chore(deps): update uvicorn requirement from <1,>=0.47.0 to >=0.48.0,<1#91
chore(deps): update uvicorn requirement from <1,>=0.47.0 to >=0.48.0,<1#91dependabot[bot] wants to merge 1 commit into
Conversation
Updates the requirements on [uvicorn](https://github.com/Kludex/uvicorn) to permit the latest version. - [Release notes](https://github.com/Kludex/uvicorn/releases) - [Changelog](https://github.com/Kludex/uvicorn/blob/main/docs/release-notes.md) - [Commits](Kludex/uvicorn@0.47.0...0.48.0) --- updated-dependencies: - dependency-name: uvicorn dependency-version: 0.48.0 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
|
Superseded by #94, which bundles this bump together with the other three open Dependabot PRs and regenerates |
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
Bundles the four open Dependabot PRs into a single release rather than landing them one-by-one with four lockfile-update follow-ups: - fastapi 0.136.1 -> 0.136.3 (#89) - uvicorn >=0.47 -> >=0.48 (#91) - idna >=3.15 -> >=3.16 (#90) - pytest-asyncio 1.3.0 -> 1.4.0 (#92, dev) While regenerating requirements.lock to clear those bumps, the resolver also pulls starlette from 0.52.1 to 1.1.0 -- this clears PYSEC-2026-161 (fix in 1.0.1), which the CI security gate had started reporting on every open Dependabot PR. fastapi 0.136.3 declares starlette>=0.46.0 with no upper bound, so the 1.x bump is in-range. Dependabot does not open PRs for undeclared transitives, hence the direct lockfile bump. Bumps __version__ to 0.19.3 and folds the [Unreleased] CHANGELOG block into a dated [0.19.3] release. No app-code or API changes. Test plan: - 222/222 pytest pass against the regenerated lockfile - ruff check app/ clean - bandit -r app/ -ll clean - pip-audit -r requirements.lock reports no known vulnerabilities Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Updates the requirements on uvicorn to permit the latest version.
Release notes
Sourced from uvicorn's releases.
Changelog
Sourced from uvicorn's changelog.
... (truncated)
Commits
73e84e5Version 0.48.0 (#2951)45ea116Ignore duplicate forwarding headers inProxyHeadersMiddleware(#2944)dd4394cchore(deps): bump idna from 3.11 to 3.15 (#2941)abe0781Defaultssl_cipherstoNoneand use OpenSSL defaults (#2940)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)