Update Python dependencies (non-major) - #12929
Open
renovate[bot] wants to merge 1 commit into
Open
Conversation
renovate
Bot
force-pushed
the
renovate/python-non-major
branch
from
June 15, 2026 21:12
a837f0d to
e7b3bdc
Compare
renovate
Bot
force-pushed
the
renovate/python-non-major
branch
from
June 16, 2026 22:19
e7b3bdc to
d4aa84c
Compare
4 tasks
renovate
Bot
force-pushed
the
renovate/python-non-major
branch
2 times, most recently
from
June 18, 2026 18:29
4486df4 to
dac9204
Compare
renovate
Bot
force-pushed
the
renovate/python-non-major
branch
2 times, most recently
from
June 21, 2026 13:44
c908250 to
6ec7f18
Compare
renovate
Bot
force-pushed
the
renovate/python-non-major
branch
3 times, most recently
from
June 23, 2026 04:48
0fdae43 to
f06c4d9
Compare
4 tasks
renovate
Bot
force-pushed
the
renovate/python-non-major
branch
3 times, most recently
from
June 25, 2026 16:59
1d3085b to
e1b559c
Compare
renovate
Bot
force-pushed
the
renovate/python-non-major
branch
4 times, most recently
from
June 27, 2026 01:09
7c21cdd to
76a115d
Compare
renovate
Bot
force-pushed
the
renovate/python-non-major
branch
5 times, most recently
from
June 30, 2026 19:12
2922224 to
4bac1ee
Compare
renovate
Bot
force-pushed
the
renovate/python-non-major
branch
5 times, most recently
from
July 9, 2026 16:30
35c47d5 to
9a2622b
Compare
renovate
Bot
force-pushed
the
renovate/python-non-major
branch
6 times, most recently
from
July 16, 2026 15:03
b366d8b to
936fc1d
Compare
renovate
Bot
force-pushed
the
renovate/python-non-major
branch
2 times, most recently
from
July 16, 2026 20:34
fd81907 to
2fa210c
Compare
renovate
Bot
force-pushed
the
renovate/python-non-major
branch
5 times, most recently
from
July 20, 2026 22:33
9a22460 to
b4f98b4
Compare
renovate
Bot
force-pushed
the
renovate/python-non-major
branch
6 times, most recently
from
July 27, 2026 19:42
f1de02b to
23cde32
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
==3.11.2→==3.11.3==4.14.3→==4.15.0==0.136.3→==0.141.1==0.115.0→==0.141.1==6.0.12→==6.0.14==0.27.2→==0.28.1==3.5.0→==3.5.1==5.9.0→==5.11.1==0.11.0→==0.14.0==6.1.1→==6.1.2==2.1.0→==2.3.1==1.1.3→==1.4.0==2.13.4→==2.13.5==2.9.1→==2.15.0==5.3.1→==5.4.0==9.0.3→==9.1.1==0.16.1→==0.16.5==2.61.1→==2.68.1==0.49.0→==0.52.4==0.30.6→==0.52.4Release Notes
agronholm/apscheduler (APScheduler)
v3.11.3Compare Source
ZoneInfotime zone, caused by the wakeup delay being computed from the naive wall-clock difference instead of the actual UTC difference (#1103)fastapi/fastapi (fastapi)
v0.141.1Compare Source
Fixes
app.frontend(). PR #16105 by @tiangolo.Docs
FASTAPI_ENVin FastAPI CLI guide. PR #16104 by @tiangolo.v0.141.0Compare Source
Features
app.frontend(check_dir="auto"), to make local development more convenient withfastapi dev. PR #16102 by @tiangolo.v0.140.13Compare Source
Fixes
status_codebeing ignored for SSE and JSONL streaming endpoints. PR #15937 by @SAURABHSALVE.Docs
format_sse_eventdocstring rendering of\n\nterminator. PR #15613 by @AshNicolus.v0.140.12Compare Source
Fixes
format_sse_eventto comply with SSE spec. PR #15515 by @Zawwarsami16.v0.140.11Compare Source
v0.140.10Compare Source
Fixes
Internal
v0.140.9Compare Source
Fixes
exclude_defaultsnot propagated to dict keys and values injsonable_encoder. PR #16043 by @MBGrao.Internal
v0.140.8Compare Source
Fixes
include_router(). PR #15077 by @alex-raw.v0.140.7Compare Source
Refactors
Internal
v0.140.6Compare Source
Refactors
v0.140.5Compare Source
Refactors
v0.140.4Compare Source
v0.140.3Compare Source
Refactors
v0.140.2Compare Source
Refactors
Internal
v0.140.1Compare Source
Refactors
v0.140.0Compare Source
Refactors
Docs
Internal
v0.139.2Compare Source
Fixes
v0.139.1Compare Source
Fixes
/users/john.doe. PR #16011 by @tiangolo.Docs
skip_usersnot being applied. PR #15995 by @YuriiMotov.Translations
llm-prompt.mdfor Hindi. PR #15810 by @YuriiMotov.Internal
FASTAPI_LATEST_CHANGEStoken inbump-pre-commit-hooksworkflow. PR #15984 by @YuriiMotov.v0.139.0Compare Source
Features
app.frontend(), e.g. for automatic cookie authentication for the frontend. PR #15908 by @tiangolo.Translations
Internal
allow-unsafe-pr-checkout: true. PR #15876 by @YuriiMotov.v0.138.2Compare Source
Refactors
app.frontend()return 404 for methods other thanGETorHEADwith no static file matches. PR #15863 by @tiangolo.Internal
v0.138.1Compare Source
Refactors
Internal
v0.138.0Compare Source
Features
app.frontend("/", directory="dist")androuter.frontend("/", directory="dist"). PR #15800 by @tiangolo.Docs
app.frontend()instructions to Agent Library Skill. PR #15805 by @tiangolo.Translations
Internal
release-notes.mdfor typos. PR #15796 by @YuriiMotov.gpt-5.5model intranslate.py, specify-chatto avoid warnings. PR #15792 by @YuriiMotov.v0.137.2Compare Source
Features
iter_route_contexts()for advanced use cases that used to userouter.routes(e.g. Jupyverse). PR #15785 by @tiangolo.Translations
Internal
coverage.sh. PR #15772 by @tiangolo.v0.137.1Compare Source
Fixes
v0.137.0Compare Source
Breaking Changes
APIRouterandAPIRouteinstances. PR #15745 by @tiangolo.Unblocks ✨ SO MANY THINGS ✨
Before this,
router.include_router(other_router)would take each path operation fromother_routerand "clone" it, or recreate it from scratch.This would mean that in the end there was only one top level router, part of the app.
The way it is structured here is that there are a few additional classes to handle intermediate metadata for router and route inclusion. That way the information of "router X includes Y and Y includes Z" is stored somewhere, without affecting (recreating / clonning) the final route.
Non Objectives
Dependencies for 404: previously I intended to support dependencies that would be executed even for 404, but that would conflict with the fact that a router could not find a match, but the next router did find a match. Executing dependencies in the router that did not find a match would not make sense, they could consume the request, body, etc. This original idea was discarded.
Specific Breaking Changes
Now
router.routesis no longer a plain list ofAPIRouteobjects, it can contain these intermediate objects that can contain additional routers, forming a tree.Any logic that depended on iterating on the
router.routesdirectly would be affected, that logic cannot expect to be able to extract data from a plain list of routes, as it's no longer a plain list but a tree.Additionally, any logic that iterated on
router.routesto modify them would now also see these new objects, and would not see all the routes in the app.router.routesshould be considered an internal implementation detail, only passed around to the FastAPI functions that need it.Features
subrouterinmainroutercan be done before adding routes (path operations) tosubrouter, because now the the entire object is stored instead of copying the routes.Alpha Features
This is not documented yet, so it's not officially supported yet and could change in the future.
But, as
APIRouteandAPIRouterinstances are now preserved, they could be customized.APIRouterhas two new methods,.matches()and.handle(), counterpart to the existing ones inAPIRoute. With this a router could customize how it matches and handles requests. For example, it could match only requests that include some specific header, for example for handling versions in headers.Still, for now, consider this very experimental and potentially changing and breaking in the future.
Future Features Enabled
APIRoutesubclasses (undocumented, but alraedy works as desccribed above)APIRoutersubclasses (undocumented, but already works as described above)Docs
Annotatedin inline example indocs/en/docs/tutorial/body-multiple-params.md. PR #15591 by @TheArchons.docs/en/docs/tutorial/security/oauth2-jwt.md. PR #14781 by @zadevhub.Translations
Internal
changing_dirinstead ofCLIRunner.isolated_filesystemto set working dir. PR #15616 by @YuriiMotov.httpx2test dependency to avoid deprecation warning. PR #15603 by @YuriiMotov.kurtmckee/feedparser (feedparser)
v6.0.14Compare Source
===================
v6.0.13Compare Source
===================
Python support
Changed
sgmllib3ktofeedparser-sgmllib.Fixed
encode/httpx (httpx)
v0.28.1Compare Source
verify=Falsetogether with client side certificates.v0.28.0Compare Source
Be aware that the default JSON request bodies now use a more compact representation. This is generally considered a prefered style, tho may require updates to test suites.
The 0.28 release includes a limited set of deprecations...
Deprecations:
We are working towards a simplified SSL configuration API.
For users of the standard
verify=Trueorverify=Falsecases, orverify=<ssl_context>case this should require no changes. The following cases have been deprecated...verifyargument as a string argument is now deprecated and will raise warnings.certargument is now deprecated and will raise warnings.Our revised SSL documentation covers how to implement the same behaviour with a more constrained API.
The following changes are also included:
proxiesargument has now been removed.appargument has now been removed.certifiandhttpcoreare only imported if required. (#3377)socks5has a valid proxy scheme. (#3178)Request()method signature in line withclient.request()andhttpx.request(). (#3378)params={}, always strictly update rather than merge with an existing querystring. (#3364)ICRAR/ijson (ijson)
v3.5.1Compare Source
ijson.common.ObjectBuilderno longer creates internal referencecycles, so discarded builders are freed by reference counting instead
of waiting for a cyclic garbage collection pass. This lowers peak
memory usage for code that builds and discards one large object at a
time. As a side effect,
builder.valueis nowNonebefore anyevent is processed
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.