Skip to content

chore(deps): bump the python-deps group with 3 updates - #7

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/python-deps-618dcf0c02
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/python-deps-618dcf0c02

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown
Contributor

Bumps the python-deps group with 3 updates: graphql-core, hypothesis and ruff.

Updates graphql-core from 3.2.12 to 3.3.0

Release notes

Sourced from graphql-core's releases.

v3.3.0

Stable release GraphQL-core v3.3.0, based on GraphQL.js v17.0.2.

This release supports Python 3.10 to 3.15.

This is the first stable release of GraphQL-core 3.3, which follows GraphQL.js 17. Since the minor version of GraphQL-core corresponds to the major version of GraphQL.js, this release contains breaking changes compared to GraphQL-core 3.2. Most of them come from GraphQL.js 17 and are described in the GraphQL.js v16 to v17 upgrade guide. If you need to stay compatible with GraphQL.js 16 or need support for Python 3.7 to 3.9, you can continue to use GraphQL-core 3.2.13.

Breaking changes compared to GraphQL-core 3.2.13:

  • Python 3.7 to 3.9 are no longer supported.
  • Functions and options that had been deprecated in GraphQL.js 16 have been removed.
  • AST nodes are now frozen dataclasses, and all AST collection fields are tuples instead of lists.
  • ExecutionContext has been renamed to Executor, and the parameter execution_context_class to executor_class.
  • subscribe() stays synchronous when possible, like execute(), and raises a GraphQLError for non-subscription operations. create_source_event_stream() now takes a built Executor (see Executor.build()) instead of the request arguments.
  • A Python int that cannot be represented exactly as a float now raises a GraphQLError when coerced to Float.
  • An explicit Undefined variable value is treated as omitted, so the variable's default applies.
  • Input coercion follows the specification more strictly, and default values are validated against their types.
  • Directives on directive definitions and directive extensions are now part of the language, so the parser option experimental_directives_on_directive_definitions has been removed.
  • Input objects that cannot be given a finite value are rejected by schema validation, with a new error message for circular input object references.
  • TypeInfo.get_input_type() and ValidationContext.get_input_type() return None inside list literals in custom scalar positions; use the new get_parent_input_type() for the enclosing scalar.

New features compared to GraphQL-core 3.2.13:

  • Incremental delivery with @defer and @stream via experimental_execute_incrementally(), following the current spec proposal.
  • Experimental fragment arguments (parser option experimental_fragment_arguments).
  • Operations can be aborted with an AbortSignal, raising an AbortedGraphQLExecutionError with the partial result, and executors support hooks.
  • The new function find_schema_changes() also reports safe changes, in addition to breaking and dangerous changes.
  • The API documentation has been updated to GraphQL.js 17; all examples in the docstrings are run as doctests.

Thanks to @​jkimbo for sponsoring this project, to @​Hama1cco for reporting a bug in the lexer, and to everybody who tested the pre-releases and reported issues.

v3.3.0rc1

Release candidate GraphQL-core v3.3.0rc1, based on GraphQL.js v17.0.0rc0.

This release candidate supports Python 3.10 to 3.14.

This is a security release. It fixes two denial-of-service vulnerabilities in the validator and the parser. Upgrading is recommended for all users of the 3.3 line.

Unlike the other releases in this series, v3.3.0rc1 does not correspond to a GraphQL.js release tag. It is a security release cut while the port of GraphQL.js v17 is still in progress, so the tracked version_js deliberately remains v17.0.0rc0.

Security fixes:

  • CVE-2026-75507 (GHSA-vj8h-fx38-h3vc, High) — the OverlappingFieldsCanBeMerged validation rule could be driven into quadratic and worse running time by a small, highly compressible query using repeated inline fragments, occupying a worker for minutes of CPU during validation, before any resolver runs. Validation now enforces a per-document comparison budget and aborts with a GraphQLError once it is exhausted.
  • CVE-2026-75508 (GHSA-r77w-qph3-7vf8, High) — comment tokens were allocated and retained but not counted toward the parser's max_tokens limit, so a comment-padded document could bypass the limit while allocating one token object per comment. max_tokens now counts every token the parser consumes, including skipped comments.

Please note the two behaviour changes this implies:

  • A pathological query that previously validated — slowly — now produces a validation error. Realistic queries stay far below the limit, which defaults to 250,000 field comparisons and can be adjusted by assigning to graphql.validation.rules.overlapping_fields_can_be_merged.MAX_FIELD_COMPARISONS.
  • Comments now count toward max_tokens, so a comment-heavy document that was previously accepted may now be rejected. If you parse documents with substantial comments and set max_tokens, you may need to raise the limit. The token_count of a parsed document now includes comments as well.

... (truncated)

Commits
  • 894141f Bump version
  • ef9b7e2 Update README for the stable release 3.3.0
  • c0b19ae Use simulation mode for CodSpeed benchmarks
  • 9f51841 docs: further improve general execution docs
  • 996cdae fix: detect default-value changes on input object fields
  • fac0e60 fix(map_schema_config): fix context for schema argument mapper
  • a4f31e3 feat: graduate directives on directives
  • a4b3f9c fix(KnownDirectivesRule): directive locations for input obj extensions
  • 9f566c1 OneOf Inhabitability
  • 9e93687 Remove incremental key from the formatted initial incremental result
  • Additional commits viewable in compare view

Updates hypothesis from 6.168.0 to 6.168.2

Commits
  • 32ebeb2 Bump hypothesis version to 6.168.2 and update changelog
  • ff7e800 Merge pull request #4886 from pschanely/atomic-constants-cache
  • e57fd12 Isolate the constants cache test from existing cache files
  • c8981a0 Write the local constants cache atomically
  • 9c55f97 Merge pull request #4877 from HypothesisWorks/create-pull-request/patch
  • 6cee8ce Bump hypothesis version to 6.168.1 and update changelog
  • d97fdf3 Merge pull request #4879 from Liam-DeVoe/more-wheels
  • 0b55178 Update pinned dependencies
  • 37da03c publish wheels for s390x and i686+musl
  • See full diff in compare view

Updates ruff from 0.16.8 to 0.16.9

Release notes

Sourced from ruff's releases.

0.16.9

Release Notes

Released on 2026-09-24.

Preview features

  • [ruff] Avoid false positives for overloaded division (RUF069) (#28309)

Bug fixes

  • [flake8-bugbear] Avoid false positives for calls with keyword arguments (B009, B010, B043) (#28776)
  • [flake8-tidy-imports] Allow lazy imports to be used in deferred annotations (TID255) (#28767)

Rule changes

  • Update LibCST-based fixes for Python 3.15 (#28616)
  • [flake8-pyi] Mention stubs in the diagnostic message (PYI002) (#28542)

Documentation

  • Fix horizontal overflow on the rules documentation page (#28699)
  • Update rules table with category information (#28651)
  • [flake8-annotations] Clarify that ANN401 checks return types in addition to arguments (#28334)
  • [flake8-bugbear] Document type-checker interaction (B010) (#28509)
  • [flake8-comprehensions] Document map/generator exception behavior (C417) (#27794)
  • [ruff] Mention related isort settings (RUF022) (#28719)

Contributors

Install ruff 0.16.9

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/ruff/releases/download/0.16.9/ruff-installer.sh | sh

... (truncated)

Changelog

Sourced from ruff's changelog.

0.16.9

Released on 2026-09-24.

Preview features

  • [ruff] Avoid false positives for overloaded division (RUF069) (#28309)

Bug fixes

  • [flake8-bugbear] Avoid false positives for calls with keyword arguments (B009, B010, B043) (#28776)
  • [flake8-tidy-imports] Allow lazy imports to be used in deferred annotations (TID255) (#28767)

Rule changes

  • Update LibCST-based fixes for Python 3.15 (#28616)
  • [flake8-pyi] Mention stubs in the diagnostic message (PYI002) (#28542)

Documentation

  • Fix horizontal overflow on the rules documentation page (#28699)
  • Update rules table with category information (#28651)
  • [flake8-annotations] Clarify that ANN401 checks return types in addition to arguments (#28334)
  • [flake8-bugbear] Document type-checker interaction (B010) (#28509)
  • [flake8-comprehensions] Document map/generator exception behavior (C417) (#27794)
  • [ruff] Mention related isort settings (RUF022) (#28719)

Contributors

Commits
  • 0be08a2 Bump version to 0.16.9 (#28882)
  • b4920b7 Rename ruff_cli to ruff_command_line (#28881)
  • 47c751b Update dependency astral-sh/uv to v0.12.18 (#28880)
  • 8c244e5 [flake8-comprehensions] Document map/generator exception behavior (C417...
  • 5edf5a1 Use target form in rooster.version_files (#28876)
  • 915bb2b [ty] Prefer existing @ paths over response files in Ruff and ty (#28877)
  • 4710e1a ci(github): update version number in placeholder of issue template (#28871)
  • eedfc62 [ty] Propagate outer type context through cast calls (#28855)
  • ceaa6a0 [ty] Contain rendered code within Markdown fences (#28869)
  • dba0f30 authorize ruff-pre-commit dispatch via OIDC (#28867)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the python-deps group with 3 updates: [graphql-core](https://github.com/graphql-python/graphql-core), [hypothesis](https://github.com/HypothesisWorks/hypothesis) and [ruff](https://github.com/astral-sh/ruff).


Updates `graphql-core` from 3.2.12 to 3.3.0
- [Release notes](https://github.com/graphql-python/graphql-core/releases)
- [Commits](graphql-python/graphql-core@v3.2.12...v3.3.0)

Updates `hypothesis` from 6.168.0 to 6.168.2
- [Release notes](https://github.com/HypothesisWorks/hypothesis/releases)
- [Commits](HypothesisWorks/hypothesis@v6.168.0...v6.168.2)

Updates `ruff` from 0.16.8 to 0.16.9
- [Release notes](https://github.com/astral-sh/ruff/releases)
- [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md)
- [Commits](astral-sh/ruff@0.16.8...0.16.9)

---
updated-dependencies:
- dependency-name: graphql-core
  dependency-version: 3.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-deps
- dependency-name: hypothesis
  dependency-version: 6.168.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: python-deps
- dependency-name: ruff
  dependency-version: 0.16.9
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: python-deps
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels Oct 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants