Skip to content

chore(deps): bump the project-python group across 1 directory with 5 updates - #119

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/project-python-21a603aaaa
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/project-python-21a603aaaa

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the project-python group with 5 updates in the / directory:

Package From To
genai-prices 0.1.6 0.1.9
httpx2 2.12.0 2.13.1
logfire-api 5.0.0 5.1.1
openai 3.8.0 3.19.2
boto3 1.43.89 1.43.102

Updates genai-prices from 0.1.6 to 0.1.9

Commits
  • d9556e8 Price one-hour Claude cache writes on Bedrock and Vertex AI, and drop Vertex'...
  • 1150d90 Note that xAI realtime reports billable audio seconds as a running total (#722)
  • 4875853 Add TypeSafe Jev's 32k context_window (#720)
  • da59fc4 Add OpenAI gpt-live-1 pricing (#719)
  • 6f2592d Add Google Gemini 3.8 Live and 3.8 Live Extended Thinking pricing (#718)
  • d89fd51 Add GPT Image 2.5 Flare and Sunburst prices (#717)
  • f3a1cfe Add AWS Bedrock GPT-6 Astra, Sol and Luna pricing (#713)
  • 59c0c27 Add Claude Opus 5.5 pricing (#709)
  • 3412a87 Add OpenAI gpt-6-sol and gpt-6-luna pricing (#708)
  • 02cb80a Add Doubleword DeepSeek V4.1 Flash pricing (#699)
  • Additional commits viewable in compare view

Updates httpx2 from 2.12.0 to 2.13.1

Release notes

Sourced from httpx2's releases.

v2.13.1

Highlights

📤 Accurate file upload lengths

Passing a file as content= now calculates Content-Length from its remaining bytes, respecting the current file position (#1214).

🔐 Reliable proxy TLS and HTTP/2 negotiation

TLS hostname overrides now apply inside HTTP proxy tunnels without affecting the proxy's own TLS connection (#1223). HTTP/2 is advertised first when enabled, and HTTP/1.1 is omitted when disabled (#1155).

🧹 Clean WebSocket shutdown

The sync WebSocket keepalive thread now exits cleanly when a ping races with connection shutdown (#1228).

httpx2

Fixed

  • Calculate Content-Length from the remaining bytes when a file is passed as content=, respecting its current position (#1214).
  • Stop the sync WebSocket keepalive thread cleanly when a ping races with connection shutdown (#1228).

httpcore2

Fixed

  • Honor the sni_hostname extension for TLS inside HTTP proxy tunnels without applying it to the proxy's TLS connection (#1223).
  • Prefer HTTP/2 during TLS protocol negotiation when enabled, and stop advertising HTTP/1.1 when it is disabled (#1155).

Full Changelog: pydantic/httpx2@v2.13.0...v2.13.1

v2.13.0

Highlights

🔐 Reliable TLS verification controls

The CLI --no-verify flag now disables TLS certificate verification as intended, and --verify provides an explicit counterpart (pydantic/httpx2#1140, pydantic/httpx2#1186).

🧹 Safer async stream cleanup

Stopping a streamed response early no longer risks a nested async generator finalization error (pydantic/httpx2#1204).

httpx2

Changed

  • Require brotlicffi 1.2.0.2 or later for the brotli extra on non-CPython implementations in pydantic/httpx2#1179

Fixed

... (truncated)

Changelog

Sourced from httpx2's changelog.

2.13.1 (September 23rd, 2026)

Fixed

  • Calculate Content-Length from the remaining bytes when a file is passed as content=, respecting its current position. (#1214)
  • Stop the sync WebSocket keepalive thread cleanly when a ping races with connection shutdown. (#1228)

2.13.0 (September 14th, 2026)

Changed

  • Require brotlicffi 1.2.0.2 or later for the brotli extra on non-CPython implementations. (#1179)

Fixed

  • Make the --no-verify CLI flag disable TLS certificate verification and add an explicit --verify counterpart. (#1140, #1186)
  • Avoid nested async generator finalization errors when streamed responses are abandoned early. (#1204)
Commits

Updates logfire-api from 5.0.0 to 5.1.1

Release notes

Sourced from logfire-api's releases.

v5.1.1

Fixes

  • Handle project setup for accounts without organizations by @​strawgate in #2470
  • Enable TCP keepalive and recycle idle connections in Logfire's HTTP sessions by @​adriangb in #2476

v5.1.0

Integrations

  • Add logfire.instrument_litestar() with support for Litestar 2.11 and later by @​dmontagu in #2249
  • Recommend Logfire extras when logfire run detects missing instrumentation packages by @​krishna3554 in #2082

Agent setup

Fixes

  • Prevent OpenTelemetry logging from deadlocking during force_flush() by @​L4XB in #2404
  • Require directory boundaries when identifying non-user code paths by @​yhz5613813 in #2375

New Contributors

Changelog

Sourced from logfire-api's changelog.

[v5.1.1] (2026-09-25)

Fixes

  • Handle project setup for accounts without organizations by @​strawgate in #2470
  • Enable TCP keepalive and recycle idle connections in Logfire's HTTP sessions by @​adriangb in #2476

[v5.1.0] (2026-09-11)

Integrations

  • Add logfire.instrument_litestar() with support for Litestar 2.11 and later by @​dmontagu in #2249
  • Recommend Logfire extras when logfire run detects missing instrumentation packages by @​krishna3554 in #2082

Agent setup

Fixes

  • Prevent OpenTelemetry logging from deadlocking during force_flush() by @​L4XB in #2404
  • Require directory boundaries when identifying non-user code paths by @​yhz5613813 in #2375

New Contributors

Commits
  • 6b5ac61 Release v5.1.1 (#2483)
  • c26516e [v5] Enable TCP keepalive and recycle idle connections in Logfire's HTTP sess...
  • a5c9fdb [v5] Handle project setup for accounts without organizations (#2470)
  • 17cc059 Release v5.1.0 (#2406)
  • acd485f Harden the OpenTelemetry flush regression test (#2405)
  • e209cda Fix Logfire setup skill guidance (#2365)
  • bb17649 Prevent OpenTelemetry logging from deadlocking during flush (#2404)
  • 5905b8e Route eval setup through the Logfire evals skill (#2402)
  • 6e08b41 Make the Logfire evals skill executable for Python and Node.js (#2400)
  • 67dae06 Document agent framework coverage across Logfire views (#2386)
  • Additional commits viewable in compare view

Updates openai from 3.8.0 to 3.19.2

Release notes

Sourced from openai's releases.

v3.19.2

3.19.2 (2026-09-23)

Bug Fixes

  • preserve single files for fallback extraction paths (#3875) (bfd3680)

Chores

  • api: clarify approximate web search location defaults (#3953) (a95c95e)
  • api: clarify Realtime modality array definitions (#3954) (e79cf53)
  • api: correct fine-tuning bounds and Realtime response reference (#3949) (325a948)

v3.19.1

3.19.1 (2026-09-23)

Bug Fixes

  • chat: preserve single-pass tool iterables (#3770) (33ffa1f)
  • client: merge HTTP headers case-insensitively (#3486) (5e39766)

Chores

  • api: clarify Chat Completions seed limits (#3945) (be9d666)

Documentation

  • clarify collaborator-only pull request policy (#3948) (ead1fa2)

v3.19.0

3.19.0 (2026-09-22)

Features

Bug Fixes

  • _utils/_transform: propagate api_exclude in _async_transform_recursive (#3324) (161ae65)
  • api: handle omission markers in queued WebSocket events (#3944) (63e4616)
  • client: retry only replayable request content (#3771) (6e0c2be)
  • client: tolerate older optional aiohttp installations (#3941) (0d91efb)

... (truncated)

Changelog

Sourced from openai's changelog.

3.19.2 (2026-09-23)

Bug Fixes

  • preserve single files for fallback extraction paths (#3875) (bfd3680)

Chores

  • api: clarify approximate web search location defaults (#3953) (a95c95e)
  • api: clarify Realtime modality array definitions (#3954) (e79cf53)
  • api: correct fine-tuning bounds and Realtime response reference (#3949) (325a948)

3.19.1 (2026-09-23)

Bug Fixes

  • chat: preserve single-pass tool iterables (#3770) (33ffa1f)
  • client: merge HTTP headers case-insensitively (#3486) (5e39766)

Chores

  • api: clarify Chat Completions seed limits (#3945) (be9d666)

Documentation

  • clarify collaborator-only pull request policy (#3948) (ead1fa2)

3.19.0 (2026-09-22)

Features

Bug Fixes

  • _utils/_transform: propagate api_exclude in _async_transform_recursive (#3324) (161ae65)
  • api: handle omission markers in queued WebSocket events (#3944) (63e4616)
  • client: retry only replayable request content (#3771) (6e0c2be)
  • client: tolerate older optional aiohttp installations (#3941) (0d91efb)
  • helpers: use asyncio.get_running_loop() inside async methods (#3289) (bac3545)

3.18.0 (2026-09-22)

... (truncated)

Commits
  • d9f7b7a release: 3.19.2 (#3951)
  • e79cf53 chore(api): clarify Realtime modality array definitions (#3954)
  • a95c95e chore(api): clarify approximate web search location defaults (#3953)
  • 325a948 chore(api): correct fine-tuning bounds and Realtime response reference (#3949)
  • bfd3680 fix: preserve single files for fallback extraction paths (#3875)
  • 4d12746 release: 3.19.1 (#3946)
  • 33ffa1f fix(chat): preserve single-pass tool iterables (#3770)
  • 5e39766 fix(client): merge HTTP headers case-insensitively (#3486)
  • ead1fa2 docs: clarify collaborator-only pull request policy (#3948)
  • be9d666 chore(api): clarify Chat Completions seed limits (#3945)
  • Additional commits viewable in compare view

Updates boto3 from 1.43.89 to 1.43.102

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

…updates

Bumps the project-python group with 5 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [genai-prices](https://github.com/pydantic/genai-prices) | `0.1.6` | `0.1.9` |
| [httpx2](https://github.com/pydantic/httpx2) | `2.12.0` | `2.13.1` |
| [logfire-api](https://github.com/pydantic/logfire) | `5.0.0` | `5.1.1` |
| [openai](https://github.com/openai/openai-python) | `3.8.0` | `3.19.2` |
| [boto3](https://github.com/boto/boto3) | `1.43.89` | `1.43.102` |



Updates `genai-prices` from 0.1.6 to 0.1.9
- [Release notes](https://github.com/pydantic/genai-prices/releases)
- [Changelog](https://github.com/pydantic/genai-prices/blob/main/RELEASE.md)
- [Commits](pydantic/genai-prices@v0.1.6...v0.1.9)

Updates `httpx2` from 2.12.0 to 2.13.1
- [Release notes](https://github.com/pydantic/httpx2/releases)
- [Changelog](https://github.com/pydantic/httpx2/blob/main/src/httpx2/CHANGELOG.md)
- [Commits](pydantic/httpx2@v2.12.0...v2.13.1)

Updates `logfire-api` from 5.0.0 to 5.1.1
- [Release notes](https://github.com/pydantic/logfire/releases)
- [Changelog](https://github.com/pydantic/logfire/blob/v5.1.1/CHANGELOG.md)
- [Commits](pydantic/logfire@v5.0.0...v5.1.1)

Updates `openai` from 3.8.0 to 3.19.2
- [Release notes](https://github.com/openai/openai-python/releases)
- [Changelog](https://github.com/openai/openai-python/blob/main/CHANGELOG.md)
- [Commits](openai/openai-python@v3.8.0...v3.19.2)

Updates `boto3` from 1.43.89 to 1.43.102
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](boto/boto3@1.43.89...1.43.102)

---
updated-dependencies:
- dependency-name: genai-prices
  dependency-version: 0.1.9
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: project-python
- dependency-name: httpx2
  dependency-version: 2.13.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: project-python
- dependency-name: logfire-api
  dependency-version: 5.1.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: project-python
- dependency-name: openai
  dependency-version: 3.19.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: project-python
- dependency-name: boto3
  dependency-version: 1.43.102
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: project-python
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added area/python Python dependencies or runtime behavior dependencies Dependency update labels Sep 28, 2026
@github-actions github-actions Bot added area/docs Affected repository area area/installer Installer, bootstrap, conversion, or rollback area/release Affected repository area area/skills Skills, workflows, or packs status/needs-triage Triage status type/pr Issue or PR type labels Sep 28, 2026
CruxExperts pushed a commit that referenced this pull request Oct 3, 2026
@dependabot @github

dependabot Bot commented on behalf of github Oct 3, 2026

Copy link
Copy Markdown
Contributor Author

Looks like these dependencies are updatable in another way, so this is no longer needed.

@dependabot dependabot Bot closed this Oct 3, 2026
@dependabot
dependabot Bot deleted the dependabot/uv/project-python-21a603aaaa branch October 3, 2026 11:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/docs Affected repository area area/installer Installer, bootstrap, conversion, or rollback area/python Python dependencies or runtime behavior area/release Affected repository area area/skills Skills, workflows, or packs dependencies Dependency update status/needs-triage Triage status type/pr Issue or PR type

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants