Skip to content

Bump the python group across 1 directory with 17 updates - #21

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/uv/python-7099256002
Open

dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/uv/python-7099256002

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 4, 2026

Copy link
Copy Markdown
Contributor

Bumps the python group with 17 updates in the / directory:

Package From To
werkzeug 3.1.8 3.1.9
click 8.4.2 8.5.0
flask-security-too 5.7.1 5.9.1
flask-caching 2.4.1 2.5.1
sqlalchemy 2.0.51 2.1.1
psycopg2-binary 2.9.12 2.9.13
cryptography 50.0.0 50.0.2
webauthn 3.0.0 3.0.1
python-dotenv 1.2.2 1.2.4
pytz 2026.2 2026.4
orjson 3.11.9 3.12.0
gunicorn 26.0.0 26.2.0
stripe 15.3.0 16.0.0
chargebee 3.25.0 3.29.0
redis 8.0.1 8.1.0
ruff 0.15.21 0.16.10
pre-commit 4.6.0 4.6.2

Updates werkzeug from 3.1.8 to 3.1.9

Release notes

Sourced from werkzeug's releases.

3.1.9

This is the Werkzeug 3.1.9 security fix release, which fixes security issues and bugs but does not otherwise change behavior and should not result in breaking changes compared to the latest feature release.

PyPI: https://pypi.org/project/Werkzeug/3.1.9/ Changes: https://werkzeug.palletsprojects.com/page/changes/#version-3-1-9 Milestone: https://github.com/pallets/werkzeug/milestone/46?closed=1

  • safe_join on Windows does not allow special devices names with empty ADS markers on NTFS. GHSA-g6x2-hccm-hh4m
  • ProfilerMiddleware uses profiling.tracing on Python 3.15. #3207
  • uri_to_iri and iri_to_uri preserve empty username, password, and port 0. #3189
  • Improve performance of parse_options_header. #3231
  • Improve performance of parse_etags. #3231
  • Improve performance of parse_cookie. #3231
  • get_host also checks that the port is in the valid range. #3236
  • The int URL converter returns a 404 instead of 500 error when the value is longer than sys.get_int_max_str_digits(). #3237
  • Improve debugger PIN generation from cgroup data inside Podman. #3245
  • Authorization parsing basic auth disallows non-base64 characters. #3248
  • application/x-www-form-urlencoded form data is no longer limited to max_form_memory_size, only max_content_length. #3251
  • LimitedStream.readinto does not resize the buffer when it reads less than the remaining size. #3253
  • Rules with 10 or more converters in a single part assign matched values correctly. #3254
  • The invalid Range suffix length -0 is no longer accepted. #3255
Changelog

Sourced from werkzeug's changelog.

Version 3.1.9

Released 2026-09-27

  • safe_join on Windows does not allow special devices names with empty ADS markers on NTFS. :ghsa:g6x2-hccm-hh4m
  • ProfilerMiddleware uses profiling.tracing on Python 3.15. :issue:3207
  • uri_to_iri and iri_to_uri preserve empty username, password, and port 0. :issue:3189
  • Improve performance of parse_options_header. :pr:3231
  • Improve performance of parse_etags. :pr:3231
  • Improve performance of parse_cookie. :pr:3231
  • get_host also checks that the port is in the valid range. :pr:3236
  • The int URL converter returns a 404 instead of 500 error when the value is longer than sys.get_int_max_str_digits(). :issue:3237
  • Improve debugger PIN generation from cgroup data inside Podman. :issue:3245
  • Authorization parsing basic auth disallows non-base64 characters. :pr:3248
  • application/x-www-form-urlencoded form data is no longer limited to max_form_memory_size, only max_content_length. :pr:3251
  • LimitedStream.readinto does not resize the buffer when it reads less than the remaining size. :pr:3253
  • Rules with 10 or more converters in a single part assign matched values correctly. :pr:3254
  • The invalid Range suffix length -0 is no longer accepted. :pr:3255
Commits

Updates click from 8.4.2 to 8.5.0

Release notes

Sourced from click's releases.

8.5.0

This is the Click 8.5.0 feature release. A feature release may include new features, remove previously deprecated code, add new deprecation, or introduce potentially breaking changes.

We encourage everyone to upgrade. You can read more about our Version Support Policy on our website.

PyPI: https://pypi.org/project/click/8.5.0/ Changes: https://click.palletsprojects.com/page/changes/#version-8-5-0 Milestone https://github.com/pallets/click/milestone/33

  • Add built-in shell completion support for PowerShell (Windows PowerShell 5.1+ and pwsh 7+) alongside the existing bash, zsh, and fish completers. Use _FOO_BAR_COMPLETE=powershell_source foo-bar to generate the completion script. #2672 #3637
  • Supported versions of Windows enable ANSI terminal styles by default. Colorama is no longer a dependency and is not used. #2986 #3505
  • {class}Argument accepts a help parameter, and help output includes a Positional arguments section when argument help is available. #2983 #3473
  • confirm() and prompt() strip ANSI color and style codes from the prompt when the output stream does not support them, matching echo(). This stripping was lost in 8.4.0 when #2969 began writing the prompt with input() directly. #3572 #3653
  • {class}Path with allow_dash=True no longer triggers a BytesWarning, an error under python -bb, when checking a value against the - convention. #2877 #3642
  • Add {func}custom_version_option, a --version option whose output is produced by a callback, covering cases {func}version_option intentionally does not. The feature set of {func}version_option is now frozen; see [discussion #3527](`@version_option` future direction pallets/click#3527). #3581
  • style() and secho() no longer silently drop the 256-color index 0 (black) passed as fg or bg, and now validate color arguments. Invalid colors raise a ValueError instead of a TypeError. #3677
  • The automatic help option stores its value under the reserved name _click_default_help instead of help, so a parameter named help no longer breaks parsing. The new name is visible in {meth}Command.to_info_dict output. Parameters that overwrite each other's value trigger a warning: an argument sharing its name with another parameter, or any parameter claiming the reserved name. Options may still share a name to compete for the same value (feature switches). #2819 #3678
  • unstyle and the ANSI handling behind help-text wrapping now strip the full CSI escape-sequence grammar. #3681
  • Streamline Option flag handling: the flag-kind, type, lazy-default and validation steps in Option.__init__ move into focused helpers, and flag_value and default keep their unset sentinel at construction (resolved lazily on read) so is UNSET reliably tells a user-supplied value from an auto-derived one. Runtime behavior is unchanged, but {meth}Parameter.to_info_dict now resolves default=True on a feature switch to its flag_value, matching what the function receives at call

... (truncated)

Changelog

Sourced from click's changelog.

Version 8.5.0

Released 2026-08-24

  • Add built-in shell completion support for PowerShell (Windows PowerShell 5.1+ and pwsh 7+) alongside the existing bash, zsh, and fish completers. Use _FOO_BAR_COMPLETE=powershell_source foo-bar to generate the completion script. {issue}2672 {pr}3637
  • Supported versions of Windows enable ANSI terminal styles by default. Colorama is no longer a dependency and is not used. {issue}2986 {pr}3505
  • {class}Argument accepts a help parameter, and help output includes a Positional arguments section when argument help is available. {issue}2983 {pr}3473
  • confirm() and prompt() strip ANSI color and style codes from the prompt when the output stream does not support them, matching echo(). This stripping was lost in 8.4.0 when {pr}2969 began writing the prompt with input() directly. {issue}3572 {pr}3653
  • Fix test failures when using pytest >= 9.1. {pr}3656
  • {class}Path with allow_dash=True no longer triggers a BytesWarning, an error under python -bb, when checking a value against the - convention. {issue}2877 {pr}3642
  • Add {func}custom_version_option, a --version option whose output is produced by a callback, covering cases {func}version_option intentionally does not. The feature set of {func}version_option is now frozen; see [discussion #3527](`@version_option` future direction pallets/click#3527). {pr}3581
  • style() and secho() no longer silently drop the 256-color index 0 (black) passed as fg or bg, and now validate color arguments. Invalid colors raise a ValueError instead of a TypeError. {pr}3677
  • The automatic help option stores its value under the reserved name _click_default_help instead of help, so a parameter named help no longer breaks parsing. The new name is visible in {meth}Command.to_info_dict output. Parameters that overwrite each other's value trigger a warning: an argument sharing its name with another parameter, or any parameter claiming the reserved name. Options may still share a name to compete for the same value (feature switches). {issue}2819 {pr}3678
  • unstyle and the ANSI handling behind help-text wrapping now strip the full CSI escape-sequence grammar. {pr}3681
  • Streamline Option flag handling: the flag-kind, type, lazy-default and validation steps in Option.__init__ move into focused helpers, and flag_value and default keep their unset sentinel at construction (resolved lazily on read) so is UNSET reliably tells a user-supplied value from an auto-derived one. Runtime behavior is unchanged, but {meth}Parameter.to_info_dict now resolves default=True on a feature switch to its flag_value, matching what the function receives at call time. {pr}3641
  • {func}get_binary_stream and {func}get_text_stream are deprecated and will be removed in Click 9.0. {issue}3481 {pr}3695
  • The following click.utils names were never intentionally public and are now private (_-prefixed). The old names remain available with a DeprecationWarning until Click 9.0: LazyFile, KeepOpenFile,

... (truncated)

Commits
  • 8b19813 Release version 8.5.0
  • 2c8cd3a Add FAQ entry about UnicodeEncodeError on Windows (#3778)
  • 131c86a Add FAQ entry about UnicodeEncodeError on Windows
  • e1fd594 Add support of pathlib.Path to edit (#3781)
  • a1d8785 Add support of pathlib.Path to edit
  • 2103e15 Forward all user's parameters set in PAGER and improve flag detection (#3777)
  • a6256bf Forwards all user's parameters set in PAGER
  • 61b69e9 Resolve the pager command once, in _pager_contextmanager (#3776)
  • 9835b0f Resolve the pager command once, in _pager_contextmanager
  • f36d58b Refactor pager stream handling (#3767)
  • Additional commits viewable in compare view

Updates flask-security-too from 5.7.1 to 5.9.1

Release notes

Sourced from flask-security-too's releases.

Release 5.9.1

This is a patch release to fix an open-redirect vulnerability - GHSA-ccgp-pv8r-95wm

Release 5.9.0

No release notes provided.

Release 5.8.2

No release notes provided.

Release 5.8.1

No release notes provided.

Release 5.8.0

No release notes provided.

Changelog

Sourced from flask-security-too's changelog.

Version 5.9.1

Released September 30, 2026

Fixes +++++ -(:pr:1293) Fix for open-redirect GHSA-ccgp-pv8r-95wm

Version 5.9.0

Released September 24, 2026

This release adds support for refresh tokens (finally!). In addition there are several configuration changes that try to align Flask-Security with latest best-practices.

Please read these notes carefully - in particular the change to the default auth token lifetime might severely impact some applications.

Features & Improvements +++++++++++++++++++++++

  • (:issue:1206) Add support for refresh tokens. See :ref:token_topic
  • (:pr:1233) Change :py:data:SECURITY_TOKEN_MAX_AGE from an int to a timedelta. Also - change default from never expire to 15 minutes.
  • (:pr:1235) Change default :py:data:SECURITY_LOGOUT_METHODS to be just "POST"
  • (:issue:1228) Change default csrf and tf_validity cookie config to secure=True
  • (:issue:1228) The tf_validity cookie name is now configurable via :py:data:SECURITY_TWO_FACTOR_VALIDITY_COOKIE_NAME
  • (:issue:1237) Add support for CSRF on logout (default False)
  • (:pr:1241) Convert all _WITHIN configuration variables to use timedelta
  • (:issue:1153) Enable localization of %(within)s variables using humanize
  • (:pr:1249) Add link expiration to confirmation and reset password email templates.
  • (:issue:536 Add template path configuration variables for all email templates.
  • (:issue:1254) Webauthn/passkey name input value is now sanitized and normalized. A new utility method :py:meth:flask_security.input_svn is now used and is available for applications to use.
  • (:pr:1271) Username validation and normalization now uses the new :py:meth:flask_security.input_svn utility. This has some backwards compatibility concerns - see below.
  • (:pr:1259) Allow redirects to exactly :py:data:SECURITY_REDIRECT_BASE_DOMAIN by adding '.' to :py:data:SECURITY_REDIRECT_ALLOWED_SUBDOMAINS.

Fixes +++++

  • (:issue:1108) /verify and /us-verify forms now include the optional next field so form-posted redirect URLs are validated and preserved. (DSeaStar)
  • (:issue:1212) Newly introduced :py:meth:.UserMixin.is_locked logic is inverted.
  • (:pr:1234) Fix for GHSA-f66q-9rf6-8795 - WebAuthn reauthentication freshness bypass. (tonghuaroot)
  • (:issue:1244) Fix login form remember me checkbox.
  • (:pr:1258) A JSON request body can set a form field (email, password, username, identity, name, phone, refresh token, recovery/2FA code, ...) to a non-string value (e.g. a dict), which used to crash with an unhandled

... (truncated)

Commits

Updates flask-caching from 2.4.1 to 2.5.1

Release notes

Sourced from flask-caching's releases.

2.5.1

This is the Flask-Caching 2.5.1 fix release, which fixes bugs but does not otherwise change behavior and should not result in breaking changes compared to the latest feature release.

PyPI: https://pypi.org/project/Flask-Caching/2.5.1/ Changes: https://flask-caching.readthedocs.io/en/latest/changelog/#version-2-5-1

2.5.0

Note: This release will invalidate your caches because we changed the default hash_method from hashlib.md5 to hashlib.sha256. This can be changed back via CACHE_HASH_METHOD if you wish to still use the old hash_method!

Added / Improved

  • Specifying timeouts now also works with datetime.timedelta. #266
  • Add config option CACHE_SERIALIZER to set the cachelib serializer the backend uses. #209
  • cachelib backends can now be configured directly via CACHE_TYPE="cachelib.ValkeyCache. #668
  • Send Signals for cache hits and misses. #237 and #667
  • Add Cache.delete_cached() and extend make_cache_key() with path and query_args arguments to make deleting views decorated with cached(query_string=True) possible. #243
  • Add CACHE_HASH_METHOD to set the hash method used for the cache keys of @cached and @memoize.
  • Add an is_stale option to @cached and @memoize. It is called on a cache hit with the cached value. Unlike forced_update it uses the value itself to check whether the cache is stale. Can be used in combination with forced_update #392
  • @cached and @memoize now preserve the wrapped function's signature and expose uncached, cache_timeout, make_cache_key delete_memoized to type checkers.
  • Add CACHE_FILE_HASH_METHOD config option to FileSystemCache to allow using a different hash function for cache keys. #660
  • Add pool_size and pool_blocking to make MemcachedCache backends thread-safe. #663
  • Document that CACHE_REDIS_HOST accepts an already created redis.Redis client instead of a host name, which allows sharing a connection pool with other extensions and the application. #629
  • Clarify docs about decorator order regarding @staticmethod and @classmethod when memoizing. #440
  • Modify SimpleCache docs as it's now thread-safe using an RLock for all operations. #663

Changed

  • Drop support for Python 3.10 and require cachelib 0.17.0+
  • Remove the deprecated lowercase CACHE_TYPE names (null, simple, filesystem, redis, redissentinel, rediscluster, uwsgi, memcached, gaememcached, saslmemcached and spreadsaslmemcached)
  • Use hashlib.sha256 instead of hashlib.md5 for hashing the cache keys. This changes the generated keys, so entries cached by an earlier version become obsolete. If you wish to still use hashlib.md5 set the config CACHE_HASH_METHOD = hashlib.md5. #563
  • @cached and @memoize now go through the public Cache proxy methods (get, set, has, delete, delete_many, get_many and set_many) instead of calling the backend directly. #417
  • CACHE_IGNORE_ERRORS is now used by every backend instead of only SimpleCache and FileSystemCache.
  • The delete_many method is now used from cachelib. A key that does not exist counts as deleted, and with CACHE_IGNORE_ERRORS set to False a RuntimeError is raised if the key could not be deleted.
  • Call @memoize forced_update callbacks once per decorated function call instead of once while making the key and again before cache lookup. #387
  • @cached now caches an HTTPException raised by the view (i.e. through abort()). This exception will now be re-raises on a cache hit. Use response_filter, to keep the exception out of the cache. #444
  • The {% cache %} Jinja tag no longer propagates backend errors. If the cache is unavailable, the block is rendered normally instead of raising, matching the existing behavior of @memoize. #564 #565

Fixed

  • Include key_prefix when building @cached(query_string=True) cache keys. #302
  • Fix a @memoize cache-key collision when a parameter has a falsy default (e.g. 0, "", False): calling with the default was keyed the same as passing None, returning the wrong cached result. #656
  • Fix @cached(response_hit_indication=True) appending a new after_request function to the app on every request.
  • Fix a view returning an iterator of strings, for example when using flask.stream_template it previously returned a list of JSON strings instead of the rendered template. #511
  • Fix __caching_id__ never being usable. @memoize silently ignored that and ran the function uncached.
  • delete_memoized now takes the instance from a bound method, so cache.delete_memoized(obj.method, 1) deletes the cache for obj.method(1) instead of silently deleting nothing. The current behaviour by passing the instance keeps working as well. #554
  • Fix @memoize invalidating a function's entire cache by not updating the memoize version key's timeout. It is now refreshed each time an entry is written, with that entry's own timeout. #531

New Contributors

... (truncated)

Changelog

Sourced from flask-caching's changelog.

Version 2.5.1

Released 2026-09-04

  • @cached no longer treats view arguments named path or query_args as the explicit make_cache_key() arguments of the same name. :issue:679

Version 2.5.0

Released 2026-08-24

  • Specifying timeouts now also works with datetime.timedelta. :issue:266
  • Add config option CACHE_SERIALIZER to set the cachelib serializer the backend uses. :issue:209
  • cachelib backends can now be configured directly via CACHE_TYPE="cachelib.ValkeyCache. :pr:668
  • @cached and @memoize now go through the public Cache proxy methods (get, set, has, delete, delete_many, get_many and set_many) instead of calling the backend directly. :issue:417
  • Document that CACHE_REDIS_HOST accepts an already created redis.Redis client instead of a host name, which allows sharing a connection pool with other extensions and the application. :issue:629
  • Send Signals for cache hits and misses. :pr:[#237](https://github.com/pallets-eco/flask-caching/issues/237) and :pr:667
  • Include key_prefix when building @cached(query_string=True) cache keys. :issue:302
  • Add Cache.delete_cached() and extend make_cache_key() with path and query_args arguments to make deleting views decorated with cached(query_string=True) possible. :issue:243
  • Use hashlib.sha256 instead of hashlib.md5 for hashing the cache keys. This changes the generated keys, so entries cached by an earlier version become obsolete. If you wish to still use hashlib.md5 set the config CACHE_HASH_METHOD = hashlib.md5. :pr:563
  • Add CACHE_HASH_METHOD to set the hash method used for the cache keys of @cached and @memoize.
  • Drop support for Python 3.10 and require cachelib 0.17.0+
  • CACHE_IGNORE_ERRORS is now used by every backend instead of only SimpleCache and FileSystemCache.
  • The delete_many method is now used from cachelib. A key that does not exist counts as deleted, and with CACHE_IGNORE_ERRORS set to False a RuntimeError is raised if the key could not be deleted.
  • Clarify docs about decorator order regarding @staticmethod and @classmethod when memoizing. :issue:440
  • Remove the deprecated lowercase CACHE_TYPE names (null, simple, filesystem, redis, redissentinel, rediscluster, uwsgi, memcached, gaememcached, saslmemcached and spreadsaslmemcached)
  • Call @memoize forced_update callbacks once per decorated function

... (truncated)

Commits
  • f1ccf5b Merge pull request #682 from pallets-eco/release-v2.5.1
  • 45320ad release version 2.5.1
  • cd48c77 Fix 'path' and 'query_args' variable in cache key. Fixes #679
  • 5330047 fix docs not building
  • 3933b3f Allow flit_core 4.x
  • 8dd912a Update publish workflow
  • 01f0e3f Version 2.5.0
  • 66a8e05 Improve exception handling for the cached decorator. Fixes #444
  • b09952d Bump cachelib to 0.17.0
  • fca9ac2 Convert str to int instead of casting
  • Additional commits viewable in compare view

Updates sqlalchemy from 2.0.51 to 2.1.1

Release notes

Sourced from sqlalchemy's releases.

2.1.1

Released: September 25, 2026

platform

  • [platform] [bug] Removed the legacy underscore-separated extra names such as mssql_pymssql and postgresql_psycopg from pyproject.toml. They normalize to the same names as the existing dash-separated extras, which is disallowed by PEP 685, and caused the 2.1.0 source distribution to fail to build with installers that enforce this rule, such as uv. The underscore spellings continue to work when installing, as installers normalize extra names before matching them.

    References: #13604

2.1.0

Released: September 24, 2026

orm

  • [orm] [feature] Added _orm.composite.column_template parameter to _orm.composite(). When the composite class is a dataclass, this parameter accepts a string template such as "person_%s", containing exactly one %s placeholder, that's used to generate column names for dataclass fields that don't otherwise have an explicit name, rather than using the bare field name. This removes the need to hand-write a _orm.mapped_column() for each field when the same composite dataclass is mapped multiple times on the same class with different column-name prefixes. Pull request courtesy Leonardo Rosa.

    References: #12575

  • [orm] [bug] Fixed issue where pickling an ORM object that had an instance level lazy loader established, such as when the _orm.raiseload() option is used, would emit a spurious warning regarding the loader containing additional criteria, if the object had itself been unpickled from a previous serialization. This would occur for objects that cross more than one serialization boundary, such as when using multiprocessing.

    This change is also backported to: 2.0.53

    References: #13574

  • [orm] [bug] Fixed issue where calling _orm.aliased() against an existing _orm.aliased() construct, without passing an explicit selectable, would disregard the selectable of the existing construct and produce an

... (truncated)

Commits

Updates psycopg2-binary from 2.9.12 to 2.9.13

Changelog

Sourced from psycopg2-binary's changelog.

Current release

What's new in psycopg 2.9.13 ^^^^^^^^^^^^^^^^^^^^^^^^^^^^

  • Add support for Python 3.15 (:ticket:[#1848](https://github.com/psycopg/psycopg2/issues/1848)).
  • Fix parsing of malformed bytea input.
  • Fix parsing of malformed int64 input in arrays (:ticket:[#1847](https://github.com/psycopg/psycopg2/issues/1847)).
  • Add a pyproject.toml file to declare a PEP 517 build backend (:ticket:[#1788](https://github.com/psycopg/psycopg2/issues/1788)).
  • Drop support for Python 3.9.

What's new in psycopg 2.9.12 ^^^^^^^^^^^^^^^^^^^^^^^^^^^^

  • Fix infinite loop with malformed interval (:ticket:1835).

What's new in psycopg 2.9.11 ^^^^^^^^^^^^^^^^^^^^^^^^^^^^

  • Add support for Python 3.14.
  • Avoid a segfault passing more arguments than placeholders if Python is built with assertions enabled (:ticket:[#1791](https://github.com/psycopg/psycopg2/issues/1791)).
  • Add riscv64 platform binary packages (:ticket:[#1813](https://github.com/psycopg/psycopg2/issues/1813)).
  • ~psycopg2.errorcodes map and ~psycopg2.errors classes updated to PostgreSQL 18.
  • Drop support for Python 3.8.

What's new in psycopg 2.9.10 ^^^^^^^^^^^^^^^^^^^^^^^^^^^^

  • Add support for Python 3.13.
  • Receive notifications on commit (:ticket:[#1728](https://github.com/psycopg/psycopg2/issues/1728)).
  • ~psycopg2.errorcodes map and ~psycopg2.errors classes updated to PostgreSQL 17.
  • Drop support for Python 3.7.

What's new in psycopg 2.9.9 ^^^^^^^^^^^^^^^^^^^^^^^^^^^

  • Add support for Python 3.12.
  • Drop support for Python 3.6.

What's new in psycopg 2.9.8

... (truncated)

Commits
  • f650e7a chore: bump to release 2.9.13
  • 368c8a1 chore!: drop support for Python 3.9
  • 9b39e65 chore: drop scaleway build support
  • 2ca7041 fix: fix handling of PostgreSQL 18 exceptions
  • 5385c02 Build CPython 3.15 wheels
  • 1d32e1f ci: only attempt triggering documentation refresh when pushing on main repo
  • 433e7b7 chore: add pyproject.toml file to declare a PEP 517 build backend
  • 8fb80bc fix: fix parsing of malformed int64 input in arrays
  • f98014a fix: fix parsing of malformed bytea input
  • 822b79c chore: bump dependencies in binary package
  • Additional commits viewable in compare view

Updates cryptography from 50.0.0 to 50.0.2

Changelog

Sourced from cryptography's changelog.

50.0.2 - 2026-09-30


* Updated Windows, macOS, and Linux wheels to be compiled with OpenSSL 4.0.3.
* Added ``abi3.abi3t`` wheels for free-threaded CPython 3.15 and later.
* Updated to PyO3 0.29.2, which fixes building ``cryptography`` on Cygwin and
  MSYS2.

.. _v50-0-1:

50.0.1 - 2026-08-25

  • Updated Windows, macOS, and Linux wheels to be compiled with OpenSSL 4.0.2.

.. _v50-0-0:

Commits

Updates webauthn from 3.0.0 to 3.0.1

Release notes

Sourced from webauthn's releases.

v3.0.1

Changes:

  • verify_registration_response() now rejects responses with attestation statement formats that are not strings (#288, h/t @​DarkaMaul)
Changelog

Sourced from webauthn's changelog.

v3.0.1

Changes:

  • verify_registration_response() now rejects responses with attestation statement formats that are not strings (#288, h/t @​DarkaMaul)
Commits
  • d72e0f5 Bump version to v3.0.1
  • 732ca23 Update CHANGELOG for v3.0.1
  • b474c8d Merge pull request #288 from trail-of-forks/dm/reject-attestations-fmt
  • 5557d97 Reject early invalid attestation formats
  • See full diff in compare view

Updates python-dotenv from 1.2.2 to 1.2.4

Release notes

Sourced from python-dotenv's releases.

v1.2.4

Fixed

  • dotenv get no longer exits with code 1 for empty string values (KEY=) by [@​ShamikOfficial] in #700
  • An unquoted empty value followed by an inline comment (e.g. KEY= # comment) is now parsed as an empty string instead of the comment text by [@​Noethix55555] in #663
  • dotenv run --no-override now expands variable references with the same precedence as load_dotenv(override=False), so a value like ${BASE}/suffix uses the existing BASE from the environment instead of the one from the .env file by [@​ROTl24] in #698

v1.2.3

Fixed

  • Strip a leading UTF-8 BOM from .env file contents so the first variable is no longer silently lost when the file is saved with BOM (e.g. by some JetBrains IDEs on Windows) by [@​h1whelan] in #640
  • set_key now escapes backslashes, so values containing them (Windows paths, regular expressions) survive a write/read round-trip. Quoted values ending in an escaped backslash are no longer mis-parsed as an escaped quote, which used to swallow the following lines by [@​dchaudhari7177] in #680
  • dotenv run now prints a friendly error instead of a traceback when no command is given by [@​bbc2] in #606
  • Cache the parsed result for empty .env files so repeated dotenv_values/load_dotenv calls no longer re-read the file by [@​ReinerBRO] in #638
Changelog

Sourced from python-dotenv's changelog.

[1.2.4] - 2026-10-01

Fixed

  • dotenv get no longer exits with code 1 for empty string values (KEY=) by [@​ShamikOfficial] in #700
  • An unquoted empty value followed by an inline comment (e.g. KEY= # comment) is now parsed as an empty string instead of the comment text by [@​Noethix55555] in #663
  • dotenv run --no-override now expands variable references with the same precedence as load_dotenv(override=False), so a value like ${BASE}/suffix uses the existing BASE from the environment instead of the one from the .env file by [@​ROTl24] in #698

[1.2.3] - 2026-08-16

Fixed

  • Strip a leading UTF-8 BOM from .env file contents so the first variable is no longer silently lost when the file is saved with BOM (e.g. by some JetBrains IDEs on Windows) by [@​h1whelan] in #640
  • set_key now escapes backslashes, so values containing them (Windows paths, regular expressions) survive a write/read round-trip. Quoted values ending in an escaped backslash are no longer mis-parsed as an escaped quote, which used to swallow the following lines by [@​dchaudhari7177] in #680
  • dotenv run now prints a friendly error instead of a traceback when no command is given by [@​bbc2] in #606
  • Cache the parsed result for empty .env files so repeated dotenv_values/load_dotenv calls no longer re-read the file by [@​ReinerBRO] in #638
Commits
  • a565c2c Bump version: 1.2.3 → 1.2.4
  • 4a7abd0 docs: add 1.2.4 release notes (#663, #698, #700)
  • f215c02 fix: dotenv get exits 0 for empty string values (#700)
  • 58f2d7c test: make test_run_with_command_flags portable and meaningful (#709)
  • e0310e5 fix: honor --no-override when expanding variables in dotenv run (#698)
  • a00cb2e docs: add CHANGELOG entry for #663 (fix #600)
  • f5485a6 fix: parse empty unquoted value with inline comment as empty string
  • 49515af Bump version: 1.2.2 → 1.2.3
  • 8ac846f chore: add release runbook (RELEASING.md) and make release target
  • bb31c94 docs: add 1.2.3 release notes (#606, #638, #680)
  • Additional commits viewable in compare view

Updates pytz from 2026.2 to 2026.4

Commits
  • 1ac6e51 Bump version numbers to 2026.4 (2026d)
  • 1672798 IANA 2026d
  • 0b5995b Squashed 'tz/' changes from 71f28b9ab3..bac9223f4b
  • e96461b Make deprecation notice louder
  • 3c7af58 Merge branch 'nicoleman0-fix/timezone-non-string-input' into 2026d
  • 234a247 Merge branch 'nicoleman0-fix/fixedoffset-basetzinfo' into 2026d
  • 8f8a588 Raise UnknownTimeZoneError for non-string zone arguments
  • 1f0f27e Make _FixedOffset a BaseTzInfo exposing _utcoffset
  • 661bca9 Bump version numbers to 2026.3.post1 for python2 fix
  • 1e31a16 Log python version running tests, force python2
  • Additional commits viewable in compare view

Updates orjson from 3.11.9 to 3.12.0

Release notes

Sourced from orjson's releases.

3.12.0

Changed

  • Serialization implementation substantially rewritten.
  • Publish PyPI wheels for Python 3.15. For Python 3.15 and later, manylinux_2_39 (2024) is targeted instead of manylinux_2_17 (2012).
  • No longer publish PyPI wheels for ppc64le and s390x.
Changelog

Sourced from orjson's changelog.

3.12.0 - 2026-08-14

Changed

  • Serialization implementation substantially rewritten.
  • Publish PyPI wheels for Python 3.15. For Python 3.15 and later, manylinux_2_39 (2024) is targeted instead of manylinux_2_17 (2012).
  • No longer publish PyPI wheels for ppc64le and s390x.
Commits

Updates gunicorn from 26.0.0 to 26.2.0

Release notes

Sourced from gunicorn's releases.

Description has been truncated

Bumps the python group with 17 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [werkzeug](https://github.com/pallets/werkzeug) | `3.1.8` | `3.1.9` |
| [click](https://github.com/pallets/click) | `8.4.2` | `8.5.0` |
| [flask-security-too](https://github.com/pallets-eco/flask-security) | `5.7.1` | `5.9.1` |
| [flask-caching](https://github.com/pallets-eco/flask-caching) | `2.4.1` | `2.5.1` |
| [sqlalchemy](https://github.com/sqlalchemy/sqlalchemy) | `2.0.51` | `2.1.1` |
| [psycopg2-binary](https://github.com/psycopg/psycopg2) | `2.9.12` | `2.9.13` |
| [cryptography](https://github.com/pyca/cryptography) | `50.0.0` | `50.0.2` |
| [webauthn](https://github.com/duo-labs/py_webauthn) | `3.0.0` | `3.0.1` |
| [python-dotenv](https://github.com/theskumar/python-dotenv) | `1.2.2` | `1.2.4` |
| [pytz](https://github.com/stub42/pytz) | `2026.2` | `2026.4` |
| [orjson](https://github.com/ijl/orjson) | `3.11.9` | `3.12.0` |
| [gunicorn](https://github.com/benoitc/gunicorn) | `26.0.0` | `26.2.0` |
| [stripe](https://github.com/stripe/stripe-python) | `15.3.0` | `16.0.0` |
| [chargebee](https://github.com/chargebee/chargebee-python) | `3.25.0` | `3.29.0` |
| [redis](https://github.com/redis/redis-py) | `8.0.1` | `8.1.0` |
| [ruff](https://github.com/astral-sh/ruff) | `0.15.21` | `0.16.10` |
| [pre-commit](https://github.com/pre-commit/pre-commit) | `4.6.0` | `4.6.2` |



Updates `werkzeug` from 3.1.8 to 3.1.9
- [Release notes](https://github.com/pallets/werkzeug/releases)
- [Changelog](https://github.com/pallets/werkzeug/blob/main/CHANGES.rst)
- [Commits](pallets/werkzeug@3.1.8...3.1.9)

Updates `click` from 8.4.2 to 8.5.0
- [Release notes](https://github.com/pallets/click/releases)
- [Changelog](https://github.com/pallets/click/blob/main/CHANGES.md)
- [Commits](pallets/click@8.4.2...8.5.0)

Updates `flask-security-too` from 5.7.1 to 5.9.1
- [Release notes](https://github.com/pallets-eco/flask-security/releases)
- [Changelog](https://github.com/pallets-eco/flask-security/blob/main/CHANGES.rst)
- [Commits](pallets-eco/flask-security@5.7.1...5.9.1)

Updates `flask-caching` from 2.4.1 to 2.5.1
- [Release notes](https://github.com/pallets-eco/flask-caching/releases)
- [Changelog](https://github.com/pallets-eco/flask-caching/blob/main/CHANGES.rst)
- [Commits](pallets-eco/flask-caching@v2.4.1...v2.5.1)

Updates `sqlalchemy` from 2.0.51 to 2.1.1
- [Release notes](https://github.com/sqlalchemy/sqlalchemy/releases)
- [Changelog](https://github.com/sqlalchemy/sqlalchemy/blob/main/CHANGES.rst)
- [Commits](https://github.com/sqlalchemy/sqlalchemy/commits)

Updates `psycopg2-binary` from 2.9.12 to 2.9.13
- [Changelog](https://github.com/psycopg/psycopg2/blob/master/NEWS)
- [Commits](psycopg/psycopg2@2.9.12...2.9.13)

Updates `cryptography` from 50.0.0 to 50.0.2
- [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst)
- [Commits](pyca/cryptography@50.0.0...50.0.2)

Updates `webauthn` from 3.0.0 to 3.0.1
- [Release notes](https://github.com/duo-labs/py_webauthn/releases)
- [Changelog](https://github.com/duo-labs/py_webauthn/blob/master/CHANGELOG.md)
- [Commits](duo-labs/py_webauthn@v3.0.0...v3.0.1)

Updates `python-dotenv` from 1.2.2 to 1.2.4
- [Release notes](https://github.com/theskumar/python-dotenv/releases)
- [Changelog](https://github.com/theskumar/python-dotenv/blob/main/CHANGELOG.md)
- [Commits](theskumar/python-dotenv@v1.2.2...v1.2.4)

Updates `pytz` from 2026.2 to 2026.4
- [Release notes](https://github.com/stub42/pytz/releases)
- [Commits](stub42/pytz@release_2026.2...release_2026.4)

Updates `orjson` from 3.11.9 to 3.12.0
- [Release notes](https://github.com/ijl/orjson/releases)
- [Changelog](https://github.com/ijl/orjson/blob/master/CHANGELOG.md)
- [Commits](ijl/orjson@3.11.9...3.12.0)

Updates `gunicorn` from 26.0.0 to 26.2.0
- [Release notes](https://github.com/benoitc/gunicorn/releases)
- [Commits](benoitc/gunicorn@26.0.0...26.2.0)

Updates `stripe` from 15.3.0 to 16.0.0
- [Release notes](https://github.com/stripe/stripe-python/releases)
- [Changelog](https://github.com/stripe/stripe-python/blob/master/CHANGELOG.md)
- [Commits](stripe/stripe-python@v15.3.0...v16.0.0)

Updates `chargebee` from 3.25.0 to 3.29.0
- [Release notes](https://github.com/chargebee/chargebee-python/releases)
- [Changelog](https://github.com/chargebee/chargebee-python/blob/master/CHANGELOG.md)
- [Commits](chargebee/chargebee-python@v3.25.0...v3.29.0)

Updates `redis` from 8.0.1 to 8.1.0
- [Release notes](https://github.com/redis/redis-py/releases)
- [Changelog](https://github.com/redis/redis-py/blob/master/CHANGES)
- [Commits](redis/redis-py@v8.0.1...v8.1.0)

Updates `ruff` from 0.15.21 to 0.16.10
- [Release notes](https://github.com/astral-sh/ruff/releases)
- [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md)
- [Commits](astral-sh/ruff@0.15.21...0.16.10)

Updates `pre-commit` from 4.6.0 to 4.6.2
- [Release notes](https://github.com/pre-commit/pre-commit/releases)
- [Changelog](https://github.com/pre-commit/pre-commit/blob/main/CHANGELOG.md)
- [Commits](pre-commit/pre-commit@v4.6.0...v4.6.2)

---
updated-dependencies:
- dependency-name: werkzeug
  dependency-version: 3.1.9
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python
- dependency-name: click
  dependency-version: 8.5.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python
- dependency-name: flask-security-too
  dependency-version: 5.9.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python
- dependency-name: flask-caching
  dependency-version: 2.5.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python
- dependency-name: sqlalchemy
  dependency-version: 2.1.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python
- dependency-name: psycopg2-binary
  dependency-version: 2.9.13
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python
- dependency-name: cryptography
  dependency-version: 50.0.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python
- dependency-name: webauthn
  dependency-version: 3.0.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python
- dependency-name: python-dotenv
  dependency-version: 1.2.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python
- dependency-name: pytz
  dependency-version: '2026.4'
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python
- dependency-name: orjson
  dependency-version: 3.12.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python
- dependency-name: gunicorn
  dependency-version: 26.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python
- dependency-name: stripe
  dependency-version: 16.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: python
- dependency-name: chargebee
  dependency-version: 3.29.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python
- dependency-name: redis
  dependency-version: 8.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python
- dependency-name: ruff
  dependency-version: 0.16.10
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python
- dependency-name: pre-commit
  dependency-version: 4.6.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels Oct 4, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants