Skip to content

Update all non-major dependencies - #663

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/all-minor-patch
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/all-minor-patch

Conversation

@renovate

@renovate renovate Bot commented Sep 19, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
cosl ==1.10.3 → ==1.11.2 age confidence
cryptography (changelog) ==50.0.1 → ==50.0.2 age confidence
jubilant ==1.13.0 → ==1.14.0 age confidence
opentelemetry-api ==1.44.0 → ==1.45.1 age confidence
ops (changelog) ==3.8.2 → ==3.9.0 age confidence
playwright (changelog) ==1.62.0 → ==1.63.0 age confidence
pydantic (changelog) ==2.13.5 → ==2.14.0 age confidence

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Release Notes

canonical/cos-lib (cosl)

v1.11.2

Compare Source

What's Changed

Full Changelog: canonical/cos-lib@1.11.1...1.11.2

v1.11.1

Compare Source

What's Changed

Full Changelog: canonical/cos-lib@1.11.0...1.11.1

v1.11.0

Compare Source

What's Changed

Full Changelog: canonical/cos-lib@1.10.3...1.11.0

pyca/cryptography (cryptography)

v50.0.2

Compare Source

canonical/jubilant (jubilant)

v1.14.0

Compare Source

Features

  • Export ConstraintValue type alias publicly (#​416)

Documentation

  • Cover the remaining SEC0030 sub-requirements (#​399)

Chores

  • Switch docs to latest Google tag (#​415)

CI

  • Swap attest-build-provenance for actions/attest (#​411)
open-telemetry/opentelemetry-python (opentelemetry-api)

v1.45.1

Compare Source

Fixed
  • opentelemetry-api: make AnyValue and AttributeValue explicit type
    aliases
    (#​5703)
  • opentelemetry-sdk: fix thread leak bug in resource initialization logic for
    long running resource detectors
    (#​5706)
  • opentelemetry-exporter-otlp-proto-http: restore requests as the default
    HTTP transport so proxy environment variables such as HTTPS_PROXY are
    honored again
    (#​5714)
  • opentelemetry-api: fix quadratic time parsing of the tracestate header
    and discard tracestate headers longer than 8192 characters
    (#​5746)

v1.45.0

Compare Source

Added
  • opentelemetry-exporter-prometheus: add support to configure Resource
    attributes as metric labels
    (#​5122)
  • infra: add renovate
    (#​5202)
  • opentelemetry-api, opentelemetry-sdk: add support for extended attribute
    values everywhere.
    (#​5266)
  • opentelemetry-sdk: wire the top-level log_level field in declarative
    configuration — when set, maps the OTel SeverityNumber value to a Python
    logging level and applies it to the opentelemetry logger so SDK internal
    diagnostics respect the configured severity.
    (#​5351)
  • opentelemetry-sdk: add the new stable AlwaysRecordSampler
    (#​5354)
  • opentelemetry-configuration, opentelemetry-sdk: wire top-level
    attribute_limits into per-signal providers via declarative config; add
    log_record_limits support to LoggerProvider
    (#​5365)
  • opentelemetry-exporter-otlp-json-http: add OTLP JSON HTTP exporter package
    (#​5374)
  • opentelemetry-api, opentelemetry-sdk: add enabled() support to the
    Logger API, SDK, and LogRecordProcessor to let instrumentation skip
    expensive work when logging is disabled
    (#​5380)
  • opentelemetry-exporter-otlp-json-file: add OTLP JSON file Docker tests
    (#​5412)
  • opentelemetry-configuration: wire the experimental
    tracer_configurator/development, meter_configurator/development and
    logger_configurator/development fields into create_tracer_provider,
    create_meter_provider and create_logger_provider, so
    per-instrumentation-scope
    enabled overrides declared in the config file are applied to the provider
    (previously these fields were parsed but silently discarded). The logger
    minimum_severity/trace_based fields are not supported by the Python SDK
    and
    are ignored with a warning.
    (#​5418)
  • docs/examples: add example on how to manually setup the SDK to get SDK
    metrics
    (#​5449)
  • opentelemetry-docker-tests: add Prometheus exporter docker tests
    (#​5457)
  • opentelemetry-sdk: count records dropped after shutdown on
    otel.sdk.processor.{span,log}.processed with error.type=already_shutdown
    (batch span/log and simple log processors), which the semantic conventions
    define as a valid value for this metric.
    (#​5509)
  • opentelemetry-semantic-conventions: update semantic conventions to v1.44.0
    (#​5511)
  • opentelemetry-sdk: add host.id to the host resource detector
    (#​5653)
  • opentelemetry-test-utils: add CapturingSampler to record what samplers
    receive in instrumentation tests
    (#​5681)
Changed
  • Enable PIE (flake8-pie) ruff rule and fix all violations
    (#​5150)
  • The public opentelemetry.util.types.AttributeValue type in package
    opentelemetry-api is being expanded to include None, heterogeneous
    sequences of primitive types (and nested sequences) as opposed to only
    homogeneous primitive sequences, and Mappings of strings to any primitive
    types or sequences/mappings (which themselves must only contain primitive
    types or sequences/mappings validated the same way).
    If a bytes type is set as an attribute value in the SDK, it will no longer
    be utf-8 decoded to a string, instead it will be passed along as is in
    accordance with the OTEL spec, since bytes is a valid type in the OTLP
    proto.
    (#​5266)
  • opentelemetry-exporter-otlp-proto-http: add a max_request_size argument
    to the OTLP HTTP exporters (traces, logs, metrics); serialized requests
    larger than the limit are dropped before sending, measured before
    compression. Defaults to 64 MiB (enabled); set to 0 to disable. Mirrors
    opentelemetry-go#8157.
    (#​5369)
  • [BREAKING] opentelemetry-api: subclasses of Logger need to implement the
    enabled method
    (#​5380)
  • opentelemetry-exporter-otlp-proto-http: refactor to use shared
    opentelemetry-exporter-otlp-common and opentelemetry-exporter-http-transport
    packages and switch default HTTP backend to urllib3
    (#​5389)
  • opentelemetry-sdk: unify logging force_flush timeout defaults to 30000ms
    (#​5438)
  • opentelemetry-python: enable Ruff default ruleset and fix auto-fixable lint
    issues
    (#​5491)
  • opentelemetry-sdk: SimpleSpanProcessor now drops spans ended after
    shutdown() instead of passing them to the exporter, and counts them on
    otel.sdk.processor.span.processed with error.type=already_shutdown.
    (#​5512)
  • Bump pytest to 9.0.3
    (#​5518)
  • opentelemetry-exporter-otlp-proto-http: clarify that the endpoint= kwarg
    requires the full signal path
    (#​5633)
  • opentelemetry-sdk: fix typos in SpanLimits docstring
    (#​5658)
Fixed
  • opentelemetry-configuration: perform environment variable substitution on
    scalar values after parsing the configuration file, so ${VAR} references
    inside comments and mapping keys are no longer substituted and undefined
    references in comments no longer abort loading
    (#​5407)
  • opentelemetry-configuration: declarative config environment variable
    substitution now replaces an unset variable that has no default with an empty
    value instead of raising an error, per the configuration spec.
    Resource attributes whose value resolves to null (an unset ${VAR} with no
    default) are skipped with a warning instead of being inserted as a null
    value.
    (#​5408)
  • 'scripts/build.sh: add opentelemetry-configurationandopentelemetry-proto-json` to the package to release
    (#​5425)
  • opentelemetry-sdk: fix View instrument-name matching so a view configured
    with an instrument's real (mixed-case) name is applied; matching is now
    case-insensitive and platform-independent instead of relying on fnmatch's
    OS-dependent case handling
    (#​5430)
  • opentelemetry-sdk: fix missing f-prefix in exponential histogram error
    messages
    (#​5434)
  • opentelemetry-configuration: resolve false-positive warning logs for newer
    schema minor version
    (#​5436)
  • opentelemetry-sdk: make methods on FixedSizeExemplarReservoirABC thread
    safe
    (#​5437)
  • opentelemetry-propagator-jaeger: fix typing issues and enable pyright
    typechecking for the package
    opentelemetry-propagator-jaeger: skip uberctx- baggage headers with an
    empty value on extraction instead of raising TypeError
    (#​5440)
  • opentelemetry-sdk: fix TypeError when instantiating a _BaseConfigurator
    subclass whose __init__ takes arguments
    (#​5441)
  • opentelemetry-sdk: fix TypeError in os.fork() when a BatchProcessor
    or PeriodicExportingMetricReader is garbage collected
    (#​5453)
  • opentelemetry-configuration: a declarative config key present with an empty
    (null) value on an object-typed node (e.g. always_on:, a - service:
    detector, or a metric console: exporter) is now treated the same as an
    explicit empty config (always_on: {}) instead of failing type dispatch or
    silently skipping the node. Both dict-typed nodes and dataclasses
    constructible with no arguments are covered.
    (#​5454)
  • opentelemetry-api: fix copy-pasted log message in SpanContext.__delattr__
    (#​5455)
  • opentelemetry-sdk: reject views with
    ExponentialBucketHistogramAggregation for asynchronous instruments instead
    of silently producing no data
    (#​5461)
  • opentelemetry-sdk: fill every bucket of SimpleFixedSizeExemplarReservoir
    before random sampling
    (#​5462)
  • opentelemetry-sdk: Import code_attributes from stable semconv package
    (#​5465)
  • opentelemetry-sdk: for both the simple and batch span/log processors, count
    otel.sdk.processor.{span,log}.processed when the processor submits records
    to the exporter instead of after export completes, and stop stamping exporter
    failures onto this metric as error.type
    (#​5472)
  • opentelemetry-sdk: fix misleading instrument name validation error message
    (name max length is 255, not 63).
    (#​5513)
  • opentelemetry-configuration: add missing process executable name to default
    service name when available in resource attributes
    (#​5534)
  • opentelemetry-sdk: fix values for process.executable.name and
    process.executable.path to match semantic conventions.
    (#​5535)
  • opentelemetry-api: fix TraceState.update dropping all entries when adding
    a new key at the 32-key limit
    (#​5543)
  • opentelemetry-sdk: bound get_aggregated_resources() wait to the timeout
    (#​5545)
  • opentelemetry-sdk: don't read process.executable.name resource attribute
    when building default service.name
    (#​5547)
  • opentelemetry-propagator-jaeger: enforce baggage limits on both uberctx-
    extract and inject, borrowing the same limits (180 entries, 4096 bytes per
    entry, 8192 bytes total) the package's core W3CBaggagePropagator already
    uses, so neither an inbound carrier nor an in-process baggage map can produce
    unbounded work or headers.
    (#​5556)
  • opentelemetry-sdk: keep metric attribute values that Python considers equal
    but the data model does not, such as True, 1 and 1.0, in separate
    metric streams
    (#​5573)
  • opentelemetry-sdk: keep Resource hashable and serialisable when an
    attribute value is bytes, instead of raising TypeError from every OTLP
    encoder
    (#​5577)
  • opentelemetry-sdk: fix instrumentation scope name matching in the tracer,
    meter and logger configurators so it is case-sensitive on every platform
    instead of relying on fnmatch's OS-dependent case handling
    (#​5584)
  • opentelemetry-sdk: fix TracerProvider() raising ValueError when
    OTEL_TRACES_SAMPLER_ARG is a syntactically valid number outside the [0.0, 1.0] range, instead of logging a warning and falling back like other invalid
    values
    (#​5594)
  • opentelemetry-sdk: retain values from synchronous instruments using
    last-value aggregation across cumulative collections
    (#​5637)
  • opentelemetry-api: Added guard for negative value on max_value_len
    (#​5647)
  • opentelemetry-sdk: fix overriding of the service.instance.id which has been
    populated from the user provided values through the resource detectors
    (#​5660)
  • opentelemetry-exporter-otlp-proto-grpc: Fix incorrect default port for OTLP
    gRPC exporter self-metrics
    (#​5668)
  • opentelemetry-api: update W3CBaggagePropagator to properly handle
    whitespace
    (#​5680)
canonical/operator (ops)

v3.9.0

Compare Source

Features

  • Add an exception note when ModelError is raised (#​2786)

Fixes

  • Make _CharmSpec covariant in its charm type (#​2715)
  • Say which tracing destination rejected the data (#​2714)
  • Detect Pydantic dataclasses from before 2.11 when mapping aliases (#​2768)
  • Enforce relation databag read permissions on all access paths (#​2738)
  • Use cached leadership in security logging, renew lease on success by @​cristiangirlea (#​2778)
  • A gone relation raises RelationNotFoundError, not "permission denied" (#​2748)
  • Treat an _Abort(0) from the charm's __init__ as success in ops.testing (#​2780)
  • Record trace data in every ops.testing run with opentelemetry-sdk 1.45 (#​2787)
  • Let charms and libraries set on without a type: ignore (#​2775)

Documentation

  • Surface the tool versions page (#​2712)
  • Update Concierge links and intersphinx URLs in doc source (#​2725)
  • Add retry loop to version check in K8s tutorial charm (#​2689)
  • Merge HACKING.md into CONTRIBUTING.md, fewer files in root (#​2734)
  • Add a how-to guide for securing a charm (#​2721)
  • Condense and trim CONTRIBUTING.md (#​2754)
  • Fix the self-review command in the discoverability how-to (#​2764)
  • Mount the project directory to a target relative to the home directory (#​2765)
  • Pull tutorial code snippets from examples/ (#​2544)

Tests

  • Add conformance tests for the tracing and certificate_transfer interfaces (#​2711)
  • Make pyright check whole trees rather than a list of directories (#​2779)

Refactoring

  • Drop typing.cast where narrowing can do the work (#​2723)
  • Only import pdb when a debugger is actually requested (#​2740)

CI

  • Enrich scheduled-failure issues with an LLM triage pass (#​2663, #​2781)
  • Stop tox writing a .venv redirect file in the examples (#​2769)
  • Move the release process from release.py to workflows (#​2772)

v3.8.3

Compare Source

Security Fixes

  • Stop recording secret content, relation data, pod specs, and action results and log messages in trace data (GHSA-4356-5g33-3qrp)
  • Stop including action results and action log messages in hook command errors
Microsoft/playwright-python (playwright)

v1.63.0

Compare Source

🪟 Locate across frames

page.frame_locator() and frame.frame_locator() called without a selector search in any frame of the
subtree, so you no longer need to locate the iframe first:

# Finds the button in any frame on the page.
page.frame_locator().get_by_role("button").click()

The rest of the locator resolves inside a single frame, just like a regular locator, and an error is thrown when it
matches elements in several frames.

👁️ Visible-only locators

New locator.visible returns a locator that matches only visible elements. It is the recommended
replacement for the :visible CSS pseudo-class:

page.locator("button").visible.click()

🖼️ Aria and screen snapshots in traces

New aria_snapshots and screen_snapshots options of
tracing.start() capture an aria snapshot and a screenshot of the page on every action:

context.tracing.start(snapshots=True, aria_snapshots=True, screen_snapshots=True)

With aria and screen snapshots recorded, the new Display Aria mode in the trace viewer shows the action screenshot
side by side with the aria snapshot, and hovering an aria node highlights it on the screenshot.

New APIs

Browser and Context
Command line
  • playwright install --no-remove keeps the browsers of other Playwright installations instead of removing them.
  • playwright codegen --http-credentials records against pages behind HTTP authentication.

Announcements

  • ⚠️ Ubuntu 20.04 is not supported anymore.
  • 🐧 On Linux arm64, Playwright now downloads the Chrome for Testing build of Chromium, the same build used on all other platforms.

Browser Versions

  • Chromium 153.0.8010.12
  • Mozilla Firefox 155.0
  • WebKit 26.6

This version was also tested against the following stable channels:

  • Google Chrome 153
  • Microsoft Edge 153
pydantic/pydantic (pydantic)

v2.14.0

Compare Source

GitHub release

What's Changed

The highlights of the v2.14 release are available in the blog post.
Several minor changes (considered non-breaking changes according to our versioning policy)
are also included in this release. Make sure to look into them before upgrading.

This release drops support for Python 3.9 and adds support for Python 3.15.

New Features
Changes
Fixes
New Contributors

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • Only on Sunday and Saturday (* * * * 0,6)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot requested a review from a team as a code owner September 19, 2026 04:26
@renovate
renovate Bot enabled auto-merge (squash) September 19, 2026 04:26
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch from 3481ae3 to 6da1b0e Compare September 25, 2026 15:55
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch from 67b096c to 46a4478 Compare October 8, 2026 21:03

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant