Update All non-major dependencies - #386
Open
renovate[bot] wants to merge 1 commit into
Open
Conversation
renovate
Bot
force-pushed
the
renovate/minor-or-patch
branch
8 times, most recently
from
August 16, 2026 18:38
9060411 to
d4e7cea
Compare
renovate
Bot
force-pushed
the
renovate/minor-or-patch
branch
3 times, most recently
from
August 20, 2026 14:54
1100cdb to
f050de8
Compare
renovate
Bot
force-pushed
the
renovate/minor-or-patch
branch
from
August 20, 2026 19:52
f050de8 to
793b676
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
==65.18.0→==65.19.1==5.1.0→==5.1.1==7.0.0→==7.1.1==0.9.10→==0.9.11==2.6.1→==2.7.0==3.17.2→==3.18.00.12.2→0.12.5==26.0.0→==26.1.0==1.2.2→==1.2.3==5.0.0→==5.0.1==0.16.1→==0.16.4==2.66.1→==2.68.0==2.1.0→==2.2.0Release Notes
allauth/django-allauth (django-allauth)
v65.19.1Compare Source
v65.19.0Compare Source
django-cms/django-cms (django-cms)
v5.1.1Compare Source
What's Changed
Full Changelog: django-cms/django-cms@5.1.0...5.1.1
django-commons/django-debug-toolbar (django-debug-toolbar)
v7.1.1Compare Source
Changelog
What's Changed
Full Changelog: django-commons/django-debug-toolbar@7.1.0...7.1.1
v7.1.0Compare Source
Changelog
django.tasks, Django 6.0+). On older versions of Django, the panel explains that upgrading is required.show_toolbar_with_dockeron Docker runtimes such as OrbStack that can resolvehost.docker.internalto an address outside the container network.What's Changed
New Contributors
Full Changelog: django-commons/django-debug-toolbar@7.0.0...7.1.0
django-cms/djangocms-text (djangocms-text)
v0.9.11Compare Source
===================
django-cms/djangocms-versioning (djangocms-versioning)
v2.7.0Compare Source
==================
What's Changed
Full Changelog: django-cms/djangocms-versioning@2.6.1...2.7.0
encode/django-rest-framework (djangorestframework)
v3.18.0Compare Source
What's Changed
Breaking changes
many=True) to dict format by @p-r-a-v-i-n in #9837Features
unaccenttoSearchFilterby @mgaligniana in #9385@throttle_scopefunction based view decorator by @d-ryzhykau in #9963nulls_distinctsupport toUniqueTogetherValidatorby @mag123c in #9866Bug fixes
choicesparam for non-editable fields by @ticosax in #9929ListFieldby @Natgho in #9902BooleanFieldrepresentation value by @emfpdlzj in #9973cc_delim_re usagewithsplit_header_valuefor Django 6.1+ compatibility by @laymonage in #9978set_rollbackto only rollback initialized connections by @jdetaeye in #9599Other changes
New Contributors
Full Changelog: encode/django-rest-framework@3.17.1...3.18.0
astral-sh/uv (ghcr.io/astral-sh/uv)
v0.12.5Compare Source
Released on 2026-08-14.
Python
Enhancements
Preview features
--indexand--default-indexto select configured package indexes by name with theindex-by-namepreview feature (#17455)cache-physical-spaceon filesystems that do not support physical-space accounting (#21133)Bug fixes
v0.12.4Compare Source
Released on 2026-08-13.
Enhancements
Requires-Python: >= 3.5.*(#21012)Preview features
uv check --no-install-projectand respectUV_NO_INSTALL_PROJECTto install dependencies without building or installing the project (#21085)uv checkhonor uv's color and progress settings, including quiet mode (#21086)Performance
Bug fixes
pythonw.exelaunchers for virtual environments created from managed Python minor-version links (#19235)uv lockto proceed when.venvis an unusable project environment (#21068)fork-strategywhen ordering forks created fromenvironmentsor existing lockfileresolution-markers(#21000)!=3.11.*, !=3.12.*inuv.lock(#21045)uv addupdates it (#21008)PYTHONEXECUTABLEand__PYVENV_LAUNCHER__overrides (#21075)uv version --bumpvalues (#21076)v0.12.3Compare Source
Released on 2026-08-07.
Python
Preview features
--output-formatto select automatic, human-readable, or raw-byte output foruv cache size(#20992)uv workspace metadata --quietwhile suppressing diagnostics (#20991)uv workspace metadataJSON output (#20990)Performance
Documentation
--python-pinto--pin-pythonin theuv init --bareexample (#20876)benoitc/gunicorn (gunicorn)
v26.1.0: gunicorn 26.1.0Compare Source
New Features
reload_extra_files: entries containing*,?or[are treated as patterns, so
ui/*/config.jsonwatches every view's configwithout listing them one by one. Patterns are re-expanded on every reload
check rather than once at startup, so a file created later starts being
watched without restarting gunicorn, and
**recurses. A pattern matchingnothing warns instead of failing, since with live expansion it may match later
(#1643,
#3662).
Security
checked against the advisory database.
tornado,h2,setuptoolsandpymdown-extensionspermitted vulnerable versions and now require the firstclean release;
pytestandhttpxwere unpinned and now carry floors. Thetornadoexample pinnedtornado<6, which was both the source of severaladvisories and older than the
>=6.5.0the tornado worker needs, so theexample could not run as pinned.
Bug Fixes
SIGHUP did not reload the logger configuration:
Arbiter.reload()re-read the configuration file but kept using the logger built at startup,
calling only
reopen_files()on its existing handlers. Changes tologconfig,logconfig_dict,logconfig_jsonandloglevelwere ignoreduntil a full restart, which in containers meant replacing the pod. The
existing logger now re-runs its setup on reload, so new handlers, formats
and levels take effect while the process identity and its listeners are
preserved, and re-running the setup no longer stacks duplicate syslog
handlers. An invalid log configuration on reload is not fatal either: the
error is reported on stderr, the previous working configuration is restored
and the master keeps running with it
(#3353).
Truncated chunked bodies accepted: RFC 9112 section 7.1.2 ends a chunked
body with
0 CRLF CRLF, the second CRLF being the mandatory empty trailersection.
ChunkedReader.parse_chunk_size()swallowed theNoMoreDataraisedwhile scanning for it, so a body cut short right after the last chunk line was
treated as complete instead of rejected. It now raises
ChunkMissingTerminator(#3382,
#3685).
--spewcrashed on dynamically generated code: the trace hook indexed the2-tuple returned by
inspect.getsourcelines()by line number rather thanindexing the list of lines, so a frame with no
__file__raisedAttributeError: 'int' object has no attribute 'rstrip'on line 1 andIndexErrorbeyond it. The tuple is now unpacked and offset by the source'sstarting line (#3344,
#3495).
Duplicate
HostandContent-Typeheaders accepted: RFC 9110 section 5.3allows only one of each, and a repeat cannot be merged into a list, so the
message means different things to gunicorn and to anything downstream. Both
are now rejected with
InvalidHeader. The check lives in the policy hookshared by both parsers, so the pure-Python and fast parsers agree. Duplicate
Content-Lengthwas already rejected and is unchanged(#3366,
#3548).
Non-worker children reported as failed workers:
reap_workers()reapsevery child through
waitpid(-1), including processes the kernel reparentedonto gunicorn when it runs as PID 1 in a container, but it logged the exit
status before checking whether the pid was ever a worker. An unrelated process
produced
Worker (pid:N) exited with code Mand triggered alerts. Moreseriously, such a process exiting with code 3 or 4 raised
HaltServerand shutthe server down. Ownership is now established first: the dirty arbiter is
reported as itself, unknown children are reaped silently at debug level, and
only real workers can halt the server
(#3220,
#3566).
Dirty arbiter exits were invisible on SIGCHLD:
handle_chld()calledreap_workers()first, whosewaitpid(-1)claimed the dirty arbiter beforereap_dirty_arbiter()could identify it, so the latter always hitECHILDandits reporting never ran. The dirty arbiter is now reaped first, and
reap_workers()recognises it if it exits mid-loop.Dirty arbiter returned stale responses after a worker timeout: when a
request reached
dirty_timeoutthe arbiter answered the client with a timeouterror but kept the worker connection open. The worker's late response was then
the first message waiting on that socket, so the next request routed to the
same worker received the previous request's result, and every request after it
stayed one response behind. The connection is now closed on timeout, so the
late answer is discarded with it
(#3626).
ASGI connection count leaked on server-initiated close:
nr_connswasonly decremented in
connection_lost(), behind a guard keyed on the sameflag
_close_transport()sets first. Every close the server started (aConnection: closeresponse, a keepalive timeout, an error abort) leaked onecount, so
ASGIWorker._shutdown()ran the fullgraceful_timeoutand warnedabout connections that were already gone. The guard now uses its own flag, so
the decrement and the rest of the cleanup run exactly once whichever side
closes first (#3661).
Inotify reloader on cwd-relative extra files:
reload_extra_filesentrieswith no directory part (for example
.env) produced an empty dirname, andwatching it raised
InotifyErrorwithENOENT. The current directory is nowwatched as
.(#3377,#3667).
StatsD zero-valued metrics: gauges, counters, histograms and timers
reporting
0were silently dropped because the value was tested fortruthiness. Only
Noneis skipped now(#3676).
Spurious no-body warning from
sendfile(): a HEAD, 204 or 304 responseserved through
sendfile()warned about dropped body bytes even when thefile was empty and nothing was dropped. It now warns only when there are
bytes to drop, matching
write()(#3684).
Bare
exceptin the gevent websocket example: narrowed toexcept Exception(#3683).ASGI
receive()cancellation: Letasyncio.CancelledErrorpropagatefrom
BodyReceiverinstead of swallowing it and returninghttp.disconnect. Frameworks that cancel their disconnect listener afterthe response completes (Django) no longer see the cancel masked, so
request_finishedfires andclose_old_connections()runs. Fixes idledatabase connections leaking since 25.1.0
(#3627,
#3654).
Control socket leak on SIGHUP reload: The control thread is now marked
ready once its loop and server are live, and the stop paths wait on that
readiness before scheduling shutdown. Reloads no longer leak one thread and
its selector fd plus unix socket per worker, which eventually raised
"too many open files"
(#3648).
WSGI body framing on HEAD/1xx/204/304: Mirror the ASGI strip-and-warn
behavior on the WSGI path.
Content-Lengthis stripped on 1xx/204 perRFC 9110 section 6.4.2, body bytes are dropped for no-body responses in
both
write()andsendfile(), and a single warning is logged per request(#3413).
Refactoring
termination message in
Arbiter.reap_workers()(#3678).
Changes
packagingis no longer a runtime dependency: it was only ever imported bythe gevent worker, to compare gevent's version. It moved to the
geventandtestingextras, so a plainpip install gunicornpulls in nothing(#3643).
Fast HTTP Parser: Require
gunicorn_h1c >= 0.6.6, which rejects duplicateHostandContent-Typeheaders in the C parser itself. Gunicorn alreadyrefuses them on both the WSGI and ASGI paths, so this changes nothing that is
reachable; it moves the rejection to where the bytes are read and lets the
ASGI corpus exercise those cases against the fast parser directly.
Full changelog: https://gunicorn.org/2026-news/
theskumar/python-dotenv (python-dotenv)
v1.2.3Compare Source
Fixed
.envfile contents so the first variable is no longer silently lost when the file is saved with BOM (e.g. by some JetBrains IDEs on Windows) by [@h1whelan] in [#640]set_keynow escapes backslashes, so values containing them (Windows paths, regular expressions) survive a write/read round-trip. Quoted values ending in an escaped backslash are no longer mis-parsed as an escaped quote, which used to swallow the following lines by [@dchaudhari7177] in [#680]dotenv runnow prints a friendly error instead of a traceback when no command is given by [@bbc2] in [#606].envfiles so repeateddotenv_values/load_dotenvcalls no longer re-read the file by [@ReinerBRO] in [#638]astral-sh/ruff (ruff)
v0.16.4Compare Source
Released on 2026-08-20.
Preview features
flake8-use-pathlib] Add autofix forPTH116(#26460)refurb] Restrictdelete-full-sliceto lists (FURB131) (#27711)refurb] SkipFURB101andFURB103when theopenargument is a file descriptor (#27643)Bug fixes
InvalidInstructionon Windows CPUs that do not supportPOPCNT(#27803)pyflakes] Emit semantic syntax errors in string type definitions asF722(#27835)pylint] Allowos._exitimports inimport-private-name(PLC2701) (#27738)Rule changes
ruff] Addctypes.LittleEndianStructureand related types to existing exception (RUF012) (#27753)nonlocal(#27628)Server
Documentation
Other changes
Contributors
v0.16.3Compare Source
Released on 2026-08-13.
Preview features
pylint] Fix false negatives on negative numbers (PLR6104) (#27251)pyupgrade] Add rule to replacewhile 1withwhile True(UP048) (#27190)Bug fixes
flake8-bandit] Also check keyword arguments (S602,S603,S607,S609) (#27687)pylint] Allowcontinueinfinallyon Python 3.8 (#27626)pylint] FixPLE1307false positive with bools (#27651)pylint] Fix false positives and negatives with%bformat character (PLE1300,PLE1307) (#27560)pylint] Improve handling of concatenated strings (PLE1300) (#27659)Rule changes
numpy] Makenp.chararrayautofix backwards-compatible (NPY201) (#27527)Performance
Exprsize to 64 bytes (#27591)CLI
ruff check --statisticsoutput (#27646)Documentation
ruff] Also suggestasyncio.TaskGroup(RUF006) (#27461)Other changes
Contributors
v0.16.2Compare Source
Released on 2026-08-06.
Bug fixes
flake8-pyi] Avoid false positives onsingledispatchfunctions (PYI041) (#27335)Server
Contributors
getsentry/sentry-python (sentry_sdk)
v2.68.0Compare Source
Important
We're making
enable_logsandenable_metricsno-op with this release (#7177), and they'll be dropped in the next major.Previously,
enable_logsalso controlled automatic logs collection from the logging and Loguru integrations. These integrations now get an integration-levelcapture_sentry_logsboolean option to allow for more control over the auto-collection. These options areFalseby default, i.e., nothing is auto-collected without your explicit opt-in.Action Needed
If you had
enable_logsset toTrue:sentry_sdk.logger.XAPI, no action necessary, the API will just work.LoggingIntegrationorLoguruIntegration, the auto-collection will be turned off in this release. You can switch auto-collection on explicitly with:If you had
enable_logsset toFalse:sentry_sdk.logger.XAPI, you'll need to remove the calls entirely or define abefore_send_logcallback to filter out unwanted logs.If you has
enable_metricsset toFalse:before_send_metricor remove the calls to the API.Why We're Doing This
We recognize this is a disruptive change for some folks and want to make it clear this is a one-off. We're removing the options because they were an unnecessary hurdle that one had to jump through to be able to use logs and metrics, and it was confusing why the logging API would not just work on its own. On the other hand, we wanted to give you more fine-grained control over automatic collection.
New Features ✨
Other
NoOpStreamedSpanby @alexander-alderman-webb in #7163NoOpStreamedSpaninset_transaction_name()by @alexander-alderman-webb in #7164NoOpStreamedSpanby @alexander-alderman-webb in #7162Bug Fixes 🐛
Internal Changes 🔧
HTTPX, HTTPX2
Other
v2.67.1Compare Source
Bug Fixes 🐛
v2.67.0Compare Source
New Features ✨
Batcher
Integrations
Langchain
Openai
gen_ai.tool.definitionsfor the Responses API by @alexander-alderman-webb in #6951gen_ai.tool.definitionsfor the Chat Completions API by [@alexander-alderman-weConfiguration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.