Skip to content

chore(deps): uv: bump the all-python group across 1 directory with 10 updates - #859

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/agent/all-python-4666157a7c
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/agent/all-python-4666157a7c

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 5, 2026

Copy link
Copy Markdown
Contributor

Bumps the all-python group with 10 updates in the /agent directory:

Package From To
boto3 1.43.78 1.43.93
bedrock-agentcore 1.18.1 1.23.0
claude-agent-sdk 0.2.110 0.2.152
fastapi 0.139.0 0.141.1
uvicorn 0.50.0 0.52.4
aws-opentelemetry-distro 0.18.0 0.19.0
mcp 1.28.1 2.2.0
ruff 0.15.20 0.16.7
ty 0.0.56 0.0.80
pygments 2.20.0 2.21.0

Updates boto3 from 1.43.78 to 1.43.93

Commits
  • 655751c Merge branch 'release-1.43.93'
  • e522bfd Bumping version to 1.43.93
  • 9c7d4c3 Add changelog entries from botocore
  • 4477cdc Merge branch 'release-1.43.92'
  • a465bee Merge branch 'release-1.43.92' into develop
  • 5d8a8ab Bumping version to 1.43.92
  • 959442c Add changelog entries from botocore
  • 5073bde Merge branch 'release-1.43.91'
  • 19fa272 Merge branch 'release-1.43.91' into develop
  • 036a8a0 Bumping version to 1.43.91
  • Additional commits viewable in compare view

Updates bedrock-agentcore from 1.18.1 to 1.23.0

Release notes

Sourced from bedrock-agentcore's releases.

Bedrock AgentCore SDK v1.23.0

Installation

pip install bedrock-agentcore==1.23.0

What's Changed

See CHANGELOG.md for details.

What's Changed

New Contributors

Full Changelog: aws/bedrock-agentcore-sdk-python@v1.22.0...v1.23.0

Bedrock AgentCore SDK v1.22.0

Installation

pip install bedrock-agentcore==1.22.0

What's Changed

See CHANGELOG.md for details.

What's Changed

Full Changelog: aws/bedrock-agentcore-sdk-python@v1.21.0...v1.22.0

Bedrock AgentCore SDK v1.21.0

Installation

pip install bedrock-agentcore==1.21.0

What's Changed

See CHANGELOG.md for details.

... (truncated)

Changelog

Sourced from bedrock-agentcore's changelog.

[1.23.0] - 2026-09-11

Added

  • feat: add RAGAS adapter for third-party eval metrics (#618) (d53af20)

Other Changes

  • Bump agentcore-devx-devtools reusable workflow pin (#660) (3c9f15e)
  • feat(tools): add WebSearchClient for invoking Amazon Web Search (#658) (cf71b14)
  • feat(gateway): add create_web_search_target() helper (#656) (7f75652)
  • fix(runtime): update shell session wire protocol (#642) (826416a)
  • ci: use dedicated release runners (#645) (ddfab76)

[1.22.0] - 2026-08-18

Other Changes

  • feat(payments): add MPP, x402 upto, and Quick Create support (#643) (66a68e3)

[1.21.0] - 2026-08-06

Other Changes

  • feat(memory): add AgentCoreMemoryStore Strands integration (#588) (439d788)
  • feat(runtime): propagate X-Amz-Bedrock-AgentCore-Identity-WAT on outbound calls (#607) (01d3800)

[1.20.0] - 2026-08-04

Added

  • feat: third-party eval metrics adapter (DeepEval + Autoevals) with strands-evals mappers (#568) (9b7d38e)

Fixed

  • fix: validate sample agent inputs (#612) (528471e)

Other Changes

  • fix(test): pin autoevals judge to the OpenAI API (#617) (703ccfd)
  • fix(a2a): bind the A2A contract port, ignore generic PORT (#615) (207adb7)
  • fix(test): repair eval adapter integ fixture and wire LLM judge key (#614) (9d8cc26)
  • fix(test): repair four unit tests drifting behind source and upstream APIs (#610) (53b0b48)
  • ci: install deepeval and autoevals for evaluation integ tests (#608) (5d23292)
  • fix(ci): add pinned deepeval and autoevals to dev group (#609) (70165d9)
  • ci: wire shared composite actions (#601) (a3382a4)

[1.19.0] - 2026-07-28

Fixed

  • fix: preserve generated API reference content (#595) (4a7a8c4)
  • fix: convert RST admonition to ADOC (#594) (641000d)

Other Changes

  • fix(a2a): advertise resolved port on explicit cards (#605) (34e06f0)
  • fix(memory-integ): address capacity cap and update failures in tests (#604) (59cbff3)
  • ci: migrate workflows to shared reusable workflows (#597) (f1a7106)

... (truncated)

Commits
  • 9f31042 chore: bump version to 1.23.0 (#662)
  • 3c9f15e Bump agentcore-devx-devtools reusable workflow pin (#660)
  • cf71b14 feat(tools): add WebSearchClient for invoking Amazon Web Search (#658)
  • 7f75652 feat(gateway): add create_web_search_target() helper (#656)
  • 826416a fix(runtime): update shell session wire protocol (#642)
  • d53af20 feat: add RAGAS adapter for third-party eval metrics (#618)
  • ddfab76 ci: use dedicated release runners (#645)
  • b981f7e chore: bump version to 1.22.0 (#644)
  • 66a68e3 feat(payments): add MPP, x402 upto, and Quick Create support (#643)
  • 5d4ca0d chore: bump version to 1.21.0 (#623)
  • Additional commits viewable in compare view

Updates claude-agent-sdk from 0.2.110 to 0.2.152

Release notes

Sourced from claude-agent-sdk's releases.

v0.2.152

Internal/Other Changes

  • Updated bundled Claude CLI to version 2.1.259

PyPI: https://pypi.org/project/claude-agent-sdk/0.2.152/

pip install claude-agent-sdk==0.2.152

v0.2.151

Internal/Other Changes

  • Updated bundled Claude CLI to version 2.1.258

PyPI: https://pypi.org/project/claude-agent-sdk/0.2.151/

pip install claude-agent-sdk==0.2.151

v0.2.150

Internal/Other Changes

  • Updated bundled Claude CLI to version 2.1.257

PyPI: https://pypi.org/project/claude-agent-sdk/0.2.150/

pip install claude-agent-sdk==0.2.150

v0.2.149

Internal/Other Changes

  • Updated bundled Claude CLI to version 2.1.252

... (truncated)

Changelog

Sourced from claude-agent-sdk's changelog.

0.2.152

Internal/Other Changes

  • Updated bundled Claude CLI to version 2.1.259

0.2.151

Internal/Other Changes

  • Updated bundled Claude CLI to version 2.1.258

0.2.150

Internal/Other Changes

  • Updated bundled Claude CLI to version 2.1.257

0.2.149

Internal/Other Changes

  • Updated bundled Claude CLI to version 2.1.252

0.2.148

Internal/Other Changes

  • Updated bundled Claude CLI to version 2.1.251

0.2.147

Internal/Other Changes

  • Updated bundled Claude CLI to version 2.1.250

0.2.146

Internal/Other Changes

  • Updated bundled Claude CLI to version 2.1.248

0.2.145

Internal/Other Changes

  • Updated bundled Claude CLI to version 2.1.247

0.2.144

... (truncated)

Commits
  • a8b1e28 docs: update changelog for v0.2.152
  • 0b41fb4 chore: release v0.2.152
  • ed1718f chore: bump bundled CLI version to 2.1.259
  • 16606a3 docs: update changelog for v0.2.151
  • dbe3998 chore: release v0.2.151
  • 637906e chore: bump bundled CLI version to 2.1.258
  • 1539d2a docs: update changelog for v0.2.150
  • 23ca647 chore: release v0.2.150
  • 036a35a chore: bump bundled CLI version to 2.1.257
  • 9597fc9 docs: update changelog for v0.2.149
  • Additional commits viewable in compare view

Updates fastapi from 0.139.0 to 0.141.1

Release notes

Sourced from fastapi's releases.

0.141.1

Fixes

  • 🐛 Fix support for background tasks and headers from dependencies in app.frontend(). PR #16105 by @​tiangolo.

Docs

0.141.0

Features

  • ✨ Add app.frontend(check_dir="auto"), to make local development more convenient with fastapi dev. PR #16102 by @​tiangolo.

0.140.13

Fixes

Docs

0.140.12

Fixes

0.140.11

Fixes

  • 🐛 Fix response_model_* params ignored for non-generator endpoints with Iterable[..] return type. PR #15093 by @​YuriiMotov.

0.140.10

Fixes

Internal

0.140.9

Fixes

  • 🐛 Fix exclude_defaults not propagated to dict keys and values in jsonable_encoder. PR #16043 by @​MBGrao.

... (truncated)

Commits
  • 95f8322 🔖 Release version 0.141.1 (#16106)
  • f137944 📝 Update release notes
  • d623544 🐛 Fix support for background tasks and headers from dependencies in `app.fron...
  • 1d211b9 📝 Update release notes
  • 8a1f876 📝 Document FASTAPI_ENV in FastAPI CLI guide (#16104)
  • c7e7b65 🔖 Release version 0.141.0 (#16103)
  • 6bceb84 📝 Update release notes
  • 5429fed ✨ Add app.frontend(check_dir="auto"), to make local development more conven...
  • 628663f 🔖 Release version 0.140.13 (#16096)
  • 0b54fd0 📝 Update release notes
  • Additional commits viewable in compare view

Updates uvicorn from 0.50.0 to 0.52.4

Release notes

Sourced from uvicorn's releases.

Version 0.52.4

Fixed

  • Remove duplicate Date headers from accepted WebSocket handshakes with websockets-sansio (#3078)

Full Changelog: Kludex/uvicorn@0.52.3...0.52.4

Version 0.52.3

Changed

  • Update zttp to 0.0.24 and use its combined receive path, improving HTTP/1.1 request parsing performance (#3067)

Full Changelog: Kludex/uvicorn@0.52.2...0.52.3

Version 0.52.2

Fixed

  • Update zttp to 0.0.22, fixing bodyless request receives and improving HTTP/1 request parsing performance (#3063)

Full Changelog: Kludex/uvicorn@0.52.1...0.52.2

Version 0.52.1

Fixed

  • Complete the closing handshake on server-initiated WebSocket closes in the websockets-sansio and wsproto implementations, waiting for the client's close reply with a 10 second timeout instead of resetting the connection (#3053)
  • Add missing write flow control to the websockets-sansio implementation, preventing data truncation on server-initiated closes with large in-flight payloads (#3048)
  • Handle connection loss while a WebSocket write is waiting on backpressure (#3050)
  • Remove duplicate Content-Type and Content-Length headers from WebSocket denial responses on the websockets-sansio implementation, and deliver non-UTF-8 denial bodies intact (#3041)

Full Changelog: Kludex/uvicorn@0.52.0...0.52.1

Version 0.52.0

This release adds an experimental HTTP/1.1 implementation backed by zttp, a sans-IO HTTP parser I've been developing on the side: a core written in Zig, with bindings to Python. It has been running under a fuzzer for some weeks now, and has been through multiple rounds of security auditing.

It is still experimental, so don't put it in front of production traffic yet. Try it with --http zttp, and please send any feedback to the issue tracker.

Added

  • Add an experimental zttp HTTP/1.1 implementation, selectable with --http zttp (#2979)

Fixed

  • Keep non-ASCII WebSocket request headers intact with websockets 17.0, which encodes them with ISO-8859-1 (#3036)

Full Changelog: Kludex/uvicorn@0.51.0...0.52.0

Version 0.51.0

What's Changed

... (truncated)

Changelog

Sourced from uvicorn's changelog.

0.52.4 (August 18, 2026)

Fixed

  • Remove duplicate Date headers from accepted WebSocket handshakes with websockets-sansio (#3078)

0.52.3 (August 13, 2026)

Changed

  • Update zttp to 0.0.24 and use its combined receive path, improving HTTP/1.1 request parsing performance (#3067)

0.52.2 (August 13, 2026)

Fixed

  • Update zttp to 0.0.22, fixing bodyless request receives and improving HTTP/1 request parsing performance (#3063)

0.52.1 (August 1, 2026)

Fixed

  • Complete the closing handshake on server-initiated WebSocket closes in the websockets-sansio and wsproto implementations, waiting for the client's close reply with a 10 second timeout instead of resetting the connection (#3053)
  • Add missing write flow control to the websockets-sansio implementation, preventing data truncation on server-initiated closes with large in-flight payloads (#3048)
  • Handle connection loss while a WebSocket write is waiting on backpressure (#3050)
  • Remove duplicate Content-Type and Content-Length headers from WebSocket denial responses on the websockets-sansio implementation, and deliver non-UTF-8 denial bodies intact (#3041)

0.52.0 (July 29, 2026)

This release adds an experimental HTTP/1.1 implementation backed by zttp, a sans-IO HTTP parser I've been developing on the side: a core written in Zig, with bindings to Python. It has been running under a fuzzer for some weeks now, and has been through multiple rounds of security auditing.

It is still experimental, so don't put it in front of production traffic yet. Try it with --http zttp, and please send any feedback to the issue tracker.

Added

  • Add an experimental zttp HTTP/1.1 implementation, selectable with --http zttp (#2979)

Fixed

  • Keep non-ASCII WebSocket request headers intact with websockets 17.0, which encodes them with ISO-8859-1 (#3036)

0.51.0 (July 8, 2026)

Added

  • Restart workers one at a time on SIGHUP, bringing each replacement up before retiring the old worker, so reloads no longer drop requests (#3025)

Removed

  • Remove colorama from the standard extra (#3027)

... (truncated)

Commits

Updates aws-opentelemetry-distro from 0.18.0 to 0.19.0

Release notes

Sourced from aws-opentelemetry-distro's releases.

Release v0.19.0

What's Changed

  • fix(mcp): fall back to HTTP headers for server-side trace context when params._meta is absent (#829)
  • fix(mcp-instrumentation): always inject W3C trace context into outbound HTTP request headers so MCP servers that read context only from HTTP (API Gateways, service meshes, non-Python MCP servers) can join the caller's trace, even with OTEL_MCP_SUPPRESS_HTTP_INSTRUMENTATION enabled (#827)
  • Nightly dependency update: OpenTelemetry 1.44.0/0.65b0 (#799)
  • feat(genai): capture user input and agent output on llama_index invoke_agent spans (#824)
  • fix(crewai): use native per-call token usage when crewai provides it (#822)
  • fix(crewai): normalize tool description across crewai versions (#821)
  • fix(serviceevents): key the incident-snapshot dedup hash on operation + bounded throw-site origin (module/path.function) (#825)
  • fix(crewai): report per-call LLM token usage instead of cumulative total (#806)
  • fix(genai): serialize tool call arguments/results and blob bytes to match OTel util-genai (primitives kept native, bytes base64-encoded) (#817)
  • feat(genai): capture user input and agent output on invoke_agent spans (#815)
  • refactor(serviceevents): make the endpoint span processor framework-agnostic
  • fix(serviceevents): gate incident trace correlation on the SAMPLED flag and harden incident dedup/rate-limiting
  • fix(genai): serialize list-valued message content into typed parts so multimodal/reasoning content is no longer stringified to a Python repr in gen_ai.input/output.messages across langchain, llama_index, and crewai (#805)
  • feat: add OTel lite SDK for Lambda cold start optimization (#789)

Upstream Components

  • opentelemetry-api - 1.44.0
  • opentelemetry-sdk - 1.44.0
  • opentelemetry-exporter-otlp-proto-grpc - 1.44.0
  • opentelemetry-exporter-otlp-proto-http - 1.44.0
  • opentelemetry-propagator-b3 - 1.44.0
  • opentelemetry-propagator-jaeger - 1.44.0
  • opentelemetry-exporter-otlp-proto-common - 1.44.0
  • opentelemetry-sdk-extension-aws - 2.1.0
  • opentelemetry-propagator-aws-xray - 1.0.2
  • opentelemetry-distro - 0.65b0
  • opentelemetry-processor-baggage - 0.65b0
  • opentelemetry-propagator-ot-trace - 0.65b0
  • opentelemetry-instrumentation - 0.65b0
  • opentelemetry-instrumentation-aws-lambda - 0.65b0
  • opentelemetry-instrumentation-aio-pika - 0.65b0
  • opentelemetry-instrumentation-aiohttp-client - 0.65b0
  • opentelemetry-instrumentation-aiokafka - 0.65b0
  • opentelemetry-instrumentation-aiopg - 0.65b0
  • opentelemetry-instrumentation-asgi - 0.65b0
  • opentelemetry-instrumentation-asyncpg - 0.65b0
  • opentelemetry-instrumentation-boto3sqs - 0.65b0
  • opentelemetry-instrumentation-botocore - 0.65b0
  • opentelemetry-instrumentation-celery - 0.65b0
  • opentelemetry-instrumentation-confluent-kafka - 0.65b0
  • opentelemetry-instrumentation-dbapi - 0.65b0
  • opentelemetry-instrumentation-django - 0.65b0
  • opentelemetry-instrumentation-falcon - 0.65b0
  • opentelemetry-instrumentation-fastapi - 0.65b0
  • opentelemetry-instrumentation-flask - 0.65b0
  • opentelemetry-instrumentation-grpc - 0.65b0
  • opentelemetry-instrumentation-httpx - 0.65b0

... (truncated)

Changelog

Sourced from aws-opentelemetry-distro's changelog.

v0.19.0 - 2026-07-22

  • fix(mcp): fall back to HTTP headers for server-side trace context when params._meta is absent (#829)
  • fix(mcp-instrumentation): always inject W3C trace context into outbound HTTP request headers so MCP servers that read context only from HTTP (API Gateways, service meshes, non-Python MCP servers) can join the caller's trace, even with OTEL_MCP_SUPPRESS_HTTP_INSTRUMENTATION enabled (#827)
  • Nightly dependency update: OpenTelemetry 1.44.0/0.65b0 (#799)
  • feat(genai): capture user input and agent output on llama_index invoke_agent spans (#824)
  • fix(crewai): use native per-call token usage when crewai provides it (#822)
  • fix(crewai): normalize tool description across crewai versions (#821)
  • fix(serviceevents): key the incident-snapshot dedup hash on operation + bounded throw-site origin (module/path.function) (#825)
  • fix(crewai): report per-call LLM token usage instead of cumulative total (#806)
  • fix(genai): serialize tool call arguments/results and blob bytes to match OTel util-genai (primitives kept native, bytes base64-encoded) (#817)
  • feat(genai): capture user input and agent output on invoke_agent spans (#815)
  • refactor(serviceevents): make the endpoint span processor framework-agnostic
  • fix(serviceevents): gate incident trace correlation on the SAMPLED flag and harden incident dedup/rate-limiting
  • fix(genai): serialize list-valued message content into typed parts so multimodal/reasoning content is no longer stringified to a Python repr in gen_ai.input/output.messages across langchain, llama_index, and crewai (#805)
  • feat: add OTel lite SDK for Lambda cold start optimization (#789)
Commits
  • 821465a Pre-release: Update version to 0.19.0 (#834)
  • ed8782f Backport #797 to release/v0.19.x: add Python 3.14 Lambda runtime (#835)
  • 4dcbf60 test(e2e): wire Python Lambda Lite SDK test into Application Signals E2E (#833)
  • 315bddd fix(mcp): extract server-side trace context from HTTP headers when _meta is a...
  • 76f8f2d Nightly dependency update: OpenTelemetry 1.44.0/0.65b0 (#799)
  • ffa8c72 fix(mcp-instrumentation): inject W3C trace context into outbound HTTP headers...
  • d7e49b5 Revert "feat(genai): extract gen_ai.tool.call.arguments/result as LLO content...
  • f9bb4f5 feat(genai): capture user input and agent output on llama_index invoke_agent ...
  • 2b43f03 Add best-effort public ECR image signing to release workflow (#828)
  • 9356e72 Key incident-snapshot dedup hash on operation + throw-site origin (#825)
  • Additional commits viewable in compare view

Updates mcp from 1.28.1 to 2.2.0

Release notes

Sourced from mcp's releases.

v2.2.0

pip install -U mcp. Docs: https://py.sdk.modelcontextprotocol.io/

A few defaults changed in this release. If you run a server or client on 2.x, skim these first:

Behaviour changes

HTTP client redirects are only followed within the endpoint's origin (#3397)

  • Client("https://..."), streamable_http_client and sse_client follow a redirect only if it stays on the same scheme, host and port (or upgrades http to https on the same host).
  • A redirect anywhere else is not followed: the call fails with MCPError and the session stays usable (an SSE connect fails with httpx2.HTTPStatusError). If that other URL is the server you meant, use it as the endpoint URL.
  • The follow_redirects setting on an httpx2.AsyncClient you pass in is no longer used for MCP requests, so you don't need it for the trailing-slash redirect any more.
  • The OAuth providers apply the same rule to their own requests.

Idle Streamable HTTP sessions now expire (legacy <=2025-11-25 spec( (#3395)

  • A stateful session with nothing in flight for 30 minutes is closed. The client's next request gets a 404 and it has to initialize again.
  • Clients that keep the GET stream open (the SDK's Client does) are not affected. Neither are stateless servers or 2026-07-28 connections.
  • A server also holds at most 10 000 sessions at once; beyond that, new sessions get a 503.
  • To turn either off: mcp.run(transport="streamable-http", session_idle_timeout=None, max_sessions=None) (also on streamable_http_app() and run_streamable_http_async()).

The OAuth client checks the authorization server's issuer on the legacy path too (#3398)

  • For servers without protected resource metadata, authorization server metadata whose issuer isn't the server's own origin is now rejected with OAuthFlowError: Authorization server metadata issuer mismatch. The protected-resource-metadata path has done this since 2.0.
  • A 403 that isn't an insufficient_scope challenge is returned to the caller instead of retried.
  • If protected resource metadata can't be fetched because of a 5xx/429, the flow now stops instead of falling back to the legacy endpoints.

Two new MCPDeprecationWarnings (#3435, #3447)

  • ClientCredentialsOAuthProvider / PrivateKeyJWTOAuthProvider without issuer=. Pass your authorization server's issuer URL; 3.0 will require it.
  • AuthSettings with resource_server_url set but validate_token_resource unset. Set it to True or False; 3.0 defaults it to True.
  • Both keep working as before in 2.x; this mostly matters if your tests turn warnings into errors.

New

  • AuthSettings.validate_token_resource: only accept tokens your TokenVerifier reports as issued for this server (#3447).
  • issuer= on ClientCredentialsOAuthProvider and PrivateKeyJWTOAuthProvider (#3398).
  • session_idle_timeout= and max_sessions= on the Streamable HTTP server entry points (#3395).

Fixes

  • A client DELETE frees its session immediately, and a refused opening request no longer leaves a session behind (#2455, #3228, #3300).
  • $refs in a tool's outputSchema resolve within that schema only; an unresolvable one surfaces as RuntimeError: Invalid schema for tool ... (#3394).

Known gaps

The tasks extension (SEP-2663), DPoP (SEP-1932) and the jwt-bearer grant are not implemented yet; https://github.com/modelcontextprotocol/python-sdk/blob/main/ROADMAP.md tracks them.

What's Changed

... (truncated)

Commits
  • 9972c21 Replace RootModel wrappers with type aliases and TypeAdapter validation (#3470)
  • fd66270 docs: refresh translations, and translate pages in parallel (#3458)
  • 08a3bc8 docs: ask for AI disclosure on comments too (#3459)
  • 7bb486a docs: stop presenting the in-memory client as the way to connect (#3443)
  • 0c91368 Add AuthSettings.validate_token_resource to check a bearer token's resource (...
  • 9771e6b Keep following a relative redirect when the endpoint URL carries userinfo (#3...
  • a925e55 Bump the locked versions of eight dev and test dependencies (#3449)
  • e8b9486 Bump pymdown-extensions from 11.0 to 11.0.1 (#3285)
  • c6762e8 Follow redirects only within the MCP endpoint's origin (#3397)
  • 5fd3abc Skip automatic docs previews for fork PRs and drop the setup-uv retry steps (...
  • Additional commits viewable in compare view

Updates ruff from 0.15.20 to 0.16.7

Release notes

Sourced from ruff's releases.

0.16.7

Release Notes

Released on 2026-09-10.

Preview features

  • [ruff] Add rule for default values on method receivers (RUF077) (#26700)
  • [ruff] Recognize re.prefixmatch (RUF039, RUF055) (#28311)

Bug fixes

  • Alternate nested quotes inside format spec interpolations (#28259)
  • [flake8-implicit-str-concat] Mark fix unsafe when it creates a docstring (ISC003) (#27981)
  • [flake8-tidy-imports] Skip fixes for multi-member imports (TID254) (#26584)
  • [pylint] Gate ImportCycleError on Python 3.15 (PLW0133) (#28310)

Rule changes

  • Correct D211 and D203 rule conflict diagnostic (#28444)
  • Recognize slice and frozendict generics (#28477)
  • Stop defining __cached__ for Python 3.15 (#28476)
  • [pyupgrade] Stop recommending removed typing.no_type_check_decorator (UP035) (#28475)

Performance

  • Reuse parser name lookups when interning (#28399)
  • Speed up inherited configuration resolution (#28299)

Documentation

  • Fix line-length path in --config example (#28392)
  • Remove the "Who’s Using Ruff?" list (#28455)

Other changes

  • Embed archive checksums in the shell installer (#28281)

Contributors

... (truncated)

Changelog

Sourced from ruff's changelog.

0.16.7

Released on 2026-09-10.

Preview features

  • [ruff] Add rule for default values on method receivers (RUF077) (#26700)
  • [ruff] Recognize re.prefixmatch (RUF039, RUF055) (#28311)

Bug fixes

  • Alternate nested quotes inside format spec interpolations (#28259)
  • [flake8-implicit-str-concat] Mark fix unsafe when it creates a docstring (ISC003) (#27981)
  • [flake8-tidy-imports] Skip fixes for multi-member imports (TID254) (#26584)
  • [pylint] Gate ImportCycleError on Python 3.15 (PLW0133) (#28310)

Rule changes

  • Correct D211 and D203 rule conflict diagnostic (#28444)
  • Recognize slice and frozendict generics (#28477)
  • Stop defining __cached__ for Python 3.15 (#28476)
  • [pyupgrade] Stop recommending removed typing.no_type_check_decorator (UP035) (#28475)

Performance

  • Reuse parser name lookups when interning (#28399)
  • Speed up inherited configuration resolution (#28299)

Documentation

  • Fix line-length path in --config example (#28392)
  • Remove the "Who’s Using Ruff?" list (#28455)

Other changes

  • Embed archive checksums in the shell installer (#28281)

Contributors

... (truncated)

Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels Sep 5, 2026
@dependabot
dependabot Bot requested review from a team and backgroundagents as code owners September 5, 2026 06:14
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels Sep 5, 2026
@isadeks

isadeks commented Sep 9, 2026

Copy link
Copy Markdown
Contributor

Not mergeable as grouped — one breaking major, plus a silent break of a documented cross-ecosystem lockstep.

1. mcp 1.28.1 → 2.1.1 is a major and moves two symbols the agent imports. //agent:typecheck fails:

error[unresolved-import]: Module `mcp.client.streamable_http` has no member
                         `streamablehttp_client`
error[unresolved-import]: Module `mcp.shared.exceptions` has no member `McpError`
error[unresolved-import]: Cannot resolve imported module `httpx`
error[invalid-argument-type]: Argument to bound method `ClientSession.call_tool`
                             is incorrect

The httpx resolution failure looks like a knock-on of mcp 2.x reshaping its dependency surface. Either way this needs a real migration of the MCP client call sites, not a lockfile refresh.

2. claude-agent-sdk 0.2.110 → 0.2.148 breaks the #215 lockstep, and CI cannot catch it. agent/pyproject.toml:19 states the invariant:

"claude-agent-sdk==0.2.110",  # ... (bundles claude CLI 2.1.191;
                              # kept in lockstep with the npm CLI pin
                              # in the Dockerfile, #215)

and agent/Dockerfile:90 is the other half:

npm install -g @anthropic-ai/claude-code@2.1.191

This PR changes only agent/pyproject.toml and agent/uv.lock. The Dockerfile pin stays at 2.1.191 while the SDK moves 38 patch releases, so the bundled CLI and the installed CLI diverge — and the inline comment still asserts 2.1.191, so it becomes a false claim in the same commit. Dependabot cannot see this because the two halves are in different ecosystems (uv and docker/npm).

Worth noting the config already handles exactly this shape for the Cedar engines — .github/dependabot.yml:48 and :71 carry reciprocal ignore entries for cedarpy@cedar-policy/cedar-wasm with a comment pointing at the decision. claude-agent-sdk ⊥ the Dockerfile CLI pin is the same class of coupling and has no such guard. That is the durable fix here.

The remaining bumps in this group (boto3, fastapi, uvicorn, pygments, aws-opentelemetry-distro, bedrock-agentcore) look routine. As in #860, they cannot be split out from here because all-python uses patterns: ["*"] with open-pull-requests-limit: 1.

Leaving open rather than closing: with the config unchanged, closing returns the same PR next Saturday.

isadeks added a commit that referenced this pull request Sep 10, 2026
Each ecosystem groups every update into one PR with a PR limit of 1, so a
breaking major freezes that ecosystem outright: the group PR cannot merge and
the limit stops a second PR being opened for the safe remainder. #860 has held
47 npm updates since 2026-09-05 behind typescript 6->7 and cdk-nag 2->3, and
#859 has held 10 python updates behind mcp 1->2.

The cost is already concrete: #860 carries astro 7.1.3 -> 7.2.9, which fixes
GHSA-26w7-cxv4-gfx2 (CVSS 9.8), and it has sat unmergeable for five days. #870
exists to hand-write that same bump plus six other advisory fixes, duplicating
work dependabot had already done.

Exclude majors from the grouped PR instead of routing them to a second group.
A group restricted to minor/patch would leave majors *ungrouped*, and an
ungrouped update gets its own PR — that would mean one PR per major dependency,
strictly worse than today. Ignoring them keeps the steady state at one grouped
PR per ecosystem, the same count as now but without the wedge.

- Ignore `version-update:semver-major` for `*` in all four ecosystems. Groups
  are left exactly as they are on main.
- Raise `open-pull-requests-limit` 1 -> 2: one grouped PR plus a slot of
  headroom, so a lone ungrouped or security PR cannot starve the group.
- Ignore `python` minor on docker (#105). 3.13 -> 3.14 must land with
  agent/mise.toml, agent/.python_version, the ruff and ty targets in
  agent/pyproject.toml, the lockfile, and three prose sites naming the base
  tag. #827 moved only the Dockerfile. Digest and patch refreshes still flow.
- Ignore `claude-agent-sdk`, mirroring cedarpy. It bundles the `claude` CLI,
  pinned separately by an `npm install -g` line in agent/Dockerfile that is in
  no package.json — so no ecosystem tracks it and only a human can move it. An
  automated SDK bump diverges bundled from installed CLI and stales the version
  in pyproject's own comment (#215).
- State `semver-major` explicitly on each per-dependency ignore even though the
  blanket rule covers it. The blanket rule is a policy that may be revisited;
  each per-dependency block is an invariant. Relaxing the policy must not
  silently degrade one.

Trade-off: a major that fixes an advisory no longer arrives as a PR. Detection
is unaffected — `//:security:deps` fails the build on any advisory regardless
of dependabot — but the upgrade is driven by hand. Majors become issues.
isadeks added a commit that referenced this pull request Sep 10, 2026
Each ecosystem groups every update into one PR with a PR limit of 1, so a
breaking major freezes that ecosystem outright: the group PR cannot merge and
the limit stops a second PR being opened for the safe remainder. #860 has held
47 npm updates since 2026-09-05 behind typescript 6->7 and cdk-nag 2->3, and
#859 has held 10 python updates behind mcp 1->2.

The cost is already concrete: #860 carries astro 7.1.3 -> 7.2.9, which fixes
GHSA-26w7-cxv4-gfx2 (CVSS 9.8), and it has sat unmergeable for five days. #870
exists to hand-write that same bump plus six other advisory fixes, duplicating
work dependabot had already done.

Exclude majors from the grouped PR instead of routing them to a second group.
A group restricted to minor/patch would leave majors *ungrouped*, and an
ungrouped update gets its own PR — that would mean one PR per major dependency,
strictly worse than today. Ignoring them keeps the steady state at one grouped
PR per ecosystem, the same count as now but without the wedge.

- Ignore `version-update:semver-major` for `*` in all four ecosystems. Groups
  are left exactly as they are on main.
- Raise `open-pull-requests-limit` 1 -> 2: one grouped PR plus a slot of
  headroom, so a lone ungrouped or security PR cannot starve the group.
- Ignore `python` minor on docker (#105). 3.13 -> 3.14 must land with
  agent/mise.toml, agent/.python_version, the ruff and ty targets in
  agent/pyproject.toml, the lockfile, and three prose sites naming the base
  tag. #827 moved only the Dockerfile. Digest and patch refreshes still flow.
- Ignore `claude-agent-sdk`, mirroring cedarpy. It bundles the `claude` CLI,
  pinned separately by an `npm install -g` line in agent/Dockerfile that is in
  no package.json — so no ecosystem tracks it and only a human can move it. An
  automated SDK bump diverges bundled from installed CLI and stales the version
  in pyproject's own comment (#215).
- State `semver-major` explicitly on each per-dependency ignore even though the
  blanket rule covers it. The blanket rule is a policy that may be revisited;
  each per-dependency block is an invariant. Relaxing the policy must not
  silently degrade one.

Trade-off: a major that fixes an advisory no longer arrives as a PR. Detection
is unaffected — `//:security:deps` fails the build on any advisory regardless
of dependabot — but the upgrade is driven by hand. Majors become issues.
isadeks added a commit that referenced this pull request Sep 10, 2026
Each ecosystem groups every update into one PR with a PR limit of 1, so a
breaking major freezes that ecosystem outright: the group PR cannot merge and
the limit stops a second PR being opened for the safe remainder. #860 has held
47 npm updates since 2026-09-05 behind typescript 6->7 and cdk-nag 2->3, and
#859 has held 10 python updates behind mcp 1->2.

The cost was concrete: #860 carries astro 7.1.3 -> 7.2.9, which fixes
GHSA-26w7-cxv4-gfx2 (CVSS 9.8), and it sat unmergeable for five days. #870 had
to hand-write that same bump plus six other advisory fixes, duplicating work
dependabot had already done.

Exclude majors from the grouped PR instead of routing them to a second group.
A group restricted to minor/patch would leave majors *ungrouped*, and an
ungrouped update gets its own PR — that would mean one PR per major dependency,
strictly worse than today. Ignoring them keeps the steady state at one grouped
PR per ecosystem, the same count as now but without the wedge.

- Ignore `version-update:semver-major` for `*` in all four ecosystems. Groups
  are left exactly as they are on main.
- Raise `open-pull-requests-limit` 1 -> 2: one grouped PR plus a slot of
  headroom, so a lone ungrouped or security PR cannot starve the group.
- Ignore `python` minor on docker (#105). 3.13 -> 3.14 must land with
  agent/mise.toml, agent/.python_version, the ruff and ty targets in
  agent/pyproject.toml, the lockfile, and three prose sites naming the base
  tag. #827 moved only the Dockerfile. Digest and patch refreshes still flow.
- Ignore `claude-agent-sdk`, mirroring cedarpy. It bundles the `claude` CLI,
  pinned separately by an `npm install -g` line in agent/Dockerfile that is in
  no package.json — so no ecosystem tracks it and only a human can move it. An
  automated SDK bump diverges bundled from installed CLI and stales the version
  in pyproject's own comment (#215).
- State `semver-major` explicitly on each per-dependency ignore even though the
  blanket rule covers it. The blanket rule is a policy that may be revisited;
  each per-dependency block is an invariant. Relaxing the policy must not
  silently degrade one.

Trade-off: a major that fixes an advisory no longer arrives as a PR. Detection
is unaffected — `//:security:deps` fails the build on any advisory regardless
of dependabot — but the upgrade is driven by hand. Majors become issues.
@dependabot
dependabot Bot force-pushed the dependabot/uv/agent/all-python-4666157a7c branch from 22c37e7 to fe0e73b Compare September 12, 2026 06:15
@scottschreckengaust scottschreckengaust added the v1 Version 1 label Sep 14, 2026

@scottschreckengaust scottschreckengaust left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Verdict: Request changes

This Dependabot all-python group bump is not mergeable as grouped. Two of the ten updates are breaking: mcp 1.28.1 → 2.1.1 is a hard, empirically-confirmed break of the agent's Gateway bridge, and claude-agent-sdk 0.2.110 → 0.2.152 silently violates the documented #215 cross-ecosystem lockstep. CI already reflects this: build (agentcore) is FAILURE and the PR is BLOCKED. This confirms and re-states the earlier maintainer comment (@isadeks) against the current head fe0e73b (the group was rebased from 0.2.148 → 0.2.152 / mcp 2.1.1; the breakage is unchanged).

Vision alignment

Dependency hygiene supports the improvable / bounded tenet, and the routine bumps (boto3, botocore, fastapi, uvicorn, pygments, aws-opentelemetry-distro, bedrock-agentcore, ruff, ty) are welcome. But shipping a red agentcore build and a broken Gateway data path directly undercuts control-plane reliability — the bridge to abca_repo_config would fail closed-to-error at runtime, not degrade gracefully.

Blocking issues

1. mcp 1.28.1 → 2.1.1 (major) breaks agent/src/gateway_tools.pyagent/pyproject.toml:24.
I ran uv sync --frozen + uv run ty check src/gateway_tools.py at this head. Result: 6 diagnostics, all traceable to the mcp 2.x major:

  • error[unresolved-import]: Cannot resolve imported module "httpx" (gateway_tools.py:206, and the same unconditional import httpx at :85 inside _sigv4_auth). mcp 2.x reshaped its transport deps: the lock removes httpx entirely (replaced by httpx2/httpcore2, uv.lock lines ~611-666). import httpx in _sigv4_auth is not guarded by try/except, so the Gateway bridge raises ModuleNotFoundError at call time whenever enableToolGateway=true. Confirmed: uv run python -c "import httpx"ModuleNotFoundError.
  • error[unresolved-import]: Module "mcp.shared.exceptions" has no member "McpError" (gateway_tools.py:212).
  • error[invalid-argument-type]: Argument to bound method "ClientSession.call_tool" is incorrect (gateway_tools.py:178): 2.x now types read_timeout_seconds: float | None, but the call passes timedelta(...).
  • (plus the streamablehttp_client / mcp.client.streamable_http and related fallout the maintainer noted.)

This is a real migration, not a lockfile refresh. Fix: either pin mcp below 2.0 in this group (add an ignore for mcp major in .github/dependabot.yml) or land a separate PR that migrates the gateway_tools.py call sites (httpxhttpx2 or whatever mcp 2.x re-exports, McpError new location, call_tool float timeout) with tests, then let the group bump ride on top.

2. claude-agent-sdk 0.2.110 → 0.2.152 breaks the #215 lockstep and lands a false comment — agent/pyproject.toml:19.
The pin at pyproject.toml:19 and agent/Dockerfile:76,90 are two halves of one documented invariant: the SDK bundles a claude CLI that must match the @anthropic-ai/claude-code@2.1.191 pin installed on PATH ("the SDK and the on-PATH CLI must agree on the control protocol", Dockerfile:77-78). This PR moves the SDK 42 patch releases but does not touch the Dockerfile, so the two diverge. Worse, the inline comment on line 19 still reads .../releases/tag/v0.2.110 (bundles claude CLI 2.1.191; kept in lockstep with the npm CLI pin in the Dockerfile, #215) — a claim that is now false in the same commit. Dependabot can't see this because the halves live in different ecosystems (uv vs docker/npm). Durable fix: mirror the pattern already used for the Cedar engines (.github/dependabot.yml:48,71 reciprocal ignore for cedarpy@cedar-policy/cedar-wasm) — add an ignore for claude-agent-sdk so it is bumped deliberately alongside the Dockerfile CLI pin and the comment. If the intent is to move the SDK, the Dockerfile CLI pin and the line-19 comment (URL tag + CLI version) must move in the same PR.

Non-blocking suggestions / nits

  • agent/pyproject.toml:19 — even independent of blocker 2, the release-tag URL (v0.2.110) is stale relative to the ==0.2.152 pin. Update to the matching tag when the SDK moves.
  • Grouping friction (informational): all-python uses patterns: ["*"] with open-pull-requests-limit: 1, so the routine bumps genuinely cannot be split from the two breaking ones inside this PR. The reciprocal-ignore fixes above are what let the safe bumps flow next cycle without dragging the breaking ones along.

Documentation

No docs/guides or design changes required for a dep bump, and none shipped — appropriate. The one doc-like artifact that IS wrong is the in-repo invariant comment at pyproject.toml:19 (see blocker 2). No Starlight mirror impact.

Tests & CI

  • CI: build (agentcore) = FAILURE; PR mergeStateStatus = BLOCKED. CodeQL NEUTRAL, secrets/deps scan SUCCESS, PR-title checks SUCCESS.
  • I independently reproduced the agent typecheck failure (6 ty diagnostics) locally against fe0e73b.
  • No bootstrap / CDK synth-coverage relevance: not applicable — this PR touches only agent/pyproject.toml and agent/uv.lock; no constructs, stacks, handlers, or CFN resource types change, so ADR-002 bootstrap-bundle checks do not apply.
  • Transitive-pin sync (#712): not applicable — no root package.json resolutions change, so the integrations/jira-forge-app overrides mirror is unaffected.

Review agents run

Execution context is a non-interactive subagent that cannot spawn the nested pr-review-toolkit agents or /security-review; I performed the equivalent analysis by hand and state that limitation explicitly here.

  • code-reviewer (by hand): guideline check — dep-bump routing correct (agent tree), lockfile internally consistent; two breaking bumps flagged.
  • silent-failure-hunter (by hand): _sigv4_auth's unconditional import httpx is NOT in the try/except that _expected_gateway_errors uses, so the Gateway path fails loudly with ModuleNotFoundError rather than silently — but it fails, which is blocker 1.
  • type-design-analyzer (by hand): no new types; call_tool timeout contract changed under us (timedelta→float).
  • comment-analyzer (by hand): pyproject.toml:19 comment is now factually false (blocker 2 / nit).
  • pr-test-analyzer (by hand): no tests added; existing agent/tests/test_gateway_tools.py would need updates once the mcp 2.x call sites are migrated.
  • security-review (by hand): no IAM/Cedar/network/secrets/input-gateway surface changed; SigV4 signing logic untouched. No security findings beyond the availability break of the signed Gateway call.

Human heuristics

  • Proportionality — Concern: a single grouped PR mixes 8 routine patch/minor bumps with 2 breaking changes; complexity of the fix (call-site migration + Dockerfile lockstep) far exceeds "refresh the lock".
  • Coherence — Concern: the claude-agent-sdk ⊥ Dockerfile-CLI coupling is the same class as the already-guarded Cedar coupling (dependabot.yml:48,71) but lacks the reciprocal guard (agent/pyproject.toml:19).
  • Clarity — Concern: pyproject.toml:19 comment asserts a CLI/tag pairing that this commit invalidates.
  • Appropriateness — Concern: verified against real installed packages (uv sync + ty), not mocks; the break is real, not theoretical.

Comment thread agent/pyproject.toml Outdated
"fastapi==0.141.1", #https://pypi.org/project/fastapi/
"uvicorn==0.52.4", #https://pypi.org/project/uvicorn/
"aws-opentelemetry-distro==0.19.0", #https://pypi.org/project/aws-opentelemetry-distro/
"mcp==2.1.1", #https://pypi.org/project/mcp/

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Blocking: mcp 1.28.1 → 2.1.1 is a major bump that breaks agent/src/gateway_tools.py. Reproduced locally at this head with uv sync --frozen && uv run ty check src/gateway_tools.py — 6 diagnostics:

  • unresolved-import: Cannot resolve module "httpx" — mcp 2.x drops httpx for httpx2, so the lock no longer contains httpx; the unconditional import httpx in _sigv4_auth (gateway_tools.py:85) now raises ModuleNotFoundError at call time whenever enableToolGateway=true.
  • Module "mcp.shared.exceptions" has no member "McpError" (gateway_tools.py:212).
  • ClientSession.call_tool(read_timeout_seconds=...) now wants float | None, not timedelta (gateway_tools.py:178).

This needs a real migration of the MCP client call sites, or pin mcp < 2.0 via a .github/dependabot.yml ignore. As-is, build (agentcore) is failing.

Comment thread agent/pyproject.toml
"bedrock-agentcore==1.18.1", #https://pypi.org/project/bedrock-agentcore/
"claude-agent-sdk==0.2.110", #https://github.com/anthropics/claude-agent-sdk-python/releases/tag/v0.2.110 (bundles claude CLI 2.1.191; kept in lockstep with the npm CLI pin in the Dockerfile, #215)
"bedrock-agentcore==1.22.0", #https://pypi.org/project/bedrock-agentcore/
"claude-agent-sdk==0.2.152", #https://github.com/anthropics/claude-agent-sdk-python/releases/tag/v0.2.110 (bundles claude CLI 2.1.191; kept in lockstep with the npm CLI pin in the Dockerfile, #215)

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Blocking: claude-agent-sdk 0.2.110 → 0.2.152 breaks the documented #215 lockstep. This comment still asserts v0.2.110 and bundles claude CLI 2.1.191; kept in lockstep with the npm CLI pin in the Dockerfile — but the Dockerfile pin (@anthropic-ai/claude-code@2.1.191, Dockerfile:90) is untouched here, so the SDK-bundled CLI and the on-PATH CLI now diverge, and the comment is false in this same commit.

Fix: either move the Dockerfile CLI pin + this comment (URL tag and CLI version) in the same PR, or add a reciprocal ignore for claude-agent-sdk in .github/dependabot.yml mirroring the Cedar-engine guard at lines 48/71, so it is bumped deliberately with the Dockerfile.

… updates

Bumps the all-python group with 10 updates in the /agent directory:

| Package | From | To |
| --- | --- | --- |
| [boto3](https://github.com/boto/boto3) | `1.43.78` | `1.43.93` |
| [bedrock-agentcore](https://github.com/aws/bedrock-agentcore-sdk-python) | `1.18.1` | `1.23.0` |
| [claude-agent-sdk](https://github.com/anthropics/claude-agent-sdk-python) | `0.2.110` | `0.2.152` |
| [fastapi](https://github.com/fastapi/fastapi) | `0.139.0` | `0.141.1` |
| [uvicorn](https://github.com/Kludex/uvicorn) | `0.50.0` | `0.52.4` |
| [aws-opentelemetry-distro](https://github.com/aws-observability/aws-otel-python-instrumentation) | `0.18.0` | `0.19.0` |
| [mcp](https://github.com/modelcontextprotocol/python-sdk) | `1.28.1` | `2.2.0` |
| [ruff](https://github.com/astral-sh/ruff) | `0.15.20` | `0.16.7` |
| [ty](https://github.com/astral-sh/ty) | `0.0.56` | `0.0.80` |
| [pygments](https://github.com/pygments/pygments) | `2.20.0` | `2.21.0` |



Updates `boto3` from 1.43.78 to 1.43.93
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](boto/boto3@1.43.78...1.43.93)

Updates `bedrock-agentcore` from 1.18.1 to 1.23.0
- [Release notes](https://github.com/aws/bedrock-agentcore-sdk-python/releases)
- [Changelog](https://github.com/aws/bedrock-agentcore-sdk-python/blob/main/CHANGELOG.md)
- [Commits](aws/bedrock-agentcore-sdk-python@v1.18.1...v1.23.0)

Updates `claude-agent-sdk` from 0.2.110 to 0.2.152
- [Release notes](https://github.com/anthropics/claude-agent-sdk-python/releases)
- [Changelog](https://github.com/anthropics/claude-agent-sdk-python/blob/main/CHANGELOG.md)
- [Commits](anthropics/claude-agent-sdk-python@v0.2.110...v0.2.152)

Updates `fastapi` from 0.139.0 to 0.141.1
- [Release notes](https://github.com/fastapi/fastapi/releases)
- [Commits](fastapi/fastapi@0.139.0...0.141.1)

Updates `uvicorn` from 0.50.0 to 0.52.4
- [Release notes](https://github.com/Kludex/uvicorn/releases)
- [Changelog](https://github.com/Kludex/uvicorn/blob/main/docs/release-notes.md)
- [Commits](Kludex/uvicorn@0.50.0...0.52.4)

Updates `aws-opentelemetry-distro` from 0.18.0 to 0.19.0
- [Release notes](https://github.com/aws-observability/aws-otel-python-instrumentation/releases)
- [Changelog](https://github.com/aws-observability/aws-otel-python-instrumentation/blob/main/CHANGELOG.md)
- [Commits](aws-observability/aws-otel-python-instrumentation@v0.18.0...v0.19.0)

Updates `mcp` from 1.28.1 to 2.2.0
- [Release notes](https://github.com/modelcontextprotocol/python-sdk/releases)
- [Changelog](https://github.com/modelcontextprotocol/python-sdk/blob/main/RELEASE.md)
- [Commits](modelcontextprotocol/python-sdk@v1.28.1...v2.2.0)

Updates `ruff` from 0.15.20 to 0.16.7
- [Release notes](https://github.com/astral-sh/ruff/releases)
- [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md)
- [Commits](astral-sh/ruff@0.15.20...0.16.7)

Updates `ty` from 0.0.56 to 0.0.80
- [Release notes](https://github.com/astral-sh/ty/releases)
- [Changelog](https://github.com/astral-sh/ty/blob/main/CHANGELOG.md)
- [Commits](astral-sh/ty@0.0.56...0.0.80)

Updates `pygments` from 2.20.0 to 2.21.0
- [Release notes](https://github.com/pygments/pygments/releases)
- [Changelog](https://github.com/pygments/pygments/blob/master/CHANGES)
- [Commits](pygments/pygments@2.20.0...2.21.0)

---
updated-dependencies:
- dependency-name: aws-opentelemetry-distro
  dependency-version: 0.19.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-python
- dependency-name: bedrock-agentcore
  dependency-version: 1.22.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-python
- dependency-name: boto3
  dependency-version: 1.43.83
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all-python
- dependency-name: claude-agent-sdk
  dependency-version: 0.2.148
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all-python
- dependency-name: fastapi
  dependency-version: 0.141.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-python
- dependency-name: mcp
  dependency-version: 2.1.1
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: all-python
- dependency-name: pygments
  dependency-version: 2.21.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: all-python
- dependency-name: ruff
  dependency-version: 0.16.5
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: all-python
- dependency-name: ty
  dependency-version: 0.0.75
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: all-python
- dependency-name: uvicorn
  dependency-version: 0.52.4
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-python
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/uv/agent/all-python-4666157a7c branch from fe0e73b to 67715e7 Compare September 19, 2026 06:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code v1 Version 1

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants