Skip to content

chore(deps): bump the uv group across 10 directories with 6 updates - #1013

Merged
ioannisj merged 1 commit into
mainfrom
dependabot/uv/examples/example-ai-crewai/uv-8b76969db4
Oct 6, 2026
Merged

ioannisj merged 1 commit into
mainfrom
dependabot/uv/examples/example-ai-crewai/uv-8b76969db4

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 6, 2026

Copy link
Copy Markdown
Contributor

Bumps the uv group with 3 updates in the /examples/example-ai-crewai directory: fsspec, multidict and oauthlib.
Bumps the uv group with 3 updates in the /examples/example-ai-dspy directory: fsspec, multidict and mako.
Bumps the uv group with 1 update in the /examples/example-ai-instructor directory: multidict.
Bumps the uv group with 1 update in the /examples/example-ai-langchain directory: langgraph-sdk.
Bumps the uv group with 1 update in the /examples/example-ai-langgraph directory: langgraph-sdk.
Bumps the uv group with 2 updates in the /examples/example-ai-litellm directory: fsspec and multidict.
Bumps the uv group with 2 updates in the /examples/example-ai-llamaindex directory: fsspec and multidict.
Bumps the uv group with 2 updates in the /examples/example-ai-pydantic-ai directory: fsspec and multidict.
Bumps the uv group with 2 updates in the /examples/example-ai-semantic-kernel directory: multidict and werkzeug.
Bumps the uv group with 1 update in the /examples/example-ai-smolagents directory: fsspec.

Updates fsspec from 2026.3.0 to 2026.6.0

Commits
  • a245700 changelog (#2049)
  • 652325d Fix async cat ranges on error (#2045)
  • 073aac8 Forward kwargs from cat_ranges to cat_file (#2044)
  • 2818611 FTP: preserve filenames containing whitespace in _mlsd2 (#2043)
  • c879384 Prevent attribute error by checking for 'forced' attribute before flushing ca...
  • 71b8a6b Reflect async _walk correctly (#2040)
  • 5eec9f9 Fix: Omit threading.get_ident() from cache token for async implementations ...
  • 8643878 Small safety improvements (#2039)
  • a1c16ab Honour simple_templates everywhere in referenceFS (#2029)
  • 85facaa Fix infinite recursion in expand_path when resolving paths with glob magic ch...
  • Additional commits viewable in compare view

Updates multidict from 6.7.1 to 6.9.1

Release notes

Sourced from multidict's releases.

6.9.1

Bug fixes

  • Fixed the C extension reading freed memory on free-threaded builds when a list handed to :py:meth:~multidict.MultiDict.update, :py:meth:~multidict.MultiDict.extend, :py:meth:~multidict.MultiDict.merge or the :py:class:~multidict.MultiDict and :py:class:~multidict.CIMultiDict constructors, a [key, value] item inside any iterable handed to them, or a list tested with in against :py:meth:~multidict.MultiDict.items, is changed by another thread; a call that catches the list shrinking under it now raises :py:exc:RuntimeError -- by :user:rodrigobnogueira.

    Related issues and pull requests on GitHub: #1437.

  • Fixed a data race on the free-threaded build where a retired hash table's reader count used relaxed atomics, letting a lock-free get()/getone()/ __getitem__() read race a concurrent free of that table. The reader-exit decrement and the drain's free check now use release/acquire ordering instead -- by :user:asvetlov.

    Related issues and pull requests on GitHub: #1481.

  • Fixed a free-threaded build bug where two threads calling update(), merge(), or __setitem__() on the same key at the same time could lose the key entirely instead of just racing on which value wins. A decref of the replaced value could transiently suspend the writer's critical section, letting a second writer for the same key observe the first writer's in-progress entry as absent and, once both settled, mistake it for a stale duplicate and delete it. Every such decref is now deferred until the writer has released its critical section, so the window can no longer open. setdefault() had an unrelated instance of the same blind spot (it could insert a duplicate rather than recognizing an in-flight key), fixed alongside it -- by :user:asvetlov.

    Related issues and pull requests on GitHub: #1483.

  • Fixed a free-threaded build bug where getall() and the items()/ keys()/values() equality path could raise KeyError or report a present, never-deleted key as missing. A concurrent update()/extend()/ __setitem__() call can have its critical section transiently suspended (a decref triggering a blocking allocator call) while an entry is marked as part of its own bookkeeping; a reader landing in that window used to treat the mark as "not found" instead of "still there, in flight" -- by :user:asvetlov.

    Related issues and pull requests on GitHub:

... (truncated)

Changelog

Sourced from multidict's changelog.

6.9.1

(2026-09-21)

Bug fixes

  • Fixed the C extension reading freed memory on free-threaded builds when a list handed to :py:meth:~multidict.MultiDict.update, :py:meth:~multidict.MultiDict.extend, :py:meth:~multidict.MultiDict.merge or the :py:class:~multidict.MultiDict and :py:class:~multidict.CIMultiDict constructors, a [key, value] item inside any iterable handed to them, or a list tested with in against :py:meth:~multidict.MultiDict.items, is changed by another thread; a call that catches the list shrinking under it now raises :py:exc:RuntimeError -- by :user:rodrigobnogueira.

    Related issues and pull requests on GitHub: :issue:1437.

  • Fixed a data race on the free-threaded build where a retired hash table's reader count used relaxed atomics, letting a lock-free get()/getone()/ __getitem__() read race a concurrent free of that table. The reader-exit decrement and the drain's free check now use release/acquire ordering instead -- by :user:asvetlov.

    Related issues and pull requests on GitHub: :issue:1481.

  • Fixed a free-threaded build bug where two threads calling update(), merge(), or __setitem__() on the same key at the same time could lose the key entirely instead of just racing on which value wins. A decref of the replaced value could transiently suspend the writer's critical section, letting a second writer for the same key observe the first writer's in-progress entry as absent and, once both settled, mistake it for a stale duplicate and delete it. Every such decref is now deferred until the writer has released its critical section, so the window can no longer open. setdefault() had an unrelated instance of the same blind spot (it could insert a duplicate rather than recognizing an in-flight key), fixed alongside it -- by :user:asvetlov.

    Related issues and pull requests on GitHub: :issue:1483.

  • Fixed a free-threaded build bug where getall() and the items()/ keys()/values() equality path could raise KeyError or report a present, never-deleted key as missing. A concurrent update()/extend()/ __setitem__() call can have its critical section transiently suspended (a decref triggering a blocking allocator call) while an entry is marked as

... (truncated)

Commits
  • 0a1770c Release 6.9.1 (#1504)
  • d220522 Upload release assets one at a time to avoid the secondary rate limit (#1503)
  • 30cd596 Stop a GIL-releasing del from segfaulting the standard C extension build ...
  • d1c331a Recheck the reader gate after taking the retired list (#1502)
  • b37f07c Allocate deferred decrefs in fixed-size blocks (#1501)
  • 563f667 Run CodSpeed benchmarks on Python 3.14 and loop the smallest ones (#1498)
  • 157c87c Cancel superseded CI runs on pull requests (#1500)
  • d43adfe Drop -I from the ASan test command so PYTHONMALLOC takes effect (#1499)
  • 2a68472 Stop items() iteration from reading a freed entry in CIMultiDict (#1496)
  • cd528d6 Rename GHSA-54p9-h82j-f925 changelog fragment to the merged commit (#1495)
  • Additional commits viewable in compare view

Updates oauthlib from 3.3.1 to 4.0.0

Release notes

Sourced from oauthlib's releases.

4.0.0

Introduction

The release 4.0.0 defines the foundation that enables AI contributions and will improve the maintenance of oauthlib by using AI agents, skills, code for both contributors and maintainers. It includes devcontainer, skills and cleanup of instructions.

What's Changed

Important: this release contains 2 breaking changes. See CHANGELOG.rst for details:

  • Removed JSONP support from token revocation endpoint (#951)
  • Client authentication validation reorganized across grants (#919, #920): the grant_type parameter is now validated before client authentication.

New Contributors

Full Changelog: oauthlib/oauthlib@v3.3.1...v4.0.0

Changelog

Sourced from oauthlib's changelog.

4.0.0 (2026-09-28):

OAuth2.0 Provider:

  • Breaking: #951: Removed JSONP support from token revocation endpoint. JSONP has been superseded by CORS for cross-origin requests. The enable_jsonp parameter has been removed from RevocationEndpoint and the callback parameter has been removed from prepare_token_revocation_request.
  • Breaking: #919, #920: Fixed DeviceCodeGrant.validate_token_request trying to authenticate public clients. Client authentication validation has been reorganized and is now shared across AuthorizationCodeGrant, DeviceCodeGrant, RefreshTokenGrant and ResourceOwnerPasswordCredentialsGrant: the grant_type parameter is validated before client authentication, so requests missing grant_type now return 400 invalid_request instead of 401 invalid_client.
  • #963: Improved PKCE code comparison

Misc:

  • #904: Stop installing examples into site-packages.
  • #930: Add devcontainer, Add Python3.14, Python3.14t.
  • #931: Fix ruff checks about unused variables.
  • #932: Dropped EOL Python 3.8 from CI.
  • #934: Pre-commit hooks autoupdate.
  • #938: Fix typos discovered by typos.
  • Add OAuthLib Maintainer agent for automated issue/PR triage and release management.
Commits
  • 145a9a4 Release 4.0.0: clarify changelog breaking changes and reformat entries
  • c8344d6 Update CHANGELOG.rst
  • e172830 Release 4.0.0: bump version to 4.0.0 and update changelog
  • 40b0ab5 Merge pull request #963 from oauthlib/ft/pkcecode
  • 1b68cea Merge pull request #920 from hekhuisk/validate-client-authentication
  • c951a1d Organized validate_client functions for all grant to avoid mistake in grnat i...
  • 74664d3 Improve PKCE code comparison
  • 9859b05 Merge pull request #950 from oauthlib/feature/3.4.0-maintainer-agent
  • 9bf9b97 Merge branch 'master' into feature/3.4.0-maintainer-agent
  • 1ba7429 Clarify agent instructions
  • Additional commits viewable in compare view

Updates fsspec from 2026.2.0 to 2026.6.0

Commits
  • a245700 changelog (#2049)
  • 652325d Fix async cat ranges on error (#2045)
  • 073aac8 Forward kwargs from cat_ranges to cat_file (#2044)
  • 2818611 FTP: preserve filenames containing whitespace in _mlsd2 (#2043)
  • c879384 Prevent attribute error by checking for 'forced' attribute before flushing ca...
  • 71b8a6b Reflect async _walk correctly (#2040)
  • 5eec9f9 Fix: Omit threading.get_ident() from cache token for async implementations ...
  • 8643878 Small safety improvements (#2039)
  • a1c16ab Honour simple_templates everywhere in referenceFS (#2029)
  • 85facaa Fix infinite recursion in expand_path when resolving paths with glob magic ch...
  • Additional commits viewable in compare view

Updates multidict from 6.7.1 to 6.9.1

Release notes

Sourced from multidict's releases.

6.9.1

Bug fixes

  • Fixed the C extension reading freed memory on free-threaded builds when a list handed to :py:meth:~multidict.MultiDict.update, :py:meth:~multidict.MultiDict.extend, :py:meth:~multidict.MultiDict.merge or the :py:class:~multidict.MultiDict and :py:class:~multidict.CIMultiDict constructors, a [key, value] item inside any iterable handed to them, or a list tested with in against :py:meth:~multidict.MultiDict.items, is changed by another thread; a call that catches the list shrinking under it now raises :py:exc:RuntimeError -- by :user:rodrigobnogueira.

    Related issues and pull requests on GitHub: #1437.

  • Fixed a data race on the free-threaded build where a retired hash table's reader count used relaxed atomics, letting a lock-free get()/getone()/ __getitem__() read race a concurrent free of that table. The reader-exit decrement and the drain's free check now use release/acquire ordering instead -- by :user:asvetlov.

    Related issues and pull requests on GitHub: #1481.

  • Fixed a free-threaded build bug where two threads calling update(), merge(), or __setitem__() on the same key at the same time could lose the key entirely instead of just racing on which value wins. A decref of the replaced value could transiently suspend the writer's critical section, letting a second writer for the same key observe the first writer's in-progress entry as absent and, once both settled, mistake it for a stale duplicate and delete it. Every such decref is now deferred until the writer has released its critical section, so the window can no longer open. setdefault() had an unrelated instance of the same blind spot (it could insert a duplicate rather than recognizing an in-flight key), fixed alongside it -- by :user:asvetlov.

    Related issues and pull requests on GitHub: #1483.

  • Fixed a free-threaded build bug where getall() and the items()/ keys()/values() equality path could raise KeyError or report a present, never-deleted key as missing. A concurrent update()/extend()/ __setitem__() call can have its critical section transiently suspended (a decref triggering a blocking allocator call) while an entry is marked as part of its own bookkeeping; a reader landing in that window used to treat the mark as "not found" instead of "still there, in flight" -- by :user:asvetlov.

    Related issues and pull requests on GitHub:

... (truncated)

Changelog

Sourced from multidict's changelog.

6.9.1

(2026-09-21)

Bug fixes

  • Fixed the C extension reading freed memory on free-threaded builds when a list handed to :py:meth:~multidict.MultiDict.update, :py:meth:~multidict.MultiDict.extend, :py:meth:~multidict.MultiDict.merge or the :py:class:~multidict.MultiDict and :py:class:~multidict.CIMultiDict constructors, a [key, value] item inside any iterable handed to them, or a list tested with in against :py:meth:~multidict.MultiDict.items, is changed by another thread; a call that catches the list shrinking under it now raises :py:exc:RuntimeError -- by :user:rodrigobnogueira.

    Related issues and pull requests on GitHub: :issue:1437.

  • Fixed a data race on the free-threaded build where a retired hash table's reader count used relaxed atomics, letting a lock-free get()/getone()/ __getitem__() read race a concurrent free of that table. The reader-exit decrement and the drain's free check now use release/acquire ordering instead -- by :user:asvetlov.

    Related issues and pull requests on GitHub: :issue:1481.

  • Fixed a free-threaded build bug where two threads calling update(), merge(), or __setitem__() on the same key at the same time could lose the key entirely instead of just racing on which value wins. A decref of the replaced value could transiently suspend the writer's critical section, letting a second writer for the same key observe the first writer's in-progress entry as absent and, once both settled, mistake it for a stale duplicate and delete it. Every such decref is now deferred until the writer has released its critical section, so the window can no longer open. setdefault() had an unrelated instance of the same blind spot (it could insert a duplicate rather than recognizing an in-flight key), fixed alongside it -- by :user:asvetlov.

    Related issues and pull requests on GitHub: :issue:1483.

  • Fixed a free-threaded build bug where getall() and the items()/ keys()/values() equality path could raise KeyError or report a present, never-deleted key as missing. A concurrent update()/extend()/ __setitem__() call can have its critical section transiently suspended (a decref triggering a blocking allocator call) while an entry is marked as

... (truncated)

Commits
  • 0a1770c Release 6.9.1 (#1504)
  • d220522 Upload release assets one at a time to avoid the secondary rate limit (#1503)
  • 30cd596 Stop a GIL-releasing del from segfaulting the standard C extension build ...
  • d1c331a Recheck the reader gate after taking the retired list (#1502)
  • b37f07c Allocate deferred decrefs in fixed-size blocks (#1501)
  • 563f667 Run CodSpeed benchmarks on Python 3.14 and loop the smallest ones (#1498)
  • 157c87c Cancel superseded CI runs on pull requests (#1500)
  • d43adfe Drop -I from the ASan test command so PYTHONMALLOC takes effect (#1499)
  • 2a68472 Stop items() iteration from reading a freed entry in CIMultiDict (#1496)
  • cd528d6 Rename GHSA-54p9-h82j-f925 changelog fragment to the merged commit (#1495)
  • Additional commits viewable in compare view

Updates mako from 1.3.12 to 1.4.2

Release notes

Sourced from mako's releases.

1.4.2

Released: Tue Sep 22 2026

bug

  • [bug] [tests] Adjusted the test suite to accommodate for a change in Pygments 2.21.0 where the HtmlFormatter now renders " and ' characters literally rather than as HTML entities, which caused failures in tests that assert against the rendered output of html_error_template().

    References: #440

  • [bug] [template] Fixed issue in TemplateLookup where a URI beginning with a drive designator (e.g. C:/../../secret.txt) could bypass the directory traversal check on Windows, allowing reads of arbitrary files outside of the template directory. The check in Template normalized the URI using os.path, which on Windows is ntpath; as ntpath splits the drive designator off and treats the remainder as rooted, the .. segments were absorbed before the check could inspect them. Normalization is now performed with posixpath, which is the same module used by TemplateLookup.get_template() to resolve the URI to a file.

    References: #441

1.4.1

Released: Wed Aug 5 2026

bug

  • [bug] [installation] Fixed issue in the 1.4.0 packaging where the repository's internal tools/ directory was detected by setuptools package discovery and installed as a top-level tools package into site-packages, shadowing unrelated tools packages belonging to other applications. Package discovery is now limited to the mako package explicitly.

    References: #438

1.4.0

Released: Tue Aug 4 2026

changed

  • [changed] [examples] The examples/bench folder has been removed as it used mostly

... (truncated)

Commits

Updates multidict from 6.7.1 to 6.9.1

Release notes

Sourced from multidict's releases.

6.9.1

Bug fixes

  • Fixed the C extension reading freed memory on free-threaded builds when a list handed to :py:meth:~multidict.MultiDict.update, :py:meth:~multidict.MultiDict.extend, :py:meth:~multidict.MultiDict.merge or the :py:class:~multidict.MultiDict and :py:class:~multidict.CIMultiDict constructors, a [key, value] item inside any iterable handed to them, or a list tested with in against :py:meth:~multidict.MultiDict.items, is changed by another thread; a call that catches the list shrinking under it now raises :py:exc:RuntimeError -- by :user:rodrigobnogueira.

    Related issues and pull requests on GitHub: #1437.

  • Fixed a data race on the free-threaded build where a retired hash table's reader count used relaxed atomics, letting a lock-free get()/getone()/ __getitem__() read race a concurrent free of that table. The reader-exit decrement and the drain's free check now use release/acquire ordering instead -- by :user:asvetlov.

    Related issues and pull requests on GitHub: #1481.

  • Fixed a free-threaded build bug where two threads calling update(), merge(), or __setitem__() on the same key at the same time could lose the key entirely instead of just racing on which value wins. A decref of the replaced value could transiently suspend the writer's critical section, letting a second writer for the same key observe the first writer's in-progress entry as absent and, once both settled, mistake it for a stale duplicate and delete it. Every such decref is now deferred until the writer has released its critical section, so the window can no longer open. setdefault() had an unrelated instance of the same blind spot (it could insert a duplicate rather than recognizing an in-flight key), fixed alongside it -- by :user:asvetlov.

    Related issues and pull requests on GitHub: #1483.

  • Fixed a free-threaded build bug where getall() and the items()/ keys()/values() equality path could raise KeyError or report a present, never-deleted key as missing. A concurrent update()/extend()/ __setitem__() call can have its critical section transiently suspended (a decref triggering a blocking allocator call) while an entry is marked as part of its own bookkeeping; a reader landing in that window used to treat the mark as "not found" instead of "still there, in flight" -- by :user:asvetlov.

    Related issues and pull requests on GitHub:

... (truncated)

Changelog

Sourced from multidict's changelog.

6.9.1

(2026-09-21)

Bug fixes

  • Fixed the C extension reading freed memory on free-threaded builds when a list handed to :py:meth:~multidict.MultiDict.update, :py:meth:~multidict.MultiDict.extend, :py:meth:~multidict.MultiDict.merge or the :py:class:~multidict.MultiDict and :py:class:~multidict.CIMultiDict constructors, a [key, value] item inside any iterable handed to them, or a list tested with in against :py:meth:~multidict.MultiDict.items, is changed by another thread; a call that catches the list shrinking under it now raises :py:exc:RuntimeError -- by :user:rodrigobnogueira.

    Related issues and pull requests on GitHub: :issue:1437.

  • Fixed a data race on the free-threaded build where a retired hash table's reader count used relaxed atomics, letting a lock-free get()/getone()/ __getitem__() read race a concurrent free of that table. The reader-exit decrement and the drain's free check now use release/acquire ordering instead -- by :user:asvetlov.

    Related issues and pull requests on GitHub: :issue:1481.

  • Fixed a free-threaded build bug where two threads calling update(), merge(), or __setitem__() on the same key at the same time could lose the key entirely instead of just racing on which value wins. A decref of the replaced value could transiently suspend the writer's critical section, letting a second writer for the same key observe the first writer's in-progress entry as absent and, once both settled, mistake it for a stale duplicate and delete it. Every such decref is now deferred until the writer has released its critical section, so the window can no longer open. setdefault() had an unrelated instance of the same blind spot (it could insert a duplicate rather than recognizing an in-flight key), fixed alongside it -- by :user:asvetlov.

    Related issues and pull requests on GitHub: :issue:1483.

  • Fixed a free-threaded build bug where getall() and the items()/ keys()/values() equality path could raise KeyError or report a present, never-deleted key as missing. A concurrent update()/extend()/ __setitem__() call can have its critical section transiently suspended (a decref triggering a blocking allocator call) while an entry is marked as

... (truncated)

Commits
  • 0a1770c Release 6.9.1 (#1504)
  • d220522 Upload release assets one at a time to avoid the secondary rate limit (#1503)
  • 30cd596 Stop a GIL-releasing del from segfaulting the standard C extension build ...
  • d1c331a Recheck the reader gate after taking the retired list (#1502)
  • b37f07c Allocate deferred decrefs in fixed-size blocks (#1501)
  • 563f667 Run CodSpeed benchmarks on Python 3.14 and loop the smallest ones (#1498)
  • 157c87c Cancel superseded CI runs on pull requests (#1500)
  • d43adfe Drop -I from the ASan test command so PYTHONMALLOC takes effect (#1499)
  • 2a68472 Stop items() iteration from reading a freed entry in CIMultiDict (#1496)
  • cd528d6 Rename GHSA-54p9-h82j-f925 changelog fragment to the merged commit (#1495)
  • Additional commits viewable in compare view

Updates langgraph-sdk from 0.4.2 to 0.4.4

Release notes

Sourced from langgraph-sdk's releases.

langgraph-sdk==0.4.4

Changes since sdk==0.4.3

  • release(sdk-py): 0.4.4 (#8738)
  • Merge commit from fork
  • feat: route LangSmith traces from thread streams (#8723)

langgraph-sdk==0.4.3

Changes since sdk==0.4.2

  • release(sdk-py): 0.4.3 (#8657)
  • feat(sdk-py): add decrypt replacement result (#8598)
  • release(langgraph): 1.2.11 (#8595)
  • chore(deps): bump the minor-and-patch group across 1 directory with 5 updates (#8532)
  • release(checkpoint): 4.2.0 (#8563)
  • chore: enforce PLC0415 in tests for the remaining packages (#8547)
  • release(langgraph): 1.2.10 (#8462)
  • chore(deps): bump websockets from 15.0.1 to 16.0 in /libs/sdk-py in the major group (#8253)
  • fix(sdk-py): support clearing cron end_time via update(end_time=None) (#8334)
  • release(langgraph): 1.2.9 (#8316)
  • release(langgraph): 1.2.8 (#8292)
  • chore(deps): bump websockets from 15.0.1 to 16.0 in /libs/langgraph in the major group (#8256)
  • chore(deps): bump the minor-and-patch group in /libs/sdk-py with 9 updates (#8252)
  • release(langgraph): 1.2.7 (#8223)
  • chore(deps-dev): bump starlette from 1.0.1 to 1.3.1 in /libs/sdk-py (#8104)
  • chore(deps): bump langsmith from 0.8.0 to 0.8.18 in /libs/sdk-py (#8174)
  • release(langgraph): 1.2.6 (#8139)
  • docs: standardize package README.md structure (#8064)
  • release(langgraph): 1.2.5 (#8062)
  • fix(langgraph): merge lc_versions config metadata (#8052)
  • chore(deps-dev): bump starlette from 1.0.0 to 1.0.1 in /libs/sdk-py (#8006)
  • chore: migrate Python type checking to ty (#8002)
  • release(langgraph): 1.2.4 (#7991)
  • test(sdk-py): add factory-graph integration test exercising the server factory path (#7978)
  • release(langgraph): 1.2.3 (#7945)
Commits

Updates langgraph-sdk from 0.3.15 to 0.4.4

Release notes

Sourced from langgraph-sdk's releases.

langgraph-sdk==0.4.4

Changes since sdk==0.4.3

  • release(sdk-py): 0.4.4 (#8738)
  • Merge commit from fork
  • feat: route LangSmith traces from thread streams (#8723)

langgraph-sdk==0.4.3

Changes since sdk==0.4.2

  • release(sdk-py): 0.4.3 (#8657)
  • feat(sdk-py): add decrypt replacement result (#8598)
  • release(langgraph): 1.2.11 (#8595)
  • chore(deps): bump the minor-and-patch group across 1 directory with 5 updates (#8532)
  • release(checkpoint): 4.2.0 (#8563)
  • chore: enforce PLC0415 in tests for the remaining packages (#8547)
  • release(langgraph): 1.2.10 (#8462)
  • chore(deps): bump websockets from 15.0.1 to 16.0 in /libs/sdk-py in the major group (#8253)
  • fix(sdk-py): support clearing cron end_time via update(end_time=None) (#8334)
  • release(langgraph): 1.2.9 (#8316)
  • release(langgraph): 1.2.8 (#8292)
  • chore(deps): bump websockets from 15.0.1 to 16.0 in /libs/langgraph in the major group (#8256)
  • chore(deps): bump the minor-and-patch group in /libs/sdk-py with 9 updates (#8252)
  • release(langgraph): 1.2.7 (#8223)
  • chore(deps-dev): bump starlette from 1.0.1 to 1.3.1 in /libs/sdk-py (#8104)
  • chore(deps): bump langsmith from 0.8.0 to 0.8.18 in /libs/sdk-py (#8174)
  • release(langgraph): 1.2.6 (#8139)
  • docs: standardize package README.md structure (#8064)
  • release(langgraph): 1.2.5 (#8062)
  • fix(langgraph): merge lc_versions config metadata (#8052)
  • chore(deps-dev): bump starlette from 1.0.0 to 1.0.1 in /libs/sdk-py (#8006)
  • chore: migrate Python type checking to ty (#8002)
  • release(langgraph): 1.2.4 (#7991)
  • test(sdk-py): add factory-graph integration test exercising the server factory path (#7978)
  • release(langgraph): 1.2.3 (#7945)
Commits

Updates fsspec from 2026.2.0 to 2026.6.0

Commits
  • a245700 changelog (#2049)
  • 652325d Fix async cat ranges on error (#2045)
  • 073aac8 Forward kwargs from cat_ranges to cat_file (#2044)
  • 2818611 FTP: preserve filenames containing whitespace in _mlsd2 (#2043)
  • c879384 Prevent attribute error by checking for 'forced' attribute before flushing ca...
  • 71b8a6b Reflect async _walk correctly (#2040)
  • 5eec9f9 Fix: Omit threading.get_ident() from cache token for async implementations ...
  • 8643878 Small safety improvements (#2039)
  • a1c16ab Honour simple_templates everywhere in referenceFS (#2029)
  • 85facaa Fix infinite recursion in expand_path when resolving paths with glob magic ch...
  • Additional commits viewable in compare view

Updates multidict from 6.7.1 to 6.9.1

Release notes

Sourced from multidict's releases.

6.9.1

Bug fixes

  • Fixed the C extension reading freed memory on free-threaded builds when a list handed to :py:meth:~multidict.MultiDict.update, :py:meth:~multidict.MultiDict.extend, :py:meth:~multidict.MultiDict.merge or the :py:class:~multidict.MultiDict and :py:class:~multidict.CIMultiDict constructors, a [key, value] item inside any iterable handed to them, or a list tested with in against :py:meth:~multidict.MultiDict.items, is changed by another thread; a call that catches the list shrinking under it now raises :py:exc:RuntimeError -- by :user:rodrigobnogueira.

    Related issues and pull requests on GitHub: #1437.

  • Fixed a data race on the free-threaded build where a retired hash table's reader count used relaxed atomics, letting a lock-free get()/getone()/ __getitem__() read race a concurrent free of that table. The reader-exit decrement and the drain's free check now use release/acquire ordering instead -- by :user:asvetlov.

    Related issues and pull requests on GitHub: #1481.

  • Fixed a free-threaded build bug where two threads calling update(), merge(), or __setitem__() on the same key at the same time could lose the key entirely instead of just racing on which value wins. A decref of the replaced value could transiently suspend the writer's critical section, letting a second writer for the same key observe the first writer's in-progress entry as absent and, once both settled, mistake it for a stale duplicate and delete it. Every such decref is now deferred until the writer has rel...

    Description has been truncated

Bumps the uv group with 3 updates in the /examples/example-ai-crewai directory: [fsspec](https://github.com/fsspec/filesystem_spec), [multidict](https://github.com/aio-libs/multidict) and [oauthlib](https://github.com/oauthlib/oauthlib).
Bumps the uv group with 3 updates in the /examples/example-ai-dspy directory: [fsspec](https://github.com/fsspec/filesystem_spec), [multidict](https://github.com/aio-libs/multidict) and [mako](https://github.com/sqlalchemy/mako).
Bumps the uv group with 1 update in the /examples/example-ai-instructor directory: [multidict](https://github.com/aio-libs/multidict).
Bumps the uv group with 1 update in the /examples/example-ai-langchain directory: [langgraph-sdk](https://github.com/langchain-ai/langgraph).
Bumps the uv group with 1 update in the /examples/example-ai-langgraph directory: [langgraph-sdk](https://github.com/langchain-ai/langgraph).
Bumps the uv group with 2 updates in the /examples/example-ai-litellm directory: [fsspec](https://github.com/fsspec/filesystem_spec) and [multidict](https://github.com/aio-libs/multidict).
Bumps the uv group with 2 updates in the /examples/example-ai-llamaindex directory: [fsspec](https://github.com/fsspec/filesystem_spec) and [multidict](https://github.com/aio-libs/multidict).
Bumps the uv group with 2 updates in the /examples/example-ai-pydantic-ai directory: [fsspec](https://github.com/fsspec/filesystem_spec) and [multidict](https://github.com/aio-libs/multidict).
Bumps the uv group with 2 updates in the /examples/example-ai-semantic-kernel directory: [multidict](https://github.com/aio-libs/multidict) and [werkzeug](https://github.com/pallets/werkzeug).
Bumps the uv group with 1 update in the /examples/example-ai-smolagents directory: [fsspec](https://github.com/fsspec/filesystem_spec).


Updates `fsspec` from 2026.3.0 to 2026.6.0
- [Commits](fsspec/filesystem_spec@2026.3.0...2026.6.0)

Updates `multidict` from 6.7.1 to 6.9.1
- [Release notes](https://github.com/aio-libs/multidict/releases)
- [Changelog](https://github.com/aio-libs/multidict/blob/master/CHANGES.rst)
- [Commits](aio-libs/multidict@v6.7.1...v6.9.1)

Updates `oauthlib` from 3.3.1 to 4.0.0
- [Release notes](https://github.com/oauthlib/oauthlib/releases)
- [Changelog](https://github.com/oauthlib/oauthlib/blob/master/CHANGELOG.rst)
- [Commits](oauthlib/oauthlib@v3.3.1...v4.0.0)

Updates `fsspec` from 2026.2.0 to 2026.6.0
- [Commits](fsspec/filesystem_spec@2026.3.0...2026.6.0)

Updates `multidict` from 6.7.1 to 6.9.1
- [Release notes](https://github.com/aio-libs/multidict/releases)
- [Changelog](https://github.com/aio-libs/multidict/blob/master/CHANGES.rst)
- [Commits](aio-libs/multidict@v6.7.1...v6.9.1)

Updates `mako` from 1.3.12 to 1.4.2
- [Release notes](https://github.com/sqlalchemy/mako/releases)
- [Changelog](https://github.com/sqlalchemy/mako/blob/main/CHANGES)
- [Commits](https://github.com/sqlalchemy/mako/commits)

Updates `multidict` from 6.7.1 to 6.9.1
- [Release notes](https://github.com/aio-libs/multidict/releases)
- [Changelog](https://github.com/aio-libs/multidict/blob/master/CHANGES.rst)
- [Commits](aio-libs/multidict@v6.7.1...v6.9.1)

Updates `langgraph-sdk` from 0.4.2 to 0.4.4
- [Release notes](https://github.com/langchain-ai/langgraph/releases)
- [Commits](langchain-ai/langgraph@0.4.2...0.4.4)

Updates `langgraph-sdk` from 0.3.15 to 0.4.4
- [Release notes](https://github.com/langchain-ai/langgraph/releases)
- [Commits](langchain-ai/langgraph@0.4.2...0.4.4)

Updates `fsspec` from 2026.2.0 to 2026.6.0
- [Commits](fsspec/filesystem_spec@2026.3.0...2026.6.0)

Updates `multidict` from 6.7.1 to 6.9.1
- [Release notes](https://github.com/aio-libs/multidict/releases)
- [Changelog](https://github.com/aio-libs/multidict/blob/master/CHANGES.rst)
- [Commits](aio-libs/multidict@v6.7.1...v6.9.1)

Updates `fsspec` from 2026.3.0 to 2026.6.0
- [Commits](fsspec/filesystem_spec@2026.3.0...2026.6.0)

Updates `multidict` from 6.7.1 to 6.9.1
- [Release notes](https://github.com/aio-libs/multidict/releases)
- [Changelog](https://github.com/aio-libs/multidict/blob/master/CHANGES.rst)
- [Commits](aio-libs/multidict@v6.7.1...v6.9.1)

Updates `fsspec` from 2026.2.0 to 2026.6.0
- [Commits](fsspec/filesystem_spec@2026.3.0...2026.6.0)

Updates `multidict` from 6.7.1 to 6.9.1
- [Release notes](https://github.com/aio-libs/multidict/releases)
- [Changelog](https://github.com/aio-libs/multidict/blob/master/CHANGES.rst)
- [Commits](aio-libs/multidict@v6.7.1...v6.9.1)

Updates `multidict` from 6.7.1 to 6.9.1
- [Release notes](https://github.com/aio-libs/multidict/releases)
- [Changelog](https://github.com/aio-libs/multidict/blob/master/CHANGES.rst)
- [Commits](aio-libs/multidict@v6.7.1...v6.9.1)

Updates `werkzeug` from 3.1.6 to 3.1.9
- [Release notes](https://github.com/pallets/werkzeug/releases)
- [Changelog](https://github.com/pallets/werkzeug/blob/main/CHANGES.rst)
- [Commits](pallets/werkzeug@3.1.6...3.1.9)

Updates `fsspec` from 2026.3.0 to 2026.6.0
- [Commits](fsspec/filesystem_spec@2026.3.0...2026.6.0)

---
updated-dependencies:
- dependency-name: fsspec
  dependency-version: 2026.6.0
  dependency-type: indirect
  dependency-group: uv
- dependency-name: multidict
  dependency-version: 6.9.1
  dependency-type: indirect
  dependency-group: uv
- dependency-name: oauthlib
  dependency-version: 4.0.0
  dependency-type: indirect
  dependency-group: uv
- dependency-name: fsspec
  dependency-version: 2026.6.0
  dependency-type: indirect
  dependency-group: uv
- dependency-name: multidict
  dependency-version: 6.9.1
  dependency-type: indirect
  dependency-group: uv
- dependency-name: mako
  dependency-version: 1.4.2
  dependency-type: indirect
  dependency-group: uv
- dependency-name: multidict
  dependency-version: 6.9.1
  dependency-type: indirect
  dependency-group: uv
- dependency-name: langgraph-sdk
  dependency-version: 0.4.4
  dependency-type: indirect
  dependency-group: uv
- dependency-name: langgraph-sdk
  dependency-version: 0.4.4
  dependency-type: indirect
  dependency-group: uv
- dependency-name: fsspec
  dependency-version: 2026.6.0
  dependency-type: indirect
  dependency-group: uv
- dependency-name: multidict
  dependency-version: 6.9.1
  dependency-type: indirect
  dependency-group: uv
- dependency-name: fsspec
  dependency-version: 2026.6.0
  dependency-type: indirect
  dependency-group: uv
- dependency-name: multidict
  dependency-version: 6.9.1
  dependency-type: indirect
  dependency-group: uv
- dependency-name: fsspec
  dependency-version: 2026.6.0
  dependency-type: indirect
  dependency-group: uv
- dependency-name: multidict
  dependency-version: 6.9.1
  dependency-type: indirect
  dependency-group: uv
- dependency-name: multidict
  dependency-version: 6.9.1
  dependency-type: indirect
  dependency-group: uv
- dependency-name: werkzeug
  dependency-version: 3.1.9
  dependency-type: indirect
  dependency-group: uv
- dependency-name: fsspec
  dependency-version: 2026.6.0
  dependency-type: indirect
  dependency-group: uv
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot requested a review from a team as a code owner October 6, 2026 09:32
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels Oct 6, 2026
@github-actions

github-actions Bot commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

posthog-python Compliance Report

Date: 2026-10-06T09:37:29.981107+00:00
Duration: 259172ms

✅ All Tests Passed!

121/121 tests passed


Capture_V1 Tests

✅ 95/95 tests passed

View Details
Test Status Duration
Endpoint And Method.Targets V1 Endpoint ✅ 514ms
Endpoint And Method.Does Not Use Legacy Endpoints ✅ 508ms
Required Headers.Has Authorization Bearer Header ✅ 508ms
Required Headers.Has Content Type Json ✅ 509ms
Required Headers.Has Posthog Sdk Info Format ✅ 507ms
Required Headers.Has Posthog Attempt Header ✅ 507ms
Required Headers.Has Posthog Request Id ✅ 508ms
Required Headers.Has Posthog Request Timestamp ✅ 506ms
Required Headers.Has User Agent ✅ 508ms
Body Format.Body Has Created At And Batch ✅ 508ms
Body Format.No Api Key In Body ✅ 508ms
Body Format.No Sent At In Body ✅ 508ms
Event Format.Event Has Required Root Fields ✅ 508ms
Event Format.Event Uuid Is Valid ✅ 507ms
Event Format.Event Timestamp Is Rfc3339 ✅ 508ms
Event Format.Non Utc Event Timestamp Is Converted To Utc ✅ 511ms
Event Format.Distinct Id Is String ✅ 508ms
Event Format.Distinct Id At Root Not Properties ✅ 507ms
Event Format.Custom Properties Preserved ✅ 508ms
Event Format.Set Properties Preserved ✅ 507ms
Event Format.Set Once Properties Preserved ✅ 508ms
Event Format.Groups Properties Preserved ✅ 508ms
Event Format.Sdk Generates Uuid If Not Provided ✅ 507ms
Event Format.Event Has Required Root Fields Batch ✅ 510ms
Event Format.Event Uuid Is Valid Batch ✅ 510ms
Event Format.Event Timestamp Is Rfc3339 Batch ✅ 509ms
Event Format.Distinct Id Is String Batch ✅ 510ms
Event Format.Distinct Id At Root Not Properties Batch ✅ 510ms
Event Format.Custom Properties Preserved Batch ✅ 509ms
Event Format.Set Properties Preserved Batch ✅ 511ms
Event Format.Set Once Properties Preserved Batch ✅ 510ms
Event Format.Groups Properties Preserved Batch ✅ 510ms
Event Format.Sdk Generates Uuid If Not Provided Batch ✅ 509ms
Batch Behavior.Multiple Events In Single Batch ✅ 512ms
Batch Behavior.Batch Envelope Smoke ✅ 510ms
Batch Behavior.Flush With No Events Sends Nothing ✅ 505ms
Batch Behavior.Flush At Triggers Batch ✅ 1007ms
Batch Behavior.Created At Reflects Batch Creation Time ✅ 508ms
Deduplication.Generates Unique Uuids ✅ 512ms
Deduplication.Different Events Same Content Different Uuids ✅ 509ms
Deduplication.Preserves Uuid On Retry ✅ 6512ms
Deduplication.Preserves Timestamp On Retry ✅ 6516ms
Deduplication.Preserves Uuid And Timestamp On Batch Retry ✅ 6518ms
Deduplication.No Duplicate Events In Batch ✅ 512ms
Header Behavior On Retry.Attempt Header Starts At One ✅ 507ms
Header Behavior On Retry.Attempt Header Increments On Retry ✅ 13523ms
Header Behavior On Retry.Request Id Preserved On Retry ✅ 6512ms
Header Behavior On Retry.Different Requests Have Different Request Ids ✅ 3015ms
Header Behavior On Retry.Request Timestamp Changes On Retry ✅ 6512ms
Response Format Validation.Success Response Has Uuid Keyed Results ✅ 508ms
Response Format Validation.Success Response Has Ok For Each Event ✅ 509ms
Response Format Validation.Success No Retry After When All Ok ✅ 508ms
Response Format Validation.Success Retry After Present When Retry Events ✅ 1510ms
Response Format Validation.Success No Retry After When Drop Only ✅ 509ms
Response Format Validation.Response Echoes Request Id ✅ 507ms
Retry Behavior.Retries On 408 ✅ 6517ms
Retry Behavior.Retries On 500 ✅ 6512ms
Retry Behavior.Retries On 503 ✅ 8518ms
Retry Behavior.Retries On 504 ✅ 6516ms
Retry Behavior.Retryable Errors Have Retry After ✅ 3513ms
Retry Behavior.Respects Retry After On Retryable Error ✅ 11519ms
Retry Behavior.Does Not Retry On 400 ✅ 2512ms
Retry Behavior.Does Not Retry On 401 ✅ 2511ms
Retry Behavior.Does Not Retry On 402 ✅ 2510ms
Retry Behavior.Does Not Retry On 413 ✅ 2510ms
Retry Behavior.Does Not Retry On 415 ✅ 2508ms
Retry Behavior.Non Retryable Errors Have No Retry After ✅ 2511ms
Retry Behavior.Implements Backoff ✅ 22520ms
Retry Behavior.Max Retries Respected ✅ 22530ms
Partial Batch Handling.Handles 200 Full Success ✅ 2510ms
Partial Batch Handling.Handles 200 With All Ok ✅ 3511ms
Partial Batch Handling.Does Not Retry Dropped Events ✅ 3510ms
Partial Batch Handling.Does Not Retry Limited Events ✅ 3514ms
Partial Batch Handling.Prunes Ok Events On Partial Retry ✅ 6536ms
Partial Batch Handling.Prunes Dropped Events On Partial Retry ✅ 6517ms
Partial Batch Handling.Retries Only Retry Events From Partial ✅ 6518ms
Partial Batch Handling.Partial Retry Preserves Uuids ✅ 6517ms
Partial Batch Handling.Partial Retry Attempt Header Increments ✅ 6517ms
Partial Batch Handling.Partial Retry Request Id Preserved ✅ 6513ms
Partial Batch Handling.Respects Retry After On Partial ✅ 8518ms
Partial Batch Handling.Unknown Result Treated As Terminal ✅ 3513ms
Partial Batch Handling.Mixed Ok Drop Limited No Retry ✅ 3511ms
Compression.Sends Gzip Content Encoding ✅ 508ms
Compression.No Content Encoding When Disabled ✅ 507ms
Compression.Compressed Body Is Decompressible ✅ 507ms
Error Handling.Does Not Retry On Unknown 4Xx ✅ 2510ms
Event Options.Cookieless Mode Override ✅ 508ms
Event Options.Disable Skew Correction Override ✅ 507ms
Event Options.Process Person Profile Override ✅ 508ms
Event Options.Product Tour Id Override ✅ 507ms
Event Options.Unset Options Omitted ✅ 507ms
Event Options.Options Override In Batch ✅ 510ms
Geoip And Historical Migration.Geoip Disable Injected Into Properties ✅ 507ms
Geoip And Historical Migration.Historical Migration Set In Body ✅ 508ms
Geoip And Historical Migration.Historical Migration Absent By Default ✅ 507ms

Capture_Ai Tests

✅ 5/5 tests passed

View Details
Test Status Duration
Routing.Capture Ai Posts To Ai Endpoint ✅ 508ms
Routing.Capture Does Not Reroute Ai Named Events ✅ 507ms
Identity.Capture Ai Event Has Uuid ✅ 507ms
Identity.Capture Ai Keeps Supplied Uuid ✅ 508ms
Timestamp Format.Non Utc Event Timestamp Is Converted To Utc ✅ 507ms

Feature_Flags Tests

✅ 17/17 tests passed

View Details
Test Status Duration
Request Payload.Request With Person Properties Device Id ✅ 9ms
Request Payload.Flags Request Uses V2 Query Param ✅ 6ms
Request Payload.Flags Request Hits Flags Path Not Decide ✅ 6ms
Request Payload.Flags Request Omits Authorization Header ✅ 6ms
Request Payload.Token In Flags Body Matches Init ✅ 6ms
Request Payload.Groups Round Trip ✅ 6ms
Request Payload.Groups Default To Empty Object ✅ 6ms
Request Payload.Disable Geoip False Propagates As Geoip Disable False ✅ 6ms
Request Payload.Disable Geoip Omitted Defaults To False ✅ 6ms
Request Payload.Flag Keys To Evaluate Contains Only Requested Key ✅ 6ms
Request Lifecycle.No Flags Request On Init Alone ✅ 3ms
Request Lifecycle.No Flags Request On Normal Capture ✅ 506ms
Request Lifecycle.Two Flag Calls Produce Two Remote Requests ✅ 10ms
Request Lifecycle.Mock Response Value Is Returned To Caller ✅ 6ms
Retry Behavior.Retries Flags On 502 ✅ 309ms
Retry Behavior.Retries Flags On 504 ✅ 309ms
Side Effect Events.Get Feature Flag Captures Feature Flag Called Event ✅ 508ms

Feature_Flags_Local_Evaluation Tests

✅ 4/4 tests passed

View Details
Test Status Duration
Versioned Boolean Matching.Matching Version Missing ✅ 44ms
Versioned Boolean Matching.Matching Version 1 ✅ 40ms
Versioned Boolean Matching.Matching Version 2 ✅ 40ms
Versioned Boolean Matching.Version Only Reload 1 2 1 2 Missing ✅ 22ms

@ioannisj
ioannisj merged commit 2273c7a into main Oct 6, 2026
42 of 43 checks passed
@ioannisj
ioannisj deleted the dependabot/uv/examples/example-ai-crewai/uv-8b76969db4 branch October 6, 2026 10:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant