Skip to content

Bump the python-dependencies group across 1 directory with 2 updates#35

Merged
angela-tarantula merged 1 commit intomainfrom
dependabot/uv/python-dependencies-d1b196a29e
Apr 1, 2026
Merged

Bump the python-dependencies group across 1 directory with 2 updates#35
angela-tarantula merged 1 commit intomainfrom
dependabot/uv/python-dependencies-d1b196a29e

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github Mar 31, 2026

Bumps the python-dependencies group with 2 updates in the / directory: jsonpointer and fastapi.

Updates jsonpointer from 3.1.0 to 3.1.1

Commits
  • ada0cad bump version to 3.1.1
  • bea0f7e Merge pull request #68 from nsano-rururu/test-py313and314
  • e6844d7 Merge branch 'master' into test-py313and314
  • 0e9ea50 Merge pull request #69 from angela-tarantula/patch-1
  • 928959c Fix flake8 issue
  • b657276 Merge branch 'master' into patch-1
  • 1233257 add test case from pull request description
  • 97cd230 Merge pull request #74 from stefankoegl/v3.1
  • b798115 release v3.1.0
  • 5f89969 Merge pull request #73 from stefankoegl/update-python
  • Additional commits viewable in compare view

Updates fastapi from 0.135.1 to 0.135.2

Release notes

Sourced from fastapi's releases.

0.135.2

Upgrades

  • ⬆️ Increase lower bound to pydantic >=2.9.0. and fix the test suite. PR #15139 by @​svlandeg.

Docs

Translations

Internal

... (truncated)

Commits
  • 25a3697 🔖 Release version 0.135.2
  • ab125da 📝 Update release notes
  • 122b6d4 📝 Add missing last release notes dates (#15202)
  • 68ac0ab 📝 Update release notes
  • ea6e287 📝 Update docs for contributors and team members regarding translation PRs (#1...
  • d0a6f20 📝 Update release notes
  • fd9e192 💄 Fix code blocks in reference docs overflowing table width (#15094)
  • fce9460 📝 Update release notes
  • 0227991 🔨 Exclude spam comments from statistics in scripts/people.py (#15088)
  • cbd64b0 📝 Update release notes
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels Mar 31, 2026
@dependabot dependabot Bot requested a review from angela-tarantula as a code owner March 31, 2026 05:37
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels Mar 31, 2026
@dependabot dependabot Bot had a problem deploying to dependabot-automation March 31, 2026 05:37 Failure
@dependabot dependabot Bot temporarily deployed to codecov-automation March 31, 2026 05:37 Inactive
@dependabot dependabot Bot temporarily deployed to codecov-automation March 31, 2026 05:37 Inactive
@dependabot dependabot Bot temporarily deployed to codecov-automation March 31, 2026 05:37 Inactive
@github-actions
Copy link
Copy Markdown
Contributor

github-actions Bot commented Mar 31, 2026

Dependency Review

The following issues were found:
  • ✅ 0 vulnerable package(s)
  • ✅ 0 package(s) with incompatible licenses
  • ✅ 0 package(s) with invalid SPDX license definitions
  • ⚠️ 1 package(s) with unknown licenses.
See the Details below.

Snapshot Warnings

⚠️: No snapshots were found for the head SHA 1d3cff6.
Ensure that dependencies are being submitted on PR branches and consider enabling retry-on-snapshot-warnings. See the documentation for more information and troubleshooting advice.

License Issues

uv.lock

PackageVersionLicenseIssue Type
fastapi0.135.2NullUnknown License
Allowed Licenses: Apache-2.0, MIT, MIT-0, BSD-2-Clause, BSD-3-Clause, MPL-2.0, 0BSD, Python-2.0, Python-2.0.1, GPL-1.0-or-later, GPL-2.0-or-later
Excluded from license check: pkg:pypi/jsonpointer@3.1.0, pkg:pypi/pytest-cov@7.1.0, pkg:pypi/ruff@0.15.7, pkg:pypi/uvicorn@0.42.0, pkg:pypi/pyinstaller@6.19.0, pkg:pypi/python-jsonpath@2.0.2, pkg:pypi/pyinstaller-hooks-contrib@2026.3, pkg:pypi/uv@0.10.12

OpenSSF Scorecard

PackageVersionScoreDetails
pip/fastapi 0.135.2 UnknownUnknown
pip/jsonpointer 3.1.1 🟢 4.6
Details
CheckScoreReason
Code-Review🟢 5Found 4/7 approved changesets -- score normalized to 5
Packaging⚠️ -1packaging workflow not detected
Maintained🟢 1014 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
Binary-Artifacts🟢 10no binaries found in the repo
Pinned-Dependencies⚠️ 0dependency not pinned by hash detected -- score normalized to 0
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Security-Policy⚠️ 0security policy file not detected
Fuzzing⚠️ 0project is not fuzzed
License🟢 9license file detected
Signed-Releases⚠️ -1no releases found
Branch-Protection🟢 3branch protection is not maximal on development and all release branches
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0

Scanned Files

  • uv.lock

@dependabot dependabot Bot temporarily deployed to dependabot-automation March 31, 2026 05:47 Inactive
@dependabot dependabot Bot had a problem deploying to dependabot-automation March 31, 2026 05:48 Failure
@angela-tarantula
Copy link
Copy Markdown
Owner

@dependabot recreate

@dependabot dependabot Bot changed the title Bump the python-dependencies group with 2 updates Bump the python-dependencies group across 1 directory with 2 updates Mar 31, 2026
@dependabot dependabot Bot force-pushed the dependabot/uv/python-dependencies-d1b196a29e branch from 1f059fb to 4ed78d6 Compare March 31, 2026 13:12
@dependabot dependabot Bot temporarily deployed to codecov-automation March 31, 2026 13:12 Inactive
@dependabot dependabot Bot temporarily deployed to codecov-automation March 31, 2026 13:12 Inactive
@dependabot dependabot Bot temporarily deployed to dependabot-automation March 31, 2026 13:12 Inactive
@dependabot dependabot Bot temporarily deployed to codecov-automation March 31, 2026 13:12 Inactive
@dependabot dependabot Bot force-pushed the dependabot/uv/python-dependencies-d1b196a29e branch from 4ed78d6 to 1988ea0 Compare April 1, 2026 01:19
@dependabot dependabot Bot temporarily deployed to codecov-automation April 1, 2026 01:19 Inactive
@dependabot dependabot Bot temporarily deployed to dependabot-automation April 1, 2026 01:19 Inactive
@dependabot dependabot Bot temporarily deployed to codecov-automation April 1, 2026 01:19 Inactive
@dependabot dependabot Bot temporarily deployed to codecov-automation April 1, 2026 01:19 Inactive
@angela-tarantula
Copy link
Copy Markdown
Owner

@dependabot recreate

Bumps the python-dependencies group with 2 updates: [jsonpointer](https://github.com/stefankoegl/python-json-pointer) and [fastapi](https://github.com/fastapi/fastapi).


Updates `jsonpointer` from 3.1.0 to 3.1.1
- [Commits](stefankoegl/python-json-pointer@v3.1.0...v3.1.1)

Updates `fastapi` from 0.135.1 to 0.135.2
- [Release notes](https://github.com/fastapi/fastapi/releases)
- [Commits](fastapi/fastapi@0.135.1...0.135.2)

---
updated-dependencies:
- dependency-name: jsonpointer
  dependency-version: 3.1.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python-dependencies
- dependency-name: fastapi
  dependency-version: 0.135.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: python-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot force-pushed the dependabot/uv/python-dependencies-d1b196a29e branch from cbef4d7 to 1d3cff6 Compare April 1, 2026 01:55
@dependabot dependabot Bot temporarily deployed to dependabot-automation April 1, 2026 01:55 Inactive
@dependabot dependabot Bot temporarily deployed to codecov-automation April 1, 2026 01:55 Inactive
@dependabot dependabot Bot temporarily deployed to codecov-automation April 1, 2026 01:55 Inactive
@dependabot dependabot Bot temporarily deployed to codecov-automation April 1, 2026 01:55 Inactive
@angela-tarantula angela-tarantula merged commit a2c4fe1 into main Apr 1, 2026
12 checks passed
@angela-tarantula angela-tarantula deleted the dependabot/uv/python-dependencies-d1b196a29e branch April 1, 2026 02:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant