Skip to content

chore(deps): bump the fastapi-minor-patch group across 1 directory with 4 updates - #342

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/reference-apps/fastapi/fastapi-minor-patch-a58c35b5a2
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/reference-apps/fastapi/fastapi-minor-patch-a58c35b5a2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown
Contributor

Bumps the fastapi-minor-patch group with 4 updates in the /reference-apps/fastapi directory: uvicorn, pymongo, aio-pika and pytest-mock.

Updates uvicorn from 0.52.4 to 0.54.0

Release notes

Sourced from uvicorn's releases.

Version 0.54.0

📨 Send metadata after the response body

uvicorn 0.54.0 adds response trailers and 103 Early Hints to its experimental HTTP/2 implementation through zttp.

uv add uvicorn==0.54.0 "zttp>=0.0.34"
  • Send HTTP/2 response trailers (#3146). The ASGI http.response.trailers extension lets applications send metadata, such as checksums, after the response body. Clients must send TE: trailers to receive them. Multiple trailer messages are combined before completing the response.
  • HTTP/2 remains experimental and opt-in. Enable it with --http zttp --http2. Upgrade-based h2c and WebSockets over HTTP/2 remain unsupported.

💡 Hint at resources before the final response

  • Send 103 Early Hints over HTTP/2 (#3137). Applications can use the ASGI http.response.early_hint extension to send resource hints before the final response. Each supplied link becomes a separate Link header.

Full changelog: 0.53.0...0.54.0

Version 0.53.0

🌐 Opt-in HTTP/2 support

uvicorn 0.53.0 adds experimental HTTP/2 through zttp, alongside a new zuvloop integration and connection-handling improvements.

uv add uvicorn==0.53.0
  • Serve HTTP/1.1 and HTTP/2 with zttp (#2982, #3101). Install zttp, then enable HTTP/2 with --http zttp --http2. Uvicorn negotiates HTTP/2 over TLS with ALPN and supports cleartext prior knowledge.
  • HTTP/2 remains experimental. Upgrade-based h2c and WebSockets over HTTP/2 are not supported.

⚙️ More event loop choice

  • Run Uvicorn with zuvloop (#3104). Install zuvloop separately and select it explicitly with --loop zuvloop on CPython 3.14 or newer.

🛡️ More reliable connections and proxies

  • Honor Connection: close token lists (#3103). Uvicorn now parses comma-separated tokens case-insensitively across HTTP implementations.
  • Trust IPv6 loopback proxies by default (#3119). The default FORWARDED_ALLOW_IPS value now includes ::1.
  • Keep upgraded WebSockets alive (#3107). Uvicorn cancels the HTTP keep-alive timer when the connection becomes a WebSocket.

Full changelog: 0.52.4...0.53.0

Changelog

Sourced from uvicorn's changelog.

0.54.0 (September 24, 2026)

HTTP/2 support remains experimental. Install zttp>=0.0.34 and enable it with --http zttp --http2.

Added

  • Add HTTP/2 response trailers through the ASGI http.response.trailers extension. Clients must send TE: trailers to receive them (#3146)
  • Add HTTP/2 103 Early Hints through the ASGI http.response.early_hint extension (#3137)

0.53.0 (September 14, 2026)

This release adds experimental HTTP/2 support through zttp. Enable it with --http zttp --http2. Upgrade-based h2c and WebSockets over HTTP/2 are not supported.

Added

  • Add experimental HTTP/2 support through zttp (#2982, #3101)
  • Add support for zuvloop (#3104)

Fixed

  • Handle comma-separated, case-insensitive Connection: close tokens across HTTP implementations (#3103)
  • Trust IPv6 loopback in the default FORWARDED_ALLOW_IPS value (#3119)
  • Cancel the HTTP keep-alive timer when upgrading to WebSocket (#3107)
Commits

Updates pymongo from 4.17.0 to 4.18.2

Release notes

Sourced from pymongo's releases.

PyMongo 4.18.2

Community notes: https://www.mongodb.com/community/forums/t/pymongo-4-18-2-released/343732

CVE-2026-96749 CVE-2026-96748 CVE-2026-96747

PyMongo 4.18.1

Community notes: https://www.mongodb.com/community/forums/t/pymongo-4-18-1-released/343338

PyMongo 4.18.0

Community notes: https://www.mongodb.com/community/forums/t/pymongo-4-18-released/343137

Changelog

Sourced from pymongo's changelog.

Changes in Version 4.18.2 (2026/09/24)

Version 4.18.2 is a bug fix release.

  • Hardened the bson buffer size guard against signed integer overflow. (CVE-2026-96749_).
  • Fixed connection string parsing to percent-decode each host individually. (CVE-2026-96748_).
  • Client-side field level encryption now rejects a KMS endpoint ending in .sock. (CVE-2026-96747_).

.. _CVE-2026-96749: https://www.cve.org/CVERecord?id=CVE-2026-96749 .. _CVE-2026-96748: https://www.cve.org/CVERecord?id=CVE-2026-96748 .. _CVE-2026-96747: https://www.cve.org/CVERecord?id=CVE-2026-96747

Issues Resolved ...............

See the PyMongo 4.18.2 release notes in JIRA_ for the list of resolved issues in this release.

.. _PyMongo 4.18.2 release notes in JIRA: https://jira.mongodb.org/secure/ReleaseNote.jspa?projectId=10004&version=52896

Changes in Version 4.18.1 (2026/09/10)

Version 4.18.1 is a bug fix release.

  • Use an exact match for the file ID in GridFS delete methods (CVE-2026-88029_).

.. _CVE-2026-88029: https://www.cve.org/CVERecord?id=CVE-2026-88029

Changes in Version 4.18.0 (2026/09/03)

PyMongo 4.18 brings a number of changes including:

  • Added srvAllowedHostsSuffix as a URI option and keyword argument to :class:~pymongo.synchronous.mongo_client.MongoClient and :class:~pymongo.asynchronous.mongo_client.AsyncMongoClient. When connecting via mongodb+srv://, this option overrides the default requirement that SRV-returned hosts share the same parent domain as the seed hostname, allowing hosts under a different domain suffix to be accepted. The suffix must not be a public suffix (per the Public Suffix List <https://publicsuffix.org/list/>_). See the :class:~pymongo.synchronous.mongo_client.MongoClient and :class:~pymongo.asynchronous.mongo_client.AsyncMongoClient documentation for security considerations.
  • Dropped support for MongoDB 4.2.
  • Added support for MongoDB 9.0.
  • PyPy support is deprecated and will be removed in a future release.

... (truncated)

Commits

Updates aio-pika from 10.0.1 to 10.1.0

Release notes

Sourced from aio-pika's releases.

10.1.0

What's Changed

Full Changelog: mosquito/aio-pika@10.0.4...10.1.0

10.0.4

What's Changed

Full Changelog: mosquito/aio-pika@10.0.3...10.0.4

10.0.3

What's Changed

Full Changelog: mosquito/aio-pika@10.0.2...10.0.3

10.0.2

What's Changed

Full Changelog: mosquito/aio-pika@10.0.1...10.0.2

Commits
  • 2a41f79 Merge pull request #720 from mosquito/fix/url-connection-options
  • d765739 Cover typed connection options with custom connection classes
  • aefa7c6 Fix overloads of connect and connect_robust methods
  • 301d711 Merge URL connection options and forward client properties
  • 6ea7396 Merge pull request #719 from mosquito/test/pool-consumer-recovery
  • 41322ff Cover pooled consumer recovery after broker restarts
  • 01b504d Merge pull request #718 from mosquito/test/channels-created-during-reconnect
  • cc584a5 Cover channel creation during connection restoration
  • ecddb11 Merge pull request #717 from mosquito/fix/stop-restore-on-close
  • edc1931 Stop automatic channel restoration when the connection closes
  • Additional commits viewable in compare view

Updates pytest-mock from 3.15.1 to 3.16.0

Release notes

Sourced from pytest-mock's releases.

v3.16.0

2026-09-27

  • #604: Fixed duplicate_iterators=True for async functions spied with mocker.spy.
  • #611: Fixed async mock assertion introspection to use awaited arguments instead of the latest call's arguments.
  • #606: mocker.resetall(return_value=True, side_effect=True) now also applies to non-callable mocks, such as those returned by mocker.create_autospec(SomeClass, instance=True). Previously both arguments were silently ignored for them.
  • #547: Added SpyType for annotating mocker.spy results.
  • Dropped support for EOL Python 3.9.
  • #147: Removed handling of RuntimeError: stop called on unstarted patcher, which can no longer occur in the supported Python versions.
  • Added support for Python 3.15.
Changelog

Sourced from pytest-mock's changelog.

3.16.0

2026-09-27

  • [#604](https://github.com/pytest-dev/pytest-mock/issues/604) <https://github.com/pytest-dev/pytest-mock/pull/604>_: Fixed duplicate_iterators=True for async functions spied with mocker.spy.
  • [#611](https://github.com/pytest-dev/pytest-mock/issues/611) <https://github.com/pytest-dev/pytest-mock/pull/611>_: Fixed async mock assertion introspection to use awaited arguments instead of the latest call's arguments.
  • [#606](https://github.com/pytest-dev/pytest-mock/issues/606) <https://github.com/pytest-dev/pytest-mock/pull/606>_: mocker.resetall(return_value=True, side_effect=True) now also applies to non-callable mocks, such as those returned by mocker.create_autospec(SomeClass, instance=True). Previously both arguments were silently ignored for them.
  • [#547](https://github.com/pytest-dev/pytest-mock/issues/547) <https://github.com/pytest-dev/pytest-mock/issues/547>_: Added SpyType for annotating mocker.spy results.
  • Dropped support for EOL Python 3.9.
  • [#147](https://github.com/pytest-dev/pytest-mock/issues/147) <https://github.com/pytest-dev/pytest-mock/issues/147>_: Removed handling of RuntimeError: stop called on unstarted patcher, which can no longer occur in the supported Python versions.
  • Added support for Python 3.15.
Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

…th 4 updates

Bumps the fastapi-minor-patch group with 4 updates in the /reference-apps/fastapi directory: [uvicorn](https://github.com/Kludex/uvicorn), [pymongo](https://github.com/mongodb/mongo-python-driver), [aio-pika](https://github.com/mosquito/aio-pika) and [pytest-mock](https://github.com/pytest-dev/pytest-mock).


Updates `uvicorn` from 0.52.4 to 0.54.0
- [Release notes](https://github.com/Kludex/uvicorn/releases)
- [Changelog](https://github.com/Kludex/uvicorn/blob/main/docs/release-notes.md)
- [Commits](Kludex/uvicorn@0.52.4...0.54.0)

Updates `pymongo` from 4.17.0 to 4.18.2
- [Release notes](https://github.com/mongodb/mongo-python-driver/releases)
- [Changelog](https://github.com/mongodb/mongo-python-driver/blob/main/doc/changelog.rst)
- [Commits](mongodb/mongo-python-driver@4.17.0...4.18.2)

Updates `aio-pika` from 10.0.1 to 10.1.0
- [Release notes](https://github.com/mosquito/aio-pika/releases)
- [Changelog](https://github.com/mosquito/aio-pika/blob/master/CHANGELOG.md)
- [Commits](mosquito/aio-pika@10.0.1...10.1.0)

Updates `pytest-mock` from 3.15.1 to 3.16.0
- [Release notes](https://github.com/pytest-dev/pytest-mock/releases)
- [Changelog](https://github.com/pytest-dev/pytest-mock/blob/main/CHANGELOG.rst)
- [Commits](pytest-dev/pytest-mock@v3.15.1...v3.16.0)

---
updated-dependencies:
- dependency-name: uvicorn
  dependency-version: 0.54.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: fastapi-minor-patch
- dependency-name: pymongo
  dependency-version: 4.18.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: fastapi-minor-patch
- dependency-name: aio-pika
  dependency-version: 10.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: fastapi-minor-patch
- dependency-name: pytest-mock
  dependency-version: 3.16.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: fastapi-minor-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Oct 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants