Skip to content

chore(deps): uv: bump the all-python group across 1 directory with 6 updates#626

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/agent/all-python-562714a858
Open

chore(deps): uv: bump the all-python group across 1 directory with 6 updates#626
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/agent/all-python-562714a858

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 18, 2026

Copy link
Copy Markdown
Contributor

Bumps the all-python group with 6 updates in the /agent directory:

Package From To
boto3 1.43.40 1.43.48
bedrock-agentcore 1.17.0 1.18.0
claude-agent-sdk 0.2.110 0.2.119
uvicorn 0.50.0 0.51.0
ruff 0.15.20 0.15.21
ty 0.0.56 0.0.59

Updates boto3 from 1.43.40 to 1.43.48

Commits
  • aa40f37 Merge branch 'release-1.43.48'
  • 13cce5d Bumping version to 1.43.48
  • 24523ab Add changelog entries from botocore
  • 11b9978 Merge branch 'release-1.43.47'
  • d1530e3 Merge branch 'release-1.43.47' into develop
  • 2a7cd54 Bumping version to 1.43.47
  • 16f140d Add changelog entries from botocore
  • c7888d6 Merge branch 'release-1.43.46'
  • 7db70ea Merge branch 'release-1.43.46' into develop
  • 1479621 Bumping version to 1.43.46
  • Additional commits viewable in compare view

Updates bedrock-agentcore from 1.17.0 to 1.18.0

Release notes

Sourced from bedrock-agentcore's releases.

Bedrock AgentCore SDK v1.18.0

Installation

pip install bedrock-agentcore==1.18.0

What's Changed

See CHANGELOG.md for details.

What's Changed

New Contributors

Full Changelog: aws/bedrock-agentcore-sdk-python@v1.17.0...v1.18.0

Changelog

Sourced from bedrock-agentcore's changelog.

[1.18.0] - 2026-07-10

Fixed

  • fix: floor monotonic timestamps to milliseconds before comparison (#573) (f855616)
  • fix: order AgentCore Memory events at millisecond resolution (#572) (a271ab4)

Other Changes

  • ci: add API reference docs generation workflow (#569) (168f4be)
  • fix(payments): address langgraph middleware review follow-ups (#570) (46a0bea)
  • feat(payments): Add LangGraph integration for payment handling (#546) (0a8a486)
Commits
  • 8df87bb chore: bump version to 1.18.0 (#574)
  • f855616 fix: floor monotonic timestamps to milliseconds before comparison (#573)
  • a271ab4 fix: order AgentCore Memory events at millisecond resolution (#572)
  • 168f4be ci: add API reference docs generation workflow (#569)
  • 46a0bea fix(payments): address langgraph middleware review follow-ups (#570)
  • 0a8a486 feat(payments): Add LangGraph integration for payment handling (#546)
  • See full diff in compare view

Updates claude-agent-sdk from 0.2.110 to 0.2.119

Release notes

Sourced from claude-agent-sdk's releases.

v0.2.119

Internal/Other Changes

  • Updated bundled Claude CLI to version 2.1.210

PyPI: https://pypi.org/project/claude-agent-sdk/0.2.119/

pip install claude-agent-sdk==0.2.119

v0.2.118

Internal/Other Changes

  • Updated bundled Claude CLI to version 2.1.209

PyPI: https://pypi.org/project/claude-agent-sdk/0.2.118/

pip install claude-agent-sdk==0.2.118

v0.2.117

Bug Fixes

  • Escaped untrusted fields in Slack issue notification workflow: Fixed the Slack notification workflow to properly escape issue titles and usernames using jq instead of bash substitution, preventing malformed JSON payloads and mrkdwn injection from specially crafted issue titles (#1116)

Internal/Other Changes

  • Updated bundled Claude CLI to version 2.1.208

PyPI: https://pypi.org/project/claude-agent-sdk/0.2.117/

pip install claude-agent-sdk==0.2.117

v0.2.116

... (truncated)

Changelog

Sourced from claude-agent-sdk's changelog.

0.2.119

Internal/Other Changes

  • Updated bundled Claude CLI to version 2.1.210

0.2.118

Internal/Other Changes

  • Updated bundled Claude CLI to version 2.1.209

0.2.117

Bug Fixes

  • Escaped untrusted fields in Slack issue notification workflow: Fixed the Slack notification workflow to properly escape issue titles and usernames using jq instead of bash substitution, preventing malformed JSON payloads and mrkdwn injection from specially crafted issue titles (#1116)

Internal/Other Changes

  • Updated bundled Claude CLI to version 2.1.208

0.2.116

Internal/Other Changes

  • Updated bundled Claude CLI to version 2.1.207
  • Fixed CI workspace trust so Claude Code honors project-scoped permission grants in checkout directories (#1085)

0.2.115

Internal/Other Changes

  • Updated bundled Claude CLI to version 2.1.206

0.2.114

Internal/Other Changes

  • Updated bundled Claude CLI to version 2.1.205

0.2.113

Internal/Other Changes

  • Updated bundled Claude CLI to version 2.1.204

0.2.112

Internal/Other Changes

... (truncated)

Commits
  • 57f67cd docs: update changelog for v0.2.119
  • d434722 chore: release v0.2.119
  • a8da0ca chore: bump bundled CLI version to 2.1.210
  • b7e0d0f docs: update changelog for v0.2.118
  • 82fcdb7 chore: release v0.2.118
  • 5b7e676 chore: bump bundled CLI version to 2.1.209
  • 059d344 docs: update changelog for v0.2.117
  • 3aed422 chore: release v0.2.117
  • 67b6ec3 chore: bump bundled CLI version to 2.1.208
  • cc76ac9 Escape untrusted issue fields in the Slack notification workflow (#1116)
  • Additional commits viewable in compare view

Updates uvicorn from 0.50.0 to 0.51.0

Release notes

Sourced from uvicorn's releases.

Version 0.51.0

What's Changed

Full Changelog: Kludex/uvicorn@0.50.2...0.51.0

Version 0.50.1

What's Changed

New Contributors

Full Changelog: Kludex/uvicorn@0.50.0...0.50.1

Changelog

Sourced from uvicorn's changelog.

0.51.0 (July 8, 2026)

Added

  • Restart workers one at a time on SIGHUP, bringing each replacement up before retiring the old worker, so reloads no longer drop requests (#3025)

Removed

  • Remove colorama from the standard extra (#3027)

0.50.2 (July 6, 2026)

Fixed

  • Require websockets>=13.0, which the default websockets-sansio implementation needs (#3021)

0.50.1 (July 6, 2026)

Fixed

  • Split comma-separated Sec-WebSocket-Protocol values in the websockets-sansio implementation (#3019)
Commits
  • e4d0b05 Version 0.51.0 (#3028)
  • 944e43d Remove colorama from the standard extra (#3027)
  • 2e78770 Restart workers with overlap on SIGHUP for near-zero-downtime reloads (#3025)
  • a1b570c Version 0.50.2 (#3022)
  • 83c7da7 Require websockets>=13.0 for the default sansio implementation (#3021)
  • b4d0116 Version 0.50.1 (#3020)
  • 2a9151d Split comma-separated Sec-WebSocket-Protocol values in the websockets-sansi...
  • 1bf3ab4 Cover the excluded-directory branch in FileFilter with a direct test (#3014)
  • 837b5f9 Deflake multiprocess, reload, and signal supervisor tests (#2975)
  • See full diff in compare view

Updates ruff from 0.15.20 to 0.15.21

Release notes

Sourced from ruff's releases.

0.15.21

Release Notes

Released on 2026-07-09.

Preview features

  • Add --add-ignore for adding ruff:ignore comments (#26346)
  • [flake8-comprehensions] Drop C409 tuple comprehension preview behavior (#25707)
  • Avoid whitespace normalization when formatting comments (#26455)
  • [pyupgrade] Lint and fix use of deprecated abc decorators (UP051) (#26417)

Bug fixes

  • Refine non-empty f-string detection (#26526)
  • Detect syntax errors in individual notebook cells (#26419)
  • [flake8-implicit-str-concat] Fix ISC003 autofix incorrectly stripping + from comments (#26554)

Rule changes

  • [flake8-executable] Mark EXE004 fix as unsafe (#26033)
  • [flake8-pyi] Mark PYI061 fixes as unsafe in Python files (#26533)
  • [pydocstyle] Skip overload-with-docstring in stub files (D418) (#26318)

Performance

  • Avoid per-token source index visitor calls (#26506)
  • Cache parenthesized expression boundaries in the formatter (#26344)
  • Improve performance of rendering edits in preview mode (#26565)
  • Inline fits_element in formatter (#26429)
  • Inline formatter printing hot paths (#26504)
  • Lazily create builtin bindings (#26510)
  • Skip empty trivia scans in the source indexer (#26507)
  • Use ICF for macOS release builds (#25780)

Formatter

  • Add --extend-exclude to ruff format (#26372)

Documentation

  • Add "How does Ruff's import sorting compare to isort?" link to README (#26530)
  • Fix Mozilla Firefox repository link in README (#26537)
  • [flake8-bandit] Fix misleading docstring for mako-templates (S702) (#26432)
  • [ruff] Fix non-triggering example for if-key-in-dict-del (RUF051) (#26433)

Contributors

... (truncated)

Changelog

Sourced from ruff's changelog.

0.15.21

Released on 2026-07-09.

Preview features

  • Add --add-ignore for adding ruff:ignore comments (#26346)
  • [flake8-comprehensions] Drop C409 tuple comprehension preview behavior (#25707)
  • Avoid whitespace normalization when formatting comments (#26455)
  • [pyupgrade] Lint and fix use of deprecated abc decorators (UP051) (#26417)

Bug fixes

  • Refine non-empty f-string detection (#26526)
  • Detect syntax errors in individual notebook cells (#26419)
  • [flake8-implicit-str-concat] Fix ISC003 autofix incorrectly stripping + from comments (#26554)

Rule changes

  • [flake8-executable] Mark EXE004 fix as unsafe (#26033)
  • [flake8-pyi] Mark PYI061 fixes as unsafe in Python files (#26533)
  • [pydocstyle] Skip overload-with-docstring in stub files (D418) (#26318)

Performance

  • Avoid per-token source index visitor calls (#26506)
  • Cache parenthesized expression boundaries in the formatter (#26344)
  • Improve performance of rendering edits in preview mode (#26565)
  • Inline fits_element in formatter (#26429)
  • Inline formatter printing hot paths (#26504)
  • Lazily create builtin bindings (#26510)
  • Skip empty trivia scans in the source indexer (#26507)
  • Use ICF for macOS release builds (#25780)

Formatter

  • Add --extend-exclude to ruff format (#26372)

Documentation

  • Add "How does Ruff's import sorting compare to isort?" link to README (#26530)
  • Fix Mozilla Firefox repository link in README (#26537)
  • [flake8-bandit] Fix misleading docstring for mako-templates (S702) (#26432)
  • [ruff] Fix non-triggering example for if-key-in-dict-del (RUF051) (#26433)

Contributors

... (truncated)

Commits

Updates ty from 0.0.56 to 0.0.59

Release notes

Sourced from ty's releases.

0.0.59

Release Notes

Released on 2026-07-12.

Bug fixes

  • Guard descriptor classification cycles (#26690)
  • Respect init=False in dataclass field-order checks (#26749)
  • Avoid duplicate diagnostics for overloaded TypeIs (#26716)

Library support

  • Pydantic: Support custom __init__ methods (#26699)
  • Pydantic: Support field metadata in Annotated (#26650)

Core type checking

  • Allow unsound equality-based narrowing for builtins (#26414)
  • Bind Self in implicit dunder calls (#26711)
  • Correct protocol method receiver binding (#26701)
  • Exempt ParamSpec callables from the dunder descriptor heuristic (#26696)
  • Remove transitive TypeVar artifacts during collection inference (#26714)

LSP server

  • Avoid broad invalidation from file check eligibility (#26741)
  • Correct how we expand tabs in docstrings (#26679)
  • Resolve ambiguity in Google-style docstring parsing in favour of observations from popular projects (#26673)

CLI

  • Avoid allocation for every stdout write (#26698)
  • Buffer diagnostic output (#26702)

Performance

  • Cache generic context (#26745)
  • Cache known class instances (#26746)
  • Reuse common TypedDict constraints through intersections (#26747)
  • Use purpose-specific types for completion and module text (#26664)

Contributors

... (truncated)

Changelog

Sourced from ty's changelog.

0.0.59

Released on 2026-07-12.

Bug fixes

  • Guard descriptor classification cycles (#26690)
  • Respect init=False in dataclass field-order checks (#26749)
  • Avoid duplicate diagnostics for overloaded TypeIs (#26716)

Library support

  • Pydantic: Support custom __init__ methods (#26699)
  • Pydantic: Support field metadata in Annotated (#26650)

Core type checking

  • Allow unsound equality-based narrowing for builtins (#26414)
  • Bind Self in implicit dunder calls (#26711)
  • Correct protocol method receiver binding (#26701)
  • Exempt ParamSpec callables from the dunder descriptor heuristic (#26696)
  • Remove transitive TypeVar artifacts during collection inference (#26714)

LSP server

  • Avoid broad invalidation from file check eligibility (#26741)
  • Correct how we expand tabs in docstrings (#26679)
  • Resolve ambiguity in Google-style docstring parsing in favour of observations from popular projects (#26673)

CLI

  • Avoid allocation for every stdout write (#26698)
  • Buffer diagnostic output (#26702)

Performance

  • Cache generic context (#26745)
  • Cache known class instances (#26746)
  • Reuse common TypedDict constraints through intersections (#26747)
  • Use purpose-specific types for completion and module text (#26664)

Contributors

... (truncated)

Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels Jul 18, 2026
@dependabot
dependabot Bot requested review from a team as code owners July 18, 2026 06:14
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels Jul 18, 2026

@scottschreckengaust scottschreckengaust left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Verdict: Request changes

The build (agentcore) check is red, and I reproduced the cause in the worktree: it is a real incompatibility introduced by the ty 0.0.56 → 0.0.58 bump in this PR, not a flake. A second, quieter problem: the claude-agent-sdk bump silently breaks the documented Dockerfile CLI lockstep invariant (#215). Both must be resolved before merge. The other four bumps (boto3, bedrock-agentcore, uvicorn, ruff) are clean.

Vision alignment

Routine dependency hygiene under the repo's own .github/dependabot.yml uv / all-python group — no tenet impact, no blast-radius change, control plane untouched. Governance is satisfied: the Dependabot config is the standing authorization, so the ADR-003 approved-issue gate does not apply, and dependabot/uv/agent/all-python-... is the standard bot branch format (de-facto-waived nit). The change belongs — but a green build is table stakes, and keeping the CLI lockstep intact is exactly the kind of "bounded, improvable control plane" hygiene the vision calls for.

Blocking issues

B1 — ty 0.0.58 bump breaks the typecheck; the required suppressions/fixes are not in this PR (agent/uv.lock:189-211, source unchanged).
Root cause, verified by running both pins against the same worktree source:

  • uvx ty@0.0.56 checkAll checks passed (exit 0) — this is main's pin.
  • uv run ty check (this PR's 0.0.58) → Found 9 diagnostics (exit 1) — identical to the CI log for run 29633654727.

So the bump alone flips the build red. ty 0.0.58 changed two behaviors:

  1. It now treats frozen-Pydantic (ConfigDict(frozen=True)) fields as read-only properties and statically errors on assignment. Every failing site is inside a deliberate with pytest.raises(ValidationError): block that mutates a frozen model to assert the runtime rejects it — a correct, intentional test pattern (agent/tests/test_attachments.py:46; agent/tests/test_models.py:30,63,140,170,416,447). The test code is correct at runtime; only the new checker rejects it.
  2. It tightened dict-literal inference: content_trust={...} literals are inferred as dict[str, str], no longer assignable to Mapping[str, Literal["trusted","untrusted-external","memory"]] | None (agent/tests/test_models.py:237,244).

Fix (pick one, in this PR so it lands atomically with the bump):

  • Add targeted # ty: ignore[invalid-assignment] to the seven frozen-mutation lines and # ty: ignore[invalid-argument-type] (or annotate the literal, e.g. content_trust: dict[str, ContentTrust] = {...} / cast(...)) to the two content_trust sites; or
  • Hold ty at 0.0.56 (exclude it from this group bump) until the test suppressions are prepared separately.
    Merging as-is lands a red build on main.

B2 — claude-agent-sdk 0.2.116 breaks the #215 CLI lockstep; Dockerfile npm pin and comment not updated (agent/pyproject.toml:19, agent/Dockerfile:49,56).
The pin comment states the SDK is "kept in lockstep with the npm CLI pin in the Dockerfile, #215." Per the upstream v0.2.116 release notes, claude-agent-sdk 0.2.116 bundles Claude CLI 2.1.207, but:

  • agent/Dockerfile:56 still installs @anthropic-ai/claude-code@2.1.191.
  • agent/Dockerfile:49 comment still says "Pinned 2.1.191 to match the CLI bundled by claude-agent-sdk 0.2.110."
  • agent/pyproject.toml:19 comment still reads .../releases/tag/v0.2.110 (bundles claude CLI 2.1.191...) while pinning 0.2.116 — stale and now wrong on both the version and the CLI number.
    This is precisely the divergence the invariant exists to prevent: the SDK's bundled subprocess CLI (2.1.207) and the globally-installed npm CLI (2.1.191) would drift apart. Fix: bump the Dockerfile npm pin to @anthropic-ai/claude-code@2.1.207 and update both comments — or, if the mismatch is deliberate, document why in the comment. Note Dependabot cannot cross-update the Dockerfile npm pin from a uv group, so this must be done by hand on the branch.

Non-blocking suggestions / nits

  • N1 — ty is unpinned in pyproject.toml (agent/pyproject.toml:88, bare "ty",) yet pinned in uv.lock. That is why Dependabot moved it as part of the group even though there is no explicit == spec to bump. Consider pinning ty==<version> like the other dev tools so pre-release type-checker churn cannot silently re-break the build on the next lock refresh.
  • N2 — Branch name dependabot/uv/agent/all-python-562714a858 does not match (feat|fix|chore|docs)/<issue>-desc; standard for Dependabot, de-facto waived.

Documentation

No docs/guides/design changes required for a dep bump, and the Starlight mirror is untouched (no docs/ edits) — mirror-sync N/A. However, B2 is partly a documentation-accuracy defect: the pyproject.toml:19 and Dockerfile:49 comments are now factually stale (v0.2.110 / CLI 2.1.191) and must be corrected alongside the code fix.

Tests & CI

  • No test logic changed; the two edited files are agent/pyproject.toml and agent/uv.lock only.
  • CI: build (agentcore) FAILURE (the //agent:typecheck step — B1). Secrets, deps, and workflow scan SUCCESS, Validate PR title SUCCESS, Dead-code detection SUCCESS (advisory), CodeQL NEUTRAL, auto-approve SKIPPED. mergeStateStatus: BLOCKED on the red check.
  • Bootstrap synth-coverage: not applicable — no CDK construct/stack/handler or CFN resource-type change.
  • Supply-chain integrity (checked directly on the lock diff): all 50 added url/sdist entries carry sha256: hashes; no hash-stripped or unpinned lines; no new name = package sections (no stealth transitive additions — versions/hashes updated in place). No OSV/malware advisory names uvicorn 0.51.0, boto3 1.43.46, or bedrock-agentcore 1.18.0 as affected. bedrock-agentcore 1.18.0 release notes show no breaking changes.

Review agents run

  • /security-review (supply-chain scope) — Ran. Its auto-collected git context resolved to the repo root (empty diff), so I performed the supply-chain assessment directly against the lock diff in the worktree: hash-pin integrity, no unexpected/transitive package additions, and OSV/malware cross-check of the six versions (esp. the poisoned-"fix" pattern from the astro 7.1.0 / MAL-2026-10726 incident). No supply-chain findings.
  • code-reviewer — Effectively performed by hand for a two-file manifest diff: the load-bearing issues are B1 (version delta vs. CI) and B2 (cross-file lockstep with the Dockerfile), both covered above.
  • silent-failure-hunter — Omitted: no error-handling/fallback code in the diff (manifests only).
  • type-design-analyzer — Omitted: no new/changed types (the ty diagnostics are checker-behavior changes against existing types, addressed in B1).
  • comment-analyzer — In scope and applied: found the stale claude-agent-sdk comment (folded into B2/N1).
  • pr-test-analyzer — Omitted: no test code added/changed; the failing tests are unchanged and correct at runtime (the checker regressed, not the tests).

Human heuristics

  • Proportionality — Pass. A grouped patch/minor dep bump; scope matches the problem.
  • Coherence — Concern. The claude-agent-sdk SDK pin and the Dockerfile npm CLI pin encode the same concept (which Claude CLI version runs) and must move together per #215; this PR moves one and not the other (agent/pyproject.toml:19 vs agent/Dockerfile:56).
  • Clarity — Concern. The pyproject.toml:19 comment now misstates both the SDK release tag (v0.2.110) and the bundled CLI (2.1.191) after the bump to 0.2.116 / CLI 2.1.207.
  • Appropriateness — Concern. Verified against real upstream behavior, not mocks: I reproduced the typecheck delta with uvx ty@0.0.56 vs 0.0.58 and confirmed the bundled-CLI number from the upstream release notes. As shipped, the change is not mergeable (red build) and not maintainable-as-is (silent lockstep drift).

…updates

Bumps the all-python group with 6 updates in the /agent directory:

| Package | From | To |
| --- | --- | --- |
| [boto3](https://github.com/boto/boto3) | `1.43.40` | `1.43.48` |
| [bedrock-agentcore](https://github.com/aws/bedrock-agentcore-sdk-python) | `1.17.0` | `1.18.0` |
| [claude-agent-sdk](https://github.com/anthropics/claude-agent-sdk-python) | `0.2.110` | `0.2.119` |
| [uvicorn](https://github.com/Kludex/uvicorn) | `0.50.0` | `0.51.0` |
| [ruff](https://github.com/astral-sh/ruff) | `0.15.20` | `0.15.21` |
| [ty](https://github.com/astral-sh/ty) | `0.0.56` | `0.0.59` |



Updates `boto3` from 1.43.40 to 1.43.48
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](boto/boto3@1.43.40...1.43.48)

Updates `bedrock-agentcore` from 1.17.0 to 1.18.0
- [Release notes](https://github.com/aws/bedrock-agentcore-sdk-python/releases)
- [Changelog](https://github.com/aws/bedrock-agentcore-sdk-python/blob/main/CHANGELOG.md)
- [Commits](aws/bedrock-agentcore-sdk-python@v1.17.0...v1.18.0)

Updates `claude-agent-sdk` from 0.2.110 to 0.2.119
- [Release notes](https://github.com/anthropics/claude-agent-sdk-python/releases)
- [Changelog](https://github.com/anthropics/claude-agent-sdk-python/blob/main/CHANGELOG.md)
- [Commits](anthropics/claude-agent-sdk-python@v0.2.110...v0.2.119)

Updates `uvicorn` from 0.50.0 to 0.51.0
- [Release notes](https://github.com/Kludex/uvicorn/releases)
- [Changelog](https://github.com/Kludex/uvicorn/blob/main/docs/release-notes.md)
- [Commits](Kludex/uvicorn@0.50.0...0.51.0)

Updates `ruff` from 0.15.20 to 0.15.21
- [Release notes](https://github.com/astral-sh/ruff/releases)
- [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md)
- [Commits](astral-sh/ruff@0.15.20...0.15.21)

Updates `ty` from 0.0.56 to 0.0.59
- [Release notes](https://github.com/astral-sh/ty/releases)
- [Changelog](https://github.com/astral-sh/ty/blob/main/CHANGELOG.md)
- [Commits](astral-sh/ty@0.0.56...0.0.59)

---
updated-dependencies:
- dependency-name: bedrock-agentcore
  dependency-version: 1.18.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-python
- dependency-name: boto3
  dependency-version: 1.43.46
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all-python
- dependency-name: claude-agent-sdk
  dependency-version: 0.2.116
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all-python
- dependency-name: ruff
  dependency-version: 0.15.21
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: all-python
- dependency-name: ty
  dependency-version: 0.0.58
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: all-python
- dependency-name: uvicorn
  dependency-version: 0.51.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-python
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/uv/agent/all-python-562714a858 branch from c25c7f0 to b1b21df Compare July 22, 2026 19:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant