Skip to content

chore(deps): bump the uv group across 10 directories with 7 updates - #198

Open
dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/uv/uv-fe8b6d61e2
Open

dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/uv/uv-fe8b6d61e2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 24, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the uv group with 6 updates in the / directory:

Package From To
aiohttp 3.11.11 3.14.3
asyncmy 0.2.11 0.2.12
cryptography 46.0.3 50.0.0
anyio 4.9.0 4.14.2
gitpython 3.1.45 3.1.59
sqlparse 0.5.3 0.6.0
anyio 4.9.0 4.14.2
gitpython 3.1.45 3.1.59
sqlparse 0.5.3 0.6.0
asyncmy 0.2.11 0.2.12
anyio 4.9.0 4.14.2
asyncmy 0.2.11 0.2.12
cryptography 46.0.3 50.0.0
asyncmy 0.2.11 0.2.12
cryptography 46.0.3 50.0.0
asyncmy 0.2.11 0.2.12
cryptography 46.0.3 50.0.0
aiohttp 3.11.11 3.14.3
anyio 4.9.0 4.14.2
asyncmy 0.2.11 0.2.12
cryptography 46.0.3 50.0.0
asyncmy 0.2.11 0.2.12
cryptography 46.0.3 50.0.0
aiohttp 3.11.11 3.14.3
asyncmy 0.2.11 0.2.12
cryptography 46.0.3 50.0.0

Bumps the uv group with 3 updates in the /projects/api_ml directory: anyio, gitpython and sqlparse.
Bumps the uv group with 3 updates in the /projects/api_public directory: asyncmy, orjson and anyio.
Bumps the uv group with 3 updates in the /projects/job_hs_migration_v3 directory: asyncmy, cryptography and orjson.
Bumps the uv group with 2 updates in the /projects/job_prune_hs_data directory: asyncmy and cryptography.
Bumps the uv group with 3 updates in the /projects/scrape_task_producer directory: asyncmy, cryptography and orjson.
Bumps the uv group with 2 updates in the /projects/website directory: aiohttp and anyio.
Bumps the uv group with 3 updates in the /projects/worker_hiscore directory: asyncmy, cryptography and orjson.
Bumps the uv group with 4 updates in the /projects/worker_ml directory: aiohttp, asyncmy, cryptography and orjson.
Bumps the uv group with 3 updates in the /projects/worker_report directory: asyncmy, cryptography and orjson.

Updates aiohttp from 3.11.11 to 3.14.3
Updates asyncmy from 0.2.11 to 0.2.12

Release notes

Sourced from asyncmy's releases.

v0.2.12

Highlights

Major performance release — the protocol core was rebuilt around direct C-level parsing. asyncmy now ranks #1 in every benchmark, including against the C-based synchronous mysqlclient. Large result sets are 5-15x faster than 0.2.11.

  • Buffered packet reading: one socket read serves hundreds of row packets (previously 2 awaits per packet)
  • C-level bulk row parsing (parse_rows_from_buffer) with pointer-based protocol reads — no struct calls on the hot path
  • Direct cell decoding via CPython C-API (PyUnicode_DecodeUTF8, PyTuple_New)
  • Zero-decode numeric/temporal columns: int/float/datetime parse straight from wire bytes
  • Escape fast path for strings without special characters
  • Compiler tuning: -O3, cdivision, bounds-check-free parsing

See benchmark/README.md for methodology and numbers.

Security

Fixes

  • Fix AttributeError: 'Connection' object has no attribute 'ssl' in sha256_password auth branch. (#147, #148, thanks @​shychee)
  • Fix OKPacketWrapper.message containing 2 stray bytes (read_struct position bug).
  • Fix LoadLocalPacketWrapper missing attribute declarations (LOAD DATA LOCAL crash).
  • Fix potential integer overflow of rowcount/insert_id on unbuffered cursors and Windows.
  • Fix OverflowError when escaping ints outside the signed 64-bit range, e.g. unsigned BIGINT 2**64-1. (#35, #127)
  • Close connection when a query is cancelled mid-read to prevent stale results leaking into pooled reuse. (#107, #108)
  • Support MySQL 8.0.19+ INSERT ... AS alias ON DUPLICATE KEY UPDATE syntax in executemany. (#116, #120, thanks @​MarkReedZ)
  • Pool closes idle/recycled connections with QUIT instead of aborting the TCP stream. (#112, #113, thanks @​Cycloctane)
  • Use setuptools instead of deprecated distutils in build. (#106, thanks @​tijuca)

Build

  • Rename build.py to build_cython.py — it shadowed the PyPA build module under cibuildwheel v3's python -m build frontend, breaking wheel builds.

Full Changelog: long2ice/asyncmy@v0.2.11...v0.2.12

Changelog

Sourced from asyncmy's changelog.

0.2.12

  • Major performance improvement: buffered packet reading, C-level bulk row parsing, pointer-based protocol reads, direct cell decoding via CPython C-API, zero-decode numeric/temporal columns, escape fast path. Large result sets are 5-15x faster; asyncmy now ranks #1 in all benchmarks, details see https://github.com/long2ice/asyncmy/blob/dev/benchmark/README.md.
  • Fix OKPacketWrapper.message containing 2 stray bytes (read_struct position bug).
  • Fix LoadLocalPacketWrapper missing attribute declarations (LOAD DATA LOCAL crash).
  • Fix potential integer overflow of rowcount/insert_id on unbuffered cursors and Windows.
  • Benchmark suite now uses warmup + best-of-3 methodology.
  • Security: remove unsafe escape_dict — dict keys could reach SQL unescaped (CVE-2025-65896). (#134, #135, thanks @​Cycloctane)
  • Fix AttributeError: 'Connection' object has no attribute 'ssl' in sha256_password auth branch. (#147, #148, thanks @​shychee)
  • Support MySQL 8.0.19+ INSERT ... AS alias ON DUPLICATE KEY UPDATE syntax in executemany. (#116, #120, thanks @​MarkReedZ)
  • Pool closes idle/recycled connections with QUIT instead of aborting the TCP stream. (#112, #113, thanks @​Cycloctane)
  • Fix OverflowError when escaping ints outside the signed 64-bit range, e.g. unsigned BIGINT 2**64-1. (#35, #127)
  • Close connection when a query is cancelled mid-read to prevent stale results leaking into pooled reuse. (#107, #108)
  • Use setuptools instead of deprecated distutils in build. (#106, thanks @​tijuca)
Commits
  • 712add9 fix: rename build.py to avoid shadowing the PyPA build module
  • fc6c71e Merge pull request #105 from tijuca/fix-typo
  • 22e5ee1 fix: apply community fixes on top of protocol rewrite
  • 39a5e16 Merge pull request #113 from Cycloctane/close_with_quit
  • b664149 Merge pull request #120 from MarkReedZ/deprecation_fix
  • 6080458 Merge pull request #135 from Cycloctane/fix-escape-dict
  • ca9d9c9 Enhance asyncmy performance and functionality
  • f9d5264 Merge pull request #136 from waketzheng/feat-uv
  • 066d658 chore: add poetry lock file
  • 24f067f chore: update uv lock
  • Additional commits viewable in compare view

Updates cryptography from 46.0.3 to 50.0.0

Changelog

Sourced from cryptography's changelog.

50.0.0 - 2026-07-31


* **SECURITY ISSUE**:
  :func:`~cryptography.hazmat.primitives.serialization.pkcs7.pkcs7_decrypt_der`
  and its PEM and S/MIME variants no longer expose distinguishable errors or
  timing when unwrapping a ``RecipientInfo``'s ``encryptedKey``, which could
  act as a Bleichenbacher oracle for callers that decrypt untrusted messages.
  A random key is now substituted on failure, as described in :rfc:`3218`.
  Credit to **@X1AOxiang** for reporting the issue. **CVE-2026-69247**
* Deprecated Diffie-Hellman key exchange over finite fields (FFDH).
  Everything FFDH is deprecated, including the types in
  ``cryptography.hazmat.primitives.asymmetric.dh`` and loading FFDH keys or
  parameters with the key loading APIs. Users should migrate to a more
  modern key exchange algorithm.
* Added ``xof()`` class methods to
  :class:`~cryptography.hazmat.primitives.hashes.SHAKE128` and
  :class:`~cryptography.hazmat.primitives.hashes.SHAKE256` for constructing
  algorithm instances configured for use with
  :class:`~cryptography.hazmat.primitives.hashes.XOFHash`.
* The :mod:`X.509 verification <cryptography.x509.verification>` APIs are now
  considered stable and are subject to our API stability policy.
* Added the :doc:`/cobblestone` recipe, an implementation of the
  Cobblestone-128 and Cobblestone-256 instantiations of the `C2SP
  chunked-encryption specification
  <https://c2sp.org/chunked-encryption>`_ for streaming authenticated
  encryption of large messages.
* Parsing a Signed Certificate Timestamp list now rejects encodings that
  carry trailing bytes after the list or after an individual SCT, instead of
  silently ignoring them.
* Added support for using :class:`~cryptography.x509.Name` as a field type in
  the :doc:`/hazmat/asn1/index` module.
* Loading a public key or an EC private key now rejects DER where the
  ``subjectPublicKey`` (or EC ``publicKey``) ``BIT STRING`` declares a non-zero
  number of unused bits, instead of silently ignoring it.
* Parsing a CRL entry's ``InvalidityDate`` extension now rejects a
  ``GeneralizedTime`` that carries fractional seconds or another non-DER form,
  matching the strict encoding already required for every other X.509 time
  field.
* :func:`~cryptography.x509.ocsp.load_der_ocsp_request` and
  :func:`~cryptography.x509.ocsp.load_der_ocsp_response` now reject a request
  or response whose ``version`` field is not ``v1``, the only version defined
  by RFC 6960, matching the version validation already performed when loading
  certificates, CSRs and CRLs.
* :class:`~cryptography.hazmat.primitives.hashes.XOFHash` is now supported
  when building against AWS-LC.
* HMAC (and therefore PBKDF2-HMAC) with SHA-3 hashes is now supported when
  building against AWS-LC.
* Diffie-Hellman (:doc:`/hazmat/primitives/asymmetric/dh`) is now supported
  when building against AWS-LC.
</tr></table> 

... (truncated)

Commits

Updates anyio from 4.9.0 to 4.14.2

Release notes

Sourced from anyio's releases.

4.14.2

  • Changed ByteReceiveStream.receive() implementations to raise a ValueError when max_bytes is not a positive integer (#1191)
  • Fixed CapacityLimiter.total_tokens rejecting float("inf") when the limiter was instantiated outside of an event loop. The adapter setter checked for infinity by identity (value is math.inf), so only the exact math.inf singleton was accepted, while every backend setter (using math.isinf()) accepts any positive infinity (#1189; PR by @​greymoth-jp).
  • Fixed to_process.run_sync() deadlocking when the worker function writes enough data to sys.stderr to fill the (undrained) pipe buffer. The worker process now redirects sys.stderr to os.devnull as well, matching the documented behavior
  • Fixed TLSStream.wrap() matching an internationalized (unicode) host name against the peer certificate using IDNA 2003 (via the standard library) instead of IDNA 2008, which could cause the host name to be matched against the wrong certificate (#1208)
  • Fixed anyio.open_process() (and run_process()) ignoring the extra_groups argument, as it mistakenly passed the value of the group argument instead (#1209)
  • Fixed CapacityLimiter.acquire_nowait() and CapacityLimiter.acquire_nowait_on_behalf_of() raising trio.WouldBlock instead of anyio.WouldBlock on the trio backend when there are no tokens available (#1218)
  • Fixed CapacityLimiter on the asyncio backend over-granting tokens (borrowed_tokens exceeding total_tokens and available_tokens going negative) when a non-blocking acquire was made in the window between a token being released and the notified waiter resuming. The freed token is now reserved for the woken waiter right away, so the non-blocking acquire correctly raises WouldBlock (#1170; PR by @​gaoflow)
  • Fixed unnecessary CPU spin when delivering cancellation from CancelScope on asyncio under certain conditions, including improper cancel scope nesting (#1111)

4.14.1

  • Fixed teardown of higher-scoped async fixtures failing on asyncio with RuntimeError: Attempted to exit cancel scope in a different task than it was entered in when an async test raise an outcome exception (e.g., pytest.skip(), pytest.xfail(), or pytest.fail()) (#1179; PR by @​EmmanuelNiyonshuti)
  • Fixed CapacityLimiter.total_tokens rejecting a value of 0 when the limiter was instantiated outside of an event loop, contradicting the documented behavior of allowing 0 total tokens (#1183; PR by @​nyxst4ck)

4.14.0

  • Added support for Python 3.15

  • Added an asynchronous implementation of the itertools module (#998; PR by @​11kkw)

  • Added the local_port parameter to connect_tcp() to allow binding to a specific local port before connecting (#1067; PR by @​nullwiz)

  • Added support for custom capacity limiters in async path and file I/O functions and classes

  • Added the create_task() task group method for easier asyncio migration (returns a TaskHandle) (#1098)

  • Changed TaskGroup.start_soon() to return a TaskHandle

  • Added an option for TaskGroup.start() to return a TaskHandle (which then contains the start value in the start_value property)

  • Added the cancel() convenience method to TaskGroup as a shortcut for cancelling the task group's cancel scope

  • Improved the error message when a known backend is not installed to suggest the install command (#1115; PR by @​EmmanuelNiyonshuti)

  • Improved anyio.Path to preserve subclass types by returning Self in methods that return path objects (#1130; PR by @​EmmanuelNiyonshuti)

  • Changed the parameter type annotation in anyio.Path.write_bytes() to accept any ReadableBuffer, thus allowing it to accept bytearray and memoryview to match pathlib.Path.write_bytes() (#1135; PR by @​SAY-5)

  • Changed several type annotations to only accept callables returning coroutine-like objects instead of arbitrary awaitables:

    • TaskGroup.start_soon()
    • TaskGroup.start()
    • anyio.from_thread.run()

    This reverts an earlier change from v3.7.0 which was made in error. (#1153)

  • Changed anyio.run to support callables returning arbitrary awaitables at runtime on all backends. Previously, this only worked on asyncio (#1171; PR by @​gschaffner)

  • Changed several classes (and their subclasses) to have __slots__ (with __weakref__):

    • anyio.CancelScope

... (truncated)

Commits
  • c384f99 Bumped up the version
  • dbba29d Fixed 100% CPU spin on cancel scope misuse (#1217)
  • 6bbc6c3 Fix CapacityLimiter over-granting tokens on asyncio (#1172)
  • 6f82b25 Refactored TestTLSStream.test_receive_invalid_max_bytes() to be less flaky
  • be24b04 Relaxed timeouts to fix test flakiness
  • 8113506 Fix test flakiness caused by slow callback duration logging
  • 1e988b6 Fixed CapacityLimiter raising trio.WouldBlock instead of anyio.WouldBlock (#1...
  • 44713f3 Pin setup-uv to a commit sha across downstream jobs (#1213)
  • f1b7301 Fixed stderr writes in a worker subprocess causing a deadlock (#1207)
  • 212be93 Fix flaky test_tcp_listener_same_port using a hardcoded port (#1206)
  • Additional commits viewable in compare view

Updates gitpython from 3.1.45 to 3.1.59

Release notes

Sourced from gitpython's releases.

3.1.59 - Security

What's Changed

Full Changelog: gitpython-developers/GitPython@3.1.58...3.1.59

3.1.58 - Security and Fixes

What's Changed

New Contributors

Full Changelog: gitpython-developers/GitPython@3.1.57...3.1.58

3.1.57 - Security and Fixes

What's Changed

New Contributors

Full Changelog: gitpython-developers/GitPython@3.1.56...3.1.57

... (truncated)

Commits
  • 66340d7 prepare changelog prior to release
  • a5e047d Merge pull request #2211 from gitpython-developers/config-sanitize-more
  • ef7568e fix: ignore includes in submodule configuration
  • 4b4e47f fix: preserve multiline config values when writing
  • b473abb Merge pull request #2210 from gitpython-developers/fix-clone-unsafe-option
  • 5ff52cc Merge pull request #2209 from caroescm/fix-index-add-chmod
  • b68afff Block separate git directories during clone
  • 93677a0 fix: index.add() now supports filters (#2021)
  • 9729ed3 Merge pull request #2208 from gitpython-developers/security-fixes
  • ce9d8e8 prepare next release
  • Additional commits viewable in compare view

Updates sqlparse from 0.5.3 to 0.6.0

Changelog

Sourced from sqlparse's changelog.

Release 0.6.0 (Aug 13, 2026)

Notable Changes

  • Drop support for Python 3.8 and 3.9. Python 3.10+ is now required.
  • IMPORTANT: Fixes a potential denial of service attack (DOS) in the lexer, which consumed CPU quadratically on statements containing many unclosed dollar-quoted literals or multiline comments (CVE-2026-59893). See the security advisory for details: GHSA-prg7-hcfm-mfcr The vulnerability was discovered by EQSTLab, min8282 and 7thpark. Thanks for reporting!
  • IMPORTANT: Fixes a potential denial of service attack (DOS) when grouping deeply nested or very wide statements. Building a token group re-read the whole group on every step, so a small statement could keep a worker busy for a long time (CVE-2026-54284, pr848 by alhudz and tonghuaroot).
  • IMPORTANT: Fixes a potential denial of service attack (DOS) in format(sql, reindent=True), which consumed CPU quadratically on long lists of tuples. See the security advisory for details: GHSA-cfqr-cjx5-5jcm
  • IMPORTANT: Fixes a potential denial of service attack (DOS) on statements that consist only of comments (CVE-2026-71491). See the security advisory for details: GHSA-f2ff-p2ww-7p4p The vulnerability was discovered by @​sanktjodel. Thanks for reporting!
  • IMPORTANT: Backslashes are now escaped in the python and php output formats. Without escaping, SQL containing a backslash could break out of the generated string literal (CVE-2026-59894). See the security advisory for details: GHSA-3496-9g83-7v6x The vulnerability was discovered by @​7thParkk. Thanks for reporting!

Enhancements

  • Modernize type annotations in top-level API functions using PEP 585 and PEP 604 syntax.
  • END FOR and END CASE are now recognized as keywords.

Bug Fixes

  • Statement splitting was rewritten on a stack-based architecture. This fixes splitting of statements with nested BEGIN ... END blocks (issue845).
  • Fix function grouping being skipped in CREATE TABLE ... AS SELECT statements when the as keyword is lowercase (pr867 by Osamaali313).
  • Recognize ROW_FORMAT as a keyword so that ALTER TABLE ... ROW_FORMAT=... no longer merges the table name and the option into a single identifier (issue773, pr860 by apoorvdarshan).
  • Recognize MATERIALIZED as a keyword so it is parsed and formatted consistently in CREATE MATERIALIZED VIEW statements (issue752, pr854 by

... (truncated)

Commits
  • 2f40da9 Update version number.
  • 5753f15 Align the changelog entries for this release with previous ones
  • b9588d9 Unify the benchmark scripts on a shared harness
  • 519e416 Pair comment/dollar-quote delimiters at the lexer position
  • a51df6d Measure reindent offsets backwards to avoid quadratic CPU use
  • 73d9ccd Update CHANGELOG
  • d1d8060 Fix uncontrolled CPU consumption (ReDoS) in the lexer's handling of dollar-qu...
  • ef2012a Fix quadratic DoS in group_comments (GHSA-f2ff-p2ww-7p4p)
  • 26112dd Update Changelog.
  • 53ff44b Escape backslashes in output formatters.
  • Additional commits viewable in compare view

Updates anyio from 4.9.0 to 4.14.2

Release notes

Sourced from anyio's releases.

4.14.2

  • Changed ByteReceiveStream.receive() implementations to raise a ValueError when max_bytes is not a positive integer (#1191)
  • Fixed CapacityLimiter.total_tokens rejecting float("inf") when the limiter was instantiated outside of an event loop. The adapter setter checked for infinity by identity (value is math.inf), so only the exact math.inf singleton was accepted, while every backend setter (using math.isinf()) accepts any positive infinity (#1189; PR by @​greymoth-jp).
  • Fixed to_process.run_sync() deadlocking when the worker function writes enough data to sys.stderr to fill the (undrained) pipe buffer. The worker process now redirects sys.stderr to os.devnull as well, matching the documented behavior
  • Fixed TLSStream.wrap() matching an internationalized (unicode) host name against the peer certificate using IDNA 2003 (via the standard library) instead of IDNA 2008, which could cause the host name to be matched against the wrong certificate (#1208)
  • Fixed anyio.open_process() (and run_process()) ignoring the extra_groups argument, as it mistakenly passed the value of the group argument instead (#1209)
  • Fixed CapacityLimiter.acquire_nowait() and CapacityLimiter.acquire_nowait_on_behalf_of() raising trio.WouldBlock instead of anyio.WouldBlock on the trio backend when there are no tokens available (#1218)
  • Fixed CapacityLimiter on the asyncio backend over-granting tokens (borrowed_tokens exceeding total_tokens and available_tokens going negative) when a non-blocking acquire was made in the window between a token being released and the notified waiter resuming. The freed token is now reserved for the woken waiter right away, so the non-blocking acquire correctly raises WouldBlock (#1170; PR by @​gaoflow)
  • Fixed unnecessary CPU spin when delivering cancellation from CancelScope on asyncio under certain conditions, including improper cancel scope nesting (#1111)

4.14.1

  • Fixed teardown of higher-scoped async fixtures failing on asyncio with RuntimeError: Attempted to exit cancel scope in a different task than it was entered in when an async test raise an outcome exception (e.g., pytest.skip(), pytest.xfail(), or pytest.fail()) (#1179; PR by @​EmmanuelNiyonshuti)
  • Fixed CapacityLimiter.total_tokens rejecting a value of 0 when the limiter was instantiated outside of an event loop, contradicting the documented behavior of allowing 0 total tokens (#1183; PR by @​nyxst4ck)

4.14.0

  • Added support for Python 3.15

  • Added an asynchronous implementation of the itertools module (#998; PR by @​11kkw)

  • Added the local_port parameter to connect_tcp() to allow binding to a specific local port before connecting (#1067; PR by @​nullwiz)

  • Added support for custom capacity limiters in async path and file I/O functions and classes

  • Added the create_task() task group method for easier asyncio migration (returns a TaskHandle) (#1098)

  • Changed TaskGroup.start_soon() to return a TaskHandle

  • Added an option for TaskGroup.start() to return a TaskHandle (which then contains the start value in the start_value property)

  • Added the cancel() convenience method to TaskGroup as a shortcut for cancelling the task group's cancel scope

  • Improved the error message when a known backend is not installed to suggest the install command (#1115; PR by @​EmmanuelNiyonshuti)

  • Improved anyio.Path to preserve subclass types by returning Self in methods that return path objects (#1130; PR by @​EmmanuelNiyonshuti)

  • Changed the parameter type annotation in anyio.Path.write_bytes() to accept any ReadableBuffer, thus allowing it to accept bytearray and memoryview to match pathlib.Path.write_bytes() (#1135; PR by @​SAY-5)

  • Changed several type annotations to only accept callables returning coroutine-like objects instead of arbitrary awaitables:

    • TaskGroup.start_soon()
    • TaskGroup.start()
    • anyio.from_thread.run()

    This reverts an earlier change from v3.7.0 which was made in error. (#1153)

  • Changed anyio.run to support callables returning arbitrary awaitables at runtime on all backends. Previously, this only worked on asyncio (#1171; PR by @​gschaffner)

  • Changed several classes (and their subclasses) to have __slots__ (with __weakref__):

    • anyio.CancelScope

... (truncated)

Commits
  • c384f99 Bumped up the version
  • dbba29d Fixed 100% CPU spin on cancel scope misuse (#1217)
  • 6bbc6c3 Fix CapacityLimiter over-granting tokens on asyncio (#1172)
  • 6f82b25 Refactored TestTLSStream.test_receive_invalid_max_bytes() to be less flaky
  • be24b04 Relaxed timeouts to fix test flakiness
  • 8113506 Fix test flakiness caused by slow callback duration logging
  • 1e988b6 Fixed CapacityLimiter raising trio.WouldBlock instead of anyio.WouldBlock (#1...
  • 44713f3 Pin setup-uv to a commit sha across downstream jobs (#1213)
  • f1b7301 Fixed stderr writes in a worker subprocess causing a deadlock (#1207)
  • 212be93 Fix flaky test_tcp_listener_same_port using a hardcoded port (#1206)
  • Additional commits viewable in compare view

Updates gitpython from 3.1.45 to 3.1.59

Release notes

Sourced from gitpython's releases.

3.1.59 - Security

What's Changed

Full Changelog: gitpython-developers/GitPython@3.1.58...3.1.59

3.1.58 - Security and Fixes

What's Changed

New Contributors

Full Changelog: gitpython-developers/GitPython@3.1.57...3.1.58

3.1.57 - Security and Fixes

What's Changed

New Contributors

Full Changelog: gitpython-developers/GitPython@3.1.56...3.1.57

... (truncated)

Commits
  • 66340d7 prepare changelog...

    Description has been truncated

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels Sep 24, 2026
---
updated-dependencies:
- dependency-name: aiohttp
  dependency-version: 3.14.3
  dependency-type: direct:production
- dependency-name: aiohttp
  dependency-version: 3.14.3
  dependency-type: direct:production
- dependency-name: aiohttp
  dependency-version: 3.14.3
  dependency-type: direct:production
- dependency-name: anyio
  dependency-version: 4.14.2
  dependency-type: indirect
- dependency-name: anyio
  dependency-version: 4.14.2
  dependency-type: indirect
- dependency-name: anyio
  dependency-version: 4.14.2
  dependency-type: indirect
- dependency-name: anyio
  dependency-version: 4.14.2
  dependency-type: indirect
- dependency-name: asyncmy
  dependency-version: 0.2.12
  dependency-type: direct:production
- dependency-name: asyncmy
  dependency-version: 0.2.12
  dependency-type: direct:production
- dependency-name: asyncmy
  dependency-version: 0.2.12
  dependency-type: direct:production
- dependency-name: asyncmy
  dependency-version: 0.2.12
  dependency-type: direct:production
- dependency-name: asyncmy
  dependency-version: 0.2.12
  dependency-type: direct:production
- dependency-name: asyncmy
  dependency-version: 0.2.12
  dependency-type: direct:production
- dependency-name: asyncmy
  dependency-version: 0.2.12
  dependency-type: direct:production
- dependency-name: asyncmy
  dependency-version: 0.2.12
  dependency-type: direct:production
- dependency-name: cryptography
  dependency-version: 50.0.0
  dependency-type: direct:production
- dependency-name: cryptography
  dependency-version: 50.0.0
  dependency-type: direct:production
- dependency-name: cryptography
  dependency-version: 50.0.0
  dependency-type: direct:production
- dependency-name: cryptography
  dependency-version: 50.0.0
  dependency-type: direct:production
- dependency-name: cryptography
  dependency-version: 50.0.0
  dependency-type: direct:production
- dependency-name: cryptography
  dependency-version: 50.0.0
  dependency-type: direct:production
- dependency-name: cryptography
  dependency-version: 50.0.0
  dependency-type: direct:production
- dependency-name: gitpython
  dependency-version: 3.1.59
  dependency-type: indirect
- dependency-name: gitpython
  dependency-version: 3.1.59
  dependency-type: indirect
- dependency-name: orjson
  dependency-version: 3.11.6
  dependency-type: direct:production
- dependency-name: orjson
  dependency-version: 3.11.6
  dependency-type: direct:production
- dependency-name: orjson
  dependency-version: 3.11.6
  dependency-type: direct:production
- dependency-name: orjson
  dependency-version: 3.11.6
  dependency-type: direct:production
- dependency-name: orjson
  dependency-version: 3.11.6
  dependency-type: direct:production
- dependency-name: orjson
  dependency-version: 3.11.6
  dependency-type: direct:production
- dependency-name: sqlparse
  dependency-version: 0.6.0
  dependency-type: indirect
- dependency-name: sqlparse
  dependency-version: 0.6.0
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/uv/uv-fe8b6d61e2 branch from e1561ec to f2b3de4 Compare September 27, 2026 16:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants