Skip to content

Bump the pip group with 5 updates - #712

Merged
ezio-melotti merged 1 commit into
mainfrom
dependabot/pip/pip-5549aceb99
Oct 1, 2026
Merged

ezio-melotti merged 1 commit into
mainfrom
dependabot/pip/pip-5549aceb99

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown
Contributor

Bumps the pip group with 5 updates:

Package From To
cachetools 7.1.7 7.2.0
multidict 6.7.1 6.9.1
pyparsing 3.3.2 3.3.3
sentry-sdk 2.68.1 2.70.0
yarl 1.24.5 1.25.1

Updates cachetools from 7.1.7 to 7.2.0

Changelog

Sourced from cachetools's changelog.

v7.2.0 (2026-09-16)

  • Deprecate use of cache=None to suppress caching with the @cached decorator.

  • Add support for Python 3.15.

  • Minor test improvements.

  • Minor documentation updates.

v7.1.8 (2026-08-31)

  • Reject negative maxsize in Cache.__init__.
Commits

Updates multidict from 6.7.1 to 6.9.1

Release notes

Sourced from multidict's releases.

6.9.1

Bug fixes

  • Fixed the C extension reading freed memory on free-threaded builds when a list handed to :py:meth:~multidict.MultiDict.update, :py:meth:~multidict.MultiDict.extend, :py:meth:~multidict.MultiDict.merge or the :py:class:~multidict.MultiDict and :py:class:~multidict.CIMultiDict constructors, a [key, value] item inside any iterable handed to them, or a list tested with in against :py:meth:~multidict.MultiDict.items, is changed by another thread; a call that catches the list shrinking under it now raises :py:exc:RuntimeError -- by :user:rodrigobnogueira.

    Related issues and pull requests on GitHub: #1437.

  • Fixed a data race on the free-threaded build where a retired hash table's reader count used relaxed atomics, letting a lock-free get()/getone()/ __getitem__() read race a concurrent free of that table. The reader-exit decrement and the drain's free check now use release/acquire ordering instead -- by :user:asvetlov.

    Related issues and pull requests on GitHub: #1481.

  • Fixed a free-threaded build bug where two threads calling update(), merge(), or __setitem__() on the same key at the same time could lose the key entirely instead of just racing on which value wins. A decref of the replaced value could transiently suspend the writer's critical section, letting a second writer for the same key observe the first writer's in-progress entry as absent and, once both settled, mistake it for a stale duplicate and delete it. Every such decref is now deferred until the writer has released its critical section, so the window can no longer open. setdefault() had an unrelated instance of the same blind spot (it could insert a duplicate rather than recognizing an in-flight key), fixed alongside it -- by :user:asvetlov.

    Related issues and pull requests on GitHub: #1483.

  • Fixed a free-threaded build bug where getall() and the items()/ keys()/values() equality path could raise KeyError or report a present, never-deleted key as missing. A concurrent update()/extend()/ __setitem__() call can have its critical section transiently suspended (a decref triggering a blocking allocator call) while an entry is marked as part of its own bookkeeping; a reader landing in that window used to treat the mark as "not found" instead of "still there, in flight" -- by :user:asvetlov.

    Related issues and pull requests on GitHub:

... (truncated)

Changelog

Sourced from multidict's changelog.

6.9.1

(2026-09-21)

Bug fixes

  • Fixed the C extension reading freed memory on free-threaded builds when a list handed to :py:meth:~multidict.MultiDict.update, :py:meth:~multidict.MultiDict.extend, :py:meth:~multidict.MultiDict.merge or the :py:class:~multidict.MultiDict and :py:class:~multidict.CIMultiDict constructors, a [key, value] item inside any iterable handed to them, or a list tested with in against :py:meth:~multidict.MultiDict.items, is changed by another thread; a call that catches the list shrinking under it now raises :py:exc:RuntimeError -- by :user:rodrigobnogueira.

    Related issues and pull requests on GitHub: :issue:1437.

  • Fixed a data race on the free-threaded build where a retired hash table's reader count used relaxed atomics, letting a lock-free get()/getone()/ __getitem__() read race a concurrent free of that table. The reader-exit decrement and the drain's free check now use release/acquire ordering instead -- by :user:asvetlov.

    Related issues and pull requests on GitHub: :issue:1481.

  • Fixed a free-threaded build bug where two threads calling update(), merge(), or __setitem__() on the same key at the same time could lose the key entirely instead of just racing on which value wins. A decref of the replaced value could transiently suspend the writer's critical section, letting a second writer for the same key observe the first writer's in-progress entry as absent and, once both settled, mistake it for a stale duplicate and delete it. Every such decref is now deferred until the writer has released its critical section, so the window can no longer open. setdefault() had an unrelated instance of the same blind spot (it could insert a duplicate rather than recognizing an in-flight key), fixed alongside it -- by :user:asvetlov.

    Related issues and pull requests on GitHub: :issue:1483.

  • Fixed a free-threaded build bug where getall() and the items()/ keys()/values() equality path could raise KeyError or report a present, never-deleted key as missing. A concurrent update()/extend()/ __setitem__() call can have its critical section transiently suspended (a decref triggering a blocking allocator call) while an entry is marked as

... (truncated)

Commits
  • 0a1770c Release 6.9.1 (#1504)
  • d220522 Upload release assets one at a time to avoid the secondary rate limit (#1503)
  • 30cd596 Stop a GIL-releasing del from segfaulting the standard C extension build ...
  • d1c331a Recheck the reader gate after taking the retired list (#1502)
  • b37f07c Allocate deferred decrefs in fixed-size blocks (#1501)
  • 563f667 Run CodSpeed benchmarks on Python 3.14 and loop the smallest ones (#1498)
  • 157c87c Cancel superseded CI runs on pull requests (#1500)
  • d43adfe Drop -I from the ASan test command so PYTHONMALLOC takes effect (#1499)
  • 2a68472 Stop items() iteration from reading a freed entry in CIMultiDict (#1496)
  • cd528d6 Rename GHSA-54p9-h82j-f925 changelog fragment to the merged commit (#1495)
  • Additional commits viewable in compare view

Updates pyparsing from 3.3.2 to 3.3.3

Changelog

Sourced from pyparsing's changelog.

Version 3.3.3 - in development

  • Added support for Python 3.15.

  • Parse actions that return a tuple value for a named expression formerly saved just the first value of the tuple. Now they return the entire tuple. Partially fixes Issue #401, PR #640 submitted by Vincent Gao et AI.

  • Fixed CI unit test jobs selecting a tox environment with no test commands. The matrix and fallback now select py-unit, as diagnosed and proposed by glaziermag in issue #662; submitted by Neal Lin et AI.

  • Fixed Dict returning an empty nested ParseResults.as_dict() as [] instead of {}. Incorporates partial solution submitted in PR #635 submitted by Leo Ji.

    Additional fixes found as part of this work:

    • Removed vestigial unused ParseResults._modal attribute.

    • Fixed incidental bug when Dict tries to create a dict with a ParseResults value for a key (not hashable).

  • Fixed Word(..., max=n) raising instead of matching up to max characters when the character set contained whitespace - Word(nums, max=3) and Word(nums + " ", max=3) gave opposite results on the same input. Now both forms match up to max and leave the rest for the next parser. PR #646 submitted by Andrew Chen et AI.

  • Fixed QuotedString stripping whitespace that is part of a multi-character quote delimiter, e.g. the leading newline in QuotedString("\n;", multiline=True). The delimiter was silently collapsed to ";", so the newline was ignored when matching. QuotedString now only rejects quote_char/end_quote_char values that are empty or entirely whitespace, and preserves any surrounding whitespace that is part of a valid delimiter. Reported in issue #492.

  • Fixed pyparsing_common.as_datetime raising Invalid date/time: microsecond must be in 0..999999 for valid ISO-8601 timestamps whose fractional seconds round up to a full second (e.g. 2021-06-15T12:30:59.9999995, common in nanosecond-precision timestamps). The rounded microseconds are now added via timedelta so the value carries into the next second instead of overflowing the datetime microsecond argument. PR submitted by Andrew Chen et AI.

  • Fixed debug output corruption when a parsed line contains a carriage return or other control character. set_debug() printed the source line verbatim, so a stray \r returned the terminal cursor to column 0 and overwrote the "Match ... at loc" text. Control characters in the debug line are now shown escaped, and the marker caret stays aligned with the match location. Issue #496, reported by Matthew Rowles.

... (truncated)

Commits
  • d90d38b Update flit version and exclusion of generated railroad diagrams from source ...
  • 4220992 Updated CI to execute unit tests, PR #663; update test_unit.py to add test ca...
  • e266043 Reworked internal recursive implementations to use local stack vars or iterat...
  • See full diff in compare view

Updates sentry-sdk from 2.68.1 to 2.70.0

Release notes

Sourced from sentry-sdk's releases.

2.70.0

New Features ✨

import sentry_sdk
from sentry_sdk.integrations.mistral import MistralIntegration
sentry_sdk.init(
dsn="...",
traces_sample_rate=1.0,
integrations=[
MistralIntegration(),
]
)

import sentry_sdk
sentry_sdk.init(
data_collection={
"user_info": False,
"gen_ai": {"inputs": False, "outputs": False},
"graphql": {"document": False, "variables": False},
"database_query_data": False,
"queues": False,
"http_bodies": [],
"cookies": {
"mode": "denylist",
"terms": ["forwarded", "-ip", "remote-", "via", "-user"],
},
"http_headers": {
"request": {
"mode": "denylist",
"terms": ["forwarded", "-ip", "remote-", "via", "-user"],
},
},
</tr></table>

... (truncated)

Changelog

Sourced from sentry-sdk's changelog.

2.70.0

New Features ✨

import sentry_sdk
from sentry_sdk.integrations.mistral import MistralIntegration
sentry_sdk.init(
dsn="...",
traces_sample_rate=1.0,
integrations=[
MistralIntegration(),
]
)

import sentry_sdk
sentry_sdk.init(
data_collection={
"user_info": False,
"gen_ai": {"inputs": False, "outputs": False},
"graphql": {"document": False, "variables": False},
"database_query_data": False,
"queues": False,
"http_bodies": [],
"cookies": {
"mode": "denylist",
"terms": ["forwarded", "-ip", "remote-", "via", "-user"],
},
"http_headers": {
"request": {
"mode": "denylist",
"terms": ["forwarded", "-ip", "remote-", "via", "-user"],
},
</tr></table>

... (truncated)

Commits
  • 1eb7df5 Update CHANGELOG.md
  • 92fd42b release: 2.70.0
  • d99edef ref(data-collection): Promote data_collection from _experiments o top-lev...
  • 045d2c1 test: Close client on teardown (#7562)
  • b454d7d feat(mistral): Record gen_ai.output.messages (#7549)
  • bdfd68c feat(mistral): Record gen_ai.input.messages (#7548)
  • ea08f64 feat(mistral): Record gen_ai.system_instructions (#7547)
  • dbddd0e feat(mistral): Record request parameters (#7531)
  • 9342968 feat(mistral): Record token usage (#7529)
  • 988fd0e feat(mistral): Add integration with Chat.complete and Chat.complete_async...
  • Additional commits viewable in compare view

Updates yarl from 1.24.5 to 1.25.1

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

---
updated-dependencies:
- dependency-name: cachetools
  dependency-version: 7.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: pip
- dependency-name: multidict
  dependency-version: 6.9.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: pip
- dependency-name: pyparsing
  dependency-version: 3.3.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: pip
- dependency-name: sentry-sdk
  dependency-version: 2.70.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: pip
- dependency-name: yarl
  dependency-version: 1.25.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: pip
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update Python code labels Oct 1, 2026
@codecov

codecov Bot commented Oct 1, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 100.00%. Comparing base (df05dd6) to head (5403779).
⚠️ Report is 1 commits behind head on main.

Impacted file tree graph

@@            Coverage Diff            @@
##              main      #712   +/-   ##
=========================================
  Coverage   100.00%   100.00%           
=========================================
  Files           18        18           
  Lines         2173      2173           
  Branches       100       100           
=========================================
  Hits          2173      2173           
Flag Coverage Δ
Python_3.10.21 100.00% <ø> (ø)
Python_3.11.16 100.00% <ø> (ø)
Python_3.12.14 100.00% <ø> (ø)
Python_3.13.15 100.00% <ø> (ø)
Python_3.14.7 100.00% <ø> (ø)
Python_3.15.0-rc.2 100.00% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@ezio-melotti
ezio-melotti merged commit 510e32f into main Oct 1, 2026
17 checks passed
@ezio-melotti
ezio-melotti deleted the dependabot/pip/pip-5549aceb99 branch October 1, 2026 09:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update Python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant