chore(deps): bump the uv group across 1 directory with 10 updates#20
Closed
dependabot[bot] wants to merge 1 commit into
Closed
chore(deps): bump the uv group across 1 directory with 10 updates#20dependabot[bot] wants to merge 1 commit into
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps the uv group with 10 updates in the / directory: | Package | From | To | | --- | --- | --- | | [mcp](https://github.com/modelcontextprotocol/python-sdk) | `1.22.0` | `1.23.0` | | [pypdf](https://github.com/py-pdf/pypdf) | `6.0.0` | `6.8.0` | | [lxml-html-clean](https://github.com/fedora-python/lxml_html_clean) | `0.3.1` | `0.4.4` | | [simpleeval](https://github.com/danthedeckie/simpleeval) | `1.0.3` | `1.0.5` | | [authlib](https://github.com/authlib/authlib) | `1.6.6` | `1.6.7` | | [flask](https://github.com/pallets/flask) | `3.0.3` | `3.1.3` | | [langchain-text-splitters](https://github.com/langchain-ai/langchain) | `0.3.7` | `0.3.9` | | [pillow](https://github.com/python-pillow/Pillow) | `12.1.0` | `12.1.1` | | [torch](https://github.com/pytorch/pytorch) | `2.2.2` | `2.8.0` | | [unstructured](https://github.com/Unstructured-IO/unstructured) | `0.16.23` | `0.18.18` | Updates `mcp` from 1.22.0 to 1.23.0 - [Release notes](https://github.com/modelcontextprotocol/python-sdk/releases) - [Changelog](https://github.com/modelcontextprotocol/python-sdk/blob/main/RELEASE.md) - [Commits](modelcontextprotocol/python-sdk@v1.22.0...v1.23.0) Updates `pypdf` from 6.0.0 to 6.8.0 - [Release notes](https://github.com/py-pdf/pypdf/releases) - [Changelog](https://github.com/py-pdf/pypdf/blob/main/CHANGELOG.md) - [Commits](py-pdf/pypdf@6.0.0...6.8.0) Updates `lxml-html-clean` from 0.3.1 to 0.4.4 - [Changelog](https://github.com/fedora-python/lxml_html_clean/blob/main/CHANGES.rst) - [Commits](fedora-python/lxml_html_clean@0.3.1...0.4.4) Updates `simpleeval` from 1.0.3 to 1.0.5 - [Release notes](https://github.com/danthedeckie/simpleeval/releases) - [Commits](danthedeckie/simpleeval@1.0.3...1.0.5) Updates `authlib` from 1.6.6 to 1.6.7 - [Release notes](https://github.com/authlib/authlib/releases) - [Changelog](https://github.com/authlib/authlib/blob/main/docs/changelog.rst) - [Commits](authlib/authlib@v1.6.6...v1.6.7) Updates `flask` from 3.0.3 to 3.1.3 - [Release notes](https://github.com/pallets/flask/releases) - [Changelog](https://github.com/pallets/flask/blob/main/CHANGES.rst) - [Commits](pallets/flask@3.0.3...3.1.3) Updates `langchain-text-splitters` from 0.3.7 to 0.3.9 - [Release notes](https://github.com/langchain-ai/langchain/releases) - [Commits](langchain-ai/langchain@langchain-text-splitters==0.3.7...langchain-text-splitters==0.3.9) Updates `pillow` from 12.1.0 to 12.1.1 - [Release notes](https://github.com/python-pillow/Pillow/releases) - [Changelog](https://github.com/python-pillow/Pillow/blob/main/CHANGES.rst) - [Commits](python-pillow/Pillow@12.1.0...12.1.1) Updates `torch` from 2.2.2 to 2.8.0 - [Release notes](https://github.com/pytorch/pytorch/releases) - [Changelog](https://github.com/pytorch/pytorch/blob/main/RELEASE.md) - [Commits](pytorch/pytorch@v2.2.2...v2.8.0) Updates `unstructured` from 0.16.23 to 0.18.18 - [Release notes](https://github.com/Unstructured-IO/unstructured/releases) - [Changelog](https://github.com/Unstructured-IO/unstructured/blob/main/CHANGELOG.md) - [Commits](Unstructured-IO/unstructured@0.16.23...0.18.18) --- updated-dependencies: - dependency-name: mcp dependency-version: 1.23.0 dependency-type: direct:production dependency-group: uv - dependency-name: pypdf dependency-version: 6.8.0 dependency-type: direct:production dependency-group: uv - dependency-name: lxml-html-clean dependency-version: 0.4.4 dependency-type: direct:production dependency-group: uv - dependency-name: simpleeval dependency-version: 1.0.5 dependency-type: direct:production dependency-group: uv - dependency-name: authlib dependency-version: 1.6.7 dependency-type: direct:production dependency-group: uv - dependency-name: flask dependency-version: 3.1.3 dependency-type: direct:production dependency-group: uv - dependency-name: langchain-text-splitters dependency-version: 0.3.9 dependency-type: direct:production dependency-group: uv - dependency-name: pillow dependency-version: 12.1.1 dependency-type: direct:production dependency-group: uv - dependency-name: torch dependency-version: 2.8.0 dependency-type: direct:production dependency-group: uv - dependency-name: unstructured dependency-version: 0.18.18 dependency-type: direct:production dependency-group: uv ... Signed-off-by: dependabot[bot] <support@github.com>
676402b to
46eed75
Compare
Contributor
Author
|
Superseded by #42. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the uv group with 10 updates in the / directory:
1.22.01.23.06.0.06.8.00.3.10.4.41.0.31.0.51.6.61.6.73.0.33.1.30.3.70.3.912.1.012.1.12.2.22.8.00.16.230.18.18Updates
mcpfrom 1.22.0 to 1.23.0Release notes
Sourced from mcp's releases.
Commits
d3a1841Merge commit from forkfa851d9feat: backwards-compatible create_message overloads for SEP-1577 (#1713)f82b0c9Support client_credentials flow with JWT and Basic auth (#1663)281fd47Add SSE polling support (SEP-1699) (#1654)2cd178aAdd on_session_created callback option (#1710)c92bb2fSEP-1686: Tasks (#1645)5983a65Skip empty SSE data to avoid parsing errors (#1670)02b7889Implement SEP-1036: URL mode elicitation for secure out-of-band interactions ...27279bcUpdate doc string on custom_route (#1660)f225013feat: implement SEP-991 URL-based client ID (CIMD) support (#1652)Updates
pypdffrom 6.0.0 to 6.8.0Release notes
Sourced from pypdf's releases.
... (truncated)
Changelog
Sourced from pypdf's changelog.
... (truncated)
Commits
a869eceREL: 6.8.03c550b3SEC: Limit allowed/Lengthvalue of stream (#3675)5dae0e2MAINT: Document and test XMP security (#3674)b9f66abDEV: Change toloadfilestrategy for PyPy in CI (#3671)071118bMAINT: Remove excessive logging in extract_links while not clear (#3670)43add64DEV: Timeout PyPy tests after one minute4228dd2DOC: Avoid usingPageObject.replace_contentson PdfReader (#3669)0e9792dENH: Add /IRT (in-reply-to) support for markup annotations (#3631)ede6db9DOC: Document how to disable jbig2dec calls6d0fa2fMAINT: Move and rename _xobj_image_helpers.py (#3661)Updates
lxml-html-cleanfrom 0.3.1 to 0.4.4Changelog
Sourced from lxml-html-clean's changelog.
... (truncated)
Commits
fd10d79Add more tests for different combinations of backslashes and unicode5b7e228Restore the removal of all backslashes from styles after decoding of unicode ...88da8f9Prepare release 0.4.49c5612cRemove <base> tags to prevent URL hijacking attacks2ef7326Implement unicode escape decoding7c854afAdd missing Python 3.14 to classifiers80cebf7Continue using the package link1cef82eUpdate safe sanitizer recommendation79f35f4CI: Drop Python 3.8, add 3.14fab1dd4Release 0.4.3Updates
simpleevalfrom 1.0.3 to 1.0.5Release notes
Sourced from simpleeval's releases.
Commits
a4659faMerge pull request #171 from danthedeckie/remove-module-access7c9180cversion number bumpcffa9f6Much stricter lockdown via _check_disallowed_items plus adding ModuleWrapper4e7f4b8Add ByamB4 to contributors list1654cbfDisallow module access & disallowed function access via attributes.9cb4a7bAdd a few additional DISALLOW_FUNCTIONS0425898Merge pull request #169 from danthedeckie/update-readme618bcf4update build tools / config8828943bump version, and update copyright year97570felint string joining fixesUpdates
authlibfrom 1.6.6 to 1.6.7Release notes
Sourced from authlib's releases.
Changelog
Sourced from authlib's changelog.
Commits
38e872achore: release 1.6.7b87c32efix: remove "none" algorithm from default jwt instanceUpdates
flaskfrom 3.0.3 to 3.1.3Release notes
Sourced from flask's releases.
Changelog
Sourced from flask's changelog.
... (truncated)
Commits
22d9247release version 3.1.3089cb86Merge commit from forkc17f379request context tracks session access27be933start version 3.1.34e652d3Abort if the instance folder cannot be created (#5903)3d03098Abort if the instance folder cannot be created407eb76document using gevent for async (#5900)ac5664ddocument using gevent for async4f79d5bIncrease required flit_core version to 3.11 (#5865)fe3b215Increase required flit_core version to 3.11Updates
langchain-text-splittersfrom 0.3.7 to 0.3.9Commits
77c9819fix(text-splitters): update langchain-core version to 0.3.727f015b6fix(text-splitters): update lock for release71ad451Merge branch 'master' of github.com:langchain-ai/langchain2c42893fix(langchain): update langchain-core version to 0.3.720e139fbrelease(langchain): 0.3.27 (#32227)622bb05fix(langchain): class HTMLSemanticPreservingSplitter ignores the text inside ...56dde3afeat(langchain): v1 scaffolding (#32166)bd3d649release(core): 0.3.72 (#32214)fb5da83fix(core): Dereference Refs for pydantic schema fails in tool schema generati...a7d0e42docs: fix typos in documentation (#32201)Updates
pillowfrom 12.1.0 to 12.1.1Release notes
Sourced from pillow's releases.
Commits
5158d9812.1.1 version bump9000313Fix OOB Write with invalid tile extents (#9427)cd01118Patch libavif for svt-av1 4.0 compatibilityUpdates
torchfrom 2.2.2 to 2.8.0Release notes
Sourced from torch's releases.
... (truncated)
Commits
ba56102Cherrypick: Add the RunLLM widget to the website (#159592)c525a02[dynamo, docs] cherry pick torch.compile programming model docs into 2.8 (#15...a1cb3cc[Release Only] Remove nvshmem from list of preload libraries (#158925)c76b235Move out super large one off foreach_copy test (#158880)20a0e22Revert "[Dynamo] Allow inlining into AO quantization modules (#152934)" (#158...9167ac8[MPS] Switch Cholesky decomp to column wise (#158237)5534685[MPS] Reimplementtri[ul]as Metal shaders (#158867)d19e08dCherry pick PR 158746 (#158801)a6c044a[cherry-pick] Unify torch.tensor and torch.ops.aten.scalar_tensor behavior (#...620ebd0[Dynamo] Use proper sources for constructing dataclass defaults (#158689)Updates
unstructuredfrom 0.16.23 to 0.18.18Release notes
Sourced from unstructured's releases.
... (truncated)
Changelog
Sourced from unstructured's changelog.
... (truncated)
Commits
b01d35bfix: sanitize MSG attachment filenames to prevent path traversal (GHS… (#4117)1c519efSecurity Fixes - CVE Remediation (#4115)c79cf3aupdated dependancies to resolve open CVEs and cut a new version (#4108)8fd07fdfeat: Add simple script to sync fork with local branch (#4102)ef68384enhancement: Speed up function _assign_hash_ids by 34% (#4101)2d44d73Luke/sept16 CVE (#4094)ab55d86⚡️ Speed up methodElementHtml._get_children_htmlby 234% (#4087)6aee131⚡️ Speed up functiongroup_broken_paragraphsby 30% (#4088)1030a69fix: update deps to resolve cve (#4093)e3854d2Setup Codeflash Github Actions to optimize all future code (#4082)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditionsYou can disable automated security fix PRs for this repo from the Security Alerts page.