Skip to content

Bump the python-security group across 1 directory with 2 updates - #3645

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/python-security-4a6c75412a
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/python-security-4a6c75412a

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 5, 2026

Copy link
Copy Markdown
Contributor

Bumps the python-security group with 2 updates in the / directory: datamodel-code-generator and httpx2.

Updates datamodel-code-generator from 0.57.0 to 0.64.0

Release notes

Sourced from datamodel-code-generator's releases.

0.64.0

Breaking Changes

Code Generation Changes

  • Self-referencing fields are now quoted with --disable-future-imports - When --disable-future-imports is set (no from __future__ import annotations and no native PEP 649 deferred evaluation on Python < 3.14), self-referencing and forward-referencing field annotations in regular BaseModel classes are now emitted as quoted forward references instead of bare names. Previously such annotations were left unquoted, producing invalid code that raised NameError (Ruff F821) at class-evaluation time. Output for the common case (with from __future__ import annotations or Python 3.14 native deferred annotations) is unchanged. Users who snapshot/golden-file generated output for the --disable-future-imports configuration with self-referencing models will see the annotation change from unquoted to quoted, e.g. children: Optional[List[Node]] → children: Optional[List["Node"]]. (#3387)

What's Changed

... (truncated)

Changelog

Sourced from datamodel-code-generator's changelog.

0.64.0 - 2026-06-14

Breaking Changes

Code Generation Changes

  • Self-referencing fields are now quoted with --disable-future-imports - When --disable-future-imports is set (no from __future__ import annotations and no native PEP 649 deferred evaluation on Python < 3.14), self-referencing and forward-referencing field annotations in regular BaseModel classes are now emitted as quoted forward references instead of bare names. Previously such annotations were left unquoted, producing invalid code that raised NameError (Ruff F821) at class-evaluation time. Output for the common case (with from __future__ import annotations or Python 3.14 native deferred annotations) is unchanged. Users who snapshot/golden-file generated output for the --disable-future-imports configuration with self-referencing models will see the annotation change from unquoted to quoted, e.g. children: Optional[List[Node]] → children: Optional[List["Node"]]. (#3387)

What's Changed

... (truncated)

Commits

Updates httpx2 from 2.10.0 to 2.12.0

Release notes

Sourced from httpx2's releases.

v2.12.0

Highlights

🛡️ Bounded response decompression

httpx2 now decodes gzip, deflate, Brotli, and Zstandard responses incrementally. Each decode step emits at most 1 MiB, so streaming a highly compressed response no longer requires materializing an entire inflated network chunk in memory (pydantic/httpx2#1126).

📦 Shared Zstandard API

Python 3.13 and earlier now use backports.zstd, which provides the same bounded incremental decompression API as compression.zstd on Python 3.14 and later (pydantic/httpx2#1146).

httpx2

Changed

Fixed

httpcore2

No changes since 2.11.0. Version bumped to stay in lockstep with httpx2.

Full Changelog: pydantic/httpx2@v2.11.0...v2.12.0

v2.11.0

Highlights

🌐 Public origin API

httpx2 now includes an immutable and hashable Origin value object, available through URL.origin. It provides normalized scheme, host, and effective port comparisons without including URL paths, queries, fragments, or credentials (pydantic/httpx2#1134).

🛠️ Request compatibility and validation

httpx2

Added

Changed

... (truncated)

Changelog

Sourced from httpx2's changelog.

2.12.0 (August 18th, 2026)

Changed

  • Use backports.zstd for Zstandard decoding on Python 3.13 and earlier. (#1146)

Fixed

  • Bound peak memory while streaming compressed responses and close response streams when decoding fails. (#1126)

2.11.0 (August 18th, 2026)

Added

  • Add the public Origin value object and URL.origin property for normalized, hashable origin comparisons. (#1134)

Changed

  • Require Brotli 1.2.0 or later for the brotli extra. (#1141)

Fixed

  • Restore deprecated status code aliases. (#1135)
  • Extract HTTP/2 release notes from changelog headings correctly. (#1136)
  • Respect explicit Transfer-Encoding headers and expose buffered request body lengths to WSGI applications. (#1137)
  • Validate multipart part header names and values before serialization. (#1142)
Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps the python-security group with 2 updates in the / directory: [datamodel-code-generator](https://github.com/datamodel-code-generator/datamodel-code-generator) and [httpx2](https://github.com/pydantic/httpx2).


Updates `datamodel-code-generator` from 0.57.0 to 0.64.0
- [Release notes](https://github.com/datamodel-code-generator/datamodel-code-generator/releases)
- [Changelog](https://github.com/datamodel-code-generator/datamodel-code-generator/blob/main/CHANGELOG.md)
- [Commits](datamodel-code-generator/datamodel-code-generator@0.57.0...0.64.0)

Updates `httpx2` from 2.10.0 to 2.12.0
- [Release notes](https://github.com/pydantic/httpx2/releases)
- [Changelog](https://github.com/pydantic/httpx2/blob/main/src/httpx2/CHANGELOG.md)
- [Commits](pydantic/httpx2@v2.10.0...v2.12.0)

---
updated-dependencies:
- dependency-name: datamodel-code-generator
  dependency-version: 0.64.0
  dependency-type: direct:development
  dependency-group: python-security
- dependency-name: httpx2
  dependency-version: 2.12.0
  dependency-type: direct:production
  dependency-group: python-security
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels Oct 5, 2026

@claude claude Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I reviewed this PR and found no bugs; because the generator jumps seven minor versions and I could not run the codegen reproducibility check locally, the CI gen_surface_types.py --check result is the one thing worth a human confirming before merge.

What was reviewed:

  • Only the dev-only codegen exact pin moves (pyproject.toml line 113); the runtime httpx2>=2.10.0 floor is unchanged and the 2.12.0 lock resolution stays within it, consistent with DEPENDENCY_POLICY.
  • uv.lock entries, hashes, and the requires-dev specifier all match the new pin.
  • Checked whether the new black/isort emscripten markers could change generated output: no, the script strips the generator header and re-formats with ruff format, so only semantic generator changes could cause drift.
Extended reasoning...

The change is a Dependabot bump touching only pyproject.toml and uv.lock: the codegen dev group's exact pin goes from datamodel-code-generator 0.57.0 to 0.64.0, and the locked (not floored) versions of httpx2 and httpcore2 move from 2.10.0 to 2.12.0. No source code, runtime dependency floors, or security-sensitive surface (auth, crypto, data handling) is touched, and no CODEOWNERS file exists. Approval was withheld only because the merge gate for this bump is whether the new generator still reproduces the committed surface types under scripts/gen_surface_types.py --check, and that command could not be executed in this review environment, so it rests on CI rather than on a result I observed. The hunt exited on dry_streak with no findings.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants