Skip to content

build(deps): bump the python-dependencies group across 1 directory with 4 updates - #143

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/python-dependencies-c6af41c74a
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/python-dependencies-c6af41c74a

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 24, 2026 •

Copy link
Copy Markdown
Contributor

Updates the requirements on mcp, evdev, playwright and ruff to permit the latest version.
Updates mcp to 2.2.0

Release notes

Sourced from mcp's releases.

v2.2.0

pip install -U mcp. Docs: https://py.sdk.modelcontextprotocol.io/

A few defaults changed in this release. If you run a server or client on 2.x, skim these first:

Behaviour changes

HTTP client redirects are only followed within the endpoint's origin (#3397)

  • Client("https://..."), streamable_http_client and sse_client follow a redirect only if it stays on the same scheme, host and port (or upgrades http to https on the same host).
  • A redirect anywhere else is not followed: the call fails with MCPError and the session stays usable (an SSE connect fails with httpx2.HTTPStatusError). If that other URL is the server you meant, use it as the endpoint URL.
  • The follow_redirects setting on an httpx2.AsyncClient you pass in is no longer used for MCP requests, so you don't need it for the trailing-slash redirect any more.
  • The OAuth providers apply the same rule to their own requests.

Idle Streamable HTTP sessions now expire (legacy <=2025-11-25 spec( (#3395)

  • A stateful session with nothing in flight for 30 minutes is closed. The client's next request gets a 404 and it has to initialize again.
  • Clients that keep the GET stream open (the SDK's Client does) are not affected. Neither are stateless servers or 2026-07-28 connections.
  • A server also holds at most 10 000 sessions at once; beyond that, new sessions get a 503.
  • To turn either off: mcp.run(transport="streamable-http", session_idle_timeout=None, max_sessions=None) (also on streamable_http_app() and run_streamable_http_async()).

The OAuth client checks the authorization server's issuer on the legacy path too (#3398)

  • For servers without protected resource metadata, authorization server metadata whose issuer isn't the server's own origin is now rejected with OAuthFlowError: Authorization server metadata issuer mismatch. The protected-resource-metadata path has done this since 2.0.
  • A 403 that isn't an insufficient_scope challenge is returned to the caller instead of retried.
  • If protected resource metadata can't be fetched because of a 5xx/429, the flow now stops instead of falling back to the legacy endpoints.

Two new MCPDeprecationWarnings (#3435, #3447)

  • ClientCredentialsOAuthProvider / PrivateKeyJWTOAuthProvider without issuer=. Pass your authorization server's issuer URL; 3.0 will require it.
  • AuthSettings with resource_server_url set but validate_token_resource unset. Set it to True or False; 3.0 defaults it to True.
  • Both keep working as before in 2.x; this mostly matters if your tests turn warnings into errors.

New

  • AuthSettings.validate_token_resource: only accept tokens your TokenVerifier reports as issued for this server (#3447).
  • issuer= on ClientCredentialsOAuthProvider and PrivateKeyJWTOAuthProvider (#3398).
  • session_idle_timeout= and max_sessions= on the Streamable HTTP server entry points (#3395).

Fixes

  • A client DELETE frees its session immediately, and a refused opening request no longer leaves a session behind (#2455, #3228, #3300).
  • $refs in a tool's outputSchema resolve within that schema only; an unresolvable one surfaces as RuntimeError: Invalid schema for tool ... (#3394).

Known gaps

The tasks extension (SEP-2663), DPoP (SEP-1932) and the jwt-bearer grant are not implemented yet; https://github.com/modelcontextprotocol/python-sdk/blob/main/ROADMAP.md tracks them.

What's Changed

... (truncated)

Commits
  • 9972c21 Replace RootModel wrappers with type aliases and TypeAdapter validation (#3470)
  • fd66270 docs: refresh translations, and translate pages in parallel (#3458)
  • 08a3bc8 docs: ask for AI disclosure on comments too (#3459)
  • 7bb486a docs: stop presenting the in-memory client as the way to connect (#3443)
  • 0c91368 Add AuthSettings.validate_token_resource to check a bearer token's resource (...
  • 9771e6b Keep following a relative redirect when the endpoint URL carries userinfo (#3...
  • a925e55 Bump the locked versions of eight dev and test dependencies (#3449)
  • e8b9486 Bump pymdown-extensions from 11.0 to 11.0.1 (#3285)
  • c6762e8 Follow redirects only within the MCP endpoint's origin (#3397)
  • 5fd3abc Skip automatic docs previews for fork PRs and drop the setup-uv retry steps (...
  • Additional commits viewable in compare view

Updates evdev to 1.9.3

Changelog

Sourced from evdev's changelog.

1.9.3 (Feb 05, 2025)

  • Fix several memory leaks in input.c.

  • Raise the minimum supported Python version to 3.9 and the setuptools version to 77.0.

1.9.2 (May 01, 2025)

  • Add the "--reproducible" build option which removes the build date and used headers from the generated ecodes.c. Example usage::

    python -m build --config-setting=--build-option='build_ecodes --reproducible' -n

  • Use Generic to set precise type for InputDevice.path.

1.9.1 (Feb 22, 2025)

  • Fix for missing UI_FF constants in generated ecodes.py.

  • More type annotations.

1.9.0 (Feb 08, 2025)

  • Fix for CPATH/C_INCLUDE_PATH being ignored during build.

  • Slightly faster reading of events in device.read() and device.read_one().

  • Fix FreeBSD support.

  • Drop deprecated InputDevice.fn (use InputDevice.path instead).

  • Improve type hint coverage and add a py.typed file to the sdist.

1.8.0 (Jan 25, 2025)

  • Binary wheels are now provided by the evdev-binary <http://pypi.python.org/pypi/evdev-binary>_ package. The package is compiled on manylinux_2_28 against kernel 4.18.

  • The evdev.ecodes module is now generated at install time and contains only constants. This allows type checking and introspection of the evdev.ecodes module, without having to execute it first. The old module is available as evdev.ecodes_runtime. In case generation of the static ecodes.py fails, the

... (truncated)

Commits
  • a47b5b5 Bump version: 1.9.2 → 1.9.3
  • faf7bc9 Drop support for Python 3.8 and raise setuptools version to 77.0
  • fae2cf9 Use an SPDX license
  • 60c6392 CI fixes
  • 5227b16 Fix memory leaks
  • a5d8cf0 Bump version: 1.9.1 → 1.9.2
  • 8f45223 Use Generic to set precise type for InputDevice.path (#241)
  • 3bc969b s/reproducibility/reproducible
  • 6b4e8ef Add a reproducibility option for building ecodes.c (#242)
  • 5f9fd2c fix utils.categorize return type (#240)
  • Additional commits viewable in compare view

Updates playwright to 1.63.0

Release notes

Sourced from playwright's releases.

v1.63.0

🪟 Locate across frames

page.frame_locator() and frame.frame_locator() called without a selector search in any frame of the subtree, so you no longer need to locate the iframe first:

# Finds the button in any frame on the page.
page.frame_locator().get_by_role("button").click()

The rest of the locator resolves inside a single frame, just like a regular locator, and an error is thrown when it matches elements in several frames.

👁️ Visible-only locators

New locator.visible returns a locator that matches only visible elements. It is the recommended replacement for the :visible CSS pseudo-class:

page.locator("button").visible.click()

🖼️ Aria and screen snapshots in traces

New aria_snapshots and screen_snapshots options of tracing.start() capture an aria snapshot and a screenshot of the page on every action:

context.tracing.start(snapshots=True, aria_snapshots=True, screen_snapshots=True)

With aria and screen snapshots recorded, the new Display Aria mode in the trace viewer shows the action screenshot side by side with the aria snapshot, and hovering an aria node highlights it on the screenshot.

New APIs

Browser and Context

Command line

  • playwright install --no-remove keeps the browsers of other Playwright installations instead of removing them.
  • playwright codegen --http-credentials records against pages behind HTTP authentication.

Announcements

  • ⚠️ Ubuntu 20.04 is not supported anymore.
  • 🐧 On Linux arm64, Playwright now downloads the Chrome for Testing build of Chromium, the same build used on all other platforms.

... (truncated)

Commits
  • 8cb967b cherry-pick(#3200): devops(docker): move docker publishing to Azure Pipelines
  • ab18c77 chore: roll Playwright to 1.63.0 (#3198)
  • 0e66a09 devops(pipeline): resolve pip and npm packages from DevDiv_PublicPackages fee...
  • 010a9cc Pin GitHub Actions to full-length commit SHAs (#3176)
  • 154f67c fix(sync): wait for initialize before leaving enter (#3168)
  • 4af2fc6 chore: roll Playwright to 1.62.1 (#3169)
  • 4d2e058 fix(connection): register protocol callback only after successful send (#3167)
  • eab2bca chore(deps): remove unused development dependencies (#3164)
  • See full diff in compare view

Updates ruff to 0.16.8

Release notes

Sourced from ruff's releases.

0.16.8

Release Notes

Released on 2026-09-16.

Bug fixes

  • Visit functional TypedDict keyword arguments correctly (#28584)
  • [flake8-simplify] Detect nested async with under sync parent (SIM117) (#27821)
  • [flake8-simplify] Preserve operand order in SIM109 fix (#27824)
  • [pyupgrade] Preserve required parentheses in multiline UP040 fixes (#28164)
  • [pyupgrade] Skip TypeVarTuple and ParamSpec conversions with bounds or constraints (UP040, UP046, UP047) (#28505)

Rule changes

  • Add support for __lazy_modules__ (#28459)
  • Recognize PEP-728 TypedDict class keywords (#28533)
  • Recognize quoted types in typing.TypeForm (#28507)
  • Support conditional assignment to __lazy_modules__ (#28491)
  • [flake8-type-checking] Prefer lazy imports over TYPE_CHECKING on Python 3.15 and later (TC001, TC002, TC003) (#28541)
  • [pyupgrade] Make the fix for UP040 always unsafe (#28526)
  • [pyupgrade] Stop recommending deprecated ByteString aliases (UP035) (#28498)
  • [ruff, flake8-use-pathlib] Recognize the parent_mode argument (RUF064, PTH103) (#28528)
  • [ruff] Detect \Z in pytest.raises() match patterns (RUF043) (#28598)

CLI

  • Use rule name and code in formatter incompatibility warnings (#28571)

Configuration

  • [flake8-tidy-imports] Add extend-banned-api (#28644)

Contributors

Install ruff 0.16.8

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/ruff/releases/download/0.16.8/ruff-installer.sh | sh
</tr></table> 

... (truncated)

Changelog

Sourced from ruff's changelog.

0.16.8

Released on 2026-09-16.

Bug fixes

  • Visit functional TypedDict keyword arguments correctly (#28584)
  • [flake8-simplify] Detect nested async with under sync parent (SIM117) (#27821)
  • [flake8-simplify] Preserve operand order in SIM109 fix (#27824)
  • [pyupgrade] Preserve required parentheses in multiline UP040 fixes (#28164)
  • [pyupgrade] Skip TypeVarTuple and ParamSpec conversions with bounds or constraints (UP040, UP046, UP047) (#28505)

Rule changes

  • Add support for __lazy_modules__ (#28459)
  • Recognize PEP-728 TypedDict class keywords (#28533)
  • Recognize quoted types in typing.TypeForm (#28507)
  • Support conditional assignment to __lazy_modules__ (#28491)
  • [flake8-type-checking] Prefer lazy imports over TYPE_CHECKING on Python 3.15 and later (TC001, TC002, TC003) (#28541)
  • [pyupgrade] Make the fix for UP040 always unsafe (#28526)
  • [pyupgrade] Stop recommending deprecated ByteString aliases (UP035) (#28498)
  • [ruff, flake8-use-pathlib] Recognize the parent_mode argument (RUF064, PTH103) (#28528)
  • [ruff] Detect \Z in pytest.raises() match patterns (RUF043) (#28598)

CLI

  • Use rule name and code in formatter incompatibility warnings (#28571)

Configuration

  • [flake8-tidy-imports] Add extend-banned-api (#28644)

Contributors

0.16.7

Released on 2026-09-10.

Preview features

  • [ruff] Add rule for default values on method receivers (RUF077) (#26700)

... (truncated)

Commits
  • 62914c4 Bump version to 0.16.8 (#28648)
  • c47e0cd [ty] Bound aliased intersection expansion during inference (#28546)
  • ff4747b renovate: update uv hashes correctly with setup-uv (#28621)
  • 94efeaa [ty] Compact reachable binding and declaration histories (#28349)
  • 50020fb [ty] Avoid storing constraint nodes twice (#28375)
  • 446bb68 [ty] Compare bound-method receivers before signatures (#28384)
  • 304ab86 [flake8-type-checking] Prefer lazy imports over TYPE_CHECKING on 3.15+ (`...
  • d940b24 [ty] Watch script dependencies in CLI watch mode (#28125)
  • fe9f065 [flake8-tidy-imports] Add extend-banned-api (#28644)
  • 31131db [ty] Support type[A & B] (#27124)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Note

Bump mcp to 2.2.0, evdev to 1.9.3, playwright to 1.63.0, and ruff to 0.16.8

  • Raises minimum runtime versions for mcp (2.1.1 → 2.2.0), evdev on Linux (1.7.0 → 1.9.3), and playwright (1.62.0 → 1.63.0) in pyproject.toml
  • Raises dev dependency ruff from 0.16.6 to 0.16.8
  • Existing upper bounds and platform markers are unchanged
  • Behavioral Change: dependency resolution now requires the new minimums; environments pinned below them will need to upgrade
📊 Macroscope summarized 909c249. 1 file reviewed, 1 issue evaluated, 0 issues filtered, 1 comment posted

🗂️ Filtered Issues

…th 4 updates

Updates the requirements on [mcp](https://github.com/modelcontextprotocol/python-sdk), [evdev](https://github.com/gvalkov/python-evdev), [playwright](https://github.com/microsoft/playwright-python) and [ruff](https://github.com/astral-sh/ruff) to permit the latest version.

Updates `mcp` to 2.2.0
- [Release notes](https://github.com/modelcontextprotocol/python-sdk/releases)
- [Changelog](https://github.com/modelcontextprotocol/python-sdk/blob/main/RELEASE.md)
- [Commits](modelcontextprotocol/python-sdk@v2.1.1...v2.2.0)

Updates `evdev` to 1.9.3
- [Changelog](https://github.com/gvalkov/python-evdev/blob/main/docs/changelog.rst)
- [Commits](gvalkov/python-evdev@v1.7.0...v1.9.3)

Updates `playwright` to 1.63.0
- [Release notes](https://github.com/microsoft/playwright-python/releases)
- [Commits](microsoft/playwright-python@v1.62.0...v1.63.0)

Updates `ruff` to 0.16.8
- [Release notes](https://github.com/astral-sh/ruff/releases)
- [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md)
- [Commits](astral-sh/ruff@0.16.6...0.16.8)

---
updated-dependencies:
- dependency-name: mcp
  dependency-version: 2.2.0
  dependency-type: direct:production
  dependency-group: python-dependencies
- dependency-name: evdev
  dependency-version: 1.9.3
  dependency-type: direct:production
  dependency-group: python-dependencies
- dependency-name: playwright
  dependency-version: 1.63.0
  dependency-type: direct:production
  dependency-group: python-dependencies
- dependency-name: ruff
  dependency-version: 0.16.8
  dependency-type: direct:development
  dependency-group: python-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Sep 24, 2026
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Sep 24, 2026
@coderabbitai

coderabbitai Bot commented Sep 24, 2026

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository: leandre755/gui_agent/.coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: c923de85-f8a0-47a1-b9f2-dc134ad08138

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@greptile-apps

greptile-apps Bot commented Sep 24, 2026

Copy link
Copy Markdown

PR author is in the excluded authors list.

@github-actions

Copy link
Copy Markdown

Governance summary

  • PR title: pass
  • Commit messages: pass
  • Size: pass (8 changed lines)
  • Sensitive automation files changed: no

Branch protection and CODEOWNERS must enforce approval for sensitive paths.

Comment thread pyproject.toml
"evdev>=1.7.0; sys_platform == 'linux'",
"playwright>=1.62.0",
"evdev>=1.9.3; sys_platform == 'linux'",
"playwright>=1.63.0",

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟠 High pyproject.toml:48

uv.lock still pins playwright 1.62.0 and ruff 0.16.7 and retains the old root requires-dist constraints, so uv sync --locked and uv run --locked reject this repository as out of date while --frozen workflows continue using versions excluded by pyproject.toml. Regenerate uv.lock after raising these lower bounds.

🚀 Reply "fix it for me" or copy this AI Prompt for your agent:
In file @pyproject.toml around line 48:

`uv.lock` still pins `playwright` 1.62.0 and `ruff` 0.16.7 and retains the old root `requires-dist` constraints, so `uv sync --locked` and `uv run --locked` reject this repository as out of date while `--frozen` workflows continue using versions excluded by `pyproject.toml`. Regenerate `uv.lock` after raising these lower bounds.

Evidence trail:
Reviewed commit 909c249: `pyproject.toml:48,53`; `uv.lock:694-711,1623-1626,2425-2428`. uv documentation: https://docs.astral.sh/uv/concepts/projects/sync/ (locked mode errors for stale metadata; frozen mode skips the check).

@macroscopeapp

macroscopeapp Bot commented Sep 24, 2026

Copy link
Copy Markdown

Approvability

Verdict: Not approved

Macroscope's review found this PR not approvable — This one-file dependency update changes production MCP, evdev, and Playwright floors, including MCP behavior affecting redirects, sessions, and authentication. The associated uv.lock remains stale for locked workflows, and the packaging file is owned by repository maintainers rather than the automated author.

Not approved because:

  • 1 blocking correctness issue found at or above your repo's Minimum Blocking Severity

Adjust the Minimum Blocking Severity for this repo — including turning it Off — in Settings. You can add or adjust custom eligibility rules. Learn more.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants