\n| [pytest-rerunfailures](https://github.com/pytest-dev/pytest-rerunfailures) | `16.4` | `16.6.1` |\n| [coverage](https://github.com/coveragepy/coveragepy) | `7.13.4` | `7.16.1` |\n| [pre-commit](https://github.com/pre-commit/pre-commit) | `4.2.0` | `4.6.2` |\n| [py-spy](https://github.com/benfred/py-spy) | `0.4.1` | `0.4.2` |\n| [maturin](https://github.com/pyo3/maturin) | `1.13.3` | `1.15.0` |\n| [python-lsp-server[all]](https://github.com/python-lsp/python-lsp-server) | `1.14.0` | `1.15.0` |\n| [python-lsp-ruff](https://github.com/python-lsp/python-lsp-ruff) | `2.3.0` | `2.3.4` |\n| [playwright](https://github.com/microsoft/playwright-python) | `1.61.0` | `1.62.0` |\n| [mypy](https://github.com/python/mypy) | `1.19.0` | `2.3.1` |\n| [types-pyyaml](https://github.com/python/typeshed) | `6.0.12.20250915` | `6.0.12.20260906` |\n| [types-reportlab](https://github.com/python/typeshed) | `4.5.0.20260509` | `5.0.0.20260911` |\n| [types-requests](https://github.com/python/typeshed) | `2.32.4.20260107` | `2.33.0.20260906` |\n| [pybind11](https://github.com/pybind/pybind11) | `3.0.4` | `3.1.0` |\n| [optuna](https://github.com/optuna/optuna) | `4.9.0` | `5.0.0` |\n\nUpdates `pin-pink` from 4.3.0 to 4.4.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/stephane-caron/pink/releases\"\u003epin-pink's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.4.0\u003c/h2\u003e\n\u003cp\u003eThis release allows custom boundaries in velocity limits, allowing bounds on joints that can't have a limit from their URDF model (such as continuous joints).\u003c/p\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eLimit: Allow custom boundaries in \u003ccode\u003eVelocityLimit\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003edocs: Document assumption that we start from a feasible configuration\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pink-kinematics/pink/blob/main/CHANGELOG.md\"\u003epin-pink's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e[4.4.0] - 2026-09-09\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eLimit: Allow custom boundaries in \u003ccode\u003eVelocityLimit\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003edocs: Document assumption that we start from a feasible configuration\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pink-kinematics/pink/commit/c14d0ae62f4fb744bbe84e35f9e16f1b680b20c0\"\u003e\u003ccode\u003ec14d0ae\u003c/code\u003e\u003c/a\u003e Release v4.4.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pink-kinematics/pink/commit/5c890570ee42d397f03d1cf8e1b8f4a9797bde97\"\u003e\u003ccode\u003e5c89057\u003c/code\u003e\u003c/a\u003e doc: Add context to configuration limit\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pink-kinematics/pink/commit/7df4f5a323c423b591ff3c35c7e66df40ff9c197\"\u003e\u003ccode\u003e7df4f5a\u003c/code\u003e\u003c/a\u003e Update link to CBF note\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pink-kinematics/pink/commit/bfd30c7aec222b66fb36629c20439bedb223d161\"\u003e\u003ccode\u003ebfd30c7\u003c/code\u003e\u003c/a\u003e lint: Apply pylint recos in FrameTask\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pink-kinematics/pink/commit/e71a42bd424680b039b782de1392b0b7ec2307d9\"\u003e\u003ccode\u003ee71a42b\u003c/code\u003e\u003c/a\u003e lint: Fix pylint recos in ManipulabilityTask\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pink-kinematics/pink/commit/a7ac5aa23b591fc203fbdc636d88c1a9b410375c\"\u003e\u003ccode\u003ea7ac5aa\u003c/code\u003e\u003c/a\u003e pixi: Group linting tasks, add format task\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pink-kinematics/pink/commit/771c0e0a5d80107771525321927eebb28fbc3400\"\u003e\u003ccode\u003e771c0e0\u003c/code\u003e\u003c/a\u003e lint: Fix two pylint errors\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pink-kinematics/pink/commit/f568e80536549a3b7f627468eb29526d3404c85b\"\u003e\u003ccode\u003ef568e80\u003c/code\u003e\u003c/a\u003e Update type of velocity_limit attribute\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pink-kinematics/pink/commit/232c9c0b76db644c212c1e9caa33bda345cb4dd2\"\u003e\u003ccode\u003e232c9c0\u003c/code\u003e\u003c/a\u003e minor: Removed comes before Fixed in Keep a Changelog\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pink-kinematics/pink/commit/3b60614b5f25ed8c1ed0f1fc596ec19133665035\"\u003e\u003ccode\u003e3b60614\u003c/code\u003e\u003c/a\u003e Update the changelog\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/stephane-caron/pink/compare/v4.3.0...v4.4.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `reactivex` from 4.1.0 to 5.1.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/ReactiveX/RxPY/releases\"\u003ereactivex's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev5.1.0\u003c/h2\u003e\n\u003cp\u003eSee \u003ca href=\"https://github.com/ReactiveX/RxPY/blob/master/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003ch2\u003ev5.0.0\u003c/h2\u003e\n\u003cp\u003eSee \u003ca href=\"https://github.com/ReactiveX/RxPY/blob/master/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003ch2\u003ev5.0.0rc2\u003c/h2\u003e\n\u003cp\u003eSee \u003ca href=\"https://github.com/ReactiveX/RxPY/blob/master/CHANGELOG.md\"\u003eCHANGELOG.md\u003c/a\u003e for details.\u003c/p\u003e\n\u003ch2\u003ev5.0.0a2\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix title header by \u003ca href=\"https://github.com/dbrattli\"\u003e\u003ccode\u003e@​dbrattli\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/pull/744\"\u003eReactiveX/RxPY#744\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/ReactiveX/RxPY/compare/v5.0.0a1...v5.0.0a2\"\u003ehttps://github.com/ReactiveX/RxPY/compare/v5.0.0a1...v5.0.0a2\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev5.0.0a1\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eGive run a scheduler parameter by \u003ca href=\"https://github.com/rmahfoud\"\u003e\u003ccode\u003e@​rmahfoud\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/pull/731\"\u003eReactiveX/RxPY#731\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAvoid use of asyncio.get_event_loop (3.14) by \u003ca href=\"https://github.com/traylenator\"\u003e\u003ccode\u003e@​traylenator\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/pull/728\"\u003eReactiveX/RxPY#728\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eMigrate to uv by \u003ca href=\"https://github.com/dbrattli\"\u003e\u003ccode\u003e@​dbrattli\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/pull/738\"\u003eReactiveX/RxPY#738\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eMigrate to ruff by \u003ca href=\"https://github.com/dbrattli\"\u003e\u003ccode\u003e@​dbrattli\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/pull/739\"\u003eReactiveX/RxPY#739\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpgrade pyright by \u003ca href=\"https://github.com/dbrattli\"\u003e\u003ccode\u003e@​dbrattli\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/pull/740\"\u003eReactiveX/RxPY#740\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix subscribe_on not forwarding scheduler to the source  by \u003ca href=\"https://github.com/jcafhe\"\u003e\u003ccode\u003e@​jcafhe\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/pull/726\"\u003eReactiveX/RxPY#726\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpgrade deps by \u003ca href=\"https://github.com/dbrattli\"\u003e\u003ccode\u003e@​dbrattli\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/pull/741\"\u003eReactiveX/RxPY#741\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eClarify what you can do with the .subscribe Disposable by \u003ca href=\"https://github.com/tmewett\"\u003e\u003ccode\u003e@​tmewett\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/pull/686\"\u003eReactiveX/RxPY#686\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRxPY v5 by \u003ca href=\"https://github.com/dbrattli\"\u003e\u003ccode\u003e@​dbrattli\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/pull/743\"\u003eReactiveX/RxPY#743\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/rmahfoud\"\u003e\u003ccode\u003e@​rmahfoud\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/pull/731\"\u003eReactiveX/RxPY#731\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tmewett\"\u003e\u003ccode\u003e@​tmewett\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/pull/686\"\u003eReactiveX/RxPY#686\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/ReactiveX/RxPY/compare/v4.1.0...v5.0.0a1\"\u003ehttps://github.com/ReactiveX/RxPY/compare/v4.1.0...v5.0.0a1\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/ReactiveX/RxPY/blob/master/CHANGELOG.md\"\u003ereactivex's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e5.1.0 - 2026-07-27\u003c/h2\u003e\n\u003ch3\u003e🚀 Features\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cem\u003e(operators)\u003c/em\u003e Add tap as an alias for do_action (\u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/issues/804\"\u003e#804\u003c/a\u003e) (\u003ca href=\"https://github.com/ReactiveX/RxPY/commit/95c54ac3652aed2bf78035c9846cb5867ee58172\"\u003e95c54ac3\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e🐞 Bug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cem\u003e(gtk)\u003c/em\u003e Call gi.require_version before importing gi.repository (\u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/issues/749\"\u003e#749\u003c/a\u003e) (\u003ca href=\"https://github.com/ReactiveX/RxPY/commit/2b9e3f338246acb7b0037c2a2d9b0882a980ce62\"\u003e2b9e3f33\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cem\u003e(operators)\u003c/em\u003e Accept concurrent.futures.Future wherever futures are accepted (\u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/issues/806\"\u003e#806\u003c/a\u003e) (\u003ca href=\"https://github.com/ReactiveX/RxPY/commit/19da6ac1487e97bb973fcc4dafc69cee4a1e12a7\"\u003e19da6ac1\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003cem\u003e(scheduler)\u003c/em\u003e Use wall clock time for now() in event loop schedulers (\u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/issues/809\"\u003e#809\u003c/a\u003e) (\u003ca href=\"https://github.com/ReactiveX/RxPY/commit/361951c7237ae100f33f81e89144935adb281509\"\u003e361951c7\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003c!-- raw HTML omitted --\u003e\u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://github.com/ReactiveX/RxPY/compare/10ccc0a3deba0d004a8f9b6079802ffdb73d1edd..b286407307ace6670f6f0072a8438bc912165d43\"\u003eView changes on Github\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e\u003c!-- raw HTML omitted --\u003e\u003c/p\u003e\n\u003ch2\u003e5.0.0 - 2026-07-20\u003c/h2\u003e\n\u003ch3\u003e🐞 Bug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cem\u003e(scripts)\u003c/em\u003e Keep uv.lock in sync and scope the version sed to [project] (\u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/issues/802\"\u003e#802\u003c/a\u003e) (\u003ca href=\"https://github.com/ReactiveX/RxPY/commit/10ccc0a3deba0d004a8f9b6079802ffdb73d1edd\"\u003e10ccc0a3\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003c!-- raw HTML omitted --\u003e\u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://github.com/ReactiveX/RxPY/compare/915311e3e002b933f2eb4d59c9eac1cab327ff78..10ccc0a3deba0d004a8f9b6079802ffdb73d1edd\"\u003eView changes on Github\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e\u003c!-- raw HTML omitted --\u003e\u003c/p\u003e\n\u003ch2\u003e5.0.0-rc.2 - 2026-07-20\u003c/h2\u003e\n\u003ch3\u003e🐞 Bug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cem\u003e(operators)\u003c/em\u003e Reset retry budget per subscription to fix retry+repeat (\u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/issues/765\"\u003e#765\u003c/a\u003e) (\u003ca href=\"https://github.com/ReactiveX/RxPY/commit/c3f19d5e83403f70d44331daf0b5a86d410f76d4\"\u003ec3f19d5e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003c!-- raw HTML omitted --\u003e\u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://github.com/ReactiveX/RxPY/compare/2975deb528c9eec73c76cf8bb53fc8780f31de45..915311e3e002b933f2eb4d59c9eac1cab327ff78\"\u003eView changes on Github\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e\u003c!-- raw HTML omitted --\u003e\u003c/p\u003e\n\u003ch2\u003e5.0.0-rc.1 - 2026-04-20\u003c/h2\u003e\n\u003cp\u003e\u003c!-- raw HTML omitted --\u003e\u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://github.com/ReactiveX/RxPY/compare/8b59bc7394f1b6a8a78e2fc4b5efe200d4f47f89..2975deb528c9eec73c76cf8bb53fc8780f31de45\"\u003eView changes on Github\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e\u003c!-- raw HTML omitted --\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eTyping: Added \u003ccode\u003eAction\u003c/code\u003e and \u003ccode\u003eStartableFactory\u003c/code\u003e to \u003ccode\u003ereactivex.typing.__all__\u003c/code\u003e,\nmaking them part of the explicit public API surface.\u003c/li\u003e\n\u003cli\u003eDocs: Added missing docstring to \u003ccode\u003eon_error_resume_next\u003c/code\u003e operator.\u003c/li\u003e\n\u003cli\u003eOperators: Fixed scheduler forwarding in \u003ccode\u003epairwise\u003c/code\u003e, \u003ccode\u003eto_marbles\u003c/code\u003e, and\n\u003ccode\u003edelay_with_mapper\u003c/code\u003e (subscription-delay path). These operators now pass the\n\u003ccode\u003escheduler\u003c/code\u003e argument through to \u003ccode\u003esource.subscribe(...)\u003c/code\u003e and, in the case of\n\u003ccode\u003edelay_with_mapper\u003c/code\u003e, to the subscription-delay observable, consistent with\nall other pipeable operators. Closes \u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/issues/480\"\u003e#480\u003c/a\u003e (partial — the operators listed\nin the issue that were not yet fixed).\u003c/li\u003e\n\u003cli\u003eCI: Skip \u003ccode\u003etests/test_scheduler/test_mainloop/test_tkinterscheduler.py\u003c/code\u003e on\nPyPy (all platforms). The module creates a Tk root at import time; PyPy's\n\u003ccode\u003e_tkinter\u003c/code\u003e finalizer calls \u003ccode\u003ethreading.notify_all\u003c/code\u003e during interpreter\nshutdown and aborts the xdist worker, failing whichever unrelated test\nwas running. Previously guarded only on macOS+PyPy.\u003c/li\u003e\n\u003cli\u003eFix: \u003ccode\u003ereactivex.timer(duetime, period)\u003c/code\u003e now correctly resets the initial\ndelay on each resubscription (e.g. via \u003ccode\u003erepeat()\u003c/code\u003e). Previously `nonlocal\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ReactiveX/RxPY/commit/bbfecfbf83605f2bb2beb8b887dfe5b5fb322a67\"\u003e\u003ccode\u003ebbfecfb\u003c/code\u003e\u003c/a\u003e chore: release reactivex@5.1.0 (\u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/issues/805\"\u003e#805\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ReactiveX/RxPY/commit/b286407307ace6670f6f0072a8438bc912165d43\"\u003e\u003ccode\u003eb286407\u003c/code\u003e\u003c/a\u003e docs: correct and expand the GIL free-threading note (\u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/issues/811\"\u003e#811\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ReactiveX/RxPY/commit/93a4f0417fe5d1d187dbd2d0dfdf2ef3b481c45c\"\u003e\u003ccode\u003e93a4f04\u003c/code\u003e\u003c/a\u003e docs: explain how to parallelize work within a single stream (\u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/issues/810\"\u003e#810\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ReactiveX/RxPY/commit/2271867415d4beaed62e6f0441fd3312e47079aa\"\u003e\u003ccode\u003e2271867\u003c/code\u003e\u003c/a\u003e Revise GIL section for Python 3.13 updates (\u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/issues/742\"\u003e#742\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ReactiveX/RxPY/commit/361951c7237ae100f33f81e89144935adb281509\"\u003e\u003ccode\u003e361951c\u003c/code\u003e\u003c/a\u003e fix(scheduler): use wall clock time for now() in event loop schedulers (\u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/issues/809\"\u003e#809\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ReactiveX/RxPY/commit/b809222be63e235f439f65794dd1d4291556d072\"\u003e\u003ccode\u003eb809222\u003c/code\u003e\u003c/a\u003e docs: read version from pyproject instead of git tags (\u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/issues/808\"\u003e#808\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ReactiveX/RxPY/commit/19e808000610335b4f6d0e0c739b59372b8b5a5f\"\u003e\u003ccode\u003e19e8080\u003c/code\u003e\u003c/a\u003e ci(deps): bump the github-actions group with 2 updates (\u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/issues/807\"\u003e#807\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ReactiveX/RxPY/commit/dd9b8ec0185ade72dcb3aac983cd495f21ca0a6d\"\u003e\u003ccode\u003edd9b8ec\u003c/code\u003e\u003c/a\u003e refactor(combine-latest): simplify logic by removing redundant loops … (\u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/issues/736\"\u003e#736\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ReactiveX/RxPY/commit/19da6ac1487e97bb973fcc4dafc69cee4a1e12a7\"\u003e\u003ccode\u003e19da6ac\u003c/code\u003e\u003c/a\u003e fix(operators): accept concurrent.futures.Future wherever futures are accepte...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ReactiveX/RxPY/commit/2b9e3f338246acb7b0037c2a2d9b0882a980ce62\"\u003e\u003ccode\u003e2b9e3f3\u003c/code\u003e\u003c/a\u003e fix(gtk): call gi.require_version before importing gi.repository (\u003ca href=\"https://redirect.github.com/ReactiveX/RxPY/issues/749\"\u003e#749\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/ReactiveX/RxPY/compare/v4.1.0...v5.1.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `pydantic` from 2.12.5 to 2.13.5\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pydantic/pydantic/releases\"\u003epydantic's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.13.5 (2026-08-28)\u003c/h2\u003e\n\u003ch3\u003eWhat's Changed\u003c/h3\u003e\n\u003ch4\u003eFixes\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eAllow reuse of validators when plugins are set by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13535\"\u003e#13535\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix missing GC traversal on some \u003ccode\u003epydantic-core\u003c/code\u003e struct fields by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13624\"\u003e#13624\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix missing GC traversal in \u003ccode\u003epydantic-core\u003c/code\u003e for \u003ccode\u003eGeneralFieldsSerializer\u003c/code\u003e by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13629\"\u003e#13629\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eCount validated model fields once in smart unions by \u003ca href=\"https://github.com/tamird\"\u003e\u003ccode\u003e@​tamird\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13731\"\u003e#13731\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev2.13.4 2026-05-06\u003c/h2\u003e\n\u003ch2\u003ev2.13.4 (2026-05-06)\u003c/h2\u003e\n\u003ch3\u003eWhat's Changed\u003c/h3\u003e\n\u003ch4\u003ePackaging\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eBump libc from 0.2.155 to 0.2.185 by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13109\"\u003e#13109\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdapt \u003ccode\u003epydantic-core\u003c/code\u003e linker flags on macOS by \u003ca href=\"https://github.com/washingtoneg\"\u003e\u003ccode\u003e@​washingtoneg\u003c/code\u003e\u003c/a\u003e and \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13147\"\u003e#13147\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003eFixes\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve \u003ccode\u003eRootModel\u003c/code\u003e core metadata by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13129\"\u003e#13129\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/pydantic/pydantic/compare/v2.13.3...v2.13.4\"\u003ehttps://github.com/pydantic/pydantic/compare/v2.13.3...v2.13.4\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.13.3 2026-04-20\u003c/h2\u003e\n\u003ch2\u003ev2.13.3 (2026-04-20)\u003c/h2\u003e\n\u003ch3\u003eWhat's Changed\u003c/h3\u003e\n\u003ch4\u003eFixes\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eHandle \u003ccode\u003eAttributeError\u003c/code\u003e subclasses with \u003ccode\u003efrom_attributes\u003c/code\u003e by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13096\"\u003e#13096\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/pydantic/pydantic/compare/v2.13.2...v2.13.3\"\u003ehttps://github.com/pydantic/pydantic/compare/v2.13.2...v2.13.3\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.13.2 2026-04-17\u003c/h2\u003e\n\u003ch2\u003ev2.13.2 (2026-04-17)\u003c/h2\u003e\n\u003ch3\u003eWhat's Changed\u003c/h3\u003e\n\u003ch4\u003eFixes\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eFix \u003ccode\u003eValidationInfo.field_name\u003c/code\u003e missing with \u003ccode\u003emodel_validate_json()\u003c/code\u003e by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13084\"\u003e#13084\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/pydantic/pydantic/compare/v2.13.1...v2.13.2\"\u003ehttps://github.com/pydantic/pydantic/compare/v2.13.1...v2.13.2\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.13.1 2026-04-15\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pydantic/pydantic/blob/v2.13.5/HISTORY.md\"\u003epydantic's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.13.5 (2026-08-28)\u003c/h2\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/pydantic/pydantic/releases/tag/v2.13.5\"\u003eGitHub release\u003c/a\u003e\u003c/p\u003e\n\u003ch3\u003eWhat's Changed\u003c/h3\u003e\n\u003ch4\u003eFixes\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eAllow reuse of validators when plugins are set by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13535\"\u003e#13535\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix missing GC traversal on some \u003ccode\u003epydantic-core\u003c/code\u003e struct fields by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13624\"\u003e#13624\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix missing GC traversal in \u003ccode\u003epydantic-core\u003c/code\u003e for \u003ccode\u003eGeneralFieldsSerializer\u003c/code\u003e by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13629\"\u003e#13629\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eCount validated model fields once in smart unions by \u003ca href=\"https://github.com/tamird\"\u003e\u003ccode\u003e@​tamird\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13731\"\u003e#13731\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev2.13.4 (2026-05-06)\u003c/h2\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/pydantic/pydantic/releases/tag/v2.13.4\"\u003eGitHub release\u003c/a\u003e\u003c/p\u003e\n\u003ch3\u003eWhat's Changed\u003c/h3\u003e\n\u003ch4\u003ePackaging\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eBump libc from 0.2.155 to 0.2.185 by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13109\"\u003e#13109\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdapt \u003ccode\u003epydantic-core\u003c/code\u003e linker flags on macOS by \u003ca href=\"https://github.com/washingtoneg\"\u003e\u003ccode\u003e@​washingtoneg\u003c/code\u003e\u003c/a\u003e and \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13147\"\u003e#13147\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003eFixes\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve \u003ccode\u003eRootModel\u003c/code\u003e core metadata by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13129\"\u003e#13129\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev2.13.3 (2026-04-20)\u003c/h2\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/pydantic/pydantic/releases/tag/v2.13.3\"\u003eGitHub release\u003c/a\u003e\u003c/p\u003e\n\u003ch3\u003eWhat's Changed\u003c/h3\u003e\n\u003ch4\u003eFixes\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eHandle \u003ccode\u003eAttributeError\u003c/code\u003e subclasses with \u003ccode\u003efrom_attributes\u003c/code\u003e by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13096\"\u003e#13096\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev2.13.2 (2026-04-17)\u003c/h2\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/pydantic/pydantic/releases/tag/v2.13.2\"\u003eGitHub release\u003c/a\u003e\u003c/p\u003e\n\u003ch3\u003eWhat's Changed\u003c/h3\u003e\n\u003ch4\u003eFixes\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eFix \u003ccode\u003eValidationInfo.field_name\u003c/code\u003e missing with \u003ccode\u003emodel_validate_json()\u003c/code\u003e by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13084\"\u003e#13084\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev2.13.1 (2026-04-15)\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/001dea020e0809844e5b17666432c9135a976f46\"\u003e\u003ccode\u003e001dea0\u003c/code\u003e\u003c/a\u003e Bump \u003ccode\u003epypa/gh-action-pypi-publish\u003c/code\u003e action to v1.14.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/558379fee957fad25858e33596146c72d5674843\"\u003e\u003ccode\u003e558379f\u003c/code\u003e\u003c/a\u003e Bump twine to v7.0.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/2cfd5d3d2ae721ea882c045f83b7f7a4003aab01\"\u003e\u003ccode\u003e2cfd5d3\u003c/code\u003e\u003c/a\u003e Do not check for docs build\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/a735bee5c64e1fe50785c376adaf1275e752b8ac\"\u003e\u003ccode\u003ea735bee\u003c/code\u003e\u003c/a\u003e Fix more Clippy lints\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/7eed4a16b87afaced4d0eafae230453de3410d64\"\u003e\u003ccode\u003e7eed4a1\u003c/code\u003e\u003c/a\u003e Fix Clippy 0.1.95 warnings\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/b353bbb20a4989b4c033e2be2b4a40d36178b16a\"\u003e\u003ccode\u003eb353bbb\u003c/code\u003e\u003c/a\u003e Prepare release v2.13.5\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/63d2cccd6e760da6bbc7fe81a53cb2bde3768f5e\"\u003e\u003ccode\u003e63d2ccc\u003c/code\u003e\u003c/a\u003e Count validated model fields once in smart unions\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/a53ec2ed342fda4e6aa3684399d04ea57be9a6e4\"\u003e\u003ccode\u003ea53ec2e\u003c/code\u003e\u003c/a\u003e Speed up PyPy CI tests\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/d65e0f96e890ca82f4b66a15d5b3bd65af2c661c\"\u003e\u003ccode\u003ed65e0f9\u003c/code\u003e\u003c/a\u003e Workaround circular import error in Mypy\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/47a6dbf8ad6216211bd0df6ec5c2c6c6ed905b72\"\u003e\u003ccode\u003e47a6dbf\u003c/code\u003e\u003c/a\u003e Fix missing GC traversal in \u003ccode\u003epydantic-core\u003c/code\u003e for \u003ccode\u003eGeneralFieldsSerializer\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/pydantic/pydantic/compare/v2.12.5...v2.13.5\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `python-dotenv` from 1.2.2 to 1.2.3\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/theskumar/python-dotenv/releases\"\u003epython-dotenv's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.2.3\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eStrip a leading UTF-8 BOM from \u003ccode\u003e.env\u003c/code\u003e file contents so the first variable is no longer silently lost when the file is saved with BOM (e.g. by some JetBrains IDEs on Windows) by [\u003ca href=\"https://github.com/h1whelan\"\u003e\u003ccode\u003e@​h1whelan\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/640\"\u003e#640\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eset_key\u003c/code\u003e now escapes backslashes, so values containing them (Windows paths, regular expressions) survive a write/read round-trip. Quoted values ending in an escaped backslash are no longer mis-parsed as an escaped quote, which used to swallow the following lines by [\u003ca href=\"https://github.com/dchaudhari7177\"\u003e\u003ccode\u003e@​dchaudhari7177\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/680\"\u003e#680\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003edotenv run\u003c/code\u003e now prints a friendly error instead of a traceback when no command is given by [\u003ca href=\"https://github.com/bbc2\"\u003e\u003ccode\u003e@​bbc2\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/606\"\u003e#606\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eCache the parsed result for empty \u003ccode\u003e.env\u003c/code\u003e files so repeated \u003ccode\u003edotenv_values\u003c/code\u003e/\u003ccode\u003eload_dotenv\u003c/code\u003e calls no longer re-read the file by [\u003ca href=\"https://github.com/ReinerBRO\"\u003e\u003ccode\u003e@​ReinerBRO\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/638\"\u003e#638\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/theskumar/python-dotenv/blob/main/CHANGELOG.md\"\u003epython-dotenv's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e[1.2.3] - 2026-08-16\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eStrip a leading UTF-8 BOM from \u003ccode\u003e.env\u003c/code\u003e file contents so the first variable is no longer silently lost when the file is saved with BOM (e.g. by some JetBrains IDEs on Windows) by [\u003ca href=\"https://github.com/h1whelan\"\u003e\u003ccode\u003e@​h1whelan\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/640\"\u003e#640\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eset_key\u003c/code\u003e now escapes backslashes, so values containing them (Windows paths, regular expressions) survive a write/read round-trip. Quoted values ending in an escaped backslash are no longer mis-parsed as an escaped quote, which used to swallow the following lines by [\u003ca href=\"https://github.com/dchaudhari7177\"\u003e\u003ccode\u003e@​dchaudhari7177\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/680\"\u003e#680\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003edotenv run\u003c/code\u003e now prints a friendly error instead of a traceback when no command is given by [\u003ca href=\"https://github.com/bbc2\"\u003e\u003ccode\u003e@​bbc2\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/606\"\u003e#606\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eCache the parsed result for empty \u003ccode\u003e.env\u003c/code\u003e files so repeated \u003ccode\u003edotenv_values\u003c/code\u003e/\u003ccode\u003eload_dotenv\u003c/code\u003e calls no longer re-read the file by [\u003ca href=\"https://github.com/ReinerBRO\"\u003e\u003ccode\u003e@​ReinerBRO\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/638\"\u003e#638\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/49515afee2d50c33cad9419b3800b3a0dc93fc59\"\u003e\u003ccode\u003e49515af\u003c/code\u003e\u003c/a\u003e Bump version: 1.2.2 → 1.2.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/8ac846ff2760b65470e769d7eed33e540f0934e1\"\u003e\u003ccode\u003e8ac846f\u003c/code\u003e\u003c/a\u003e chore: add release runbook (RELEASING.md) and make release target\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/bb31c944fb4b40e8dea59587f525840c38326166\"\u003e\u003ccode\u003ebb31c94\u003c/code\u003e\u003c/a\u003e docs: add 1.2.3 release notes (\u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/606\"\u003e#606\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/638\"\u003e#638\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/680\"\u003e#680\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/f7b18d9c72d1abcc2ad4023424b84f5bee30d266\"\u003e\u003ccode\u003ef7b18d9\u003c/code\u003e\u003c/a\u003e fix: round-trip backslashes through set_key (\u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/680\"\u003e#680\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/751f8c148222e58aa173c83c4e5e6cfccb2cc124\"\u003e\u003ccode\u003e751f8c1\u003c/code\u003e\u003c/a\u003e ci(deps): bump actions/checkout from 6.0.2 to 6.0.3 in the github-actions gro...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/f1937b68f338d7ebd7754da377ca08b2f0df8dbb\"\u003e\u003ccode\u003ef1937b6\u003c/code\u003e\u003c/a\u003e chore(deps): update mkdocs-include-markdown-plugin requirement from \u0026gt;=6.0.0 t...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/45b93720dd5e9e127d0be3971a04855d34e464d8\"\u003e\u003ccode\u003e45b9372\u003c/code\u003e\u003c/a\u003e chore(deps): update pytest requirement from \u0026gt;=3.9 to \u0026gt;=9.0.3 (\u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/653\"\u003e#653\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/72896e9244d2a1ff8d5e1934d3df8a35c813799a\"\u003e\u003ccode\u003e72896e9\u003c/code\u003e\u003c/a\u003e docs: fix broken mkdocs link in CONTRIBUTING.md (\u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/636\"\u003e#636\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/72754a16a4743e4c92edf87ce59ba0e4ff78758d\"\u003e\u003ccode\u003e72754a1\u003c/code\u003e\u003c/a\u003e ci(deps): bump peaceiris/actions-gh-pages from 4.0.0 to 4.1.0 in the github-a...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/078325e92558330e9addc661b789c7b6123fa73c\"\u003e\u003ccode\u003e078325e\u003c/code\u003e\u003c/a\u003e ci(security): harden CI/CD supply chain with SHA pinning and least-privilege ...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/theskumar/python-dotenv/compare/v1.2.2...v1.2.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `packaging` from 25.0 to 26.3\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pypa/packaging/releases\"\u003epackaging's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e26.3\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003ch3\u003eFeatures\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdd a public \u003ccode\u003eVersionRange\u003c/code\u003e API and \u003ccode\u003eSpecifierSet.to_range()\u003c/code\u003e, representing the versions a specifier set accepts as an interval set that supports intersection, union, difference, complement, set relations, membership tests, and filtering. \u003ccode\u003eVersionRange.to_specifier_set()\u003c/code\u003e converts a range back to a \u003ccode\u003eSpecifierSet\u003c/code\u003e where a PEP 440 form exists. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1267\"\u003e#1267\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1270\"\u003e#1270\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1298\"\u003e#1298\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ePEP 808: accept \u003ccode\u003eMetadata-Version: 2.6\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1194\"\u003e#1194\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdd a \u003ccode\u003elimit\u003c/code\u003e argument to \u003ccode\u003eparse_tag()\u003c/code\u003e for compressed tag sets. (\u003ca href=\"https://redirect.github.com/pypa/packaging/issues/1220\"\u003e#1220\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdd a \u003ccode\u003eprefer_sdist_predicate\u003c/code\u003e argument to \u003ccode\u003ePylock.select()\u003c/code\u003e to prefer source distributions over wheels for selected packages. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1334\"\u003e#1334\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003epure_python_tags()\u003c/code\u003e to generate the pure-Python tags for a Python version without touching the running platform. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1346\"\u003e#1346\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003eSpecifierSet.is_subset()\u003c/code\u003e, \u003ccode\u003eSpecifierSet.is_superset()\u003c/code\u003e, and \u003ccode\u003eSpecifierSet.is_disjoint()\u003c/code\u003e, which compare the versions two specifier sets accept. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1313\"\u003e#1313\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBehavior adaptations\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eDrop support for Python 3.8; packaging now requires Python 3.9 or later. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1157\"\u003e#1157\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ePrefer native \u003ccode\u003elinux_*\u003c/code\u003e platform tags over \u003ccode\u003emanylinux\u003c/code\u003e and \u003ccode\u003emusllinux\u003c/code\u003e tags on Linux. (\u003ca href=\"https://redirect.github.com/pypa/packaging/issues/160\"\u003e#160\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixes for versions and specifiers\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eRaise \u003ccode\u003eInvalidVersion\u003c/code\u003e instead of \u003ccode\u003eTypeError\u003c/code\u003e when \u003ccode\u003eVersion\u003c/code\u003e is given a non-string. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1319\"\u003e#1319\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRaise \u003ccode\u003eInvalidVersion\u003c/code\u003e for non-string pre-release letters passed to \u003ccode\u003eVersion.from_parts\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1241\"\u003e#1241\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix an \u003ccode\u003eAttributeError\u003c/code\u003e when hashing internally trimmed versions. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1242\"\u003e#1242\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix \u003ccode\u003eSpecifierSet.is_unsatisfiable\u003c/code\u003e for post-release boundary intersections. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1257\"\u003e#1257\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixes for requirements and markers\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eMake \u003ccode\u003eRequirement.__hash__\u003c/code\u003e consistent with \u003ccode\u003e__eq__\u003c/code\u003e for trailing-zero-equivalent specifiers (e.g. \u003ccode\u003efoo==1.0.0\u003c/code\u003e and \u003ccode\u003efoo==1.0.0.0\u003c/code\u003e), so equal requirements hash equal and deduplicate in sets and dicts. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1232\"\u003e#1232\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eNormalize requested extra names before comparing or hashing requirements. (\u003ca href=\"https://redirect.github.com/pypa/packaging/issues/644\"\u003e#644\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ePreserve a \u003ccode\u003eRequirement\u003c/code\u003e's specifier \u003ccode\u003eprereleases\u003c/code\u003e override across a pickle round trip. (\u003ca href=\"https://redirect.github.com/pypa/packaging/issues/1204\"\u003e#1204\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRaise \u003ccode\u003eInvalidRequirement\u003c/code\u003e instead of \u003ccode\u003eInvalidSpecifier\u003c/code\u003e when a requirement contains an invalid specifier. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1332\"\u003e#1332\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eClarify the error for post-release prefix wildcards like \u003ccode\u003e==1.0.post1.*\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1299\"\u003e#1299\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ePreserve quoting semantics when serializing marker values, so round-tripped markers parse back to the same marker. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1213\"\u003e#1213\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eKeep the parentheses of a nested group when serializing markers. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1316\"\u003e#1316\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eNormalize \u003ccode\u003eextra\u003c/code\u003e and \u003ccode\u003edependency_groups\u003c/code\u003e values in nested markers at parse time. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1246\"\u003e#1246\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1310\"\u003e#1310\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRaise \u003ccode\u003eUndefinedComparison\u003c/code\u003e when a set-valued variable like \u003ccode\u003eextras\u003c/code\u003e is used outside the membership form. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1265\"\u003e#1265\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRaise \u003ccode\u003eUndefinedEnvironmentName\u003c/code\u003e (a \u003ccode\u003eKeyError\u003c/code\u003e subclass) for missing environment keys during marker evaluation. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1276\"\u003e#1276\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eWrap malformed string literal errors in \u003ccode\u003eInvalidMarker\u003c/code\u003e / \u003ccode\u003eInvalidRequirement\u003c/code\u003e instead of leaking a low-level error. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1249\"\u003e#1249\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eReject requirements and markers with a trailing line break. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1345\"\u003e#1345\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixes for metadata and licenses\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eCollect all \u003ccode\u003efrom_email\u003c/code\u003e validation errors into one \u003ccode\u003eExceptionGroup\u003c/code\u003e instead of raising the first. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1268\"\u003e#1268\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAccept the UTF-8 charset case-insensitively in email payloads. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1330\"\u003e#1330\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eReject malformed \u003ccode\u003eDescription-Content-Type\u003c/code\u003e values. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1329\"\u003e#1329\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eDon't rewrite user values that contain \u003ccode\u003e{field}\u003c/code\u003e placeholders in error messages. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1327\"\u003e#1327\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRoute multipart email payloads to \u003ccode\u003eunparsed\u003c/code\u003e instead of asserting. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1247\"\u003e#1247\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eMake \u003ccode\u003eInvalidMetadata\u003c/code\u003e and \u003ccode\u003eCyclicDependencyGroup\u003c/code\u003e picklable. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1328\"\u003e#1328\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFold every line boundary \u003ccode\u003estr.splitlines\u003c/code\u003e recognizes when writing a header with \u003ccode\u003eRFC822Message\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/pypa/packaging/pull/1356\"\u003e#1356\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pypa/packaging/blob/main/CHANGELOG.rst\"\u003epackaging's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e26.3 - 2026-08-03\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003e\nFeatures:\n\u003cul\u003e\n\u003cli\u003eAdd a public :class:\u003ccode\u003e~packaging.ranges.VersionRange\u003c/code\u003e API and\u003cbr /\u003e\n:meth:\u003ccode\u003eSpecifierSet.to_range() \u0026amp;lt;packaging.specifiers.SpecifierSet.to_range\u0026amp;gt;\u003c/code\u003e,\u003cbr /\u003e\nrepresenting the versions a specifier set accepts as an interval set that\u003cbr /\u003e\nsupports intersection, union, difference, complement, set relations,\u003cbr /\u003e\nmembership tests, and filtering.\u003cbr /\u003e\n:meth:\u003ccode\u003e~packaging.ranges.VersionRange.to_specifier_set\u003c/code\u003e converts a range back\u003cbr /\u003e\nto a :class:\u003ccode\u003e~packaging.specifiers.SpecifierSet\u003c/code\u003e where a PEP 440 form exists.\u003cbr /\u003e\n(:pull:\u003ccode\u003e1267\u003c/code\u003e, :pull:\u003ccode\u003e1270\u003c/code\u003e, :pull:\u003ccode\u003e1298\u003c/code\u003e)\u003c/li\u003e\n\u003cli\u003ePEP 808: accept \u003ccode\u003eMetadata-Version: 2.6\u003c/code\u003e. (:pull:\u003ccode\u003e1194\u003c/code\u003e)\u003c/li\u003e\n\u003cli\u003eAdd a \u003ccode\u003elimit\u003c/code\u003e argument to \u003ccode\u003eparse_tag()\u003c/code\u003e for compressed tag sets.\u003cbr /\u003e\n(:issue:\u003ccode\u003e1220\u003c/code\u003e)\u003c/li\u003e\n\u003cli\u003eAdd a \u003ccode\u003eprefer_sdist_predicate\u003c/code\u003e argument to \u003ccode\u003ePylock.select()\u003c/code\u003e to prefer\u003cbr /\u003e\nsource distributions over wheels for selected packages. (:pull:\u003ccode\u003e1334\u003c/code\u003e)\u003c/li\u003e\n\u003cli\u003eAdd :func:\u003ccode\u003e~packaging.tags.pure_python_tags\u003c/code\u003e to generate the pure-Python\u003cbr /\u003e\ntags for a Python version without touching the running platform.\u003cbr /\u003e\n(:pull:\u003ccode\u003e1346\u003c/code\u003e)\u003c/li\u003e\n\u003cli\u003eAdd :meth:\u003ccode\u003eSpecifierSet.is_subset() \u0026amp;lt;packaging.specifiers.SpecifierSet.is_subset\u0026amp;gt;\u003c/code\u003e, :meth:\u003ccode\u003e~packaging.specifiers.SpecifierSet.is_superset\u003c/code\u003e,\u003cbr /\u003e\nand :meth:\u003ccode\u003e~packaging.specifiers.SpecifierSet.is_disjoint\u003c/code\u003e, which compare the\u003cbr /\u003e\nversions two specifier sets accept. (:pull:\u003ccode\u003e1313\u003c/code\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eBehavior adaptations:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eDrop support for Python 3.8; packaging now requires Python 3.9 or later.\u003cbr /\u003e\n(:pull:\u003ccode\u003e1157\u003c/code\u003e)\u003c/li\u003e\n\u003cli\u003ePrefer native \u003ccode\u003elinux_*\u003c/code\u003e platform tags over \u003ccode\u003emanylinux\u003c/code\u003e and \u003ccode\u003emusllinux\u003c/code\u003e\u003cbr /\u003e\ntags on Linux. (:issue:\u003ccode\u003e160\u003c/code\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eFixes for versions and specifiers:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eRaise \u003ccode\u003eInvalidVersion\u003c/code\u003e instead of \u003ccode\u003eTypeError\u003c/code\u003e when \u003ccode\u003eVersion\u003c/code\u003e is given a\u003cbr /\u003e\nnon-string. (:pull:\u003ccode\u003e1319\u003c/code\u003e)\u003c/li\u003e\n\u003cli\u003eRaise \u003ccode\u003eInvalidVersion\u003c/code\u003e for non-string pre-release letters passed to\u003cbr /\u003e\n\u003ccode\u003eVersion.from_parts\u003c/code\u003e. (:pull:\u003ccode\u003e1241\u003c/code\u003e)\u003c/li\u003e\n\u003cli\u003eFix an \u003ccode\u003eAttributeError\u003c/code\u003e when hashing internally trimmed versions.\u003cbr /\u003e\n(:pull:\u003ccode\u003e1242\u003c/code\u003e)\u003c/li\u003e\n\u003cli\u003eFix \u003ccode\u003eSpecifierSet.is_unsatisfiable\u003c/code\u003e for post-release boundary\u003cbr /\u003e\nintersections. (:pull:\u003ccode\u003e1257\u003c/code\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eFixes for requirements and markers:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eMake \u003ccode\u003eRequirement.__hash__\u003c/code\u003e consistent with \u003ccode\u003e__eq__\u003c/code\u003e for\u003cbr /\u003e\ntrailing-zero-equivalent specifiers (e.g. \u003ccode\u003efoo==1.0.0\u003c/code\u003e and\u003cbr /\u003e\n\u003ccode\u003efoo==1.0.0.0\u003c/code\u003e), so equal requirements hash equal and deduplicate in\u003cbr /\u003e\nsets and dicts. (:pull:\u003ccode\u003e1232\u003c/code\u003e)\u003cbr /\u003e\n\u0026lt;/tr\u0026gt;\u0026lt;/table\u0026gt;\u003cbr /\u003e\n\u003c/code\u003e\u003c/pre\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/packaging/commit/929fd4b1410ac7ef61ef3f45b2f5d7e87711a9b5\"\u003e\u003ccode\u003e929fd4b\u003c/code\u003e\u003c/a\u003e Bump for release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/packaging/commit/f300ebf0c155e1f7ea6d62fba11dba4bac3d1944\"\u003e\u003ccode\u003ef300ebf\u003c/code\u003e\u003c/a\u003e chore(deps): bump the pre-commit group with 5 updates (\u003ca href=\"https://redirect.github.com/pypa/packaging/issues/1357\"\u003e#1357\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/packaging/commit/f91d97566a966177ad7ea5a7c703b12a7273e3b1\"\u003e\u003ccode\u003ef91d975\u003c/code\u003e\u003c/a\u003e ci(downstream): bump hatchling to 1.31.0 and fix its pytest rootdir (\u003ca href=\"https://redirect.github.com/pypa/packaging/issues/1361\"\u003e#1361\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/packaging/commit/b1a7124fe3d40c3302c029e9eb01ac3fc3496a54\"\u003e\u003ccode\u003eb1a7124\u003c/code\u003e\u003c/a\u003e chore(deps): bump the github-actions group with 7 updates (\u003ca href=\"https://redirect.github.com/pypa/packaging/issues/1358\"\u003e#1358\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/packaging/commit/2d873eb6002021a8c007c933fbdab58b37a5079b\"\u003e\u003ccode\u003e2d873eb\u003c/code\u003e\u003c/a\u003e fix(metadata): fold every line boundary when writing headers (\u003ca href=\"https://redirect.github.com/pypa/packaging/issues/1356\"\u003e#1356\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/packaging/commit/413d006fadf5b9b14d78ad444201d8189bff8c64\"\u003e\u003ccode\u003e413d006\u003c/code\u003e\u003c/a\u003e docs: changelog for 26.3 (\u003ca href=\"https://redirect.github.com/pypa/packaging/issues/1343\"\u003e#1343\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/packaging/commit/4eb0753dba8fcaaac8eb75463374e448f0931558\"\u003e\u003ccode\u003e4eb0753\u003c/code\u003e\u003c/a\u003e docs(metadata): explain selective field validation (\u003ca href=\"https://redirect.github.com/pypa/packaging/issues/1342\"\u003e#1342\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/packaging/commit/77e9ed42b6db9c5c011a5148047a356ebe42692a\"\u003e\u003ccode\u003e77e9ed4\u003c/code\u003e\u003c/a\u003e feat(tags): add pure Python tag generator (\u003ca href=\"https://redirect.github.com/pypa/packaging/issues/1346\"\u003e#1346\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/packaging/commit/7cea5e88671ed14016e9ab3dd08eab064f596564\"\u003e\u003ccode\u003e7cea5e8\u003c/code\u003e\u003c/a\u003e ci: drop 3.13t on Windows (3.13.14t may fail to build, run takes 9 minutes) (...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/packaging/commit/45a8b3402db5ff82158f2d0eabaf8447aa7a50bf\"\u003e\u003ccode\u003e45a8b34\u003c/code\u003e\u003c/a\u003e docs: add missing versionadded/versionchanged directives (\u003ca href=\"https://redirect.github.com/pypa/packaging/issues/1344\"\u003e#1344\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/pypa/packaging/compare/25.0...26.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `filelock` from 3.23.0 to 3.32.6\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/tox-dev/py-filelock/releases\"\u003efilelock's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e3.32.6\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e🐛 fix(lease): reject a duration no marker can carry by \u003ca href=\"https://github.com/lprnmns\"\u003e\u003ccode\u003e@​lprnmns\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/723\"\u003etox-dev/filelock#723\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e🐛 fix(soft-rw): reject non-finite timing options by \u003ca href=\"https://github.com/lprnmns\"\u003e\u003ccode\u003e@​lprnmns\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/724\"\u003etox-dev/filelock#724\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: preserve exception notes when copying and pickling by \u003ca href=\"https://github.com/jackwalkerlabs\"\u003e\u003ccode\u003e@​jackwalkerlabs\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/729\"\u003etox-dev/filelock#729\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etest(soft-rw): reuse existing test module by \u003ca href=\"https://github.com/gaborbernat\"\u003e\u003ccode\u003e@​gaborbernat\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/730\"\u003etox-dev/filelock#730\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: respect ACL write access when the owner write bit is absent by \u003ca href=\"https://github.com/jackwalkerlabs\"\u003e\u003ccode\u003e@​jackwalkerlabs\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/728\"\u003etox-dev/filelock#728\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix SoftReadWriteLock state lock timeout by \u003ca href=\"https://github.com/Sohel2309\"\u003e\u003ccode\u003e@​Sohel2309\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/726\"\u003etox-dev/filelock#726\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jackwalkerlabs\"\u003e\u003ccode\u003e@​jackwalkerlabs\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/729\"\u003etox-dev/filelock#729\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Sohel2309\"\u003e\u003ccode\u003e@​Sohel2309\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/726\"\u003etox-dev/filelock#726\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/tox-dev/filelock/compare/3.32.5...3.32.6\"\u003ehttps://github.com/tox-dev/filelock/compare/3.32.5...3.32.6\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003e3.32.5\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e🧪 test(fork): report where a stalled fork stops by \u003ca href=\"https://github.com/gaborbernat\"\u003e\u003ccode\u003e@​gaborbernat\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/715\"\u003etox-dev/filelock#715\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e📝 docs: say that mode is read-only in the thread-local section by \u003ca href=\"https://github.com/Gares95\"\u003e\u003ccode\u003e@​Gares95\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/716\"\u003etox-dev/filelock#716\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e🐛 fix(lease): clear token after failed acquire by \u003ca href=\"https://github.com/lprnmns\"\u003e\u003ccode\u003e@​lprnmns\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/721\"\u003etox-dev/filelock#721\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/lprnmns\"\u003e\u003ccode\u003e@​lprnmns\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/721\"\u003etox-dev/filelock#721\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/tox-dev/filelock/compare/3.32.4...3.32.5\"\u003ehttps://github.com/tox-dev/filelock/compare/3.32.4...3.32.5\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003e3.32.4\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e🐛 fix: retry transient denials on open and claim read by \u003ca href=\"https://github.com/gaborbernat\"\u003e\u003ccode\u003e@​gaborbernat\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/705\"\u003etox-dev/filelock#705\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e🧪 test: deflake six scheduled-run failures by \u003ca href=\"https://github.com/gaborbernat\"\u003e\u003ccode\u003e@​gaborbernat\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/704\"\u003etox-dev/filelock#704\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e🧪 test: cover a reclaimed private record for real by \u003ca href=\"https://github.com/gaborbernat\"\u003e\u003ccode\u003e@​gaborbernat\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/706\"\u003etox-dev/filelock#706\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e🧪 test(fork): fork once the event loop has closed by \u003ca href=\"https://github.com/gaborbernat\"\u003e\u003ccode\u003e@​gaborbernat\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/714\"\u003etox-dev/filelock#714\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e🔧 chore: batch dependency updates weekly on Tuesday by \u003ca href=\"https://github.com/gaborbernat\"\u003e\u003ccode\u003e@​gaborbernat\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/713\"\u003etox-dev/filelock#713\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eescape the hostname every marker publishes by \u003ca href=\"https://github.com/dxbjavid\"\u003e\u003ccode\u003e@​dxbjavid\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/709\"\u003etox-dev/filelock#709\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/tox-dev/filelock/compare/3.32.3...3.32.4\"\u003ehttps://github.com/tox-dev/filelock/compare/3.32.3...3.32.4\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003e3.32.3\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e🧪 test(strict): deflake close-fault injections on graalpy by \u003ca href=\"https://github.com/gaborbernat\"\u003e\u003ccode\u003e@​gaborbernat\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/697\"\u003etox-dev/filelock#697\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e📄 docs: publish llms.txt from the docs build by \u003ca href=\"https://github.com/gaborbernat\"\u003e\u003ccode\u003e@​gaborbernat\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/tox-dev/filelock/pull/700\"\u003etox-dev/filelock#700\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/tox-dev/filelock/blob/main/docs/changelog.rst\"\u003efilelock's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e###########\nChangelog\n###########\u003c/p\u003e\n\u003cp\u003e.. towncrier-draft-entries:: Unreleased\u003c/p\u003e\n\u003cp\u003e.. towncrier release notes start\u003c/p\u003e\n\u003chr /\u003e\n\u003cp\u003e4.0.1 (2026-09-19)\u003c/p\u003e\n\u003chr /\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003epoll_interval\u003c/code\u003e is now validated at construction, on the setter, and on \u003ccode\u003eacquire()\u003c/code\u003e: a negative, non-finite, or\nnon-numeric value raises :class:\u003ccode\u003eValueError\u003c/code\u003e/:class:\u003ccode\u003eTypeError\u003c/code\u003e immediately instead of failing inside \u003ccode\u003etime.sleep\u003c/code\u003e. :pr:\u003ccode\u003e739\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr /\u003e\n\u003cp\u003e4.0.0 (2026-09-17)\u003c/p\u003e\n\u003chr /\u003e\n\u003cul\u003e\n\u003cli\u003eThe :class:\u003ccode\u003e~filelock.SoftReadWriteLock\u003c/code\u003e on-disk protocol is a generation log under \u003ccode\u003e\u0026lt;path\u0026gt;.rw\u003c/code\u003e, and a process\nrunning an earlier release does not see it: an old and a new participant on one lock path do not exclude each\nother. Stop every participant, upgrade them all, then restart them; the new code ignores leftover \u003ccode\u003e.state\u003c/code\u003e,\n\u003ccode\u003e.write\u003c/code\u003e and \u003ccode\u003e.readers/\u003c/code\u003e files, and you can delete them. The filesystem must provide no-replace hard links, as\nit must for :class:\u003ccode\u003e~filelock.StrictSoftFileLock\u003c/code\u003e, so a runtime without \u003ccode\u003eos.link\u003c/code\u003e raises\n:class:\u003ccode\u003e~filelock.SoftFileLockProtocolError\u003c/code\u003e on acquire. Constructing a singleton again with a different\n\u003ccode\u003eon_compromise\u003c/code\u003e, or with \u003ccode\u003epoll_interval\u003c/code\u003e at or above \u003ccode\u003estale_threshold\u003c/code\u003e, now raises :class:\u003ccode\u003eValueError\u003c/code\u003e. :pr:\u003ccode\u003e735\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e:class:\u003ccode\u003e~filelock.SoftReadWriteLock\u003c/code\u003e exposes :attr:\u003ccode\u003e~filelock.SoftReadWriteLock.generation\u003c/code\u003e as a fencing token for\nthe protected resource and reports a lost hold through \u003ccode\u003eon_compromise\u003c/code\u003e and\n:attr:\u003ccode\u003e~filelock.SoftReadWriteLock.compromise\u003c/code\u003e. :pr:\u003ccode\u003e735\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e:class:\u003ccode\u003e~filelock.SoftReadWriteLock\u003c/code\u003e no longer deadlocks when a holder dies on another host mid-transition, and\n\u003ccode\u003erelease()\u003c/code\u003e no longer waits on a mutex a dead host left behind (:pr:\u003ccode\u003e725\u003c/code\u003e, :pr:\u003ccode\u003e735\u003c/code\u003e). The state mutex is gone.\nEach transition is one atomic snapshot commit, and liveness is a heartbeat nonce read on the observer's own clock\nrather than an \u003ccode\u003emtime\u003c/code\u003e read against another host's. :pr:\u003ccode\u003e735\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr /\u003e\n\u003cp\u003e3.32.7 (2026-09-16)\u003c/p\u003e\n\u003chr /\u003e\n\u003cul\u003e\n\u003cli\u003eValidate final-symlink refusal by error number so the test works across libc implementations. :pr:\u003ccode\u003e737\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eDocument that :meth:\u003ccode\u003e~filelock.BaseFileLock.acquire\u003c/code\u003e reads \u003ccode\u003eblocking=None\u003c/code\u003e as the lock's \u003ccode\u003eblocking\u003c/code\u003e attribute and\nraises :class:\u003ccode\u003e~filelock.Timeout\u003c/code\u003e after one attempt when \u003ccode\u003eblocking=False\u003c/code\u003e. :pr:\u003ccode\u003e733\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr /\u003e\n\u003cp\u003e3.32.6 (2026-09-08)\u003c/p\u003e\n\u003chr /\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eSoftFileLease\u003c/code\u003e and \u003ccode\u003eAsyncSoftFileLease\u003c/code\u003e now reject a boolean or non-finite \u003ccode\u003elease_duration\u003c/code\u003e, which used to\npublish an owner record their own \u003ccode\u003eowner\u003c/code\u003e property reads back as malformed. :pr:\u003ccode\u003e723\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eReject non-finite heartbeat, stale, and polling intervals in \u003ccode\u003eSoftReadWriteLock\u003c/code\u003e and \u003ccode\u003eAsyncSoftReadWriteLock\u003c/code\u003e,\nincluding cached singleton construction and overflow in the default stale threshold. :pr:\u003ccode\u003e724\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tox-dev/filelock/commit/4efd93e0482e8095a0b6949fb337206e7f67495d\"\u003e\u003ccode\u003e4efd93e\u003c/code\u003e\u003c/a\u003e Release 3.32.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tox-dev/filelock/commit/7b7b7a8b9b10acf826cca246441297468039b0c1\"\u003e\u003ccode\u003e7b7b7a8\u003c/code\u003e\u003c/a\u003e Fix SoftReadWriteLock state lock timeout (\u003ca href=\"https://redirect.github.com/tox-dev/py-filelock/issues/726\"\u003e#726\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tox-dev/filelock/commit/f2f7b8696426c518b6828ea10e755c0ba2a4ffe2\"\u003e\u003ccode\u003ef2f7b86\u003c/code\u003e\u003c/a\u003e fix: respect ACL write access when the owner write bit is absent (\u003ca href=\"https://redirect.github.com/tox-dev/py-filelock/issues/728\"\u003e#728\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tox-dev/filelock/commit/e947a694fb0da6676c4861c8bfef3650e5656153\"\u003e\u003ccode\u003ee947a69\u003c/code\u003e\u003c/a\u003e test(soft-rw): reuse existing test module (\u003ca href=\"https://redirect.github.com/tox-dev/py-filelock/issues/730\"\u003e#730\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tox-dev/filelock/commit/da3ae2bca0035fb9e5269257e6f393360866cf88\"\u003e\u003ccode\u003eda3ae2b\u003c/code\u003e\u003c/a\u003e fix: preserve exception notes when copying and pickling (\u003ca href=\"https://redirect.github.com/tox-dev/py-filelock/issues/729\"\u003e#729\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tox-dev/filelock/commit/ae9cb5b2d66d6a79edd76b292fa7320c11468812\"\u003e\u003ccode\u003eae9cb5b\u003c/code\u003e\u003c/a\u003e 🐛 fix(soft-rw): reject non-finite timing options (\u003ca href=\"https://redirect.github.com/tox-dev/py-filelock/issues/724\"\u003e#724\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tox-dev/filelock/commit/d00f9bbd709fbe92a99a38cb1e32b6690813e5a8\"\u003e\u003ccode\u003ed00f9bb\u003c/code\u003e\u003c/a\u003e [pre-commit.ci] pre-commit autoupdate (\u003ca href=\"https://redirect.github.com/tox-dev/py-filelock/issues/727\"\u003e#727\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tox-dev/filelock/commit/82f66d7b0aaa83755f8d71d0b0da88408b58ec4a\"\u003e\u003ccode\u003e82f66d7\u003c/code\u003e\u003c/a\u003e 🐛 fix(lease): reject a duration no marker can carry (\u003ca href=\"https://redirect.github.com/tox-dev/py-filelock/issues/723\"\u003e#723\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tox-dev/filelock/commit/1d9e9e7e43a1089c57d7c6f20d6a2268235a4745\"\u003e\u003ccode\u003e1d9e9e7\u003c/code\u003e\u003c/a\u003e [pre-commit.ci] pre-commit autoupdate (\u003ca href=\"https://redirect.github.com/tox-dev/py-filelock/issues/722\"\u003e#722\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tox-dev/filelock/commit/1585dfef9355a5c77d4a9498cc34d3a98056fdb9\"\u003e\u003ccode\u003e1585dfe\u003c/code\u003e\u003c/a\u003e Release 3.32.5\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/tox-dev/py-filelock/compare/3.23.0...3.32.6\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `plum-dispatch` from 2.5.7 to 2.10.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/beartype/plum/releases\"\u003eplum-dispatch's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.10.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eOptimise \u003ccode\u003e_wrap_type_hint\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/310\"\u003e#310\u003c/a\u003e by \u003ca href=\"https://github.com/nstarman\"\u003e\u003ccode\u003e@​nstarman\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eBuild macOS arm64 mypyc wheels (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/320\"\u003e#320\u003c/a\u003e by \u003ca href=\"https://github.com/nstarman\"\u003e\u003ccode\u003e@​nstarman\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFix \u003ca href=\"https://redirect.github.com/beartype/plum/issues/317\"\u003e#317\u003c/a\u003e and \u003ca href=\"https://redirect.github.com/beartype/plum/issues/318\"\u003e#318\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/319\"\u003e#319\u003c/a\u003e by \u003ca href=\"https://github.com/nstarman\"\u003e\u003ccode\u003e@​nstarman\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev2.10.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eCompile more things with \u003ccode\u003emypyc\u003c/code\u003e for faster dispatch (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/287\"\u003e#287\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/beartype/plum/issues/288\"\u003e#288\u003c/a\u003e, and \u003ca href=\"https://redirect.github.com/beartype/plum/issues/289\"\u003e#289\u003c/a\u003e by \u003ca href=\"https://github.com/nstarman\"\u003e\u003ccode\u003e@​nstarman\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eMake concurrent dispatch resolution thread safe (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/281\"\u003e#281\u003c/a\u003e by \u003ca href=\"https://github.com/nstarman\"\u003e\u003ccode\u003e@​nstarman\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFix support for \u003ccode\u003ebeartype\u0026gt;=0.23\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/296\"\u003e#296\u003c/a\u003e by \u003ca href=\"https://github.com/nstarman\"\u003e\u003ccode\u003e@​nstarman\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eImprove typing (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/268\"\u003e#268\u003c/a\u003e by \u003ca href=\"https://github.com/nstarman\"\u003e\u003ccode\u003e@​nstarman\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eRemove \u003ccode\u003eVal\u003c/code\u003e, which was deprecated in v0.5.0 in favour of \u003ccode\u003etyping.Literal\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/269\"\u003e#269\u003c/a\u003e by \u003ca href=\"https://github.com/nstarman\"\u003e\u003ccode\u003e@​nstarman\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev2.9.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSupport union aliases in Python 3.14 and later (\u003ca href=\"https://github.com/nstarman\"\u003e\u003ccode\u003e@​nstarman\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev2.8.0\u003c/h2\u003e\n\u003cp\u003eStarting this release, Plum will be available on PyPI as both \u003ccode\u003eplum-dispatch\u003c/code\u003e and \u003ccode\u003eplum\u003c/code\u003e.\u003c/p\u003e\n\u003ch2\u003ev2.7.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd \u003ccode\u003efaithful\u003c/code\u003e keyword to \u003ccode\u003eModuleType\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev2.7.0\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eNote:\u003c/strong\u003e All imports should now go through \u003ccode\u003eplum\u003c/code\u003e directly! That is, not \u003ccode\u003eplum.signature.Signature\u003c/code\u003e, but \u003ccode\u003eplum.Signature\u003c/code\u003e. Please do open an issue if this release breaks something that shouldn't break.\u003c/p\u003e\n\u003cp\u003eChanges:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eSignificantly improve typing of the internals (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/179\"\u003e#179\u003c/a\u003e and \u003ca href=\"https://redirect.github.com/beartype/plum/issues/242\"\u003e#242\u003c/a\u003e by \u003ca href=\"https://github.com/nstarman\"\u003e\u003ccode\u003e@​nstarman\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eSwitch to \u003ccode\u003euv\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/218\"\u003e#218\u003c/a\u003e by \u003ca href=\"https://github.com/nstarman\"\u003e\u003ccode\u003e@​nstarman\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eMake modules private for public/private separation (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/241\"\u003e#241\u003c/a\u003e by \u003ca href=\"https://github.com/nstarman\"\u003e\u003ccode\u003e@​nstarman\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eSwitch to \u003ccode\u003esrc\u003c/code\u003e layout (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/249\"\u003e#249\u003c/a\u003e by \u003ca href=\"https://github.com/nstarman\"\u003e\u003ccode\u003e@​nstarman\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eImprove config (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/248\"\u003e#248\u003c/a\u003e by \u003ca href=\"https://github.com/nstarman\"\u003e\u003ccode\u003e@​nstarman\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eEnable \u003ccode\u003emypyc\u003c/code\u003e builds for better performance (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/247\"\u003e#247\u003c/a\u003e by \u003ca href=\"https://github.com/nstarman\"\u003e\u003ccode\u003e@​nstarman\u003c/code\u003e\u003c/a\u003e)!\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev2.6.1\u003c/h2\u003e\n\u003cp\u003eThis release features numerous very helpful contributions and improvements by \u003ca href=\"https://github.com/nstarman\"\u003e\u003ccode\u003e@​nstarman\u003c/code\u003e\u003c/a\u003e!\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUse dependency groups (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/195\"\u003e#195\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eTreat \u003ccode\u003etyping_extensions\u003c/code\u003e as standard library and make more use of it (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/226\"\u003e#226\u003c/a\u003e and \u003ca href=\"https://redirect.github.com/beartype/plum/issues/232\"\u003e#232\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eComplete deprecation cycles (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/230\"\u003e#230\u003c/a\u003e and \u003ca href=\"https://redirect.github.com/beartype/plum/issues/236\"\u003e#236\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eTurn various arguments into positional-only (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/229\"\u003e#229\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eRemove unnecessary path manipulation (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/233\"\u003e#233\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eRework tests with a \u003ccode\u003edispatch\u003c/code\u003e fixture (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/234\"\u003e#234\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eAvoid using a deprecated NumPy module (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/231\"\u003e#231\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eDrops support for Python 3.9 (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/228\"\u003e#228\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eImport exports from \u003ccode\u003emethods.py\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/237\"\u003e#237\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixes an incorrect \u003ccode\u003eoverload\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/238\"\u003e#238\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eUse \u003ccode\u003enox\u003c/code\u003e for testing (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/235\"\u003e#235\u003c/a\u003e and \u003ca href=\"https://redirect.github.com/beartype/plum/issues/240\"\u003e#240\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/beartype/plum/issues/228\"\u003e#228\u003c/a\u003e also fixes an important bug to do with the handling of unions (CC \u003ca href=\"https://github.com/davidwyld\"\u003e\u003ccode\u003e@​davidwyld\u003c/code\u003e\u003c/a\u003e).\u003c/p\u003e\n\u003ch2\u003ev2.6.0\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/beartype/plum/commit/c835c8cf5ebea4f00ee304a647e026739034e63b\"\u003e\u003ccode\u003ec835c8c\u003c/code\u003e\u003c/a\u003e fix(mypyc): keep \u003ccode\u003eFunction\u003c/code\u003e weak-referenceable on the compiled wheels (\u003ca href=\"https://redirect.github.com/beartype/plum/issues/319\"\u003e#319\u003c...\n\n_Description has been truncated_","html_url":"https://github.com/dimensionalOS/dimos/pull/4260","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/dimensionalOS%2Fdimos/issues/4260","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/4260/packages"}},{"old_version":"3.13.3","new_version":"3.14.3","update_type":"minor","path":null,"pr_created_at":"2026-09-22T01:41:11.000Z","version_change":"3.13.3 → 3.14.3","issue":{"uuid":"5534319114","node_id":"PR_kwDOS8i2VM8AAAABEgrTaA","number":119,"state":"open","title":"Bump the minor-update group with 191 updates","user":"dependabot[bot]","labels":["dependencies"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-22T01:41:11.000Z","updated_at":"2026-09-22T01:41:25.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","group_name":"minor-update","update_count":191,"packages":[{"name":"regex","old_version":"2026.2.28","new_version":"2026.9.10","repository_url":"https://github.com/mrabarnett/mrab-regex"},{"name":"requests","old_version":"2.32.3","new_version":"2.34.2","repository_url":"https://github.com/psf/requests"},{"name":"tqdm","old_version":"4.67.3","new_version":"4.70.1","repository_url":"https://github.com/tqdm/tqdm"},{"name":"transformers","old_version":"5.15.0","new_version":"5.17.0","repository_url":"https://github.com/huggingface/transformers"},{"name":"huggingface-hub","old_version":"1.28.0","new_version":"1.32.0","repository_url":"https://github.com/huggingface/huggingface_hub"},{"name":"tokenizers","old_version":"0.22.2","new_version":"0.23.2","repository_url":"https://github.com/huggingface/tokenizers"},{"name":"fastapi","old_version":"0.136.3","new_version":"0.141.1","repository_url":"https://github.com/fastapi/fastapi"},{"name":"starlette","old_version":"1.3.1","new_version":"1.6.0","repository_url":"https://github.com/Kludex/starlette"},{"name":"aiohttp","old_version":"3.13.3","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"pydantic","old_version":"2.12.0","new_version":"2.13.5","repository_url":"https://github.com/pydantic/pydantic"},{"name":"prometheus-client","old_version":"0.22.0","new_version":"0.26.0","repository_url":"https://github.com/prometheus/client_python"},{"name":"prometheus-fastapi-instrumentator","old_version":"8.0.2","new_version":"8.1.0","repository_url":"https://github.com/trallnag/prometheus-fastapi-instrumentator"},{"name":"tiktoken","old_version":"0.12.0","new_version":"0.14.0","repository_url":"https://github.com/openai/tiktoken"},{"name":"lark","old_version":"1.2.2","new_version":"1.3.1","repository_url":"https://github.com/lark-parser/lark"},{"name":"typing-extensions","old_version":"4.15.0","new_version":"4.16.0","repository_url":"https://github.com/python/typing_extensions"},{"name":"jsonschema","old_version":"4.23.0","new_version":"4.26.0","repository_url":"https://github.com/python-jsonschema/jsonschema"},{"name":"pyzmq","old_version":"27.1.0","new_version":"27.2.0","repository_url":"https://github.com/zeromq/pyzmq"},{"name":"python-json-logger","old_version":"4.1.0","new_version":"4.2.0","repository_url":"https://github.com/nhairs/python-json-logger"},{"name":"pybase64","old_version":"1.4.3","new_version":"1.5.0","repository_url":"https://github.com/mayeut/pybase64"},{"name":"mcp","old_version":"2.1.1","new_version":"2.2.0","repository_url":"https://github.com/modelcontextprotocol/python-sdk"},{"name":"opentelemetry-sdk","old_version":"1.35.0","new_version":"1.44.0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"opentelemetry-api","old_version":"1.35.0","new_version":"1.44.0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"opentelemetry-exporter-otlp","old_version":"1.35.0","new_version":"1.44.0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"opentelemetry-semantic-conventions-ai","old_version":"0.4.13","new_version":"0.5.1"},{"name":"triton","old_version":"3.7.1","new_version":"3.8.0","repository_url":"https://github.com/triton-lang/triton"},{"name":"numba","old_version":"0.65.0","new_version":"0.67.0","repository_url":"https://github.com/numba/numba"},{"name":"torchcodec","old_version":"0.14.0+cu130","new_version":"0.16.0","repository_url":"https://github.com/pytorch/torchcodec"},{"name":"tpu-inference","old_version":"0.28.0","new_version":"0.29.0","repository_url":"https://github.com/vllm-project/tpu-inference"},{"name":"pynvvideocodec","old_version":"2.0.4","new_version":"2.2.3"},{"name":"fastsafetensors","old_version":"0.3.3","new_version":"0.4.0","repository_url":"https://github.com/foundation-model-stack/fastsafetensors"},{"name":"instanttensor","old_version":"0.1.9","new_version":"0.2.0","repository_url":"https://github.com/scitix/InstantTensor"},{"name":"nvidia-cutlass-dsl","old_version":"4.6.2","new_version":"4.7.1","repository_url":"https://github.com/NVIDIA/cutlass"},{"name":"tokenspeed-mla","old_version":"0.1.8","new_version":"0.2.9","repository_url":"https://github.com/lightseekorg/tokenspeed"},{"name":"absl-py","old_version":"2.1.0","new_version":"2.5.0","repository_url":"https://github.com/abseil/abseil-py"},{"name":"accelerate","old_version":"1.13.0","new_version":"1.15.0","repository_url":"https://github.com/huggingface/accelerate"},{"name":"aiohappyeyeballs","old_version":"2.6.1","new_version":"2.7.1","repository_url":"https://github.com/aio-libs/aiohappyeyeballs"},{"name":"alembic","old_version":"1.16.4","new_version":"1.20.0","repository_url":"https://github.com/sqlalchemy/alembic"},{"name":"annotated-types","old_version":"0.7.0","new_version":"0.8.0","repository_url":"https://github.com/annotated-types/annotated-types"},{"name":"anyio","old_version":"4.14.1","new_version":"4.15.1","repository_url":"https://github.com/agronholm/anyio"},{"name":"arctic-inference","old_version":"0.1.1","new_version":"0.3.0"},{"name":"argcomplete","old_version":"3.5.1","new_version":"3.7.2","repository_url":"https://github.com/kislyuk/argcomplete"},{"name":"audioread","old_version":"3.0.1","new_version":"3.1.0","repository_url":"https://github.com/beetbox/audioread"},{"name":"azure-core","old_version":"1.38.2","new_version":"1.41.0","repository_url":"https://github.com/Azure/azure-sdk-for-python"},{"name":"azure-storage-blob","old_version":"12.28.0","new_version":"12.30.2","repository_url":"https://github.com/Azure/azure-sdk-for-python"},{"name":"blobfile","old_version":"3.0.0","new_version":"3.3.0","repository_url":"https://github.com/blobfile/blobfile"},{"name":"bm25s","old_version":"0.2.13","new_version":"0.3.11","repository_url":"https://github.com/xhluca/bm25s"},{"name":"boto3","old_version":"1.35.57","new_version":"1.43.98","repository_url":"https://github.com/boto/boto3"},{"name":"botocore","old_version":"1.35.57","new_version":"1.43.98","repository_url":"https://github.com/boto/botocore"},{"name":"cffi","old_version":"2.0.0","new_version":"2.1.1","repository_url":"https://github.com/python-cffi/cffi"},{"name":"charset-normalizer","old_version":"3.4.0","new_version":"3.5.1","repository_url":"https://github.com/jawah/charset_normalizer"},{"name":"click","old_version":"8.4.2","new_version":"8.5.0","repository_url":"https://github.com/pallets/click"},{"name":"cohere","old_version":"7.0.8","new_version":"7.1.1","repository_url":"https://github.com/cohere-ai/cohere-python"},{"name":"cohere-melody","old_version":"0.11.1","new_version":"0.15.0","repository_url":"https://github.com/cohere-ai/melody"},{"name":"colorlog","old_version":"6.10.1","new_version":"6.12.0","repository_url":"https://github.com/borntyping/python-colorlog"},{"name":"coverage","old_version":"7.10.6","new_version":"7.16.1","repository_url":"https://github.com/coveragepy/coveragepy"},{"name":"cramjam","old_version":"2.9.0","new_version":"2.11.0","repository_url":"https://github.com/milesgranger/pyrus-cramjam"},{"name":"cuda-bindings","old_version":"13.0.3","new_version":"13.4.2","repository_url":"https://github.com/NVIDIA/cuda-python"},{"name":"cuda-pathfinder","old_version":"1.3.3","new_version":"1.8.2","repository_url":"https://github.com/NVIDIA/cuda-python"},{"name":"cuda-toolkit","old_version":"13.0.3.0","new_version":"13.4.2"},{"name":"datamodel-code-generator","old_version":"0.26.3","new_version":"0.82.0","repository_url":"https://github.com/datamodel-code-generator/datamodel-code-generator"},{"name":"dataproperty","old_version":"1.0.1","new_version":"1.1.1","repository_url":"https://github.com/thombashi/DataProperty"},{"name":"decorator","old_version":"5.1.1","new_version":"5.3.1","repository_url":"https://github.com/micheles/decorator"},{"name":"detect-installer","old_version":"0.1.0","new_version":"0.2.1"},{"name":"dill","old_version":"0.3.8","new_version":"0.4.1","repository_url":"https://github.com/uqfoundation/dill"},{"name":"distlib","old_version":"0.3.9","new_version":"0.4.3","repository_url":"https://github.com/pypa/distlib"},{"name":"dnspython","old_version":"2.7.0","new_version":"2.8.0","repository_url":"https://github.com/rthalley/dnspython"},{"name":"docker","old_version":"7.1.0","new_version":"7.2.0","repository_url":"https://github.com/docker/docker-py"},{"name":"einx","old_version":"0.3.0","new_version":"0.4.3","repository_url":"https://github.com/fferflo/einx"},{"name":"email-validator","old_version":"2.2.0","new_version":"2.3.0","repository_url":"https://github.com/JoshData/python-email-validator"},{"name":"fastapi-cloud-cli","old_version":"0.21.0","new_version":"0.26.0","repository_url":"https://github.com/fastapilabs/fastapi-cloud-cli"},{"name":"fastar","old_version":"0.11.0","new_version":"0.12.0","repository_url":"https://github.com/DoctorJohn/fastar"},{"name":"fonttools","old_version":"4.55.0","new_version":"4.65.0","repository_url":"https://github.com/fonttools/fonttools"},{"name":"frozenlist","old_version":"1.5.0","new_version":"1.8.0","repository_url":"https://github.com/aio-libs/frozenlist"},{"name":"genson","old_version":"1.3.0","new_version":"1.4.0","repository_url":"https://github.com/wolverdude/genson"},{"name":"google-api-core","old_version":"2.24.2","new_version":"2.38.0","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"google-auth","old_version":"2.40.2","new_version":"2.58.0","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"google-cloud-core","old_version":"2.4.3","new_version":"2.7.0","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"google-cloud-storage","old_version":"3.4.0","new_version":"3.14.1","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"google-crc32c","old_version":"1.7.1","new_version":"1.8.0","repository_url":"https://github.com/googleapis/python-crc32c"},{"name":"google-resumable-media","old_version":"2.7.2","new_version":"2.10.2","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"googleapis-common-protos","old_version":"1.70.0","new_version":"1.75.3","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"greenlet","old_version":"3.2.3","new_version":"3.5.6","repository_url":"https://github.com/python-greenlet/greenlet"},{"name":"grpcio","old_version":"1.78.0","new_version":"1.84.0","repository_url":"https://github.com/grpc/grpc"},{"name":"grpcio-reflection","old_version":"1.78.0","new_version":"1.84.0"},{"name":"h2","old_version":"4.3.0","new_version":"4.4.1","repository_url":"https://github.com/python-hyper/h2"},{"name":"hiredis","old_version":"3.0.0","new_version":"3.4.1","repository_url":"https://github.com/redis/hiredis-py"},{"name":"hpack","old_version":"4.1.0","new_version":"4.2.0","repository_url":"https://github.com/python-hyper/hpack"},{"name":"httpcore2","old_version":"2.12.0","new_version":"2.13.0","repository_url":"https://github.com/pydantic/httpx2"},{"name":"httpx","old_version":"0.27.2","new_version":"0.28.1","repository_url":"https://github.com/encode/httpx"},{"name":"httpx2","old_version":"2.12.0","new_version":"2.13.0","repository_url":"https://github.com/pydantic/httpx2"},{"name":"humanize","old_version":"4.11.0","new_version":"4.16.0","repository_url":"https://github.com/python-humanize/humanize"},{"name":"hypothesis","old_version":"6.131.0","new_version":"6.168.0","repository_url":"https://github.com/HypothesisWorks/hypothesis"},{"name":"idna","old_version":"3.19","new_version":"3.20","repository_url":"https://github.com/kjd/idna"},{"name":"iniconfig","old_version":"2.0.0","new_version":"2.3.0","repository_url":"https://github.com/pytest-dev/iniconfig"},{"name":"jiter","old_version":"0.15.0","new_version":"0.17.0","repository_url":"https://github.com/pydantic/jiter"},{"name":"jmespath","old_version":"1.0.1","new_version":"1.1.0","repository_url":"https://github.com/jmespath/jmespath.py"},{"name":"joblib","old_version":"1.4.2","new_version":"1.6.0","repository_url":"https://github.com/joblib/joblib"},{"name":"jsonschema-rs","old_version":"0.46.5","new_version":"0.56.0","repository_url":"https://github.com/Stranger6667/jsonschema"},{"name":"kiwisolver","old_version":"1.4.7","new_version":"1.5.1","repository_url":"https://github.com/nucleic/kiwi"},{"name":"lazy-loader","old_version":"0.4","new_version":"0.5","repository_url":"https://github.com/scientific-python/lazy-loader"},{"name":"llguidance","old_version":"1.7.6","new_version":"1.8.0","repository_url":"https://github.com/microsoft/llguidance"},{"name":"llvmlite","old_version":"0.47.0","new_version":"0.49.0","repository_url":"https://github.com/numba/llvmlite"},{"name":"mako","old_version":"1.3.10","new_version":"1.4.1","repository_url":"https://github.com/sqlalchemy/mako"},{"name":"matplotlib","old_version":"3.9.2","new_version":"3.10.9","repository_url":"https://github.com/matplotlib/matplotlib"},{"name":"mcp-types","old_version":"2.1.1","new_version":"2.2.0","repository_url":"https://github.com/modelcontextprotocol/python-sdk"},{"name":"mpmath","old_version":"1.3.0","new_version":"1.4.1","repository_url":"https://github.com/mpmath/mpmath"},{"name":"msal","old_version":"1.34.0","new_version":"1.39.0","repository_url":"https://github.com/AzureAD/microsoft-authentication-library-for-python"},{"name":"msgpack","old_version":"1.1.0","new_version":"1.2.2","repository_url":"https://github.com/msgpack/msgpack-python"},{"name":"mteb","old_version":"2.8.3","new_version":"2.21.0","repository_url":"https://github.com/embeddings-benchmark/mteb"},{"name":"multidict","old_version":"6.1.0","new_version":"6.9.0","repository_url":"https://github.com/aio-libs/multidict"},{"name":"mypy-extensions","old_version":"1.0.0","new_version":"1.1.0","repository_url":"https://github.com/python/mypy_extensions"},{"name":"networkx","old_version":"3.2.1","new_version":"3.4.2","repository_url":"https://github.com/networkx/networkx"},{"name":"nltk","old_version":"3.9.1","new_version":"3.10.3","repository_url":"https://github.com/nltk/nltk"},{"name":"nvidia-cublas","old_version":"13.1.1.3","new_version":"13.8.0.4"},{"name":"nvidia-cuda-cupti","old_version":"13.0.85","new_version":"13.4.92"},{"name":"nvidia-cuda-nvrtc","old_version":"13.0.88","new_version":"13.4.92"},{"name":"nvidia-cuda-runtime","old_version":"13.0.96","new_version":"13.4.92"},{"name":"nvidia-cudnn-cu13","old_version":"9.20.0.48","new_version":"9.26.0.51"},{"name":"nvidia-cufft","old_version":"12.0.0.61","new_version":"12.4.0.43"},{"name":"nvidia-cufile","old_version":"1.15.1.6","new_version":"1.19.1.55"},{"name":"nvidia-cusolver","old_version":"12.0.4.66","new_version":"12.3.4.7"},{"name":"nvidia-cusparse","old_version":"12.6.3.3","new_version":"12.8.6.72"},{"name":"nvidia-cusparselt-cu13","old_version":"0.8.1","new_version":"0.9.1"},{"name":"nvidia-nccl-cu13","old_version":"2.29.7","new_version":"2.31.2"},{"name":"nvidia-nvjitlink","old_version":"13.0.88","new_version":"13.4.92"},{"name":"nvidia-nvshmem-cu13","old_version":"3.4.5","new_version":"3.7.2"},{"name":"nvidia-nvtx","old_version":"13.0.85","new_version":"13.4.92"},{"name":"opentelemetry-exporter-otlp-proto-common","old_version":"1.35.0","new_version":"1.44.0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"opentelemetry-exporter-otlp-proto-grpc","old_version":"1.35.0","new_version":"1.44.0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"opentelemetry-exporter-otlp-proto-http","old_version":"1.35.0","new_version":"1.44.0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"opentelemetry-exporter-prometheus","old_version":"0.56b0","new_version":"0.65b0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"opentelemetry-proto","old_version":"1.35.0","new_version":"1.44.0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"opentelemetry-semantic-conventions","old_version":"0.56b0","new_version":"0.65b0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"orjson","old_version":"3.11.5","new_version":"3.12.0","repository_url":"https://github.com/ijl/orjson"},{"name":"pathvalidate","old_version":"3.2.1","new_version":"3.3.1","repository_url":"https://github.com/thombashi/pathvalidate"},{"name":"peft","old_version":"0.19.1","new_version":"0.21.0","repository_url":"https://github.com/huggingface/peft"},{"name":"perceptron","old_version":"0.1.4","new_version":"0.3.5","repository_url":"https://github.com/perceptron-ai-inc/perceptron"},{"name":"platformdirs","old_version":"4.3.6","new_version":"4.11.10","repository_url":"https://github.com/tox-dev/platformdirs"},{"name":"pluggy","old_version":"1.5.0","new_version":"1.6.0","repository_url":"https://github.com/pytest-dev/pluggy"},{"name":"polars","old_version":"1.29.0","new_version":"1.44.2","repository_url":"https://github.com/pola-rs/polars"},{"name":"pooch","old_version":"1.8.2","new_version":"1.9.0","repository_url":"https://github.com/fatiando/pooch"},{"name":"propcache","old_version":"0.2.0","new_version":"0.5.4","repository_url":"https://github.com/aio-libs/propcache"},{"name":"proto-plus","old_version":"1.26.1","new_version":"1.28.4","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"pycryptodomex","old_version":"3.22.0","new_version":"3.23.0","repository_url":"https://github.com/Legrandin/pycryptodome"},{"name":"pydantic-core","old_version":"2.41.1","new_version":"2.49.0","repository_url":"https://github.com/pydantic/pydantic"},{"name":"pydantic-extra-types","old_version":"2.10.5","new_version":"2.11.1","repository_url":"https://github.com/pydantic/pydantic-extra-types"},{"name":"pydantic-settings","old_version":"2.14.2","new_version":"2.15.0","repository_url":"https://github.com/pydantic/pydantic-settings"},{"name":"pygments","old_version":"2.18.0","new_version":"2.21.0","repository_url":"https://github.com/pygments/pygments"},{"name":"pyjwt","old_version":"2.11.0","new_version":"2.14.0","repository_url":"https://github.com/jpadilla/pyjwt"},{"name":"pyparsing","old_version":"3.2.0","new_version":"3.3.2","repository_url":"https://github.com/pyparsing/pyparsing"},{"name":"pyrate-limiter","old_version":"4.4.0","new_version":"4.5.0","repository_url":"https://github.com/vutran1710/PyrateLimiter"},{"name":"pystemmer","old_version":"3.0.0","new_version":"3.1.0","repository_url":"https://github.com/snowballstem/pystemmer"},{"name":"pytest-forked","old_version":"1.6.0","new_version":"1.7.5","repository_url":"https://github.com/pytest-dev/pytest-forked"},{"name":"pytest-mock","old_version":"3.14.0","new_version":"3.15.1","repository_url":"https://github.com/pytest-dev/pytest-mock"},{"name":"pytest-timeout","old_version":"2.3.1","new_version":"2.4.0","repository_url":"https://github.com/pytest-dev/pytest-timeout"},{"name":"python-rapidjson","old_version":"1.20","new_version":"1.25","repository_url":"https://github.com/python-rapidjson/python-rapidjson"},{"name":"rapidfuzz","old_version":"3.12.1","new_version":"3.14.5","repository_url":"https://github.com/rapidfuzz/RapidFuzz"},{"name":"referencing","old_version":"0.35.1","new_version":"0.37.0","repository_url":"https://github.com/python-jsonschema/referencing"},{"name":"responses","old_version":"0.25.3","new_version":"0.26.3","repository_url":"https://github.com/getsentry/responses"},{"name":"rignore","old_version":"0.7.6","new_version":"0.8.1"},{"name":"runai-model-streamer","old_version":"0.15.7","new_version":"0.16.1"},{"name":"runai-model-streamer-azure","old_version":"0.15.7","new_version":"0.16.1"},{"name":"runai-model-streamer-gcs","old_version":"0.15.7","new_version":"0.16.1"},{"name":"runai-model-streamer-s3","old_version":"0.15.7","new_version":"0.16.1"},{"name":"s3transfer","old_version":"0.10.3","new_version":"0.19.2","repository_url":"https://github.com/boto/s3transfer"},{"name":"sacrebleu","old_version":"2.4.3","new_version":"2.6.0","repository_url":"https://github.com/mjpost/sacrebleu"},{"name":"schemathesis","old_version":"4.21.6","new_version":"4.27.4","repository_url":"https://github.com/schemathesis/schemathesis"},{"name":"scikit-learn","old_version":"1.5.2","new_version":"1.7.2","repository_url":"https://github.com/scikit-learn/scikit-learn"},{"name":"scipy","old_version":"1.13.1","new_version":"1.15.3","repository_url":"https://github.com/scipy/scipy"},{"name":"sentry-sdk","old_version":"2.63.0","new_version":"2.69.2","repository_url":"https://github.com/getsentry/sentry-python"},{"name":"six","old_version":"1.16.0","new_version":"1.17.0","repository_url":"https://github.com/benjaminp/six"},{"name":"soundfile","old_version":"0.12.1","new_version":"0.14.0","repository_url":"https://github.com/bastibe/python-soundfile"},{"name":"statsmodels","old_version":"0.14.4","new_version":"0.15.0","repository_url":"https://github.com/statsmodels/statsmodels"},{"name":"sympy","old_version":"1.13.3","new_version":"1.14.0","repository_url":"https://github.com/sympy/sympy"},{"name":"tabulate","old_version":"0.9.0","new_version":"0.10.0","repository_url":"https://github.com/astanin/python-tabulate"},{"name":"tblib","old_version":"3.1.0","new_version":"3.2.2","repository_url":"https://github.com/ionelmc/python-tblib"},{"name":"tensorizer","old_version":"2.10.1","new_version":"2.12.1","repository_url":"https://github.com/coreweave/tensorizer"},{"name":"termcolor","old_version":"3.1.0","new_version":"3.3.0","repository_url":"https://github.com/termcolor/termcolor"},{"name":"threadpoolctl","old_version":"3.5.0","new_version":"3.7.0","repository_url":"https://github.com/joblib/threadpoolctl"},{"name":"tritonclient","old_version":"2.64.0","new_version":"2.71.0","repository_url":"https://github.com/triton-inference-server/client"},{"name":"typer","old_version":"0.26.8","new_version":"0.27.2","repository_url":"https://github.com/fastapi/typer"},{"name":"urllib3","old_version":"2.2.3","new_version":"2.8.0","repository_url":"https://github.com/urllib3/urllib3"},{"name":"uvicorn","old_version":"0.35.0","new_version":"0.53.0","repository_url":"https://github.com/Kludex/uvicorn"},{"name":"vector-quantize-pytorch","old_version":"1.21.2","new_version":"1.31.4","repository_url":"https://github.com/lucidrains/vector-quantizer-pytorch"},{"name":"wcwidth","old_version":"0.2.13","new_version":"0.8.4","repository_url":"https://github.com/jquast/wcwidth"},{"name":"yarl","old_version":"1.17.1","new_version":"1.25.1","repository_url":"https://github.com/aio-libs/yarl"},{"name":"conch-triton-kernels","old_version":"1.2.1","new_version":"1.3","repository_url":"https://github.com/stackav-oss/conch"},{"name":"griffelib","old_version":"2.0.2","new_version":"2.3.0"},{"name":"mkdocs-git-revision-date-localized-plugin","old_version":"1.5.1","new_version":"1.6.0","repository_url":"https://github.com/timvink/mkdocs-git-revision-date-localized-plugin"},{"name":"ruff","old_version":"0.15.12","new_version":"0.16.8","repository_url":"https://github.com/astral-sh/ruff"},{"name":"zentorch","old_version":"2.13.0.0","new_version":"2.14.0.0","repository_url":"https://github.com/amd/ZenDNN-pytorch-plugin"}],"path":null,"ecosystem":"pip"},"body":"Bumps the minor-update group with 191 updates:\n\n| Package | From | To |\n| --- | --- | --- |\n| [regex](https://github.com/mrabarnett/mrab-regex) | `2026.2.28` | `2026.9.10` |\n| [requests](https://github.com/psf/requests) | `2.32.3` | `2.34.2` |\n| [tqdm](https://github.com/tqdm/tqdm) | `4.67.3` | `4.70.1` |\n| [transformers](https://github.com/huggingface/transformers) | `5.15.0` | `5.17.0` |\n| [huggingface-hub](https://github.com/huggingface/huggingface_hub) | `1.28.0` | `1.32.0` |\n| [tokenizers](https://github.com/huggingface/tokenizers) | `0.22.2` | `0.23.2` |\n| [fastapi](https://github.com/fastapi/fastapi) | `0.136.3` | `0.141.1` |\n| [starlette](https://github.com/Kludex/starlette) | `1.3.1` | `1.6.0` |\n| [aiohttp](https://github.com/aio-libs/aiohttp) | `3.13.3` | `3.14.3` |\n| [pydantic](https://github.com/pydantic/pydantic) | `2.12.0` | `2.13.5` |\n| [prometheus-client](https://github.com/prometheus/client_python) | `0.22.0` | `0.26.0` |\n| [prometheus-fastapi-instrumentator](https://github.com/trallnag/prometheus-fastapi-instrumentator) | `8.0.2` | `8.1.0` |\n| [tiktoken](https://github.com/openai/tiktoken) | `0.12.0` | `0.14.0` |\n| [lark](https://github.com/lark-parser/lark) | `1.2.2` | `1.3.1` |\n| [typing-extensions](https://github.com/python/typing_extensions) | `4.15.0` | `4.16.0` |\n| [jsonschema](https://github.com/python-jsonschema/jsonschema) | `4.23.0` | `4.26.0` |\n| [pyzmq](https://github.com/zeromq/pyzmq) | `27.1.0` | `27.2.0` |\n| [python-json-logger](https://github.com/nhairs/python-json-logger) | `4.1.0` | `4.2.0` |\n| [pybase64](https://github.com/mayeut/pybase64) | `1.4.3` | `1.5.0` |\n| [mcp](https://github.com/modelcontextprotocol/python-sdk) | `2.1.1` | `2.2.0` |\n| [opentelemetry-sdk](https://github.com/open-telemetry/opentelemetry-python) | `1.35.0` | `1.44.0` |\n| [opentelemetry-api](https://github.com/open-telemetry/opentelemetry-python) | `1.35.0` | `1.44.0` |\n| [opentelemetry-exporter-otlp](https://github.com/open-telemetry/opentelemetry-python) | `1.35.0` | `1.44.0` |\n| opentelemetry-semantic-conventions-ai | `0.4.13` | `0.5.1` |\n| [triton](https://github.com/triton-lang/triton) | `3.7.1` | `3.8.0` |\n| [numba](https://github.com/numba/numba) | `0.65.0` | `0.67.0` |\n| [torchcodec](https://github.com/pytorch/torchcodec) | `0.14.0+cu130` | `0.16.0` |\n| [tpu-inference](https://github.com/vllm-project/tpu-inference) | `0.28.0` | `0.29.0` |\n| pynvvideocodec | `2.0.4` | `2.2.3` |\n| [fastsafetensors](https://github.com/foundation-model-stack/fastsafetensors) | `0.3.3` | `0.4.0` |\n| [instanttensor](https://github.com/scitix/InstantTensor) | `0.1.9` | `0.2.0` |\n| [nvidia-cutlass-dsl](https://github.com/NVIDIA/cutlass) | `4.6.2` | `4.7.1` |\n| [tokenspeed-mla](https://github.com/lightseekorg/tokenspeed) | `0.1.8` | `0.2.9` |\n| [absl-py](https://github.com/abseil/abseil-py) | `2.1.0` | `2.5.0` |\n| [accelerate](https://github.com/huggingface/accelerate) | `1.13.0` | `1.15.0` |\n| [aiohappyeyeballs](https://github.com/aio-libs/aiohappyeyeballs) | `2.6.1` | `2.7.1` |\n| [alembic](https://github.com/sqlalchemy/alembic) | `1.16.4` | `1.20.0` |\n| [annotated-types](https://github.com/annotated-types/annotated-types) | `0.7.0` | `0.8.0` |\n| [anyio](https://github.com/agronholm/anyio) | `4.14.1` | `4.15.1` |\n| arctic-inference | `0.1.1` | `0.3.0` |\n| [argcomplete](https://github.com/kislyuk/argcomplete) | `3.5.1` | `3.7.2` |\n| [audioread](https://github.com/beetbox/audioread) | `3.0.1` | `3.1.0` |\n| [azure-core](https://github.com/Azure/azure-sdk-for-python) | `1.38.2` | `1.41.0` |\n| [azure-storage-blob](https://github.com/Azure/azure-sdk-for-python) | `12.28.0` | `12.30.2` |\n| [blobfile](https://github.com/blobfile/blobfile) | `3.0.0` | `3.3.0` |\n| [bm25s](https://github.com/xhluca/bm25s) | `0.2.13` | `0.3.11` |\n| [boto3](https://github.com/boto/boto3) | `1.35.57` | `1.43.98` |\n| [botocore](https://github.com/boto/botocore) | `1.35.57` | `1.43.98` |\n| [cffi](https://github.com/python-cffi/cffi) | `2.0.0` | `2.1.1` |\n| [charset-normalizer](https://github.com/jawah/charset_normalizer) | `3.4.0` | `3.5.1` |\n| [click](https://github.com/pallets/click) | `8.4.2` | `8.5.0` |\n| [cohere](https://github.com/cohere-ai/cohere-python) | `7.0.8` | `7.1.1` |\n| [cohere-melody](https://github.com/cohere-ai/melody) | `0.11.1` | `0.15.0` |\n| [colorlog](https://github.com/borntyping/python-colorlog) | `6.10.1` | `6.12.0` |\n| [coverage](https://github.com/coveragepy/coveragepy) | `7.10.6` | `7.16.1` |\n| [cramjam](https://github.com/milesgranger/pyrus-cramjam) | `2.9.0` | `2.11.0` |\n| [cuda-bindings](https://github.com/NVIDIA/cuda-python) | `13.0.3` | `13.4.2` |\n| [cuda-pathfinder](https://github.com/NVIDIA/cuda-python) | `1.3.3` | `1.8.2` |\n| [cuda-toolkit](https://developer.nvidia.com/cuda-toolkit) | `13.0.3.0` | `13.4.2` |\n| [datamodel-code-generator](https://github.com/datamodel-code-generator/datamodel-code-generator) | `0.26.3` | `0.82.0` |\n| [dataproperty](https://github.com/thombashi/DataProperty) | `1.0.1` | `1.1.1` |\n| [decorator](https://github.com/micheles/decorator) | `5.1.1` | `5.3.1` |\n| detect-installer | `0.1.0` | `0.2.1` |\n| [dill](https://github.com/uqfoundation/dill) | `0.3.8` | `0.4.1` |\n| [distlib](https://github.com/pypa/distlib) | `0.3.9` | `0.4.3` |\n| [dnspython](https://github.com/rthalley/dnspython) | `2.7.0` | `2.8.0` |\n| [docker](https://github.com/docker/docker-py) | `7.1.0` | `7.2.0` |\n| [einx](https://github.com/fferflo/einx) | `0.3.0` | `0.4.3` |\n| [email-validator](https://github.com/JoshData/python-email-validator) | `2.2.0` | `2.3.0` |\n| [fastapi-cloud-cli](https://github.com/fastapilabs/fastapi-cloud-cli) | `0.21.0` | `0.26.0` |\n| [fastar](https://github.com/DoctorJohn/fastar) | `0.11.0` | `0.12.0` |\n| [fonttools](https://github.com/fonttools/fonttools) | `4.55.0` | `4.65.0` |\n| [frozenlist](https://github.com/aio-libs/frozenlist) | `1.5.0` | `1.8.0` |\n| [genson](https://github.com/wolverdude/genson) | `1.3.0` | `1.4.0` |\n| [google-api-core](https://github.com/googleapis/google-cloud-python) | `2.24.2` | `2.38.0` |\n| [google-auth](https://github.com/googleapis/google-cloud-python) | `2.40.2` | `2.58.0` |\n| [google-cloud-core](https://github.com/googleapis/google-cloud-python) | `2.4.3` | `2.7.0` |\n| [google-cloud-storage](https://github.com/googleapis/google-cloud-python) | `3.4.0` | `3.14.1` |\n| [google-crc32c](https://github.com/googleapis/python-crc32c) | `1.7.1` | `1.8.0` |\n| [google-resumable-media](https://github.com/googleapis/google-cloud-python) | `2.7.2` | `2.10.2` |\n| [googleapis-common-protos](https://github.com/googleapis/google-cloud-python) | `1.70.0` | `1.75.3` |\n| [greenlet](https://github.com/python-greenlet/greenlet) | `3.2.3` | `3.5.6` |\n| [grpcio](https://github.com/grpc/grpc) | `1.78.0` | `1.84.0` |\n| [grpcio-reflection](https://grpc.io) | `1.78.0` | `1.84.0` |\n| [h2](https://github.com/python-hyper/h2) | `4.3.0` | `4.4.1` |\n| [hiredis](https://github.com/redis/hiredis-py) | `3.0.0` | `3.4.1` |\n| [hpack](https://github.com/python-hyper/hpack) | `4.1.0` | `4.2.0` |\n| [httpcore2](https://github.com/pydantic/httpx2) | `2.12.0` | `2.13.0` |\n| [httpx](https://github.com/encode/httpx) | `0.27.2` | `0.28.1` |\n| [httpx2](https://github.com/pydantic/httpx2) | `2.12.0` | `2.13.0` |\n| [humanize](https://github.com/python-humanize/humanize) | `4.11.0` | `4.16.0` |\n| [hypothesis](https://github.com/HypothesisWorks/hypothesis) | `6.131.0` | `6.168.0` |\n| [idna](https://github.com/kjd/idna) | `3.19` | `3.20` |\n| [iniconfig](https://github.com/pytest-dev/iniconfig) | `2.0.0` | `2.3.0` |\n| [jiter](https://github.com/pydantic/jiter) | `0.15.0` | `0.17.0` |\n| [jmespath](https://github.com/jmespath/jmespath.py) | `1.0.1` | `1.1.0` |\n| [joblib](https://github.com/joblib/joblib) | `1.4.2` | `1.6.0` |\n| [jsonschema-rs](https://github.com/Stranger6667/jsonschema) | `0.46.5` | `0.56.0` |\n| [kiwisolver](https://github.com/nucleic/kiwi) | `1.4.7` | `1.5.1` |\n| [lazy-loader](https://github.com/scientific-python/lazy-loader) | `0.4` | `0.5` |\n| [llguidance](https://github.com/microsoft/llguidance) | `1.7.6` | `1.8.0` |\n| [llvmlite](https://github.com/numba/llvmlite) | `0.47.0` | `0.49.0` |\n| [mako](https://github.com/sqlalchemy/mako) | `1.3.10` | `1.4.1` |\n| [matplotlib](https://github.com/matplotlib/matplotlib) | `3.9.2` | `3.10.9` |\n| [mcp-types](https://github.com/modelcontextprotocol/python-sdk) | `2.1.1` | `2.2.0` |\n| [mpmath](https://github.com/mpmath/mpmath) | `1.3.0` | `1.4.1` |\n| [msal](https://github.com/AzureAD/microsoft-authentication-library-for-python) | `1.34.0` | `1.39.0` |\n| [msgpack](https://github.com/msgpack/msgpack-python) | `1.1.0` | `1.2.2` |\n| [mteb](https://github.com/embeddings-benchmark/mteb) | `2.8.3` | `2.21.0` |\n| [multidict](https://github.com/aio-libs/multidict) | `6.1.0` | `6.9.0` |\n| [mypy-extensions](https://github.com/python/mypy_extensions) | `1.0.0` | `1.1.0` |\n| [networkx](https://github.com/networkx/networkx) | `3.2.1` | `3.4.2` |\n| [nltk](https://github.com/nltk/nltk) | `3.9.1` | `3.10.3` |\n| [nvidia-cublas](https://developer.nvidia.com/cuda-zone) | `13.1.1.3` | `13.8.0.4` |\n| [nvidia-cuda-cupti](https://developer.nvidia.com/cuda-zone) | `13.0.85` | `13.4.92` |\n| [nvidia-cuda-nvrtc](https://developer.nvidia.com/cuda-zone) | `13.0.88` | `13.4.92` |\n| [nvidia-cuda-runtime](https://developer.nvidia.com/cuda-zone) | `13.0.96` | `13.4.92` |\n| [nvidia-cudnn-cu13](https://developer.nvidia.com/cuda-zone) | `9.20.0.48` | `9.26.0.51` |\n| [nvidia-cufft](https://developer.nvidia.com/cuda-zone) | `12.0.0.61` | `12.4.0.43` |\n| [nvidia-cufile](https://developer.nvidia.com/cuda-zone) | `1.15.1.6` | `1.19.1.55` |\n| [nvidia-cusolver](https://developer.nvidia.com/cuda-zone) | `12.0.4.66` | `12.3.4.7` |\n| [nvidia-cusparse](https://developer.nvidia.com/cuda-zone) | `12.6.3.3` | `12.8.6.72` |\n| [nvidia-cusparselt-cu13](https://developer.nvidia.com/cusparselt) | `0.8.1` | `0.9.1` |\n| [nvidia-nccl-cu13](https://developer.nvidia.com/cuda-zone) | `2.29.7` | `2.31.2` |\n| [nvidia-nvjitlink](https://developer.nvidia.com/cuda-zone) | `13.0.88` | `13.4.92` |\n| [nvidia-nvshmem-cu13](https://developer.nvidia.com/cuda-zone) | `3.4.5` | `3.7.2` |\n| [nvidia-nvtx](https://developer.nvidia.com/cuda-zone) | `13.0.85` | `13.4.92` |\n| [opentelemetry-exporter-otlp-proto-common](https://github.com/open-telemetry/opentelemetry-python) | `1.35.0` | `1.44.0` |\n| [opentelemetry-exporter-otlp-proto-grpc](https://github.com/open-telemetry/opentelemetry-python) | `1.35.0` | `1.44.0` |\n| [opentelemetry-exporter-otlp-proto-http](https://github.com/open-telemetry/opentelemetry-python) | `1.35.0` | `1.44.0` |\n| [opentelemetry-exporter-prometheus](https://github.com/open-telemetry/opentelemetry-python) | `0.56b0` | `0.65b0` |\n| [opentelemetry-proto](https://github.com/open-telemetry/opentelemetry-python) | `1.35.0` | `1.44.0` |\n| [opentelemetry-semantic-conventions](https://github.com/open-telemetry/opentelemetry-python) | `0.56b0` | `0.65b0` |\n| [orjson](https://github.com/ijl/orjson) | `3.11.5` | `3.12.0` |\n| [pathvalidate](https://github.com/thombashi/pathvalidate) | `3.2.1` | `3.3.1` |\n| [peft](https://github.com/huggingface/peft) | `0.19.1` | `0.21.0` |\n| [perceptron](https://github.com/perceptron-ai-inc/perceptron) | `0.1.4` | `0.3.5` |\n| [platformdirs](https://github.com/tox-dev/platformdirs) | `4.3.6` | `4.11.10` |\n| [pluggy](https://github.com/pytest-dev/pluggy) | `1.5.0` | `1.6.0` |\n| [polars](https://github.com/pola-rs/polars) | `1.29.0` | `1.44.2` |\n| [pooch](https://github.com/fatiando/pooch) | `1.8.2` | `1.9.0` |\n| [propcache](https://github.com/aio-libs/propcache) | `0.2.0` | `0.5.4` |\n| [proto-plus](https://github.com/googleapis/google-cloud-python) | `1.26.1` | `1.28.4` |\n| [pycryptodomex](https://github.com/Legrandin/pycryptodome) | `3.22.0` | `3.23.0` |\n| [pydantic-core](https://github.com/pydantic/pydantic) | `2.41.1` | `2.49.0` |\n| [pydantic-extra-types](https://github.com/pydantic/pydantic-extra-types) | `2.10.5` | `2.11.1` |\n| [pydantic-settings](https://github.com/pydantic/pydantic-settings) | `2.14.2` | `2.15.0` |\n| [pygments](https://github.com/pygments/pygments) | `2.18.0` | `2.21.0` |\n| [pyjwt](https://github.com/jpadilla/pyjwt) | `2.11.0` | `2.14.0` |\n| [pyparsing](https://github.com/pyparsing/pyparsing) | `3.2.0` | `3.3.2` |\n| [pyrate-limiter](https://github.com/vutran1710/PyrateLimiter) | `4.4.0` | `4.5.0` |\n| [pystemmer](https://github.com/snowballstem/pystemmer) | `3.0.0` | `3.1.0` |\n| [pytest-forked](https://github.com/pytest-dev/pytest-forked) | `1.6.0` | `1.7.5` |\n| [pytest-mock](https://github.com/pytest-dev/pytest-mock) | `3.14.0` | `3.15.1` |\n| [pytest-timeout](https://github.com/pytest-dev/pytest-timeout) | `2.3.1` | `2.4.0` |\n| [python-rapidjson](https://github.com/python-rapidjson/python-rapidjson) | `1.20` | `1.25` |\n| [rapidfuzz](https://github.com/rapidfuzz/RapidFuzz) | `3.12.1` | `3.14.5` |\n| [referencing](https://github.com/python-jsonschema/referencing) | `0.35.1` | `0.37.0` |\n| [responses](https://github.com/getsentry/responses) | `0.25.3` | `0.26.3` |\n| rignore | `0.7.6` | `0.8.1` |\n| runai-model-streamer | `0.15.7` | `0.16.1` |\n| runai-model-streamer-azure | `0.15.7` | `0.16.1` |\n| runai-model-streamer-gcs | `0.15.7` | `0.16.1` |\n| runai-model-streamer-s3 | `0.15.7` | `0.16.1` |\n| [s3transfer](https://github.com/boto/s3transfer) | `0.10.3` | `0.19.2` |\n| [sacrebleu](https://github.com/mjpost/sacrebleu) | `2.4.3` | `2.6.0` |\n| [schemathesis](https://github.com/schemathesis/schemathesis) | `4.21.6` | `4.27.4` |\n| [scikit-learn](https://github.com/scikit-learn/scikit-learn) | `1.5.2` | `1.7.2` |\n| [scipy](https://github.com/scipy/scipy) | `1.13.1` | `1.15.3` |\n| [sentry-sdk](https://github.com/getsentry/sentry-python) | `2.63.0` | `2.69.2` |\n| [six](https://github.com/benjaminp/six) | `1.16.0` | `1.17.0` |\n| [soundfile](https://github.com/bastibe/python-soundfile) | `0.12.1` | `0.14.0` |\n| [statsmodels](https://github.com/statsmodels/statsmodels) | `0.14.4` | `0.15.0` |\n| [sympy](https://github.com/sympy/sympy) | `1.13.3` | `1.14.0` |\n| [tabulate](https://github.com/astanin/python-tabulate) | `0.9.0` | `0.10.0` |\n| [tblib](https://github.com/ionelmc/python-tblib) | `3.1.0` | `3.2.2` |\n| [tensorizer](https://github.com/coreweave/tensorizer) | `2.10.1` | `2.12.1` |\n| [termcolor](https://github.com/termcolor/termcolor) | `3.1.0` | `3.3.0` |\n| [threadpoolctl](https://github.com/joblib/threadpoolctl) | `3.5.0` | `3.7.0` |\n| [tritonclient](https://github.com/triton-inference-server/client) | `2.64.0` | `2.71.0` |\n| [typer](https://github.com/fastapi/typer) | `0.26.8` | `0.27.2` |\n| [urllib3](https://github.com/urllib3/urllib3) | `2.2.3` | `2.8.0` |\n| [uvicorn](https://github.com/Kludex/uvicorn) | `0.35.0` | `0.53.0` |\n| [vector-quantize-pytorch](https://github.com/lucidrains/vector-quantizer-pytorch) | `1.21.2` | `1.31.4` |\n| [wcwidth](https://github.com/jquast/wcwidth) | `0.2.13` | `0.8.4` |\n| [yarl](https://github.com/aio-libs/yarl) | `1.17.1` | `1.25.1` |\n| [conch-triton-kernels](https://github.com/stackav-oss/conch) | `1.2.1` | `1.3` |\n| griffelib | `2.0.2` | `2.3.0` |\n| [mkdocs-git-revision-date-localized-plugin](https://github.com/timvink/mkdocs-git-revision-date-localized-plugin) | `1.5.1` | `1.6.0` |\n| [ruff](https://github.com/astral-sh/ruff) | `0.15.12` | `0.16.8` |\n| [zentorch](https://github.com/amd/ZenDNN-pytorch-plugin) | `2.13.0.0` | `2.14.0.0` |\n\nUpdates `regex` from 2026.2.28 to 2026.9.10\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/mrabarnett/mrab-regex/blob/hg/changelog.txt\"\u003eregex's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003eVersion: 2026.9.19\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eGit issue 619: `Match.expand()` segfaults after `detach_string()` when the template references a group\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.9.10\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eFixed version.\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.9.9\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003ePR [#615](https://github.com/mrabarnett/mrab-regex/issues/615): Fix Python API error propagation in match helpers\n\u003cp\u003ePR \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/616\"\u003e#616\u003c/a\u003e: Preserve Python Exceptions in Input Decoding and String Detachment\u003c/p\u003e\n\u003cp\u003ePR \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/617\"\u003e#617\u003c/a\u003e: Prevent Invalid Pointer Use and Exception State Corruption in Byte String Joining\u003c/p\u003e\n\u003cp\u003ePR \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/618\"\u003e#618\u003c/a\u003e: Propagate Allocation and Internal Errors During Pattern Compilation and Scanner Execution\n\u003c/code\u003e\u003c/pre\u003e\u003c/p\u003e\n\u003cp\u003eVersion: 2026.9.3\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eNew version of cibuildwheel no longer supports building for free-threaded Python 3.13.\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.9.2\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eNew version of cibuildwheel no longer needs nor supports cpython-freethreading option.\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.9.1\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eUpdated cibuildwheel.\nSupport Python 3.15.\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.8.31\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eFixed version.\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.8.30\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eGit issue 611: Heap out-of-bounds write at compile time\nGit issue 612: count_one() size underflow through the stale required-string cache\nGit issue 613: (*SKIP) inside an atomic group, plus an equality-only scan stop\nGit issue 614: build_GROUP() does not propagate the match direction\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.8.12\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eSupport Python 3.15.\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eVersion: 2026.7.19\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003eGit issue 607: SIGSEGV: NULL pointer dereference in `basic_match()` when `(?R)`/`(?0)` recursion is used inside a fuzzy-matching quantifier\nGit issue 608: SIGSEGV: out-of-bounds read in `bytes1_char_at()` with `DOTALL` + a fuzzy constraint + `(?r)` reverse-direction matching\n\u003c/code\u003e\u003c/pre\u003e\n\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/7dd71c15c4fb5c94206bed1763abd4c2bd2f1b33\"\u003e\u003ccode\u003e7dd71c1\u003c/code\u003e\u003c/a\u003e Fixed version.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/59124d62299e212931786aa74ead15388abaf376\"\u003e\u003ccode\u003e59124d6\u003c/code\u003e\u003c/a\u003e PR \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/615\"\u003e#615\u003c/a\u003e: Fix Python API error propagation in match helpers\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/25e15218bd44ca26677e3c28709e94a0ca0d9b8e\"\u003e\u003ccode\u003e25e1521\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/618\"\u003e#618\u003c/a\u003e from dynapx/fix-compiler-error-propagation\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/3ad78cfb73850c2f1178d19553fa14661f73d9cb\"\u003e\u003ccode\u003e3ad78cf\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/616\"\u003e#616\u003c/a\u003e from dynapx/fix-detach-string-error-propagation\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/f54253c332574bd5a9d96d3ec9d62b5db954dac7\"\u003e\u003ccode\u003ef54253c\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/mrabarnett/mrab-regex/issues/615\"\u003e#615\u003c/a\u003e from dynapx/fix-python-api-error-propagation\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/c44224476cd6a6e53be0e458dfdcf3b81d76e426\"\u003e\u003ccode\u003ec442244\u003c/code\u003e\u003c/a\u003e Propagate scanner internal errors\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/68837e7af862250cd08fa49ff584a2bbff246e0f\"\u003e\u003ccode\u003e68837e7\u003c/code\u003e\u003c/a\u003e Propagate node stack allocation failures\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/f1df5387982d526cc9475fddcc8d1043b02ffc9a\"\u003e\u003ccode\u003ef1df538\u003c/code\u003e\u003c/a\u003e Propagate check stack allocation failures\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/d8873b119a49cde8d2613253827bf973261bb2bc\"\u003e\u003ccode\u003ed8873b1\u003c/code\u003e\u003c/a\u003e Preserve Python exceptions in input decoding\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mrabarnett/mrab-regex/commit/910784fb8039c445a68e84a261119a96031c811c\"\u003e\u003ccode\u003e910784f\u003c/code\u003e\u003c/a\u003e Propagate detach_string slicing errors\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/mrabarnett/mrab-regex/compare/2026.2.28...2026.9.10\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `requests` from 2.32.3 to 2.34.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/psf/requests/releases\"\u003erequests's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.34.2\u003c/h2\u003e\n\u003ch2\u003e2.34.2 (2026-05-14)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMoved \u003ccode\u003eheaders\u003c/code\u003e input type back to \u003ccode\u003eMapping\u003c/code\u003e to avoid invariance issues with \u003ccode\u003eMutableMapping\u003c/code\u003e and inferred dict types. Users calling \u003ccode\u003eRequest.headers.update()\u003c/code\u003e may need to narrow typing in their code. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7441\"\u003e#7441\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/psf/requests/blob/main/HISTORY.md#2342-2026-05-14\"\u003ehttps://github.com/psf/requests/blob/main/HISTORY.md#2342-2026-05-14\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.34.1\u003c/h2\u003e\n\u003ch2\u003e2.34.1 (2026-05-13)\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eBugfixes\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eWidened \u003ccode\u003ejson\u003c/code\u003e input type from \u003ccode\u003edict\u003c/code\u003e and \u003ccode\u003elist\u003c/code\u003e to \u003ccode\u003eMapping\u003c/code\u003e\nand \u003ccode\u003eSequence\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7436\"\u003e#7436\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eChanged \u003ccode\u003eheaders\u003c/code\u003e input type to MutableMapping and removed \u003ccode\u003eNone\u003c/code\u003e from\n\u003ccode\u003eRequest.headers\u003c/code\u003e typing to improve handling for users. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7431\"\u003e#7431\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eResponse.reason\u003c/code\u003e moved from \u003ccode\u003estr | None\u003c/code\u003e to \u003ccode\u003estr\u003c/code\u003e to improve handling\nfor users. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7437\"\u003e#7437\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed a bug where some bodies with custom \u003ccode\u003e__getattr__\u003c/code\u003e implementations\nweren't being properly detected as Iterables. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7433\"\u003e#7433\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/k223kim\"\u003e\u003ccode\u003e@​k223kim\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/psf/requests/pull/7433\"\u003epsf/requests#7433\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/psf/requests/blob/main/HISTORY.md#2341-2026-05-13\"\u003ehttps://github.com/psf/requests/blob/main/HISTORY.md#2341-2026-05-13\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.34.0\u003c/h2\u003e\n\u003ch2\u003e2.34.0 (2026-05-11)\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eAnnouncements\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eRequests 2.34.0 introduces inline types, replacing those provided by\ntypeshed. Public API types should be fully compatible with mypy, pyright,\nand ty. \u003cstrong\u003eWe believe types are comprehensive but if you find issues, please\nreport them to the \u003ca href=\"https://redirect.github.com/psf/requests/issues/7271\"\u003epinned tracking issue\u003c/a\u003e.\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eSpecial thanks to \u003ca href=\"https://github.com/bastimeyer\"\u003e\u003ccode\u003e@​bastimeyer\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/cthoyt\"\u003e\u003ccode\u003e@​cthoyt\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/edgarrmondragon\"\u003e\u003ccode\u003e@​edgarrmondragon\u003c/code\u003e\u003c/a\u003e, and \u003ca href=\"https://github.com/srittau\"\u003e\u003ccode\u003e@​srittau\u003c/code\u003e\u003c/a\u003e for\nhelping review and test the types ahead of the release. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7272\"\u003e#7272\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eImprovements\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eDigest Auth hashing algorithms have added \u003ccode\u003eusedforsecurity=False\u003c/code\u003e to clarify\nsecurity considerations. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7310\"\u003e#7310\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests added support for Python 3.15 based on beta1. Downstream projects\nshould be able to start testing prior to its release in October. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7422\"\u003e#7422\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests added support for Python 3.14t. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7419\"\u003e#7419\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eBugfixes\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eResponse.history\u003c/code\u003e no longer contains a reference to itself, preventing\naccidental looping when traversing the history list. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7328\"\u003e#7328\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests no longer performs greedy matching on no_proxy domains. The\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/psf/requests/blob/main/HISTORY.md\"\u003erequests's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e2.34.2 (2026-05-14)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMoved \u003ccode\u003eheaders\u003c/code\u003e input type back to \u003ccode\u003eMapping\u003c/code\u003e to avoid invariance issues\nwith \u003ccode\u003eMutableMapping\u003c/code\u003e and inferred dict types. Users calling\n\u003ccode\u003eRequest.headers.update()\u003c/code\u003e may need to narrow typing in their code. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7441\"\u003e#7441\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.34.1 (2026-05-13)\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eBugfixes\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eWidened \u003ccode\u003ejson\u003c/code\u003e input type from \u003ccode\u003edict\u003c/code\u003e and \u003ccode\u003elist\u003c/code\u003e to \u003ccode\u003eMapping\u003c/code\u003e\nand \u003ccode\u003eSequence\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7436\"\u003e#7436\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eChanged \u003ccode\u003eheaders\u003c/code\u003e input type to MutableMapping and removed \u003ccode\u003eNone\u003c/code\u003e from\n\u003ccode\u003eRequest.headers\u003c/code\u003e typing to improve handling for users. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7431\"\u003e#7431\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eResponse.reason\u003c/code\u003e moved from \u003ccode\u003estr | None\u003c/code\u003e to \u003ccode\u003estr\u003c/code\u003e to improve handling\nfor users. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7437\"\u003e#7437\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed a bug where some bodies with custom \u003ccode\u003e__getattr__\u003c/code\u003e implementations\nweren't being properly detected as Iterables. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7433\"\u003e#7433\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.34.0 (2026-05-11)\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eAnnouncements\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eRequests 2.34.0 introduces inline types, replacing those provided by\ntypeshed. Public API types should be fully compatible with mypy, pyright,\nand ty. We believe types are comprehensive but if you find issues, please\nreport them to the pinned tracking issue.\u003c/p\u003e\n\u003cp\u003eSpecial thanks to \u003ca href=\"https://github.com/bastimeyer\"\u003e\u003ccode\u003e@​bastimeyer\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/cthoyt\"\u003e\u003ccode\u003e@​cthoyt\u003c/code\u003e\u003c/a\u003e, \u003ca href=\"https://github.com/edgarrmondragon\"\u003e\u003ccode\u003e@​edgarrmondragon\u003c/code\u003e\u003c/a\u003e, and \u003ca href=\"https://github.com/srittau\"\u003e\u003ccode\u003e@​srittau\u003c/code\u003e\u003c/a\u003e for\nhelping review and test the types ahead of the release. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7272\"\u003e#7272\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eImprovements\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eDigest Auth hashing algorithms have added \u003ccode\u003eusedforsecurity=False\u003c/code\u003e to clarify\nsecurity considerations. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7310\"\u003e#7310\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests added support for Python 3.15 based on beta1. Downstream projects\nshould be able to start testing prior to its release in October. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7422\"\u003e#7422\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests added support for Python 3.14t. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7419\"\u003e#7419\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eBugfixes\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eResponse.history\u003c/code\u003e no longer contains a reference to itself, preventing\naccidental looping when traversing the history list. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7328\"\u003e#7328\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests no longer performs greedy matching on no_proxy domains. The\nproxy_bypass implementation has been updated with CPython's fix from\nbpo-39057. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7427\"\u003e#7427\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRequests no longer incorrectly strips duplicate leading slashes in\nURI paths. This should address user issues with specific presigned\nURLs. Note the full fix requires urllib3 2.7.0+. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7315\"\u003e#7315\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/6e83187b8feb273ed4c6cdab5efd8d54901dfab3\"\u003e\u003ccode\u003e6e83187\u003c/code\u003e\u003c/a\u003e v2.34.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/84d10f0be83e8f6aeca8a05230c52216431c4d0b\"\u003e\u003ccode\u003e84d10f0\u003c/code\u003e\u003c/a\u003e Move Request.headers back to Mapping (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7441\"\u003e#7441\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/b7b549b54571d03950b16afd2d01bc6ff0348224\"\u003e\u003ccode\u003eb7b549b\u003c/code\u003e\u003c/a\u003e v2.34.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/e511bc72777a94c45d004e010c597925092e1efe\"\u003e\u003ccode\u003ee511bc7\u003c/code\u003e\u003c/a\u003e Fix mutability issues with headers input types (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7431\"\u003e#7431\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/5691f596134c2feb121e595c77a0178921fcce61\"\u003e\u003ccode\u003e5691f59\u003c/code\u003e\u003c/a\u003e Update JsonType containers to read-based collections (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7436\"\u003e#7436\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/2144213c307691710c9d665700860fc4993c3035\"\u003e\u003ccode\u003e2144213\u003c/code\u003e\u003c/a\u003e Constrain Response.reason to str (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7437\"\u003e#7437\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/6404f345e562d962abe6700a1c357ec1e7e18232\"\u003e\u003ccode\u003e6404f34\u003c/code\u003e\u003c/a\u003e Fix \u003ccode\u003eprepare_body\u003c/code\u003e stream detection for \u003ccode\u003e__getattr__\u003c/code\u003e-based file wrappers (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7\"\u003e#7\u003c/a\u003e...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/0b401c76b6e80a4eecf3c690085b2553f6e261ca\"\u003e\u003ccode\u003e0b401c7\u003c/code\u003e\u003c/a\u003e v2.34.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/86b378d3f60f828daa13ca50aa82e287ff7b66b4\"\u003e\u003ccode\u003e86b378d\u003c/code\u003e\u003c/a\u003e Align Session.get parameters with requests.get (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7429\"\u003e#7429\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/a4f9a5999bdb9bf2d6e7c8aa973b28cacb17134f\"\u003e\u003ccode\u003ea4f9a59\u003c/code\u003e\u003c/a\u003e Port bpo-39057 to Requests (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7427\"\u003e#7427\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/psf/requests/compare/v2.32.3...v2.34.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `tqdm` from 4.67.3 to 4.70.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/tqdm/tqdm/releases\"\u003etqdm's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003etqdm v4.70.1 stable\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003econtrib.concurrent\u003c/code\u003e: fix no-len iterables (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1830\"\u003e#1830\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1828\"\u003e#1828\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003etests: major overhaul (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1819\"\u003e#1819\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eupdate AI policy in PR template\u003c/li\u003e\n\u003cli\u003emisc lint \u0026amp; tidy\u003c/li\u003e\n\u003cli\u003eCI: bump workflow actions \u0026amp; pre-commit hooks\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003etqdm v4.70.0 stable\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003econtrib.concurrent\u003c/code\u003e: major improvements\n\u003cul\u003e\n\u003cli\u003esupport \u003ccode\u003eprocess_map(mp_context, max_tasks_per_child)\u003c/code\u003e, \u003ccode\u003ethread_map(thread_name_prefix)\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1265\"\u003e#1265\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix \u003ccode\u003etotal\u003c/code\u003e based on shortest iterable length (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1473\"\u003e#1473\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003euse default \u003ccode\u003emax_workers\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1543\"\u003e#1543\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1530\"\u003e#1530\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1518\"\u003e#1518\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003esupport \u003ccode\u003etimeout\u003c/code\u003e, \u003ccode\u003ebuffersize\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1576\"\u003e#1576\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eimprove ETA (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1708\"\u003e#1708\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1161\"\u003e#1161\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eupdate \u003ccode\u003eas_completed\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1709\"\u003e#1709\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1565\"\u003e#1565\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eadd \u003ccode\u003etqdm.concurrent.intepreter_map\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1777\"\u003e#1777\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003easyncio\u003c/code\u003e: support iterables with only \u003ccode\u003e__aiter__\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1714\"\u003e#1714\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1686\"\u003e#1686\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003esupport \u003ccode\u003ereset(float(\u0026quot;inf\u0026quot;))\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1783\"\u003e#1783\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1781\"\u003e#1781\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/651\"\u003e#651\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eframework: test \u0026amp; reduce wheel size (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1782\"\u003e#1782\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003etqdm v4.69.1 stable\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003econtrib.logging\u003c/code\u003e: preserve filters (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1775\"\u003e#1775\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1581\"\u003e#1581\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003erich\u003c/code\u003e: misc fixes (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1773\"\u003e#1773\u003c/a\u003e)\n\u003cul\u003e\n\u003cli\u003esupport generators (without \u003ccode\u003elen\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1391\"\u003e#1391\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix potential \u003ccode\u003eAttributeError\u003c/code\u003e on exit (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1674\"\u003e#1674\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003efix \u003ccode\u003etotal=float('inf')\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1781\"\u003e#1781\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/651\"\u003e#651\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix potential \u003ccode\u003eAttributeError\u003c/code\u003e on exit (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1778\"\u003e#1778\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1668\"\u003e#1668\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1537\"\u003e#1537\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/261\"\u003e#261\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix minor docs typos (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1780\"\u003e#1780\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1746\"\u003e#1746\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003etqdm v4.69.0 stable\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eadd \u003ccode\u003etqdm.asyncio.gather(..., return_exceptions=False)\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1776\"\u003e#1776\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1671\"\u003e#1671\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1286\"\u003e#1286\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003emisc minor framework updates\n\u003cul\u003e\n\u003cli\u003ebump workflow actions \u0026amp; pre-commit hooks\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003etqdm v4.68.4 stable\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003etrim to \u003ccode\u003encols\u003c/code\u003e even when \u003ccode\u003e'{bar}' not in bar_format\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1717\"\u003e#1717\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1767\"\u003e#1767\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1658\"\u003e#1658\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix \u003ccode\u003etqdm.write\u003c/code\u003e when \u003ccode\u003estdout=None\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1768\"\u003e#1768\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1654\"\u003e#1654\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003etqdm v4.68.3 stable\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eutils\u003c/code\u003e: delay \u003ccode\u003eos.get_terminal_size\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1763\"\u003e#1763\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1760\"\u003e#1760\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eautonotebook\u003c/code\u003e: support QtConsole, Spyder, JupyterLite (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1763\"\u003e#1763\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1628\"\u003e#1628\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1559\"\u003e#1559\u003c/a\u003e \u0026lt;- \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1283\"\u003e#1283\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1098\"\u003e#1098\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/512\"\u003e#512\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eminor docs updates\n\u003cul\u003e\n\u003cli\u003efix typo (\u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1762\"\u003e#1762\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003euse \u003ccode\u003egit-fame\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003emisc minor framework updates\n\u003cul\u003e\n\u003cli\u003efix \u0026amp; update CI build\u003c/li\u003e\n\u003cli\u003epre-commit: add docs \u0026amp; metadata generation\u003c/li\u003e\n\u003cli\u003emove \u003ccode\u003etox.ini\u003c/code\u003e -\u0026gt; \u003ccode\u003epyproject.toml\u003c/code\u003e, move \u003ccode\u003etox-gh-actions\u003c/code\u003e -\u0026gt; \u003ccode\u003etox-gh\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eadd Python 3.14, drop 3.7 support\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/9cf5a12b1f955468a17f0ba3c59092b23e4258ac\"\u003e\u003ccode\u003e9cf5a12\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1830\"\u003e#1830\u003c/a\u003e from eaubin/master\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/24b9e1e08a097f1c30f2d235b63f9eb25ba47974\"\u003e\u003ccode\u003e24b9e1e\u003c/code\u003e\u003c/a\u003e misc tidy\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/2a9e4e82ddba07c5dd6d126e23a4745b76ea49c8\"\u003e\u003ccode\u003e2a9e4e8\u003c/code\u003e\u003c/a\u003e contrib.concurrent: fix no-len iterables\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/8d6ff8de5a9066de77d0a9df3e80a022a3dcf146\"\u003e\u003ccode\u003e8d6ff8d\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/tqdm/tqdm/issues/1819\"\u003e#1819\u003c/a\u003e from tqdm/devel\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/bed379609c2c8300671c784c8f85a185c8cf6fb3\"\u003e\u003ccode\u003ebed3796\u003c/code\u003e\u003c/a\u003e tests: major overhaul\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/4d3d3194d5467e0701bc0f4b836a735273ef0868\"\u003e\u003ccode\u003e4d3d319\u003c/code\u003e\u003c/a\u003e AI policy\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/5dcb022b55553b60ed2131b64aa5bf1e65470df1\"\u003e\u003ccode\u003e5dcb022\u003c/code\u003e\u003c/a\u003e minor syntax update\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/309effe4244bf45427c5add7f1bcf33f98a7b421\"\u003e\u003ccode\u003e309effe\u003c/code\u003e\u003c/a\u003e tests: pre-commit coverage\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/604193aa03b5f5c0ad5f3d441951f0fbb515f1e4\"\u003e\u003ccode\u003e604193a\u003c/code\u003e\u003c/a\u003e tests: slight tidy\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tqdm/tqdm/commit/17f1cac07c89943eb0e6082875b3821205308d4f\"\u003e\u003ccode\u003e17f1cac\u003c/code\u003e\u003c/a\u003e CI: bump workflow actions\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/tqdm/tqdm/compare/v4.67.3...v4.70.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `transformers` from 5.15.0 to 5.17.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/huggingface/transformers/releases\"\u003etransformers's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eRelease 5.17.0\u003c/h2\u003e\n\u003ch1\u003eRelease v5.17.0\u003c/h1\u003e\n\u003ch2\u003eNew Model additions\u003c/h2\u003e\n\u003ch3\u003eHYV4\u003c/h3\u003e\n\n\u003cp\u003eHy4-Preview is a 780B-parameter mixture-of-experts language model that activates 49B parameters per\ntoken. Each MoE layer holds 256 routed experts plus one always-active shared expert and routes every\ntoken to 8 of them. The context window is 1M tokens.\u003c/p\u003e\n\u003cp\u003eThe architecture combines four features:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eMulti-head Latent Attention (MLA)\u003c/strong\u003e compresses keys and values into a low-rank latent\n(\u003ccode\u003ekv_lora_rank\u003c/code\u003e) that \u003ccode\u003ekv_b_proj\u003c/code\u003e expands back to one key/value per query head.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eDeepSeek Sparse Attention (DSA)\u003c/strong\u003e selects \u003ccode\u003eindex_topk\u003c/code\u003e keys per query with a lightweight indexer.\nFollowing \u003ca href=\"https://huggingface.co/papers/2603.12201\"\u003eIndexShare\u003c/a\u003e, only the layers marked \u003ccode\u003e\u0026quot;full\u0026quot;\u003c/code\u003e\nin \u003ccode\u003eindexer_types\u003c/code\u003e run an indexer; \u003ccode\u003e\u0026quot;shared\u0026quot;\u003c/code\u003e layers reuse the previous full layer's selection.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eGated MLA with learnable attention sinks\u003c/strong\u003e, where each head owns a sink logit that participates\nin the softmax and contributes no value, as in \u003ca href=\"https://github.com/huggingface/transformers/blob/HEAD/gpt_oss\"\u003eGPT-OSS\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eIndependent Hyper-Connections (iHC)\u003c/strong\u003e replace the plain residual path with \u003ccode\u003ehc_mult\u003c/code\u003e parallel\nresidual streams that are collapsed before, and redistributed after, every sublayer.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThe implementation does not execute the multi-token prediction (MTP) layers. Released checkpoints\nkeep those weights so that other runtimes can use them for speculative decoding; they are ignored\nat load time.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/hy_v4\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAdd h4 (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48473\"\u003e#48473\u003c/a\u003e) by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/transformers/pull/48473\"\u003e#48473\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eVibeVoice\u003c/h3\u003e\n\n\u003cp\u003e\u003ca href=\"https://huggingface.co/papers/2508.19205\"\u003eVibeVoice\u003c/a\u003e is a novel framework for synthesizing high-fidelity, long-form speech with multiple speakers by employing a next-token diffusion approach within a Large Language Model (LLM) structure. It's designed to capture the authentic conversational \u0026quot;vibe\u0026quot; and is particularly suited for generating audio content like podcasts and multi-participant audiobooks.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/vibevoice\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eImplement VibeVoice  (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/40546\"\u003e#40546\u003c/a\u003e) by \u003ca href=\"https://github.com/pengzhiliang\"\u003e\u003ccode\u003e@​pengzhiliang\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/transformers/pull/40546\"\u003e#40546\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eNeoMME\u003c/h3\u003e\n\u003cp\u003eNeoMME is a family of efficient 260M and 800M parameter multimodal-native multilingual foundation encoders from H Company. It processes multilingual text tokens and raw image patches in a single bidirectional Transformer encoder, without a separately pretrained vision tower or causal language model.\u003c/p\u003e\n\u003cp\u003eNeoMME-Retriever is a model fine-tuned from the NeoMME backbone for visual document retrieval with joint late-interaction and dense objectives. It takes text queries and documents (text or page screenshots) and produces multi-vector embeddings for MeanMaxSim scoring (late-interaction) and mean-pooled embeddings for cosine similarity (dense).\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/neomme\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/856157a2f3e9594954310df18fdccc31ffddebe9\"\u003e\u003ccode\u003e856157a\u003c/code\u003e\u003c/a\u003e v5.17.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/5b7dcb0d36c242d8d85920a81c564ef3a86ca6dd\"\u003e\u003ccode\u003e5b7dcb0\u003c/code\u003e\u003c/a\u003e MRoPE continued (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48594\"\u003e#48594\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/50bbcc630ed1675d15d2def3877c88d6c2630415\"\u003e\u003ccode\u003e50bbcc6\u003c/code\u003e\u003c/a\u003e [fix] Update stale expected strings in HunYuanVL integration tests (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48646\"\u003e#48646\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/e8bcd79c4c77a529bc34d6e19f7d718164b7fa6a\"\u003e\u003ccode\u003ee8bcd79\u003c/code\u003e\u003c/a\u003e [Quantizaiton]support 5/6/7 bits in AutoRound (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48481\"\u003e#48481\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/3283d5f78ed6836d39430c8190a6e0500be78698\"\u003e\u003ccode\u003e3283d5f\u003c/code\u003e\u003c/a\u003e [fix] Update stale golden values and fix expected_logits shape in FlavaForPre...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/5f47b5aad791b69dff597b903614fb2bef8b88a1\"\u003e\u003ccode\u003e5f47b5a\u003c/code\u003e\u003c/a\u003e [tests] Fix integration test golden values broken by fast image processor def...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/fc501343edfccdc840eb8594a6cafa8185c2de53\"\u003e\u003ccode\u003efc50134\u003c/code\u003e\u003c/a\u003e Add Fun-ASR-Nano model (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46180\"\u003e#46180\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/d9fe823d1cedbba33dd0aeef08f773abe971688e\"\u003e\u003ccode\u003ed9fe823\u003c/code\u003e\u003c/a\u003e Fix YOLOS device mismatch with device_map=\u0026quot;auto\u0026quot; (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46886\"\u003e#46886\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/cbc1651a032b923da7f4b44b3d0e6f68e6ba6b55\"\u003e\u003ccode\u003ecbc1651\u003c/code\u003e\u003c/a\u003e [\u003ccode\u003eGenerate\u003c/code\u003e] Avoid unconditionally downloading remote hub file (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48620\"\u003e#48620\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/bd05a4b2baf8b37b8f64c0c2c70d2628583f7c2a\"\u003e\u003ccode\u003ebd05a4b\u003c/code\u003e\u003c/a\u003e Honor \u003ccode\u003eshift_labels\u003c/code\u003e in decoder-only LLM/VLM losses (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48493\"\u003e#48493\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/huggingface/transformers/compare/v5.15.0...v5.17.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `huggingface-hub` from 1.28.0 to 1.32.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/huggingface/huggingface_hub/releases\"\u003ehuggingface-hub's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e[v1.32.0] Shared blob store, sandbox security hardening and faster imports\u003c/h2\u003e\n\u003ch2\u003e:open_file_folder: [Cache] Shared blob store: deduplicate Xet files across repos\u003c/h2\u003e\n\u003cp\u003eThe cache now deduplicates Xet files across repos. A Xet file downloaded through \u003ccode\u003ehf_xet\u003c/code\u003e is stored once at \u003ccode\u003e\u0026lt;CACHE_DIR\u0026gt;/blobs/\u0026lt;prefix\u0026gt;/\u0026lt;xet_hash\u0026gt;\u003c/code\u003e and every repo that needs it gets a relative symlink instead of a download: no bytes are transferred and no extra space is used, even across different repos — or after the repo that first downloaded the file was deleted. The per-repo snapshot layout is unchanged, older clients keep reading and downloading normally, and any failure to share silently falls back to regular repo-local storage. Set \u003ccode\u003eHF_HUB_DISABLE_SHARED_BLOBS=1\u003c/code\u003e to opt out entirely. Shared files carry a \u003ccode\u003e\u0026lt;xet_hash\u0026gt;.refs\u003c/code\u003e manifest listing the repo blobs referencing them, which \u003ccode\u003ehf cache rm\u003c/code\u003e consults on deletion and \u003ccode\u003ehf cache prune\u003c/code\u003e sweeps to reclaim payloads that no cached repo uses anymore.\u003c/p\u003e\n\u003cp\u003e📚 \u003cstrong\u003eDocumentation:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/huggingface_hub/main/en/guides/manage-cache\"\u003eManage your cache\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e[Cache] Add cross-repo shared blob store by \u003ca href=\"https://github.com/hanouticelina\"\u003e\u003ccode\u003e@​hanouticelina\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4498\"\u003e#4498\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e:computer: [Jobs] Ship config inside UV scripts\u003c/h2\u003e\n\u003cp\u003eA UV script that only runs correctly on a specific runtime can now carry that runtime with it. An optional \u003ccode\u003e[tool.hf-jobs]\u003c/code\u003e table in the script's PEP 723 header accepts \u003ccode\u003eimage\u003c/code\u003e, \u003ccode\u003eflavor\u003c/code\u003e, \u003ccode\u003epython\u003c/code\u003e, \u003ccode\u003etimeout\u003c/code\u003e, \u003ccode\u003ename\u003c/code\u003e, \u003ccode\u003enamespace\u003c/code\u003e, \u003ccode\u003eenv\u003c/code\u003e, \u003ccode\u003esecrets\u003c/code\u003e, \u003ccode\u003elabels\u003c/code\u003e, \u003ccode\u003evolumes\u003c/code\u003e, \u003ccode\u003enetwork_group\u003c/code\u003e and \u003ccode\u003enetwork_aliases\u003c/code\u003e, and \u003ccode\u003ehf jobs uv run\u003c/code\u003e reads it at submit time. CLI flags always win, and \u003ccode\u003eenv\u003c/code\u003e/\u003ccode\u003esecrets\u003c/code\u003e/\u003ccode\u003elabels\u003c/code\u003e/\u003ccode\u003evolumes\u003c/code\u003e merge entry by entry instead of being replaced, so \u003ccode\u003e-e\u003c/code\u003e/\u003ccode\u003e-v\u003c/code\u003e add to what the script declares. Typos and unknown keys are rejected with the list of valid options, secrets are passed by name only (values come from your environment), and every run prints a config summary with script-sourced values marked and secrets redacted. Note that the table is read by the CLI only: \u003ccode\u003erun_uv_job()\u003c/code\u003e and \u003ccode\u003ecreate_scheduled_uv_job()\u003c/code\u003e ignore it.\u003c/p\u003e\n\u003cpre lang=\"python\"\u003e\u003ccode\u003e# /// script\r\n# requires-python = \u0026quot;\u0026gt;=3.11\u0026quot;\r\n# dependencies = [\u0026quot;vllm\u0026quot;, \u0026quot;datasets\u0026quot;]\r\n#\r\n# [tool.hf-jobs]\r\n# image   = \u0026quot;vllm/vllm-openai:unlimited-ocr\u0026quot;\r\n# flavor  = \u0026quot;l4x1\u0026quot;\r\n# python  = \u0026quot;/usr/bin/python3\u0026quot;\r\n# secrets = [\u0026quot;HF_TOKEN\u0026quot;]\r\n# ///\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003e📚 \u003cstrong\u003eDocumentation:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/huggingface_hub/main/en/guides/jobs\"\u003eRun and manage Jobs\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e[CLI] Read a UV script's \u003ccode\u003e[tool.hf-jobs]\u003c/code\u003e launch config (opus-generated) by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4598\"\u003e#4598\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🛡️ [Sandbox] security hardening\u003c/h2\u003e\n\u003cp\u003eAn internal security review of the Sandbox API resulted in a 9-PR hardening series. Pooled sandboxes now use their own per-sandbox capability token instead of the host-wide credential, pool hosts are fully validated (initiator, namespace, image, flavor, command, URL) before any credential is sent to them, the \u003ccode\u003esbx-server\u003c/code\u003e binary is pinned by digest and verified before being run as PID 1, and the local pool cache is bound to the endpoint, credential and namespace that wrote it. Secret values no longer end up in \u003ccode\u003eargv\u003c/code\u003e when using \u003ccode\u003ehf sandbox exec --secrets\u003c/code\u003e, background processes are addressed by their server-assigned id (so \u003ccode\u003ekill()\u003c/code\u003e actually stops them and reports honestly), transfers and command output are bounded to avoid unbounded memory usage in the client, and pool ownership is decided per host so a \u003ccode\u003ewith SandboxPool(...)\u003c/code\u003e block never again tears down a colleague's discovered host. The security documentation was also rewritten to state precisely what the sandbox contract is — and what it is not — including a new \u0026quot;Known limitations\u0026quot; section.\u003c/p\u003e\n\u003cp\u003e📚 \u003cstrong\u003eDocumentation:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/huggingface_hub/main/en/guides/sandbox\"\u003eSandboxes\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e[sandbox audit] Make the sandbox security contract match the implementation by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4831\"\u003e#4831\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[sandbox audit] Use each pooled sandbox's own capability token by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4832\"\u003e#4832\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[sandbox audit] Validate a pool host before sending it a credential by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4834\"\u003e#4834\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[sandbox audit] Bind the sandbox pool cache to the endpoint, credential and namespace that wrote it by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4838\"\u003e#4838\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[sandbox audit] Bound what a transfer or a command's output costs the client by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4839\"\u003e#4839\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[sandbox audit] Decide host teardown per host, and report it honestly by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4840\"\u003e#4840\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[sandbox audit] Address background processes by their server-assigned id by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4836\"\u003e#4836\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[sandbox audit] Pin the sandbox server binary by digest and verify it before running it by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4837\"\u003e#4837\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[sandbox audit] Keep secret values out of argv in the CLI and fix the env/secrets docs by \u003ca href=\"https://github.com/Wauplin\"\u003e\u003ccode\u003e@​Wauplin\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4835\"\u003e#4835\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🔒 Security hardening for serialization and validation\u003c/h2\u003e\n\u003cp\u003eThree changes make the library safer against malicious or malformed inputs, with a stricter behavior worth noting. Torch checkpoint deserialization was hardened across 11 reported vulnerabilities: \u003ccode\u003eload_state_dict_from_file\u003c/code\u003e now defaults to \u003ccode\u003esafe=True\u003c/code\u003e (always using the safetensors loader), the pickle path defaults to \u003ccode\u003eweights_only=True\u003c/code\u003e, and unsafe combinations raise explicit errors instead of silently falling through. Path validation now rejects \u003ccode\u003e..\u003c/code\u003e segments anywhere in \u003ccode\u003epath_in_repo\u003c/code\u003e (previously only a leading one was caught), so uploads like \u003ccode\u003e\u0026quot;a/../../etc/passwd\u0026quot;\u003c/code\u003e are refused. Finally, \u003ccode\u003erepo_id\u003c/code\u003e validation is restricted to ASCII word characters as documented, so non-ASCII ids like \u003ccode\u003ecafé\u003c/code\u003e are rejected client-side instead of failing later on the Hub.\u003c/p\u003e\n\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/8814aabc81298df547bece9e71e4e88d3e513928\"\u003e\u003ccode\u003e8814aab\u003c/code\u003e\u003c/a\u003e Release: v1.32.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/445770606fa5ca80765a8e7a3d6e8cfaacaf7919\"\u003e\u003ccode\u003e4457706\u003c/code\u003e\u003c/a\u003e Release: v1.32.0.rc0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/b064a14629f9cdf3622e3fcac52c4f0e4e58c6b6\"\u003e\u003ccode\u003eb064a14\u003c/code\u003e\u003c/a\u003e [Download] Send X-HF-Download-Counter header on download calls (\u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4613\"\u003e#4613\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/79dd41ed6dec58314dad130fe7b8b578c8a1737d\"\u003e\u003ccode\u003e79dd41e\u003c/code\u003e\u003c/a\u003e [Docs] Fix hf discussions info options that do not exist (\u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4886\"\u003e#4886\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/d7b62c7becb6ba75667ab2c5b32d9338bcd5a4d4\"\u003e\u003ccode\u003ed7b62c7\u003c/code\u003e\u003c/a\u003e [CLI] Fix card data serialization (\u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4882\"\u003e#4882\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/f94ea55533a6fc796f191723823217fe75dfd462\"\u003e\u003ccode\u003ef94ea55\u003c/code\u003e\u003c/a\u003e [Buckets] Send mtime when copying files (\u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4920\"\u003e#4920\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/6e3d21f5d5a663468e58b37e6b94871e97534c24\"\u003e\u003ccode\u003e6e3d21f\u003c/code\u003e\u003c/a\u003e [Cache] Add cross-repo shared blob store (\u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4498\"\u003e#4498\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/5a9cdda63f231a1b57a05eab88dc4357c790ba87\"\u003e\u003ccode\u003e5a9cdda\u003c/code\u003e\u003c/a\u003e [Core] Speed up package imports (\u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4914\"\u003e#4914\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/2075fd68e69297eed60e1b058ef9b67b742b505d\"\u003e\u003ccode\u003e2075fd6\u003c/code\u003e\u003c/a\u003e [Cache] Support kernel repos in \u003ccode\u003ehf cache\u003c/code\u003e commands (\u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4905\"\u003e#4905\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/huggingface_hub/commit/af6b41ece7448c5d7531699376c6f5974a2d24cc\"\u003e\u003ccode\u003eaf6b41e\u003c/code\u003e\u003c/a\u003e [Core] Reject path traversal via embedded \u0026quot;..\u0026quot; segments in path_in_repo (\u003ca href=\"https://redirect.github.com/huggingface/huggingface_hub/issues/4884\"\u003e#4884\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/huggingface/huggingface_hub/compare/v1.28.0...v1.32.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `tokenizers` from 0.22.2 to 0.23.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/huggingface/tokenizers/releases\"\u003etokenizers's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev0.23.2\u003c/h2\u003e\n\u003cp\u003eThis is the last v0 release, we are moving to v1!!\u003c/p\u003e\n\u003cp\u003eMore details coming soon 👀\u003c/p\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate daachorse from 1.0.1 to 3.0.0 by \u003ca href=\"https://github.com/musicinmybrain\"\u003e\u003ccode\u003e@​musicinmybrain\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2050\"\u003ehuggingface/tokenizers#2050\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eCi test fixes by \u003ca href=\"https://github.com/sebpop\"\u003e\u003ccode\u003e@​sebpop\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2079\"\u003ehuggingface/tokenizers#2079\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAvoid full vocab clone in get_vocab_size() by \u003ca href=\"https://github.com/eunseo9311\"\u003e\u003ccode\u003e@​eunseo9311\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2074\"\u003ehuggingface/tokenizers#2074\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: pin benchmark jobs to a larger dedicated runner by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2084\"\u003ehuggingface/tokenizers#2084\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: target benchmark runners by group, not nonexistent label by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2090\"\u003ehuggingface/tokenizers#2090\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBindings: acquire model read-lock once per call instead of per pre-token by \u003ca href=\"https://github.com/sebpop\"\u003e\u003ccode\u003e@​sebpop\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2072\"\u003ehuggingface/tokenizers#2072\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: split audit in a separate job by \u003ca href=\"https://github.com/SBrandeis\"\u003e\u003ccode\u003e@​SBrandeis\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2103\"\u003ehuggingface/tokenizers#2103\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: install libcairo on benchmark runners by \u003ca href=\"https://github.com/SBrandeis\"\u003e\u003ccode\u003e@​SBrandeis\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2100\"\u003ehuggingface/tokenizers#2100\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(ci): enable npm's trusted publisher for releases by \u003ca href=\"https://github.com/McPatate\"\u003e\u003ccode\u003e@​McPatate\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2111\"\u003ehuggingface/tokenizers#2111\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: bump pyo3 to version 0.29 by \u003ca href=\"https://github.com/SBrandeis\"\u003e\u003ccode\u003e@​SBrandeis\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2115\"\u003ehuggingface/tokenizers#2115\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eperf: add benchmarks for the \u003ccode\u003edecode\u003c/code\u003e API by \u003ca href=\"https://github.com/SBrandeis\"\u003e\u003ccode\u003e@​SBrandeis\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2099\"\u003ehuggingface/tokenizers#2099\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: cache HF test data and authenticate Hub downloads to avoid rate limits by \u003ca href=\"https://github.com/SBrandeis\"\u003e\u003ccode\u003e@​SBrandeis\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2102\"\u003ehuggingface/tokenizers#2102\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eImplementing Parity-aware BPE by \u003ca href=\"https://github.com/cimeister\"\u003e\u003ccode\u003e@​cimeister\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/1974\"\u003ehuggingface/tokenizers#1974\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eMake doc builds faster by \u003ca href=\"https://github.com/mishig25\"\u003e\u003ccode\u003e@​mishig25\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2158\"\u003ehuggingface/tokenizers#2158\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(deps-dev): bump websocket-driver from 0.7.4 to 0.7.5 in /tokenizers/examples/unstable_wasm/www by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2208\"\u003ehuggingface/tokenizers#2208\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(deps-dev): bump shell-quote from 1.8.3 to 1.10.0 in /tokenizers/examples/unstable_wasm/www by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2244\"\u003ehuggingface/tokenizers#2244\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: remove stale examples (kills 50% of dependabot traffic) by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2285\"\u003ehuggingface/tokenizers#2285\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(node): drop 8 unused devDependencies by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2286\"\u003ehuggingface/tokenizers#2286\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: pin every action to one SHA, drop stale audit suppressions by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2291\"\u003ehuggingface/tokenizers#2291\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(node): take node security alerts from 33 to 0 by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2287\"\u003ehuggingface/tokenizers#2287\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(python): pin the ruff rule set so a ruff release can't redden main by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2292\"\u003ehuggingface/tokenizers#2292\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd a ParityBpeTrainer example and list it in the trainers API docs by \u003ca href=\"https://github.com/cimeister\"\u003e\u003ccode\u003e@​cimeister\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2217\"\u003ehuggingface/tokenizers#2217\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eunseo9311\"\u003e\u003ccode\u003e@​eunseo9311\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/2074\"\u003ehuggingface/tokenizers#2074\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cimeister\"\u003e\u003ccode\u003e@​cimeister\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/pull/1974\"\u003ehuggingface/tokenizers#1974\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/huggingface/tokenizers/compare/v0.23.1...v0.23.2\"\u003ehttps://github.com/huggingface/tokenizers/compare/v0.23.1...v0.23.2\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eRelease v0.23.1\u003c/h2\u003e\n\u003ch2\u003eTL;DR\u003c/h2\u003e\n\u003cp\u003e\u003ccode\u003etokenizers 0.23.1\u003c/code\u003e is the first proper stable release in the \u003ccode\u003e0.23\u003c/code\u003e line — \u003ccode\u003e0.23.0\u003c/code\u003e only ever shipped as \u003ccode\u003erc0\u003c/code\u003e because the release pipeline itself was broken (Node side hadn't shipped multi-platform binaries since 2023, Python side was on \u003ccode\u003epyo3 0.27\u003c/code\u003e without free-threaded support). \u003ccode\u003e0.23.1\u003c/code\u003e is the version where everything actually goes out the door together: full Node multi-platform wheels for the first time in years, Python 3.14 (regular \u003cstrong\u003eand\u003c/strong\u003e free-threaded \u003ccode\u003e3.14t\u003c/code\u003e), full type hints for every Python class, and a stack of measurable perf wins on the BPE / added-vocab hot paths.\u003c/p\u003e\n\u003cp\u003eThere is no functional \u003ccode\u003e0.23.0\u003c/code\u003e published — we tag \u003ccode\u003e0.23.1\u003c/code\u003e directly so users don't accidentally pull a never-shipped version.\u003c/p\u003e\n\u003chr /\u003e\n\u003ch2\u003e🚨 Breaking changes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eDrop Python 3.9\u003c/strong\u003e (\u003ca href=\"https://redirect.github.com/huggingface/tokenizers/issues/1952\"\u003e#1952\u003c/a\u003e) — \u003ccode\u003erequires-python = \u0026quot;\u0026gt;=3.10\u0026quot;\u003c/code\u003e; 3.9 users stay on \u003ccode\u003e0.22.x\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ccode\u003eadd_tokens\u003c/code\u003e normalizes \u003ccode\u003econtent\u003c/code\u003e at insertion\u003c/strong\u003e (\u003ca href=\"https://redirect.github.com/huggingface/tokenizers/issues/1995\"\u003e#1995\u003c/a\u003e) — re-saved \u003ccode\u003etokenizer.json\u003c/code\u003e may differ in the \u003ccode\u003eadded_tokens\u003c/code\u003e block. Existing files load unchanged.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eType stubs are precise\u003c/strong\u003e (\u003ca href=\"https://redirect.github.com/huggingface/tokenizers/issues/1928\"\u003e#1928\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/huggingface/tokenizers/issues/1997\"\u003e#1997\u003c/a\u003e) — methods that returned \u003ccode\u003eAny\u003c/code\u003e now return real types; \u003ccode\u003emypy --strict\u003c/code\u003e may surface previously-hidden errors. Stub layout also moved from \u003ccode\u003etokenizers/\u0026lt;sub\u0026gt;/__init__.pyi\u003c/code\u003e to \u003ccode\u003etokenizers/\u0026lt;sub\u0026gt;.pyi\u003c/code\u003e. This breaks the surface of some of the processors like \u003ccode\u003eRobertaProcessign\u003c/code\u003e's \u003ccode\u003e__init__\u003c/code\u003e .\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e3.14t-only\u003c/strong\u003e: setters/getters return \u003ccode\u003ePyResult\u0026lt;T\u0026gt;\u003c/code\u003e because of \u003ccode\u003eArc\u0026lt;RwLock\u0026lt;Tokenizer\u0026gt;\u0026gt;\u003c/code\u003e; a poisoned lock surfaces as \u003ccode\u003ePyException\u003c/code\u003e instead of a panic.\u003c/li\u003e\n\u003c/ul\u003e\n\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/tokenizers/commit/88a4498ad4ea1a9487b0a9b0ff881383fd5a06a3\"\u003e\u003ccode\u003e88a4498\u003c/code\u003e\u003c/a\u003e add lock\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/tokenizers/commit/e4ea65f27057e593656ff1335b95afe2e552b88d\"\u003e\u003ccode\u003ee4ea65f\u003c/code\u003e\u003c/a\u003e real release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/tokenizers/commit/7c5964b4afae7b710d254eacd5a9fa180ba2cfef\"\u003e\u003ccode\u003e7c5964b\u003c/code\u003e\u003c/a\u003e add lock\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/tokenizers/commit/bc405ad60991a0639f8b09b40f13f91c38e50e87\"\u003e\u003ccode\u003ebc405ad\u003c/code\u003e\u003c/a\u003e push rc0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/tokenizers/commit/d5827816baedcbf1cb5b452dea8048150b6872df\"\u003e\u003ccode\u003ed582781\u003c/code\u003e\u003c/a\u003e Add a ParityBpeTrainer example and list it in the trainers API docs (\u003ca href=\"https://redirect.github.com/huggingface/tokenizers/iss...\n\n_Description has been truncated_","html_url":"https://github.com/yhfgyyf/vllm-deepseek-v4-sm89/pull/119","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/yhfgyyf%2Fvllm-deepseek-v4-sm89/issues/119","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/119/packages"}},{"old_version":"3.14.1","new_version":"3.14.3","update_type":"patch","path":null,"pr_created_at":"2026-09-20T06:49:46.000Z","version_change":"3.14.1 → 3.14.3","issue":{"uuid":"5516302428","node_id":"PR_kwDOQeYl_s8AAAABESeotw","number":586,"state":"open","title":"chore(deps): bump the python-runtime group with 7 updates","user":"dependabot[bot]","labels":[],"assignees":[],"locked":false,"comments_count":3,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-20T06:49:46.000Z","updated_at":"2026-09-20T06:49:52.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps): bump","group_name":"python-runtime","update_count":7,"packages":[{"name":"xrpl-py","old_version":"5.0.0","new_version":"5.2.0","repository_url":"https://github.com/XRPLF/xrpl-py"},{"name":"numpy","old_version":"2.2.6","new_version":"2.5.3","repository_url":"https://github.com/numpy/numpy"},{"name":"opencv-python","old_version":"4.13.0.92","new_version":"5.0.0.93","repository_url":"https://github.com/opencv/opencv-python"},{"name":"pillow","old_version":"12.2.0","new_version":"12.3.0","repository_url":"https://github.com/python-pillow/Pillow"},{"name":"python-dotenv","old_version":"0.21.1","new_version":"1.2.3","repository_url":"https://github.com/theskumar/python-dotenv"},{"name":"aiohttp","old_version":"3.14.1","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"cryptography","old_version":"50.0.0","new_version":"50.0.1","repository_url":"https://github.com/pyca/cryptography"}],"path":null,"ecosystem":"pip"},"body":"Bumps the python-runtime group with 7 updates:\n\n| Package | From | To |\n| --- | --- | --- |\n| [xrpl-py](https://github.com/XRPLF/xrpl-py) | `5.0.0` | `5.2.0` |\n| [numpy](https://github.com/numpy/numpy) | `2.2.6` | `2.5.3` |\n| [opencv-python](https://github.com/opencv/opencv-python) | `4.13.0.92` | `5.0.0.93` |\n| [pillow](https://github.com/python-pillow/Pillow) | `12.2.0` | `12.3.0` |\n| [python-dotenv](https://github.com/theskumar/python-dotenv) | `0.21.1` | `1.2.3` |\n| [aiohttp](https://github.com/aio-libs/aiohttp) | `3.14.1` | `3.14.3` |\n| [cryptography](https://github.com/pyca/cryptography) | `50.0.0` | `50.0.1` |\n\nUpdates `xrpl-py` from 5.0.0 to 5.2.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/XRPLF/xrpl-py/releases\"\u003exrpl-py's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev5.2.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003echore(coderabbit): reduce review noise and load .ai-review/instructions.md by \u003ca href=\"https://github.com/arshjafri-ripple\"\u003e\u003ccode\u003e@​arshjafri-ripple\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/XRPLF/xrpl-py/pull/1024\"\u003eXRPLF/xrpl-py#1024\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: remove integration test requirement for beta releases by \u003ca href=\"https://github.com/pdp2121\"\u003e\u003ccode\u003e@​pdp2121\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/XRPLF/xrpl-py/pull/1039\"\u003eXRPLF/xrpl-py#1039\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSupport \u003ccode\u003efixCleanup3_4_0\u003c/code\u003e signing prefixes (\u003ccode\u003eSponsor\u003c/code\u003e) by \u003ca href=\"https://github.com/pdp2121\"\u003e\u003ccode\u003e@​pdp2121\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/XRPLF/xrpl-py/pull/1036\"\u003eXRPLF/xrpl-py#1036\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat: Support LendingProtocolV1_1 by \u003ca href=\"https://github.com/pdp2121\"\u003e\u003ccode\u003e@​pdp2121\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/XRPLF/xrpl-py/pull/1034\"\u003eXRPLF/xrpl-py#1034\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/XRPLF/xrpl-py/compare/v5.1.0...v5.2.0\"\u003ehttps://github.com/XRPLF/xrpl-py/compare/v5.1.0...v5.2.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev5.2.0b0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSet dependabot version update frequency to quarterly by \u003ca href=\"https://github.com/Patel-Raj11\"\u003e\u003ccode\u003e@​Patel-Raj11\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/XRPLF/xrpl-py/pull/898\"\u003eXRPLF/xrpl-py#898\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRelease pipeline by \u003ca href=\"https://github.com/shichengripple001\"\u003e\u003ccode\u003e@​shichengripple001\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/XRPLF/xrpl-py/pull/876\"\u003eXRPLF/xrpl-py#876\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix number serialization by \u003ca href=\"https://github.com/ckeshava\"\u003e\u003ccode\u003e@​ckeshava\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/XRPLF/xrpl-py/pull/900\"\u003eXRPLF/xrpl-py#900\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdates to the Lending-Protocol transactions by \u003ca href=\"https://github.com/ckeshava\"\u003e\u003ccode\u003e@​ckeshava\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/XRPLF/xrpl-py/pull/901\"\u003eXRPLF/xrpl-py#901\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003erefactor: improve int32 integration by \u003ca href=\"https://github.com/mvadari\"\u003e\u003ccode\u003e@​mvadari\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/XRPLF/xrpl-py/pull/902\"\u003eXRPLF/xrpl-py#902\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix \u003ccode\u003eRequest.from_xrpl\u003c/code\u003e by aliasing it to \u003ccode\u003eRequest.from_dict\u003c/code\u003e by \u003ca href=\"https://github.com/mvadari\"\u003e\u003ccode\u003e@​mvadari\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/XRPLF/xrpl-py/pull/892\"\u003eXRPLF/xrpl-py#892\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRelease 4.5.0: release-4.5.0 → main by \u003ca href=\"https://github.com/github-actions\"\u003e\u003ccode\u003e@​github-actions\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/XRPLF/xrpl-py/pull/904\"\u003eXRPLF/xrpl-py#904\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd pull request types to unit test workflow by \u003ca href=\"https://github.com/shichengripple001\"\u003e\u003ccode\u003e@​shichengripple001\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/XRPLF/xrpl-py/pull/911\"\u003eXRPLF/xrpl-py#911\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eDrop support for Python 3.8 by \u003ca href=\"https://github.com/kuan121\"\u003e\u003ccode\u003e@​kuan121\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/XRPLF/xrpl-py/pull/917\"\u003eXRPLF/xrpl-py#917\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(deps): bump aquasecurity/trivy-action from 0.33.1 to 0.34.0 in /.github/workflows by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/XRPLF/xrpl-py/pull/912\"\u003eXRPLF/xrpl-py#912\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: incorrect SField definitions for Lending Protocols and DynamicMPTs by \u003ca href=\"https://github.com/pdp2121\"\u003e\u003ccode\u003e@​pdp2121\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/XRPLF/xrpl-py/pull/918\"\u003eXRPLF/xrpl-py#918\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eupdate trivy-action version by \u003ca href=\"https://github.com/Patel-Raj11\"\u003e\u003ccode\u003e@​Patel-Raj11\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/XRPLF/xrpl-py/pull/922\"\u003eXRPLF/xrpl-py#922\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix _calculate_precision by \u003ca href=\"https://github.com/Patel-Raj11\"\u003e\u003ccode\u003e@​Patel-Raj11\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/XRPLF/xrpl-py/pull/924\"\u003eXRPLF/xrpl-py#924\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eDrop python 3.9 support by \u003ca href=\"https://github.com/Patel-Raj11\"\u003e\u003ccode\u003e@​Patel-Raj11\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/XRPLF/xrpl-py/pull/940\"\u003eXRPLF/xrpl-py#940\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate default algorithm in\u003ccode\u003eWallet\u003c/code\u003e class (breaking change) by \u003ca href=\"https://github.com/ckeshava\"\u003e\u003ccode\u003e@​ckeshava\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/XRPLF/xrpl-py/pull/942\"\u003eXRPLF/xrpl-py#942\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(deps): quarterly batch dependency upgrade 2026-Q2 by \u003ca href=\"https://github.com/Patel-Raj11\"\u003e\u003ccode\u003e@​Patel-Raj11\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/XRPLF/xrpl-py/pull/995\"\u003eXRPLF/xrpl-py#995\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eCollection of bug-fixes by \u003ca href=\"https://github.com/ckeshava\"\u003e\u003ccode\u003e@​ckeshava\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/XRPLF/xrpl-py/pull/993\"\u003eXRPLF/xrpl-py#993\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: docker path for integration test by \u003ca href=\"https://github.com/pdp2121\"\u003e\u003ccode\u003e@​pdp2121\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/XRPLF/xrpl-py/pull/1003\"\u003eXRPLF/xrpl-py#1003\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: preserve significant trailing zeros in \u003ccode\u003eAmount.to_json\u003c/code\u003e for IOU values by \u003ca href=\"https://github.com/ckeshava\"\u003e\u003ccode\u003e@​ckeshava\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/XRPLF/xrpl-py/pull/1001\"\u003eXRPLF/xrpl-py#1001\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(wallet): infer signing algorithm from seed prefix in Wallet.from_seed / Wallet.from_secret by \u003ca href=\"https://github.com/ckeshava\"\u003e\u003ccode\u003e@​ckeshava\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/XRPLF/xrpl-py/pull/999\"\u003eXRPLF/xrpl-py#999\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRelease 5.0.0: release-5.0.0 → main by \u003ca href=\"https://github.com/github-actions\"\u003e\u003ccode\u003e@​github-actions\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/XRPLF/xrpl-py/pull/1004\"\u003eXRPLF/xrpl-py#1004\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat: Batch (XLS-56) V1_1 signing support by \u003ca href=\"https://github.com/Patel-Raj11\"\u003e\u003ccode\u003e@​Patel-Raj11\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/XRPLF/xrpl-py/pull/1015\"\u003eXRPLF/xrpl-py#1015\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: support private xrpld images via committed config file by \u003ca href=\"https://github.com/rrmanukyan\"\u003e\u003ccode\u003e@​rrmanukyan\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/XRPLF/xrpl-py/pull/1019\"\u003eXRPLF/xrpl-py#1019\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: Handle signing fields correctly in definitions generation by \u003ca href=\"https://github.com/mvadari\"\u003e\u003ccode\u003e@​mvadari\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/XRPLF/xrpl-py/pull/1021\"\u003eXRPLF/xrpl-py#1021\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSupport for Dynamic MPT (XLS-94d) by \u003ca href=\"https://github.com/kuan121\"\u003e\u003ccode\u003e@​kuan121\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/XRPLF/xrpl-py/pull/877\"\u003eXRPLF/xrpl-py#877\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eExpand team required-reviewers into individual member logins for Slack notifications by \u003ca href=\"https://github.com/github-actions\"\u003e\u003ccode\u003e@​github-actions\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/XRPLF/xrpl-py/pull/1029\"\u003eXRPLF/xrpl-py#1029\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSupport XLS-68 Sponsored Fees and Reserves by \u003ca href=\"https://github.com/kuan121\"\u003e\u003ccode\u003e@​kuan121\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/XRPLF/xrpl-py/pull/1020\"\u003eXRPLF/xrpl-py#1020\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat: ConfidentialMPT Support by \u003ca href=\"https://github.com/pdp2121\"\u003e\u003ccode\u003e@​pdp2121\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/XRPLF/xrpl-py/pull/919\"\u003eXRPLF/xrpl-py#919\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRelease 5.1.0: release-5.1.0 → main by \u003ca href=\"https://github.com/github-actions\"\u003e\u003ccode\u003e@​github-actions\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/XRPLF/xrpl-py/pull/1032\"\u003eXRPLF/xrpl-py#1032\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(coderabbit): reduce review noise and load .ai-review/instructions.md by \u003ca href=\"https://github.com/arshjafri-ripple\"\u003e\u003ccode\u003e@​arshjafri-ripple\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/XRPLF/xrpl-py/pull/1024\"\u003eXRPLF/xrpl-py#1024\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/shichengripple001\"\u003e\u003ccode\u003e@​shichengripple001\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/XRPLF/xrpl-py/pull/876\"\u003eXRPLF/xrpl-py#876\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/github-actions\"\u003e\u003ccode\u003e@​github-actions\u003c/code\u003e\u003c/a\u003e[bot] made their first contribution in \u003ca href=\"https://redirect.github.com/XRPLF/xrpl-py/pull/904\"\u003eXRPLF/xrpl-py#904\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kuan121\"\u003e\u003ccode\u003e@​kuan121\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/XRPLF/xrpl-py/pull/917\"\u003eXRPLF/xrpl-py#917\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/rrmanukyan\"\u003e\u003ccode\u003e@​rrmanukyan\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/XRPLF/xrpl-py/pull/1019\"\u003eXRPLF/xrpl-py#1019\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/arshjafri-ripple\"\u003e\u003ccode\u003e@​arshjafri-ripple\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/XRPLF/xrpl-py/pull/1024\"\u003eXRPLF/xrpl-py#1024\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/XRPLF/xrpl-py/compare/v4.4.0...v5.2.0b0\"\u003ehttps://github.com/XRPLF/xrpl-py/compare/v4.4.0...v5.2.0b0\u003c/a\u003e\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/XRPLF/xrpl-py/blob/v5.2.0/CHANGELOG.md\"\u003exrpl-py's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e[[5.2.0]]\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eSupport for the \u003ccode\u003eLendingProtocolV1_1\u003c/code\u003e amendment.\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003eencode_for_signing_counterparty\u003c/code\u003e / \u003ccode\u003eencode_for_multisigning_counterparty\u003c/code\u003e and \u003ccode\u003eencode_for_signing_sponsor\u003c/code\u003e / \u003ccode\u003eencode_for_multisigning_sponsor\u003c/code\u003e for the role-specific signing prefixes introduced by \u003ccode\u003efixCleanup3_4_0\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eSupport the \u003ccode\u003efixCleanup3_4_0\u003c/code\u003e signing prefixes.\u003c/li\u003e\n\u003cli\u003eRegenerate \u003ccode\u003edefinitions.json\u003c/code\u003e from rippled 3.4.0: adds new fields (e.g. \u003ccode\u003eVaultKind\u003c/code\u003e, \u003ccode\u003eSubscriptionDate\u003c/code\u003e, \u003ccode\u003eRedemptionDate\u003c/code\u003e) and removes Hook/Emit field definitions, as Hooks is no longer supported.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e[[5.1.0]]\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eSupport for \u003ccode\u003eConfidential MPT\u003c/code\u003e (XLS-0096). The optional native cryptography (proof generation and balance decryption) is provided by the separate \u003ccode\u003exrpl.ext.confidential\u003c/code\u003e extension.\u003c/li\u003e\n\u003cli\u003eAdded support for the Sponsored Fees and Reserves (XLS-68)\u003c/li\u003e\n\u003cli\u003eSupport for \u003ccode\u003eDynamic Multi-Purpose Tokens\u003c/code\u003e (XLS-94)\u003c/li\u003e\n\u003cli\u003eAdd support for Batch (XLS-56) \u003ccode\u003eBatchV1_1\u003c/code\u003e signing.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eRemoved\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eDrop support for the older \u003ccode\u003eBatch\u003c/code\u003e signing format (never live on any network, so no existing signatures are affected).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/XRPLF/xrpl-py/commit/a553301e2c4caaf0bf808fc48d18e5271a5c7d28\"\u003e\u003ccode\u003ea553301\u003c/code\u003e\u003c/a\u003e bump packages\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/XRPLF/xrpl-py/commit/634ab7a4c5c18c547a9336fcaa8320a15ccca4ce\"\u003e\u003ccode\u003e634ab7a\u003c/code\u003e\u003c/a\u003e feat: Support LendingProtocolV1_1 (\u003ca href=\"https://redirect.github.com/XRPLF/xrpl-py/issues/1034\"\u003e#1034\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/XRPLF/xrpl-py/commit/28836d0a7346e92adce877eeb02721fff218fb89\"\u003e\u003ccode\u003e28836d0\u003c/code\u003e\u003c/a\u003e Support \u003ccode\u003efixCleanup3_4_0\u003c/code\u003e signing prefixes (\u003ccode\u003eSponsor\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/XRPLF/xrpl-py/issues/1036\"\u003e#1036\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/XRPLF/xrpl-py/commit/a29bdba371fabdf08aafda1dbbb15c8bfbfcc4a8\"\u003e\u003ccode\u003ea29bdba\u003c/code\u003e\u003c/a\u003e ci: remove integration test requirement for beta releases (\u003ca href=\"https://redirect.github.com/XRPLF/xrpl-py/issues/1039\"\u003e#1039\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/XRPLF/xrpl-py/commit/10ed82ee1f25c8bef0bf3bbc08d2708d6dde2a0f\"\u003e\u003ccode\u003e10ed82e\u003c/code\u003e\u003c/a\u003e chore(coderabbit): reduce review noise and load .ai-review/instructions.md (#...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/XRPLF/xrpl-py/commit/ad08b5b79ee221fd32ca610bf72e6e0dcfb7c894\"\u003e\u003ccode\u003ead08b5b\u003c/code\u003e\u003c/a\u003e Release 5.1.0: release-5.1.0 → main (\u003ca href=\"https://redirect.github.com/XRPLF/xrpl-py/issues/1032\"\u003e#1032\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/XRPLF/xrpl-py/commit/d80063149a70c5478d5f3fe5fef1b2bdd81bf67c\"\u003e\u003ccode\u003ed800631\u003c/code\u003e\u003c/a\u003e feat: ConfidentialMPT Support (\u003ca href=\"https://redirect.github.com/XRPLF/xrpl-py/issues/919\"\u003e#919\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/XRPLF/xrpl-py/commit/e648619de0961b13dc6f7548f4973bf5345b888e\"\u003e\u003ccode\u003ee648619\u003c/code\u003e\u003c/a\u003e Support XLS-68 Sponsored Fees and Reserves (\u003ca href=\"https://redirect.github.com/XRPLF/xrpl-py/issues/1020\"\u003e#1020\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/XRPLF/xrpl-py/commit/524f230c6581a99d876137a4d8121391df691a30\"\u003e\u003ccode\u003e524f230\u003c/code\u003e\u003c/a\u003e Expand team required-reviewers into individual member logins for Slack notifi...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/XRPLF/xrpl-py/commit/cddeb632e611348550edc4c9c03eb90ae562789a\"\u003e\u003ccode\u003ecddeb63\u003c/code\u003e\u003c/a\u003e Support for Dynamic MPT (XLS-94d) (\u003ca href=\"https://redirect.github.com/XRPLF/xrpl-py/issues/877\"\u003e#877\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/XRPLF/xrpl-py/compare/v5.0.0...v5.2.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `numpy` from 2.2.6 to 2.5.3\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/numpy/numpy/releases\"\u003enumpy's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.5.3 (Sep 6, 2026)\u003c/h2\u003e\n\u003ch1\u003eNumPy 2.5.3 Release Notes\u003c/h1\u003e\n\u003cp\u003eThe NumPy 2.5.3 is a patch release that fixes bugs discovered after the 2.5.2\nrelease. Apart from the usual bug and maintenance work, there are a number of\nStringDType related fixes for problems discovered during the ongoing string\nwork in the main branch.\u003c/p\u003e\n\u003cp\u003eThis release supports Python versions 3.12-3.15\u003c/p\u003e\n\u003ch2\u003eChanges\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eCasting a fixed-width byte string array (\u003ccode\u003enp.bytes_\u003c/code\u003e) to \u003ccode\u003eStringDType\u003c/code\u003e\nnow raises \u003ccode\u003eTypeError\u003c/code\u003e when the bytes are not valid UTF-8. Previously the\ninvalid bytes were stored as-is and later caused undefined behavior in\nstring operations.\u003c/p\u003e\n\u003cp\u003e(\u003ca href=\"https://redirect.github.com/numpy/numpy/pull/32296\"\u003egh-32296\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ccode\u003eMaskedArray._fill_value\u003c/code\u003e would become stale when ufuncs that change dtype\nleft the result holding a fill_value typed for the old dtype. The mismatch\nwas silent until something later called \u003ccode\u003e_check_fill_value\u003c/code\u003e, such as\n\u003ccode\u003e.view()\u003c/code\u003e, and then a \u003ccode\u003eTypeError\u003c/code\u003e would be raised. Now, when the copied\nfill_value is no longer valid for the new dtype, fall back to the\ndefault fill_value for that dtype instead of propagating the stale value.\nThis may raise a \u003ccode\u003eComplexWarning\u003c/code\u003e if the fill_value is complex and the\nnew dtype is real.\u003c/p\u003e\n\u003cp\u003e(\u003ca href=\"https://redirect.github.com/numpy/numpy/pull/32423\"\u003egh-32423\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eContributors\u003c/h2\u003e\n\u003cp\u003eA total of 9 people contributed to this release. People with a \u0026quot;+\u0026quot; by their\nnames contributed a patch for the first time.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eCharles Harris\u003c/li\u003e\n\u003cli\u003eIason Krommydas\u003c/li\u003e\n\u003cli\u003eJames Davies +\u003c/li\u003e\n\u003cli\u003eJoren Hammudoglu\u003c/li\u003e\n\u003cli\u003eMaanas Arora\u003c/li\u003e\n\u003cli\u003eMatti Picus\u003c/li\u003e\n\u003cli\u003eNathan Goldbaum\u003c/li\u003e\n\u003cli\u003eShikhar Goel +\u003c/li\u003e\n\u003cli\u003eYeonho Kim +\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ePull requests merged\u003c/h2\u003e\n\u003cp\u003eA total of 27 pull requests were merged for this release.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/numpy/numpy/pull/32235\"\u003e#32235\u003c/a\u003e: MAINT: Prepare 2.5.x for further development\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/numpy/numpy/blob/main/doc/RELEASE_WALKTHROUGH.rst\"\u003enumpy's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003eThis is a walkthrough of the NumPy 2.4.0 release on Linux, which will be the\nfirst feature release using the \u003ccode\u003enumpy/numpy-release \u0026lt;https://github.com/numpy/numpy-release\u0026gt;\u003c/code\u003e__ repository.\u003c/p\u003e\n\u003cp\u003eThe commands can be copied into the command line, but be sure to replace 2.4.0\nwith the correct version. This should be read together with the\n:ref:\u003ccode\u003egeneral release guide \u0026lt;prepare_release\u0026gt;\u003c/code\u003e.\u003c/p\u003e\n\u003ch1\u003eFacility preparation\u003c/h1\u003e\n\u003cp\u003eBefore beginning to make a release, use the \u003ccode\u003erequirements/*_requirements.txt\u003c/code\u003e files to\nensure that you have the needed software. Most software can be installed with\npip, but some will require apt-get, dnf, or whatever your system uses for\nsoftware. You will also need a GitHub personal access token (PAT) to push the\ndocumentation. There are a few ways to streamline things:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eGit can be set up to use a keyring to store your GitHub personal access token.\nSearch online for the details.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch1\u003ePrior to release\u003c/h1\u003e\n\u003ch2\u003eAdd/drop Python versions\u003c/h2\u003e\n\u003cp\u003eWhen adding or dropping Python versions, multiple config and CI files need to\nbe edited in addition to changing the minimum version in \u003ccode\u003epyproject.toml\u003c/code\u003e.\nMake these changes in an ordinary PR against main and backport if necessary.\nWe currently release wheels for new Python versions after the first Python RC\nonce manylinux and cibuildwheel support that new Python version.\u003c/p\u003e\n\u003ch2\u003eBackport pull requests\u003c/h2\u003e\n\u003cp\u003eChanges that have been marked for this release must be backported to the\nmaintenance/2.4.x branch.\u003c/p\u003e\n\u003ch2\u003eUpdate 2.4.0 milestones\u003c/h2\u003e\n\u003cp\u003eLook at the issues/prs with 2.4.0 milestones and either push them off to a\nlater version, or maybe remove the milestone. You may need to add a milestone.\u003c/p\u003e\n\u003ch2\u003eCheck the numpy-release repo\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/numpy/numpy/commit/dd88c0c19b54ad9ed3533224221285bf0873249a\"\u003e\u003ccode\u003edd88c0c\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/numpy/numpy/issues/32511\"\u003e#32511\u003c/a\u003e from charris/prepare-2.5.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/numpy/numpy/commit/edcac6acc392f4010933ee83e8a4769a7cfe92c5\"\u003e\u003ccode\u003eedcac6a\u003c/code\u003e\u003c/a\u003e REL: Prepare for the NumPy 2.5.3 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/numpy/numpy/commit/fd4d908aff89773ead13f7c6a0ab31153f14439e\"\u003e\u003ccode\u003efd4d908\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/numpy/numpy/issues/32509\"\u003e#32509\u003c/a\u003e from charris/backport-32496\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/numpy/numpy/commit/65bb1da13d0ee784be84d173b86784f0d64bdaca\"\u003e\u003ccode\u003e65bb1da\u003c/code\u003e\u003c/a\u003e BUG: fix crash in ufunc.resolve_dtypes with a Python scalar type (\u003ca href=\"https://redirect.github.com/numpy/numpy/issues/32496\"\u003e#32496\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/numpy/numpy/commit/294956e85dfaea149aada1278c2ed6be0f6f28c8\"\u003e\u003ccode\u003e294956e\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/numpy/numpy/issues/32506\"\u003e#32506\u003c/a\u003e from charris/backport-32503\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/numpy/numpy/commit/26428d9a3f5ab4f604b326347e3a9c6dcc00c1cb\"\u003e\u003ccode\u003e26428d9\u003c/code\u003e\u003c/a\u003e DOC: fix scipy docs links in intersphinx mapping (\u003ca href=\"https://redirect.github.com/numpy/numpy/issues/32507\"\u003e#32507\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/numpy/numpy/commit/5fab1cbc6aa9e119d9f931243a56c6fbca989476\"\u003e\u003ccode\u003e5fab1cb\u003c/code\u003e\u003c/a\u003e DOC: use static scipy doc site for intershpinx (\u003ca href=\"https://redirect.github.com/numpy/numpy/issues/32503\"\u003e#32503\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/numpy/numpy/commit/7beed2f7e9a24e493a04ff7e2eb1db0d7f9c50e6\"\u003e\u003ccode\u003e7beed2f\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/numpy/numpy/issues/32481\"\u003e#32481\u003c/a\u003e from ngoldbaum/stringdtype-backport\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/numpy/numpy/commit/8972f70798a2ba1bb4557157982fd6001906f993\"\u003e\u003ccode\u003e8972f70\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/numpy/numpy/issues/32478\"\u003e#32478\u003c/a\u003e from charris/backport-32466\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/numpy/numpy/commit/ab1b58902a868d4151ef3cf8dbeb91d8a1924fa4\"\u003e\u003ccode\u003eab1b589\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/numpy/numpy/issues/32477\"\u003e#32477\u003c/a\u003e from charris/backport-32423\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/numpy/numpy/compare/v2.2.6...v2.5.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `opencv-python` from 4.13.0.92 to 5.0.0.93\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/opencv/opencv-python/releases\"\u003eopencv-python's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e5.0.0.93\u003c/h2\u003e\n\u003cp\u003eOpenCV 5.0.0 released!\u003c/p\u003e\n\u003cp\u003eOpenCV 5.0.0 overview: \u003ca href=\"https://opencv.org/opencv-5\"\u003ehttps://opencv.org/opencv-5\u003c/a\u003e\nOpenCV 4.x -\u0026gt; 5.x migration guide: \u003ca href=\"https://github.com/opencv/opencv/wiki/OpenCV-4-to-5-migration\"\u003ehttps://github.com/opencv/opencv/wiki/OpenCV-4-to-5-migration\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/opencv/opencv-python/commits\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `pillow` from 12.2.0 to 12.3.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/python-pillow/Pillow/releases\"\u003epillow's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e12.3.0\u003c/h2\u003e\n\u003cp\u003e\u003ca href=\"https://pillow.readthedocs.io/en/stable/releasenotes/12.3.0.html\"\u003ehttps://pillow.readthedocs.io/en/stable/releasenotes/12.3.0.html\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eRemovals\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRemove non-image ImageCms modes \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9697\"\u003e#9697\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eDocumentation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd release notes for SBOM and performance improvements \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9747\"\u003e#9747\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdd security release notes \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9741\"\u003e#9741\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdd release notes for Python 3.15 beta wheels \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9696\"\u003e#9696\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eImageFont can also be used with ImageText \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9597\"\u003e#9597\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdditional guidelines for security reports \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9659\"\u003e#9659\u003c/a\u003e [\u003ca href=\"https://github.com/wiredfool\"\u003e\u003ccode\u003e@​wiredfool\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eFixed typo \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9636\"\u003e#9636\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdded CVEs to 12.2.0 release notes \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9591\"\u003e#9591\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eRevise development support information in README \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9583\"\u003e#9583\u003c/a\u003e [\u003ca href=\"https://github.com/aclark4life\"\u003e\u003ccode\u003e@​aclark4life\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdd INCIDENT_RESPONSE.md \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9555\"\u003e#9555\u003c/a\u003e [\u003ca href=\"https://github.com/aclark4life\"\u003e\u003ccode\u003e@​aclark4life\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdd STRIDE threat model to security docs \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9562\"\u003e#9562\u003c/a\u003e [\u003ca href=\"https://github.com/aclark4life\"\u003e\u003ccode\u003e@​aclark4life\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdd CVEs to 12.2.0 release notes \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9556\"\u003e#9556\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate README with revised security policy \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9553\"\u003e#9553\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate security policy \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9552\"\u003e#9552\u003c/a\u003e [\u003ca href=\"https://github.com/aclark4life\"\u003e\u003ccode\u003e@​aclark4life\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate macOS tested Python versions \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9534\"\u003e#9534\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eDependencies\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate dependency harfbuzz to v14.2.1 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9720\"\u003e#9720\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency mypy to v2 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9653\"\u003e#9653\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency cibuildwheel to v4 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9665\"\u003e#9665\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate github-actions \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9655\"\u003e#9655\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency libavif to v1.4.2 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9652\"\u003e#9652\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency lcms2 to v2.19.1 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9651\"\u003e#9651\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency check-jsonschema to v0.37.2 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9650\"\u003e#9650\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate google/oss-fuzz digest to d872252 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9614\"\u003e#9614\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency lcms2 to v2.19 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9609\"\u003e#9609\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency libpng to v1.6.58 - autoclosed \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9608\"\u003e#9608\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency harfbuzz to v14 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9610\"\u003e#9610\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency mypy to v1.20.2 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9599\"\u003e#9599\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate github-actions \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9611\"\u003e#9611\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency cibuildwheel to v3.4.1 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9607\"\u003e#9607\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eMove dependency versions to single JSON and enable Renovate \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9559\"\u003e#9559\u003c/a\u003e [\u003ca href=\"https://github.com/hugovk\"\u003e\u003ccode\u003e@​hugovk\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdated raqm to 0.10.5 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9557\"\u003e#9557\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency cibuildwheel to v3.4.0 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9532\"\u003e#9532\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eTesting\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRemove matrix.os from benchmark \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9735\"\u003e#9735\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eRemove references to libavif patch \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9734\"\u003e#9734\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdd benchmark tests \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9654\"\u003e#9654\u003c/a\u003e [\u003ca href=\"https://github.com/akx\"\u003e\u003ccode\u003e@​akx\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUse reshape() instead of setting NumPy array shape directly \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9728\"\u003e#9728\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/bb1d8e8ab8d29048624d96e3ee53cecf7c13d13d\"\u003e\u003ccode\u003ebb1d8e8\u003c/code\u003e\u003c/a\u003e 12.3.0 version bump\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/e63fc481dc2e07e21d5403deafb8f1ed98a513af\"\u003e\u003ccode\u003ee63fc48\u003c/code\u003e\u003c/a\u003e Add release notes for SBOM and performance improvements (\u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9747\"\u003e#9747\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/13b701bbab291eec4bc87ea17ba06c94e5fe3054\"\u003e\u003ccode\u003e13b701b\u003c/code\u003e\u003c/a\u003e Add release notes for \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9679\"\u003e#9679\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/5564ca72fcd59d040e270af5dcf17a0d7161c364\"\u003e\u003ccode\u003e5564ca7\u003c/code\u003e\u003c/a\u003e List methods\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/a0920fd384f800b5d0ba3dd29ecdeae4f1d4043b\"\u003e\u003ccode\u003ea0920fd\u003c/code\u003e\u003c/a\u003e Speed up ImageChops operations (\u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9738\"\u003e#9738\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/07e9a6cd5336dc6cf8cae9165cd70cdd2b3e42fc\"\u003e\u003ccode\u003e07e9a6c\u003c/code\u003e\u003c/a\u003e Speed up \u003ccode\u003eImage.filter()\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9736\"\u003e#9736\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/a94578cf9649ea13e426cf7fb2b71b39ffc0dd50\"\u003e\u003ccode\u003ea94578c\u003c/code\u003e\u003c/a\u003e Speed up \u003ccode\u003eImage.getchannel()\u003c/code\u003e, \u003ccode\u003eImage.merge()\u003c/code\u003e, \u003ccode\u003eImage.putalpha()\u003c/code\u003e and `Image...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/53e02c43c919d149b2a154a5180079f9df18fbbb\"\u003e\u003ccode\u003e53e02c4\u003c/code\u003e\u003c/a\u003e Speed up \u003ccode\u003eImage.fill()\u003c/code\u003e, \u003ccode\u003eImage.linear_gradient()\u003c/code\u003e and `Image.radial_gradient...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/af037475be8634ba739744243164ba9e2c8346a6\"\u003e\u003ccode\u003eaf03747\u003c/code\u003e\u003c/a\u003e Speed up \u003ccode\u003eImage.resample()\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9739\"\u003e#9739\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/5c9ca56c3e5fba52b647809fbb0986c87e73a571\"\u003e\u003ccode\u003e5c9ca56\u003c/code\u003e\u003c/a\u003e Speed up \u003ccode\u003ealpha_composite\u003c/code\u003e, \u003ccode\u003ematrix\u003c/code\u003e, \u003ccode\u003enegative\u003c/code\u003e, \u003ccode\u003equantize\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9740\"\u003e#9740\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/python-pillow/Pillow/compare/12.2.0...12.3.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `python-dotenv` from 0.21.1 to 1.2.3\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/theskumar/python-dotenv/releases\"\u003epython-dotenv's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.2.3\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eStrip a leading UTF-8 BOM from \u003ccode\u003e.env\u003c/code\u003e file contents so the first variable is no longer silently lost when the file is saved with BOM (e.g. by some JetBrains IDEs on Windows) by [\u003ca href=\"https://github.com/h1whelan\"\u003e\u003ccode\u003e@​h1whelan\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/640\"\u003e#640\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eset_key\u003c/code\u003e now escapes backslashes, so values containing them (Windows paths, regular expressions) survive a write/read round-trip. Quoted values ending in an escaped backslash are no longer mis-parsed as an escaped quote, which used to swallow the following lines by [\u003ca href=\"https://github.com/dchaudhari7177\"\u003e\u003ccode\u003e@​dchaudhari7177\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/680\"\u003e#680\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003edotenv run\u003c/code\u003e now prints a friendly error instead of a traceback when no command is given by [\u003ca href=\"https://github.com/bbc2\"\u003e\u003ccode\u003e@​bbc2\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/606\"\u003e#606\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eCache the parsed result for empty \u003ccode\u003e.env\u003c/code\u003e files so repeated \u003ccode\u003edotenv_values\u003c/code\u003e/\u003ccode\u003eload_dotenv\u003c/code\u003e calls no longer re-read the file by [\u003ca href=\"https://github.com/ReinerBRO\"\u003e\u003ccode\u003e@​ReinerBRO\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/638\"\u003e#638\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev1.2.2\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eSupport for Python 3.14, including the free-threaded (3.14t) build. (#)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eThe \u003ccode\u003edotenv run\u003c/code\u003e command now forwards flags directly to the specified command by \u003ca href=\"https://github.com/bbc2\"\u003e\u003ccode\u003e@​bbc2\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/pull/607\"\u003etheskumar/python-dotenv#607\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eImproved documentation clarity regarding override behavior and the reference page.\u003c/li\u003e\n\u003cli\u003eUpdated PyPy support to version 3.11.\u003c/li\u003e\n\u003cli\u003eDocumentation for FIFO file support.\u003c/li\u003e\n\u003cli\u003eSupport for Python 3.9.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eImproved \u003ccode\u003eset_key\u003c/code\u003e and \u003ccode\u003eunset_key\u003c/code\u003e behavior when interacting with symlinks by \u003ca href=\"https://github.com/bbc2\"\u003e\u003ccode\u003e@​bbc2\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://github.com/theskumar/python-dotenv/commit/790c5c02991100aa1bf41ee5330aca75edc51311\"\u003e#790c5\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eCorrected the license specifier and added missing Python 3.14 classifiers in package metadata by \u003ca href=\"https://github.com/JYOuyang\"\u003e\u003ccode\u003e@​JYOuyang\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/pull/590\"\u003etheskumar/python-dotenv#590\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBreaking Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ccode\u003edotenv.set_key\u003c/code\u003e and \u003ccode\u003edotenv.unset_key\u003c/code\u003e used to follow symlinks in some\nsituations. This is no longer the case. For that behavior to be restored in\nall cases, \u003ccode\u003efollow_symlinks=True\u003c/code\u003e should be used.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eIn the CLI, \u003ccode\u003eset\u003c/code\u003e and \u003ccode\u003eunset\u003c/code\u003e used to follow symlinks in some situations. This\nis no longer the case.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ccode\u003edotenv.set_key\u003c/code\u003e, \u003ccode\u003edotenv.unset_key\u003c/code\u003e and the CLI commands \u003ccode\u003eset\u003c/code\u003e and \u003ccode\u003eunset\u003c/code\u003e\nused to reset the file mode of the modified .env file to \u003ccode\u003e0o600\u003c/code\u003e in some\nsituations. This is no longer the case: The original mode of the file is now\npreserved. Is the file needed to be created or wasn't a regular file, mode\n\u003ccode\u003e0o600\u003c/code\u003e is used.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMisc\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eskip 000 permission tests for root user by \u003ca href=\"https://github.com/burnout-projects\"\u003e\u003ccode\u003e@​burnout-projects\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/pull/561\"\u003etheskumar/python-dotenv#561\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump actions/checkout from 5 to 6 in the github-actions group by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/pull/593\"\u003etheskumar/python-dotenv#593\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd Windows testing to CI by \u003ca href=\"https://github.com/bbc2\"\u003e\u003ccode\u003e@​bbc2\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/pull/604\"\u003etheskumar/python-dotenv#604\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eImprove workflow efficiency with best practices by \u003ca href=\"https://github.com/theskumar\"\u003e\u003ccode\u003e@​theskumar\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/pull/609\"\u003etheskumar/python-dotenv#609\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRemove the use of \u003ccode\u003esh\u003c/code\u003e in tests by \u003ca href=\"https://github.com/bbc2\"\u003e\u003ccode\u003e@​bbc2\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/pull/612\"\u003etheskumar/python-dotenv#612\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/theskumar/python-dotenv/blob/main/CHANGELOG.md\"\u003epython-dotenv's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e[1.2.3] - 2026-08-16\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eStrip a leading UTF-8 BOM from \u003ccode\u003e.env\u003c/code\u003e file contents so the first variable is no longer silently lost when the file is saved with BOM (e.g. by some JetBrains IDEs on Windows) by [\u003ca href=\"https://github.com/h1whelan\"\u003e\u003ccode\u003e@​h1whelan\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/640\"\u003e#640\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eset_key\u003c/code\u003e now escapes backslashes, so values containing them (Windows paths, regular expressions) survive a write/read round-trip. Quoted values ending in an escaped backslash are no longer mis-parsed as an escaped quote, which used to swallow the following lines by [\u003ca href=\"https://github.com/dchaudhari7177\"\u003e\u003ccode\u003e@​dchaudhari7177\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/680\"\u003e#680\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003edotenv run\u003c/code\u003e now prints a friendly error instead of a traceback when no command is given by [\u003ca href=\"https://github.com/bbc2\"\u003e\u003ccode\u003e@​bbc2\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/606\"\u003e#606\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eCache the parsed result for empty \u003ccode\u003e.env\u003c/code\u003e files so repeated \u003ccode\u003edotenv_values\u003c/code\u003e/\u003ccode\u003eload_dotenv\u003c/code\u003e calls no longer re-read the file by [\u003ca href=\"https://github.com/ReinerBRO\"\u003e\u003ccode\u003e@​ReinerBRO\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/638\"\u003e#638\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e[1.2.2] - 2026-03-01\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eSupport for Python 3.14, including the free-threaded (3.14t) build. (\u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/588\"\u003e#588\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eThe \u003ccode\u003edotenv run\u003c/code\u003e command now forwards flags directly to the specified command by [\u003ca href=\"https://github.com/bbc2\"\u003e\u003ccode\u003e@​bbc2\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/607\"\u003e#607\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eImproved documentation clarity regarding override behavior and the reference page.\u003c/li\u003e\n\u003cli\u003eUpdated PyPy support to version 3.11.\u003c/li\u003e\n\u003cli\u003eDocumentation for FIFO file support.\u003c/li\u003e\n\u003cli\u003eDropped Support for Python 3.9.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eImproved \u003ccode\u003eset_key\u003c/code\u003e and \u003ccode\u003eunset_key\u003c/code\u003e behavior when interacting with symlinks by [\u003ca href=\"https://github.com/bbc2\"\u003e\u003ccode\u003e@​bbc2\u003c/code\u003e\u003c/a\u003e] in [790c5c0]\u003c/li\u003e\n\u003cli\u003eCorrected the license specifier and added missing Python 3.14 classifiers in package metadata by [\u003ca href=\"https://github.com/JYOuyang\"\u003e\u003ccode\u003e@​JYOuyang\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/590\"\u003e#590\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBreaking Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ccode\u003edotenv.set_key\u003c/code\u003e and \u003ccode\u003edotenv.unset_key\u003c/code\u003e used to follow symlinks in some\nsituations. This is no longer the case. For that behavior to be restored in\nall cases, \u003ccode\u003efollow_symlinks=True\u003c/code\u003e should be used.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eIn the CLI, \u003ccode\u003eset\u003c/code\u003e and \u003ccode\u003eunset\u003c/code\u003e used to follow symlinks in some situations. This\nis no longer the case.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ccode\u003edotenv.set_key\u003c/code\u003e, \u003ccode\u003edotenv.unset_key\u003c/code\u003e and the CLI commands \u003ccode\u003eset\u003c/code\u003e and \u003ccode\u003eunset\u003c/code\u003e\nused to reset the file mode of the modified .env file to \u003ccode\u003e0o600\u003c/code\u003e in some\nsituations. This is no longer the case: The original mode of the file is now\npreserved. Is the file needed to be created or wasn't a regular file, mode\n\u003ccode\u003e0o600\u003c/code\u003e is used.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e[1.2.1] - 2025-10-26\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMove more config to \u003ccode\u003epyproject.toml\u003c/code\u003e, removed \u003ccode\u003esetup.cfg\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eAdd support for reading \u003ccode\u003e.env\u003c/code\u003e from FIFOs (Unix) by [\u003ca href=\"https://github.com/sidharth-sudhir\"\u003e\u003ccode\u003e@​sidharth-sudhir\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/586\"\u003e#586\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e[1.2.0] - 2025-10-26\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/49515afee2d50c33cad9419b3800b3a0dc93fc59\"\u003e\u003ccode\u003e49515af\u003c/code\u003e\u003c/a\u003e Bump version: 1.2.2 → 1.2.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/8ac846ff2760b65470e769d7eed33e540f0934e1\"\u003e\u003ccode\u003e8ac846f\u003c/code\u003e\u003c/a\u003e chore: add release runbook (RELEASING.md) and make release target\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/bb31c944fb4b40e8dea59587f525840c38326166\"\u003e\u003ccode\u003ebb31c94\u003c/code\u003e\u003c/a\u003e docs: add 1.2.3 release notes (\u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/606\"\u003e#606\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/638\"\u003e#638\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/680\"\u003e#680\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/f7b18d9c72d1abcc2ad4023424b84f5bee30d266\"\u003e\u003ccode\u003ef7b18d9\u003c/code\u003e\u003c/a\u003e fix: round-trip backslashes through set_key (\u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/680\"\u003e#680\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/751f8c148222e58aa173c83c4e5e6cfccb2cc124\"\u003e\u003ccode\u003e751f8c1\u003c/code\u003e\u003c/a\u003e ci(deps): bump actions/checkout from 6.0.2 to 6.0.3 in the github-actions gro...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/f1937b68f338d7ebd7754da377ca08b2f0df8dbb\"\u003e\u003ccode\u003ef1937b6\u003c/code\u003e\u003c/a\u003e chore(deps): update mkdocs-include-markdown-plugin requirement from \u0026gt;=6.0.0 t...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/45b93720dd5e9e127d0be3971a04855d34e464d8\"\u003e\u003ccode\u003e45b9372\u003c/code\u003e\u003c/a\u003e chore(deps): update pytest requirement from \u0026gt;=3.9 to \u0026gt;=9.0.3 (\u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/653\"\u003e#653\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/72896e9244d2a1ff8d5e1934d3df8a35c813799a\"\u003e\u003ccode\u003e72896e9\u003c/code\u003e\u003c/a\u003e docs: fix broken mkdocs link in CONTRIBUTING.md (\u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/636\"\u003e#636\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/72754a16a4743e4c92edf87ce59ba0e4ff78758d\"\u003e\u003ccode\u003e72754a1\u003c/code\u003e\u003c/a\u003e ci(deps): bump peaceiris/actions-gh-pages from 4.0.0 to 4.1.0 in the github-a...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/078325e92558330e9addc661b789c7b6123fa73c\"\u003e\u003ccode\u003e078325e\u003c/code\u003e\u003c/a\u003e ci(security): harden CI/CD supply chain with SHA pinning and least-privilege ...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/theskumar/python-dotenv/compare/v0.21.1...v1.2.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `aiohttp` from 3.14.1 to 3.14.3\nUpdates `cryptography` from 50.0.0 to 50.0.1\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst\"\u003ecryptography's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e50.0.1 - 2026-08-25\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003e\n* Updated Windows, macOS, and Linux wheels to be compiled with OpenSSL 4.0.2.\n\u003cp\u003e.. _v50-0-0:\u003cbr /\u003e\n\u003c/code\u003e\u003c/pre\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/ffde75a2b594822c740a2e4748b56c00548302bf\"\u003e\u003ccode\u003effde75a\u003c/code\u003e\u003c/a\u003e bump for 50.0.1 + changelog (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15520\"\u003e#15520\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/pyca/cryptography/compare/50.0.0...50.0.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\n\n\n\u003c/details\u003e","html_url":"https://github.com/Team-Hamsa/LFG/pull/586","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/Team-Hamsa%2FLFG/issues/586","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/586/packages"}},{"old_version":"3.14.1","new_version":"3.14.3","update_type":"patch","path":"/services/ai-orchestrator-service","pr_created_at":"2026-09-19T19:44:57.000Z","version_change":"3.14.1 → 3.14.3","issue":{"uuid":"5513101412","node_id":"PR_kwDOT_waCs8AAAABEP-mQw","number":89,"state":"open","title":"build(deps): bump the pip-minor-patch group in /services/ai-orchestrator-service with 70 updates","user":"dependabot[bot]","labels":[],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-19T19:44:57.000Z","updated_at":"2026-09-19T19:44:58.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"build(deps): bump","group_name":"pip-minor-patch","update_count":70,"packages":[{"name":"aiohttp","old_version":"3.14.1","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"annotated-doc","old_version":"0.0.4","new_version":"0.0.5","repository_url":"https://github.com/fastapi/annotated-doc"},{"name":"annotated-types","old_version":"0.7.0","new_version":"0.8.0","repository_url":"https://github.com/annotated-types/annotated-types"},{"name":"anyio","old_version":"4.14.2","new_version":"4.15.1","repository_url":"https://github.com/agronholm/anyio"},{"name":"build","old_version":"1.5.0","new_version":"1.6.1","repository_url":"https://github.com/pypa/build"},{"name":"certifi","old_version":"2026.6.17","new_version":"2026.7.22","repository_url":"https://github.com/certifi/python-certifi"},{"name":"cffi","old_version":"2.1.0","new_version":"2.1.1","repository_url":"https://github.com/python-cffi/cffi"},{"name":"charset-normalizer","old_version":"3.4.9","new_version":"3.5.1","repository_url":"https://github.com/jawah/charset_normalizer"},{"name":"click","old_version":"8.4.2","new_version":"8.5.0","repository_url":"https://github.com/pallets/click"},{"name":"cloudpathlib","old_version":"0.24.0","new_version":"0.25.0","repository_url":"https://github.com/drivendataorg/cloudpathlib"},{"name":"contourpy","old_version":"1.3.3","new_version":"1.4.0","repository_url":"https://github.com/contourpy/contourpy"},{"name":"durationpy","old_version":"0.10","new_version":"0.11","repository_url":"https://github.com/icholy/durationpy"},{"name":"fastapi","old_version":"0.139.2","new_version":"0.141.1","repository_url":"https://github.com/fastapi/fastapi"},{"name":"filelock","old_version":"3.30.2","new_version":"3.32.7","repository_url":"https://github.com/tox-dev/py-filelock"},{"name":"fonttools","old_version":"4.63.0","new_version":"4.65.0","repository_url":"https://github.com/fonttools/fonttools"},{"name":"fsspec","old_version":"2026.6.0","new_version":"2026.7.0","repository_url":"https://github.com/fsspec/filesystem_spec"},{"name":"google-auth","old_version":"2.55.2","new_version":"2.58.0","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"google-genai","old_version":"2.12.0","new_version":"2.23.0","repository_url":"https://github.com/googleapis/python-genai"},{"name":"googleapis-common-protos","old_version":"1.75.0","new_version":"1.75.3","repository_url":"https://github.com/googleapis/google-cloud-python"},{"name":"grpcio","old_version":"1.82.1","new_version":"1.84.0","repository_url":"https://github.com/grpc/grpc"},{"name":"hf-xet","old_version":"1.5.2","new_version":"1.6.0","repository_url":"https://github.com/huggingface/xet-core"},{"name":"huggingface-hub","old_version":"1.23.0","new_version":"1.31.0","repository_url":"https://github.com/huggingface/huggingface_hub"},{"name":"idna","old_version":"3.18","new_version":"3.19","repository_url":"https://github.com/kjd/idna"},{"name":"jiter","old_version":"0.16.0","new_version":"0.17.0","repository_url":"https://github.com/pydantic/jiter"},{"name":"joblib","old_version":"1.5.3","new_version":"1.6.0","repository_url":"https://github.com/joblib/joblib"},{"name":"kiwisolver","old_version":"1.5.0","new_version":"1.5.1","repository_url":"https://github.com/nucleic/kiwi"},{"name":"langchain","old_version":"1.3.14","new_version":"1.4.1","repository_url":"https://github.com/langchain-ai/langchain"},{"name":"langchain-core","old_version":"1.4.9","new_version":"1.6.3","repository_url":"https://github.com/langchain-ai/langchain"},{"name":"langchain-google-genai","old_version":"4.2.7","new_version":"4.4.0","repository_url":"https://github.com/langchain-ai/langchain-google"},{"name":"langchain-protocol","old_version":"0.0.18","new_version":"0.0.19","repository_url":"https://github.com/langchain-ai/agent-protocol"},{"name":"langgraph","old_version":"1.2.9","new_version":"1.2.11","repository_url":"https://github.com/langchain-ai/langgraph"},{"name":"langgraph-checkpoint","old_version":"4.1.1","new_version":"4.2.0","repository_url":"https://github.com/langchain-ai/langgraph"},{"name":"langgraph-sdk","old_version":"0.4.2","new_version":"0.4.4","repository_url":"https://github.com/langchain-ai/langgraph"},{"name":"langsmith","old_version":"0.10.5","new_version":"0.12.6","repository_url":"https://github.com/langchain-ai/langsmith-sdk"},{"name":"mmh3","old_version":"5.2.1","new_version":"5.3.0","repository_url":"https://github.com/hajimes/mmh3"},{"name":"mpmath","old_version":"1.3.0","new_version":"1.4.1","repository_url":"https://github.com/mpmath/mpmath"},{"name":"multidict","old_version":"6.7.1","new_version":"6.8.0","repository_url":"https://github.com/aio-libs/multidict"},{"name":"narwhals","old_version":"2.24.0","new_version":"2.26.0","repository_url":"https://github.com/narwhals-dev/narwhals"},{"name":"numpy","old_version":"2.5.1","new_version":"2.5.3","repository_url":"https://github.com/numpy/numpy"},{"name":"onnxruntime","old_version":"1.27.0","new_version":"1.30.0","repository_url":"https://github.com/microsoft/onnxruntime"},{"name":"orjson","old_version":"3.11.9","new_version":"3.12.0","repository_url":"https://github.com/ijl/orjson"},{"name":"packaging","old_version":"26.2","new_version":"26.3","repository_url":"https://github.com/pypa/packaging"},{"name":"pandas","old_version":"3.0.3","new_version":"3.0.5","repository_url":"https://github.com/pandas-dev/pandas"},{"name":"propcache","old_version":"0.5.2","new_version":"0.5.4","repository_url":"https://github.com/aio-libs/propcache"},{"name":"protobuf","old_version":"7.35.1","new_version":"7.36.1","repository_url":"https://github.com/protocolbuffers/protobuf"},{"name":"pybase64","old_version":"1.4.3","new_version":"1.5.0","repository_url":"https://github.com/mayeut/pybase64"},{"name":"pydantic","old_version":"2.13.4","new_version":"2.13.5","repository_url":"https://github.com/pydantic/pydantic"},{"name":"pydantic-settings","old_version":"2.14.2","new_version":"2.15.0","repository_url":"https://github.com/pydantic/pydantic-settings"},{"name":"pydantic-core","old_version":"2.46.4","new_version":"2.49.0","repository_url":"https://github.com/pydantic/pydantic"},{"name":"pygments","old_version":"2.20.0","new_version":"2.21.0","repository_url":"https://github.com/pygments/pygments"},{"name":"pyproject-hooks","old_version":"1.2.0","new_version":"1.3.3","repository_url":"https://github.com/pypa/pyproject-hooks"},{"name":"python-dotenv","old_version":"1.2.2","new_version":"1.2.3","repository_url":"https://github.com/theskumar/python-dotenv"},{"name":"regex","old_version":"2026.7.10","new_version":"2026.9.10","repository_url":"https://github.com/mrabarnett/mrab-regex"},{"name":"scikit-learn","old_version":"1.9.0","new_version":"1.9.1","repository_url":"https://github.com/scikit-learn/scikit-learn"},{"name":"scipy","old_version":"1.18.0","new_version":"1.18.1","repository_url":"https://github.com/scipy/scipy"},{"name":"smart-open","old_version":"8.0.0","new_version":"8.0.1","repository_url":"https://github.com/piskvorky/smart_open"},{"name":"starlette","old_version":"1.3.1","new_version":"1.6.0","repository_url":"https://github.com/Kludex/starlette"},{"name":"threadpoolctl","old_version":"3.6.0","new_version":"3.7.0","repository_url":"https://github.com/joblib/threadpoolctl"},{"name":"tokenizers","old_version":"0.22.2","new_version":"0.23.2","repository_url":"https://github.com/huggingface/tokenizers"},{"name":"torch","old_version":"2.13.0","new_version":"2.14.0","repository_url":"https://github.com/pytorch/pytorch"},{"name":"tqdm","old_version":"4.68.4","new_version":"4.70.1","repository_url":"https://github.com/tqdm/tqdm"},{"name":"transformers","old_version":"5.14.1","new_version":"5.17.0","repository_url":"https://github.com/huggingface/transformers"},{"name":"typer","old_version":"0.26.8","new_version":"0.27.2","repository_url":"https://github.com/fastapi/typer"},{"name":"typing-inspection","old_version":"0.4.2","new_version":"0.4.4","repository_url":"https://github.com/pydantic/typing-inspection"},{"name":"tzdata","old_version":"2026.3","new_version":"2026.4","repository_url":"https://github.com/python/tzdata"},{"name":"urllib3","old_version":"2.7.0","new_version":"2.8.0","repository_url":"https://github.com/urllib3/urllib3"},{"name":"uvicorn","old_version":"0.51.0","new_version":"0.53.0","repository_url":"https://github.com/Kludex/uvicorn"},{"name":"websocket-client","old_version":"1.9.0","new_version":"1.9.2","repository_url":"https://github.com/websocket-client/websocket-client"},{"name":"wrapt","old_version":"2.2.2","new_version":"2.4.1","repository_url":"https://github.com/GrahamDumpleton/wrapt"},{"name":"yarl","old_version":"1.24.2","new_version":"1.25.1","repository_url":"https://github.com/aio-libs/yarl"}],"path":"/services/ai-orchestrator-service","ecosystem":"pip"},"body":"Bumps the pip-minor-patch group in /services/ai-orchestrator-service with 70 updates:\n\n| Package | From | To |\n| --- | --- | --- |\n| [aiohttp](https://github.com/aio-libs/aiohttp) | `3.14.1` | `3.14.3` |\n| [annotated-doc](https://github.com/fastapi/annotated-doc) | `0.0.4` | `0.0.5` |\n| [annotated-types](https://github.com/annotated-types/annotated-types) | `0.7.0` | `0.8.0` |\n| [anyio](https://github.com/agronholm/anyio) | `4.14.2` | `4.15.1` |\n| [build](https://github.com/pypa/build) | `1.5.0` | `1.6.1` |\n| [certifi](https://github.com/certifi/python-certifi) | `2026.6.17` | `2026.7.22` |\n| [cffi](https://github.com/python-cffi/cffi) | `2.1.0` | `2.1.1` |\n| [charset-normalizer](https://github.com/jawah/charset_normalizer) | `3.4.9` | `3.5.1` |\n| [click](https://github.com/pallets/click) | `8.4.2` | `8.5.0` |\n| [cloudpathlib](https://github.com/drivendataorg/cloudpathlib) | `0.24.0` | `0.25.0` |\n| [contourpy](https://github.com/contourpy/contourpy) | `1.3.3` | `1.4.0` |\n| [durationpy](https://github.com/icholy/durationpy) | `0.10` | `0.11` |\n| [fastapi](https://github.com/fastapi/fastapi) | `0.139.2` | `0.141.1` |\n| [filelock](https://github.com/tox-dev/py-filelock) | `3.30.2` | `3.32.7` |\n| [fonttools](https://github.com/fonttools/fonttools) | `4.63.0` | `4.65.0` |\n| [fsspec](https://github.com/fsspec/filesystem_spec) | `2026.6.0` | `2026.7.0` |\n| [google-auth](https://github.com/googleapis/google-cloud-python) | `2.55.2` | `2.58.0` |\n| [google-genai](https://github.com/googleapis/python-genai) | `2.12.0` | `2.23.0` |\n| [googleapis-common-protos](https://github.com/googleapis/google-cloud-python) | `1.75.0` | `1.75.3` |\n| [grpcio](https://github.com/grpc/grpc) | `1.82.1` | `1.84.0` |\n| [hf-xet](https://github.com/huggingface/xet-core) | `1.5.2` | `1.6.0` |\n| [huggingface-hub](https://github.com/huggingface/huggingface_hub) | `1.23.0` | `1.31.0` |\n| [idna](https://github.com/kjd/idna) | `3.18` | `3.19` |\n| [jiter](https://github.com/pydantic/jiter) | `0.16.0` | `0.17.0` |\n| [joblib](https://github.com/joblib/joblib) | `1.5.3` | `1.6.0` |\n| [kiwisolver](https://github.com/nucleic/kiwi) | `1.5.0` | `1.5.1` |\n| [langchain](https://github.com/langchain-ai/langchain) | `1.3.14` | `1.4.1` |\n| [langchain-core](https://github.com/langchain-ai/langchain) | `1.4.9` | `1.6.3` |\n| [langchain-google-genai](https://github.com/langchain-ai/langchain-google) | `4.2.7` | `4.4.0` |\n| [langchain-protocol](https://github.com/langchain-ai/agent-protocol) | `0.0.18` | `0.0.19` |\n| [langgraph](https://github.com/langchain-ai/langgraph) | `1.2.9` | `1.2.11` |\n| [langgraph-checkpoint](https://github.com/langchain-ai/langgraph) | `4.1.1` | `4.2.0` |\n| [langgraph-sdk](https://github.com/langchain-ai/langgraph) | `0.4.2` | `0.4.4` |\n| [langsmith](https://github.com/langchain-ai/langsmith-sdk) | `0.10.5` | `0.12.6` |\n| [mmh3](https://github.com/hajimes/mmh3) | `5.2.1` | `5.3.0` |\n| [mpmath](https://github.com/mpmath/mpmath) | `1.3.0` | `1.4.1` |\n| [multidict](https://github.com/aio-libs/multidict) | `6.7.1` | `6.8.0` |\n| [narwhals](https://github.com/narwhals-dev/narwhals) | `2.24.0` | `2.26.0` |\n| [numpy](https://github.com/numpy/numpy) | `2.5.1` | `2.5.3` |\n| [onnxruntime](https://github.com/microsoft/onnxruntime) | `1.27.0` | `1.30.0` |\n| [orjson](https://github.com/ijl/orjson) | `3.11.9` | `3.12.0` |\n| [packaging](https://github.com/pypa/packaging) | `26.2` | `26.3` |\n| [pandas](https://github.com/pandas-dev/pandas) | `3.0.3` | `3.0.5` |\n| [propcache](https://github.com/aio-libs/propcache) | `0.5.2` | `0.5.4` |\n| [protobuf](https://github.com/protocolbuffers/protobuf) | `7.35.1` | `7.36.1` |\n| [pybase64](https://github.com/mayeut/pybase64) | `1.4.3` | `1.5.0` |\n| [pydantic](https://github.com/pydantic/pydantic) | `2.13.4` | `2.13.5` |\n| [pydantic-settings](https://github.com/pydantic/pydantic-settings) | `2.14.2` | `2.15.0` |\n| [pydantic-core](https://github.com/pydantic/pydantic) | `2.46.4` | `2.49.0` |\n| [pygments](https://github.com/pygments/pygments) | `2.20.0` | `2.21.0` |\n| [pyproject-hooks](https://github.com/pypa/pyproject-hooks) | `1.2.0` | `1.3.3` |\n| [python-dotenv](https://github.com/theskumar/python-dotenv) | `1.2.2` | `1.2.3` |\n| [regex](https://github.com/mrabarnett/mrab-regex) | `2026.7.10` | `2026.9.10` |\n| [scikit-learn](https://github.com/scikit-learn/scikit-learn) | `1.9.0` | `1.9.1` |\n| [scipy](https://github.com/scipy/scipy) | `1.18.0` | `1.18.1` |\n| [smart-open](https://github.com/piskvorky/smart_open) | `8.0.0` | `8.0.1` |\n| [starlette](https://github.com/Kludex/starlette) | `1.3.1` | `1.6.0` |\n| [threadpoolctl](https://github.com/joblib/threadpoolctl) | `3.6.0` | `3.7.0` |\n| [tokenizers](https://github.com/huggingface/tokenizers) | `0.22.2` | `0.23.2` |\n| [torch](https://github.com/pytorch/pytorch) | `2.13.0` | `2.14.0` |\n| [tqdm](https://github.com/tqdm/tqdm) | `4.68.4` | `4.70.1` |\n| [transformers](https://github.com/huggingface/transformers) | `5.14.1` | `5.17.0` |\n| [typer](https://github.com/fastapi/typer) | `0.26.8` | `0.27.2` |\n| [typing-inspection](https://github.com/pydantic/typing-inspection) | `0.4.2` | `0.4.4` |\n| [tzdata](https://github.com/python/tzdata) | `2026.3` | `2026.4` |\n| [urllib3](https://github.com/urllib3/urllib3) | `2.7.0` | `2.8.0` |\n| [uvicorn](https://github.com/Kludex/uvicorn) | `0.51.0` | `0.53.0` |\n| [websocket-client](https://github.com/websocket-client/websocket-client) | `1.9.0` | `1.9.2` |\n| [wrapt](https://github.com/GrahamDumpleton/wrapt) | `2.2.2` | `2.4.1` |\n| [yarl](https://github.com/aio-libs/yarl) | `1.24.2` | `1.25.1` |\n\nUpdates `aiohttp` from 3.14.1 to 3.14.3\nUpdates `annotated-doc` from 0.0.4 to 0.0.5\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/fastapi/annotated-doc/releases\"\u003eannotated-doc's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e0.0.5\u003c/h2\u003e\n\u003ch3\u003eBreaking Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e➖ Drop support for Python 3.8. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/36\"\u003e#36\u003c/a\u003e by \u003ca href=\"https://github.com/svlandeg\"\u003e\u003ccode\u003e@​svlandeg\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eUpgrades\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e⬆ Bump ruff from 0.14.3 to 0.14.10. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/31\"\u003e#31\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDocs\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e📝 Update security policy. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/63\"\u003e#63\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eInternal\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e⬆️ Upgrade latest-changes to 0.7.1. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/92\"\u003e#92\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump the github-actions group across 1 directory with 3 updates. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/91\"\u003e#91\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump the python-packages group across 1 directory with 3 updates. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/90\"\u003e#90\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump pre-commit hooks. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/89\"\u003e#89\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e👷 Add GH workflow to bump pre-commit hook versions. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/81\"\u003e#81\u003c/a\u003e by \u003ca href=\"https://github.com/YuriiMotov\"\u003e\u003ccode\u003e@​YuriiMotov\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e🔧 Set Dependabot schedule interval to \u0026quot;monthly\u0026quot;. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/82\"\u003e#82\u003c/a\u003e by \u003ca href=\"https://github.com/YuriiMotov\"\u003e\u003ccode\u003e@​YuriiMotov\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e👷 Fix latest-changes checkout target. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/85\"\u003e#85\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆️ Update issue-manager to 0.8.1. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/84\"\u003e#84\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆️ Update latest-changes to 0.6.1. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/83\"\u003e#83\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump the python-packages group across 1 directory with 3 updates. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/72\"\u003e#72\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump the github-actions group across 1 directory with 3 updates. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/80\"\u003e#80\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump \u003ca href=\"https://github.com/crate-ci/typos\"\u003ehttps://github.com/crate-ci/typos\u003c/a\u003e from v1.46.0 to 1.47.2 in the pre-commit group across 1 directory. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/76\"\u003e#76\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e👷 Simplify pull request workflow triggers. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/79\"\u003e#79\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e👷 Update issue-manager to 0.7.1. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/78\"\u003e#78\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆️ Update issue-manager to 0.7.0. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/77\"\u003e#77\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e🔒️ Update zizmor workflow security checks. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/75\"\u003e#75\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e👷 Fix alls-green test dependency. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/74\"\u003e#74\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e👷 Add pre-commit hook to catch typos. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/68\"\u003e#68\u003c/a\u003e by \u003ca href=\"https://github.com/YuriiMotov\"\u003e\u003ccode\u003e@​YuriiMotov\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump the python-packages group with 3 updates. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/70\"\u003e#70\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump the github-actions group with 2 updates. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/71\"\u003e#71\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e👷 Automate release preparation. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/69\"\u003e#69\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e👷 Configure Dependabot to group updates and update weekly. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/62\"\u003e#62\u003c/a\u003e by \u003ca href=\"https://github.com/YuriiMotov\"\u003e\u003ccode\u003e@​YuriiMotov\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e🔥 Remove config files now in central GitHub repo. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/65\"\u003e#65\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e👷 Fix branch name in \u003ccode\u003eguard-dependencies.yml\u003c/code\u003e. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/61\"\u003e#61\u003c/a\u003e by \u003ca href=\"https://github.com/svlandeg\"\u003e\u003ccode\u003e@​svlandeg\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e🔒️ Only allow team members to modify dependencies. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/60\"\u003e#60\u003c/a\u003e by \u003ca href=\"https://github.com/svlandeg\"\u003e\u003ccode\u003e@​svlandeg\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump ty from 0.0.33 to 0.0.34. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/58\"\u003e#58\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump prek from 0.3.11 to 0.3.13. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/59\"\u003e#59\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e🔒️ Add zizmor and fix audit findings. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/50\"\u003e#50\u003c/a\u003e by \u003ca href=\"https://github.com/YuriiMotov\"\u003e\u003ccode\u003e@​YuriiMotov\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆️ Bump the lower bound of \u003ccode\u003ety\u003c/code\u003e to 0.0.25. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/57\"\u003e#57\u003c/a\u003e by \u003ca href=\"https://github.com/svlandeg\"\u003e\u003ccode\u003e@​svlandeg\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e👷 Configure \u003ccode\u003ety\u003c/code\u003e to exit with error code on warnings. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/56\"\u003e#56\u003c/a\u003e by \u003ca href=\"https://github.com/svlandeg\"\u003e\u003ccode\u003e@​svlandeg\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump actions/add-to-project from 1.0.2 to 2.0.0. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/54\"\u003e#54\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump actions/labeler from 6.0.1 to 6.1.0. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/55\"\u003e#55\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump ruff from 0.15.8 to 0.15.12. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/51\"\u003e#51\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump prek from 0.3.8 to 0.3.11. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/53\"\u003e#53\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump ty from 0.0.27 to 0.0.33. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/52\"\u003e#52\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/fastapi/annotated-doc/blob/main/release-notes.md\"\u003eannotated-doc's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e0.0.5 (2026-07-28)\u003c/h2\u003e\n\u003ch3\u003eBreaking Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e➖ Drop support for Python 3.8. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/36\"\u003e#36\u003c/a\u003e by \u003ca href=\"https://github.com/svlandeg\"\u003e\u003ccode\u003e@​svlandeg\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eUpgrades\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e⬆ Bump ruff from 0.14.3 to 0.14.10. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/31\"\u003e#31\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDocs\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e📝 Update security policy. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/63\"\u003e#63\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eInternal\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e⬆️ Upgrade latest-changes to 0.7.1. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/92\"\u003e#92\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump the github-actions group across 1 directory with 3 updates. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/91\"\u003e#91\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump the python-packages group across 1 directory with 3 updates. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/90\"\u003e#90\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump pre-commit hooks. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/89\"\u003e#89\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e👷 Add GH workflow to bump pre-commit hook versions. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/81\"\u003e#81\u003c/a\u003e by \u003ca href=\"https://github.com/YuriiMotov\"\u003e\u003ccode\u003e@​YuriiMotov\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e🔧 Set Dependabot schedule interval to \u0026quot;monthly\u0026quot;. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/82\"\u003e#82\u003c/a\u003e by \u003ca href=\"https://github.com/YuriiMotov\"\u003e\u003ccode\u003e@​YuriiMotov\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e👷 Fix latest-changes checkout target. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/85\"\u003e#85\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆️ Update issue-manager to 0.8.1. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/84\"\u003e#84\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆️ Update latest-changes to 0.6.1. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/83\"\u003e#83\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump the python-packages group across 1 directory with 3 updates. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/72\"\u003e#72\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump the github-actions group across 1 directory with 3 updates. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/80\"\u003e#80\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump \u003ca href=\"https://github.com/crate-ci/typos\"\u003ehttps://github.com/crate-ci/typos\u003c/a\u003e from v1.46.0 to 1.47.2 in the pre-commit group across 1 directory. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/76\"\u003e#76\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e👷 Simplify pull request workflow triggers. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/79\"\u003e#79\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e👷 Update issue-manager to 0.7.1. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/78\"\u003e#78\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆️ Update issue-manager to 0.7.0. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/77\"\u003e#77\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e🔒️ Update zizmor workflow security checks. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/75\"\u003e#75\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e👷 Fix alls-green test dependency. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/74\"\u003e#74\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e👷 Add pre-commit hook to catch typos. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/68\"\u003e#68\u003c/a\u003e by \u003ca href=\"https://github.com/YuriiMotov\"\u003e\u003ccode\u003e@​YuriiMotov\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump the python-packages group with 3 updates. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/70\"\u003e#70\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump the github-actions group with 2 updates. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/71\"\u003e#71\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e👷 Automate release preparation. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/69\"\u003e#69\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e👷 Configure Dependabot to group updates and update weekly. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/62\"\u003e#62\u003c/a\u003e by \u003ca href=\"https://github.com/YuriiMotov\"\u003e\u003ccode\u003e@​YuriiMotov\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e🔥 Remove config files now in central GitHub repo. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/65\"\u003e#65\u003c/a\u003e by \u003ca href=\"https://github.com/tiangolo\"\u003e\u003ccode\u003e@​tiangolo\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e👷 Fix branch name in \u003ccode\u003eguard-dependencies.yml\u003c/code\u003e. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/61\"\u003e#61\u003c/a\u003e by \u003ca href=\"https://github.com/svlandeg\"\u003e\u003ccode\u003e@​svlandeg\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e🔒️ Only allow team members to modify dependencies. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/60\"\u003e#60\u003c/a\u003e by \u003ca href=\"https://github.com/svlandeg\"\u003e\u003ccode\u003e@​svlandeg\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump ty from 0.0.33 to 0.0.34. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/58\"\u003e#58\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump prek from 0.3.11 to 0.3.13. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/59\"\u003e#59\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e🔒️ Add zizmor and fix audit findings. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/50\"\u003e#50\u003c/a\u003e by \u003ca href=\"https://github.com/YuriiMotov\"\u003e\u003ccode\u003e@​YuriiMotov\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆️ Bump the lower bound of \u003ccode\u003ety\u003c/code\u003e to 0.0.25. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/57\"\u003e#57\u003c/a\u003e by \u003ca href=\"https://github.com/svlandeg\"\u003e\u003ccode\u003e@​svlandeg\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e👷 Configure \u003ccode\u003ety\u003c/code\u003e to exit with error code on warnings. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/56\"\u003e#56\u003c/a\u003e by \u003ca href=\"https://github.com/svlandeg\"\u003e\u003ccode\u003e@​svlandeg\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump actions/add-to-project from 1.0.2 to 2.0.0. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/54\"\u003e#54\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump actions/labeler from 6.0.1 to 6.1.0. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/55\"\u003e#55\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump ruff from 0.15.8 to 0.15.12. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/51\"\u003e#51\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e⬆ Bump prek from 0.3.8 to 0.3.11. PR \u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/pull/53\"\u003e#53\u003c/a\u003e by \u003ca href=\"https://github.com/apps/dependabot\"\u003e\u003ccode\u003e@​dependabot[bot]\u003c/code\u003e\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastapi/annotated-doc/commit/ef48d6ad51d226f772fd9c5284f55199afe4007c\"\u003e\u003ccode\u003eef48d6a\u003c/code\u003e\u003c/a\u003e 🔖 Release version 0.0.5 (\u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/issues/93\"\u003e#93\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastapi/annotated-doc/commit/c628000835a26f6bc8c776f90bcbcf95211f233b\"\u003e\u003ccode\u003ec628000\u003c/code\u003e\u003c/a\u003e 📝 Update release notes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastapi/annotated-doc/commit/e0b4579d2ad8d62a304c9f30a1c2c084f0d372e5\"\u003e\u003ccode\u003ee0b4579\u003c/code\u003e\u003c/a\u003e ➖ Drop support for Python 3.8 (\u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/issues/36\"\u003e#36\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastapi/annotated-doc/commit/ef956b4e9f2c0e2bead1cba7a6888e1ed8c2c237\"\u003e\u003ccode\u003eef956b4\u003c/code\u003e\u003c/a\u003e 📝 Update release notes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastapi/annotated-doc/commit/84bf1e5402c5e0cfd1462c5d3c8bae22fb717bd8\"\u003e\u003ccode\u003e84bf1e5\u003c/code\u003e\u003c/a\u003e ⬆️ Upgrade latest-changes to 0.7.1 (\u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/issues/92\"\u003e#92\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastapi/annotated-doc/commit/cf773e138b1dc5608ce0f0d11e1939c410ef6228\"\u003e\u003ccode\u003ecf773e1\u003c/code\u003e\u003c/a\u003e 📝 Update release notes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastapi/annotated-doc/commit/1375d6eb8147cb2352d080ef09f356dfc18e0d29\"\u003e\u003ccode\u003e1375d6e\u003c/code\u003e\u003c/a\u003e ⬆ Bump the github-actions group across 1 directory with 3 updates (\u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/issues/91\"\u003e#91\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastapi/annotated-doc/commit/cd373656cbf40e5fd4cc28680ca5e05bf12709cb\"\u003e\u003ccode\u003ecd37365\u003c/code\u003e\u003c/a\u003e 📝 Update release notes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastapi/annotated-doc/commit/f9f3b695cbacc4ffc37d9cebff6e05bd1751f68a\"\u003e\u003ccode\u003ef9f3b69\u003c/code\u003e\u003c/a\u003e ⬆ Bump the python-packages group across 1 directory with 3 updates (\u003ca href=\"https://redirect.github.com/fastapi/annotated-doc/issues/90\"\u003e#90\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fastapi/annotated-doc/commit/842084457f0a7739fb91d2a4ea602b2bc4e15767\"\u003e\u003ccode\u003e8420844\u003c/code\u003e\u003c/a\u003e 📝 Update release notes\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/fastapi/annotated-doc/compare/0.0.4...0.0.5\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `annotated-types` from 0.7.0 to 0.8.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/annotated-types/annotated-types/releases\"\u003eannotated-types's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev0.8.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRename DocInfo to Doc by \u003ca href=\"https://github.com/zen-xu\"\u003e\u003ccode\u003e@​zen-xu\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/pull/80\"\u003eannotated-types/annotated-types#80\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd support for Python 3.13 by \u003ca href=\"https://github.com/hugovk\"\u003e\u003ccode\u003e@​hugovk\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/pull/83\"\u003eannotated-types/annotated-types#83\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix docstring of \u003ccode\u003eTimezone\u003c/code\u003e by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/pull/84\"\u003eannotated-types/annotated-types#84\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate license-files to be PEP-639 compliant (\u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/issues/85\"\u003e#85\u003c/a\u003e) by \u003ca href=\"https://github.com/shoeffner\"\u003e\u003ccode\u003e@​shoeffner\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/pull/86\"\u003eannotated-types/annotated-types#86\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: typo in README.md by \u003ca href=\"https://github.com/camiloaz\"\u003e\u003ccode\u003e@​camiloaz\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/pull/87\"\u003eannotated-types/annotated-types#87\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eadd CI for PyPy3.11 and fix test (issue 71) by \u003ca href=\"https://github.com/mattip\"\u003e\u003ccode\u003e@​mattip\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/pull/88\"\u003eannotated-types/annotated-types#88\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix string predicate names in doc by \u003ca href=\"https://github.com/leogermond\"\u003e\u003ccode\u003e@​leogermond\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/pull/90\"\u003eannotated-types/annotated-types#90\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd SPDX license expression by \u003ca href=\"https://github.com/wichert\"\u003e\u003ccode\u003e@​wichert\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/pull/92\"\u003eannotated-types/annotated-types#92\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdded Python 3.14 to the test matrix by \u003ca href=\"https://github.com/imtoopunkforyou\"\u003e\u003ccode\u003e@​imtoopunkforyou\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/pull/96\"\u003eannotated-types/annotated-types#96\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd support for Python 3.14 and drop EOL 3.8-3.9 by \u003ca href=\"https://github.com/hugovk\"\u003e\u003ccode\u003e@​hugovk\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/pull/97\"\u003eannotated-types/annotated-types#97\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix typo in \u003ccode\u003eLen\u003c/code\u003e docstring by \u003ca href=\"https://github.com/Dutcho\"\u003e\u003ccode\u003e@​Dutcho\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/pull/100\"\u003eannotated-types/annotated-types#100\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePrepare for 0.8.0 release by \u003ca href=\"https://github.com/adriangb\"\u003e\u003ccode\u003e@​adriangb\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/pull/103\"\u003eannotated-types/annotated-types#103\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/zen-xu\"\u003e\u003ccode\u003e@​zen-xu\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/pull/80\"\u003eannotated-types/annotated-types#80\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hugovk\"\u003e\u003ccode\u003e@​hugovk\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/pull/83\"\u003eannotated-types/annotated-types#83\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/shoeffner\"\u003e\u003ccode\u003e@​shoeffner\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/pull/86\"\u003eannotated-types/annotated-types#86\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/camiloaz\"\u003e\u003ccode\u003e@​camiloaz\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/pull/87\"\u003eannotated-types/annotated-types#87\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mattip\"\u003e\u003ccode\u003e@​mattip\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/pull/88\"\u003eannotated-types/annotated-types#88\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/leogermond\"\u003e\u003ccode\u003e@​leogermond\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/pull/90\"\u003eannotated-types/annotated-types#90\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/wichert\"\u003e\u003ccode\u003e@​wichert\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/pull/92\"\u003eannotated-types/annotated-types#92\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/imtoopunkforyou\"\u003e\u003ccode\u003e@​imtoopunkforyou\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/pull/96\"\u003eannotated-types/annotated-types#96\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Dutcho\"\u003e\u003ccode\u003e@​Dutcho\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/pull/100\"\u003eannotated-types/annotated-types#100\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/annotated-types/annotated-types/compare/v0.7.0...v0.8.0\"\u003ehttps://github.com/annotated-types/annotated-types/compare/v0.7.0...v0.8.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/annotated-types/annotated-types/commit/9eb96680138269811a39d838d720abc3dce33954\"\u003e\u003ccode\u003e9eb9668\u003c/code\u003e\u003c/a\u003e Prepare for 0.8.0 release (\u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/issues/103\"\u003e#103\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/annotated-types/annotated-types/commit/10b77644f88b385357653730a1ab23748ca3ae2e\"\u003e\u003ccode\u003e10b7764\u003c/code\u003e\u003c/a\u003e Fix typo in \u003ccode\u003eLen\u003c/code\u003e docstring (\u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/issues/100\"\u003e#100\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/annotated-types/annotated-types/commit/955f7576d616feb6e9407c74498517787c38afd4\"\u003e\u003ccode\u003e955f757\u003c/code\u003e\u003c/a\u003e Add support for Python 3.14 and drop EOL 3.8-3.9 (\u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/issues/97\"\u003e#97\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/annotated-types/annotated-types/commit/bd280fea7983550d266f993d868b8dd7ff822bf1\"\u003e\u003ccode\u003ebd280fe\u003c/code\u003e\u003c/a\u003e Added Python 3.14 to the test matrix (\u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/issues/96\"\u003e#96\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/annotated-types/annotated-types/commit/a471bb757663452459893e6f593118ec21eb1b9e\"\u003e\u003ccode\u003ea471bb7\u003c/code\u003e\u003c/a\u003e Add SPDX license expression (\u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/issues/92\"\u003e#92\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/annotated-types/annotated-types/commit/eab91d9a8c0d3f73661fc4b0794a1fe76c94fa84\"\u003e\u003ccode\u003eeab91d9\u003c/code\u003e\u003c/a\u003e Fix string predicate names in doc (\u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/issues/90\"\u003e#90\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/annotated-types/annotated-types/commit/03ad9c3c7b4d4dfe9e33c09075a3a2766c0820e1\"\u003e\u003ccode\u003e03ad9c3\u003c/code\u003e\u003c/a\u003e add CI for PyPy3.11 and fix test (issue 71) (\u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/issues/88\"\u003e#88\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/annotated-types/annotated-types/commit/5ae60437f0ab493cedd27311bc6ce6d2188e8d8b\"\u003e\u003ccode\u003e5ae6043\u003c/code\u003e\u003c/a\u003e fix: typo in README.md (\u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/issues/87\"\u003e#87\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/annotated-types/annotated-types/commit/b60ad7bff90019c7de3547df1c8e3586eb328423\"\u003e\u003ccode\u003eb60ad7b\u003c/code\u003e\u003c/a\u003e Update license-files to be PEP-639 compliant (\u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/issues/85\"\u003e#85\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/issues/86\"\u003e#86\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/annotated-types/annotated-types/commit/3fbeb6d129760ae48d7a0372fb9301764acc95ae\"\u003e\u003ccode\u003e3fbeb6d\u003c/code\u003e\u003c/a\u003e Fix docstring of \u003ccode\u003eTimezone\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/annotated-types/annotated-types/issues/84\"\u003e#84\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/annotated-types/annotated-types/compare/v0.7.0...v0.8.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `anyio` from 4.14.2 to 4.15.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/agronholm/anyio/releases\"\u003eanyio's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e4.15.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImplemented a compatibility fix for supporting direct access of \u003ccode\u003eanyio.*\u003c/code\u003e submodules from the main package even when those submodules were not directly imported first (\u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1311\"\u003e#1311\u003c/a\u003e \u0026lt;\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1311%5C%3E\"\u003eagronholm/anyio#1311\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.15.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eAdded support for the newer keyword-only arguments on \u003ccode\u003eanyio.Path\u003c/code\u003e methods to match the standard library \u003ccode\u003epathlib.Path\u003c/code\u003e:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003efollow_symlinks\u003c/code\u003e on \u003ccode\u003eexists()\u003c/code\u003e (Python 3.12+)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003efollow_symlinks\u003c/code\u003e on \u003ccode\u003eis_dir()\u003c/code\u003e (Python 3.13+)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003efollow_symlinks\u003c/code\u003e on \u003ccode\u003eis_file()\u003c/code\u003e (Python 3.13+)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003efollow_symlinks\u003c/code\u003e on \u003ccode\u003eowner()\u003c/code\u003e (Python 3.13+)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003efollow_symlinks\u003c/code\u003e on \u003ccode\u003egroup()\u003c/code\u003e (Python 3.13+)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003enewline\u003c/code\u003e on \u003ccode\u003eread_text()\u003c/code\u003e (Python 3.13+)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e(\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1286\"\u003e#1286\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1293\"\u003e#1293\u003c/a\u003e; PR by \u003ca href=\"https://github.com/jaideeppyne\"\u003e\u003ccode\u003e@​jaideeppyne\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAdded \u003ccode\u003eamap\u003c/code\u003e, \u003ccode\u003egather\u003c/code\u003e, and \u003ccode\u003eas_completed\u003c/code\u003e utility functions to simplify common patterns (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1173\"\u003e#1173\u003c/a\u003e; PR by \u003ca href=\"https://github.com/Graeme22\"\u003e\u003ccode\u003e@​Graeme22\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAdded \u003ccode\u003e--anyio-mode\u003c/code\u003e command-line option as an alternative to the \u003ccode\u003eanyio_mode\u003c/code\u003e ini setting, and fix the pytest plugin's auto mode detection to recognize the mode when set via either mechanism(e.g: \u003ccode\u003epytest_asyncio\u003c/code\u003e). (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1242\"\u003e#1242\u003c/a\u003e; PR by \u003ca href=\"https://github.com/EmmanuelNiyonshuti\"\u003e\u003ccode\u003e@​EmmanuelNiyonshuti\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAdded the \u003ccode\u003eanyio.Future\u003c/code\u003e synchronization primitive which behaves similar to \u003ccode\u003easyncio.Future\u003c/code\u003e, allowing tasks to wait for a value (or exception) from another task (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1146\"\u003e#1146\u003c/a\u003e; PR by \u003ca href=\"https://github.com/Vizonex\"\u003e\u003ccode\u003e@​Vizonex\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAdded guidance for managing multiple memory object stream producers and consumers with cloned streams (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/330\"\u003e#330\u003c/a\u003e; PR by \u003ca href=\"https://github.com/nightcityblade\"\u003e\u003ccode\u003e@​nightcityblade\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAdded \u003ccode\u003eStapledObjectStream.send_nowait()\u003c/code\u003e that delegates to the underlying \u003ccode\u003eObjectSendStream\u003c/code\u003e, if it implements it (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1241\"\u003e#1241\u003c/a\u003e; PR by \u003ca href=\"https://github.com/davidbrochart\"\u003e\u003ccode\u003e@​davidbrochart\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAdded the \u003ccode\u003emove_on_at()\u003c/code\u003e and \u003ccode\u003efail_at()\u003c/code\u003e functions to complement \u003ccode\u003emove_on_after()\u003c/code\u003e and \u003ccode\u003efail_after()\u003c/code\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eChanged the default name for a task spawned with \u003ccode\u003eTaskGroup.create_task(func())\u003c/code\u003e to match the default task name for the analogous task spawned with \u003ccode\u003eTaskGroup.start_soon(func)\u003c/code\u003e or \u003ccode\u003eTaskGroup.start(func)\u003c/code\u003e in more situations. Previously, the default name of a \u003ccode\u003eTaskGroup.create_task\u003c/code\u003e task never included the module name. (The default name for a task spawned with \u003ccode\u003eTaskGroup.start_soon\u003c/code\u003e or \u003ccode\u003eTaskGroup.start\u003c/code\u003e typically includes the module name.) (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1234\"\u003e#1234\u003c/a\u003e; PR by \u003ca href=\"https://github.com/gschaffner\"\u003e\u003ccode\u003e@​gschaffner\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eChanged the \u003ccode\u003eanyio\u003c/code\u003e and \u003ccode\u003eanyio.abc\u003c/code\u003e modules to lazily (much like \u003ccode\u003e810\u003c/code\u003e) import the necessary submodules. This is done by parsing the AST of the module and building a lookup table from the \u003ccode\u003eif TYPE_CHECKING:\u003c/code\u003e block. A fallback mode has been provided for installations where the source code is unavailable (e.g. PyInstaller). (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1169\"\u003e#1169\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed free-threading compatibility issues arising from the fact that on Python 3.14 free-threading builds, newly created threads inherit the current context by default, causing AnyIO to behave erroneously in relation to \u003ccode\u003estart_blocking_portal()\u003c/code\u003e and \u003ccode\u003eanyio.to_thread.run_sync()\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1224\"\u003e#1224\u003c/a\u003e; PR by \u003ca href=\"https://github.com/EmmanuelNiyonshuti\"\u003e\u003ccode\u003e@​EmmanuelNiyonshuti\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed \u003ccode\u003eSpooledTemporaryFile.readinto()\u003c/code\u003e and \u003ccode\u003ereadinto1()\u003c/code\u003e reading twice before rollover, so the destination buffer was overwritten by the second read and the file position advanced twice, silently losing data (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1215\"\u003e#1215\u003c/a\u003e; PR by \u003ca href=\"https://github.com/c-tonneslan\"\u003e\u003ccode\u003e@​c-tonneslan\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAdded a \u003ccode\u003ereason\u003c/code\u003e parameter to \u003ccode\u003efail_after\u003c/code\u003e (and the new \u003ccode\u003efail_at\u003c/code\u003e) allowing for added exception context when raising \u003ccode\u003eTimeoutError\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1227\"\u003e#1227\u003c/a\u003e; PR by \u003ca href=\"https://github.com/Graeme22\"\u003e\u003ccode\u003e@​Graeme22\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed the default \u003ccode\u003eTaskHandle.name\u003c/code\u003e missing part of the task name for tasks started with \u003ccode\u003eTaskGroup.start\u003c/code\u003e on Trio (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1231\"\u003e#1231\u003c/a\u003e; PR by \u003ca href=\"https://github.com/gschaffner\"\u003e\u003ccode\u003e@​gschaffner\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed \u003ccode\u003eanyio.run\u003c/code\u003e leaking, or at least, delaying collection of loop and root_task due to the root task being cached in a \u003ccode\u003eRunVar\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1203\"\u003e#1203\u003c/a\u003e; PR by \u003ca href=\"https://github.com/tapetersen\"\u003e\u003ccode\u003e@​tapetersen\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed \u003ccode\u003eanyio.Path.with_stem()\u003c/code\u003e silently producing a wrong path (e.g. \u003ccode\u003ePath(\u0026quot;.txt\u0026quot;)\u003c/code\u003e) instead of raising \u003ccode\u003eValueError\u003c/code\u003e when given an empty stem on a path with a non-empty suffix, unlike \u003ccode\u003epathlib.PurePath.with_stem\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1200\"\u003e#1200\u003c/a\u003e; PR by \u003ca href=\"https://github.com/Sanjays2402\"\u003e\u003ccode\u003e@​Sanjays2402\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed \u003ccode\u003eUNIXSocketStream.aclose()\u003c/code\u003e raising \u003ccode\u003easyncio.InvalidStateError\u003c/code\u003e when a concurrent receive or send operation had just been cancelled on the asyncio backend (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1267\"\u003e#1267\u003c/a\u003e; PR by \u003ca href=\"https://github.com/alloutflo\"\u003e\u003ccode\u003e@​alloutflo\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed the pytest plugin importing the deprecated \u003ccode\u003e_pytest.python.CallSpec2\u003c/code\u003e alias, which triggers \u003ccode\u003ePytestRemovedIn10Warning\u003c/code\u003e on \u003ccode\u003epytest\u0026gt;=9.2\u003c/code\u003e and crashes pytest at startup when \u003ccode\u003efilterwarnings = error\u003c/code\u003e is configured (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1271\"\u003e#1271\u003c/a\u003e; PR by \u003ca href=\"https://github.com/matthewfeickert\"\u003e\u003ccode\u003e@​matthewfeickert\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed an asyncio worker thread race that could raise \u003ccode\u003eRuntimeError\u003c/code\u003e when the event loop closed between checking its state and scheduling the worker result (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1265\"\u003e#1265\u003c/a\u003e; PR by \u003ca href=\"https://github.com/hansu650\"\u003e\u003ccode\u003e@​hansu650\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFixed \u003ccode\u003eCapacityLimiter\u003c/code\u003e on the asyncio backend over-granting tokens when \u003ccode\u003etotal_tokens\u003c/code\u003e was raised while the limiter was over-subscribed (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1223\"\u003e#1223\u003c/a\u003e; PR by \u003ca href=\"https://github.com/zelinewang\"\u003e\u003ccode\u003e@​zelinewang\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/ffcd1542cd6d127980205f90a0100078849dd703\"\u003e\u003ccode\u003effcd154\u003c/code\u003e\u003c/a\u003e Bumped up the version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/0ecf5ed98d294242509b043ebd1a0843e52d892f\"\u003e\u003ccode\u003e0ecf5ed\u003c/code\u003e\u003c/a\u003e Added a workaround for third party code accessing unimported submodules (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1309\"\u003e#1309\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/928366259543412a2deb1e2ba09ea45ffa92ef4f\"\u003e\u003ccode\u003e9283662\u003c/code\u003e\u003c/a\u003e Bumped up the version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/d137692a90f76e4f71605e32ea5ca94cab3a539d\"\u003e\u003ccode\u003ed137692\u003c/code\u003e\u003c/a\u003e Improved the instructions for AI agents\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/033fc52b8fa8e90c5d0ef24b10b3860e974a6265\"\u003e\u003ccode\u003e033fc52\u003c/code\u003e\u003c/a\u003e Shield TemporaryDirectory cleanup from cancellation (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1304\"\u003e#1304\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/942e9a6552cc10b5aaa779d84bfc8e2c3d5fcffc\"\u003e\u003ccode\u003e942e9a6\u003c/code\u003e\u003c/a\u003e [pre-commit.ci] pre-commit autoupdate (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1305\"\u003e#1305\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/b825c3be7cb4ca1a8000b8065d4e147843deb704\"\u003e\u003ccode\u003eb825c3b\u003c/code\u003e\u003c/a\u003e Fixed pyproject.toml changes not triggering the test suite\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/9727dc504681e2986b5bc285de9571fb467539af\"\u003e\u003ccode\u003e9727dc5\u003c/code\u003e\u003c/a\u003e Fixed start inconsistencies between trio and asyncio (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1198\"\u003e#1198\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/b05fe6d160a640355c201363cab286a7d2581da8\"\u003e\u003ccode\u003eb05fe6d\u003c/code\u003e\u003c/a\u003e Fixed wrong type in move_on_after (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1297\"\u003e#1297\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/44d0c93cc20079acbf38ba4dbed5ab9df323f153\"\u003e\u003ccode\u003e44d0c93\u003c/code\u003e\u003c/a\u003e Fixed asyncio task group coroutine cleanup (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1275\"\u003e#1275\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/agronholm/anyio/compare/4.14.2...4.15.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `build` from 1.5.0 to 1.6.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pypa/build/releases\"\u003ebuild's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e1.6.1\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003echore[v1]: prepare for v1.6.1 by \u003ca href=\"https://github.com/henryiii\"\u003e\u003ccode\u003e@​henryiii\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1181\"\u003epypa/build#1181\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/pypa/build/compare/1.6.0...1.6.1\"\u003ehttps://github.com/pypa/build/compare/1.6.0...1.6.1\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003e1.6.0\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eReplace prettier with mdformat and yamlfmt by \u003ca href=\"https://github.com/gaborbernat\"\u003e\u003ccode\u003e@​gaborbernat\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1133\"\u003epypa/build#1133\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eLet yamlfmt format the workflows by \u003ca href=\"https://github.com/gaborbernat\"\u003e\u003ccode\u003e@​gaborbernat\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1134\"\u003epypa/build#1134\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e🐛 fix(release): semver auto bump, changelog reflow, and roll back 1.5.1 by \u003ca href=\"https://github.com/gaborbernat\"\u003e\u003ccode\u003e@​gaborbernat\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1132\"\u003epypa/build#1132\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: hash verification in --dependency-constraints-txt could be silently skipped by \u003ca href=\"https://github.com/manfred-kaiser\"\u003e\u003ccode\u003e@​manfred-kaiser\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1140\"\u003epypa/build#1140\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e🐛 fix(ci): bump build-and-inspect-python-package to v3.0.1 by \u003ca href=\"https://github.com/gaborbernat\"\u003e\u003ccode\u003e@​gaborbernat\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1147\"\u003epypa/build#1147\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e🐛 fix(ci): pin coverage core to ctrace so test contexts record by \u003ca href=\"https://github.com/gaborbernat\"\u003e\u003ccode\u003e@​gaborbernat\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1148\"\u003epypa/build#1148\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: run mypy on more parts of the code by \u003ca href=\"https://github.com/henryiii\"\u003e\u003ccode\u003e@​henryiii\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1151\"\u003epypa/build#1151\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: turn up strictness on mypy by \u003ca href=\"https://github.com/henryiii\"\u003e\u003ccode\u003e@​henryiii\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1153\"\u003epypa/build#1153\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: faster mypy, fix merge error by \u003ca href=\"https://github.com/henryiii\"\u003e\u003ccode\u003e@​henryiii\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1156\"\u003epypa/build#1156\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e🐛 fix(ci): rerun integration tests on transient network errors by \u003ca href=\"https://github.com/gaborbernat\"\u003e\u003ccode\u003e@​gaborbernat\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1150\"\u003epypa/build#1150\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: clean up unused casts in tests by \u003ca href=\"https://github.com/henryiii\"\u003e\u003ccode\u003e@​henryiii\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1154\"\u003epypa/build#1154\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003erefactor(typing): apply review feedback from \u003ca href=\"https://redirect.github.com/pypa/build/issues/1093\"\u003e#1093\u003c/a\u003e by \u003ca href=\"https://github.com/henryiii\"\u003e\u003ccode\u003e@​henryiii\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1155\"\u003epypa/build#1155\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: Generator is more accurate than Iterator by \u003ca href=\"https://github.com/henryiii\"\u003e\u003ccode\u003e@​henryiii\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1152\"\u003epypa/build#1152\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etests: mark test_main_sdist_input_end_to_end with pytest.mark.network by \u003ca href=\"https://github.com/frenzymadness\"\u003e\u003ccode\u003e@​frenzymadness\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1144\"\u003epypa/build#1144\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRevert \u0026quot;⚠️ feat(util): deprecate project_wheel_metadata\u0026quot; by \u003ca href=\"https://github.com/henryiii\"\u003e\u003ccode\u003e@​henryiii\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1158\"\u003epypa/build#1158\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etests: download integration sources once per run by \u003ca href=\"https://github.com/henryiii\"\u003e\u003ccode\u003e@​henryiii\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1157\"\u003epypa/build#1157\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUse stdlib \u003ccode\u003eimportlib.metadata\u003c/code\u003e for typing by \u003ca href=\"https://github.com/layday\"\u003e\u003ccode\u003e@​layday\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1162\"\u003epypa/build#1162\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eDrop redundant \u003ccode\u003eexc_info\u003c/code\u003e parameter from backend exception wrapper by \u003ca href=\"https://github.com/layday\"\u003e\u003ccode\u003e@​layday\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1161\"\u003epypa/build#1161\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eDrop a few PyPy-specific test skips by \u003ca href=\"https://github.com/layday\"\u003e\u003ccode\u003e@​layday\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1164\"\u003epypa/build#1164\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e🔧 chore: batch dependency updates weekly on Tuesday by \u003ca href=\"https://github.com/gaborbernat\"\u003e\u003ccode\u003e@​gaborbernat\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1165\"\u003epypa/build#1165\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e👷 ci: use app token for releases by \u003ca href=\"https://github.com/gaborbernat\"\u003e\u003ccode\u003e@​gaborbernat\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1169\"\u003epypa/build#1169\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/manfred-kaiser\"\u003e\u003ccode\u003e@​manfred-kaiser\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1140\"\u003epypa/build#1140\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/frenzymadness\"\u003e\u003ccode\u003e@​frenzymadness\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1144\"\u003epypa/build#1144\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/pypa/build/compare/1.5.1...1.6.0\"\u003ehttps://github.com/pypa/build/compare/1.5.1...1.6.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003e1.5.1\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e✨ feat(cli): accept sdist tarball as srcdir argument by \u003ca href=\"https://github.com/gaborbernat\"\u003e\u003ccode\u003e@​gaborbernat\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1057\"\u003epypa/build#1057\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: drop 3.9 branches for version_info checks by \u003ca href=\"https://github.com/henryiii\"\u003e\u003ccode\u003e@​henryiii\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1059\"\u003epypa/build#1059\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etests: skip test_uv_install_strips_pythonpath with missing uv by \u003ca href=\"https://github.com/mtelka\"\u003e\u003ccode\u003e@​mtelka\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1063\"\u003epypa/build#1063\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: remove myself from codeowners by \u003ca href=\"https://github.com/FFY00\"\u003e\u003ccode\u003e@​FFY00\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1066\"\u003epypa/build#1066\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003erefactor: safe_extractall to use pathlib.Path by \u003ca href=\"https://github.com/henryiii\"\u003e\u003ccode\u003e@​henryiii\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pypa/build/pull/1060\"\u003epypa/build#1060\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pypa/build/blob/main/CHANGELOG.rst\"\u003ebuild's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e####################\n1.6.1 (2026-09-10)\n####################\u003c/p\u003e\n\u003chr /\u003e\n\u003cp\u003eBugfixes\u003c/p\u003e\n\u003chr /\u003e\n\u003cul\u003e\n\u003cli\u003eAvoid trying to detect symlinks on Windows, regression in 1.6.0 - by :user:\u003ccode\u003ehenryiii\u003c/code\u003e (:issue:\u003ccode\u003e1175\u003c/code\u003e) (:issue:\u003ccode\u003e1175\u003c/code\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr /\u003e\n\u003cp\u003eDocumentation\u003c/p\u003e\n\u003chr /\u003e\n\u003cul\u003e\n\u003cli\u003eFix doubled backslashes in the Windows pip config path (\u003ccode\u003e%APPDATA%\\pip\\pip.ini\u003c/code\u003e) in the docs - by :user:\u003ccode\u003earoh3006\u003c/code\u003e\n(:issue:\u003ccode\u003e1149\u003c/code\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr /\u003e\n\u003cp\u003eMiscellaneous\u003c/p\u003e\n\u003chr /\u003e\n\u003cul\u003e\n\u003cli\u003e:issue:\u003ccode\u003e1168\u003c/code\u003e, :issue:\u003ccode\u003e1170\u003c/code\u003e, :issue:\u003ccode\u003e1178\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e####################\n1.6.0 (2026-08-27)\n####################\u003c/p\u003e\n\u003chr /\u003e\n\u003cp\u003eFeatures\u003c/p\u003e\n\u003chr /\u003e\n\u003cul\u003e\n\u003cli\u003eAdd \u003ccode\u003e--report=PATH\u003c/code\u003e to write a machine-readable JSON report of built artifacts; \u003ccode\u003e--metadata\u003c/code\u003e now also accepts\n\u003ccode\u003e.whl\u003c/code\u003e files - by :user:\u003ccode\u003egaborbernat\u003c/code\u003e (:issue:\u003ccode\u003e198\u003c/code\u003e)\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003esrcdir\u003c/code\u003e argument now accepts \u003ccode\u003e.tar.gz\u003c/code\u003e source distributions, extracting and building from them - by\n:user:\u003ccode\u003egaborbernat\u003c/code\u003e (:issue:\u003ccode\u003e311\u003c/code\u003e)\u003c/li\u003e\n\u003cli\u003eThe \u0026quot;Unmet dependencies\u0026quot; error from \u003ccode\u003e--no-isolation\u003c/code\u003e builds now shows the wanted version, found version, and\ninterpreter - by :user:\u003ccode\u003egaborbernat\u003c/code\u003e (:issue:\u003ccode\u003e504\u003c/code\u003e)\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003e--sdist-extract-dir\u003c/code\u003e to extract the intermediate sdist into a persistent directory, enabling compiler cache\nreuse across rebuilds - by :user:\u003ccode\u003egaborbernat\u003c/code\u003e (:issue:\u003ccode\u003e614\u003c/code\u003e)\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003e--env-dir\u003c/code\u003e to place the isolated build environment at a fixed path, enabling compiler cache reuse across builds\n\u003cul\u003e\n\u003cli\u003eby :user:\u003ccode\u003egaborbernat\u003c/code\u003e (:issue:\u003ccode\u003e655\u003c/code\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003ePrint a summary of resolved dependency versions (\u003ccode\u003ename==version\u003c/code\u003e) after installing them in isolated builds - by\n:user:\u003ccode\u003egaborbernat\u003c/code\u003e (:issue:\u003ccode\u003e959\u003c/code\u003e)\u003c/li\u003e\n\u003cli\u003eOn build failure, print a tip pointing to \u003ccode\u003e--env-dir\u003c/code\u003e and \u003ccode\u003e--sdist-extract-dir\u003c/code\u003e for debugging and link to the\n\u0026quot;Debug a failed build\u0026quot; how-to - reported by :user:\u003ccode\u003edimpase\u003c/code\u003e, implemented by :user:\u003ccode\u003egaborbernat\u003c/code\u003e (:issue:\u003ccode\u003e966\u003c/code\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr /\u003e\n\u003cp\u003eBugfixes\u003c/p\u003e\n\u003chr /\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/build/commit/89cccef40df9011f03bec18cf52c53d1096ed6ee\"\u003e\u003ccode\u003e89cccef\u003c/code\u003e\u003c/a\u003e chore: prepare for 1.6.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/build/commit/a6f707a75fc8548d7707645e97c7903197387849\"\u003e\u003ccode\u003ea6f707a\u003c/code\u003e\u003c/a\u003e ci: support releases from v* branches (\u003ca href=\"https://redirect.github.com/pypa/build/issues/1178\"\u003e#1178\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/build/commit/77851610de5d3894fa8a88e06e0232901cf93758\"\u003e\u003ccode\u003e7785161\u003c/code\u003e\u003c/a\u003e docs: fix doubled backslashes in Windows pip config path (\u003ca href=\"https://redirect.github.com/pypa/build/issues/1149\"\u003e#1149\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/build/commit/244b250c3219070eebb29764f7709262d48afd41\"\u003e\u003ccode\u003e244b250\u003c/code\u003e\u003c/a\u003e fix: always use copies for the isolated venv on Windows (\u003ca href=\"https://redirect.github.com/pypa/build/issues/1176\"\u003e#1176\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/build/commit/c93ca6f6d252e4d8df7fda4a61f8f9ed8a55a411\"\u003e\u003ccode\u003ec93ca6f\u003c/code\u003e\u003c/a\u003e build(deps): bump re-actors/alls-green from 1.2.2 to 1.3.0 in the github-acti...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/build/commit/e02ffd32241aec2e306d90869417c1e900c0adb4\"\u003e\u003ccode\u003ee02ffd3\u003c/code\u003e\u003c/a\u003e pre-commit: bump repositories (\u003ca href=\"https://redirect.github.com/pypa/build/issues/1173\"\u003e#1173\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/build/commit/aad39a800e3d81bf907018ebe2fab135717da59b\"\u003e\u003ccode\u003eaad39a8\u003c/code\u003e\u003c/a\u003e docs: fix changelog page heading levels and sidebar (\u003ca href=\"https://redirect.github.com/pypa/build/issues/1171\"\u003e#1171\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/build/commit/5c3fd46b5c38c7caea5dd95ce365971104a734aa\"\u003e\u003ccode\u003e5c3fd46\u003c/code\u003e\u003c/a\u003e docs: use PyPI ref directly (\u003ca href=\"https://redirect.github.com/pypa/build/issues/1172\"\u003e#1172\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/build/commit/1c5bd6c21cbd33c1816978d45219d48fb4c2b269\"\u003e\u003ccode\u003e1c5bd6c\u003c/code\u003e\u003c/a\u003e 🐛 fix(release): format generated changelog (\u003ca href=\"https://redirect.github.com/pypa/build/issues/1170\"\u003e#1170\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/build/commit/7f0cc7ed19969558c7daeaa3652ce2ffc81599c1\"\u003e\u003ccode\u003e7f0cc7e\u003c/code\u003e\u003c/a\u003e 🔧 build(type): replace mypy with pyrefly (\u003ca href=\"https://redirect.github.com/pypa/build/issues/1168\"\u003e#1168\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/pypa/build/compare/1.5.0...1.6.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `certifi` from 2026.6.17 to 2026.7.22\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/certifi/python-certifi/commit/f4bc676bc101fe2235846e37044e8c693d6cbaf4\"\u003e\u003ccode\u003ef4bc676\u003c/code\u003e\u003c/a\u003e 2026.07.22 (\u003ca href=\"https://redirect.github.com/certifi/python-certifi/issues/428\"\u003e#428\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/certifi/python-certifi/commit/4c91f9c5f9b4676d40d2930025ba04d80dd536f6\"\u003e\u003ccode\u003e4c91f9c\u003c/code\u003e\u003c/a\u003e Bump actions/setup-python from 6.3.0 to 7.0.0 (\u003ca href=\"https://redirect.github.com/certifi/python-certifi/issues/427\"\u003e#427\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/certifi/python-certifi/commit/01a66c5cf32eadb8f03a0504c24cb44f6d581248\"\u003e\u003ccode\u003e01a66c5\u003c/code\u003e\u003c/a\u003e Bump actions/checkout from 7.0.0 to 7.0.1 (\u003ca href=\"https://redirect.github.com/certifi/python-certifi/issues/426\"\u003e#426\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/certifi/python-certifi/commit/eb355f41cb71f71012ecf1a4d27a57d0ee2b1337\"\u003e\u003ccode\u003eeb355f4\u003c/code\u003e\u003c/a\u003e Bump pypa/gh-action-pypi-publish from 1.14.0 to 1.14.1 (\u003ca href=\"https://redirect.github.com/certifi/python-certifi/issues/425\"\u003e#425\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/certifi/python-certifi/commit/474e6fc996d55b91632248da0bade702504e62dc\"\u003e\u003ccode\u003e474e6fc\u003c/code\u003e\u003c/a\u003e Include tests in the source distribution (\u003ca href=\"https://redirect.github.com/certifi/python-certifi/issues/424\"\u003e#424\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/certifi/python-certifi/commit/a31ef39bb5906af7dc9729890f7e4e04e75afdae\"\u003e\u003ccode\u003ea31ef39\u003c/code\u003e\u003c/a\u003e Bump actions/setup-python from 6.2.0 to 6.3.0 (\u003ca href=\"https://redirect.github.com/certifi/python-certifi/issues/420\"\u003e#420\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/certifi/python-certifi/commit/98eb2c76a9c7a8519912023dca00f762bbcd59af\"\u003e\u003ccode\u003e98eb2c7\u003c/code\u003e\u003c/a\u003e Bump actions/checkout from 6.0.3 to 7.0.0 (\u003ca href=\"https://redirect.github.com/certifi/python-certifi/issues/419\"\u003e#419\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/certifi/python-certifi/compare/2026.06.17...2026.07.22\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `cffi` from 2.1.0 to 2.1.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/python-cffi/cffi/releases\"\u003ecffi's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.1.1\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMinimize internal Python API usage for interpreter and thread state sampling where possible. Avoids breaking ABI change in Python \u0026gt;= 3.15.0b4 (\u003ca href=\"https://redirect.github.com/python-cffi/cffi/pull/269\"\u003epython-cffi/cffi#269\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/python-cffi/cffi/compare/v2.1.0...v2.1.1\"\u003ehttps://github.com/python-cffi/cffi/compare/v2.1.0...v2.1.1\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-cffi/cffi/commit/fd33e7700f0ebafe6f30bd5053f13327221b77a2\"\u003e\u003ccode\u003efd33e77\u003c/code\u003e\u003c/a\u003e New release 2.1.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-cffi/cffi/commit/56a7876b8cd3b2d8148233a90e0121d74cd83852\"\u003e\u003ccode\u003e56a7876\u003c/code\u003e\u003c/a\u003e Use PyGILState_Ensure to avoid accessing CPython internals (\u003ca href=\"https://redirect.github.com/python-cffi/cffi/issues/269\"\u003e#269\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/python-cffi/cffi/issues/270\"\u003e#270\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/python-cffi/cffi/compare/v2.1.0...v2.1.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `charset-normalizer` from 3.4.9 to 3.5.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/jawah/charset_normalizer/releases\"\u003echarset-normalizer's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eVersion 3.5.1\u003c/h2\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/Ousret/charset_normalizer/compare/3.5.0...3.5.1\"\u003e3.5.1\u003c/a\u003e (2026-08-15)\u003c/h2\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eRaised upper bound of setuptools to v84 (\u003ca href=\"https://redirect.github.com/jawah/charset_normalizer/issues/794\"\u003e#794\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eCache performance access optimization for our CharInfo struct (prebuilt only).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eNo longer decoding large content when the noise detector output give a high entropy.\nOnly impacted large content input \u0026gt;1M bytes.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eVersion 3.5.0\u003c/h2\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/Ousret/charset_normalizer/compare/3.4.9...3.5.0\"\u003e3.5.0\u003c/a\u003e (2026-08-12)\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eExplicit support for Python 3.15\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eComparing a CharsetMatch to a non-alias encoding strings (\u003ca href=\"https://redirect.github.com/jawah/charset_normalizer/issues/773\"\u003e#773\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eReturn 0.0 CharsetMatch.multi_byte_usage for empty payloads instead of crashing (\u003ca href=\"https://redirect.github.com/jawah/charset_normalizer/issues/774\"\u003e#774\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eA file with both a charset declaration and BOM/SIG did not verify first the BOM/SIG charset.\u003c/li\u003e\n\u003cli\u003eiso2022* cases misdetected due to a flaw in our multibyte chunking logic.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eReplaced the optional mypyc build with Cython extensions while retaining the\npure Python fallback. The previous engine (mypyc) started to hit rough limit around\nthe optimization of our noise/coherence detector while Cython allows us to\nsteer the engine toward the right generated optimized sources.\nThis change SHOULD not impact bundler (e.g. Pyinstaller) as the module are\nimmediately discoverable (i.e. not hidden import like mypyc did).\nMoreover, a long wished distribution is the abi3 wheels, this will allow us\nto no longer rush each year when a new Python interpreter is released.\nWe still distribute the interpreter specific wheels for faster performance.\u003c/li\u003e\n\u003cli\u003eApplied micro-optimization on several utils.\u003c/li\u003e\n\u003cli\u003eCharsetMatches no longer sort on each match insertion.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMisc\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eRemoved an old performance optimization attempt in apy.py (success_fast_tracked+payload_result_cache).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/jawah/charset_normalizer/blob/master/CHANGELOG.md\"\u003echarset-normalizer's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/Ousret/charset_normalizer/compare/3.5.0...3.5.1\"\u003e3.5.1\u003c/a\u003e (2026-08-15)\u003c/h2\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eRaised upper bound of setuptools to v84 (\u003ca href=\"https://redirect.github.com/jawah/charset_normalizer/issues/794\"\u003e#794\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eCache performance access optimization for our CharInfo struct (prebuilt only).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eNo longer decoding large content when the noise detector output give a high entropy.\nOnly impacted large content input \u0026gt;1M bytes.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/Ousret/charset_normalizer/compare/3.4.9...3.5.0\"\u003e3.5.0\u003c/a\u003e (2026-08-12)\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eExplicit support for Python 3.15\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eComparing a CharsetMatch to a non-alias encoding strings (\u003ca href=\"https://redirect.github.com/jawah/charset_normalizer/issues/773\"\u003e#773\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eReturn 0.0 CharsetMatch.multi_byte_usage for empty payloads instead of crashing (\u003ca href=\"https://redirect.github.com/jawah/charset_normalizer/issues/774\"\u003e#774\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eA file with both a charset declaration and BOM/SIG did not verify first the BOM/SIG charset.\u003c/li\u003e\n\u003cli\u003eiso2022* cases misdetected due to a flaw in our multibyte chunking logic.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eReplaced the optional mypyc build with Cython extensions while retaining the\npure Python fallback. The previous engine (mypyc) started to hit rough limit around\nthe optimization of our noise/coherence detector while Cython allows us to\nsteer the engine toward the right generated optimized sources.\nThis change SHOULD not impact bundler (e.g. Pyinstaller) as the module are\nimmediately discoverable (i.e. not hidden import like mypyc did).\nMoreover, a long wished distribution is the abi3 wheels, this will allow us\nto no longer rush each year when a new Python interpreter is released.\nWe still distribute the interpreter specific wheels for faster performance.\u003c/li\u003e\n\u003cli\u003eApplied micro-optimization on several utils.\u003c/li\u003e\n\u003cli\u003eCharsetMatches no longer sort on each match insertion.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMisc\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eRemoved an old performance optimization attempt in apy.py (success_fast_tracked+payload_result_cache).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jawah/charset_normalizer/commit/e239bdc5cc1eb1f0db08d4046ad531f805dbea71\"\u003e\u003ccode\u003ee239bdc\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/jawah/charset_normalizer/issues/795\"\u003e#795\u003c/a\u003e from jawah/release-3.5.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jawah/charset_normalizer/commit/648ad776db64a00aa7efd70a94656ac43784abb3\"\u003e\u003ccode\u003e648ad77\u003c/code\u003e\u003c/a\u003e docs: update faq\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jawah/charset_normalizer/commit/fab27492c39baa61aca12826022e266781108570\"\u003e\u003ccode\u003efab2749\u003c/code\u003e\u003c/a\u003e docs: write changelog for 3.5.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jawah/charset_normalizer/commit/7d32774e75d16cccd3d22c758a77fca135952787\"\u003e\u003ccode\u003e7d32774\u003c/code\u003e\u003c/a\u003e chore: bump version to 3.5.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jawah/charset_normalizer/commit/9a69f609f254ba4bfe9d0cbf375728e43360cdf2\"\u003e\u003ccode\u003e9a69f60\u003c/code\u003e\u003c/a\u003e docs: update data/info\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jawah/charset_normalizer/commit/5dcc6dd81a8a0a4bd525f8d6f508da8285caf402\"\u003e\u003ccode\u003e5dcc6dd\u003c/code\u003e\u003c/a\u003e perf: charinfo cache access optimization in cython\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jawah/charset_normalizer/commit/ea3b4479270762be1228562c590e5a212727f208\"\u003e\u003ccode\u003eea3b447\u003c/code\u003e\u003c/a\u003e fix: do not validate-decode large payload when md says it's noise\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jawah/char...\n\n_Description has been truncated_","html_url":"https://github.com/RanugaVW/Clario-multiAgent-triage-micro-services/pull/89","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/RanugaVW%2FClario-multiAgent-triage-micro-services/issues/89","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/89/packages"}},{"old_version":"3.13.3","new_version":"3.14.3","update_type":"minor","path":null,"pr_created_at":"2026-09-19T03:51:06.000Z","version_change":"3.13.3 → 3.14.3","issue":{"uuid":"5507547597","node_id":"PR_kwDOUTCdd88AAAABELl5rw","number":2,"state":"open","title":"chore(deps): bump the uv group across 2 directories with 15 updates","user":"dependabot[bot]","labels":["dependencies","python:uv"],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-19T03:51:06.000Z","updated_at":"2026-09-19T03:51:56.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps): bump","group_name":"uv","update_count":15,"packages":[{"name":"aiohttp","old_version":"3.13.3","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"cryptography","old_version":"46.0.5","new_version":"50.0.0","repository_url":"https://github.com/pyca/cryptography"},{"name":"h2","old_version":"4.4.0","new_version":"4.4.1","repository_url":"https://github.com/python-hyper/h2"},{"name":"httpcore2","old_version":"2.9.0","new_version":"2.10.0","repository_url":"https://github.com/pydantic/httpx2"},{"name":"httpx2","old_version":"2.9.0","new_version":"2.10.0","repository_url":"https://github.com/pydantic/httpx2"},{"name":"pyjwt","old_version":"2.10.1","new_version":"2.13.0","repository_url":"https://github.com/jpadilla/pyjwt"},{"name":"python-dotenv","old_version":"1.1.0","new_version":"1.2.2","repository_url":"https://github.com/theskumar/python-dotenv"},{"name":"requests","old_version":"2.32.5","new_version":"2.33.0","repository_url":"https://github.com/psf/requests"},{"name":"urllib3","old_version":"2.6.3","new_version":"2.7.0","repository_url":"https://github.com/urllib3/urllib3"}],"path":null,"ecosystem":"pip"},"body":"Bumps the uv group with 9 updates in the /examples/python directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [aiohttp](https://github.com/aio-libs/aiohttp) | `3.13.3` | `3.14.3` |\n| [cryptography](https://github.com/pyca/cryptography) | `46.0.5` | `50.0.0` |\n| [h2](https://github.com/python-hyper/h2) | `4.4.0` | `4.4.1` |\n| [httpcore2](https://github.com/pydantic/httpx2) | `2.9.0` | `2.10.0` |\n| [httpx2](https://github.com/pydantic/httpx2) | `2.9.0` | `2.10.0` |\n| [pyjwt](https://github.com/jpadilla/pyjwt) | `2.10.1` | `2.13.0` |\n| [python-dotenv](https://github.com/theskumar/python-dotenv) | `1.1.0` | `1.2.2` |\n| [requests](https://github.com/psf/requests) | `2.32.5` | `2.33.0` |\n| [urllib3](https://github.com/urllib3/urllib3) | `2.6.3` | `2.7.0` |\n\nBumps the uv group with 12 updates in the /python directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [web3](https://github.com/ApeWorX/web3.py) | `7.6.0` | `7.15.0` |\n| [aiohttp](https://github.com/aio-libs/aiohttp) | `3.13.3` | `3.14.3` |\n| [anyio](https://github.com/agronholm/anyio) | `4.9.0` | `4.14.2` |\n| [cryptography](https://github.com/pyca/cryptography) | `46.0.5` | `50.0.0` |\n| [idna](https://github.com/kjd/idna) | `3.10` | `3.15` |\n| [pygments](https://github.com/pygments/pygments) | `2.19.1` | `2.20.0` |\n| [pyjwt](https://github.com/jpadilla/pyjwt) | `2.10.1` | `2.13.0` |\n| [python-dotenv](https://github.com/theskumar/python-dotenv) | `1.1.0` | `1.2.2` |\n| [requests](https://github.com/psf/requests) | `2.32.5` | `2.33.0` |\n| [starlette](https://github.com/Kludex/starlette) | `0.52.1` | `1.3.1` |\n| [urllib3](https://github.com/urllib3/urllib3) | `2.6.3` | `2.7.0` |\n| [pytest](https://github.com/pytest-dev/pytest) | `8.3.5` | `9.0.3` |\n\n\nUpdates `aiohttp` from 3.13.3 to 3.14.3\nUpdates `cryptography` from 46.0.5 to 50.0.0\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst\"\u003ecryptography's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e50.0.0 - 2026-07-31\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003e\n* **SECURITY ISSUE**:\n  :func:`~cryptography.hazmat.primitives.serialization.pkcs7.pkcs7_decrypt_der`\n  and its PEM and S/MIME variants no longer expose distinguishable errors or\n  timing when unwrapping a ``RecipientInfo``'s ``encryptedKey``, which could\n  act as a Bleichenbacher oracle for callers that decrypt untrusted messages.\n  A random key is now substituted on failure, as described in :rfc:`3218`.\n  Credit to **@X1AOxiang** for reporting the issue. **CVE-2026-69247**\n* Deprecated Diffie-Hellman key exchange over finite fields (FFDH).\n  Everything FFDH is deprecated, including the types in\n  ``cryptography.hazmat.primitives.asymmetric.dh`` and loading FFDH keys or\n  parameters with the key loading APIs. Users should migrate to a more\n  modern key exchange algorithm.\n* Added ``xof()`` class methods to\n  :class:`~cryptography.hazmat.primitives.hashes.SHAKE128` and\n  :class:`~cryptography.hazmat.primitives.hashes.SHAKE256` for constructing\n  algorithm instances configured for use with\n  :class:`~cryptography.hazmat.primitives.hashes.XOFHash`.\n* The :mod:`X.509 verification \u0026lt;cryptography.x509.verification\u0026gt;` APIs are now\n  considered stable and are subject to our API stability policy.\n* Added the :doc:`/cobblestone` recipe, an implementation of the\n  Cobblestone-128 and Cobblestone-256 instantiations of the `C2SP\n  chunked-encryption specification\n  \u0026lt;https://c2sp.org/chunked-encryption\u0026gt;`_ for streaming authenticated\n  encryption of large messages.\n* Parsing a Signed Certificate Timestamp list now rejects encodings that\n  carry trailing bytes after the list or after an individual SCT, instead of\n  silently ignoring them.\n* Added support for using :class:`~cryptography.x509.Name` as a field type in\n  the :doc:`/hazmat/asn1/index` module.\n* Loading a public key or an EC private key now rejects DER where the\n  ``subjectPublicKey`` (or EC ``publicKey``) ``BIT STRING`` declares a non-zero\n  number of unused bits, instead of silently ignoring it.\n* Parsing a CRL entry's ``InvalidityDate`` extension now rejects a\n  ``GeneralizedTime`` that carries fractional seconds or another non-DER form,\n  matching the strict encoding already required for every other X.509 time\n  field.\n* :func:`~cryptography.x509.ocsp.load_der_ocsp_request` and\n  :func:`~cryptography.x509.ocsp.load_der_ocsp_response` now reject a request\n  or response whose ``version`` field is not ``v1``, the only version defined\n  by RFC 6960, matching the version validation already performed when loading\n  certificates, CSRs and CRLs.\n* :class:`~cryptography.hazmat.primitives.hashes.XOFHash` is now supported\n  when building against AWS-LC.\n* HMAC (and therefore PBKDF2-HMAC) with SHA-3 hashes is now supported when\n  building against AWS-LC.\n* Diffie-Hellman (:doc:`/hazmat/primitives/asymmetric/dh`) is now supported\n  when building against AWS-LC.\n\u0026lt;/tr\u0026gt;\u0026lt;/table\u0026gt; \n\u003c/code\u003e\u003c/pre\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/dcb7050b807b00392fa9fe2eac7cb362fcf355cc\"\u003e\u003ccode\u003edcb7050\u003c/code\u003e\u003c/a\u003e Prepare for 50.0.0 release (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15372\"\u003e#15372\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/53fccd93413a8d7f07d6d8999681f27b75cffa3f\"\u003e\u003ccode\u003e53fccd9\u003c/code\u003e\u003c/a\u003e Don't leak how PKCS#7 encryptedKey decryption failed (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15369\"\u003e#15369\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/d472f978470fbefa521b86d98b2ecccbbb4d1dd8\"\u003e\u003ccode\u003ed472f97\u003c/code\u003e\u003c/a\u003e Add \u003ccode\u003efrom __future__ import annotations\u003c/code\u003e to all src/ Python files (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15371\"\u003e#15371\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/908773d53829fb1466c6db364b31321c3cd8eb9a\"\u003e\u003ccode\u003e908773d\u003c/code\u003e\u003c/a\u003e Bump downstream dependencies in CI (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15368\"\u003e#15368\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/2cc07cc948948211899bcb0cddd1fddf86e95812\"\u003e\u003ccode\u003e2cc07cc\u003c/code\u003e\u003c/a\u003e Bump BoringSSL, OpenSSL, AWS-LC in CI (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15367\"\u003e#15367\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/c94ede9f040fa44942f7139772603419000acf66\"\u003e\u003ccode\u003ec94ede9\u003c/code\u003e\u003c/a\u003e chore(deps): bump ruff from 0.16.0 to 0.16.1 (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15366\"\u003e#15366\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/67a8308dc9ea4cce6056e0f1438f903c208c3f35\"\u003e\u003ccode\u003e67a8308\u003c/code\u003e\u003c/a\u003e chore(deps): bump virtualenv from 21.7.0 to 21.7.1 (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15365\"\u003e#15365\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/95018ffcdbbc510fd92fc872e3a3e80aa6e58596\"\u003e\u003ccode\u003e95018ff\u003c/code\u003e\u003c/a\u003e Release the GIL in one-shot AEAD encrypt/decrypt (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15361\"\u003e#15361\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/6954733eaf55a0074abf88f06f7242dfca3a5d02\"\u003e\u003ccode\u003e6954733\u003c/code\u003e\u003c/a\u003e Release the GIL during DH and DSA parameter generation (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15364\"\u003e#15364\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/6893b94c33e948f6240082461424cfb5da2dacc6\"\u003e\u003ccode\u003e6893b94\u003c/code\u003e\u003c/a\u003e Import _serialization instead of serialization in x509/extensions (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15363\"\u003e#15363\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/pyca/cryptography/compare/46.0.5...50.0.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `h2` from 4.4.0 to 4.4.1\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/python-hyper/h2/blob/master/CHANGELOG.rst\"\u003eh2's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e4.4.1 (2026-08-03)\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eBugfixes\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003ePerformance improvement: remove consumed frames in-place from data buffer.\u003c/li\u003e\n\u003cli\u003eReject duplicate Host headers in request headers. Thanks to Sunand Mohan for the report.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-hyper/h2/commit/bc239af1d1b85bc70482804f30a0e0e587d90a08\"\u003e\u003ccode\u003ebc239af\u003c/code\u003e\u003c/a\u003e v4.4.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-hyper/h2/commit/92b925ed1b1817c82db32893503f74f47fcf4452\"\u003e\u003ccode\u003e92b925e\u003c/code\u003e\u003c/a\u003e add test for duplicate host headers\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-hyper/h2/commit/292a40829feefda98c8509dcdbbb4a57af9bd6a6\"\u003e\u003ccode\u003e292a408\u003c/code\u003e\u003c/a\u003e reject duplicate Host headers in request headers\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-hyper/h2/commit/04d3b87cbc1db020d28c7cfb44fe194558efbdde\"\u003e\u003ccode\u003e04d3b87\u003c/code\u003e\u003c/a\u003e update changelog\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-hyper/h2/commit/439b970d0fa19891fa81068907de97dfa3a07c3a\"\u003e\u003ccode\u003e439b970\u003c/code\u003e\u003c/a\u003e prepare for next release cycle\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-hyper/h2/commit/9a7ff7430df669fa8e90b6121f3cc1ed64d1115a\"\u003e\u003ccode\u003e9a7ff74\u003c/code\u003e\u003c/a\u003e performance: remove consumed frames in place from data buffer (\u003ca href=\"https://redirect.github.com/python-hyper/h2/issues/1321\"\u003e#1321\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/python-hyper/h2/compare/v4.4.0...v4.4.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `httpcore2` from 2.9.0 to 2.10.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pydantic/httpx2/releases\"\u003ehttpcore2's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.10.0\u003c/h2\u003e\n\u003ch2\u003eHighlights\u003c/h2\u003e\n\u003ch3\u003e🚀 Performance and memory improvements\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eSending large HTTP/2 request bodies no longer copies the body quadratically - sending a 256 MiB body went from ~36s to under 0.1s (\u003ca href=\"https://redirect.github.com/pydantic/httpx2/pull/1127\"\u003epydantic/httpx2#1127\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eSSE parsing is up to 35x faster on highly fragmented streams (\u003ca href=\"https://redirect.github.com/pydantic/httpx2/pull/1117\"\u003epydantic/httpx2#1117\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eCookie extraction is now skipped for responses without a \u003ccode\u003eSet-Cookie\u003c/code\u003e header, making typical requests roughly 8% faster (\u003ca href=\"https://redirect.github.com/pydantic/httpx2/pull/1107\"\u003epydantic/httpx2#1107\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e🕸️ WebAssembly / Emscripten support\u003c/h3\u003e\n\u003cp\u003e\u003ccode\u003ehttpx2\u003c/code\u003e now runs on Pyodide / Emscripten, using a JavaScript \u003ccode\u003efetch\u003c/code\u003e-based transport defined in \u003ccode\u003ehttpx2-jsfetch\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/pydantic/httpx2/pull/1119\"\u003epydantic/httpx2#1119\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/pydantic/httpx2/pull/1114\"\u003epydantic/httpx2#1114\u003c/a\u003e). Thanks \u003ca href=\"https://github.com/hoodmane\"\u003e\u003ccode\u003e@​hoodmane\u003c/code\u003e\u003c/a\u003e!\u003c/p\u003e\n\u003ch2\u003ehttpx2\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdd support for running on WebAssembly / Emscripten via Pyodide by \u003ca href=\"https://github.com/hoodmane\"\u003e\u003ccode\u003e@​hoodmane\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/httpx2/pull/1119\"\u003epydantic/httpx2#1119\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003emax_event_size\u003c/code\u003e to cap SSE event buffering by \u003ca href=\"https://github.com/Kludex\"\u003e\u003ccode\u003e@​Kludex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/httpx2/pull/1071\"\u003epydantic/httpx2#1071\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd RFC 9110 status code constants by \u003ca href=\"https://github.com/mbeijen\"\u003e\u003ccode\u003e@​mbeijen\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/httpx2/pull/1069\"\u003epydantic/httpx2#1069\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd support for Python 3.15 by \u003ca href=\"https://github.com/hugovk\"\u003e\u003ccode\u003e@​hugovk\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/httpx2/pull/1090\"\u003epydantic/httpx2#1090\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eImprove SSE chunk buffering performance by \u003ca href=\"https://github.com/Kludex\"\u003e\u003ccode\u003e@​Kludex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/httpx2/pull/1117\"\u003epydantic/httpx2#1117\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSkip cookie extraction without \u003ccode\u003eSet-Cookie\u003c/code\u003e by \u003ca href=\"https://github.com/Kludex\"\u003e\u003ccode\u003e@​Kludex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/httpx2/pull/1107\"\u003epydantic/httpx2#1107\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eReturn \u003ccode\u003estr | None\u003c/code\u003e instead of \u003ccode\u003eAny\u003c/code\u003e from \u003ccode\u003eHeaders.get\u003c/code\u003e by \u003ca href=\"https://github.com/ItsDrike\"\u003e\u003ccode\u003e@​ItsDrike\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/httpx2/pull/1121\"\u003epydantic/httpx2#1121\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eEnforce WebSocket max message size across fragments by \u003ca href=\"https://github.com/Kludex\"\u003e\u003ccode\u003e@​Kludex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/httpx2/pull/1085\"\u003epydantic/httpx2#1085\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eIgnore unsolicited and duplicate Pong frames by \u003ca href=\"https://github.com/Kludex\"\u003e\u003ccode\u003e@​Kludex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/httpx2/pull/1122\"\u003epydantic/httpx2#1122\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ehttpcore2\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdd support for Python 3.15 by \u003ca href=\"https://github.com/hugovk\"\u003e\u003ccode\u003e@​hugovk\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/httpx2/pull/1090\"\u003epydantic/httpx2#1090\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAvoid quadratic copying when sending large HTTP/2 request bodies by \u003ca href=\"https://github.com/Kludex\"\u003e\u003ccode\u003e@​Kludex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/httpx2/pull/1127\"\u003epydantic/httpx2#1127\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ePropagate the original exception instead of raising \u003ccode\u003eKeyError\u003c/code\u003e when an HTTP/2 stream fails by \u003ca href=\"https://github.com/yhay81\"\u003e\u003ccode\u003e@​yhay81\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/httpx2/pull/1093\"\u003epydantic/httpx2#1093\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eStart TLS for the \u003ccode\u003ewss\u003c/code\u003e scheme in SOCKS5 proxy connections by \u003ca href=\"https://github.com/Kludex\"\u003e\u003ccode\u003e@​Kludex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/httpx2/pull/1104\"\u003epydantic/httpx2#1104\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🙏 New Contributors\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/httpx2/commit/a966320e75477b8c55ee78fdb8f57ead6a574cb0\"\u003e\u003ccode\u003ea966320\u003c/code\u003e\u003c/a\u003e Version 2.10.0 (\u003ca href=\"https://redirect.github.com/pydantic/httpx2/issues/1129\"\u003e#1129\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/httpx2/commit/586f968f5510aa4d3b7edd1f1b039684c42945ee\"\u003e\u003ccode\u003e586f968\u003c/code\u003e\u003c/a\u003e Avoid quadratic copying when sending large HTTP/2 request bodies (\u003ca href=\"https://redirect.github.com/pydantic/httpx2/issues/1127\"\u003e#1127\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/httpx2/commit/dee1d1ace3021404d0aa255957821eda97c94c43\"\u003e\u003ccode\u003edee1d1a\u003c/code\u003e\u003c/a\u003e Return \u003ccode\u003estr | None\u003c/code\u003e instead of \u003ccode\u003eAny\u003c/code\u003e from \u003ccode\u003eHeaders.get\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/pydantic/httpx2/issues/1121\"\u003e#1121\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/httpx2/commit/dec24ad57d1d337de7de23c011eb566a145e7b40\"\u003e\u003ccode\u003edec24ad\u003c/code\u003e\u003c/a\u003e Use \u003ccode\u003ehttpx2-jsfetch\u003c/code\u003e on Emscripten (\u003ca href=\"https://redirect.github.com/pydantic/httpx2/issues/1119\"\u003e#1119\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/httpx2/commit/454b8b2197f62d699ff3ad762917643926b4da77\"\u003e\u003ccode\u003e454b8b2\u003c/code\u003e\u003c/a\u003e Ignore unsolicited and duplicate Pong frames (\u003ca href=\"https://redirect.github.com/pydantic/httpx2/issues/1122\"\u003e#1122\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/httpx2/commit/cbfc0e04ef6507da29ccbb3b9c2e5b23dd693414\"\u003e\u003ccode\u003ecbfc0e0\u003c/code\u003e\u003c/a\u003e Improve SSE chunk buffering performance (\u003ca href=\"https://redirect.github.com/pydantic/httpx2/issues/1117\"\u003e#1117\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/httpx2/commit/ad141d876c7d3c3f58555cbb0a178ec2c1f15b51\"\u003e\u003ccode\u003ead141d8\u003c/code\u003e\u003c/a\u003e Refactor SSE parser coordination (\u003ca href=\"https://redirect.github.com/pydantic/httpx2/issues/1118\"\u003e#1118\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/httpx2/commit/e0b01245e42d2091034ee9455cbb068bc0d6c0c6\"\u003e\u003ccode\u003ee0b0124\u003c/code\u003e\u003c/a\u003e Make \u003ccode\u003e_client\u003c/code\u003e depend on the \u003ccode\u003e_transports\u003c/code\u003e package instead of its submodules ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/httpx2/commit/e52f963c62f397f225c8d29573aedbe5ae613906\"\u003e\u003ccode\u003ee52f963\u003c/code\u003e\u003c/a\u003e Skip dependencies not needed on Emscripten (\u003ca href=\"https://redirect.github.com/pydantic/httpx2/issues/1114\"\u003e#1114\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/httpx2/commit/5d9eedc98186c612d0e426df417f78f6ec21e9ca\"\u003e\u003ccode\u003e5d9eedc\u003c/code\u003e\u003c/a\u003e Add \u003ccode\u003emax_event_size\u003c/code\u003e to cap SSE event buffering (\u003ca href=\"https://redirect.github.com/pydantic/httpx2/issues/1071\"\u003e#1071\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/pydantic/httpx2/compare/v2.9.0...v2.10.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `httpx2` from 2.9.0 to 2.10.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pydantic/httpx2/releases\"\u003ehttpx2's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.10.0\u003c/h2\u003e\n\u003ch2\u003eHighlights\u003c/h2\u003e\n\u003ch3\u003e🚀 Performance and memory improvements\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eSending large HTTP/2 request bodies no longer copies the body quadratically - sending a 256 MiB body went from ~36s to under 0.1s (\u003ca href=\"https://redirect.github.com/pydantic/httpx2/pull/1127\"\u003epydantic/httpx2#1127\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eSSE parsing is up to 35x faster on highly fragmented streams (\u003ca href=\"https://redirect.github.com/pydantic/httpx2/pull/1117\"\u003epydantic/httpx2#1117\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eCookie extraction is now skipped for responses without a \u003ccode\u003eSet-Cookie\u003c/code\u003e header, making typical requests roughly 8% faster (\u003ca href=\"https://redirect.github.com/pydantic/httpx2/pull/1107\"\u003epydantic/httpx2#1107\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e🕸️ WebAssembly / Emscripten support\u003c/h3\u003e\n\u003cp\u003e\u003ccode\u003ehttpx2\u003c/code\u003e now runs on Pyodide / Emscripten, using a JavaScript \u003ccode\u003efetch\u003c/code\u003e-based transport defined in \u003ccode\u003ehttpx2-jsfetch\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/pydantic/httpx2/pull/1119\"\u003epydantic/httpx2#1119\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/pydantic/httpx2/pull/1114\"\u003epydantic/httpx2#1114\u003c/a\u003e). Thanks \u003ca href=\"https://github.com/hoodmane\"\u003e\u003ccode\u003e@​hoodmane\u003c/code\u003e\u003c/a\u003e!\u003c/p\u003e\n\u003ch2\u003ehttpx2\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdd support for running on WebAssembly / Emscripten via Pyodide by \u003ca href=\"https://github.com/hoodmane\"\u003e\u003ccode\u003e@​hoodmane\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/httpx2/pull/1119\"\u003epydantic/httpx2#1119\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003emax_event_size\u003c/code\u003e to cap SSE event buffering by \u003ca href=\"https://github.com/Kludex\"\u003e\u003ccode\u003e@​Kludex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/httpx2/pull/1071\"\u003epydantic/httpx2#1071\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd RFC 9110 status code constants by \u003ca href=\"https://github.com/mbeijen\"\u003e\u003ccode\u003e@​mbeijen\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/httpx2/pull/1069\"\u003epydantic/httpx2#1069\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd support for Python 3.15 by \u003ca href=\"https://github.com/hugovk\"\u003e\u003ccode\u003e@​hugovk\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/httpx2/pull/1090\"\u003epydantic/httpx2#1090\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eImprove SSE chunk buffering performance by \u003ca href=\"https://github.com/Kludex\"\u003e\u003ccode\u003e@​Kludex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/httpx2/pull/1117\"\u003epydantic/httpx2#1117\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSkip cookie extraction without \u003ccode\u003eSet-Cookie\u003c/code\u003e by \u003ca href=\"https://github.com/Kludex\"\u003e\u003ccode\u003e@​Kludex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/httpx2/pull/1107\"\u003epydantic/httpx2#1107\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eReturn \u003ccode\u003estr | None\u003c/code\u003e instead of \u003ccode\u003eAny\u003c/code\u003e from \u003ccode\u003eHeaders.get\u003c/code\u003e by \u003ca href=\"https://github.com/ItsDrike\"\u003e\u003ccode\u003e@​ItsDrike\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/httpx2/pull/1121\"\u003epydantic/httpx2#1121\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eEnforce WebSocket max message size across fragments by \u003ca href=\"https://github.com/Kludex\"\u003e\u003ccode\u003e@​Kludex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/httpx2/pull/1085\"\u003epydantic/httpx2#1085\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eIgnore unsolicited and duplicate Pong frames by \u003ca href=\"https://github.com/Kludex\"\u003e\u003ccode\u003e@​Kludex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/httpx2/pull/1122\"\u003epydantic/httpx2#1122\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ehttpcore2\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdd support for Python 3.15 by \u003ca href=\"https://github.com/hugovk\"\u003e\u003ccode\u003e@​hugovk\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/httpx2/pull/1090\"\u003epydantic/httpx2#1090\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAvoid quadratic copying when sending large HTTP/2 request bodies by \u003ca href=\"https://github.com/Kludex\"\u003e\u003ccode\u003e@​Kludex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/httpx2/pull/1127\"\u003epydantic/httpx2#1127\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ePropagate the original exception instead of raising \u003ccode\u003eKeyError\u003c/code\u003e when an HTTP/2 stream fails by \u003ca href=\"https://github.com/yhay81\"\u003e\u003ccode\u003e@​yhay81\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/httpx2/pull/1093\"\u003epydantic/httpx2#1093\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eStart TLS for the \u003ccode\u003ewss\u003c/code\u003e scheme in SOCKS5 proxy connections by \u003ca href=\"https://github.com/Kludex\"\u003e\u003ccode\u003e@​Kludex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/httpx2/pull/1104\"\u003epydantic/httpx2#1104\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🙏 New Contributors\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pydantic/httpx2/blob/main/src/httpx2/CHANGELOG.md\"\u003ehttpx2's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e2.10.0 (August 9th, 2026)\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdd support for running on WebAssembly / Emscripten via Pyodide, using a JavaScript\n\u003ccode\u003efetch\u003c/code\u003e-based transport defined in \u003ccode\u003ehttpx2-jsfetch\u003c/code\u003e.\n(\u003ca href=\"https://redirect.github.com/pydantic/httpx2/pull/1119\"\u003e#1119\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003emax_event_size\u003c/code\u003e to cap SSE event buffering. (\u003ca href=\"https://redirect.github.com/pydantic/httpx2/pull/1071\"\u003e#1071\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdd RFC 9110 status code constants. (\u003ca href=\"https://redirect.github.com/pydantic/httpx2/pull/1069\"\u003e#1069\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdd support for Python 3.15. (\u003ca href=\"https://redirect.github.com/pydantic/httpx2/pull/1090\"\u003e#1090\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eImprove SSE chunk buffering performance. (\u003ca href=\"https://redirect.github.com/pydantic/httpx2/pull/1117\"\u003e#1117\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSkip cookie extraction for responses without \u003ccode\u003eSet-Cookie\u003c/code\u003e headers. (\u003ca href=\"https://redirect.github.com/pydantic/httpx2/pull/1107\"\u003e#1107\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eReturn \u003ccode\u003estr | None\u003c/code\u003e instead of \u003ccode\u003eAny\u003c/code\u003e from \u003ccode\u003eHeaders.get\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/pydantic/httpx2/pull/1121\"\u003e#1121\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eEnforce the WebSocket max message size across fragmented messages. (\u003ca href=\"https://redirect.github.com/pydantic/httpx2/pull/1085\"\u003e#1085\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eIgnore unsolicited and duplicate WebSocket Pong frames. (\u003ca href=\"https://redirect.github.com/pydantic/httpx2/pull/1122\"\u003e#1122\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.9.1 (July 24th, 2026)\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAlias \u003ccode\u003ehttpcore\u003c/code\u003e imports to \u003ccode\u003ehttpcore2\u003c/code\u003e in \u003ccode\u003ealias_httpx()\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/pydantic/httpx2/pull/1082\"\u003e#1082\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/httpx2/commit/a966320e75477b8c55ee78fdb8f57ead6a574cb0\"\u003e\u003ccode\u003ea966320\u003c/code\u003e\u003c/a\u003e Version 2.10.0 (\u003ca href=\"https://redirect.github.com/pydantic/httpx2/issues/1129\"\u003e#1129\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/httpx2/commit/dee1d1ace3021404d0aa255957821eda97c94c43\"\u003e\u003ccode\u003edee1d1a\u003c/code\u003e\u003c/a\u003e Return \u003ccode\u003estr | None\u003c/code\u003e instead of \u003ccode\u003eAny\u003c/code\u003e from \u003ccode\u003eHeaders.get\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/pydantic/httpx2/issues/1121\"\u003e#1121\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/httpx2/commit/dec24ad57d1d337de7de23c011eb566a145e7b40\"\u003e\u003ccode\u003edec24ad\u003c/code\u003e\u003c/a\u003e Use \u003ccode\u003ehttpx2-jsfetch\u003c/code\u003e on Emscripten (\u003ca href=\"https://redirect.github.com/pydantic/httpx2/issues/1119\"\u003e#1119\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/httpx2/commit/454b8b2197f62d699ff3ad762917643926b4da77\"\u003e\u003ccode\u003e454b8b2\u003c/code\u003e\u003c/a\u003e Ignore unsolicited and duplicate Pong frames (\u003ca href=\"https://redirect.github.com/pydantic/httpx2/issues/1122\"\u003e#1122\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/httpx2/commit/cbfc0e04ef6507da29ccbb3b9c2e5b23dd693414\"\u003e\u003ccode\u003ecbfc0e0\u003c/code\u003e\u003c/a\u003e Improve SSE chunk buffering performance (\u003ca href=\"https://redirect.github.com/pydantic/httpx2/issues/1117\"\u003e#1117\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/httpx2/commit/ad141d876c7d3c3f58555cbb0a178ec2c1f15b51\"\u003e\u003ccode\u003ead141d8\u003c/code\u003e\u003c/a\u003e Refactor SSE parser coordination (\u003ca href=\"https://redirect.github.com/pydantic/httpx2/issues/1118\"\u003e#1118\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/httpx2/commit/e0b01245e42d2091034ee9455cbb068bc0d6c0c6\"\u003e\u003ccode\u003ee0b0124\u003c/code\u003e\u003c/a\u003e Make \u003ccode\u003e_client\u003c/code\u003e depend on the \u003ccode\u003e_transports\u003c/code\u003e package instead of its submodules ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/httpx2/commit/e52f963c62f397f225c8d29573aedbe5ae613906\"\u003e\u003ccode\u003ee52f963\u003c/code\u003e\u003c/a\u003e Skip dependencies not needed on Emscripten (\u003ca href=\"https://redirect.github.com/pydantic/httpx2/issues/1114\"\u003e#1114\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/httpx2/commit/5d9eedc98186c612d0e426df417f78f6ec21e9ca\"\u003e\u003ccode\u003e5d9eedc\u003c/code\u003e\u003c/a\u003e Add \u003ccode\u003emax_event_size\u003c/code\u003e to cap SSE event buffering (\u003ca href=\"https://redirect.github.com/pydantic/httpx2/issues/1071\"\u003e#1071\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/httpx2/commit/55fad715eb24b3b1c6bbf96757bcb49a03e121de\"\u003e\u003ccode\u003e55fad71\u003c/code\u003e\u003c/a\u003e Bump the python-packages group across 1 directory with 15 updates (\u003ca href=\"https://redirect.github.com/pydantic/httpx2/issues/1112\"\u003e#1112\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/pydantic/httpx2/compare/v2.9.0...v2.10.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `pyjwt` from 2.10.1 to 2.13.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/jpadilla/pyjwt/releases\"\u003epyjwt's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e2.13.0\u003c/h2\u003e\n\u003ch1\u003ePyJWT 2.13.0 — Security Release\u003c/h1\u003e\n\u003cp\u003eThis release bundles five security fixes plus three additional hardening / spec-compliance changes. We recommend all users upgrade.\u003c/p\u003e\n\u003ch2\u003eSecurity\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/security/advisories/GHSA-xgmm-8j9v-c9wx\"\u003e\u003ccode\u003eGHSA-xgmm-8j9v-c9wx\u003c/code\u003e\u003c/a\u003e — JWK JSON accepted as HMAC secret (algorithm confusion).\u003c/strong\u003e \u003ccode\u003eHMACAlgorithm.prepare_key\u003c/code\u003e previously rejected PEM- and SSH-formatted asymmetric keys but did not catch a JWK passed as a raw JSON string. In a verifier configured with both symmetric and asymmetric algorithms in \u003ccode\u003ealgorithms=[…]\u003c/code\u003e and a raw-JSON JWK as the key, an attacker could forge HS256 tokens using the JWK text as the HMAC secret. The guard has been extended to reject any JWK-shaped JSON. \u003cem\u003eReported by \u003ca href=\"https://github.com/aradona91\"\u003e\u003ccode\u003e@​aradona91\u003c/code\u003e\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/security/advisories/GHSA-jq35-7prp-9v3f\"\u003e\u003ccode\u003eGHSA-jq35-7prp-9v3f\u003c/code\u003e\u003c/a\u003e — Algorithm allow-list bypass with \u003ccode\u003ePyJWK\u003c/code\u003e / \u003ccode\u003ePyJWKClient\u003c/code\u003e.\u003c/strong\u003e When verifying with a \u003ccode\u003ePyJWK\u003c/code\u003e, the caller's \u003ccode\u003ealgorithms=[…]\u003c/code\u003e allow-list was checked against the token header \u003ccode\u003ealg\u003c/code\u003e as a string only; actual verification used the algorithm bound to the \u003ccode\u003ePyJWK\u003c/code\u003e. An attacker who controlled a registered JWKS key could sign with one algorithm and advertise another on the header. PyJWT now requires the token header \u003ccode\u003ealg\u003c/code\u003e to match the \u003ccode\u003ePyJWK\u003c/code\u003e's algorithm before verification. \u003cem\u003eReported by \u003ca href=\"https://github.com/sushi-gif\"\u003e\u003ccode\u003e@​sushi-gif\u003c/code\u003e\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/security/advisories/GHSA-w7vc-732c-9m39\"\u003e\u003ccode\u003eGHSA-w7vc-732c-9m39\u003c/code\u003e\u003c/a\u003e — DoS via base64 decode of unused payload segment when \u003ccode\u003eb64=false\u003c/code\u003e.\u003c/strong\u003e For detached-payload JWS (\u003ccode\u003eb64=false\u003c/code\u003e), the compact-form payload segment was base64-decoded before being discarded in favor of the caller-supplied \u003ccode\u003edetached_payload\u003c/code\u003e. An attacker could inflate the unused segment to force CPU + memory cost without holding a valid signature. The segment is now required to be empty per RFC 7515 Appendix F, and is no longer decoded. \u003cem\u003eReported by \u003ca href=\"https://github.com/thesmartshadow\"\u003e\u003ccode\u003e@​thesmartshadow\u003c/code\u003e\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/security/advisories/GHSA-993g-76c3-p5m4\"\u003e\u003ccode\u003eGHSA-993g-76c3-p5m4\u003c/code\u003e\u003c/a\u003e — \u003ccode\u003ePyJWKClient\u003c/code\u003e accepts non-HTTP(S) URIs.\u003c/strong\u003e \u003ccode\u003ePyJWKClient.fetch_data\u003c/code\u003e passed its URI to \u003ccode\u003eurllib.request.urlopen\u003c/code\u003e, which by default also handles \u003ccode\u003efile://\u003c/code\u003e, \u003ccode\u003eftp://\u003c/code\u003e, and \u003ccode\u003edata:\u003c/code\u003e schemes. An application that fed an attacker-influenced URI into \u003ccode\u003ePyJWKClient\u003c/code\u003e could be coerced into reading local files or reaching other unintended schemes. \u003ccode\u003ePyJWKClient\u003c/code\u003e now rejects any URI whose scheme isn't \u003ccode\u003ehttp\u003c/code\u003e or \u003ccode\u003ehttps\u003c/code\u003e. \u003cem\u003eReported by \u003ca href=\"https://github.com/KEIJOT\"\u003e\u003ccode\u003e@​KEIJOT\u003c/code\u003e\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/security/advisories/GHSA-fhv5-28vv-h8m8\"\u003e\u003ccode\u003eGHSA-fhv5-28vv-h8m8\u003c/code\u003e\u003c/a\u003e — \u003ccode\u003ePyJWKClient\u003c/code\u003e cache wiped on fetch error.\u003c/strong\u003e A \u003ccode\u003efinally\u003c/code\u003e-block \u003ccode\u003eput(jwk_set=None)\u003c/code\u003e cleared the JWK Set cache whenever a fetch raised, turning a transient JWKS-endpoint outage into application-wide auth failure. The cache write was moved into the success path; transient errors no longer evict valid cached keys. \u003cem\u003eReported by \u003ca href=\"https://github.com/eddieran\"\u003e\u003ccode\u003e@​eddieran\u003c/code\u003e\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eFixed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eReject empty HMAC keys outright in \u003ccode\u003eHMACAlgorithm.prepare_key\u003c/code\u003e with \u003ccode\u003eInvalidKeyError\u003c/code\u003e instead of accepting them with only a warning. Defends against the \u003ccode\u003eos.getenv(\u0026quot;JWT_SECRET\u0026quot;, \u0026quot;\u0026quot;)\u003c/code\u003e footgun. \u003cem\u003eThanks to \u003ca href=\"https://github.com/SnailSploit\"\u003e\u003ccode\u003e@​SnailSploit\u003c/code\u003e\u003c/a\u003e and \u003ca href=\"https://github.com/spartan8806\"\u003e\u003ccode\u003e@​spartan8806\u003c/code\u003e\u003c/a\u003e for the reports.\u003c/em\u003e\u003c/li\u003e\n\u003cli\u003eForward per-call \u003ccode\u003eoptions\u003c/code\u003e (including \u003ccode\u003eenforce_minimum_key_length\u003c/code\u003e) from \u003ccode\u003ePyJWT.decode\u003c/code\u003e through to \u003ccode\u003ePyJWS._verify_signature\u003c/code\u003e. The option was previously silently dropped between the two layers, so it only took effect when set on the \u003ccode\u003ePyJWT\u003c/code\u003e instance. \u003cem\u003eThanks to \u003ca href=\"https://github.com/WLUB\"\u003e\u003ccode\u003e@​WLUB\u003c/code\u003e\u003c/a\u003e for the report.\u003c/em\u003e\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eRFC 7797 §3 compliance for \u003ccode\u003eb64=false\u003c/code\u003e:\u003c/strong\u003e the encoder now auto-adds \u003ccode\u003e\u0026quot;b64\u0026quot;\u003c/code\u003e to \u003ccode\u003ecrit\u003c/code\u003e, and the decoder rejects tokens that set \u003ccode\u003eb64=false\u003c/code\u003e without listing it in \u003ccode\u003ecrit\u003c/code\u003e. \u003cem\u003eThanks to \u003ca href=\"https://github.com/MachineLearning-Nerd\"\u003e\u003ccode\u003e@​MachineLearning-Nerd\u003c/code\u003e\u003c/a\u003e for the report.\u003c/em\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eChanged\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMigrate the \u003ccode\u003edev\u003c/code\u003e, \u003ccode\u003edocs\u003c/code\u003e, and \u003ccode\u003etests\u003c/code\u003e package extras to dependency groups, by \u003ca href=\"https://github.com/kurtmckee\"\u003e\u003ccode\u003e@​kurtmckee\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/jpadilla/pyjwt/pull/1152\"\u003e#1152\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eUpgrade notes\u003c/h2\u003e\n\u003cp\u003eMost fixes are invisible to correctly-configured callers. A few behavioral changes you may encounter:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eEmpty HMAC keys now raise.\u003c/strong\u003e If your app passed \u003ccode\u003e\u0026quot;\u0026quot;\u003c/code\u003e or \u003ccode\u003eb\u0026quot;\u0026quot;\u003c/code\u003e as a secret (often via a missing env var, e.g. \u003ccode\u003eos.getenv(\u0026quot;JWT_SECRET\u0026quot;, \u0026quot;\u0026quot;)\u003c/code\u003e), \u003ccode\u003eencode\u003c/code\u003e/\u003ccode\u003edecode\u003c/code\u003e will now raise \u003ccode\u003eInvalidKeyError\u003c/code\u003e. This is the intended behavior — fix the configuration.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ccode\u003ePyJWK\u003c/code\u003e decoding now requires the token's \u003ccode\u003ealg\u003c/code\u003e to match the JWK's algorithm.\u003c/strong\u003e Previously a mismatch was silently honored if the header \u003ccode\u003ealg\u003c/code\u003e appeared in the allow-list. Tokens that relied on this mismatch will now fail with \u003ccode\u003eInvalidAlgorithmError\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ccode\u003ePyJWKClient\u003c/code\u003e now rejects non-HTTP(S) URIs at construction time.\u003c/strong\u003e Tests or dev environments that fetched JWKS from \u003ccode\u003efile://\u003c/code\u003e URIs need to switch to a local HTTP server or load the JWKS by other means (e.g. construct \u003ccode\u003ePyJWKSet.from_dict(...)\u003c/code\u003e directly).\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ccode\u003eb64=false\u003c/code\u003e tokens are now strictly RFC 7515 / 7797 compliant.\u003c/strong\u003e Tokens with a non-empty compact-form payload segment, or that omit \u003ccode\u003e\u0026quot;b64\u0026quot;\u003c/code\u003e from \u003ccode\u003ecrit\u003c/code\u003e, will be rejected. PyJWT-produced tokens always satisfy both invariants, so round-trips through PyJWT are unaffected.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ccode\u003eenforce_minimum_key_length\u003c/code\u003e set per-call now takes effect.\u003c/strong\u003e Callers who passed \u003ccode\u003eoptions={\u0026quot;enforce_minimum_key_length\u0026quot;: True}\u003c/code\u003e to \u003ccode\u003ejwt.decode()\u003c/code\u003e previously got no enforcement; they will now get \u003ccode\u003eInvalidKeyError\u003c/code\u003e on undersized keys, as documented.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull changelog:\u003c/strong\u003e \u003ca href=\"https://github.com/jpadilla/pyjwt/compare/2.12.1...2.13.0\"\u003ehttps://github.com/jpadilla/pyjwt/compare/2.12.1...2.13.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003e2.12.1\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd typing_extensions dependency for Python \u0026lt; 3.11 by \u003ca href=\"https://github.com/jpadilla\"\u003e\u003ccode\u003e@​jpadilla\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/jpadilla/pyjwt/pull/1151\"\u003ejpadilla/pyjwt#1151\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/jpadilla/pyjwt/compare/2.12.0...2.12.1\"\u003ehttps://github.com/jpadilla/pyjwt/compare/2.12.0...2.12.1\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003e2.12.0\u003c/h2\u003e\n\u003ch2\u003eSecurity\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eValidate the crit (Critical) Header Parameter defined in RFC 7515 §4.1.11. by \u003ca href=\"https://github.com/dmbs335\"\u003e\u003ccode\u003e@​dmbs335\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://github.com/jpadilla/pyjwt/security/advisories/GHSA-752w-5fwx-jx9f\"\u003eGHSA-752w-5fwx-jx9f\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/jpadilla/pyjwt/blob/master/CHANGELOG.rst\"\u003epyjwt's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ccode\u003ev2.13.0 \u0026lt;https://github.com/jpadilla/pyjwt/compare/2.12.1...2.13.0\u0026gt;\u003c/code\u003e__\u003c/h2\u003e\n\u003cp\u003eSecurity\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003e\n- Reject JWK JSON documents passed as raw HMAC secrets in\n  ``HMACAlgorithm.prepare_key`` to close an algorithm-confusion gap that\n  the existing PEM/SSH guard did not cover. Reported by @aradona91 in\n  `GHSA-xgmm-8j9v-c9wx \u0026lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-xgmm-8j9v-c9wx\u0026gt;`__.\n- Bind the JWT header ``alg`` to ``PyJWK.algorithm_name`` during\n  verification so the caller's ``algorithms=[...]`` allow-list cannot be\n  bypassed when decoding with a ``PyJWK`` / ``PyJWKClient`` key. Reported\n  by @sushi-gif in `GHSA-jq35-7prp-9v3f \u0026lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-jq35-7prp-9v3f\u0026gt;`__.\n- Reject non-``http(s)`` URI schemes in ``PyJWKClient`` so attacker-\n  influenced URIs cannot read local files or reach unintended schemes via\n  urllib's default ``file://`` / ``ftp://`` / ``data:`` handlers. Reported\n  by @KEIJOT in `GHSA-993g-76c3-p5m4 \u0026lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-993g-76c3-p5m4\u0026gt;`__.\n- Preserve the cached JWK Set on fetch errors in ``PyJWKClient.fetch_data``.\n  The previous ``finally``-block ``put(None)`` pattern cleared the cache\n  on any transient outage, turning one bad JWKS request into application-\n  wide auth failure. Reported by @eddieran in `GHSA-fhv5-28vv-h8m8 \u0026lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-fhv5-28vv-h8m8\u0026gt;`__.\n- Skip the unconditional base64 decode of the compact-form payload segment\n  when ``b64=false`` is set in the protected header, and require that\n  segment to be empty (RFC 7515 Appendix F detached form). Closes an\n  unauthenticated DoS amplifier. Reported by @thesmartshadow in\n  `GHSA-w7vc-732c-9m39 \u0026lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-w7vc-732c-9m39\u0026gt;`__.\n\u003cp\u003eFixed\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003e\n- Reject empty HMAC keys outright in ``HMACAlgorithm.prepare_key`` with\n  ``InvalidKeyError`` instead of accepting them with only a warning.\n  Thanks to @SnailSploit and @spartan8806 for independently flagging the\n  footgun.\n- Forward per-call ``options`` (including ``enforce_minimum_key_length``)\n  from ``PyJWT.decode`` through to ``PyJWS._verify_signature`` so the\n  option actually takes effect when set at the call site rather than only\n  on the ``PyJWT`` instance. Thanks to @WLUB for the report.\n- RFC 7797 §3 compliance for ``b64=false``: the encoder now auto-adds\n  ``\u0026amp;quot;b64\u0026amp;quot;`` to the ``crit`` header parameter, and the decoder rejects\n  tokens that set ``b64=false`` without listing it in ``crit``. Thanks to\n  @MachineLearning-Nerd for the report.\n\nChanged\n\u003c/code\u003e\u003c/pre\u003e\n\u003cul\u003e\n\u003cli\u003eMigrate the \u003ccode\u003edev\u003c/code\u003e, \u003ccode\u003edocs\u003c/code\u003e, and \u003ccode\u003etests\u003c/code\u003e package extras to dependency groups by \u003ca href=\"https://github.com/kurtmckee\"\u003e\u003ccode\u003e@​kurtmckee\u003c/code\u003e\u003c/a\u003e in \u003ccode\u003e[#1152](https://github.com/jpadilla/pyjwt/issues/1152) \u0026amp;lt;https://github.com/jpadilla/pyjwt/pull/1152\u0026amp;gt;\u003c/code\u003e__\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003ccode\u003ev2.12.1 \u0026amp;lt;https://github.com/jpadilla/pyjwt/compare/2.12.0...2.12.1\u0026amp;gt;\u003c/code\u003e__\n\u0026lt;/tr\u0026gt;\u0026lt;/table\u0026gt;\n\u003c/code\u003e\u003c/pre\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/7144e4534c34810f4525dc4578a32addd8212cff\"\u003e\u003ccode\u003e7144e45\u003c/code\u003e\u003c/a\u003e Apply ruff format\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/d2f4bec4963897c0ef96ef64a875894f2c8542ab\"\u003e\u003ccode\u003ed2f4bec\u003c/code\u003e\u003c/a\u003e Restore \u003ccode\u003ecast()\u003c/code\u003e calls with cross-version \u003ccode\u003etype: ignore\u003c/code\u003e for \u003ccode\u003eprepare_key\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/22f478cebddd8294259c30f037ecb92b0b348774\"\u003e\u003ccode\u003e22f478c\u003c/code\u003e\u003c/a\u003e Remove redundant casts in \u003ccode\u003eRSAAlgorithm.prepare_key\u003c/code\u003e and `ECAlgorithm.prepare...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/95791b1759b8aa4f2203575d344d5c78564cdc81\"\u003e\u003ccode\u003e95791b1\u003c/code\u003e\u003c/a\u003e Bundle security fixes and hardening into 2.13.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/dcc27a9d3182a2349c30b160758785c6ce7a6508\"\u003e\u003ccode\u003edcc27a9\u003c/code\u003e\u003c/a\u003e [pre-commit.ci] pre-commit autoupdate (\u003ca href=\"https://redirect.github.com/jpadilla/pyjwt/issues/1155\"\u003e#1155\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/9d08a9a1896845ed8eaf88e6f6ac61e5800c3e7a\"\u003e\u003ccode\u003e9d08a9a\u003c/code\u003e\u003c/a\u003e [pre-commit.ci] pre-commit autoupdate (\u003ca href=\"https://redirect.github.com/jpadilla/pyjwt/issues/1146\"\u003e#1146\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/b87c10014d4109f0214fea188d00faaaf8a80e64\"\u003e\u003ccode\u003eb87c100\u003c/code\u003e\u003c/a\u003e Bump codecov/codecov-action from 5 to 6 (\u003ca href=\"https://redirect.github.com/jpadilla/pyjwt/issues/1154\"\u003e#1154\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/40e3147eb5f790d8d041772e5fc00728a176c812\"\u003e\u003ccode\u003e40e3147\u003c/code\u003e\u003c/a\u003e Migrate development extras to dependency groups (\u003ca href=\"https://redirect.github.com/jpadilla/pyjwt/issues/1152\"\u003e#1152\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/a4e1a3d1218b01c5806420b8f16d9308ac4adc30\"\u003e\u003ccode\u003ea4e1a3d\u003c/code\u003e\u003c/a\u003e Add typing_extensions dependency for Python \u0026lt; 3.11 (\u003ca href=\"https://redirect.github.com/jpadilla/pyjwt/issues/1151\"\u003e#1151\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/bd9700cca7f9258fadcc429c1034e508025931f2\"\u003e\u003ccode\u003ebd9700c\u003c/code\u003e\u003c/a\u003e Use PyJWK algorithm when encoding without explicit algorithm (\u003ca href=\"https://redirect.github.com/jpadilla/pyjwt/issues/1148\"\u003e#1148\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/jpadilla/pyjwt/compare/2.10.1...2.13.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `python-dotenv` from 1.1.0 to 1.2.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/theskumar/python-dotenv/releases\"\u003epython-dotenv's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.2.2\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eSupport for Python 3.14, including the free-threaded (3.14t) build. (#)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eThe \u003ccode\u003edotenv run\u003c/code\u003e command now forwards flags directly to the specified command by \u003ca href=\"https://github.com/bbc2\"\u003e\u003ccode\u003e@​bbc2\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/pull/607\"\u003etheskumar/python-dotenv#607\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eImproved documentation clarity regarding override behavior and the reference page.\u003c/li\u003e\n\u003cli\u003eUpdated PyPy support to version 3.11.\u003c/li\u003e\n\u003cli\u003eDocumentation for FIFO file support.\u003c/li\u003e\n\u003cli\u003eSupport for Python 3.9.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eImproved \u003ccode\u003eset_key\u003c/code\u003e and \u003ccode\u003eunset_key\u003c/code\u003e behavior when interacting with symlinks by \u003ca href=\"https://github.com/bbc2\"\u003e\u003ccode\u003e@​bbc2\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://github.com/theskumar/python-dotenv/commit/790c5c02991100aa1bf41ee5330aca75edc51311\"\u003e#790c5\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eCorrected the license specifier and added missing Python 3.14 classifiers in package metadata by \u003ca href=\"https://github.com/JYOuyang\"\u003e\u003ccode\u003e@​JYOuyang\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/pull/590\"\u003etheskumar/python-dotenv#590\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBreaking Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ccode\u003edotenv.set_key\u003c/code\u003e and \u003ccode\u003edotenv.unset_key\u003c/code\u003e used to follow symlinks in some\nsituations. This is no longer the case. For that behavior to be restored in\nall cases, \u003ccode\u003efollow_symlinks=True\u003c/code\u003e should be used.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eIn the CLI, \u003ccode\u003eset\u003c/code\u003e and \u003ccode\u003eunset\u003c/code\u003e used to follow symlinks in some situations. This\nis no longer the case.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ccode\u003edotenv.set_key\u003c/code\u003e, \u003ccode\u003edotenv.unset_key\u003c/code\u003e and the CLI commands \u003ccode\u003eset\u003c/code\u003e and \u003ccode\u003eunset\u003c/code\u003e\nused to reset the file mode of the modified .env file to \u003ccode\u003e0o600\u003c/code\u003e in some\nsituations. This is no longer the case: The original mode of the file is now\npreserved. Is the file needed to be created or wasn't a regular file, mode\n\u003ccode\u003e0o600\u003c/code\u003e is used.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMisc\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eskip 000 permission tests for root user by \u003ca href=\"https://github.com/burnout-projects\"\u003e\u003ccode\u003e@​burnout-projects\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/pull/561\"\u003etheskumar/python-dotenv#561\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump actions/checkout from 5 to 6 in the github-actions group by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/pull/593\"\u003etheskumar/python-dotenv#593\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd Windows testing to CI by \u003ca href=\"https://github.com/bbc2\"\u003e\u003ccode\u003e@​bbc2\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/pull/604\"\u003etheskumar/python-dotenv#604\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eImprove workflow efficiency with best practices by \u003ca href=\"https://github.com/theskumar\"\u003e\u003ccode\u003e@​theskumar\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/pull/609\"\u003etheskumar/python-dotenv#609\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRemove the use of \u003ccode\u003esh\u003c/code\u003e in tests by \u003ca href=\"https://github.com/bbc2\"\u003e\u003ccode\u003e@​bbc2\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/pull/612\"\u003etheskumar/python-dotenv#612\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/JYOuyang\"\u003e\u003ccode\u003e@​JYOuyang\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/pull/590\"\u003etheskumar/python-dotenv#590\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/burnout-projects\"\u003e\u003ccode\u003e@​burnout-projects\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/pull/561\"\u003etheskumar/python-dotenv#561\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cpackham-atlnz\"\u003e\u003ccode\u003e@​cpackham-atlnz\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/pull/597\"\u003etheskumar/python-dotenv#597\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/theskumar/python-dotenv/compare/v1.2.1...v1.2.2\"\u003ehttps://github.com/theskumar/python-dotenv/compare/v1.2.1...v1.2.2\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev1.2.1\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/theskumar/python-dotenv/blob/main/CHANGELOG.md\"\u003epython-dotenv's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e[1.2.2] - 2026-03-01\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eSupport for Python 3.14, including the free-threaded (3.14t) build. (\u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/588\"\u003e#588\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eThe \u003ccode\u003edotenv run\u003c/code\u003e command now forwards flags directly to the specified command by [\u003ca href=\"https://github.com/bbc2\"\u003e\u003ccode\u003e@​bbc2\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/607\"\u003e#607\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eImproved documentation clarity regarding override behavior and the reference page.\u003c/li\u003e\n\u003cli\u003eUpdated PyPy support to version 3.11.\u003c/li\u003e\n\u003cli\u003eDocumentation for FIFO file support.\u003c/li\u003e\n\u003cli\u003eDropped Support for Python 3.9.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eImproved \u003ccode\u003eset_key\u003c/code\u003e and \u003ccode\u003eunset_key\u003c/code\u003e behavior when interacting with symlinks by [\u003ca href=\"https://github.com/bbc2\"\u003e\u003ccode\u003e@​bbc2\u003c/code\u003e\u003c/a\u003e] in [790c5c0]\u003c/li\u003e\n\u003cli\u003eCorrected the license specifier and added missing Python 3.14 classifiers in package metadata by [\u003ca href=\"https://github.com/JYOuyang\"\u003e\u003ccode\u003e@​JYOuyang\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/590\"\u003e#590\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBreaking Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ccode\u003edotenv.set_key\u003c/code\u003e and \u003ccode\u003edotenv.unset_key\u003c/code\u003e used to follow symlinks in some\nsituations. This is no longer the case. For that behavior to be restored in\nall cases, \u003ccode\u003efollow_symlinks=True\u003c/code\u003e should be used.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eIn the CLI, \u003ccode\u003eset\u003c/code\u003e and \u003ccode\u003eunset\u003c/code\u003e used to follow symlinks in some situations. This\nis no longer the case.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ccode\u003edotenv.set_key\u003c/code\u003e, \u003ccode\u003edotenv.unset_key\u003c/code\u003e and the CLI commands \u003ccode\u003eset\u003c/code\u003e and \u003ccode\u003eunset\u003c/code\u003e\nused to reset the file mode of the modified .env file to \u003ccode\u003e0o600\u003c/code\u003e in some\nsituations. This is no longer the case: The original mode of the file is now\npreserved. Is the file needed to be created or wasn't a regular file, mode\n\u003ccode\u003e0o600\u003c/code\u003e is used.\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e[1.2.1] - 2025-10-26\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMove more config to \u003ccode\u003epyproject.toml\u003c/code\u003e, removed \u003ccode\u003esetup.cfg\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eAdd support for reading \u003ccode\u003e.env\u003c/code\u003e from FIFOs (Unix) by [\u003ca href=\"https://github.com/sidharth-sudhir\"\u003e\u003ccode\u003e@​sidharth-sudhir\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/586\"\u003e#586\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e[1.2.0] - 2025-10-26\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade build system to use PEP 517 \u0026amp; PEP 518 to use \u003ccode\u003ebuild\u003c/code\u003e and \u003ccode\u003epyproject.toml\u003c/code\u003e by [\u003ca href=\"https://github.com/EpicWink\"\u003e\u003ccode\u003e@​EpicWink\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/583\"\u003e#583\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd support for Python 3.14 by [\u003ca href=\"https://github.com/23f3001135\"\u003e\u003ccode\u003e@​23f3001135\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/579\"\u003e#579\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd support for disabling of \u003ccode\u003eload_dotenv()\u003c/code\u003e using \u003ccode\u003ePYTHON_DOTENV_DISABLED\u003c/code\u003e env var. by [\u003ca href=\"https://github.com/matthewfranglen\"\u003e\u003ccode\u003e@​matthewfranglen\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/569\"\u003e#569\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e[1.1.1] - 2025-06-24\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eCLI: Ensure \u003ccode\u003efind_dotenv\u003c/code\u003e work reliably on python 3.13 by [\u003ca href=\"https://github.com/theskumar\"\u003e\u003ccode\u003e@​theskumar\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/563\"\u003e#563\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/36004e0e34be7665ff2b11a8a4005144f76f176d\"\u003e\u003ccode\u003e36004e0\u003c/code\u003e\u003c/a\u003e Bump version: 1.2.1 → 1.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/eb202520e5933c9daf42501e1e42fdb0144002c8\"\u003e\u003ccode\u003eeb20252\u003c/code\u003e\u003c/a\u003e docs: update changelog for v1.2.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/790c5c02991100aa1bf41ee5330aca75edc51311\"\u003e\u003ccode\u003e790c5c0\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/43340da220fb4ca4f95357bbe21a3c7f8f1278b1\"\u003e\u003ccode\u003e43340da\u003c/code\u003e\u003c/a\u003e Remove the use of \u003ccode\u003esh\u003c/code\u003e in tests (\u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/612\"\u003e#612\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/09d7cee32459e7abdcb5c9d8122a552589c06a9c\"\u003e\u003ccode\u003e09d7cee\u003c/code\u003e\u003c/a\u003e docs: clarify override behavior and document FIFO support (\u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/610\"\u003e#610\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/c8de2887c00198c22842c5ae5e92d1747467363c\"\u003e\u003ccode\u003ec8de288\u003c/code\u003e\u003c/a\u003e ci: improve workflow efficiency with best practices (\u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/609\"\u003e#609\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/7bd9e3dbfedc0983ad7d56d5570013035242bdf4\"\u003e\u003ccode\u003e7bd9e3d\u003c/code\u003e\u003c/a\u003e Add Windows testing to CI (\u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/604\"\u003e#604\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/1baaf04f336072e0ee324d5df9563ec767f14f81\"\u003e\u003ccode\u003e1baaf04\u003c/code\u003e\u003c/a\u003e Drop Python 3.9 support and update to PyPy 3.11 (\u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/608\"\u003e#608\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/4a22cf8993804aeede0c20b75bb1a29d3a99e9dc\"\u003e\u003ccode\u003e4a22cf8\u003c/code\u003e\u003c/a\u003e ci: enable testing on Python 3.14t (free-threaded) (\u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/588\"\u003e#588\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/e2e8e776b42e382ae38b44d3982dd649e7507dd4\"\u003e\u003ccode\u003ee2e8e77\u003c/code\u003e\u003c/a\u003e Fix license specifier (\u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/597\"\u003e#597\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/theskumar/python-dotenv/compare/v1.1.0...v1.2.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `requests` from 2.32.5 to 2.33.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/psf/requests/releases\"\u003erequests's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.33.0\u003c/h2\u003e\n\u003ch2\u003e2.33.0 (2026-03-25)\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eAnnouncements\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e📣 Requests is adding inline types. If you have a typed code base that uses Requests, please take a look at \u003ca href=\"https://redirect.github.com/psf/requests/issues/7271\"\u003e#7271\u003c/a\u003e. Give it a try, and report any gaps or feedback you may have in the issue. 📣\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eSecurity\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eCVE-2026-25645 \u003ccode\u003erequests.utils.extract_zipped_paths\u003c/code\u003e now extracts contents to a non-deterministic location to prevent malicious file replacement. This does not affect default usage of Requests, only applications calling the utility function directly.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eImprovements\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eMigrated to a PEP 517 build system using setuptools. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7012\"\u003e#7012\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eBugfixes\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eFixed an issue where an empty netrc entry could cause malformed authentication to be applied to Requests on Python 3.11+. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7205\"\u003e#7205\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eDeprecations\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eDropped support for Python 3.9 following its end of support. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7196\"\u003e#7196\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eDocumentation\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eVarious typo fixes and doc improvements.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/M0d3v1\"\u003e\u003ccode\u003e@​M0d3v1\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/psf/requests/pull/6865\"\u003epsf/requests#6865\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/aminvakil\"\u003e\u003ccode\u003e@​aminvakil\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/psf/requests/pull/7220\"\u003epsf/requests#7220\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/E8Price\"\u003e\u003ccode\u003e@​E8Price\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/psf/requests/pull/6960\"\u003epsf/requests#6960\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mitre88\"\u003e\u003ccode\u003e@​mitre88\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/psf/requests/pull/7244\"\u003epsf/requests#7244\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/magsen\"\u003e\u003ccode\u003e@​magsen\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/psf/requests/pull/6553\"\u003epsf/requests#6553\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Rohan5commit\"\u003e\u003ccode\u003e@​Rohan5commit\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/psf/requests/pull/7227\"\u003epsf/requests#7227\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/psf/requests/blob/main/HISTORY.md#2330-2026-03-25\"\u003ehttps://github.com/psf/requests/blob/main/HISTORY.md#2330-2026-03-25\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/psf/requests/blob/main/HISTORY.md\"\u003erequests's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e2.33.0 (2026-03-25)\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eAnnouncements\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e📣 Requests is adding inline types. If you have a typed code base that\nuses Requests, please take a look at \u003ca href=\"https://redirect.github.com/psf/requests/issues/7271\"\u003e#7271\u003c/a\u003e. Give it a try, and report\nany gaps or feedback you may have in the issue. 📣\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eSecurity\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eCVE-2026-25645 \u003ccode\u003erequests.utils.extract_zipped_paths\u003c/code\u003e now extracts\ncontents to a non-deterministic location to prevent malicious file\nreplacement. This does not affect default usage of Requests, only\napplications calling the utility function directly.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eImprovements\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eMigrated to a PEP 517 build system using setuptools. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7012\"\u003e#7012\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eBugfixes\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eFixed an issue where an empty netrc entry could cause\nmalformed authentication to be applied to Requests on\nPython 3.11+. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7205\"\u003e#7205\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eDeprecations\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eDropped support for Python 3.9 following its end of support. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7196\"\u003e#7196\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eDocumentation\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eVarious typo fixes and doc improvements.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/bc04dfd6dad4cb02cd92f5daa81eb562d280a761\"\u003e\u003ccode\u003ebc04dfd\u003c/code\u003e\u003c/a\u003e v2.33.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/66d21cb07bd6255b1280291c4fafb71803cdb3b7\"\u003e\u003ccode\u003e66d21cb\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/8b9bc8fc0f63be84602387913c4b689f19efd028\"\u003e\u003ccode\u003e8b9bc8f\u003c/code\u003e\u003c/a\u003e Move badges to top of README (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7293\"\u003e#7293\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/e331a288f369973f5de0ec8901c94cae4fa87286\"\u003e\u003ccode\u003ee331a28\u003c/code\u003e\u003c/a\u003e Remove unused extraction call (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7292\"\u003e#7292\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/753fd08c5eacce0aa0df73fe47e49525c67e0a29\"\u003e\u003ccode\u003e753fd08\u003c/code\u003e\u003c/a\u003e docs: fix FAQ grammar in httplib2 example\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/774a0b837a194ee885d4fdd9ca947900cc3daf71\"\u003e\u003ccode\u003e774a0b8\u003c/code\u003e\u003c/a\u003e docs(socks): same block as other sections\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/9c72a41bec8597f948c9d8caa5dc3f12273b3303\"\u003e\u003ccode\u003e9c72a41\u003c/code\u003e\u003c/a\u003e Bump github/codeql-action from 4.33.0 to 4.34.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/ebf71906798ec82f34e07d3168f8b8aecaf8a3be\"\u003e\u003ccode\u003eebf7190\u003c/code\u003e\u003c/a\u003e Bump github/codeql-action from 4.32.0 to 4.33.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/0e4ae38f0c93d4f92a96c774bd52c069d12a4798\"\u003e\u003ccode\u003e0e4ae38\u003c/code\u003e\u003c/a\u003e docs: exclude Response.is_permanent_redirect from API docs (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7244\"\u003e#7244\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/d568f47278492e630cc990a259047c67991d007a\"\u003e\u003ccode\u003ed568f47\u003c/code\u003e\u003c/a\u003e docs: clarify Quickstart POST example (\u003ca href=\"https://redirect.github.com/psf/requests/issues/6960\"\u003e#6960\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/psf/requests/compare/v2.32.5...v2.33.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `urllib3` from 2.6.3 to 2.7.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/urllib3/urllib3/releases\"\u003eurllib3's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e2.7.0\u003c/h2\u003e\n\u003ch2\u003e🚀 urllib3 is fundraising for HTTP/2 support\u003c/h2\u003e\n\u003cp\u003e\u003ca href=\"https://sethmlarson.dev/urllib3-is-fundraising-for-http2-support\"\u003eurllib3 is raising ~$40,000 USD\u003c/a\u003e to release HTTP/2 support and ensure long-term sustainable maintenance of the project after a sharp decline in financial support. If your company or organization uses Python and would benefit from HTTP/2 support in Requests, pip, cloud SDKs, and thousands of other projects \u003ca href=\"https://opencollective.com/urllib3\"\u003eplease consider contributing financially\u003c/a\u003e to ensure HTTP/2 support is developed sustainably and maintained for the long-haul.\u003c/p\u003e\n\u003cp\u003eThank you for your support.\u003c/p\u003e\n\u003ch2\u003eSecurity\u003c/h2\u003e\n\u003cp\u003eAddressed high-severity security issues. Impact was limited to specific use cases detailed in the accompanying advisories; overall user exposure was estimated to be marginal.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eDecompression-bomb safeguards of the streaming API were bypassed:\u003c/p\u003e\n\u003col\u003e\n\u003cli\u003eWhen \u003ccode\u003eHTTPResponse.drain_conn()\u003c/code\u003e was called after the response had been read and decompressed partially. (Reported by \u003ca href=\"https://github.com/Cycloctane\"\u003e\u003ccode\u003e@​Cycloctane\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eDuring the second \u003ccode\u003eHTTPResponse.read(amt=N)\u003c/code\u003e or \u003ccode\u003eHTTPResponse.stream(amt=N)\u003c/code\u003e call when the response was decompressed using the official \u003ca href=\"https://pypi.org/project/brotli/\"\u003eBrotli\u003c/a\u003e library. (Reported by \u003ca href=\"https://github.com/kimkou2024\"\u003e\u003ccode\u003e@​kimkou2024\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ol\u003e\n\u003cp\u003eSee GHSA-mf9v-mfxr-j63j for details.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eHTTP pools created using \u003ccode\u003eProxyManager.connection_from_url\u003c/code\u003e did not strip sensitive headers specified in \u003ccode\u003eRetry.remove_headers_on_redirect\u003c/code\u003e when redirecting to a different host. (GHSA-qccp-gfcp-xxvc reported by \u003ca href=\"https://github.com/christos-spearbit\"\u003e\u003ccode\u003e@​christos-spearbit\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eDeprecations and Removals\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUsed \u003ccode\u003eFutureWarning\u003c/code\u003e instead of \u003ccode\u003eDeprecationWarning\u003c/code\u003e for better visibility of existing deprecation notices. Rescheduled the removal of deprecated features to version 3.0. (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/3763\"\u003eurllib3/urllib3#3763\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRemoved support for end-of-life Python 3.9. (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/3720\"\u003eurllib3/urllib3#3720\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRemoved support for end-of-life PyPy3.10. (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/4979\"\u003eurllib3/urllib3#4979\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eBumped the minimum supported pyOpenSSL version to 19.0.0. (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/3777\"\u003eurllib3/urllib3#3777\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eBugfixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed a bug where \u003ccode\u003eHTTPResponse.read(amt=None)\u003c/code\u003e was ignoring decompressed data buffered from previous partial reads. (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/3636\"\u003eurllib3/urllib3#3636\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed a bug where \u003ccode\u003eHTTPResponse.read()\u003c/code\u003e could cache only part of the response after a partial read when \u003ccode\u003ecache_content=True\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/4967\"\u003eurllib3/urllib3#4967\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eHTTPResponse.stream()\u003c/code\u003e and \u003ccode\u003eHTTPResponse.read_chunked()\u003c/code\u003e to handle \u003ccode\u003eamt=0\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/3793\"\u003eurllib3/urllib3#3793\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eUpdated \u003ccode\u003e_TYPE_BODY\u003c/code\u003e type alias to include missing \u003ccode\u003eIterable[str]\u003c/code\u003e, matching the documented and runtime behavior of chunked request bodies. (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/3798\"\u003eurllib3/urllib3#3798\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eLocationParseError\u003c/code\u003e when paths resembling schemeless URIs were passed to \u003ccode\u003eHTTPConnectionPool.urlopen()\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/3352\"\u003eurllib3/urllib3#3352\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eBaseHTTPResponse.readinto()\u003c/code\u003e type annotation to accept \u003ccode\u003ememoryview\u003c/code\u003e in addition to \u003ccode\u003ebytearray\u003c/code\u003e, matching the \u003ccode\u003eio.RawIOBase.readinto\u003c/code\u003e contract and enabling use with \u003ccode\u003eio.BufferedReader\u003c/code\u003e without type errors. (\u003ca href=\"https://redirect.github.com/urllib3/urllib3/issues/3764\"\u003eurllib3/urllib3#3764\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/urllib3/urllib3/blob/main/CHANGES.rst\"\u003eurllib3's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003e2.7.0 (2026-05-07)\u003c/h1\u003e\n\u003ch2\u003eSecurity\u003c/h2\u003e\n\u003cp\u003eAddressed high-severity security issues.\nImpact was limited to specific use cases detailed in the accompanying\nadvisories; overall user exposure was estimated to be marginal.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eDecompression-bomb safeguards of the streaming API were bypassed:\u003c/p\u003e\n\u003col\u003e\n\u003cli\u003eWhen \u003ccode\u003eHTTPResponse.drain_conn()\u003c/code\u003e was called after the response had been\nread and decompressed partially.\u003c/li\u003e\n\u003cli\u003eDuring the second \u003ccode\u003eHTTPResponse.read(amt=N)\u003c/code\u003e or\n\u003ccode\u003eHTTPResponse.stream(amt=N)\u003c/code\u003e call when the response was decompressed\nusing the official \u003ccode\u003eBrotli \u0026lt;https://pypi.org/project/brotli/\u0026gt;\u003c/code\u003e__ library.\u003c/li\u003e\n\u003c/ol\u003e\n\u003cp\u003eSee \u003ccode\u003eGHSA-mf9v-mfxr-j63j \u0026lt;https://github.com/urllib3/urllib3/security/advisories/GHSA-mf9v-mfxr-j63j\u0026gt;\u003c/code\u003e__\nfor details.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eHTTP pools created using \u003ccode\u003eProxyManager.connection_from_url\u003c/code\u003e did not strip\nsensitive headers specified in \u003ccode\u003eRetry.remove_headers_on_redirect\u003c/code\u003e when\nredirecting to a different host.\n(\u003ccode\u003eGHSA-qccp-gfcp-xxvc \u0026lt;https://github.com/urllib3/urllib3/security/advisories/GHSA-qccp-gfcp-xxvc\u0026gt;\u003c/code\u003e__)\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eDeprecations and Removals\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUsed \u003ccode\u003eFutureWarning\u003c/code\u003e instead of \u003ccode\u003eDeprecationWarning\u003c/code\u003e for better\nvisibility of existing deprecation notices. Rescheduled the removal of\ndeprecated features to version 3.0.\n(\u003ccode\u003e[#3763](https://github.com/urllib3/urllib3/issues/3763) \u0026lt;https://github.com/urllib3/urllib3/issues/3763\u0026gt;\u003c/code\u003e__)\u003c/li\u003e\n\u003cli\u003eRemoved support for end-of-life Python 3.9.\n(\u003ccode\u003e[#3720](https://github.com/urllib3/urllib3/issues/3720) \u0026lt;https://github.com/urllib3/urllib3/issues/3720\u0026gt;\u003c/code\u003e__)\u003c/li\u003e\n\u003cli\u003eRemoved support for end-of-life PyPy3.10.\n(\u003ccode\u003e[#4979](https://github.com/urllib3/urllib3/issues/4979) \u0026lt;https://github.com/urllib3/urllib3/issues/4979\u0026gt;\u003c/code\u003e__)\u003c/li\u003e\n\u003cli\u003eBumped the minimum supported pyOpenSSL version to 19.0.0.\n(\u003ccode\u003e[#3777](https://github.com/urllib3/urllib3/issues/3777) \u0026lt;https://github.com/urllib3/urllib3/issues/3777\u0026gt;\u003c/code\u003e__)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eBugfixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed a bug where \u003ccode\u003eHTTPResponse.read(amt=None)\u003c/code\u003e was ignoring decompressed\ndata buffered from previous partial reads.\n(\u003ccode\u003e[#3636](https://github.com/urllib3/urllib3/issues/3636) \u0026lt;https://github.com/urllib3/urllib3/issues/3636\u0026gt;\u003c/code\u003e__)\u003c/li\u003e\n\u003cli\u003eFixed a bug where \u003ccode\u003eHTTPResponse.read()\u003c/code\u003e could cache only part of the\nresponse after a partial read when \u003ccode\u003ecache_content=True\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/urllib3/urllib3/commit/9a950b92d999f906b6020bb2d1076ee56cddd5d2\"\u003e\u003ccode\u003e9a950b9\u003c/code\u003e\u003c/a\u003e Release 2.7.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/urllib3/urllib3/commit/5ec0de499b9166ca71c65ab04f2a7e4eb0d66fcc\"\u003e\u003ccode\u003e5ec0de4\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/urllib3/urllib3/commit/2bdcc44d1e163fb5cc48a8662425e35e15adfe6a\"\u003e\u003ccode\u003e2bdcc44\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/urllib3/urllib3/commit/f45b0df09d8620ac6ed0491eb9362c8c87b7bc2c\"\u003e\u003ccode\u003ef45b0...\n\n_Description has been truncated_","html_url":"https://github.com/dabelstech-creator/cdp-sdk/pull/2","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/dabelstech-creator%2Fcdp-sdk/issues/2","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/2/packages"}},{"old_version":"3.14.1","new_version":"3.14.3","update_type":"patch","path":null,"pr_created_at":"2026-09-19T00:45:27.000Z","version_change":"3.14.1 → 3.14.3","issue":{"uuid":"5506554398","node_id":"PR_kwDOURkMPc8AAAABEKy_IQ","number":2,"state":"open","title":"build(deps): bump the pip group across 1 directory with 3 updates","user":"dependabot[bot]","labels":["dependencies","python"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-19T00:45:27.000Z","updated_at":"2026-09-19T00:45:34.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"build(deps): bump","group_name":"pip","update_count":3,"packages":[{"name":"pillow","old_version":"12.2.0","new_version":"12.3.0","repository_url":"https://github.com/python-pillow/Pillow"},{"name":"aiohttp","old_version":"3.14.1","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"anyio","old_version":"4.13.0","new_version":"4.14.2","repository_url":"https://github.com/agronholm/anyio"}],"path":null,"ecosystem":"pip"},"body":"Bumps the pip group with 3 updates in the /examples/wine-recommender directory: [pillow](https://github.com/python-pillow/Pillow), [aiohttp](https://github.com/aio-libs/aiohttp) and [anyio](https://github.com/agronholm/anyio).\n\nUpdates `pillow` from 12.2.0 to 12.3.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/python-pillow/Pillow/releases\"\u003epillow's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e12.3.0\u003c/h2\u003e\n\u003cp\u003e\u003ca href=\"https://pillow.readthedocs.io/en/stable/releasenotes/12.3.0.html\"\u003ehttps://pillow.readthedocs.io/en/stable/releasenotes/12.3.0.html\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eRemovals\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRemove non-image ImageCms modes \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9697\"\u003e#9697\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eDocumentation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd release notes for SBOM and performance improvements \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9747\"\u003e#9747\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdd security release notes \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9741\"\u003e#9741\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdd release notes for Python 3.15 beta wheels \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9696\"\u003e#9696\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eImageFont can also be used with ImageText \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9597\"\u003e#9597\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdditional guidelines for security reports \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9659\"\u003e#9659\u003c/a\u003e [\u003ca href=\"https://github.com/wiredfool\"\u003e\u003ccode\u003e@​wiredfool\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eFixed typo \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9636\"\u003e#9636\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdded CVEs to 12.2.0 release notes \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9591\"\u003e#9591\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eRevise development support information in README \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9583\"\u003e#9583\u003c/a\u003e [\u003ca href=\"https://github.com/aclark4life\"\u003e\u003ccode\u003e@​aclark4life\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdd INCIDENT_RESPONSE.md \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9555\"\u003e#9555\u003c/a\u003e [\u003ca href=\"https://github.com/aclark4life\"\u003e\u003ccode\u003e@​aclark4life\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdd STRIDE threat model to security docs \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9562\"\u003e#9562\u003c/a\u003e [\u003ca href=\"https://github.com/aclark4life\"\u003e\u003ccode\u003e@​aclark4life\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdd CVEs to 12.2.0 release notes \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9556\"\u003e#9556\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate README with revised security policy \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9553\"\u003e#9553\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate security policy \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9552\"\u003e#9552\u003c/a\u003e [\u003ca href=\"https://github.com/aclark4life\"\u003e\u003ccode\u003e@​aclark4life\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate macOS tested Python versions \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9534\"\u003e#9534\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eDependencies\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate dependency harfbuzz to v14.2.1 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9720\"\u003e#9720\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency mypy to v2 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9653\"\u003e#9653\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency cibuildwheel to v4 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9665\"\u003e#9665\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate github-actions \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9655\"\u003e#9655\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency libavif to v1.4.2 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9652\"\u003e#9652\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency lcms2 to v2.19.1 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9651\"\u003e#9651\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency check-jsonschema to v0.37.2 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9650\"\u003e#9650\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate google/oss-fuzz digest to d872252 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9614\"\u003e#9614\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency lcms2 to v2.19 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9609\"\u003e#9609\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency libpng to v1.6.58 - autoclosed \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9608\"\u003e#9608\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency harfbuzz to v14 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9610\"\u003e#9610\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency mypy to v1.20.2 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9599\"\u003e#9599\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate github-actions \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9611\"\u003e#9611\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency cibuildwheel to v3.4.1 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9607\"\u003e#9607\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eMove dependency versions to single JSON and enable Renovate \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9559\"\u003e#9559\u003c/a\u003e [\u003ca href=\"https://github.com/hugovk\"\u003e\u003ccode\u003e@​hugovk\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdated raqm to 0.10.5 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9557\"\u003e#9557\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency cibuildwheel to v3.4.0 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9532\"\u003e#9532\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eTesting\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRemove matrix.os from benchmark \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9735\"\u003e#9735\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eRemove references to libavif patch \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9734\"\u003e#9734\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdd benchmark tests \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9654\"\u003e#9654\u003c/a\u003e [\u003ca href=\"https://github.com/akx\"\u003e\u003ccode\u003e@​akx\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUse reshape() instead of setting NumPy array shape directly \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9728\"\u003e#9728\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/bb1d8e8ab8d29048624d96e3ee53cecf7c13d13d\"\u003e\u003ccode\u003ebb1d8e8\u003c/code\u003e\u003c/a\u003e 12.3.0 version bump\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/e63fc481dc2e07e21d5403deafb8f1ed98a513af\"\u003e\u003ccode\u003ee63fc48\u003c/code\u003e\u003c/a\u003e Add release notes for SBOM and performance improvements (\u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9747\"\u003e#9747\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/13b701bbab291eec4bc87ea17ba06c94e5fe3054\"\u003e\u003ccode\u003e13b701b\u003c/code\u003e\u003c/a\u003e Add release notes for \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9679\"\u003e#9679\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/5564ca72fcd59d040e270af5dcf17a0d7161c364\"\u003e\u003ccode\u003e5564ca7\u003c/code\u003e\u003c/a\u003e List methods\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/a0920fd384f800b5d0ba3dd29ecdeae4f1d4043b\"\u003e\u003ccode\u003ea0920fd\u003c/code\u003e\u003c/a\u003e Speed up ImageChops operations (\u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9738\"\u003e#9738\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/07e9a6cd5336dc6cf8cae9165cd70cdd2b3e42fc\"\u003e\u003ccode\u003e07e9a6c\u003c/code\u003e\u003c/a\u003e Speed up \u003ccode\u003eImage.filter()\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9736\"\u003e#9736\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/a94578cf9649ea13e426cf7fb2b71b39ffc0dd50\"\u003e\u003ccode\u003ea94578c\u003c/code\u003e\u003c/a\u003e Speed up \u003ccode\u003eImage.getchannel()\u003c/code\u003e, \u003ccode\u003eImage.merge()\u003c/code\u003e, \u003ccode\u003eImage.putalpha()\u003c/code\u003e and `Image...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/53e02c43c919d149b2a154a5180079f9df18fbbb\"\u003e\u003ccode\u003e53e02c4\u003c/code\u003e\u003c/a\u003e Speed up \u003ccode\u003eImage.fill()\u003c/code\u003e, \u003ccode\u003eImage.linear_gradient()\u003c/code\u003e and `Image.radial_gradient...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/af037475be8634ba739744243164ba9e2c8346a6\"\u003e\u003ccode\u003eaf03747\u003c/code\u003e\u003c/a\u003e Speed up \u003ccode\u003eImage.resample()\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9739\"\u003e#9739\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/5c9ca56c3e5fba52b647809fbb0986c87e73a571\"\u003e\u003ccode\u003e5c9ca56\u003c/code\u003e\u003c/a\u003e Speed up \u003ccode\u003ealpha_composite\u003c/code\u003e, \u003ccode\u003ematrix\u003c/code\u003e, \u003ccode\u003enegative\u003c/code\u003e, \u003ccode\u003equantize\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9740\"\u003e#9740\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/python-pillow/Pillow/compare/12.2.0...12.3.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `aiohttp` from 3.14.1 to 3.14.3\nUpdates `anyio` from 4.13.0 to 4.14.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/agronholm/anyio/releases\"\u003eanyio's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e4.14.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eChanged \u003ccode\u003eByteReceiveStream.receive()\u003c/code\u003e implementations to raise a \u003ccode\u003eValueError\u003c/code\u003e when \u003ccode\u003emax_bytes\u003c/code\u003e is not a positive integer (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1191\"\u003e#1191\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eCapacityLimiter.total_tokens\u003c/code\u003e rejecting \u003ccode\u003efloat(\u0026quot;inf\u0026quot;)\u003c/code\u003e when the limiter was instantiated outside of an event loop. The adapter setter checked for infinity by identity (\u003ccode\u003evalue is math.inf\u003c/code\u003e), so only the exact \u003ccode\u003emath.inf\u003c/code\u003e singleton was accepted, while every backend setter (using \u003ccode\u003emath.isinf()\u003c/code\u003e) accepts any positive infinity (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1189\"\u003e#1189\u003c/a\u003e; PR by \u003ca href=\"https://github.com/greymoth-jp\"\u003e\u003ccode\u003e@​greymoth-jp\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eto_process.run_sync()\u003c/code\u003e deadlocking when the worker function writes enough data to \u003ccode\u003esys.stderr\u003c/code\u003e to fill the (undrained) pipe buffer. The worker process now redirects \u003ccode\u003esys.stderr\u003c/code\u003e to \u003ccode\u003eos.devnull\u003c/code\u003e as well, matching the documented behavior\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eTLSStream.wrap()\u003c/code\u003e matching an internationalized (unicode) host name against the peer certificate using IDNA 2003 (via the standard library) instead of IDNA 2008, which could cause the host name to be matched against the wrong certificate (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1208\"\u003e#1208\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eanyio.open_process()\u003c/code\u003e (and \u003ccode\u003erun_process()\u003c/code\u003e) ignoring the \u003ccode\u003eextra_groups\u003c/code\u003e argument, as it mistakenly passed the value of the \u003ccode\u003egroup\u003c/code\u003e argument instead (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1209\"\u003e#1209\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eCapacityLimiter.acquire_nowait()\u003c/code\u003e and \u003ccode\u003eCapacityLimiter.acquire_nowait_on_behalf_of()\u003c/code\u003e raising \u003ccode\u003etrio.WouldBlock\u003c/code\u003e instead of \u003ccode\u003eanyio.WouldBlock\u003c/code\u003e on the \u003ccode\u003etrio\u003c/code\u003e backend when there are no tokens available (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1218\"\u003e#1218\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eCapacityLimiter\u003c/code\u003e on the asyncio backend over-granting tokens (\u003ccode\u003eborrowed_tokens\u003c/code\u003e exceeding \u003ccode\u003etotal_tokens\u003c/code\u003e and \u003ccode\u003eavailable_tokens\u003c/code\u003e going negative) when a non-blocking acquire was made in the window between a token being released and the notified waiter resuming. The freed token is now reserved for the woken waiter right away, so the non-blocking acquire correctly raises \u003ccode\u003eWouldBlock\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1170\"\u003e#1170\u003c/a\u003e; PR by \u003ca href=\"https://github.com/gaoflow\"\u003e\u003ccode\u003e@​gaoflow\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed unnecessary CPU spin when delivering cancellation from \u003ccode\u003eCancelScope\u003c/code\u003e on asyncio under certain conditions, including improper cancel scope nesting (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1111\"\u003e#1111\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.14.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed teardown of higher-scoped async fixtures failing on asyncio with \u003ccode\u003eRuntimeError: Attempted to exit cancel scope in a different task than it was entered in\u003c/code\u003e when an async test raise an outcome exception (e.g., \u003ccode\u003epytest.skip()\u003c/code\u003e, \u003ccode\u003epytest.xfail()\u003c/code\u003e, or \u003ccode\u003epytest.fail()\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1179\"\u003e#1179\u003c/a\u003e; PR by \u003ca href=\"https://github.com/EmmanuelNiyonshuti\"\u003e\u003ccode\u003e@​EmmanuelNiyonshuti\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eCapacityLimiter.total_tokens\u003c/code\u003e rejecting a value of \u003ccode\u003e0\u003c/code\u003e when the limiter was instantiated outside of an event loop, contradicting the documented behavior of allowing 0 total tokens (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1183\"\u003e#1183\u003c/a\u003e; PR by \u003ca href=\"https://github.com/nyxst4ck\"\u003e\u003ccode\u003e@​nyxst4ck\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.14.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eAdded support for Python 3.15\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAdded an asynchronous implementation of the \u003ccode\u003eitertools\u003c/code\u003e module (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/998\"\u003e#998\u003c/a\u003e; PR by \u003ca href=\"https://github.com/11kkw\"\u003e\u003ccode\u003e@​11kkw\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAdded the \u003ccode\u003elocal_port\u003c/code\u003e parameter to \u003ccode\u003econnect_tcp()\u003c/code\u003e to allow binding to a specific local port before connecting (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1067\"\u003e#1067\u003c/a\u003e; PR by \u003ca href=\"https://github.com/nullwiz\"\u003e\u003ccode\u003e@​nullwiz\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAdded support for custom capacity limiters in async path and file I/O functions and classes\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAdded the \u003ccode\u003ecreate_task()\u003c/code\u003e task group method for easier asyncio migration (returns a \u003ccode\u003eTaskHandle\u003c/code\u003e) (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1098\"\u003e#1098\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eChanged \u003ccode\u003eTaskGroup.start_soon()\u003c/code\u003e to return a \u003ccode\u003eTaskHandle\u003c/code\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAdded an option for \u003ccode\u003eTaskGroup.start()\u003c/code\u003e to return a \u003ccode\u003eTaskHandle\u003c/code\u003e (which then contains the start value in the \u003ccode\u003estart_value\u003c/code\u003e property)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eAdded the \u003ccode\u003ecancel()\u003c/code\u003e convenience method to \u003ccode\u003eTaskGroup\u003c/code\u003e as a shortcut for cancelling the task group's cancel scope\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eImproved the error message when a known backend is not installed to suggest the install command (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1115\"\u003e#1115\u003c/a\u003e; PR by \u003ca href=\"https://github.com/EmmanuelNiyonshuti\"\u003e\u003ccode\u003e@​EmmanuelNiyonshuti\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eImproved \u003ccode\u003eanyio.Path\u003c/code\u003e to preserve subclass types by returning \u003ccode\u003eSelf\u003c/code\u003e in methods that return path objects (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1130\"\u003e#1130\u003c/a\u003e; PR by \u003ca href=\"https://github.com/EmmanuelNiyonshuti\"\u003e\u003ccode\u003e@​EmmanuelNiyonshuti\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eChanged the parameter type annotation in \u003ccode\u003eanyio.Path.write_bytes()\u003c/code\u003e to accept any \u003ccode\u003eReadableBuffer\u003c/code\u003e, thus allowing it to accept \u003ccode\u003ebytearray\u003c/code\u003e and \u003ccode\u003ememoryview\u003c/code\u003e to match \u003ccode\u003epathlib.Path.write_bytes()\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1135\"\u003e#1135\u003c/a\u003e; PR by \u003ca href=\"https://github.com/SAY-5\"\u003e\u003ccode\u003e@​SAY-5\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eChanged several type annotations to only accept callables returning coroutine-like objects instead of arbitrary awaitables:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eTaskGroup.start_soon()\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eTaskGroup.start()\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eanyio.from_thread.run()\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThis reverts an earlier change from v3.7.0 which was made in error. (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1153\"\u003e#1153\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eChanged \u003ccode\u003eanyio.run\u003c/code\u003e to support callables returning arbitrary awaitables at runtime on all backends. Previously, this only worked on asyncio (\u003ca href=\"https://redirect.github.com/agronholm/anyio/pull/1171\"\u003e#1171\u003c/a\u003e; PR by \u003ca href=\"https://github.com/gschaffner\"\u003e\u003ccode\u003e@​gschaffner\u003c/code\u003e\u003c/a\u003e)\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eChanged several classes (and their subclasses) to have \u003ccode\u003e__slots__\u003c/code\u003e (with \u003ccode\u003e__weakref__\u003c/code\u003e):\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eanyio.CancelScope\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/c384f99687c64c59ed8a11c3a0f11a2d57daff71\"\u003e\u003ccode\u003ec384f99\u003c/code\u003e\u003c/a\u003e Bumped up the version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/dbba29d1ade7936f18fb71ba24aa92978673482a\"\u003e\u003ccode\u003edbba29d\u003c/code\u003e\u003c/a\u003e Fixed 100% CPU spin on cancel scope misuse (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1217\"\u003e#1217\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/6bbc6c33caabc13af5bc4256f745027cf8d5d7b8\"\u003e\u003ccode\u003e6bbc6c3\u003c/code\u003e\u003c/a\u003e Fix CapacityLimiter over-granting tokens on asyncio (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1172\"\u003e#1172\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/6f82b2537cbbe98f3df3f295499056ab7de0b15b\"\u003e\u003ccode\u003e6f82b25\u003c/code\u003e\u003c/a\u003e Refactored TestTLSStream.test_receive_invalid_max_bytes() to be less flaky\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/be24b0414f67f604bcbdd5ea3bcc56ab920d872e\"\u003e\u003ccode\u003ebe24b04\u003c/code\u003e\u003c/a\u003e Relaxed timeouts to fix test flakiness\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/81135065749b4f60c06619b9caaf0a11871c1ddf\"\u003e\u003ccode\u003e8113506\u003c/code\u003e\u003c/a\u003e Fix test flakiness caused by slow callback duration logging\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/1e988b617b69588e33fecb75e36a9837245f562f\"\u003e\u003ccode\u003e1e988b6\u003c/code\u003e\u003c/a\u003e Fixed CapacityLimiter raising trio.WouldBlock instead of anyio.WouldBlock (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1\"\u003e#1\u003c/a\u003e...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/44713f345cd29dd4e7d76553c134543a1296cc62\"\u003e\u003ccode\u003e44713f3\u003c/code\u003e\u003c/a\u003e Pin setup-uv to a commit sha across downstream jobs (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1213\"\u003e#1213\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/f1b7301c8264b0d2e8d24a5788fd29e93dea4040\"\u003e\u003ccode\u003ef1b7301\u003c/code\u003e\u003c/a\u003e Fixed stderr writes in a worker subprocess causing a deadlock (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1207\"\u003e#1207\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/agronholm/anyio/commit/212be93c2cf2c841e753e95e5e2c543ee7feca90\"\u003e\u003ccode\u003e212be93\u003c/code\u003e\u003c/a\u003e Fix flaky test_tcp_listener_same_port using a hardcoded port (\u003ca href=\"https://redirect.github.com/agronholm/anyio/issues/1206\"\u003e#1206\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/agronholm/anyio/compare/4.13.0...4.14.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/dabelstech-creator/sie/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/dabelstech-creator/sie/pull/2","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/dabelstech-creator%2Fsie/issues/2","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/2/packages"}},{"old_version":"3.14.1","new_version":"3.14.3","update_type":"patch","path":"the pip group across 1 directory","pr_created_at":"2026-09-18T08:47:08.000Z","version_change":"3.14.1 → 3.14.3","issue":{"uuid":"5497591666","node_id":"PR_kwDONPLcn88AAAABEDfUKA","number":57,"state":"closed","title":"build(deps): bump aiohttp from 3.14.1 to 3.14.3 in the pip group across 1 directory","user":"dependabot[bot]","labels":["invalid","dependencies","python"],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":"2026-09-18T08:47:20.000Z","author_association":null,"state_reason":null,"created_at":"2026-09-18T08:47:08.000Z","updated_at":"2026-09-18T08:47:29.000Z","time_to_close":12,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"build(deps)","packages":[{"name":"aiohttp","old_version":"3.14.1","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"}],"path":"the pip group across 1 directory","ecosystem":"pip"},"body":"Bumps the pip group with 1 update in the / directory: [aiohttp](https://github.com/aio-libs/aiohttp).\n\nUpdates `aiohttp` from 3.14.1 to 3.14.3\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=aiohttp\u0026package-manager=pip\u0026previous-version=3.14.1\u0026new-version=3.14.3)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/Jackie264/iptv-api/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/Jackie264/iptv-api/pull/57","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/Jackie264%2Fiptv-api/issues/57","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/57/packages"}},{"old_version":"3.14.1","new_version":"3.14.3","update_type":"patch","path":null,"pr_created_at":"2026-09-18T03:02:53.000Z","version_change":"3.14.1 → 3.14.3","issue":{"uuid":"5495148202","node_id":"PR_kwDOT1KaUM8AAAABEBip8g","number":16,"state":"closed","title":"build(deps): bump the pip group across 33 directories with 3 updates","user":"dependabot[bot]","labels":["dependencies","python"],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":"2026-09-18T03:04:26.000Z","author_association":null,"state_reason":null,"created_at":"2026-09-18T03:02:53.000Z","updated_at":"2026-09-18T03:04:28.000Z","time_to_close":93,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"build(deps): bump","group_name":"pip","update_count":3,"packages":[{"name":"aiohttp","old_version":"3.14.1","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"soupsieve","old_version":"2.8.4","new_version":"2.9","repository_url":"https://github.com/facelessuser/soupsieve"},{"name":"aiohttp","old_version":"3.14.1","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"soupsieve","old_version":"2.8.4","new_version":"2.9","repository_url":"https://github.com/facelessuser/soupsieve"},{"name":"tornado","old_version":"6.5.7","new_version":"6.5.8","repository_url":"https://github.com/tornadoweb/tornado"},{"name":"aiohttp","old_version":"3.14.1","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"aiohttp","old_version":"3.14.1","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"aiohttp","old_version":"3.14.1","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"aiohttp","old_version":"3.14.1","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"aiohttp","old_version":"3.14.1","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"aiohttp","old_version":"3.14.1","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"aiohttp","old_version":"3.14.1","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"aiohttp","old_version":"3.14.1","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"aiohttp","old_version":"3.14.1","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"aiohttp","old_version":"3.14.1","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"aiohttp","old_version":"3.14.1","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"soupsieve","old_version":"2.8.4","new_version":"2.9","repository_url":"https://github.com/facelessuser/soupsieve"},{"name":"aiohttp","old_version":"3.14.1","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"aiohttp","old_version":"3.14.1","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"soupsieve","old_version":"2.8.4","new_version":"2.9","repository_url":"https://github.com/facelessuser/soupsieve"},{"name":"aiohttp","old_version":"3.14.1","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"aiohttp","old_version":"3.14.1","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"aiohttp","old_version":"3.14.1","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"aiohttp","old_version":"3.14.1","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"aiohttp","old_version":"3.14.1","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"aiohttp","old_version":"3.14.1","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"aiohttp","old_version":"3.14.1","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"aiohttp","old_version":"3.14.1","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"aiohttp","old_version":"3.14.1","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"soupsieve","old_version":"2.8.4","new_version":"2.9","repository_url":"https://github.com/facelessuser/soupsieve"},{"name":"aiohttp","old_version":"3.14.1","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"aiohttp","old_version":"3.14.1","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"aiohttp","old_version":"3.14.1","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"aiohttp","old_version":"3.14.1","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"aiohttp","old_version":"3.14.1","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"aiohttp","old_version":"3.14.1","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"aiohttp","old_version":"3.14.1","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"aiohttp","old_version":"3.14.1","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"soupsieve","old_version":"2.8.4","new_version":"2.9","repository_url":"https://github.com/facelessuser/soupsieve"}],"path":null,"ecosystem":"pip"},"body":"Bumps the pip group with 2 updates in the /cli directory: [aiohttp](https://github.com/aio-libs/aiohttp) and [soupsieve](https://github.com/facelessuser/soupsieve).\nBumps the pip group with 2 updates in the /openbb_platform directory: [aiohttp](https://github.com/aio-libs/aiohttp) and [soupsieve](https://github.com/facelessuser/soupsieve).\nBumps the pip group with 1 update in the /openbb_platform/extensions/devtools directory: [tornado](https://github.com/tornadoweb/tornado).\nBumps the pip group with 1 update in the /openbb_platform/providers/biztoc directory: [aiohttp](https://github.com/aio-libs/aiohttp).\nBumps the pip group with 1 update in the /openbb_platform/providers/bls directory: [aiohttp](https://github.com/aio-libs/aiohttp).\nBumps the pip group with 1 update in the /openbb_platform/providers/cboe directory: [aiohttp](https://github.com/aio-libs/aiohttp).\nBumps the pip group with 1 update in the /openbb_platform/providers/cftc directory: [aiohttp](https://github.com/aio-libs/aiohttp).\nBumps the pip group with 1 update in the /openbb_platform/providers/congress_gov directory: [aiohttp](https://github.com/aio-libs/aiohttp).\nBumps the pip group with 1 update in the /openbb_platform/providers/deribit directory: [aiohttp](https://github.com/aio-libs/aiohttp).\nBumps the pip group with 1 update in the /openbb_platform/providers/ecb directory: [aiohttp](https://github.com/aio-libs/aiohttp).\nBumps the pip group with 1 update in the /openbb_platform/providers/econdb directory: [aiohttp](https://github.com/aio-libs/aiohttp).\nBumps the pip group with 1 update in the /openbb_platform/providers/eia directory: [aiohttp](https://github.com/aio-libs/aiohttp).\nBumps the pip group with 1 update in the /openbb_platform/providers/famafrench directory: [aiohttp](https://github.com/aio-libs/aiohttp).\nBumps the pip group with 2 updates in the /openbb_platform/providers/federal_reserve directory: [aiohttp](https://github.com/aio-libs/aiohttp) and [soupsieve](https://github.com/facelessuser/soupsieve).\nBumps the pip group with 1 update in the /openbb_platform/providers/finra directory: [aiohttp](https://github.com/aio-libs/aiohttp).\nBumps the pip group with 2 updates in the /openbb_platform/providers/finviz directory: [aiohttp](https://github.com/aio-libs/aiohttp) and [soupsieve](https://github.com/facelessuser/soupsieve).\nBumps the pip group with 1 update in the /openbb_platform/providers/fmp directory: [aiohttp](https://github.com/aio-libs/aiohttp).\nBumps the pip group with 1 update in the /openbb_platform/providers/fred directory: [aiohttp](https://github.com/aio-libs/aiohttp).\nBumps the pip group with 1 update in the /openbb_platform/providers/government_us directory: [aiohttp](https://github.com/aio-libs/aiohttp).\nBumps the pip group with 1 update in the /openbb_platform/providers/imf directory: [aiohttp](https://github.com/aio-libs/aiohttp).\nBumps the pip group with 1 update in the /openbb_platform/providers/intrinio directory: [aiohttp](https://github.com/aio-libs/aiohttp).\nBumps the pip group with 1 update in the /openbb_platform/providers/multpl directory: [aiohttp](https://github.com/aio-libs/aiohttp).\nBumps the pip group with 1 update in the /openbb_platform/providers/nasdaq directory: [aiohttp](https://github.com/aio-libs/aiohttp).\nBumps the pip group with 1 update in the /openbb_platform/providers/oecd directory: [aiohttp](https://github.com/aio-libs/aiohttp).\nBumps the pip group with 2 updates in the /openbb_platform/providers/sec directory: [aiohttp](https://github.com/aio-libs/aiohttp) and [soupsieve](https://github.com/facelessuser/soupsieve).\nBumps the pip group with 1 update in the /openbb_platform/providers/seeking_alpha directory: [aiohttp](https://github.com/aio-libs/aiohttp).\nBumps the pip group with 1 update in the /openbb_platform/providers/stockgrid directory: [aiohttp](https://github.com/aio-libs/aiohttp).\nBumps the pip group with 1 update in the /openbb_platform/providers/tiingo directory: [aiohttp](https://github.com/aio-libs/aiohttp).\nBumps the pip group with 1 update in the /openbb_platform/providers/tmx directory: [aiohttp](https://github.com/aio-libs/aiohttp).\nBumps the pip group with 1 update in the /openbb_platform/providers/tradier directory: [aiohttp](https://github.com/aio-libs/aiohttp).\nBumps the pip group with 1 update in the /openbb_platform/providers/tradingeconomics directory: [aiohttp](https://github.com/aio-libs/aiohttp).\nBumps the pip group with 1 update in the /openbb_platform/providers/wsj directory: [aiohttp](https://github.com/aio-libs/aiohttp).\nBumps the pip group with 2 updates in the /openbb_platform/providers/yfinance directory: [aiohttp](https://github.com/aio-libs/aiohttp) and [soupsieve](https://github.com/facelessuser/soupsieve).\n\nUpdates `aiohttp` from 3.14.1 to 3.14.3\nUpdates `soupsieve` from 2.8.4 to 2.9\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/facelessuser/soupsieve/releases\"\u003esoupsieve's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e2.9\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eNEW\u003c/strong\u003e: Drop Python 3.9 support.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eNEW\u003c/strong\u003e: Lazy compile selector patterns to improve initial import speed.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eFIX\u003c/strong\u003e: Correct \u003ccode\u003e:nth-child\u003c/code\u003e/\u003ccode\u003e:nth-of-type\u003c/code\u003e (and \u003ccode\u003e-last-\u003c/code\u003e variants) for \u003ccode\u003eAn+B\u003c/code\u003e values whose sequence steps onto\nindex 0 or onto the last child (e.g. \u003ccode\u003e:nth-child(2n-2)\u003c/code\u003e, \u003ccode\u003e:nth-child(n-1)\u003c/code\u003e, \u003ccode\u003e:nth-child(n+5)\u003c/code\u003e), which previously\nmatched the wrong elements or nothing at all (\u003ca href=\"https://github.com/gaoflow\"\u003e\u003ccode\u003e@​gaoflow\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eFIX\u003c/strong\u003e: More efficient CSS ID matching (\u003ca href=\"https://github.com/kaimandalic\"\u003e\u003ccode\u003e@​kaimandalic\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eFIX\u003c/strong\u003e: Fix inefficient trimming of comments and white space (\u003ca href=\"https://github.com/kaimandalic\"\u003e\u003ccode\u003e@​kaimandalic\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/8763f914472fc83652babda708bed5c8ef287004\"\u003e\u003ccode\u003e8763f91\u003c/code\u003e\u003c/a\u003e Format changelog message\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/cf198fcddc9230f06ed39f974eba0ce076b85cda\"\u003e\u003ccode\u003ecf198fc\u003c/code\u003e\u003c/a\u003e Fix inefficient trimming of comments and white space\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/ce44e4996e6632871c18cdd7a7fb641be8ef34ef\"\u003e\u003ccode\u003ece44e49\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/751c57b2c7e978e206b94b7dba17f8e2af392e19\"\u003e\u003ccode\u003e751c57b\u003c/code\u003e\u003c/a\u003e Fix :nth-child/:nth-of-type matching for An+B index boundaries (\u003ca href=\"https://redirect.github.com/facelessuser/soupsieve/issues/297\"\u003e#297\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/08e9ede4dcfafef860155319ef5eb9708e75d10b\"\u003e\u003ccode\u003e08e9ede\u003c/code\u003e\u003c/a\u003e Drop Python 3.9\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/d6e68303a6c3e0e410530939b92955ba24a07a81\"\u003e\u003ccode\u003ed6e6830\u003c/code\u003e\u003c/a\u003e Rework selector mapping\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/d2d1581fe275f89cb2e792589fed770aeb9e99b3\"\u003e\u003ccode\u003ed2d1581\u003c/code\u003e\u003c/a\u003e Utilize property for accessing lazy regular expression pattern\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/b8701dec25c84a3910fd9a03222a3804fa119a1d\"\u003e\u003ccode\u003eb8701de\u003c/code\u003e\u003c/a\u003e Build patterns and regexes lazily in css_parser (\u003ca href=\"https://redirect.github.com/facelessuser/soupsieve/issues/296\"\u003e#296\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/facelessuser/soupsieve/compare/2.8.4...2.9\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `aiohttp` from 3.14.1 to 3.14.3\nUpdates `soupsieve` from 2.8.4 to 2.9\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/facelessuser/soupsieve/releases\"\u003esoupsieve's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e2.9\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eNEW\u003c/strong\u003e: Drop Python 3.9 support.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eNEW\u003c/strong\u003e: Lazy compile selector patterns to improve initial import speed.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eFIX\u003c/strong\u003e: Correct \u003ccode\u003e:nth-child\u003c/code\u003e/\u003ccode\u003e:nth-of-type\u003c/code\u003e (and \u003ccode\u003e-last-\u003c/code\u003e variants) for \u003ccode\u003eAn+B\u003c/code\u003e values whose sequence steps onto\nindex 0 or onto the last child (e.g. \u003ccode\u003e:nth-child(2n-2)\u003c/code\u003e, \u003ccode\u003e:nth-child(n-1)\u003c/code\u003e, \u003ccode\u003e:nth-child(n+5)\u003c/code\u003e), which previously\nmatched the wrong elements or nothing at all (\u003ca href=\"https://github.com/gaoflow\"\u003e\u003ccode\u003e@​gaoflow\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eFIX\u003c/strong\u003e: More efficient CSS ID matching (\u003ca href=\"https://github.com/kaimandalic\"\u003e\u003ccode\u003e@​kaimandalic\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eFIX\u003c/strong\u003e: Fix inefficient trimming of comments and white space (\u003ca href=\"https://github.com/kaimandalic\"\u003e\u003ccode\u003e@​kaimandalic\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/8763f914472fc83652babda708bed5c8ef287004\"\u003e\u003ccode\u003e8763f91\u003c/code\u003e\u003c/a\u003e Format changelog message\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/cf198fcddc9230f06ed39f974eba0ce076b85cda\"\u003e\u003ccode\u003ecf198fc\u003c/code\u003e\u003c/a\u003e Fix inefficient trimming of comments and white space\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/ce44e4996e6632871c18cdd7a7fb641be8ef34ef\"\u003e\u003ccode\u003ece44e49\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/751c57b2c7e978e206b94b7dba17f8e2af392e19\"\u003e\u003ccode\u003e751c57b\u003c/code\u003e\u003c/a\u003e Fix :nth-child/:nth-of-type matching for An+B index boundaries (\u003ca href=\"https://redirect.github.com/facelessuser/soupsieve/issues/297\"\u003e#297\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/08e9ede4dcfafef860155319ef5eb9708e75d10b\"\u003e\u003ccode\u003e08e9ede\u003c/code\u003e\u003c/a\u003e Drop Python 3.9\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/d6e68303a6c3e0e410530939b92955ba24a07a81\"\u003e\u003ccode\u003ed6e6830\u003c/code\u003e\u003c/a\u003e Rework selector mapping\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/d2d1581fe275f89cb2e792589fed770aeb9e99b3\"\u003e\u003ccode\u003ed2d1581\u003c/code\u003e\u003c/a\u003e Utilize property for accessing lazy regular expression pattern\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/b8701dec25c84a3910fd9a03222a3804fa119a1d\"\u003e\u003ccode\u003eb8701de\u003c/code\u003e\u003c/a\u003e Build patterns and regexes lazily in css_parser (\u003ca href=\"https://redirect.github.com/facelessuser/soupsieve/issues/296\"\u003e#296\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/facelessuser/soupsieve/compare/2.8.4...2.9\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `tornado` from 6.5.7 to 6.5.8\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/tornadoweb/tornado/blob/master/docs/releases.rst\"\u003etornado's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003eRelease notes\u003c/h1\u003e\n\u003cp\u003e.. toctree::\n:maxdepth: 2\u003c/p\u003e\n\u003cp\u003ereleases/v6.5.10\nreleases/v6.5.9\nreleases/v6.5.8\nreleases/v6.5.7\nreleases/v6.5.6\nreleases/v6.5.5\nreleases/v6.5.4\nreleases/v6.5.3\nreleases/v6.5.2\nreleases/v6.5.1\nreleases/v6.5.0\nreleases/v6.4.2\nreleases/v6.4.1\nreleases/v6.4.0\nreleases/v6.3.3\nreleases/v6.3.2\nreleases/v6.3.1\nreleases/v6.3.0\nreleases/v6.2.0\nreleases/v6.1.0\nreleases/v6.0.4\nreleases/v6.0.3\nreleases/v6.0.2\nreleases/v6.0.1\nreleases/v6.0.0\nreleases/v5.1.1\nreleases/v5.1.0\nreleases/v5.0.2\nreleases/v5.0.1\nreleases/v5.0.0\nreleases/v4.5.3\nreleases/v4.5.2\nreleases/v4.5.1\nreleases/v4.5.0\nreleases/v4.4.3\nreleases/v4.4.2\nreleases/v4.4.1\nreleases/v4.4.0\nreleases/v4.3.0\nreleases/v4.2.1\nreleases/v4.2.0\nreleases/v4.1.0\nreleases/v4.0.2\nreleases/v4.0.1\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tornadoweb/tornado/commit/a55abe3e3bf59994f29b2f7084c46341f0d4f6a7\"\u003e\u003ccode\u003ea55abe3\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/tornadoweb/tornado/issues/3704\"\u003e#3704\u003c/a\u003e from bdarnell/security-6.5.8\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tornadoweb/tornado/commit/fc794885f0ccf9c33f3a66d890abcc237dd50b3c\"\u003e\u003ccode\u003efc79488\u003c/code\u003e\u003c/a\u003e docs: add additional credit to release notes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tornadoweb/tornado/commit/7b017630d3139ca0d1ebdf6ac3b3ffe7725a7129\"\u003e\u003ccode\u003e7b01763\u003c/code\u003e\u003c/a\u003e Fix test_strip_headers_on_redirect's URL-embedded-credentials cases\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tornadoweb/tornado/commit/d72fff8d7b9b8f6aa68505847e5483d600e3184c\"\u003e\u003ccode\u003ed72fff8\u003c/code\u003e\u003c/a\u003e release notes and version bump for 6.5.8\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tornadoweb/tornado/commit/b168818f8aae39808b981878fb358cbe02a6238e\"\u003e\u003ccode\u003eb168818\u003c/code\u003e\u003c/a\u003e auth: Formally deprecated OpenIDMixin\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tornadoweb/tornado/commit/da284767eae8e1f0484f123b8c3225f6465b09c7\"\u003e\u003ccode\u003eda28476\u003c/code\u003e\u003c/a\u003e web: Also check for semicolons in deprecated mixed-case cookie args\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tornadoweb/tornado/commit/8d6363ed7b69d5f0da806efe34d256627a2191de\"\u003e\u003ccode\u003e8d6363e\u003c/code\u003e\u003c/a\u003e httputil: Enforce a new limit on the number of arguments in a request\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tornadoweb/tornado/commit/de85b3f87446e323e881bbaa3d5a74f4b76e5f05\"\u003e\u003ccode\u003ede85b3f\u003c/code\u003e\u003c/a\u003e httputil: Apply multipart max_parts limit earlier\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/tornadoweb/tornado/compare/v6.5.7...v6.5.8\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `aiohttp` from 3.14.1 to 3.14.3\nUpdates `aiohttp` from 3.14.1 to 3.14.3\nUpdates `aiohttp` from 3.14.1 to 3.14.3\nUpdates `aiohttp` from 3.14.1 to 3.14.3\nUpdates `aiohttp` from 3.14.1 to 3.14.3\nUpdates `aiohttp` from 3.14.1 to 3.14.3\nUpdates `aiohttp` from 3.14.1 to 3.14.3\nUpdates `aiohttp` from 3.14.1 to 3.14.3\nUpdates `aiohttp` from 3.14.1 to 3.14.3\nUpdates `aiohttp` from 3.14.1 to 3.14.3\nUpdates `aiohttp` from 3.14.1 to 3.14.3\nUpdates `soupsieve` from 2.8.4 to 2.9\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/facelessuser/soupsieve/releases\"\u003esoupsieve's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e2.9\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eNEW\u003c/strong\u003e: Drop Python 3.9 support.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eNEW\u003c/strong\u003e: Lazy compile selector patterns to improve initial import speed.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eFIX\u003c/strong\u003e: Correct \u003ccode\u003e:nth-child\u003c/code\u003e/\u003ccode\u003e:nth-of-type\u003c/code\u003e (and \u003ccode\u003e-last-\u003c/code\u003e variants) for \u003ccode\u003eAn+B\u003c/code\u003e values whose sequence steps onto\nindex 0 or onto the last child (e.g. \u003ccode\u003e:nth-child(2n-2)\u003c/code\u003e, \u003ccode\u003e:nth-child(n-1)\u003c/code\u003e, \u003ccode\u003e:nth-child(n+5)\u003c/code\u003e), which previously\nmatched the wrong elements or nothing at all (\u003ca href=\"https://github.com/gaoflow\"\u003e\u003ccode\u003e@​gaoflow\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eFIX\u003c/strong\u003e: More efficient CSS ID matching (\u003ca href=\"https://github.com/kaimandalic\"\u003e\u003ccode\u003e@​kaimandalic\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eFIX\u003c/strong\u003e: Fix inefficient trimming of comments and white space (\u003ca href=\"https://github.com/kaimandalic\"\u003e\u003ccode\u003e@​kaimandalic\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/8763f914472fc83652babda708bed5c8ef287004\"\u003e\u003ccode\u003e8763f91\u003c/code\u003e\u003c/a\u003e Format changelog message\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/cf198fcddc9230f06ed39f974eba0ce076b85cda\"\u003e\u003ccode\u003ecf198fc\u003c/code\u003e\u003c/a\u003e Fix inefficient trimming of comments and white space\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/ce44e4996e6632871c18cdd7a7fb641be8ef34ef\"\u003e\u003ccode\u003ece44e49\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/751c57b2c7e978e206b94b7dba17f8e2af392e19\"\u003e\u003ccode\u003e751c57b\u003c/code\u003e\u003c/a\u003e Fix :nth-child/:nth-of-type matching for An+B index boundaries (\u003ca href=\"https://redirect.github.com/facelessuser/soupsieve/issues/297\"\u003e#297\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/08e9ede4dcfafef860155319ef5eb9708e75d10b\"\u003e\u003ccode\u003e08e9ede\u003c/code\u003e\u003c/a\u003e Drop Python 3.9\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/d6e68303a6c3e0e410530939b92955ba24a07a81\"\u003e\u003ccode\u003ed6e6830\u003c/code\u003e\u003c/a\u003e Rework selector mapping\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/d2d1581fe275f89cb2e792589fed770aeb9e99b3\"\u003e\u003ccode\u003ed2d1581\u003c/code\u003e\u003c/a\u003e Utilize property for accessing lazy regular expression pattern\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/b8701dec25c84a3910fd9a03222a3804fa119a1d\"\u003e\u003ccode\u003eb8701de\u003c/code\u003e\u003c/a\u003e Build patterns and regexes lazily in css_parser (\u003ca href=\"https://redirect.github.com/facelessuser/soupsieve/issues/296\"\u003e#296\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/facelessuser/soupsieve/compare/2.8.4...2.9\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `aiohttp` from 3.14.1 to 3.14.3\nUpdates `aiohttp` from 3.14.1 to 3.14.3\nUpdates `soupsieve` from 2.8.4 to 2.9\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/facelessuser/soupsieve/releases\"\u003esoupsieve's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e2.9\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eNEW\u003c/strong\u003e: Drop Python 3.9 support.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eNEW\u003c/strong\u003e: Lazy compile selector patterns to improve initial import speed.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eFIX\u003c/strong\u003e: Correct \u003ccode\u003e:nth-child\u003c/code\u003e/\u003ccode\u003e:nth-of-type\u003c/code\u003e (and \u003ccode\u003e-last-\u003c/code\u003e variants) for \u003ccode\u003eAn+B\u003c/code\u003e values whose sequence steps onto\nindex 0 or onto the last child (e.g. \u003ccode\u003e:nth-child(2n-2)\u003c/code\u003e, \u003ccode\u003e:nth-child(n-1)\u003c/code\u003e, \u003ccode\u003e:nth-child(n+5)\u003c/code\u003e), which previously\nmatched the wrong elements or nothing at all (\u003ca href=\"https://github.com/gaoflow\"\u003e\u003ccode\u003e@​gaoflow\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eFIX\u003c/strong\u003e: More efficient CSS ID matching (\u003ca href=\"https://github.com/kaimandalic\"\u003e\u003ccode\u003e@​kaimandalic\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eFIX\u003c/strong\u003e: Fix inefficient trimming of comments and white space (\u003ca href=\"https://github.com/kaimandalic\"\u003e\u003ccode\u003e@​kaimandalic\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/8763f914472fc83652babda708bed5c8ef287004\"\u003e\u003ccode\u003e8763f91\u003c/code\u003e\u003c/a\u003e Format changelog message\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/cf198fcddc9230f06ed39f974eba0ce076b85cda\"\u003e\u003ccode\u003ecf198fc\u003c/code\u003e\u003c/a\u003e Fix inefficient trimming of comments and white space\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/ce44e4996e6632871c18cdd7a7fb641be8ef34ef\"\u003e\u003ccode\u003ece44e49\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/751c57b2c7e978e206b94b7dba17f8e2af392e19\"\u003e\u003ccode\u003e751c57b\u003c/code\u003e\u003c/a\u003e Fix :nth-child/:nth-of-type matching for An+B index boundaries (\u003ca href=\"https://redirect.github.com/facelessuser/soupsieve/issues/297\"\u003e#297\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/08e9ede4dcfafef860155319ef5eb9708e75d10b\"\u003e\u003ccode\u003e08e9ede\u003c/code\u003e\u003c/a\u003e Drop Python 3.9\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/d6e68303a6c3e0e410530939b92955ba24a07a81\"\u003e\u003ccode\u003ed6e6830\u003c/code\u003e\u003c/a\u003e Rework selector mapping\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/d2d1581fe275f89cb2e792589fed770aeb9e99b3\"\u003e\u003ccode\u003ed2d1581\u003c/code\u003e\u003c/a\u003e Utilize property for accessing lazy regular expression pattern\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/b8701dec25c84a3910fd9a03222a3804fa119a1d\"\u003e\u003ccode\u003eb8701de\u003c/code\u003e\u003c/a\u003e Build patterns and regexes lazily in css_parser (\u003ca href=\"https://redirect.github.com/facelessuser/soupsieve/issues/296\"\u003e#296\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/facelessuser/soupsieve/compare/2.8.4...2.9\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `aiohttp` from 3.14.1 to 3.14.3\nUpdates `aiohttp` from 3.14.1 to 3.14.3\nUpdates `aiohttp` from 3.14.1 to 3.14.3\nUpdates `aiohttp` from 3.14.1 to 3.14.3\nUpdates `aiohttp` from 3.14.1 to 3.14.3\nUpdates `aiohttp` from 3.14.1 to 3.14.3\nUpdates `aiohttp` from 3.14.1 to 3.14.3\nUpdates `aiohttp` from 3.14.1 to 3.14.3\nUpdates `aiohttp` from 3.14.1 to 3.14.3\nUpdates `soupsieve` from 2.8.4 to 2.9\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/facelessuser/soupsieve/releases\"\u003esoupsieve's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e2.9\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eNEW\u003c/strong\u003e: Drop Python 3.9 support.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eNEW\u003c/strong\u003e: Lazy compile selector patterns to improve initial import speed.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eFIX\u003c/strong\u003e: Correct \u003ccode\u003e:nth-child\u003c/code\u003e/\u003ccode\u003e:nth-of-type\u003c/code\u003e (and \u003ccode\u003e-last-\u003c/code\u003e variants) for \u003ccode\u003eAn+B\u003c/code\u003e values whose sequence steps onto\nindex 0 or onto the last child (e.g. \u003ccode\u003e:nth-child(2n-2)\u003c/code\u003e, \u003ccode\u003e:nth-child(n-1)\u003c/code\u003e, \u003ccode\u003e:nth-child(n+5)\u003c/code\u003e), which previously\nmatched the wrong elements or nothing at all (\u003ca href=\"https://github.com/gaoflow\"\u003e\u003ccode\u003e@​gaoflow\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eFIX\u003c/strong\u003e: More efficient CSS ID matching (\u003ca href=\"https://github.com/kaimandalic\"\u003e\u003ccode\u003e@​kaimandalic\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eFIX\u003c/strong\u003e: Fix inefficient trimming of comments and white space (\u003ca href=\"https://github.com/kaimandalic\"\u003e\u003ccode\u003e@​kaimandalic\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/8763f914472fc83652babda708bed5c8ef287004\"\u003e\u003ccode\u003e8763f91\u003c/code\u003e\u003c/a\u003e Format changelog message\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/cf198fcddc9230f06ed39f974eba0ce076b85cda\"\u003e\u003ccode\u003ecf198fc\u003c/code\u003e\u003c/a\u003e Fix inefficient trimming of comments and white space\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/ce44e4996e6632871c18cdd7a7fb641be8ef34ef\"\u003e\u003ccode\u003ece44e49\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/751c57b2c7e978e206b94b7dba17f8e2af392e19\"\u003e\u003ccode\u003e751c57b\u003c/code\u003e\u003c/a\u003e Fix :nth-child/:nth-of-type matching for An+B index boundaries (\u003ca href=\"https://redirect.github.com/facelessuser/soupsieve/issues/297\"\u003e#297\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/08e9ede4dcfafef860155319ef5eb9708e75d10b\"\u003e\u003ccode\u003e08e9ede\u003c/code\u003e\u003c/a\u003e Drop Python 3.9\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/d6e68303a6c3e0e410530939b92955ba24a07a81\"\u003e\u003ccode\u003ed6e6830\u003c/code\u003e\u003c/a\u003e Rework selector mapping\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/d2d1581fe275f89cb2e792589fed770aeb9e99b3\"\u003e\u003ccode\u003ed2d1581\u003c/code\u003e\u003c/a\u003e Utilize property for accessing lazy regular expression pattern\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/b8701dec25c84a3910fd9a03222a3804fa119a1d\"\u003e\u003ccode\u003eb8701de\u003c/code\u003e\u003c/a\u003e Build patterns and regexes lazily in css_parser (\u003ca href=\"https://redirect.github.com/facelessuser/soupsieve/issues/296\"\u003e#296\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/facelessuser/soupsieve/compare/2.8.4...2.9\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `aiohttp` from 3.14.1 to 3.14.3\nUpdates `aiohttp` from 3.14.1 to 3.14.3\nUpdates `aiohttp` from 3.14.1 to 3.14.3\nUpdates `aiohttp` from 3.14.1 to 3.14.3\nUpdates `aiohttp` from 3.14.1 to 3.14.3\nUpdates `aiohttp` from 3.14.1 to 3.14.3\nUpdates `aiohttp` from 3.14.1 to 3.14.3\nUpdates `aiohttp` from 3.14.1 to 3.14.3\nUpdates `soupsieve` from 2.8.4 to 2.9\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/facelessuser/soupsieve/releases\"\u003esoupsieve's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e2.9\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eNEW\u003c/strong\u003e: Drop Python 3.9 support.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eNEW\u003c/strong\u003e: Lazy compile selector patterns to improve initial import speed.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eFIX\u003c/strong\u003e: Correct \u003ccode\u003e:nth-child\u003c/code\u003e/\u003ccode\u003e:nth-of-type\u003c/code\u003e (and \u003ccode\u003e-last-\u003c/code\u003e variants) for \u003ccode\u003eAn+B\u003c/code\u003e values whose sequence steps onto\nindex 0 or onto the last child (e.g. \u003ccode\u003e:nth-child(2n-2)\u003c/code\u003e, \u003ccode\u003e:nth-child(n-1)\u003c/code\u003e, \u003ccode\u003e:nth-child(n+5)\u003c/code\u003e), which previously\nmatched the wrong elements or nothing at all (\u003ca href=\"https://github.com/gaoflow\"\u003e\u003ccode\u003e@​gaoflow\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eFIX\u003c/strong\u003e: More efficient CSS ID matching (\u003ca href=\"https://github.com/kaimandalic\"\u003e\u003ccode\u003e@​kaimandalic\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eFIX\u003c/strong\u003e: Fix inefficient trimming of comments and white space (\u003ca href=\"https://github.com/kaimandalic\"\u003e\u003ccode\u003e@​kaimandalic\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/8763f914472fc83652babda708bed5c8ef287004\"\u003e\u003ccode\u003e8763f91\u003c/code\u003e\u003c/a\u003e Format changelog message\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/cf198fcddc9230f06ed39f974eba0ce076b85cda\"\u003e\u003ccode\u003ecf198fc\u003c/code\u003e\u003c/a\u003e Fix inefficient trimming of comments and white space\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/ce44e4996e6632871c18cdd7a7fb641be8ef34ef\"\u003e\u003ccode\u003ece44e49\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/751c57b2c7e978e206b94b7dba17f8e2af392e19\"\u003e\u003ccode\u003e751c57b\u003c/code\u003e\u003c/a\u003e Fix :nth-child/:nth-of-type matching for An+B index boundaries (\u003ca href=\"https://redirect.github.com/facelessuser/soupsieve/issues/297\"\u003e#297\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/08e9ede4dcfafef860155319ef5eb9708e75d10b\"\u003e\u003ccode\u003e08e9ede\u003c/code\u003e\u003c/a\u003e Drop Python 3.9\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/d6e68303a6c3e0e410530939b92955ba24a07a81\"\u003e\u003ccode\u003ed6e6830\u003c/code\u003e\u003c/a\u003e Rework selector mapping\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/d2d1581fe275f89cb2e792589fed770aeb9e99b3\"\u003e\u003ccode\u003ed2d1581\u003c/code\u003e\u003c/a\u003e Utilize property for accessing lazy regular expression pattern\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/b8701dec25c84a3910fd9a03222a3804fa119a1d\"\u003e\u003ccode\u003eb8701de\u003c/code\u003e\u003c/a\u003e Build patterns and regexes lazily in css_parser (\u003ca href=\"https://redirect.github.com/facelessuser/soupsieve/issues/296\"\u003e#296\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/facelessuser/soupsieve/compare/2.8.4...2.9\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/2233admin/openalice-data/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/2233admin/openalice-data/pull/16","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/2233admin%2Fopenalice-data/issues/16","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/16/packages"}},{"old_version":"3.13.3","new_version":"3.14.3","update_type":"minor","path":null,"pr_created_at":"2026-09-18T02:21:41.000Z","version_change":"3.13.3 → 3.14.3","issue":{"uuid":"5494887783","node_id":"PR_kwDOS3o3yM8AAAABEBVZYQ","number":2,"state":"open","title":"Bump the uv group across 1 directory with 15 updates","user":"dependabot[bot]","labels":["dependencies","python:uv"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-18T02:21:41.000Z","updated_at":"2026-09-18T02:22:24.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","group_name":"uv","update_count":15,"packages":[{"name":"gitpython","old_version":"3.1.44","new_version":"3.1.59","repository_url":"https://github.com/gitpython-developers/GitPython"},{"name":"langchain","old_version":"1.2.10","new_version":"1.3.9","repository_url":"https://github.com/langchain-ai/langchain"},{"name":"langsmith","old_version":"0.7.7","new_version":"0.8.18","repository_url":"https://github.com/langchain-ai/langsmith-sdk"},{"name":"pyjwt","old_version":"2.10.1","new_version":"2.13.0","repository_url":"https://github.com/jpadilla/pyjwt"},{"name":"setuptools","old_version":"80.10.2","new_version":"83.0.0","repository_url":"https://github.com/pypa/setuptools"},{"name":"aiohttp","old_version":"3.13.3","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"langgraph-checkpoint","old_version":"4.0.0","new_version":"4.2.0","repository_url":"https://github.com/langchain-ai/langgraph"},{"name":"langgraph-sdk","old_version":"0.3.9","new_version":"0.4.4","repository_url":"https://github.com/langchain-ai/langgraph"},{"name":"msgpack","old_version":"1.1.2","new_version":"1.2.1","repository_url":"https://github.com/msgpack/msgpack-python"},{"name":"pyasn1","old_version":"0.6.2","new_version":"0.6.4","repository_url":"https://github.com/pyasn1/pyasn1"},{"name":"pydantic-settings","old_version":"2.13.1","new_version":"2.14.2","repository_url":"https://github.com/pydantic/pydantic-settings"},{"name":"python-engineio","old_version":"4.13.1","new_version":"4.13.2","repository_url":"https://github.com/miguelgrinberg/python-engineio"},{"name":"python-socketio","old_version":"5.16.1","new_version":"5.16.2","repository_url":"https://github.com/sponsors/miguelgrinberg"},{"name":"soupsieve","old_version":"2.8.3","new_version":"2.9","repository_url":"https://github.com/facelessuser/soupsieve"},{"name":"thrift","old_version":"0.22.0","new_version":"0.24.0","repository_url":"https://github.com/apache/thrift"}],"path":null,"ecosystem":"pip"},"body":"Bumps the uv group with 15 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [gitpython](https://github.com/gitpython-developers/GitPython) | `3.1.44` | `3.1.59` |\n| [langchain](https://github.com/langchain-ai/langchain) | `1.2.10` | `1.3.9` |\n| [langsmith](https://github.com/langchain-ai/langsmith-sdk) | `0.7.7` | `0.8.18` |\n| [pyjwt](https://github.com/jpadilla/pyjwt) | `2.10.1` | `2.13.0` |\n| [setuptools](https://github.com/pypa/setuptools) | `80.10.2` | `83.0.0` |\n| [aiohttp](https://github.com/aio-libs/aiohttp) | `3.13.3` | `3.14.3` |\n| [langgraph-checkpoint](https://github.com/langchain-ai/langgraph) | `4.0.0` | `4.2.0` |\n| [langgraph-sdk](https://github.com/langchain-ai/langgraph) | `0.3.9` | `0.4.4` |\n| [msgpack](https://github.com/msgpack/msgpack-python) | `1.1.2` | `1.2.1` |\n| [pyasn1](https://github.com/pyasn1/pyasn1) | `0.6.2` | `0.6.4` |\n| [pydantic-settings](https://github.com/pydantic/pydantic-settings) | `2.13.1` | `2.14.2` |\n| [python-engineio](https://github.com/miguelgrinberg/python-engineio) | `4.13.1` | `4.13.2` |\n| [python-socketio](https://github.com/sponsors/miguelgrinberg) | `5.16.1` | `5.16.2` |\n| [soupsieve](https://github.com/facelessuser/soupsieve) | `2.8.3` | `2.9` |\n| [thrift](https://github.com/apache/thrift) | `0.22.0` | `0.24.0` |\n\n\nUpdates `gitpython` from 3.1.44 to 3.1.59\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/gitpython-developers/GitPython/releases\"\u003egitpython's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e3.1.59 - Security\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eprepare changelog for upcoming release by \u003ca href=\"https://github.com/Byron\"\u003e\u003ccode\u003e@​Byron\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2207\"\u003egitpython-developers/GitPython#2207\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBlock file-reading Git options by \u003ca href=\"https://github.com/Byron\"\u003e\u003ccode\u003e@​Byron\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2208\"\u003egitpython-developers/GitPython#2208\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eindex: write blobs via git hash-object, not gitdb's odb.store by \u003ca href=\"https://github.com/caroescm\"\u003e\u003ccode\u003e@​caroescm\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2209\"\u003egitpython-developers/GitPython#2209\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBlock separate git directories during clone by \u003ca href=\"https://github.com/Byron\"\u003e\u003ccode\u003e@​Byron\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2210\"\u003egitpython-developers/GitPython#2210\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: harden config parsing boundaries by \u003ca href=\"https://github.com/Byron\"\u003e\u003ccode\u003e@​Byron\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2211\"\u003egitpython-developers/GitPython#2211\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003erepo.index.add()\u003c/code\u003e now respects worktree filters  \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2209\"\u003egitpython-developers/GitPython#2209\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/gitpython-developers/GitPython/compare/3.1.58...3.1.59\"\u003ehttps://github.com/gitpython-developers/GitPython/compare/3.1.58...3.1.59\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003e3.1.58 - Security and Fixes\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003etest: allow Python startup before timeout by \u003ca href=\"https://github.com/Byron\"\u003e\u003ccode\u003e@​Byron\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2195\"\u003egitpython-developers/GitPython#2195\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eResolve Windows hook Bash through PATH by \u003ca href=\"https://github.com/Byron\"\u003e\u003ccode\u003e@​Byron\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2199\"\u003egitpython-developers/GitPython#2199\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRevert \u0026quot;Resolve Windows hook Bash through PATH\u0026quot; by \u003ca href=\"https://github.com/Byron\"\u003e\u003ccode\u003e@​Byron\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2200\"\u003egitpython-developers/GitPython#2200\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etest: focus pytest summary on unexpected failures by \u003ca href=\"https://github.com/raisulchowdhury\"\u003e\u003ccode\u003e@​raisulchowdhury\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2203\"\u003egitpython-developers/GitPython#2203\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eValidate submodule names before filesystem operations by \u003ca href=\"https://github.com/Byron\"\u003e\u003ccode\u003e@​Byron\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2202\"\u003egitpython-developers/GitPython#2202\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eHandle invalid submodule names during recursive updates by \u003ca href=\"https://github.com/Byron\"\u003e\u003ccode\u003e@​Byron\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2205\"\u003egitpython-developers/GitPython#2205\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix Windows path handling on Python 3.13+ by \u003ca href=\"https://github.com/Byron\"\u003e\u003ccode\u003e@​Byron\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2196\"\u003egitpython-developers/GitPython#2196\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efixup 2202 by \u003ca href=\"https://github.com/Byron\"\u003e\u003ccode\u003e@​Byron\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2206\"\u003egitpython-developers/GitPython#2206\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eCorrect Windows hook Bash precedence by \u003ca href=\"https://github.com/Byron\"\u003e\u003ccode\u003e@​Byron\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2201\"\u003egitpython-developers/GitPython#2201\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eHarden config and Git option validation by \u003ca href=\"https://github.com/Byron\"\u003e\u003ccode\u003e@​Byron\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2204\"\u003egitpython-developers/GitPython#2204\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSkip tests that need symlink privileges instead of erroring by \u003ca href=\"https://github.com/Cyrus580529\"\u003e\u003ccode\u003e@​Cyrus580529\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2197\"\u003egitpython-developers/GitPython#2197\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/raisulchowdhury\"\u003e\u003ccode\u003e@​raisulchowdhury\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2203\"\u003egitpython-developers/GitPython#2203\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Cyrus580529\"\u003e\u003ccode\u003e@​Cyrus580529\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2197\"\u003egitpython-developers/GitPython#2197\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/gitpython-developers/GitPython/compare/3.1.57...3.1.58\"\u003ehttps://github.com/gitpython-developers/GitPython/compare/3.1.57...3.1.58\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003e3.1.57 - Security and Fixes\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMerge gitdb and smmap into the GitPython repository by \u003ca href=\"https://github.com/Byron\"\u003e\u003ccode\u003e@​Byron\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2179\"\u003egitpython-developers/GitPython#2179\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump actions/setup-python from 6 to 7 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2185\"\u003egitpython-developers/GitPython#2185\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump the pre-commit group with 2 updates by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2186\"\u003egitpython-developers/GitPython#2186\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump Vampire/setup-wsl from 6.0.0 to 7.0.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2124\"\u003egitpython-developers/GitPython#2124\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRender protected Traversable methods in the reference by \u003ca href=\"https://github.com/pick7\"\u003e\u003ccode\u003e@​pick7\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2192\"\u003egitpython-developers/GitPython#2192\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUse standard prefixes for parsed patch diffs by \u003ca href=\"https://github.com/pick7\"\u003e\u003ccode\u003e@​pick7\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2191\"\u003egitpython-developers/GitPython#2191\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eHonor kill_after_timeout with output streams by \u003ca href=\"https://github.com/pick7\"\u003e\u003ccode\u003e@​pick7\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2189\"\u003egitpython-developers/GitPython#2189\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRedact Authorization extra headers from command errors by \u003ca href=\"https://github.com/pick7\"\u003e\u003ccode\u003e@​pick7\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2188\"\u003egitpython-developers/GitPython#2188\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eImprove RemoteProgress parse return typing by \u003ca href=\"https://github.com/pick7\"\u003e\u003ccode\u003e@​pick7\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2187\"\u003egitpython-developers/GitPython#2187\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdopt basedpyright with a legacy baseline by \u003ca href=\"https://github.com/Byron\"\u003e\u003ccode\u003e@​Byron\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2194\"\u003egitpython-developers/GitPython#2194\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBlock unsafe Git file and URL options by \u003ca href=\"https://github.com/Byron\"\u003e\u003ccode\u003e@​Byron\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2193\"\u003egitpython-developers/GitPython#2193\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pick7\"\u003e\u003ccode\u003e@​pick7\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2192\"\u003egitpython-developers/GitPython#2192\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/gitpython-developers/GitPython/compare/3.1.56...3.1.57\"\u003ehttps://github.com/gitpython-developers/GitPython/compare/3.1.56...3.1.57\u003c/a\u003e\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gitpython-developers/GitPython/commit/66340d77aab9a7468f4aed3681d4ef1e3c0ec931\"\u003e\u003ccode\u003e66340d7\u003c/code\u003e\u003c/a\u003e prepare changelog prior to release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gitpython-developers/GitPython/commit/a5e047d0db7047c4249c0de335585470b14d50c4\"\u003e\u003ccode\u003ea5e047d\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/issues/2211\"\u003e#2211\u003c/a\u003e from gitpython-developers/config-sanitize-more\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gitpython-developers/GitPython/commit/ef7568e3b317ce617eacda39b8b54dcdff8c3b5c\"\u003e\u003ccode\u003eef7568e\u003c/code\u003e\u003c/a\u003e fix: ignore includes in submodule configuration\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gitpython-developers/GitPython/commit/4b4e47fc1224e23b0c8ee7220a7192818f2e4abb\"\u003e\u003ccode\u003e4b4e47f\u003c/code\u003e\u003c/a\u003e fix: preserve multiline config values when writing\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gitpython-developers/GitPython/commit/b473abb0f7de754392e1ec923f2fe296509013ab\"\u003e\u003ccode\u003eb473abb\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/issues/2210\"\u003e#2210\u003c/a\u003e from gitpython-developers/fix-clone-unsafe-option\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gitpython-developers/GitPython/commit/5ff52cccca770fd69c6caf0b8f281d3e45d599be\"\u003e\u003ccode\u003e5ff52cc\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/issues/2209\"\u003e#2209\u003c/a\u003e from caroescm/fix-index-add-chmod\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gitpython-developers/GitPython/commit/b68afff45af0f49e79a3e2d2162018986b37ad5d\"\u003e\u003ccode\u003eb68afff\u003c/code\u003e\u003c/a\u003e Block separate git directories during clone\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gitpython-developers/GitPython/commit/93677a00ab9dcb06cc08595fd1f88a4b4a0fa23b\"\u003e\u003ccode\u003e93677a0\u003c/code\u003e\u003c/a\u003e fix: \u003ccode\u003eindex.add()\u003c/code\u003e now supports filters (\u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/issues/2021\"\u003e#2021\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gitpython-developers/GitPython/commit/9729ed3b948f2bde09f1f188c5311e172212b67e\"\u003e\u003ccode\u003e9729ed3\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/issues/2208\"\u003e#2208\u003c/a\u003e from gitpython-developers/security-fixes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gitpython-developers/GitPython/commit/ce9d8e8d150e06ae2e2cc2efa229071cd3048a93\"\u003e\u003ccode\u003ece9d8e8\u003c/code\u003e\u003c/a\u003e prepare next release\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/gitpython-developers/GitPython/compare/3.1.44...3.1.59\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `langchain` from 1.2.10 to 1.3.9\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/langchain-ai/langchain/releases\"\u003elangchain's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003elangchain==1.3.9\u003c/h2\u003e\n\u003cp\u003eChanges since langchain==1.3.8\u003c/p\u003e\n\u003cp\u003erelease(anthropic): 1.4.6 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38105\"\u003e#38105\u003c/a\u003e)\nrelease(langchain): 1.3.9 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38104\"\u003e#38104\u003c/a\u003e)\nfix(langchain,anthropic): confine file-search results and tighten anthropic \u003ccode\u003eallowed_prefixes\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38106\"\u003e#38106\u003c/a\u003e)\u003c/p\u003e\n\u003ch2\u003elangchain==1.3.8\u003c/h2\u003e\n\u003cp\u003eChanges since langchain==1.3.7\u003c/p\u003e\n\u003cp\u003erelease(langchain): 1.3.8 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38096\"\u003e#38096\u003c/a\u003e)\nstyle(core,langchain,langchain-classic,partners): replace double backticks in docstrings (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38095\"\u003e#38095\u003c/a\u003e)\nrelease(core): 1.4.6 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38061\"\u003e#38061\u003c/a\u003e)\nchore(langchain): add overloads to \u003ccode\u003ecreate_agent\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/34309\"\u003e#34309\u003c/a\u003e)\nchore(infra): bump mypy to 2.1 and unify type-check config across the monorepo (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/36470\"\u003e#36470\u003c/a\u003e)\nfix(langchain): support async middleware decorator typing (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/34584\"\u003e#34584\u003c/a\u003e)\nfix(langchain): tighten structured output model fallbacks (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38042\"\u003e#38042\u003c/a\u003e)\nrelease(anthropic): 1.4.5 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38036\"\u003e#38036\u003c/a\u003e)\nhotfix(core): bump lockfile(s) (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38032\"\u003e#38032\u003c/a\u003e)\nrefactor(langchain): refactor \u003ccode\u003etest_create_agent_tool_validation\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/34443\"\u003e#34443\u003c/a\u003e)\u003c/p\u003e\n\u003ch2\u003elangchain==1.3.7\u003c/h2\u003e\n\u003cp\u003eChanges since langchain==1.3.6\u003c/p\u003e\n\u003cp\u003erelease(langchain): 1.3.7 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38024\"\u003e#38024\u003c/a\u003e)\nstyle(langchain): add ruff rules ARG (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/34435\"\u003e#34435\u003c/a\u003e)\nfeat(langchain): add \u003ccode\u003eProviderToolSearchMiddleware\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/37969\"\u003e#37969\u003c/a\u003e)\nchore(langchain): activate mypy \u003ccode\u003ewarn_return_any\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/34249\"\u003e#34249\u003c/a\u003e)\ntest(langchain): mark legacy trigger view for 2.0 removal (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38002\"\u003e#38002\u003c/a\u003e)\u003c/p\u003e\n\u003ch2\u003elangchain==1.3.6\u003c/h2\u003e\n\u003cp\u003eChanges since langchain==1.3.5\u003c/p\u003e\n\u003cp\u003erelease(langchain): 1.3.6 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38001\"\u003e#38001\u003c/a\u003e)\nfix(langchain): preserve summarization trigger compatibility (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38000\"\u003e#38000\u003c/a\u003e)\u003c/p\u003e\n\u003ch2\u003elangchain==1.3.5\u003c/h2\u003e\n\u003cp\u003eChanges since langchain==1.3.4\u003c/p\u003e\n\u003cp\u003erelease(langchain): 1.3.5 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/37998\"\u003e#37998\u003c/a\u003e)\nfeat(langchain): port AND-capable trigger conditions to \u003ccode\u003eSummarizationMiddleware\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/34576\"\u003e#34576\u003c/a\u003e)\nhotfix(openai): min core dep (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/37990\"\u003e#37990\u003c/a\u003e)\nfeat(openai): support \u003ccode\u003eapply_patch\u003c/code\u003e built-in tool (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/37157\"\u003e#37157\u003c/a\u003e)\nchore: bump pyarrow from 21.0.0 to 23.0.1 in /libs/langchain_v1 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/37930\"\u003e#37930\u003c/a\u003e)\nchore: bump dependencies  (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/37892\"\u003e#37892\u003c/a\u003e)\nchore: bump aiohttp from 3.13.4 to 3.14.0 in /libs/langchain_v1 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/37888\"\u003e#37888\u003c/a\u003e)\u003c/p\u003e\n\u003ch2\u003elangchain-openai==1.3.5\u003c/h2\u003e\n\u003cp\u003eChanges since langchain-openai==1.3.4\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/3bfb6a33e788aaca1626a7c09cbdbdbef6977012\"\u003e\u003ccode\u003e3bfb6a3\u003c/code\u003e\u003c/a\u003e release(langchain): 1.3.9 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38104\"\u003e#38104\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/dcaf7795a3e6590af55c3ff7bda6add6355e9ea6\"\u003e\u003ccode\u003edcaf779\u003c/code\u003e\u003c/a\u003e fix(langchain,anthropic): confine file-search results and tighten anthropic `...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/0392b6bae4bdfc0b7ed5aeb2e9e414bbb7ea643b\"\u003e\u003ccode\u003e0392b6b\u003c/code\u003e\u003c/a\u003e fix(core): fix Pydantic v1 support in tools/runnable (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/33698\"\u003e#33698\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/f6d63bc9f344b2949e91a6904d301553376b4f10\"\u003e\u003ccode\u003ef6d63bc\u003c/code\u003e\u003c/a\u003e release(langchain): 1.3.8 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38096\"\u003e#38096\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/5d20596d73789020f53c622b22c0a9893ba09606\"\u003e\u003ccode\u003e5d20596\u003c/code\u003e\u003c/a\u003e style(core,langchain,langchain-classic,partners): replace double backticks in...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/fb55c6660a2ac26038a64dac1534048294bc51ab\"\u003e\u003ccode\u003efb55c66\u003c/code\u003e\u003c/a\u003e chore: bump langsmith from 0.8.9 to 0.8.14 in /libs/partners/huggingface (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38\"\u003e#38\u003c/a\u003e...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/51daae5c139712f6f1347b5a801f672680ba1eba\"\u003e\u003ccode\u003e51daae5\u003c/code\u003e\u003c/a\u003e chore: bump langsmith from 0.8.9 to 0.8.14 in /libs/partners/chroma (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38092\"\u003e#38092\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/70e9579e433043321fb8e93a8a51770c946363d0\"\u003e\u003ccode\u003e70e9579\u003c/code\u003e\u003c/a\u003e chore: bump langsmith from 0.8.9 to 0.8.14 in /libs/partners/fireworks (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38093\"\u003e#38093\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/6c0e9af3246e3bbf98838e4b9ec563ad563dd748\"\u003e\u003ccode\u003e6c0e9af\u003c/code\u003e\u003c/a\u003e chore: bump langsmith from 0.8.9 to 0.8.14 in /libs/partners/xai (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38094\"\u003e#38094\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/222dc846e0e965a0d6764d772226590eec14b917\"\u003e\u003ccode\u003e222dc84\u003c/code\u003e\u003c/a\u003e ci(infra): clarify early PR auto-close guidance (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38090\"\u003e#38090\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/langchain-ai/langchain/compare/langchain==1.2.10...langchain==1.3.9\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `langsmith` from 0.7.7 to 0.8.18\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/langchain-ai/langsmith-sdk/releases\"\u003elangsmith's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev0.8.18\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003echore(deps-dev): bump vitest from 3.2.4 to 3.2.6 in /js by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3002\"\u003elangchain-ai/langsmith-sdk#3002\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(deps): bump pyjwt from 2.12.1 to 2.13.0 in /python by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3030\"\u003elangchain-ai/langsmith-sdk#3030\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(deps): bump python-multipart from 0.0.27 to 0.0.31 in /python by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3036\"\u003elangchain-ai/langsmith-sdk#3036\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(deps): bump aiohttp from 3.14.0 to 3.14.1 in /python by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3037\"\u003elangchain-ai/langsmith-sdk#3037\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(deps): bump cryptography from 46.0.7 to 48.0.1 in /python by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3038\"\u003elangchain-ai/langsmith-sdk#3038\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(deps): bump starlette from 1.0.1 to 1.3.1 in /python by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3039\"\u003elangchain-ai/langsmith-sdk#3039\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(deps-dev): bump langchain-anthropic from 1.4.4 to 1.4.6 in /python by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3044\"\u003elangchain-ai/langsmith-sdk#3044\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(deps): bump the npm_and_yarn group across 4 directories with 4 updates by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3046\"\u003elangchain-ai/langsmith-sdk#3046\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(deps): bump the npm_and_yarn group across 2 directories with 2 updates by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3060\"\u003elangchain-ai/langsmith-sdk#3060\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etest(python): fix integration assertions for updated attachment error message by \u003ca href=\"https://github.com/QuentinBrosse\"\u003e\u003ccode\u003e@​QuentinBrosse\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3061\"\u003elangchain-ai/langsmith-sdk#3061\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: reconcile bumpversion config and mandate release process for agents by \u003ca href=\"https://github.com/QuentinBrosse\"\u003e\u003ccode\u003e@​QuentinBrosse\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3062\"\u003elangchain-ai/langsmith-sdk#3062\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003erelease(py): 0.8.18 by \u003ca href=\"https://github.com/QuentinBrosse\"\u003e\u003ccode\u003e@​QuentinBrosse\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3063\"\u003elangchain-ai/langsmith-sdk#3063\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/langchain-ai/langsmith-sdk/compare/v0.8.17...v0.8.18\"\u003ehttps://github.com/langchain-ai/langsmith-sdk/compare/v0.8.17...v0.8.18\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev0.8.17\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efeat: expose the resources from the generated openapi client in the langsmith client by \u003ca href=\"https://github.com/sineha-mani\"\u003e\u003ccode\u003e@​sineha-mani\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3018\"\u003elangchain-ai/langsmith-sdk#3018\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(js): port \u003ccode\u003eisTracingEnabled\u003c/code\u003e utility from Python by \u003ca href=\"https://github.com/dqbd\"\u003e\u003ccode\u003e@​dqbd\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3032\"\u003elangchain-ai/langsmith-sdk#3032\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd sandbox mount support to JS SDK by \u003ca href=\"https://github.com/DanielKneipp\"\u003e\u003ccode\u003e@​DanielKneipp\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3010\"\u003elangchain-ai/langsmith-sdk#3010\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003erelease(js): bump to 0.7.9 by \u003ca href=\"https://github.com/dqbd\"\u003e\u003ccode\u003e@​dqbd\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3035\"\u003elangchain-ai/langsmith-sdk#3035\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd sandbox mount support to Python SDK by \u003ca href=\"https://github.com/DanielKneipp\"\u003e\u003ccode\u003e@​DanielKneipp\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3009\"\u003elangchain-ai/langsmith-sdk#3009\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003edocs: note that _openapi_client directories are auto-generated by \u003ca href=\"https://github.com/KiewanVillatel\"\u003e\u003ccode\u003e@​KiewanVillatel\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3034\"\u003elangchain-ai/langsmith-sdk#3034\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: update JS SDK type declarations with skipLibCheck disabled by \u003ca href=\"https://github.com/sineha-mani\"\u003e\u003ccode\u003e@​sineha-mani\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3043\"\u003elangchain-ai/langsmith-sdk#3043\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003erelease(js): 0.7.10 by \u003ca href=\"https://github.com/dqbd\"\u003e\u003ccode\u003e@​dqbd\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3045\"\u003elangchain-ai/langsmith-sdk#3045\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat: adding python async for online evals by \u003ca href=\"https://github.com/sineha-mani\"\u003e\u003ccode\u003e@​sineha-mani\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3048\"\u003elangchain-ai/langsmith-sdk#3048\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd sandbox Git mount SDK helpers by \u003ca href=\"https://github.com/DanielKneipp\"\u003e\u003ccode\u003e@​DanielKneipp\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3040\"\u003elangchain-ai/langsmith-sdk#3040\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: use insights tab in sdk report links [closes LSO-2936] by \u003ca href=\"https://github.com/eric-langchain\"\u003e\u003ccode\u003e@​eric-langchain\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3050\"\u003elangchain-ai/langsmith-sdk#3050\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efeat(client): warn when backend version is below minimum required by \u003ca href=\"https://github.com/KiewanVillatel\"\u003e\u003ccode\u003e@​KiewanVillatel\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3041\"\u003elangchain-ai/langsmith-sdk#3041\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: bump _MIN_BACKEND_VERSION to 0.16.5rc1 by \u003ca href=\"https://github.com/langtions-bot\"\u003e\u003ccode\u003e@​langtions-bot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3053\"\u003elangchain-ai/langsmith-sdk#3053\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(sandbox): use built-in gcp auth host matching by \u003ca href=\"https://github.com/DanielKneipp\"\u003e\u003ccode\u003e@​DanielKneipp\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3055\"\u003elangchain-ai/langsmith-sdk#3055\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore(python): py to 0.8.17 by \u003ca href=\"https://github.com/sineha-mani\"\u003e\u003ccode\u003e@​sineha-mani\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3056\"\u003elangchain-ai/langsmith-sdk#3056\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/sineha-mani\"\u003e\u003ccode\u003e@​sineha-mani\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3018\"\u003elangchain-ai/langsmith-sdk#3018\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eric-langchain\"\u003e\u003ccode\u003e@​eric-langchain\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3050\"\u003elangchain-ai/langsmith-sdk#3050\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/langchain-ai/langsmith-sdk/compare/v0.8.16...v0.8.17\"\u003ehttps://github.com/langchain-ai/langsmith-sdk/compare/v0.8.16...v0.8.17\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev0.8.16\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efeat(py): add sync/async conversion for Sandbox and SandboxClient [INF-0000] by \u003ca href=\"https://github.com/ramon-langchain\"\u003e\u003ccode\u003e@​ramon-langchain\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3019\"\u003elangchain-ai/langsmith-sdk#3019\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(experiments): extract keys from wrapped evaluator function by \u003ca href=\"https://github.com/shamikkarkhanis\"\u003e\u003ccode\u003e@​shamikkarkhanis\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3014\"\u003elangchain-ai/langsmith-sdk#3014\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: repoint \u003ca href=\"mailto:support@langchain.dev\"\u003esupport@langchain.dev\u003c/a\u003e mentions to the Support Portal by \u003ca href=\"https://github.com/lutan-langchain\"\u003e\u003ccode\u003e@​lutan-langchain\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3024\"\u003elangchain-ai/langsmith-sdk#3024\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix(python): derive create_child run id from start_time [LSDK-220] by \u003ca href=\"https://github.com/harisaiharish\"\u003e\u003ccode\u003e@​harisaiharish\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3027\"\u003elangchain-ai/langsmith-sdk#3027\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: sync langsmith_api by \u003ca href=\"https://github.com/langtions-bot\"\u003e\u003ccode\u003e@​langtions-bot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3020\"\u003elangchain-ai/langsmith-sdk#3020\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: js to 0.7.8 and py to 0.8.16 by \u003ca href=\"https://github.com/shamikkarkhanis\"\u003e\u003ccode\u003e@​shamikkarkhanis\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/pull/3029\"\u003elangchain-ai/langsmith-sdk#3029\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langsmith-sdk/commit/31c2bf650b84a44577d8b4443298fb7e78025b8f\"\u003e\u003ccode\u003e31c2bf6\u003c/code\u003e\u003c/a\u003e release(py): 0.8.18 (\u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3063\"\u003e#3063\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langsmith-sdk/commit/8955b688689fdf47871d44013787410a42ea13fd\"\u003e\u003ccode\u003e8955b68\u003c/code\u003e\u003c/a\u003e chore: reconcile bumpversion config and mandate release process for agents (#...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langsmith-sdk/commit/411401f6ca5ff401c29772ed097c9c9ed97f994c\"\u003e\u003ccode\u003e411401f\u003c/code\u003e\u003c/a\u003e test(python): fix integration assertions for updated attachment error message...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langsmith-sdk/commit/9c5515620f9bfa2145fc65d6f4353c4c8a3e96b6\"\u003e\u003ccode\u003e9c55156\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langsmith-sdk/commit/5b2bd8db3c50d3f19e98f41288c87d9c0ac0b136\"\u003e\u003ccode\u003e5b2bd8d\u003c/code\u003e\u003c/a\u003e chore(deps): bump the npm_and_yarn group across 2 directories with 2 updates ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langsmith-sdk/commit/d8642f9099a48025d00c7283ad3cd2ce56fec775\"\u003e\u003ccode\u003ed8642f9\u003c/code\u003e\u003c/a\u003e chore(deps): bump the npm_and_yarn group across 4 directories with 4 updates ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langsmith-sdk/commit/953c2e5e25e41ecb4dba428adbac1c446c0a0071\"\u003e\u003ccode\u003e953c2e5\u003c/code\u003e\u003c/a\u003e chore(deps-dev): bump langchain-anthropic from 1.4.4 to 1.4.6 in /python (\u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3044\"\u003e#3044\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langsmith-sdk/commit/5513699e2d25c2147e02c296bc3b90f7d0923d8a\"\u003e\u003ccode\u003e5513699\u003c/code\u003e\u003c/a\u003e chore(deps): bump starlette from 1.0.1 to 1.3.1 in /python (\u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3039\"\u003e#3039\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langsmith-sdk/commit/8becdefdf422a02e03f78cf3ebb4c62c136b7cf3\"\u003e\u003ccode\u003e8becdef\u003c/code\u003e\u003c/a\u003e chore(deps): bump cryptography from 46.0.7 to 48.0.1 in /python (\u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3038\"\u003e#3038\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langsmith-sdk/commit/1a9c522febbf313bbe649ca75c39158fec048934\"\u003e\u003ccode\u003e1a9c522\u003c/code\u003e\u003c/a\u003e chore(deps): bump aiohttp from 3.14.0 to 3.14.1 in /python (\u003ca href=\"https://redirect.github.com/langchain-ai/langsmith-sdk/issues/3037\"\u003e#3037\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/langchain-ai/langsmith-sdk/compare/v0.7.7...v0.8.18\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `pyjwt` from 2.10.1 to 2.13.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/jpadilla/pyjwt/releases\"\u003epyjwt's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e2.13.0\u003c/h2\u003e\n\u003ch1\u003ePyJWT 2.13.0 — Security Release\u003c/h1\u003e\n\u003cp\u003eThis release bundles five security fixes plus three additional hardening / spec-compliance changes. We recommend all users upgrade.\u003c/p\u003e\n\u003ch2\u003eSecurity\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/security/advisories/GHSA-xgmm-8j9v-c9wx\"\u003e\u003ccode\u003eGHSA-xgmm-8j9v-c9wx\u003c/code\u003e\u003c/a\u003e — JWK JSON accepted as HMAC secret (algorithm confusion).\u003c/strong\u003e \u003ccode\u003eHMACAlgorithm.prepare_key\u003c/code\u003e previously rejected PEM- and SSH-formatted asymmetric keys but did not catch a JWK passed as a raw JSON string. In a verifier configured with both symmetric and asymmetric algorithms in \u003ccode\u003ealgorithms=[…]\u003c/code\u003e and a raw-JSON JWK as the key, an attacker could forge HS256 tokens using the JWK text as the HMAC secret. The guard has been extended to reject any JWK-shaped JSON. \u003cem\u003eReported by \u003ca href=\"https://github.com/aradona91\"\u003e\u003ccode\u003e@​aradona91\u003c/code\u003e\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/security/advisories/GHSA-jq35-7prp-9v3f\"\u003e\u003ccode\u003eGHSA-jq35-7prp-9v3f\u003c/code\u003e\u003c/a\u003e — Algorithm allow-list bypass with \u003ccode\u003ePyJWK\u003c/code\u003e / \u003ccode\u003ePyJWKClient\u003c/code\u003e.\u003c/strong\u003e When verifying with a \u003ccode\u003ePyJWK\u003c/code\u003e, the caller's \u003ccode\u003ealgorithms=[…]\u003c/code\u003e allow-list was checked against the token header \u003ccode\u003ealg\u003c/code\u003e as a string only; actual verification used the algorithm bound to the \u003ccode\u003ePyJWK\u003c/code\u003e. An attacker who controlled a registered JWKS key could sign with one algorithm and advertise another on the header. PyJWT now requires the token header \u003ccode\u003ealg\u003c/code\u003e to match the \u003ccode\u003ePyJWK\u003c/code\u003e's algorithm before verification. \u003cem\u003eReported by \u003ca href=\"https://github.com/sushi-gif\"\u003e\u003ccode\u003e@​sushi-gif\u003c/code\u003e\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/security/advisories/GHSA-w7vc-732c-9m39\"\u003e\u003ccode\u003eGHSA-w7vc-732c-9m39\u003c/code\u003e\u003c/a\u003e — DoS via base64 decode of unused payload segment when \u003ccode\u003eb64=false\u003c/code\u003e.\u003c/strong\u003e For detached-payload JWS (\u003ccode\u003eb64=false\u003c/code\u003e), the compact-form payload segment was base64-decoded before being discarded in favor of the caller-supplied \u003ccode\u003edetached_payload\u003c/code\u003e. An attacker could inflate the unused segment to force CPU + memory cost without holding a valid signature. The segment is now required to be empty per RFC 7515 Appendix F, and is no longer decoded. \u003cem\u003eReported by \u003ca href=\"https://github.com/thesmartshadow\"\u003e\u003ccode\u003e@​thesmartshadow\u003c/code\u003e\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/security/advisories/GHSA-993g-76c3-p5m4\"\u003e\u003ccode\u003eGHSA-993g-76c3-p5m4\u003c/code\u003e\u003c/a\u003e — \u003ccode\u003ePyJWKClient\u003c/code\u003e accepts non-HTTP(S) URIs.\u003c/strong\u003e \u003ccode\u003ePyJWKClient.fetch_data\u003c/code\u003e passed its URI to \u003ccode\u003eurllib.request.urlopen\u003c/code\u003e, which by default also handles \u003ccode\u003efile://\u003c/code\u003e, \u003ccode\u003eftp://\u003c/code\u003e, and \u003ccode\u003edata:\u003c/code\u003e schemes. An application that fed an attacker-influenced URI into \u003ccode\u003ePyJWKClient\u003c/code\u003e could be coerced into reading local files or reaching other unintended schemes. \u003ccode\u003ePyJWKClient\u003c/code\u003e now rejects any URI whose scheme isn't \u003ccode\u003ehttp\u003c/code\u003e or \u003ccode\u003ehttps\u003c/code\u003e. \u003cem\u003eReported by \u003ca href=\"https://github.com/KEIJOT\"\u003e\u003ccode\u003e@​KEIJOT\u003c/code\u003e\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/security/advisories/GHSA-fhv5-28vv-h8m8\"\u003e\u003ccode\u003eGHSA-fhv5-28vv-h8m8\u003c/code\u003e\u003c/a\u003e — \u003ccode\u003ePyJWKClient\u003c/code\u003e cache wiped on fetch error.\u003c/strong\u003e A \u003ccode\u003efinally\u003c/code\u003e-block \u003ccode\u003eput(jwk_set=None)\u003c/code\u003e cleared the JWK Set cache whenever a fetch raised, turning a transient JWKS-endpoint outage into application-wide auth failure. The cache write was moved into the success path; transient errors no longer evict valid cached keys. \u003cem\u003eReported by \u003ca href=\"https://github.com/eddieran\"\u003e\u003ccode\u003e@​eddieran\u003c/code\u003e\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eFixed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eReject empty HMAC keys outright in \u003ccode\u003eHMACAlgorithm.prepare_key\u003c/code\u003e with \u003ccode\u003eInvalidKeyError\u003c/code\u003e instead of accepting them with only a warning. Defends against the \u003ccode\u003eos.getenv(\u0026quot;JWT_SECRET\u0026quot;, \u0026quot;\u0026quot;)\u003c/code\u003e footgun. \u003cem\u003eThanks to \u003ca href=\"https://github.com/SnailSploit\"\u003e\u003ccode\u003e@​SnailSploit\u003c/code\u003e\u003c/a\u003e and \u003ca href=\"https://github.com/spartan8806\"\u003e\u003ccode\u003e@​spartan8806\u003c/code\u003e\u003c/a\u003e for the reports.\u003c/em\u003e\u003c/li\u003e\n\u003cli\u003eForward per-call \u003ccode\u003eoptions\u003c/code\u003e (including \u003ccode\u003eenforce_minimum_key_length\u003c/code\u003e) from \u003ccode\u003ePyJWT.decode\u003c/code\u003e through to \u003ccode\u003ePyJWS._verify_signature\u003c/code\u003e. The option was previously silently dropped between the two layers, so it only took effect when set on the \u003ccode\u003ePyJWT\u003c/code\u003e instance. \u003cem\u003eThanks to \u003ca href=\"https://github.com/WLUB\"\u003e\u003ccode\u003e@​WLUB\u003c/code\u003e\u003c/a\u003e for the report.\u003c/em\u003e\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eRFC 7797 §3 compliance for \u003ccode\u003eb64=false\u003c/code\u003e:\u003c/strong\u003e the encoder now auto-adds \u003ccode\u003e\u0026quot;b64\u0026quot;\u003c/code\u003e to \u003ccode\u003ecrit\u003c/code\u003e, and the decoder rejects tokens that set \u003ccode\u003eb64=false\u003c/code\u003e without listing it in \u003ccode\u003ecrit\u003c/code\u003e. \u003cem\u003eThanks to \u003ca href=\"https://github.com/MachineLearning-Nerd\"\u003e\u003ccode\u003e@​MachineLearning-Nerd\u003c/code\u003e\u003c/a\u003e for the report.\u003c/em\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eChanged\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMigrate the \u003ccode\u003edev\u003c/code\u003e, \u003ccode\u003edocs\u003c/code\u003e, and \u003ccode\u003etests\u003c/code\u003e package extras to dependency groups, by \u003ca href=\"https://github.com/kurtmckee\"\u003e\u003ccode\u003e@​kurtmckee\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/jpadilla/pyjwt/pull/1152\"\u003e#1152\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eUpgrade notes\u003c/h2\u003e\n\u003cp\u003eMost fixes are invisible to correctly-configured callers. A few behavioral changes you may encounter:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eEmpty HMAC keys now raise.\u003c/strong\u003e If your app passed \u003ccode\u003e\u0026quot;\u0026quot;\u003c/code\u003e or \u003ccode\u003eb\u0026quot;\u0026quot;\u003c/code\u003e as a secret (often via a missing env var, e.g. \u003ccode\u003eos.getenv(\u0026quot;JWT_SECRET\u0026quot;, \u0026quot;\u0026quot;)\u003c/code\u003e), \u003ccode\u003eencode\u003c/code\u003e/\u003ccode\u003edecode\u003c/code\u003e will now raise \u003ccode\u003eInvalidKeyError\u003c/code\u003e. This is the intended behavior — fix the configuration.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ccode\u003ePyJWK\u003c/code\u003e decoding now requires the token's \u003ccode\u003ealg\u003c/code\u003e to match the JWK's algorithm.\u003c/strong\u003e Previously a mismatch was silently honored if the header \u003ccode\u003ealg\u003c/code\u003e appeared in the allow-list. Tokens that relied on this mismatch will now fail with \u003ccode\u003eInvalidAlgorithmError\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ccode\u003ePyJWKClient\u003c/code\u003e now rejects non-HTTP(S) URIs at construction time.\u003c/strong\u003e Tests or dev environments that fetched JWKS from \u003ccode\u003efile://\u003c/code\u003e URIs need to switch to a local HTTP server or load the JWKS by other means (e.g. construct \u003ccode\u003ePyJWKSet.from_dict(...)\u003c/code\u003e directly).\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ccode\u003eb64=false\u003c/code\u003e tokens are now strictly RFC 7515 / 7797 compliant.\u003c/strong\u003e Tokens with a non-empty compact-form payload segment, or that omit \u003ccode\u003e\u0026quot;b64\u0026quot;\u003c/code\u003e from \u003ccode\u003ecrit\u003c/code\u003e, will be rejected. PyJWT-produced tokens always satisfy both invariants, so round-trips through PyJWT are unaffected.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ccode\u003eenforce_minimum_key_length\u003c/code\u003e set per-call now takes effect.\u003c/strong\u003e Callers who passed \u003ccode\u003eoptions={\u0026quot;enforce_minimum_key_length\u0026quot;: True}\u003c/code\u003e to \u003ccode\u003ejwt.decode()\u003c/code\u003e previously got no enforcement; they will now get \u003ccode\u003eInvalidKeyError\u003c/code\u003e on undersized keys, as documented.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull changelog:\u003c/strong\u003e \u003ca href=\"https://github.com/jpadilla/pyjwt/compare/2.12.1...2.13.0\"\u003ehttps://github.com/jpadilla/pyjwt/compare/2.12.1...2.13.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003e2.12.1\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd typing_extensions dependency for Python \u0026lt; 3.11 by \u003ca href=\"https://github.com/jpadilla\"\u003e\u003ccode\u003e@​jpadilla\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/jpadilla/pyjwt/pull/1151\"\u003ejpadilla/pyjwt#1151\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/jpadilla/pyjwt/compare/2.12.0...2.12.1\"\u003ehttps://github.com/jpadilla/pyjwt/compare/2.12.0...2.12.1\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003e2.12.0\u003c/h2\u003e\n\u003ch2\u003eSecurity\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eValidate the crit (Critical) Header Parameter defined in RFC 7515 §4.1.11. by \u003ca href=\"https://github.com/dmbs335\"\u003e\u003ccode\u003e@​dmbs335\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://github.com/jpadilla/pyjwt/security/advisories/GHSA-752w-5fwx-jx9f\"\u003eGHSA-752w-5fwx-jx9f\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/jpadilla/pyjwt/blob/master/CHANGELOG.rst\"\u003epyjwt's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ccode\u003ev2.13.0 \u0026lt;https://github.com/jpadilla/pyjwt/compare/2.12.1...2.13.0\u0026gt;\u003c/code\u003e__\u003c/h2\u003e\n\u003cp\u003eSecurity\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003e\n- Reject JWK JSON documents passed as raw HMAC secrets in\n  ``HMACAlgorithm.prepare_key`` to close an algorithm-confusion gap that\n  the existing PEM/SSH guard did not cover. Reported by @aradona91 in\n  `GHSA-xgmm-8j9v-c9wx \u0026lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-xgmm-8j9v-c9wx\u0026gt;`__.\n- Bind the JWT header ``alg`` to ``PyJWK.algorithm_name`` during\n  verification so the caller's ``algorithms=[...]`` allow-list cannot be\n  bypassed when decoding with a ``PyJWK`` / ``PyJWKClient`` key. Reported\n  by @sushi-gif in `GHSA-jq35-7prp-9v3f \u0026lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-jq35-7prp-9v3f\u0026gt;`__.\n- Reject non-``http(s)`` URI schemes in ``PyJWKClient`` so attacker-\n  influenced URIs cannot read local files or reach unintended schemes via\n  urllib's default ``file://`` / ``ftp://`` / ``data:`` handlers. Reported\n  by @KEIJOT in `GHSA-993g-76c3-p5m4 \u0026lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-993g-76c3-p5m4\u0026gt;`__.\n- Preserve the cached JWK Set on fetch errors in ``PyJWKClient.fetch_data``.\n  The previous ``finally``-block ``put(None)`` pattern cleared the cache\n  on any transient outage, turning one bad JWKS request into application-\n  wide auth failure. Reported by @eddieran in `GHSA-fhv5-28vv-h8m8 \u0026lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-fhv5-28vv-h8m8\u0026gt;`__.\n- Skip the unconditional base64 decode of the compact-form payload segment\n  when ``b64=false`` is set in the protected header, and require that\n  segment to be empty (RFC 7515 Appendix F detached form). Closes an\n  unauthenticated DoS amplifier. Reported by @thesmartshadow in\n  `GHSA-w7vc-732c-9m39 \u0026lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-w7vc-732c-9m39\u0026gt;`__.\n\u003cp\u003eFixed\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003e\n- Reject empty HMAC keys outright in ``HMACAlgorithm.prepare_key`` with\n  ``InvalidKeyError`` instead of accepting them with only a warning.\n  Thanks to @SnailSploit and @spartan8806 for independently flagging the\n  footgun.\n- Forward per-call ``options`` (including ``enforce_minimum_key_length``)\n  from ``PyJWT.decode`` through to ``PyJWS._verify_signature`` so the\n  option actually takes effect when set at the call site rather than only\n  on the ``PyJWT`` instance. Thanks to @WLUB for the report.\n- RFC 7797 §3 compliance for ``b64=false``: the encoder now auto-adds\n  ``\u0026amp;quot;b64\u0026amp;quot;`` to the ``crit`` header parameter, and the decoder rejects\n  tokens that set ``b64=false`` without listing it in ``crit``. Thanks to\n  @MachineLearning-Nerd for the report.\n\nChanged\n\u003c/code\u003e\u003c/pre\u003e\n\u003cul\u003e\n\u003cli\u003eMigrate the \u003ccode\u003edev\u003c/code\u003e, \u003ccode\u003edocs\u003c/code\u003e, and \u003ccode\u003etests\u003c/code\u003e package extras to dependency groups by \u003ca href=\"https://github.com/kurtmckee\"\u003e\u003ccode\u003e@​kurtmckee\u003c/code\u003e\u003c/a\u003e in \u003ccode\u003e[#1152](https://github.com/jpadilla/pyjwt/issues/1152) \u0026amp;lt;https://github.com/jpadilla/pyjwt/pull/1152\u0026amp;gt;\u003c/code\u003e__\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003ccode\u003ev2.12.1 \u0026amp;lt;https://github.com/jpadilla/pyjwt/compare/2.12.0...2.12.1\u0026amp;gt;\u003c/code\u003e__\n\u0026lt;/tr\u0026gt;\u0026lt;/table\u0026gt;\n\u003c/code\u003e\u003c/pre\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/7144e4534c34810f4525dc4578a32addd8212cff\"\u003e\u003ccode\u003e7144e45\u003c/code\u003e\u003c/a\u003e Apply ruff format\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/d2f4bec4963897c0ef96ef64a875894f2c8542ab\"\u003e\u003ccode\u003ed2f4bec\u003c/code\u003e\u003c/a\u003e Restore \u003ccode\u003ecast()\u003c/code\u003e calls with cross-version \u003ccode\u003etype: ignore\u003c/code\u003e for \u003ccode\u003eprepare_key\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/22f478cebddd8294259c30f037ecb92b0b348774\"\u003e\u003ccode\u003e22f478c\u003c/code\u003e\u003c/a\u003e Remove redundant casts in \u003ccode\u003eRSAAlgorithm.prepare_key\u003c/code\u003e and `ECAlgorithm.prepare...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/95791b1759b8aa4f2203575d344d5c78564cdc81\"\u003e\u003ccode\u003e95791b1\u003c/code\u003e\u003c/a\u003e Bundle security fixes and hardening into 2.13.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/dcc27a9d3182a2349c30b160758785c6ce7a6508\"\u003e\u003ccode\u003edcc27a9\u003c/code\u003e\u003c/a\u003e [pre-commit.ci] pre-commit autoupdate (\u003ca href=\"https://redirect.github.com/jpadilla/pyjwt/issues/1155\"\u003e#1155\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/9d08a9a1896845ed8eaf88e6f6ac61e5800c3e7a\"\u003e\u003ccode\u003e9d08a9a\u003c/code\u003e\u003c/a\u003e [pre-commit.ci] pre-commit autoupdate (\u003ca href=\"https://redirect.github.com/jpadilla/pyjwt/issues/1146\"\u003e#1146\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/b87c10014d4109f0214fea188d00faaaf8a80e64\"\u003e\u003ccode\u003eb87c100\u003c/code\u003e\u003c/a\u003e Bump codecov/codecov-action from 5 to 6 (\u003ca href=\"https://redirect.github.com/jpadilla/pyjwt/issues/1154\"\u003e#1154\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/40e3147eb5f790d8d041772e5fc00728a176c812\"\u003e\u003ccode\u003e40e3147\u003c/code\u003e\u003c/a\u003e Migrate development extras to dependency groups (\u003ca href=\"https://redirect.github.com/jpadilla/pyjwt/issues/1152\"\u003e#1152\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/a4e1a3d1218b01c5806420b8f16d9308ac4adc30\"\u003e\u003ccode\u003ea4e1a3d\u003c/code\u003e\u003c/a\u003e Add typing_extensions dependency for Python \u0026lt; 3.11 (\u003ca href=\"https://redirect.github.com/jpadilla/pyjwt/issues/1151\"\u003e#1151\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/bd9700cca7f9258fadcc429c1034e508025931f2\"\u003e\u003ccode\u003ebd9700c\u003c/code\u003e\u003c/a\u003e Use PyJWK algorithm when encoding without explicit algorithm (\u003ca href=\"https://redirect.github.com/jpadilla/pyjwt/issues/1148\"\u003e#1148\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/jpadilla/pyjwt/compare/2.10.1...2.13.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `setuptools` from 80.10.2 to 83.0.0\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pypa/setuptools/blob/main/NEWS.rst\"\u003esetuptools's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003ev83.0.0\u003c/h1\u003e\n\u003ch2\u003eFeatures\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRequire Python 3.10 or later.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eBugfixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eMANIFEST.in\u003c/code\u003e matching (via \u003ccode\u003eFileList\u003c/code\u003e) is now insensitive to Unicode\nnormalization form. A pattern authored in one form (e.g. NFC, as typically\nsaved by editors) now matches a file whose name is stored on disk in another\n(e.g. NFD, as produced by macOS APFS/HFS+). Previously an \u003ccode\u003eexclude\u003c/code\u003e,\n\u003ccode\u003eglobal-exclude\u003c/code\u003e, \u003ccode\u003erecursive-exclude\u003c/code\u003e, or \u003ccode\u003eprune\u003c/code\u003e rule could silently\nfail to drop a non-ASCII-named file from the source distribution, publishing\nit despite the exclusion -- see GHSA-h35f-9h28-mq5c.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eDeprecations and Removals\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003epypa/distutils#334\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch1\u003ev82.0.1\u003c/h1\u003e\n\u003ch2\u003eBugfixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix the loading of \u003ccode\u003elauncher manifest.xml\u003c/code\u003e file. (\u003ca href=\"https://redirect.github.com/pypa/setuptools/issues/5047\"\u003e#5047\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eReplaced deprecated \u003ccode\u003ejson.__version__\u003c/code\u003e with fixture in tests. (\u003ca href=\"https://redirect.github.com/pypa/setuptools/issues/5186\"\u003e#5186\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eImproved Documentation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd advice about how to improve predictability when installing sdists. (\u003ca href=\"https://redirect.github.com/pypa/setuptools/issues/5168\"\u003e#5168\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eMisc\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/pypa/setuptools/issues/4941\"\u003e#4941\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/pypa/setuptools/issues/5157\"\u003e#5157\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/pypa/setuptools/issues/5169\"\u003e#5169\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/pypa/setuptools/issues/5175\"\u003e#5175\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003ev82.0.0\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/setuptools/commit/6519f728c6f23c992df81a5691ef7655184a20eb\"\u003e\u003ccode\u003e6519f72\u003c/code\u003e\u003c/a\u003e Bump version: 82.0.1 → 83.0.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/setuptools/commit/d1151b125b29a6ee1c7db860f7ee6c365d525b5f\"\u003e\u003ccode\u003ed1151b1\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/pypa/setuptools/issues/5250\"\u003e#5250\u003c/a\u003e from pypa/feature/distutils-d7633fbed\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/setuptools/commit/a2df31e6a741b0fe775969618fe6a3a3d032e900\"\u003e\u003ccode\u003ea2df31e\u003c/code\u003e\u003c/a\u003e Capture removal of dry_run parameter in changelog.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/setuptools/commit/00144dc3fb6d023fd81cdc26c380a012b084df9b\"\u003e\u003ccode\u003e00144dc\u003c/code\u003e\u003c/a\u003e Moved newsfragment to the release where it occurred.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/setuptools/commit/a4a5a2b160357be77626aa077ddd1d8ee53be50f\"\u003e\u003ccode\u003ea4a5a2b\u003c/code\u003e\u003c/a\u003e Add news fragment.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/setuptools/commit/77470c23c35031c9e37d7512694ac5ca52bfcaac\"\u003e\u003ccode\u003e77470c2\u003c/code\u003e\u003c/a\u003e Merge \u003ca href=\"https://github.com/pypa/distutils\"\u003ehttps://github.com/pypa/distutils\u003c/a\u003e into feature/distutils-d7633fbed\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/setuptools/commit/3c43897420f25a1be1afe6eaa905d056009cc736\"\u003e\u003ccode\u003e3c43897\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/pypa/setuptools/issues/5247\"\u003e#5247\u003c/a\u003e from pypa/copilot/fix-pypy-version-issue\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/setuptools/commit/bb6ea66b4bd01cb35d7c68a1bc61b96d59190269\"\u003e\u003ccode\u003ebb6ea66\u003c/code\u003e\u003c/a\u003e Bump PyPy from 3.10 to 3.11 in CI workflow\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/setuptools/commit/a2bc3aca2f55eb9b93ea633e58ba68170ce14451\"\u003e\u003ccode\u003ea2bc3ac\u003c/code\u003e\u003c/a\u003e Fix broken intersphinx reference to build's installation docs\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/setuptools/commit/2d6a739c64cfedc65e1f635af7b52340aac8d99b\"\u003e\u003ccode\u003e2d6a739\u003c/code\u003e\u003c/a\u003e Use stacked parametrize decorators instead of itertools.product\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/pypa/setuptools/compare/v80.10.2...v83.0.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `aiohttp` from 3.13.3 to 3.14.3\nUpdates `langgraph-checkpoint` from 4.0.0 to 4.2.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/langchain-ai/langgraph/releases\"\u003elanggraph-checkpoint's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003elanggraph-checkpoint==4.2.0\u003c/h2\u003e\n\u003cp\u003eChanges since checkpoint==4.1.1\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003erelease(checkpoint): 4.2.0 (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8563\"\u003e#8563\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix(checkpoint): collect writes at plain-value seed in delta channel history (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8526\"\u003e#8526\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore: enforce PLC0415 in tests for the remaining packages (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8547\"\u003e#8547\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore: enable RUF100 and clear unused noqa directives (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8546\"\u003e#8546\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore(deps): bump the minor-and-patch group in /libs/checkpoint with 4 updates (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8490\"\u003e#8490\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efeat(checkpoint,checkpoint-postgres): add opt-in omit_expired to skip expired rows on read (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8354\"\u003e#8354\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore(deps): bump the minor-and-patch group in /libs/checkpoint with 5 updates (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8248\"\u003e#8248\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore(deps): bump langsmith from 0.8.0 to 0.8.18 in /libs/checkpoint (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8173\"\u003e#8173\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003edocs: standardize package \u003ccode\u003eREADME.md\u003c/code\u003e structure (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8064\"\u003e#8064\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore: migrate Python type checking to ty (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8002\"\u003e#8002\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore(deps-dev): bump the major group in /libs/checkpoint with 2 updates (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/7967\"\u003e#7967\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore(deps): bump the minor-and-patch group in /libs/checkpoint with 3 updates (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/7960\"\u003e#7960\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003elanggraph-checkpoint==4.1.1\u003c/h2\u003e\n\u003cp\u003eChanges since checkpoint==4.1.0\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003erelease(checkpoint): 4.1.1 (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/7890\"\u003e#7890\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix(checkpoint): restrict lc:2 envelope revival to default constructor (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/7892\"\u003e#7892\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore(deps): bump idna from 3.11 to 3.15 in /libs/checkpoint (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/7860\"\u003e#7860\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore(deps): bump langsmith from 0.7.31 to 0.8.0 in /libs/checkpoint (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/7784\"\u003e#7784\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003elanggraph-checkpoint==4.1.0\u003c/h2\u003e\n\u003cp\u003eChanges since checkpoint==4.1.0a4\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003erelease: bump alpha packages to official versions (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/7775\"\u003e#7775\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore(deps): bump urllib3 from 2.6.3 to 2.7.0 in /libs/checkpoint (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/7762\"\u003e#7762\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore(deps): bump langchain-core from 1.3.2 to 1.3.3 in /libs/checkpoint (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/7752\"\u003e#7752\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efeat(checkpoint): force delta channel snapshot after max supersteps since last snapshot (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/7746\"\u003e#7746\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix(checkpoint): specify allowed_objects in Reviver (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/7743\"\u003e#7743\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore: remove keepset helper (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/7745\"\u003e#7745\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore(langgraph): add guide/conformance for delta channel checkpointer (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/7736\"\u003e#7736\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003edocs(checkpoint): mark DeltaChannel and delta-history APIs as beta (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/7732\"\u003e#7732\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore(deps): bump the minor-and-patch group across 1 directory with 3 updates (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/7670\"\u003e#7670\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore: \u0026quot;chore: minor clean up around checkpoint and delta channel\u0026quot; (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/7706\"\u003e#7706\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore: minor clean up around checkpoint and delta channel (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/7705\"\u003e#7705\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003elanggraph-checkpoint==4.1.0a4\u003c/h2\u003e\n\u003cp\u003eChanges since checkpoint==4.1.0a3\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003erelease: alpha bump (a4) for langgraph, checkpoint, checkpoint-postgres (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/7701\"\u003e#7701\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efeat: public get_writes_history saver API + delta cadence rework (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/7699\"\u003e#7699\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003elanggraph-checkpoint==4.1.0a3\u003c/h2\u003e\n\u003cp\u003eChanges since checkpoint==4.1.0a2\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003erelease: alpha bump (a3) for langgraph, checkpoint, checkpoint-postgres (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/7678\"\u003e#7678\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore(langgraph): use two phase read to avoid unnecessary data transport (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/7660\"\u003e#7660\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langgraph/commit/f55e77274dad40897ef7b2d52cc7c0b85b792247\"\u003e\u003ccode\u003ef55e772\u003c/code\u003e\u003c/a\u003e release(checkpoint): 4.2.0 (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8563\"\u003e#8563\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langgraph/commit/a90ab4435853b8a5b6f82b20220b4c76af0e46d1\"\u003e\u003ccode\u003ea90ab44\u003c/code\u003e\u003c/a\u003e fix(checkpoint): collect writes at plain-value seed in delta channel history ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langgraph/commit/ea5f9cc9fb8c4b123769daab4753af34de29b1e9\"\u003e\u003ccode\u003eea5f9cc\u003c/code\u003e\u003c/a\u003e chore: enforce PLC0415 in tests for the remaining packages (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8547\"\u003e#8547\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langgraph/commit/36a505ac65e956da09e93cc753609635a511047e\"\u003e\u003ccode\u003e36a505a\u003c/code\u003e\u003c/a\u003e test(checkpoint-postgres,checkpoint-sqlite): run the conformance suite (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8537\"\u003e#8537\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langgraph/commit/d569e18f4bd78b7652cb88c84b8dd098057e4f7d\"\u003e\u003ccode\u003ed569e18\u003c/code\u003e\u003c/a\u003e fix(checkpoint-postgres): find plain-value seeds when walking delta history (...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langgraph/commit/f22af6248c93df08b553e9a264f6367797e0fddb\"\u003e\u003ccode\u003ef22af62\u003c/code\u003e\u003c/a\u003e chore: enable RUF100 and clear unused noqa directives (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8546\"\u003e#8546\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langgraph/commit/658541c4960f329864a2523fc7d52427e8190bed\"\u003e\u003ccode\u003e658541c\u003c/code\u003e\u003c/a\u003e chore(checkpoint-postgres,checkpoint-sqlite): enable PLC0415 lint rule (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8540\"\u003e#8540\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langgraph/commit/fb3d5f0399222504e015fe959e0e79fdc6e00a65\"\u003e\u003ccode\u003efb3d5f0\u003c/code\u003e\u003c/a\u003e chore(deps): bump the minor-and-patch group in /libs/cli/js-examples with 8 u...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langgraph/commit/01521c1b1cc4c035f64b9be40f2913285128f526\"\u003e\u003ccode\u003e01521c1\u003c/code\u003e\u003c/a\u003e chore(deps): bump the minor-and-patch group in /libs/cli/js-monorepo-example ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langgraph/commit/cd62febcfae628d0930d1f7d3cb3b5919d4b800f\"\u003e\u003ccode\u003ecd62feb\u003c/code\u003e\u003c/a\u003e chore(deps): bump the minor-and-patch group in /libs/checkpoint with 4 update...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/langchain-ai/langgraph/compare/checkpoint==4.0.0...checkpoint==4.2.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `langgraph-sdk` from 0.3.9 to 0.4.4\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/langchain-ai/langgraph/releases\"\u003elanggraph-sdk's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003elanggraph-sdk==0.4.4\u003c/h2\u003e\n\u003cp\u003eChanges since sdk==0.4.3\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003erelease(sdk-py): 0.4.4 (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8738\"\u003e#8738\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eMerge commit from fork\u003c/li\u003e\n\u003cli\u003efeat: route LangSmith traces from thread streams (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8723\"\u003e#8723\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003elanggraph-sdk==0.4.3\u003c/h2\u003e\n\u003cp\u003eChanges since sdk==0.4.2\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003erelease(sdk-py): 0.4.3 (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8657\"\u003e#8657\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efeat(sdk-py): add decrypt replacement result (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8598\"\u003e#8598\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003erelease(langgraph): 1.2.11 (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8595\"\u003e#8595\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore(deps): bump the minor-and-patch group across 1 directory with 5 updates (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8532\"\u003e#8532\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003erelease(checkpoint): 4.2.0 (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8563\"\u003e#8563\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore: enforce PLC0415 in tests for the remaining packages (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8547\"\u003e#8547\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003erelease(langgraph): 1.2.10 (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8462\"\u003e#8462\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore(deps): bump websockets from 15.0.1 to 16.0 in /libs/sdk-py in the major group (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8253\"\u003e#8253\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix(sdk-py): support clearing cron end_time via update(end_time=None) (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8334\"\u003e#8334\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003erelease(langgraph): 1.2.9 (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8316\"\u003e#8316\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003erelease(langgraph): 1.2.8 (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8292\"\u003e#8292\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore(deps): bump websockets from 15.0.1 to 16.0 in /libs/langgraph in the major group (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8256\"\u003e#8256\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore(deps): bump the minor-and-patch group in /libs/sdk-py with 9 updates (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8252\"\u003e#8252\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003erelease(langgraph): 1.2.7 (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8223\"\u003e#8223\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore(deps-dev): bump starlette from 1.0.1 to 1.3.1 in /libs/sdk-py (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8104\"\u003e#8104\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore(deps): bump langsmith from 0.8.0 to 0.8.18 in /libs/sdk-py (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8174\"\u003e#8174\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003erelease(langgraph): 1.2.6 (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8139\"\u003e#8139\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003edocs: standardize package \u003ccode\u003eREADME.md\u003c/code\u003e structure (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8064\"\u003e#8064\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003erelease(langgraph): 1.2.5 (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8062\"\u003e#8062\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix(langgraph): merge \u003ccode\u003elc_versions\u003c/code\u003e config metadata (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8052\"\u003e#8052\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore(deps-dev): bump starlette from 1.0.0 to 1.0.1 in /libs/sdk-py (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8006\"\u003e#8006\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore: migrate Python type checking to ty (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8002\"\u003e#8002\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003erelease(langgraph): 1.2.4 (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/7991\"\u003e#7991\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003etest(sdk-py): add factory-graph integration test exercising the server factory path (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/7978\"\u003e#7978\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003erelease(langgraph): 1.2.3 (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/7945\"\u003e#7945\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003elanggraph-sdk==0.4.2\u003c/h2\u003e\n\u003cp\u003eChanges since sdk==0.4.1\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003erelease(sdk-py): 0.4.2 (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/7955\"\u003e#7955\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix(sdk-py): percent-encode thread_id in v3 stream transport default paths (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/7954\"\u003e#7954\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003elanggraph-sdk==0.4.1\u003c/h2\u003e\n\u003cp\u003eChanges since sdk==0.4.0\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003erelease(sdk-py): 0.4.1 (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/7944\"\u003e#7944\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efeat(sdk-py): extract stream decoders and add interleave_projections (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/7935\"\u003e#7935\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efeat(langgraph): add v3 streaming support to RemoteGraph (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/7927\"\u003e#7927\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix(sdk-py): make \u003ccode\u003etools_agent\u003c/code\u003e fake model stateless (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/7930\"\u003e#7930\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langgraph/commit/a64414c87c8db294fd3b1c5581f39f5b491ef07e\"\u003e\u003ccode\u003ea64414c\u003c/code\u003e\u003c/a\u003e langgraph: release 0.4.4 (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/4704\"\u003e#4704\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langgraph/commit/3a1c02ff3364fa68d6659282dc994e5c57fd1833\"\u003e\u003ccode\u003e3a1c02f\u003c/code\u003e\u003c/a\u003e update for consistency\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langgraph/commit/5ab2aa79bb4949ec96d593ffdd3f7fe6d1c7cc32\"\u003e\u003ccode\u003e5ab2aa7\u003c/code\u003e\u003c/a\u003e lint again\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langgraph/commit/c33e64daa6295be3fadd5c8664185fc4268b9f71\"\u003e\u003ccode\u003ec33e64d\u003c/code\u003e\u003c/a\u003e use list\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langgraph/commit/4ffae6065f1c7fe4dc00fed21ee9a584cbbb14b3\"\u003e\u003ccode\u003e4ffae60\u003c/code\u003e\u003c/a\u003e lint + update\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langgraph/commit/54ddde9d4c73a31cb921420867231542ae7faa72\"\u003e\u003ccode\u003e54ddde9\u003c/code\u003e\u003c/a\u003e update\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langgraph/commit/60c41ce69e17fff2367eb816a667dd38cf7bb58e\"\u003e\u003ccode\u003e60...\n\n_Description has been truncated_","html_url":"https://github.com/sdelmas/SREGym/pull/2","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/sdelmas%2FSREGym/issues/2","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/2/packages"}},{"old_version":"3.8.4","new_version":"3.14.3","update_type":"minor","path":null,"pr_created_at":"2026-09-17T23:24:37.000Z","version_change":"3.8.4 → 3.14.3","issue":{"uuid":"5493704562","node_id":"PR_kwDONmOZWc8AAAABEAY7cg","number":3,"state":"open","title":"Bump the pip group across 1 directory with 7 updates","user":"dependabot[bot]","labels":["dependencies","python"],"assignees":[],"locked":false,"comments_count":4,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-17T23:24:37.000Z","updated_at":"2026-09-17T23:24:46.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","group_name":"pip","update_count":7,"packages":[{"name":"aiohttp","old_version":"3.8.4","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"cryptography","old_version":"41.0.1","new_version":"50.0.0","repository_url":"https://github.com/pyca/cryptography"},{"name":"httplib2","old_version":"0.22.0","new_version":"0.32.0","repository_url":"https://github.com/httplib2/httplib2"},{"name":"langchain","old_version":"0.0.189","new_version":"1.3.9","repository_url":"https://github.com/langchain-ai/langchain"},{"name":"nltk","old_version":"3.8.1","new_version":"3.10.3","repository_url":"https://github.com/nltk/nltk"},{"name":"pillow","old_version":"9.5.0","new_version":"12.3.0","repository_url":"https://github.com/python-pillow/Pillow"},{"name":"soupsieve","old_version":"2.4.1","new_version":"2.9","repository_url":"https://github.com/facelessuser/soupsieve"}],"path":null,"ecosystem":"pip"},"body":"Bumps the pip group with 7 updates in the /document-processor directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [aiohttp](https://github.com/aio-libs/aiohttp) | `3.8.4` | `3.14.3` |\n| [cryptography](https://github.com/pyca/cryptography) | `41.0.1` | `50.0.0` |\n| [httplib2](https://github.com/httplib2/httplib2) | `0.22.0` | `0.32.0` |\n| [langchain](https://github.com/langchain-ai/langchain) | `0.0.189` | `1.3.9` |\n| [nltk](https://github.com/nltk/nltk) | `3.8.1` | `3.10.3` |\n| [pillow](https://github.com/python-pillow/Pillow) | `9.5.0` | `12.3.0` |\n| [soupsieve](https://github.com/facelessuser/soupsieve) | `2.4.1` | `2.9` |\n\n\nUpdates `aiohttp` from 3.8.4 to 3.14.3\nUpdates `cryptography` from 41.0.1 to 50.0.0\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst\"\u003ecryptography's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e50.0.0 - 2026-07-31\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003e\n* **SECURITY ISSUE**:\n  :func:`~cryptography.hazmat.primitives.serialization.pkcs7.pkcs7_decrypt_der`\n  and its PEM and S/MIME variants no longer expose distinguishable errors or\n  timing when unwrapping a ``RecipientInfo``'s ``encryptedKey``, which could\n  act as a Bleichenbacher oracle for callers that decrypt untrusted messages.\n  A random key is now substituted on failure, as described in :rfc:`3218`.\n  Credit to **@X1AOxiang** for reporting the issue. **CVE-2026-69247**\n* Deprecated Diffie-Hellman key exchange over finite fields (FFDH).\n  Everything FFDH is deprecated, including the types in\n  ``cryptography.hazmat.primitives.asymmetric.dh`` and loading FFDH keys or\n  parameters with the key loading APIs. Users should migrate to a more\n  modern key exchange algorithm.\n* Added ``xof()`` class methods to\n  :class:`~cryptography.hazmat.primitives.hashes.SHAKE128` and\n  :class:`~cryptography.hazmat.primitives.hashes.SHAKE256` for constructing\n  algorithm instances configured for use with\n  :class:`~cryptography.hazmat.primitives.hashes.XOFHash`.\n* The :mod:`X.509 verification \u0026lt;cryptography.x509.verification\u0026gt;` APIs are now\n  considered stable and are subject to our API stability policy.\n* Added the :doc:`/cobblestone` recipe, an implementation of the\n  Cobblestone-128 and Cobblestone-256 instantiations of the `C2SP\n  chunked-encryption specification\n  \u0026lt;https://c2sp.org/chunked-encryption\u0026gt;`_ for streaming authenticated\n  encryption of large messages.\n* Parsing a Signed Certificate Timestamp list now rejects encodings that\n  carry trailing bytes after the list or after an individual SCT, instead of\n  silently ignoring them.\n* Added support for using :class:`~cryptography.x509.Name` as a field type in\n  the :doc:`/hazmat/asn1/index` module.\n* Loading a public key or an EC private key now rejects DER where the\n  ``subjectPublicKey`` (or EC ``publicKey``) ``BIT STRING`` declares a non-zero\n  number of unused bits, instead of silently ignoring it.\n* Parsing a CRL entry's ``InvalidityDate`` extension now rejects a\n  ``GeneralizedTime`` that carries fractional seconds or another non-DER form,\n  matching the strict encoding already required for every other X.509 time\n  field.\n* :func:`~cryptography.x509.ocsp.load_der_ocsp_request` and\n  :func:`~cryptography.x509.ocsp.load_der_ocsp_response` now reject a request\n  or response whose ``version`` field is not ``v1``, the only version defined\n  by RFC 6960, matching the version validation already performed when loading\n  certificates, CSRs and CRLs.\n* :class:`~cryptography.hazmat.primitives.hashes.XOFHash` is now supported\n  when building against AWS-LC.\n* HMAC (and therefore PBKDF2-HMAC) with SHA-3 hashes is now supported when\n  building against AWS-LC.\n* Diffie-Hellman (:doc:`/hazmat/primitives/asymmetric/dh`) is now supported\n  when building against AWS-LC.\n\u0026lt;/tr\u0026gt;\u0026lt;/table\u0026gt; \n\u003c/code\u003e\u003c/pre\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/dcb7050b807b00392fa9fe2eac7cb362fcf355cc\"\u003e\u003ccode\u003edcb7050\u003c/code\u003e\u003c/a\u003e Prepare for 50.0.0 release (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15372\"\u003e#15372\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/53fccd93413a8d7f07d6d8999681f27b75cffa3f\"\u003e\u003ccode\u003e53fccd9\u003c/code\u003e\u003c/a\u003e Don't leak how PKCS#7 encryptedKey decryption failed (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15369\"\u003e#15369\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/d472f978470fbefa521b86d98b2ecccbbb4d1dd8\"\u003e\u003ccode\u003ed472f97\u003c/code\u003e\u003c/a\u003e Add \u003ccode\u003efrom __future__ import annotations\u003c/code\u003e to all src/ Python files (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15371\"\u003e#15371\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/908773d53829fb1466c6db364b31321c3cd8eb9a\"\u003e\u003ccode\u003e908773d\u003c/code\u003e\u003c/a\u003e Bump downstream dependencies in CI (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15368\"\u003e#15368\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/2cc07cc948948211899bcb0cddd1fddf86e95812\"\u003e\u003ccode\u003e2cc07cc\u003c/code\u003e\u003c/a\u003e Bump BoringSSL, OpenSSL, AWS-LC in CI (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15367\"\u003e#15367\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/c94ede9f040fa44942f7139772603419000acf66\"\u003e\u003ccode\u003ec94ede9\u003c/code\u003e\u003c/a\u003e chore(deps): bump ruff from 0.16.0 to 0.16.1 (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15366\"\u003e#15366\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/67a8308dc9ea4cce6056e0f1438f903c208c3f35\"\u003e\u003ccode\u003e67a8308\u003c/code\u003e\u003c/a\u003e chore(deps): bump virtualenv from 21.7.0 to 21.7.1 (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15365\"\u003e#15365\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/95018ffcdbbc510fd92fc872e3a3e80aa6e58596\"\u003e\u003ccode\u003e95018ff\u003c/code\u003e\u003c/a\u003e Release the GIL in one-shot AEAD encrypt/decrypt (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15361\"\u003e#15361\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/6954733eaf55a0074abf88f06f7242dfca3a5d02\"\u003e\u003ccode\u003e6954733\u003c/code\u003e\u003c/a\u003e Release the GIL during DH and DSA parameter generation (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15364\"\u003e#15364\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/6893b94c33e948f6240082461424cfb5da2dacc6\"\u003e\u003ccode\u003e6893b94\u003c/code\u003e\u003c/a\u003e Import _serialization instead of serialization in x509/extensions (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15363\"\u003e#15363\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/pyca/cryptography/compare/41.0.1...50.0.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `httplib2` from 0.22.0 to 0.32.0\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/httplib2/httplib2/blob/master/CHANGELOG\"\u003ehttplib2's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e0.32.0\u003c/p\u003e\n\u003cp\u003ePython support 3.8+ only\u003c/p\u003e\n\u003cp\u003edecompression limited by size and ratio\u003c/p\u003e\n\u003cp\u003edecoder foundation to support more compression algorithms\u003c/p\u003e\n\u003cp\u003e0.31.2\u003c/p\u003e\n\u003cp\u003ebuild(deps): pp.DelimitedList (camel case) only available in pyparsing\u0026gt;=3.1\n\u003ca href=\"https://redirect.github.com/httplib2/httplib2/issues/255\"\u003ehttplib2/httplib2#255\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eDO NOT use 0.31.1\u003c/p\u003e\n\u003cp\u003e0.31.1\u003c/p\u003e\n\u003cp\u003eauth: use pyparsing v3 PEP8-compliant method names\n\u003ca href=\"https://redirect.github.com/httplib2/httplib2/pull/253\"\u003ehttplib2/httplib2#253\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e0.31.0\u003c/p\u003e\n\u003cp\u003ehttps: avoid costly load_verify_locations when SSL certificate validation is disabled\n\u003ca href=\"https://redirect.github.com/httplib2/httplib2/pull/249\"\u003ehttplib2/httplib2#249\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e0.30.2\u003c/p\u003e\n\u003cp\u003eNo changes in library. Fix automatic pypi release from CI.\u003c/p\u003e\n\u003cp\u003e0.30.1\u003c/p\u003e\n\u003cp\u003erestore socks proxy support, was broken in 0.30.0\n\u003ca href=\"https://redirect.github.com/httplib2/httplib2/issues/251\"\u003ehttplib2/httplib2#251\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e0.30.0\u003c/p\u003e\n\u003cp\u003eBREAKING CHANGE! Python support 3.7+ only\u003c/p\u003e\n\u003cp\u003ehttps: Do not rely on ssl.PROTOCOL_TLS, which has been deprecated in Python3.10\n\u003ca href=\"https://redirect.github.com/httplib2/httplib2/pull/243\"\u003ehttplib2/httplib2#243\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/httplib2/httplib2/commit/ba9bf505cd899f522f2bb58ca608444adf49afc1\"\u003e\u003ccode\u003eba9bf50\u003c/code\u003e\u003c/a\u003e v0.32.0 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/httplib2/httplib2/commit/87581ad6cf752fe3da2090c59058261d2d00a427\"\u003e\u003ccode\u003e87581ad\u003c/code\u003e\u003c/a\u003e decompression limited by size and ratio; require python 3.8+\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/httplib2/httplib2/commit/a99a11fba8d5fa3bb9c47827e5cbfd641dfb88d3\"\u003e\u003ccode\u003ea99a11f\u003c/code\u003e\u003c/a\u003e v0.31.2 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/httplib2/httplib2/commit/370010a12ef4b97ebeeac59f52d071de7bc3faa8\"\u003e\u003ccode\u003e370010a\u003c/code\u003e\u003c/a\u003e dep-compat: pp.DelimitedList (camel case) only available in pyparsing\u0026gt;=3.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/httplib2/httplib2/commit/6d2ea322d53a03d058cd8e63c12871cdd1127ca9\"\u003e\u003ccode\u003e6d2ea32\u003c/code\u003e\u003c/a\u003e v0.31.1 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/httplib2/httplib2/commit/d1b0ce329667f0b0047381c089e53ea1055f2fca\"\u003e\u003ccode\u003ed1b0ce3\u003c/code\u003e\u003c/a\u003e auth: use pyparsing v3 PEP8-compliant method names\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/httplib2/httplib2/commit/3288ba77ccb1924a6a79350f300ebb84140ec064\"\u003e\u003ccode\u003e3288ba7\u003c/code\u003e\u003c/a\u003e chore: harden publishing. use github attestations\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/httplib2/httplib2/commit/26cfea5d07a5817cf214d9978c856c91abf4e078\"\u003e\u003ccode\u003e26cfea5\u003c/code\u003e\u003c/a\u003e v0.31.0 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/httplib2/httplib2/commit/cbd3d21004374997167d9b8ab36b4ec211881a57\"\u003e\u003ccode\u003ecbd3d21\u003c/code\u003e\u003c/a\u003e chore: CI use trusted publishing\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/httplib2/httplib2/commit/147d7d5d00b4cd383dbdda839089237aa0c2a836\"\u003e\u003ccode\u003e147d7d5\u003c/code\u003e\u003c/a\u003e https: avoid costly load_verify_locations when SSL certificate validation is ...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/httplib2/httplib2/compare/v0.22.0...v0.32.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `langchain` from 0.0.189 to 1.3.9\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/langchain-ai/langchain/releases\"\u003elangchain's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003elangchain==1.3.9\u003c/h2\u003e\n\u003cp\u003eChanges since langchain==1.3.8\u003c/p\u003e\n\u003cp\u003erelease(anthropic): 1.4.6 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38105\"\u003e#38105\u003c/a\u003e)\nrelease(langchain): 1.3.9 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38104\"\u003e#38104\u003c/a\u003e)\nfix(langchain,anthropic): confine file-search results and tighten anthropic \u003ccode\u003eallowed_prefixes\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38106\"\u003e#38106\u003c/a\u003e)\u003c/p\u003e\n\u003ch2\u003elangchain==1.3.8\u003c/h2\u003e\n\u003cp\u003eChanges since langchain==1.3.7\u003c/p\u003e\n\u003cp\u003erelease(langchain): 1.3.8 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38096\"\u003e#38096\u003c/a\u003e)\nstyle(core,langchain,langchain-classic,partners): replace double backticks in docstrings (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38095\"\u003e#38095\u003c/a\u003e)\nrelease(core): 1.4.6 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38061\"\u003e#38061\u003c/a\u003e)\nchore(langchain): add overloads to \u003ccode\u003ecreate_agent\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/34309\"\u003e#34309\u003c/a\u003e)\nchore(infra): bump mypy to 2.1 and unify type-check config across the monorepo (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/36470\"\u003e#36470\u003c/a\u003e)\nfix(langchain): support async middleware decorator typing (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/34584\"\u003e#34584\u003c/a\u003e)\nfix(langchain): tighten structured output model fallbacks (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38042\"\u003e#38042\u003c/a\u003e)\nrelease(anthropic): 1.4.5 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38036\"\u003e#38036\u003c/a\u003e)\nhotfix(core): bump lockfile(s) (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38032\"\u003e#38032\u003c/a\u003e)\nrefactor(langchain): refactor \u003ccode\u003etest_create_agent_tool_validation\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/34443\"\u003e#34443\u003c/a\u003e)\u003c/p\u003e\n\u003ch2\u003elangchain==1.3.7\u003c/h2\u003e\n\u003cp\u003eChanges since langchain==1.3.6\u003c/p\u003e\n\u003cp\u003erelease(langchain): 1.3.7 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38024\"\u003e#38024\u003c/a\u003e)\nstyle(langchain): add ruff rules ARG (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/34435\"\u003e#34435\u003c/a\u003e)\nfeat(langchain): add \u003ccode\u003eProviderToolSearchMiddleware\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/37969\"\u003e#37969\u003c/a\u003e)\nchore(langchain): activate mypy \u003ccode\u003ewarn_return_any\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/34249\"\u003e#34249\u003c/a\u003e)\ntest(langchain): mark legacy trigger view for 2.0 removal (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38002\"\u003e#38002\u003c/a\u003e)\u003c/p\u003e\n\u003ch2\u003elangchain==1.3.6\u003c/h2\u003e\n\u003cp\u003eChanges since langchain==1.3.5\u003c/p\u003e\n\u003cp\u003erelease(langchain): 1.3.6 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38001\"\u003e#38001\u003c/a\u003e)\nfix(langchain): preserve summarization trigger compatibility (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38000\"\u003e#38000\u003c/a\u003e)\u003c/p\u003e\n\u003ch2\u003elangchain==1.3.5\u003c/h2\u003e\n\u003cp\u003eChanges since langchain==1.3.4\u003c/p\u003e\n\u003cp\u003erelease(langchain): 1.3.5 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/37998\"\u003e#37998\u003c/a\u003e)\nfeat(langchain): port AND-capable trigger conditions to \u003ccode\u003eSummarizationMiddleware\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/34576\"\u003e#34576\u003c/a\u003e)\nhotfix(openai): min core dep (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/37990\"\u003e#37990\u003c/a\u003e)\nfeat(openai): support \u003ccode\u003eapply_patch\u003c/code\u003e built-in tool (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/37157\"\u003e#37157\u003c/a\u003e)\nchore: bump pyarrow from 21.0.0 to 23.0.1 in /libs/langchain_v1 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/37930\"\u003e#37930\u003c/a\u003e)\nchore: bump dependencies  (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/37892\"\u003e#37892\u003c/a\u003e)\nchore: bump aiohttp from 3.13.4 to 3.14.0 in /libs/langchain_v1 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/37888\"\u003e#37888\u003c/a\u003e)\u003c/p\u003e\n\u003ch2\u003elangchain-openai==1.3.5\u003c/h2\u003e\n\u003cp\u003eChanges since langchain-openai==1.3.4\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/3bfb6a33e788aaca1626a7c09cbdbdbef6977012\"\u003e\u003ccode\u003e3bfb6a3\u003c/code\u003e\u003c/a\u003e release(langchain): 1.3.9 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38104\"\u003e#38104\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/dcaf7795a3e6590af55c3ff7bda6add6355e9ea6\"\u003e\u003ccode\u003edcaf779\u003c/code\u003e\u003c/a\u003e fix(langchain,anthropic): confine file-search results and tighten anthropic `...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/0392b6bae4bdfc0b7ed5aeb2e9e414bbb7ea643b\"\u003e\u003ccode\u003e0392b6b\u003c/code\u003e\u003c/a\u003e fix(core): fix Pydantic v1 support in tools/runnable (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/33698\"\u003e#33698\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/f6d63bc9f344b2949e91a6904d301553376b4f10\"\u003e\u003ccode\u003ef6d63bc\u003c/code\u003e\u003c/a\u003e release(langchain): 1.3.8 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38096\"\u003e#38096\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/5d20596d73789020f53c622b22c0a9893ba09606\"\u003e\u003ccode\u003e5d20596\u003c/code\u003e\u003c/a\u003e style(core,langchain,langchain-classic,partners): replace double backticks in...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/fb55c6660a2ac26038a64dac1534048294bc51ab\"\u003e\u003ccode\u003efb55c66\u003c/code\u003e\u003c/a\u003e chore: bump langsmith from 0.8.9 to 0.8.14 in /libs/partners/huggingface (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38\"\u003e#38\u003c/a\u003e...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/51daae5c139712f6f1347b5a801f672680ba1eba\"\u003e\u003ccode\u003e51daae5\u003c/code\u003e\u003c/a\u003e chore: bump langsmith from 0.8.9 to 0.8.14 in /libs/partners/chroma (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38092\"\u003e#38092\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/70e9579e433043321fb8e93a8a51770c946363d0\"\u003e\u003ccode\u003e70e9579\u003c/code\u003e\u003c/a\u003e chore: bump langsmith from 0.8.9 to 0.8.14 in /libs/partners/fireworks (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38093\"\u003e#38093\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/6c0e9af3246e3bbf98838e4b9ec563ad563dd748\"\u003e\u003ccode\u003e6c0e9af\u003c/code\u003e\u003c/a\u003e chore: bump langsmith from 0.8.9 to 0.8.14 in /libs/partners/xai (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38094\"\u003e#38094\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/222dc846e0e965a0d6764d772226590eec14b917\"\u003e\u003ccode\u003e222dc84\u003c/code\u003e\u003c/a\u003e ci(infra): clarify early PR auto-close guidance (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38090\"\u003e#38090\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/langchain-ai/langchain/compare/v0.0.189...langchain==1.3.9\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `nltk` from 3.8.1 to 3.10.3\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nltk/nltk/releases\"\u003enltk's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev3.10.3\u003c/h2\u003e\n\u003cp\u003eVersion 3.10.3 2026-08-12\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003edocs: wrap Chat-80 HOWTO output\u003c/li\u003e\n\u003cli\u003eSandbox Stanford JAR execution to nltk_data directories\u003c/li\u003e\n\u003cli\u003eHarden path-traversal / file-I/O sandbox: close write-side symlink TOCTOU + shared-temp squat, lock the cluster with a living audit (CWE-22/59/377)\u003c/li\u003e\n\u003cli\u003eExtend algorithmic-complexity DoS hardening: repo-wide sweep + two-string distances (CWE-407/CWE-400)\u003c/li\u003e\n\u003cli\u003eBound unbounded-work DoS in parsers and grammar transforms (CWE-407/674/835)\u003c/li\u003e\n\u003cli\u003efix(security): sandbox MaltParser's Java execution (CVE-2026-12252, CVE-2026-12841)\u003c/li\u003e\n\u003cli\u003efix(security): trust the system temp dir only when it is private (CWE-377/CWE-378)\u003c/li\u003e\n\u003cli\u003efix(security): validate corpus-reader roots against the data sandbox (CWE-73)\u003c/li\u003e\n\u003cli\u003efix(security): validate per-call java() options and replace the -XX:/-D allowlist with a minimal one (CWE-88)\u003c/li\u003e\n\u003cli\u003eAdditional security hardening (CWE-407, CWE-426, CWE-427, CWE-502, CWE-59, CWE-776, CWE-918)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThanks to the following contributors to 3.10.3: Mohammad Favas S, leduckhuong, Ziyu Lin, dougtrainer28-cmyk, Chaitanya Kadian, 0xRenSec, Arpit Jain, Jace, nguyencanhthuong, Liling Tan, medimedi, Eric Kafe.\u003c/p\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSandbox Stanford JAR execution to nltk_data directories by \u003ca href=\"https://github.com/ekaf\"\u003e\u003ccode\u003e@​ekaf\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nltk/nltk/pull/3743\"\u003enltk/nltk#3743\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003edocs: wrap Chat-80 HOWTO output by \u003ca href=\"https://github.com/medisean\"\u003e\u003ccode\u003e@​medisean\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nltk/nltk/pull/3741\"\u003enltk/nltk#3741\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eci: sandboxed-open guard + stabilize security tests across platforms/pythons (\u003ca href=\"https://redirect.github.com/nltk/nltk/issues/3740\"\u003e#3740\u003c/a\u003e) by \u003ca href=\"https://github.com/alvations\"\u003e\u003ccode\u003e@​alvations\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nltk/nltk/pull/3744\"\u003enltk/nltk#3744\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePrepare release 3.10.3 by \u003ca href=\"https://github.com/ekaf\"\u003e\u003ccode\u003e@​ekaf\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nltk/nltk/pull/3745\"\u003enltk/nltk#3745\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/medisean\"\u003e\u003ccode\u003e@​medisean\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/nltk/nltk/pull/3741\"\u003enltk/nltk#3741\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/nltk/nltk/compare/v3.10.2...v3.10.3\"\u003ehttps://github.com/nltk/nltk/compare/v3.10.2...v3.10.3\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev3.10.3-rc1\u003c/h2\u003e\n\u003cp\u003eVersion 3.10.3 2026-08-12\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003edocs: wrap Chat-80 HOWTO output\u003c/li\u003e\n\u003cli\u003eSandbox Stanford JAR execution to nltk_data directories\u003c/li\u003e\n\u003cli\u003eHarden path-traversal / file-I/O sandbox: close write-side symlink TOCTOU + shared-temp squat, lock the cluster with a living audit (CWE-22/59/377)\u003c/li\u003e\n\u003cli\u003eExtend algorithmic-complexity DoS hardening: repo-wide sweep + two-string distances (CWE-407/CWE-400)\u003c/li\u003e\n\u003cli\u003eBound unbounded-work DoS in parsers and grammar transforms (CWE-407/674/835)\u003c/li\u003e\n\u003cli\u003efix(security): sandbox MaltParser's Java execution (CVE-2026-12252, CVE-2026-12841)\u003c/li\u003e\n\u003cli\u003efix(security): trust the system temp dir only when it is private (CWE-377/CWE-378)\u003c/li\u003e\n\u003cli\u003efix(security): validate corpus-reader roots against the data sandbox (CWE-73)\u003c/li\u003e\n\u003cli\u003efix(security): validate per-call java() options and replace the -XX:/-D allowlist with a minimal one (CWE-88)\u003c/li\u003e\n\u003cli\u003eAdditional security hardening (CWE-407, CWE-426, CWE-427, CWE-502, CWE-59, CWE-776, CWE-918)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThanks to the following contributors to 3.10.3: Mohammad Favas S, leduckhuong, Ziyu Lin, dougtrainer28-cmyk, Chaitanya Kadian, 0xRenSec, Arpit Jain, Jace, nguyencanhthuong, Liling Tan, medimedi, Eric Kafe.\u003c/p\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSandbox Stanford JAR execution to nltk_data directories by \u003ca href=\"https://github.com/ekaf\"\u003e\u003ccode\u003e@​ekaf\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nltk/nltk/pull/3743\"\u003enltk/nltk#3743\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003edocs: wrap Chat-80 HOWTO output by \u003ca href=\"https://github.com/medisean\"\u003e\u003ccode\u003e@​medisean\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/nltk/nltk/pull/3741\"\u003enltk/nltk#3741\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/nltk/nltk/blob/develop/ChangeLog\"\u003enltk's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003eVersion 3.10.3 2026-08-12\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003edocs: wrap Chat-80 HOWTO output\u003c/li\u003e\n\u003cli\u003eSandbox Stanford JAR execution to nltk_data directories\u003c/li\u003e\n\u003cli\u003eHarden path-traversal / file-I/O sandbox: close write-side symlink TOCTOU + shared-temp squat, lock the cluster with a living audit (CWE-22/59/377)\u003c/li\u003e\n\u003cli\u003eExtend algorithmic-complexity DoS hardening: repo-wide sweep + two-string distances (CWE-407/CWE-400)\u003c/li\u003e\n\u003cli\u003eBound unbounded-work DoS in parsers and grammar transforms (CWE-407/674/835)\u003c/li\u003e\n\u003cli\u003efix(security): sandbox MaltParser's Java execution (CVE-2026-12252, CVE-2026-12841)\u003c/li\u003e\n\u003cli\u003efix(security): trust the system temp dir only when it is private (CWE-377/CWE-378)\u003c/li\u003e\n\u003cli\u003efix(security): validate corpus-reader roots against the data sandbox (CWE-73)\u003c/li\u003e\n\u003cli\u003efix(security): validate per-call java() options and replace the -XX:/-D allowlist with a minimal one (CWE-88)\u003c/li\u003e\n\u003cli\u003eAdditional security hardening (CWE-407, CWE-426, CWE-427, CWE-502, CWE-59, CWE-776, CWE-918)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThanks to the following contributors to 3.10.3: Mohammad Favas S, leduckhuong, Ziyu Lin, dougtrainer28-cmyk, Chaitanya Kadian, 0xRenSec, Arpit Jain, Jace, nguyencanhthuong, Liling Tan, medimedi, Eric Kafe.\u003c/p\u003e\n\u003cp\u003eVersion 3.10.2 2026-08-05\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eRemove inisec.py and document PYTHONSAFEPATH instead\u003c/li\u003e\n\u003cli\u003eSkip draft step in release workflow\u003c/li\u003e\n\u003cli\u003eFix symlink escape in FramenetCorpusReader (CWE-59)\u003c/li\u003e\n\u003cli\u003eGuard tempfile.gettempdir() when building pathsec allowed roots\u003c/li\u003e\n\u003cli\u003eadd tests for transitive_closure\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThanks to the following contributors to 3.10.2:\nLitesh Ghute, Eric Kafe, Evan Kiefer, tarann26 and Rav Singh Chandan\u003c/p\u003e\n\u003cp\u003eVersion 3.10.1 2026-07-29\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eExpand \u003ccode\u003e~\u003c/code\u003e in env-var paths\u003c/li\u003e\n\u003cli\u003eValidate types after WordNet app pickle deserialization\u003c/li\u003e\n\u003cli\u003eFix uncontrolled search path in HunposTagger\u003c/li\u003e\n\u003cli\u003eUse exact thirds in \u003ccode\u003emasi_distance\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eAvoid retaining bllip import exceptions\u003c/li\u003e\n\u003cli\u003eFix \u003ccode\u003eword_tokenize\u003c/code\u003e: pad opening single quote before multi-letter words.\u003c/li\u003e\n\u003cli\u003eImplement \u003ccode\u003eTree.pformat_latex_forest\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003ePrevent module hijacking in inline imports.\u003c/li\u003e\n\u003cli\u003eFix ReDoS in TweetTokenizer URL and email regexes.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThanks to the following contributors to 3.10.1:\nAbhinav, Litesh Ghute, Eric Kafe, Eryk Kaźmierczak, Selim C.,\nMuhtasim Munif Fahim, Triniti K., and Tom Y. Mitich.\u003c/p\u003e\n\u003cp\u003eVersion 3.10.0 2026-06-11\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eEnforce the stricter \u003ccode\u003enltk.pathsec\u003c/code\u003e security policy by default\u003c/li\u003e\n\u003cli\u003eDocument the new security model and migration guidance\u003c/li\u003e\n\u003cli\u003eHarden resource loading against path traversal and SSRF/DNS-rebinding\u003c/li\u003e\n\u003cli\u003eHarden downloader path handling and block XML entity expansion\u003c/li\u003e\n\u003cli\u003eClose remaining corpus-reader security edge cases\u003c/li\u003e\n\u003cli\u003eReplace unsafe \u003ccode\u003eexec()\u003c/code\u003e usage in the utility CLI\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nltk/nltk/commit/303f6e2ba8e4548a5f54fd65d86bb5c9a949f1db\"\u003e\u003ccode\u003e303f6e2\u003c/code\u003e\u003c/a\u003e Prepare release 3.10.3 (\u003ca href=\"https://redirect.github.com/nltk/nltk/issues/3745\"\u003e#3745\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nltk/nltk/commit/cf2aaacc3d99533a73e86709c1d839966ea25e17\"\u003e\u003ccode\u003ecf2aaac\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/nltk/nltk/issues/3744\"\u003e#3744\u003c/a\u003e from alvations/ci-guard-open\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nltk/nltk/commit/6cd8320cee54d4fc271610e744f71d44cb367dda\"\u003e\u003ccode\u003e6cd8320\u003c/code\u003e\u003c/a\u003e test: robustness on Python 3.14 / 3.14t CI (UnicodeDecodeError + timing flake)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nltk/nltk/commit/e965330e017d8180843c4a12b91bcfadd5d4e489\"\u003e\u003ccode\u003ee965330\u003c/code\u003e\u003c/a\u003e fix: perceptron save_to_json breaks on Windows (os.open can't fd-open a direc...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nltk/nltk/commit/df1bb4c5742c8943205e4564a7c03e1992cf4f4d\"\u003e\u003ccode\u003edf1bb4c\u003c/code\u003e\u003c/a\u003e test: make pathsec security tests platform-independent (fix Linux/Windows CI)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nltk/nltk/commit/0e5c7be3793cf826039a2048846138e58f864553\"\u003e\u003ccode\u003e0e5c7be\u003c/code\u003e\u003c/a\u003e ci: guard against un-sandboxed open() in sandbox-sensitive modules (\u003ca href=\"https://redirect.github.com/nltk/nltk/issues/3740\"\u003e#3740\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nltk/nltk/commit/50178263a0787a7850e66f3e85775338669f101a\"\u003e\u003ccode\u003e5017826\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nltk/nltk/commit/40d0f062649022f7f36afed4a2ca3980f574aae9\"\u003e\u003ccode\u003e40d0f06\u003c/code\u003e\u003c/a\u003e Triple-check hardening: perceptron TOCTOU squat, pathsec fd-leak, bcp47 entit...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nltk/nltk/commit/483c5fe650542ceaa2b45e8565f72e878834376f\"\u003e\u003ccode\u003e483c5fe\u003c/code\u003e\u003c/a\u003e Harden path-traversal / file-I/O sandbox: close write-side symlink TOCTOU + s...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/nltk/nltk/commit/722778fd9ff987da3cf5ff6e442ac43fed1637b0\"\u003e\u003ccode\u003e722778f\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/nltk/nltk/compare/3.8.1...v3.10.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `pillow` from 9.5.0 to 12.3.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/python-pillow/Pillow/releases\"\u003epillow's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e12.3.0\u003c/h2\u003e\n\u003cp\u003e\u003ca href=\"https://pillow.readthedocs.io/en/stable/releasenotes/12.3.0.html\"\u003ehttps://pillow.readthedocs.io/en/stable/releasenotes/12.3.0.html\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eRemovals\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRemove non-image ImageCms modes \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9697\"\u003e#9697\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eDocumentation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd release notes for SBOM and performance improvements \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9747\"\u003e#9747\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdd security release notes \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9741\"\u003e#9741\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdd release notes for Python 3.15 beta wheels \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9696\"\u003e#9696\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eImageFont can also be used with ImageText \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9597\"\u003e#9597\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdditional guidelines for security reports \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9659\"\u003e#9659\u003c/a\u003e [\u003ca href=\"https://github.com/wiredfool\"\u003e\u003ccode\u003e@​wiredfool\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eFixed typo \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9636\"\u003e#9636\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdded CVEs to 12.2.0 release notes \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9591\"\u003e#9591\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eRevise development support information in README \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9583\"\u003e#9583\u003c/a\u003e [\u003ca href=\"https://github.com/aclark4life\"\u003e\u003ccode\u003e@​aclark4life\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdd INCIDENT_RESPONSE.md \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9555\"\u003e#9555\u003c/a\u003e [\u003ca href=\"https://github.com/aclark4life\"\u003e\u003ccode\u003e@​aclark4life\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdd STRIDE threat model to security docs \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9562\"\u003e#9562\u003c/a\u003e [\u003ca href=\"https://github.com/aclark4life\"\u003e\u003ccode\u003e@​aclark4life\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdd CVEs to 12.2.0 release notes \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9556\"\u003e#9556\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate README with revised security policy \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9553\"\u003e#9553\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate security policy \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9552\"\u003e#9552\u003c/a\u003e [\u003ca href=\"https://github.com/aclark4life\"\u003e\u003ccode\u003e@​aclark4life\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate macOS tested Python versions \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9534\"\u003e#9534\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eDependencies\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate dependency harfbuzz to v14.2.1 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9720\"\u003e#9720\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency mypy to v2 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9653\"\u003e#9653\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency cibuildwheel to v4 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9665\"\u003e#9665\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate github-actions \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9655\"\u003e#9655\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency libavif to v1.4.2 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9652\"\u003e#9652\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency lcms2 to v2.19.1 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9651\"\u003e#9651\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency check-jsonschema to v0.37.2 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9650\"\u003e#9650\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate google/oss-fuzz digest to d872252 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9614\"\u003e#9614\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency lcms2 to v2.19 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9609\"\u003e#9609\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency libpng to v1.6.58 - autoclosed \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9608\"\u003e#9608\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency harfbuzz to v14 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9610\"\u003e#9610\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency mypy to v1.20.2 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9599\"\u003e#9599\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate github-actions \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9611\"\u003e#9611\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency cibuildwheel to v3.4.1 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9607\"\u003e#9607\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eMove dependency versions to single JSON and enable Renovate \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9559\"\u003e#9559\u003c/a\u003e [\u003ca href=\"https://github.com/hugovk\"\u003e\u003ccode\u003e@​hugovk\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdated raqm to 0.10.5 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9557\"\u003e#9557\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency cibuildwheel to v3.4.0 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9532\"\u003e#9532\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eTesting\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRemove matrix.os from benchmark \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9735\"\u003e#9735\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eRemove references to libavif patch \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9734\"\u003e#9734\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdd benchmark tests \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9654\"\u003e#9654\u003c/a\u003e [\u003ca href=\"https://github.com/akx\"\u003e\u003ccode\u003e@​akx\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUse reshape() instead of setting NumPy array shape directly \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9728\"\u003e#9728\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/python-pillow/Pillow/blob/main/CHANGES.rst\"\u003epillow's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003eChangelog (Pillow)\u003c/h1\u003e\n\u003ch2\u003e11.1.0 and newer\u003c/h2\u003e\n\u003cp\u003eSee GitHub Releases:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/releases\"\u003ehttps://github.com/python-pillow/Pillow/releases\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e11.0.0 (2024-10-15)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eUpdate licence to MIT-CMU \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/8460\"\u003e#8460\u003c/a\u003e\n[hugovk]\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eConditionally define ImageCms type hint to avoid requiring core \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/8197\"\u003e#8197\u003c/a\u003e\n[radarhere]\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eSupport writing LONG8 offsets in AppendingTiffWriter \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/8417\"\u003e#8417\u003c/a\u003e\n[radarhere]\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUse ImageFile.MAXBLOCK when saving TIFF images \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/8461\"\u003e#8461\u003c/a\u003e\n[radarhere]\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eDo not close provided file handles with libtiff when saving \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/8458\"\u003e#8458\u003c/a\u003e\n[radarhere]\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eSupport ImageFilter.BuiltinFilter for I;16* images \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/8438\"\u003e#8438\u003c/a\u003e\n[radarhere]\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUse ImagingCore.ptr instead of ImagingCore.id \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/8341\"\u003e#8341\u003c/a\u003e\n[homm, radarhere, hugovk]\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUpdated EPS mode when opening images without transparency \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/8281\"\u003e#8281\u003c/a\u003e\n[Yay295, radarhere]\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUse transparency when combining P frames from APNGs \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/8443\"\u003e#8443\u003c/a\u003e\n[radarhere]\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eSupport all resampling filters when resizing I;16* images \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/8422\"\u003e#8422\u003c/a\u003e\n[radarhere]\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFree memory on early return \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/8413\"\u003e#8413\u003c/a\u003e\n[radarhere]\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eCast int before potentially exceeding INT_MAX \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/8402\"\u003e#8402\u003c/a\u003e\n[radarhere]\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/bb1d8e8ab8d29048624d96e3ee53cecf7c13d13d\"\u003e\u003ccode\u003ebb1d8e8\u003c/code\u003e\u003c/a\u003e 12.3.0 version bump\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/e63fc481dc2e07e21d5403deafb8f1ed98a513af\"\u003e\u003ccode\u003ee63fc48\u003c/code\u003e\u003c/a\u003e Add release notes for SBOM and performance improvements (\u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9747\"\u003e#9747\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/13b701bbab291eec4bc87ea17ba06c94e5fe3054\"\u003e\u003ccode\u003e13b701b\u003c/code\u003e\u003c/a\u003e Add release notes for \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9679\"\u003e#9679\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/5564ca72fcd59d040e270af5dcf17a0d7161c364\"\u003e\u003ccode\u003e5564ca7\u003c/code\u003e\u003c/a\u003e List methods\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/a0920fd384f800b5d0ba3dd29ecdeae4f1d4043b\"\u003e\u003ccode\u003ea0920fd\u003c/code\u003e\u003c/a\u003e Speed up ImageChops operations (\u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9738\"\u003e#9738\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/07e9a6cd5336dc6cf8cae9165cd70cdd2b3e42fc\"\u003e\u003ccode\u003e07e9a6c\u003c/code\u003e\u003c/a\u003e Speed up \u003ccode\u003eImage.filter()\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9736\"\u003e#9736\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/a94578cf9649ea13e426cf7fb2b71b39ffc0dd50\"\u003e\u003ccode\u003ea94578c\u003c/code\u003e\u003c/a\u003e Speed up \u003ccode\u003eImage.getchannel()\u003c/code\u003e, \u003ccode\u003eImage.merge()\u003c/code\u003e, \u003ccode\u003eImage.putalpha()\u003c/code\u003e and `Image...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/53e02c43c919d149b2a154a5180079f9df18fbbb\"\u003e\u003ccode\u003e53e02c4\u003c/code\u003e\u003c/a\u003e Speed up \u003ccode\u003eImage.fill()\u003c/code\u003e, \u003ccode\u003eImage.linear_gradient()\u003c/code\u003e and `Image.radial_gradient...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/af037475be8634ba739744243164ba9e2c8346a6\"\u003e\u003ccode\u003eaf03747\u003c/code\u003e\u003c/a\u003e Speed up \u003ccode\u003eImage.resample()\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9739\"\u003e#9739\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/5c9ca56c3e5fba52b647809fbb0986c87e73a571\"\u003e\u003ccode\u003e5c9ca56\u003c/code\u003e\u003c/a\u003e Speed up \u003ccode\u003ealpha_composite\u003c/code\u003e, \u003ccode\u003ematrix\u003c/code\u003e, \u003ccode\u003enegative\u003c/code\u003e, \u003ccode\u003equantize\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9740\"\u003e#9740\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/python-pillow/Pillow/compare/9.5.0...12.3.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `soupsieve` from 2.4.1 to 2.9\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/facelessuser/soupsieve/releases\"\u003esoupsieve's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e2.9\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eNEW\u003c/strong\u003e: Drop Python 3.9 support.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eNEW\u003c/strong\u003e: Lazy compile selector patterns to improve initial import speed.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eFIX\u003c/strong\u003e: Correct \u003ccode\u003e:nth-child\u003c/code\u003e/\u003ccode\u003e:nth-of-type\u003c/code\u003e (and \u003ccode\u003e-last-\u003c/code\u003e variants) for \u003ccode\u003eAn+B\u003c/code\u003e values whose sequence steps onto\nindex 0 or onto the last child (e.g. \u003ccode\u003e:nth-child(2n-2)\u003c/code\u003e, \u003ccode\u003e:nth-child(n-1)\u003c/code\u003e, \u003ccode\u003e:nth-child(n+5)\u003c/code\u003e), which previously\nmatched the wrong elements or nothing at all (\u003ca href=\"https://github.com/gaoflow\"\u003e\u003ccode\u003e@​gaoflow\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eFIX\u003c/strong\u003e: More efficient CSS ID matching (\u003ca href=\"https://github.com/kaimandalic\"\u003e\u003ccode\u003e@​kaimandalic\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eFIX\u003c/strong\u003e: Fix inefficient trimming of comments and white space (\u003ca href=\"https://github.com/kaimandalic\"\u003e\u003ccode\u003e@​kaimandalic\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.8.4\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eFIX\u003c/strong\u003e: Fix another inefficient attribute pattern (\u003ca href=\"https://github.com/mauriceng98\"\u003e\u003ccode\u003e@​mauriceng98\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eFIX\u003c/strong\u003e: Limit total number of selectors processed in a pattern to prevent massive selector requests (\u003ca href=\"https://github.com/mauriceng98\"\u003e\u003ccode\u003e@​mauriceng98\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.8.3\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eFIX\u003c/strong\u003e: Fix inefficient attribute pattern.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.8.2\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eFIX\u003c/strong\u003e: Ensure custom selectors or namespace dictionaries reject non-string keys (\u003ca href=\"https://github.com/mundanevision20\"\u003e\u003ccode\u003e@​mundanevision20\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eFIX\u003c/strong\u003e: Fix handling of \u003ccode\u003e:in-range\u003c/code\u003e and \u003ccode\u003e:out-of-range\u003c/code\u003e with end of year weeks (\u003ca href=\"https://github.com/mundanevision20\"\u003e\u003ccode\u003e@​mundanevision20\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eFIX\u003c/strong\u003e: Fix a potential infinite loop in the pretty printing debug function (\u003ca href=\"https://github.com/mundanevision20\"\u003e\u003ccode\u003e@​mundanevision20\u003c/code\u003e\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.8.1\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eFIX\u003c/strong\u003e: Changes in tests to accommodate latest Python HTML parser changes.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.8\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eNEW\u003c/strong\u003e: Drop support for Python 3.8.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eNEW\u003c/strong\u003e: Add support for Python 3.14.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eNEW\u003c/strong\u003e: Deploy with PyPI's \u0026quot;Trusted Publisher\u0026quot;.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.7\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eNEW\u003c/strong\u003e: Add \u003ccode\u003e:open\u003c/code\u003e pseudo selector.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eNEW\u003c/strong\u003e: Add \u003ccode\u003e:muted\u003c/code\u003e pseudo selector.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eNEW\u003c/strong\u003e: Recognize the following pseudo selectors: \u003ccode\u003e:autofill\u003c/code\u003e, \u003ccode\u003e:buffering\u003c/code\u003e, \u003ccode\u003e:fullscreen\u003c/code\u003e, \u003ccode\u003e:picture-in-picture\u003c/code\u003e,\n\u003ccode\u003e:popover-open\u003c/code\u003e, \u003ccode\u003e:seeking\u003c/code\u003e, \u003ccode\u003e:stalled\u003c/code\u003e, and \u003ccode\u003e:volume-locked\u003c/code\u003e. These selectors, while recognized, will not match any\nelement as they require a live environment to check element states and browser states. This just prevents Soup Sieve\nfrom failing when any of these selectors are specified.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eNEW\u003c/strong\u003e: A number of existing pseudo-classes are no longer noted as experimental.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eFIX\u003c/strong\u003e: Typing fixes.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.6\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eNEW\u003c/strong\u003e: Add official support for Python 3.13.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eNEW\u003c/strong\u003e: Add support for \u003ccode\u003e\u0026amp;\u003c/code\u003e as scoping root per the CSS Nesting Module, Level 1. When \u003ccode\u003e\u0026amp;\u003c/code\u003e is used outside the\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/8763f914472fc83652babda708bed5c8ef287004\"\u003e\u003ccode\u003e8763f91\u003c/code\u003e\u003c/a\u003e Format changelog message\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/cf198fcddc9230f06ed39f974eba0ce076b85cda\"\u003e\u003ccode\u003ecf198fc\u003c/code\u003e\u003c/a\u003e Fix inefficient trimming of comments and white space\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/ce44e4996e6632871c18cdd7a7fb641be8ef34ef\"\u003e\u003ccode\u003ece44e49\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/751c57b2c7e978e206b94b7dba17f8e2af392e19\"\u003e\u003ccode\u003e751c57b\u003c/code\u003e\u003c/a\u003e Fix :nth-child/:nth-of-type matching for An+B index boundaries (\u003ca href=\"https://redirect.github.com/facelessuser/soupsieve/issues/297\"\u003e#297\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/08e9ede4dcfafef860155319ef5eb9708e75d10b\"\u003e\u003ccode\u003e08e9ede\u003c/code\u003e\u003c/a\u003e Drop Python 3.9\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/d6e68303a6c3e0e410530939b92955ba24a07a81\"\u003e\u003ccode\u003ed6e6830\u003c/code\u003e\u003c/a\u003e Rework selector mapping\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/d2d1581fe275f89cb2e792589fed770aeb9e99b3\"\u003e\u003ccode\u003ed2d1581\u003c/code\u003e\u003c/a\u003e Utilize property for accessing lazy regular expression pattern\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/b8701dec25c84a3910fd9a03222a3804fa119a1d\"\u003e\u003ccode\u003eb8701de\u003c/code\u003e\u003c/a\u003e Build patterns and regexes lazily in css_parser (\u003ca href=\"https://redirect.github.com/facelessuser/soupsieve/issues/296\"\u003e#296\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/28108ab805818c832d9568142a99844fd95a0d39\"\u003e\u003ccode\u003e28108ab\u003c/code\u003e\u003c/a\u003e Limit excessive selectors\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/facelessuser/soupsieve/commit/ef188721d6cc95641e99297b3a26ac17b7dfcfa7\"\u003e\u003ccode\u003eef18872\u003c/code\u003e\u003c/a\u003e Fix test for Windows\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/facelessuser/soupsieve/compare/2.4.1...2.9\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/black-da-bull/vector-admin/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/black-da-bull/vector-admin/pull/3","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/black-da-bull%2Fvector-admin/issues/3","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/3/packages"}},{"old_version":"3.12.14","new_version":"3.14.3","update_type":"minor","path":null,"pr_created_at":"2026-09-17T11:43:08.000Z","version_change":"3.12.14 → 3.14.3","issue":{"uuid":"5486867022","node_id":"PR_kwDOOhhJoc8AAAABD62WHw","number":26,"state":"open","title":"Bump the pip group across 2 directories with 8 updates","user":"dependabot[bot]","labels":["dependencies","python"],"assignees":[],"locked":false,"comments_count":10,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-17T11:43:08.000Z","updated_at":"2026-09-17T11:44:07.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","group_name":"pip","update_count":8,"packages":[{"name":"setuptools","old_version":"75.3.0","new_version":"83.0.0","repository_url":"https://github.com/pypa/setuptools"},{"name":"python-multipart","old_version":"0.0.20","new_version":"0.0.31","repository_url":"https://github.com/Kludex/python-multipart"},{"name":"pyjwt","old_version":"2.10.1","new_version":"2.13.0","repository_url":"https://github.com/jpadilla/pyjwt"},{"name":"aiohttp","old_version":"3.12.14","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"gitpython","old_version":"3.1.44","new_version":"3.1.59","repository_url":"https://github.com/gitpython-developers/GitPython"},{"name":"h2","old_version":"4.3.0","new_version":"4.4.1","repository_url":"https://github.com/python-hyper/h2"},{"name":"tornado","old_version":"6.5","new_version":"6.5.8","repository_url":"https://github.com/tornadoweb/tornado"}],"path":null,"ecosystem":"pip"},"body":"Bumps the pip group with 7 updates in the /backend directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [setuptools](https://github.com/pypa/setuptools) | `75.3.0` | `83.0.0` |\n| [python-multipart](https://github.com/Kludex/python-multipart) | `0.0.20` | `0.0.31` |\n| [pyjwt](https://github.com/jpadilla/pyjwt) | `2.10.1` | `2.13.0` |\n| [aiohttp](https://github.com/aio-libs/aiohttp) | `3.12.14` | `3.14.3` |\n| [gitpython](https://github.com/gitpython-developers/GitPython) | `3.1.44` | `3.1.59` |\n| [h2](https://github.com/python-hyper/h2) | `4.3.0` | `4.4.1` |\n| [tornado](https://github.com/tornadoweb/tornado) | `6.5` | `6.5.8` |\n\nBumps the pip group with 1 update in the /backend/sandbox/docker directory: [pillow](https://github.com/python-pillow/Pillow).\n\nUpdates `setuptools` from 75.3.0 to 83.0.0\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pypa/setuptools/blob/main/NEWS.rst\"\u003esetuptools's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003ev83.0.0\u003c/h1\u003e\n\u003ch2\u003eFeatures\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRequire Python 3.10 or later.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eBugfixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eMANIFEST.in\u003c/code\u003e matching (via \u003ccode\u003eFileList\u003c/code\u003e) is now insensitive to Unicode\nnormalization form. A pattern authored in one form (e.g. NFC, as typically\nsaved by editors) now matches a file whose name is stored on disk in another\n(e.g. NFD, as produced by macOS APFS/HFS+). Previously an \u003ccode\u003eexclude\u003c/code\u003e,\n\u003ccode\u003eglobal-exclude\u003c/code\u003e, \u003ccode\u003erecursive-exclude\u003c/code\u003e, or \u003ccode\u003eprune\u003c/code\u003e rule could silently\nfail to drop a non-ASCII-named file from the source distribution, publishing\nit despite the exclusion -- see GHSA-h35f-9h28-mq5c.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eDeprecations and Removals\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003epypa/distutils#334\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch1\u003ev82.0.1\u003c/h1\u003e\n\u003ch2\u003eBugfixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix the loading of \u003ccode\u003elauncher manifest.xml\u003c/code\u003e file. (\u003ca href=\"https://redirect.github.com/pypa/setuptools/issues/5047\"\u003e#5047\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eReplaced deprecated \u003ccode\u003ejson.__version__\u003c/code\u003e with fixture in tests. (\u003ca href=\"https://redirect.github.com/pypa/setuptools/issues/5186\"\u003e#5186\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eImproved Documentation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd advice about how to improve predictability when installing sdists. (\u003ca href=\"https://redirect.github.com/pypa/setuptools/issues/5168\"\u003e#5168\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eMisc\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://redirect.github.com/pypa/setuptools/issues/4941\"\u003e#4941\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/pypa/setuptools/issues/5157\"\u003e#5157\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/pypa/setuptools/issues/5169\"\u003e#5169\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/pypa/setuptools/issues/5175\"\u003e#5175\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003ev82.0.0\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/setuptools/commit/6519f728c6f23c992df81a5691ef7655184a20eb\"\u003e\u003ccode\u003e6519f72\u003c/code\u003e\u003c/a\u003e Bump version: 82.0.1 → 83.0.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/setuptools/commit/d1151b125b29a6ee1c7db860f7ee6c365d525b5f\"\u003e\u003ccode\u003ed1151b1\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/pypa/setuptools/issues/5250\"\u003e#5250\u003c/a\u003e from pypa/feature/distutils-d7633fbed\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/setuptools/commit/a2df31e6a741b0fe775969618fe6a3a3d032e900\"\u003e\u003ccode\u003ea2df31e\u003c/code\u003e\u003c/a\u003e Capture removal of dry_run parameter in changelog.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/setuptools/commit/00144dc3fb6d023fd81cdc26c380a012b084df9b\"\u003e\u003ccode\u003e00144dc\u003c/code\u003e\u003c/a\u003e Moved newsfragment to the release where it occurred.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/setuptools/commit/a4a5a2b160357be77626aa077ddd1d8ee53be50f\"\u003e\u003ccode\u003ea4a5a2b\u003c/code\u003e\u003c/a\u003e Add news fragment.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/setuptools/commit/77470c23c35031c9e37d7512694ac5ca52bfcaac\"\u003e\u003ccode\u003e77470c2\u003c/code\u003e\u003c/a\u003e Merge \u003ca href=\"https://github.com/pypa/distutils\"\u003ehttps://github.com/pypa/distutils\u003c/a\u003e into feature/distutils-d7633fbed\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/setuptools/commit/3c43897420f25a1be1afe6eaa905d056009cc736\"\u003e\u003ccode\u003e3c43897\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/pypa/setuptools/issues/5247\"\u003e#5247\u003c/a\u003e from pypa/copilot/fix-pypy-version-issue\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/setuptools/commit/bb6ea66b4bd01cb35d7c68a1bc61b96d59190269\"\u003e\u003ccode\u003ebb6ea66\u003c/code\u003e\u003c/a\u003e Bump PyPy from 3.10 to 3.11 in CI workflow\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/setuptools/commit/a2bc3aca2f55eb9b93ea633e58ba68170ce14451\"\u003e\u003ccode\u003ea2bc3ac\u003c/code\u003e\u003c/a\u003e Fix broken intersphinx reference to build's installation docs\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypa/setuptools/commit/2d6a739c64cfedc65e1f635af7b52340aac8d99b\"\u003e\u003ccode\u003e2d6a739\u003c/code\u003e\u003c/a\u003e Use stacked parametrize decorators instead of itertools.product\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/pypa/setuptools/compare/v75.3.0...v83.0.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `python-multipart` from 0.0.20 to 0.0.31\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/Kludex/python-multipart/releases\"\u003epython-multipart's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eVersion 0.0.31\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSpeed up multipart header parsing and callback dispatch by \u003ca href=\"https://github.com/Kludex\"\u003e\u003ccode\u003e@​Kludex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/295\"\u003eKludex/python-multipart#295\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBound header field name size before validating by \u003ca href=\"https://github.com/Kludex\"\u003e\u003ccode\u003e@​Kludex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/296\"\u003eKludex/python-multipart#296\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eValidate Content-Length is non-negative in parse_form by \u003ca href=\"https://github.com/Kludex\"\u003e\u003ccode\u003e@​Kludex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/297\"\u003eKludex/python-multipart#297\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/Kludex/python-multipart/compare/0.0.30...0.0.31\"\u003ehttps://github.com/Kludex/python-multipart/compare/0.0.30...0.0.31\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eVersion 0.0.30\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eTreat only \u003ccode\u003e\u0026amp;\u003c/code\u003e as the urlencoded field separator by \u003ca href=\"https://github.com/Kludex\"\u003e\u003ccode\u003e@​Kludex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/290\"\u003eKludex/python-multipart#290\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eIgnore RFC 2231 extended parameters in \u003ccode\u003eparse_options_header\u003c/code\u003e by \u003ca href=\"https://github.com/Kludex\"\u003e\u003ccode\u003e@​Kludex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/291\"\u003eKludex/python-multipart#291\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/Kludex/python-multipart/compare/0.0.29...0.0.30\"\u003ehttps://github.com/Kludex/python-multipart/compare/0.0.29...0.0.30\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eVersion 0.0.29\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eHandle malformed RFC 2231 continuations in \u003ccode\u003eparse_options_header\u003c/code\u003e by \u003ca href=\"https://github.com/manunio\"\u003e\u003ccode\u003e@​manunio\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/270\"\u003eKludex/python-multipart#270\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/Kludex/python-multipart/compare/0.0.28...0.0.29\"\u003ehttps://github.com/Kludex/python-multipart/compare/0.0.28...0.0.29\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eVersion 0.0.28\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSpeed up partial-boundary tail scan via \u003ccode\u003ebytes.find\u003c/code\u003e by \u003ca href=\"https://github.com/Kludex\"\u003e\u003ccode\u003e@​Kludex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/281\"\u003eKludex/python-multipart#281\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eCap multipart boundary length at 256 bytes by \u003ca href=\"https://github.com/Kludex\"\u003e\u003ccode\u003e@​Kludex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/282\"\u003eKludex/python-multipart#282\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/Kludex/python-multipart/compare/0.0.27...0.0.28\"\u003ehttps://github.com/Kludex/python-multipart/compare/0.0.27...0.0.28\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eVersion 0.0.27\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePass parse offsets via constructors by \u003ca href=\"https://github.com/Kludex\"\u003e\u003ccode\u003e@​Kludex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/268\"\u003eKludex/python-multipart#268\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd multipart header limits by \u003ca href=\"https://github.com/Kludex\"\u003e\u003ccode\u003e@​Kludex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/267\"\u003eKludex/python-multipart#267\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/Kludex/python-multipart/compare/0.0.26...0.0.27\"\u003ehttps://github.com/Kludex/python-multipart/compare/0.0.26...0.0.27\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eVersion 0.0.26\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSkip preamble before first multipart boundary by \u003ca href=\"https://github.com/Kludex\"\u003e\u003ccode\u003e@​Kludex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/262\"\u003eKludex/python-multipart#262\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSilently discard epilogue data after the closing boundary by \u003ca href=\"https://github.com/Kludex\"\u003e\u003ccode\u003e@​Kludex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/259\"\u003eKludex/python-multipart#259\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/Kludex/python-multipart/compare/0.0.25...0.0.26\"\u003ehttps://github.com/Kludex/python-multipart/compare/0.0.25...0.0.26\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eVersion 0.0.25\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eApply Apache-2.0 properly by \u003ca href=\"https://github.com/Kludex\"\u003e\u003ccode\u003e@​Kludex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/247\"\u003eKludex/python-multipart#247\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eHandle multipart headers case-insensitively by \u003ca href=\"https://github.com/Kludex\"\u003e\u003ccode\u003e@​Kludex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/252\"\u003eKludex/python-multipart#252\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/Kludex/python-multipart/blob/main/CHANGELOG.md\"\u003epython-multipart's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e0.0.31 (2026-06-04)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSpeed up multipart header parsing and callback dispatch \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/295\"\u003e#295\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eBound header field name size before validating \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/296\"\u003e#296\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eValidate \u003ccode\u003eContent-Length\u003c/code\u003e is non-negative in \u003ccode\u003eparse_form\u003c/code\u003e \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/297\"\u003e#297\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e0.0.30 (2026-05-31)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eParse \u003ccode\u003eapplication/x-www-form-urlencoded\u003c/code\u003e bodies per the WHATWG URL standard, treating only \u003ccode\u003e\u0026amp;\u003c/code\u003e as a field separator \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/290\"\u003e#290\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eIgnore RFC 2231/5987 extended parameters (\u003ccode\u003ename*\u003c/code\u003e, \u003ccode\u003efilename*\u003c/code\u003e) in \u003ccode\u003eparse_options_header\u003c/code\u003e, keeping the plain parameter authoritative per \u003ca href=\"https://datatracker.ietf.org/doc/html/rfc7578#section-4.2\"\u003eRFC 7578 §4.2\u003c/a\u003e \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/291\"\u003e#291\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e0.0.29 (2026-05-17)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eHandle malformed RFC 2231 continuations in \u003ccode\u003eparse_options_header\u003c/code\u003e \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/270\"\u003e#270\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e0.0.28 (2026-05-10)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSpeed up partial-boundary tail scan via \u003ccode\u003ebytes.find\u003c/code\u003e \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/281\"\u003e#281\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eCap multipart boundary length at 256 bytes \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/282\"\u003e#282\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e0.0.27 (2026-04-27)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd multipart header limits \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/267\"\u003e#267\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003ePass parse offsets via constructors \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/268\"\u003e#268\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e0.0.26 (2026-04-10)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSkip preamble before the first multipart boundary more efficiently \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/262\"\u003e#262\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eSilently discard epilogue data after the closing multipart boundary \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/259\"\u003e#259\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e0.0.25 (2026-04-10)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd MIME content type info to \u003ccode\u003eFile\u003c/code\u003e \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/143\"\u003e#143\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eHandle CTE values case-insensitively \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/258\"\u003e#258\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eRemove custom \u003ccode\u003eFormParser\u003c/code\u003e classes \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/257\"\u003e#257\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003eUPLOAD_DELETE_TMP\u003c/code\u003e to \u003ccode\u003eFormParser\u003c/code\u003e config \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/254\"\u003e#254\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eEmit \u003ccode\u003efield_end\u003c/code\u003e for trailing bare field names on finalize \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/230\"\u003e#230\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eHandle multipart headers case-insensitively \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/252\"\u003e#252\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eApply Apache-2.0 properly \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/247\"\u003e#247\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e0.0.24 (2026-04-05)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eValidate \u003ccode\u003echunk_size\u003c/code\u003e in \u003ccode\u003eparse_form()\u003c/code\u003e \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/244\"\u003e#244\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e0.0.23 (2026-04-05)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRemove unused \u003ccode\u003etrust_x_headers\u003c/code\u003e parameter and \u003ccode\u003eX-File-Name\u003c/code\u003e fallback \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/196\"\u003e#196\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eReturn processed length from \u003ccode\u003eQuerystringParser._internal_write\u003c/code\u003e \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/229\"\u003e#229\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eCleanup metadata dunders from \u003ccode\u003e__init__.py\u003c/code\u003e \u003ca href=\"https://redirect.github.com/Kludex/python-multipart/pull/227\"\u003e#227\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/python-multipart/commit/4cffc68a165f7a6f6b7756ce006fabf07a05b7a4\"\u003e\u003ccode\u003e4cffc68\u003c/code\u003e\u003c/a\u003e Version 0.0.31 (\u003ca href=\"https://redirect.github.com/Kludex/python-multipart/issues/298\"\u003e#298\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/python-multipart/commit/c814948acf509cef7881fa75c969969b19239bbf\"\u003e\u003ccode\u003ec814948\u003c/code\u003e\u003c/a\u003e Reject negative \u003ccode\u003eContent-Length\u003c/code\u003e in \u003ccode\u003eparse_form\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/Kludex/python-multipart/issues/297\"\u003e#297\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/python-multipart/commit/6b837d47bc68826ed5cbbcb50c6c6a6093444494\"\u003e\u003ccode\u003e6b837d4\u003c/code\u003e\u003c/a\u003e Bound header field name size before validating (\u003ca href=\"https://redirect.github.com/Kludex/python-multipart/issues/296\"\u003e#296\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/python-multipart/commit/e0c4f9df2e737d1663fbbdd6563f80613a2089f9\"\u003e\u003ccode\u003ee0c4f9d\u003c/code\u003e\u003c/a\u003e Bump the github-actions group with 3 updates (\u003ca href=\"https://redirect.github.com/Kludex/python-multipart/issues/294\"\u003e#294\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/python-multipart/commit/b8a01bb683e8e8675fdb5d831b206a478c8215aa\"\u003e\u003ccode\u003eb8a01bb\u003c/code\u003e\u003c/a\u003e Bump the python-packages group with 3 updates (\u003ca href=\"https://redirect.github.com/Kludex/python-multipart/issues/293\"\u003e#293\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/python-multipart/commit/6732164f30c58e28589a1e22213d2f6b8c6bad9f\"\u003e\u003ccode\u003e6732164\u003c/code\u003e\u003c/a\u003e Speed up multipart header parsing and callback dispatch (\u003ca href=\"https://redirect.github.com/Kludex/python-multipart/issues/295\"\u003e#295\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/python-multipart/commit/9d3ead568a259f222cff6425262ff63e88d930d4\"\u003e\u003ccode\u003e9d3ead5\u003c/code\u003e\u003c/a\u003e Version 0.0.30 (\u003ca href=\"https://redirect.github.com/Kludex/python-multipart/issues/292\"\u003e#292\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/python-multipart/commit/3506c15ce99cb62faf2d5ceb3c4c1e5800cb843d\"\u003e\u003ccode\u003e3506c15\u003c/code\u003e\u003c/a\u003e Ignore RFC 2231 extended parameters in \u003ccode\u003eparse_options_header\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/Kludex/python-multipart/issues/291\"\u003e#291\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/python-multipart/commit/d69df35cd2cad9c72794c2c340db646afae957d8\"\u003e\u003ccode\u003ed69df35\u003c/code\u003e\u003c/a\u003e Treat only \u003ccode\u003e\u0026amp;\u003c/code\u003e as the urlencoded field separator (\u003ca href=\"https://redirect.github.com/Kludex/python-multipart/issues/290\"\u003e#290\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/python-multipart/commit/1e6ff9740b09fb439755f30e2b0e2ada1d297325\"\u003e\u003ccode\u003e1e6ff97\u003c/code\u003e\u003c/a\u003e Bump idna from 3.11 to 3.15 (\u003ca href=\"https://redirect.github.com/Kludex/python-multipart/issues/289\"\u003e#289\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/Kludex/python-multipart/compare/0.0.20...0.0.31\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `pyjwt` from 2.10.1 to 2.13.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/jpadilla/pyjwt/releases\"\u003epyjwt's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e2.13.0\u003c/h2\u003e\n\u003ch1\u003ePyJWT 2.13.0 — Security Release\u003c/h1\u003e\n\u003cp\u003eThis release bundles five security fixes plus three additional hardening / spec-compliance changes. We recommend all users upgrade.\u003c/p\u003e\n\u003ch2\u003eSecurity\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/security/advisories/GHSA-xgmm-8j9v-c9wx\"\u003e\u003ccode\u003eGHSA-xgmm-8j9v-c9wx\u003c/code\u003e\u003c/a\u003e — JWK JSON accepted as HMAC secret (algorithm confusion).\u003c/strong\u003e \u003ccode\u003eHMACAlgorithm.prepare_key\u003c/code\u003e previously rejected PEM- and SSH-formatted asymmetric keys but did not catch a JWK passed as a raw JSON string. In a verifier configured with both symmetric and asymmetric algorithms in \u003ccode\u003ealgorithms=[…]\u003c/code\u003e and a raw-JSON JWK as the key, an attacker could forge HS256 tokens using the JWK text as the HMAC secret. The guard has been extended to reject any JWK-shaped JSON. \u003cem\u003eReported by \u003ca href=\"https://github.com/aradona91\"\u003e\u003ccode\u003e@​aradona91\u003c/code\u003e\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/security/advisories/GHSA-jq35-7prp-9v3f\"\u003e\u003ccode\u003eGHSA-jq35-7prp-9v3f\u003c/code\u003e\u003c/a\u003e — Algorithm allow-list bypass with \u003ccode\u003ePyJWK\u003c/code\u003e / \u003ccode\u003ePyJWKClient\u003c/code\u003e.\u003c/strong\u003e When verifying with a \u003ccode\u003ePyJWK\u003c/code\u003e, the caller's \u003ccode\u003ealgorithms=[…]\u003c/code\u003e allow-list was checked against the token header \u003ccode\u003ealg\u003c/code\u003e as a string only; actual verification used the algorithm bound to the \u003ccode\u003ePyJWK\u003c/code\u003e. An attacker who controlled a registered JWKS key could sign with one algorithm and advertise another on the header. PyJWT now requires the token header \u003ccode\u003ealg\u003c/code\u003e to match the \u003ccode\u003ePyJWK\u003c/code\u003e's algorithm before verification. \u003cem\u003eReported by \u003ca href=\"https://github.com/sushi-gif\"\u003e\u003ccode\u003e@​sushi-gif\u003c/code\u003e\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/security/advisories/GHSA-w7vc-732c-9m39\"\u003e\u003ccode\u003eGHSA-w7vc-732c-9m39\u003c/code\u003e\u003c/a\u003e — DoS via base64 decode of unused payload segment when \u003ccode\u003eb64=false\u003c/code\u003e.\u003c/strong\u003e For detached-payload JWS (\u003ccode\u003eb64=false\u003c/code\u003e), the compact-form payload segment was base64-decoded before being discarded in favor of the caller-supplied \u003ccode\u003edetached_payload\u003c/code\u003e. An attacker could inflate the unused segment to force CPU + memory cost without holding a valid signature. The segment is now required to be empty per RFC 7515 Appendix F, and is no longer decoded. \u003cem\u003eReported by \u003ca href=\"https://github.com/thesmartshadow\"\u003e\u003ccode\u003e@​thesmartshadow\u003c/code\u003e\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/security/advisories/GHSA-993g-76c3-p5m4\"\u003e\u003ccode\u003eGHSA-993g-76c3-p5m4\u003c/code\u003e\u003c/a\u003e — \u003ccode\u003ePyJWKClient\u003c/code\u003e accepts non-HTTP(S) URIs.\u003c/strong\u003e \u003ccode\u003ePyJWKClient.fetch_data\u003c/code\u003e passed its URI to \u003ccode\u003eurllib.request.urlopen\u003c/code\u003e, which by default also handles \u003ccode\u003efile://\u003c/code\u003e, \u003ccode\u003eftp://\u003c/code\u003e, and \u003ccode\u003edata:\u003c/code\u003e schemes. An application that fed an attacker-influenced URI into \u003ccode\u003ePyJWKClient\u003c/code\u003e could be coerced into reading local files or reaching other unintended schemes. \u003ccode\u003ePyJWKClient\u003c/code\u003e now rejects any URI whose scheme isn't \u003ccode\u003ehttp\u003c/code\u003e or \u003ccode\u003ehttps\u003c/code\u003e. \u003cem\u003eReported by \u003ca href=\"https://github.com/KEIJOT\"\u003e\u003ccode\u003e@​KEIJOT\u003c/code\u003e\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003cstrong\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/security/advisories/GHSA-fhv5-28vv-h8m8\"\u003e\u003ccode\u003eGHSA-fhv5-28vv-h8m8\u003c/code\u003e\u003c/a\u003e — \u003ccode\u003ePyJWKClient\u003c/code\u003e cache wiped on fetch error.\u003c/strong\u003e A \u003ccode\u003efinally\u003c/code\u003e-block \u003ccode\u003eput(jwk_set=None)\u003c/code\u003e cleared the JWK Set cache whenever a fetch raised, turning a transient JWKS-endpoint outage into application-wide auth failure. The cache write was moved into the success path; transient errors no longer evict valid cached keys. \u003cem\u003eReported by \u003ca href=\"https://github.com/eddieran\"\u003e\u003ccode\u003e@​eddieran\u003c/code\u003e\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eFixed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eReject empty HMAC keys outright in \u003ccode\u003eHMACAlgorithm.prepare_key\u003c/code\u003e with \u003ccode\u003eInvalidKeyError\u003c/code\u003e instead of accepting them with only a warning. Defends against the \u003ccode\u003eos.getenv(\u0026quot;JWT_SECRET\u0026quot;, \u0026quot;\u0026quot;)\u003c/code\u003e footgun. \u003cem\u003eThanks to \u003ca href=\"https://github.com/SnailSploit\"\u003e\u003ccode\u003e@​SnailSploit\u003c/code\u003e\u003c/a\u003e and \u003ca href=\"https://github.com/spartan8806\"\u003e\u003ccode\u003e@​spartan8806\u003c/code\u003e\u003c/a\u003e for the reports.\u003c/em\u003e\u003c/li\u003e\n\u003cli\u003eForward per-call \u003ccode\u003eoptions\u003c/code\u003e (including \u003ccode\u003eenforce_minimum_key_length\u003c/code\u003e) from \u003ccode\u003ePyJWT.decode\u003c/code\u003e through to \u003ccode\u003ePyJWS._verify_signature\u003c/code\u003e. The option was previously silently dropped between the two layers, so it only took effect when set on the \u003ccode\u003ePyJWT\u003c/code\u003e instance. \u003cem\u003eThanks to \u003ca href=\"https://github.com/WLUB\"\u003e\u003ccode\u003e@​WLUB\u003c/code\u003e\u003c/a\u003e for the report.\u003c/em\u003e\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eRFC 7797 §3 compliance for \u003ccode\u003eb64=false\u003c/code\u003e:\u003c/strong\u003e the encoder now auto-adds \u003ccode\u003e\u0026quot;b64\u0026quot;\u003c/code\u003e to \u003ccode\u003ecrit\u003c/code\u003e, and the decoder rejects tokens that set \u003ccode\u003eb64=false\u003c/code\u003e without listing it in \u003ccode\u003ecrit\u003c/code\u003e. \u003cem\u003eThanks to \u003ca href=\"https://github.com/MachineLearning-Nerd\"\u003e\u003ccode\u003e@​MachineLearning-Nerd\u003c/code\u003e\u003c/a\u003e for the report.\u003c/em\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eChanged\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMigrate the \u003ccode\u003edev\u003c/code\u003e, \u003ccode\u003edocs\u003c/code\u003e, and \u003ccode\u003etests\u003c/code\u003e package extras to dependency groups, by \u003ca href=\"https://github.com/kurtmckee\"\u003e\u003ccode\u003e@​kurtmckee\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/jpadilla/pyjwt/pull/1152\"\u003e#1152\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eUpgrade notes\u003c/h2\u003e\n\u003cp\u003eMost fixes are invisible to correctly-configured callers. A few behavioral changes you may encounter:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eEmpty HMAC keys now raise.\u003c/strong\u003e If your app passed \u003ccode\u003e\u0026quot;\u0026quot;\u003c/code\u003e or \u003ccode\u003eb\u0026quot;\u0026quot;\u003c/code\u003e as a secret (often via a missing env var, e.g. \u003ccode\u003eos.getenv(\u0026quot;JWT_SECRET\u0026quot;, \u0026quot;\u0026quot;)\u003c/code\u003e), \u003ccode\u003eencode\u003c/code\u003e/\u003ccode\u003edecode\u003c/code\u003e will now raise \u003ccode\u003eInvalidKeyError\u003c/code\u003e. This is the intended behavior — fix the configuration.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ccode\u003ePyJWK\u003c/code\u003e decoding now requires the token's \u003ccode\u003ealg\u003c/code\u003e to match the JWK's algorithm.\u003c/strong\u003e Previously a mismatch was silently honored if the header \u003ccode\u003ealg\u003c/code\u003e appeared in the allow-list. Tokens that relied on this mismatch will now fail with \u003ccode\u003eInvalidAlgorithmError\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ccode\u003ePyJWKClient\u003c/code\u003e now rejects non-HTTP(S) URIs at construction time.\u003c/strong\u003e Tests or dev environments that fetched JWKS from \u003ccode\u003efile://\u003c/code\u003e URIs need to switch to a local HTTP server or load the JWKS by other means (e.g. construct \u003ccode\u003ePyJWKSet.from_dict(...)\u003c/code\u003e directly).\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ccode\u003eb64=false\u003c/code\u003e tokens are now strictly RFC 7515 / 7797 compliant.\u003c/strong\u003e Tokens with a non-empty compact-form payload segment, or that omit \u003ccode\u003e\u0026quot;b64\u0026quot;\u003c/code\u003e from \u003ccode\u003ecrit\u003c/code\u003e, will be rejected. PyJWT-produced tokens always satisfy both invariants, so round-trips through PyJWT are unaffected.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ccode\u003eenforce_minimum_key_length\u003c/code\u003e set per-call now takes effect.\u003c/strong\u003e Callers who passed \u003ccode\u003eoptions={\u0026quot;enforce_minimum_key_length\u0026quot;: True}\u003c/code\u003e to \u003ccode\u003ejwt.decode()\u003c/code\u003e previously got no enforcement; they will now get \u003ccode\u003eInvalidKeyError\u003c/code\u003e on undersized keys, as documented.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull changelog:\u003c/strong\u003e \u003ca href=\"https://github.com/jpadilla/pyjwt/compare/2.12.1...2.13.0\"\u003ehttps://github.com/jpadilla/pyjwt/compare/2.12.1...2.13.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003e2.12.1\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd typing_extensions dependency for Python \u0026lt; 3.11 by \u003ca href=\"https://github.com/jpadilla\"\u003e\u003ccode\u003e@​jpadilla\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/jpadilla/pyjwt/pull/1151\"\u003ejpadilla/pyjwt#1151\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/jpadilla/pyjwt/compare/2.12.0...2.12.1\"\u003ehttps://github.com/jpadilla/pyjwt/compare/2.12.0...2.12.1\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003e2.12.0\u003c/h2\u003e\n\u003ch2\u003eSecurity\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eValidate the crit (Critical) Header Parameter defined in RFC 7515 §4.1.11. by \u003ca href=\"https://github.com/dmbs335\"\u003e\u003ccode\u003e@​dmbs335\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://github.com/jpadilla/pyjwt/security/advisories/GHSA-752w-5fwx-jx9f\"\u003eGHSA-752w-5fwx-jx9f\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/jpadilla/pyjwt/blob/master/CHANGELOG.rst\"\u003epyjwt's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ccode\u003ev2.13.0 \u0026lt;https://github.com/jpadilla/pyjwt/compare/2.12.1...2.13.0\u0026gt;\u003c/code\u003e__\u003c/h2\u003e\n\u003cp\u003eSecurity\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003e\n- Reject JWK JSON documents passed as raw HMAC secrets in\n  ``HMACAlgorithm.prepare_key`` to close an algorithm-confusion gap that\n  the existing PEM/SSH guard did not cover. Reported by @aradona91 in\n  `GHSA-xgmm-8j9v-c9wx \u0026lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-xgmm-8j9v-c9wx\u0026gt;`__.\n- Bind the JWT header ``alg`` to ``PyJWK.algorithm_name`` during\n  verification so the caller's ``algorithms=[...]`` allow-list cannot be\n  bypassed when decoding with a ``PyJWK`` / ``PyJWKClient`` key. Reported\n  by @sushi-gif in `GHSA-jq35-7prp-9v3f \u0026lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-jq35-7prp-9v3f\u0026gt;`__.\n- Reject non-``http(s)`` URI schemes in ``PyJWKClient`` so attacker-\n  influenced URIs cannot read local files or reach unintended schemes via\n  urllib's default ``file://`` / ``ftp://`` / ``data:`` handlers. Reported\n  by @KEIJOT in `GHSA-993g-76c3-p5m4 \u0026lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-993g-76c3-p5m4\u0026gt;`__.\n- Preserve the cached JWK Set on fetch errors in ``PyJWKClient.fetch_data``.\n  The previous ``finally``-block ``put(None)`` pattern cleared the cache\n  on any transient outage, turning one bad JWKS request into application-\n  wide auth failure. Reported by @eddieran in `GHSA-fhv5-28vv-h8m8 \u0026lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-fhv5-28vv-h8m8\u0026gt;`__.\n- Skip the unconditional base64 decode of the compact-form payload segment\n  when ``b64=false`` is set in the protected header, and require that\n  segment to be empty (RFC 7515 Appendix F detached form). Closes an\n  unauthenticated DoS amplifier. Reported by @thesmartshadow in\n  `GHSA-w7vc-732c-9m39 \u0026lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-w7vc-732c-9m39\u0026gt;`__.\n\u003cp\u003eFixed\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003e\n- Reject empty HMAC keys outright in ``HMACAlgorithm.prepare_key`` with\n  ``InvalidKeyError`` instead of accepting them with only a warning.\n  Thanks to @SnailSploit and @spartan8806 for independently flagging the\n  footgun.\n- Forward per-call ``options`` (including ``enforce_minimum_key_length``)\n  from ``PyJWT.decode`` through to ``PyJWS._verify_signature`` so the\n  option actually takes effect when set at the call site rather than only\n  on the ``PyJWT`` instance. Thanks to @WLUB for the report.\n- RFC 7797 §3 compliance for ``b64=false``: the encoder now auto-adds\n  ``\u0026amp;quot;b64\u0026amp;quot;`` to the ``crit`` header parameter, and the decoder rejects\n  tokens that set ``b64=false`` without listing it in ``crit``. Thanks to\n  @MachineLearning-Nerd for the report.\n\nChanged\n\u003c/code\u003e\u003c/pre\u003e\n\u003cul\u003e\n\u003cli\u003eMigrate the \u003ccode\u003edev\u003c/code\u003e, \u003ccode\u003edocs\u003c/code\u003e, and \u003ccode\u003etests\u003c/code\u003e package extras to dependency groups by \u003ca href=\"https://github.com/kurtmckee\"\u003e\u003ccode\u003e@​kurtmckee\u003c/code\u003e\u003c/a\u003e in \u003ccode\u003e[#1152](https://github.com/jpadilla/pyjwt/issues/1152) \u0026amp;lt;https://github.com/jpadilla/pyjwt/pull/1152\u0026amp;gt;\u003c/code\u003e__\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003ccode\u003ev2.12.1 \u0026amp;lt;https://github.com/jpadilla/pyjwt/compare/2.12.0...2.12.1\u0026amp;gt;\u003c/code\u003e__\n\u0026lt;/tr\u0026gt;\u0026lt;/table\u0026gt;\n\u003c/code\u003e\u003c/pre\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/7144e4534c34810f4525dc4578a32addd8212cff\"\u003e\u003ccode\u003e7144e45\u003c/code\u003e\u003c/a\u003e Apply ruff format\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/d2f4bec4963897c0ef96ef64a875894f2c8542ab\"\u003e\u003ccode\u003ed2f4bec\u003c/code\u003e\u003c/a\u003e Restore \u003ccode\u003ecast()\u003c/code\u003e calls with cross-version \u003ccode\u003etype: ignore\u003c/code\u003e for \u003ccode\u003eprepare_key\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/22f478cebddd8294259c30f037ecb92b0b348774\"\u003e\u003ccode\u003e22f478c\u003c/code\u003e\u003c/a\u003e Remove redundant casts in \u003ccode\u003eRSAAlgorithm.prepare_key\u003c/code\u003e and `ECAlgorithm.prepare...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/95791b1759b8aa4f2203575d344d5c78564cdc81\"\u003e\u003ccode\u003e95791b1\u003c/code\u003e\u003c/a\u003e Bundle security fixes and hardening into 2.13.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/dcc27a9d3182a2349c30b160758785c6ce7a6508\"\u003e\u003ccode\u003edcc27a9\u003c/code\u003e\u003c/a\u003e [pre-commit.ci] pre-commit autoupdate (\u003ca href=\"https://redirect.github.com/jpadilla/pyjwt/issues/1155\"\u003e#1155\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/9d08a9a1896845ed8eaf88e6f6ac61e5800c3e7a\"\u003e\u003ccode\u003e9d08a9a\u003c/code\u003e\u003c/a\u003e [pre-commit.ci] pre-commit autoupdate (\u003ca href=\"https://redirect.github.com/jpadilla/pyjwt/issues/1146\"\u003e#1146\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/b87c10014d4109f0214fea188d00faaaf8a80e64\"\u003e\u003ccode\u003eb87c100\u003c/code\u003e\u003c/a\u003e Bump codecov/codecov-action from 5 to 6 (\u003ca href=\"https://redirect.github.com/jpadilla/pyjwt/issues/1154\"\u003e#1154\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/40e3147eb5f790d8d041772e5fc00728a176c812\"\u003e\u003ccode\u003e40e3147\u003c/code\u003e\u003c/a\u003e Migrate development extras to dependency groups (\u003ca href=\"https://redirect.github.com/jpadilla/pyjwt/issues/1152\"\u003e#1152\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/a4e1a3d1218b01c5806420b8f16d9308ac4adc30\"\u003e\u003ccode\u003ea4e1a3d\u003c/code\u003e\u003c/a\u003e Add typing_extensions dependency for Python \u0026lt; 3.11 (\u003ca href=\"https://redirect.github.com/jpadilla/pyjwt/issues/1151\"\u003e#1151\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jpadilla/pyjwt/commit/bd9700cca7f9258fadcc429c1034e508025931f2\"\u003e\u003ccode\u003ebd9700c\u003c/code\u003e\u003c/a\u003e Use PyJWK algorithm when encoding without explicit algorithm (\u003ca href=\"https://redirect.github.com/jpadilla/pyjwt/issues/1148\"\u003e#1148\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/jpadilla/pyjwt/compare/2.10.1...2.13.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `aiohttp` from 3.12.14 to 3.14.3\nUpdates `gitpython` from 3.1.44 to 3.1.59\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/gitpython-developers/GitPython/releases\"\u003egitpython's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e3.1.59 - Security\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eprepare changelog for upcoming release by \u003ca href=\"https://github.com/Byron\"\u003e\u003ccode\u003e@​Byron\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2207\"\u003egitpython-developers/GitPython#2207\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBlock file-reading Git options by \u003ca href=\"https://github.com/Byron\"\u003e\u003ccode\u003e@​Byron\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2208\"\u003egitpython-developers/GitPython#2208\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eindex: write blobs via git hash-object, not gitdb's odb.store by \u003ca href=\"https://github.com/caroescm\"\u003e\u003ccode\u003e@​caroescm\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2209\"\u003egitpython-developers/GitPython#2209\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBlock separate git directories during clone by \u003ca href=\"https://github.com/Byron\"\u003e\u003ccode\u003e@​Byron\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2210\"\u003egitpython-developers/GitPython#2210\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: harden config parsing boundaries by \u003ca href=\"https://github.com/Byron\"\u003e\u003ccode\u003e@​Byron\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2211\"\u003egitpython-developers/GitPython#2211\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003erepo.index.add()\u003c/code\u003e now respects worktree filters  \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2209\"\u003egitpython-developers/GitPython#2209\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/gitpython-developers/GitPython/compare/3.1.58...3.1.59\"\u003ehttps://github.com/gitpython-developers/GitPython/compare/3.1.58...3.1.59\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003e3.1.58 - Security and Fixes\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003etest: allow Python startup before timeout by \u003ca href=\"https://github.com/Byron\"\u003e\u003ccode\u003e@​Byron\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2195\"\u003egitpython-developers/GitPython#2195\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eResolve Windows hook Bash through PATH by \u003ca href=\"https://github.com/Byron\"\u003e\u003ccode\u003e@​Byron\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2199\"\u003egitpython-developers/GitPython#2199\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRevert \u0026quot;Resolve Windows hook Bash through PATH\u0026quot; by \u003ca href=\"https://github.com/Byron\"\u003e\u003ccode\u003e@​Byron\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2200\"\u003egitpython-developers/GitPython#2200\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003etest: focus pytest summary on unexpected failures by \u003ca href=\"https://github.com/raisulchowdhury\"\u003e\u003ccode\u003e@​raisulchowdhury\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2203\"\u003egitpython-developers/GitPython#2203\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eValidate submodule names before filesystem operations by \u003ca href=\"https://github.com/Byron\"\u003e\u003ccode\u003e@​Byron\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2202\"\u003egitpython-developers/GitPython#2202\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eHandle invalid submodule names during recursive updates by \u003ca href=\"https://github.com/Byron\"\u003e\u003ccode\u003e@​Byron\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2205\"\u003egitpython-developers/GitPython#2205\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix Windows path handling on Python 3.13+ by \u003ca href=\"https://github.com/Byron\"\u003e\u003ccode\u003e@​Byron\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2196\"\u003egitpython-developers/GitPython#2196\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efixup 2202 by \u003ca href=\"https://github.com/Byron\"\u003e\u003ccode\u003e@​Byron\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2206\"\u003egitpython-developers/GitPython#2206\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eCorrect Windows hook Bash precedence by \u003ca href=\"https://github.com/Byron\"\u003e\u003ccode\u003e@​Byron\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2201\"\u003egitpython-developers/GitPython#2201\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eHarden config and Git option validation by \u003ca href=\"https://github.com/Byron\"\u003e\u003ccode\u003e@​Byron\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2204\"\u003egitpython-developers/GitPython#2204\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSkip tests that need symlink privileges instead of erroring by \u003ca href=\"https://github.com/Cyrus580529\"\u003e\u003ccode\u003e@​Cyrus580529\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2197\"\u003egitpython-developers/GitPython#2197\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/raisulchowdhury\"\u003e\u003ccode\u003e@​raisulchowdhury\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2203\"\u003egitpython-developers/GitPython#2203\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Cyrus580529\"\u003e\u003ccode\u003e@​Cyrus580529\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2197\"\u003egitpython-developers/GitPython#2197\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/gitpython-developers/GitPython/compare/3.1.57...3.1.58\"\u003ehttps://github.com/gitpython-developers/GitPython/compare/3.1.57...3.1.58\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003e3.1.57 - Security and Fixes\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMerge gitdb and smmap into the GitPython repository by \u003ca href=\"https://github.com/Byron\"\u003e\u003ccode\u003e@​Byron\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2179\"\u003egitpython-developers/GitPython#2179\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump actions/setup-python from 6 to 7 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2185\"\u003egitpython-developers/GitPython#2185\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ebuild(deps): bump the pre-commit group with 2 updates by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2186\"\u003egitpython-developers/GitPython#2186\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump Vampire/setup-wsl from 6.0.0 to 7.0.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2124\"\u003egitpython-developers/GitPython#2124\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRender protected Traversable methods in the reference by \u003ca href=\"https://github.com/pick7\"\u003e\u003ccode\u003e@​pick7\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2192\"\u003egitpython-developers/GitPython#2192\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUse standard prefixes for parsed patch diffs by \u003ca href=\"https://github.com/pick7\"\u003e\u003ccode\u003e@​pick7\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2191\"\u003egitpython-developers/GitPython#2191\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eHonor kill_after_timeout with output streams by \u003ca href=\"https://github.com/pick7\"\u003e\u003ccode\u003e@​pick7\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2189\"\u003egitpython-developers/GitPython#2189\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRedact Authorization extra headers from command errors by \u003ca href=\"https://github.com/pick7\"\u003e\u003ccode\u003e@​pick7\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2188\"\u003egitpython-developers/GitPython#2188\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eImprove RemoteProgress parse return typing by \u003ca href=\"https://github.com/pick7\"\u003e\u003ccode\u003e@​pick7\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2187\"\u003egitpython-developers/GitPython#2187\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdopt basedpyright with a legacy baseline by \u003ca href=\"https://github.com/Byron\"\u003e\u003ccode\u003e@​Byron\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2194\"\u003egitpython-developers/GitPython#2194\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBlock unsafe Git file and URL options by \u003ca href=\"https://github.com/Byron\"\u003e\u003ccode\u003e@​Byron\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2193\"\u003egitpython-developers/GitPython#2193\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pick7\"\u003e\u003ccode\u003e@​pick7\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/pull/2192\"\u003egitpython-developers/GitPython#2192\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/gitpython-developers/GitPython/compare/3.1.56...3.1.57\"\u003ehttps://github.com/gitpython-developers/GitPython/compare/3.1.56...3.1.57\u003c/a\u003e\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gitpython-developers/GitPython/commit/66340d77aab9a7468f4aed3681d4ef1e3c0ec931\"\u003e\u003ccode\u003e66340d7\u003c/code\u003e\u003c/a\u003e prepare changelog prior to release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gitpython-developers/GitPython/commit/a5e047d0db7047c4249c0de335585470b14d50c4\"\u003e\u003ccode\u003ea5e047d\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/issues/2211\"\u003e#2211\u003c/a\u003e from gitpython-developers/config-sanitize-more\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gitpython-developers/GitPython/commit/ef7568e3b317ce617eacda39b8b54dcdff8c3b5c\"\u003e\u003ccode\u003eef7568e\u003c/code\u003e\u003c/a\u003e fix: ignore includes in submodule configuration\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gitpython-developers/GitPython/commit/4b4e47fc1224e23b0c8ee7220a7192818f2e4abb\"\u003e\u003ccode\u003e4b4e47f\u003c/code\u003e\u003c/a\u003e fix: preserve multiline config values when writing\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gitpython-developers/GitPython/commit/b473abb0f7de754392e1ec923f2fe296509013ab\"\u003e\u003ccode\u003eb473abb\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/issues/2210\"\u003e#2210\u003c/a\u003e from gitpython-developers/fix-clone-unsafe-option\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gitpython-developers/GitPython/commit/5ff52cccca770fd69c6caf0b8f281d3e45d599be\"\u003e\u003ccode\u003e5ff52cc\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/issues/2209\"\u003e#2209\u003c/a\u003e from caroescm/fix-index-add-chmod\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gitpython-developers/GitPython/commit/b68afff45af0f49e79a3e2d2162018986b37ad5d\"\u003e\u003ccode\u003eb68afff\u003c/code\u003e\u003c/a\u003e Block separate git directories during clone\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gitpython-developers/GitPython/commit/93677a00ab9dcb06cc08595fd1f88a4b4a0fa23b\"\u003e\u003ccode\u003e93677a0\u003c/code\u003e\u003c/a\u003e fix: \u003ccode\u003eindex.add()\u003c/code\u003e now supports filters (\u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/issues/2021\"\u003e#2021\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gitpython-developers/GitPython/commit/9729ed3b948f2bde09f1f188c5311e172212b67e\"\u003e\u003ccode\u003e9729ed3\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/gitpython-developers/GitPython/issues/2208\"\u003e#2208\u003c/a\u003e from gitpython-developers/security-fixes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gitpython-developers/GitPython/commit/ce9d8e8d150e06ae2e2cc2efa229071cd3048a93\"\u003e\u003ccode\u003ece9d8e8\u003c/code\u003e\u003c/a\u003e prepare next release\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/gitpython-developers/GitPython/compare/3.1.44...3.1.59\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `h2` from 4.3.0 to 4.4.1\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/python-hyper/h2/blob/master/CHANGELOG.rst\"\u003eh2's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e4.4.1 (2026-08-03)\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eBugfixes\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003ePerformance improvement: remove consumed frames in-place from data buffer.\u003c/li\u003e\n\u003cli\u003eReject duplicate Host headers in request headers. Thanks to Sunand Mohan for the report.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e4.4.0 (2026-07-23)\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eAPI Changes (Backward Incompatible)\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eSupport for Python 3.9 has been removed.\u003c/li\u003e\n\u003cli\u003eSupport for PyPy 3.9 has been removed.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eStream.end_stream()\u003c/code\u003e now raises \u003ccode\u003eNoSuchStreamError\u003c/code\u003e or \u003ccode\u003eStreamClosedError\u003c/code\u003e exceptions, instead of a generic \u003ccode\u003eKeyError\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eDuplicate \u003ccode\u003econtent-length\u003c/code\u003e headers with different values now raise \u003ccode\u003eProtocolError\u003c/code\u003e.\nPreviously, the first \u003ccode\u003econtent-length\u003c/code\u003e header was accepted and later conflicting values were ignored. Thanks to Harshal Parekh for the report.\u003c/li\u003e\n\u003cli\u003eParse \u003ccode\u003econtent-length\u003c/code\u003e headers according to RFC9110 grammar for numbers (1*DIGIT). Thanks to Arkadiusz Marta for the report.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003ebackfill from v4.3.0\u003c/strong\u003e Convert emitted events into Python \u003ccode\u003edataclass\u003c/code\u003e, which introduces new constructors with required arguments.\nInstantiating these events without arguments, as previously commonly used API pattern, will no longer work.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eAPI Changes (Backward Compatible)\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eSupport for Python 3.14 has been added.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eH2Connection.receive_data\u003c/code\u003e now accepts any byte-like object that\nimplements the buffer protocol, such as \u003ccode\u003ebytes\u003c/code\u003e, \u003ccode\u003ebytearray\u003c/code\u003e, and\n\u003ccode\u003ememoryview\u003c/code\u003e. Existing \u003ccode\u003ebytes\u003c/code\u003e callers are unaffected.\u003c/li\u003e\n\u003cli\u003eAlign CONNECT pseudo-header validation with RFC 9113 s8.3 and RFC 8441 s4.\nOrdinary CONNECT now requires \u003ccode\u003e:method=CONNECT\u003c/code\u003e and \u003ccode\u003e:authority\u003c/code\u003e, and\nforbids \u003ccode\u003e:scheme\u003c/code\u003e/\u003ccode\u003e:path\u003c/code\u003e. Extended CONNECT (e.g., WebSocket) requires\n\u003ccode\u003e:scheme\u003c/code\u003e, \u003ccode\u003e:path\u003c/code\u003e, \u003ccode\u003e:authority\u003c/code\u003e plus \u003ccode\u003e:protocol\u003c/code\u003e. (PR \u003ca href=\"https://redirect.github.com/python-hyper/h2/issues/1309\"\u003e#1309\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix incorrect substring matching of secure header in \u003ccode\u003ecookie\u003c/code\u003e and \u003ccode\u003e:method\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eBugfixes\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eFix to allow sending 0 bytes on a stream even if the flow control window is negative.\u003c/li\u003e\n\u003cli\u003eReject non-zero \u003ccode\u003eSETTINGS_ENABLE_PUSH\u003c/code\u003e values received from servers.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-hyper/h2/commit/bc239af1d1b85bc70482804f30a0e0e587d90a08\"\u003e\u003ccode\u003ebc239af\u003c/code\u003e\u003c/a\u003e v4.4.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-hyper/h2/commit/92b925ed1b1817c82db32893503f74f47fcf4452\"\u003e\u003ccode\u003e92b925e\u003c/code\u003e\u003c/a\u003e add test for duplicate host headers\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-hyper/h2/commit/292a40829feefda98c8509dcdbbb4a57af9bd6a6\"\u003e\u003ccode\u003e292a408\u003c/code\u003e\u003c/a\u003e reject duplicate Host headers in request headers\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-hyper/h2/commit/04d3b87cbc1db020d28c7cfb44fe194558efbdde\"\u003e\u003ccode\u003e04d3b87\u003c/code\u003e\u003c/a\u003e update changelog\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-hyper/h2/commit/439b970d0fa19891fa81068907de97dfa3a07c3a\"\u003e\u003ccode\u003e439b970\u003c/code\u003e\u003c/a\u003e prepare for next release cycle\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-hyper/h2/commit/9a7ff7430df669fa8e90b6121f3cc1ed64d1115a\"\u003e\u003ccode\u003e9a7ff74\u003c/code\u003e\u003c/a\u003e performance: remove consumed frames in place from data buffer (\u003ca href=\"https://redirect.github.com/python-hyper/h2/issues/1321\"\u003e#1321\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-hyper/h2/commit/6cce763997eca5b826f3e435a611b7a7fc73f633\"\u003e\u003ccode\u003e6cce763\u003c/code\u003e\u003c/a\u003e v4.4.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-hyper/h2/commit/dfafda3b0cd96455b45d1785ef1ebc6968bba5cf\"\u003e\u003ccode\u003edfafda3\u003c/code\u003e\u003c/a\u003e Bump pytest from 8.4.2 to 9.0.3 (\u003ca href=\"https://redirect.github.com/python-hyper/h2/issues/1320\"\u003e#1320\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-hyper/h2/commit/b45207cedf9fabe2c77bb3c1c10f403a610599a0\"\u003e\u003ccode\u003eb45207c\u003c/code\u003e\u003c/a\u003e dependencies and packaging++\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-hyper/h2/commit/c40145f69c5473850849fe96301ac0416b1afea6\"\u003e\u003ccode\u003ec40145f\u003c/code\u003e\u003c/a\u003e parse \u003ccode\u003econtent-length\u003c/code\u003e headers according to RFC9110 grammar for numbers (1*DI...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/python-hyper/h2/compare/v4.3.0...v4.4.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `tornado` from 6.5 to 6.5.8\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/tornadoweb/tornado/blob/master/docs/releases.rst\"\u003etornado's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003eRelease notes\u003c/h1\u003e\n\u003cp\u003e.. toctree::\n:maxdepth: 2\u003c/p\u003e\n\u003cp\u003ereleases/v6.5.10\nreleases/v6.5.9\nreleases/v6.5.8\nreleases/v6.5.7\nreleases/v6.5.6\nreleases/v6.5.5\nreleases/v6.5.4\nreleases/v6.5.3\nreleases/v6.5.2\nreleases/v6.5.1\nreleases/v6.5.0\nreleases/v6.4.2\nreleases/v6.4.1\nreleases/v6.4.0\nreleases/v6.3.3\nreleases/v6.3.2\nreleases/v6.3.1\nreleases/v6.3.0\nreleases/v6.2.0\nreleases/v6.1.0\nreleases/v6.0.4\nreleases/v6.0.3\nreleases/v6.0.2\nreleases/v6.0.1\nreleases/v6.0.0\nreleases/v5.1.1\nreleases/v5.1.0\nreleases/v5.0.2\nreleases/v5.0.1\nreleases/v5.0.0\nreleases/v4.5.3\nreleases/v4.5.2\nreleases/v4.5.1\nreleases/v4.5.0\nreleases/v4.4.3\nreleases/v4.4.2\nreleases/v4.4.1\nreleases/v4.4.0\nreleases/v4.3.0\nreleases/v4.2.1\nreleases/v4.2.0\nreleases/v4.1.0\nreleases/v4.0.2\nreleases/v4.0.1\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tornadoweb/tornado/commit/a55abe3e3bf59994f29b2f7084c46341f0d4f6a7\"\u003e\u003ccode\u003ea55abe3\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/tornadoweb/tornado/issues/3704\"\u003e#3704\u003c/a\u003e from bdarnell/security-6.5.8\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tornadoweb/tornado/commit/fc794885f0ccf9c33f3a66d890abcc237dd50b3c\"\u003e\u003ccode\u003efc79488\u003c/code\u003e\u003c/a\u003e docs: add additional credit to release notes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tornadoweb/tornado/commit/7b017630d3139ca0d1ebdf6ac3b3ffe7725a7129\"\u003e\u003ccode\u003e7b01763\u003c/code\u003e\u003c/a\u003e Fix test_strip_headers_on_redirect's URL-embedded-credentials cases\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tornadoweb/tornado/commit/d72fff8d7b9b8f6aa68505847e5483d600e3184c\"\u003e\u003ccode\u003ed72fff8\u003c/code\u003e\u003c/a\u003e release notes and version bump for 6.5.8\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tornadoweb/tornado/commit/b168818f8aae39808b981878fb358cbe02a6238e\"\u003e\u003ccode\u003eb168818\u003c/code\u003e\u003c/a\u003e auth: Formally deprecated OpenIDMixin\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tornadoweb/tornado/commit/da284767eae8e1f0484f123b8c3225f6465b09c7\"\u003e\u003ccode\u003eda28476\u003c/code\u003e\u003c/a\u003e web: Also check for semicolons in deprecated mixed-case cookie args\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tornadoweb/tornado/commit/8d6363ed7b69d5f0da806efe34d256627a2191de\"\u003e\u003ccode\u003e8d6363e\u003c/code\u003e\u003c/a\u003e httputil: Enforce a new limit on the number of arguments in a request\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tornadoweb/tornado/commit/de85b3f87446e323e881bbaa3d5a74f4b76e5f05\"\u003e\u003ccode\u003ede85b3f\u003c/code\u003e\u003c/a\u003e httputil: Apply multipart max_parts limit earlier\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tornadoweb/tornado/commit/48fc2d43d1f48b8b3b0be5dcf6a7634c6f45b1c4\"\u003e\u003ccode\u003e48fc2d4\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/tornadoweb/tornado/issues/3633\"\u003e#3633\u003c/a\u003e from bdarnell/curl-reset-65\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tornadoweb/tornado/commit/4ae1ddd14245e56e9fb6fb14d4b9508301fbb841\"\u003e\u003ccode\u003e4ae1ddd\u003c/code\u003e\u003c/a\u003e Release notes and version bump for 6.5.7\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/tornadoweb/tornado/compare/v6.5.0...v6.5.8\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `pillow` from 10.3.0 to 12.3.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/python-pillow/Pillow/releases\"\u003epillow's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e12.3.0\u003c/h2\u003e\n\u003cp\u003e\u003ca href=\"https://pillow.readthedocs.io/en/stable/releasenotes/12.3.0.html\"\u003ehttps://pillow.readthedocs.io/en/stable/releasenotes/12.3.0.html\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eRemovals\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRemove non-image ImageCms modes \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9697\"\u003e#9697\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eDocumentation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd release notes for SBOM and performance improvements \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9747\"\u003e#9747\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdd security release notes \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9741\"\u003e#9741\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdd release notes for Python 3.15 beta wheels \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9696\"\u003e#9696\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eImageFont can also be used with ImageText \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9597\"\u003e#9597\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdditional guidelines for security reports \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9659\"\u003e#9659\u003c/a\u003e [\u003ca href=\"https://github.com/wiredfool\"\u003e\u003ccode\u003e@​wiredfool\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eFixed typo \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9636\"\u003e#9636\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdded CVEs to 12.2.0 release notes \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9591\"\u003e#9591\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eRevise development support information in README \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9583\"\u003e#9583\u003c/a\u003e [\u003ca href=\"https://github.com/aclark4life\"\u003e\u003ccode\u003e@​aclark4life\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdd INCIDENT_RESPONSE.md \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9555\"\u003e#9555\u003c/a\u003e [\u003ca href=\"https://github.com/aclark4life\"\u003e\u003ccode\u003e@​aclark4life\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdd STRIDE threat model to security docs \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9562\"\u003e#9562\u003c/a\u003e [\u003ca href=\"https://github.com/aclark4life\"\u003e\u003ccode\u003e@​aclark4life\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdd CVEs to 12.2.0 release notes \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9556\"\u003e#9556\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate README with revised security policy \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9553\"\u003e#9553\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate security policy \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9552\"\u003e#9552\u003c/a\u003e [\u003ca href=\"https://github.com/aclark4life\"\u003e\u003ccode\u003e@​aclark4life\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate macOS tested Python versions \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9534\"\u003e#9534\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eDependencies\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate dependency harfbuzz to v14.2.1 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9720\"\u003e#9720\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency mypy to v2 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9653\"\u003e#9653\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency cibuildwheel to v4 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9665\"\u003e#9665\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate github-actions \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9655\"\u003e#9655\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency libavif to v1.4.2 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9652\"\u003e#9652\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency lcms2 to v2.19.1 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9651\"\u003e#9651\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency check-jsonschema to v0.37.2 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9650\"\u003e#9650\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate google/oss-fuzz digest to d872252 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9614\"\u003e#9614\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency lcms2 to v2.19 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9609\"\u003e#9609\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency libpng to v1.6.58 - autoclosed \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9608\"\u003e#9608\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency harfbuzz to v14 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9610\"\u003e#9610\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency mypy to v1.20.2 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9599\"\u003e#9599\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate github-actions \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9611\"\u003e#9611\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency cibuildwheel to v3.4.1 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9607\"\u003e#9607\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eMove dependency versions to single JSON and enable Renovate \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9559\"\u003e#9559\u003c/a\u003e [\u003ca href=\"https://github.com/hugovk\"\u003e\u003ccode\u003e@​hugovk\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdated raqm to 0.10.5 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9557\"\u003e#9557\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency cibuildwheel to v3.4.0 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9532\"\u003e#9532\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eTesting\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRemove matrix.os from benchmark \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9735\"\u003e#9735\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eRemove references to libavif patch \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9734\"\u003e#9734\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdd benchmark tests \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9654\"\u003e#9654\u003c/a\u003e [\u003ca href=\"https://github.com/akx\"\u003e\u003ccode\u003e@​akx\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUse reshape() instead of setting NumPy array shape directly \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9728\"\u003e#9728\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/python-pillow/Pillow/blob/main/CHANGES.rst\"\u003epillow's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003eChangelog (Pillow)\u003c/h1\u003e\n\u003ch2\u003e11.1.0 and newer\u003c/h2\u003e\n\u003cp\u003eSee GitHub Releases:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/releases\"\u003ehttps://github.com/python-pillow/Pillow/releases\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e11.0.0 (2024-10-15)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eUpdate licence to MIT-CMU \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/8460\"\u003e#8460\u003c/a\u003e\n[hugovk]\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eConditionally define ImageCms type hint to avoid requiring core \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/8197\"\u003e#8197\u003c/a\u003e\n[radarhere]\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eSupport writing LONG8 offsets in AppendingTiffWriter \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/8417\"\u003e#8417\u003c/a\u003e\n[radarhere]\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUse ImageFile.MAXBLOCK when saving TIFF images \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/8461\"\u003e#8461\u003c/a\u003e\n[radarhere]\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eDo not close provided file handles with libtiff when saving \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/8458\"\u003e#8458\u003c/a\u003e\n[radarhere]\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eSupport ImageFilter.BuiltinFilter for I;16* images \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/8438\"\u003e#8438\u003c/a\u003e\n[radarhere]\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUse ImagingCore.ptr instead of ImagingCore.id \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/8341\"\u003e#8341\u003c/a\u003e\n[homm, radarhere, hugovk]\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUpdated EPS mode when opening images without transparency \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/8281\"\u003e#8281\u003c/a\u003e\n[Yay295, radarhere]\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUse transparency when combining P frames from APNGs \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/8443\"\u003e#8443\u003c/a\u003e\n[radarhere]\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eSupport all resampling filters when resizing I;16* images \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/8422\"\u003e#8422\u003c/a\u003e\n[radarhere]\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFree memory on early return \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/8413\"\u003e#8413\u003c/a\u003e\n[radarhere]\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eCast int before potentially exceeding INT_MAX \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/8402\"\u003e#8402\u003c/a\u003e\n[radarhere]\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/bb1d8e8ab8d29048624d96e3ee53cecf7c13d13d\"\u003e\u003ccode\u003ebb1d8e8\u003c/code\u003e\u003c/a\u003e 12.3.0 version bump\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/e63fc481dc2e07e21d5403deafb8f1ed98a513af\"\u003e\u003ccode\u003ee63fc48\u003c/code\u003e\u003c/a\u003e Add release notes for SBOM and performance improvements (\u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9747\"\u003e#9747\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/13b701bbab291eec4bc87ea17ba06c94e5fe3054\"\u003e\u003ccode\u003e13b701b\u003c/code\u003e\u003c/a\u003e Add release notes for \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9679\"\u003e#9679\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/5564ca72fcd59d040e270af5dcf17a0d7161c364\"\u003e\u003ccode\u003e5564ca7\u003c/code\u003e\u003c/a\u003e List methods\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/a0920fd384f800b5d0ba3dd29ecdeae4f1d4043b\"\u003e\u003ccode\u003ea0920fd\u003c/code\u003e\u003c/a\u003e Speed up ImageChops operations (\u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9738\"\u003e#9738\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/07e9a6cd5336dc6cf8cae9165cd70cdd2b3e42fc\"\u003e\u003ccode\u003e07e9a6c\u003c/code\u003e\u003c/a\u003e Speed up \u003ccode\u003eImage.filter()\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9736\"\u003e#9736\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/a94578cf9649ea13e426cf7fb2b71b39ffc0dd50\"\u003e\u003ccode\u003ea94578c\u003c/code\u003e\u003c/a\u003e Speed up \u003ccode\u003eImage.getchannel()\u003c/code\u003e, \u003ccode\u003eImage.merge()\u003c/code\u003e, \u003ccode\u003eImage.putalpha()\u003c/code\u003e and `Image...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/53e02c43c919d149b2a154a5180079f9df18fbbb\"\u003e\u003ccode\u003e53e02c4\u003c/code\u003e\u003c/a\u003e Speed up \u003ccode\u003eImage.fill()\u003c/code\u003e, \u003ccode\u003eImage.linear_gradient()\u003c/code\u003e and `Image.radial_gradient...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/af037475be8634ba739744243164ba9e2c8346a6\"\u003e\u003ccode\u003eaf03747\u003c/code\u003e\u003c/a\u003e Speed up \u003ccode\u003eImage.resample()\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9739\"\u003e#9739\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/5c9ca56c3e5fba52b647809fbb0986c87e73a571\"\u003e\u003ccode\u003e5c9ca56\u003c/code\u003e\u003c/a\u003e Speed up \u003ccode\u003ealpha_composite\u003c/code\u003e, \u003ccode\u003ematrix\u003c/code\u003e, \u003ccode\u003enegative\u003c/code\u003e, \u003ccode\u003equantize\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9740\"\u003e#9740\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/python-pillow/Pillow/compare/10.3.0...12.3.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/RemyLoveLogicAI/suna/network/alerts).\n\n\u003c/details\u003e\n\n\u003cdiv id='description'\u003e\n\u003ca href=\"https://bito.ai#summarystart\"\u003e\u003c/a\u003e\u003ch3\u003eSummary by Bito\u003c/h3\u003e\u003cul\u003e\u003cli\u003eUpdated aiohttp dependency from 3.12.14 to 3.14.3 in backend/poetry.lock and backend/pyproject.toml.\u003c/li\u003e\n\u003cli\u003eUpdated backend/sandbox/docker/requirements.txt to reflect dependency changes.\u003c/li\u003e\n\u003cli\u003eUpdated frontend/package.json and frontend/package-lock.json with various dependency updates.\u003c/li\u003e\n\u003cli\u003eIncreased minimum Python version requirement for aiohttp to 3.10.\u003c/li\u003e\n\u003c/ul\u003e\u003c/div\u003e\n\n\u003c!-- This is an auto-generated description by cubic. --\u003e\n---\n## Summary by cubic\nBumps 8 Python dependencies in `backend` and `backend/sandbox/docker`, pulling in security fixes for `pyjwt`, `gitpython`, and `tornado`.\n\n**Notes**\n- `pyjwt` 2.13.0 now raises `InvalidKeyError` on empty HMAC secrets and rejects non-HTTP(S) `PyJWKClient` URIs.\n- `python-multipart` 0.0.31 adds header and boundary size limits and rejects negative `Content-Length`.\n- `h2` 4.4.1 drops Python 3.9 and raises `NoSuchStreamError`/`StreamClosedError` instead of `KeyError` for closed streams.\n- `setuptools`, `aiohttp`, and `python-multipart` now require Python 3.10+, which is satisfied by `python = \"^3.11\"`.\n\n\u003csup\u003eWritten for commit 0b5994a4f371a4bc53a09cf49370ed24e8f9df1b. Summary will update on new commits.\u003c/sup\u003e\n\n\u003ca href=\"https://cubic.dev/pr/RemyLoveLogicAI/suna/pull/26?utm_source=github\" target=\"_blank\" rel=\"noopener noreferrer\" data-no-image-dialog=\"true\"\u003e\u003cpicture\u003e\u003csource media=\"(prefers-color-scheme: dark)\" srcset=\"https://www.cubic.dev/buttons/review-in-cubic-dark.svg\"\u003e\u003csource media=\"(prefers-color-scheme: light)\" srcset=\"https://www.cubic.dev/buttons/review-in-cubic-light.svg\"\u003e\u003cimg alt=\"Review in cubic\" src=\"https://www.cubic.dev/buttons/review-in-cubic-dark.svg\"\u003e\u003c/picture\u003e\u003c/a\u003e\n\n\u003c!-- End of auto-generated description by cubic. --\u003e\n\n","html_url":"https://github.com/RemyLoveLogicAI/suna/pull/26","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/RemyLoveLogicAI%2Fsuna/issues/26","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/26/packages"}},{"old_version":"3.9.5","new_version":"3.14.3","update_type":"minor","path":null,"pr_created_at":"2026-09-17T11:04:28.000Z","version_change":"3.9.5 → 3.14.3","issue":{"uuid":"5486487206","node_id":"PR_kwDOLyV66M8AAAABD6imRQ","number":1,"state":"open","title":"chore(deps): bump the pip group across 1 directory with 12 updates","user":"dependabot[bot]","labels":["dependencies","python"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-17T11:04:28.000Z","updated_at":"2026-09-17T11:04:50.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps): bump","group_name":"pip","update_count":12,"packages":[{"name":"aiohttp","old_version":"3.9.5","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"cryptography","old_version":"42.0.5","new_version":"50.0.0","repository_url":"https://github.com/pyca/cryptography"},{"name":"flask","old_version":"3.0.3","new_version":"3.1.3","repository_url":"https://github.com/pallets/flask"},{"name":"httplib2","old_version":"0.22.0","new_version":"0.32.0","repository_url":"https://github.com/httplib2/httplib2"},{"name":"idna","old_version":"3.7","new_version":"3.15","repository_url":"https://github.com/kjd/idna"},{"name":"marshmallow","old_version":"3.21.1","new_version":"3.26.2","repository_url":"https://github.com/marshmallow-code/marshmallow"},{"name":"orjson","old_version":"3.10.1","new_version":"3.11.6","repository_url":"https://github.com/ijl/orjson"},{"name":"pillow","old_version":"10.3.0","new_version":"12.3.0","repository_url":"https://github.com/python-pillow/Pillow"},{"name":"pyasn1","old_version":"0.6.0","new_version":"0.6.4","repository_url":"https://github.com/pyasn1/pyasn1"},{"name":"requests","old_version":"2.31.0","new_version":"2.33.0","repository_url":"https://github.com/psf/requests"},{"name":"urllib3","old_version":"2.2.1","new_version":"2.7.0","repository_url":"https://github.com/urllib3/urllib3"},{"name":"werkzeug","old_version":"3.0.2","new_version":"3.1.8","repository_url":"https://github.com/pallets/werkzeug"}],"path":null,"ecosystem":"pip"},"body":"Bumps the pip group with 12 updates in the /src/shoppingassistantservice directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [aiohttp](https://github.com/aio-libs/aiohttp) | `3.9.5` | `3.14.3` |\n| [cryptography](https://github.com/pyca/cryptography) | `42.0.5` | `50.0.0` |\n| [flask](https://github.com/pallets/flask) | `3.0.3` | `3.1.3` |\n| [httplib2](https://github.com/httplib2/httplib2) | `0.22.0` | `0.32.0` |\n| [idna](https://github.com/kjd/idna) | `3.7` | `3.15` |\n| [marshmallow](https://github.com/marshmallow-code/marshmallow) | `3.21.1` | `3.26.2` |\n| [orjson](https://github.com/ijl/orjson) | `3.10.1` | `3.11.6` |\n| [pillow](https://github.com/python-pillow/Pillow) | `10.3.0` | `12.3.0` |\n| [pyasn1](https://github.com/pyasn1/pyasn1) | `0.6.0` | `0.6.4` |\n| [requests](https://github.com/psf/requests) | `2.31.0` | `2.33.0` |\n| [urllib3](https://github.com/urllib3/urllib3) | `2.2.1` | `2.7.0` |\n| [werkzeug](https://github.com/pallets/werkzeug) | `3.0.2` | `3.1.8` |\n\n\nUpdates `aiohttp` from 3.9.5 to 3.14.3\nUpdates `cryptography` from 42.0.5 to 50.0.0\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst\"\u003ecryptography's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e50.0.0 - 2026-07-31\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003e\n* **SECURITY ISSUE**:\n  :func:`~cryptography.hazmat.primitives.serialization.pkcs7.pkcs7_decrypt_der`\n  and its PEM and S/MIME variants no longer expose distinguishable errors or\n  timing when unwrapping a ``RecipientInfo``'s ``encryptedKey``, which could\n  act as a Bleichenbacher oracle for callers that decrypt untrusted messages.\n  A random key is now substituted on failure, as described in :rfc:`3218`.\n  Credit to **@X1AOxiang** for reporting the issue. **CVE-2026-69247**\n* Deprecated Diffie-Hellman key exchange over finite fields (FFDH).\n  Everything FFDH is deprecated, including the types in\n  ``cryptography.hazmat.primitives.asymmetric.dh`` and loading FFDH keys or\n  parameters with the key loading APIs. Users should migrate to a more\n  modern key exchange algorithm.\n* Added ``xof()`` class methods to\n  :class:`~cryptography.hazmat.primitives.hashes.SHAKE128` and\n  :class:`~cryptography.hazmat.primitives.hashes.SHAKE256` for constructing\n  algorithm instances configured for use with\n  :class:`~cryptography.hazmat.primitives.hashes.XOFHash`.\n* The :mod:`X.509 verification \u0026lt;cryptography.x509.verification\u0026gt;` APIs are now\n  considered stable and are subject to our API stability policy.\n* Added the :doc:`/cobblestone` recipe, an implementation of the\n  Cobblestone-128 and Cobblestone-256 instantiations of the `C2SP\n  chunked-encryption specification\n  \u0026lt;https://c2sp.org/chunked-encryption\u0026gt;`_ for streaming authenticated\n  encryption of large messages.\n* Parsing a Signed Certificate Timestamp list now rejects encodings that\n  carry trailing bytes after the list or after an individual SCT, instead of\n  silently ignoring them.\n* Added support for using :class:`~cryptography.x509.Name` as a field type in\n  the :doc:`/hazmat/asn1/index` module.\n* Loading a public key or an EC private key now rejects DER where the\n  ``subjectPublicKey`` (or EC ``publicKey``) ``BIT STRING`` declares a non-zero\n  number of unused bits, instead of silently ignoring it.\n* Parsing a CRL entry's ``InvalidityDate`` extension now rejects a\n  ``GeneralizedTime`` that carries fractional seconds or another non-DER form,\n  matching the strict encoding already required for every other X.509 time\n  field.\n* :func:`~cryptography.x509.ocsp.load_der_ocsp_request` and\n  :func:`~cryptography.x509.ocsp.load_der_ocsp_response` now reject a request\n  or response whose ``version`` field is not ``v1``, the only version defined\n  by RFC 6960, matching the version validation already performed when loading\n  certificates, CSRs and CRLs.\n* :class:`~cryptography.hazmat.primitives.hashes.XOFHash` is now supported\n  when building against AWS-LC.\n* HMAC (and therefore PBKDF2-HMAC) with SHA-3 hashes is now supported when\n  building against AWS-LC.\n* Diffie-Hellman (:doc:`/hazmat/primitives/asymmetric/dh`) is now supported\n  when building against AWS-LC.\n\u0026lt;/tr\u0026gt;\u0026lt;/table\u0026gt; \n\u003c/code\u003e\u003c/pre\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/dcb7050b807b00392fa9fe2eac7cb362fcf355cc\"\u003e\u003ccode\u003edcb7050\u003c/code\u003e\u003c/a\u003e Prepare for 50.0.0 release (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15372\"\u003e#15372\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/53fccd93413a8d7f07d6d8999681f27b75cffa3f\"\u003e\u003ccode\u003e53fccd9\u003c/code\u003e\u003c/a\u003e Don't leak how PKCS#7 encryptedKey decryption failed (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15369\"\u003e#15369\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/d472f978470fbefa521b86d98b2ecccbbb4d1dd8\"\u003e\u003ccode\u003ed472f97\u003c/code\u003e\u003c/a\u003e Add \u003ccode\u003efrom __future__ import annotations\u003c/code\u003e to all src/ Python files (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15371\"\u003e#15371\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/908773d53829fb1466c6db364b31321c3cd8eb9a\"\u003e\u003ccode\u003e908773d\u003c/code\u003e\u003c/a\u003e Bump downstream dependencies in CI (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15368\"\u003e#15368\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/2cc07cc948948211899bcb0cddd1fddf86e95812\"\u003e\u003ccode\u003e2cc07cc\u003c/code\u003e\u003c/a\u003e Bump BoringSSL, OpenSSL, AWS-LC in CI (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15367\"\u003e#15367\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/c94ede9f040fa44942f7139772603419000acf66\"\u003e\u003ccode\u003ec94ede9\u003c/code\u003e\u003c/a\u003e chore(deps): bump ruff from 0.16.0 to 0.16.1 (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15366\"\u003e#15366\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/67a8308dc9ea4cce6056e0f1438f903c208c3f35\"\u003e\u003ccode\u003e67a8308\u003c/code\u003e\u003c/a\u003e chore(deps): bump virtualenv from 21.7.0 to 21.7.1 (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15365\"\u003e#15365\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/95018ffcdbbc510fd92fc872e3a3e80aa6e58596\"\u003e\u003ccode\u003e95018ff\u003c/code\u003e\u003c/a\u003e Release the GIL in one-shot AEAD encrypt/decrypt (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15361\"\u003e#15361\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/6954733eaf55a0074abf88f06f7242dfca3a5d02\"\u003e\u003ccode\u003e6954733\u003c/code\u003e\u003c/a\u003e Release the GIL during DH and DSA parameter generation (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15364\"\u003e#15364\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyca/cryptography/commit/6893b94c33e948f6240082461424cfb5da2dacc6\"\u003e\u003ccode\u003e6893b94\u003c/code\u003e\u003c/a\u003e Import _serialization instead of serialization in x509/extensions (\u003ca href=\"https://redirect.github.com/pyca/cryptography/issues/15363\"\u003e#15363\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/pyca/cryptography/compare/42.0.5...50.0.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `flask` from 3.0.3 to 3.1.3\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pallets/flask/releases\"\u003eflask's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e3.1.3\u003c/h2\u003e\n\u003cp\u003eThis is the Flask 3.1.3 security fix release, which fixes a security issue but does not otherwise change behavior and should not result in breaking changes compared to the latest feature release.\u003c/p\u003e\n\u003cp\u003ePyPI: \u003ca href=\"https://pypi.org/project/Flask/3.1.3/\"\u003ehttps://pypi.org/project/Flask/3.1.3/\u003c/a\u003e\nChanges: \u003ca href=\"https://flask.palletsprojects.com/page/changes/#version-3-1-3\"\u003ehttps://flask.palletsprojects.com/page/changes/#version-3-1-3\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eThe session is marked as accessed for operations that only access the keys but not the values, such as \u003ccode\u003ein\u003c/code\u003e and \u003ccode\u003elen\u003c/code\u003e. \u003ca href=\"https://github.com/pallets/flask/security/advisories/GHSA-68rp-wp8r-4726\"\u003eGHSA-68rp-wp8r-4726\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.1.2\u003c/h2\u003e\n\u003cp\u003eThis is the Flask 3.1.2 fix release, which fixes bugs but does not otherwise change behavior and should not result in breaking changes compared to the latest feature release.\u003c/p\u003e\n\u003cp\u003ePyPI: \u003ca href=\"https://pypi.org/project/Flask/3.1.2/\"\u003ehttps://pypi.org/project/Flask/3.1.2/\u003c/a\u003e\nChanges: \u003ca href=\"https://flask.palletsprojects.com/page/changes/#version-3-1-2\"\u003ehttps://flask.palletsprojects.com/page/changes/#version-3-1-2\u003c/a\u003e\nMilestone: \u003ca href=\"https://github.com/pallets/flask/milestone/38?closed=1\"\u003ehttps://github.com/pallets/flask/milestone/38?closed=1\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003estream_with_context\u003c/code\u003e does not fail inside async views. \u003ca href=\"https://redirect.github.com/pallets/flask/issues/5774\"\u003e#5774\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eWhen using \u003ccode\u003efollow_redirects\u003c/code\u003e in the test client, the final state of \u003ccode\u003esession\u003c/code\u003e is correct. \u003ca href=\"https://redirect.github.com/pallets/flask/issues/5786\"\u003e#5786\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRelax type hint for passing bytes IO to \u003ccode\u003esend_file\u003c/code\u003e. \u003ca href=\"https://redirect.github.com/pallets/flask/issues/5776\"\u003e#5776\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.1.1\u003c/h2\u003e\n\u003cp\u003eThis is the Flask 3.1.1 fix release, which fixes bugs but does not otherwise change behavior and should not result in breaking changes compared to the latest feature release.\u003c/p\u003e\n\u003cp\u003ePyPI: \u003ca href=\"https://pypi.org/project/Flask/3.1.1/\"\u003ehttps://pypi.org/project/Flask/3.1.1/\u003c/a\u003e\nChanges: \u003ca href=\"https://flask.palletsprojects.com/en/stable/changes/#version-3-1-1\"\u003ehttps://flask.palletsprojects.com/en/stable/changes/#version-3-1-1\u003c/a\u003e\nMilestone \u003ca href=\"https://github.com/pallets/flask/milestone/36?closed=1\"\u003ehttps://github.com/pallets/flask/milestone/36?closed=1\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eFix signing key selection order when key rotation is enabled via \u003ccode\u003eSECRET_KEY_FALLBACKS\u003c/code\u003e. GHSA-4grg-w6v8-c28g\u003c/li\u003e\n\u003cli\u003eFix type hint for \u003ccode\u003ecli_runner.invoke\u003c/code\u003e. \u003ca href=\"https://redirect.github.com/pallets/flask/issues/5645\"\u003e#5645\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eflask --help\u003c/code\u003e loads the app and plugins first to make sure all commands are shown. \u003ca href=\"https://redirect.github.com/pallets/flask/issues/5673\"\u003e#5673\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eMark sans-io base class as being able to handle views that return \u003ccode\u003eAsyncIterable\u003c/code\u003e. This is not accurate for Flask, but makes typing easier for Quart. \u003ca href=\"https://redirect.github.com/pallets/flask/issues/5659\"\u003e#5659\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.1.0\u003c/h2\u003e\n\u003cp\u003eThis is the Flask 3.1.0 feature release. A feature release may include new features, remove previously deprecated code, add new deprecations, or introduce potentially breaking changes. We encourage everyone to upgrade, and to use a tool such as \u003ca href=\"https://pypi.org/project/pip-tools/\"\u003epip-tools\u003c/a\u003e to pin all dependencies and control upgrades. Test with warnings treated as errors to be able to adapt to deprecation warnings early.\u003c/p\u003e\n\u003cp\u003ePyPI: \u003ca href=\"https://pypi.org/project/Flask/3.1.0/\"\u003ehttps://pypi.org/project/Flask/3.1.0/\u003c/a\u003e\nChanges: \u003ca href=\"https://flask.palletsprojects.com/en/stable/changes/#version-3-1-0\"\u003ehttps://flask.palletsprojects.com/en/stable/changes/#version-3-1-0\u003c/a\u003e\nMilestone: \u003ca href=\"https://github.com/pallets/flask/milestone/33?closed=1\"\u003ehttps://github.com/pallets/flask/milestone/33?closed=1\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eDrop support for Python 3.8. \u003ca href=\"https://redirect.github.com/pallets/flask/issues/5623\"\u003e#5623\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate minimum dependency versions to latest feature releases. Werkzeug \u0026gt;= 3.1, ItsDangerous \u0026gt;= 2.2, Blinker \u0026gt;= 1.9. \u003ca href=\"https://redirect.github.com/pallets/flask/issues/5624\"\u003e#5624\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/pallets/flask/issues/5633\"\u003e#5633\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eProvide a configuration option to control automatic option responses. \u003ca href=\"https://redirect.github.com/pallets/flask/issues/5496\"\u003e#5496\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eFlask.open_resource\u003c/code\u003e/\u003ccode\u003eopen_instance_resource\u003c/code\u003e and \u003ccode\u003eBlueprint.open_resource\u003c/code\u003e take an \u003ccode\u003eencoding\u003c/code\u003e parameter to use when opening in text mode. It defaults to \u003ccode\u003eutf-8\u003c/code\u003e. \u003ca href=\"https://redirect.github.com/pallets/flask/issues/5504\"\u003e#5504\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eRequest.max_content_length\u003c/code\u003e can be customized per-request instead of only through the \u003ccode\u003eMAX_CONTENT_LENGTH\u003c/code\u003e config. Added \u003ccode\u003eMAX_FORM_MEMORY_SIZE\u003c/code\u003e and \u003ccode\u003eMAX_FORM_PARTS\u003c/code\u003e config. Added documentation about resource limits to the security page. \u003ca href=\"https://redirect.github.com/pallets/flask/issues/5625\"\u003e#5625\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd support for the \u003ccode\u003ePartitioned\u003c/code\u003e cookie attribute (CHIPS), with the \u003ccode\u003eSESSION_COOKIE_PARTITIONED\u003c/code\u003e config. \u003ca href=\"https://redirect.github.com/pallets/flask/issues/5472\"\u003e#5472\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e-e path\u003c/code\u003e takes precedence over default \u003ccode\u003e.env\u003c/code\u003e and \u003ccode\u003e.flaskenv\u003c/code\u003e files. \u003ccode\u003eload_dotenv\u003c/code\u003e loads default files in addition to a path unless \u003ccode\u003eload_defaults=False\u003c/code\u003e is passed. \u003ca href=\"https://redirect.github.com/pallets/flask/issues/5628\"\u003e#5628\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSupport key rotation with the \u003ccode\u003eSECRET_KEY_FALLBACKS\u003c/code\u003e config, a list of old secret keys that can still be used for unsigning. Extensions will need to add support. \u003ca href=\"https://redirect.github.com/pallets/flask/issues/5621\"\u003e#5621\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix how setting \u003ccode\u003ehost_matching=True\u003c/code\u003e or \u003ccode\u003esubdomain_matching=False\u003c/code\u003e interacts with \u003ccode\u003eSERVER_NAME\u003c/code\u003e. Setting \u003ccode\u003eSERVER_NAME\u003c/code\u003e no longer restricts requests to only that domain. \u003ca href=\"https://redirect.github.com/pallets/flask/issues/5553\"\u003e#5553\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eRequest.trusted_hosts\u003c/code\u003e is checked during routing, and can be set through the \u003ccode\u003eTRUSTED_HOSTS\u003c/code\u003e config. \u003ca href=\"https://redirect.github.com/pallets/flask/issues/5636\"\u003e#5636\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pallets/flask/blob/main/CHANGES.rst\"\u003eflask's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eVersion 3.1.3\u003c/h2\u003e\n\u003cp\u003eReleased 2026-02-18\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eThe session is marked as accessed for operations that only access the keys\nbut not the values, such as \u003ccode\u003ein\u003c/code\u003e and \u003ccode\u003elen\u003c/code\u003e. :ghsa:\u003ccode\u003e68rp-wp8r-4726\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eVersion 3.1.2\u003c/h2\u003e\n\u003cp\u003eReleased 2025-08-19\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003estream_with_context\u003c/code\u003e does not fail inside async views. :issue:\u003ccode\u003e5774\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eWhen using \u003ccode\u003efollow_redirects\u003c/code\u003e in the test client, the final state\nof \u003ccode\u003esession\u003c/code\u003e is correct. :issue:\u003ccode\u003e5786\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eRelax type hint for passing bytes IO to \u003ccode\u003esend_file\u003c/code\u003e. :issue:\u003ccode\u003e5776\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eVersion 3.1.1\u003c/h2\u003e\n\u003cp\u003eReleased 2025-05-13\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eFix signing key selection order when key rotation is enabled via\n\u003ccode\u003eSECRET_KEY_FALLBACKS\u003c/code\u003e. :ghsa:\u003ccode\u003e4grg-w6v8-c28g\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eFix type hint for \u003ccode\u003ecli_runner.invoke\u003c/code\u003e. :issue:\u003ccode\u003e5645\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eflask --help\u003c/code\u003e loads the app and plugins first to make sure all commands\nare shown. :issue:\u003ccode\u003e5673\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eMark sans-io base class as being able to handle views that return\n\u003ccode\u003eAsyncIterable\u003c/code\u003e. This is not accurate for Flask, but makes typing easier\nfor Quart. :pr:\u003ccode\u003e5659\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eVersion 3.1.0\u003c/h2\u003e\n\u003cp\u003eReleased 2024-11-13\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eDrop support for Python 3.8. :pr:\u003ccode\u003e5623\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eUpdate minimum dependency versions to latest feature releases.\nWerkzeug \u0026gt;= 3.1, ItsDangerous \u0026gt;= 2.2, Blinker \u0026gt;= 1.9. :pr:\u003ccode\u003e5624,5633\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eProvide a configuration option to control automatic option\nresponses. :pr:\u003ccode\u003e5496\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eFlask.open_resource\u003c/code\u003e/\u003ccode\u003eopen_instance_resource\u003c/code\u003e and\n\u003ccode\u003eBlueprint.open_resource\u003c/code\u003e take an \u003ccode\u003eencoding\u003c/code\u003e parameter to use when\nopening in text mode. It defaults to \u003ccode\u003eutf-8\u003c/code\u003e. :issue:\u003ccode\u003e5504\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eRequest.max_content_length\u003c/code\u003e can be customized per-request instead of only\nthrough the \u003ccode\u003eMAX_CONTENT_LENGTH\u003c/code\u003e config. Added\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pallets/flask/commit/22d924701a6ae2e4cd01e9a15bbaf3946094af65\"\u003e\u003ccode\u003e22d9247\u003c/code\u003e\u003c/a\u003e release version 3.1.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pallets/flask/commit/089cb86dd22bff589a4eafb7ab8e42dc357623b4\"\u003e\u003ccode\u003e089cb86\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pallets/flask/commit/c17f379390731543eea33a570a47bd4ef76a54fa\"\u003e\u003ccode\u003ec17f379\u003c/code\u003e\u003c/a\u003e request context tracks session access\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pallets/flask/commit/27be9338405382445a7cb01151e084559b98d602\"\u003e\u003ccode\u003e27be933\u003c/code\u003e\u003c/a\u003e start version 3.1.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pallets/flask/commit/4e652d3f68b90d50aa2301d3b7e68c3fafd9251d\"\u003e\u003ccode\u003e4e652d3\u003c/code\u003e\u003c/a\u003e Abort if the instance folder cannot be created (\u003ca href=\"https://redirect.github.com/pallets/flask/issues/5903\"\u003e#5903\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pallets/flask/commit/3d03098a97ddc6a908aa4a50c2ef7381f8297d0a\"\u003e\u003ccode\u003e3d03098\u003c/code\u003e\u003c/a\u003e Abort if the instance folder cannot be created\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pallets/flask/commit/407eb76b27884848383a37c7274654f0271e4bc4\"\u003e\u003ccode\u003e407eb76\u003c/code\u003e\u003c/a\u003e document using gevent for async (\u003ca href=\"https://redirect.github.com/pallets/flask/issues/5900\"\u003e#5900\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pallets/flask/commit/ac5664d2281533eacafd64f5cc7d5edcdaccab60\"\u003e\u003ccode\u003eac5664d\u003c/code\u003e\u003c/a\u003e document using gevent for async\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pallets/flask/commit/4f79d5b59a56bc4356a97f2e81a35f98cb18d7b3\"\u003e\u003ccode\u003e4f79d5b\u003c/code\u003e\u003c/a\u003e Increase required flit_core version to 3.11 (\u003ca href=\"https://redirect.github.com/pallets/flask/issues/5865\"\u003e#5865\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pallets/flask/commit/fe3b215d3ade4db68262dae1a3cdc464a1fc524f\"\u003e\u003ccode\u003efe3b215\u003c/code\u003e\u003c/a\u003e Increase required flit_core version to 3.11\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/pallets/flask/compare/3.0.3...3.1.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `httplib2` from 0.22.0 to 0.32.0\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/httplib2/httplib2/blob/master/CHANGELOG\"\u003ehttplib2's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e0.32.0\u003c/p\u003e\n\u003cp\u003ePython support 3.8+ only\u003c/p\u003e\n\u003cp\u003edecompression limited by size and ratio\u003c/p\u003e\n\u003cp\u003edecoder foundation to support more compression algorithms\u003c/p\u003e\n\u003cp\u003e0.31.2\u003c/p\u003e\n\u003cp\u003ebuild(deps): pp.DelimitedList (camel case) only available in pyparsing\u0026gt;=3.1\n\u003ca href=\"https://redirect.github.com/httplib2/httplib2/issues/255\"\u003ehttplib2/httplib2#255\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eDO NOT use 0.31.1\u003c/p\u003e\n\u003cp\u003e0.31.1\u003c/p\u003e\n\u003cp\u003eauth: use pyparsing v3 PEP8-compliant method names\n\u003ca href=\"https://redirect.github.com/httplib2/httplib2/pull/253\"\u003ehttplib2/httplib2#253\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e0.31.0\u003c/p\u003e\n\u003cp\u003ehttps: avoid costly load_verify_locations when SSL certificate validation is disabled\n\u003ca href=\"https://redirect.github.com/httplib2/httplib2/pull/249\"\u003ehttplib2/httplib2#249\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e0.30.2\u003c/p\u003e\n\u003cp\u003eNo changes in library. Fix automatic pypi release from CI.\u003c/p\u003e\n\u003cp\u003e0.30.1\u003c/p\u003e\n\u003cp\u003erestore socks proxy support, was broken in 0.30.0\n\u003ca href=\"https://redirect.github.com/httplib2/httplib2/issues/251\"\u003ehttplib2/httplib2#251\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e0.30.0\u003c/p\u003e\n\u003cp\u003eBREAKING CHANGE! Python support 3.7+ only\u003c/p\u003e\n\u003cp\u003ehttps: Do not rely on ssl.PROTOCOL_TLS, which has been deprecated in Python3.10\n\u003ca href=\"https://redirect.github.com/httplib2/httplib2/pull/243\"\u003ehttplib2/httplib2#243\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/httplib2/httplib2/commit/ba9bf505cd899f522f2bb58ca608444adf49afc1\"\u003e\u003ccode\u003eba9bf50\u003c/code\u003e\u003c/a\u003e v0.32.0 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/httplib2/httplib2/commit/87581ad6cf752fe3da2090c59058261d2d00a427\"\u003e\u003ccode\u003e87581ad\u003c/code\u003e\u003c/a\u003e decompression limited by size and ratio; require python 3.8+\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/httplib2/httplib2/commit/a99a11fba8d5fa3bb9c47827e5cbfd641dfb88d3\"\u003e\u003ccode\u003ea99a11f\u003c/code\u003e\u003c/a\u003e v0.31.2 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/httplib2/httplib2/commit/370010a12ef4b97ebeeac59f52d071de7bc3faa8\"\u003e\u003ccode\u003e370010a\u003c/code\u003e\u003c/a\u003e dep-compat: pp.DelimitedList (camel case) only available in pyparsing\u0026gt;=3.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/httplib2/httplib2/commit/6d2ea322d53a03d058cd8e63c12871cdd1127ca9\"\u003e\u003ccode\u003e6d2ea32\u003c/code\u003e\u003c/a\u003e v0.31.1 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/httplib2/httplib2/commit/d1b0ce329667f0b0047381c089e53ea1055f2fca\"\u003e\u003ccode\u003ed1b0ce3\u003c/code\u003e\u003c/a\u003e auth: use pyparsing v3 PEP8-compliant method names\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/httplib2/httplib2/commit/3288ba77ccb1924a6a79350f300ebb84140ec064\"\u003e\u003ccode\u003e3288ba7\u003c/code\u003e\u003c/a\u003e chore: harden publishing. use github attestations\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/httplib2/httplib2/commit/26cfea5d07a5817cf214d9978c856c91abf4e078\"\u003e\u003ccode\u003e26cfea5\u003c/code\u003e\u003c/a\u003e v0.31.0 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/httplib2/httplib2/commit/cbd3d21004374997167d9b8ab36b4ec211881a57\"\u003e\u003ccode\u003ecbd3d21\u003c/code\u003e\u003c/a\u003e chore: CI use trusted publishing\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/httplib2/httplib2/commit/147d7d5d00b4cd383dbdda839089237aa0c2a836\"\u003e\u003ccode\u003e147d7d5\u003c/code\u003e\u003c/a\u003e https: avoid costly load_verify_locations when SSL certificate validation is ...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/httplib2/httplib2/compare/v0.22.0...v0.32.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `idna` from 3.7 to 3.15\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/kjd/idna/releases\"\u003eidna's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev3.15\u003c/h2\u003e\n\u003cp\u003eNo release notes provided.\u003c/p\u003e\n\u003ch2\u003ev3.14\u003c/h2\u003e\n\u003cp\u003eNo release notes provided.\u003c/p\u003e\n\u003ch2\u003ev3.13\u003c/h2\u003e\n\u003cp\u003eNo release notes provided.\u003c/p\u003e\n\u003ch2\u003ev3.12\u003c/h2\u003e\n\u003cp\u003eNo release notes provided.\u003c/p\u003e\n\u003ch2\u003ev3.11\u003c/h2\u003e\n\u003cp\u003eNo release notes provided.\u003c/p\u003e\n\u003ch2\u003ev3.10\u003c/h2\u003e\n\u003cp\u003eNo release notes provided.\u003c/p\u003e\n\u003ch2\u003ev3.9\u003c/h2\u003e\n\u003cp\u003eNo release notes provided.\u003c/p\u003e\n\u003ch2\u003ev3.8\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix regression where IDNAError exception was not being produced for certain inputs.\u003c/li\u003e\n\u003cli\u003eAdd support for Python 3.13, drop support for Python 3.5 as it is no longer testable.\u003c/li\u003e\n\u003cli\u003eDocumentation improvements\u003c/li\u003e\n\u003cli\u003eUpdates to package testing using Github actions\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThanks to Hugo van Kemenade for contributions to this release.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/kjd/idna/compare/v3.7...v3.8\"\u003ehttps://github.com/kjd/idna/compare/v3.7...v3.8\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/kjd/idna/blob/master/HISTORY.md\"\u003eidna's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e3.15 (2026-05-12)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eEnforce DNS-length cap on individual labels early in \u003ccode\u003echeck_label\u003c/code\u003e,\nshort-circuiting contextual-rule processing for oversized input\nwhile staying compatible with UTS 46 usage.\u003c/li\u003e\n\u003cli\u003eTidy core helpers: hoist bidi category sets to module-level\nfrozensets (avoiding per-codepoint list construction), simplify\nlength checks, and reuse the shared \u003ccode\u003e_unicode_dots_re\u003c/code\u003e from\n\u003ccode\u003eidna.core\u003c/code\u003e in the codec module.\u003c/li\u003e\n\u003cli\u003eUse \u003ccode\u003eraise ... from err\u003c/code\u003e for proper exception chaining and\nswitch internal string formatting to f-strings.\u003c/li\u003e\n\u003cli\u003eAllow \u003ccode\u003eflit_core\u003c/code\u003e 4.x in the build backend.\u003c/li\u003e\n\u003cli\u003eExpand the ruff lint set (flake8-bugbear, flake8-simplify,\npyupgrade, perflint) and apply the surfaced fixes; pin lint CI\nto Python 3.14.\u003c/li\u003e\n\u003cli\u003eAdd Dependabot configuration for GitHub Actions.\u003c/li\u003e\n\u003cli\u003eConvert README and HISTORY from reStructuredText to Markdown.\u003c/li\u003e\n\u003cli\u003eReference CVE-2026-45409 for the 3.14 advisory in place of the\ninitial GHSA identifier.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThanks to Felix Yan, Stan Ulbrych, and metsw24-max for\ncontributions to this release.\u003c/p\u003e\n\u003ch2\u003e3.14 (2026-05-10)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRemoved opportunity to process long inputs into quadratic\ntime by rejecting oversize inputs up-front. Closes a bypass\nof the CVE-2024-3651 mitigation. [CVE-2026-45409]\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThanks to Stan Ulbrych for reporting the issue.\u003c/p\u003e\n\u003ch2\u003e3.13 (2026-04-22)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eCorrect classification error for codepoint U+A7F1\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.12 (2026-04-21)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate to Unicode 17.0.0.\u003c/li\u003e\n\u003cli\u003eIssue a deprecation warning for the transitional argument.\u003c/li\u003e\n\u003cli\u003eAdded lazy-loading to provide some performance improvements.\u003c/li\u003e\n\u003cli\u003eRemoved vestiges of code related to Python 2 support, including\nsegmentation of data structures specific to Jython.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThanks to Rodrigo Nogueira for contributions to this release.\u003c/p\u003e\n\u003ch2\u003e3.11 (2025-10-12)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate to Unicode 16.0.0, including significant changes to UTS46\nprocessing. As a result of Unicode ending support for it, transitional\nprocessing no longer has an effect and returns the same result.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kjd/idna/commit/af30a092e158181d0b35ac66dfa813788126bdd8\"\u003e\u003ccode\u003eaf30a09\u003c/code\u003e\u003c/a\u003e Release 3.15\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kjd/idna/commit/30314d4628744ca14cf2b5820564e5127a9f86f2\"\u003e\u003ccode\u003e30314d4\u003c/code\u003e\u003c/a\u003e Pre-release 3.15rc0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kjd/idna/commit/05d4b219aa9eddc47371fcbd2000f0301016f3e9\"\u003e\u003ccode\u003e05d4b21\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/kjd/idna/issues/237\"\u003e#237\u003c/a\u003e from kjd/convert-docs-to-markdown\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kjd/idna/commit/2987fdba1962bbb2358399e0084ba062b98a0bee\"\u003e\u003ccode\u003e2987fdb\u003c/code\u003e\u003c/a\u003e Convert README and HISTORY from reStructuredText to Markdown\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kjd/idna/commit/59fa8002d514bf4a5ce7b58f67b9ec587d53fa9c\"\u003e\u003ccode\u003e59fa800\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/kjd/idna/issues/236\"\u003e#236\u003c/a\u003e from kjd/dependabot/github_actions/actions-f3e34333ea\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kjd/idna/commit/def69834ced5d4b3c50439d8b99c4c856ec19ca2\"\u003e\u003ccode\u003edef6983\u003c/code\u003e\u003c/a\u003e Merge branch 'master' into dependabot/github_actions/actions-f3e34333ea\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kjd/idna/commit/bbd8004a797185d8c56bb555cd5c88fde05e0631\"\u003e\u003ccode\u003ebbd8004\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/kjd/idna/issues/234\"\u003e#234\u003c/a\u003e from StanFromIreland/patch-1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kjd/idna/commit/edd07c05024344a6ccb517414ccb36683aee99fc\"\u003e\u003ccode\u003eedd07c0\u003c/code\u003e\u003c/a\u003e Bump github/codeql-action from 3.35.2 to 4.35.2 in the actions group\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kjd/idna/commit/5557db030c11bdec50d62aa5f631d705d33ba123\"\u003e\u003ccode\u003e5557db0\u003c/code\u003e\u003c/a\u003e Merge branch 'master' into patch-1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kjd/idna/commit/f11746cf4981d25123ef7830d3ee60f07de8ae3d\"\u003e\u003ccode\u003ef11746c\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/kjd/idna/issues/235\"\u003e#235\u003c/a\u003e from StanFromIreland/patch-2\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/kjd/idna/compare/v3.7...v3.15\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `marshmallow` from 3.21.1 to 3.26.2\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/marshmallow-code/marshmallow/blob/dev/CHANGELOG.rst\"\u003emarshmallow's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e3.26.2 (2025-12-19)\u003c/h2\u003e\n\u003cp\u003eBug fixes:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e:cve:\u003ccode\u003e2025-68480\u003c/code\u003e: Merge error store messages without rebuilding collections.\nThanks 카푸치노 for reporting and :user:\u003ccode\u003edeckar01\u003c/code\u003e for the fix.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.26.1 (2025-02-03)\u003c/h2\u003e\n\u003cp\u003eBug fixes:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eTyping: Fix type annotations for \u003ccode\u003eclass Meta \u0026lt;marshmallow.Schema.Meta\u0026gt;\u003c/code\u003e options (:issue:\u003ccode\u003e2804\u003c/code\u003e).\nThanks :user:\u003ccode\u003elawrence-law\u003c/code\u003e for reporting.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eOther changes:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eRemove default value for the \u003ccode\u003edata\u003c/code\u003e param of \u003ccode\u003eNested._deserialize \u0026lt;marshmallow.fields.Nested._deserialize\u0026gt;\u003c/code\u003e (:issue:\u003ccode\u003e2802\u003c/code\u003e).\nThanks :user:\u003ccode\u003egbenson\u003c/code\u003e for reporting.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.26.0 (2025-01-22)\u003c/h2\u003e\n\u003cp\u003eFeatures:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eTyping: Add type annotations and improved documentation for \u003ccode\u003eclass Meta \u0026lt;marshmallow.Schema.Meta\u0026gt;\u003c/code\u003e options (:pr:\u003ccode\u003e2760\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eTyping: Improve type coverage of \u003ccode\u003emarshmallow.Schema.SchemaMeta\u003c/code\u003e (:pr:\u003ccode\u003e2761\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eTyping: \u003ccode\u003emarshmallow.Schema.loads\u003c/code\u003e parameter allows \u003ccode\u003ebytes\u003c/code\u003e and \u003ccode\u003ebytesarray\u003c/code\u003e (:pr:\u003ccode\u003e2769\u003c/code\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eBug fixes:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eRespect \u003ccode\u003edata_key\u003c/code\u003e when schema validators raise a \u003ccode\u003eValidationError \u0026lt;marshmallow.exceptions.ValidationError\u0026gt;\u003c/code\u003e\nwith a \u003ccode\u003efield_name\u003c/code\u003e argument (:issue:\u003ccode\u003e2170\u003c/code\u003e). Thanks :user:\u003ccode\u003ematejsp\u003c/code\u003e for reporting.\u003c/li\u003e\n\u003cli\u003eCorrectly handle multiple \u003ccode\u003e@post_load \u0026lt;marshmallow.post_load\u0026gt;\u003c/code\u003e methods where one method appends to\nthe data and another passes \u003ccode\u003epass_original=True\u003c/code\u003e (:issue:\u003ccode\u003e1755\u003c/code\u003e).\nThanks :user:\u003ccode\u003eghostwheel42\u003c/code\u003e for reporting.\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eURL\u003c/code\u003e fields now properly validate \u003ccode\u003efile\u003c/code\u003e paths (:issue:\u003ccode\u003e2249\u003c/code\u003e).\nThanks :user:\u003ccode\u003e0xDEC0DE\u003c/code\u003e for reporting and fixing.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eDocumentation:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAdd :doc:\u003ccode\u003eupgrading guides \u0026lt;upgrading\u0026gt;\u003c/code\u003e for 3.24 and 3.26 (:pr:\u003ccode\u003e2780\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eVarious documentation improvements (:pr:\u003ccode\u003e2757\u003c/code\u003e, :pr:\u003ccode\u003e2759\u003c/code\u003e, :pr:\u003ccode\u003e2765\u003c/code\u003e, :pr:\u003ccode\u003e2774\u003c/code\u003e, :pr:\u003ccode\u003e2778\u003c/code\u003e, :pr:\u003ccode\u003e2783\u003c/code\u003e, :pr:\u003ccode\u003e2796\u003c/code\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eDeprecations:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eThe \u003ccode\u003eordered\u003c/code\u003e \u003ccode\u003eclass Meta \u0026lt;marshmallow.Schema.Meta\u0026gt;\u003c/code\u003e option is deprecated (:issue:\u003ccode\u003e2146\u003c/code\u003e, :pr:\u003ccode\u003e2762\u003c/code\u003e).\nField order is already preserved by default. Set \u003ccode\u003emarshmallow.Schema.dict_class\u003c/code\u003e to \u003ccode\u003ecollections.OrderedDict\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/marshmallow-code/marshmallow/commit/1407d5102ae020421ddc8425474e976325a9539e\"\u003e\u003ccode\u003e1407d51\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/marshmallow-code/marshmallow/issues/2878\"\u003e#2878\u003c/a\u003e from marshmallow-code/3.x-mypy-unreachable\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/marshmallow-code/marshmallow/commit/b2292f513845ccbd134bd55501a9bcbcdd18f8ac\"\u003e\u003ccode\u003eb2292f5\u003c/code\u003e\u003c/a\u003e Fix mypy errors\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/marshmallow-code/marshmallow/commit/8acd211847244fa28e0174728ff310fddf0d7fa2\"\u003e\u003ccode\u003e8acd211\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/marshmallow-code/marshmallow/issues/2877\"\u003e#2877\u003c/a\u003e from marshmallow-code/3.x-delint\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/marshmallow-code/marshmallow/commit/b4bcb4a96f16a3b94c1b52ac82a66b57bbee1d88\"\u003e\u003ccode\u003eb4bcb4a\u003c/code\u003e\u003c/a\u003e [pre-commit.ci] auto fixes from pre-commit.com hooks\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/marshmallow-code/marshmallow/commit/b78af7a0ea3102f8c2379bebe115a015e4018a62\"\u003e\u003ccode\u003eb78af7a\u003c/code\u003e\u003c/a\u003e Delint\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/marshmallow-code/marshmallow/commit/2c4451e5129411da79161add51cfc76fe852549d\"\u003e\u003ccode\u003e2c4451e\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/marshmallow-code/marshmallow/commit/86d101a1aee2fe0a521c976015d1940437493cde\"\u003e\u003ccode\u003e86d101a\u003c/code\u003e\u003c/a\u003e Bump version and update changelog\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/marshmallow-code/marshmallow/commit/489a8d421dc7955bb53b89e962d69465fbc5b6af\"\u003e\u003ccode\u003e489a8d4\u003c/code\u003e\u003c/a\u003e Only deep copy error message collections\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/marshmallow-code/marshmallow/commit/6d4a17dad54ea9711040c6aa6ba4d59267242a41\"\u003e\u003ccode\u003e6d4a17d\u003c/code\u003e\u003c/a\u003e Add test coverage for error message modification\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/marshmallow-code/marshmallow/commit/0356a3f1c307830f8ded56d823abca5611c594c9\"\u003e\u003ccode\u003e0356a3f\u003c/code\u003e\u003c/a\u003e Merge error store messages without rebuilding collections\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/marshmallow-code/marshmallow/compare/3.21.1...3.26.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `orjson` from 3.10.1 to 3.11.6\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/ijl/orjson/releases\"\u003eorjson's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e3.11.6\u003c/h2\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eorjson now includes code licensed under the Mozilla Public License 2.0 (MPL-2.0).\u003c/li\u003e\n\u003cli\u003eDrop support for Python 3.9.\u003c/li\u003e\n\u003cli\u003eABI compatibility with CPython 3.15 alpha 5.\u003c/li\u003e\n\u003cli\u003eBuild now depends on Rust 1.89 or later instead of 1.85.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFix sporadic crash serializing deeply nested \u003ccode\u003elist\u003c/code\u003e of \u003ccode\u003edict\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.11.5\u003c/h2\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eShow simple error message instead of traceback when attempting to\nbuild on unsupported Python versions.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.11.4\u003c/h2\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eABI compatibility with CPython 3.15 alpha 1.\u003c/li\u003e\n\u003cli\u003ePublish PyPI wheels for 3.14 and manylinux i686, manylinux arm7,\nmanylinux ppc64le, manylinux s390x.\u003c/li\u003e\n\u003cli\u003eBuild now requires a C compiler.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.11.3\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFix PyPI project metadata when using maturin 1.9.2 or later.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.11.2\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFix build using Rust 1.89 on amd64.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eBuild now depends on Rust 1.85 or later instead of 1.82.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.11.1\u003c/h2\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ePublish PyPI wheels for CPython 3.14.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFix \u003ccode\u003estr\u003c/code\u003e on big-endian architectures.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.11.0\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/ijl/orjson/blob/master/CHANGELOG.md\"\u003eorjson's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e3.11.6 - 2026-01-29\u003c/h2\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eorjson now includes code licensed under the Mozilla Public License 2.0 (MPL-2.0).\u003c/li\u003e\n\u003cli\u003eDrop support for Python 3.9.\u003c/li\u003e\n\u003cli\u003eABI compatibility with CPython 3.15 alpha 5.\u003c/li\u003e\n\u003cli\u003eBuild now depends on Rust 1.89 or later instead of 1.85.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFix sporadic crash serializing deeply nested \u003ccode\u003elist\u003c/code\u003e of \u003ccode\u003edict\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.11.5 - 2025-12-06\u003c/h2\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eShow simple error message instead of traceback when attempting to\nbuild on unsupported Python versions.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.11.4 - 2025-10-24\u003c/h2\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eABI compatibility with CPython 3.15 alpha 1.\u003c/li\u003e\n\u003cli\u003ePublish PyPI wheels for 3.14 and manylinux i686, manylinux arm7,\nmanylinux ppc64le, manylinux s390x.\u003c/li\u003e\n\u003cli\u003eBuild now requires a C compiler.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.11.3 - 2025-08-26\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFix PyPI project metadata when using maturin 1.9.2 or later.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.11.2 - 2025-08-12\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFix build using Rust 1.89 on amd64.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eBuild now depends on Rust 1.85 or later instead of 1.82.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ijl/orjson/commit/ec02024c3837255064f248c0d2d331319b75e9ad\"\u003e\u003ccode\u003eec02024\u003c/code\u003e\u003c/a\u003e 3.11.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ijl/orjson/commit/d58168733189f82b3fd0c058dff73e05d09202e6\"\u003e\u003ccode\u003ed581687\u003c/code\u003e\u003c/a\u003e build, clippy misc\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ijl/orjson/commit/4105b29b2275f200f6fae01349bef02ccf1bc2e2\"\u003e\u003ccode\u003e4105b29\u003c/code\u003e\u003c/a\u003e writer::num\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ijl/orjson/commit/62bb185b70785ded49c79c26f8c9781f1e6fe370\"\u003e\u003ccode\u003e62bb185\u003c/code\u003e\u003c/a\u003e Fix sporadic crash on serializing object close\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ijl/orjson/commit/d860078a973f44401265c5c4ad12a7dbe4f839ad\"\u003e\u003ccode\u003ed860078\u003c/code\u003e\u003c/a\u003e PyRef idiom refactors\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ijl/orjson/commit/343ae2f148197918aba9f8562db42c364620e4b8\"\u003e\u003ccode\u003e343ae2f\u003c/code\u003e\u003c/a\u003e Deserializer, Utf8Buffer\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ijl/orjson/commit/7835f58d1c56947d1cf7a18acdfc07a2bca9b0f2\"\u003e\u003ccode\u003e7835f58\u003c/code\u003e\u003c/a\u003e PyBytesRef and other input refactor\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ijl/orjson/commit/71e0516424ce1e11613eb1780f18e8cde83989fd\"\u003e\u003ccode\u003e71e0516\u003c/code\u003e\u003c/a\u003e PyStrRef\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ijl/orjson/commit/1096df42dc585fde837ed0c930a346f5ef7dbb94\"\u003e\u003ccode\u003e1096df4\u003c/code\u003e\u003c/a\u003e MSRV 1.89\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ijl/orjson/commit/b718e75b8ba18a707c2b44b6de14d52547573771\"\u003e\u003ccode\u003eb718e75\u003c/code\u003e\u003c/a\u003e Drop support for python3.9\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/ijl/orjson/compare/3.10.1...3.11.6\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `pillow` from 10.3.0 to 12.3.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/python-pillow/Pillow/releases\"\u003epillow's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e12.3.0\u003c/h2\u003e\n\u003cp\u003e\u003ca href=\"https://pillow.readthedocs.io/en/stable/releasenotes/12.3.0.html\"\u003ehttps://pillow.readthedocs.io/en/stable/releasenotes/12.3.0.html\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eRemovals\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRemove non-image ImageCms modes \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9697\"\u003e#9697\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eDocumentation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd release notes for SBOM and performance improvements \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9747\"\u003e#9747\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdd security release notes \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9741\"\u003e#9741\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdd release notes for Python 3.15 beta wheels \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9696\"\u003e#9696\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eImageFont can also be used with ImageText \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9597\"\u003e#9597\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdditional guidelines for security reports \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9659\"\u003e#9659\u003c/a\u003e [\u003ca href=\"https://github.com/wiredfool\"\u003e\u003ccode\u003e@​wiredfool\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eFixed typo \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9636\"\u003e#9636\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdded CVEs to 12.2.0 release notes \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9591\"\u003e#9591\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eRevise development support information in README \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9583\"\u003e#9583\u003c/a\u003e [\u003ca href=\"https://github.com/aclark4life\"\u003e\u003ccode\u003e@​aclark4life\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdd INCIDENT_RESPONSE.md \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9555\"\u003e#9555\u003c/a\u003e [\u003ca href=\"https://github.com/aclark4life\"\u003e\u003ccode\u003e@​aclark4life\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdd STRIDE threat model to security docs \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9562\"\u003e#9562\u003c/a\u003e [\u003ca href=\"https://github.com/aclark4life\"\u003e\u003ccode\u003e@​aclark4life\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdd CVEs to 12.2.0 release notes \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9556\"\u003e#9556\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate README with revised security policy \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9553\"\u003e#9553\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate security policy \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9552\"\u003e#9552\u003c/a\u003e [\u003ca href=\"https://github.com/aclark4life\"\u003e\u003ccode\u003e@​aclark4life\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate macOS tested Python versions \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9534\"\u003e#9534\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eDependencies\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate dependency harfbuzz to v14.2.1 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9720\"\u003e#9720\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency mypy to v2 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9653\"\u003e#9653\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency cibuildwheel to v4 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9665\"\u003e#9665\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate github-actions \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9655\"\u003e#9655\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency libavif to v1.4.2 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9652\"\u003e#9652\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency lcms2 to v2.19.1 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9651\"\u003e#9651\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency check-jsonschema to v0.37.2 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9650\"\u003e#9650\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate google/oss-fuzz digest to d872252 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9614\"\u003e#9614\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency lcms2 to v2.19 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9609\"\u003e#9609\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency libpng to v1.6.58 - autoclosed \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9608\"\u003e#9608\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency harfbuzz to v14 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9610\"\u003e#9610\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency mypy to v1.20.2 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9599\"\u003e#9599\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate github-actions \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9611\"\u003e#9611\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency cibuildwheel to v3.4.1 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9607\"\u003e#9607\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eMove dependency versions to single JSON and enable Renovate \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9559\"\u003e#9559\u003c/a\u003e [\u003ca href=\"https://github.com/hugovk\"\u003e\u003ccode\u003e@​hugovk\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdated raqm to 0.10.5 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9557\"\u003e#9557\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUpdate dependency cibuildwheel to v3.4.0 \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9532\"\u003e#9532\u003c/a\u003e [@\u003ca href=\"https://github.com/apps/renovate\"\u003erenovate[bot]\u003c/a\u003e]\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eTesting\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRemove matrix.os from benchmark \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9735\"\u003e#9735\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eRemove references to libavif patch \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9734\"\u003e#9734\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eAdd benchmark tests \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9654\"\u003e#9654\u003c/a\u003e [\u003ca href=\"https://github.com/akx\"\u003e\u003ccode\u003e@​akx\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003cli\u003eUse reshape() instead of setting NumPy array shape directly \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9728\"\u003e#9728\u003c/a\u003e [\u003ca href=\"https://github.com/radarhere\"\u003e\u003ccode\u003e@​radarhere\u003c/code\u003e\u003c/a\u003e]\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/python-pillow/Pillow/blob/main/CHANGES.rst\"\u003epillow's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003eChangelog (Pillow)\u003c/h1\u003e\n\u003ch2\u003e11.1.0 and newer\u003c/h2\u003e\n\u003cp\u003eSee GitHub Releases:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/releases\"\u003ehttps://github.com/python-pillow/Pillow/releases\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e11.0.0 (2024-10-15)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eUpdate licence to MIT-CMU \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/8460\"\u003e#8460\u003c/a\u003e\n[hugovk]\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eConditionally define ImageCms type hint to avoid requiring core \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/8197\"\u003e#8197\u003c/a\u003e\n[radarhere]\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eSupport writing LONG8 offsets in AppendingTiffWriter \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/8417\"\u003e#8417\u003c/a\u003e\n[radarhere]\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUse ImageFile.MAXBLOCK when saving TIFF images \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/8461\"\u003e#8461\u003c/a\u003e\n[radarhere]\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eDo not close provided file handles with libtiff when saving \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/8458\"\u003e#8458\u003c/a\u003e\n[radarhere]\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eSupport ImageFilter.BuiltinFilter for I;16* images \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/8438\"\u003e#8438\u003c/a\u003e\n[radarhere]\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUse ImagingCore.ptr instead of ImagingCore.id \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/8341\"\u003e#8341\u003c/a\u003e\n[homm, radarhere, hugovk]\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUpdated EPS mode when opening images without transparency \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/8281\"\u003e#8281\u003c/a\u003e\n[Yay295, radarhere]\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUse transparency when combining P frames from APNGs \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/8443\"\u003e#8443\u003c/a\u003e\n[radarhere]\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eSupport all resampling filters when resizing I;16* images \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/8422\"\u003e#8422\u003c/a\u003e\n[radarhere]\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFree memory on early return \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/8413\"\u003e#8413\u003c/a\u003e\n[radarhere]\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eCast int before potentially exceeding INT_MAX \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/8402\"\u003e#8402\u003c/a\u003e\n[radarhere]\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/bb1d8e8ab8d29048624d96e3ee53cecf7c13d13d\"\u003e\u003ccode\u003ebb1d8e8\u003c/code\u003e\u003c/a\u003e 12.3.0 version bump\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/e63fc481dc2e07e21d5403deafb8f1ed98a513af\"\u003e\u003ccode\u003ee63fc48\u003c/code\u003e\u003c/a\u003e Add release notes for SBOM and performance improvements (\u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9747\"\u003e#9747\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/13b701bbab291eec4bc87ea17ba06c94e5fe3054\"\u003e\u003ccode\u003e13b701b\u003c/code\u003e\u003c/a\u003e Add release notes for \u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9679\"\u003e#9679\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/5564ca72fcd59d040e270af5dcf17a0d7161c364\"\u003e\u003ccode\u003e5564ca7\u003c/code\u003e\u003c/a\u003e List methods\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/a0920fd384f800b5d0ba3dd29ecdeae4f1d4043b\"\u003e\u003ccode\u003ea0920fd\u003c/code\u003e\u003c/a\u003e Speed up ImageChops operations (\u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9738\"\u003e#9738\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/07e9a6cd5336dc6cf8cae9165cd70cdd2b3e42fc\"\u003e\u003ccode\u003e07e9a6c\u003c/code\u003e\u003c/a\u003e Speed up \u003ccode\u003eImage.filter()\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9736\"\u003e#9736\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/a94578cf9649ea13e426cf7fb2b71b39ffc0dd50\"\u003e\u003ccode\u003ea94578c\u003c/code\u003e\u003c/a\u003e Speed up \u003ccode\u003eImage.getchannel()\u003c/code\u003e, \u003ccode\u003eImage.merge()\u003c/code\u003e, \u003ccode\u003eImage.putalpha()\u003c/code\u003e and `Image...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/53e02c43c919d149b2a154a5180079f9df18fbbb\"\u003e\u003ccode\u003e53e02c4\u003c/code\u003e\u003c/a\u003e Speed up \u003ccode\u003eImage.fill()\u003c/code\u003e, \u003ccode\u003eImage.linear_gradient()\u003c/code\u003e and `Image.radial_gradient...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/af037475be8634ba739744243164ba9e2c8346a6\"\u003e\u003ccode\u003eaf03747\u003c/code\u003e\u003c/a\u003e Speed up \u003ccode\u003eImage.resample()\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9739\"\u003e#9739\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/python-pillow/Pillow/commit/5c9ca56c3e5fba52b647809fbb0986c87e73a571\"\u003e\u003ccode\u003e5c9ca56\u003c/code\u003e\u003c/a\u003e Speed up \u003ccode\u003ealpha_composite\u003c/code\u003e, \u003ccode\u003ematrix\u003c/code\u003e, \u003ccode\u003enegative\u003c/code\u003e, \u003ccode\u003equantize\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/python-pillow/Pillow/issues/9740\"\u003e#9740\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/python-pillow/Pillow/compare/10.3.0...12.3.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `pyasn1` from 0.6.0 to 0.6.4\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pyasn1/pyasn1/releases\"\u003epyasn1's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eRelease 0.6.4\u003c/h2\u003e\n\u003cp\u003eThis is a security release.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eCVE-2026-59885 (GHSA-8ppf-4f7h-5ppj): Fixed quadratic time complexity in the OBJECT IDENTIFIER and RELATIVE-OID decoders. A small crafted substrate encoding many arcs could consume excessive CPU.\u003c/li\u003e\n\u003cli\u003eCVE-2026-59884 (GHSA-m4p7-r5rc-7g4j): Limited BER long-form tag IDs to 20 octets (140 bits). Unbounded tag IDs allowed a crafted substrate to consume excessive CPU and memory.\u003c/li\u003e\n\u003cli\u003eCVE-2026-59886 (GHSA-hm4w-wwcw-mr6r): Fixed excessive memory and CPU consumption in \u003ccode\u003eReal.__float__()\u003c/code\u003e for values with large base-10 exponents.\u003c/li\u003e\n\u003cli\u003ePinned PyPI publish GitHub Action to an immutable commit.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eAll changes are noted in the \u003ca href=\"https://github.com/pyasn1/pyasn1/blob/main/CHANGES.rst\"\u003eCHANGELOG\u003c/a\u003e.\u003c/p\u003e\n\u003ch2\u003eRelease 0.6.3\u003c/h2\u003e\n\u003cp\u003eIt's a minor release.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAdded nesting depth limit to ASN.1 decoder to prevent stack overflow from deeply nested structures (CVE-2026-30922).\u003c/li\u003e\n\u003cli\u003eFixed OverflowError from oversized BER length field.\u003c/li\u003e\n\u003cli\u003eFixed DeprecationWarning stacklevel for deprecated attributes.\u003c/li\u003e\n\u003cli\u003eFixed asDateTime incorrect fractional seconds parsing.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eAll changes are noted in the \u003ca href=\"https://github.com/pyasn1/pyasn1/blob/master/CHANGES.rst\"\u003eCHANGELOG\u003c/a\u003e.\u003c/p\u003e\n\u003ch2\u003eRelease 0.6.2\u003c/h2\u003e\n\u003cp\u003eIt's a minor release.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eFixed continuation octet limits in OID/RELATIVE-OID decoder (CVE-2026-23490).\u003c/li\u003e\n\u003cli\u003eAdded support for Python 3.14.\u003c/li\u003e\n\u003cli\u003eAdded SECURITY.md policy.\u003c/li\u003e\n\u003cli\u003eMigrated to pyproject.toml packaging.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eAll changes are noted in the \u003ca href=\"https://github.com/pyasn1/pyasn1/blob/master/CHANGES.rst\"\u003eCHANGELOG\u003c/a\u003e.\u003c/p\u003e\n\u003ch2\u003eRelease 0.6.1\u003c/h2\u003e\n\u003cp\u003eIt's a minor release.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAdded support for Python 3.13.\u003c/li\u003e\n\u003cli\u003eCleaned Python 2-related code.\u003c/li\u003e\n\u003cli\u003eRemoved bdist_wheel universal flag from setup.cfg.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eAll changes are noted in the \u003ca href=\"https://github.com/pyasn1/pyasn1/blob/master/CHANGES.rst\"\u003eCHANGELOG\u003c/a\u003e.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pyasn1/pyasn1/blob/main/CHANGES.rst\"\u003epyasn1's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eRevision 0.6.4, released 08-07-2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eCVE-2026-59885 (GHSA-8ppf-4f7h-5ppj): Fixed quadratic time\ncomplexity in the OBJECT IDENTIFIER and RELATIVE-OID decoders.\nA small crafted substrate encoding many arcs could consume\nexcessive CPU. Arcs are now accumulated in linear time; decoded\nvalues are unchanged (thanks for reporting, tynus2)\u003c/li\u003e\n\u003cli\u003eCVE-2026-59884 (GHSA-m4p7-r5rc-7g4j): Limited BER long-form tag\nIDs to 20 octets (140 bits), matching the OID arc limit introduced\nin 0.6.2. Unbounded tag IDs allowed a crafted substrate to consume\nexcessive CPU and memory; longer tag IDs are now rejected with\nPyAsn1Error. Also fixed Tag and TagSet repr() failing on huge tag\n(thanks for reporting, mikeappsec)\nIDs due to the integer-to-string conversion limit (Python 3.11+)\u003c/li\u003e\n\u003cli\u003eCVE-2026-59886 (GHSA-hm4w-wwcw-mr6r): Fixed excessive memory and\nCPU consumption in Real.\u003cstrong\u003efloat\u003c/strong\u003e() for values with large base-10\nexponents. Conversion no longer materializes huge intermediate\nintegers; values too large to represent as a Python float raise\nOverflowError promptly, and prettyPrint() renders them as\n'\u003c!-- raw HTML omitted --\u003e' as before. Also fixed base-10 mantissa normalization\nto use exact integer arithmetic; mantissas larger than 2**53\ncould previously lose precision through float division\n(thanks for reporting, gvozdila)\u003c/li\u003e\n\u003cli\u003ePinned PyPI publish GitHub Action to an immutable commit\n[pr \u003ca href=\"https://redirect.github.com/pyasn1/pyasn1/issues/113\"\u003e#113\u003c/a\u003e](\u003ca href=\"https://redirect.github.com/pyasn1/pyasn1/pull/113\"\u003epyasn1/pyasn1#113\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eRevision 0.6.3, released 16-03-2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eCVE-2026-30922 (GHSA-jr27-m4p2-rc6r): Added nesting depth\nlimit to ASN.1 decoder to prevent stack overflow from deeply\nnested structures (thanks for reporting, romanticpragmatism)\u003c/li\u003e\n\u003cli\u003eFixed OverflowError from oversized BER length field\n[issue \u003ca href=\"https://redirect.github.com/pyasn1/pyasn1/issues/54\"\u003e#54\u003c/a\u003e](\u003ca href=\"https://redirect.github.com/pyasn1/pyasn1/issues/54\"\u003epyasn1/pyasn1#54\u003c/a\u003e)\n[pr \u003ca href=\"https://redirect.github.com/pyasn1/pyasn1/issues/100\"\u003e#100\u003c/a\u003e](\u003ca href=\"https://redirect.github.com/pyasn1/pyasn1/pull/100\"\u003epyasn1/pyasn1#100\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed DeprecationWarning stacklevel for deprecated attributes\n[issue \u003ca href=\"https://redirect.github.com/pyasn1/pyasn1/issues/86\"\u003e#86\u003c/a\u003e](\u003ca href=\"https://redirect.github.com/pyasn1/pyasn1/issues/86\"\u003epyasn1/pyasn1#86\u003c/a\u003e)\n[pr \u003ca href=\"https://redirect.github.com/pyasn1/pyasn1/issues/101\"\u003e#101\u003c/a\u003e](\u003ca href=\"https://redirect.github.com/pyasn1/pyasn1/pull/101\"\u003epyasn1/pyasn1#101\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixed asDateTime incorrect fractional seconds parsing\n[issue \u003ca href=\"https://redirect.github.com/pyasn1/pyasn1/issues/81\"\u003e#81\u003c/a\u003e](\u003ca href=\"https://redirect.github.com/pyasn1/pyasn1/issues/81\"\u003epyasn1/pyasn1#81\u003c/a\u003e)\n[pr \u003ca href=\"https://redirect.github.com/pyasn1/pyasn1/issues/102\"\u003e#102\u003c/a\u003e](\u003ca href=\"https://redirect.github.com/pyasn1/pyasn1/pull/102\"\u003epyasn1/pyasn1#102\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eRevision 0.6.2, released 16-01-2026\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eCVE-2026-23490 (GHSA-63vm-454h-vhhq): Fixed continuation octet limits\nin OID/RELATIVE-OID decoder (thanks to tsigouris007)\u003c/li\u003e\n\u003cli\u003eAdded support for Python 3.14\n[pr \u003ca href=\"https://redirect.github.com/pyasn1/pyasn1/issues/97\"\u003e#97\u003c/a\u003e](\u003ca href=\"https://redirect.github.com/pyasn1/pyasn1/pull/97\"\u003epyasn1/pyasn1#97\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyasn1/pyasn1/commit/72e4803405816c371ed3b2cb4be181c47f038406\"\u003e\u003ccode\u003e72e4803\u003c/code\u003e\u003c/a\u003e Prepare release 0.6.4\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyasn1/pyasn1/commit/0c19eeb853731db1c717ff125ea001a1e558332d\"\u003e\u003ccode\u003e0c19eeb\u003c/code\u003e\u003c/a\u003e Pin PyPI publish action to immutable commit (\u003ca href=\"https://redirect.github.com/pyasn1/pyasn1/issues/113\"\u003e#113\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyasn1/pyasn1/commit/45bdb19eb7df4b3780fe9c912c63e99bffc39dd9\"\u003e\u003ccode\u003e45bdb19\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyasn1/pyasn1/commit/628e36ecbb5277a3f01572ce418ef54271b165a5\"\u003e\u003ccode\u003e628e36e\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyasn1/pyasn1/commit/e60c691cb91addb8fcefa2f537e85ede6fb1e886\"\u003e\u003ccode\u003ee60c691\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyasn1/pyasn1/commit/af65c3b92e9deeae50db4de390982dd970d87f98\"\u003e\u003ccode\u003eaf65c3b\u003c/code\u003e\u003c/a\u003e Prepare release 0.6.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyasn1/pyasn1/commit/5a49bd1fe93b5b866a1210f6bf0a3924f21572c8\"\u003e\u003ccode\u003e5a49bd1\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyasn1/pyasn1/commit/5494ba43f738e700ca9f7c7a69ec5c44908c9a9f\"\u003e\u003ccode\u003e5494ba4\u003c/code\u003e\u003c/a\u003e Fix asDateTime incorrect fractional seconds parsing (\u003ca href=\"https://redirect.github.com/pyasn1/pyasn1/issues/102\"\u003e#102\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyasn1/pyasn1/commit/71f486e6c32d0f270868aa1b2bb5ceb7d5fd5476\"\u003e\u003ccode\u003e71f486e\u003c/code\u003e\u003c/a\u003e Fix DeprecationWarning stacklevel for deprecated attributes (\u003ca href=\"https://redirect.github.com/pyasn1/pyasn1/issues/101\"\u003e#101\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pyasn1/pyasn1/commit/d7cb42dcaa9a66e18f14c4609c2ed00c5b65f7e8\"\u003e\u003ccode\u003ed7cb42d\u003c/code\u003e\u003c/a\u003e Fix OverflowError from oversized BER length field (\u003ca href=\"https://redirect.github.com/pyasn1/pyasn1/issues/100\"\u003e#100\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/pyasn1/pyasn1/compare/v0.6.0...v0.6.4\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `requests` from 2.31.0 to 2.33.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/psf/requests/releases\"\u003erequests's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.33.0\u003c/h2\u003e\n\u003ch2\u003e2.33.0 (2026-03-25)\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eAnnouncements\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e📣 Requests is adding inline types. If you have a typed code base that uses Requests, please take a look at \u003ca href=\"https://redirect.github.com/psf/requests/issues/7271\"\u003e#7271\u003c/a\u003e. Give it a try, and report any gaps or feedback you may have in the issue. 📣\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eSecurity\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eCVE-2026-25645 \u003ccode\u003erequests.utils.extract_zipped_paths\u003c/code\u003e now extracts contents to a non-deterministic location to prevent malicious file replacement. This does not affect default usage of Requests, only applications calling the utility function directly.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eImprovements\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eMigrated to a PEP 517 build system using setuptools. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7012\"\u003e#7012\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eBugfixes\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eFixed an issue where an empty netrc entry could cause malformed authentication to be applied to Requests on Python 3.11+. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7205\"\u003e#7205\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eDeprecations\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eDropped support for Python 3.9 following its end of support. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7196\"\u003e#7196\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eDocumentation\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eVarious typo fixes and doc improvements.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/M0d3v1\"\u003e\u003ccode\u003e@​M0d3v1\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/psf/requests/pull/6865\"\u003epsf/requests#6865\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/aminvakil\"\u003e\u003ccode\u003e@​aminvakil\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/psf/requests/pull/7220\"\u003epsf/requests#7220\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/E8Price\"\u003e\u003ccode\u003e@​E8Price\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/psf/requests/pull/6960\"\u003epsf/requests#6960\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mitre88\"\u003e\u003ccode\u003e@​mitre88\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/psf/requests/pull/7244\"\u003epsf/requests#7244\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/magsen\"\u003e\u003ccode\u003e@​magsen\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/psf/requests/pull/6553\"\u003epsf/requests#6553\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Rohan5commit\"\u003e\u003ccode\u003e@​Rohan5commit\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/psf/requests/pull/7227\"\u003epsf/requests#7227\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/psf/requests/blob/main/HISTORY.md#2330-2026-03-25\"\u003ehttps://github.com/psf/requests/blob/main/HISTORY.md#2330-2026-03-25\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003ev2.32.5\u003c/h2\u003e\n\u003ch2\u003e2.32.5 (2025-08-18)\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eBugfixes\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eThe SSLContext caching feature originally introduced in 2.32.0 has created\na new class of issues in Requests that have had negative impact across a number\nof use cases. The Requests team has decided to revert this feature as long term\nmaintenance of it is proving to be unsustainable in its current iteration.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eDeprecations\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAdded support for Python 3.14.\u003c/li\u003e\n\u003cli\u003eDropped support for Python 3.8 following its end of support.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev2.32.4\u003c/h2\u003e\n\u003ch2\u003e2.32.4 (2025-06-10)\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/psf/requests/blob/main/HISTORY.md\"\u003erequests's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e2.33.0 (2026-03-25)\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eAnnouncements\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e📣 Requests is adding inline types. If you have a typed code base that\nuses Requests, please take a look at \u003ca href=\"https://redirect.github.com/psf/requests/issues/7271\"\u003e#7271\u003c/a\u003e. Give it a try, and report\nany gaps or feedback you may have in the issue. 📣\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eSecurity\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eCVE-2026-25645 \u003ccode\u003erequests.utils.extract_zipped_paths\u003c/code\u003e now extracts\ncontents to a non-deterministic location to prevent malicious file\nreplacement. This does not affect default usage of Requests, only\napplications calling the utility function directly.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eImprovements\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eMigrated to a PEP 517 build system using setuptools. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7012\"\u003e#7012\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eBugfixes\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eFixed an issue where an empty netrc entry could cause\nmalformed authentication to be applied to Requests on\nPython 3.11+. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7205\"\u003e#7205\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eDeprecations\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eDropped support for Python 3.9 following its end of support. (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7196\"\u003e#7196\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eDocumentation\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eVarious typo fixes and doc improvements.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.32.5 (2025-08-18)\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eBugfixes\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eThe SSLContext caching feature originally introduced in 2.32.0 has created\na new class of issues in Requests that have had negative impact across a number\nof use cases. The Requests team has decided to revert this feature as long term\nmaintenance of it is proving to be unsustainable in its current iteration.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eDeprecations\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAdded support for Python 3.14.\u003c/li\u003e\n\u003cli\u003eDropped support for Python 3.8 following its end of support.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.32.4 (2025-06-10)\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eSecurity\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eCVE-2024-47081 Fixed an issue where a maliciously crafted URL and trusted\nenvironment will retrieve credentials for the wrong hostname/machine from a\nnetrc file.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/bc04dfd6dad4cb02cd92f5daa81eb562d280a761\"\u003e\u003ccode\u003ebc04dfd\u003c/code\u003e\u003c/a\u003e v2.33.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/66d21cb07bd6255b1280291c4fafb71803cdb3b7\"\u003e\u003ccode\u003e66d21cb\u003c/code\u003e\u003c/a\u003e Merge commit from fork\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/8b9bc8fc0f63be84602387913c4b689f19efd028\"\u003e\u003ccode\u003e8b9bc8f\u003c/code\u003e\u003c/a\u003e Move badges to top of README (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7293\"\u003e#7293\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/e331a288f369973f5de0ec8901c94cae4fa87286\"\u003e\u003ccode\u003ee331a28\u003c/code\u003e\u003c/a\u003e Remove unused extraction call (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7292\"\u003e#7292\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/753fd08c5eacce0aa0df73fe47e49525c67e0a29\"\u003e\u003ccode\u003e753fd08\u003c/code\u003e\u003c/a\u003e docs: fix FAQ grammar in httplib2 example\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/774a0b837a194ee885d4fdd9ca947900cc3daf71\"\u003e\u003ccode\u003e774a0b8\u003c/code\u003e\u003c/a\u003e docs(socks): same block as other sections\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/9c72a41bec8597f948c9d8caa5dc3f12273b3303\"\u003e\u003ccode\u003e9c72a41\u003c/code\u003e\u003c/a\u003e Bump github/codeql-action from 4.33.0 to 4.34.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/ebf71906798ec82f34e07d3168f8b8aecaf8a3be\"\u003e\u003ccode\u003eebf7190\u003c/code\u003e\u003c/a\u003e Bump github/codeql-action from 4.32.0 to 4.33.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/0e4ae38f0c93d4f92a96c774bd52c069d12a4798\"\u003e\u003ccode\u003e0e4ae38\u003c/code\u003e\u003c/a\u003e docs: exclude Response.is_permanent_redirect from API docs (\u003ca href=\"https://redirect.github.com/psf/requests/issues/7244\"\u003e#7244\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/psf/requests/commit/d568f47278492e630cc990a259047c67991d007a\"\u003e\u003ccode\u003ed568f47\u003c/code\u003e\u003c/a\u003e docs: clarify Quickstart POST example (\u003ca href=\"https://redirect.github.com/psf/requests/issues/6960\"\u003e#6960\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/psf/requests/compare/v2.31.0...v2.33.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `urllib3` from 2.2.1 to 2.7.0\n\u003cdetails\u003e\n\u003csumm...\n\n_Description has been truncated_","html_url":"https://github.com/rajivranjanmars/microservices-demo/pull/1","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/rajivranjanmars%2Fmicroservices-demo/issues/1","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/1/packages"}},{"old_version":"3.12.15","new_version":"3.14.3","update_type":"minor","path":"/content/response_integrations/google/wiz","pr_created_at":"2026-09-16T04:31:16.000Z","version_change":"3.12.15 → 3.14.3","issue":{"uuid":"5470240775","node_id":"PR_kwDOQmqEms8AAAABDtdtPg","number":200,"state":"open","title":"Bump aiohttp from 3.12.15 to 3.14.3 in /content/response_integrations/google/wiz","user":"dependabot[bot]","labels":["dependencies","python:uv","migration"],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-16T04:31:16.000Z","updated_at":"2026-09-16T04:32:16.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","packages":[{"name":"aiohttp","old_version":"3.12.15","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"}],"path":"/content/response_integrations/google/wiz","ecosystem":"pip"},"body":"Bumps [aiohttp](https://github.com/aio-libs/aiohttp) from 3.12.15 to 3.14.3.\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=aiohttp\u0026package-manager=uv\u0026previous-version=3.12.15\u0026new-version=3.14.3)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/metron-labs/content-hub/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/metron-labs/content-hub/pull/200","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/metron-labs%2Fcontent-hub/issues/200","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/200/packages"}},{"old_version":"3.14.1","new_version":"3.14.3","update_type":"patch","path":null,"pr_created_at":"2026-09-16T02:22:32.000Z","version_change":"3.14.1 → 3.14.3","issue":{"uuid":"5469471709","node_id":"PR_kwDOTZpjNs8AAAABDs21bA","number":26,"state":"closed","title":"chore(deps): bump the pip-minor-patch group across 1 directory with 76 updates","user":"dependabot[bot]","labels":["dependencies","python"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":"2026-09-23T02:15:39.000Z","author_association":null,"state_reason":null,"created_at":"2026-09-16T02:22:32.000Z","updated_at":"2026-09-23T02:15:41.000Z","time_to_close":604387,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps): bump","group_name":"pip-minor-patch","update_count":76,"packages":[{"name":"langchain","old_version":"1.3.13","new_version":"1.4.0","repository_url":"https://github.com/langchain-ai/langchain"},{"name":"langchain-core","old_version":"1.4.9","new_version":"1.6.3","repository_url":"https://github.com/langchain-ai/langchain"},{"name":"langchain-openai","old_version":"1.3.5","new_version":"1.6.2","repository_url":"https://github.com/langchain-ai/langchain"},{"name":"langgraph","old_version":"1.2.9","new_version":"1.2.11","repository_url":"https://github.com/langchain-ai/langgraph"},{"name":"langgraph-checkpoint","old_version":"4.1.1","new_version":"4.2.0","repository_url":"https://github.com/langchain-ai/langgraph"},{"name":"python-dotenv","old_version":"1.2.2","new_version":"1.2.3","repository_url":"https://github.com/theskumar/python-dotenv"},{"name":"pypdfium2","old_version":"5.11.0","new_version":"5.13.0","repository_url":"https://github.com/pypdfium2-team/pypdfium2"},{"name":"duckdb","old_version":"1.5.4","new_version":"1.5.5","repository_url":"https://github.com/duckdb/duckdb-python"},{"name":"scikit-learn","old_version":"1.9.0","new_version":"1.9.1","repository_url":"https://github.com/scikit-learn/scikit-learn"},{"name":"joblib","old_version":"1.5.3","new_version":"1.6.0","repository_url":"https://github.com/joblib/joblib"},{"name":"yfinance","old_version":"1.5.1","new_version":"1.7.0","repository_url":"https://github.com/ranaroussi/yfinance"},{"name":"akshare","old_version":"1.18.64","new_version":"1.18.94","repository_url":"https://github.com/akfamily/akshare"},{"name":"ccxt","old_version":"4.5.64","new_version":"4.5.78","repository_url":"https://github.com/ccxt/ccxt"},{"name":"fastapi","old_version":"0.139.0","new_version":"0.141.1","repository_url":"https://github.com/fastapi/fastapi"},{"name":"uvicorn","old_version":"0.51.0","new_version":"0.52.4","repository_url":"https://github.com/Kludex/uvicorn"},{"name":"pydantic","old_version":"2.13.4","new_version":"2.13.5","repository_url":"https://github.com/pydantic/pydantic"},{"name":"sse-starlette","old_version":"3.4.5","new_version":"3.4.11","repository_url":"https://github.com/sysid/sse-starlette"},{"name":"ddgs","old_version":"9.14.4","new_version":"9.16.0","repository_url":"https://github.com/deedy5/ddgs"},{"name":"matplotlib","old_version":"3.11.0","new_version":"3.11.2","repository_url":"https://github.com/matplotlib/matplotlib"},{"name":"prompt-toolkit","old_version":"3.0.52","new_version":"3.0.53","repository_url":"https://github.com/prompt-toolkit/python-prompt-toolkit"},{"name":"aiohttp","old_version":"3.14.1","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"pyjwt","old_version":"2.13.0","new_version":"2.14.0","repository_url":"https://github.com/jpadilla/pyjwt"},{"name":"aiofile","old_version":"3.11.1","new_version":"3.12.3","repository_url":"https://github.com/mosquito/aiofile"},{"name":"annotated-doc","old_version":"0.0.4","new_version":"0.0.5","repository_url":"https://github.com/fastapi/annotated-doc"},{"name":"annotated-types","old_version":"0.7.0","new_version":"0.8.0","repository_url":"https://github.com/annotated-types/annotated-types"},{"name":"anyio","old_version":"4.14.2","new_version":"4.15.1","repository_url":"https://github.com/agronholm/anyio"},{"name":"authlib","old_version":"1.7.2","new_version":"1.8.0","repository_url":"https://github.com/authlib/authlib"},{"name":"cachetools","old_version":"7.1.4","new_version":"7.1.8","repository_url":"https://github.com/tkem/cachetools"},{"name":"caio","old_version":"0.10.2","new_version":"0.12.4","repository_url":"https://github.com/mosquito/caio"},{"name":"certifi","old_version":"2026.6.17","new_version":"2026.7.22","repository_url":"https://github.com/certifi/python-certifi"},{"name":"cffi","old_version":"2.1.0","new_version":"2.1.1","repository_url":"https://github.com/python-cffi/cffi"},{"name":"charset-normalizer","old_version":"3.4.9","new_version":"3.5.1","repository_url":"https://github.com/jawah/charset_normalizer"},{"name":"click","old_version":"8.4.2","new_version":"8.5.0","repository_url":"https://github.com/pallets/click"},{"name":"cssselect2","old_version":"0.9.0","new_version":"0.10.1","repository_url":"https://github.com/Kozea/cssselect2"},{"name":"curl-cffi","old_version":"0.15.0","new_version":"0.16.3","repository_url":"https://github.com/lexiforest/curl_cffi"},{"name":"cyclopts","old_version":"4.21.0","new_version":"4.25.2","repository_url":"https://github.com/BrianPugh/cyclopts"},{"name":"fonttools","old_version":"4.63.0","new_version":"4.65.0","repository_url":"https://github.com/fonttools/fonttools"},{"name":"griffelib","old_version":"2.1.0","new_version":"2.3.0"},{"name":"h2","old_version":"4.3.0","new_version":"4.4.1","repository_url":"https://github.com/python-hyper/h2"},{"name":"idna","old_version":"3.18","new_version":"3.19","repository_url":"https://github.com/kjd/idna"},{"name":"jaraco-functools","old_version":"4.5.0","new_version":"4.6.0","repository_url":"https://github.com/jaraco/jaraco.functools"},{"name":"jiter","old_version":"0.16.0","new_version":"0.17.0","repository_url":"https://github.com/pydantic/jiter"},{"name":"joserfc","old_version":"1.7.3","new_version":"1.7.5","repository_url":"https://github.com/authlib/joserfc"},{"name":"kiwisolver","old_version":"1.5.0","new_version":"1.5.1","repository_url":"https://github.com/nucleic/kiwi"},{"name":"langchain-protocol","old_version":"0.0.18","new_version":"0.0.19","repository_url":"https://github.com/langchain-ai/agent-protocol"},{"name":"langgraph-sdk","old_version":"0.4.2","new_version":"0.4.4","repository_url":"https://github.com/langchain-ai/langgraph"},{"name":"langsmith","old_version":"0.10.2","new_version":"0.12.4","repository_url":"https://github.com/langchain-ai/langsmith-sdk"},{"name":"llvmlite","old_version":"0.48.0","new_version":"0.49.0","repository_url":"https://github.com/numba/llvmlite"},{"name":"lxml","old_version":"6.1.1","new_version":"6.1.3","repository_url":"https://github.com/lxml/lxml"},{"name":"multidict","old_version":"6.7.1","new_version":"6.8.0","repository_url":"https://github.com/aio-libs/multidict"},{"name":"narwhals","old_version":"2.23.0","new_version":"2.26.0","repository_url":"https://github.com/narwhals-dev/narwhals"},{"name":"numba","old_version":"0.66.0","new_version":"0.67.0","repository_url":"https://github.com/numba/numba"},{"name":"opentelemetry-api","old_version":"1.43.0","new_version":"1.44.0","repository_url":"https://github.com/open-telemetry/opentelemetry-python"},{"name":"orjson","old_version":"3.11.9","new_version":"3.12.0","repository_url":"https://github.com/ijl/orjson"},{"name":"packaging","old_version":"26.2","new_version":"26.3","repository_url":"https://github.com/pypa/packaging"},{"name":"peewee","old_version":"4.2.1","new_version":"4.5.1","repository_url":"https://github.com/coleifer/peewee"},{"name":"platformdirs","old_version":"4.10.0","new_version":"4.11.8","repository_url":"https://github.com/tox-dev/platformdirs"},{"name":"protobuf","old_version":"7.35.1","new_version":"7.36.1","repository_url":"https://github.com/protocolbuffers/protobuf"},{"name":"pydantic-core","old_version":"2.47.0","new_version":"2.49.0","repository_url":"https://github.com/pydantic/pydantic"},{"name":"pydantic-settings","old_version":"2.14.2","new_version":"2.15.0","repository_url":"https://github.com/pydantic/pydantic-settings"},{"name":"pygments","old_version":"2.20.0","new_version":"2.21.0","repository_url":"https://github.com/pygments/pygments"},{"name":"pyphen","old_version":"0.17.2","new_version":"0.18.1","repository_url":"https://github.com/Kozea/Pyphen"},{"name":"pytz","old_version":"2026.2","new_version":"2026.3.post1","repository_url":"https://github.com/stub42/pytz"},{"name":"regex","old_version":"2026.7.10","new_version":"2026.9.10","repository_url":"https://github.com/mrabarnett/mrab-regex"},{"name":"simplejson","old_version":"4.1.1","new_version":"4.1.2","repository_url":"https://github.com/simplejson/simplejson"},{"name":"soupsieve","old_version":"2.8.4","new_version":"2.9.2","repository_url":"https://github.com/facelessuser/soupsieve"},{"name":"starlette","old_version":"1.3.1","new_version":"1.6.0","repository_url":"https://github.com/Kludex/starlette"},{"name":"tiktoken","old_version":"0.13.0","new_version":"0.14.0","repository_url":"https://github.com/openai/tiktoken"},{"name":"tqdm","old_version":"4.68.4","new_version":"4.70.1","repository_url":"https://github.com/tqdm/tqdm"},{"name":"typing-inspection","old_version":"0.4.2","new_version":"0.4.4","repository_url":"https://github.com/pydantic/typing-inspection"},{"name":"tzdata","old_version":"2026.3","new_version":"2026.4","repository_url":"https://github.com/python/tzdata"},{"name":"uncalled-for","old_version":"0.3.2","new_version":"0.4.0","repository_url":"https://github.com/chrisguidry/uncalled-for"},{"name":"wcwidth","old_version":"0.8.2","new_version":"0.8.3","repository_url":"https://github.com/jquast/wcwidth"},{"name":"webencodings","old_version":"0.5.1","new_version":"0.6.1","repository_url":"https://github.com/CourtBouillon/webencodings"},{"name":"websocket-client","old_version":"1.9.0","new_version":"1.9.2","repository_url":"https://github.com/websocket-client/websocket-client"},{"name":"yarl","old_version":"1.24.2","new_version":"1.24.5","repository_url":"https://github.com/aio-libs/yarl"}],"path":null,"ecosystem":"pip"},"body":"Bumps the pip-minor-patch group with 76 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [langchain](https://github.com/langchain-ai/langchain) | `1.3.13` | `1.4.0` |\n| [langchain-core](https://github.com/langchain-ai/langchain) | `1.4.9` | `1.6.3` |\n| [langchain-openai](https://github.com/langchain-ai/langchain) | `1.3.5` | `1.6.2` |\n| [langgraph](https://github.com/langchain-ai/langgraph) | `1.2.9` | `1.2.11` |\n| [langgraph-checkpoint](https://github.com/langchain-ai/langgraph) | `4.1.1` | `4.2.0` |\n| [python-dotenv](https://github.com/theskumar/python-dotenv) | `1.2.2` | `1.2.3` |\n| [pypdfium2](https://github.com/pypdfium2-team/pypdfium2) | `5.11.0` | `5.13.0` |\n| [duckdb](https://github.com/duckdb/duckdb-python) | `1.5.4` | `1.5.5` |\n| [scikit-learn](https://github.com/scikit-learn/scikit-learn) | `1.9.0` | `1.9.1` |\n| [joblib](https://github.com/joblib/joblib) | `1.5.3` | `1.6.0` |\n| [yfinance](https://github.com/ranaroussi/yfinance) | `1.5.1` | `1.7.0` |\n| [akshare](https://github.com/akfamily/akshare) | `1.18.64` | `1.18.94` |\n| [ccxt](https://github.com/ccxt/ccxt) | `4.5.64` | `4.5.78` |\n| [fastapi](https://github.com/fastapi/fastapi) | `0.139.0` | `0.141.1` |\n| [uvicorn](https://github.com/Kludex/uvicorn) | `0.51.0` | `0.52.4` |\n| [pydantic](https://github.com/pydantic/pydantic) | `2.13.4` | `2.13.5` |\n| [sse-starlette](https://github.com/sysid/sse-starlette) | `3.4.5` | `3.4.11` |\n| [ddgs](https://github.com/deedy5/ddgs) | `9.14.4` | `9.16.0` |\n| [matplotlib](https://github.com/matplotlib/matplotlib) | `3.11.0` | `3.11.2` |\n| [prompt-toolkit](https://github.com/prompt-toolkit/python-prompt-toolkit) | `3.0.52` | `3.0.53` |\n| [aiohttp](https://github.com/aio-libs/aiohttp) | `3.14.1` | `3.14.3` |\n| [pyjwt](https://github.com/jpadilla/pyjwt) | `2.13.0` | `2.14.0` |\n| [aiofile](https://github.com/mosquito/aiofile) | `3.11.1` | `3.12.3` |\n| [annotated-doc](https://github.com/fastapi/annotated-doc) | `0.0.4` | `0.0.5` |\n| [annotated-types](https://github.com/annotated-types/annotated-types) | `0.7.0` | `0.8.0` |\n| [anyio](https://github.com/agronholm/anyio) | `4.14.2` | `4.15.1` |\n| [authlib](https://github.com/authlib/authlib) | `1.7.2` | `1.8.0` |\n| [cachetools](https://github.com/tkem/cachetools) | `7.1.4` | `7.1.8` |\n| [caio](https://github.com/mosquito/caio) | `0.10.2` | `0.12.4` |\n| [certifi](https://github.com/certifi/python-certifi) | `2026.6.17` | `2026.7.22` |\n| [cffi](https://github.com/python-cffi/cffi) | `2.1.0` | `2.1.1` |\n| [charset-normalizer](https://github.com/jawah/charset_normalizer) | `3.4.9` | `3.5.1` |\n| [click](https://github.com/pallets/click) | `8.4.2` | `8.5.0` |\n| [cssselect2](https://github.com/Kozea/cssselect2) | `0.9.0` | `0.10.1` |\n| [curl-cffi](https://github.com/lexiforest/curl_cffi) | `0.15.0` | `0.16.3` |\n| [cyclopts](https://github.com/BrianPugh/cyclopts) | `4.21.0` | `4.25.2` |\n| [fonttools](https://github.com/fonttools/fonttools) | `4.63.0` | `4.65.0` |\n| griffelib | `2.1.0` | `2.3.0` |\n| [h2](https://github.com/python-hyper/h2) | `4.3.0` | `4.4.1` |\n| [idna](https://github.com/kjd/idna) | `3.18` | `3.19` |\n| [jaraco-functools](https://github.com/jaraco/jaraco.functools) | `4.5.0` | `4.6.0` |\n| [jiter](https://github.com/pydantic/jiter) | `0.16.0` | `0.17.0` |\n| [joserfc](https://github.com/authlib/joserfc) | `1.7.3` | `1.7.5` |\n| [kiwisolver](https://github.com/nucleic/kiwi) | `1.5.0` | `1.5.1` |\n| [langchain-protocol](https://github.com/langchain-ai/agent-protocol) | `0.0.18` | `0.0.19` |\n| [langgraph-sdk](https://github.com/langchain-ai/langgraph) | `0.4.2` | `0.4.4` |\n| [langsmith](https://github.com/langchain-ai/langsmith-sdk) | `0.10.2` | `0.12.4` |\n| [llvmlite](https://github.com/numba/llvmlite) | `0.48.0` | `0.49.0` |\n| [lxml](https://github.com/lxml/lxml) | `6.1.1` | `6.1.3` |\n| [multidict](https://github.com/aio-libs/multidict) | `6.7.1` | `6.8.0` |\n| [narwhals](https://github.com/narwhals-dev/narwhals) | `2.23.0` | `2.26.0` |\n| [numba](https://github.com/numba/numba) | `0.66.0` | `0.67.0` |\n| [opentelemetry-api](https://github.com/open-telemetry/opentelemetry-python) | `1.43.0` | `1.44.0` |\n| [orjson](https://github.com/ijl/orjson) | `3.11.9` | `3.12.0` |\n| [packaging](https://github.com/pypa/packaging) | `26.2` | `26.3` |\n| [peewee](https://github.com/coleifer/peewee) | `4.2.1` | `4.5.1` |\n| [platformdirs](https://github.com/tox-dev/platformdirs) | `4.10.0` | `4.11.8` |\n| [protobuf](https://github.com/protocolbuffers/protobuf) | `7.35.1` | `7.36.1` |\n| [pydantic-core](https://github.com/pydantic/pydantic) | `2.47.0` | `2.49.0` |\n| [pydantic-settings](https://github.com/pydantic/pydantic-settings) | `2.14.2` | `2.15.0` |\n| [pygments](https://github.com/pygments/pygments) | `2.20.0` | `2.21.0` |\n| [pyphen](https://github.com/Kozea/Pyphen) | `0.17.2` | `0.18.1` |\n| [pytz](https://github.com/stub42/pytz) | `2026.2` | `2026.3.post1` |\n| [regex](https://github.com/mrabarnett/mrab-regex) | `2026.7.10` | `2026.9.10` |\n| [simplejson](https://github.com/simplejson/simplejson) | `4.1.1` | `4.1.2` |\n| [soupsieve](https://github.com/facelessuser/soupsieve) | `2.8.4` | `2.9.2` |\n| [starlette](https://github.com/Kludex/starlette) | `1.3.1` | `1.6.0` |\n| [tiktoken](https://github.com/openai/tiktoken) | `0.13.0` | `0.14.0` |\n| [tqdm](https://github.com/tqdm/tqdm) | `4.68.4` | `4.70.1` |\n| [typing-inspection](https://github.com/pydantic/typing-inspection) | `0.4.2` | `0.4.4` |\n| [tzdata](https://github.com/python/tzdata) | `2026.3` | `2026.4` |\n| [uncalled-for](https://github.com/chrisguidry/uncalled-for) | `0.3.2` | `0.4.0` |\n| [wcwidth](https://github.com/jquast/wcwidth) | `0.8.2` | `0.8.3` |\n| [webencodings](https://github.com/CourtBouillon/webencodings) | `0.5.1` | `0.6.1` |\n| [websocket-client](https://github.com/websocket-client/websocket-client) | `1.9.0` | `1.9.2` |\n| [yarl](https://github.com/aio-libs/yarl) | `1.24.2` | `1.24.5` |\n\n\nUpdates `langchain` from 1.3.13 to 1.4.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/langchain-ai/langchain/releases\"\u003elangchain's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003elangchain-perplexity==1.4.0\u003c/h2\u003e\n\u003cp\u003eChanges since langchain-perplexity==1.3.2\u003c/p\u003e\n\u003cp\u003erelease(perplexity): 1.4.0 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/37993\"\u003e#37993\u003c/a\u003e)\nfeat(perplexity): \u003ccode\u003ebind_tools\u003c/code\u003e and Responses-API tool round-trip (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/37934\"\u003e#37934\u003c/a\u003e)\nhotfix(openai): min core dep (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/37990\"\u003e#37990\u003c/a\u003e)\u003c/p\u003e\n\u003ch2\u003elangchain-openai==1.4.0\u003c/h2\u003e\n\u003cp\u003eChanges since langchain-openai==1.3.5\u003c/p\u003e\n\u003cp\u003erelease(openai): 1.4.0 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38983\"\u003e#38983\u003c/a\u003e)\nchore: bump pillow from 12.2.0 to 12.3.0 in /libs/partners/openai (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38999\"\u003e#38999\u003c/a\u003e)\nfeat(core): add \u003ccode\u003ereasoning_effort\u003c/code\u003e as a standard chat model parameter (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38887\"\u003e#38887\u003c/a\u003e)\nchore(model-profiles): refresh model profile data (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38797\"\u003e#38797\u003c/a\u003e)\u003c/p\u003e\n\u003ch2\u003elangchain==1.4.0\u003c/h2\u003e\n\u003cp\u003eChanges since langchain==1.3.18\u003c/p\u003e\n\u003cp\u003edocs(langchain): runnable \u003ccode\u003elangchain.mcp\u003c/code\u003e examples (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/39976\"\u003e#39976\u003c/a\u003e)\nfeat(langchain): \u003ccode\u003elangchain.mcp\u003c/code\u003e namespace, \u003ccode\u003eMCPAdapter\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/39939\"\u003e#39939\u003c/a\u003e)\nperf(anthropic,langchain): omit middleware trace inputs (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/40098\"\u003e#40098\u003c/a\u003e)\nfix(langchain): include model destination in agent tool routing (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38355\"\u003e#38355\u003c/a\u003e)\nchore(langchain): bump vcrpy test dependency minimum to \u003ccode\u003e\u0026gt;=8.2.0\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/39942\"\u003e#39942\u003c/a\u003e)\u003c/p\u003e\n\u003ch2\u003elangchain==1.4.0a4\u003c/h2\u003e\n\u003cp\u003eInitial release\u003c/p\u003e\n\u003cp\u003erelease(langchain): 1.4.0a4\ntest(langchain): cover mixed-era ClientGroup and group elicitation\nUpdate libs/langchain_v1/langchain/mcp/adapter.py\nfix(langchain): drive MCP elicitation via member session for fastmcp 4.0.1\nfix(sdk): use latest fastmcp and rm reentrant impl\ncr\ncr\nrefactor(langchain): inline MCP client arming into \u003ccode\u003e__init__\u003c/code\u003e\nrefactor(langchain): stamp an arm marker instead of introspecting the handler closure\nfix(langchain): gate MCP interrupt routing on the negotiated protocol era\nrefactor(langchain): drop MCP \u003ccode\u003eelicitation\u003c/code\u003e flag, derive interrupt routing from the client\nfix(sdk): add _ReentrantClientGroup\nfix(langchain): narrow \u003ccode\u003eMCPAdapter.client\u003c/code\u003e union in mcp tests for mypy\nchore(langchain): format \u003ccode\u003emcp/adapter.py\u003c/code\u003e\nrelease(langchain): 1.4.0a3\nfeat(langchain): group MCP tool metadata under an \u003ccode\u003emcp\u003c/code\u003e namespace\nrefactor(langchain): stop exporting \u003ccode\u003eMCPAdapterTarget\u003c/code\u003e from \u003ccode\u003elangchain.mcp\u003c/code\u003e\nrefactor(langchain): rename \u003ccode\u003econvert_mcp_tool_to_langchain_tool\u003c/code\u003e to \u003ccode\u003eas_langchain_tool\u003c/code\u003e\nrefactor(langchain): rename \u003ccode\u003eMCPAdapter.get_tools\u003c/code\u003e to \u003ccode\u003elist_tools\u003c/code\u003e\nfeat(langchain): expose \u003ccode\u003ecache_mode\u003c/code\u003e on \u003ccode\u003eMCPAdapter.get_tools\u003c/code\u003e\nchore(langchain): require \u003ccode\u003efastmcp\u003c/code\u003e 4.0.0\nfeat(langchain): accept a \u003ccode\u003eClientGroup\u003c/code\u003e as an \u003ccode\u003eMCPAdapter\u003c/code\u003e target\nfeat(langchain): mark the \u003ccode\u003elangchain.mcp\u003c/code\u003e namespace as beta\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/79cab2dc7f58be720cac43db3677b4c1fd971f91\"\u003e\u003ccode\u003e79cab2d\u003c/code\u003e\u003c/a\u003e release(anthropic): 1.7.1 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/40181\"\u003e#40181\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/1e6a4f0b45b60475f566f3ad49fb32ea99d22233\"\u003e\u003ccode\u003e1e6a4f0\u003c/code\u003e\u003c/a\u003e chore(model-profiles): refresh model profile data (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/40171\"\u003e#40171\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/8330dfe987988c1bcbbc5e8d9af9a67e5a1c2744\"\u003e\u003ccode\u003e8330dfe\u003c/code\u003e\u003c/a\u003e docs(langchain): runnable \u003ccode\u003elangchain.mcp\u003c/code\u003e examples (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/39976\"\u003e#39976\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/280442b54c80db2175ced4a20ab59eab86a32dc1\"\u003e\u003ccode\u003e280442b\u003c/code\u003e\u003c/a\u003e feat(langchain): \u003ccode\u003elangchain.mcp\u003c/code\u003e namespace, \u003ccode\u003eMCPAdapter\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/39939\"\u003e#39939\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/f5ee2b65f4cf2f1a9fe688bcae6ad2af966582bd\"\u003e\u003ccode\u003ef5ee2b6\u003c/code\u003e\u003c/a\u003e chore(chroma): bump Pygments security constraint (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/40162\"\u003e#40162\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/234255c1c7427b5ed6dc505abad41ddfa6c9ff8f\"\u003e\u003ccode\u003e234255c\u003c/code\u003e\u003c/a\u003e chore(model-profiles): refresh model profile data (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/40009\"\u003e#40009\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/79e0e4adbafc1fda1ca9956e184be8b8819aa7ab\"\u003e\u003ccode\u003e79e0e4a\u003c/code\u003e\u003c/a\u003e chore(deps): bump mistune from 3.3.0 to 3.3.3 in /libs/langchain (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/40149\"\u003e#40149\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/e90201b7af5cd32762744c974ca9ce3f27efc9d8\"\u003e\u003ccode\u003ee90201b\u003c/code\u003e\u003c/a\u003e chore(deps): bump mistune from 3.3.0 to 3.3.3 in /libs/core (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/40150\"\u003e#40150\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/4240248e7b08ed72e85ce0744350c33beddb0ac8\"\u003e\u003ccode\u003e4240248\u003c/code\u003e\u003c/a\u003e chore(deps): bump mistune from 3.3.0 to 3.3.3 in /libs/text-splitters (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/40148\"\u003e#40148\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/530290a9d445069d80a68cdcd4d0da768f2aa2b0\"\u003e\u003ccode\u003e530290a\u003c/code\u003e\u003c/a\u003e chore(deps): bump uv to 0.12.8 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/40092\"\u003e#40092\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/langchain-ai/langchain/compare/langchain==1.3.13...langchain==1.4.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `langchain-core` from 1.4.9 to 1.6.3\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/langchain-ai/langchain/releases\"\u003elangchain-core's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003elangchain-core==1.6.3\u003c/h2\u003e\n\u003cp\u003eChanges since langchain-core==1.6.2\u003c/p\u003e\n\u003cp\u003erelease(core): 1.6.3 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/40407\"\u003e#40407\u003c/a\u003e)\nfeat(core): Allow model name and provider tracing metadata override based on gateway response (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/40406\"\u003e#40406\u003c/a\u003e)\ntest(core): cover the deprecated \u003ccode\u003e.text()\u003c/code\u003e access path (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/40243\"\u003e#40243\u003c/a\u003e)\ndocs(core): remove stale Args/Raises entries from FileCallbackHandler._write and ChatGeneration.set_text (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/40211\"\u003e#40211\u003c/a\u003e)\u003c/p\u003e\n\u003ch2\u003elangchain-core==1.6.2\u003c/h2\u003e\n\u003cp\u003eChanges since langchain-core==1.6.1\u003c/p\u003e\n\u003cp\u003erelease(core): 1.6.2 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/40209\"\u003e#40209\u003c/a\u003e)\nfeat(openai): support async tools (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/40208\"\u003e#40208\u003c/a\u003e)\nchore(deps): bump mistune from 3.3.0 to 3.3.3 in /libs/core (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/40150\"\u003e#40150\u003c/a\u003e)\nchore(deps): bump tornado from 6.5.7 to 6.5.8 in /libs/core (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/40113\"\u003e#40113\u003c/a\u003e)\nfix(core): avoid mutation in google-genai standard content (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/40023\"\u003e#40023\u003c/a\u003e)\nfix(core): avoid mutation in bedrock converse standard content (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/40022\"\u003e#40022\u003c/a\u003e)\u003c/p\u003e\n\u003ch2\u003elangchain-core==1.6.1\u003c/h2\u003e\n\u003cp\u003eChanges since langchain-core==1.6.0\u003c/p\u003e\n\u003cp\u003erevert: release(core): 1.6.2 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/39971\"\u003e#39971\u003c/a\u003e)\nrelease(core): 1.6.2 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/39967\"\u003e#39967\u003c/a\u003e)\nfix(core): shore up indexing in genai v1 streaming content (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/39964\"\u003e#39964\u003c/a\u003e)\nfix(core): make \u003ccode\u003eStructuredTool\u003c/code\u003e JSON-serializable (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/39631\"\u003e#39631\u003c/a\u003e)\nchore(deps): bump minor and patch dependencies (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/39869\"\u003e#39869\u003c/a\u003e)\nrelease(core): 1.6.1 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/39832\"\u003e#39832\u003c/a\u003e)\nfeat(core): propagate gateway information on error path (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/39829\"\u003e#39829\u003c/a\u003e)\u003c/p\u003e\n\u003ch2\u003elangchain-core==1.6.0\u003c/h2\u003e\n\u003cp\u003eChanges since langchain-core==1.5.6\u003c/p\u003e\n\u003cp\u003erelease(core): 1.6.0 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/39760\"\u003e#39760\u003c/a\u003e)\nfix(core): resolve postponed annotations in \u003ccode\u003eStructuredTool._injected_args_keys\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/39602\"\u003e#39602\u003c/a\u003e)\nfeat(core): add standard model exception types (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/39538\"\u003e#39538\u003c/a\u003e)\nfix(core): allow deserializing \u003ccode\u003eRunnablePick\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/39753\"\u003e#39753\u003c/a\u003e)\nfix(core): make \u003ccode\u003econvert_to_openai_function\u003c/code\u003e handle callables and non-dict mappings (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/39750\"\u003e#39750\u003c/a\u003e)\nfix(core): make subprocess and temporary file tests portable on Windows (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/39664\"\u003e#39664\u003c/a\u003e)\nfix(core): fail fast when tool schemas can't resolve forward refs during serialization (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/39570\"\u003e#39570\u003c/a\u003e)\ntest(core): avoid version-dependent runnable snapshots (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/39705\"\u003e#39705\u003c/a\u003e)\nfix(core): require all nested properties for strict tool schemas (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/39306\"\u003e#39306\u003c/a\u003e)\nfix(core): remove stale sync-stream \u003ccode\u003exfail\u003c/code\u003e [closes \u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/39720\"\u003e#39720\u003c/a\u003e] (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/39723\"\u003e#39723\u003c/a\u003e)\nperf(core): Lazily import transformers (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38037\"\u003e#38037\u003c/a\u003e)\nfix(core): accept non-dict Mapping values in mustache templates (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/39680\"\u003e#39680\u003c/a\u003e)\ndocs(core): clarify \u003ccode\u003eRunnable\u003c/code\u003e pipe coercion [closes \u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/39075\"\u003e#39075\u003c/a\u003e] (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/39707\"\u003e#39707\u003c/a\u003e)\nfix(core): finalize chain-group runs on \u003ccode\u003eBaseException\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/39699\"\u003e#39699\u003c/a\u003e)\u003c/p\u003e\n\u003ch2\u003elangchain-core==1.5.6\u003c/h2\u003e\n\u003cp\u003eChanges since langchain-core==1.5.5\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/348c9dc572599947d2d7d33d6a5b8b936e92a1d4\"\u003e\u003ccode\u003e348c9dc\u003c/code\u003e\u003c/a\u003e release(core): 1.6.3 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/40407\"\u003e#40407\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/e0e1557bd6ebae13915c59d942ef2824b51a10c6\"\u003e\u003ccode\u003ee0e1557\u003c/code\u003e\u003c/a\u003e feat(core): Allow model name and provider tracing metadata override based on ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/67ee6cb63dd9ae7f3a4dfedc3095652bce15a125\"\u003e\u003ccode\u003e67ee6cb\u003c/code\u003e\u003c/a\u003e chore(model-profiles): refresh model profile data (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/40399\"\u003e#40399\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/d5d7cc56ab3932c9a10dc76b31cd5d4a778c3f2a\"\u003e\u003ccode\u003ed5d7cc5\u003c/code\u003e\u003c/a\u003e release(anthropic): 1.7.2 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/40387\"\u003e#40387\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/4436bd2b67814877a3797613de28882adcdb6edf\"\u003e\u003ccode\u003e4436bd2\u003c/code\u003e\u003c/a\u003e fix(anthropic): preserve invalid tool use blocks (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/40372\"\u003e#40372\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/443154df9db5251d73730e1de3eb63bf352e586f\"\u003e\u003ccode\u003e443154d\u003c/code\u003e\u003c/a\u003e feat(huggingface): use torch.accelerator for device-agnostic device count det...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/3539ca08d92e10b65b6f3117cfd657b16b05c865\"\u003e\u003ccode\u003e3539ca0\u003c/code\u003e\u003c/a\u003e fix(huggingface): remove retired IPEX backend (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/39649\"\u003e#39649\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/45d94fb0fa10bf8cab95dcb1e76c2bc39165535d\"\u003e\u003ccode\u003e45d94fb\u003c/code\u003e\u003c/a\u003e chore(model-profiles): refresh model profile data (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/40358\"\u003e#40358\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/60357692c76651a7cd6153496a24658fa355bdcc\"\u003e\u003ccode\u003e6035769\u003c/code\u003e\u003c/a\u003e release(openai): 1.6.2 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/40339\"\u003e#40339\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/a7b0f0ae50acebb527a25e153ff16621d37ba650\"\u003e\u003ccode\u003ea7b0f0a\u003c/code\u003e\u003c/a\u003e docs: update OpenWiki (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/40318\"\u003e#40318\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/langchain-ai/langchain/compare/langchain-core==1.4.9...langchain-core==1.6.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `langchain-openai` from 1.3.5 to 1.6.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/langchain-ai/langchain/releases\"\u003elangchain-openai's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003elangchain-openai==1.6.2\u003c/h2\u003e\n\u003cp\u003eChanges since langchain-openai==1.6.1\u003c/p\u003e\n\u003cp\u003erelease(openai): 1.6.2 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/40339\"\u003e#40339\u003c/a\u003e)\nfix(openai): add GPT-6 Astra reasoning efforts (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/40330\"\u003e#40330\u003c/a\u003e)\nchore(deps): bump httpx2 from 2.10.0 to 2.12.0 in /libs/partners/openai (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/40309\"\u003e#40309\u003c/a\u003e)\u003c/p\u003e\n\u003ch2\u003elangchain-openai==1.6.1\u003c/h2\u003e\n\u003cp\u003eChanges since langchain-openai==1.6.0\u003c/p\u003e\n\u003cp\u003efix(openai): bump \u003ccode\u003emax_completion_tokens\u003c/code\u003e in cache breakpoint integration test (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/40284\"\u003e#40284\u003c/a\u003e)\nrelease(openai): 1.6.1 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/40268\"\u003e#40268\u003c/a\u003e)\nchore(model-profiles): refresh model profile data (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/40217\"\u003e#40217\u003c/a\u003e)\nfix(openai): support Azure AD auth with OpenAI 3.8 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/40190\"\u003e#40190\u003c/a\u003e)\nfeat(openai): support async tools (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/40208\"\u003e#40208\u003c/a\u003e)\nfeat(openai): support \u003ccode\u003econfiguration_update\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/40201\"\u003e#40201\u003c/a\u003e)\nchore(model-profiles): refresh model profile data (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/40171\"\u003e#40171\u003c/a\u003e)\nfix(openai): route \u003ccode\u003egpt-5.6-sol\u003c/code\u003e to responses API (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/40133\"\u003e#40133\u003c/a\u003e)\nchore(openai): fix tests (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/39972\"\u003e#39972\u003c/a\u003e)\nfix(openai): correct \u003ccode\u003ereasoning_effort_levels\u003c/code\u003e for gpt-5 and gpt-5.1 profiles (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/39936\"\u003e#39936\u003c/a\u003e)\nchore(model-profiles): refresh model profile data (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/39954\"\u003e#39954\u003c/a\u003e)\u003c/p\u003e\n\u003ch2\u003elangchain-openai==1.6.0\u003c/h2\u003e\n\u003cp\u003eChanges since langchain-openai==1.5.2\u003c/p\u003e\n\u003cp\u003erelease(openai): 1.6.0 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/39762\"\u003e#39762\u003c/a\u003e)\nfeat(core): add standard model exception types (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/39538\"\u003e#39538\u003c/a\u003e)\nfix(openai): raise clear error on unexpected response type in \u003ccode\u003e_create_chat_result\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/39731\"\u003e#39731\u003c/a\u003e)\u003c/p\u003e\n\u003ch2\u003elangchain-openai==1.5.2\u003c/h2\u003e\n\u003cp\u003eChanges since langchain-openai==1.5.1\u003c/p\u003e\n\u003cp\u003erelease(openai): 1.5.2 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/39719\"\u003e#39719\u003c/a\u003e)\nfix(openai): preserve reasoning item boundaries (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/39278\"\u003e#39278\u003c/a\u003e)\nrelease(openai): 1.5.2a1 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/39709\"\u003e#39709\u003c/a\u003e)\nfeat(openai): extract gateway metadata from response headers when available (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/39706\"\u003e#39706\u003c/a\u003e)\nchore(openai): update snapshots (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/39657\"\u003e#39657\u003c/a\u003e)\nfix(openai): support o-series models in \u003ccode\u003eget_num_tokens_from_messages\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38710\"\u003e#38710\u003c/a\u003e)\u003c/p\u003e\n\u003ch2\u003elangchain-openai==1.5.2a1\u003c/h2\u003e\n\u003cp\u003eInitial release\u003c/p\u003e\n\u003cp\u003erelease(openai): 1.5.2a1 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/39709\"\u003e#39709\u003c/a\u003e)\nfeat(openai): extract gateway metadata from response headers when available (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/39706\"\u003e#39706\u003c/a\u003e)\nchore(openai): update snapshots (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/39657\"\u003e#39657\u003c/a\u003e)\nfix(openai): support o-series models in \u003ccode\u003eget_num_tokens_from_messages\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/38710\"\u003e#38710\u003c/a\u003e)\nrelease(openai): 1.5.1 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/39653\"\u003e#39653\u003c/a\u003e)\nfix(openai): preserve streamed encrypted reasoning (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/39635\"\u003e#39635\u003c/a\u003e)\nchore(infra): support langsmith gateway in CI (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/39651\"\u003e#39651\u003c/a\u003e)\nrelease(openai): 1.5.0 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/39629\"\u003e#39629\u003c/a\u003e)\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/60357692c76651a7cd6153496a24658fa355bdcc\"\u003e\u003ccode\u003e6035769\u003c/code\u003e\u003c/a\u003e release(openai): 1.6.2 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/40339\"\u003e#40339\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/a7b0f0ae50acebb527a25e153ff16621d37ba650\"\u003e\u003ccode\u003ea7b0f0a\u003c/code\u003e\u003c/a\u003e docs: update OpenWiki (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/40318\"\u003e#40318\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/1611938f49dda48aa069d1fdce429430257488b7\"\u003e\u003ccode\u003e1611938\u003c/code\u003e\u003c/a\u003e fix(openai): add GPT-6 Astra reasoning efforts (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/40330\"\u003e#40330\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/f092c9a78b3c532ef4c01935c0d4514209ff9f96\"\u003e\u003ccode\u003ef092c9a\u003c/code\u003e\u003c/a\u003e chore(model-profiles): refresh model profile data (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/40317\"\u003e#40317\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/22f3421aeedec55962f712a34d86d9683bf6cf59\"\u003e\u003ccode\u003e22f3421\u003c/code\u003e\u003c/a\u003e docs: update OpenWiki (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/40218\"\u003e#40218\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/1c40140b3daf80c5baa7427d707ef2beb6c404b2\"\u003e\u003ccode\u003e1c40140\u003c/code\u003e\u003c/a\u003e chore(deps): bump httpx2 from 2.10.0 to 2.12.0 in /libs/partners/openai (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/40309\"\u003e#40309\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/db613a96050bc6e594fdcd618af7532264dcceb8\"\u003e\u003ccode\u003edb613a9\u003c/code\u003e\u003c/a\u003e fix(openai): bump \u003ccode\u003emax_completion_tokens\u003c/code\u003e in cache breakpoint integration tes...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/9f2eb7f46719742875ebea9e31d53e168e8b81a2\"\u003e\u003ccode\u003e9f2eb7f\u003c/code\u003e\u003c/a\u003e release(openai): 1.6.1 (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/40268\"\u003e#40268\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/765eb32901fa524e1428f94a9ee91b371a63ab62\"\u003e\u003ccode\u003e765eb32\u003c/code\u003e\u003c/a\u003e chore(model-profiles): refresh model profile data (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/40277\"\u003e#40277\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langchain/commit/e670c7a03ba36fd1516f0185f7ec1186c89aa471\"\u003e\u003ccode\u003ee670c7a\u003c/code\u003e\u003c/a\u003e chore(model-profiles): refresh model profile data (\u003ca href=\"https://redirect.github.com/langchain-ai/langchain/issues/40258\"\u003e#40258\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/langchain-ai/langchain/compare/langchain-openai==1.3.5...langchain-openai==1.6.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `langgraph` from 1.2.9 to 1.2.11\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/langchain-ai/langgraph/releases\"\u003elanggraph's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003elanggraph==1.2.11\u003c/h2\u003e\n\u003cp\u003eChanges since 1.2.10\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003erelease(langgraph): 1.2.11 (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8595\"\u003e#8595\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efeat(langgraph): expose \u003ccode\u003etrace_policy\u003c/code\u003e on \u003ccode\u003eadd_node\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8523\"\u003e#8523\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore(deps): bump the minor-and-patch group across 1 directory with 7 updates (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8533\"\u003e#8533\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore(deps): bump the minor-and-patch group across 1 directory with 5 updates (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8532\"\u003e#8532\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003erelease(checkpoint-postgres): 3.1.2 (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8565\"\u003e#8565\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003erelease(checkpoint): 4.2.0 (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8563\"\u003e#8563\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix(checkpoint): collect writes at plain-value seed in delta channel history (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8526\"\u003e#8526\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore: enforce PLC0415 in tests for the remaining packages (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8547\"\u003e#8547\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003etest(checkpoint-postgres,checkpoint-sqlite): run the conformance suite (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8537\"\u003e#8537\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore: enable RUF100 and clear unused noqa directives (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8546\"\u003e#8546\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore(deps-dev): bump types-requests from 2.33.0.20260518 to 2.33.0.20260712 in /libs/langgraph (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8502\"\u003e#8502\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore(deps): bump cryptography from 48.0.1 to 50.0.0 in /libs/langgraph (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8528\"\u003e#8528\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003erelease(checkpoint-sqlite): 3.1.1 (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8481\"\u003e#8481\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003erelease(checkpoint-postgres): 3.1.1 (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8480\"\u003e#8480\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003elanggraph==1.2.10\u003c/h2\u003e\n\u003cp\u003eChanges since 1.2.9\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003erelease(langgraph): 1.2.10 (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8462\"\u003e#8462\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore(deps): bump jupyterlab from 4.5.9 to 4.5.10 in /libs/langgraph (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8440\"\u003e#8440\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore(deps): bump setuptools from 80.9.0 to 83.0.0 in /libs/langgraph (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8435\"\u003e#8435\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efeat(langgraph): type v3 stream_events return and native projections (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8389\"\u003e#8389\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003erevert(langgraph): delete TracePolicy (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8403\"\u003e#8403\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efeat(langgraph): drop tags from TracePolicy (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8402\"\u003e#8402\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efeat(langgraph): expose \u003ccode\u003etrace_policy\u003c/code\u003e on \u003ccode\u003eadd_node\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8362\"\u003e#8362\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore(deps): bump mistune from 3.2.1 to 3.3.0 in /libs/langgraph (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8317\"\u003e#8317\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore(deps): bump soupsieve from 2.8.1 to 2.8.4 in /libs/langgraph (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8318\"\u003e#8318\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore(cli): allow langgraph-api versions up to 1.0.0 (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8319\"\u003e#8319\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langgraph/commit/644815f9e5bc52ad8f7a5227a456227e9c3e639b\"\u003e\u003ccode\u003e644815f\u003c/code\u003e\u003c/a\u003e release(langgraph): 1.2.11 (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8595\"\u003e#8595\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langgraph/commit/7d6b5790ba84ce38c26f27a533d8419a31103c36\"\u003e\u003ccode\u003e7d6b579\u003c/code\u003e\u003c/a\u003e feat(langgraph): expose \u003ccode\u003etrace_policy\u003c/code\u003e on \u003ccode\u003eadd_node\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8523\"\u003e#8523\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langgraph/commit/d56666f7fbf0d380ad84cdf0cbe5aa48ab0cc086\"\u003e\u003ccode\u003ed56666f\u003c/code\u003e\u003c/a\u003e chore(deps): bump the minor-and-patch group across 1 directory with 7 updates...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langgraph/commit/6a2822d3c77dad49a96718de73095f18717728be\"\u003e\u003ccode\u003e6a2822d\u003c/code\u003e\u003c/a\u003e chore(deps): bump the minor-and-patch group across 1 directory with 5 updates...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langgraph/commit/fde3068970679184b68d3d068a92c83c966a4888\"\u003e\u003ccode\u003efde3068\u003c/code\u003e\u003c/a\u003e release(checkpoint-postgres): 3.1.2 (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8565\"\u003e#8565\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langgraph/commit/f55e77274dad40897ef7b2d52cc7c0b85b792247\"\u003e\u003ccode\u003ef55e772\u003c/code\u003e\u003c/a\u003e release(checkpoint): 4.2.0 (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8563\"\u003e#8563\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langgraph/commit/a90ab4435853b8a5b6f82b20220b4c76af0e46d1\"\u003e\u003ccode\u003ea90ab44\u003c/code\u003e\u003c/a\u003e fix(checkpoint): collect writes at plain-value seed in delta channel history ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langgraph/commit/ea5f9cc9fb8c4b123769daab4753af34de29b1e9\"\u003e\u003ccode\u003eea5f9cc\u003c/code\u003e\u003c/a\u003e chore: enforce PLC0415 in tests for the remaining packages (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8547\"\u003e#8547\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langgraph/commit/36a505ac65e956da09e93cc753609635a511047e\"\u003e\u003ccode\u003e36a505a\u003c/code\u003e\u003c/a\u003e test(checkpoint-postgres,checkpoint-sqlite): run the conformance suite (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8537\"\u003e#8537\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langgraph/commit/d569e18f4bd78b7652cb88c84b8dd098057e4f7d\"\u003e\u003ccode\u003ed569e18\u003c/code\u003e\u003c/a\u003e fix(checkpoint-postgres): find plain-value seeds when walking delta history (...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/langchain-ai/langgraph/compare/1.2.9...1.2.11\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `langgraph-checkpoint` from 4.1.1 to 4.2.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/langchain-ai/langgraph/releases\"\u003elanggraph-checkpoint's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003elanggraph-checkpoint==4.2.0\u003c/h2\u003e\n\u003cp\u003eChanges since checkpoint==4.1.1\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003erelease(checkpoint): 4.2.0 (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8563\"\u003e#8563\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efix(checkpoint): collect writes at plain-value seed in delta channel history (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8526\"\u003e#8526\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore: enforce PLC0415 in tests for the remaining packages (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8547\"\u003e#8547\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore: enable RUF100 and clear unused noqa directives (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8546\"\u003e#8546\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore(deps): bump the minor-and-patch group in /libs/checkpoint with 4 updates (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8490\"\u003e#8490\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003efeat(checkpoint,checkpoint-postgres): add opt-in omit_expired to skip expired rows on read (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8354\"\u003e#8354\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore(deps): bump the minor-and-patch group in /libs/checkpoint with 5 updates (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8248\"\u003e#8248\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore(deps): bump langsmith from 0.8.0 to 0.8.18 in /libs/checkpoint (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8173\"\u003e#8173\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003edocs: standardize package \u003ccode\u003eREADME.md\u003c/code\u003e structure (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8064\"\u003e#8064\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore: migrate Python type checking to ty (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8002\"\u003e#8002\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore(deps-dev): bump the major group in /libs/checkpoint with 2 updates (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/7967\"\u003e#7967\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003echore(deps): bump the minor-and-patch group in /libs/checkpoint with 3 updates (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/7960\"\u003e#7960\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langgraph/commit/f55e77274dad40897ef7b2d52cc7c0b85b792247\"\u003e\u003ccode\u003ef55e772\u003c/code\u003e\u003c/a\u003e release(checkpoint): 4.2.0 (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8563\"\u003e#8563\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langgraph/commit/a90ab4435853b8a5b6f82b20220b4c76af0e46d1\"\u003e\u003ccode\u003ea90ab44\u003c/code\u003e\u003c/a\u003e fix(checkpoint): collect writes at plain-value seed in delta channel history ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langgraph/commit/ea5f9cc9fb8c4b123769daab4753af34de29b1e9\"\u003e\u003ccode\u003eea5f9cc\u003c/code\u003e\u003c/a\u003e chore: enforce PLC0415 in tests for the remaining packages (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8547\"\u003e#8547\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langgraph/commit/36a505ac65e956da09e93cc753609635a511047e\"\u003e\u003ccode\u003e36a505a\u003c/code\u003e\u003c/a\u003e test(checkpoint-postgres,checkpoint-sqlite): run the conformance suite (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8537\"\u003e#8537\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langgraph/commit/d569e18f4bd78b7652cb88c84b8dd098057e4f7d\"\u003e\u003ccode\u003ed569e18\u003c/code\u003e\u003c/a\u003e fix(checkpoint-postgres): find plain-value seeds when walking delta history (...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langgraph/commit/f22af6248c93df08b553e9a264f6367797e0fddb\"\u003e\u003ccode\u003ef22af62\u003c/code\u003e\u003c/a\u003e chore: enable RUF100 and clear unused noqa directives (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8546\"\u003e#8546\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langgraph/commit/658541c4960f329864a2523fc7d52427e8190bed\"\u003e\u003ccode\u003e658541c\u003c/code\u003e\u003c/a\u003e chore(checkpoint-postgres,checkpoint-sqlite): enable PLC0415 lint rule (\u003ca href=\"https://redirect.github.com/langchain-ai/langgraph/issues/8540\"\u003e#8540\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langgraph/commit/fb3d5f0399222504e015fe959e0e79fdc6e00a65\"\u003e\u003ccode\u003efb3d5f0\u003c/code\u003e\u003c/a\u003e chore(deps): bump the minor-and-patch group in /libs/cli/js-examples with 8 u...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langgraph/commit/01521c1b1cc4c035f64b9be40f2913285128f526\"\u003e\u003ccode\u003e01521c1\u003c/code\u003e\u003c/a\u003e chore(deps): bump the minor-and-patch group in /libs/cli/js-monorepo-example ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/langchain-ai/langgraph/commit/cd62febcfae628d0930d1f7d3cb3b5919d4b800f\"\u003e\u003ccode\u003ecd62feb\u003c/code\u003e\u003c/a\u003e chore(deps): bump the minor-and-patch group in /libs/checkpoint with 4 update...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/langchain-ai/langgraph/compare/checkpoint==4.1.1...checkpoint==4.2.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `python-dotenv` from 1.2.2 to 1.2.3\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/theskumar/python-dotenv/releases\"\u003epython-dotenv's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.2.3\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eStrip a leading UTF-8 BOM from \u003ccode\u003e.env\u003c/code\u003e file contents so the first variable is no longer silently lost when the file is saved with BOM (e.g. by some JetBrains IDEs on Windows) by [\u003ca href=\"https://github.com/h1whelan\"\u003e\u003ccode\u003e@​h1whelan\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/640\"\u003e#640\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eset_key\u003c/code\u003e now escapes backslashes, so values containing them (Windows paths, regular expressions) survive a write/read round-trip. Quoted values ending in an escaped backslash are no longer mis-parsed as an escaped quote, which used to swallow the following lines by [\u003ca href=\"https://github.com/dchaudhari7177\"\u003e\u003ccode\u003e@​dchaudhari7177\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/680\"\u003e#680\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003edotenv run\u003c/code\u003e now prints a friendly error instead of a traceback when no command is given by [\u003ca href=\"https://github.com/bbc2\"\u003e\u003ccode\u003e@​bbc2\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/606\"\u003e#606\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eCache the parsed result for empty \u003ccode\u003e.env\u003c/code\u003e files so repeated \u003ccode\u003edotenv_values\u003c/code\u003e/\u003ccode\u003eload_dotenv\u003c/code\u003e calls no longer re-read the file by [\u003ca href=\"https://github.com/ReinerBRO\"\u003e\u003ccode\u003e@​ReinerBRO\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/638\"\u003e#638\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/theskumar/python-dotenv/blob/main/CHANGELOG.md\"\u003epython-dotenv's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e[1.2.3] - 2026-08-16\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eStrip a leading UTF-8 BOM from \u003ccode\u003e.env\u003c/code\u003e file contents so the first variable is no longer silently lost when the file is saved with BOM (e.g. by some JetBrains IDEs on Windows) by [\u003ca href=\"https://github.com/h1whelan\"\u003e\u003ccode\u003e@​h1whelan\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/640\"\u003e#640\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eset_key\u003c/code\u003e now escapes backslashes, so values containing them (Windows paths, regular expressions) survive a write/read round-trip. Quoted values ending in an escaped backslash are no longer mis-parsed as an escaped quote, which used to swallow the following lines by [\u003ca href=\"https://github.com/dchaudhari7177\"\u003e\u003ccode\u003e@​dchaudhari7177\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/680\"\u003e#680\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003edotenv run\u003c/code\u003e now prints a friendly error instead of a traceback when no command is given by [\u003ca href=\"https://github.com/bbc2\"\u003e\u003ccode\u003e@​bbc2\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/606\"\u003e#606\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eCache the parsed result for empty \u003ccode\u003e.env\u003c/code\u003e files so repeated \u003ccode\u003edotenv_values\u003c/code\u003e/\u003ccode\u003eload_dotenv\u003c/code\u003e calls no longer re-read the file by [\u003ca href=\"https://github.com/ReinerBRO\"\u003e\u003ccode\u003e@​ReinerBRO\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/638\"\u003e#638\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/49515afee2d50c33cad9419b3800b3a0dc93fc59\"\u003e\u003ccode\u003e49515af\u003c/code\u003e\u003c/a\u003e Bump version: 1.2.2 → 1.2.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/8ac846ff2760b65470e769d7eed33e540f0934e1\"\u003e\u003ccode\u003e8ac846f\u003c/code\u003e\u003c/a\u003e chore: add release runbook (RELEASING.md) and make release target\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/bb31c944fb4b40e8dea59587f525840c38326166\"\u003e\u003ccode\u003ebb31c94\u003c/code\u003e\u003c/a\u003e docs: add 1.2.3 release notes (\u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/606\"\u003e#606\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/638\"\u003e#638\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/680\"\u003e#680\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/f7b18d9c72d1abcc2ad4023424b84f5bee30d266\"\u003e\u003ccode\u003ef7b18d9\u003c/code\u003e\u003c/a\u003e fix: round-trip backslashes through set_key (\u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/680\"\u003e#680\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/751f8c148222e58aa173c83c4e5e6cfccb2cc124\"\u003e\u003ccode\u003e751f8c1\u003c/code\u003e\u003c/a\u003e ci(deps): bump actions/checkout from 6.0.2 to 6.0.3 in the github-actions gro...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/f1937b68f338d7ebd7754da377ca08b2f0df8dbb\"\u003e\u003ccode\u003ef1937b6\u003c/code\u003e\u003c/a\u003e chore(deps): update mkdocs-include-markdown-plugin requirement from \u0026gt;=6.0.0 t...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/45b93720dd5e9e127d0be3971a04855d34e464d8\"\u003e\u003ccode\u003e45b9372\u003c/code\u003e\u003c/a\u003e chore(deps): update pytest requirement from \u0026gt;=3.9 to \u0026gt;=9.0.3 (\u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/653\"\u003e#653\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/72896e9244d2a1ff8d5e1934d3df8a35c813799a\"\u003e\u003ccode\u003e72896e9\u003c/code\u003e\u003c/a\u003e docs: fix broken mkdocs link in CONTRIBUTING.md (\u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/636\"\u003e#636\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/72754a16a4743e4c92edf87ce59ba0e4ff78758d\"\u003e\u003ccode\u003e72754a1\u003c/code\u003e\u003c/a\u003e ci(deps): bump peaceiris/actions-gh-pages from 4.0.0 to 4.1.0 in the github-a...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/078325e92558330e9addc661b789c7b6123fa73c\"\u003e\u003ccode\u003e078325e\u003c/code\u003e\u003c/a\u003e ci(security): harden CI/CD supply chain with SHA pinning and least-privilege ...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/theskumar/python-dotenv/compare/v1.2.2...v1.2.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `pypdfium2` from 5.11.0 to 5.13.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pypdfium2-team/pypdfium2/releases\"\u003epypdfium2's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e5.13.0\u003c/h2\u003e\n\u003ch2\u003eRelease 5.13.0\u003c/h2\u003e\n\u003ch3\u003eSummary\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eExperimental \u003ccode\u003epyemscripten_2026_0_wasm32\u003c/code\u003e (Pyodide) build support added. \u003cem\u003eHowever, the resulting builds are flaky at runtime and subject to various types of random crashes. Freezes on shutdown have also been observed.\u003c/em\u003e\nWhile these issues persist, PyEmscripten wheels will not be uploaded to PyPI, but they are included in the release process and can be downloaded from GitHub on an experimental basis. If you can help track down and fix these issues, please reach out.\nNote: Our PyEmscripten wheels are bigger than usual, as they are built with debug symbols (a non-debug build is not considered useful at this stage).\u003c/li\u003e\n\u003cli\u003eFixed compatibility with Python 3.6 and 3.7.\n\u003cul\u003e\n\u003cli\u003eRuntime support was inadvertently broken due to a faulty cached property backport which held only one cache per class, not per instance as should have been.\nThe accidental loss of caches broke key assumptions of our autoclose logic, which relies on \u003ccode\u003ecached_property\u003c/code\u003e since 5.8.0. (Earlier versions that did not make extensive use of cached properties might work but have not been explicitly tested.)\u003c/li\u003e\n\u003cli\u003eThis release replaces both \u003ccode\u003efunctools.cached_property\u003c/code\u003e and the faulty \u003ccode\u003efunctools.lru_cache()\u003c/code\u003e based backport with our own, backward compatible \u003ccode\u003ecached_property\u003c/code\u003e implementation along with thorough documentation.\u003c/li\u003e\n\u003cli\u003eAlso, fixed setup (i.e. source installation) with Python 3.6 and its max available setup dependency versions (that is, \u003ccode\u003esetuptools\u003c/code\u003e 59). This had probably been broken for a long time. (A few non-breaking issues remain, e.g. for some reason we end up with a \u003ccode\u003epurelib\u003c/code\u003e directory, but it should be \u003ccode\u003eplatlib\u003c/code\u003e.)\u003c/li\u003e\n\u003cli\u003eBear in mind that ctypesgen continues to require Python \u003ccode\u003e\u0026gt;=3.8\u003c/code\u003e at this time (3.6 compat not being a priority in that case), but you can install with \u003ccode\u003e--no-build-isolation\u003c/code\u003e and let the reference bindings be used, or try adding ctypesgen's \u003ccode\u003esrc/\u003c/code\u003e to \u003ccode\u003ePYTHONPATH\u003c/code\u003e to bypass setup, and see how it goes.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eNote: We do not plan to (and practically cannot) keep up compatibility with outdated Python versions indefinitely.\u003c/strong\u003e In particular, setup compatibility may be dropped sooner or later in favor of contemporary Python packaging concepts, like migrating as much as possible to \u003ccode\u003epyproject.toml\u003c/code\u003e. That said, we are happy to restore compatibility at this point, and fix any \u003cem\u003eunintentional\u003c/em\u003e breakage.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eMANIFEST.in\u003c/code\u003e missing Windows spoof headers, which resulted in subtly incorrect bindings when installing from an sdist on Windows, as seen in test failures. (Release wheels have been unaffected and passed the test suite, so this issue went unnoticed for a while.)\u003c/li\u003e\n\u003cli\u003eBumped \u003ccode\u003egn-dist\u003c/code\u003e from \u003ccode\u003e2407.1\u003c/code\u003e to \u003ccode\u003e2407.3\u003c/code\u003e. Made its setup python 3.6 compatible likewise (wheels should have worked before now). Changed versioning and release process so that CI no longer needs to push to the repository (may eventually become a blueprint for pypdfium2 itself). More documentation added, including \u003ccode\u003emanylinux2014\u003c/code\u003e POC.\u003c/li\u003e\n\u003cli\u003eInternal improvements (non-exhaustive):\n\u003cul\u003e\n\u003cli\u003eProperly clean up \u003ccode\u003e*.egg-info/\u003c/code\u003e and \u003ccode\u003ebuild/\u003c/code\u003e before packaging, to avoid mad file inclusion bugs (ran into this while working on setup include rules).\u003c/li\u003e\n\u003cli\u003eMigrated from requirements files to PEP 735 dependency groups (\u003ccode\u003epyproject.toml\u003c/code\u003e).\nRecent enough \u003ccode\u003epip\u003c/code\u003e should be available to Python \u0026gt;= 3.9. For compatibility with older versions, feel free to use \u003ccode\u003e./utils/misc/install_dep_group.py\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eApplied dependency cooldowns to internal callers of \u003ccode\u003epip install\u003c/code\u003e. Always use virtual environments in CI. Use lockfiles in sensitive areas (e.g. publish jobs).\u003c/li\u003e\n\u003cli\u003eRearranged \u0026amp; improved utilities. Cleaner distinction between \u003ccode\u003esetupsrc/\u003c/code\u003e and \u003ccode\u003eutils/\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eWork around persistent i686 container network issues by downgrading host runner to \u003ccode\u003eubuntu-24.04\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eLet \u003ccode\u003esetupsrc/\u003c/code\u003e share code from \u003ccode\u003esrc/\u003c/code\u003e through a \u003ccode\u003epypdfium2_cfg._shared\u003c/code\u003e submodule that can be added to \u003ccode\u003esys.path\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBuild info\u003c/h3\u003e\n\u003cp\u003eThis release was made with the following build strategies:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003ePBIN: \u003ccode\u003e[macosx_arm64, macosx_x86_64, win_amd64, win_arm64, win32, manylinux_x86_64, manylinux_i686, manylinux_aarch64, manylinux_armv7l, manylinux_ppc64le, manylinux_mips64le, android_arm64_v8a, android_armeabi_v7a]\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eSBLD: \u003ccode\u003e[manylinux_mipsle]\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eCIBW: \u003ccode\u003e[manylinux_riscv64, manylinux_loongarch64, manylinux_s390x, musllinux_x86_64, musllinux_aarch64, musllinux_armv7l, musllinux_i686, musllinux_ppc64le, musllinux_s390x, musllinux_riscv64, musllinux_loongarch64, pyodide_wasm32]\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cblockquote\u003e\n\u003cp\u003e[!CAUTION]\nThe following builds are affected by known, major issues (e.g. endianness bugs, crashes, freezes) and are \u003cstrong\u003eNOT\u003c/strong\u003e considered ready for production use:\n\u003ccode\u003e[manylinux_s390x, musllinux_s390x, pyodide_wasm32]\u003c/code\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003ch3\u003eCommit logs\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cp\u003eCommits between \u003ca href=\"https://github.com/pypdfium2-team/pypdfium2/tree/5.12.1\"\u003e\u003ccode\u003e5.12.1\u003c/code\u003e\u003c/a\u003e and \u003ca href=\"https://github.com/pypdfium2-team/pypdfium2/tree/5.13.0\"\u003e\u003ccode\u003e5.13.0\u003c/code\u003e\u003c/a\u003e (latest commit first):\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypdfium2-team/pypdfium2/commit/a4659102e4c258ee18c661232c0f9763f6c85ad0\"\u003e\u003ccode\u003ea4659102\u003c/code\u003e\u003c/a\u003e [autorelease main] update 5.13.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypdfium2-team/pypdfium2/commit/9094de358328ae44236c5cb401a8155311e450a0\"\u003e\u003ccode\u003e9094de35\u003c/code\u003e\u003c/a\u003e continue on changelog/docs\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypdfium2-team/pypdfium2/commit/b89e367a5dec13b99ec20f0beed137146a75bbcf\"\u003e\u003ccode\u003eb89e367a\u003c/code\u003e\u003c/a\u003e git_net_additions.py: minor tweaks\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypdfium2-team/pypdfium2/commit/57157e789f2573f6d4b61e58e8c7a778674afdd1\"\u003e\u003ccode\u003e57157e78\u003c/code\u003e\u003c/a\u003e readme: don't overdo admonitions\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypdfium2-team/pypdfium2/commit/033d5ce066aba79233d4f406678bbac057ad6011\"\u003e\u003ccode\u003e033d5ce0\u003c/code\u003e\u003c/a\u003e changelog: less waffle\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypdfium2-team/pypdfium2/commit/5afbd6193eff87df05153148116a82d9f7cd7fa3\"\u003e\u003ccode\u003e5afbd619\u003c/code\u003e\u003c/a\u003e install_buildtools: use compat function for dependency group\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypdfium2-team/pypdfium2/commit/a4659102e4c258ee18c661232c0f9763f6c85ad0\"\u003e\u003ccode\u003ea465910\u003c/code\u003e\u003c/a\u003e [autorelease main] update 5.13.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypdfium2-team/pypdfium2/commit/9094de358328ae44236c5cb401a8155311e450a0\"\u003e\u003ccode\u003e9094de3\u003c/code\u003e\u003c/a\u003e continue on changelog/docs\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypdfium2-team/pypdfium2/commit/b89e367a5dec13b99ec20f0beed137146a75bbcf\"\u003e\u003ccode\u003eb89e367\u003c/code\u003e\u003c/a\u003e git_net_additions.py: minor tweaks\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypdfium2-team/pypdfium2/commit/57157e789f2573f6d4b61e58e8c7a778674afdd1\"\u003e\u003ccode\u003e57157e7\u003c/code\u003e\u003c/a\u003e readme: don't overdo admonitions\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypdfium2-team/pypdfium2/commit/033d5ce066aba79233d4f406678bbac057ad6011\"\u003e\u003ccode\u003e033d5ce\u003c/code\u003e\u003c/a\u003e changelog: less waffle\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypdfium2-team/pypdfium2/commit/5afbd6193eff87df05153148116a82d9f7cd7fa3\"\u003e\u003ccode\u003e5afbd61\u003c/code\u003e\u003c/a\u003e install_buildtools: use compat function for dependency group\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypdfium2-team/pypdfium2/commit/3282e36375fd6e139f885ff634747ab0fe643e66\"\u003e\u003ccode\u003e3282e36\u003c/code\u003e\u003c/a\u003e Add zizmor to check step\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypdfium2-team/pypdfium2/commit/07b84aaaa9c4c44429e0316c15c179b64c004d0a\"\u003e\u003ccode\u003e07b84aa\u003c/code\u003e\u003c/a\u003e Progress changelog\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypdfium2-team/pypdfium2/commit/6ec38d2aa64d59f02892ddf07f601bbdb5bbf53e\"\u003e\u003ccode\u003e6ec38d2\u003c/code\u003e\u003c/a\u003e git_net_additions: further improve fallback\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pypdfium2-team/pypdfium2/commit/b5cdd7c7fcd2c01cd7744b6824f977bbbcb831c6\"\u003e\u003ccode\u003eb5cdd7c\u003c/code\u003e\u003c/a\u003e git_net_additions: fancier fallback for binary files\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/pypdfium2-team/pypdfium2/compare/5.11.0...5.13.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `duckdb` from 1.5.4 to 1.5.5\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/duckdb/duckdb-python/releases\"\u003educkdb's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.5.5 Bugfix Release\u003c/h2\u003e\n\u003cp\u003eSee \u003ca href=\"https://github.com/duckdb/duckdb/releases/tag/v1.5.5\"\u003eDuckDB's changelog\u003c/a\u003e for all changes in DuckDB.\u003c/p\u003e\n\u003ch2\u003eWhat's Changed in DuckDB-Python\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix numpy deprecations by \u003ca href=\"https://github.com/evertlammerts\"\u003e\u003ccode\u003e@​evertlammerts\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/duckdb/duckdb-python/pull/505\"\u003educkdb/duckdb-python#505\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix alias of \u003ccode\u003eDuckDBPyRelation.query\u003c/code\u003e (closes \u003ca href=\"https://redirect.github.com/duckdb/duckdb-python/issues/468\"\u003e#468\u003c/a\u003e) by \u003ca href=\"https://github.com/evertlammerts\"\u003e\u003ccode\u003e@​evertlammerts\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/duckdb/duckdb-python/pull/524\"\u003educkdb/duckdb-python#524\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/duckdb/duckdb-python/commit/b236c8194ed14c7a7c685e0534dde501cc855b3a\"\u003e\u003ccode\u003eb236c81\u003c/code\u003e\u003c/a\u003e Pin submodule to release hash\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/duckdb/duckdb-python/commit/e6a21c5b5d65d741fafd5a7389c93b8b86a7f249\"\u003e\u003ccode\u003ee6a21c5\u003c/code\u003e\u003c/a\u003e [duckdb-labs bot] Bump DuckDB submodule (\u003ca href=\"https://redirect.github.com/duckdb/duckdb-python/issues/554\"\u003e#554\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/duckdb/duckdb-python/commit/f637bf42683030cbb108268581b866f13cb75031\"\u003e\u003ccode\u003ef637bf4\u003c/code\u003e\u003c/a\u003e Bump submodule\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/duckdb/duckdb-python/commit/4c5c73c63381bd0587fd42b41093c8f0abe9f17c\"\u003e\u003ccode\u003e4c5c73c\u003c/code\u003e\u003c/a\u003e [duckdb-labs bot] Bump DuckDB submodule (\u003ca href=\"https://redirect.github.com/duckdb/duckdb-python/issues/551\"\u003e#551\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/duckdb/duckdb-python/commit/6fae28061912de88c3c0f6e6ad6b2f3fc5ee5235\"\u003e\u003ccode\u003e6fae280\u003c/code\u003e\u003c/a\u003e Bump submodule\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/duckdb/duckdb-python/commit/d8d5f0a36003c9090ea9480cdefa8f4b4122fece\"\u003e\u003ccode\u003ed8d5f0a\u003c/code\u003e\u003c/a\u003e [duckdb-labs bot] Bump DuckDB submodule (\u003ca href=\"https://redirect.github.com/duckdb/duckdb-python/issues/548\"\u003e#548\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/duckdb/duckdb-python/commit/5d85f06025e83e3d2c69813acf4b2dc02bebc415\"\u003e\u003ccode\u003e5d85f06\u003c/code\u003e\u003c/a\u003e Bump submodule\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/duckdb/duckdb-python/commit/c3cbf8d9ca87cea3dfbb89bfa2102ff4ec530f00\"\u003e\u003ccode\u003ec3cbf8d\u003c/code\u003e\u003c/a\u003e [duckdb-labs bot] Bump DuckDB submodule (\u003ca href=\"https://redirect.github.com/duckdb/duckdb-python/issues/545\"\u003e#545\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/duckdb/duckdb-python/commit/93418b65c6ca821d71d9a091fb5218ad55d8a4eb\"\u003e\u003ccode\u003e93418b6\u003c/code\u003e\u003c/a\u003e Bump submodule\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/duckdb/duckdb-python/commit/24f1915b590e1e663a14c0bff9e49bf28ebece9b\"\u003e\u003ccode\u003e24f1915\u003c/code\u003e\u003c/a\u003e [duckdb-labs bot] Bump DuckDB submodule (\u003ca href=\"https://redirect.github.com/duckdb/duckdb-python/issues/539\"\u003e#539\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/duckdb/duckdb-python/compare/v1.5.4...v1.5.5\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `scikit-learn` from 1.9.0 to 1.9.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/scikit-learn/scikit-learn/releases\"\u003escikit-learn's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eScikit-learn 1.9.1\u003c/h2\u003e\n\u003cp\u003eWe're happy to announce the 1.9.1 release.\u003c/p\u003e\n\u003cp\u003eThis release contains a few bug fixes and is the first version supporting Python 3.15.\u003c/p\u003e\n\u003cp\u003eYou can see the changelog here: \u003ca href=\"https://scikit-learn.org/stable/whats_new/v1.9.html#version-1-9-1\"\u003ehttps://scikit-learn.org/stable/whats_new/v1.9.html#version-1-9-1\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eYou can upgrade with pip as usual:\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003epip install -U scikit-learn\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eThe conda-forge builds can be installed using:\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003econda install -c conda-forge scikit-learn\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eThanks to everyone who contributed to this release !\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/scikit-learn/scikit-learn/commit/866c0f51e7560ef0303cbcc5f159df5382ea9e3f\"\u003e\u003ccode\u003e866c0f5\u003c/code\u003e\u003c/a\u003e generate changelog\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/scikit-learn/scikit-learn/commit/12f135fbffe3b3e7e294e4ef16f0b59f68e6a6b9\"\u003e\u003ccode\u003e12f135f\u003c/code\u003e\u003c/a\u003e update upper bounds\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/scikit-learn/scikit-learn/commit/43ff2f20bc5bfbe92b9cd3ec9d86214da8ee2c6e\"\u003e\u003ccode\u003e43ff2f2\u003c/code\u003e\u003c/a\u003e bump version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/scikit-learn/scikit-learn/commit/b8515241202663142b65dbe92294e96a6dc5def2\"\u003e\u003ccode\u003eb851524\u003c/code\u003e\u003c/a\u003e DOC Mark dev index as orphan (\u003ca href=\"https://redirect.github.com/scikit-learn/scikit-learn/issues/34916\"\u003e#34916\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/scikit-learn/scikit-learn/commit/01d56d48da18e7b365c4d2ebcd5d1fddaa24dd12\"\u003e\u003ccode\u003e01d56d4\u003c/code\u003e\u003c/a\u003e DOC Fix wikipedia principal eigenvector example references (\u003ca href=\"https://redirect.github.com/scikit-learn/scikit-learn/issues/34915\"\u003e#34915\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/scikit-learn/scikit-learn/commit/b86a1e227c2c424b17f8872d4094bbbc061e32c9\"\u003e\u003ccode\u003eb86a1e2\u003c/code\u003e\u003c/a\u003e :lock: :robot: CI Update lock files for array-api CI build(s) :lock: :robot: ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/scikit-learn/scikit-learn/commit/d282698440cec541f2427794b8c205fb4b1420be\"\u003e\u003ccode\u003ed282698\u003c/code\u003e\u003c/a\u003e :lock: :robot: CI Update lock files for main CI build(s) :lock: :robot: (\u003ca href=\"https://redirect.github.com/scikit-learn/scikit-learn/issues/34897\"\u003e#34897\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/scikit-learn/scikit-learn/commit/eb34279083fe9297d141efddceaf38c596a49766\"\u003e\u003ccode\u003eeb34279\u003c/code\u003e\u003c/a\u003e :lock: :robot: CI Update lock files for free-threaded CI build(s) :lock: :rob...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/scikit-learn/scikit-learn/commit/7581303c447a0daa07fa74ba8104e327c11f1dc5\"\u003e\u003ccode\u003e7581303\u003c/code\u003e\u003c/a\u003e FIX: Fix \u003ccode\u003eQuantileTransformer(ignore_implicit_zeros=True)\u003c/code\u003e sub-sampling behav...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/scikit-learn/scikit-learn/commit/ac47f4de75eacad880b77db09aa1f677f6038274\"\u003e\u003ccode\u003eac47f4d\u003c/code\u003e\u003c/a\u003e FIX: avoid EfficiencyWarning in OPTICS with metric='precomputed' (\u003ca href=\"https://redirect.github.com/scikit-learn/scikit-learn/issues/34692\"\u003e#34692\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/scikit-learn/scikit-learn/compare/1.9.0...1.9.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `joblib` from 1.5.3 to 1.6.0\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/joblib/joblib/blob/main/CHANGES.rst\"\u003ejoblib's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eRelease 1.6.0 - 2026/08/31\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eFix caching of functions whose source cannot be retrieved, such as functions\ndefined in a notebook cell. Their identity fell back to\n\u003ccode\u003estr(hash(func.__code__))\u003c/code\u003e, which is salted by \u003ccode\u003ePYTHONHASHSEED\u003c/code\u003e and so\ndiffered between processes. A worker reading the \u003ccode\u003efunc_code.py\u003c/code\u003e written by\nanother one concluded that the function had changed and wiped the whole\ncache directory for it, discarding results computed by its peers.\n\u003ccode\u003efunc_code.py\u003c/code\u003e is also no longer rewritten in place, so a reader can no\nlonger catch it half-written and draw the same conclusion.\n\u003ca href=\"https://redirect.github.com/joblib/joblib/issues/1694\"\u003ejoblib/joblib#1694\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eDrop python 3.9 support. The oldest supported Python version\nis now Python 3.10.\n\u003ca href=\"https://redirect.github.com/joblib/joblib/pull/1773\"\u003ejoblib/joblib#1773\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix \u003ccode\u003eeval_expr\u003c/code\u003e (used to evaluate the \u003ccode\u003epre_dispatch\u003c/code\u003e argument of\n\u003ccode\u003eParallel\u003c/code\u003e) to raise a \u003ccode\u003eValueError\u003c/code\u003e as documented instead of leaking a\n\u003ccode\u003eZeroDivisionError\u003c/code\u003e for expressions that divide or take a modulo by zero.\n\u003ca href=\"https://redirect.github.com/joblib/joblib/pull/1810\"\u003ejoblib/joblib#1810\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ccode\u003eMemorizedResult\u003c/code\u003e now forwards \u003ccode\u003emmap_mode\u003c/code\u003e to its store backend, so a\ncached array reconstructed from a location is memory-mapped as requested\ninstead of being loaded fully into memory.\n\u003ca href=\"https://redirect.github.com/joblib/joblib/pull/1799\"\u003ejoblib/joblib#1799\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eUnvendor cloudpickle to more quickly benefit from maintenance releases\nof cloudpickle\n\u003ca href=\"https://redirect.github.com/joblib/joblib/pull/1775\"\u003ejoblib/joblib#1775\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix \u003ccode\u003eMemory.cache\u003c/code\u003e for functions with a keyword-only argument that has a\ndefault declared before a keyword-only argument without a default.\n\u003ca href=\"https://redirect.github.com/joblib/joblib/issues/1731\"\u003ejoblib/joblib#1731\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix behavior of \u003ccode\u003efilter_args\u003c/code\u003e on some precise cases.\n\u003ca href=\"https://redirect.github.com/joblib/joblib/pull/1800\"\u003ejoblib/joblib#1800\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix a concurrency error that could happen with unordered generator.\n\u003ca href=\"https://redirect.github.com/joblib/joblib/pull/1789\"\u003ejoblib/joblib#1789\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix: \u003ccode\u003edump()\u003c/code\u003e now accepts any input \u003ccode\u003eos.PathLike\u003c/code\u003e object to be consistent with\n\u003ccode\u003eload\u003c/code\u003e.\n\u003ca href=\"https://redirect.github.com/joblib/joblib/pull/1812\"\u003ejoblib/joblib#1812\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eThe documentation now uses pydata sphinx theme. Furthermore, optional dependencies\n\u003ccode\u003etest\u003c/code\u003e and \u003ccode\u003edocs\u003c/code\u003e have been added to \u003ccode\u003epyproject.toml\u003c/code\u003e.\n\u003ca href=\"https://redirect.github.com/joblib/joblib/pull/1774\"\u003ejoblib/joblib#1774\u003c/a\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eVendor \u003ccode\u003eloky 3.6.0\u003c/code\u003e\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/joblib/joblib/commit/cd9a6b05fc4f2b1c8202eb62c4e863484f8cc099\"\u003e\u003ccode\u003ecd9a6b0\u003c/code\u003e\u003c/a\u003e Release 1.6.0 (\u003ca href=\"https://redirect.github.com/joblib/joblib/issues/1844\"\u003e#1844\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/joblib/joblib/commit/d873f972949d78166af6c945667c53f04d41fed6\"\u003e\u003ccode\u003ed873f97\u003c/code\u003e\u003c/a\u003e MNT vendor loky 3.6.0 (\u003ca href=\"https://redirect.github.com/joblib/joblib/issues/1843\"\u003e#1843\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/joblib/joblib/commit/4ff61afd0849f18fddf5fbd137c1f02bfaed5223\"\u003e\u003ccode\u003e4ff61af\u003c/code\u003e\u003c/a\u003e Bump the github-actions group with 4 updates (\u003ca href=\"https://redirect.github.com/joblib/joblib/issues/1832\"\u003e#1832\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/joblib/joblib/commit/804f4725e1a27b1425c8aabcf7312ceb11c3a07d\"\u003e\u003ccode\u003e804f472\u003c/code\u003e\u003c/...\n\n_Description has been truncated_","html_url":"https://github.com/Vatsa1374/Vibe-trading-/pull/26","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/Vatsa1374%2FVibe-trading-/issues/26","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/26/packages"}},{"old_version":"\u003e=3.13.3","new_version":"\u003e=3.14.3","update_type":"minor","path":null,"pr_created_at":"2026-09-16T02:11:59.000Z","version_change":"\u003e=3.13.3 → \u003e=3.14.3","issue":{"uuid":"5469403115","node_id":"PR_kwDOUc0WIs8AAAABDszVZA","number":10,"state":"open","title":"chore(deps): update aiohttp requirement from \u003e=3.13.3 to \u003e=3.14.3","user":"dependabot[bot]","labels":[],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-16T02:11:59.000Z","updated_at":"2026-09-16T02:11:59.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps): update","packages":[{"name":"aiohttp","old_version":"\u003e=3.13.3","new_version":"\u003e=3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"}],"path":null,"ecosystem":"pip"},"body":"Updates the requirements on [aiohttp](https://github.com/aio-libs/aiohttp) to permit the latest version.\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\n\n\n\u003c/details\u003e","html_url":"https://github.com/01sure/Multi-Agent-Intelligent-Warehouse/pull/10","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/01sure%2FMulti-Agent-Intelligent-Warehouse/issues/10","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/10/packages"}},{"old_version":"3.14.1","new_version":"3.14.3","update_type":"patch","path":null,"pr_created_at":"2026-09-15T22:10:08.000Z","version_change":"3.14.1 → 3.14.3","issue":{"uuid":"5467892353","node_id":"PR_kwDOTIfnCs8AAAABDrnK9A","number":17,"state":"open","title":"build(deps): bump the minor-and-patch group across 1 directory with 14 updates","user":"dependabot[bot]","labels":["dependencies","python:uv"],"assignees":[],"locked":false,"comments_count":8,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-15T22:10:08.000Z","updated_at":"2026-09-15T22:11:35.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"build(deps): bump","group_name":"minor-and-patch","update_count":14,"packages":[{"name":"uvicorn","old_version":"0.49.0","new_version":"0.52.4","repository_url":"https://github.com/Kludex/uvicorn"},{"name":"pydantic","old_version":"2.13.4","new_version":"2.13.5","repository_url":"https://github.com/pydantic/pydantic"},{"name":"python-dotenv","old_version":"1.2.2","new_version":"1.2.3","repository_url":"https://github.com/theskumar/python-dotenv"},{"name":"tiktoken","old_version":"0.13.0","new_version":"0.14.0","repository_url":"https://github.com/openai/tiktoken"},{"name":"pydantic-settings","old_version":"2.14.2","new_version":"2.15.0","repository_url":"https://github.com/pydantic/pydantic-settings"},{"name":"aiohttp","old_version":"3.14.1","new_version":"3.14.3","repository_url":"https://github.com/aio-libs/aiohttp"},{"name":"reportlab","old_version":"5.0.0","new_version":"5.0.1"},{"name":"grpcio","old_version":"1.81.1","new_version":"1.83.1","repository_url":"https://github.com/grpc/grpc"},{"name":"nvidia-riva-client","old_version":"2.26.0","new_version":"2.27.0","repository_url":"https://github.com/nvidia-riva/python-clients"},{"name":"torch","old_version":"2.12.1+cu130","new_version":"2.14.0","repository_url":"https://github.com/pytorch/pytorch"},{"name":"transformers","old_version":"5.12.1","new_version":"5.17.0","repository_url":"https://github.com/huggingface/transformers"},{"name":"accelerate","old_version":"1.14.0","new_version":"1.15.0","repository_url":"https://github.com/huggingface/accelerate"},{"name":"ty","old_version":"0.0.55","new_version":"0.0.80","repository_url":"https://github.com/astral-sh/ty"},{"name":"ruff","old_version":"0.15.20","new_version":"0.16.7","repository_url":"https://github.com/astral-sh/ruff"}],"path":null,"ecosystem":"pip"},"body":"Bumps the minor-and-patch group with 14 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [uvicorn](https://github.com/Kludex/uvicorn) | `0.49.0` | `0.52.4` |\n| [pydantic](https://github.com/pydantic/pydantic) | `2.13.4` | `2.13.5` |\n| [python-dotenv](https://github.com/theskumar/python-dotenv) | `1.2.2` | `1.2.3` |\n| [tiktoken](https://github.com/openai/tiktoken) | `0.13.0` | `0.14.0` |\n| [pydantic-settings](https://github.com/pydantic/pydantic-settings) | `2.14.2` | `2.15.0` |\n| [aiohttp](https://github.com/aio-libs/aiohttp) | `3.14.1` | `3.14.3` |\n| [reportlab](https://www.reportlab.com/) | `5.0.0` | `5.0.1` |\n| [grpcio](https://github.com/grpc/grpc) | `1.81.1` | `1.83.1` |\n| [nvidia-riva-client](https://github.com/nvidia-riva/python-clients) | `2.26.0` | `2.27.0` |\n| [torch](https://github.com/pytorch/pytorch) | `2.12.1+cu130` | `2.14.0` |\n| [transformers](https://github.com/huggingface/transformers) | `5.12.1` | `5.17.0` |\n| [accelerate](https://github.com/huggingface/accelerate) | `1.14.0` | `1.15.0` |\n| [ty](https://github.com/astral-sh/ty) | `0.0.55` | `0.0.80` |\n| [ruff](https://github.com/astral-sh/ruff) | `0.15.20` | `0.16.7` |\n\n\nUpdates `uvicorn` from 0.49.0 to 0.52.4\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/Kludex/uvicorn/releases\"\u003euvicorn's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eVersion 0.52.4\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eRemove duplicate \u003ccode\u003eDate\u003c/code\u003e headers from accepted WebSocket handshakes with \u003ccode\u003ewebsockets-sansio\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/3078\"\u003e#3078\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/Kludex/uvicorn/compare/0.52.3...0.52.4\"\u003ehttps://github.com/Kludex/uvicorn/compare/0.52.3...0.52.4\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eVersion 0.52.3\u003c/h2\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate \u003ccode\u003ezttp\u003c/code\u003e to 0.0.24 and use its combined receive path, improving HTTP/1.1 request parsing performance (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3067\"\u003e#3067\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/Kludex/uvicorn/compare/0.52.2...0.52.3\"\u003ehttps://github.com/Kludex/uvicorn/compare/0.52.2...0.52.3\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eVersion 0.52.2\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate \u003ccode\u003ezttp\u003c/code\u003e to 0.0.22, fixing bodyless request receives and improving HTTP/1 request parsing performance (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3063\"\u003e#3063\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/Kludex/uvicorn/compare/0.52.1...0.52.2\"\u003ehttps://github.com/Kludex/uvicorn/compare/0.52.1...0.52.2\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eVersion 0.52.1\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eComplete the closing handshake on server-initiated WebSocket closes in the \u003ccode\u003ewebsockets-sansio\u003c/code\u003e and \u003ccode\u003ewsproto\u003c/code\u003e implementations, waiting for the client's close reply with a 10 second timeout instead of resetting the connection (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3053\"\u003e#3053\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdd missing write flow control to the \u003ccode\u003ewebsockets-sansio\u003c/code\u003e implementation, preventing data truncation on server-initiated closes with large in-flight payloads (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3048\"\u003e#3048\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eHandle connection loss while a WebSocket write is waiting on backpressure (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3050\"\u003e#3050\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRemove duplicate \u003ccode\u003eContent-Type\u003c/code\u003e and \u003ccode\u003eContent-Length\u003c/code\u003e headers from WebSocket denial responses on the \u003ccode\u003ewebsockets-sansio\u003c/code\u003e implementation, and deliver non-UTF-8 denial bodies intact (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3041\"\u003e#3041\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/Kludex/uvicorn/compare/0.52.0...0.52.1\"\u003ehttps://github.com/Kludex/uvicorn/compare/0.52.0...0.52.1\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eVersion 0.52.0\u003c/h2\u003e\n\u003cp\u003eThis release adds an experimental HTTP/1.1 implementation backed by \u003ca href=\"https://zttp.marcelotryle.com/\"\u003ezttp\u003c/a\u003e, a sans-IO HTTP parser I've been developing on the side: a core written in Zig, with bindings to Python. It has been running under a fuzzer for some weeks now, and has been through multiple rounds of security auditing.\u003c/p\u003e\n\u003cp\u003eIt is still \u003cstrong\u003eexperimental\u003c/strong\u003e, so don't put it in front of production traffic yet. Try it with \u003ccode\u003e--http zttp\u003c/code\u003e, and please send any feedback to the \u003ca href=\"https://github.com/Kludex/uvicorn/issues\"\u003eissue tracker\u003c/a\u003e.\u003c/p\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdd an experimental \u003ccode\u003ezttp\u003c/code\u003e HTTP/1.1 implementation, selectable with \u003ccode\u003e--http zttp\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/2979\"\u003e#2979\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eKeep non-ASCII WebSocket request headers intact with websockets 17.0, which encodes them with ISO-8859-1 (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3036\"\u003e#3036\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/Kludex/uvicorn/compare/0.51.0...0.52.0\"\u003ehttps://github.com/Kludex/uvicorn/compare/0.51.0...0.52.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eVersion 0.51.0\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRestart workers with overlap on SIGHUP for near-zero-downtime reloads by \u003ca href=\"https://github.com/Kludex\"\u003e\u003ccode\u003e@​Kludex\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/3025\"\u003eKludex/uvicorn#3025\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/Kludex/uvicorn/blob/main/docs/release-notes.md\"\u003euvicorn's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e0.52.4 (August 18, 2026)\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eRemove duplicate \u003ccode\u003eDate\u003c/code\u003e headers from accepted WebSocket handshakes with \u003ccode\u003ewebsockets-sansio\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/pull/3078\"\u003e#3078\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e0.52.3 (August 13, 2026)\u003c/h2\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate \u003ccode\u003ezttp\u003c/code\u003e to 0.0.24 and use its combined receive path, improving HTTP/1.1 request parsing performance (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3067\"\u003e#3067\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e0.52.2 (August 13, 2026)\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate \u003ccode\u003ezttp\u003c/code\u003e to 0.0.22, fixing bodyless request receives and improving HTTP/1 request parsing performance (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3063\"\u003e#3063\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e0.52.1 (August 1, 2026)\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eComplete the closing handshake on server-initiated WebSocket closes in the \u003ccode\u003ewebsockets-sansio\u003c/code\u003e and \u003ccode\u003ewsproto\u003c/code\u003e implementations, waiting for the client's close reply with a 10 second timeout instead of resetting the connection (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3053\"\u003e#3053\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdd missing write flow control to the \u003ccode\u003ewebsockets-sansio\u003c/code\u003e implementation, preventing data truncation on server-initiated closes with large in-flight payloads (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3048\"\u003e#3048\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eHandle connection loss while a WebSocket write is waiting on backpressure (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3050\"\u003e#3050\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRemove duplicate \u003ccode\u003eContent-Type\u003c/code\u003e and \u003ccode\u003eContent-Length\u003c/code\u003e headers from WebSocket denial responses on the \u003ccode\u003ewebsockets-sansio\u003c/code\u003e implementation, and deliver non-UTF-8 denial bodies intact (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3041\"\u003e#3041\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e0.52.0 (July 29, 2026)\u003c/h2\u003e\n\u003cp\u003eThis release adds an experimental HTTP/1.1 implementation backed by \u003ca href=\"https://zttp.marcelotryle.com/\"\u003ezttp\u003c/a\u003e, a sans-IO HTTP parser I've been developing on the side: a core written in Zig, with bindings to Python. It has been running under a fuzzer for some weeks now, and has been through multiple rounds of security auditing.\u003c/p\u003e\n\u003cp\u003eIt is still \u003cstrong\u003eexperimental\u003c/strong\u003e, so don't put it in front of production traffic yet. Try it with \u003ccode\u003e--http zttp\u003c/code\u003e, and please send any feedback to the \u003ca href=\"https://github.com/Kludex/uvicorn/issues\"\u003eissue tracker\u003c/a\u003e.\u003c/p\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdd an experimental \u003ccode\u003ezttp\u003c/code\u003e HTTP/1.1 implementation, selectable with \u003ccode\u003e--http zttp\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/2979\"\u003e#2979\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eKeep non-ASCII WebSocket request headers intact with websockets 17.0, which encodes them with ISO-8859-1 (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3036\"\u003e#3036\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e0.51.0 (July 8, 2026)\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eRestart workers one at a time on \u003ccode\u003eSIGHUP\u003c/code\u003e, bringing each replacement up before retiring the old worker, so reloads no longer drop requests (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3025\"\u003e#3025\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eRemoved\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eRemove \u003ccode\u003ecolorama\u003c/code\u003e from the \u003ccode\u003estandard\u003c/code\u003e extra (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3027\"\u003e#3027\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/8988c23704fc373c9206cca53ec57dd8ad7f44a5\"\u003e\u003ccode\u003e8988c23\u003c/code\u003e\u003c/a\u003e Stabilize macOS Python 3.13 signal shutdown tests (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3084\"\u003e#3084\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/898ddca9254b53c5bf7a6ee509756704caaa949f\"\u003e\u003ccode\u003e898ddca\u003c/code\u003e\u003c/a\u003e Update PyPI publish action to version 1.14.2 (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3083\"\u003e#3083\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/3869f8aac2bdd040fa3fbe564e1dad67e2637641\"\u003e\u003ccode\u003e3869f8a\u003c/code\u003e\u003c/a\u003e Restore Mermaid diagram rendering (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3080\"\u003e#3080\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/64148a9c574e1eb87d3d09b3ce4c256606f8d973\"\u003e\u003ccode\u003e64148a9\u003c/code\u003e\u003c/a\u003e Version 0.52.4 (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3079\"\u003e#3079\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/9e9e5691bd14d5c4cd66d9bd76c7730bc48461a2\"\u003e\u003ccode\u003e9e9e569\u003c/code\u003e\u003c/a\u003e docs: correct release example PR number (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3072\"\u003e#3072\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/b783dacab50b9d6767b0cf65826b2dc3aae21909\"\u003e\u003ccode\u003eb783dac\u003c/code\u003e\u003c/a\u003e Remove duplicate Date header from SansIO WebSocket handshakes (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3078\"\u003e#3078\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/27019b2a4b1fa6d68a289fcf7d738fbdc6ee4e5d\"\u003e\u003ccode\u003e27019b2\u003c/code\u003e\u003c/a\u003e chore(deps): bump the python-packages group across 1 directory with 11 update...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/1b6427311bb84a15addee688f6d41d96e33f8b0a\"\u003e\u003ccode\u003e1b64273\u003c/code\u003e\u003c/a\u003e Fix a typo in index.md (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3006\"\u003e#3006\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/a68da608147c5f79d962352dce11de8f6e32d972\"\u003e\u003ccode\u003ea68da60\u003c/code\u003e\u003c/a\u003e Version 0.52.3 (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3068\"\u003e#3068\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kludex/uvicorn/commit/6e3bb4c5c22531c16d341f2da49f2653307f412f\"\u003e\u003ccode\u003e6e3bb4c\u003c/code\u003e\u003c/a\u003e Use zttp 0.0.24 fast receive path (\u003ca href=\"https://redirect.github.com/Kludex/uvicorn/issues/3067\"\u003e#3067\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/Kludex/uvicorn/compare/0.49.0...0.52.4\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `pydantic` from 2.13.4 to 2.13.5\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pydantic/pydantic/releases\"\u003epydantic's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.13.5 (2026-08-28)\u003c/h2\u003e\n\u003ch3\u003eWhat's Changed\u003c/h3\u003e\n\u003ch4\u003eFixes\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eAllow reuse of validators when plugins are set by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13535\"\u003e#13535\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix missing GC traversal on some \u003ccode\u003epydantic-core\u003c/code\u003e struct fields by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13624\"\u003e#13624\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix missing GC traversal in \u003ccode\u003epydantic-core\u003c/code\u003e for \u003ccode\u003eGeneralFieldsSerializer\u003c/code\u003e by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13629\"\u003e#13629\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eCount validated model fields once in smart unions by \u003ca href=\"https://github.com/tamird\"\u003e\u003ccode\u003e@​tamird\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13731\"\u003e#13731\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pydantic/pydantic/blob/v2.13.5/HISTORY.md\"\u003epydantic's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.13.5 (2026-08-28)\u003c/h2\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/pydantic/pydantic/releases/tag/v2.13.5\"\u003eGitHub release\u003c/a\u003e\u003c/p\u003e\n\u003ch3\u003eWhat's Changed\u003c/h3\u003e\n\u003ch4\u003eFixes\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eAllow reuse of validators when plugins are set by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13535\"\u003e#13535\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix missing GC traversal on some \u003ccode\u003epydantic-core\u003c/code\u003e struct fields by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13624\"\u003e#13624\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix missing GC traversal in \u003ccode\u003epydantic-core\u003c/code\u003e for \u003ccode\u003eGeneralFieldsSerializer\u003c/code\u003e by \u003ca href=\"https://github.com/Viicos\"\u003e\u003ccode\u003e@​Viicos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13629\"\u003e#13629\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eCount validated model fields once in smart unions by \u003ca href=\"https://github.com/tamird\"\u003e\u003ccode\u003e@​tamird\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic/pull/13731\"\u003e#13731\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/001dea020e0809844e5b17666432c9135a976f46\"\u003e\u003ccode\u003e001dea0\u003c/code\u003e\u003c/a\u003e Bump \u003ccode\u003epypa/gh-action-pypi-publish\u003c/code\u003e action to v1.14.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/558379fee957fad25858e33596146c72d5674843\"\u003e\u003ccode\u003e558379f\u003c/code\u003e\u003c/a\u003e Bump twine to v7.0.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/2cfd5d3d2ae721ea882c045f83b7f7a4003aab01\"\u003e\u003ccode\u003e2cfd5d3\u003c/code\u003e\u003c/a\u003e Do not check for docs build\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/a735bee5c64e1fe50785c376adaf1275e752b8ac\"\u003e\u003ccode\u003ea735bee\u003c/code\u003e\u003c/a\u003e Fix more Clippy lints\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/7eed4a16b87afaced4d0eafae230453de3410d64\"\u003e\u003ccode\u003e7eed4a1\u003c/code\u003e\u003c/a\u003e Fix Clippy 0.1.95 warnings\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/b353bbb20a4989b4c033e2be2b4a40d36178b16a\"\u003e\u003ccode\u003eb353bbb\u003c/code\u003e\u003c/a\u003e Prepare release v2.13.5\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/63d2cccd6e760da6bbc7fe81a53cb2bde3768f5e\"\u003e\u003ccode\u003e63d2ccc\u003c/code\u003e\u003c/a\u003e Count validated model fields once in smart unions\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/a53ec2ed342fda4e6aa3684399d04ea57be9a6e4\"\u003e\u003ccode\u003ea53ec2e\u003c/code\u003e\u003c/a\u003e Speed up PyPy CI tests\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/d65e0f96e890ca82f4b66a15d5b3bd65af2c661c\"\u003e\u003ccode\u003ed65e0f9\u003c/code\u003e\u003c/a\u003e Workaround circular import error in Mypy\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic/commit/47a6dbf8ad6216211bd0df6ec5c2c6c6ed905b72\"\u003e\u003ccode\u003e47a6dbf\u003c/code\u003e\u003c/a\u003e Fix missing GC traversal in \u003ccode\u003epydantic-core\u003c/code\u003e for \u003ccode\u003eGeneralFieldsSerializer\u003c/code\u003e\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/pydantic/pydantic/compare/v2.13.4...v2.13.5\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `python-dotenv` from 1.2.2 to 1.2.3\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/theskumar/python-dotenv/releases\"\u003epython-dotenv's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev1.2.3\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eStrip a leading UTF-8 BOM from \u003ccode\u003e.env\u003c/code\u003e file contents so the first variable is no longer silently lost when the file is saved with BOM (e.g. by some JetBrains IDEs on Windows) by [\u003ca href=\"https://github.com/h1whelan\"\u003e\u003ccode\u003e@​h1whelan\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/640\"\u003e#640\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eset_key\u003c/code\u003e now escapes backslashes, so values containing them (Windows paths, regular expressions) survive a write/read round-trip. Quoted values ending in an escaped backslash are no longer mis-parsed as an escaped quote, which used to swallow the following lines by [\u003ca href=\"https://github.com/dchaudhari7177\"\u003e\u003ccode\u003e@​dchaudhari7177\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/680\"\u003e#680\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003edotenv run\u003c/code\u003e now prints a friendly error instead of a traceback when no command is given by [\u003ca href=\"https://github.com/bbc2\"\u003e\u003ccode\u003e@​bbc2\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/606\"\u003e#606\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eCache the parsed result for empty \u003ccode\u003e.env\u003c/code\u003e files so repeated \u003ccode\u003edotenv_values\u003c/code\u003e/\u003ccode\u003eload_dotenv\u003c/code\u003e calls no longer re-read the file by [\u003ca href=\"https://github.com/ReinerBRO\"\u003e\u003ccode\u003e@​ReinerBRO\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/638\"\u003e#638\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/theskumar/python-dotenv/blob/main/CHANGELOG.md\"\u003epython-dotenv's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e[1.2.3] - 2026-08-16\u003c/h2\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eStrip a leading UTF-8 BOM from \u003ccode\u003e.env\u003c/code\u003e file contents so the first variable is no longer silently lost when the file is saved with BOM (e.g. by some JetBrains IDEs on Windows) by [\u003ca href=\"https://github.com/h1whelan\"\u003e\u003ccode\u003e@​h1whelan\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/640\"\u003e#640\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eset_key\u003c/code\u003e now escapes backslashes, so values containing them (Windows paths, regular expressions) survive a write/read round-trip. Quoted values ending in an escaped backslash are no longer mis-parsed as an escaped quote, which used to swallow the following lines by [\u003ca href=\"https://github.com/dchaudhari7177\"\u003e\u003ccode\u003e@​dchaudhari7177\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/680\"\u003e#680\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003edotenv run\u003c/code\u003e now prints a friendly error instead of a traceback when no command is given by [\u003ca href=\"https://github.com/bbc2\"\u003e\u003ccode\u003e@​bbc2\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/606\"\u003e#606\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eCache the parsed result for empty \u003ccode\u003e.env\u003c/code\u003e files so repeated \u003ccode\u003edotenv_values\u003c/code\u003e/\u003ccode\u003eload_dotenv\u003c/code\u003e calls no longer re-read the file by [\u003ca href=\"https://github.com/ReinerBRO\"\u003e\u003ccode\u003e@​ReinerBRO\u003c/code\u003e\u003c/a\u003e] in \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/638\"\u003e#638\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/49515afee2d50c33cad9419b3800b3a0dc93fc59\"\u003e\u003ccode\u003e49515af\u003c/code\u003e\u003c/a\u003e Bump version: 1.2.2 → 1.2.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/8ac846ff2760b65470e769d7eed33e540f0934e1\"\u003e\u003ccode\u003e8ac846f\u003c/code\u003e\u003c/a\u003e chore: add release runbook (RELEASING.md) and make release target\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/bb31c944fb4b40e8dea59587f525840c38326166\"\u003e\u003ccode\u003ebb31c94\u003c/code\u003e\u003c/a\u003e docs: add 1.2.3 release notes (\u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/606\"\u003e#606\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/638\"\u003e#638\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/680\"\u003e#680\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/f7b18d9c72d1abcc2ad4023424b84f5bee30d266\"\u003e\u003ccode\u003ef7b18d9\u003c/code\u003e\u003c/a\u003e fix: round-trip backslashes through set_key (\u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/680\"\u003e#680\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/751f8c148222e58aa173c83c4e5e6cfccb2cc124\"\u003e\u003ccode\u003e751f8c1\u003c/code\u003e\u003c/a\u003e ci(deps): bump actions/checkout from 6.0.2 to 6.0.3 in the github-actions gro...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/f1937b68f338d7ebd7754da377ca08b2f0df8dbb\"\u003e\u003ccode\u003ef1937b6\u003c/code\u003e\u003c/a\u003e chore(deps): update mkdocs-include-markdown-plugin requirement from \u0026gt;=6.0.0 t...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/45b93720dd5e9e127d0be3971a04855d34e464d8\"\u003e\u003ccode\u003e45b9372\u003c/code\u003e\u003c/a\u003e chore(deps): update pytest requirement from \u0026gt;=3.9 to \u0026gt;=9.0.3 (\u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/653\"\u003e#653\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/72896e9244d2a1ff8d5e1934d3df8a35c813799a\"\u003e\u003ccode\u003e72896e9\u003c/code\u003e\u003c/a\u003e docs: fix broken mkdocs link in CONTRIBUTING.md (\u003ca href=\"https://redirect.github.com/theskumar/python-dotenv/issues/636\"\u003e#636\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/72754a16a4743e4c92edf87ce59ba0e4ff78758d\"\u003e\u003ccode\u003e72754a1\u003c/code\u003e\u003c/a\u003e ci(deps): bump peaceiris/actions-gh-pages from 4.0.0 to 4.1.0 in the github-a...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/theskumar/python-dotenv/commit/078325e92558330e9addc661b789c7b6123fa73c\"\u003e\u003ccode\u003e078325e\u003c/code\u003e\u003c/a\u003e ci(security): harden CI/CD supply chain with SHA pinning and least-privilege ...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/theskumar/python-dotenv/compare/v1.2.2...v1.2.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `tiktoken` from 0.13.0 to 0.14.0\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/openai/tiktoken/blob/main/CHANGELOG.md\"\u003etiktoken's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e[v0.14.0]\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBuild wheels for Python 3.15\u003c/li\u003e\n\u003cli\u003eSupport looking up more GPT-5 series models\u003c/li\u003e\n\u003cli\u003eUpgrade dependencies\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/openai/tiktoken/commit/4e71bbe0c078468e00fefbf94b39849389f346e5\"\u003e\u003ccode\u003e4e71bbe\u003c/code\u003e\u003c/a\u003e Release 0.14.0 (\u003ca href=\"https://redirect.github.com/openai/tiktoken/issues/597\"\u003e#597\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/openai/tiktoken/commit/212b893ba940cba53476851103d2e5c1d0020c6e\"\u003e\u003ccode\u003e212b893\u003c/code\u003e\u003c/a\u003e Fail open for GPT-5 model tokenisers (\u003ca href=\"https://redirect.github.com/openai/tiktoken/issues/596\"\u003e#596\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/openai/tiktoken/commit/4187ba33e48b7c554de02c17149ff0c5e50ddf38\"\u003e\u003ccode\u003e4187ba3\u003c/code\u003e\u003c/a\u003e Upgrade dependencies (\u003ca href=\"https://redirect.github.com/openai/tiktoken/issues/595\"\u003e#595\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/openai/tiktoken/commit/92a82552fc5d046839f83e3505a6d9b002208ac2\"\u003e\u003ccode\u003e92a8255\u003c/code\u003e\u003c/a\u003e Remove test-skip comment for macOS arm64 (\u003ca href=\"https://redirect.github.com/openai/tiktoken/issues/562\"\u003e#562\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/openai/tiktoken/commit/674f5e65caad92c2b17f944fbdc4256fea32890e\"\u003e\u003ccode\u003e674f5e6\u003c/code\u003e\u003c/a\u003e Build Python 3.15 (\u003ca href=\"https://redirect.github.com/openai/tiktoken/issues/594\"\u003e#594\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/openai/tiktoken/commit/dbea866194b3c7d496a029c8faf9ad238064a992\"\u003e\u003ccode\u003edbea866\u003c/code\u003e\u003c/a\u003e Remove deprecated freethreading build\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/openai/tiktoken/commit/f6782242d03134d18b9a551845fd7d69fd23106e\"\u003e\u003ccode\u003ef678224\u003c/code\u003e\u003c/a\u003e Update cibuildwheel\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/openai/tiktoken/commit/08a5f3b2c987ada4fc5aa1f16c643c203fa8acaa\"\u003e\u003ccode\u003e08a5f3b\u003c/code\u003e\u003c/a\u003e ci: use static artifact name for sdist build job (\u003ca href=\"https://redirect.github.com/openai/tiktoken/issues/535\"\u003e#535\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/openai/tiktoken/compare/0.13.0...0.14.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `pydantic-settings` from 2.14.2 to 2.15.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pydantic/pydantic-settings/releases\"\u003epydantic-settings's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2.15.0\u003c/h2\u003e\n\u003ch2\u003eHighlights\u003c/h2\u003e\n\u003ch3\u003eBehavior changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ccode\u003ecase_sensitive\u003c/code\u003e now applies to init kwargs and config-file sources\u003c/strong\u003e (\u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/900\"\u003e#900\u003c/a\u003e). \u003ccode\u003eInitSettingsSource\u003c/code\u003e and the JSON/TOML/YAML config sources previously ignored \u003ccode\u003ecase_sensitive\u003c/code\u003e. Since it defaults to \u003ccode\u003eFalse\u003c/code\u003e, \u003cstrong\u003ecase-insensitive matching is now the default\u003c/strong\u003e for these sources — e.g. \u003ccode\u003eSettings(TeSt=...)\u003c/code\u003e now populates a \u003ccode\u003etest\u003c/code\u003e field where it previously did not. Nested keys are still matched case-sensitively.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eFields with unresolved forward references now emit a warning\u003c/strong\u003e (\u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/901\"\u003e#901\u003c/a\u003e). Settings sources can silently fail to resolve such fields; they now raise \u003ccode\u003eIncompleteFieldDefinitionWarning\u003c/code\u003e telling you to call \u003ccode\u003emodel_rebuild()\u003c/code\u003e. If you have \u003ccode\u003efilterwarnings = error\u003c/code\u003e configured, this may surface as a new failure.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eNon-JSON env values for strict fields now raise \u003ccode\u003eValidationError\u003c/code\u003e\u003c/strong\u003e (\u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/926\"\u003e#926\u003c/a\u003e) instead of a less specific error.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eNew features\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eShow environment variable names in CLI help\u003c/strong\u003e via \u003ccode\u003ecli_show_env_vars=True\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/860\"\u003e#860\u003c/a\u003e), so generated \u003ccode\u003e--help\u003c/code\u003e output doubles as configuration documentation.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ccode\u003ePYDANTIC_SETTINGS_DEBUG\u003c/code\u003e for debugging settings resolution\u003c/strong\u003e (\u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/906\"\u003e#906\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/913\"\u003e#913\u003c/a\u003e). Set it to a truthy value with \u003ccode\u003eDEBUG\u003c/code\u003e logging enabled to see each source's contribution in priority order, which source won for each value, and which \u003ccode\u003eenv_file\u003c/code\u003e/secret files were probed, loaded, or skipped — the long-standing \u0026quot;why isn't my \u003ccode\u003e.env\u003c/code\u003e being picked up?\u0026quot; question.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ccode\u003etoml_table_header\u003c/code\u003e for regular TOML files\u003c/strong\u003e (\u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/882\"\u003e#882\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/886\"\u003e#886\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/887\"\u003e#887\u003c/a\u003e), letting you root settings at a nested table in any TOML file, not just \u003ccode\u003epyproject.toml\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003e\u003ccode\u003eTraversable\u003c/code\u003e support for JSON/TOML/YAML file sources\u003c/strong\u003e (\u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/902\"\u003e#902\u003c/a\u003e), so you can load config packaged inside a distribution — including files inside a zip or wheel — via \u003ccode\u003eimportlib.resources.files(...)\u003c/code\u003e without casting to \u003ccode\u003ePath\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eGCP: \u003ccode\u003eproject_id\u003c/code\u003e can come from an earlier settings source\u003c/strong\u003e (\u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/878\"\u003e#878\u003c/a\u003e), rather than only from the constructor or \u003ccode\u003eGOOGLE_CLOUD_PROJECT\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBug fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFix env vars not loading on Windows with \u003ccode\u003ecase_sensitive=True\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/894\"\u003e#894\u003c/a\u003e). Windows upper-cases \u003ccode\u003eos.environ\u003c/code\u003e keys, so fields raised \u003ccode\u003eField required\u003c/code\u003e instead of picking up their values.\u003c/li\u003e\n\u003cli\u003eRead secret files as UTF-8 instead of the platform locale encoding (\u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/917\"\u003e#917\u003c/a\u003e). On Windows code pages such as cp1252 this silently corrupted non-ASCII secrets.\u003c/li\u003e\n\u003cli\u003eFix \u003ccode\u003eAliasPath\u003c/code\u003e on nested model fields not JSON-decoding env values (\u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/898\"\u003e#898\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFix case-insensitive matching for \u003cstrong\u003eoptional\u003c/strong\u003e nested models (\u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/905\"\u003e#905\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFix dotenv extras being wrongly claimed by a complex field sharing a name prefix (\u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/912\"\u003e#912\u003c/a\u003e) — e.g. \u003ccode\u003edbx_token\u003c/code\u003e being swallowed by a \u003ccode\u003edb: dict\u003c/code\u003e field.\u003c/li\u003e\n\u003cli\u003eFix \u003ccode\u003enested_model_default_partial_update=True\u003c/code\u003e corrupting discriminated unions (\u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/876\"\u003e#876\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFix \u003ccode\u003eSecret\u003c/code\u003e subclasses crashing when loaded from the environment (\u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/920\"\u003e#920\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFix enum names not parsing through nested annotations such as \u003ccode\u003eOptional[Annotated[MyEnum, ...]]\u003c/code\u003e with \u003ccode\u003eenv_parse_enums=True\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/910\"\u003e#910\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eAn empty \u003ccode\u003eyaml_config_section\u003c/code\u003e now falls back to defaults instead of raising \u003ccode\u003eAttributeError: 'NoneType' object has no attribute 'keys'\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/914\"\u003e#914\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eNestedSecretsSettingsSource\u003c/code\u003e no longer follows symlinks pointing outside \u003ccode\u003esecrets_dir\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/889\"\u003e#889\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eGCP: skip the \u003ccode\u003elist_secrets\u003c/code\u003e call when \u003ccode\u003ecase_sensitive=True\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/862\"\u003e#862\u003c/a\u003e), lowering the required IAM permissions to just \u003ccode\u003eroles/secretmanager.secretAccessor\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eAWS: \u003ccode\u003etypes-boto3[secretsmanager]\u003c/code\u003e is no longer required at runtime (\u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/880\"\u003e#880\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDocumentation\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eDocument JSON parsing of complex env values, plus a comma-separated-values recipe (\u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/919\"\u003e#919\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eRecommend an async settings loading pattern (\u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/908\"\u003e#908\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eClarify behavior when an unprefixed value is present in a dotenv file (\u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/895\"\u003e#895\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eClarify environment variable helper descriptions (\u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/867\"\u003e#867\u003c/a\u003e) and fix assorted typos (\u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/904\"\u003e#904\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate documentation link for Pydantic settings by \u003ca href=\"https://github.com/hramezani\"\u003e\u003ccode\u003e@​hramezani\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/863\"\u003epydantic/pydantic-settings#863\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump the python-packages group with 4 updates by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/865\"\u003epydantic/pydantic-settings#865\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003edocs: clarify environment variable helper descriptions by \u003ca href=\"https://github.com/vip892766gma\"\u003e\u003ccode\u003e@​vip892766gma\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/867\"\u003epydantic/pydantic-settings#867\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump the python-packages group with 4 updates by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/870\"\u003epydantic/pydantic-settings#870\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump the python-packages group with 4 updates by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/875\"\u003epydantic/pydantic-settings#875\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSkip list_secrets call when case_sensitive=True by \u003ca href=\"https://github.com/ecerulm\"\u003e\u003ccode\u003e@​ecerulm\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/862\"\u003epydantic/pydantic-settings#862\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eGoogleSecretManagerSettingsSource: read project_id from previous sources by \u003ca href=\"https://github.com/ecerulm\"\u003e\u003ccode\u003e@​ecerulm\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/pull/878\"\u003epydantic/pydantic-settings#878\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic-settings/commit/f725ca187bee4212e9ef799eefa3cb25be788462\"\u003e\u003ccode\u003ef725ca1\u003c/code\u003e\u003c/a\u003e Prepare release 2.15.0 (\u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/issues/930\"\u003e#930\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic-settings/commit/28f35c25fac5d61210d532c31a300d49c0b684a4\"\u003e\u003ccode\u003e28f35c2\u003c/code\u003e\u003c/a\u003e Bump the python-packages group with 4 updates (\u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/issues/929\"\u003e#929\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic-settings/commit/9056db049560897229f2603493753bae27b6479f\"\u003e\u003ccode\u003e9056db0\u003c/code\u003e\u003c/a\u003e test: move function-local imports to the top of test modules (\u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/issues/927\"\u003e#927\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic-settings/commit/f077e3ab3d9492838c7ef9275a88c95134688095\"\u003e\u003ccode\u003ef077e3a\u003c/code\u003e\u003c/a\u003e fix: raise ValidationError for non-JSON env values on strict fields (\u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/issues/926\"\u003e#926\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic-settings/commit/ae25d703c458b57f5a9a425f6ec9a28ad868f980\"\u003e\u003ccode\u003eae25d70\u003c/code\u003e\u003c/a\u003e fix: treat Secret subclasses as non-complex fields (\u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/issues/716\"\u003e#716\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/issues/920\"\u003e#920\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic-settings/commit/798dcea2a23b08a3e9b37994014e036224f6dd18\"\u003e\u003ccode\u003e798dcea\u003c/code\u003e\u003c/a\u003e Bump the python-packages group with 4 updates (\u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/issues/924\"\u003e#924\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic-settings/commit/a190041d353bda2d432ea1908de4c499ae89ee0a\"\u003e\u003ccode\u003ea190041\u003c/code\u003e\u003c/a\u003e Bump the github-actions group with 4 updates (\u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/issues/925\"\u003e#925\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic-settings/commit/5d9333282b5c85d65a457c45e4476369b9949726\"\u003e\u003ccode\u003e5d93332\u003c/code\u003e\u003c/a\u003e Bump the python-packages group with 4 updates (\u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/issues/921\"\u003e#921\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic-settings/commit/d2fdeda91157140d2ff0c05404f32a9b1218115a\"\u003e\u003ccode\u003ed2fdeda\u003c/code\u003e\u003c/a\u003e fix: read secret files as UTF-8 instead of the locale encoding (\u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/issues/917\"\u003e#917\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pydantic/pydantic-settings/commit/2256a4e60f83f2da81e7654252562fc4841aa5d4\"\u003e\u003ccode\u003e2256a4e\u003c/code\u003e\u003c/a\u003e Bump the python-packages group with 3 updates (\u003ca href=\"https://redirect.github.com/pydantic/pydantic-settings/issues/915\"\u003e#915\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/pydantic/pydantic-settings/compare/v2.14.2...v2.15.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `aiohttp` from 3.14.1 to 3.14.3\nUpdates `reportlab` from 5.0.0 to 5.0.1\n\nUpdates `grpcio` from 1.81.1 to 1.83.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/grpc/grpc/releases\"\u003egrpcio's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eRelease v1.83.1\u003c/h2\u003e\n\u003cp\u003eThis is release gRPC Core 1.83.1 (garden).\u003c/p\u003e\n\u003cp\u003eFor gRPC documentation, see \u003ca href=\"https://grpc.io/\"\u003egrpc.io\u003c/a\u003e. For previous releases, see \u003ca href=\"https://github.com/grpc/grpc/releases\"\u003eReleases\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003eThis release contains refinements, improvements, and bug fixes.\u003c/p\u003e\n\u003ch2\u003eRelease v1.83.0\u003c/h2\u003e\n\u003cp\u003eThis is release 1.83.0 (\u003ca href=\"https://github.com/grpc/grpc/blob/master/doc/g_stands_for.md\"\u003egarden\u003c/a\u003e) of gRPC Core.\u003c/p\u003e\n\u003cp\u003eFor gRPC documentation, see \u003ca href=\"https://grpc.io/\"\u003egrpc.io\u003c/a\u003e. For previous releases, see \u003ca href=\"https://github.com/grpc/grpc/releases\"\u003eReleases\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003eThis release contains refinements, improvements, and bug fixes, with highlights listed below.\u003c/p\u003e\n\u003ch2\u003eCore\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e[Security] Default to Post-Quantum Cryptography in TLS key exchange. (\u003ca href=\"https://redirect.github.com/grpc/grpc/pull/42560\"\u003e#42560\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[authz] don't pass RBAC policy by value when constructing authorization engine. (\u003ca href=\"https://redirect.github.com/grpc/grpc/pull/42636\"\u003e#42636\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eC#\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMigrate CSharp Grpc.Tools to new DotNet Version. (\u003ca href=\"https://redirect.github.com/grpc/grpc/pull/42661\"\u003e#42661\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[C#] Tools - Build: Fix protoc SIGSEGV on ARM64 by aligning max-page-size and migrating to manylinux_2_28. (\u003ca href=\"https://redirect.github.com/grpc/grpc/pull/42590\"\u003e#42590\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ePython\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e[Backport][v1.83.x][Python] grpc-status: Relax protobuf dependency lower bound to allow 6.x. (\u003ca href=\"https://redirect.github.com/grpc/grpc/pull/43001\"\u003e#43001\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[Python] Add abort_with_status to the aio ServicerContext ABC. (\u003ca href=\"https://redirect.github.com/grpc/grpc/pull/42733\"\u003e#42733\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[Python] Update lower bound for protobuf from 6.33.5 to 7.35.1. (\u003ca href=\"https://redirect.github.com/grpc/grpc/pull/42914\"\u003e#42914\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[Python] Pyright typeCheckingMode - standard. (\u003ca href=\"https://redirect.github.com/grpc/grpc/pull/42739\"\u003e#42739\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[Python] Support Python 3.15 - Upgrade bazel dep rules_python to 2.0.2. (\u003ca href=\"https://redirect.github.com/grpc/grpc/pull/42637\"\u003e#42637\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[Python] Hide internal symbols from Python's \u003ccode\u003ecygrpc\u003c/code\u003e shared object. (\u003ca href=\"https://redirect.github.com/grpc/grpc/pull/42325\"\u003e#42325\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[Python] Handle custom Interceptor exceptions in InterceptedCall APIs . (\u003ca href=\"https://redirect.github.com/grpc/grpc/pull/42593\"\u003e#42593\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eRelease v1.83.0-pre1\u003c/h2\u003e\n\u003cp\u003eThis is a prerelease of gRPC Core 1.83.0 (garden).\u003c/p\u003e\n\u003cp\u003eFor gRPC documentation, see \u003ca href=\"https://grpc.io/\"\u003egrpc.io\u003c/a\u003e. For previous releases, see \u003ca href=\"https://github.com/grpc/grpc/releases\"\u003eReleases\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003eThis prerelease contains refinements, improvements, and bug fixes.\u003c/p\u003e\n\u003ch2\u003eRelease v1.82.2\u003c/h2\u003e\n\u003cp\u003eThis is release gRPC Core 1.82.2 (glacier).\u003c/p\u003e\n\u003cp\u003eFor gRPC documentation, see \u003ca href=\"https://grpc.io/\"\u003egrpc.io\u003c/a\u003e. For previous releases, see \u003ca href=\"https://github.com/grpc/grpc/releases\"\u003eReleases\u003c/a\u003e.\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/grpc/grpc/commit/aae267021b1ac256f8b9038d0ef528c3798cc137\"\u003e\u003ccode\u003eaae2670\u003c/code\u003e\u003c/a\u003e [Backport][v1.83.x] Fix legacy_channel.cc compile error with `std::optional\u0026lt;a...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/grpc/grpc/commit/b77ea3602cccdc92071942d6d9731d99dff3d8d4\"\u003e\u003ccode\u003eb77ea36\u003c/code\u003e\u003c/a\u003e [Backport][v1.83.x] Memory optimization (\u003ca href=\"https://redirect.github.com/grpc/grpc/issues/43297\"\u003e#43297\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/grpc/grpc/commit/9dcd5aaed80912634d360915480198c3a9305942\"\u003e\u003ccode\u003e9dcd5aa\u003c/code\u003e\u003c/a\u003e [CI] Fix Python 3.15 Sanity (\u003ca href=\"https://redirect.github.com/grpc/grpc/issues/43299\"\u003e#43299\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/grpc/grpc/commit/ed8899e28f7e00214988b2dbe283dfc9b6a0b6a8\"\u003e\u003ccode\u003eed8899e\u003c/code\u003e\u003c/a\u003e [Backport][v1.83.x]  Fixing bug in GoAway and gRPC Message Compression (\u003ca href=\"https://redirect.github.com/grpc/grpc/issues/43270\"\u003e#43270\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/grpc/grpc/commit/5f8d6dff1b8c99de5ebc5cc36530a78464b20dfa\"\u003e\u003ccode\u003e5f8d6df\u003c/code\u003e\u003c/a\u003e [Release] Bump version to 1.83.1 (on v1.83.x branch) (\u003ca href=\"https://redirect.github.com/grpc/grpc/issues/43274\"\u003e#43274\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/grpc/grpc/commit/291e0be51f7a637da0d107f4f56ccfcf8ed0c37d\"\u003e\u003ccode\u003e291e0be\u003c/code\u003e\u003c/a\u003e [Backport][v1.83.x][Python] Fix the StatusCode Enums to be int (\u003ca href=\"https://redirect.github.com/grpc/grpc/issues/43252\"\u003e#43252\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/grpc/grpc/commit/05ceb5d3595e6d907ef713658ae050504d5e8965\"\u003e\u003ccode\u003e05ceb5d\u003c/code\u003e\u003c/a\u003e [CI][Backport][v1.83.x][Python] Fix PSM Interop xds-v3 Python continuous fail...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/grpc/grpc/commit/dbc73b8a0d7db0df335067b2892a16b09f0da3fa\"\u003e\u003ccode\u003edbc73b8\u003c/code\u003e\u003c/a\u003e [Backport][v1.83.x][PHP]updated workflow to preserve github folder (\u003ca href=\"https://redirect.github.com/grpc/grpc/issues/43243\"\u003e#43243\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/grpc/grpc/commit/c876f4da50f7da2f331888b88b2a7243514139fe\"\u003e\u003ccode\u003ec876f4d\u003c/code\u003e\u003c/a\u003e [Release] Bump version to 1.83.0 (on v1.83.x branch) (\u003ca href=\"https://redirect.github.com/grpc/grpc/issues/43036\"\u003e#43036\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/grpc/grpc/commit/b5c40cd49e0734dbc4078ec3fd8b9d20c2d3c5bc\"\u003e\u003ccode\u003eb5c40cd\u003c/code\u003e\u003c/a\u003e [Backport][v1.83.x][Python] grpc-status: Relax protobuf dependency lower boun...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/grpc/grpc/compare/v1.81.1...v1.83.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `nvidia-riva-client` from 2.26.0 to 2.27.0\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/nvidia-riva/python-clients/commits\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `torch` from 2.12.1+cu130 to 2.14.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/pytorch/pytorch/releases\"\u003etorch's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003ePyTorch 2.14.0 Release Notes\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/blob/HEAD/#highlights\"\u003eHighlights\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/blob/HEAD/#backwards-incompatible-changes\"\u003eBackwards Incompatible Changes\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/blob/HEAD/#deprecations\"\u003eDeprecations\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/blob/HEAD/#new-features\"\u003eNew Features\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/blob/HEAD/#improvements\"\u003eImprovements\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/blob/HEAD/#bug-fixes\"\u003eBug fixes\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/blob/HEAD/#performance\"\u003ePerformance\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/blob/HEAD/#documentation\"\u003eDocumentation\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/blob/HEAD/#security\"\u003eSecurity\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pytorch/pytorch/blob/HEAD/#developers\"\u003eDevelopers\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch1\u003eHighlights\u003c/h1\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cp\u003eFor more details about these highlighted features, you can look at the release blogpost. Below are the full release notes for this release.\u003c/p\u003e\n\u003ch1\u003eBackwards Incompatible Changes\u003c/h1\u003e\n\u003ch2\u003etorch.nn\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003e\u003ccode\u003etorch.nn.LinearCrossEntropyOptions\u003c/code\u003e no longer accepts \u003ccode\u003eacc_policy=\u0026quot;balanced\u0026quot;\u003c/code\u003e; use \u003ccode\u003e\u0026quot;compact\u0026quot;\u003c/code\u003e instead (\u003ca href=\"https://redirect.github.com/pytorch/pytorch/issues/188283\"\u003e#188283\u003c/a\u003e)\u003c/p\u003e\n\u003cp\u003eThe \u003ccode\u003e\u0026quot;balanced\u0026quot;\u003c/code\u003e policy was removed because \u003ccode\u003e\u0026quot;compact\u0026quot;\u003c/code\u003e provides the same weight-gradient accumulation precision with lower memory use on CUDA, already uses the equivalent scratch layout for mixed-precision inputs on other devices, and was never selected by \u003ccode\u003e\u0026quot;auto\u0026quot;\u003c/code\u003e. Constructing the options with \u003ccode\u003eacc_policy=\u0026quot;balanced\u0026quot;\u003c/code\u003e now raises \u003ccode\u003eValueError: invalid acc_policy: 'balanced'; expected one of 'auto', 'accurate', 'compact'\u003c/code\u003e.\u003c/p\u003e\n\u003cp\u003eBefore:\u003c/p\u003e\n\u003cpre lang=\"python\"\u003e\u003ccode\u003eoptions = torch.nn.LinearCrossEntropyOptions(acc_policy=\u0026quot;balanced\u0026quot;)\r\nloss = torch.nn.functional.linear_cross_entropy(\r\n    input, linear_weight, target, options=options\r\n)\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eAfter:\u003c/p\u003e\n\u003cpre lang=\"python\"\u003e\u003ccode\u003eoptions = torch.nn.LinearCrossEntropyOptions(acc_policy=\u0026quot;compact\u0026quot;)\r\nloss = torch.nn.functional.linear_cross_entropy(\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/pytorch/pytorch/commits/v2.14.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `transformers` from 5.12.1 to 5.17.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/huggingface/transformers/releases\"\u003etransformers's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eRelease 5.17.0\u003c/h2\u003e\n\u003ch1\u003eRelease v5.17.0\u003c/h1\u003e\n\u003ch2\u003eNew Model additions\u003c/h2\u003e\n\u003ch3\u003eHYV4\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cp\u003eHy4-Preview is a 780B-parameter mixture-of-experts language model that activates 49B parameters per\ntoken. Each MoE layer holds 256 routed experts plus one always-active shared expert and routes every\ntoken to 8 of them. The context window is 1M tokens.\u003c/p\u003e\n\u003cp\u003eThe architecture combines four features:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eMulti-head Latent Attention (MLA)\u003c/strong\u003e compresses keys and values into a low-rank latent\n(\u003ccode\u003ekv_lora_rank\u003c/code\u003e) that \u003ccode\u003ekv_b_proj\u003c/code\u003e expands back to one key/value per query head.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eDeepSeek Sparse Attention (DSA)\u003c/strong\u003e selects \u003ccode\u003eindex_topk\u003c/code\u003e keys per query with a lightweight indexer.\nFollowing \u003ca href=\"https://huggingface.co/papers/2603.12201\"\u003eIndexShare\u003c/a\u003e, only the layers marked \u003ccode\u003e\u0026quot;full\u0026quot;\u003c/code\u003e\nin \u003ccode\u003eindexer_types\u003c/code\u003e run an indexer; \u003ccode\u003e\u0026quot;shared\u0026quot;\u003c/code\u003e layers reuse the previous full layer's selection.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eGated MLA with learnable attention sinks\u003c/strong\u003e, where each head owns a sink logit that participates\nin the softmax and contributes no value, as in \u003ca href=\"https://github.com/huggingface/transformers/blob/HEAD/gpt_oss\"\u003eGPT-OSS\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eIndependent Hyper-Connections (iHC)\u003c/strong\u003e replace the plain residual path with \u003ccode\u003ehc_mult\u003c/code\u003e parallel\nresidual streams that are collapsed before, and redistributed after, every sublayer.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eThe implementation does not execute the multi-token prediction (MTP) layers. Released checkpoints\nkeep those weights so that other runtimes can use them for speculative decoding; they are ignored\nat load time.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/hy_v4\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAdd h4 (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48473\"\u003e#48473\u003c/a\u003e) by \u003ca href=\"https://github.com/ArthurZucker\"\u003e\u003ccode\u003e@​ArthurZucker\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/transformers/pull/48473\"\u003e#48473\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eVibeVoice\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cp\u003e\u003ca href=\"https://huggingface.co/papers/2508.19205\"\u003eVibeVoice\u003c/a\u003e is a novel framework for synthesizing high-fidelity, long-form speech with multiple speakers by employing a next-token diffusion approach within a Large Language Model (LLM) structure. It's designed to capture the authentic conversational \u0026quot;vibe\u0026quot; and is particularly suited for generating audio content like podcasts and multi-participant audiobooks.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/vibevoice\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eImplement VibeVoice  (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/40546\"\u003e#40546\u003c/a\u003e) by \u003ca href=\"https://github.com/pengzhiliang\"\u003e\u003ccode\u003e@​pengzhiliang\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/transformers/pull/40546\"\u003e#40546\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eNeoMME\u003c/h3\u003e\n\u003cp\u003eNeoMME is a family of efficient 260M and 800M parameter multimodal-native multilingual foundation encoders from H Company. It processes multilingual text tokens and raw image patches in a single bidirectional Transformer encoder, without a separately pretrained vision tower or causal language model.\u003c/p\u003e\n\u003cp\u003eNeoMME-Retriever is a model fine-tuned from the NeoMME backbone for visual document retrieval with joint late-interaction and dense objectives. It takes text queries and documents (text or page screenshots) and produces multi-vector embeddings for MeanMaxSim scoring (late-interaction) and mean-pooled embeddings for cosine similarity (dense).\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLinks:\u003c/strong\u003e \u003ca href=\"https://huggingface.co/docs/transformers/main/en/model_doc/neomme\"\u003eDocumentation\u003c/a\u003e\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/856157a2f3e9594954310df18fdccc31ffddebe9\"\u003e\u003ccode\u003e856157a\u003c/code\u003e\u003c/a\u003e v5.17.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/5b7dcb0d36c242d8d85920a81c564ef3a86ca6dd\"\u003e\u003ccode\u003e5b7dcb0\u003c/code\u003e\u003c/a\u003e MRoPE continued (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48594\"\u003e#48594\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/50bbcc630ed1675d15d2def3877c88d6c2630415\"\u003e\u003ccode\u003e50bbcc6\u003c/code\u003e\u003c/a\u003e [fix] Update stale expected strings in HunYuanVL integration tests (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48646\"\u003e#48646\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/e8bcd79c4c77a529bc34d6e19f7d718164b7fa6a\"\u003e\u003ccode\u003ee8bcd79\u003c/code\u003e\u003c/a\u003e [Quantizaiton]support 5/6/7 bits in AutoRound (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48481\"\u003e#48481\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/3283d5f78ed6836d39430c8190a6e0500be78698\"\u003e\u003ccode\u003e3283d5f\u003c/code\u003e\u003c/a\u003e [fix] Update stale golden values and fix expected_logits shape in FlavaForPre...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/5f47b5aad791b69dff597b903614fb2bef8b88a1\"\u003e\u003ccode\u003e5f47b5a\u003c/code\u003e\u003c/a\u003e [tests] Fix integration test golden values broken by fast image processor def...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/fc501343edfccdc840eb8594a6cafa8185c2de53\"\u003e\u003ccode\u003efc50134\u003c/code\u003e\u003c/a\u003e Add Fun-ASR-Nano model (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46180\"\u003e#46180\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/d9fe823d1cedbba33dd0aeef08f773abe971688e\"\u003e\u003ccode\u003ed9fe823\u003c/code\u003e\u003c/a\u003e Fix YOLOS device mismatch with device_map=\u0026quot;auto\u0026quot; (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/46886\"\u003e#46886\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/cbc1651a032b923da7f4b44b3d0e6f68e6ba6b55\"\u003e\u003ccode\u003ecbc1651\u003c/code\u003e\u003c/a\u003e [\u003ccode\u003eGenerate\u003c/code\u003e] Avoid unconditionally downloading remote hub file (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48620\"\u003e#48620\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/transformers/commit/bd05a4b2baf8b37b8f64c0c2c70d2628583f7c2a\"\u003e\u003ccode\u003ebd05a4b\u003c/code\u003e\u003c/a\u003e Honor \u003ccode\u003eshift_labels\u003c/code\u003e in decoder-only LLM/VLM losses (\u003ca href=\"https://redirect.github.com/huggingface/transformers/issues/48493\"\u003e#48493\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/huggingface/transformers/compare/v5.12.1...v5.17.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `accelerate` from 1.14.0 to 1.15.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/huggingface/accelerate/releases\"\u003eaccelerate's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003ev1.15.0: FSDP2 activation memory, dtensor improvements\u003c/h1\u003e\n\u003ch2\u003eFSDP2\u003c/h2\u003e\n\u003cp\u003eA large batch of FSDP2 work this release: two fixes that cut activation memory at long sequence lengths, tied-embedding support on torch \u0026gt;= 2.13, and a round of checkpointing correctness and scale fixes.\u003c/p\u003e\n\u003cp\u003eActivation checkpointing was wrapping each \u003cem\u003echild\u003c/em\u003e of the matched layer (\u003ccode\u003eself_attn\u003c/code\u003e, \u003ccode\u003emlp\u003c/code\u003e, the norms) instead of the layer itself, so every inter-child activation stayed saved for backward. It now wraps the layer.\u003c/p\u003e\n\u003cp\u003eThere's also a new FSDP2-only \u003ccode\u003eactivation_checkpointing_offload\u003c/code\u003e, which moves the remaining per-layer checkpoint inputs to pinned CPU memory. Gradients are exactly those of plain activation checkpointing:\u003c/p\u003e\n\u003cpre lang=\"yaml\"\u003e\u003ccode\u003e# fsdp2.yaml\r\nfsdp_config:\r\n  fsdp_version: 2\r\n  fsdp_auto_wrap_policy: TRANSFORMER_BASED_WRAP\r\n  fsdp_activation_checkpointing: true\r\n  fsdp_activation_checkpointing_offload: true\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003cpre lang=\"bash\"\u003e\u003ccode\u003eaccelerate launch --config_file fsdp2.yaml train.py\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003cul\u003e\n\u003cli\u003eFSDP2 activation checkpointing: wrap the matched transformer layer itself, not each of its children by \u003ca href=\"https://github.com/qgallouedec\"\u003e\u003ccode\u003e@​qgallouedec\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4172\"\u003e#4172\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd FSDP2 \u003ccode\u003eactivation_checkpointing_offload\u003c/code\u003e: offload checkpointed layer inputs to pinned CPU memory by \u003ca href=\"https://github.com/qgallouedec\"\u003e\u003ccode\u003e@​qgallouedec\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4175\"\u003e#4175\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix FSDP2 tied-embedding models on torch \u0026gt;= 2.13: put the output embedding in the same fully_shard group by \u003ca href=\"https://github.com/qgallouedec\"\u003e\u003ccode\u003e@​qgallouedec\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4171\"\u003e#4171\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix FSDP2/PEFT/\u003ccode\u003eFULL_STATE_DICT\u003c/code\u003e dropping every rank's adapter shard except rank 0 by \u003ca href=\"https://github.com/AmineDiro\"\u003e\u003ccode\u003e@​AmineDiro\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4206\"\u003e#4206\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFSDP2: per-rank torch.save/load for SHARDED_STATE_DICT to fix 2800+ NPU checkpoint timeout by \u003ca href=\"https://github.com/gygdh-001\"\u003e\u003ccode\u003e@​gygdh-001\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4105\"\u003e#4105\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix FSDP sharded checkpoint path resolution by \u003ca href=\"https://github.com/HaomingSong\"\u003e\u003ccode\u003e@​HaomingSong\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4119\"\u003e#4119\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRaise a clear error when FSDP is enabled on a mesh with no shard dimension by \u003ca href=\"https://github.com/qgallouedec\"\u003e\u003ccode\u003e@​qgallouedec\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4180\"\u003e#4180\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eDTensor\u003c/h2\u003e\n\u003cp\u003eTwo fixes for DTensor-sharded models, which you hit with FSDP2, tensor parallelism, or any N-D parallelism setup: gradient clipping no longer fails on the \u003ccode\u003eforeach\u003c/code\u003e op when plain tensors and DTensors are mixed, and \u003ccode\u003eprepare_model\u003c/code\u003e leaves an already-sharded model where it is:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eClip grad norm support for dtensors by \u003ca href=\"https://github.com/michaelbenayoun\"\u003e\u003ccode\u003e@​michaelbenayoun\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4219\"\u003e#4219\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eprepare_model: don't move DTensor-sharded models to the device by \u003ca href=\"https://github.com/qgallouedec\"\u003e\u003ccode\u003e@​qgallouedec\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4181\"\u003e#4181\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eOffloading \u0026amp; Quantization\u003c/h2\u003e\n\u003cp\u003eAn entire model can now be dispatched to disk, including tied weights — useful for tools like \u003ccode\u003ellm-compressor\u003c/code\u003e that compress large models on machines that can't hold them:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e[Offloading] Support full disk offloading by \u003ca href=\"https://github.com/kylesayrs\"\u003e\u003ccode\u003e@​kylesayrs\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4083\"\u003e#4083\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix disk offload crash on FP8 tensors by \u003ca href=\"https://github.com/shoemoney\"\u003e\u003ccode\u003e@​shoemoney\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4151\"\u003e#4151\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eTrackers\u003c/h2\u003e\n\u003cp\u003eCustom trackers can be registered by name and then selected from \u003ccode\u003elog_with=\u003c/code\u003e like any built-in one:\u003c/p\u003e\n\u003cpre lang=\"python\"\u003e\u003ccode\u003efrom accelerate import Accelerator\r\nfrom accelerate.tracking import register_tracker_class\r\n\u0026lt;/tr\u0026gt;\u0026lt;/table\u0026gt; \n\u003c/code\u003e\u003c/pre\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/accelerate/commit/6afc1e5ee217051fde702b23de2813344dc0fd33\"\u003e\u003ccode\u003e6afc1e5\u003c/code\u003e\u003c/a\u003e Release: v1.15.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/accelerate/commit/636a9343b4265db1212b04c778b8910b5cbfa713\"\u003e\u003ccode\u003e636a934\u003c/code\u003e\u003c/a\u003e Fix nightly CI: tensor parallel size detection and DeepSpeed warmup steps (\u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4\"\u003e#4\u003c/a\u003e...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/accelerate/commit/385d9fb40bdb92b0cb34775ad0ef493c171e559f\"\u003e\u003ccode\u003e385d9fb\u003c/code\u003e\u003c/a\u003e docs: fix three dead links left by the docs restructure (\u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4230\"\u003e#4230\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/accelerate/commit/c424d0b82d4ed61672bf30f1a81ce80370fd945a\"\u003e\u003ccode\u003ec424d0b\u003c/code\u003e\u003c/a\u003e docs: fix garbled sentence in CONTRIBUTING.md (\u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4231\"\u003e#4231\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/accelerate/commit/0f7e35fe7902cc6ba8dc01b146d6447900464b88\"\u003e\u003ccode\u003e0f7e35f\u003c/code\u003e\u003c/a\u003e Clip grad norm support for dtensors (\u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4219\"\u003e#4219\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/accelerate/commit/b2ac5095f04585043e21d295afe3aaaacdcc8357\"\u003e\u003ccode\u003eb2ac509\u003c/code\u003e\u003c/a\u003e Fix FSDP2/ PEFT/\u003ccode\u003eFULL_STATE_DICT\u003c/code\u003e dropping every rank's adapter shard except ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/accelerate/commit/33e8bc499254e7f3886db3f8a277d05a4ad2667e\"\u003e\u003ccode\u003e33e8bc4\u003c/code\u003e\u003c/a\u003e Fix load_accelerator_state only restoring one RNG backend (\u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4217\"\u003e#4217\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/accelerate/commit/50de3ad45f4da279819529e443ba746eb5b3b187\"\u003e\u003ccode\u003e50de3ad\u003c/code\u003e\u003c/a\u003e Treat MPS out-of-memory errors as OOM in find_executable_batch_size (\u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4227\"\u003e#4227\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/accelerate/commit/ab5fe8e507366f814fee59138eb96b9879cb05d6\"\u003e\u003ccode\u003eab5fe8e\u003c/code\u003e\u003c/a\u003e feat: add the neuron device branch in state (\u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4218\"\u003e#4218\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/huggingface/accelerate/commit/9baf95be958c3fd8b2449d1463e6a89e14f61e7d\"\u003e\u003ccode\u003e9baf95b\u003c/code\u003e\u003c/a\u003e Fix MLFLOW_NESTED_RUN never being able to turn nesting off (\u003ca href=\"https://redirect.github.com/huggingface/accelerate/issues/4223\"\u003e#4223\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/huggingface/accelerate/compare/v1.14.0...v1.15.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `ty` from 0.0.55 to 0.0.80\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/astral-sh/ty/releases\"\u003ety's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e0.0.80\u003c/h2\u003e\n\u003ch2\u003eRelease Notes\u003c/h2\u003e\n\u003cp\u003eReleased on 2026-09-09.\u003c/p\u003e\n\u003ch3\u003eBug fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFix \u003ccode\u003e--force-exclude\u003c/code\u003e for directories with an excluded ancestor (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28451\"\u003e#28451\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ePreserve metaclass candidates after conflicts (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28461\"\u003e#28461\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eLSP server\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eGive existing autofixes descriptive titles (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28456\"\u003e#28456\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ePrevent LSP hangs during inlay hint bursts (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28390\"\u003e#28390\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDiagnostic improvements\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve redundant-condition diagnostics with unreachable operands (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28374\"\u003e#28374\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eCore type checking\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eCheck captured receivers when calling wrapped classmethods (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28467\"\u003e#28467\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix cached classmethods on generic classes (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28207\"\u003e#28207\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix disjointness of type guards and boolean literals (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28363\"\u003e#28363\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eInfer tuple variance from the full tuple spec (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28446\"\u003e#28446\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eInfer tuple variance more precisely (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28426\"\u003e#28426\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ePreserve callable identity across specialized types (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28409\"\u003e#28409\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ePreserve callback type context through ParamSpec forwarding (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28439\"\u003e#28439\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ePreserve wrapped functions in precise \u003ccode\u003efunctools.partial\u003c/code\u003e relations (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28460\"\u003e#28460\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRespect descriptor protocol for \u003ccode\u003e__set__\u003c/code\u003e itself (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28408\"\u003e#28408\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRespect type-variable bounds in argument context (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28448\"\u003e#28448\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eUnwrap union alternatives in overload implementations (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28468\"\u003e#28468\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003ePerformance\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eDistribute \u003ccode\u003elen\u003c/code\u003e inference over unions (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28470\"\u003e#28470\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFast-path concrete literal intersections (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28348\"\u003e#28348\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eMemory usage improvements\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAvoid excess capacity in multi-binding tables (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28412\"\u003e#28412\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eShare equivalent place tables within a file (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28319\"\u003e#28319\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eShare names in synthesized constructor parameters (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28398\"\u003e#28398\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eContributors\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/sharkdp\"\u003e\u003ccode\u003e@​sharkdp\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/charliermarsh\"\u003e\u003ccode\u003e@​charliermarsh\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ibraheemdev\"\u003e\u003ccode\u003e@​ibraheemdev\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/AlexWaygood\"\u003e\u003ccode\u003e@​AlexWaygood\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/astral-sh/ty/blob/main/CHANGELOG.md\"\u003ety's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e0.0.80\u003c/h2\u003e\n\u003cp\u003eReleased on 2026-09-09.\u003c/p\u003e\n\u003ch3\u003eBug fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFix \u003ccode\u003e--force-exclude\u003c/code\u003e for directories with an excluded ancestor (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28451\"\u003e#28451\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ePreserve metaclass candidates after conflicts (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28461\"\u003e#28461\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eLSP server\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eGive existing autofixes descriptive titles (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28456\"\u003e#28456\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ePrevent LSP hangs during inlay hint bursts (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28390\"\u003e#28390\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDiagnostic improvements\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ePreserve redundant-condition diagnostics with unreachable operands (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28374\"\u003e#28374\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eCore type checking\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eCheck captured receivers when calling wrapped classmethods (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28467\"\u003e#28467\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix cached classmethods on generic classes (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28207\"\u003e#28207\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix disjointness of type guards and boolean literals (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28363\"\u003e#28363\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eInfer tuple variance from the full tuple spec (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28446\"\u003e#28446\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eInfer tuple variance more precisely (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28426\"\u003e#28426\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ePreserve callable identity across specialized types (\u003ca href=\"https://redirect.github.com/astral-sh/ruff/pull/28409\"\u003e#28409\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ePreserve callback type context through ParamSpec forwarding (\u003ca href=\"https...\n\n_Description has been truncated_","html_url":"https://github.com/kalburgimanju/ai-code-master/pull/17","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/kalburgimanju%2Fai-code-master/issues/17","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/17/packages"}}]}