Skip to content

chore(deps): bump the all group across 1 directory with 9 updates#1453

Merged
vincentsarago merged 2 commits into
mainfrom
dependabot/uv/all-74a146d13b
Jul 20, 2026
Merged

chore(deps): bump the all group across 1 directory with 9 updates#1453
vincentsarago merged 2 commits into
mainfrom
dependabot/uv/all-74a146d13b

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 18, 2026

Copy link
Copy Markdown
Contributor

Bumps the all group with 9 updates in the / directory:

Package From To
httpx2 2.4.0 2.5.0
obstore 0.10.1 0.11.0
boto3 1.43.0 1.43.46
ipython 9.14.1 9.15.0
uvicorn 0.49.0 0.51.0
fastapi 0.138.0 0.139.0
rio-tiler 9.3.0 9.4.0
xarray 2026.4.0 2026.7.0
gcsfs 2026.6.0 2026.7.0

Updates httpx2 from 2.4.0 to 2.5.0

Changelog

Sourced from httpx2's changelog.

2.5.0 (June 25th, 2026)

Added

  • Add native server-sent events support via client.sse(). (#1046)
  • Support | and |= operators for Headers. (#1047)

Fixed

  • Allow IPv6 CIDR notation in no_proxy. (#967)
Commits
  • 9b7ee8e Version 2.5.0 (#1051)
  • 9d5dd67 Inline SSE header defaults using the Headers union operator (#1049)
  • a6e4c43 Suppress empty SSE keepalive events and accept case-insensitive content type ...
  • f1a6268 Support | and |= operators for Headers (#1047)
  • e709094 Add native server-sent events support via client.sse() (#1046)
  • 82b9e2d Allow IPv6 CIDR notation in no_proxy (#967)
  • See full diff in compare view

Updates obstore from 0.10.1 to 0.11.0

Commits

Updates boto3 from 1.43.0 to 1.43.46

Commits
  • c7888d6 Merge branch 'release-1.43.46'
  • 1479621 Bumping version to 1.43.46
  • 54abdb4 Add changelog entries from botocore
  • 75de637 Merge branch 'release-1.43.45'
  • d3449aa Merge branch 'release-1.43.45' into develop
  • 497253d Bumping version to 1.43.45
  • 5e9768e Add changelog entries from botocore
  • 19a915b Merge branch 'release-1.43.44'
  • 1b69a06 Merge branch 'release-1.43.44' into develop
  • b0e3f6a Bumping version to 1.43.44
  • Additional commits viewable in compare view

Updates ipython from 9.14.1 to 9.15.0

Commits
  • 2273f39 release 9.15.0
  • 4774918 fix
  • 4bec98b update whatsnew
  • 42fcfe4 [3.11] Skip stup for Numpy that is not using > 3.11 syntax
  • b5da9ac fix: clarify tk simple-prompt gui message
  • 00bcdee fix: don't let kitty graphics detection crash IPython startup
  • 60f2e26 Fix #12726: %run honors quotes when expanding glob args
  • 3ea7aa6 Strip ANSI escape sequences from Sphinx directive output
  • 9b7d419 Add %xmode Doctest mode for doctest friendly tracebacks
  • fdbdf1c Increase codecov threshold to 0.2% to avoid false PR failures
  • Additional commits viewable in compare view

Updates uvicorn from 0.49.0 to 0.51.0

Release notes

Sourced from uvicorn's releases.

Version 0.51.0

What's Changed

Full Changelog: Kludex/uvicorn@0.50.2...0.51.0

Version 0.50.1

What's Changed

New Contributors

Full Changelog: Kludex/uvicorn@0.50.0...0.50.1

Version 0.50.0

What's Changed

Full Changelog: Kludex/uvicorn@0.49.0...0.50.0

Changelog

Sourced from uvicorn's changelog.

0.51.0 (July 8, 2026)

Added

  • Restart workers one at a time on SIGHUP, bringing each replacement up before retiring the old worker, so reloads no longer drop requests (#3025)

Removed

  • Remove colorama from the standard extra (#3027)

0.50.2 (July 6, 2026)

Fixed

  • Require websockets>=13.0, which the default websockets-sansio implementation needs (#3021)

0.50.1 (July 6, 2026)

Fixed

  • Split comma-separated Sec-WebSocket-Protocol values in the websockets-sansio implementation (#3019)

0.50.0 (July 4, 2026)

If you use WebSockets, note that --ws auto now picks the websockets-sansio implementation. You shouldn't need it, but you can pin --ws websockets to get the deprecated legacy one back.

Changed

  • Exit with the dedicated code 3 on any startup failure: app loading, socket bind and lifespan startup errors previously exited with a mix of 0, 1 and 3 (#3001)
  • Stop the multiprocess supervisor when a worker exits with code 3 instead of restarting it forever (#3001)
  • Default --ws auto to websockets-sansio when websockets is installed (#2985)
  • Skip the eager app import in the parent process with --reload or --workers, fixing a memory regression introduced in 0.47.0 (#3012)
  • Build a fresh asgi scope dict per request (#2977)
  • Cache the asgi scope sub-dict per connection (#2976)
  • Avoid copying single-frame WebSocket payloads in websockets-sansio (#2983)
  • Memoize trusted host checks in ProxyHeadersMiddleware (#2970)
  • Replace click.style with an internal ANSI style helper (#2981)

Deprecated

  • Deprecate the legacy websockets implementation; use websockets-sansio or wsproto instead (#2985)
Commits
  • e4d0b05 Version 0.51.0 (#3028)
  • 944e43d Remove colorama from the standard extra (#3027)
  • 2e78770 Restart workers with overlap on SIGHUP for near-zero-downtime reloads (#3025)
  • a1b570c Version 0.50.2 (#3022)
  • 83c7da7 Require websockets>=13.0 for the default sansio implementation (#3021)
  • b4d0116 Version 0.50.1 (#3020)
  • 2a9151d Split comma-separated Sec-WebSocket-Protocol values in the websockets-sansi...
  • 1bf3ab4 Cover the excluded-directory branch in FileFilter with a direct test (#3014)
  • 837b5f9 Deflake multiprocess, reload, and signal supervisor tests (#2975)
  • 21d2c16 Version 0.50.0 (#3013)
  • Additional commits viewable in compare view

Updates fastapi from 0.138.0 to 0.139.0

Release notes

Sourced from fastapi's releases.

0.139.0

Features

  • ✨ Support dependencies in app.frontend(), e.g. for automatic cookie authentication for the frontend. PR #15908 by @​tiangolo.

Translations

Internal

0.138.1

Refactors

  • ♻️ Refactor Library Skills, make info easier to find for agents. PR #15841 by @​tiangolo.

Internal

... (truncated)

Commits
  • cecd96d 🔖 Release version 0.139.0 (#15910)
  • aea6609 📝 Update release notes
  • 319be50 ✨ Support dependencies in app.frontend(), e.g. for automatic cookie authent...
  • 66a90f6 📝 Update release notes
  • d30a3eb 👥 Update FastAPI People - Experts (#15909)
  • 122f1b5 📝 Update release notes
  • fd6ece3 👥 Update FastAPI GitHub topic repositories (#15906)
  • ec2a6ad 📝 Update release notes
  • 9d7d7fe 🌐 Update translations for fr (update-outdated) (#15897)
  • 8dc852d 📝 Update release notes
  • Additional commits viewable in compare view

Updates rio-tiler from 9.3.0 to 9.4.0

Release notes

Sourced from rio-tiler's releases.

9.4.0

What's Changed

Full Changelog: cogeotiff/rio-tiler@9.3.0...9.4.0

Changelog

Sourced from rio-tiler's changelog.

9.4.0 (2026-07-02)

  • change: _variables attribute in rio_tiler.experimental.zarr.GeoZarrReader to be a list of dict instead of a list of string

    # before
    with GeoZarrReader(input={zarr.AsyncGroup}) as src:
        print(src._variables)
        >> ["data:b1", "data:b2", "data:b3"]
    await src.info()
    >> {
        "bounds": ...
        "variables": ["data:b1", "data:b2", "data:b3"]
    }
    
    now
    with GeoZarrReader(input={zarr.AsyncGroup}) as src:
    print(src._variables)
    >> [
    {"name": "b1", "group": "data", "long_name": "data:b1", "multiscale": False, "nbands": 1},
    {"name": "b2", "group": "data", "long_name": "data:b2", "multiscale": False, "nbands": 1},
    {"name": "b3", "group": "data", "long_name": "data:b3", "multiscale": False, "nbands": 1}
    ]
    await src.info()
    >> {
        "bounds": ...
        "variables": [
            {"name": "b1", "group": "data", "long_name": "data:b1", "multiscale": False, "nbands": 1},
            {"name": "b2", "group": "data", "long_name": "data:b2", "multiscale": False, "nbands": 1},
            {"name": "b3", "group": "data", "long_name": "data:b3", "multiscale": False, "nbands": 1}
        ]
    }

  • change: change input for rio_tiler.experimental.zarr.get_group_metadata to accept no input group to get the metadata for the root group.

    # before
    with GeoZarrReader(input={zarr.AsyncGroup}) as src:
        await src.get_group_metadata("root")
    now
    with GeoZarrReader(input={zarr.AsyncGroup}) as src:
    await src.get_group_metadata()

Commits
  • c4b4d37 Bump version: 9.3.0 → 9.4.0
  • 09bf9cc chore: release date
  • 5955e9c feat(async-geozarr): add more variable info (#957)
  • be01299 fix: type
  • e086aae chore: update pre-commit config
  • 71bb272 chore(deps): update lockfile
  • fc35944 chore(deps): bump actions/checkout in the all group across 1 directory (#958)
  • 9f2267d chore(deps-dev): bump the all group with 3 updates (#960)
  • ab40c76 chore(deps): bump the all group with 5 updates (#959)
  • See full diff in compare view

Updates xarray from 2026.4.0 to 2026.7.0

Release notes

Sourced from xarray's releases.

v2026.07.0

This release adds support for Dask's query-optimizing expression arrays, along with new day_of_week and day_of_year datetime accessor attributes. It also includes a number of bug fixes, notably for a performance regression in :py:meth:Coordinates.to_index, Zarr fill_value round-tripping, and excessive memory use in drop_encoding.

Thanks to the 25 contributors to this release: Davis Bennett, Deepak Cherian, Ian Hunt-Isaak, Illviljan, Jonathan Dung, Julia Signell, Justus Magin, Kai Mühlbauer, MJSHANG, Mark Harfouche, Mathias Hauser, Matt Van Horn, Matthew Rocklin, Max Jones, Maximilian Roos, Nick Hodgskin, S Anand, Spencer Clark, Sreekant Baheti, Timothy Hodson, Tom Nicholas, Vincent Gao, Wali Reheman, Wei Ji and eeshsaxena

What's Changed

... (truncated)

Commits

Updates gcsfs from 2026.6.0 to 2026.7.0

Release notes

Sourced from gcsfs's releases.

2026.7.0

What's Changed

New Contributors

... (truncated)

Commits
  • 0c845df chore: release 2026.7.0 (#953)
  • 91319ec fix(macrobenchmarks): fix cloud build machine type networkPerformanceConfig e...
  • 80ea100 fix(macrobenchmarks): use random optimizer moments, not zeros, in CPU sim (#949)
  • 4ce07fe test(macrobench): use default DDP timeout in llama CPU simulation (#947)
  • 25d99d9 Update release process documentation (#945)
  • 28cdac6 Add permissions and path filters to release-on-merge workflow (#944)
  • 1b08827 fix(cleanup): retry GKE cluster deletion on failure (#943)
  • 8f47e73 fix(macrobenchmarks): remove HNS validation and external model bucket check (...
  • 3fb3782 fix: seed timer at training start to avoid AttributeError (#941)
  • a91711f Automate monthly release process (#916)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the all group with 9 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [httpx2](https://github.com/pydantic/httpx2) | `2.4.0` | `2.5.0` |
| [obstore](https://github.com/geospatial-jeff/pyasyncio-benchmark) | `0.10.1` | `0.11.0` |
| [boto3](https://github.com/boto/boto3) | `1.43.0` | `1.43.46` |
| [ipython](https://github.com/ipython/ipython) | `9.14.1` | `9.15.0` |
| [uvicorn](https://github.com/Kludex/uvicorn) | `0.49.0` | `0.51.0` |
| [fastapi](https://github.com/fastapi/fastapi) | `0.138.0` | `0.139.0` |
| [rio-tiler](https://github.com/cogeotiff/rio-tiler) | `9.3.0` | `9.4.0` |
| [xarray](https://github.com/pydata/xarray) | `2026.4.0` | `2026.7.0` |
| [gcsfs](https://github.com/fsspec/gcsfs) | `2026.6.0` | `2026.7.0` |



Updates `httpx2` from 2.4.0 to 2.5.0
- [Release notes](https://github.com/pydantic/httpx2/releases)
- [Changelog](https://github.com/pydantic/httpx2/blob/main/src/httpx2/CHANGELOG.md)
- [Commits](pydantic/httpx2@v2.4.0...v2.5.0)

Updates `obstore` from 0.10.1 to 0.11.0
- [Commits](https://github.com/geospatial-jeff/pyasyncio-benchmark/commits)

Updates `boto3` from 1.43.0 to 1.43.46
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](boto/boto3@1.43.0...1.43.46)

Updates `ipython` from 9.14.1 to 9.15.0
- [Release notes](https://github.com/ipython/ipython/releases)
- [Commits](ipython/ipython@9.14.1...9.15.0)

Updates `uvicorn` from 0.49.0 to 0.51.0
- [Release notes](https://github.com/Kludex/uvicorn/releases)
- [Changelog](https://github.com/Kludex/uvicorn/blob/main/docs/release-notes.md)
- [Commits](Kludex/uvicorn@0.49.0...0.51.0)

Updates `fastapi` from 0.138.0 to 0.139.0
- [Release notes](https://github.com/fastapi/fastapi/releases)
- [Commits](fastapi/fastapi@0.138.0...0.139.0)

Updates `rio-tiler` from 9.3.0 to 9.4.0
- [Release notes](https://github.com/cogeotiff/rio-tiler/releases)
- [Changelog](https://github.com/cogeotiff/rio-tiler/blob/main/CHANGES.md)
- [Commits](cogeotiff/rio-tiler@9.3.0...9.4.0)

Updates `xarray` from 2026.4.0 to 2026.7.0
- [Release notes](https://github.com/pydata/xarray/releases)
- [Commits](pydata/xarray@v2026.04.0...v2026.07.0)

Updates `gcsfs` from 2026.6.0 to 2026.7.0
- [Release notes](https://github.com/fsspec/gcsfs/releases)
- [Commits](fsspec/gcsfs@2026.6.0...2026.7.0)

---
updated-dependencies:
- dependency-name: httpx2
  dependency-version: 2.5.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: all
- dependency-name: obstore
  dependency-version: 0.11.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: all
- dependency-name: boto3
  dependency-version: 1.43.46
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: all
- dependency-name: ipython
  dependency-version: 9.15.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: all
- dependency-name: uvicorn
  dependency-version: 0.51.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: all
- dependency-name: fastapi
  dependency-version: 0.139.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all
- dependency-name: rio-tiler
  dependency-version: 9.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all
- dependency-name: xarray
  dependency-version: 2026.7.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all
- dependency-name: gcsfs
  dependency-version: 2026.7.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels Jul 18, 2026
@vincentsarago

This comment was marked as outdated.

@vincentsarago
vincentsarago merged commit 6471560 into main Jul 20, 2026
10 checks passed
@vincentsarago
vincentsarago deleted the dependabot/uv/all-74a146d13b branch July 20, 2026 15:11
@dependabot @github

dependabot Bot commented on behalf of github Jul 20, 2026

Copy link
Copy Markdown
Contributor Author

Looks like this PR has been edited by someone other than Dependabot. That means Dependabot can't rebase it - sorry!

If you're happy for Dependabot to recreate it from scratch, overwriting any edits, you can request @dependabot recreate.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant