Skip to content

chore(deps): Bump the python-minor-and-patch group with 3 updates - #142

Merged
DoRmAmMu1997 merged 2 commits into
mainfrom
dependabot/pip/python-minor-and-patch-1e6762a2e4
Sep 28, 2026
Merged

DoRmAmMu1997 merged 2 commits into
mainfrom
dependabot/pip/python-minor-and-patch-1e6762a2e4

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 28, 2026

Copy link
Copy Markdown
Contributor

Bumps the python-minor-and-patch group with 3 updates: numpy, claude-agent-sdk and sqlalchemy.

Updates numpy from 2.4.6 to 2.5.3

Release notes

Sourced from numpy's releases.

v2.5.3 (Sep 6, 2026)

NumPy 2.5.3 Release Notes

The NumPy 2.5.3 is a patch release that fixes bugs discovered after the 2.5.2 release. Apart from the usual bug and maintenance work, there are a number of StringDType related fixes for problems discovered during the ongoing string work in the main branch.

This release supports Python versions 3.12-3.15

Changes

  • Casting a fixed-width byte string array (np.bytes_) to StringDType now raises TypeError when the bytes are not valid UTF-8. Previously the invalid bytes were stored as-is and later caused undefined behavior in string operations.

    (gh-32296)

  • MaskedArray._fill_value would become stale when ufuncs that change dtype left the result holding a fill_value typed for the old dtype. The mismatch was silent until something later called _check_fill_value, such as .view(), and then a TypeError would be raised. Now, when the copied fill_value is no longer valid for the new dtype, fall back to the default fill_value for that dtype instead of propagating the stale value. This may raise a ComplexWarning if the fill_value is complex and the new dtype is real.

    (gh-32423)

Contributors

A total of 9 people contributed to this release. People with a "+" by their names contributed a patch for the first time.

  • Charles Harris
  • Iason Krommydas
  • James Davies +
  • Joren Hammudoglu
  • Maanas Arora
  • Matti Picus
  • Nathan Goldbaum
  • Shikhar Goel +
  • Yeonho Kim +

Pull requests merged

A total of 27 pull requests were merged for this release.

  • #32235: MAINT: Prepare 2.5.x for further development

... (truncated)

Commits
  • dd88c0c Merge pull request #32511 from charris/prepare-2.5.3
  • edcac6a REL: Prepare for the NumPy 2.5.3 release
  • fd4d908 Merge pull request #32509 from charris/backport-32496
  • 65bb1da BUG: fix crash in ufunc.resolve_dtypes with a Python scalar type (#32496)
  • 294956e Merge pull request #32506 from charris/backport-32503
  • 26428d9 DOC: fix scipy docs links in intersphinx mapping (#32507)
  • 5fab1cb DOC: use static scipy doc site for intershpinx (#32503)
  • 7beed2f Merge pull request #32481 from ngoldbaum/stringdtype-backport
  • 8972f70 Merge pull request #32478 from charris/backport-32466
  • ab1b589 Merge pull request #32477 from charris/backport-32423
  • Additional commits viewable in compare view

Updates claude-agent-sdk from 0.2.157 to 0.2.159

Release notes

Sourced from claude-agent-sdk's releases.

v0.2.159

Internal/Other Changes

  • Updated bundled Claude CLI to version 2.1.281
  • Pinned default model for e2e tests to claude-opus-5 to work around CI failures with the CLI's new default model (#1287)

PyPI: https://pypi.org/project/claude-agent-sdk/0.2.159/

pip install claude-agent-sdk==0.2.159

v0.2.158

New Features

  • verbatim_prompts option: Added ClaudeAgentOptions.verbatim_prompts (default False). When True, user messages are delivered to the CLI exactly as written — no @path file expansion and no slash-command dispatch. This prevents untrusted text inlined into prompts from triggering unintended file reads or command execution. Works with query(), ClaudeSDKClient.connect(), and ClaudeSDKClient.query() for both string and async-iterable prompts. Requires CLI 2.1.248+; a warning is logged on older CLIs. (#1269)

Internal/Other Changes

  • Updated bundled Claude CLI to version 2.1.280
  • CI improvements: recompressed wheels and raised the PyPI pre-flight threshold (#1283)

PyPI: https://pypi.org/project/claude-agent-sdk/0.2.158/

pip install claude-agent-sdk==0.2.158
Changelog

Sourced from claude-agent-sdk's changelog.

0.2.159

Internal/Other Changes

  • Updated bundled Claude CLI to version 2.1.281
  • Pinned default model for e2e tests to claude-opus-5 to work around CI failures with the CLI's new default model (#1287)

0.2.158

New Features

  • verbatim_prompts option: Added ClaudeAgentOptions.verbatim_prompts (default False). When True, user messages are delivered to the CLI exactly as written — no @path file expansion and no slash-command dispatch. This prevents untrusted text inlined into prompts from triggering unintended file reads or command execution. Works with query(), ClaudeSDKClient.connect(), and ClaudeSDKClient.query() for both string and async-iterable prompts. Requires CLI 2.1.248+; a warning is logged on older CLIs. (#1269)

Internal/Other Changes

  • Updated bundled Claude CLI to version 2.1.280
  • CI improvements: recompressed wheels and raised the PyPI pre-flight threshold (#1283)

0.2.156

Internal/Other Changes

  • Updated bundled Claude CLI to version 2.1.276

0.2.155

Internal/Other Changes

  • Updated bundled Claude CLI to version 2.1.275

0.2.154

Internal/Other Changes

  • Updated bundled Claude CLI to version 2.1.274

0.2.153

New Features

  • snapshot option for system prompts: Added a snapshot field to SystemPromptPreset and a new SystemPromptCustom typed dict. When snapshot is True, the session keeps the system prompt recorded on its first request, improving prompt-caching behavior across resumed sessions. When False, the prompt is rebuilt on every request, useful for iterating on append text. Requires CLI 2.1.257+ (#1268)

Internal/Other Changes

  • Updated bundled Claude CLI to version 2.1.273

0.2.152

Internal/Other Changes

... (truncated)

Commits

Updates sqlalchemy from 2.0.54 to 2.1.0

Release notes

Sourced from sqlalchemy's releases.

2.1.0

Released: September 24, 2026

orm

  • [orm] [feature] Added _orm.composite.column_template parameter to _orm.composite(). When the composite class is a dataclass, this parameter accepts a string template such as "person_%s", containing exactly one %s placeholder, that's used to generate column names for dataclass fields that don't otherwise have an explicit name, rather than using the bare field name. This removes the need to hand-write a _orm.mapped_column() for each field when the same composite dataclass is mapped multiple times on the same class with different column-name prefixes. Pull request courtesy Leonardo Rosa.

    References: #12575

  • [orm] [bug] Fixed issue where pickling an ORM object that had an instance level lazy loader established, such as when the _orm.raiseload() option is used, would emit a spurious warning regarding the loader containing additional criteria, if the object had itself been unpickled from a previous serialization. This would occur for objects that cross more than one serialization boundary, such as when using multiprocessing.

    This change is also backported to: 2.0.53

    References: #13574

  • [orm] [bug] Fixed issue where calling _orm.aliased() against an existing _orm.aliased() construct, without passing an explicit selectable, would disregard the selectable of the existing construct and produce an alias of the mapped table instead, if that selectable were anything other than a table or a plain subquery, leading to incorrect results and/or non-working queries.

    This includes _orm.aliased() against a _orm.with_polymorphic() construct, which would previously produce an alias of the base mapped class only, discarding the polymorphic selectable and additional mappers. The new construct now retains these, so that criteria against subclass attributes and the innerjoin and selectable parameters of _orm.with_polymorphic() take effect, and subclass columns are loaded up front. The SQL rendered for these constructs now includes the polymorphic selectable.

    This change is also backported to: 2.0.53

    References: #13583, #13584

... (truncated)

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the python-minor-and-patch group with 3 updates: [numpy](https://github.com/numpy/numpy), [claude-agent-sdk](https://github.com/anthropics/claude-agent-sdk-python) and [sqlalchemy](https://github.com/sqlalchemy/sqlalchemy).


Updates `numpy` from 2.4.6 to 2.5.3
- [Release notes](https://github.com/numpy/numpy/releases)
- [Changelog](https://github.com/numpy/numpy/blob/main/doc/RELEASE_WALKTHROUGH.rst)
- [Commits](numpy/numpy@v2.4.6...v2.5.3)

Updates `claude-agent-sdk` from 0.2.157 to 0.2.159
- [Release notes](https://github.com/anthropics/claude-agent-sdk-python/releases)
- [Changelog](https://github.com/anthropics/claude-agent-sdk-python/blob/main/CHANGELOG.md)
- [Commits](https://github.com/anthropics/claude-agent-sdk-python/commits/v0.2.159)

Updates `sqlalchemy` from 2.0.54 to 2.1.0
- [Release notes](https://github.com/sqlalchemy/sqlalchemy/releases)
- [Changelog](https://github.com/sqlalchemy/sqlalchemy/blob/main/CHANGES.rst)
- [Commits](https://github.com/sqlalchemy/sqlalchemy/commits)

---
updated-dependencies:
- dependency-name: numpy
  dependency-version: 2.5.3
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-minor-and-patch
- dependency-name: claude-agent-sdk
  dependency-version: 0.2.159
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python-minor-and-patch
- dependency-name: sqlalchemy
  dependency-version: 2.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Sep 28, 2026
SQLAlchemy 2.1 types Row/Result with TypeVarTuple, so a raw text() query's
scalar_one() no longer has an inferable type and mypy failed with
"Need type annotation" in test_scan_storage_migrations.py. Annotate the one
affected local.

2.1 also makes psycopg 3 the default driver for a bare postgresql:// URL.
_normalize_database_url still rewrites bare URLs to postgresql+psycopg://
(the short postgres:// scheme is never accepted, and the explicit driver no
longer depends on SQLAlchemy's default), so only its docstring and the
deployment-runtime LLD row that described the old psycopg2 default change.

Checked against the 2.1 migration notes: app code has no filter_by() calls
and no Session.execute(text(...)) (the new unconditional autoflush), and
Alembic receives the raw URL string, so the URL-escaping change does not
alter the SQLite path.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@DoRmAmMu1997
DoRmAmMu1997 merged commit d0e7c58 into main Sep 28, 2026
7 checks passed
@DoRmAmMu1997
DoRmAmMu1997 deleted the dependabot/pip/python-minor-and-patch-1e6762a2e4 branch September 28, 2026 09:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant