Skip to content

MESH-2092 py dev (deps): Bump the patch-and-minor group across 1 directory with 26 updates - #346

Closed
dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/pip/patch-and-minor-2c1a13674d
Closed

dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/pip/patch-and-minor-2c1a13674d

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the patch-and-minor group with 26 updates in the / directory:

Package From To
urllib3 2.7.0 2.8.0
nhs-aws-helpers 0.8.45 0.8.82
aws-lambda-powertools 3.34.0 3.35.0
boto3 1.43.58 1.43.104
mypy 2.3.0 2.3.1
coverage 7.15.4 7.16.2
moto 5.2.2 5.2.3
boto3-stubs 1.43.36 1.43.104
ruff 0.16.3 0.16.9
tox 4.60.0 4.64.4
botocore 1.43.71 1.43.104
charset-normalizer 3.5.0 3.5.1
idna 3.18 3.20
mypy-boto3-backup 1.43.66 1.43.78
mypy-boto3-cloudwatch 1.43.54 1.43.102
mypy-boto3-ecs 1.43.65 1.43.93
mypy-boto3-events 1.43.0 1.43.102
mypy-boto3-glue 1.43.70 1.43.104
mypy-boto3-healthlake 1.43.67 1.43.83
mypy-boto3-lambda 1.43.60 1.43.91
mypy-boto3-logs 1.43.66 1.43.82
mypy-boto3-s3 1.43.66 1.43.93
mypy-boto3-sns 1.43.23 1.43.97
mypy-boto3-ssm 1.43.53 1.43.104
mypy-boto3-stepfunctions 1.43.7 1.43.88
mypy-boto3-sts 1.43.0 1.43.94

Updates urllib3 from 2.7.0 to 2.8.0

Release notes

Sourced from urllib3's releases.

2.8.0

🚀 urllib3 is fundraising for HTTP/2 support

urllib3 is raising ~$40,000 USD to release HTTP/2 support and ensure long-term sustainable maintenance of the project. If your company or organization uses Python and would benefit from HTTP/2 support in Requests, pip, cloud SDKs, and thousands of other projects please consider contributing financially to ensure HTTP/2 support is developed sustainably and maintained for the long-haul.

Thank you for your support.

Security

Fixed the following security issues:

  • The TLS configuration for HTTPS proxies could be ignored or overridden. (High severity, GHSA-8988-9cw3-xx77)
  • HTTPResponse.stream() and read_chunked() could buffer a chunk-size line of unbounded length in memory. (High severity, GHSA-vxq7-64xx-v4gw)
  • Chunked Deflate streaming could enter an infinite loop. (Medium severity, GHSA-gh4c-6fx4-qh6g)

[!IMPORTANT] urllib3 2.8.0 fixes HTTPS proxy TLS configuration being ignored or overridden by destination settings. Configurations relying on that behavior may require changes.

Configure proxy CA certificates and client certificates in proxy_ssl_context, and proxy identity checks with proxy_assert_hostname or proxy_assert_fingerprint. Destination client certificates and identity overrides no longer apply to HTTPS forwarding proxy connections.

[!NOTE] CVE IDs had not yet been assigned to these advisories at the time of release due to a backlog at GitHub's CNA.

Deprecations & Removals

  • Deprecated using an empty collection as the Retry option allowed_methods to retry any verb. (#5044)

Features

  • Added Url.auth_decoded and Url.auth_decoded_joined convenience properties to the result of parse_url(). (#4945)
  • Added basic_auth_encoding and proxy_basic_auth_encoding parameters to urllib3.util.make_headers(). (#5092)

Bugfixes

  • Fixed response header handling to replace obsolete folded header lines (obs-fold) with spaces in accordance with RFC 9112, preventing raw CRLF sequences from appearing in header values such as Set-Cookie. (#1362)

  • Fixed usage of proxy_ssl_context with ProxyManager when use_forwarding_for_https=True. Passing ssl_context instead of proxy_ssl_context for HTTPS proxies in this configuration now emits a FutureWarning and will raise an error in v3.0. (#2577)

  • Changed behavior of the default ConnectionPool.pool initialization. LifoQueue is now resolved from the queue module after the ConnectionPool is instantiated instead of using the default cached QueueCls class property. This is done because sometimes the queue.LifoQueue is monkey-patched late in the program, such as by gevent. (#3289)

  • Raised UnrewindableBodyError instead of ValueError when retrying a request whose body had tell() but not seek(). (#3779)

  • Decoded percent-encoded SOCKS proxy credentials before authenticating with the proxy server. (#3785)

  • Fixed HTTPResponse.drain_conn() to discard unread response data in 64 KiB chunks (same as the default amt when doing HTTPResponse.stream(...)). (#5019)

  • Fixed is_ipaddress() to detect non-standard IPv4 forms accepted by socket.connect, such as hex (0x7f000001), octal (0177.0.0.1), and decimal integers (2130706433), ensuring SSL certificate verification uses the correct mode for these addresses. (#5029)

  • Fixed HTTPConnectionPool.urlopen raising a misleading FullPoolError instead of ValueError when called with an invalid timeout argument on a pool created with block=True. (#5059)

  • Fixed port-zero handling to preserve explicit :0 values instead of substituting the default ports 80 or 443 in URL parsing, pool selection, proxy configuration, connection_from_url(), and HTTP/2 request authority. (#5071, #5101)

  • Fixed a bug where PoolManager passed the assert_hostname and assert_fingerprint parameters to HTTP connection pools. (#5077)

  • Fixed HTTPConnectionPool.urlopen() and HTTP proxy forwarding to strip URL fragments from absolute request targets before sending requests. (#5079)

  • Added safeguards to the proxy tunneling code to prevent potential security issues when handling invalid characters in the proxy host and HTTP headers. This change affects users of Python 3.10, Python 3.11, and Python 3.12 when the standard library does not contain the fix; those on newer Python versions should upgrade to 3.13.14+ or 3.14.5+ to get the same security fixes. (#5091)

  • Fixed HTTPSConnection.connect() overriding ProxyConfig.ssl_context's certificate policy and proxy identity checks with the target connection's TLS settings when forwarding through an HTTPS proxy.

    HTTPSConnection no longer applies target SNI, assertions, or client credentials to forwarding proxy handshakes and continues to use its ssl_context as a fallback when an HTTPS proxy forwards an HTTP target. (#5093)

  • Fixed URL parsing to more strictly enforce RFC 3986 host syntax, rejecting invalid host input such as raw spaces and control characters, malformed percent-encodings, and percent-encoded control characters in HTTP(S) hosts and IPv6 zone identifiers, including proxy CONNECT tunnel targets. Host normalization now also follows RFC 3986 normalization rules for percent-encoded octets by decoding percent-encoded unreserved characters and uppercasing the hexadecimal digits of retained percent-encoded octets. (#5095)

... (truncated)

Changelog

Sourced from urllib3's changelog.

2.8.0 (2026-09-15)

Security

Fixed the following security issues:

  • The TLS configuration for HTTPS proxies could be ignored or overridden. (High severity, GHSA-8988-9cw3-xx77 <https://github.com/urllib3/urllib3/security/advisories/GHSA-8988-9cw3-xx77>__)
  • HTTPResponse.stream() and read_chunked() could buffer a chunk-size line of unbounded length in memory. (High severity, GHSA-vxq7-64xx-v4gw <https://github.com/urllib3/urllib3/security/advisories/GHSA-vxq7-64xx-v4gw>__)
  • Chunked Deflate streaming could enter an infinite loop. (Medium severity, GHSA-gh4c-6fx4-qh6g <https://github.com/urllib3/urllib3/security/advisories/GHSA-gh4c-6fx4-qh6g>__)

.. caution::

urllib3 2.8.0 fixes HTTPS proxy TLS configuration being ignored or
overridden by destination settings. Configurations relying on that
behavior may require changes.

Configure proxy CA certificates and client certificates in proxy_ssl_context, and proxy identity checks with proxy_assert_hostname or proxy_assert_fingerprint. Destination client certificates and identity overrides no longer apply to HTTPS forwarding proxy connections.

Deprecations & Removals

  • Deprecated using an empty collection as the Retry option allowed_methods to retry any verb. ([#5044](https://github.com/urllib3/urllib3/issues/5044) <https://github.com/urllib3/urllib3/issues/5044>__)

Features

  • Added Url.auth_decoded and Url.auth_decoded_joined convenience properties to the result of parse_url(). ([#4945](https://github.com/urllib3/urllib3/issues/4945) <https://github.com/urllib3/urllib3/issues/4945>__)
  • Added basic_auth_encoding and proxy_basic_auth_encoding parameters to urllib3.util.make_headers(). ([#5092](https://github.com/urllib3/urllib3/issues/5092) <https://github.com/urllib3/urllib3/issues/5092>__)

Bugfixes

... (truncated)

Commits
  • b1d30ab Release 2.8.0
  • 9016d7e Skip test_read_chunked_with_trailing_data_does_not_hang for brotlicffi (#5258)
  • 9101f58 Fix nox -s docs warning (#5256)
  • cd770b0 Merge commit from fork
  • ea2ad7b Merge commit from fork
  • 0716e31 Fix loading unencrypted client keys with a password in pyOpenSSL (#5255)
  • 43c68c8 Test pickling of InvalidChunkLength (#5247)
  • 308b279 Share security policy between GitHub and Read the Docs (#5253)
  • 53fa073 Add policy on duplicate pull requests (#5252)
  • 5f2a6a8 Assert on the ALPN extension in test_tunnel_sets_http_11_alpn (#5232)
  • Additional commits viewable in compare view

Updates nhs-aws-helpers from 0.8.45 to 0.8.82

Commits

Updates aws-lambda-powertools from 3.34.0 to 3.35.0

Release notes

Sourced from aws-lambda-powertools's releases.

v3.35.0

Summary

This release includes an important security improvement for Data Masking and a significant cold start optimization for Parser.

We are happy to welcome six new contributors in this release: @​Adityaj0, @​manshahH, @​ErezMizrahi, @​wuodar, @​MohammedAlkindi, and @​TanbirRamim. Thank you for taking the time to report problems, work through reviews, and improve the prokject.

Data Masking now fails closed

Previously, an error while applying a masking rule could emit a warning and return the original value unchanged. Since callers received a normal return value, they could continue logging or storing data believing that masking had succeeded.

Data Masking now raises DataMaskingError when a masking provider fails, a masking path is invalid, or a regular expression cannot be compiled. Existing Data Masking exceptions now inherit from this common base exception.

from aws_lambda_powertools.utilities.data_masking import DataMasking
from aws_lambda_powertools.utilities.data_masking.exceptions import DataMaskingError
data_masker = DataMasking()
try:
masked = data_masker.erase(
{"customer": {"email": "customer@example.com"}},
masking_rules={"customer.email": {"regex_pattern": "[", "mask_format": "*"}},
)
except DataMaskingError:
# Stop processing the payload when masking cannot be completed.
raise

Missing fields continue to follow the existing raise_on_missing_field setting. With its default value, a missing field raises DataMaskingFieldNotFoundError; when explicitly disabled, Data Masking emits a warning and continues.

See #8446 for the complete change.

Faster Parser imports

Importing parse or event_parser previously loaded all 16 Parser envelope modules, even when the application did not use an envelope.

Envelopes and BaseEnvelope are now loaded only when first accessed. Existing public imports continue to work, so no application changes are required.

In the Lambda benchmark contributed in #8405, this reduced INIT_DURATION by approximately 900ms on arm64 with Python 3.13 and 1024MB of memory. The exact improvement depends on the function and packaging configuration.

Thank you @​ErezMizrahi for finding this and working through the compatibility details with us.

Changes

... (truncated)

Changelog

Sourced from aws-lambda-powertools's changelog.

[v3.35.0] - 2026-09-15

Maintenance

  • version bump
  • deps: bump valkey-glide from 2.5.1 to 2.5.2 (#8459)

Commits
  • 4770746 chore: version bump
  • d7d5168 chore(deps): bump valkey-glide from 2.5.1 to 2.5.2 (#8459)
  • 440e3ec chore(deps-dev): bump cdklabs-generative-ai-cdk-constructs from 0.1.318 to 0....
  • 226f384 chore(deps-dev): bump types-python-dateutil from 2.9.0.20260518 to 2.9.0.2026...
  • b712d3c chore(deps): bump aws-encryption-sdk from 4.0.6 to 4.0.7 (#8460)
  • a5b8045 chore(deps): bump avro from 1.12.1 to 1.12.2 (#8462)
  • 94b9d5e fix(metrics): stop spurious overwrite warnings from set_default_dimensions (#...
  • 14af77f chore(feature_flags): warn on empty schema and empty rules (#8430)
  • 362a797 fix(event_handler): match generic alias response models in OpenAPI schema (#8...
  • 237f4db fix(feature_flags): missing context key never satisfies a condition (#8429)
  • Additional commits viewable in compare view

Updates boto3 from 1.43.58 to 1.43.104

Commits
  • ca37987 Merge branch 'release-1.43.104'
  • c468e3d Bumping version to 1.43.104
  • f2d1bac Add changelog entries from botocore
  • 0470368 Merge branch 'release-1.43.103'
  • 378d670 Merge branch 'release-1.43.103' into develop
  • 1b65309 Bumping version to 1.43.103
  • 655adc5 Add changelog entries from botocore
  • da00dd2 Merge branch 'release-1.43.102'
  • 76d6266 Merge branch 'release-1.43.102' into develop
  • 551d660 Bumping version to 1.43.102
  • Additional commits viewable in compare view

Updates mypy from 2.3.0 to 2.3.1

Changelog

Sourced from mypy's changelog.

Mypy 2.3.1

  • Fix mypyc crash on double yielding Iterators (Daniël van Noord, PR 21826)
  • Fix mypyc default_factory for inherited dataclass (Daniël van Noord, PR 21785)
  • Clear mypyc coroutine env on coroutine completion (Piotr Sawicki, PR 21734)
  • Fix crash when unpacking return value from overload (Shantanu, PR 21830)

Acknowledgements

Thanks to all mypy contributors who contributed to this release:

  • Agriya Khetarpal
  • Ethan Sarp
  • Ivan Levkivskyi
  • Jingchen Ye
  • Jukka Lehtosalo
  • Piotr Sawicki
  • Shantanu
  • Tom Bannink
  • Viktor Szépe
  • ygale

I'd also like to thank my employer, Dropbox, for supporting mypy development.

Mypy 2.2

We've just uploaded mypy 2.2.0 to the Python Package Index (PyPI). Mypy is a static type checker for Python. This release includes new features, performance improvements and bug fixes. You can install it as follows:

python3 -m pip install -U mypy

You can read the full documentation for this release on Read the Docs.

Support for Closed TypedDicts (PEP 728)

Mypy now supports closed TypedDicts as specified in PEP 728. A closed TypedDict cannot have extra keys beyond those explicitly defined. This allows the type checker to determine that certain operations are safe when they otherwise wouldn't be due to the potential presence of unknown keys.

You can use the closed keyword argument with TypedDict:

HasName = TypedDict("HasName", {"name": str})
HasOnlyName = TypedDict("HasOnlyName", {"name": str}, closed=True)
Movie = TypedDict("Movie", {"name": str, "year": int})
movie: Movie = {"name": "Nimona", "year": 2023}
has_name: HasName = movie  # OK: HasName is open (default)
has_only_name: HasOnlyName = movie  # Error: HasOnlyName is closed and Movie has extra "year" key
</tr></table>

... (truncated)

Commits

Updates coverage from 7.15.4 to 7.16.2

Release notes

Sourced from coverage's releases.

7.16.2

Version 7.16.2 — 2026-09-27

  • Fix: on Python 3.14 and later, a for loop completing immediately before a function return could mistakenly report an uncovered branch. This is now fixed, closing issue 2168.
  • Fix: on Python 3.14 and later, the else clause of a try whose body is a with statement could incorrectly be reported as covered when the with raised. This is now fixed, closing issue 2289.
  • Fix: with dynamic_context = test_function, test methods written as @staticmethod or @classmethod were not given a context of their own. Now they are, on Python 3.11 and later. Closes issue 1923.

➡️  PyPI page: coverage 7.16.2. :arrow_right:  To install: python3 -m pip install coverage==7.16.2

7.16.1

Version 7.16.1 — 2026-09-13

  • Fix: when the body of an irrefutable case (like case _:) is entirely excluded, the case line is now excluded too, just as an excluded else: body removes the else: line. Previously the case line was left behind and reported as missing. Closes issue 1563 with pull 2269.
  • Fix: using CoverageData.update() twice on an in-memory database would fail, as described in issue 2279. This is now fixed.

➡️  PyPI page: coverage 7.16.1. :arrow_right:  To install: python3 -m pip install coverage==7.16.1

7.16.0

Version 7.16.0 — 2026-08-28

  • When combining files, now path separator slashes will automatically be converted to the local file system style. This makes it less necessary to define [paths] configuration to combine data across operating systems. Fixes issue 2266.
  • The Coverage.switch_context() method now returns the previous context.
  • Fix: previously, a [paths] pattern would be replaced everywhere in a file path when it was only meant to be replaced once, in the leading portion of the path. This is now fixed, in pull 2268.
  • Fixes to validation of options and configuration settings:
    • Negative precision settings now always cause useful error messages (pull 2261).
    • An invalid regex in the --contexts option (or the [report] contexts setting) reported a confusing “Couldn’t use data file …: user-defined function raised exception” error. Now it raises a proper configuration error naming the bad regex, like other regex settings do (pull 2262).
    • Non-string values in TOML configuration settings now produce a helpful error message instead of a traceback. This affects list settings whose elements aren’t strings (like omit, exclude_lines, or a [paths] entry), file settings like data_file, and any wrong-typed value in the [paths] section (pull 2263).
    • coverage run refuses run-affecting command-line options like --branch alongside --concurrency=multiprocessing, since they can’t reach the subprocesses. The check only recognized multiprocessing as the entire option value, so --concurrency=multiprocessing,thread slipped through and failed later with “Can’t combine statement coverage data with branch data”. Each named concurrency library is now properly considered (pull 2270).
  • Fix: coverage annotate -d DIR raised an AssertionError if any measured file had an extension other than .py, such as a .pyw file on Windows. The original extension is now restored on the annotated copy (pull 2265).

➡️  PyPI page: coverage 7.16.0. :arrow_right:  To install: python3 -m pip install coverage==7.16.0

Changelog

Sourced from coverage's changelog.

Version 7.16.2 — 2026-09-27

  • Fix: on Python 3.14 and later, a for loop completing immediately before a function return could mistakenly report an uncovered branch. This is now fixed, closing issue 2168_.

  • Fix: on Python 3.14 and later, the else clause of a try whose body is a with statement could incorrectly be reported as covered when the with raised. This is now fixed, closing issue 2289_.

  • Fix: with dynamic_context = test_function, test methods written as @staticmethod or @classmethod were not given a context of their own. Now they are, on Python 3.11 and later. Closes issue 1923_.

.. _issue 1923: coveragepy/coveragepy#1923 .. _issue 2168: coveragepy/coveragepy#2168 .. _issue 2289: coveragepy/coveragepy#2289

.. _changes_7-16-1:

Version 7.16.1 — 2026-09-13

  • Fix: when the body of an irrefutable case (like case _:) is entirely excluded, the case line is now excluded too, just as an excluded else: body removes the else: line. Previously the case line was left behind and reported as missing. Closes issue 1563_ with pull 2269_.

  • Fix: using :meth:.CoverageData.update twice on an in-memory database would fail, as described in issue 2279_. This is now fixed.

.. _issue 1563: coveragepy/coveragepy#1563 .. _pull 2269: coveragepy/coveragepy#2269 .. _issue 2279: coveragepy/coveragepy#2279

.. _changes_7-16-0:

Version 7.16.0 — 2026-08-28

  • When combining files, now path separator slashes will automatically be converted to the local file system style. This makes it less necessary to define [paths] configuration to combine data across operating systems. Fixes issue 2266_.

  • The :meth:.Coverage.switch_context method now returns the previous context.

  • Fix: previously, a [paths] pattern would be replaced everywhere in a file

... (truncated)

Commits

Updates moto from 5.2.2 to 5.2.3

Changelog

Sourced from moto's changelog.

5.2.3

Docker Digest for 5.2.3: sha256:91fd602a21f49cf9eb82fdf474015a3c131d40104c8297ea6a2ca920708ae32c

General:
    * Dropped support for the Panorama service, following the removal by botocore

New Services: * Clean Rooms: * create_collaboration() * create_configured_table() * create_membership() * delete_collaboration() * delete_configured_table() * delete_membership() * get_collaboration() * get_configured_table() * get_membership() * list_collaborations() * list_configured_tables() * list_members() * list_memberships() * list_tags_for_resource() * tag_resource() * untag_resource() * update_collaboration() * update_configured_table() * update_membership()

* DevOps Agent:
    * create_agent_space()
    * delete_agent_space()
    * get_agent_space()
    * list_agent_spaces()
    * list_tags_for_resource()
    * tag_resource()
    * update_agent_space()
    * untag_resource()
  • Payment Cryptography:
    • add_key_replication_regions()
    • create_alias()
    • create_key()
    • delete_alias()
    • delete_resource_policy()
    • disable_default_key_replication_regions()
    • enable_default_key_replication_regions()
    • get_alias()
    • get_default_key_replication_regions()
    • get_key()

... (truncated)

Commits

Updates boto3-stubs from 1.43.36 to 1.43.104

Commits

Updates ruff from 0.16.3 to 0.16.9

Release notes

Sourced from ruff's releases.

0.16.9

Release Notes

Released on 2026-09-24.

Preview features

  • [ruff] Avoid false positives for overloaded division (RUF069) (#28309)

Bug fixes

  • [flake8-bugbear] Avoid false positives for calls with keyword arguments (B009, B010, B043) (#28776)
  • [flake8-tidy-imports] Allow lazy imports to be used in deferred annotations (TID255) (#28767)

Rule changes

  • Update LibCST-based fixes for Python 3.15 (#28616)
  • [flake8-pyi] Mention stubs in the diagnostic message (PYI002) (#28542)

Documentation

  • Fix horizontal overflow on the rules documentation page (#28699)
  • Update rules table with category information (#28651)
  • [flake8-annotations] Clarify that ANN401 checks return types in addition to arguments (#28334)
  • [flake8-bugbear] Document type-checker interaction (B010) (#28509)
  • [flake8-comprehensions] Document map/generator exception behavior (C417) (#27794)
  • [ruff] Mention related isort settings (RUF022) (#28719)

Contributors

Install ruff 0.16.9

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/ruff/releases/download/0.16.9/ruff-installer.sh | sh

... (truncated)

Changelog

Sourced from ruff's changelog.

0.16.9

Released on 2026-09-24.

Preview features

  • [ruff] Avoid false positives for overloaded division (RUF069) (#28309)

Bug fixes

  • [flake8-bugbear] Avoid false positives for calls with keyword arguments (B009, B010, B043) (#28776)
  • [flake8-tidy-imports] Allow lazy imports to be used in deferred annotations (TID255) (#28767)

Rule changes

  • Update LibCST-based fixes for Python 3.15 (#28616)
  • [flake8-pyi] Mention stubs in the diagnostic message (PYI002) (#28542)

Documentation

  • Fix horizontal overflow on the rules documentation page (#28699)
  • Update rules table with category information (#28651)
  • [flake8-annotations] Clarify that ANN401 checks return types in addition to arguments (#28334)
  • [flake8-bugbear] Document type-checker interaction (B010) (#28509)
  • [flake8-comprehensions] Document map/generator exception behavior (C417) (#27794)
  • [ruff] Mention related isort settings (RUF022) (#28719)

Contributors

0.16.8

Released on 2026-09-16.

Bug fixes

  • Visit functional TypedDict keyword arguments correctly (#28584)
  • [flake8-simplify] Detect nested async with under sync parent (SIM117) (#27821)
  • [flake8-simplify] Preserve operand order in SIM109 fix (#27824)

... (truncated)

Commits
  • 0be08a2 Bump version to 0.16.9 (#28882)
  • b4920b7 Rename ruff_cli to ruff_command_line (#28881)
  • 47c751b Update dependency astral-sh/uv to v0.12.18 (#28880)
  • 8c244e5 [flake8-comprehensions] Document map/generator exception behavior (C417...
  • 5edf5a1 Use target form in rooster.version_files (#28876)
  • 915bb2b [ty] Prefer existing @ paths over response files in Ruff and ty (#28877)
  • 4710e1a ci(github): update version number in placeholder of issue template (#28871)
  • eedfc62 [ty] Propagate outer type context through cast calls (#28855)
  • ceaa6a0 [ty] Contain rendered code within Markdown fences (#28869)
  • dba0f30 authorize ruff-pre-commit dispatch via OIDC (#28867)
  • Additional commits viewable in compare view

Updates tox from 4.60.0 to 4.64.4

Release notes

Sourced from tox's releases.

v4.64.4

What's Changed

New Contributors

Full Changelog: tox-dev/tox@4.64.3...4.64.4

v4.64.3

What's Changed

New Contributors

Full Changelog: tox-dev/tox@4.64.2...4.64.3

v4.64.2

What's Changed

Full Changelog: tox-dev/tox@4.64.1...4.64.2

v4.64.1

What's Changed

Full Changelog: tox-dev/tox@4.64.0...4.64.1

v4.64.0

What's Changed

... (truncated)

Changelog

Sourced from tox's changelog.

Bug fixes - 4.64.4

  • Pass --pre once, before the packages, in the default install_command with :ref:pip_pre set to true. (:issue:4097)
  • Fix list conversion for command line defaults from environment variables and user configuration files. For example, TOX_LABELS=old;new selects environments labeled old or new, and TOX_LIST_KEYS_ONLY=env_name;deps selects both configuration keys. Support list-valued options without an explicit default or element type, including append actions. (:issue:4098)

v4.64.3 (2026-09-26)


Bug fixes - 4.64.3

  • A set_env written as a list of tables in TOML now keeps every file entry and honors the order of the entries, so merging one environment's set_env into another no longer drops the environment file it referenced (:issue:4093) - by :user:Rodrigo-Palma.

    • Each { file = "..." } entry is read; previously only the last one survived, because the entries were merged into a single table first and a table cannot hold the key twice.
    • A variable set after a file entry wins over the value the file provides, matching the file| form in INI; previously a repeated variable was pulled back to its first position, letting the file override it.
    • A later entry that sets a variable without a marker clears the marker an earlier entry gave it, again matching the INI form. (:issue:4093)
  • Create the package build environment change_dir directory before running the build commands, as the documentation already promises. (:issue:4095)


v4.64.2 (2026-09-24)


Bug fixes - 4.64.2

  • A tox environment with env_dir = "{tox_root}/.venv" no longer crashes with FileExistsError after another environment ran (:issue:4090) - by :user:gaborbernat.

    • With :ref:venv_redirect unset, the new default, tox writes the redirect file unless a tox environment lives at .venv; with true, tox fails the run with an error naming that environment.
    • tox deletes a redirect file it wrote where an environment should live, and fails the environment with an error naming any other file there. (:issue:4091)
  • The :PEP:832 .venv redirect file now names a deliberate development environment - by :user:gaborbernat.

    • tox picks :ref:venv_redirect_env, else an environment named dev, else the first that installs the project in development mode, and writes nothing without one, so a project that uses tox for tests alone gets no file.

... (truncated)

Commits

Updates botocore from 1.43.71 to 1.43.104

Commits
  • 66a4744 Merge branch 'release-1.43.104'
  • 8dff27e Bumping version to 1.43.104
  • 047f09a Update to latest models

…ctory with 26 updates

Bumps the patch-and-minor group with 26 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [urllib3](https://github.com/urllib3/urllib3) | `2.7.0` | `2.8.0` |
| [nhs-aws-helpers](https://github.com/NHSDigital/nhs-aws-helpers) | `0.8.45` | `0.8.82` |
| [aws-lambda-powertools](https://github.com/aws-powertools/powertools-lambda-python) | `3.34.0` | `3.35.0` |
| [boto3](https://github.com/boto/boto3) | `1.43.58` | `1.43.104` |
| [mypy](https://github.com/python/mypy) | `2.3.0` | `2.3.1` |
| [coverage](https://github.com/coveragepy/coveragepy) | `7.15.4` | `7.16.2` |
| [moto](https://github.com/getmoto/moto) | `5.2.2` | `5.2.3` |
| [boto3-stubs](https://github.com/youtype/mypy_boto3_builder) | `1.43.36` | `1.43.104` |
| [ruff](https://github.com/astral-sh/ruff) | `0.16.3` | `0.16.9` |
| [tox](https://github.com/tox-dev/tox) | `4.60.0` | `4.64.4` |
| [botocore](https://github.com/boto/botocore) | `1.43.71` | `1.43.104` |
| [charset-normalizer](https://github.com/jawah/charset_normalizer) | `3.5.0` | `3.5.1` |
| [idna](https://github.com/kjd/idna) | `3.18` | `3.20` |
| [mypy-boto3-backup](https://github.com/youtype/mypy_boto3_builder) | `1.43.66` | `1.43.78` |
| [mypy-boto3-cloudwatch](https://github.com/youtype/mypy_boto3_builder) | `1.43.54` | `1.43.102` |
| [mypy-boto3-ecs](https://github.com/youtype/mypy_boto3_builder) | `1.43.65` | `1.43.93` |
| [mypy-boto3-events](https://github.com/youtype/mypy_boto3_builder) | `1.43.0` | `1.43.102` |
| [mypy-boto3-glue](https://github.com/youtype/mypy_boto3_builder) | `1.43.70` | `1.43.104` |
| [mypy-boto3-healthlake](https://github.com/youtype/mypy_boto3_builder) | `1.43.67` | `1.43.83` |
| [mypy-boto3-lambda](https://github.com/youtype/mypy_boto3_builder) | `1.43.60` | `1.43.91` |
| [mypy-boto3-logs](https://github.com/youtype/mypy_boto3_builder) | `1.43.66` | `1.43.82` |
| [mypy-boto3-s3](https://github.com/youtype/mypy_boto3_builder) | `1.43.66` | `1.43.93` |
| [mypy-boto3-sns](https://github.com/youtype/mypy_boto3_builder) | `1.43.23` | `1.43.97` |
| [mypy-boto3-ssm](https://github.com/youtype/mypy_boto3_builder) | `1.43.53` | `1.43.104` |
| [mypy-boto3-stepfunctions](https://github.com/youtype/mypy_boto3_builder) | `1.43.7` | `1.43.88` |
| [mypy-boto3-sts](https://github.com/youtype/mypy_boto3_builder) | `1.43.0` | `1.43.94` |



Updates `urllib3` from 2.7.0 to 2.8.0
- [Release notes](https://github.com/urllib3/urllib3/releases)
- [Changelog](https://github.com/urllib3/urllib3/blob/main/CHANGES.rst)
- [Commits](urllib3/urllib3@2.7.0...2.8.0)

Updates `nhs-aws-helpers` from 0.8.45 to 0.8.82
- [Commits](https://github.com/NHSDigital/nhs-aws-helpers/commits)

Updates `aws-lambda-powertools` from 3.34.0 to 3.35.0
- [Release notes](https://github.com/aws-powertools/powertools-lambda-python/releases)
- [Changelog](https://github.com/aws-powertools/powertools-lambda-python/blob/develop/CHANGELOG.md)
- [Commits](aws-powertools/powertools-lambda-python@v3.34.0...v3.35.0)

Updates `boto3` from 1.43.58 to 1.43.104
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](boto/boto3@1.43.58...1.43.104)

Updates `mypy` from 2.3.0 to 2.3.1
- [Changelog](https://github.com/python/mypy/blob/master/CHANGELOG.md)
- [Commits](python/mypy@v2.3.0...v2.3.1)

Updates `coverage` from 7.15.4 to 7.16.2
- [Release notes](https://github.com/coveragepy/coveragepy/releases)
- [Changelog](https://github.com/coveragepy/coveragepy/blob/main/CHANGES.rst)
- [Commits](coveragepy/coveragepy@7.15.4...7.16.2)

Updates `moto` from 5.2.2 to 5.2.3
- [Release notes](https://github.com/getmoto/moto/releases)
- [Changelog](https://github.com/getmoto/moto/blob/master/CHANGELOG.md)
- [Commits](getmoto/moto@5.2.2...5.2.3)

Updates `boto3-stubs` from 1.43.36 to 1.43.104
- [Release notes](https://github.com/youtype/mypy_boto3_builder/releases)
- [Commits](https://github.com/youtype/mypy_boto3_builder/commits)

Updates `ruff` from 0.16.3 to 0.16.9
- [Release notes](https://github.com/astral-sh/ruff/releases)
- [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md)
- [Commits](astral-sh/ruff@0.16.3...0.16.9)

Updates `tox` from 4.60.0 to 4.64.4
- [Release notes](https://github.com/tox-dev/tox/releases)
- [Changelog](https://github.com/tox-dev/tox/blob/main/docs/changelog.rst)
- [Commits](tox-dev/tox@4.60.0...4.64.4)

Updates `botocore` from 1.43.71 to 1.43.104
- [Commits](boto/botocore@1.43.71...1.43.104)

Updates `charset-normalizer` from 3.5.0 to 3.5.1
- [Release notes](https://github.com/jawah/charset_normalizer/releases)
- [Changelog](https://github.com/jawah/charset_normalizer/blob/master/CHANGELOG.md)
- [Commits](jawah/charset_normalizer@3.5.0...3.5.1)

Updates `idna` from 3.18 to 3.20
- [Release notes](https://github.com/kjd/idna/releases)
- [Changelog](https://github.com/kjd/idna/blob/master/HISTORY.md)
- [Commits](kjd/idna@v3.18...v3.20)

Updates `mypy-boto3-backup` from 1.43.66 to 1.43.78
- [Release notes](https://github.com/youtype/mypy_boto3_builder/releases)
- [Commits](https://github.com/youtype/mypy_boto3_builder/commits)

Updates `mypy-boto3-cloudwatch` from 1.43.54 to 1.43.102
- [Release notes](https://github.com/youtype/mypy_boto3_builder/releases)
- [Commits](https://github.com/youtype/mypy_boto3_builder/commits)

Updates `mypy-boto3-ecs` from 1.43.65 to 1.43.93
- [Release notes](https://github.com/youtype/mypy_boto3_builder/releases)
- [Commits](https://github.com/youtype/mypy_boto3_builder/commits)

Updates `mypy-boto3-events` from 1.43.0 to 1.43.102
- [Release notes](https://github.com/youtype/mypy_boto3_builder/releases)
- [Commits](https://github.com/youtype/mypy_boto3_builder/commits)

Updates `mypy-boto3-glue` from 1.43.70 to 1.43.104
- [Release notes](https://github.com/youtype/mypy_boto3_builder/releases)
- [Commits](https://github.com/youtype/mypy_boto3_builder/commits)

Updates `mypy-boto3-healthlake` from 1.43.67 to 1.43.83
- [Release notes](https://github.com/youtype/mypy_boto3_builder/releases)
- [Commits](https://github.com/youtype/mypy_boto3_builder/commits)

Updates `mypy-boto3-lambda` from 1.43.60 to 1.43.91
- [Release notes](https://github.com/youtype/mypy_boto3_builder/releases)
- [Commits](https://github.com/youtype/mypy_boto3_builder/commits)

Updates `mypy-boto3-logs` from 1.43.66 to 1.43.82
- [Release notes](https://github.com/youtype/mypy_boto3_builder/releases)
- [Commits](https://github.com/youtype/mypy_boto3_builder/commits)

Updates `mypy-boto3-s3` from 1.43.66 to 1.43.93
- [Release notes](https://github.com/youtype/mypy_boto3_builder/releases)
- [Commits](https://github.com/youtype/mypy_boto3_builder/commits)

Updates `mypy-boto3-sns` from 1.43.23 to 1.43.97
- [Release notes](https://github.com/youtype/mypy_boto3_builder/releases)
- [Commits](https://github.com/youtype/mypy_boto3_builder/commits)

Updates `mypy-boto3-ssm` from 1.43.53 to 1.43.104
- [Release notes](https://github.com/youtype/mypy_boto3_builder/releases)
- [Commits](https://github.com/youtype/mypy_boto3_builder/commits)

Updates `mypy-boto3-stepfunctions` from 1.43.7 to 1.43.88
- [Release notes](https://github.com/youtype/mypy_boto3_builder/releases)
- [Commits](https://github.com/youtype/mypy_boto3_builder/commits)

Updates `mypy-boto3-sts` from 1.43.0 to 1.43.94
- [Release notes](https://github.com/youtype/mypy_boto3_builder/releases)
- [Commits](https://github.com/youtype/mypy_boto3_builder/commits)

---
updated-dependencies:
- dependency-name: urllib3
  dependency-version: 2.8.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: patch-and-minor
- dependency-name: nhs-aws-helpers
  dependency-version: 0.8.82
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: patch-and-minor
- dependency-name: aws-lambda-powertools
  dependency-version: 3.35.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: patch-and-minor
- dependency-name: boto3
  dependency-version: 1.43.104
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: patch-and-minor
- dependency-name: mypy
  dependency-version: 2.3.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: patch-and-minor
- dependency-name: coverage
  dependency-version: 7.16.2
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: patch-and-minor
- dependency-name: moto
  dependency-version: 5.2.3
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: patch-and-minor
- dependency-name: boto3-stubs
  dependency-version: 1.43.104
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: patch-and-minor
- dependency-name: ruff
  dependency-version: 0.16.9
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: patch-and-minor
- dependency-name: tox
  dependency-version: 4.64.4
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: patch-and-minor
- dependency-name: botocore
  dependency-version: 1.43.104
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: patch-and-minor
- dependency-name: charset-normalizer
  dependency-version: 3.5.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: patch-and-minor
- dependency-name: idna
  dependency-version: '3.20'
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: patch-and-minor
- dependency-name: mypy-boto3-backup
  dependency-version: 1.43.78
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: patch-and-minor
- dependency-name: mypy-boto3-cloudwatch
  dependency-version: 1.43.102
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: patch-and-minor
- dependency-name: mypy-boto3-ecs
  dependency-version: 1.43.93
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: patch-and-minor
- dependency-name: mypy-boto3-events
  dependency-version: 1.43.102
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: patch-and-minor
- dependency-name: mypy-boto3-glue
  dependency-version: 1.43.104
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: patch-and-minor
- dependency-name: mypy-boto3-healthlake
  dependency-version: 1.43.83
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: patch-and-minor
- dependency-name: mypy-boto3-lambda
  dependency-version: 1.43.91
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: patch-and-minor
- dependency-name: mypy-boto3-logs
  dependency-version: 1.43.82
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: patch-and-minor
- dependency-name: mypy-boto3-s3
  dependency-version: 1.43.93
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: patch-and-minor
- dependency-name: mypy-boto3-sns
  dependency-version: 1.43.97
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: patch-and-minor
- dependency-name: mypy-boto3-ssm
  dependency-version: 1.43.104
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: patch-and-minor
- dependency-name: mypy-boto3-stepfunctions
  dependency-version: 1.43.88
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: patch-and-minor
- dependency-name: mypy-boto3-sts
  dependency-version: 1.43.94
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: patch-and-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update Python code labels Oct 6, 2026
@dependabot
dependabot Bot requested review from a team and matt-mercer as code owners October 6, 2026 07:48
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update Python code labels Oct 6, 2026
@shared-merge-writeback
shared-merge-writeback Bot enabled auto-merge (squash) October 6, 2026 07:48
@dependabot @github

dependabot Bot commented on behalf of github Oct 8, 2026

Copy link
Copy Markdown
Contributor Author

Looks like these dependencies are updatable in another way, so this is no longer needed.

@dependabot dependabot Bot closed this Oct 8, 2026
auto-merge was automatically disabled October 8, 2026 07:47

Pull request was closed

@dependabot
dependabot Bot deleted the dependabot/pip/patch-and-minor-2c1a13674d branch October 8, 2026 07:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update Python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants