Skip to content

chore(deps): Update python-dependencies - #3356

Open
renovate[bot] wants to merge 1 commit into
developmentfrom
renovate/python-dependencies
Open

renovate[bot] wants to merge 1 commit into
developmentfrom
renovate/python-dependencies

Conversation

@renovate

@renovate renovate Bot commented Sep 1, 2026

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence
PyJWT ==2.13.0==2.14.0 age confidence
alembic (changelog) ==1.19.1==1.20.0 age confidence
anyio (changelog) ==4.14.2==4.15.1 age confidence
contourpy (changelog) ==1.3.3==1.4.0 age confidence
fonttools ==4.64.0==4.65.0 age confidence
jiter ==0.16.0==0.17.0 age confidence
matplotlib ==3.11.1==3.11.2 age confidence
multidict ==6.7.1==6.8.0 age confidence
numpy (changelog) ==2.5.2==2.5.3 age confidence
platformdirs (changelog) ==4.11.6==4.11.8 age confidence
propcache ==0.5.2==0.5.4 age confidence
pure-eval ==0.2.3==0.2.4 age confidence
rembg ==2.0.81==2.0.84 age confidence
ruff (source, changelog) ==0.16.5==0.16.7 age confidence
sentry-sdk (changelog) ==2.68.1==2.69.2 age confidence
sqlalchemy (changelog) ==2.0.52==2.0.54 age confidence
tornado (source) ==6.5.8==6.5.10 age confidence
tqdm (changelog) ==4.70.0==4.70.1 age confidence
urllib3 (changelog) ==2.7.0==2.8.0 age confidence
wrapt (changelog) ==2.4.0==2.4.1 age confidence
yarl ==1.24.5==1.25.1 age confidence

Release Notes

jpadilla/pyjwt (PyJWT)

v2.14.0

Compare Source

agronholm/anyio (anyio)

v4.15.1

Compare Source

v4.15.0

Compare Source

  • Added support for the newer keyword-only arguments on anyio.Path methods to match the standard library pathlib.Path:

    • follow_symlinks on exists() (Python 3.12+)
    • follow_symlinks on is_dir() (Python 3.13+)
    • follow_symlinks on is_file() (Python 3.13+)
    • follow_symlinks on owner() (Python 3.13+)
    • follow_symlinks on group() (Python 3.13+)
    • newline on read_text() (Python 3.13+)

    (#​1286, #​1293; PR by @​jaideeppyne)

  • Added amap, gather, and as_completed utility functions to simplify common patterns (#​1173; PR by @​Graeme22)

  • Added --anyio-mode command-line option as an alternative to the anyio_mode ini setting, and fix the pytest plugin's auto mode detection to recognize the mode when set via either mechanism(e.g: pytest_asyncio). (#​1242; PR by @​EmmanuelNiyonshuti)

  • Added the anyio.Future synchronization primitive which behaves similar to asyncio.Future, allowing tasks to wait for a value (or exception) from another task (#​1146; PR by @​Vizonex)

  • Added guidance for managing multiple memory object stream producers and consumers with cloned streams (#​330; PR by @​nightcityblade)

  • Added StapledObjectStream.send_nowait() that delegates to the underlying ObjectSendStream, if it implements it (#​1241; PR by @​davidbrochart)

  • Added the move_on_at() and fail_at() functions to complement move_on_after() and fail_after()

  • Changed the default name for a task spawned with TaskGroup.create_task(func()) to match the default task name for the analogous task spawned with TaskGroup.start_soon(func) or TaskGroup.start(func) in more situations. Previously, the default name of a TaskGroup.create_task task never included the module name. (The default name for a task spawned with TaskGroup.start_soon or TaskGroup.start typically includes the module name.) (#​1234; PR by @​gschaffner)

  • Changed the anyio and anyio.abc modules to lazily (much like 810) import the necessary submodules. This is done by parsing the AST of the module and building a lookup table from the if TYPE_CHECKING: block. A fallback mode has been provided for installations where the source code is unavailable (e.g. PyInstaller). (#​1169)

  • Fixed free-threading compatibility issues arising from the fact that on Python 3.14 free-threading builds, newly created threads inherit the current context by default, causing AnyIO to behave erroneously in relation to start_blocking_portal() and anyio.to_thread.run_sync() (#​1224; PR by @​EmmanuelNiyonshuti)

  • Fixed SpooledTemporaryFile.readinto() and readinto1() reading twice before rollover, so the destination buffer was overwritten by the second read and the file position advanced twice, silently losing data (#​1215; PR by @​c-tonneslan)

  • Added a reason parameter to fail_after (and the new fail_at) allowing for added exception context when raising TimeoutError (#​1227; PR by @​Graeme22)

  • Fixed the default TaskHandle.name missing part of the task name for tasks started with TaskGroup.start on Trio (#​1231; PR by @​gschaffner)

  • Fixed anyio.run leaking, or at least, delaying collection of loop and root_task due to the root task being cached in a RunVar. (#​1203; PR by @​tapetersen)

  • Fixed anyio.Path.with_stem() silently producing a wrong path (e.g. Path(".txt")) instead of raising ValueError when given an empty stem on a path with a non-empty suffix, unlike pathlib.PurePath.with_stem (#​1200; PR by @​Sanjays2402)

  • Fixed UNIXSocketStream.aclose() raising asyncio.InvalidStateError when a concurrent receive or send operation had just been cancelled on the asyncio backend (#​1267; PR by @​alloutflo)

  • Fixed the pytest plugin importing the deprecated _pytest.python.CallSpec2 alias, which triggers PytestRemovedIn10Warning on pytest>=9.2 and crashes pytest at startup when filterwarnings = error is configured (#​1271; PR by @​matthewfeickert)

  • Fixed an asyncio worker thread race that could raise RuntimeError when the event loop closed between checking its state and scheduling the worker result (#​1265; PR by @​hansu650)

  • Fixed CapacityLimiter on the asyncio backend over-granting tokens when total_tokens was raised while the limiter was over-subscribed (#​1223; PR by @​zelinewang)

  • Fixed asyncio task groups leaking unawaited coroutines when a custom task constructor fails; default task creation is unaffected (#​1274; PR by @​dsfaccini)

  • Fixed inconsistencies between Trio and asyncio when target TaskGroup is cancelled before a task created with .start() calls TaskStatus.started()

    • The started task shouldn't get a CancelledError until the first checkpoint after the started() call.
    • A value passed to started() should be available on the TaskHandle and correctly passed back to the caller of start even if cancelled.
    • The CancelledError shouldn't leak out of the TaskGroup.start() call to the calling task.

    (#​1197; PR by @​tapetersen)

  • Fixed TemporaryDirectory not cleaning up when the host task was cancelled while exiting the context manager, as the cleanup now runs in a shielded cancel scope (#​1304; PR by @​smurfix)

contourpy/contourpy (contourpy)

v1.4.0: Version 1.4.0

Compare Source

ContourPy 1.4.0 introduces a new readonly property ContourGenerator.name for the algorithm name, adds support for CPython 3.15, and is the first release to upload pyodide wheels to PyPI. Support for riscv64 and iOS architectures is added but considered experimental, wheels are available from the Scientific Python Nightly Wheels service but not PyPI.

Enhancements:

  • Add ContourGenerator.name readonly property (#​566)

Compatibility:

Code improvements:

  • Remove unused ntotal argument in mpl2005 build_cntr_list_v2 (#​550)

Documentation improvements:

  • Use myst markdown for documentation instead of RST (#​551)
  • Switch docs to sphinx book theme (#​552)

Build, testing and CI improvements:

  • Switch from macos-13 to macos-15-intel github runners (#​507)
  • Fully test on python 3.14 (#​509)
  • Build intel mac wheels on macos-15-intel runner (#​513)
  • Update license metadata to use PEP 639 (#​525)
  • Update test images for bokeh 3.9.0 (#​533)
  • Remove use of cirrus CI (#​537)
  • Add zizmor to pre-commit (#​546)
  • Remove testing on python 3.13t (#​555)
  • Update test images and thresholds (#​542, #​561)
fonttools/fonttools (fonttools)

v4.65.0

Compare Source

  • [glyf] Add __iter__, items and values methods to the glyf table to make it more dict-like (#​4156).
  • [feaLib] Escape the anonymous block tag when scanning for its terminator, so tags containing regex metacharacters are matched literally (#​4167).
  • [varLib] Strip directory components from <variable-font name="..."/> when deriving the output filename in the varLib command line, so a designspace cannot write outside the output directory (#​4168).
  • [feaLib] Fix tracking of the current script and language across redundant script statements. Rules following a script statement that names the first declared language system no longer end up under the DFLT script, and a script statement naming the already-current script still narrows the language systems and terminates the current lookup while leaving the lookupflag alone, matching makeotf (#​1824, #​2522, #​4169).
  • [varLib.interpolatable] Escape glyph names in the HTML report (#​4172).
  • [otlLib] Fix overflow handling when building contextual lookups: offset overflows now raise OTLOffsetOverflowError instead of AttributeError so another contextual format can be tried (regression from #​3439). When all formats overflow, split the ruleset in halves until it fits (#​4171).
pydantic/jiter (jiter)

v0.17.0: 2026-09-12

Compare Source

What's Changed

Full Changelog: pydantic/jiter@v0.16.0...v0.17.0

matplotlib/matplotlib (matplotlib)

v3.11.2: REL: v3.11.2

Compare Source

This is the second bugfix release of the 3.11.x series.

This release contains several bug-fixes and adjustments:

  • Speed up RGBA-stage image resampling
  • Fix hexbin clipping in PDF output
  • Fix \text with internal braces
  • Fix some crashes and make some checks more robust to unlikely cases
  • Fix frame skew when saving GIF animations with PillowWriter
  • Fix HiDPI handling in Qt toolbar and WebAgg embeddings
  • Fix ResizeEvent handling for TextBox
  • Fix bug with PGF hatch linewidth and color
  • Fix a bug with drawing an empty Collection
  • Fix incorrect glyphs in Cairo backends
  • Improve build system to prevent conflicts between wheels and system libraries
aio-libs/multidict (multidict)

v6.8.0

Compare Source

=====

(2026-09-09)

Bug fixes

  • A segmentation fault that could be triggered when getting an item is now fixed
    -- by :user:Vizonex.

    Related issues and pull requests on GitHub:
    :issue:1310.

  • Fixed reference leak in iterators, views and istr
    -- by :user:Vizonex.

    Related issues and pull requests on GitHub:
    :issue:1311.

  • Fixed the pure-Python :class:~multidict.MultiDict constructor and
    :py:meth:~multidict.MultiDict.extend,
    :py:meth:~multidict.MultiDict.update, and
    :py:meth:~multidict.MultiDict.merge methods over-allocating their
    internal hash table when called with both a positional argument and
    keyword arguments, because keyword arguments were counted twice in the
    size estimate -- by :user:aiolibsbot.

    Related issues and pull requests on GitHub:
    :issue:1338.

  • Fixed __repr__ of :class:~multidict.MultiDict,
    :class:~multidict.CIMultiDict, their proxies, and the keys/items views
    producing invalid output when keys contained quote characters --
    keys are now formatted with :func:repr so the result is a valid Python
    string literal -- by :user:aiolibsbot.

    Related issues and pull requests on GitHub:
    :issue:1342.

  • Fixed a segfault when calling :py:meth:~multidict.MultiDict.add with only one of its two required arguments supplied by keyword, e.g. d.add(key="k"). Extra keyword arguments passed to the lookup and removal methods are also now rejected with :exc:TypeError instead of being silently ignored.

    -- by :user:devdanzin

    Related issues and pull requests on GitHub:
    :issue:1376.

  • Fixed a segfault when constructing a multidict iterator type directly, e.g. type(iter(md.keys())).__new__(...). Such an iterator had a NULL internal pointer that next() dereferenced. The iterator types now forbid direct instantiation, the same way the view types were fixed in :issue:1163.

    -- by :user:devdanzin

    Related issues and pull requests on GitHub:
    :issue:1377.

  • Fixed a segfault when using a :py:class:~multidict.MultiDict or :py:class:~multidict.CIMultiDict created via __new__ without calling __init__ (for example a subclass that does not call super().__init__()). The internal state was left as NULL pointers that the first method call dereferenced. tp_new now initializes the object to a valid empty mapping.

    -- by :user:devdanzin

    Related issues and pull requests on GitHub:
    :issue:1378.

  • Fixed two crashes in the C extension caused by holding a raw pointer into a hash table across an operation that could reshape it. Updating a multidict from itself (e.g. d.extend(d)) freed the very table being iterated -- a use-after-free; extend(self) now doubles the contents and update(self)/merge(self) are no-ops. Building a multidict from a list of pairs whose case-insensitive key .lower() shrinks that list read past the end of the list; the length is now re-checked on every iteration.

    -- by :user:devdanzin

    Related issues and pull requests on GitHub:
    :issue:1379.

  • Fixed three reference/resource leaks on error paths in the C extension: the items-view __contains__ leaked the first element of a candidate pair when reading the second one raised; __repr__ leaked its PyUnicodeWriter when the multidict was mutated during iteration; and the internal iteration helper leaked the identity reference when key materialization failed under low memory.

    -- by :user:devdanzin

    Related issues and pull requests on GitHub:
    :issue:1381.

  • Stopped several feature-detection fallbacks in the C extension from swallowing every exception. When probing an argument (arg.items()/arg.keys()) or measuring it (len(other)) fails, the code now clears only the expected :exc:TypeError/:exc:AttributeError and lets everything else -- notably :exc:MemoryError and :exc:KeyboardInterrupt -- propagate, matching the already-correct sites elsewhere in the module.

    -- by :user:devdanzin

    Related issues and pull requests on GitHub:
    :issue:1382.

  • Fixed a segmentation fault when extending a multidict with itself
    -- by :user:cananoo and :user:asvetlov.

    Related issues and pull requests on GitHub:
    :issue:1398.

  • Fixed a memory leak when MultiDict and CIMultiDict instances are
    initialized more than once -- by :user:asvetlov.

    Related issues and pull requests on GitHub:
    :issue:1412.

  • Fixed a reference leak in items-view set operations
    -- by :user:asvetlov.

    Related issues and pull requests on GitHub:
    :issue:1413.

  • Fixed a memory leak when destroying C-extension multidict instances
    and proxies -- by :user:asvetlov.

    Related issues and pull requests on GitHub:
    :issue:1415.

  • Fixed a reference leak from repeated __init__ calls on
    MultiDictProxy and CIMultiDictProxy instances -- by :user:asvetlov.

    Related issues and pull requests on GitHub:
    :issue:1419.

  • Fixed missing decref for :data:None on error in :meth:~multidict.MultiDict.setdefault
    -- by :user:asvetlov

    Related issues and pull requests on GitHub:
    :issue:1421.

Features

  • Added :py:func:reversed support to the keys, values, and items views of
    :class:~multidict.MultiDict, :class:~multidict.CIMultiDict, and their
    proxies in both the C-extension and pure-Python implementations
    -- by :user:aiolibsbot.

    Related issues and pull requests on GitHub:
    :issue:448.

  • Optimized key identity comparison for C Extension.

    Now it uses fast path that is equal to :c:func:PyUnicode_Equal from
    Python 3.14+ but without redundant type checks. It gives ~15% speed-up on benchmarks with many key comparisons.

    -- by :user:asvetlov

    Related issues and pull requests on GitHub:
    :issue:1406.

  • Changed both the pure-Python and C implementations to mark a temporarily
    removed hash table entry by setting the high bit of its hash instead of
    overwriting it with a sentinel value, so restoring the entry no longer
    recomputes the hash; :meth:~multidict.MultiDict.getall is faster ~10% now in C version
    -- by :user:asvetlov

    Related issues and pull requests on GitHub:
    :issue:1426.

Removals and backward incompatible breaking changes

  • Dropped support for Python 3.9 as it has reached end of life.

    Related issues and pull requests on GitHub:
    :issue:1316.

  • Dropped support for free-threaded Python 3.13 -- by :user:ngoldbaum.

    Related issues and pull requests on GitHub:
    :issue:1326.

Improved documentation

  • Fixed CIMultiDictProxy documentation to state it inherits from
    MultiDictProxy (not MultiDict), and fixed missing word in
    istr section -- by :user:veeceey.

    Related issues and pull requests on GitHub:
    :issue:1298.

  • Clarified that istr preserves the original casing and
    compares as a regular str; case-insensitive matching is
    handled by CIMultiDict -- by :user:gyanu2507.

    Related issues and pull requests on GitHub:
    :issue:1397.

  • Fixed broken RST markup in items() docstrings
    -- by :user:veeceey.

    Related issues and pull requests on GitHub:
    :issue:1299.

Packaging updates and notes for downstreams

  • Dropped support for free-threaded Python 3.13 -- by :user:ngoldbaum.

    Related issues and pull requests on GitHub:
    :issue:1326.

  • Wheels for iOS and Android (CPython 3.13+) are now published on
    release-tag builds, so downstreams on those platforms no longer need a
    local compiler to install multidict; these wheels are build-verified
    only, since running the test suite on mobile needs a simulator or an
    emulator -- by :user:aiolibsbot.

    Related issues and pull requests on GitHub:
    :issue:1337.

  • Added support for building and shipping riscv64 wheels
    -- by :user:justeph.

    Related issues and pull requests on GitHub:
    :issue:1293.

  • The setuptools build dependency lower bound has been restored to be
    >= 47 after an incorrect automated increase in :pr:1315
    -- by :user:aiolibsbot.

    Related issues and pull requests on GitHub:
    :issue:1400.

Contributor-facing changes

  • Added support for collecting code coverage of isolated multidict tests
    -- by :user:Vizonex.

    Related issues and pull requests on GitHub:
    :issue:1314.

  • Switched to mirrors-clang-format and enabled clang-format in pre-commit.ci
    -- by :user:bdraco.

    Related issues and pull requests on GitHub:
    :issue:1318.

  • Added a release-tag-gated CI job that cross-compiles the C extension
    for iOS and Android through cibuildwheel -- by :user:aiolibsbot.

    Related issues and pull requests on GitHub:
    :issue:1337.

  • Added an AGENTS.md orientation file at the repository root, covering the
    pull request template, the CHANGES/ news fragment conventions, the
    draft-PR / human-review workflow, and the dual pure-Python and C-extension
    parity rule, so LLM contributors land changes that match project style
    -- by :user:bdraco.

    Related issues and pull requests on GitHub:
    :issue:1339.

  • Added init, installable, instantiation, parametrization,
    parametrized, postfix, and unparseable to the docs spelling list
    so news fragments and docs can use these words without failing the spell
    check build -- by :user:pctablet505.

    Related issues and pull requests on GitHub:
    :issue:1343.

  • Documented three common agent failure modes in
    :file:AGENTS.md: the docs spell check
    (make doc-spelling) catches unknown words in news fragments
    before CI does; coverage runs over the test tree too, so
    unreachable defensive raise guards and one-sided cleanup
    branches in tests will surface as uncovered on the codecov
    patch report; and branch creation is restricted on
    aio-libs/multidict, so PRs must be pushed from a fork
    -- by :user:bdraco.

    Related issues and pull requests on GitHub:
    :issue:1343, :issue:1345.

  • Trimmed the CI test matrix to drop redundant Py_DEBUG jobs on
    macOS and Windows and to gate the windows-11-arm wheel build to
    release-time only, cutting CI wall-clock by roughly a third without
    reducing code coverage -- by :user:aiolibsbot.

    Related issues and pull requests on GitHub:
    :issue:1346.

  • Added a CLAUDE.md at the repository root that imports
    :file:AGENTS.md via Claude Code's @-syntax, so the
    project's LLM contributor rules load automatically when
    working in Claude Code
    -- by :user:aiolibsbot.

    Related issues and pull requests on GitHub:
    :issue:1347.

  • Enabled the I (import sorting) rule in
    [tool.ruff.lint] so ruff check covers import order on top
    of the existing UP (pyupgrade) group, and updated the
    ruff-check pre-commit hook to run with
    --fix --exit-non-zero-on-fix --show-fixes so import-order
    fixes apply on commit. Sorted imports in four tests/ files
    to match the new rule -- by :user:bdraco.

    Related issues and pull requests on GitHub:
    :issue:1348.

  • Enabled the PLC0415 (import-outside-top-level) rule in
    [tool.ruff.lint]. Function-scoped imports must now opt in
    with # noqa: PLC0415 plus a comment explaining the reason
    (typically avoiding a heavy optional dependency at import time).
    This catches a pattern that LLM contributors frequently introduce.
    There are currently no opt-outs in the tree, so the rule is
    enforced everywhere ruff check runs
    -- by :user:bdraco.

    Related issues and pull requests on GitHub:
    :issue:1349.

  • Switched the cibuildwheel build frontend to build[uv] so
    that uv provisions every build and test virtual environment
    in the wheel matrix. Test-dependency installation in particular
    drops from a multi-second pip install per ABI to a roughly
    sub-second uv resolve
    -- by :user:bdraco.

    Related issues and pull requests on GitHub:
    :issue:1350.

  • Overrode CIBW_BUILD_FRONTEND=build for the odd-arch wheel
    matrix; the upstream manylinux/musllinux images for
    those arches do not ship uv
    -- by :user:bdraco.

    Related issues and pull requests on GitHub:
    :issue:1352.

  • Allowed re-running the deploy job after a partial release failure: the
    Make Release step now skips when the GitHub Release already exists,
    and the PyPI publish step uses skip-existing so dists that were
    already uploaded on a prior attempt do not break the retry
    -- by :user:bdraco.

    Related issues and pull requests on GitHub:
    :issue:1353.

  • Switched the aarch64 and armv7l wheel builds to GitHub's native ARM
    runners. The aarch64 wheels now build without QEMU emulation, and
    armv7l runs on aarch64 hosts so its 32-bit ARM execution is far
    cheaper than the previous aarch64-on-x86_64 path
    -- by :user:bdraco.

    Related issues and pull requests on GitHub:
    :issue:1354.

  • Documented design principles for pure-Python :class:~multidict.istr implementation
    -- by :user:asvetlov

    Related issues and pull requests on GitHub:
    :issue:1360.

  • Pinned coverage to the ctrace measurement core so the test suite runs
    on Python 3.14. Coverage picks sysmon there, which cannot record the
    dynamic contexts pytest-cov switches at runtime, and the resulting warning
    became an error under the suite's filterwarnings setting
    -- by :user:rodrigobnogueira.

    Related issues and pull requests on GitHub:
    :issue:1393.

  • Dependabot has been restricted to the requirements subdirectory to
    avoid unintended updates outside dependency requirement files
    -- by :user:aiolibsbot.

    Related issues and pull requests on GitHub:
    :issue:1400.

  • Enabled automatic upgrades from ruff after each python version that is dropped
    -- by :user:Vizonex.

    Related issues and pull requests on GitHub:
    :issue:1325.

Miscellaneous internal changes

  • Explicitly marked empty_htkeys as const.

    Moved the structure to .rodata linker section.

    Unexpected modification of the structure will lead to segfault instead
    of corrupting the data and fail fast.

    .rodata is mount as read-only-mapped, it is shared well across
    multiple threads without cache misses.

    The change is pretty trivial, it is made for the sake of correctness,
    not for speedup.

    -- by :user:asvetlov.

    Related issues and pull requests on GitHub:
    :issue:1405.

  • Slightly reorganized multidict creating process.

    1. Removed unnecessary calculations when md_init() creates an empty multidict.
    2. Now tp_alloc slot is used in object cloning instead of bare :c:func:PyType_GenericNew call.

    -- by :user:asvetlov

    Related issues and pull requests on GitHub:
    :issue:1420.

  • Dropped dead code, _md_del_at() and _md_del_at_for_upd() never fails
    -- by :user:asvetlov

    Related issues and pull requests on GitHub:
    :issue:1423.

  • Fixed a missing space in the :exc:ValueError message
    raised when constructing a multidict from a sequence
    -- by :user:veeceey.

    Related issues and pull requests on GitHub:
    :issue:1295.

  • Renamed the benchmark script from benchmarks/becnhmark.py to
    benchmarks/benchmark.py so it matches the invocation documented in
    :doc:benchmark -- by :user:aiolibsbot.

    Related issues and pull requests on GitHub:
    :issue:1335.


numpy/numpy (numpy)

v2.5.3

Compare Source

tox-dev/platformdirs (platformdirs)

v4.11.8

Compare Source

What's Changed

New Contributors

Full Changelog: tox-dev/platformdirs@4.11.7...4.11.8

v4.11.7

Compare Source

Full Changelog: tox-dev/platformdirs@4.11.6...4.11.7

aio-libs/propcache (propcache)

v0.5.4

Compare Source

=====

(2026-09-15)

Packaging updates and notes for downstreams

  • Fixed the release wheels being compiled without optimization since
    version 0.5.0. The build backend set CFLAGS to add
    -ffile-prefix-map, which replaced the interpreter's own compiler
    flags instead of extending them, so -O3 and -DNDEBUG were
    dropped; the extra flags now go through CPPFLAGS, which is
    appended. Cached property reads are about 1.5x faster than in 0.5.3
    -- by :user:bdraco.

    Related issues and pull requests on GitHub:
    :issue:244, :issue:302.


v0.5.3

Compare Source

=====

(2026-09-15)

Bug fixes

  • Fixed a possible crash in the C implementation of cached_property
    and under_cached_property on free-threaded Python, where a cached
    value could be freed by another thread while it was being read; errors
    raised while looking up the cache are now propagated on all builds,
    and the computed value is no longer leaked if storing it fails
    -- by :user:bdraco.

    Related issues and pull requests on GitHub:
    :issue:297.

Removals and backward incompatible breaking changes

  • Dropped support for free-threaded Python 3.13 -- by :user:Vizonex.

    Related issues and pull requests on GitHub:
    :issue:223.

Improved documentation

  • Updated discussion links from the defunct Google Groups forum to
    GitHub Discussions
    -- by :user:gundalow.

    Related issues and pull requests on GitHub:
    :issue:217.

Packaging updates and notes for downstreams

  • The setuptools build dependency lower bound has been restored to be
    >= 47 after an incorrect automated increase in :pr:207
    -- by :user:bbhtt.

    Related issues and pull requests on GitHub:
    :issue:207.

  • Dropped support for free-threaded Python 3.13 -- by :user:Vizonex.

    Related issues and pull requests on GitHub:
    :issue:223.

  • Dropped the deprecated License :: OSI Approved :: Apache Software License classifier; setuptools 84 warns about it and the dist
    build treats warnings as errors, so releases could no longer be built
    -- by :user:bdraco.

    Related issues and pull requests on GitHub:
    :issue:299.

Contributor-facing changes

  • Dependabot has been restricted to the requirements subdirectory to
    avoid unintended updates outside dependency requirement files
    -- by :user:bbhtt.

    Related issues and pull requests on GitHub:
    :issue:207.

  • Added an AGENTS.md file with contributor guidance for AI
    coding agents, adapted from the yarl equivalent
    -- by :user:bdraco.

    Related issues and pull requests on GitHub:
    :issue:231.

  • Migrated from standalone black and isort pre-commit hooks
    to ruff format and the ruff I lint rule, sharing a new
    [tool.ruff] config in pyproject.toml. ruff-check runs
    with --fix so import-order fixes apply on commit, and the
    orphan [isort] block in setup.cfg was removed
    -- by :user:bdraco.

    Related issues and pull requests on GitHub:
    :issue:232.

  • Switched the cibuildwheel build frontend to build[uv] so
    that uv provisions every build and test virtual environment
    in the wheel matrix. Test-dependency installation in particular
    drops from a multi-second pip install per ABI to a roughly
    sub-second uv resolve
    -- by :user:bdraco.

    Related issues and pull requests on GitHub:
    :issue:234.

  • Dropped the libffi-devel install from the cibuildwheel
    Linux before-all step. It was added in :pr:75 so
    cffi could build from source during wheel testing; the
    current wheel-test chain no longer pulls in cffi, so the
    header package is dead weight
    -- by :user:bdraco.

    Related issues and pull requests on GitHub:
    :issue:236.

  • The type preciseness coverage report generated by MyPy <https://mypy-lang.org>__ is now uploaded to Coveralls <https://coveralls.io/github/aio-libs/propcache>__ and
    will not be included in the Codecov views <https://app.codecov.io/gh/aio-libs/propcache>__ going forward
    -- by :user:aiolibsbot.

    Related issues and pull requests on GitHub:
    :issue:239.

  • Switched CI/CD to tox-dev/workflow's :file:reusable-tox.yml
    driven by an in-tree :file:tox.ini. The build,
    metadata-validation and lint (pre-commit,
    spellcheck-docs) jobs all run through the reusable workflow;
    mypy coverage uploads to Coveralls from a post-tox-job
    hook
    -- by :user:bdraco.

    Related issues and pull requests on GitHub:
    :issue:243.

  • Overrode CIBW_BUILD_FRONTEND=build for the QEMU-emulated
    odd-arch wheel matrix, since the pypa odd-arch container images
    do not ship uv preinstalled and the project's
    :file:pyproject.toml sets build-frontend = "build[uv]"
    -- by :user:bdraco.

    Related issues and pull requests on GitHub:
    :issue:246.

  • Allowed re-running the deploy job after a partial release failure: the
    Make Release step now skips when the GitHub Release already exists,
    and the PyPI publish step uses skip-existing so dists that were
    already uploaded on a prior attempt do not break the retry
    -- by :user:bdraco.

    Related issues and pull requests on GitHub:
    :issue:247.

  • Switched the aarch64 and armv7l wheel builds to GitHub's native ARM
    runners. The aarch64 wheels now build without QEMU emulation, and
    armv7l runs on aarch64 hosts so its 32-bit ARM execution is far
    cheaper than the previous aarch64-on-x86_64 path
    -- by :user:bdraco.

    Related issues and pull requests on GitHub:
    :issue:248.

  • Added UV_CONSTRAINT and UV_BUILD_CONSTRAINT alongside
    PIP_CONSTRAINT and PIP_BUILD_CONSTRAINT in the
    cibuildwheel environment so the :file:requirements/cython.txt
    pin is honored under the build[uv] frontend; uv pip
    ignores the PIP_ variables and reads only the UV_ ones,
    while the PIP_ variants are kept for the pip fallback path
    -- by :user:bdraco.

    Related issues and pull requests on GitHub:
    :issue:249.

  • Fixed coverage for testing benchmarks when codspeed is not installed
    -- by :user:Vizonex.

    Related issues and pull requests on GitHub:
    :issue:251.

  • Stopped running the test suite inside the wheel build jobs outside of
    release builds, since the test matrix installs and tests the same
    wheels, and added Python 3.15 and 3.15t to the test matrix so those
    wheels stay covered. Off-tag macOS builds are now limited to the
    architecture the test matrix runs on. Release builds still build every
    architecture and test every wheel, and all release checks in the CI
    workflow now use github.ref_type
    -- by :user:bdraco.

    Related issues and pull requests on GitHub:
    :issue:300.


alexmojaki/pure_eval (pure-eval)

v0.2.4

Compare Source

danielgatis/rembg (rembg)

v2.0.84

Compare Source

What's Changed

Full Changelog: danielgatis/rembg@v2.0.83...v2.0.84

v2.0.83

Compare Source

Full Changelog: danielgatis/rembg@v2.0.82...v2.0.83

v2.0.82

Compare Source

Full Changelog: danielgatis/rembg@v2.0.81...v2.0.82

astral-sh/ruff (ruff)

v0.16.7

Compare Source

Released on 2026-09-10.

Preview features
  • [ruff] Add rule for default values on method receivers (RUF077) (#​26700)
  • [ruff] Recognize re.prefixmatch (RUF039, RUF055) (#​28311)
Bug fixes
  • Alternate nested quotes inside format spec interpolations (#​28259)
  • [flake8-implicit-str-concat] Mark fix unsafe when it creates a docstring (ISC003) (#​27981)
  • [flake8-tidy-imports] Skip fixes for multi-member imports (TID254) (#​26584)
  • [pylint] Gate ImportCycleError on Python 3.15 (PLW0133) (#​28310)
Rule changes
  • Correct D211 and D203 rule conflict diagnostic (#​28444)
  • Recognize slice and frozendict generics (#​28477)
  • Stop defining __cached__ for Python 3.15 (#​28476)
  • [pyupgrade] Stop recommending removed typing.no_type_check_decorator (UP035) (#​28475)
Performance
  • Reuse parser name lookups when interning (#​28399)
  • Speed up inherited configuration resolution (#​28299)
Documentation
  • Fix line-length path in --config example (#​28392)
  • Remove the "Who’s Using Ruff?" list (#​28455)
Other changes
  • Embed archive checksums in the shell installer (#​28281)
Contributors

v0.16.6

Compare Source

Released on 2026-09-03.

Preview features
  • Move pytest-fixture-autouse to the restriction category (#​28219)
  • [flake8-pytest-style] Add an autofix for PT020 (#​27993)
  • [flake8-tidy-imports] Prevent fix loop between TID254 and TID255 (#​28262)
  • [isort] Exclude pragma comments from line length calculation (I001) (#​27313)
Bug fixes
  • Validate unary expressions when parsing (#​28233)
  • [flake8-async, pylint] Recognize builtins.open (ASYNC230, PLW1514) (#​28021)
  • [flake8-bugbear] Fix panic on match subjects (B031) (#​27781)
  • [flake8-datetimez] Reject tzinfo=None for datetime bounds (DTZ901) (#​28022)
  • [flake8-pytest-style] Avoid duplicate PT017 diagnostics (#​27918)
  • [ruff] Remove lint.external hi

Important

✂ PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the dependencies Pull requests that update a dependency file label Sep 1, 2026
@renovate

renovate Bot commented Sep 1, 2026

Copy link
Copy Markdown
Contributor Author

Branch automerge failure

This PR was configured for branch automerge. However, this is not possible, so it has been raised as a PR instead.


  • Branch has one or more failed status checks

@renovate
renovate Bot force-pushed the renovate/python-dependencies branch from 020e048 to 3253945 Compare September 2, 2026 22:51
@renovate renovate Bot changed the title chore(deps): Update dependency platformdirs to v4.11.7 chore(deps): Update python-dependencies Sep 2, 2026
@renovate
renovate Bot force-pushed the renovate/python-dependencies branch 15 times, most recently from bd730c6 to e17289f Compare September 9, 2026 22:26
@coderabbitai

coderabbitai Bot commented Sep 9, 2026

Copy link
Copy Markdown
Contributor

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 3626b956-e9f2-4c67-a7f4-23c6f3afc888

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@renovate
renovate Bot force-pushed the renovate/python-dependencies branch 10 times, most recently from 6419cfd to d28557d Compare September 11, 2026 08:36
@renovate
renovate Bot force-pushed the renovate/python-dependencies branch 12 times, most recently from 42930f1 to d45171a Compare September 15, 2026 21:41
@renovate
renovate Bot force-pushed the renovate/python-dependencies branch from d45171a to d7e7e49 Compare September 16, 2026 01:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants