Skip to content

build(deps): bump the python-dependencies group with 10 updates #3065

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 1 commit into from
May 9, 2025

Conversation

dependabot[bot]
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github May 8, 2025

Updates the requirements on django, django-db-connection-pool, langchain-openai, langchain-mcp-adapters, langchain-huggingface, langgraph, boto3, tencentcloud-sdk-python, anthropic and pylint to permit the latest version.
Updates django to 5.2.1

Commits
  • bc833e8 [5.2.x] Bumped version for 5.2.1 release.
  • c9731dc [5.2.x] Fixed CVE-2025-32873 -- Mitigated potential DoS in strip_tags().
  • ae6b5df [5.2.x] Simplified artifact building steps in docs/internals/howto-release-dj...
  • 44bda7a [5.2.x] Refs #36052, #32234 -- Fixed inspectdb tests for CompositePrimaryKey ...
  • 3c887e5 [5.2.x] Fixed #17461 -- Doc'd the presumed order of foreign keys on the inter...
  • 57c2451 [5.2.x] Made cosmetic edits and added upcoming security release to release no...
  • 1367a19 [5.2.x] Fixed #36357 -- Skipped unique_together in inspectdb output for compo...
  • ec73fd6 [5.2.x] Fixed #36358 -- Corrected introspection of composite primary keys on ...
  • 5d03c71 [5.2.x] Refs #36052, #32234 -- Removed create_test_table_with_composite_prima...
  • 7f6a5fb [5.2.x] Fixed #36360 -- Fixed QuerySet.update() crash when referring annotati...
  • Additional commits viewable in compare view

Updates django-db-connection-pool to 1.2.6

Release notes

Sourced from django-db-connection-pool's releases.

1.2.6

What's Changed

New Contributors

Full Changelog: altairbow/django-db-connection-pool@1.2.5...1.2.6

Commits

Updates langchain-openai to 0.3.16

Release notes

Sourced from langchain-openai's releases.

langchain-openai==0.3.16

Changes since langchain-openai==0.3.15

openai: release 0.3.16 (#31100) openai[patch]: format system content blocks for Responses API (#31096) core, openai[patch]: prefer provider-assigned IDs when aggregating message chunks (#31080) openai[patch]: propagate service_tier to response metadata (#31089)

Commits

Updates langchain-mcp-adapters to 0.0.10

Updates langchain-huggingface to 0.2.0

Release notes

Sourced from langchain-huggingface's releases.

langchain-huggingface==0.2.0

Changes since langchain-huggingface==0.1.2

huggingface: release 0.2 (#31153) huggingface[patch]: update lockfile (#31152) huggingface: fix embeddings return type (#31072) partners: (langchain-huggingface) Chat Models - Integrate Hugging Face Inference Providers and remove deprecated code (#30733) packaging: remove Python upper bound for langchain and co libs (#31025) ci: temporarily run chroma on 3.12 for CI (#31056) partners: bug fix check_imports.py exit code. (#30897) partners[lint]: run pyupgrade to get code in line with 3.9 standards (#30781) partners: (langchain-huggingface) Embeddings - Integrate Inference Providers and remove deprecated code (#30735) Clean up numpy dependencies and speed up 3.13 CI with numpy>=2.1.0 (#30714) multiple: fix uv path deps (#29790) huggingface: Add ipex support to HuggingFaceEmbeddings (#29386) infra: add UV_FROZEN to makefiles (#29642) infra: migrate to uv (#29566) partners: Fixed the procedure of initializing pad_token_id (#29500) huggingface: Add IPEX models support (#29179) multiple: disable socket for unit tests (#29080) required tool_choice added for ChatHuggingFace (#28851) partners: add 'model' alias for consistency in embedding classes (#28374) huggingface: fix standard test lint (#28714) huggingface: fix tool argument serialization in _convert_TGI_message_to_LC_message (#26075) huggingface[fix]: HuggingFaceEndpointEmbeddings model parameter passing error when async embed (#27953) standard-tests: rename langchain_standard_tests to langchain_tests, release 0.3.2 (#28203) multiple: langchain-standard-tests -> langchain-tests (#28139) standard-tests[patch]: add test for async tool calling (#28133) langchain-huggingface: use separate kwargs for queries and docs (#27857)

Commits
  • d7e016c huggingface: release 0.2 (#31153)
  • 4b11cbe huggingface[patch]: update lockfile (#31152)
  • b5b90b5 anthropic[patch]: be robust to null fields when translating usage metadata (#...
  • f70b263 core: release 0.3.59 (#31150)
  • bb69d4c docs: specify js support for tavily (#31149)
  • 1df3ee9 partners: (langchain-openai) total_tokens should not add 'Nonetype' t… (#31146)
  • 19041dc docs: update langchain-cloudflare repo/path on packages.yaml (#31138)
  • 3cba22d docs: Pinecone Rerank example notebook (#31147)
  • 66d1ed6 fix(core): Permit OpenAI style blocks to be passed into convert_to_openai_mes...
  • a15034d docs: Fixed grammar for chat prompt composition (#31148)
  • Additional commits viewable in compare view

Updates langgraph to 0.4.3

Release notes

Sourced from langgraph's releases.

0.4.3

Changes since 0.4.2

  • release: 0.4.3 (#4592)
  • langgraph: use tuples for streamed message events in RemoteGraph (#4589)
  • Fix remote streaming of subgraphs (#4590)
  • Add a limit to Pregel.draw (#4575)
Commits

Updates boto3 to 1.38.11

Commits
  • 94ec98f Merge branch 'release-1.38.11'
  • d256dfa Bumping version to 1.38.11
  • ccc1ea8 Add changelog entries from botocore
  • eb8a0c6 Merge branch 'release-1.38.10'
  • 0b1da1e Merge branch 'release-1.38.10' into develop
  • 348fbb5 Bumping version to 1.38.10
  • 3042078 Add changelog entries from botocore
  • 87e4ebb Merge branch 'release-1.38.9'
  • 663bcac Merge branch 'release-1.38.9' into develop
  • e9b46c8 Bumping version to 1.38.9
  • Additional commits viewable in compare view

Updates tencentcloud-sdk-python to 3.0.1374

Changelog

Sourced from tencentcloud-sdk-python's changelog.

Release 3.0.1374

云硬盘(cbs) 版本:2017-03-12

第 68 次发布

发布时间:2025-05-08 01:12:47

本次发布包含了以下内容:

改善已有的文档。

修改数据结构:

云托付物理服务器(chc) 版本:2023-04-18

第 5 次发布

发布时间:2025-05-08 01:17:25

本次发布包含了以下内容:

改善已有的文档。

修改接口:

负载均衡(clb) 版本:2018-03-17

第 127 次发布

发布时间:2025-05-08 01:18:42

本次发布包含了以下内容:

改善已有的文档。

... (truncated)

Commits

Updates anthropic to 0.51.0

Release notes

Sourced from anthropic's releases.

v0.51.0

0.51.0 (2025-05-07)

Full Changelog: v0.50.0...v0.51.0

Features

  • api: adds web search capabilities to the Claude API (bec0cf9)

Bug Fixes

  • pydantic v1: more robust ModelField.annotation check (c50f406)
  • sockets: handle non-portable socket flags (#935) (205c8dd)

Chores

  • broadly detect json family of content-type headers (66bbb3a)
  • ci: only use depot for staging repos (c867a11)
  • ci: run on more branches and use depot runners (95f5f17)
  • internal: add back missing custom modifications for Web Search (f43ba69)
  • internal: minor formatting changes (8afef08)
  • use lazy imports for resources (704be81)
Changelog

Sourced from anthropic's changelog.

0.51.0 (2025-05-07)

Full Changelog: v0.50.0...v0.51.0

Features

  • api: adds web search capabilities to the Claude API (bec0cf9)

Bug Fixes

  • pydantic v1: more robust ModelField.annotation check (c50f406)
  • sockets: handle non-portable socket flags (#935) (205c8dd)

Chores

  • broadly detect json family of content-type headers (66bbb3a)
  • ci: only use depot for staging repos (c867a11)
  • ci: run on more branches and use depot runners (95f5f17)
  • internal: add back missing custom modifications for Web Search (f43ba69)
  • internal: minor formatting changes (8afef08)
  • use lazy imports for resources (704be81)

0.50.0 (2025-04-22)

Full Changelog: v0.49.0...v0.50.0

Features

  • api: extract ContentBlockDelta events into their own schemas (#920) (ae773d6)
  • api: manual updates (46ac1f8)
  • api: manual updates (48d9739)
  • api: manual updates (66e8cc3)
  • api: manual updates (a74746e)

Bug Fixes

  • ci: ensure pip is always available (#907) (3632687)
  • ci: remove publishing patch (#908) (cae0323)
  • client: deduplicate stop reason type (#913) (3ab0194)
  • client: send all configured auth headers (#929) (9d2581e)
  • perf: optimize some hot paths (cff76cb)
  • perf: skip traversing types for NotGiven values (dadac7f)
  • project: bump httpx minimum version to 0.25.0 (b554138), closes #902
  • types: handle more discriminated union shapes (#906) (2fc179a)
  • vertex: explicitly include requests extra (2b1221b)

... (truncated)

Commits
  • e42451a release: 0.51.0
  • 4c7f97f chore(internal): add back missing custom modifications for Web Search
  • 2da00f2 feat(api): adds web search capabilities to the Claude API
  • 51fd796 fix(sockets): handle non-portable socket flags (#935)
  • ac6cfee chore: use lazy imports for resources
  • 215f5bb chore: broadly detect json family of content-type headers
  • bcaa8a5 chore(ci): only use depot for staging repos
  • a41e9c3 chore(ci): run on more branches and use depot runners
  • bfebcd9 chore(internal): minor formatting changes
  • e3548ac fix(pydantic v1): more robust ModelField.annotation check
  • See full diff in compare view

Updates pylint to 3.3.7

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Updates the requirements on [django](https://github.com/django/django), [django-db-connection-pool](https://github.com/altairbow/django-db-connection-pool), [langchain-openai](https://github.com/langchain-ai/langchain), langchain-mcp-adapters, [langchain-huggingface](https://github.com/langchain-ai/langchain), [langgraph](https://github.com/langchain-ai/langgraph), [boto3](https://github.com/boto/boto3), [tencentcloud-sdk-python](https://github.com/TencentCloud/tencentcloud-sdk-python), [anthropic](https://github.com/anthropics/anthropic-sdk-python) and [pylint](https://github.com/pylint-dev/pylint) to permit the latest version.

Updates `django` to 5.2.1
- [Commits](django/django@5.2...5.2.1)

Updates `django-db-connection-pool` to 1.2.6
- [Release notes](https://github.com/altairbow/django-db-connection-pool/releases)
- [Commits](altairbow/django-db-connection-pool@1.2.5...1.2.6)

Updates `langchain-openai` to 0.3.16
- [Release notes](https://github.com/langchain-ai/langchain/releases)
- [Commits](langchain-ai/langchain@langchain-openai==0.3.15...langchain-openai==0.3.16)

Updates `langchain-mcp-adapters` to 0.0.10

Updates `langchain-huggingface` to 0.2.0
- [Release notes](https://github.com/langchain-ai/langchain/releases)
- [Commits](langchain-ai/langchain@langchain-huggingface==0.1.2...langchain-huggingface==0.2.0)

Updates `langgraph` to 0.4.3
- [Release notes](https://github.com/langchain-ai/langgraph/releases)
- [Commits](langchain-ai/langgraph@0.4.1...0.4.3)

Updates `boto3` to 1.38.11
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](boto/boto3@1.38.6...1.38.11)

Updates `tencentcloud-sdk-python` to 3.0.1374
- [Changelog](https://github.com/TencentCloud/tencentcloud-sdk-python/blob/master/SERVICE_CHANGELOG.md)
- [Commits](TencentCloud/tencentcloud-sdk-python@3.0.1372...3.0.1374)

Updates `anthropic` to 0.51.0
- [Release notes](https://github.com/anthropics/anthropic-sdk-python/releases)
- [Changelog](https://github.com/anthropics/anthropic-sdk-python/blob/main/CHANGELOG.md)
- [Commits](anthropics/anthropic-sdk-python@v0.50.0...v0.51.0)

Updates `pylint` to 3.3.7
- [Release notes](https://github.com/pylint-dev/pylint/releases)
- [Commits](pylint-dev/pylint@v3.3.6...v3.3.7)

---
updated-dependencies:
- dependency-name: django
  dependency-version: 5.2.1
  dependency-type: direct:production
  dependency-group: python-dependencies
- dependency-name: django-db-connection-pool
  dependency-version: 1.2.6
  dependency-type: direct:production
  dependency-group: python-dependencies
- dependency-name: langchain-openai
  dependency-version: 0.3.16
  dependency-type: direct:production
  dependency-group: python-dependencies
- dependency-name: langchain-mcp-adapters
  dependency-version: 0.0.10
  dependency-type: direct:production
  dependency-group: python-dependencies
- dependency-name: langchain-huggingface
  dependency-version: 0.2.0
  dependency-type: direct:production
  dependency-group: python-dependencies
- dependency-name: langgraph
  dependency-version: 0.4.3
  dependency-type: direct:production
  dependency-group: python-dependencies
- dependency-name: boto3
  dependency-version: 1.38.11
  dependency-type: direct:production
  dependency-group: python-dependencies
- dependency-name: tencentcloud-sdk-python
  dependency-version: 3.0.1374
  dependency-type: direct:production
  dependency-group: python-dependencies
- dependency-name: anthropic
  dependency-version: 0.51.0
  dependency-type: direct:production
  dependency-group: python-dependencies
- dependency-name: pylint
  dependency-version: 3.3.7
  dependency-type: direct:production
  dependency-group: python-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file python Pull requests that update Python code labels May 8, 2025
Copy link

f2c-ci-robot bot commented May 8, 2025

Adding the "do-not-merge/release-note-label-needed" label because no release-note block was detected, please follow our release note process to remove it.

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes/test-infra repository.

Copy link

f2c-ci-robot bot commented May 8, 2025

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by:

The full list of commands accepted by this bot can be found here.

Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@liuruibin liuruibin merged commit 1a34c67 into v2 May 9, 2025
1 of 4 checks passed
@liuruibin liuruibin deleted the dependabot/pip/v2/python-dependencies-5977f6bd51 branch May 9, 2025 02:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file do-not-merge/release-note-label-needed python Pull requests that update Python code
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant