Skip to content

🔧 chore(deps): Bump the uv-production group with 4 updates - #16

Merged
Misery7100 merged 1 commit into
mainfrom
dependabot-uv-uv-production-2f58e63dbe
Oct 4, 2026
Merged

Misery7100 merged 1 commit into
mainfrom
dependabot-uv-uv-production-2f58e63dbe

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 4, 2026

Copy link
Copy Markdown
Contributor

Bumps the uv-production group with 4 updates: pydantic, typer, opensandbox and uvicorn.

Updates pydantic from 2.13.4 to 2.13.5

Release notes

Sourced from pydantic's releases.

v2.13.5 (2026-08-28)

What's Changed

Fixes

  • Allow reuse of validators when plugins are set by @​Viicos in #13535
  • Fix missing GC traversal on some pydantic-core struct fields by @​Viicos in #13624
  • Fix missing GC traversal in pydantic-core for GeneralFieldsSerializer by @​Viicos in #13629
  • Count validated model fields once in smart unions by @​tamird in #13731
Changelog

Sourced from pydantic's changelog.

v2.13.5 (2026-08-28)

GitHub release

What's Changed

Fixes

  • Allow reuse of validators when plugins are set by @​Viicos in #13535
  • Fix missing GC traversal on some pydantic-core struct fields by @​Viicos in #13624
  • Fix missing GC traversal in pydantic-core for GeneralFieldsSerializer by @​Viicos in #13629
  • Count validated model fields once in smart unions by @​tamird in #13731
Commits
  • 001dea0 Bump pypa/gh-action-pypi-publish action to v1.14.2
  • 558379f Bump twine to v7.0.0
  • 2cfd5d3 Do not check for docs build
  • a735bee Fix more Clippy lints
  • 7eed4a1 Fix Clippy 0.1.95 warnings
  • b353bbb Prepare release v2.13.5
  • 63d2ccc Count validated model fields once in smart unions
  • a53ec2e Speed up PyPy CI tests
  • d65e0f9 Workaround circular import error in Mypy
  • 47a6dbf Fix missing GC traversal in pydantic-core for GeneralFieldsSerializer
  • Additional commits viewable in compare view

Updates typer from 0.27.1 to 0.27.2

Release notes

Sourced from typer's releases.

0.27.2

Refactors

  • ♻️ Create exceptions module and TyperException base class. PR #1942 by @​svlandeg.

Docs

  • 🐛 Fix showing fast button as external link in animated terminals in docs. PR #1912 by @​phalberg.

Internal

Changelog

Sourced from typer's changelog.

0.27.2 (2026-08-28)

Refactors

  • ♻️ Create exceptions module and TyperException base class. PR #1942 by @​svlandeg.

Docs

  • 🐛 Fix showing fast button as external link in animated terminals in docs. PR #1912 by @​phalberg.

Internal

Commits

Updates opensandbox from 0.1.15 to 0.1.16

Release notes

Sourced from opensandbox's releases.

Python Sandbox SDK v0.1.16

What's New

✨ Features

  • Resilient HTTP transport — Async and sync clients now share a configurable retry transport with backoff, jitter, Retry-After handling, per-attempt timeouts, an overall deadline, and retry callbacks. Retries are enabled by default for idempotent requests on HTTP 429, 502, and 503; callers that require the previous fast-fail behavior can use RetryPolicy.disabled(). User-supplied transports remain untouched, and streaming SSE requests bypass replay. #1372
  • Sandbox lifecycle hooks — Sandbox.create and SandboxSync.create now accept optional preStart and periodic lifecycle hooks, with stable Python models and server-aligned validation. Hook timeout ranges remain server-authoritative. #1588 #1605
  • Background runs in isolated sessions — Isolated sessions can start detached work and poll its status and incremental combined output. Active background runs suspend idle collection; read-only workspaces reject background execution because they cannot persist run logs. #1456
  • Runtime allocation and hardening visibility — Sandbox responses can expose confirmed Pool allocation summaries, while isolated capabilities include execd init mode and hardening-layer state. These fields are additive and remain absent when the server cannot confirm the corresponding state. #1481 #1474
  • Pool capacity back-pressure — Compatible lifecycle servers can now surface exhausted Kubernetes Pool capacity as HTTP 429 with KUBERNETES::POOL_CAPACITY_EXHAUSTED and Retry-After, instead of eventually reporting a generic readiness timeout. Sandbox creation remains non-idempotent and is not automatically replayed on this status. #1581

⚡ Performance

  • Faster sandbox startup — Async sandbox creation, connection, and resume resolve execd and egress endpoints concurrently, reducing the two management API lookups to one parallel wait. Failure propagation and create cleanup semantics remain unchanged. #1531
  • Bounded parallel Pool cleanup — Idle sandbox release uses bounded concurrency while preserving best-effort cleanup and legacy public behavior. The measured 100-sandbox cleanup in the PR dropped from about 8.3 seconds to 0.8 seconds. #1475

🐛 Bug Fixes

  • Standards-compliant SSE parsing — Command and isolated execution streams now use SSE-specific framing, preserving Unicode separators inside JSON strings while remaining compatible with legacy bare-JSON frames. #1444
  • Reliable background command completion — Background command streams stop after execution_complete, preventing false RemoteProtocolError failures when the peer closes before the final HTTP terminator. Foreground streaming behavior is unchanged. #1532
  • Endpoint cache race fix — Completing an older endpoint fetch no longer removes a newer replacement inflight fetch in async or sync clients. #1567
  • More useful API errors — Unstructured 4xx and 5xx response bodies are included in exception messages and remain available as raw response_body bytes. HTTP 429 responses use SandboxRateLimitException and expose parsed retry_after when present. #1496 #1372
  • Cleaner readiness diagnostics — Readiness timeout messages retain timing, connection context, and the last health-check error without suggesting deployment-specific network fixes that may not apply. #1493

📦 Misc

  • Regenerated lifecycle models, bumped the package fallback version to 0.1.16, and aligned async and sync default User-Agent strings with the release. #1622 #1623

👥 Contributors

Commits
  • 169adf7 Merge pull request #1623 from ninan-nn/bump/python-sandbox-v0.1.16
  • 48ed648 Merge branch 'main' into bump/python-sandbox-v0.1.16
  • 402300d Merge pull request #1624 from opensandbox-group/fix/docs-dead-link-policy-tra...
  • 3748e3e docs: fix dead link to egress policy-traffic-vault-flow doc
  • 079e262 chore(python): bump sandbox SDK to 0.1.16
  • 60bf191 Merge pull request #1581 from hpliStartAgain/fix/pool-capacity-exhaustion
  • 420a8b9 Merge branch 'main' into fix/pool-capacity-exhaustion
  • d1c2aa2 Merge pull request #1622 from ninan-nn/feature/generate_api_20260825
  • cc878e7 Merge branch 'main' into fix/pool-capacity-exhaustion
  • bf37018 chore(sdks): update generated code
  • Additional commits viewable in compare view

Updates uvicorn from 0.52.4 to 0.54.0

Release notes

Sourced from uvicorn's releases.

Version 0.54.0

📨 Send metadata after the response body

uvicorn 0.54.0 adds response trailers and 103 Early Hints to its experimental HTTP/2 implementation through zttp.

uv add uvicorn==0.54.0 "zttp>=0.0.34"
  • Send HTTP/2 response trailers (#3146). The ASGI http.response.trailers extension lets applications send metadata, such as checksums, after the response body. Clients must send TE: trailers to receive them. Multiple trailer messages are combined before completing the response.
  • HTTP/2 remains experimental and opt-in. Enable it with --http zttp --http2. Upgrade-based h2c and WebSockets over HTTP/2 remain unsupported.

💡 Hint at resources before the final response

  • Send 103 Early Hints over HTTP/2 (#3137). Applications can use the ASGI http.response.early_hint extension to send resource hints before the final response. Each supplied link becomes a separate Link header.

Full changelog: 0.53.0...0.54.0

Version 0.53.0

🌐 Opt-in HTTP/2 support

uvicorn 0.53.0 adds experimental HTTP/2 through zttp, alongside a new zuvloop integration and connection-handling improvements.

uv add uvicorn==0.53.0
  • Serve HTTP/1.1 and HTTP/2 with zttp (#2982, #3101). Install zttp, then enable HTTP/2 with --http zttp --http2. Uvicorn negotiates HTTP/2 over TLS with ALPN and supports cleartext prior knowledge.
  • HTTP/2 remains experimental. Upgrade-based h2c and WebSockets over HTTP/2 are not supported.

⚙️ More event loop choice

  • Run Uvicorn with zuvloop (#3104). Install zuvloop separately and select it explicitly with --loop zuvloop on CPython 3.14 or newer.

🛡️ More reliable connections and proxies

  • Honor Connection: close token lists (#3103). Uvicorn now parses comma-separated tokens case-insensitively across HTTP implementations.
  • Trust IPv6 loopback proxies by default (#3119). The default FORWARDED_ALLOW_IPS value now includes ::1.
  • Keep upgraded WebSockets alive (#3107). Uvicorn cancels the HTTP keep-alive timer when the connection becomes a WebSocket.

Full changelog: 0.52.4...0.53.0

Changelog

Sourced from uvicorn's changelog.

0.54.0 (September 24, 2026)

HTTP/2 support remains experimental. Install zttp>=0.0.34 and enable it with --http zttp --http2.

Added

  • Add HTTP/2 response trailers through the ASGI http.response.trailers extension. Clients must send TE: trailers to receive them (#3146)
  • Add HTTP/2 103 Early Hints through the ASGI http.response.early_hint extension (#3137)

0.53.0 (September 14, 2026)

This release adds experimental HTTP/2 support through zttp. Enable it with --http zttp --http2. Upgrade-based h2c and WebSockets over HTTP/2 are not supported.

Added

  • Add experimental HTTP/2 support through zttp (#2982, #3101)
  • Add support for zuvloop (#3104)

Fixed

  • Handle comma-separated, case-insensitive Connection: close tokens across HTTP implementations (#3103)
  • Trust IPv6 loopback in the default FORWARDED_ALLOW_IPS value (#3119)
  • Cancel the HTTP keep-alive timer when upgrading to WebSocket (#3107)
Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the uv-production group with 4 updates: [pydantic](https://github.com/pydantic/pydantic), [typer](https://github.com/fastapi/typer), [opensandbox](https://github.com/opensandbox-group/OpenSandbox) and [uvicorn](https://github.com/Kludex/uvicorn).


Updates `pydantic` from 2.13.4 to 2.13.5
- [Release notes](https://github.com/pydantic/pydantic/releases)
- [Changelog](https://github.com/pydantic/pydantic/blob/v2.13.5/HISTORY.md)
- [Commits](pydantic/pydantic@v2.13.4...v2.13.5)

Updates `typer` from 0.27.1 to 0.27.2
- [Release notes](https://github.com/fastapi/typer/releases)
- [Changelog](https://github.com/fastapi/typer/blob/master/docs/release-notes.md)
- [Commits](fastapi/typer@0.27.1...0.27.2)

Updates `opensandbox` from 0.1.15 to 0.1.16
- [Release notes](https://github.com/opensandbox-group/OpenSandbox/releases)
- [Commits](opensandbox-group/OpenSandbox@python/sandbox/v0.1.15...python/sandbox/v0.1.16)

Updates `uvicorn` from 0.52.4 to 0.54.0
- [Release notes](https://github.com/Kludex/uvicorn/releases)
- [Changelog](https://github.com/Kludex/uvicorn/blob/main/docs/release-notes.md)
- [Commits](Kludex/uvicorn@0.52.4...0.54.0)

---
updated-dependencies:
- dependency-name: pydantic
  dependency-version: 2.13.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: uv-production
- dependency-name: typer
  dependency-version: 0.27.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: uv-production
- dependency-name: opensandbox
  dependency-version: 0.1.16
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: uv-production
- dependency-name: uvicorn
  dependency-version: 0.54.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: uv-production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Oct 4, 2026
@Misery7100
Misery7100 merged commit 144ee78 into main Oct 4, 2026
5 checks passed
@dependabot
dependabot Bot deleted the dependabot-uv-uv-production-2f58e63dbe branch October 4, 2026 12:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant