Skip to content

chore(deps): bump the all group across 1 directory with 6 updates#1451

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/all-d38364ce7d
Closed

chore(deps): bump the all group across 1 directory with 6 updates#1451
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/all-d38364ce7d

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 11, 2026

Copy link
Copy Markdown
Contributor

Bumps the all group with 6 updates in the / directory:

Package From To
httpx2 2.4.0 2.5.0
obstore 0.10.1 0.11.0
ipython 9.14.1 9.15.0
uvicorn 0.49.0 0.50.0
fastapi 0.138.0 0.139.0
rio-tiler 9.3.0 9.4.0

Updates httpx2 from 2.4.0 to 2.5.0

Changelog

Sourced from httpx2's changelog.

2.5.0 (June 25th, 2026)

Added

  • Add native server-sent events support via client.sse(). (#1046)
  • Support | and |= operators for Headers. (#1047)

Fixed

  • Allow IPv6 CIDR notation in no_proxy. (#967)
Commits
  • 9b7ee8e Version 2.5.0 (#1051)
  • 9d5dd67 Inline SSE header defaults using the Headers union operator (#1049)
  • a6e4c43 Suppress empty SSE keepalive events and accept case-insensitive content type ...
  • f1a6268 Support | and |= operators for Headers (#1047)
  • e709094 Add native server-sent events support via client.sse() (#1046)
  • 82b9e2d Allow IPv6 CIDR notation in no_proxy (#967)
  • See full diff in compare view

Updates obstore from 0.10.1 to 0.11.0

Commits

Updates ipython from 9.14.1 to 9.15.0

Commits
  • 2273f39 release 9.15.0
  • 4774918 fix
  • 4bec98b update whatsnew
  • 42fcfe4 [3.11] Skip stup for Numpy that is not using > 3.11 syntax
  • b5da9ac fix: clarify tk simple-prompt gui message
  • 00bcdee fix: don't let kitty graphics detection crash IPython startup
  • 60f2e26 Fix #12726: %run honors quotes when expanding glob args
  • 3ea7aa6 Strip ANSI escape sequences from Sphinx directive output
  • 9b7d419 Add %xmode Doctest mode for doctest friendly tracebacks
  • fdbdf1c Increase codecov threshold to 0.2% to avoid false PR failures
  • Additional commits viewable in compare view

Updates uvicorn from 0.49.0 to 0.50.0

Release notes

Sourced from uvicorn's releases.

Version 0.50.0

What's Changed

Full Changelog: Kludex/uvicorn@0.49.0...0.50.0

Changelog

Sourced from uvicorn's changelog.

0.50.0 (July 4, 2026)

If you use WebSockets, note that --ws auto now picks the websockets-sansio implementation. You shouldn't need it, but you can pin --ws websockets to get the deprecated legacy one back.

Changed

  • Exit with the dedicated code 3 on any startup failure: app loading, socket bind and lifespan startup errors previously exited with a mix of 0, 1 and 3 (#3001)
  • Stop the multiprocess supervisor when a worker exits with code 3 instead of restarting it forever (#3001)
  • Default --ws auto to websockets-sansio when websockets is installed (#2985)
  • Skip the eager app import in the parent process with --reload or --workers, fixing a memory regression introduced in 0.47.0 (#3012)
  • Build a fresh asgi scope dict per request (#2977)
  • Cache the asgi scope sub-dict per connection (#2976)
  • Avoid copying single-frame WebSocket payloads in websockets-sansio (#2983)
  • Memoize trusted host checks in ProxyHeadersMiddleware (#2970)
  • Replace click.style with an internal ANSI style helper (#2981)

Deprecated

  • Deprecate the legacy websockets implementation; use websockets-sansio or wsproto instead (#2985)
Commits
  • 21d2c16 Version 0.50.0 (#3013)
  • 6c42e8d Skip the eager app import in the parent when spawning workers (#3012)
  • 56a4631 Exit with a dedicated code on startup failure and stop the supervisor when a ...
  • 3314dfc chore(deps): bump the github-actions group with 4 updates (#3007)
  • e8a31bc chore(deps): bump the python-packages group across 1 directory with 9 updates...
  • 8d088b1 Deprecate the legacy websockets implementation and default auto to websocke...
  • 5b08cf6 Avoid copying single-frame WebSocket payloads in websockets-sansio (#2983)
  • bf3f60c Replace click.style with an internal ANSI style helper (#2981)
  • eea1bcc Build a fresh asgi scope dict per request (#2977)
  • afed211 Cache the asgi scope sub-dict per connection (#2976)
  • Additional commits viewable in compare view

Updates fastapi from 0.138.0 to 0.139.0

Release notes

Sourced from fastapi's releases.

0.139.0

Features

  • ✨ Support dependencies in app.frontend(), e.g. for automatic cookie authentication for the frontend. PR #15908 by @​tiangolo.

Translations

Internal

0.138.1

Refactors

  • ♻️ Refactor Library Skills, make info easier to find for agents. PR #15841 by @​tiangolo.

Internal

... (truncated)

Commits
  • cecd96d 🔖 Release version 0.139.0 (#15910)
  • aea6609 📝 Update release notes
  • 319be50 ✨ Support dependencies in app.frontend(), e.g. for automatic cookie authent...
  • 66a90f6 📝 Update release notes
  • d30a3eb 👥 Update FastAPI People - Experts (#15909)
  • 122f1b5 📝 Update release notes
  • fd6ece3 👥 Update FastAPI GitHub topic repositories (#15906)
  • ec2a6ad 📝 Update release notes
  • 9d7d7fe 🌐 Update translations for fr (update-outdated) (#15897)
  • 8dc852d 📝 Update release notes
  • Additional commits viewable in compare view

Updates rio-tiler from 9.3.0 to 9.4.0

Release notes

Sourced from rio-tiler's releases.

9.4.0

What's Changed

Full Changelog: cogeotiff/rio-tiler@9.3.0...9.4.0

Changelog

Sourced from rio-tiler's changelog.

9.4.0 (2026-07-02)

  • change: _variables attribute in rio_tiler.experimental.zarr.GeoZarrReader to be a list of dict instead of a list of string

    # before
    with GeoZarrReader(input={zarr.AsyncGroup}) as src:
        print(src._variables)
        >> ["data:b1", "data:b2", "data:b3"]
    await src.info()
    >> {
        "bounds": ...
        "variables": ["data:b1", "data:b2", "data:b3"]
    }
    
    now
    with GeoZarrReader(input={zarr.AsyncGroup}) as src:
    print(src._variables)
    >> [
    {"name": "b1", "group": "data", "long_name": "data:b1", "multiscale": False, "nbands": 1},
    {"name": "b2", "group": "data", "long_name": "data:b2", "multiscale": False, "nbands": 1},
    {"name": "b3", "group": "data", "long_name": "data:b3", "multiscale": False, "nbands": 1}
    ]
    await src.info()
    >> {
        "bounds": ...
        "variables": [
            {"name": "b1", "group": "data", "long_name": "data:b1", "multiscale": False, "nbands": 1},
            {"name": "b2", "group": "data", "long_name": "data:b2", "multiscale": False, "nbands": 1},
            {"name": "b3", "group": "data", "long_name": "data:b3", "multiscale": False, "nbands": 1}
        ]
    }

  • change: change input for rio_tiler.experimental.zarr.get_group_metadata to accept no input group to get the metadata for the root group.

    # before
    with GeoZarrReader(input={zarr.AsyncGroup}) as src:
        await src.get_group_metadata("root")
    now
    with GeoZarrReader(input={zarr.AsyncGroup}) as src:
    await src.get_group_metadata()

Commits
  • c4b4d37 Bump version: 9.3.0 → 9.4.0
  • 09bf9cc chore: release date
  • 5955e9c feat(async-geozarr): add more variable info (#957)
  • be01299 fix: type
  • e086aae chore: update pre-commit config
  • 71bb272 chore(deps): update lockfile
  • fc35944 chore(deps): bump actions/checkout in the all group across 1 directory (#958)
  • 9f2267d chore(deps-dev): bump the all group with 3 updates (#960)
  • ab40c76 chore(deps): bump the all group with 5 updates (#959)
  • See full diff in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the all group with 6 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [httpx2](https://github.com/pydantic/httpx2) | `2.4.0` | `2.5.0` |
| [obstore](https://github.com/geospatial-jeff/pyasyncio-benchmark) | `0.10.1` | `0.11.0` |
| [ipython](https://github.com/ipython/ipython) | `9.14.1` | `9.15.0` |
| [uvicorn](https://github.com/Kludex/uvicorn) | `0.49.0` | `0.50.0` |
| [fastapi](https://github.com/fastapi/fastapi) | `0.138.0` | `0.139.0` |
| [rio-tiler](https://github.com/cogeotiff/rio-tiler) | `9.3.0` | `9.4.0` |



Updates `httpx2` from 2.4.0 to 2.5.0
- [Release notes](https://github.com/pydantic/httpx2/releases)
- [Changelog](https://github.com/pydantic/httpx2/blob/main/src/httpx2/CHANGELOG.md)
- [Commits](pydantic/httpx2@v2.4.0...v2.5.0)

Updates `obstore` from 0.10.1 to 0.11.0
- [Commits](https://github.com/geospatial-jeff/pyasyncio-benchmark/commits)

Updates `ipython` from 9.14.1 to 9.15.0
- [Release notes](https://github.com/ipython/ipython/releases)
- [Commits](ipython/ipython@9.14.1...9.15.0)

Updates `uvicorn` from 0.49.0 to 0.50.0
- [Release notes](https://github.com/Kludex/uvicorn/releases)
- [Changelog](https://github.com/Kludex/uvicorn/blob/main/docs/release-notes.md)
- [Commits](Kludex/uvicorn@0.49.0...0.50.0)

Updates `fastapi` from 0.138.0 to 0.139.0
- [Release notes](https://github.com/fastapi/fastapi/releases)
- [Commits](fastapi/fastapi@0.138.0...0.139.0)

Updates `rio-tiler` from 9.3.0 to 9.4.0
- [Release notes](https://github.com/cogeotiff/rio-tiler/releases)
- [Changelog](https://github.com/cogeotiff/rio-tiler/blob/main/CHANGES.md)
- [Commits](cogeotiff/rio-tiler@9.3.0...9.4.0)

---
updated-dependencies:
- dependency-name: httpx2
  dependency-version: 2.5.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: all
- dependency-name: obstore
  dependency-version: 0.11.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: all
- dependency-name: ipython
  dependency-version: 9.15.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: all
- dependency-name: uvicorn
  dependency-version: 0.50.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: all
- dependency-name: fastapi
  dependency-version: 0.139.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all
- dependency-name: rio-tiler
  dependency-version: 9.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels Jul 11, 2026
@dependabot @github

dependabot Bot commented on behalf of github Jul 18, 2026

Copy link
Copy Markdown
Contributor Author

Looks like these dependencies are updatable in another way, so this is no longer needed.

@dependabot dependabot Bot closed this Jul 18, 2026
@dependabot
dependabot Bot deleted the dependabot/uv/all-d38364ce7d branch July 18, 2026 21:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants