Repository navigation
chore(deps): bump the python-maintenance group across 1 directory with 14 updates - #3988
Conversation
OkTest Summary❌ Failed for Python SDK PR #3988. SDK merge ( |
Castiron custom codeEvaluated main: Mixed files: 46 → 52 6 newly customized · 0 customizations removed · 0 existing customizations changed · 0 generated baselines changed Compared
46 existing customizations unchanged
6 more in the full report. A changed generated baseline means this report cannot reliably identify which handwritten lines changed. Inspect the custom-code diffDownload the exact patch produced by this run (requires repository access): gh run download 37945796978 --repo openai/openai-python \
--name castiron-custom-code-37945796978-1 --dir /tmp/castiron-custom-code-37945796978-1
git apply --stat /tmp/castiron-custom-code-37945796978-1/custom-code.patch
cat /tmp/castiron-custom-code-37945796978-1/custom-code.patchOr reproduce it from an SDK checkout containing the vendored reporter: git fetch --no-tags origin 8bfffd40158460d0f5e651590b95cfef5292d93e aac2cccb41cc7ae0f4a221da5f8a0225f79e0836
python3 scripts/castiron/custom_code_report.py report \
--base 8bfffd40158460d0f5e651590b95cfef5292d93e \
--head aac2cccb41cc7ae0f4a221da5f8a0225f79e0836 --fetch --require-head-hash --public \
--out /tmp/castiron-custom-code-aac2cccb41cc
cat /tmp/castiron-custom-code-aac2cccb41cc/custom-code.patchThis is the current full custom patch for mixed files, not an attribution of only the handwritten lines changed by this PR. |
4d22f62 to
0625586
Compare
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 0625586b9c
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
45eab89 to
c2e530b
Compare
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
6949659 to
9bf8a62
Compare
|
Note Codex usage limits have been reached for code reviews. Please check with the admins of this repo to increase the limits by adding credits. |
…h 14 updates Bumps the python-maintenance group with 14 updates in the / directory: | Package | From | To | | --- | --- | --- | | [httpx2](https://github.com/pydantic/httpx2) | `2.12.0` | `2.13.1` | | [typing-extensions](https://github.com/python/typing_extensions) | `4.15.0` | `4.16.0` | | [anyio](https://github.com/agronholm/anyio) | `4.12.1` | `4.15.1` | | [jiter](https://github.com/pydantic/jiter) | `0.16.0` | `0.17.0` | | [sounddevice](https://github.com/spatialaudio/python-sounddevice) | `0.5.3` | `0.5.6` | | [botocore](https://github.com/boto/botocore) | `1.42.97` | `1.43.106` | | [urllib3](https://github.com/urllib3/urllib3) | `2.7.0` | `2.8.0` | | [pytest](https://github.com/pytest-dev/pytest) | `9.0.3` | `9.1.1` | | [ruff](https://github.com/astral-sh/ruff) | `0.14.7` | `0.16.9` | | [inline-snapshot](https://github.com/15r10nk/inline-snapshot) | `0.31.1` | `0.35.4` | | [azure-identity](https://github.com/Azure/azure-sdk-for-python) | `1.25.1` | `1.25.3` | | [trio](https://github.com/python-trio/trio) | `0.31.0` | `0.34.0` | | [hatchling](https://github.com/pypa/hatch) | `1.27.0` | `1.32.4` | | [trove-classifiers](https://github.com/pypa/trove-classifiers) | `2026.6.1.19` | `2026.9.21.13` | Updates `httpx2` from 2.12.0 to 2.13.1 - [Release notes](https://github.com/pydantic/httpx2/releases) - [Changelog](https://github.com/pydantic/httpx2/blob/main/src/httpx2/CHANGELOG.md) - [Commits](pydantic/httpx2@v2.12.0...v2.13.1) Updates `typing-extensions` from 4.15.0 to 4.16.0 - [Release notes](https://github.com/python/typing_extensions/releases) - [Changelog](https://github.com/python/typing_extensions/blob/main/CHANGELOG.md) - [Commits](python/typing_extensions@4.15.0...4.16.0) Updates `anyio` from 4.12.1 to 4.15.1 - [Release notes](https://github.com/agronholm/anyio/releases) - [Commits](agronholm/anyio@4.12.1...4.15.1) Updates `jiter` from 0.16.0 to 0.17.0 - [Release notes](https://github.com/pydantic/jiter/releases) - [Commits](pydantic/jiter@v0.16.0...v0.17.0) Updates `sounddevice` from 0.5.3 to 0.5.6 - [Release notes](https://github.com/spatialaudio/python-sounddevice/releases) - [Changelog](https://github.com/spatialaudio/python-sounddevice/blob/master/NEWS.rst) - [Commits](spatialaudio/python-sounddevice@0.5.3...0.5.6) Updates `botocore` from 1.42.97 to 1.43.106 - [Commits](boto/botocore@1.42.97...1.43.106) Updates `urllib3` from 2.7.0 to 2.8.0 - [Release notes](https://github.com/urllib3/urllib3/releases) - [Changelog](https://github.com/urllib3/urllib3/blob/main/CHANGES.rst) - [Commits](urllib3/urllib3@2.7.0...2.8.0) Updates `pytest` from 9.0.3 to 9.1.1 - [Release notes](https://github.com/pytest-dev/pytest/releases) - [Changelog](https://github.com/pytest-dev/pytest/blob/main/CHANGELOG.rst) - [Commits](pytest-dev/pytest@9.0.3...9.1.1) Updates `ruff` from 0.14.7 to 0.16.9 - [Release notes](https://github.com/astral-sh/ruff/releases) - [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md) - [Commits](astral-sh/ruff@0.14.7...0.16.9) Updates `inline-snapshot` from 0.31.1 to 0.35.4 - [Release notes](https://github.com/15r10nk/inline-snapshot/releases) - [Changelog](https://github.com/15r10nk/inline-snapshot/blob/main/CHANGELOG.md) - [Commits](15r10nk/inline-snapshot@0.31.1...0.35.4) Updates `azure-identity` from 1.25.1 to 1.25.3 - [Release notes](https://github.com/Azure/azure-sdk-for-python/releases) - [Commits](Azure/azure-sdk-for-python@azure-identity_1.25.1...azure-identity_1.25.3) Updates `trio` from 0.31.0 to 0.34.0 - [Release notes](https://github.com/python-trio/trio/releases) - [Commits](python-trio/trio@v0.31.0...v0.34.0) Updates `hatchling` from 1.27.0 to 1.32.4 - [Release notes](https://github.com/pypa/hatch/releases) - [Commits](pypa/hatch@hatchling-v1.27.0...hatchling-v1.32.4) Updates `trove-classifiers` from 2026.6.1.19 to 2026.9.21.13 - [Release notes](https://github.com/pypa/trove-classifiers/releases) - [Commits](pypa/trove-classifiers@2026.6.1.19...2026.9.21.13) --- updated-dependencies: - dependency-name: anyio dependency-version: 4.15.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: python-maintenance - dependency-name: azure-identity dependency-version: 1.25.3 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: python-maintenance - dependency-name: botocore dependency-version: 1.43.98 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: python-maintenance - dependency-name: hatchling dependency-version: 1.32.4 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: python-maintenance - dependency-name: httpx2 dependency-version: 2.13.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: python-maintenance - dependency-name: inline-snapshot dependency-version: 0.35.4 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: python-maintenance - dependency-name: jiter dependency-version: 0.17.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: python-maintenance - dependency-name: pytest dependency-version: 9.1.1 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: python-maintenance - dependency-name: ruff dependency-version: 0.16.8 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: python-maintenance - dependency-name: sounddevice dependency-version: 0.5.6 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: python-maintenance - dependency-name: trio dependency-version: 0.34.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: python-maintenance - dependency-name: trove-classifiers dependency-version: 2026.9.21.13 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: python-maintenance - dependency-name: typing-extensions dependency-version: 4.16.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: python-maintenance - dependency-name: urllib3 dependency-version: 2.8.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: python-maintenance ... Signed-off-by: dependabot[bot] <support@github.com>
9bf8a62 to
fa06208
Compare
|
Fixed the failing checks by restoring the uv.lock release-please marker and the canonical Bedrock requirement spelling. Applied narrowly scoped Ruff fixes in the Castiron scripts, preserving the ValueError contract and budget enforcement, and synchronized the reporter integrity hash. Published SDK dependency bounds and Python support are unchanged. Local validation: Ruff; mypy (1,978 files); 59 Castiron tests (one skipped); 1,920 dependency-workflow tests; 600 transport/TLS/files/streaming/Bedrock/Azure/model/large-payload tests; 128 built-wheel tests at AnyIO 4.10.0; 160 Pydantic-v1 tests; hashed wheel and sdist builds. Two consecutive independent clean review rounds completed. Watching CI on the pushed commit before approval. |
|
Fixed the remaining lint failure in aac2ccc: inline-snapshot 0.35.4 exposes a partially unknown get_snapshot_value return type, so the test helpers now narrow their known string/bytes response payloads and suppress only the affected upstream import diagnostic. No SDK runtime change. Repository-pinned Pyright: zero errors; full mypy: 1,978 files clean; Ruff: clean; 58 affected snapshot tests pass. Two fresh independent review rounds found no blockers. The preceding head passed Python 3.10, Python 3.14, HTTPX2, and build CI; monitoring all checks again for this final head. All 171 changed distribution artifacts across these Python PRs were matched against upstream PyPI URLs, SHA-256 hashes, and sizes. |
jbeckwith-oai
left a comment
There was a problem hiding this comment.
Approved after comprehensive review and green exact-head CI on aac2ccc. Published SDK dependency ranges, Python >=3.10 support, extras, and SDK APIs remain unchanged. Reviewed the complete dependency graph and upstream release changes; verified all changed artifacts against upstream PyPI URLs, SHA-256 hashes, and sizes. Hatchling builds both distributions successfully (metadata 2.5); its build pins and transitive dependency closure agree. Fixed the release-please marker, canonical Bedrock requirement spelling, new Ruff diagnostics, reporter integrity checksum, and inline-snapshot typing incompatibility without changing SDK runtime behavior or weakening global checks.
Validation: exact-head lint, build, Python 3.10/3.14, HTTPX2, policy, lock freshness, CodeQL, breaking-change and custom-code checks all pass. Additional local tests covered TLS, streaming, file handling, Bedrock, Azure, model parsing, large payloads, the AnyIO 4.10.0 floor, and Pydantic v1. Repository-pinned Pyright and full mypy pass. Independent reviewers completed two consecutive clean rounds on the main change and two more on the final typing fix. No consumer-breaking change found. Ready for normal protected merge.
## Current scope This PR now updates only the contributor PyJWT security constraint and lock entry to 2.14.0. The SDK runtime requirements, AnyIO minimum, and Python minimum stay unchanged. The AnyIO refresh is covered by maintenance PR openai#3988; the candidate-only policy exception was removed. The notes below are Dependabot's original batch description and include the AnyIO update that is no longer part of this PR. Bumps the python-security group with 2 updates in the / directory: [anyio](https://github.com/agronholm/anyio) and [pyjwt](https://github.com/jpadilla/pyjwt). Updates `anyio` from 4.12.1 to 4.14.2 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/agronholm/anyio/releases">anyio's releases</a>.</em></p> <blockquote> <h2>4.14.2</h2> <ul> <li>Changed <code>ByteReceiveStream.receive()</code> implementations to raise a <code>ValueError</code> when <code>max_bytes</code> is not a positive integer (<a href="https://redirect.github.com/agronholm/anyio/pull/1191">#1191</a>)</li> <li>Fixed <code>CapacityLimiter.total_tokens</code> rejecting <code>float("inf")</code> when the limiter was instantiated outside of an event loop. The adapter setter checked for infinity by identity (<code>value is math.inf</code>), so only the exact <code>math.inf</code> singleton was accepted, while every backend setter (using <code>math.isinf()</code>) accepts any positive infinity (<a href="https://redirect.github.com/agronholm/anyio/pull/1189">#1189</a>; PR by <a href="https://github.com/greymoth-jp"><code>@greymoth-jp</code></a>).</li> <li>Fixed <code>to_process.run_sync()</code> deadlocking when the worker function writes enough data to <code>sys.stderr</code> to fill the (undrained) pipe buffer. The worker process now redirects <code>sys.stderr</code> to <code>os.devnull</code> as well, matching the documented behavior</li> <li>Fixed <code>TLSStream.wrap()</code> matching an internationalized (unicode) host name against the peer certificate using IDNA 2003 (via the standard library) instead of IDNA 2008, which could cause the host name to be matched against the wrong certificate (<a href="https://redirect.github.com/agronholm/anyio/pull/1208">#1208</a>)</li> <li>Fixed <code>anyio.open_process()</code> (and <code>run_process()</code>) ignoring the <code>extra_groups</code> argument, as it mistakenly passed the value of the <code>group</code> argument instead (<a href="https://redirect.github.com/agronholm/anyio/pull/1209">#1209</a>)</li> <li>Fixed <code>CapacityLimiter.acquire_nowait()</code> and <code>CapacityLimiter.acquire_nowait_on_behalf_of()</code> raising <code>trio.WouldBlock</code> instead of <code>anyio.WouldBlock</code> on the <code>trio</code> backend when there are no tokens available (<a href="https://redirect.github.com/agronholm/anyio/pull/1218">#1218</a>)</li> <li>Fixed <code>CapacityLimiter</code> on the asyncio backend over-granting tokens (<code>borrowed_tokens</code> exceeding <code>total_tokens</code> and <code>available_tokens</code> going negative) when a non-blocking acquire was made in the window between a token being released and the notified waiter resuming. The freed token is now reserved for the woken waiter right away, so the non-blocking acquire correctly raises <code>WouldBlock</code> (<a href="https://redirect.github.com/agronholm/anyio/issues/1170">#1170</a>; PR by <a href="https://github.com/gaoflow"><code>@gaoflow</code></a>)</li> <li>Fixed unnecessary CPU spin when delivering cancellation from <code>CancelScope</code> on asyncio under certain conditions, including improper cancel scope nesting (<a href="https://redirect.github.com/agronholm/anyio/issues/1111">#1111</a>)</li> </ul> <h2>4.14.1</h2> <ul> <li>Fixed teardown of higher-scoped async fixtures failing on asyncio with <code>RuntimeError: Attempted to exit cancel scope in a different task than it was entered in</code> when an async test raise an outcome exception (e.g., <code>pytest.skip()</code>, <code>pytest.xfail()</code>, or <code>pytest.fail()</code>) (<a href="https://redirect.github.com/agronholm/anyio/issues/1179">#1179</a>; PR by <a href="https://github.com/EmmanuelNiyonshuti"><code>@EmmanuelNiyonshuti</code></a>)</li> <li>Fixed <code>CapacityLimiter.total_tokens</code> rejecting a value of <code>0</code> when the limiter was instantiated outside of an event loop, contradicting the documented behavior of allowing 0 total tokens (<a href="https://redirect.github.com/agronholm/anyio/pull/1183">#1183</a>; PR by <a href="https://github.com/nyxst4ck"><code>@nyxst4ck</code></a>)</li> </ul> <h2>4.14.0</h2> <ul> <li> <p>Added support for Python 3.15</p> </li> <li> <p>Added an asynchronous implementation of the <code>itertools</code> module (<a href="https://redirect.github.com/agronholm/anyio/issues/998">#998</a>; PR by <a href="https://github.com/11kkw"><code>@11kkw</code></a>)</p> </li> <li> <p>Added the <code>local_port</code> parameter to <code>connect_tcp()</code> to allow binding to a specific local port before connecting (<a href="https://redirect.github.com/agronholm/anyio/issues/1067">#1067</a>; PR by <a href="https://github.com/nullwiz"><code>@nullwiz</code></a>)</p> </li> <li> <p>Added support for custom capacity limiters in async path and file I/O functions and classes</p> </li> <li> <p>Added the <code>create_task()</code> task group method for easier asyncio migration (returns a <code>TaskHandle</code>) (<a href="https://redirect.github.com/agronholm/anyio/pull/1098">#1098</a>)</p> </li> <li> <p>Changed <code>TaskGroup.start_soon()</code> to return a <code>TaskHandle</code></p> </li> <li> <p>Added an option for <code>TaskGroup.start()</code> to return a <code>TaskHandle</code> (which then contains the start value in the <code>start_value</code> property)</p> </li> <li> <p>Added the <code>cancel()</code> convenience method to <code>TaskGroup</code> as a shortcut for cancelling the task group's cancel scope</p> </li> <li> <p>Improved the error message when a known backend is not installed to suggest the install command (<a href="https://redirect.github.com/agronholm/anyio/pull/1115">#1115</a>; PR by <a href="https://github.com/EmmanuelNiyonshuti"><code>@EmmanuelNiyonshuti</code></a>)</p> </li> <li> <p>Improved <code>anyio.Path</code> to preserve subclass types by returning <code>Self</code> in methods that return path objects (<a href="https://redirect.github.com/agronholm/anyio/issues/1130">#1130</a>; PR by <a href="https://github.com/EmmanuelNiyonshuti"><code>@EmmanuelNiyonshuti</code></a>)</p> </li> <li> <p>Changed the parameter type annotation in <code>anyio.Path.write_bytes()</code> to accept any <code>ReadableBuffer</code>, thus allowing it to accept <code>bytearray</code> and <code>memoryview</code> to match <code>pathlib.Path.write_bytes()</code> (<a href="https://redirect.github.com/agronholm/anyio/issues/1135">#1135</a>; PR by <a href="https://github.com/SAY-5"><code>@SAY-5</code></a>)</p> </li> <li> <p>Changed several type annotations to only accept callables returning coroutine-like objects instead of arbitrary awaitables:</p> <ul> <li><code>TaskGroup.start_soon()</code></li> <li><code>TaskGroup.start()</code></li> <li><code>anyio.from_thread.run()</code></li> </ul> <p>This reverts an earlier change from v3.7.0 which was made in error. (<a href="https://redirect.github.com/agronholm/anyio/pull/1153">#1153</a>)</p> </li> <li> <p>Changed <code>anyio.run</code> to support callables returning arbitrary awaitables at runtime on all backends. Previously, this only worked on asyncio (<a href="https://redirect.github.com/agronholm/anyio/pull/1171">#1171</a>; PR by <a href="https://github.com/gschaffner"><code>@gschaffner</code></a>)</p> </li> <li> <p>Changed several classes (and their subclasses) to have <code>__slots__</code> (with <code>__weakref__</code>):</p> <ul> <li><code>anyio.CancelScope</code></li> </ul> </li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/agronholm/anyio/commit/c384f99687c64c59ed8a11c3a0f11a2d57daff71"><code>c384f99</code></a> Bumped up the version</li> <li><a href="https://github.com/agronholm/anyio/commit/dbba29d1ade7936f18fb71ba24aa92978673482a"><code>dbba29d</code></a> Fixed 100% CPU spin on cancel scope misuse (<a href="https://redirect.github.com/agronholm/anyio/issues/1217">#1217</a>)</li> <li><a href="https://github.com/agronholm/anyio/commit/6bbc6c33caabc13af5bc4256f745027cf8d5d7b8"><code>6bbc6c3</code></a> Fix CapacityLimiter over-granting tokens on asyncio (<a href="https://redirect.github.com/agronholm/anyio/issues/1172">#1172</a>)</li> <li><a href="https://github.com/agronholm/anyio/commit/6f82b2537cbbe98f3df3f295499056ab7de0b15b"><code>6f82b25</code></a> Refactored TestTLSStream.test_receive_invalid_max_bytes() to be less flaky</li> <li><a href="https://github.com/agronholm/anyio/commit/be24b0414f67f604bcbdd5ea3bcc56ab920d872e"><code>be24b04</code></a> Relaxed timeouts to fix test flakiness</li> <li><a href="https://github.com/agronholm/anyio/commit/81135065749b4f60c06619b9caaf0a11871c1ddf"><code>8113506</code></a> Fix test flakiness caused by slow callback duration logging</li> <li><a href="https://github.com/agronholm/anyio/commit/1e988b617b69588e33fecb75e36a9837245f562f"><code>1e988b6</code></a> Fixed CapacityLimiter raising trio.WouldBlock instead of anyio.WouldBlock (<a href="https://redirect.github.com/agronholm/anyio/issues/1">#1</a>...</li> <li><a href="https://github.com/agronholm/anyio/commit/44713f345cd29dd4e7d76553c134543a1296cc62"><code>44713f3</code></a> Pin setup-uv to a commit sha across downstream jobs (<a href="https://redirect.github.com/agronholm/anyio/issues/1213">#1213</a>)</li> <li><a href="https://github.com/agronholm/anyio/commit/f1b7301c8264b0d2e8d24a5788fd29e93dea4040"><code>f1b7301</code></a> Fixed stderr writes in a worker subprocess causing a deadlock (<a href="https://redirect.github.com/agronholm/anyio/issues/1207">#1207</a>)</li> <li><a href="https://github.com/agronholm/anyio/commit/212be93c2cf2c841e753e95e5e2c543ee7feca90"><code>212be93</code></a> Fix flaky test_tcp_listener_same_port using a hardcoded port (<a href="https://redirect.github.com/agronholm/anyio/issues/1206">#1206</a>)</li> <li>Additional commits viewable in <a href="https://github.com/agronholm/anyio/compare/4.12.1...4.14.2">compare view</a></li> </ul> </details> <br /> Updates `pyjwt` from 2.13.0 to 2.14.0 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/jpadilla/pyjwt/releases">pyjwt's releases</a>.</em></p> <blockquote> <h2>2.14.0</h2> <p>See the <a href="https://github.com/jpadilla/pyjwt/blob/2.14.0/CHANGELOG.rst">2.14.0 changelog</a> for the complete release details and related security advisories.</p> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/jpadilla/pyjwt/blob/master/CHANGELOG.rst">pyjwt's changelog</a>.</em></p> <blockquote> <h2><code>v2.14.0 <https://github.com/jpadilla/pyjwt/compare/2.13.0...2.14.0></code>__</h2> <p>Security</p> <pre><code> - Harden HMAC key validation against public-key material supplied as JWK, JWKS, array, encoded, BOM-prefixed, DER, or PEM input. See `GHSA-r6x4-923q-g947 <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-r6x4-923q-g947>`__, `GHSA-ffc3-869f-jxw9 <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-ffc3-869f-jxw9>`__, `GHSA-p4g4-x82p-q773 <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-p4g4-x82p-q773>`__, and `GHSA-w2cx-738m-mc7w <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-w2cx-738m-mc7w>`__. - Reject automatic redirects when ``PyJWKClient`` fetches a JWKS, preventing redirected destinations from being treated as trusted key sources. See `GHSA-9v7f-9g4p-ffgj <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-9v7f-9g4p-ffgj>`__. - Limit repeated JWKS refreshes caused by unknown key IDs while preserving normal key-rotation behavior. See `GHSA-2gx3-rcp4-g85q <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-2gx3-rcp4-g85q>`__. - Handle deeply nested and malformed JWS/JWK input without uncaught recursion errors or whole-set parsing failures. See `GHSA-8wjv-2p76-3863 <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-8wjv-2p76-3863>`__ and `GHSA-w6j9-cwv2-h6wq <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-w6j9-cwv2-h6wq>`__. - Enforce compact JWS encoding rules during decoding. See `GHSA-hxm8-2xgr-2p9m <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-hxm8-2xgr-2p9m>`__. - Reject detached-payload arguments for attached JWS inputs. Thanks to `@xclow3n <https://github.com/xclow3n>`__ for reporting this behavior; fixed in commit `37b54877 <https://github.com/jpadilla/pyjwt/commit/37b54877bf7bea67e8149130e96929e3ec798122>`__. <p>Fixed</p> <pre><code> - Apply HMAC key validation consistently when keys are loaded through ``PyJWK`` and ``PyJWKClient``. See `GHSA-pxh4-856f-4h89 &lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-pxh4-856f-4h89&gt;`__. - Reject empty HMAC keys when represented as JWKs. See `GHSA-pxh4-856f-4h89 &lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-pxh4-856f-4h89&gt;`__. </code></pre> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="jpadilla/pyjwt@c6fe464b356ff4b1ebc9ba62172d331a40aa27df"><code>c6fe464</code></a> release: prepare v2.14.0</li> <li><a href="jpadilla/pyjwt@f5413029ae7a2e31b1367b5303ea86a2f54ccf42"><code>f541302</code></a> style: apply Ruff formatting</li> <li><a href="jpadilla/pyjwt@801cd128528c62d9b23fcd161d1a2e1c17982f95"><code>801cd12</code></a> fix: reject public JWK container HMAC keys</li> <li><a href="jpadilla/pyjwt@af8181ca0bec5e6b372fbba9afbe23702b787ceb"><code>af8181c</code></a> fix: reject empty HMAC keys from JWKs</li> <li><a href="jpadilla/pyjwt@ba4853a75fb9676362da17f67d0f64bd18afd4e1"><code>ba4853a</code></a> Throttle repeated PyJWKClient refreshes</li> <li><a href="jpadilla/pyjwt@2798504fa2663364573cf2d1043d8d7fef389499"><code>2798504</code></a> fix: reject DER public keys as HMAC secrets</li> <li><a href="jpadilla/pyjwt@8b4e233a22206b34ec1186e912e75c0b2396ac07"><code>8b4e233</code></a> fix: reject loader-accepted PEM variants</li> <li><a href="jpadilla/pyjwt@1f8180a211256dfe5cf32294b6753f554a5a4258"><code>1f8180a</code></a> fix: format JWS tests</li> <li><a href="jpadilla/pyjwt@cff1ac55fe5f1096fd05295b269fce053ee290ab"><code>cff1ac5</code></a> Fix redirect handler return annotation</li> <li><a href="jpadilla/pyjwt@0a795b8e1f6ef08f634aa7086fc41cc6d5ce3e56"><code>0a795b8</code></a> Reject redirects in PyJWKClient fetches</li> <li>Additional commits viewable in <a href="jpadilla/pyjwt@2.13.0...2.14.0">compare view</a></li> </ul> </details> <br /></code></pre> <!-- codex-thread: 01a12104-2d95-7572-8826-2b1c2f51fff0 --> --------- Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Marcus Wood <marcuswood@openai.com> Co-authored-by: Justin Beckwith <jbeckwith@openai.com>
Bumps the python-maintenance group with 14 updates in the / directory:
2.12.02.13.14.15.04.16.04.12.14.15.10.16.00.17.00.5.30.5.61.42.971.43.1062.7.02.8.09.0.39.1.10.14.70.16.90.31.10.35.41.25.11.25.30.31.00.34.01.27.01.32.42026.6.1.192026.9.21.13Updates
httpx2from 2.12.0 to 2.13.1Release notes
Sourced from httpx2's releases.
... (truncated)
Changelog
Sourced from httpx2's changelog.
Commits
d91c9f4Correct the upcoming release version to 2.13.1 (#1228)62a607dPrepare version 2.14.0 (#1227)df9783dRespect file cursor positions when calculating raw content length (#1214)04d152bdocs: correct stale URL.query example (#1222)f295185Prepare version 2.13.0 (#1208)8f215b5Use portable links in API docstrings (#1202)36d636aGrouphttpx2.__all__exports by source module (#1188)f1064aaBump the python-packages group across 1 directory with 11 updates (#1179)bc27137Update uv-dynamic-versioning requirement from >=0.14.0 to >=0.14.1 (#1180)62e0827Restore--no-verifyCLI flag (#1186)Updates
typing-extensionsfrom 4.15.0 to 4.16.0Release notes
Sourced from typing-extensions's releases.
... (truncated)
Changelog
Sourced from typing-extensions's changelog.
Commits
f29cd28Prepare relase 4.16.0 (#774)4317461Bump version to 4.16.0rc2.dev (#772)4f71098Prepare release 4.16.0rc2 (#771)37ed08aRemove use ofasyncio.coroutines.iscoroutinefunction()(#769)8dcc559ImproveTypedDictdocumentation (#770)224f8d5Post-release followups for 3.16.0rc1 (#767)777de3ePrepare release 4.16.0rc1 (#766)890be90Type variable tuple variance (#741)0e05458Pin SQLAlchemy third-party tests to pytest==9.0.3 (#765)d277746docs: add version compatibility table (#733)Updates
anyiofrom 4.12.1 to 4.15.1Release notes
Sourced from anyio's releases.
... (truncated)
Commits
ffcd154Bumped up the version0ecf5edAdded a workaround for third party code accessing unimported submodules (#1309)9283662Bumped up the versiond137692Improved the instructions for AI agents033fc52Shield TemporaryDirectory cleanup from cancellation (#1304)942e9a6[pre-commit.ci] pre-commit autoupdate (#1305)b825c3bFixed pyproject.toml changes not triggering the test suite9727dc5Fixed start inconsistencies between trio and asyncio (#1198)b05fe6dFixed wrong type in move_on_after (#1297)44d0c93Fixed asyncio task group coroutine cleanup (#1275)Updates
jiterfrom 0.16.0 to 0.17.0Commits
2b5ec63release: 0.17.0 (#294)6881310Return CPython's singletons for empty and single-character strings (#293)819dc92Lock the Python string cache once per parse (#289)e9c1cabAddJsonValueScratch, reusable stacks for parsing values (#292)01f5c8edrop Python 3.9, update PGO workflows (#288)9c6d8e9use digit run to determine float or integer decode (#286)9e7d52fx86_64 SIMD string scanning and int decoding (#279)1da1e5cBuild containers on shared stacks, allocate them exactly once (#269)b0a501eDisable ASLR for the CodSpeed bench run (#284)e8e4297Benchmark script summary and validation, LTO for release builds (#282)Updates
sounddevicefrom 0.5.3 to 0.5.6Release notes
Sourced from sounddevice's releases.
Changelog
Sourced from sounddevice's changelog.
Commits
bd3f0dfRelease 0.5.69e55e73Fix architecture detection on Windows ARM64 (#631)e8e7befBump actions/setup-python from 6 to 7dfa004dGitHub Actions: Upgrade from ubuntu-22.04 to ubuntu-24.04 (#634)950d205update linkfd24bd3Bump actions/checkout from 6 to 788de286CI: bump Python versions0f16231Bump idna from 3.11 to 3.15 in the uv group across 1 directory2634256Bump urllib3 from 2.6.3 to 2.7.0 in the uv group across 1 directory715d988Bump actions/download-artifact from 7 to 8Updates
botocorefrom 1.42.97 to 1.43.106Commits
ca596c7Merge branch 'release-1.43.106'1808528Bumping version to 1.43.1063d316f0Update endpoints model053554bUpdate to latest modelse9bb16cMerge branch 'release-1.43.105'21f2f87Merge branch 'release-1.43.105' into develop8be13b2Bumping version to 1.43.1059931e97Update to latest models66a4744Merge branch 'release-1.43.104'358f8eeMerge branch 'release-1.43.104' into developUpdates
urllib3from 2.7.0 to 2.8.0Release notes
Sourced from urllib3's releases.
... (truncated)
Changelog
Sourced from urllib3's changelog.
... (truncated)
Commits
b1d30abRelease 2.8.09016d7eSkiptest_read_chunked_with_trailing_data_does_not_hangfor brotlicffi (#5258)9101f58Fixnox -s docswarning (#5256)cd770b0Merge commit from forkea2ad7bMerge commit from fork0716e31Fix loading unencrypted client keys with a password in pyOpenSSL (#5255)43c68c8Test pickling ofInvalidChunkLength(#5247)308b279Share security policy between GitHub and Read the Docs (#5253)53fa073Add policy on duplicate pull requests (#5252)5f2a6a8Assert on the ALPN extension in test_tunnel_sets_http_11_alpn (#5232)Updates
pytestfrom 9.0.3 to 9.1.1Release notes
Sourced from pytest's releases.
... (truncated)
Commits
cf470ecPrepare release version 9.1.1e0c8ce6Merge pull request #14625 from pytest-dev/patchback/backports/9.1.x/a07c31a97...1b82d16Merge pull request #14624 from pytest-dev/patchback/backports/9.1.x/b375b79ec...501c4bcMerge pull request #14596 from bluetech/doc-classmethodb61f588Merge pull request #14622 from chrisburr/fix-14608-initial-conftest-test-subdir9a567e0[automated] Update plugin list (#14617) (#14618)ef8b299Merge pull request #14620 from pytest-dev/patchback/backports/9.1.x/680f9f3ed...66abd07Merge pull request #14220 from bysiber/fix-stale-iexp-raisesgroup79fbf93Merge pull request #14612 from pytest-dev/patchback/backports/9.1.x/974ed48b6...0d312ebMerge pull request #14611 from bluetech/parametrize-argvalues-typingUpdates
rufffrom 0.14.7 to 0.16.9Release notes
Sourced from ruff's releases.
... (truncated)
Changelog
Sourced from ruff's changelog.