Skip to content

chore(deps): bump the all group across 1 directory with 15 updates - #168

Merged
maxrjones merged 3 commits into
mainfrom
dependabot/uv/all-2019ea6444
Oct 6, 2026
Merged

maxrjones merged 3 commits into
mainfrom
dependabot/uv/all-2019ea6444

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown
Contributor

Bumps the all group with 15 updates in the / directory:

Package From To
aiobotocore 3.9.0 3.9.1
fsspec 2026.7.0 2026.9.0
icechunk 2.1.2 2.2.2
numpy 2.5.2 2.5.3
pydantic 2.13.4 2.13.5
s3fs 2026.7.0 2026.9.0
zarr 3.3.0 3.4.0
uvicorn 0.52.4 0.53.0
mangum 0.21.0 0.22.0
dask 2026.7.1 2026.8.0
httpx2 2.12.0 2.13.1
ipython 9.16.1 9.17.1
ruff 0.16.4 0.16.8
aws-cdk-lib 2.266.0 2.270.0
matplotlib 3.11.1 3.11.2

Updates aiobotocore from 3.9.0 to 3.9.1

Release notes

Sourced from aiobotocore's releases.

3.9.1

  • bump botocore dependency specification to support "botocore >= 1.43.66, < 1.43.76" (#1693, #1709)
  • seed the amz-sdk-request header's max token on the initial request attempt (previously only appeared once a retry occurred) and honour a per-request read_timeout override when computing retry timing, matching botocore 1.43.66 and 1.43.72 (#1709)
  • fix login credential refreshes calling botocore's sync-only create_o_auth2_token compatibility alias, which aiobotocore cannot resolve asynchronously, by calling the generated create_oauth2_token method directly (closes #1697) (#1704)
  • fix a concurrency-safety issue in HTTPSession session management (closes #1695) (#1696)
Changelog

Sourced from aiobotocore's changelog.

3.9.1 (2026-08-20) ^^^^^^^^^^^^^^^^^^^

  • bump botocore dependency specification to support "botocore >= 1.43.66, < 1.43.76" (#1693, #1709)
  • seed the amz-sdk-request header's max token on the initial request attempt (previously only appeared once a retry occurred) and honour a per-request read_timeout override when computing retry timing, matching botocore 1.43.66 and 1.43.72 (#1709)
  • fix login credential refreshes calling botocore's sync-only create_o_auth2_token compatibility alias, which aiobotocore cannot resolve asynchronously, by calling the generated create_oauth2_token method directly (closes #1697) (#1704)
  • fix a concurrency-safety issue in HTTPSession session management (closes #1695) (#1696)
Commits
  • c92e345 Release v3.9.1 (#1710)
  • 212c18f build(deps-dev): bump time-machine from 3.3.1 to 3.4.0 (#1718)
  • ba76b51 build(deps): bump astral-sh/setup-uv from 9.0.0 to 10.0.1 (#1713)
  • 1975e82 feat: support botocore 1.43.75 — seed max attempts and honour per-request rea...
  • e7bc502 build(deps): bump httpx2 from 2.7.0 to 2.9.1 (#1701)
  • 6bb1bc1 build(deps-dev): bump anthropic from 0.119.0 to 0.120.2 (#1702)
  • 9409dc5 build(deps): bump anthropics/claude-code-action from 1.0.182 to 1.0.187 (#1706)
  • bf5b5b2 build(deps-dev): bump time-machine from 3.2.0 to 3.3.1 (#1708)
  • 267a823 build(deps-dev): bump packaging from 26.2 to 26.3 (#1707)
  • d8e57fa fix: use generated SignIn OAuth method for login refresh (#1704)
  • Additional commits viewable in compare view

Updates fsspec from 2026.7.0 to 2026.9.0

Commits
  • 0f76baa changelog (#2166)
  • 695f831 Add age-based cleanup for simplecache (#2118)
  • 42aa468 Mirror readinto from the pyarrow stream onto ArrowFile (#2111)
  • 4a4e6ae Make the SFTP host key policy configurable (#2126)
  • a0ce6db Normalize paths in AsyncFileSystemWrapper like the wrapped filesystem (#2159)
  • c5fea6d Fix cat_ranges on whole-file caches after #2154 (#2163)
  • 9efb18b Patch HAS_CPYTHON_API where _fast_slice reads it (#2164)
  • 27bcd35 feat(AdaptiveReadaheadCache): introducing a new cache-type adaptive (#2093)
  • a681aca Ignore a leading slash in TarFileSystem paths (#2148)
  • 57c55f8 Make names relative in DirFileSystem.walk(detail=True) (#2160)
  • Additional commits viewable in compare view

Updates icechunk from 2.1.2 to 2.2.2

Changelog

Sourced from icechunk's changelog.

Python Icechunk Library 2.2.2

Fixes

  • Fix a garbage collection deadlock on machines with few CPUs (#2389).

Python Icechunk Library 2.2.1

Features

  • icechunk-js can read HTTP(S) virtual chunks in the browser via Repository.setHttpVirtualChunkFetcher() and createHttpVirtualChunkFetcher() (#2363).

Fixes

  • Update tests to deal with Tigris and other stores listing whole-second timestamps (#2368).
  • reset_branch conflict errors report the actual branch tip instead of the expected parent twice (#2360).
  • Repositories with more than one million snapshots are readable again (#2388).
  • Metadata files that could not be read back are no longer written: large files are validated before upload (#2388).

Performance

  • Speed up manifest metadata lookups during commits, reads, and manifest preloading in repositories with many manifests by using binary search instead of linear scans (#2381).
  • Garbage collection lists 32 ways in parallel on S3 and GCS, one listing per possible first character of an object id. Listing a 2.8 million object repository drops from 299 s to 15 s. Azure and local storage keep a single listing (#2371, #2385).
  • Garbage collection fetches each snapshot once, concurrently, and lists the snapshots prefix once (#2358).
  • Branch and tag lookups no longer deserialize every snapshot's metadata (#2377).
  • upgrade_icechunk_repository walks the v1 ancestry from prefetched snapshot infos. A 285,824 snapshot migration drops from 451 s to 209 s (#2383).
  • Repo info accessors no longer re-validate the whole file on every call (#2388).

Python Icechunk Library 2.2.0

Features

  • The inspect_* methods now report a header for the file they read: the library version that wrote it, and that file's spec version, file type and compression (#2347).
  • Add hf_storage, a preset for Hugging Face Storage Buckets. It takes the bucket's namespace. It sets the gateway endpoint, the region and path-style URLs. The gateway discards user metadata, so Icechunk cannot recover from a lost response to a conditional write (#2346).
  • Add branch (list, create, delete), tag (list, create, delete) and ancestry subcommands to the icechunk command line interface (#2299).

Fixes

  • Fix garbage collection deleting still-referenced transaction logs when the host and object-store clocks are skewed (#2310).
  • Deleting a chunk key that cannot exist (coordinates outside the chunk grid, missing node, or a group path) is now a no-op instead of raising, matching zarr-python's stores. Writing a chunk outside the grid is still rejected (#2312).
  • to_icechunk no longer passes synchronizer and zarr_version to xarray's ZarrStore.open_group; xarray removed both parameters and passing them made to_icechunk fail with a TypeError on xarray development versions (#2312).
  • Writing a chunk with length 0 is now rejected instead of being committed. A chunk must decode to the full chunk shape, so no valid chunk is ever zero bytes long, and such a chunk could only fail once it was read back — long after the commit that introduced it. This is how a sparse GeoTIFF's unstored tiles (offset = 0, byteCount = 0) used to reach a repository. Applies to inline, virtual and materialized chunks alike, which means Icechunk deliberately rejects an empty write at a chunk key where a plain key-value store would accept it, in the same way it already rejects invalid zarr keys and invalid metadata. To record that a chunk is not stored at all, delete it rather than writing a zero-length one; it then reads back as the array's fill value (#2328).
  • Object metadata keys no longer contain _: they are now icspecver, icclient, icfiletype, iccompalg and icechunkwriteid. S3 gateways fronted by nginx dropped the old names, which failed writes with AccessDenied: There were headers present in the request which were not signed. The old names stay available as *_DEPRECATED constants (#2354).
  • S3 endpoints whose URL includes a path no longer fail with NoSuchBucket. Hugging Face Storage Buckets use such a URL: https://s3.hf.co/<namespace>. The AWS SDK joins the endpoint path and the bucket name without a separator. Requests therefore addressed /<namespace><bucket>/<key>. Icechunk now appends the missing /. Endpoints without a path, such as Tigris, R2 and MinIO, keep the same behavior (#2346).

Performance

  • Writing to a store no longer copies the NumPy buffer: set and set_if_not_exists pass the buffer through instead of converting it to bytes. PyStore.set and PyStore.set_if_not_exists now accept BytesLike (#2332).
Commits
  • 342b3a2 prepare v2.2.2 release (#2390)
  • 3b84553 Fix GC deadlock on hosts with few CPUs (#2389)
  • 5f4bb36 Tests: draw delete_chunk keys from the storage grid in the compat test (#2387)
  • 659ccf0 Verify metadata files before writing them (#2388)
  • e1b29f1 Prepare for 2.2.1 (#2386)
  • 5e97d2e Add browser HTTP virtual-chunk support to icechunk-js (#2363)
  • 50b1c90 GC: split object-id listings on GCS too (#2385)
  • d553418 GC: list object-id prefixes concurrently on S3 (#2371)
  • 72dd20e Tests: Check ancestry file completeness in the VersionControlTest model (#2...
  • e4be5cb Migration: walk v1 ancestry from prefetched SnapshotInfo, not the LRU cache (...
  • Additional commits viewable in compare view

Updates numpy from 2.5.2 to 2.5.3

Release notes

Sourced from numpy's releases.

v2.5.3 (Sep 6, 2026)

NumPy 2.5.3 Release Notes

The NumPy 2.5.3 is a patch release that fixes bugs discovered after the 2.5.2 release. Apart from the usual bug and maintenance work, there are a number of StringDType related fixes for problems discovered during the ongoing string work in the main branch.

This release supports Python versions 3.12-3.15

Changes

  • Casting a fixed-width byte string array (np.bytes_) to StringDType now raises TypeError when the bytes are not valid UTF-8. Previously the invalid bytes were stored as-is and later caused undefined behavior in string operations.

    (gh-32296)

  • MaskedArray._fill_value would become stale when ufuncs that change dtype left the result holding a fill_value typed for the old dtype. The mismatch was silent until something later called _check_fill_value, such as .view(), and then a TypeError would be raised. Now, when the copied fill_value is no longer valid for the new dtype, fall back to the default fill_value for that dtype instead of propagating the stale value. This may raise a ComplexWarning if the fill_value is complex and the new dtype is real.

    (gh-32423)

Contributors

A total of 9 people contributed to this release. People with a "+" by their names contributed a patch for the first time.

  • Charles Harris
  • Iason Krommydas
  • James Davies +
  • Joren Hammudoglu
  • Maanas Arora
  • Matti Picus
  • Nathan Goldbaum
  • Shikhar Goel +
  • Yeonho Kim +

Pull requests merged

A total of 27 pull requests were merged for this release.

  • #32235: MAINT: Prepare 2.5.x for further development

... (truncated)

Commits
  • dd88c0c Merge pull request #32511 from charris/prepare-2.5.3
  • edcac6a REL: Prepare for the NumPy 2.5.3 release
  • fd4d908 Merge pull request #32509 from charris/backport-32496
  • 65bb1da BUG: fix crash in ufunc.resolve_dtypes with a Python scalar type (#32496)
  • 294956e Merge pull request #32506 from charris/backport-32503
  • 26428d9 DOC: fix scipy docs links in intersphinx mapping (#32507)
  • 5fab1cb DOC: use static scipy doc site for intershpinx (#32503)
  • 7beed2f Merge pull request #32481 from ngoldbaum/stringdtype-backport
  • 8972f70 Merge pull request #32478 from charris/backport-32466
  • ab1b589 Merge pull request #32477 from charris/backport-32423
  • Additional commits viewable in compare view

Updates pydantic from 2.13.4 to 2.13.5

Release notes

Sourced from pydantic's releases.

v2.13.5 (2026-08-28)

What's Changed

Fixes

  • Allow reuse of validators when plugins are set by @​Viicos in #13535
  • Fix missing GC traversal on some pydantic-core struct fields by @​Viicos in #13624
  • Fix missing GC traversal in pydantic-core for GeneralFieldsSerializer by @​Viicos in #13629
  • Count validated model fields once in smart unions by @​tamird in #13731
Changelog

Sourced from pydantic's changelog.

v2.13.5 (2026-08-28)

GitHub release

What's Changed

Fixes

  • Allow reuse of validators when plugins are set by @​Viicos in #13535
  • Fix missing GC traversal on some pydantic-core struct fields by @​Viicos in #13624
  • Fix missing GC traversal in pydantic-core for GeneralFieldsSerializer by @​Viicos in #13629
  • Count validated model fields once in smart unions by @​tamird in #13731
Commits
  • 001dea0 Bump pypa/gh-action-pypi-publish action to v1.14.2
  • 558379f Bump twine to v7.0.0
  • 2cfd5d3 Do not check for docs build
  • a735bee Fix more Clippy lints
  • 7eed4a1 Fix Clippy 0.1.95 warnings
  • b353bbb Prepare release v2.13.5
  • 63d2ccc Count validated model fields once in smart unions
  • a53ec2e Speed up PyPy CI tests
  • d65e0f9 Workaround circular import error in Mypy
  • 47a6dbf Fix missing GC traversal in pydantic-core for GeneralFieldsSerializer
  • Additional commits viewable in compare view

Updates s3fs from 2026.7.0 to 2026.9.0

Commits
  • 62f45e6 changelog (#1044)
  • 85a6ec5 Retry transient errors on each listing page (#1042)
  • 359cf57 Preserve coroutine errors without a response local (#1041)
  • 6d5b34b version-guard and strict the big exclusive-write xfails, stale since moto 5.1...
  • d3dd9b7 Fix requester pays propogation and bug with combining head_bucket and `req...
  • See full diff in compare view

Updates zarr from 3.3.0 to 3.4.0

Release notes

Sourced from zarr's releases.

v3.4.0

zarr 3.4.0. Highlights are in the release blog post; the full per-change list is in the release notes. This release adds a required dependency on msgspec>=0.19.

What's Changed

... (truncated)

Changelog

Sourced from zarr's changelog.

3.4.0 (2026-09-15)

Features

  • JSON metadata validation now delegates to msgspec.convert for the type coercions it supports (Literal membership, int / bool strictness, list-to-tuple), replacing the per-field hand-written parse_* logic. User-defined attributes retain their existing JSON handling. A latent generator-exhaustion bug in parse_storage_transformers is also fixed. See #3285.

    As a result some metadata inputs are now parsed more strictly. The previous per-field checks compared values with ==, which accepts any numerically equal object, so a float such as 2.0 was accepted as zarr_format; it is now rejected because it is not an int. Booleans are likewise no longer accepted where an int is expected, since bool is an int subclass. Metadata that conforms to the Zarr specification is unaffected. (#4063)

  • zarr.registry.get_codec_class now raises zarr.errors.UnknownCodecError instead of KeyError when no implementation is registered for a codec, and zarr.core.config.BadConfigError instead of KeyError when the implementation named in config["codecs"][name] is not registered. zarr.registry.get_numcodec raises UnknownCodecError instead of the ValueError numcodecs raises for an unregistered Zarr format 2 codec id (numcodecs.errors.UnknownCodecError on numcodecs 0.15.1 and later). All of these are subclasses of ValueError, so except ValueError is unaffected, but except KeyError and except numcodecs.errors.UnknownCodecError are.

    These errors now name Python packages known to provide the codec, so that a user who cannot read an array learns what to install:

    An implementation for codec 'wavpack' is not available. Register one explicitly using the codec
    registry (see ...), or install a Python package that registers a codec implementation with
    numcodecs. Known packages supporting this codec: wavpack-numcodecs.
    

    The tables covering this live in src/zarr/registry.py, one per Zarr format, and include the codecs numcodecs gates behind its own optional dependencies (zfpy, pcodec, crc32c, msgpack2). Codec authors can add their published package to them.

    A codec whose from_dict raises KeyError on a malformed configuration now surfaces as zarr.errors.MetadataValidationError naming the codec and the missing key. Previously it was reported as UnknownCodecError: Unknown codec: '<configuration key>', presenting a configuration key as though it were a codec name, and on the zarr.open path a bare KeyError could be swallowed by the array-then-group fallback and reported as an unrelated group error.

    zarr.errors.UnknownCodecError is now exported from zarr.errors. (#4277)

  • zarr.create_array, Group.create_array, zarr.from_array, and the entry points built on them now accept a numpy array as the chunks or shards specification, alongside ints, tuples, and numpy integer scalars. This is new for that API: it has never accepted numpy arrays in any 3.x release, because each entry point compared the specification to the "auto" or "keep" sentinel string before normalizing it, and for a numpy array that comparison raised numpy's ambiguous-truth-value ValueError. Those sentinel checks are now guarded so array-like specifications reach the normalizer, bringing this API in line with the legacy zarr.create / zarr.array / zarr.open_array functions, which have accepted numpy arrays since 2.x. (#4329)

Bugfixes

... (truncated)

Commits
  • 292aeb4 docs: 3.4.0 release notes (#4360)
  • 4484a60 docs(blog): zarr 3.4.0 release post (#4355)
  • 4c61dcf refactor(store): polish the LocalStore rename retry from #4358 (#4359)
  • 6947dd8 fix(store): retry the LocalStore rename when the destination is busy (#4358)
  • 0de6077 fix(indexing): delegate source tokenization to Dask (#4348)
  • 34dd17c fix(indexing): validate index-array bounds during JSON loading (#4347)
  • 1f13742 test(indexing): broaden planner property coverage (#4346)
  • 8ff7cb1 fix(indexing): audit factual contracts and close validation gaps (#4345)
  • 5d60db6 fix: complete imagecodecs codec package hints (#4351)
  • ba883a5 fix(zarr-indexing): reject overflowing integer selectors (#4333)
  • Additional commits viewable in compare view

Updates uvicorn from 0.52.4 to 0.53.0

Release notes

Sourced from uvicorn's releases.

Version 0.53.0

🌐 Opt-in HTTP/2 support

uvicorn 0.53.0 adds experimental HTTP/2 through zttp, alongside a new zuvloop integration and connection-handling improvements.

uv add uvicorn==0.53.0
  • Serve HTTP/1.1 and HTTP/2 with zttp (#2982, #3101). Install zttp, then enable HTTP/2 with --http zttp --http2. Uvicorn negotiates HTTP/2 over TLS with ALPN and supports cleartext prior knowledge.
  • HTTP/2 remains experimental. Upgrade-based h2c and WebSockets over HTTP/2 are not supported.

⚙️ More event loop choice

  • Run Uvicorn with zuvloop (#3104). Install zuvloop separately and select it explicitly with --loop zuvloop on CPython 3.14 or newer.

🛡️ More reliable connections and proxies

  • Honor Connection: close token lists (#3103). Uvicorn now parses comma-separated tokens case-insensitively across HTTP implementations.
  • Trust IPv6 loopback proxies by default (#3119). The default FORWARDED_ALLOW_IPS value now includes ::1.
  • Keep upgraded WebSockets alive (#3107). Uvicorn cancels the HTTP keep-alive timer when the connection becomes a WebSocket.

Full changelog: 0.52.4...0.53.0

Changelog

Sourced from uvicorn's changelog.

0.53.0 (September 14, 2026)

This release adds experimental HTTP/2 support through zttp. Enable it with --http zttp --http2. Upgrade-based h2c and WebSockets over HTTP/2 are not supported.

Added

  • Add experimental HTTP/2 support through zttp (#2982, #3101)
  • Add support for zuvloop (#3104)

Fixed

  • Handle comma-separated, case-insensitive Connection: close tokens across HTTP implementations (#3103)
  • Trust IPv6 loopback in the default FORWARDED_ALLOW_IPS value (#3119)
  • Cancel the HTTP keep-alive timer when upgrading to WebSocket (#3107)
Commits
  • 421708f Version 0.53.0 (#3136)
  • f1a1bff Unset the keep-alive timer when upgrading to WebSocket (#3107)
  • 63971ed Document HTTP/2 support (#3130)
  • 7d1a005 Remove race from multiprocess health check test (#3128)
  • 5ac6265 Add ::1 to FORWARDED_ALLOW_IPS (#3119)
  • 098b206 Remove timing race from SIGHUP supervisor test (#3127)
  • 968f15e chore(deps): bump the github-actions group with 4 updates (#3113)
  • 7d4c08c chore(deps): bump the python-packages group across 1 directory with 11 update...
  • fe528a4 Require explicit opt-in for zttp HTTP/2 (#3101)
  • fa324a4 chore(deps-dev): bump httpx2 from 2.10.0 to 2.12.0 (#3121)
  • Additional commits viewable in compare view

Updates mangum from 0.21.0 to 0.22.0

Release notes

Sourced from mangum's releases.

0.22.0 - Python 3.15, tested against the real thing

Python 3.15, tested against the real thing

Mangum 0.22.0 moves the supported Python window forward and backs every release with end-to-end tests against a real Lambda runtime.

pip install mangum==0.22.0
  • Python 3.15 is supported. The full suite and strict type checking pass on 3.15 (#404).
  • Python 3.9 is no longer supported. The minimum is now Python 3.10 (#393).
  • Adapters are now verified against a real Lambda runtime. The test suite deploys Mangum to LocalStack and drives it through a Lambda Function URL and an API Gateway REST API with real HTTP requests - covering the HTTP v2 and REST v1 event formats plus lifespan startup, instead of relying only on hand-written mock events (#400, #401).

Full changelog: 0.21.0...0.22.0

Changelog

Sourced from mangum's changelog.

0.22.0

Commits

Updates dask from 2026.7.1 to 2026.8.0

Release notes

Sourced from dask's releases.

2026.8.0

Changes

See the Changelog for more information.

Commits
  • 9dc535d Version 2026.8.0
  • 817e5ff docs: fix duplicated-word typos in docstrings (#12516)
  • ba5045e Bump scientific-python/issue-from-pytest-log-action from 1.6.0 to 1.6.1 (#12524)
  • a543291 docs: fix broken cross-references in expr-system docs (#12494)
  • aac2ce2 Suppress Pandas4Warning in nightly CI caused by PyArrow (#12498)

Bumps the all group with 15 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [aiobotocore](https://github.com/aio-libs/aiobotocore) | `3.9.0` | `3.9.1` |
| [fsspec](https://github.com/fsspec/filesystem_spec) | `2026.7.0` | `2026.9.0` |
| [icechunk](https://github.com/earth-mover/icechunk) | `2.1.2` | `2.2.2` |
| [numpy](https://github.com/numpy/numpy) | `2.5.2` | `2.5.3` |
| [pydantic](https://github.com/pydantic/pydantic) | `2.13.4` | `2.13.5` |
| [s3fs](https://github.com/fsspec/s3fs) | `2026.7.0` | `2026.9.0` |
| [zarr](https://github.com/zarr-developers/zarr-python) | `3.3.0` | `3.4.0` |
| [uvicorn](https://github.com/Kludex/uvicorn) | `0.52.4` | `0.53.0` |
| [mangum](https://github.com/Kludex/mangum) | `0.21.0` | `0.22.0` |
| [dask](https://github.com/dask/dask) | `2026.7.1` | `2026.8.0` |
| [httpx2](https://github.com/pydantic/httpx2) | `2.12.0` | `2.13.1` |
| [ipython](https://github.com/ipython/ipython) | `9.16.1` | `9.17.1` |
| [ruff](https://github.com/astral-sh/ruff) | `0.16.4` | `0.16.8` |
| [aws-cdk-lib](https://github.com/aws/aws-cdk) | `2.266.0` | `2.270.0` |
| [matplotlib](https://github.com/matplotlib/matplotlib) | `3.11.1` | `3.11.2` |



Updates `aiobotocore` from 3.9.0 to 3.9.1
- [Release notes](https://github.com/aio-libs/aiobotocore/releases)
- [Changelog](https://github.com/aio-libs/aiobotocore/blob/main/CHANGES.rst)
- [Commits](aio-libs/aiobotocore@3.9.0...3.9.1)

Updates `fsspec` from 2026.7.0 to 2026.9.0
- [Commits](fsspec/filesystem_spec@2026.7.0...2026.9.0)

Updates `icechunk` from 2.1.2 to 2.2.2
- [Release notes](https://github.com/earth-mover/icechunk/releases)
- [Changelog](https://github.com/earth-mover/icechunk/blob/main/Changelog.python.md)
- [Commits](earth-mover/icechunk@v2.1.2...v2.2.2)

Updates `numpy` from 2.5.2 to 2.5.3
- [Release notes](https://github.com/numpy/numpy/releases)
- [Changelog](https://github.com/numpy/numpy/blob/main/doc/RELEASE_WALKTHROUGH.rst)
- [Commits](numpy/numpy@v2.5.2...v2.5.3)

Updates `pydantic` from 2.13.4 to 2.13.5
- [Release notes](https://github.com/pydantic/pydantic/releases)
- [Changelog](https://github.com/pydantic/pydantic/blob/v2.13.5/HISTORY.md)
- [Commits](pydantic/pydantic@v2.13.4...v2.13.5)

Updates `s3fs` from 2026.7.0 to 2026.9.0
- [Changelog](https://github.com/fsspec/s3fs/blob/main/release-procedure.md)
- [Commits](fsspec/s3fs@2026.7.0...2026.9.0)

Updates `zarr` from 3.3.0 to 3.4.0
- [Release notes](https://github.com/zarr-developers/zarr-python/releases)
- [Changelog](https://github.com/zarr-developers/zarr-python/blob/main/docs/release-notes.md)
- [Commits](zarr-developers/zarr-python@v3.3.0...v3.4.0)

Updates `uvicorn` from 0.52.4 to 0.53.0
- [Release notes](https://github.com/Kludex/uvicorn/releases)
- [Changelog](https://github.com/Kludex/uvicorn/blob/main/docs/release-notes.md)
- [Commits](Kludex/uvicorn@0.52.4...0.53.0)

Updates `mangum` from 0.21.0 to 0.22.0
- [Release notes](https://github.com/Kludex/mangum/releases)
- [Changelog](https://github.com/Kludex/mangum/blob/main/CHANGELOG.md)
- [Commits](Kludex/mangum@0.21.0...0.22.0)

Updates `dask` from 2026.7.1 to 2026.8.0
- [Release notes](https://github.com/dask/dask/releases)
- [Changelog](https://github.com/dask/dask/blob/main/docs/release-procedure.md)
- [Commits](dask/dask@2026.7.1...2026.8.0)

Updates `httpx2` from 2.12.0 to 2.13.1
- [Release notes](https://github.com/pydantic/httpx2/releases)
- [Changelog](https://github.com/pydantic/httpx2/blob/main/src/httpx2/CHANGELOG.md)
- [Commits](pydantic/httpx2@v2.12.0...v2.13.1)

Updates `ipython` from 9.16.1 to 9.17.1
- [Release notes](https://github.com/ipython/ipython/releases)
- [Commits](ipython/ipython@9.16.1...9.17.1)

Updates `ruff` from 0.16.4 to 0.16.8
- [Release notes](https://github.com/astral-sh/ruff/releases)
- [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md)
- [Commits](astral-sh/ruff@0.16.4...0.16.8)

Updates `aws-cdk-lib` from 2.266.0 to 2.270.0
- [Release notes](https://github.com/aws/aws-cdk/releases)
- [Changelog](https://github.com/aws/aws-cdk/blob/main/CHANGELOG.v2.alpha.md)
- [Commits](aws/aws-cdk@v2.266.0...v2.270.0)

Updates `matplotlib` from 3.11.1 to 3.11.2
- [Release notes](https://github.com/matplotlib/matplotlib/releases)
- [Commits](matplotlib/matplotlib@v3.11.1...v3.11.2)

---
updated-dependencies:
- dependency-name: aiobotocore
  dependency-version: 3.9.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all
- dependency-name: fsspec
  dependency-version: 2026.9.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all
- dependency-name: icechunk
  dependency-version: 2.2.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all
- dependency-name: numpy
  dependency-version: 2.5.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all
- dependency-name: pydantic
  dependency-version: 2.13.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all
- dependency-name: s3fs
  dependency-version: 2026.9.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all
- dependency-name: zarr
  dependency-version: 3.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all
- dependency-name: uvicorn
  dependency-version: 0.53.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: all
- dependency-name: mangum
  dependency-version: 0.22.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all
- dependency-name: dask
  dependency-version: 2026.8.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: all
- dependency-name: httpx2
  dependency-version: 2.13.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: all
- dependency-name: ipython
  dependency-version: 9.17.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: all
- dependency-name: ruff
  dependency-version: 0.16.8
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: all
- dependency-name: aws-cdk-lib
  dependency-version: 2.270.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: all
- dependency-name: matplotlib
  dependency-version: 3.11.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: all
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels Oct 1, 2026
@github-actions github-actions Bot added the chore label Oct 1, 2026
@kafitzgerald

Copy link
Copy Markdown
Contributor

FWIW, this is failing because Dependabot has updated Ruff in uv, but it's still pinned to the older version in .pre-commit-config.yaml causing the sync-with-uv hook to fail.

I think we might be able to work around this in the future by adding the pre-commit ecosystem and grouping the updates. I'll go ahead and fix this manually though.

@maxrjones
maxrjones enabled auto-merge (squash) October 5, 2026 20:34
@maxrjones
maxrjones merged commit 30180bb into main Oct 6, 2026
11 of 13 checks passed
@maxrjones
maxrjones deleted the dependabot/uv/all-2019ea6444 branch October 6, 2026 14:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

chore dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants