Skip to content

chore(deps): bump the python-dependencies group with 7 updates - #239

Merged
github-actions[bot] merged 1 commit into
masterfrom
dependabot/pip/master/python-dependencies-7f2f01e99a
Oct 5, 2026
Merged

github-actions[bot] merged 1 commit into
masterfrom
dependabot/pip/master/python-dependencies-7f2f01e99a

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 4, 2026

Copy link
Copy Markdown
Contributor

Bumps the python-dependencies group with 7 updates:

Package From To
cryptography 50.0.1 50.0.2
pyjwt 2.15.0 2.15.1
boto3 1.43.102 1.43.107
botocore 1.43.102 1.43.107
pytest-mock 3.15.1 3.16.0
pylint 4.0.9 4.1.1
mypy 2.3.1 2.4.0

Updates cryptography from 50.0.1 to 50.0.2

Changelog

Sourced from cryptography's changelog.

50.0.2 - 2026-09-30


* Updated Windows, macOS, and Linux wheels to be compiled with OpenSSL 4.0.3.
* Added ``abi3.abi3t`` wheels for free-threaded CPython 3.15 and later.
* Updated to PyO3 0.29.2, which fixes building ``cryptography`` on Cygwin and
  MSYS2.

.. _v50-0-1:

Commits

Updates pyjwt from 2.15.0 to 2.15.1

Release notes

Sourced from pyjwt's releases.

2.15.1

See the 2.15.1 changelog for complete release details.

Changelog

Sourced from pyjwt's changelog.

v2.15.1 <https://github.com/jpadilla/pyjwt/compare/2.15.0...2.15.1>__

Fixed


- Accept trailing Base64URL ``=`` padding when decoding JWS segments, so
  tokens issued by AWS ALB and similar systems verify instead of raising
  ``DecodeError: Invalid crypto padding``. Non-alphabet junk such as
  ``!!!!`` remains rejected (`[#1209](https://github.com/jpadilla/pyjwt/issues/1209) <https://github.com/jpadilla/pyjwt/issues/1209>`__).
Commits

Updates boto3 from 1.43.102 to 1.43.107

Commits

Updates botocore from 1.43.102 to 1.43.107

Commits
  • 646bd4e Merge branch 'release-1.43.107'
  • ed29178 Bumping version to 1.43.107
  • 6672725 Update endpoints model
  • f19f55e Update to latest models
  • ca596c7 Merge branch 'release-1.43.106'
  • 96abf2d Merge branch 'release-1.43.106' into develop
  • 1808528 Bumping version to 1.43.106
  • 3d316f0 Update endpoints model
  • 053554b Update to latest models
  • e9bb16c Merge branch 'release-1.43.105'
  • Additional commits viewable in compare view

Updates pytest-mock from 3.15.1 to 3.16.0

Release notes

Sourced from pytest-mock's releases.

v3.16.0

2026-09-27

  • #604: Fixed duplicate_iterators=True for async functions spied with mocker.spy.
  • #611: Fixed async mock assertion introspection to use awaited arguments instead of the latest call's arguments.
  • #606: mocker.resetall(return_value=True, side_effect=True) now also applies to non-callable mocks, such as those returned by mocker.create_autospec(SomeClass, instance=True). Previously both arguments were silently ignored for them.
  • #547: Added SpyType for annotating mocker.spy results.
  • Dropped support for EOL Python 3.9.
  • #147: Removed handling of RuntimeError: stop called on unstarted patcher, which can no longer occur in the supported Python versions.
  • Added support for Python 3.15.
Changelog

Sourced from pytest-mock's changelog.

3.16.0

2026-09-27

  • [#604](https://github.com/pytest-dev/pytest-mock/issues/604) <https://github.com/pytest-dev/pytest-mock/pull/604>_: Fixed duplicate_iterators=True for async functions spied with mocker.spy.
  • [#611](https://github.com/pytest-dev/pytest-mock/issues/611) <https://github.com/pytest-dev/pytest-mock/pull/611>_: Fixed async mock assertion introspection to use awaited arguments instead of the latest call's arguments.
  • [#606](https://github.com/pytest-dev/pytest-mock/issues/606) <https://github.com/pytest-dev/pytest-mock/pull/606>_: mocker.resetall(return_value=True, side_effect=True) now also applies to non-callable mocks, such as those returned by mocker.create_autospec(SomeClass, instance=True). Previously both arguments were silently ignored for them.
  • [#547](https://github.com/pytest-dev/pytest-mock/issues/547) <https://github.com/pytest-dev/pytest-mock/issues/547>_: Added SpyType for annotating mocker.spy results.
  • Dropped support for EOL Python 3.9.
  • [#147](https://github.com/pytest-dev/pytest-mock/issues/147) <https://github.com/pytest-dev/pytest-mock/issues/147>_: Removed handling of RuntimeError: stop called on unstarted patcher, which can no longer occur in the supported Python versions.
  • Added support for Python 3.15.
Commits

Updates pylint from 4.0.9 to 4.1.1

Release notes

Sourced from pylint's releases.

v4.1.1

What's new in Pylint 4.1.1?

Release date: 2026-09-29

Other Changes

  • Pylint 4.1.0 could not be uploaded to PyPI, because it required an unreleased version of dill on Python 3.15, and PyPI refuses such a dependency. 4.1.1 is the first 4.1 release available on PyPI, see the 4.1.0 changes below.

    Refs #11495

v4.1.0

What's new in Pylint 4.1.0?

Release date: 2026-09-29

Startup is about 25% faster thanks to lazy imports. The import checker caches its isort configuration, which makes pylint about 17% faster on ansible. Finding the files to lint with --recursive=y no longer walks ignored directories such as .venv or node_modules, which took seconds on large trees. The duplicate-code checker and symilar also received optimizations that result in considerable performance improvements and memory use reduction on larger codebases. For example, pandas analysis went from 20 min to 55 s and pylint does not get OOM-killed when analyzing cpython anymore.

Python 3.15 support progresses: the unpacking in comprehensions added by PEP 798 no longer raises false positives, and the standard library deprecations of Python 3.15 are followed.

For CI, there is a new built-in junit output format (--output-format=junit), the NO_COLOR and FORCE_COLOR environment variables are respected, and the files to lint can now be set with the files option in the configuration file.

New checks: looping-through-iterator, impossible-comparison, chained-comparison-all-equal and using-comprehension-unpacking-in-unsupported-version.

Running with --jobs no longer duplicates the messages of extensions or ignores extensions enabled in the configuration.

Plugin authors: the confidence parameter can no longer be None, except in is_message_enabled, and the MSG_STATE_* constants are deprecated in favor of the MessageDisableReason enum.

The required astroid version is now 4.3.2. See the astroid changelog for additional fixes, features, and performance improvements applicable to pylint.

... (truncated)

Commits
  • 8c6daca Bump pylint to 4.1.1, update changelog (#11499)
  • bdb17b3 [Backport maintenance/4.1.x] Only pin the unreleased dill for the tests (#11498)
  • 92bb7ba Bump pylint to 4.1.0, update changelog
  • 9144956 Fix a crash in import-private-name on attribute access rooted at a non-Name n...
  • 68366cb Fix false positive for unnecessary-lambda when variable is reassigned or de...
  • c741677 [pre-commit.ci] pre-commit autoupdate (#11488)
  • a9ebdf6 Add regression test for unsubscriptable-object FP on class_getitem (#11487)
  • b877d3b Do not flag ungrouped imports inside OS platform guards (#11217)
  • 87351be Update OSS-Fuzz docs for Python 3.14 (#11485)
  • 4f263c1 Fix access checks through called methods (#11456)
  • Additional commits viewable in compare view

Updates mypy from 2.3.1 to 2.4.0

Changelog

Sourced from mypy's changelog.

Mypy Release Notes

Next Release

Mypy 2.4

We've just uploaded mypy 2.4.0 to the Python Package Index (PyPI). Mypy is a static type checker for Python. This release includes new features, performance improvements and bug fixes. You can install it as follows:

python3 -m pip install -U mypy

You can read the full documentation for this release on Read the Docs.

Python 3.15 Support

Mypy 2.4 supports running on Python 3.15 and type checking most Python 3.15 features. This includes the new builtin sentinel type for sentinel values (PEP 661), which mypy now supports (see below for details). Lazy imports (PEP 810) and unpacking in comprehensions (PEP 798) are also supported. Closed TypedDicts (PEP 728) have been supported since mypy 2.2, but the extra_items TypedDict argument, also introduced in PEP 728, is still unsupported. Support for extra_items will be added in a future mypy release.

Native Parser Enabled by Default

Mypy now uses the new native parser by default. It's based on the Ruff parser, and it's significantly faster than the legacy parser, which uses the stdlib ast module. The native parser also has other benefits:

  • You can target newer Python versions and use recent Python syntax even when running mypy on an older Python version. For example, you can use --python-version 3.15 when running mypy on Python 3.14.
  • Stub files can use syntax that is newer than the target Python version. For example, stubs can use the PEP 695 generic class syntax (class Box[T]: ...) when running on or targeting Python 3.10.
  • Parallel type checking requires the native parser.

The legacy parser is still available through --no-native-parser, or native_parser = False in the config file (native_parser = false under [tool.mypy] in pyproject.toml). We are planning to remove the legacy parser in early 2027. If you run into a problem with the native parser, please report it on the issue tracker.

Unlike the legacy parser, the native parser doesn't support type comments for variables defined by for and with statements. These type comments are silently ignored, and the types of the variables are

... (truncated)

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the python-dependencies group with 7 updates:

| Package | From | To |
| --- | --- | --- |
| [cryptography](https://github.com/pyca/cryptography) | `50.0.1` | `50.0.2` |
| [pyjwt](https://github.com/jpadilla/pyjwt) | `2.15.0` | `2.15.1` |
| [boto3](https://github.com/boto/boto3) | `1.43.102` | `1.43.107` |
| [botocore](https://github.com/boto/botocore) | `1.43.102` | `1.43.107` |
| [pytest-mock](https://github.com/pytest-dev/pytest-mock) | `3.15.1` | `3.16.0` |
| [pylint](https://github.com/pylint-dev/pylint) | `4.0.9` | `4.1.1` |
| [mypy](https://github.com/python/mypy) | `2.3.1` | `2.4.0` |


Updates `cryptography` from 50.0.1 to 50.0.2
- [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst)
- [Commits](pyca/cryptography@50.0.1...50.0.2)

Updates `pyjwt` from 2.15.0 to 2.15.1
- [Release notes](https://github.com/jpadilla/pyjwt/releases)
- [Changelog](https://github.com/jpadilla/pyjwt/blob/master/CHANGELOG.rst)
- [Commits](jpadilla/pyjwt@2.15.0...2.15.1)

Updates `boto3` from 1.43.102 to 1.43.107
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](boto/boto3@1.43.102...1.43.107)

Updates `botocore` from 1.43.102 to 1.43.107
- [Commits](boto/botocore@1.43.102...1.43.107)

Updates `pytest-mock` from 3.15.1 to 3.16.0
- [Release notes](https://github.com/pytest-dev/pytest-mock/releases)
- [Changelog](https://github.com/pytest-dev/pytest-mock/blob/main/CHANGELOG.rst)
- [Commits](pytest-dev/pytest-mock@v3.15.1...v3.16.0)

Updates `pylint` from 4.0.9 to 4.1.1
- [Release notes](https://github.com/pylint-dev/pylint/releases)
- [Commits](pylint-dev/pylint@v4.0.9...v4.1.1)

Updates `mypy` from 2.3.1 to 2.4.0
- [Changelog](https://github.com/python/mypy/blob/master/CHANGELOG.md)
- [Commits](python/mypy@v2.3.1...v2.4.0)

---
updated-dependencies:
- dependency-name: cryptography
  dependency-version: 50.0.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python-dependencies
- dependency-name: pyjwt
  dependency-version: 2.15.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python-dependencies
- dependency-name: boto3
  dependency-version: 1.43.107
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python-dependencies
- dependency-name: botocore
  dependency-version: 1.43.107
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python-dependencies
- dependency-name: pytest-mock
  dependency-version: 3.16.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: python-dependencies
- dependency-name: pylint
  dependency-version: 4.1.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: python-dependencies
- dependency-name: mypy
  dependency-version: 2.4.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: python-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added auto update Changes by automated library update tool infrastructure Project setup and deployment no RN No release notes required labels Oct 4, 2026
@github-actions
github-actions Bot enabled auto-merge (squash) October 4, 2026 23:53
@coderabbitai

coderabbitai Bot commented Oct 4, 2026

Copy link
Copy Markdown
Contributor

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 59211f2c-78e4-43b0-a352-3c9d2e492391

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions
github-actions Bot merged commit 92100d8 into master Oct 5, 2026
10 of 11 checks passed
@github-actions
github-actions Bot deleted the dependabot/pip/master/python-dependencies-7f2f01e99a branch October 5, 2026 12:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

auto update Changes by automated library update tool infrastructure Project setup and deployment no RN No release notes required

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant