Skip to content

chore(deps): uv: bump the all-python group across 1 directory with 6 updates - #626

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/agent/all-python-562714a858
Closed

chore(deps): uv: bump the all-python group across 1 directory with 6 updates#626
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/agent/all-python-562714a858

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 18, 2026

Copy link
Copy Markdown
Contributor

Bumps the all-python group with 6 updates in the /agent directory:

Package From To
boto3 1.43.40 1.43.48
bedrock-agentcore 1.17.0 1.18.0
claude-agent-sdk 0.2.110 0.2.119
uvicorn 0.50.0 0.51.0
ruff 0.15.20 0.15.21
ty 0.0.56 0.0.59

Updates boto3 from 1.43.40 to 1.43.48

Commits
  • aa40f37 Merge branch 'release-1.43.48'
  • 13cce5d Bumping version to 1.43.48
  • 24523ab Add changelog entries from botocore
  • 11b9978 Merge branch 'release-1.43.47'
  • d1530e3 Merge branch 'release-1.43.47' into develop
  • 2a7cd54 Bumping version to 1.43.47
  • 16f140d Add changelog entries from botocore
  • c7888d6 Merge branch 'release-1.43.46'
  • 7db70ea Merge branch 'release-1.43.46' into develop
  • 1479621 Bumping version to 1.43.46
  • Additional commits viewable in compare view

Updates bedrock-agentcore from 1.17.0 to 1.18.0

Release notes

Sourced from bedrock-agentcore's releases.

Bedrock AgentCore SDK v1.18.0

Installation

pip install bedrock-agentcore==1.18.0

What's Changed

See CHANGELOG.md for details.

What's Changed

New Contributors

Full Changelog: aws/bedrock-agentcore-sdk-python@v1.17.0...v1.18.0

Changelog

Sourced from bedrock-agentcore's changelog.

[1.18.0] - 2026-07-10

Fixed

  • fix: floor monotonic timestamps to milliseconds before comparison (#573) (f855616)
  • fix: order AgentCore Memory events at millisecond resolution (#572) (a271ab4)

Other Changes

  • ci: add API reference docs generation workflow (#569) (168f4be)
  • fix(payments): address langgraph middleware review follow-ups (#570) (46a0bea)
  • feat(payments): Add LangGraph integration for payment handling (#546) (0a8a486)
Commits
  • 8df87bb chore: bump version to 1.18.0 (#574)
  • f855616 fix: floor monotonic timestamps to milliseconds before comparison (#573)
  • a271ab4 fix: order AgentCore Memory events at millisecond resolution (#572)
  • 168f4be ci: add API reference docs generation workflow (#569)
  • 46a0bea fix(payments): address langgraph middleware review follow-ups (#570)
  • 0a8a486 feat(payments): Add LangGraph integration for payment handling (#546)
  • See full diff in compare view

Updates claude-agent-sdk from 0.2.110 to 0.2.119

Release notes

Sourced from claude-agent-sdk's releases.

v0.2.119

Internal/Other Changes

  • Updated bundled Claude CLI to version 2.1.210

PyPI: https://pypi.org/project/claude-agent-sdk/0.2.119/

pip install claude-agent-sdk==0.2.119

v0.2.118

Internal/Other Changes

  • Updated bundled Claude CLI to version 2.1.209

PyPI: https://pypi.org/project/claude-agent-sdk/0.2.118/

pip install claude-agent-sdk==0.2.118

v0.2.117

Bug Fixes

  • Escaped untrusted fields in Slack issue notification workflow: Fixed the Slack notification workflow to properly escape issue titles and usernames using jq instead of bash substitution, preventing malformed JSON payloads and mrkdwn injection from specially crafted issue titles (#1116)

Internal/Other Changes

  • Updated bundled Claude CLI to version 2.1.208

PyPI: https://pypi.org/project/claude-agent-sdk/0.2.117/

pip install claude-agent-sdk==0.2.117

v0.2.116

... (truncated)

Changelog

Sourced from claude-agent-sdk's changelog.

0.2.119

Internal/Other Changes

  • Updated bundled Claude CLI to version 2.1.210

0.2.118

Internal/Other Changes

  • Updated bundled Claude CLI to version 2.1.209

0.2.117

Bug Fixes

  • Escaped untrusted fields in Slack issue notification workflow: Fixed the Slack notification workflow to properly escape issue titles and usernames using jq instead of bash substitution, preventing malformed JSON payloads and mrkdwn injection from specially crafted issue titles (#1116)

Internal/Other Changes

  • Updated bundled Claude CLI to version 2.1.208

0.2.116

Internal/Other Changes

  • Updated bundled Claude CLI to version 2.1.207
  • Fixed CI workspace trust so Claude Code honors project-scoped permission grants in checkout directories (#1085)

0.2.115

Internal/Other Changes

  • Updated bundled Claude CLI to version 2.1.206

0.2.114

Internal/Other Changes

  • Updated bundled Claude CLI to version 2.1.205

0.2.113

Internal/Other Changes

  • Updated bundled Claude CLI to version 2.1.204

0.2.112

Internal/Other Changes

... (truncated)

Commits
  • 57f67cd docs: update changelog for v0.2.119
  • d434722 chore: release v0.2.119
  • a8da0ca chore: bump bundled CLI version to 2.1.210
  • b7e0d0f docs: update changelog for v0.2.118
  • 82fcdb7 chore: release v0.2.118
  • 5b7e676 chore: bump bundled CLI version to 2.1.209
  • 059d344 docs: update changelog for v0.2.117
  • 3aed422 chore: release v0.2.117
  • 67b6ec3 chore: bump bundled CLI version to 2.1.208
  • cc76ac9 Escape untrusted issue fields in the Slack notification workflow (#1116)
  • Additional commits viewable in compare view

Updates uvicorn from 0.50.0 to 0.51.0

Release notes

Sourced from uvicorn's releases.

Version 0.51.0

What's Changed

Full Changelog: Kludex/uvicorn@0.50.2...0.51.0

Version 0.50.1

What's Changed

New Contributors

Full Changelog: Kludex/uvicorn@0.50.0...0.50.1

Changelog

Sourced from uvicorn's changelog.

0.51.0 (July 8, 2026)

Added

  • Restart workers one at a time on SIGHUP, bringing each replacement up before retiring the old worker, so reloads no longer drop requests (#3025)

Removed

  • Remove colorama from the standard extra (#3027)

0.50.2 (July 6, 2026)

Fixed

  • Require websockets>=13.0, which the default websockets-sansio implementation needs (#3021)

0.50.1 (July 6, 2026)

Fixed

  • Split comma-separated Sec-WebSocket-Protocol values in the websockets-sansio implementation (#3019)
Commits
  • e4d0b05 Version 0.51.0 (#3028)
  • 944e43d Remove colorama from the standard extra (#3027)
  • 2e78770 Restart workers with overlap on SIGHUP for near-zero-downtime reloads (#3025)
  • a1b570c Version 0.50.2 (#3022)
  • 83c7da7 Require websockets>=13.0 for the default sansio implementation (#3021)
  • b4d0116 Version 0.50.1 (#3020)
  • 2a9151d Split comma-separated Sec-WebSocket-Protocol values in the websockets-sansi...
  • 1bf3ab4 Cover the excluded-directory branch in FileFilter with a direct test (#3014)
  • 837b5f9 Deflake multiprocess, reload, and signal supervisor tests (#2975)
  • See full diff in compare view

Updates ruff from 0.15.20 to 0.15.21

Release notes

Sourced from ruff's releases.

0.15.21

Release Notes

Released on 2026-07-09.

Preview features

  • Add --add-ignore for adding ruff:ignore comments (#26346)
  • [flake8-comprehensions] Drop C409 tuple comprehension preview behavior (#25707)
  • Avoid whitespace normalization when formatting comments (#26455)
  • [pyupgrade] Lint and fix use of deprecated abc decorators (UP051) (#26417)

Bug fixes

  • Refine non-empty f-string detection (#26526)
  • Detect syntax errors in individual notebook cells (#26419)
  • [flake8-implicit-str-concat] Fix ISC003 autofix incorrectly stripping + from comments (#26554)

Rule changes

  • [flake8-executable] Mark EXE004 fix as unsafe (#26033)
  • [flake8-pyi] Mark PYI061 fixes as unsafe in Python files (#26533)
  • [pydocstyle] Skip overload-with-docstring in stub files (D418) (#26318)

Performance

  • Avoid per-token source index visitor calls (#26506)
  • Cache parenthesized expression boundaries in the formatter (#26344)
  • Improve performance of rendering edits in preview mode (#26565)
  • Inline fits_element in formatter (#26429)
  • Inline formatter printing hot paths (#26504)
  • Lazily create builtin bindings (#26510)
  • Skip empty trivia scans in the source indexer (#26507)
  • Use ICF for macOS release builds (#25780)

Formatter

  • Add --extend-exclude to ruff format (#26372)

Documentation

  • Add "How does Ruff's import sorting compare to isort?" link to README (#26530)
  • Fix Mozilla Firefox repository link in README (#26537)
  • [flake8-bandit] Fix misleading docstring for mako-templates (S702) (#26432)
  • [ruff] Fix non-triggering example for if-key-in-dict-del (RUF051) (#26433)

Contributors

... (truncated)

Changelog

Sourced from ruff's changelog.

0.15.21

Released on 2026-07-09.

Preview features

  • Add --add-ignore for adding ruff:ignore comments (#26346)
  • [flake8-comprehensions] Drop C409 tuple comprehension preview behavior (#25707)
  • Avoid whitespace normalization when formatting comments (#26455)
  • [pyupgrade] Lint and fix use of deprecated abc decorators (UP051) (#26417)

Bug fixes

  • Refine non-empty f-string detection (#26526)
  • Detect syntax errors in individual notebook cells (#26419)
  • [flake8-implicit-str-concat] Fix ISC003 autofix incorrectly stripping + from comments (#26554)

Rule changes

  • [flake8-executable] Mark EXE004 fix as unsafe (#26033)
  • [flake8-pyi] Mark PYI061 fixes as unsafe in Python files (#26533)
  • [pydocstyle] Skip overload-with-docstring in stub files (D418) (#26318)

Performance

  • Avoid per-token source index visitor calls (#26506)
  • Cache parenthesized expression boundaries in the formatter (#26344)
  • Improve performance of rendering edits in preview mode (#26565)
  • Inline fits_element in formatter (#26429)
  • Inline formatter printing hot paths (#26504)
  • Lazily create builtin bindings (#26510)
  • Skip empty trivia scans in the source indexer (#26507)
  • Use ICF for macOS release builds (#25780)

Formatter

  • Add --extend-exclude to ruff format (#26372)

Documentation

  • Add "How does Ruff's import sorting compare to isort?" link to README (#26530)
  • Fix Mozilla Firefox repository link in README (#26537)
  • [flake8-bandit] Fix misleading docstring for mako-templates (S702) (#26432)
  • [ruff] Fix non-triggering example for if-key-in-dict-del (RUF051) (#26433)

Contributors

... (truncated)

Commits

Updates ty from 0.0.56 to 0.0.59

Release notes

Sourced from ty's releases.

0.0.59

Release Notes

Released on 2026-07-12.

Bug fixes

  • Guard descriptor classification cycles (#26690)
  • Respect init=False in dataclass field-order checks (#26749)
  • Avoid duplicate diagnostics for overloaded TypeIs (#26716)

Library support

  • Pydantic: Support custom __init__ methods (#26699)
  • Pydantic: Support field metadata in Annotated (#26650)

Core type checking

  • Allow unsound equality-based narrowing for builtins (#26414)
  • Bind Self in implicit dunder calls (#26711)
  • Correct protocol method receiver binding (#26701)
  • Exempt ParamSpec callables from the dunder descriptor heuristic (#26696)
  • Remove transitive TypeVar artifacts during collection inference (#26714)

LSP server

  • Avoid broad invalidation from file check eligibility (#26741)
  • Correct how we expand tabs in docstrings (#26679)
  • Resolve ambiguity in Google-style docstring parsing in favour of observations from popular projects (#26673)

CLI

  • Avoid allocation for every stdout write (#26698)
  • Buffer diagnostic output (#26702)

Performance

  • Cache generic context (#26745)
  • Cache known class instances (#26746)
  • Reuse common TypedDict constraints through intersections (#26747)
  • Use purpose-specific types for completion and module text (#26664)

Contributors

... (truncated)

Changelog

Sourced from ty's changelog.

0.0.59

Released on 2026-07-12.

Bug fixes

  • Guard descriptor classification cycles (#26690)
  • Respect init=False in dataclass field-order checks (#26749)
  • Avoid duplicate diagnostics for overloaded TypeIs (#26716)

Library support

  • Pydantic: Support custom __init__ methods (#26699)
  • Pydantic: Support field metadata in Annotated (#26650)

Core type checking

  • Allow unsound equality-based narrowing for builtins (#26414)
  • Bind Self in implicit dunder calls (#26711)
  • Correct protocol method receiver binding (#26701)
  • Exempt ParamSpec callables from the dunder descriptor heuristic (#26696)
  • Remove transitive TypeVar artifacts during collection inference (#26714)

LSP server

  • Avoid broad invalidation from file check eligibility (#26741)
  • Correct how we expand tabs in docstrings (#26679)
  • Resolve ambiguity in Google-style docstring parsing in favour of observations from popular projects (#26673)

CLI

  • Avoid allocation for every stdout write (#26698)
  • Buffer diagnostic output (#26702)

Performance

  • Cache generic context (#26745)
  • Cache known class instances (#26746)
  • Reuse common TypedDict constraints through intersections (#26747)
  • Use purpose-specific types for completion and module text (#26664)

Contributors

... (truncated)

Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels Jul 18, 2026
@dependabot
dependabot Bot requested review from a team as code owners July 18, 2026 06:14
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels Jul 18, 2026

@scottschreckengaust scottschreckengaust left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Verdict: Request changes

The build (agentcore) check is red, and I reproduced the cause in the worktree: it is a real incompatibility introduced by the ty 0.0.56 → 0.0.58 bump in this PR, not a flake. A second, quieter problem: the claude-agent-sdk bump silently breaks the documented Dockerfile CLI lockstep invariant (#215). Both must be resolved before merge. The other four bumps (boto3, bedrock-agentcore, uvicorn, ruff) are clean.

Vision alignment

Routine dependency hygiene under the repo's own .github/dependabot.yml uv / all-python group — no tenet impact, no blast-radius change, control plane untouched. Governance is satisfied: the Dependabot config is the standing authorization, so the ADR-003 approved-issue gate does not apply, and dependabot/uv/agent/all-python-... is the standard bot branch format (de-facto-waived nit). The change belongs — but a green build is table stakes, and keeping the CLI lockstep intact is exactly the kind of "bounded, improvable control plane" hygiene the vision calls for.

Blocking issues

B1 — ty 0.0.58 bump breaks the typecheck; the required suppressions/fixes are not in this PR (agent/uv.lock:189-211, source unchanged).
Root cause, verified by running both pins against the same worktree source:

  • uvx ty@0.0.56 checkAll checks passed (exit 0) — this is main's pin.
  • uv run ty check (this PR's 0.0.58) → Found 9 diagnostics (exit 1) — identical to the CI log for run 29633654727.

So the bump alone flips the build red. ty 0.0.58 changed two behaviors:

  1. It now treats frozen-Pydantic (ConfigDict(frozen=True)) fields as read-only properties and statically errors on assignment. Every failing site is inside a deliberate with pytest.raises(ValidationError): block that mutates a frozen model to assert the runtime rejects it — a correct, intentional test pattern (agent/tests/test_attachments.py:46; agent/tests/test_models.py:30,63,140,170,416,447). The test code is correct at runtime; only the new checker rejects it.
  2. It tightened dict-literal inference: content_trust={...} literals are inferred as dict[str, str], no longer assignable to Mapping[str, Literal["trusted","untrusted-external","memory"]] | None (agent/tests/test_models.py:237,244).

Fix (pick one, in this PR so it lands atomically with the bump):

  • Add targeted # ty: ignore[invalid-assignment] to the seven frozen-mutation lines and # ty: ignore[invalid-argument-type] (or annotate the literal, e.g. content_trust: dict[str, ContentTrust] = {...} / cast(...)) to the two content_trust sites; or
  • Hold ty at 0.0.56 (exclude it from this group bump) until the test suppressions are prepared separately.
    Merging as-is lands a red build on main.

B2 — claude-agent-sdk 0.2.116 breaks the #215 CLI lockstep; Dockerfile npm pin and comment not updated (agent/pyproject.toml:19, agent/Dockerfile:49,56).
The pin comment states the SDK is "kept in lockstep with the npm CLI pin in the Dockerfile, #215." Per the upstream v0.2.116 release notes, claude-agent-sdk 0.2.116 bundles Claude CLI 2.1.207, but:

  • agent/Dockerfile:56 still installs @anthropic-ai/claude-code@2.1.191.
  • agent/Dockerfile:49 comment still says "Pinned 2.1.191 to match the CLI bundled by claude-agent-sdk 0.2.110."
  • agent/pyproject.toml:19 comment still reads .../releases/tag/v0.2.110 (bundles claude CLI 2.1.191...) while pinning 0.2.116 — stale and now wrong on both the version and the CLI number.
    This is precisely the divergence the invariant exists to prevent: the SDK's bundled subprocess CLI (2.1.207) and the globally-installed npm CLI (2.1.191) would drift apart. Fix: bump the Dockerfile npm pin to @anthropic-ai/claude-code@2.1.207 and update both comments — or, if the mismatch is deliberate, document why in the comment. Note Dependabot cannot cross-update the Dockerfile npm pin from a uv group, so this must be done by hand on the branch.

Non-blocking suggestions / nits

  • N1 — ty is unpinned in pyproject.toml (agent/pyproject.toml:88, bare "ty",) yet pinned in uv.lock. That is why Dependabot moved it as part of the group even though there is no explicit == spec to bump. Consider pinning ty==<version> like the other dev tools so pre-release type-checker churn cannot silently re-break the build on the next lock refresh.
  • N2 — Branch name dependabot/uv/agent/all-python-562714a858 does not match (feat|fix|chore|docs)/<issue>-desc; standard for Dependabot, de-facto waived.

Documentation

No docs/guides/design changes required for a dep bump, and the Starlight mirror is untouched (no docs/ edits) — mirror-sync N/A. However, B2 is partly a documentation-accuracy defect: the pyproject.toml:19 and Dockerfile:49 comments are now factually stale (v0.2.110 / CLI 2.1.191) and must be corrected alongside the code fix.

Tests & CI

  • No test logic changed; the two edited files are agent/pyproject.toml and agent/uv.lock only.
  • CI: build (agentcore) FAILURE (the //agent:typecheck step — B1). Secrets, deps, and workflow scan SUCCESS, Validate PR title SUCCESS, Dead-code detection SUCCESS (advisory), CodeQL NEUTRAL, auto-approve SKIPPED. mergeStateStatus: BLOCKED on the red check.
  • Bootstrap synth-coverage: not applicable — no CDK construct/stack/handler or CFN resource-type change.
  • Supply-chain integrity (checked directly on the lock diff): all 50 added url/sdist entries carry sha256: hashes; no hash-stripped or unpinned lines; no new name = package sections (no stealth transitive additions — versions/hashes updated in place). No OSV/malware advisory names uvicorn 0.51.0, boto3 1.43.46, or bedrock-agentcore 1.18.0 as affected. bedrock-agentcore 1.18.0 release notes show no breaking changes.

Review agents run

  • /security-review (supply-chain scope) — Ran. Its auto-collected git context resolved to the repo root (empty diff), so I performed the supply-chain assessment directly against the lock diff in the worktree: hash-pin integrity, no unexpected/transitive package additions, and OSV/malware cross-check of the six versions (esp. the poisoned-"fix" pattern from the astro 7.1.0 / MAL-2026-10726 incident). No supply-chain findings.
  • code-reviewer — Effectively performed by hand for a two-file manifest diff: the load-bearing issues are B1 (version delta vs. CI) and B2 (cross-file lockstep with the Dockerfile), both covered above.
  • silent-failure-hunter — Omitted: no error-handling/fallback code in the diff (manifests only).
  • type-design-analyzer — Omitted: no new/changed types (the ty diagnostics are checker-behavior changes against existing types, addressed in B1).
  • comment-analyzer — In scope and applied: found the stale claude-agent-sdk comment (folded into B2/N1).
  • pr-test-analyzer — Omitted: no test code added/changed; the failing tests are unchanged and correct at runtime (the checker regressed, not the tests).

Human heuristics

  • Proportionality — Pass. A grouped patch/minor dep bump; scope matches the problem.
  • Coherence — Concern. The claude-agent-sdk SDK pin and the Dockerfile npm CLI pin encode the same concept (which Claude CLI version runs) and must move together per #215; this PR moves one and not the other (agent/pyproject.toml:19 vs agent/Dockerfile:56).
  • Clarity — Concern. The pyproject.toml:19 comment now misstates both the SDK release tag (v0.2.110) and the bundled CLI (2.1.191) after the bump to 0.2.116 / CLI 2.1.207.
  • Appropriateness — Concern. Verified against real upstream behavior, not mocks: I reproduced the typecheck delta with uvx ty@0.0.56 vs 0.0.58 and confirmed the bundled-CLI number from the upstream release notes. As shipped, the change is not mergeable (red build) and not maintainable-as-is (silent lockstep drift).

…updates

Bumps the all-python group with 6 updates in the /agent directory:

| Package | From | To |
| --- | --- | --- |
| [boto3](https://github.com/boto/boto3) | `1.43.40` | `1.43.48` |
| [bedrock-agentcore](https://github.com/aws/bedrock-agentcore-sdk-python) | `1.17.0` | `1.18.0` |
| [claude-agent-sdk](https://github.com/anthropics/claude-agent-sdk-python) | `0.2.110` | `0.2.119` |
| [uvicorn](https://github.com/Kludex/uvicorn) | `0.50.0` | `0.51.0` |
| [ruff](https://github.com/astral-sh/ruff) | `0.15.20` | `0.15.21` |
| [ty](https://github.com/astral-sh/ty) | `0.0.56` | `0.0.59` |



Updates `boto3` from 1.43.40 to 1.43.48
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](boto/boto3@1.43.40...1.43.48)

Updates `bedrock-agentcore` from 1.17.0 to 1.18.0
- [Release notes](https://github.com/aws/bedrock-agentcore-sdk-python/releases)
- [Changelog](https://github.com/aws/bedrock-agentcore-sdk-python/blob/main/CHANGELOG.md)
- [Commits](aws/bedrock-agentcore-sdk-python@v1.17.0...v1.18.0)

Updates `claude-agent-sdk` from 0.2.110 to 0.2.119
- [Release notes](https://github.com/anthropics/claude-agent-sdk-python/releases)
- [Changelog](https://github.com/anthropics/claude-agent-sdk-python/blob/main/CHANGELOG.md)
- [Commits](anthropics/claude-agent-sdk-python@v0.2.110...v0.2.119)

Updates `uvicorn` from 0.50.0 to 0.51.0
- [Release notes](https://github.com/Kludex/uvicorn/releases)
- [Changelog](https://github.com/Kludex/uvicorn/blob/main/docs/release-notes.md)
- [Commits](Kludex/uvicorn@0.50.0...0.51.0)

Updates `ruff` from 0.15.20 to 0.15.21
- [Release notes](https://github.com/astral-sh/ruff/releases)
- [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md)
- [Commits](astral-sh/ruff@0.15.20...0.15.21)

Updates `ty` from 0.0.56 to 0.0.59
- [Release notes](https://github.com/astral-sh/ty/releases)
- [Changelog](https://github.com/astral-sh/ty/blob/main/CHANGELOG.md)
- [Commits](astral-sh/ty@0.0.56...0.0.59)

---
updated-dependencies:
- dependency-name: bedrock-agentcore
  dependency-version: 1.18.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-python
- dependency-name: boto3
  dependency-version: 1.43.46
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all-python
- dependency-name: claude-agent-sdk
  dependency-version: 0.2.116
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all-python
- dependency-name: ruff
  dependency-version: 0.15.21
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: all-python
- dependency-name: ty
  dependency-version: 0.0.58
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: all-python
- dependency-name: uvicorn
  dependency-version: 0.51.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-python
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/uv/agent/all-python-562714a858 branch from c25c7f0 to b1b21df Compare July 22, 2026 19:00
@dependabot @github

dependabot Bot commented on behalf of github Jul 25, 2026

Copy link
Copy Markdown
Contributor Author

Looks like these dependencies are updatable in another way, so this is no longer needed.

@dependabot dependabot Bot closed this Jul 25, 2026
@dependabot
dependabot Bot deleted the dependabot/uv/agent/all-python-562714a858 branch July 25, 2026 06:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant