Skip to content

deps(python)(deps): bump the python-minor-patch group across 1 directory with 5 updates - #12

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/pip/python-minor-patch-c94b78a390
Open

dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/pip/python-minor-patch-c94b78a390

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 17, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the python-minor-patch group with 5 updates in the / directory:

Package From To
fastapi 0.136.3 0.141.1
uvicorn 0.48.0 0.52.3
beautifulsoup4 4.14.3 4.15.0
supabase 2.30.1 2.31.0
fpdf2 2.8.7 2.8.8

Updates fastapi from 0.136.3 to 0.141.1

Release notes

Sourced from fastapi's releases.

0.141.1

Fixes

  • 🐛 Fix support for background tasks and headers from dependencies in app.frontend(). PR #16105 by @​tiangolo.

Docs

0.141.0

Features

  • ✨ Add app.frontend(check_dir="auto"), to make local development more convenient with fastapi dev. PR #16102 by @​tiangolo.

0.140.13

Fixes

Docs

0.140.12

Fixes

0.140.11

Fixes

  • 🐛 Fix response_model_* params ignored for non-generator endpoints with Iterable[..] return type. PR #15093 by @​YuriiMotov.

0.140.10

Fixes

Internal

0.140.9

Fixes

  • 🐛 Fix exclude_defaults not propagated to dict keys and values in jsonable_encoder. PR #16043 by @​MBGrao.

... (truncated)

Commits
  • 95f8322 🔖 Release version 0.141.1 (#16106)
  • f137944 📝 Update release notes
  • d623544 🐛 Fix support for background tasks and headers from dependencies in `app.fron...
  • 1d211b9 📝 Update release notes
  • 8a1f876 📝 Document FASTAPI_ENV in FastAPI CLI guide (#16104)
  • c7e7b65 🔖 Release version 0.141.0 (#16103)
  • 6bceb84 📝 Update release notes
  • 5429fed ✨ Add app.frontend(check_dir="auto"), to make local development more conven...
  • 628663f 🔖 Release version 0.140.13 (#16096)
  • 0b54fd0 📝 Update release notes
  • Additional commits viewable in compare view

Updates uvicorn from 0.48.0 to 0.52.3

Release notes

Sourced from uvicorn's releases.

Version 0.52.3

Changed

  • Update zttp to 0.0.24 and use its combined receive path, improving HTTP/1.1 request parsing performance (#3067)

Full Changelog: Kludex/uvicorn@0.52.2...0.52.3

Version 0.52.2

Fixed

  • Update zttp to 0.0.22, fixing bodyless request receives and improving HTTP/1 request parsing performance (#3063)

Full Changelog: Kludex/uvicorn@0.52.1...0.52.2

Version 0.52.1

Fixed

  • Complete the closing handshake on server-initiated WebSocket closes in the websockets-sansio and wsproto implementations, waiting for the client's close reply with a 10 second timeout instead of resetting the connection (#3053)
  • Add missing write flow control to the websockets-sansio implementation, preventing data truncation on server-initiated closes with large in-flight payloads (#3048)
  • Handle connection loss while a WebSocket write is waiting on backpressure (#3050)
  • Remove duplicate Content-Type and Content-Length headers from WebSocket denial responses on the websockets-sansio implementation, and deliver non-UTF-8 denial bodies intact (#3041)

Full Changelog: Kludex/uvicorn@0.52.0...0.52.1

Version 0.52.0

This release adds an experimental HTTP/1.1 implementation backed by zttp, a sans-IO HTTP parser I've been developing on the side: a core written in Zig, with bindings to Python. It has been running under a fuzzer for some weeks now, and has been through multiple rounds of security auditing.

It is still experimental, so don't put it in front of production traffic yet. Try it with --http zttp, and please send any feedback to the issue tracker.

Added

  • Add an experimental zttp HTTP/1.1 implementation, selectable with --http zttp (#2979)

Fixed

  • Keep non-ASCII WebSocket request headers intact with websockets 17.0, which encodes them with ISO-8859-1 (#3036)

Full Changelog: Kludex/uvicorn@0.51.0...0.52.0

Version 0.51.0

What's Changed

Full Changelog: Kludex/uvicorn@0.50.2...0.51.0

Version 0.50.2

What's Changed

... (truncated)

Changelog

Sourced from uvicorn's changelog.

0.52.3 (August 13, 2026)

Changed

  • Update zttp to 0.0.24 and use its combined receive path, improving HTTP/1.1 request parsing performance (#3067)

0.52.2 (August 13, 2026)

Fixed

  • Update zttp to 0.0.22, fixing bodyless request receives and improving HTTP/1 request parsing performance (#3063)

0.52.1 (August 1, 2026)

Fixed

  • Complete the closing handshake on server-initiated WebSocket closes in the websockets-sansio and wsproto implementations, waiting for the client's close reply with a 10 second timeout instead of resetting the connection (#3053)
  • Add missing write flow control to the websockets-sansio implementation, preventing data truncation on server-initiated closes with large in-flight payloads (#3048)
  • Handle connection loss while a WebSocket write is waiting on backpressure (#3050)
  • Remove duplicate Content-Type and Content-Length headers from WebSocket denial responses on the websockets-sansio implementation, and deliver non-UTF-8 denial bodies intact (#3041)

0.52.0 (July 29, 2026)

This release adds an experimental HTTP/1.1 implementation backed by zttp, a sans-IO HTTP parser I've been developing on the side: a core written in Zig, with bindings to Python. It has been running under a fuzzer for some weeks now, and has been through multiple rounds of security auditing.

It is still experimental, so don't put it in front of production traffic yet. Try it with --http zttp, and please send any feedback to the issue tracker.

Added

  • Add an experimental zttp HTTP/1.1 implementation, selectable with --http zttp (#2979)

Fixed

  • Keep non-ASCII WebSocket request headers intact with websockets 17.0, which encodes them with ISO-8859-1 (#3036)

0.51.0 (July 8, 2026)

Added

  • Restart workers one at a time on SIGHUP, bringing each replacement up before retiring the old worker, so reloads no longer drop requests (#3025)

Removed

  • Remove colorama from the standard extra (#3027)

0.50.2 (July 6, 2026)

Fixed

  • Require websockets>=13.0, which the default websockets-sansio implementation needs (#3021)

... (truncated)

Commits

Updates beautifulsoup4 from 4.14.3 to 4.15.0

Updates supabase from 2.30.1 to 2.31.0

Release notes

Sourced from supabase's releases.

v2.31.0

2.31.0 (2026-06-04)

Features

  • update X-Client-Info to use structured semicolon-delimited metadata (#1479) (cb3857c)

Bug Fixes

  • storage: make pyiceberg an optional dependency (#1513) (d16cfc0)
Changelog

Sourced from supabase's changelog.

2.31.0 (2026-06-04)

Features

  • update X-Client-Info to use structured semicolon-delimited metadata (#1479) (cb3857c)

Bug Fixes

  • storage: make pyiceberg an optional dependency (#1513) (d16cfc0)
Commits
  • 6f522d3 chore(main): release 2.31.0 (#1509)
  • d16cfc0 fix(storage): make pyiceberg an optional dependency (#1513)
  • 57efcff chore(deps): bump actions/checkout from 6.0.2 to 6.0.3 (#1512)
  • 033dbfe chore(deps): bump astral-sh/setup-uv from 8.1.0 to 8.2.0 (#1511)
  • cb3857c feat: update X-Client-Info to use structured semicolon-delimited metadata (#1...
  • 1a97dfc chore(auth): add more cloudflare network error codes (#1504)
  • See full diff in compare view

Updates fpdf2 from 2.8.7 to 2.8.8

Release notes

Sourced from fpdf2's releases.

Add resource access controls, SVG complexity limits, Optional Content Groups, and other features and bug fixes

[2.8.8] - 2026-08-09

[!WARNING] Upgrading to fpdf2 2.8.8 is strongly recommended for applications that render user-provided images, SVGs, or HTML content.

Added

Fixed

  • custom height passed to Paragraph.ln() in a text region is now applied to the line it terminates instead of the first line of the following paragraph - cf. [issue #1786](py-pdf/fpdf2#1786) - thanks to @​Sanjays2402
  • the optional numpy import in image_parsing.py no longer crashes on CPUs unsupported by numpy's manylinux wheel baseline; RuntimeError is now treated the same as ImportError, so numpy degrades to unavailable instead of taking down import fpdf - cf. [issue #1908](py-pdf/fpdf2#1908) - thanks to @​stumpylog
  • font state (family, style, size, current font, and the page-level "font is set" flag) no longer leaks back onto the FPDF instance after a text_columns() / text_region() context exits, so a subsequent pdf.cell() / pdf.write() renders at the caller's font instead of the last paragraph's - cf. [issue #1804](py-pdf/fpdf2#1804) - thanks to @​Pawansingh3889
  • text rendering when the first text on a page starts with a fallback glyph - cf. [issue #1772](py-pdf/fpdf2#1772)
  • preserve boundary-neutral formatting during bidirectional text preprocessing - cf. [issue #1779](py-pdf/fpdf2#1779)
  • transform application on user space gradients - cf. [issue #1784](py-pdf/fpdf2#1784)
  • dependency extras for camelot-py and endesive on pyproject.toml - cf. [issue #1792](py-pdf/fpdf2#1792)
  • preserve link annotations during dry-run of FPDF.multi_cell - cf. [issue #1807](py-pdf/fpdf2#1807) - thanks to @​CoLa5
  • preserve two consecutive markdown links (without space inbetween) - cf. [issue #1814](py-pdf/fpdf2#1814) - thanks to @​CoLa5
  • support markdown style around markdown links - cf. [issue #1826](py-pdf/fpdf2#1826) - thanks to @​CoLa5
  • Reset gstate for ToC-rendering - cf. [issue #1837](py-pdf/fpdf2#1837) - thanks to @​CoLa5
  • preserve markdown format in FPDF.multi_cell in dry-run - cf. [issue #1840](py-pdf/fpdf2#1840) - thanks to @​CoLa5
  • fix page order after dry-run of FPDF.multi_cell in ToC - cf. [issue #1836](py-pdf/fpdf2#1836) - thanks to @​CoLa5
  • rendering SVG arcs with very small sweeps that previously rounded to zero - cf. [issue #1831](py-pdf/fpdf2#1831)
  • spurious "Not enough horizontal space to render a single character" error when text without break opportunities is split into many small fragments, e.g. by a fallback font alternating with the main font - cf. [issue #1250](py-pdf/fpdf2#1250) - thanks to @​uttam12331
  • number of surviving escape characters - cf. [issue #1215](py-pdf/fpdf2#1215) - thanks to @​amidou-naba
  • leading spaces on new lines inside <pre> and <pre><code> blocks are no longer dropped - cf. [issue #1063](py-pdf/fpdf2#1063) - thanks to @​eugen-goebel
  • FPDF.set_font() can restore current_font when the selected font state diverged - cf. [PR #1872](py-pdf/fpdf2#1872) - thanks to @​gaoflow
  • embed CID-keyed CFF fonts as raw CFF programs so browser PDF viewers render them correctly - cf. [issue #1874](py-pdf/fpdf2#1874)
  • fixed broken links on documentation not directly leading to the API reference - cf. [issue #1876](py-pdf/fpdf2#1876) - thanks to @​iamfazakb
  • reject SVG <use> cycles and excessive nested expansion to prevent resource exhaustion in FPDF.image()
  • count SVG <switch> elements in SVG complexity limits
  • declare the default base state and display order for Optional Content Groups so PDF viewers can list layers correctly - cf. [issue #1895](py-pdf/fpdf2#1895)

Changed

  • skip byte-for-byte compressed data comparison when zlib-ng is detected, regardless of OS
Changelog

Sourced from fpdf2's changelog.

[2.8.8] - 2026-08-09

Added

Fixed

  • custom height passed to Paragraph.ln() in a text region is now applied to the line it terminates instead of the first line of the following paragraph - cf. [issue #1786](py-pdf/fpdf2#1786) - thanks to @​Sanjays2402
  • the optional numpy import in image_parsing.py no longer crashes on CPUs unsupported by numpy's manylinux wheel baseline; RuntimeError is now treated the same as ImportError, so numpy degrades to unavailable instead of taking down import fpdf - cf. [issue #1908](py-pdf/fpdf2#1908) - thanks to @​stumpylog
  • font state (family, style, size, current font, and the page-level "font is set" flag) no longer leaks back onto the FPDF instance after a text_columns() / text_region() context exits, so a subsequent pdf.cell() / pdf.write() renders at the caller's font instead of the last paragraph's - cf. [issue #1804](py-pdf/fpdf2#1804) - thanks to @​Pawansingh3889
  • text rendering when the first text on a page starts with a fallback glyph - cf. [issue #1772](py-pdf/fpdf2#1772)
  • preserve boundary-neutral formatting during bidirectional text preprocessing - cf. [issue #1779](py-pdf/fpdf2#1779)
  • transform application on user space gradients - cf. [issue #1784](py-pdf/fpdf2#1784)
  • dependency extras for camelot-py and endesive on pyproject.toml - cf. [issue #1792](py-pdf/fpdf2#1792)
  • preserve link annotations during dry-run of FPDF.multi_cell - cf. [issue #1807](py-pdf/fpdf2#1807) - thanks to @​CoLa5
  • preserve two consecutive markdown links (without space inbetween) - cf. [issue #1814](py-pdf/fpdf2#1814) - thanks to @​CoLa5
  • support markdown style around markdown links - cf. [issue #1826](py-pdf/fpdf2#1826) - thanks to @​CoLa5
  • Reset gstate for ToC-rendering - cf. [issue #1837](py-pdf/fpdf2#1837) - thanks to @​CoLa5
  • preserve markdown format in FPDF.multi_cell in dry-run - cf. [issue #1840](py-pdf/fpdf2#1840) - thanks to @​CoLa5
  • fix page order after dry-run of FPDF.multi_cell in ToC - cf. [issue #1836](py-pdf/fpdf2#1836) - thanks to @​CoLa5
  • rendering SVG arcs with very small sweeps that previously rounded to zero - cf. [issue #1831](py-pdf/fpdf2#1831)
  • spurious "Not enough horizontal space to render a single character" error when text without break opportunities is split into many small fragments, e.g. by a fallback font alternating with the main font - cf. [issue #1250](py-pdf/fpdf2#1250) - thanks to @​uttam12331
  • number of surviving escape characters - cf. [issue #1215](py-pdf/fpdf2#1215) - thanks to @​amidou-naba
  • leading spaces on new lines inside <pre> and <pre><code> blocks are no longer dropped - cf. [issue #1063](py-pdf/fpdf2#1063) - thanks to @​eugen-goebel
  • FPDF.set_font() can restore current_font when the selected font state diverged - cf. [PR #1872](py-pdf/fpdf2#1872) - thanks to @​gaoflow
  • embed CID-keyed CFF fonts as raw CFF programs so browser PDF viewers render them correctly - cf. [issue #1874](py-pdf/fpdf2#1874)
  • fixed broken links on documentation not directly leading to the API reference - cf. [issue #1876](py-pdf/fpdf2#1876) - thanks to @​iamfazakb
  • reject SVG <use> cycles and excessive nested expansion to prevent resource exhaustion in FPDF.image()
  • count SVG <switch> elements in SVG complexity limits
  • declare the default base state and display order for Optional Content Groups so PDF viewers can list layers correctly - cf. [issue #1895](py-pdf/fpdf2#1895)

Changed

  • skip byte-for-byte compressed data comparison when zlib-ng is detected, regardless of OS
Commits
  • e1fc653 release v2.8.8 (#1916)
  • 42ec664 add Sanjays2402 as a contributor for code (#1915)
  • af9d7dc fix(text_region): apply Paragraph.ln(h) height to the line it terminates (#1904)
  • 81951f8 add stumpylog as a contributor for bug, and code (#1913)
  • b30c38c Fix: catch RuntimeError alongside ImportError for the optional numpy import (...
  • 63df0d0 Update github/codeql-action action to v4.37.6 (#1910)
  • 11a30e6 Update crate-ci/typos action to v1.49.0 (#1911)
  • f65707b Update step-security/harden-runner action to v2.20.1 (#1912)
  • a7f7c89 Update github/codeql-action action to v4.37.4 (#1907)
  • fe9d8f5 Update pypa/gh-action-pypi-publish action to v1.14.2 (#1906)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

…ory with 5 updates

Bumps the python-minor-patch group with 5 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [fastapi](https://github.com/fastapi/fastapi) | `0.136.3` | `0.141.1` |
| [uvicorn](https://github.com/Kludex/uvicorn) | `0.48.0` | `0.52.3` |
| [beautifulsoup4](https://www.crummy.com/software/BeautifulSoup/bs4/) | `4.14.3` | `4.15.0` |
| [supabase](https://github.com/supabase/supabase-py) | `2.30.1` | `2.31.0` |
| [fpdf2](https://github.com/py-pdf/fpdf2) | `2.8.7` | `2.8.8` |



Updates `fastapi` from 0.136.3 to 0.141.1
- [Release notes](https://github.com/fastapi/fastapi/releases)
- [Commits](fastapi/fastapi@0.136.3...0.141.1)

Updates `uvicorn` from 0.48.0 to 0.52.3
- [Release notes](https://github.com/Kludex/uvicorn/releases)
- [Changelog](https://github.com/Kludex/uvicorn/blob/main/docs/release-notes.md)
- [Commits](Kludex/uvicorn@0.48.0...0.52.3)

Updates `beautifulsoup4` from 4.14.3 to 4.15.0

Updates `supabase` from 2.30.1 to 2.31.0
- [Release notes](https://github.com/supabase/supabase-py/releases)
- [Changelog](https://github.com/supabase/supabase-py/blob/main/CHANGELOG.md)
- [Commits](supabase/supabase-py@v2.30.1...v2.31.0)

Updates `fpdf2` from 2.8.7 to 2.8.8
- [Release notes](https://github.com/py-pdf/fpdf2/releases)
- [Changelog](https://github.com/py-pdf/fpdf2/blob/master/CHANGELOG.md)
- [Commits](py-pdf/fpdf2@2.8.7...2.8.8)

---
updated-dependencies:
- dependency-name: fastapi
  dependency-version: 0.141.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-minor-patch
- dependency-name: uvicorn
  dependency-version: 0.52.3
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-minor-patch
- dependency-name: beautifulsoup4
  dependency-version: 4.15.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-minor-patch
- dependency-name: supabase
  dependency-version: 2.31.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-minor-patch
- dependency-name: fpdf2
  dependency-version: 2.8.8
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python-minor-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Aug 17, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: dependencies, python. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants