Skip to content

chore(deps): bump uvicorn from 0.46.0 to 0.51.0 - #632

Closed
dependabot[bot] wants to merge 1 commit into
stagingfrom
dependabot/uv/staging/uvicorn-0.51.0
Closed

chore(deps): bump uvicorn from 0.46.0 to 0.51.0#632
dependabot[bot] wants to merge 1 commit into
stagingfrom
dependabot/uv/staging/uvicorn-0.51.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 12, 2026

Copy link
Copy Markdown
Contributor

Bumps uvicorn from 0.46.0 to 0.51.0.

Release notes

Sourced from uvicorn's releases.

Version 0.51.0

What's Changed

Full Changelog: Kludex/uvicorn@0.50.2...0.51.0

Version 0.50.1

What's Changed

New Contributors

Full Changelog: Kludex/uvicorn@0.50.0...0.50.1

Version 0.50.0

What's Changed

Full Changelog: Kludex/uvicorn@0.49.0...0.50.0

Version 0.49.0

What's Changed

Full Changelog: Kludex/uvicorn@0.48.0...0.49.0

Version 0.48.0

What's Changed

Full Changelog: Kludex/uvicorn@0.47.0...0.48.0

Version 0.47.0

What's Changed

... (truncated)

Changelog

Sourced from uvicorn's changelog.

0.51.0 (July 8, 2026)

Added

  • Restart workers one at a time on SIGHUP, bringing each replacement up before retiring the old worker, so reloads no longer drop requests (#3025)

Removed

  • Remove colorama from the standard extra (#3027)

0.50.2 (July 6, 2026)

Fixed

  • Require websockets>=13.0, which the default websockets-sansio implementation needs (#3021)

0.50.1 (July 6, 2026)

Fixed

  • Split comma-separated Sec-WebSocket-Protocol values in the websockets-sansio implementation (#3019)

0.50.0 (July 4, 2026)

If you use WebSockets, note that --ws auto now picks the websockets-sansio implementation. You shouldn't need it, but you can pin --ws websockets to get the deprecated legacy one back.

Changed

  • Exit with the dedicated code 3 on any startup failure: app loading, socket bind and lifespan startup errors previously exited with a mix of 0, 1 and 3 (#3001)
  • Stop the multiprocess supervisor when a worker exits with code 3 instead of restarting it forever (#3001)
  • Default --ws auto to websockets-sansio when websockets is installed (#2985)
  • Skip the eager app import in the parent process with --reload or --workers, fixing a memory regression introduced in 0.47.0 (#3012)
  • Build a fresh asgi scope dict per request (#2977)
  • Cache the asgi scope sub-dict per connection (#2976)
  • Avoid copying single-frame WebSocket payloads in websockets-sansio (#2983)
  • Memoize trusted host checks in ProxyHeadersMiddleware (#2970)
  • Replace click.style with an internal ANSI style helper (#2981)

Deprecated

  • Deprecate the legacy websockets implementation; use websockets-sansio or wsproto instead (#2985)

0.49.0 (June 3, 2026)

Changed

  • Bump httptools minimum version to 0.8.0 (#2962)
  • Consume duplicate forwarding headers in ProxyHeadersMiddleware (reverses the 0.48.0 behavior of ignoring them) (#2971)

0.48.0 (May 24, 2026)

... (truncated)

Commits
  • e4d0b05 Version 0.51.0 (#3028)
  • 944e43d Remove colorama from the standard extra (#3027)
  • 2e78770 Restart workers with overlap on SIGHUP for near-zero-downtime reloads (#3025)
  • a1b570c Version 0.50.2 (#3022)
  • 83c7da7 Require websockets>=13.0 for the default sansio implementation (#3021)
  • b4d0116 Version 0.50.1 (#3020)
  • 2a9151d Split comma-separated Sec-WebSocket-Protocol values in the websockets-sansi...
  • 1bf3ab4 Cover the excluded-directory branch in FileFilter with a direct test (#3014)
  • 837b5f9 Deflake multiprocess, reload, and signal supervisor tests (#2975)
  • 21d2c16 Version 0.50.0 (#3013)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [uvicorn](https://github.com/Kludex/uvicorn) from 0.46.0 to 0.51.0.
- [Release notes](https://github.com/Kludex/uvicorn/releases)
- [Changelog](https://github.com/Kludex/uvicorn/blob/main/docs/release-notes.md)
- [Commits](Kludex/uvicorn@0.46.0...0.51.0)

---
updated-dependencies:
- dependency-name: uvicorn
  dependency-version: 0.51.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels Jul 12, 2026
@github-actions

Copy link
Copy Markdown

Dependency Review

The following issues were found:
  • ✅ 0 vulnerable package(s)
  • ✅ 0 package(s) with incompatible licenses
  • ✅ 0 package(s) with invalid SPDX license definitions
  • ⚠️ 1 package(s) with unknown licenses.
See the Details below.

License Issues

uv.lock

PackageVersionLicenseIssue Type
uvicorn0.51.0NullUnknown License

OpenSSF Scorecard

PackageVersionScoreDetails
pip/uvicorn 0.51.0 UnknownUnknown

Scanned Files

  • uv.lock

@overcut-ai

overcut-ai Bot commented Jul 12, 2026

Copy link
Copy Markdown

Completed Working on "Code Review"

✅ Code review complete. No issues found - all changes look good! ✅

✅ Workflow completed successfully.


👉 View complete log

barakb added a commit that referenced this pull request Jul 13, 2026
…ons) (#640)

* chore(deps): consolidate Dependabot updates (Python, npm, GitHub Actions)

Combines 15 open Dependabot PRs (#625-#639) into a single change set.

Python (pyproject.toml + uv.lock):
- fastapi 0.136.1 -> 0.139.0 (#634)
- litellm 1.84.0 -> 1.92.0 (#630)
- openai 2.44.0 -> 2.45.0 (#631)
- tqdm 4.67.3 -> 4.68.4 (#636)
- uvicorn 0.46.0 -> 0.51.0 (#632)

npm (app/package.json + app/package-lock.json):
- @tanstack/react-query 5.90.21 -> 5.101.2 (#635)
- date-fns 3.6.0 -> 4.4.0 (#637)
- lucide-react 0.577.0 -> 1.24.0 (#639)
- react-day-picker 8.10.2 -> 10.0.1 (#638)
- postcss 8.5.16 -> 8.5.17 (#633)

GitHub Actions:
- astral-sh/setup-uv 8.2.0 -> 8.3.2 (#626)
- docker/build-push-action 7.2.0 -> 7.3.0 (#628)
- docker/login-action 4.2.0 -> 4.4.0 (#627)
- docker/metadata-action 6.1.0 -> 6.2.0 (#625)
- rojopolis/spellcheck-github-actions 0.62.0 -> 0.63.0 (#629)

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* fix(ui): replace removed lucide-react Github icon with inline SVG

lucide-react v1 dropped its brand icons, so the `Github` named export no
longer exists. AuthModal's "Sign in with GitHub" button relied on it. Use
an inline GitHub logo SVG, matching the existing inline Google logo in the
same component, so the bump to lucide-react ^1.24.0 doesn't break the build.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* chore(deps): sync root package-lock.json with bumped app deps

The root package.json links the frontend via `queryweaver-app: file:app`,
so the root lock file embeds the app dependency tree. The E2E workflow runs
`npm ci` at the repo root, which requires the lock file to be in sync.
Regenerate it to match the bumped app dependencies.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

* fix(a11y): hide decorative OAuth icons from assistive tech

Both the Google and GitHub button icons are decorative — the button text
labels the action — so mark both SVGs `aria-hidden="true" focusable="false"`
for consistent screen-reader behavior.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

---------

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@dependabot @github

dependabot Bot commented on behalf of github Jul 13, 2026

Copy link
Copy Markdown
Contributor Author

Looks like uvicorn is up-to-date now, so this is no longer needed.

@dependabot dependabot Bot closed this Jul 13, 2026
@dependabot
dependabot Bot deleted the dependabot/uv/staging/uvicorn-0.51.0 branch July 13, 2026 06:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants