Skip to content

fix(deps): update python-dependencies - #11

Merged
pagefault3228 merged 1 commit into
mainfrom
renovate/python-dependencies
Sep 15, 2026
Merged

pagefault3228 merged 1 commit into
mainfrom
renovate/python-dependencies

Conversation

@renovate

@renovate renovate Bot commented Sep 15, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
SQLAlchemy (changelog) ==2.0.52 → ==2.0.53 age confidence
alembic (changelog) ==1.19.2 → ==1.20.0 age confidence
filelock ==3.32.5 → ==3.32.6 age confidence
ruff (source, changelog) ==0.16.6 → ==0.16.7 age confidence
semgrep (changelog) ==1.176.1 → ==1.177.0 age confidence
uvicorn (changelog) ==0.52.4 → ==0.53.0 age confidence

Release Notes

tox-dev/py-filelock (filelock)

v3.32.6

Compare Source

What's Changed
New Contributors

Full Changelog: tox-dev/filelock@3.32.5...3.32.6

astral-sh/ruff (ruff)

v0.16.7

Compare Source

Released on 2026-09-10.

Preview features
  • [ruff] Add rule for default values on method receivers (RUF077) (#​26700)
  • [ruff] Recognize re.prefixmatch (RUF039, RUF055) (#​28311)
Bug fixes
  • Alternate nested quotes inside format spec interpolations (#​28259)
  • [flake8-implicit-str-concat] Mark fix unsafe when it creates a docstring (ISC003) (#​27981)
  • [flake8-tidy-imports] Skip fixes for multi-member imports (TID254) (#​26584)
  • [pylint] Gate ImportCycleError on Python 3.15 (PLW0133) (#​28310)
Rule changes
  • Correct D211 and D203 rule conflict diagnostic (#​28444)
  • Recognize slice and frozendict generics (#​28477)
  • Stop defining __cached__ for Python 3.15 (#​28476)
  • [pyupgrade] Stop recommending removed typing.no_type_check_decorator (UP035) (#​28475)
Performance
  • Reuse parser name lookups when interning (#​28399)
  • Speed up inherited configuration resolution (#​28299)
Documentation
  • Fix line-length path in --config example (#​28392)
  • Remove the "Who’s Using Ruff?" list (#​28455)
Other changes
  • Embed archive checksums in the shell installer (#​28281)
Contributors
semgrep/semgrep (semgrep)

v1.177.0

1.177.0 - 2026-09-10

### Added
  • Added native Supply Chain support for Bazel workspaces using rules_jvm_external. Semgrep now recognizes a maven_install.json pinned lockfile (versions 0.1.0 and 3, as emitted by rules_jvm_external 3.x through current) paired with a MODULE.bazel (or legacy WORKSPACE / WORKSPACE.bazel) marker as a Maven-ecosystem subproject, and attributes findings to the workspace root rather than the lockfile's directory. Workspace-declared root artifacts are identified via __INPUT_ARTIFACTS_HASH for accurate direct-vs-transitive classification; dependencies are emitted with Unknown transitivity when that field is not available. This is the first milestone of native Bazel coverage; broader ecosystem support (rules_python, rules_go, rules_js) and Bazel-aware reachability attribution follow. (SC-2008)
  • Several performance improvements for regex-only rules where the underlying
    regex are inefficient to run on our default regex engine (currently PCRE2). For
    example, a rule matching FOOBAR(a+)\1 will skip any file that does not
    contain FOOBAR without running the regex. (scrt-979)
### Changed
  • Prefilter conditions now evaluate their cheap string predicates before their
    expensive regex predicates. Since evaluation short-circuits, a file that a
    string check already rules in or out no longer pays for regex predicates
    (which is what a pattern's prefilter falls back to when no literal substring
    can be extracted from it, and which can be slow on files with very long
    lines). (prefilter-rank-conjuncts)
  • Supply Chain scans can report dependencies from their Gradle module build files instead of the root manifest. This behavior is disabled by default during rollout and can be tested with --x-gradle-module-attribution. Enabling it can change finding IDs because finding paths change; the ID calculation is unchanged. (SC-2560)
### Fixed
  • Speed up semgrep ci filtering when a deployment has many triage-ignored findings. (triage-ignored-performance)

  • Semgrep no longer crashes with an OCaml stack trace when a proxy environment
    variable holds an unusable value. HTTP_PROXY, HTTPS_PROXY, or ALL_PROXY
    set to an empty value is now ignored with a warning, and the scan
    proceeds without a proxy. A non-empty value that is not a usable proxy URL
    now exits with an error message, with any credentials in the URL
    redacted, instead of failing inside the HTTP client.

    Semgrep also now adds the missing scheme to a proxy URL supplied
    without one; https for HTTPS_PROXY and http` otherwise. (ENGINE-2208)

  • Supply Chain: lockfileless Gradle scans now report a "Resource Inaccessible"
    resolution error when a repository refuses a request (for example a 401 from a
    private registry), instead of exiting successfully with a silently incomplete
    dependency list. (sc-3358)

### Infra/Release Changes
  • Improves shutdown time during scans with --trace. (otel-shutdown-flush)
Kludex/uvicorn (uvicorn)

v0.53.0: Version 0.53.0

Compare Source

🌐 Opt-in HTTP/2 support

uvicorn 0.53.0 adds experimental HTTP/2 through zttp, alongside a new zuvloop integration and connection-handling improvements.

uv add uvicorn==0.53.0
  • Serve HTTP/1.1 and HTTP/2 with zttp (#​2982, #​3101). Install zttp, then enable HTTP/2 with --http zttp --http2. Uvicorn negotiates HTTP/2 over TLS with ALPN and supports cleartext prior knowledge.
  • HTTP/2 remains experimental. Upgrade-based h2c and WebSockets over HTTP/2 are not supported.

⚙️ More event loop choice

  • Run Uvicorn with zuvloop (#​3104). Install zuvloop separately and select it explicitly with --loop zuvloop on CPython 3.14 or newer.

🛡️ More reliable connections and proxies

  • Honor Connection: close token lists (#​3103). Uvicorn now parses comma-separated tokens case-insensitively across HTTP implementations.
  • Trust IPv6 loopback proxies by default (#​3119). The default FORWARDED_ALLOW_IPS value now includes ::1.
  • Keep upgraded WebSockets alive (#​3107). Uvicorn cancels the HTTP keep-alive timer when the connection becomes a WebSocket.

Full changelog: 0.52.4...0.53.0


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • Between 12:00 AM and 03:59 AM, only on Monday (* 0-3 * * 1)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@pagefault3228
pagefault3228 merged commit 3edb4c7 into main Sep 15, 2026
5 of 6 checks passed
@pagefault3228
pagefault3228 deleted the renovate/python-dependencies branch September 15, 2026 04:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant