Skip to content

chore(deps): bump the python group across 1 directory with 6 updates - #189

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/python-860035f767
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/python-860035f767

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 4, 2026 •

Copy link
Copy Markdown
Contributor

Updates the requirements on dateparser, sentry-sdk, deepseek-harness-sdk, pyright, ruff and uv-build to permit the latest version.
Updates dateparser from 1.4.2 to 1.4.3

Release notes

Sourced from dateparser's releases.

1.4.3

Fixes:

  • Make parsing thread-safe: parsing from several threads no longer raises an intermittent KeyError from the shared language caches, and a DATE_ORDER or RELATIVE_BASE value meant for one parse no longer leaks into the settings that other parses read, where it could make them return a wrong date (#1346)
  • Do not share the language detector and the detected locale between search_dates() calls, so concurrent searches over text in different languages no longer return None or a date read in the wrong locale (#1371)
  • Resolve the BST and HDT timezone abbreviations to the offsets the tz database gives them, UTC+1 (British Summer Time) and UTC-9 (Hawaii-Aleutian Daylight Time), instead of +11 and -9:30, which no zone goes by those names today; abbreviations that the tz database maps to more than one offset, such as CST and IST, keep their current offset. Text carrying these abbreviations keeps its wall clock but moves by 10 hours for BST and 30 minutes for HDT, which can put the parsed instant on a different day (#1366)
  • Reject a %j (day of year) value that the parsed year does not have, instead of rolling it over into the next year, so "1999366" with date_formats=["%Y%j"] returns None rather than 2000-01-01. A format with no year directive is checked against the year strptime defaults to, 1900, which is not a leap year, so "366" with date_formats=["%j"] now returns None where it used to return January 1 (#1370)

Cleanups and internal improvements:

  • Add CodSpeed benchmarks and a workflow that runs them, so a performance regression such as the quadratic backtracking fixed in 1.4.1 is reported on the pull request that introduces it (#1365)
Changelog

Sourced from dateparser's changelog.

1.4.3 (2026-09-03)

Fixes:

  • Make parsing thread-safe: parsing from several threads no longer raises an intermittent KeyError from the shared language caches, and a DATE_ORDER or RELATIVE_BASE value meant for one parse no longer leaks into the settings that other parses read, where it could make them return a wrong date (#1346)
  • Do not share the language detector and the detected locale between search_dates() calls, so concurrent searches over text in different languages no longer return None or a date read in the wrong locale (#1371)
  • Resolve the BST and HDT timezone abbreviations to the offsets the tz database gives them, UTC+1 (British Summer Time) and UTC-9 (Hawaii-Aleutian Daylight Time), instead of +11 and -9:30, which no zone goes by those names today; abbreviations that the tz database maps to more than one offset, such as CST and IST, keep their current offset. Text carrying these abbreviations keeps its wall clock but moves by 10 hours for BST and 30 minutes for HDT, which can put the parsed instant on a different day (#1366)
  • Reject a %j (day of year) value that the parsed year does not have, instead of rolling it over into the next year, so "1999366" with date_formats=["%Y%j"] returns None rather than 2000-01-01. A format with no year directive is checked against the year strptime defaults to, 1900, which is not a leap year, so "366" with date_formats=["%j"] now returns None where it used to return January 1 (#1370)

Cleanups and internal improvements:

  • Add CodSpeed benchmarks and a workflow that runs them, so a performance regression such as the quadratic backtracking fixed in 1.4.1 is reported on the pull request that introduces it (#1365)
Commits

Updates sentry-sdk from 2.68.1 to 2.70.0

Release notes

Sourced from sentry-sdk's releases.

2.70.0

New Features ✨

import sentry_sdk
from sentry_sdk.integrations.mistral import MistralIntegration
sentry_sdk.init(
dsn="...",
traces_sample_rate=1.0,
integrations=[
MistralIntegration(),
]
)

import sentry_sdk
sentry_sdk.init(
data_collection={
"user_info": False,
"gen_ai": {"inputs": False, "outputs": False},
"graphql": {"document": False, "variables": False},
"database_query_data": False,
"queues": False,
"http_bodies": [],
"cookies": {
"mode": "denylist",
"terms": ["forwarded", "-ip", "remote-", "via", "-user"],
},
"http_headers": {
"request": {
"mode": "denylist",
"terms": ["forwarded", "-ip", "remote-", "via", "-user"],
},
},
</tr></table>

... (truncated)

Changelog

Sourced from sentry-sdk's changelog.

2.70.0

New Features ✨

import sentry_sdk
from sentry_sdk.integrations.mistral import MistralIntegration
sentry_sdk.init(
dsn="...",
traces_sample_rate=1.0,
integrations=[
MistralIntegration(),
]
)

import sentry_sdk
sentry_sdk.init(
data_collection={
"user_info": False,
"gen_ai": {"inputs": False, "outputs": False},
"graphql": {"document": False, "variables": False},
"database_query_data": False,
"queues": False,
"http_bodies": [],
"cookies": {
"mode": "denylist",
"terms": ["forwarded", "-ip", "remote-", "via", "-user"],
},
"http_headers": {
"request": {
"mode": "denylist",
"terms": ["forwarded", "-ip", "remote-", "via", "-user"],
},
</tr></table>

... (truncated)

Commits
  • 1eb7df5 Update CHANGELOG.md
  • 92fd42b release: 2.70.0
  • d99edef ref(data-collection): Promote data_collection from _experiments o top-lev...
  • 045d2c1 test: Close client on teardown (#7562)
  • b454d7d feat(mistral): Record gen_ai.output.messages (#7549)
  • bdfd68c feat(mistral): Record gen_ai.input.messages (#7548)
  • ea08f64 feat(mistral): Record gen_ai.system_instructions (#7547)
  • dbddd0e feat(mistral): Record request parameters (#7531)
  • 9342968 feat(mistral): Record token usage (#7529)
  • 988fd0e feat(mistral): Add integration with Chat.complete and Chat.complete_async...
  • Additional commits viewable in compare view

Updates deepseek-harness-sdk from 0.1.1rc1 to 0.1.5rc1

Release notes

Sourced from deepseek-harness-sdk's releases.

v0.1.5-rc.1

中文 | English

作为 0.1.5 系列的首个候选版本,本版本汇总了自 v0.1.2-rc.1 以来的主要用户和开发者相关变更。

  • DeepSeek 模型适配器新增 DeepSeek-V41-Flash(deepseek-flash)支持文本、图片及会话历史中的系统提示词更新。新会话默认使用该模型,配置文件显式指定模型时以配置值为准。 @​LegGasai
  • Web 支持上传任意类型的通用文件:文件与图片可在同一预览区混排,后台上传支持进度、取消与会话切换续显,模型可通过已保存路径使用现有文件工具按需读取。 @​CreatixChu
  • 可继续对话的子代理支持消息排队、编辑、删除、单条或全部 Steer 与停止操作;排队消息发送期间显示“发送中”,并暂不可编辑、删除或 Steer。 @​Dudu-0223, @​LegGasai
  • 支持动态修改系统提示词且不破坏 KV Cache,模型需显式声明支持。 @​tianyicui
  • Web 右侧 Sidebar 支持多标签、分栏、全屏以及 Markdown、代码、HTML、PDF 和图片预览,包括子代理和未激活会话的文件;模型可显式交付文件,并可在 Sidebar 中预览、用默认应用打开或在文件管理器中定位。原 Detail 面板已移除。 @​imccyu, @​Yifffan, @​yixiangihsiang, @​CreatixChu, @​yudshj
  • 模型探测新增对自定义模型提供商 models 对象和 Anthropic 原生模型列表的支持,并支持回填模型名称、上下文窗口及最大输出 token 的回填。 @​LegGasai
  • 所有出站网络请求都会遵循启动环境中的 HTTP_PROXY、HTTPS_PROXY、ALL_PROXY 与 NO_PROXY 配置。 @​LegGasai
  • Web 顶栏新增“在应用中打开”,可用已安装的编辑器、IDE、终端或文件管理器等打开 Workspace。 @​yixiangihsiang
  • 反馈可独立提交,无需继续对话;/feedback 命令支持提交明细反馈内容,提交时附带相关会话内容。 @​tianyicui, @​Chinesezjc, @​CreatixChu

体验优化

  • Web 可直接显示顶层及 PTC 嵌套 read_image 的图片结果,以及模型回复中引用的 POSIX 绝对路径本地图片,包括工作区外截图;加载失败时显示替代文字或原路径。 @​Chinesezjc, @​kermanx
  • Skill 选择器支持模糊搜索;优化聊天气泡中的的 Skill 和命令引用。 @​LegGasai
  • 调整会话内可点击链接的颜色、hover/focus 样式和分类图标,优化 Markdown 链接、文件引用、网页来源、产物链接与 Workflow 成员链接的辨识度。 @​yixiangihsiang
  • Windows 上的本地非终端子进程不再弹出控制台窗口。 @​turtle1999
  • Agent Team 的 send_message 统一采用 steer 语义,并在跨 Agent 和冷恢复投递中保留发送者归属与顺序。 @​Dudu-0223
  • 改善长会话打开、恢复和持续对话时的卡顿,降低内存占用。 @​imccyu, @​tianyicui, @​Dudu-0223
  • 引用较长会话时,模型可按需读取预览中未展示的内容。 @​tianyicui
  • 改善设置面板的标签、开关状态样式,改善浅色和深色主题下的显示效果,改善本地化与可访问性 @​LegGasai, @​turtle2099
  • PTC 模式下支持展开查看命令及其输出。 @​tianyicui
  • 改善 Web 输入框的菜单层级、提示文字和间距;会话统计改为两个可展开的摘要,分别查看轮次与速度、精确 Token 用量与缓存命中。 @​Yifffan
  • 内置斜杠命令说明支持中文,并随界面语言即时更新;切换语言时保留已打开菜单和查询内容。 @​Kaige-Gao

问题修复

  • 用户在 Web 中暂停目标会立即终止当前模型轮次,且模型不能自行恢复;恢复必须由用户触发,尚未激活的目标也显示恢复入口。 @​mektpoy
  • 修复 DeepSeek 流式工具调用的续传分片用空值覆盖调用 ID 或名称的问题,避免工具以空名称失败并写入无法重新打开的会话记录。 @​LegGasai
  • 修复 Python SDK 单文件 runtime 将 Bash 中以 node 开头的命令错误重写为 dsh runtime 的问题。 @​imccyu
  • 修复从会话搜索结果进入会话后仍停留在搜索界面的问题;目标会话会在所属 Workspace 中展开并滚动到可见位置。 @​Dudu-0223
  • 修复 Windows 盘符根目录 Workspace 的路径分隔符、标题与绝对路径校验,确保盘符根目录可以正常使用。 @​turtle1999
  • 修复 Web 断线后无法自动恢复的问题。 @​LegGasai
  • 修复发送消息或调整窗口后,聊天不再自动滚动到底部的问题。 @​tianyicui
  • 修复 Windows 上 Python SDK 运行时可能出现的启动崩溃。 @​tianyicui
  • 修复会话运行中发送按钮与 Enter 的行为不一致:两者均遵循“繁忙时的发送行为”设置,并明确提示排队或插话发送。 @​lsdsjy
  • 拒绝不含正文或附件的空消息及空白队列编辑,保留仅发送图片或文件的能力。 @​turtle1999
  • 修复查找项目根目录遇到权限或 I/O 错误时误用上级项目指令的问题,相关错误会直接报告。 @​turtle1999
  • 修复折叠的思考摘要直接显示 Markdown 加粗标记的问题,展开内容保持完整。 @​turtle1999
  • 修复模型目录变化后失效的 pi-ai 配置导致整个模型设置入口消失的问题;错误项保留诊断和修复入口 @​LegGasai
  • 在发现模型或创建自定义 provider 前校验并规范化 Base URL,并直接提示无效地址。 @​turtle2099
  • 修复 Windows Web 界面的原生文件夹选择器可能在其他窗口后方打开的问题。 @​Elevator14B
  • 修复在 Composer 中输入空白字符后占位提示仍然显示的问题。 @​CreatixChu
  • 修复工具筛选后的子代理仍收到不可用文件和 Web 工具指导的问题。 @​koalazf99

... (truncated)

Commits
  • 183f08e Merge pull request #3912 from deepseek-harness/worktree/release/dsh-0.1.5-rc.1
  • 1ef9c1f release(dsh): 0.1.5-rc.1
  • ecc6f11 Merge pull request #3824 from deepseek-harness/worktree/deepseek-flash-catalog
  • 0729dbe feat(llm): restore V4 Flash Vision Exp catalog entry
  • 441385f feat(llm): retain V4 models alongside V41 Flash
  • c98fe6e test(web): pin the recorded model before scenario overlays
  • 719331e test: keep webhook smoke on the shipped model route
  • 61c5954 test: pin model routes in webhook and Cordis fixtures
  • bc5fd3b feat(llm): default Chat Completions to DeepSeek V41 Flash
  • 4cbaeb8 Merge pull request #3909 from deepseek-harness/fix/sidebar-preview-layout-polish
  • Additional commits viewable in compare view

Updates pyright from 1.1.411 to 1.1.414

Commits

Updates ruff from 0.16.5 to 0.16.9

Release notes

Sourced from ruff's releases.

0.16.9

Release Notes

Released on 2026-09-24.

Preview features

  • [ruff] Avoid false positives for overloaded division (RUF069) (#28309)

Bug fixes

  • [flake8-bugbear] Avoid false positives for calls with keyword arguments (B009, B010, B043) (#28776)
  • [flake8-tidy-imports] Allow lazy imports to be used in deferred annotations (TID255) (#28767)

Rule changes

  • Update LibCST-based fixes for Python 3.15 (#28616)
  • [flake8-pyi] Mention stubs in the diagnostic message (PYI002) (#28542)

Documentation

  • Fix horizontal overflow on the rules documentation page (#28699)
  • Update rules table with category information (#28651)
  • [flake8-annotations] Clarify that ANN401 checks return types in addition to arguments (#28334)
  • [flake8-bugbear] Document type-checker interaction (B010) (#28509)
  • [flake8-comprehensions] Document map/generator exception behavior (C417) (#27794)
  • [ruff] Mention related isort settings (RUF022) (#28719)

Contributors

Install ruff 0.16.9

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/ruff/releases/download/0.16.9/ruff-installer.sh | sh

... (truncated)

Changelog

Sourced from ruff's changelog.

0.16.9

Released on 2026-09-24.

Preview features

  • [ruff] Avoid false positives for overloaded division (RUF069) (#28309)

Bug fixes

  • [flake8-bugbear] Avoid false positives for calls with keyword arguments (B009, B010, B043) (#28776)
  • [flake8-tidy-imports] Allow lazy imports to be used in deferred annotations (TID255) (#28767)

Rule changes

  • Update LibCST-based fixes for Python 3.15 (#28616)
  • [flake8-pyi] Mention stubs in the diagnostic message (PYI002) (#28542)

Documentation

  • Fix horizontal overflow on the rules documentation page (#28699)
  • Update rules table with category information (#28651)
  • [flake8-annotations] Clarify that ANN401 checks return types in addition to arguments (#28334)
  • [flake8-bugbear] Document type-checker interaction (B010) (#28509)
  • [flake8-comprehensions] Document map/generator exception behavior (C417) (#27794)
  • [ruff] Mention related isort settings (RUF022) (#28719)

Contributors

0.16.8

Released on 2026-09-16.

Bug fixes

  • Visit functional TypedDict keyword arguments correctly (#28584)
  • [flake8-simplify] Detect nested async with under sync parent (SIM117) (#27821)
  • [flake8-simplify] Preserve operand order in SIM109 fix (#27824)

... (truncated)

Commits
  • 0be08a2 Bump version to 0.16.9 (#28882)
  • b4920b7 Rename ruff_cli to ruff_command_line (#28881)
  • 47c751b Update dependency astral-sh/uv to v0.12.18 (#28880)
  • 8c244e5 [flake8-comprehensions] Document map/generator exception behavior (C417...
  • 5edf5a1 Use target form in rooster.version_files (#28876)
  • 915bb2b [ty] Prefer existing @ paths over response files in Ruff and ty (#28877)
  • 4710e1a ci(github): update version number in placeholder of issue template (#28871)
  • eedfc62 [ty] Propagate outer type context through cast calls (#28855)
  • ceaa6a0 [ty] Contain rendered code within Markdown fences (#28869)
  • dba0f30 authorize ruff-pre-commit dispatch via OIDC (#28867)
  • Additional commits viewable in compare view

Updates uv-build to 0.12.19

Release notes

Sourced from uv-build's releases.

0.12.19

Release Notes

Released on 2026-09-24.

Python

  • Add PyPy 3.11.16 and 3.12.14 (#21847)
  • Update GraalPy 3.13.0 to build 25.4.4 (#21847)

Enhancements

  • Format upload URLs with backticks in uv publish errors (#21934)

Preview features

  • Run build-backend hooks with lazy imports on CPython 3.15 and later using the build-lazy-imports preview feature (#21967)
  • Omit unused resolution settings from uv.lock and ignore changes to them when checking lockfile freshness with the resolution-inputs preview feature (#21913)

Bug fixes

  • Preserve signed and encoded query parameters in direct-URL metadata to avoid reinstalling unchanged packages (#21971)
  • Recognize 1.0.0 as satisfying ===1 during installed-package checks, matching resolution (#21931)
  • Avoid collisions between Git checkout readiness markers and .ok files in dependencies (#21891)
  • Preserve always-false python_version markers when parsing their serialized form (#21939)

Rust API

  • Restore the public FlatDistributions export and its BTreeMap conversion for downstream resolvers (#21965)

Documentation

  • Make individual preview-feature reference entries linkable by name (#21950)

Install uv 0.12.19

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.19/uv-installer.sh | sh

Install prebuilt binaries via powershell script

powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.19/uv-installer.ps1 | iex"

Download uv 0.12.19

... (truncated)

Changelog

Sourced from uv-build's changelog.

0.12.19

Released on 2026-09-24.

Python

  • Add PyPy 3.11.16 and 3.12.14 (#21847)
  • Update GraalPy 3.13.0 to build 25.4.4 (#21847)

Enhancements

  • Format upload URLs with backticks in uv publish errors (#21934)

Preview features

  • Run build-backend hooks with lazy imports on CPython 3.15 and later using the build-lazy-imports preview feature (#21967)
  • Omit unused resolution settings from uv.lock and ignore changes to them when checking lockfile freshness with the resolution-inputs preview feature (#21913)

Bug fixes

  • Preserve signed and encoded query parameters in direct-URL metadata to avoid reinstalling unchanged packages (#21971)
  • Recognize 1.0.0 as satisfying ===1 during installed-package checks, matching resolution (#21931)
  • Avoid collisions between Git checkout readiness markers and .ok files in dependencies (#21891)
  • Preserve always-false python_version markers when parsing their serialized form (#21939)

Rust API

  • Restore the public FlatDistributions export and its BTreeMap conversion for downstream resolvers (#21965)

Documentation

  • Make individual preview-feature reference entries linkable by name (#21950)

0.12.18

Released on 2026-09-22.

This release addresses GHSA-2cv4-cqwr-gwf7, which is a path traversal weakness during wheel installation on Windows. No other platforms are affected by this advisory.

Enhancements

  • Add --output-format json to uv pip install and uv pip sync, including for --dry-run and --check (#21893)
  • Add --check to uv pip install and uv pip sync to report planned changes without modifying the environment (#21844)
  • Identify failures from get_requires_for_build_* hooks correctly in build errors (#21881)

Preview features

  • Validate build requirements for uv build --no-build-isolation with --preview-features build-dependency-check; use --skip-dependency-check to opt out (#21880)

Performance

... (truncated)

Commits

@dependabot
dependabot Bot requested a review from futrime as a code owner October 4, 2026 03:10
@dependabot dependabot Bot changed the title chore(deps): bump the python group with 6 updates chore(deps): bump the python group across 1 directory with 6 updates Oct 4, 2026
@dependabot
dependabot Bot force-pushed the dependabot/uv/python-860035f767 branch from 3f5e587 to 2a83f7d Compare October 4, 2026 10:29
@dependabot
dependabot Bot force-pushed the dependabot/uv/python-860035f767 branch 3 times, most recently from d8949db to b653cea Compare October 5, 2026 03:06
Updates the requirements on [dateparser](https://github.com/scrapinghub/dateparser), [sentry-sdk](https://github.com/getsentry/sentry-python), [deepseek-harness-sdk](https://github.com/deepseek-ai/deepseek-harness), [pyright](https://github.com/RobertCraigie/pyright-python), [ruff](https://github.com/astral-sh/ruff) and [uv-build](https://github.com/astral-sh/uv) to permit the latest version.

Updates `dateparser` from 1.4.2 to 1.4.3
- [Release notes](https://github.com/scrapinghub/dateparser/releases)
- [Changelog](https://github.com/scrapinghub/dateparser/blob/master/HISTORY.rst)
- [Commits](scrapinghub/dateparser@v1.4.2...v1.4.3)

Updates `sentry-sdk` from 2.68.1 to 2.70.0
- [Release notes](https://github.com/getsentry/sentry-python/releases)
- [Changelog](https://github.com/getsentry/sentry-python/blob/master/CHANGELOG.md)
- [Commits](getsentry/sentry-python@2.68.1...2.70.0)

Updates `deepseek-harness-sdk` from 0.1.1rc1 to 0.1.5rc1
- [Release notes](https://github.com/deepseek-ai/deepseek-harness/releases)
- [Commits](deepseek-ai/deepseek-harness@dsh-v0.1.1-rc.1...dsh-v0.1.5-rc.1)

Updates `pyright` from 1.1.411 to 1.1.414
- [Release notes](https://github.com/RobertCraigie/pyright-python/releases)
- [Commits](RobertCraigie/pyright-python@v1.1.411...v1.1.414)

Updates `ruff` from 0.16.5 to 0.16.9
- [Release notes](https://github.com/astral-sh/ruff/releases)
- [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md)
- [Commits](astral-sh/ruff@0.16.5...0.16.9)

Updates `uv-build` to 0.12.19
- [Release notes](https://github.com/astral-sh/uv/releases)
- [Changelog](https://github.com/astral-sh/uv/blob/main/CHANGELOG.md)
- [Commits](astral-sh/uv@0.12.7...0.12.19)

---
updated-dependencies:
- dependency-name: dateparser
  dependency-version: 1.4.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python
- dependency-name: deepseek-harness-sdk
  dependency-version: 0.1.5rc1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python
- dependency-name: pyright
  dependency-version: 1.1.414
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: python
- dependency-name: ruff
  dependency-version: 0.16.9
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: python
- dependency-name: sentry-sdk
  dependency-version: 2.70.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python
- dependency-name: uv-build
  dependency-version: 0.12.19
  dependency-type: direct:development
  dependency-group: python
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/uv/python-860035f767 branch from b653cea to 893b197 Compare October 5, 2026 13:57

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant