Skip to content

build(deps): bump the python-deps group across 3 directories with 6 updates - #583

Merged
aojea merged 1 commit into
mainfrom
dependabot/pip/cmd/chaos-agent/python-deps-68b621913f
Oct 6, 2026
Merged

aojea merged 1 commit into
mainfrom
dependabot/pip/cmd/chaos-agent/python-deps-68b621913f

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 6, 2026

Copy link
Copy Markdown
Contributor

Updates the requirements on openai, langchain, langchain-openai, sse-starlette, starlette and uvicorn to permit the latest version.
Updates openai to 3.20.0

Release notes

Sourced from openai's releases.

v3.20.0

3.20.0 (2026-09-28)

Features

  • api: add Agents credential and session options (#3967) (bb68198)
  • api: add Cyber access programs to Responses (#3956) (09c5b6f)
  • responses: opt in to incremental WebSocket text and tool snapshots (#3973) (d0207b4)
  • responses: preserve detailed WebSocket accumulator snapshots (#3981) (a380cf2)

Bug Fixes

  • client: retry unmapped TLS transport errors (#3982) (0d35a26)
  • live: avoid hangs at fractional transcript grouping deadlines (#3970) (4ef4129)
  • live: keep query parameters out of WebSocket endpoint paths (#3972) (f9c458b)
  • live: preserve caller queues and prevent uncertain WebSocket replay (#3980) (80e9686)
  • realtime: preserve base URL queries in WebSocket upgrades (#3971) (f7bd4a7)
  • realtime: retain configured queues without replaying attempted sends (#3978) (a52805c)

Chores

  • api: clarify documented API error responses (#3965) (384fee3)
  • api: document batch error responses (#3961) (6e4a79c)
  • api: document files and uploads error responses (#3960) (a9d727f)
  • api: document fine-tuning and model errors (#3964) (5d4003c)
  • api: document Responses not-found errors (#3959) (63099e7)
  • api: document stored chat completion errors (#3963) (a73fe0c)
Changelog

Sourced from openai's changelog.

3.20.0 (2026-09-28)

Features

  • api: add Agents credential and session options (#3967) (bb68198)
  • api: add Cyber access programs to Responses (#3956) (09c5b6f)
  • responses: opt in to incremental WebSocket text and tool snapshots (#3973) (d0207b4)
  • responses: preserve detailed WebSocket accumulator snapshots (#3981) (a380cf2)

Bug Fixes

  • client: retry unmapped TLS transport errors (#3982) (0d35a26)
  • live: avoid hangs at fractional transcript grouping deadlines (#3970) (4ef4129)
  • live: keep query parameters out of WebSocket endpoint paths (#3972) (f9c458b)
  • live: preserve caller queues and prevent uncertain WebSocket replay (#3980) (80e9686)
  • realtime: preserve base URL queries in WebSocket upgrades (#3971) (f7bd4a7)
  • realtime: retain configured queues without replaying attempted sends (#3978) (a52805c)

Chores

  • api: clarify documented API error responses (#3965) (384fee3)
  • api: document batch error responses (#3961) (6e4a79c)
  • api: document files and uploads error responses (#3960) (a9d727f)
  • api: document fine-tuning and model errors (#3964) (5d4003c)
  • api: document Responses not-found errors (#3959) (63099e7)
  • api: document stored chat completion errors (#3963) (a73fe0c)

3.19.2 (2026-09-23)

Bug Fixes

  • preserve single files for fallback extraction paths (#3875) (bfd3680)

Chores

  • api: clarify approximate web search location defaults (#3953) (a95c95e)
  • api: clarify Realtime modality array definitions (#3954) (e79cf53)
  • api: correct fine-tuning bounds and Realtime response reference (#3949) (325a948)

3.19.1 (2026-09-23)

Bug Fixes

  • chat: preserve single-pass tool iterables (#3770) (33ffa1f)

... (truncated)

Commits
  • 68b173a release: 3.20.0 (#3957)
  • 0d35a26 fix(client): retry unmapped TLS transport errors (#3982)
  • a380cf2 feat(responses): preserve detailed WebSocket accumulator snapshots (#3981)
  • 80e9686 fix(live): preserve caller queues and prevent uncertain WebSocket replay (#3980)
  • 78074d7 test(realtime): verify recovery boundaries and replacement credentials (#3979)
  • a52805c fix(realtime): retain configured queues without replaying attempted sends (#3...
  • a444e42 test: verify Live grouper disposal on a shared Python WebSocket (#3977)
  • d0207b4 feat(responses): opt in to incremental WebSocket text and tool snapshots (#3973)
  • 4ef4129 fix(live): avoid hangs at fractional transcript grouping deadlines (#3970)
  • f9c458b fix(live): keep query parameters out of WebSocket endpoint paths (#3972)
  • Additional commits viewable in compare view

Updates langchain to 1.4.3

Release notes

Sourced from langchain's releases.

langchain-fireworks==1.4.3

Changes since langchain-fireworks==1.4.2

release(fireworks): 1.4.3 chore: bump vcrpy from 8.1.1 to 8.2.1 in /libs/partners/fireworks (#38314) chore: bump langsmith from 0.8.16 to 0.8.18 in /libs/partners/fireworks (#38313) chore: bump langsmith from 0.8.14 to 0.8.16 in /libs/partners/fireworks (#38235) chore: bump pytest from 9.0.3 to 9.1.0 in /libs/partners/fireworks (#38233) chore(model-profiles): refresh model profile data (#38210) chore(model-profiles): refresh model profile data (#38191) chore(model-profiles): refresh model profile data (#38133) docs: refresh README installation and resources (#38119) release(core): 1.4.7 (#38111) fix(core,partners): rename package version trace metadata (#38110) style(core,langchain,langchain-classic,partners): replace double backticks in docstrings (#38095) chore: bump langsmith from 0.8.9 to 0.8.14 in /libs/partners/fireworks (#38093) release(core): 1.4.6 (#38061) feat(core,partners): add package version tracking to tracing metadata (#35295) chore(infra): bump mypy to 2.1 and unify type-check config across the monorepo (#36470) feat(standard-tests): validate tool call chunks during streaming (#34707) chore(partners): bump locks (#38052) hotfix(openai): min core dep (#37990) chore(model-profiles): refresh model profile data (#37973) chore(model-profiles): refresh model profile data (#37936) test(langchain,partners): disable pytest-benchmark under xdist to silence PytestBenchmarkWarning (#37901) fix(partners): cap aiohttp below 3.14 for vcrpy compat (#37898) chore(model-profiles): refresh model profile data (#37895) chore: bump aiohttp from 3.13.5 to 3.14.0 in /libs/partners/fireworks (#37882) chore: bump langsmith from 0.8.7 to 0.8.9 in /libs/partners/fireworks (#37883) chore: bump langsmith from 0.8.0 to 0.8.7 in /libs/partners/fireworks (#37781) chore: bump requests from 2.34.0 to 2.34.2 in /libs/partners/fireworks (#37782)

Commits
  • be854a1 release(langchain): 1.4.3 (#40888)
  • 2ade674 fix(langchain): sanitize cache settings for fallback models (#40886)
  • 88b9727 feat(fireworks): add prompt caching middleware (#38823)
  • 60e57f5 fix(fireworks): classify mid-stream read timeouts (#40874)
  • 42f04f4 docs: update OpenWiki (#40781)
  • 213f230 chore(model-profiles): refresh model profile data (#40869)
  • d750819 chore(model-profiles): refresh model profile data (#40833)
  • 1ef23d6 fix(anthropic): serialize invalid tool calls as tool use on replay (#40864)
  • 80b7409 feat(langchain): support Bedrock Mantle chat models in init_chat_model (#40...
  • 40fe8d6 docs(core): fix docstring examples that don't run as copied (#40815)
  • Additional commits viewable in compare view

Updates langchain-openai to 1.6.6

Release notes

Sourced from langchain-openai's releases.

langchain-openai==1.6.6

Changes since langchain-openai==1.6.5

release(openai): 1.6.6 (#40800) fix(openai): raise on error events in stream path (#40791)

Commits
  • 7622d3d release(openai): 1.6.6 (#40800)
  • 2dd956b docs(infra): fix AGENTS.md root setup guidance and package doc accuracy (#40794)
  • 49f4b40 fix(openai): raise on error events in stream path (#40791)
  • 19cadaa fix(core): abbreviate long tool IDs in XML buffer strings (#40792)
  • 798441e chore(anthropic): fix integration test cassette (#40790)
  • a476942 release(openai): 1.6.5 (#40787)
  • 46c6bdf release(anthropic): 1.7.4 (#40786)
  • 290daba fix(anthropic): add Opus 5.5 and GPT-6 profile augmentations (#40785)
  • 59baeb2 feat(anthropic,openai): mid-conversation tool changes on SystemMessage (#40...
  • 4b65996 chore(model-profiles): refresh model profile data (#40780)
  • Additional commits viewable in compare view

Updates sse-starlette to 3.5.0

Release notes

Sourced from sse-starlette's releases.

v3.5.0

Fixed

  • A stopped uvicorn server no longer cancels SSE streams of later servers in the same process (#211, regression since 3.1.1). Typical trigger: test suites starting a real server per test.

Behaviour change

  • AppStatus.should_exit is no longer set when sse-starlette detects uvicorn's own Server.should_exit (fallback path, e.g. uvicorn "module:app"). Streams still close on shutdown. If you read AppStatus.should_exit to detect shutdown, use shutdown_event instead.
  • A real SIGTERM/SIGINT still sets AppStatus.should_exit process-wide; see README "Testing" if your tests send real signals to an in-process server.

Upgrade note

  • If you called AppStatus.disable_automatic_graceful_drain() only to work around #211, remove it to get automatic stream draining back.

What's Changed

Full Changelog: sysid/sse-starlette@v3.4.11...v3.5.0

Commits
  • 1705b2d Bump version to 3.5.0
  • 16179fd Merge pull request #212 from sysid/fix/issue211
  • 3821353 fix(shutdown): re-resolve uvicorn server on every watcher poll
  • 6925c68 fix(tests): import httpx2 instead of removed httpx dependency
  • aa3b89e build(deps): bump starlette to 1.7.0 for anyio BlockingPortal deprecation
  • 329a72c build(deps): bump anyio, autobahn, setuptools for security advisories
  • d43a29f test(experimentation): assert consumer line counts in main thread
  • 96afe01 fix(shutdown): stop latching AppStatus.should_exit from uvicorn state
  • See full diff in compare view

Updates starlette to 1.7.0

Release notes

Sourced from starlette's releases.

Version 1.7.0

This release adds experimental OpenTelemetry tracing, HTTP QUERY support, and response trailers in TestClient. Starlette now requires AnyIO 4.

[!WARNING] OpenTelemetryMiddleware is experimental. Its API and emitted telemetry may change in minor releases without a deprecation period.

Added

  • Add experimental OpenTelemetryMiddleware for HTTP server spans, with URL exclusions and custom tracer providers #3438, #3463, and #3520.
  • Expose the matched route through scope["route"] #3438.
  • Support the QUERY HTTP method in HTTPEndpoint, CORS, and OpenAPI 3.2 schema generation #3489.
  • Capture HTTP response trailers in TestClient and expose them through response.extensions["http.response.trailers"] #3563.
  • Support partitioned cookies in SessionMiddleware #3510.
  • Add partitioned to Response.delete_cookie() on Python 3.14 and later #3376.
  • Support IPv6 hosts in TrustedHostMiddleware and TestClient #3471.
  • Support Python 3.15 #3508.

Changed

  • Require anyio>=4.0.0,<5, dropping support for AnyIO 3 #3512.
  • Raise WebSocketDisconnected, a RuntimeError subclass, for disconnected WebSocket operations #2767.
  • Accept Collection[str] in CORSMiddleware configuration annotations, including sets and frozensets #3518.

Fixed

  • Run background tasks only after the response is sent when using BaseHTTPMiddleware #3476.
  • Return 400 for invalid multipart parser input #3492.
  • Include Vary: Origin on all normal CORS responses and vary preflight responses by all request headers that affect them #3516 and #3517.
  • Handle malformed Host headers and IPv6 authorities consistently across URL construction, host routing, and redirect middleware #3472.
  • Ignore Range headers when FileResponse has a status other than 200, preserving its status and full body #3568.
  • Handle standalone If-None-Match: * in StaticFiles #3201.
  • Reject WebSocket requests to StaticFiles without raising an assertion error #3532.
  • Persist session mutations made with popitem() and |= #3436.
  • Handle empty and absent payloads in WebSocketEndpoint.decode() #3372.
  • Implement identity on SimpleUser and UnauthenticatedUser #3271.
  • Allow HTTPException to use non-standard status codes without an explicit detail #3545.
  • Avoid deprecated AnyIO imports in TestClient and add explicit imports in WSGIMiddleware for AnyIO 4.15 compatibility #3498 and #3501.
  • Offload debug traceback rendering to a worker thread in ServerErrorMiddleware #2858.

Full changelog: 1.6.0...1.7.0

Changelog

Sourced from starlette's changelog.

1.7.0 (September 23, 2026)

This release adds experimental OpenTelemetry tracing and requires AnyIO 4.

!!! warning "OpenTelemetryMiddleware is experimental" Its API and emitted telemetry may change in minor releases without a deprecation period #3574.

Added

  • Add experimental OpenTelemetryMiddleware for HTTP server spans, with URL exclusions and custom tracer providers #3438, #3463, and #3520.
  • Expose the matched route through scope["route"] #3438.
  • Support the QUERY HTTP method in HTTPEndpoint, CORS, and OpenAPI 3.2 schema generation #3489.
  • Capture HTTP response trailers in TestClient and expose them through response.extensions["http.response.trailers"] #3563.
  • Support partitioned cookies in SessionMiddleware #3510.
  • Add partitioned to Response.delete_cookie() on Python 3.14 and later #3376.
  • Support IPv6 hosts in TrustedHostMiddleware and TestClient #3471.
  • Support Python 3.15 #3508.

Changed

  • Require anyio>=4.0.0,<5, dropping support for AnyIO 3 #3512.
  • Raise WebSocketDisconnected, a RuntimeError subclass, for disconnected WebSocket operations #2767.
  • Accept Collection[str] in CORSMiddleware configuration annotations, including sets and frozensets #3518.

Fixed

  • Run background tasks only after the response is sent when using BaseHTTPMiddleware #3476.
  • Return 400 for invalid multipart parser input #3492.
  • Include Vary: Origin on all normal CORS responses and vary preflight responses by all request headers that affect them #3516 and #3517.
  • Handle malformed Host headers and IPv6 authorities consistently across URL construction, host routing, and redirect middleware #3472.
  • Ignore Range headers when FileResponse has a status other than 200, preserving its status and full body #3568.
  • Handle standalone If-None-Match: * in StaticFiles #3201.
  • Reject WebSocket requests to StaticFiles without raising an assertion error #3532.
  • Persist session mutations made with popitem() and |= #3436.
  • Handle empty and absent payloads in WebSocketEndpoint.decode() #3372.
  • Implement identity on SimpleUser and UnauthenticatedUser #3271.
  • Allow HTTPException to use non-standard status codes without an explicit detail #3545.
  • Avoid deprecated AnyIO imports in TestClient and add explicit imports in WSGIMiddleware for AnyIO 4.15 compatibility #3498 and #3501.
  • Offload debug traceback rendering to a worker thread in ServerErrorMiddleware #2858.

1.6.0 (August 8, 2026)

Added

  • Add max_body_size to Starlette and route classes #3431.
  • Expose http.response.debug information via response extensions #3130.

1.5.1 (August 8, 2026)

... (truncated)

Commits
  • 2269e9a Version 1.7.0 (#3575)
  • 4fe55eb Preserve FileResponse status for range requests (#3568)
  • 1f08daf Mark OpenTelemetryMiddleware as experimental (#3574)
  • 57de5fa Support HTTP response trailers in TestClient (#3563)
  • 03f12b7 Allow HTTPException to use non-standard status codes (#3545)
  • 76fd00f Reject WebSocket requests to StaticFiles (#3532)
  • f03f65c docs: fix 'its not available' and 'This ensure' wording (#3526)
  • 485aca4 docs: the test client is built on httpx2, not httpx (#3525)
  • fd662b1 Implement identity on SimpleUser and UnauthenticatedUser (#3271)
  • 41db6a7 Stabilize CodSpeed upload buffer allocations (#3524)
  • Additional commits viewable in compare view

Updates uvicorn to 0.54.0

Release notes

Sourced from uvicorn's releases.

Version 0.54.0

📨 Send metadata after the response body

uvicorn 0.54.0 adds response trailers and 103 Early Hints to its experimental HTTP/2 implementation through zttp.

uv add uvicorn==0.54.0 "zttp>=0.0.34"
  • Send HTTP/2 response trailers (#3146). The ASGI http.response.trailers extension lets applications send metadata, such as checksums, after the response body. Clients must send TE: trailers to receive them. Multiple trailer messages are combined before completing the response.
  • HTTP/2 remains experimental and opt-in. Enable it with --http zttp --http2. Upgrade-based h2c and WebSockets over HTTP/2 remain unsupported.

💡 Hint at resources before the final response

  • Send 103 Early Hints over HTTP/2 (#3137). Applications can use the ASGI http.response.early_hint extension to send resource hints before the final response. Each supplied link becomes a separate Link header.

Full changelog: 0.53.0...0.54.0

Changelog

Sourced from uvicorn's changelog.

0.54.0 (September 24, 2026)

HTTP/2 support remains experimental. Install zttp>=0.0.34 and enable it with --http zttp --http2.

Added

  • Add HTTP/2 response trailers through the ASGI http.response.trailers extension. Clients must send TE: trailers to receive them (#3146)
  • Add HTTP/2 103 Early Hints through the ASGI http.response.early_hint extension (#3137)

0.53.0 (September 14, 2026)

This release adds experimental HTTP/2 support through zttp. Enable it with --http zttp --http2. Upgrade-based h2c and WebSockets over HTTP/2 are not supported.

Added

  • Add experimental HTTP/2 support through zttp (#2982, #3101)
  • Add support for zuvloop (#3104)

Fixed

  • Handle comma-separated, case-insensitive Connection: close tokens across HTTP implementations (#3103)
  • Trust IPv6 loopback in the default FORWARDED_ALLOW_IPS value (#3119)
  • Cancel the HTTP keep-alive timer when upgrading to WebSocket (#3107)

0.52.4 (August 18, 2026)

Fixed

  • Remove duplicate Date headers from accepted WebSocket handshakes with websockets-sansio (#3078)

0.52.3 (August 13, 2026)

Changed

  • Update zttp to 0.0.24 and use its combined receive path, improving HTTP/1.1 request parsing performance (#3067)

0.52.2 (August 13, 2026)

Fixed

  • Update zttp to 0.0.22, fixing bodyless request receives and improving HTTP/1 request parsing performance (#3063)

0.52.1 (August 1, 2026)

Fixed

  • Complete the closing handshake on server-initiated WebSocket closes in the websockets-sansio and wsproto implementations, waiting for the client's close reply with a 10 second timeout instead of resetting the connection (#3053)
  • Add missing write flow control to the websockets-sansio implementation, preventing data truncation on server-initiated closes with large in-flight payloads (#3048)
  • Handle connection loss while a WebSocket write is waiting on backpressure (#3050)

... (truncated)

Commits

Updates sse-starlette to 3.5.0

Release notes

Sourced from sse-starlette's releases.

v3.5.0

Fixed

  • A stopped uvicorn server no longer cancels SSE streams of later servers in the same process (#211, regression since 3.1.1). Typical trigger: test suites starting a real server per test.

Behaviour change

  • AppStatus.should_exit is no longer set when sse-starlette detects uvicorn's own Server.should_exit (fallback path, e.g. uvicorn "module:app"). Streams still close on shutdown. If you read AppStatus.should_exit to detect shutdown, use shutdown_event instead.
  • A real SIGTERM/SIGINT still sets AppStatus.should_exit process-wide; see README "Testing" if your tests send real signals to an in-process server.

Upgrade note

  • If you called AppStatus.disable_automatic_graceful_drain() only to work around #211, remove it to get automatic stream draining back.

What's Changed

Full Changelog: sysid/sse-starlette@v3.4.11...v3.5.0

Commits
  • 1705b2d Bump version to 3.5.0
  • 16179fd Merge pull request #212 from sysid/fix/issue211
  • 3821353 fix(shutdown): re-resolve uvicorn server on every watcher poll
  • 6925c68 fix(tests): import httpx2 instead of removed httpx dependency
  • aa3b89e build(deps): bump starlette to 1.7.0 for anyio BlockingPortal deprecation
  • 329a72c build(deps): bump anyio, autobahn, setuptools for security advisories
  • d43a29f test(experimentation): assert consumer line counts in main thread
  • 96afe01 fix(shutdown): stop latching AppStatus.should_exit from uvicorn state
  • See full diff in compare view

Updates starlette to 1.7.0

Release notes

Sourced from starlette's releases.

Version 1.7.0

This release adds experimental OpenTelemetry tracing, HTTP QUERY support, and response trailers in TestClient. Starlette now requires AnyIO 4.

[!WARNING] OpenTelemetryMiddleware is experimental. Its API and emitted telemetry may change in minor releases without a deprecation period.

Added

  • Add experimental OpenTelemetryMiddleware for HTTP server spans, with URL exclusions and custom tracer providers #3438, #3463, and #3520.
  • Expose the matched route through scope["route"] #3438.
  • Support the QUERY HTTP method in HTTPEndpoint, CORS, and OpenAPI 3.2 schema generation #3489.
  • Capture HTTP response trailers in TestClient and expose them through response.extensions["http.response.trailers"] #3563.
  • Support partitioned cookies in SessionMiddleware #3510.
  • Add partitioned to Response.delete_cookie() on Python 3.14 and later #3376.
  • Support IPv6 hosts in TrustedHostMiddleware and TestClient #3471.
  • Support Python 3.15 #3508.

Changed

  • Require anyio>=4.0.0,<5, dropping support for AnyIO 3 #3512.
  • Raise WebSocketDisconnected, a RuntimeError subclass, for disconnected WebSocket operations #2767.
  • Accept Collection[str] in CORSMiddleware configuration annotations, including sets and frozensets #3518.

Fixed

  • Run background tasks only after the response is sent when using BaseHTTPMiddleware #3476.
  • Return 400 for invalid multipart parser input #3492.
  • Include Vary: Origin on all normal CORS responses and vary preflight responses by all request headers that affect them #3516 and #3517.
  • Handle malformed Host headers and IPv6 authorities consistently across URL construction, host routing, and redirect middleware #3472.
  • Ignore Range headers when FileResponse has a status other than 200, preserving its status and full body #3568.
  • Handle standalone If-None-Match: * in StaticFiles #3201.
  • Reject WebSocket requests to StaticFiles without raising an assertion error #3532.
  • Persist session mutations made with popitem() and |= #3436.
  • Handle empty and absent payloads in WebSocketEndpoint.decode() #3372.
  • Implement identity on SimpleUser and UnauthenticatedUser #3271.
  • Allow HTTPException to use non-standard status codes without an explicit detail #3545.
  • Avoid deprecated AnyIO imports in TestClient and add explicit imports in WSGIMiddleware for AnyIO 4.15 compatibility #3498 and #3501.
  • Offload debug traceback rendering to a worker thread in ServerErrorMiddleware #2858.

Full changelog: 1.6.0...1.7.0

Changelog

Sourced from starlette's changelog.

1.7.0 (September 23, 2026)

This release adds experimental OpenTelemetry tracing and requires AnyIO 4.

!!! warning "OpenTelemetryMiddleware is experimental" Its API and emitted telemetry may change in minor releases without a deprecation period #3574.

Added

  • Add experimental OpenTelemetryMiddleware for HTTP server spans, with URL exclusions and custom tracer providers #3438, #3463, and #3520.
  • Expose the matched route through scope["route"] #3438.
  • Support the QUERY HTTP method in HTTPEndpoint, CORS, and OpenAPI 3.2 schema generation #3489.
  • Capture HTTP response trailers in TestClient and expose them through response.extensions["http.response.trailers"] #3563.
  • Support partitioned cookies in SessionMiddleware #3510.
  • Add partitioned to Response.delete_cookie() on Python 3.14 and later #3376.
  • Support IPv6 hosts in TrustedHostMiddleware and TestClient #3471.
  • Support Python 3.15 #3508.

Changed

  • Require anyio>=4.0.0,<5, dropping support for AnyIO 3 #3512.
  • Raise WebSocketDisconnected, a RuntimeError subclass, for disconnected WebSocket operations #2767.
  • Accept Collection[str] in CORSMiddleware configuration annotations, including sets and frozensets #3518.

Fixed

  • Run background tasks only after the response is sent when using BaseHTTPMiddleware #3476.
  • Return 400 for invalid multipart parser input #3492.
  • Include Vary: Origin on all normal CORS responses and vary preflight responses by all request headers that affect them #3516 and #3517.
  • Handle malformed Host headers and IPv6 authorities consistently across URL construction, host routing, and redirect middleware #3472.
  • Ignore Range headers when FileResponse has a status other than 200, preserving its status and full body #3568.
  • Handle standalone If-None-Match: * in StaticFiles #3201.
  • Reject WebSocket requests to StaticFiles without raising an assertion error #3532.
  • Persist session mutations made with popitem() and |= #3436.
  • Handle empty and absent payloads in WebSocketEndpoint.decode() #3372.
  • Implement identity on SimpleUser and UnauthenticatedUser #3271.
  • Allow HTTPException to use non-standard status codes without an explicit detail #3545.
  • Avoid deprecated AnyIO imports in TestClient and add explicit imports in WSGIMiddleware for AnyIO 4.15 compatibility #3498 and #3501.
  • Offload debug traceback rendering to a worker thread in ServerErrorMiddleware #2858.

1.6.0 (August 8, 2026)

Added

  • Add max_body_size to Starlette and route classes #3431.
  • Expose http.response.debug information via response extensions #3130.

1.5.1 (August 8, 2026)

... (truncated)

Commits

…pdates

Updates the requirements on [openai](https://github.com/openai/openai-python), [langchain](https://github.com/langchain-ai/langchain), [langchain-openai](https://github.com/langchain-ai/langchain), [sse-starlette](https://github.com/sysid/sse-starlette), [starlette](https://github.com/Kludex/starlette) and [uvicorn](https://github.com/Kludex/uvicorn) to permit the latest version.

Updates `openai` to 3.20.0
- [Release notes](https://github.com/openai/openai-python/releases)
- [Changelog](https://github.com/openai/openai-python/blob/main/CHANGELOG.md)
- [Commits](openai/openai-python@v3.18.0...v3.20.0)

Updates `langchain` to 1.4.3
- [Release notes](https://github.com/langchain-ai/langchain/releases)
- [Commits](langchain-ai/langchain@langchain==1.4.2...langchain==1.4.3)

Updates `langchain-openai` to 1.6.6
- [Release notes](https://github.com/langchain-ai/langchain/releases)
- [Commits](langchain-ai/langchain@langchain-openai==1.6.3...langchain-openai==1.6.6)

Updates `sse-starlette` to 3.5.0
- [Release notes](https://github.com/sysid/sse-starlette/releases)
- [Commits](sysid/sse-starlette@v3.4.11...v3.5.0)

Updates `starlette` to 1.7.0
- [Release notes](https://github.com/Kludex/starlette/releases)
- [Changelog](https://github.com/Kludex/starlette/blob/main/docs/release-notes.md)
- [Commits](Kludex/starlette@1.6.0...1.7.0)

Updates `uvicorn` to 0.54.0
- [Release notes](https://github.com/Kludex/uvicorn/releases)
- [Changelog](https://github.com/Kludex/uvicorn/blob/main/docs/release-notes.md)
- [Commits](Kludex/uvicorn@0.53.0...0.54.0)

Updates `sse-starlette` to 3.5.0
- [Release notes](https://github.com/sysid/sse-starlette/releases)
- [Commits](sysid/sse-starlette@v3.4.11...v3.5.0)

Updates `starlette` to 1.7.0
- [Release notes](https://github.com/Kludex/starlette/releases)
- [Changelog](https://github.com/Kludex/starlette/blob/main/docs/release-notes.md)
- [Commits](Kludex/starlette@1.6.0...1.7.0)

Updates `uvicorn` to 0.54.0
- [Release notes](https://github.com/Kludex/uvicorn/releases)
- [Changelog](https://github.com/Kludex/uvicorn/blob/main/docs/release-notes.md)
- [Commits](Kludex/uvicorn@0.53.0...0.54.0)

---
updated-dependencies:
- dependency-name: openai
  dependency-version: 3.20.0
  dependency-type: direct:production
  dependency-group: python-deps
- dependency-name: langchain
  dependency-version: 1.4.3
  dependency-type: direct:production
  dependency-group: python-deps
- dependency-name: langchain-openai
  dependency-version: 1.6.6
  dependency-type: direct:production
  dependency-group: python-deps
- dependency-name: sse-starlette
  dependency-version: 3.5.0
  dependency-type: direct:production
  dependency-group: python-deps
- dependency-name: starlette
  dependency-version: 1.7.0
  dependency-type: direct:production
  dependency-group: python-deps
- dependency-name: uvicorn
  dependency-version: 0.54.0
  dependency-type: direct:production
  dependency-group: python-deps
- dependency-name: sse-starlette
  dependency-version: 3.5.0
  dependency-type: direct:production
  dependency-group: python-deps
- dependency-name: starlette
  dependency-version: 1.7.0
  dependency-type: direct:production
  dependency-group: python-deps
- dependency-name: uvicorn
  dependency-version: 0.54.0
  dependency-type: direct:production
  dependency-group: python-deps
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Oct 6, 2026
@dependabot
dependabot Bot requested a review from aojea as a code owner October 6, 2026 06:33
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Oct 6, 2026
@aojea
aojea merged commit 92c2f8b into main Oct 6, 2026
19 checks passed
@dependabot
dependabot Bot deleted the dependabot/pip/cmd/chaos-agent/python-deps-68b621913f branch October 6, 2026 06:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant