Skip to content

build(deps): bump the back-prod-minor-update group across 1 directory with 3 updates - #2915

Closed
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/pip/back/back-prod-minor-update-c218aa36f5
Closed

dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/pip/back/back-prod-minor-update-c218aa36f5

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the back-prod-minor-update group with 3 updates in the /back directory: sentry-sdk, peewee and pyjwt.

Updates sentry-sdk from 2.69.2 to 2.70.0

Release notes

Sourced from sentry-sdk's releases.

2.70.0

New Features ✨

import sentry_sdk
from sentry_sdk.integrations.mistral import MistralIntegration
sentry_sdk.init(
dsn="...",
traces_sample_rate=1.0,
integrations=[
MistralIntegration(),
]
)

import sentry_sdk
sentry_sdk.init(
data_collection={
"user_info": False,
"gen_ai": {"inputs": False, "outputs": False},
"graphql": {"document": False, "variables": False},
"database_query_data": False,
"queues": False,
"http_bodies": [],
"cookies": {
"mode": "denylist",
"terms": ["forwarded", "-ip", "remote-", "via", "-user"],
},
"http_headers": {
"request": {
"mode": "denylist",
"terms": ["forwarded", "-ip", "remote-", "via", "-user"],
},
},
</tr></table>

... (truncated)

Changelog

Sourced from sentry-sdk's changelog.

2.70.0

New Features ✨

import sentry_sdk
from sentry_sdk.integrations.mistral import MistralIntegration
sentry_sdk.init(
dsn="...",
traces_sample_rate=1.0,
integrations=[
MistralIntegration(),
]
)

import sentry_sdk
sentry_sdk.init(
data_collection={
"user_info": False,
"gen_ai": {"inputs": False, "outputs": False},
"graphql": {"document": False, "variables": False},
"database_query_data": False,
"queues": False,
"http_bodies": [],
"cookies": {
"mode": "denylist",
"terms": ["forwarded", "-ip", "remote-", "via", "-user"],
},
"http_headers": {
"request": {
"mode": "denylist",
"terms": ["forwarded", "-ip", "remote-", "via", "-user"],
},
</tr></table>

... (truncated)

Commits
  • 1eb7df5 Update CHANGELOG.md
  • 92fd42b release: 2.70.0
  • d99edef ref(data-collection): Promote data_collection from _experiments o top-lev...
  • 045d2c1 test: Close client on teardown (#7562)
  • b454d7d feat(mistral): Record gen_ai.output.messages (#7549)
  • bdfd68c feat(mistral): Record gen_ai.input.messages (#7548)
  • ea08f64 feat(mistral): Record gen_ai.system_instructions (#7547)
  • dbddd0e feat(mistral): Record request parameters (#7531)
  • 9342968 feat(mistral): Record token usage (#7529)
  • 988fd0e feat(mistral): Add integration with Chat.complete and Chat.complete_async...
  • Additional commits viewable in compare view

Updates peewee from 4.4.0 to 4.5.1

Release notes

Sourced from peewee's releases.

4.5.1

Couple little things for EnumField.

  • EnumField and IntEnumField validate member value types (str and int respectively) at field construction.
  • EnumField and IntEnumField default choices to (value, name) pairs derived from the enum.
  • Fix #3075, migration generation for EnumField. Generated migrations will emit the storage field type (e.g. IntegerField) rather than EnumField().

View commits

4.5.0

Backwards-incompatible:

  • MySQL and MariaDB connections no longer set sql_mode. Peewee had been setting PIPES_AS_CONCAT, but the param replaced the server's mode rather than adding to it, which silently disabled STRICT_TRANS_TABLES (etc). Going forward Peewee will not modify sql_mode by default and use CONCAT() rather than || for MySQL/MariaDB.
  • MySQL and MariaDB connection charset defaults to utf8mb4 instead of utf8, which is an alias for utf8mb3 and cannot store 4-byte characters.
  • A field's sequence= is now qualified with the model's Meta.schema. If the name you pass already contains a dot it is treated as fully-qualified and used as-is, so sequence='other.seq' is unaffected by Meta.schema. Also, sequence_exists() accepts a schema-qualified name.
  • SQLite BEGIN, COMMIT and ROLLBACK are issued directly on a cursor rather than through execute_sql(), so they are no longer debug-logged, do not fire query hooks and are not counted by count_queries(). This matches Postgres and MySQL.
  • atomic() and transaction() on a closed database with autoconnect=False now raise InterfaceError on Postgres and MySQL, as they already did on SQLite (and as queries do). Previously begin() opened a connection regardless of autoconnect.

Improvements:

  • Add SqliteDatabase(..., lock_type=...) to set the default locking strategy for transactions that do not specify one, e.g. lock_type='IMMEDIATE'.
  • Postgres introspection (get_tables(), get_columns(), get_indexes(), get_primary_keys(), get_foreign_keys(), get_views()) with no schema now follows the search path via current_schema() instead of assuming public, matching MySQL's DATABASE() behavior.
  • Add Runner(db, schema=...) and pwmigrate --schema for running migrations against a specific schema. The history table lives in that schema, so each schema tracks its own applied set and one set of migration files can be run against any number of schemas.
  • Add SchemaMigrator(db, schema=...), which qualifies every table name w/the given schema (or database on MySQL). Not supported for SQLite, as the table-rebuild rewrites DDL straight from sqlite_master.
  • Add websearch=True to TSVectorField.match() and Match() to parse the query using websearch_to_tsquery() (pg 11+). Accepts user input without raising (quoted phrases, or, and -negation).
  • Add Database.query_hooks, a list of callables invoked after every query with a QueryEvent named tuple (sql, params, duration, exception), on success and failure both. No timing overhead when the list is empty.
  • Add Database.after_commit(fn), which runs a callable after the outermost transaction commits. Hook is discarded on rollback and runs immediately if no transaction is active. Use for, e.g., writing a row PK to a task queue.
  • Add EnumField and IntEnumField to playhouse.fields, storing member.value and returning the member, rejecting unknown values on write and comparison. to_pydantic() maps any field with an enum_class attribute to the enum itself, so schemas validate membership.
  • Add Database.dispose() / PooledDatabase.dispose() for discarding and resetting local connection state, e.g. in a child process after fork().
  • Model.bind_ctx() and Database.bind_ctx() can be used as decorators, like the other peewee context-managers. Previously the decorator form raised TypeError: '_BoundModelsContext' object is not callable.
  • TimeField supports utc offsets like DateTimeField, parsing e.g. '11:12:13+02:00' to an aware datetime.time instead of returning str. Only sqlite stores the offset. The postgres/mysql drivers drop it on write.

View commits

Changelog

Sourced from peewee's changelog.

4.5.1

  • EnumField and IntEnumField validate member value types (str and int respectively) at field construction.
  • EnumField and IntEnumField default choices to (value, name) pairs derived from the enum.
  • Fix #3075, migration generation for EnumField. Generated migrations will emit the storage field type (e.g. IntegerField) rather than EnumField().

View commits

4.5.0

Backwards-incompatible:

  • MySQL and MariaDB connections no longer set sql_mode. Peewee had been setting PIPES_AS_CONCAT, but the param replaced the server's mode rather than adding to it, which silently disabled STRICT_TRANS_TABLES (etc). Going forward Peewee will not modify sql_mode by default and use CONCAT() rather than || for MySQL/MariaDB.
  • MySQL and MariaDB connection charset defaults to utf8mb4 instead of utf8, which is an alias for utf8mb3 and cannot store 4-byte characters.
  • A field's sequence= is now qualified with the model's Meta.schema. If the name you pass already contains a dot it is treated as fully-qualified and used as-is, so sequence='other.seq' is unaffected by Meta.schema. Also, sequence_exists() accepts a schema-qualified name.
  • SQLite BEGIN, COMMIT and ROLLBACK are issued directly on a cursor rather than through execute_sql(), so they are no longer debug-logged, do not fire query hooks and are not counted by count_queries(). This matches Postgres and MySQL.
  • atomic() and transaction() on a closed database with autoconnect=False now raise InterfaceError on Postgres and MySQL, as they already did on SQLite (and as queries do). Previously begin() opened a connection regardless of autoconnect.

Improvements:

  • Add SqliteDatabase(..., lock_type=...) to set the default locking strategy for transactions that do not specify one, e.g. lock_type='IMMEDIATE'.
  • Postgres introspection (get_tables(), get_columns(), get_indexes(), get_primary_keys(), get_foreign_keys(), get_views()) with no schema now follows the search path via current_schema() instead of assuming public, matching MySQL's DATABASE() behavior.
  • Add Runner(db, schema=...) and pwmigrate --schema for running migrations against a specific schema. The history table lives in that schema, so each schema tracks its own applied set and one set of migration files can be run against any number of schemas.
  • Add SchemaMigrator(db, schema=...), which qualifies every table name w/the given schema (or database on MySQL). Not supported for SQLite, as the table-rebuild rewrites DDL straight from sqlite_master.

... (truncated)

Commits

Updates pyjwt from 2.14.0 to 2.15.0

Release notes

Sourced from pyjwt's releases.

2.15.0

See the 2.15.0 changelog for complete release details.

Changelog

Sourced from pyjwt's changelog.

v2.15.0 <https://github.com/jpadilla/pyjwt/compare/2.14.0...2.15.0>__

Security


- Wrap recursion errors from deeply nested JWT payloads in ``DecodeError``
  instead of exposing a raw ``RecursionError``.

Added


- Support Python 3.15 by @kytta in `[#1202](https://github.com/jpadilla/pyjwt/issues/1202) &lt;https://github.com/jpadilla/pyjwt/pull/1202&gt;`__

Changed

  • JWKSetCache now stores the parsed PyJWKSet rather than the raw JWKS payload, so a cache hit no longer re-parses every key. JWKSetCache.put() accepts either form and raises PyJWKSetError for anything else. As a result, PyJWKClient.get_jwk_set() returns the same PyJWKSet instance for as long as it stays cached, rather than a freshly built one per call in [#1208](https://github.com/jpadilla/pyjwt/issues/1208) &lt;https://github.com/jpadilla/pyjwt/pull/1208&gt;__
  • PyJWKClient.fetch_data() now raises PyJWKClientError(&quot;The JWKS endpoint did not return a JSON object&quot;) when the endpoint response is not a JSON object, instead of returning it for get_jwk_set() to reject. Callers reaching the JWKS through get_jwk_set() see the same error as before in [#1208](https://github.com/jpadilla/pyjwt/issues/1208) &lt;https://github.com/jpadilla/pyjwt/pull/1208&gt;__

Fixed


- Return cached ``PyJWKSet`` values from ``PyJWKClient.get_jwk_set()`` instead
  of raising ``PyJWKClientError(&quot;The JWKS endpoint did not return a JSON
  object&quot;)``. ``JWKSetCache.put()`` documents ``PyJWKSet`` as the cached value,
  so callers pre-populating the cache to avoid a network round-trip could not
  read it back in `[#914](https://github.com/jpadilla/pyjwt/issues/914) &lt;https://github.com/jpadilla/pyjwt/issues/914&gt;`__ and
  `[#1208](https://github.com/jpadilla/pyjwt/issues/1208) &lt;https://github.com/jpadilla/pyjwt/pull/1208&gt;`__
- ``PyJWKClient.get_jwk_set()`` now caches the key set it returns, so a
  ``fetch_data()`` override that filters or transforms the JWKS is no longer
  undone by the next cache hit in
  `[#1208](https://github.com/jpadilla/pyjwt/issues/1208) &lt;https://github.com/jpadilla/pyjwt/pull/1208&gt;`__
- Raise the documented ``PyJWTError`` subclass instead of leaking a
  ``TypeError`` when the ``exp``, ``nbf``, or ``iat`` claim decodes to a
  non-numeric, non-string value such as a list, dict, or ``null``.
- Reject OKP JWK private keys when their public ``x`` component does not
  match the private ``d`` component.
- Treat malformed JWK Set members as unusable keys rather than letting
  ``AttributeError`` or ``TypeError`` escape ``PyJWKSet``. A member that is not
&lt;/tr&gt;&lt;/table&gt; 
</code></pre>
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>

<ul>
<li><a href="https://github.com/jpadilla/pyjwt/commit/1d41a6478e1562e68ff667fcd703356acf085f68&quot;&gt;&lt;code&gt;1d41a64&lt;/code&gt;&lt;/a> chore: prepare 2.15.0 release</li>
<li><a href="https://github.com/jpadilla/pyjwt/commit/9bc06658f875b9b40091539140bbbdc4639161c3&quot;&gt;&lt;code&gt;9bc0665&lt;/code&gt;&lt;/a> fix: make recursive payload tests deterministic</li>
<li><a href="https://github.com/jpadilla/pyjwt/commit/5fde08a6cf906aa7698de2d6391d88b73006b17b&quot;&gt;&lt;code&gt;5fde08a&lt;/code&gt;&lt;/a> fix: normalize recursive JWT payload errors</li>
<li><a href="https://github.com/jpadilla/pyjwt/commit/171062d2d734315272a901100aa4b109f2fc3c19&quot;&gt;&lt;code&gt;171062d&lt;/code&gt;&lt;/a> utils: mention bytes in force_bytes type error (<a href="https://redirect.github.com/jpadilla/pyjwt/issues/1173&quot;&gt;#1173&lt;/a&gt;)&lt;/li>
<li><a href="https://github.com/jpadilla/pyjwt/commit/c9d4d5375bf464ef363506fed9eb6e7f33217ab6&quot;&gt;&lt;code&gt;c9d4d53&lt;/code&gt;&lt;/a> docs/conf: drop duplicate 'and' from read() docstring (<a href="https://redirect.github.com/jpadilla/pyjwt/issues/1174&quot;&gt;#1174&lt;/a&gt;)&lt;/li>
<li><a href="https://github.com/jpadilla/pyjwt/commit/2763752196113e1473b0ed7905aa6034aedfbe53&quot;&gt;&lt;code&gt;2763752&lt;/code&gt;&lt;/a> Add support for Python 3.15 (<a href="https://redirect.github.com/jpadilla/pyjwt/issues/1202&quot;&gt;#1202&lt;/a&gt;)&lt;/li>
<li><a href="https://github.com/jpadilla/pyjwt/commit/4adcd02722f5011c60079d3978dfc167b9a8eaa5&quot;&gt;&lt;code&gt;4adcd02&lt;/code&gt;&lt;/a> Catch http.client.HTTPException in PyJWKClient.fetch_data (<a href="https://redirect.github.com/jpadilla/pyjwt/issues/1201&quot;&gt;#1201&lt;/a&gt;)&lt;/li>
<li><a href="https://github.com/jpadilla/pyjwt/commit/9e501d993b4d3e7dba14bdb1722b1d993ac75097&quot;&gt;&lt;code&gt;9e501d9&lt;/code&gt;&lt;/a> fix: correct docstring typo in _validate_jti (<a href="https://redirect.github.com/jpadilla/pyjwt/issues/1179&quot;&gt;#1179&lt;/a&gt;)&lt;/li>
<li><a href="https://github.com/jpadilla/pyjwt/commit/4047c44d51950ffda15f40054508d3f17c43b1e2&quot;&gt;&lt;code&gt;4047c44&lt;/code&gt;&lt;/a> docs: clarify JWK certificate member handling (<a href="https://redirect.github.com/jpadilla/pyjwt/issues/1212&quot;&gt;#1212&lt;/a&gt;)&lt;/li>
<li><a href="https://github.com/jpadilla/pyjwt/commit/f4e2b59f543cc82d46d9d69922bba59e804216b9&quot;&gt;&lt;code&gt;f4e2b59&lt;/code&gt;&lt;/a> [pre-commit.ci] pre-commit autoupdate (<a href="https://redirect.github.com/jpadilla/pyjwt/issues/1210&quot;&gt;#1210&lt;/a&gt;)&lt;/li>
<li>Additional commits viewable in <a href="https://github.com/jpadilla/pyjwt/compare/2.14.0...2.15.0&quot;&gt;compare view</a></li>
</ul>
</details>

<br />

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update Python code labels Sep 28, 2026
@codecov

codecov Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 74.24%. Comparing base (53ced4d) to head (f8cb958).

Additional details and impacted files
@@           Coverage Diff           @@
##           master    #2915   +/-   ##
=======================================
  Coverage   74.24%   74.24%           
=======================================
  Files         332      332           
  Lines       25459    25459           
  Branches     2536     2537    +1     
=======================================
  Hits        18902    18902           
  Misses       6507     6507           
  Partials       50       50           
Flag Coverage Δ
frontend 66.80% <ø> (ø)
sharedComponents 44.29% <ø> (ø)
sharedFront 91.72% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

… with 3 updates

Bumps the back-prod-minor-update group with 3 updates in the /back directory: [sentry-sdk](https://github.com/getsentry/sentry-python), [peewee](https://github.com/coleifer/peewee) and [pyjwt](https://github.com/jpadilla/pyjwt).


Updates `sentry-sdk` from 2.69.2 to 2.70.0
- [Release notes](https://github.com/getsentry/sentry-python/releases)
- [Changelog](https://github.com/getsentry/sentry-python/blob/master/CHANGELOG.md)
- [Commits](getsentry/sentry-python@2.69.2...2.70.0)

Updates `peewee` from 4.4.0 to 4.5.1
- [Release notes](https://github.com/coleifer/peewee/releases)
- [Changelog](https://github.com/coleifer/peewee/blob/master/CHANGELOG.md)
- [Commits](coleifer/peewee@4.4.0...4.5.1)

Updates `pyjwt` from 2.14.0 to 2.15.0
- [Release notes](https://github.com/jpadilla/pyjwt/releases)
- [Changelog](https://github.com/jpadilla/pyjwt/blob/master/CHANGELOG.rst)
- [Commits](jpadilla/pyjwt@2.14.0...2.15.0)

---
updated-dependencies:
- dependency-name: peewee
  dependency-version: 4.5.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: back-prod-minor-update
- dependency-name: pyjwt
  dependency-version: 2.15.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: back-prod-minor-update
- dependency-name: sentry-sdk
  dependency-version: 2.70.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: back-prod-minor-update
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title build(deps): bump the back-prod-minor-update group in /back with 3 updates build(deps): bump the back-prod-minor-update group across 1 directory with 3 updates Sep 30, 2026
@dependabot
dependabot Bot force-pushed the dependabot/pip/back/back-prod-minor-update-c218aa36f5 branch from 2dbc262 to f8cb958 Compare September 30, 2026 12:44
@pylipp

pylipp commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

@dependabot rebase

@dependabot @github

dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown
Contributor Author

Looks like these dependencies are updatable in another way, so this is no longer needed.

@dependabot dependabot Bot closed this Oct 1, 2026
@dependabot
dependabot Bot deleted the dependabot/pip/back/back-prod-minor-update-c218aa36f5 branch October 1, 2026 10:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update Python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant