Skip to content

chore(deps): bump gql from 3.5.3 to 4.0.0 - #23

Closed
dependabot[bot] wants to merge 2 commits into
mainfrom
dependabot/pip/gql-4.0.0
Closed

dependabot[bot] wants to merge 2 commits into
mainfrom
dependabot/pip/gql-4.0.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 22, 2026 •

Copy link
Copy Markdown
Contributor

Bumps gql from 3.5.3 to 4.0.0.

Release notes

Sourced from gql's releases.

v4.0.0

Breaking Changes

  • Change transports prototype using GraphQLRequest (#551)
  • Using GraphQLRequest instead of DocumentNode for gql, execute, subscribe methods (#556): This is a big change:
    • the gql and dsl_gql methods will now return a GraphQLRequest instead of a Document Node a GraphQLRequest is an object containing the document and optional variable_values and operation_name
    • ALL the execute and subscribe methods now receive a GraphQLRequest as main argument instead of a DocumentNode, variable_values and operation_name arguments
    • The old method of sending variable_values as an argument of execute or subscribe still works but is deprecated See https://gql.readthedocs.io/en/latest/usage/variables.html for the new syntax.
  • Fix subscription task cancel exception swallow (#548): Previously if a task was cancelled while a subscription task was active, the asyncio.CancelledError Exception would be swallowed by our code. This is not the case anymore so you should now trap that Exception yourself.
  • Clean up the file upload interface with FileVar class (#549): The file upload functionality has been modified to require FileVar instances for uploaded files (the old method still works but is deprecated). See https://gql.readthedocs.io/en/latest/usage/file_upload.html
  • Set logging level to DEBUG for all transports (#552)
  • introspection now requests deprecated input fields by default (#553) Note that some backends might not support this and return Unknown argument includeDeprecated. See #564
  • Trapping dependencies Exceptions into TransportConnectionFailed (#558): Now gql will trap Exceptions raised by dependencies when executing a request and will encapsulate that Exception into the TransportConnectionFailed Exception
  • Set ssl=True by default for AIOHTTPTransport (#538) (issue #529)
  • New TransportConnectionClosed Exception replacing ConnectionClosed Exception (#536)
  • websocket attribute removed from transport, now using _connected instead (#536)
  • Upgrade lastest websockets and Exceptions overhaul (#543)

Features

Batching requests is now fully supported, on sync or async transports, with automatic batching:

  • Implementation of execute_batch for async transports (#550)
  • Implementation of automatic batching for async (#554)

See https://gql.readthedocs.io/en/latest/advanced/batching_requests.html

Fixes

  • Fix httpx test deprecated warning (#542)
  • Refactor websockets transports (#536) :

Refactor WebSockets Transport with Dependency Injection Architecture

This major architectural improvement implements dependency injection patterns across the WebSockets transport layer, creating a more modular, testable, and extensible system:

  • Created abstract AdapterConnection interface in common/adapters/connection.py
  • Implemented concrete WebSocketsAdapter to wrap the websockets library

... (truncated)

Commits
  • 059caba Bump version number to 4.0.0
  • 7695620 Restrict graphql-core to <3.3 instead of <3.2.7 on stable branch
  • 16c76bf Merge branch 'master' into stable
  • dba4953 Documentation improvements (#561)
  • a90f923 Bump version number to 4.0.0b0
  • 4af703e Trapping dependencies Exceptions into TransportConnectionFailed (#558)
  • 4fa1553 Refactor transports (#557)
  • b3789ef Using GraphQLRequest instead of DocumentNode for gql, execute, subscribe meth...
  • b221c0e Remove MIT license classifier (#555)
  • 7fcb5b6 Implementation of automatic batching for async (#554)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

felixschndr and others added 2 commits September 22, 2026 17:57
Bumps [gql](https://github.com/graphql-python/gql) from 3.5.3 to 4.0.0.
- [Release notes](https://github.com/graphql-python/gql/releases)
- [Commits](graphql-python/gql@v3.5.3...v4.0.0)

---
updated-dependencies:
- dependency-name: gql
  dependency-version: 4.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Sep 22, 2026
@felixschndr

Copy link
Copy Markdown
Owner

@dependabot recreate

@dependabot @github

dependabot Bot commented on behalf of github Sep 23, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/pip/gql-4.0.0 branch September 23, 2026 06:35
@dependabot @github

dependabot Bot commented on behalf of github Sep 23, 2026

Copy link
Copy Markdown
Contributor Author

Oh no! Something went wrong on our end. Please try again later.

If the problem persists, please contact GitHub support for assistance 🙇

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant