Skip to content

chore(deps): bump the python-runtime group across 1 directory with 18 updates - #282

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/backend_api_python/python-runtime-5cd129c003
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/backend_api_python/python-runtime-5cd129c003

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 9, 2026

Copy link
Copy Markdown
Contributor

Updates the requirements on ruff, yfinance, aiohttp, pandas, ta-lib, websocket-client, litellm, certifi, akshare, pyjwt, python-dotenv, cryptography, psycopg2-binary, redis, gunicorn, marshmallow, reportlab and alpaca-py to permit the latest version.
Updates ruff to 0.16.10

Release notes

Sourced from ruff's releases.

0.16.10

Release Notes

Released on 2026-10-01.

Preview features

  • Add a migration guide for categories (#28087)
  • [pyupgrade] Add rule for context manager iterator annotations (UP052) (#29000)

Performance

  • Reduce memory used by diagnostics (#28951)

Server

  • Avoid running uv format in untrusted workspaces (#28873)

Documentation

  • Fix links to moved changelog sections and renamed mdtests (#28941)
  • Add Python 3.15 as a supported version (#28907)
  • Add ty as a type checker example (#28906)

Other changes

  • Update Rust toolchain to 1.99 and MSRV to 1.97 (#29047)

Contributors

Install ruff 0.16.10

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/ruff/releases/download/0.16.10/ruff-installer.sh | sh

Install prebuilt binaries via powershell script

powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/ruff/releases/download/0.16.10/ruff-installer.ps1 | iex"

Download ruff 0.16.10

... (truncated)

Changelog

Sourced from ruff's changelog.

0.16.10

Released on 2026-10-01.

Preview features

  • Add a migration guide for categories (#28087)
  • [pyupgrade] Add rule for context manager iterator annotations (UP052) (#29000)

Performance

  • Reduce memory used by diagnostics (#28951)

Server

  • Avoid running uv format in untrusted workspaces (#28873)

Documentation

  • Fix links to moved changelog sections and renamed mdtests (#28941)
  • Add Python 3.15 as a supported version (#28907)
  • Add ty as a type checker example (#28906)

Other changes

  • Update Rust toolchain to 1.99 and MSRV to 1.97 (#29047)

Contributors

0.16.9

Released on 2026-09-24.

Preview features

  • [ruff] Avoid false positives for overloaded division (RUF069) (#28309)

Bug fixes

  • [flake8-bugbear] Avoid false positives for calls with keyword arguments (B009, B010, B043) (#28776)
  • [flake8-tidy-imports] Allow lazy imports to be used in deferred annotations (TID255) (#28767)

Rule changes

  • Update LibCST-based fixes for Python 3.15 (#28616)

... (truncated)

Commits
  • 3265ed1 Bump version to 0.16.10 (#29055)
  • e786964 Authorize shared PR security-review workflow to publish findings (#29052)
  • a81291e [ty] Defer uv workspace discovery until after project configuration (#28525)
  • b6a74d2 [ty] Refresh uv project metadata when uv files change (#28529)
  • 41d30df Update Rust toolchain to 1.99 and MSRV to 1.97 (#29047)
  • 317e0a3 [ty] Bound nested callable signature display (#29049)
  • 8546752 [ty] Fix member lookup on union-bounded type variables (#29018)
  • 56180bc [ty] Specialize instance members once (#29043)
  • aa9a1ff [ty] Avoid stale I/O diagnostics when closing deleted files (#28988)
  • 2d25346 [ty] Improve unresolved-import documentation (#29039)
  • Additional commits viewable in compare view

Updates yfinance to 1.7.0

Release notes

Sourced from yfinance's releases.

1.7.0

Main change:

  • history_metadata now lazy-loads tradingPeriods

Fixes for:

  • proxy
  • stock-split price-repair

Full changelog #2959

Thanks @​amosli

Changelog

Sourced from yfinance's changelog.

1.7.0

Features / improvements:

  • Make history_metadata lazy-load 'tradingPeriods' #2922 Fixes
  • Improve robustness of YfData when behind a SOCKS5 proxy #2953 Price repair:
  • Fix bug in volume-validation of stock-split-repair #2958

1.6.0

Features / improvements

1.5.2

Patches

  • Fix yfinance breaking with curl_cffi>=0.16

1.5.1

Minor

  • Fall back to chunked requests when single-URL fundamentals fetch times out #2811
  • Replace valuation-measures HTML scrape with timeseries API #2851 Patches
  • Determine login and subscription tier via the subscriptions API #2845
  • Preserve user login cookies across cookie-strategy switches #2850

... (truncated)

Commits
  • 3d9d2f0 Version 1.7.0
  • 43f3021 Merge pull request #2959 from ranaroussi/dev
  • 686a031 Minor test fix
  • fdede94 Merge pull request #2953 from amosli/fix/cookie-crumb-proxy-resilience
  • 5c1f64e Fixes for PR #2958
  • c732994 Merge pull request #2958 from ranaroussi/fix/price-repair-split-volume-valida...
  • ba7b650 Fix proxy wipe and make cookie/crumb failures non-fatal
  • 0f29c85 Fix bug in volume-validation of stock-split-repair, that was wrongly blocking...
  • baeca64 Merge pull request #2918 from dokson/fix/drop-nospam-extra
  • 5261b4d Drop unusable nospam extra and py2 cruft
  • Additional commits viewable in compare view

Updates aiohttp to 3.14.4
Updates pandas to 3.0.6

Release notes

Sourced from pandas's releases.

pandas 3.0.6

We are pleased to announce the release of pandas 3.0.6. This is a patch release in the 3.0.x series and includes some regression fixes and bug fixes. We recommend that all users of the 3.0.x series upgrade to this version. This is also the first release to support Python 3.15.

See the full whatsnew for a list of all the changes.

Pandas 3.0 supports Python 3.11 and higher. The release can be installed from PyPI:

python -m pip install --upgrade pandas==3.0.*

Or from conda-forge

conda install -c conda-forge pandas=3.0

Please report any issues with the release on the pandas issue tracker.

Thanks to all the contributors who made this release possible.

Commits
  • 2905718 RLS: 3.0.6
  • 3188ced [backport 3.0.x] BUG: read_csv(sep=None) raised TypeError instead of falling...
  • f097905 DOC: cleanup 3.0.6 whatsnew + mention Python 3.15 support (#68965) (#68969)
  • 4f68223 [backport 3.0.x] BUG: fix setting with bool column mask into 1-column DataFra...
  • e3df0e8 [backport 3.0.x] BUG: full-slice setitem into a pyarrow-backed array shared m...
  • b7735f6 Backport PR #66117 on branch 3.0.x (BUG: interpolate leaving NAs unfilled for...
  • bca0b77 [backport 3.0.x] BUG: read_csv leaked the string-intern table when a column f...
  • bca1e5d [backport 3.0.x] BUG: prevent external mutation of RangeIndex._data (CoW) (#6...
  • c95b42c [3.0.x] CI: skip cython-lint on pre-commit.ci (#68910)
  • 9cbd884 [backport 3.0.x] Backport of some already merged regression fixes (#68447)
  • Additional commits viewable in compare view

Updates ta-lib from 0.7.1 to 0.8.1

Release notes

Sourced from ta-lib's releases.

v0.8.1

  • [CHANGE]: talib.stream is now the real streaming API of TA-Lib C 0.8.1: stream.SMA(close) returns a handle, not a value. handle.value is the value at the last history bar, handle.update(bar) costs O(1) and returns that bar's value, handle.peek(bar) evaluates a forming bar without committing it, and handle.copy() forks it. stream.SMA.open_and_fill() returns the handle and the Function API's series in one pass. A multi-output function answers with the same tuple the Function API returns. The old last-value functions -- talib.stream.SMA, talib.stream_SMA, and their _ta_lib.pyi stubs -- are gone; talib/stream.pyi types the handles instead.

    Migrating is stream.X(...) -> stream.X(...).value, and the compiler cannot find the sites for you: if stream.CDLDOJI(o, h, l, c): used to test the pattern and now tests a handle, which is always true.

  • [NEW]: talib.InsufficientHistory, raised when a stream is opened with too little history. It is the library's one recoverable error, so it is catchable on its own rather than as a bare Exception.

  • [FIX]: help(talib.SUPERTREND) and the abstract stub named the outputs real and integer; they are supertrend and trend, the names abstract.Function('SUPERTREND').output_names already reported.

  • [FIX]: An empty array given to a function whose lookback is zero, such as talib.ACOS or talib.MA(x, timeperiod=1), made TA-Lib read and write one element outside the buffers, which could crash the interpreter later or corrupt memory silently. An empty input now returns empty outputs without calling TA-Lib, whatever the function and its parameters. The bug dates from 0.4.27.

v0.8.0

  • [NEW]: Support TA-Lib C 0.8.1, which is now the minimum required version.

  • [NEW]: The 40 functions TA-Lib C added since 0.7.1: AC, ADR, AO, CMF, CMOU, COPPOCK, CUMSUM, CVI, DONCHIAN, DPO, EFI, ER, ERI, FOSC, FRACTAL, HA, HMA, KC, KDJ, MARKETFI, MASSI, NVI, PERCENTILE, PERCENTRANK, PVI, PVO, PVT, QSTICK, RMA, RVI, RVOL, SMI, SUPERTREND, TSI, VHF, VORTEX, VWAP, VWMA, WAD, ZLEMA.

  • [NEW]: New moving averages: MA_Type.HMA, MA_Type.DISABLED, MA_Type.DEFAULT, MA_Type.ZLEMA and MA_Type.RMA.

  • [NEW]: set_unstable_period() and get_unstable_period() accept 'RMA', 'HA' and 'RVI'.

  • [FIX]: abstract raised KeyError on function and output flags added after this wrapper was written; unknown flag bits are now ignored.

  • [FIX]: A moving-average parameter not spelled exactly matype -- KDJ's slowk_matype -- defaulted to SMA rather than to the function's own documented default.

  • [FIX]: An integer output is documented as the candlestick -100/0/100 convention only for candlestick functions; SUPERTREND's is a trend direction.

  • [CHANGE]: APO and PPO now default matype to EMA, and BBANDS defaults timeperiod to 20, following TA-Lib C 0.8.1.

  • [FIX]: set_unstable_period() targeted the wrong function for every id after IMI (e.g. 'RSI' set PLUS_DM); ids now come from the C header. 'ADXR', 'MFI' and 'STOCHRSI' are no-ops that emit a DeprecationWarning.

  • [CHANGE]: Remove the unnecessary build runtime dependency and wheel build dependency.

  • [NEW]: Upgrade to Cython 3.3.0

Changelog

Sourced from ta-lib's changelog.

0.8.1

  • [CHANGE]: talib.stream is now the real streaming API of TA-Lib C 0.8.1: stream.SMA(close) returns a handle, not a value. handle.value is the value at the last history bar, handle.update(bar) costs O(1) and returns that bar's value, handle.peek(bar) evaluates a forming bar without committing it, and handle.copy() forks it. stream.SMA.open_and_fill() returns the handle and the Function API's series in one pass. A multi-output function answers with the same tuple the Function API returns. The old last-value functions -- talib.stream.SMA, talib.stream_SMA, and their _ta_lib.pyi stubs -- are gone; talib/stream.pyi types the handles instead.

    Migrating is stream.X(...) -> stream.X(...).value, and the compiler cannot find the sites for you: if stream.CDLDOJI(o, h, l, c): used to test the pattern and now tests a handle, which is always true.

  • [NEW]: talib.InsufficientHistory, raised when a stream is opened with too little history. It is the library's one recoverable error, so it is catchable on its own rather than as a bare Exception.

  • [FIX]: help(talib.SUPERTREND) and the abstract stub named the outputs real and integer; they are supertrend and trend, the names abstract.Function('SUPERTREND').output_names already reported.

  • [FIX]: An empty array given to a function whose lookback is zero, such as talib.ACOS or talib.MA(x, timeperiod=1), made TA-Lib read and write one element outside the buffers, which could crash the interpreter later or corrupt memory silently. An empty input now returns empty outputs without calling TA-Lib, whatever the function and its parameters. The bug dates from 0.4.27.

0.8.0

  • [NEW]: Support TA-Lib C 0.8.1, which is now the minimum required version.

  • [NEW]: The 40 functions TA-Lib C added since 0.7.1: AC, ADR, AO, CMF, CMOU, COPPOCK, CUMSUM, CVI, DONCHIAN, DPO, EFI, ER, ERI, FOSC, FRACTAL, HA, HMA, KC, KDJ, MARKETFI, MASSI, NVI, PERCENTILE, PERCENTRANK, PVI, PVO, PVT, QSTICK, RMA, RVI, RVOL, SMI, SUPERTREND, TSI, VHF, VORTEX, VWAP, VWMA, WAD, ZLEMA.

  • [NEW]: New moving averages: MA_Type.HMA, MA_Type.DISABLED, MA_Type.DEFAULT, MA_Type.ZLEMA and MA_Type.RMA.

  • [NEW]: set_unstable_period() and get_unstable_period() accept 'RMA', 'HA' and 'RVI'.

... (truncated)

Commits
  • 8f5cadc docs: updates
  • e5aab28 ci: add the dev-* release lane, pinned to the wheels' TA-Lib C
  • f4ad30e test: accept a TA-Lib C newer than we require
  • 9c7f7bd update README from TA-Lib C 0.7.1 to 0.8.1
  • 7a10655 version bump
  • f972213 fix(func): no input, no output
  • bdb8c5e fix(func): SUPERTREND's outputs are supertrend and trend
  • 7a5544c changelog: the streaming entries belong to the next release
  • 25dd74b fix(abstract): stop relying on Cython resolving __NAME from class scope
  • a93703b perf(stream): multi-output handles answer with a plain tuple
  • Additional commits viewable in compare view

Updates websocket-client to 1.9.2

Release notes

Sourced from websocket-client's releases.

v1.9.2

1.9.2

  • Fix race in WebSocketApp.close() when run_forever() thread clears the socket during the close handshake (#1057, fixes #1055 and #1056)
Changelog

Sourced from websocket-client's changelog.

  • 1.9.2

    • Fix race in WebSocketApp.close() when run_forever() thread clears the socket during the close handshake (#1057, fixes #1055 and #1056)
  • 1.9.1

    • Add Python 3.14 support to setup config and CI (f2bc97a)
    • Fix close() dropping close frame when reason is str (2f22e2e)
    • Fix close() type annotation and docstring for timeout and reason (d69f730)
    • Make abort() robust for sockets that cannot shutdown, same logic as shutdown() (1904e3d)
    • Raise WebSocketException for redirects missing a Location header (97e34db)
    • Raise when WebSocket connect redirect limit is exhausted (be0d38d)
    • Raise WebSocketException for redirects to invalid targets (62ef6af)
    • Fix unformatted ABNF validation error messages (0145b7b)
    • Fix validate_utf8() crash on str input (4a8e6ed)
    • Store status_message on WebSocketBadStatusException (368aeda)
    • Raise WebSocketException for check_hostname with CERT_NONE (0232aca)
    • Fix handleDisconnect type annotation: None default requires Optional (20f3712)
    • Remove unreachable not frame check in recv_data_frame() (b684242)
    • Set proxy_timeout on proxy_info without a proxy host (68f0aed)
    • Fix _wsdump.py bytes annotations and remove dead code (5ecc6e4)
    • Export STATUS_SERVICE_RESTART and STATUS_TRY_AGAIN_LATER close codes (22279c4)
    • Fix extract_err_message() to always return str (e2091bd)
    • Raise WebSocketProxyException for SOCKS proxy without a port, correct proxy port docs (3c62bdf)
    • Raise WebSocketException for malformed HTTP responses (04f4d94)
    • Fix docs examples using dead or unreachable endpoints (2fc92c0)
    • Add pyproject.toml, drop deprecated setup.py metadata (8b34f50)
    • Apply linting (3b4ffab)
  • 1.9.0

    • Remove Python 3.8 support (EOL), add Python 3.13 (5f25030)
    • Remove localhost and 127.0.0.1 from default NO_PROXY list (#994)
    • Support IPv6 CIDRs in the no_proxy option (#1033)
    • Fix thread safety condition in teardown() to improve run_forever() (#1015)
    • Fix #1024 by chunking data, recursion in on_error callback, thread leak in _stop_ping_thread(), avoid implicit None in recv() (#1036)
    • Avoid bare except clauses for better error handling (#1036)
    • Fix async (#983)
    • Resolve mypy type errors (#996, #1006, 813d570)
    • Test coverage improvements (#1035, #1036)
    • flake8 linting improvements (#1034)
  • 1.8.0

    • Added on_reconnect parameter to WebSocketApp to handle callback ambiguity (#972)
    • Improve handling of SSLEOFError and use reconnect bool (#961)
    • Minor linting and docs CI build upgrades (981c00e, 75ba91a, bec2608)
  • 1.7.0

    • Renamed mask variable in ABNF to prevent name collision with mask() function (9b51f73)
    • Fixed old http import of HTTPStatus in _handshake.py (9b51f73)
    • Add send_text() and send_bytes() to _app.py (#953)
    • Improved typehint support (#953, 9b51f73, 8b73d00)

... (truncated)

Commits

Updates litellm to 1.104.0

Release notes

Sourced from litellm's releases.

v1.104.0

Verify Docker Image Signature

All LiteLLM Docker images are signed with cosign. Every release is signed with the same key introduced in commit 0112e53.

Verify using the pinned commit hash (recommended):

A commit hash is cryptographically immutable, so this is the strongest way to ensure you are using the original signing key:

cosign verify \
  --key https://raw.githubusercontent.com/BerriAI/litellm/0112e53046018d726492c814b3644b7d376029d0/cosign.pub \
  ghcr.io/berriai/litellm:v1.104.0

Verify using the release tag (convenience):

Tags are protected in this repository and resolve to the same key. This option is easier to read but relies on tag protection rules:

cosign verify \
  --key https://raw.githubusercontent.com/BerriAI/litellm/v1.104.0/cosign.pub \
  ghcr.io/berriai/litellm:v1.104.0

Expected output:

The following checks were performed on each of these signatures:
  - The cosign claims were validated
  - The signatures were verified against the specified public key

What's Changed

... (truncated)

Commits
  • 7964577 Merge pull request #44397 from BerriAI/litellm_fix_d03a47
  • 5bb3b88 fix(proxy-extras): keep the post-migration sanity check from building the han...
  • 5aa0cd0 chore(release): backport part of #43902 and #43983 to rc/1.104.0 (#44332)
  • 31d6c60 chore(release): backport #44283 and part of #44229 to rc/1.104.0 (#44312)
  • 656daa0 chore(release): backport #44277 to rc/1.104.0 and bump oauthlib (#44304)
  • a1f27fc test: fix three order-dependent and timing-flaky tests (#44271) (#44280)
  • 6e747b0 test(integration): opt the config pass-through spend-log case into auth (#44267)
  • 2e5981c Merge pull request #44224 from BerriAI/litellm_rc_1_104_0_extras_post1
  • 13d3ba8 chore: bump litellm-proxy-extras to 0.4.102.post1
  • e012755 Merge pull request #44206 from BerriAI/litellm_rc_1_104_0_enforce_migration_c...
  • Additional commits viewable in compare view

Updates certifi to 2026.7.22

Commits

Updates akshare to 1.19.1

Changelog

Sourced from akshare's changelog.

1.19.1 fix: fix futures_gfex_warehouse_receipt interface

1. 修复 futures_gfex_warehouse_receipt 接口报 `KeyError: "['增减'] not in index"` 的问题:广州期货交易所将增减字段由 regWbillQty 改为 diff,现改为按 diff 映射
2. 修正“增减”列的取值:原先映射的 regWbillQty 并非增减量,现取值与“今日仓单量”减“昨日仓单量”一致
3. 为接口补充 15 秒请求超时

1.18.99 fix: raise a meaningful error when dce rejects the request

1. 大连商品交易所网站启用了瑞数反爬虫验证,程序请求返回 HTTP 412 挑战页,futures_warehouse_receipt_dce 接口此前会抛出令人费解的 `JSONDecodeError`;现改为抛出携带状态码的 `APIError` 并说明原因,同时补充 15 秒请求超时

1.18.98 fix: fix futures_shfe_warehouse_receipt interface

1. 修复 futures_shfe_warehouse_receipt 接口在 2025-11-18 及之后的交易日报 `JSONDecodeError` 的问题:上海期货交易所不再提供 dailystock.dat 数据文件,现改为解析网页版仓单日报,更早日期仍使用原数据文件
2. 网页版按表头名称映射列,兼容“地区、仓库”“厂库、地区”“地区、交割仓库、本日数量”等不同列顺序,并正确处理合并单元格;此后日期的 DataFrame 仅包含 VARNAME、REGNAME、WHABBRNAME、WRTWGHTS、WRTCHANGE、ROWSTATUS 六列
3. 为新数据源补充 15 秒请求超时

1.18.97 fix: fix stock_report_fund_hold interface

1. 修复 stock_report_fund_hold 接口因东方财富返回字段顺序变动导致的列错位问题,改为按字段名映射股票代码、股票简称及持仓变动相关数据
2. 为 stock_report_fund_hold 接口补充 15 秒请求超时,避免上游长时间无响应时进程一直阻塞不返回

1.18.96 fix: fix stock_zh_a_spot interface

1. 修复 stock_zh_a_spot 接口在新浪分页请求超时参数为 0 时,上游长时间无响应时进程一直阻塞不返回的问题

1.18.95 fix: raise a meaningful error when legulegu rejects the request

1. 修复乐咕乐股系列接口在上游拒绝请求时抛出 `AttributeError: 'NoneType' object has no attribute 'attrs'` 的问题:共用的 CSRF 获取逻辑此前既不校验状态码也不判空,上游返回的 403 错误页会被当作正常页面解析;现改为抛出携带状态码的 `APIError`,页面缺少 `_csrf` 标签时抛出 `DataParsingError`
2. 受益接口共 14 个:stock_buffett_index_lg、stock_index_pe_lg、stock_index_pb_lg、stock_market_pe_lg、stock_market_pb_lg、stock_a_congestion_lg、stock_ebs_lg、stock_a_gxl_lg、stock_hk_gxl_lg、stock_a_ttm_lyr、stock_a_all_pb、fund_stock_position_lg、fund_balance_position_lg、fund_linghuo_position_lg

1.18.94 fix: fix fund_money_fund_info_em interface

1. 优化 stock_board_concept_hist_em 接口的空数据兜底逻辑:仅对合法空历史返回空 DataFrame,对无效概念板块名称或 BK 代码抛出明确异常

1.18.93 fix: fix fund_money_fund_info_em interface

1. 修复 fund_money_fund_info_em 接口

1.18.92 fix: improve Xueqiu login requirement guidance

1. 优化 stock_individual_basic_info_xq 系列接口在雪球返回 400016 时的提示信息,明确匿名访问当前受限且需要通过 `token=` 传入有效 `xq_a_token`
2. 补充中概股、美股、港股雪球公司信息接口的登录态依赖说明
3. 修复 fund_money_fund_info_em 接口因东方财富历史净值返回体新增字段而触发 Length mismatch 的问题

1.18.91 docs: migrate the Markdown parser to myst-parser

1. 文档 Markdown 解析器由 recommonmark 迁移至 myst-parser,并移除随之无用的 sphinx-markdown-tables 与 markdown 依赖
2. 修正 docs 目录下 25 个文件的标题层级,使每个页面具备唯一的一级标题且不再跳级
3. 接口条目层级调整后可生成锚点,文档站中每个接口均支持直接链接定位
4. 为 dependabot 增加依赖分组配置,避免多个拉取请求同时修改同一文件

... (truncated)

Commits
  • 25634c6 Dev (#7433)
  • 0191689 fix(stock_report_fund_hold): 修复接口字段错位并添加请求超时 (#7427)
  • 2e13a5f fix(stock_zh_a_spot): 修复接口超时阻塞问题 (#7425)
  • 72de989 Dev (#7424)
  • 8e95744 build(deps): bump the python group with 4 updates (#7408)
  • caa6c55 构建(pre-commit): 更新ruff-pre-commit至v0.16.4版本 (#7409)
  • 0e7db00 fix(stock_board_concept_hist_em): 优化错误处理与空数据兜底逻辑 (#7406)
  • e7d3e24 fix(fund): 修复fund_money_fund_info_em接口字段不匹配问题 (#7405)
  • 1b9aeb5 ci: bump astral-sh/setup-uv from 9.0.0 to 10.0.1 in the actions group (#7399)
  • ea5b388 build(deps-dev): bump ruff from 0.16.2 to 0.16.3 in the python group (#7400)
  • Additional commits viewable in compare view

Updates pyjwt to 2.15.1

Release notes

Sourced from pyjwt's releases.

2.15.1

See the 2.15.1 changelog for complete release details.

Changelog

Sourced from pyjwt's changelog.

v2.15.1 <https://github.com/jpadilla/pyjwt/compare/2.15.0...2.15.1>__

Fixed


- Accept trailing Base64URL ``=`` padding when decoding JWS segments, so
  tokens issued by AWS ALB and similar systems verify instead of raising
  ``DecodeError: Invalid crypto padding``. Non-alphabet junk such as
  ``!!!!`` remains rejected (`[#1209](https://github.com/jpadilla/pyjwt/issues/1209) <https://github.com/jpadilla/pyjwt/issues/1209>`__).

v2.15.0 &lt;https://github.com/jpadilla/pyjwt/compare/2.14.0...2.15.0&gt;__

Security

  • Wrap recursion errors from deeply nested JWT payloads in DecodeError instead of exposing a raw RecursionError.

Added


- Support Python 3.15 by @kytta in `[#1202](https://github.com/jpadilla/pyjwt/issues/1202) <https://github.com/jpadilla/pyjwt/pull/1202>`__

Changed

  • JWKSetCache now stores the parsed PyJWKSet rather than the raw JWKS payload, so a cache hit no longer re-parses every key. JWKSetCache.put() accepts either form and raises PyJWKSetError for anything else. As a result, PyJWKClient.get_jwk_set() returns the same PyJWKSet instance for as long as it stays cached, rather than a freshly built one per call in [#1208](https://github.com/jpadilla/pyjwt/issues/1208) <https://github.com/jpadilla/pyjwt/pull/1208>__
  • PyJWKClient.fetch_data() now raises PyJWKClientError("The JWKS endpoint did not return a JSON object") when the endpoint response is not a JSON object, instead of returning it for get_jwk_set() to reject. Callers reaching the JWKS through get_jwk_set() see the same error as before in [#1208](https://github.com/jpadilla/pyjwt/issues/1208) <https://github.com/jpadilla/pyjwt/pull/1208>__

Fixed


- Return cached ``PyJWKSet`` values from ``PyJWKClient.get_jwk_set()`` instead
  of raising ``PyJWKClientError("The JWKS endpoint did not return a JSON
  object")``. ``JWKSetCache.put()`` documents ``PyJWKSet`` as the cached value,
  so callers pre-populating the cache to avoid a network round-trip could not
  read it back in `[#914](https://github.com/jpadilla/pyjwt/issues/914) <https://github.com/jpadilla/pyjwt/issues/914>`__ and
  `[#1208](https://github.com/jpadilla/pyjwt/issues/1208) <https://github.com/jpadilla/pyjwt/pull/1208>`__
</tr></table> 

... (truncated)

Commits

Updates python-dotenv to 1.2.4

Release notes

Sourced from python-dotenv's releases.

v1.2.4

Fixed

  • dotenv get no longer exits with code 1 for empty string values (KEY=) by [@​ShamikOfficial] in #700
  • An unquoted empty value followed by an inline comment (e.g. KEY= # comment) is now parsed as an empty string instead of the comment text by [@​Noethix55555] in #663
  • dotenv run --no-override now expands variable references with the same precedence as load_dotenv(override=False), so a value like ${BASE}/suffix uses the existing BASE from the environment instead of the one from the .env file by [@​ROTl24] in #698
Changelog

Sourced from python-dotenv's changelog.

[1.2.4] - 2026-10-01

Fixed

  • dotenv get no longer exits with code 1 for empty string values (KEY=) by [@​ShamikOfficial] in #700
  • An unquoted empty value followed by an inline comment (e.g. KEY= # comment) is now parsed as an empty string instead of the comment text by [@​Noethix55555] in #663
  • dotenv run --no-override now expands variable references with the same precedence as load_dotenv(override=False), so a value like ${BASE}/suffix uses the existing BASE from the environment instead of the one from the .env file by [@​ROTl24] in #698

[1.2.3] - 2026-08-16

Fixed

  • Strip a leading UTF-8 BOM from .env file contents so the first variable is no longer silently lost when the file is saved with BOM (e.g. by some JetBrains IDEs on Windows) by [@​h1whelan] in #640
  • set_key now escapes backslashes, so values containing them (Windows paths, regular expressions) survive a write/read round-trip. Quoted values ending in an escaped backslash are no longer mis-parsed as an escaped quote, which used to swallow the following lines by [@​dchaudhari7177] in #680
  • dotenv run now prints a friendly error instead of a traceback when no command is given by [@​bbc2] in #606
  • Cache the parsed result for empty .env files so repeated dotenv_values/load_dotenv calls no longer re-read the file by [@​ReinerBRO] in #638

[1.2.2] - 2026-03-01

Added

  • Support for Python 3.14, including the free-threaded (3.14t) build. (#588)

Changed

  • The dotenv run command now forwards flags directly to the specified command by [@​bbc2] in #607
  • Improved documentation clarity regarding override behavior and the reference page.
  • Updated PyPy support to version 3.11.
  • Documentation for FIFO file support.
  • Dropped Support for Python 3.9.

Fixed

  • Improved set_key and unset_key behavior when interacting with symlinks by [@​bbc2] in [790c5c0]
  • Corrected the license specifier and added missing Python 3.14 classifiers in package metadata by [@​JYOuyang] in #590

Breaking Changes

  • dotenv.set_key and dotenv.unset_key used to follow symlinks in some situations. This is no longer the case. For that behavior to be restored in all cases, follow_symlinks=True should be used.

  • In the CLI, set and unsetDescription has been truncated

… updates

---
updated-dependencies:
- dependency-name: ruff
  dependency-version: 0.16.10
  dependency-type: direct:development
  dependency-group: python-runtime
- dependency-name: yfinance
  dependency-version: 1.7.0
  dependency-type: direct:production
  dependency-group: python-runtime
- dependency-name: aiohttp
  dependency-version: 3.14.4
  dependency-type: direct:production
  dependency-group: python-runtime
- dependency-name: pandas
  dependency-version: 3.0.6
  dependency-type: direct:production
  dependency-group: python-runtime
- dependency-name: ta-lib
  dependency-version: 0.8.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-runtime
- dependency-name: websocket-client
  dependency-version: 1.9.2
  dependency-type: direct:production
  dependency-group: python-runtime
- dependency-name: litellm
  dependency-version: 1.104.0
  dependency-type: direct:production
  dependency-group: python-runtime
- dependency-name: certifi
  dependency-version: 2026.7.22
  dependency-type: direct:production
  dependency-group: python-runtime
- dependency-name: akshare
  dependency-version: 1.19.1
  dependency-type: direct:production
  dependency-group: python-runtime
- dependency-name: pyjwt
  dependency-version: 2.15.1
  dependency-type: direct:production
  dependency-group: python-runtime
- dependency-name: python-dotenv
  dependency-version: 1.2.4
  dependency-type: direct:production
  dependency-group: python-runtime
- dependency-name: cryptography
  dependency-version: 50.0.2
  dependency-type: direct:production
  dependency-group: python-runtime
- dependency-name: psycopg2-binary
  dependency-version: 2.9.13
  dependency-type: direct:production
  dependency-group: python-runtime
- dependency-name: redis
  dependency-version: 8.1.0
  dependency-type: direct:production
  dependency-group: python-runtime
- dependency-name: gunicorn
  dependency-version: 26.2.0
  dependency-type: direct:production
  dependency-group: python-runtime
- dependency-name: marshmallow
  dependency-version: 4.3.1
  dependency-type: direct:production
  dependency-group: python-runtime
- dependency-name: reportlab
  dependency-version: 5.0.1
  dependency-type: direct:production
  dependency-group: python-runtime
- dependency-name: alpaca-py
  dependency-version: 0.44.0
  dependency-type: direct:production
  dependency-group: python-runtime
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Oct 9, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants