Skip to content

build(deps): bump the web group across 1 directory with 6 updates - #9

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/web-4d704b1b3b
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/web-4d704b1b3b

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 26, 2026 •

Copy link
Copy Markdown

Updates the requirements on fastapi, uvicorn, streamlit, altair, requests and httpx to permit the latest version.
Updates fastapi to 0.141.1

Release notes

Sourced from fastapi's releases.

0.141.1

Fixes

  • 🐛 Fix support for background tasks and headers from dependencies in app.frontend(). PR #16105 by @​tiangolo.

Docs

Commits
  • 95f8322 🔖 Release version 0.141.1 (#16106)
  • f137944 📝 Update release notes
  • d623544 🐛 Fix support for background tasks and headers from dependencies in `app.fron...
  • 1d211b9 📝 Update release notes
  • 8a1f876 📝 Document FASTAPI_ENV in FastAPI CLI guide (#16104)
  • c7e7b65 🔖 Release version 0.141.0 (#16103)
  • 6bceb84 📝 Update release notes
  • 5429fed ✨ Add app.frontend(check_dir="auto"), to make local development more conven...
  • 628663f 🔖 Release version 0.140.13 (#16096)
  • 0b54fd0 📝 Update release notes
  • Additional commits viewable in compare view

Updates uvicorn to 0.52.4

Release notes

Sourced from uvicorn's releases.

Version 0.52.4

Fixed

  • Remove duplicate Date headers from accepted WebSocket handshakes with websockets-sansio (#3078)

Full Changelog: Kludex/uvicorn@0.52.3...0.52.4

Changelog

Sourced from uvicorn's changelog.

0.52.4 (August 18, 2026)

Fixed

  • Remove duplicate Date headers from accepted WebSocket handshakes with websockets-sansio (#3078)

0.52.3 (August 13, 2026)

Changed

  • Update zttp to 0.0.24 and use its combined receive path, improving HTTP/1.1 request parsing performance (#3067)

0.52.2 (August 13, 2026)

Fixed

  • Update zttp to 0.0.22, fixing bodyless request receives and improving HTTP/1 request parsing performance (#3063)

0.52.1 (August 1, 2026)

Fixed

  • Complete the closing handshake on server-initiated WebSocket closes in the websockets-sansio and wsproto implementations, waiting for the client's close reply with a 10 second timeout instead of resetting the connection (#3053)
  • Add missing write flow control to the websockets-sansio implementation, preventing data truncation on server-initiated closes with large in-flight payloads (#3048)
  • Handle connection loss while a WebSocket write is waiting on backpressure (#3050)
  • Remove duplicate Content-Type and Content-Length headers from WebSocket denial responses on the websockets-sansio implementation, and deliver non-UTF-8 denial bodies intact (#3041)

0.52.0 (July 29, 2026)

This release adds an experimental HTTP/1.1 implementation backed by zttp, a sans-IO HTTP parser I've been developing on the side: a core written in Zig, with bindings to Python. It has been running under a fuzzer for some weeks now, and has been through multiple rounds of security auditing.

It is still experimental, so don't put it in front of production traffic yet. Try it with --http zttp, and please send any feedback to the issue tracker.

Added

  • Add an experimental zttp HTTP/1.1 implementation, selectable with --http zttp (#2979)

Fixed

  • Keep non-ASCII WebSocket request headers intact with websockets 17.0, which encodes them with ISO-8859-1 (#3036)

0.51.0 (July 8, 2026)

Added

  • Restart workers one at a time on SIGHUP, bringing each replacement up before retiring the old worker, so reloads no longer drop requests (#3025)

Removed

  • Remove colorama from the standard extra (#3027)

... (truncated)

Commits

Updates streamlit to 1.62.0

Release notes

Sourced from streamlit's releases.

1.62.0

What's Changed

Breaking Changes 🛠

New Features 🎉

Bug Fixes 🐛

Other Changes

... (truncated)

Commits
  • 5a6be2b Up version to 1.62.0
  • 576fcde [fix] date_input and datetime_input overflow styling in narrow containers...
  • 5261cd8 [fix] Restore metric sparkline after empty chart data (#16543)
  • 3bea909 [feature] Add wrap parameter to st.multiselect (#16509)
  • 98b2ff8 [refactor] Use Starlette 1.5 native gzip media/range handling (#16462)
  • 54435f1 Remove BaseWeb and related dependencies (#16514)
  • 96dae80 [feature] Add in-error install-skills callout (#15693)
  • ae7786d Add TimeField to DateTimeInput calendar popover (#16502)
  • 72385a2 [spec] Add type="step" for st.expander and st.status (#14875)
  • 653c13e Bump ruff from 0.16.2 to 0.16.3 in the python-ruff group (#16552)
  • Additional commits viewable in compare view

Updates altair to 6.2.2

Release notes

Sourced from altair's releases.

Version 6.2.2

What's Changed

Bug Fixes

Documentation

Maintenance

New Contributors

Full Changelog: vega/altair@v6.2.1...v6.2.2

Commits
  • a976571 fix: Include layered concat views in selection params (#4069)
  • 432157b fix: Avoid layered concat view name collisions (#4066)
  • b875b95 docs: Fix a broken example and sync another one with VL (#4010)
  • 7b289f9 ci: Enable partial Python 3.14t coverage (#4038)
  • 105ff2b docs: Validate docs publish clone (#4064)
  • c82dd2e ci: Disambiguate workflow naming (#4063)
  • 624bee9 docs: Add an interactive bin-size example to the gallery (#4050)
  • 3b1acf6 docs: Add an Andrews curves example to the gallery (#4049)
  • edea5f6 ci: Document how local versioning works and add base tag (#4051)
  • f8b4337 ci: Publish official docs after release is published (#4054)
  • Additional commits viewable in compare view

Updates requests to 2.34.2

Release notes

Sourced from requests's releases.

v2.34.2

2.34.2 (2026-05-14)

  • Moved headers input type back to Mapping to avoid invariance issues with MutableMapping and inferred dict types. Users calling Request.headers.update() may need to narrow typing in their code. (#7441)

Full Changelog: https://github.com/psf/requests/blob/main/HISTORY.md#2342-2026-05-14

Changelog

Sourced from requests's changelog.

2.34.2 (2026-05-14)

  • Moved headers input type back to Mapping to avoid invariance issues with MutableMapping and inferred dict types. Users calling Request.headers.update() may need to narrow typing in their code. (#7441)

2.34.1 (2026-05-13)

Bugfixes

  • Widened json input type from dict and list to Mapping and Sequence. (#7436)
  • Changed headers input type to MutableMapping and removed None from Request.headers typing to improve handling for users. (#7431)
  • Response.reason moved from str | None to str to improve handling for users. (#7437)
  • Fixed a bug where some bodies with custom __getattr__ implementations weren't being properly detected as Iterables. (#7433)

2.34.0 (2026-05-11)

Announcements

  • Requests 2.34.0 introduces inline types, replacing those provided by typeshed. Public API types should be fully compatible with mypy, pyright, and ty. We believe types are comprehensive but if you find issues, please report them to the pinned tracking issue.

    Special thanks to @​bastimeyer, @​cthoyt, @​edgarrmondragon, and @​srittau for helping review and test the types ahead of the release. (#7272)

Improvements

  • Digest Auth hashing algorithms have added usedforsecurity=False to clarify security considerations. (#7310)
  • Requests added support for Python 3.15 based on beta1. Downstream projects should be able to start testing prior to its release in October. (#7422)
  • Requests added support for Python 3.14t. (#7419)

Bugfixes

  • Response.history no longer contains a reference to itself, preventing accidental looping when traversing the history list. (#7328)
  • Requests no longer performs greedy matching on no_proxy domains. The proxy_bypass implementation has been updated with CPython's fix from bpo-39057. (#7427)
  • Requests no longer incorrectly strips duplicate leading slashes in URI paths. This should address user issues with specific presigned URLs. Note the full fix requires urllib3 2.7.0+. (#7315)

... (truncated)

Commits

Updates httpx to 0.28.1

Release notes

Sourced from httpx's releases.

Version 0.28.1

0.28.1 (6th December, 2024)

  • Fix SSL case where verify=False together with client side certificates.
Changelog

Sourced from httpx's changelog.

0.28.1 (6th December, 2024)

  • Fix SSL case where verify=False together with client side certificates.

0.28.0 (28th November, 2024)

Be aware that the default JSON request bodies now use a more compact representation. This is generally considered a prefered style, tho may require updates to test suites.

The 0.28 release includes a limited set of deprecations...

Deprecations:

We are working towards a simplified SSL configuration API.

For users of the standard verify=True or verify=False cases, or verify=<ssl_context> case this should require no changes. The following cases have been deprecated...

  • The verify argument as a string argument is now deprecated and will raise warnings.
  • The cert argument is now deprecated and will raise warnings.

Our revised SSL documentation covers how to implement the same behaviour with a more constrained API.

The following changes are also included:

  • The deprecated proxies argument has now been removed.
  • The deprecated app argument has now been removed.
  • JSON request bodies use a compact representation. (#3363)
  • Review URL percent escape sets, based on WHATWG spec. (#3371, #3373)
  • Ensure certifi and httpcore are only imported if required. (#3377)
  • Treat socks5h as a valid proxy scheme. (#3178)
  • Cleanup Request() method signature in line with client.request() and httpx.request(). (#3378)
  • Bugfix: When passing params={}, always strictly update rather than merge with an existing querystring. (#3364)

0.27.2 (27th August, 2024)

Fixed

  • Reintroduced supposedly-private URLTypes shortcut. (#2673)

0.27.1 (27th August, 2024)

Added

  • Support for zstd content decoding using the python zstandard package is added. Installable using httpx[zstd]. (#3139)

Fixed

  • Improved error messaging for InvalidURL exceptions. (#3250)
  • Fix app type signature in ASGITransport. (#3109)

0.27.0 (21st February, 2024)

... (truncated)

Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Aug 26, 2026
@Vanshcloud
Vanshcloud force-pushed the main branch 2 times, most recently from 78581f8 to ab76848 Compare August 26, 2026 12:45
@dependabot dependabot Bot changed the title build(deps): bump the web group with 6 updates build(deps): bump the web group across 1 directory with 6 updates Aug 26, 2026
@dependabot
dependabot Bot force-pushed the dependabot/pip/web-4d704b1b3b branch 2 times, most recently from 3110a1e to 29fa5b8 Compare August 26, 2026 17:21
@Vanshcloud
Vanshcloud self-requested a review as a code owner August 27, 2026 09:06
@dependabot
dependabot Bot force-pushed the dependabot/pip/web-4d704b1b3b branch from 29fa5b8 to 09ff162 Compare August 27, 2026 13:25
Updates the requirements on [fastapi](https://github.com/fastapi/fastapi), [uvicorn](https://github.com/Kludex/uvicorn), [streamlit](https://github.com/streamlit/streamlit), [altair](https://github.com/vega/altair), [requests](https://github.com/psf/requests) and [httpx](https://github.com/encode/httpx) to permit the latest version.

Updates `fastapi` to 0.141.1
- [Release notes](https://github.com/fastapi/fastapi/releases)
- [Commits](fastapi/fastapi@0.110.0...0.141.1)

Updates `uvicorn` to 0.52.4
- [Release notes](https://github.com/Kludex/uvicorn/releases)
- [Changelog](https://github.com/Kludex/uvicorn/blob/main/docs/release-notes.md)
- [Commits](Kludex/uvicorn@0.27.0...0.52.4)

Updates `streamlit` to 1.62.0
- [Release notes](https://github.com/streamlit/streamlit/releases)
- [Commits](streamlit/streamlit@1.49.0...1.62.0)

Updates `altair` to 6.2.2
- [Release notes](https://github.com/vega/altair/releases)
- [Commits](vega/altair@v5.0.0...v6.2.2)

Updates `requests` to 2.34.2
- [Release notes](https://github.com/psf/requests/releases)
- [Changelog](https://github.com/psf/requests/blob/main/HISTORY.md)
- [Commits](psf/requests@v2.31.0...v2.34.2)

Updates `httpx` to 0.28.1
- [Release notes](https://github.com/encode/httpx/releases)
- [Changelog](https://github.com/encode/httpx/blob/master/CHANGELOG.md)
- [Commits](encode/httpx@0.27.0...0.28.1)

---
updated-dependencies:
- dependency-name: altair
  dependency-version: 6.2.2
  dependency-type: direct:production
  dependency-group: web
- dependency-name: fastapi
  dependency-version: 0.141.1
  dependency-type: direct:production
  dependency-group: web
- dependency-name: httpx
  dependency-version: 0.28.1
  dependency-type: direct:development
  dependency-group: web
- dependency-name: requests
  dependency-version: 2.34.2
  dependency-type: direct:production
  dependency-group: web
- dependency-name: streamlit
  dependency-version: 1.62.0
  dependency-type: direct:production
  dependency-group: web
- dependency-name: uvicorn
  dependency-version: 0.52.4
  dependency-type: direct:production
  dependency-group: web
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/pip/web-4d704b1b3b branch from 09ff162 to fb24f43 Compare September 1, 2026 04:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants