From 498e89df11bc9b019be0fb3f59762191e78cbbd8 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Fri, 2 Oct 2026 22:01:46 +0000 Subject: [PATCH 1/2] chore(deps): bump the backend-minor-and-patch group across 1 directory with 9 updates Bumps the backend-minor-and-patch group with 9 updates in the /apps/backend directory: | Package | From | To | | --- | --- | --- | | [fastapi](https://github.com/fastapi/fastapi) | `0.141.1` | `0.142.0` | | [uvicorn](https://github.com/Kludex/uvicorn) | `0.53.0` | `0.54.0` | | [pyjwt](https://github.com/jpadilla/pyjwt) | `2.14.0` | `2.15.1` | | [sqlalchemy](https://github.com/sqlalchemy/sqlalchemy) | `2.0.54` | `2.1.1` | | [xhtml2pdf](https://github.com/xhtml2pdf/xhtml2pdf) | `0.2.20` | `0.2.21` | | [ruff](https://github.com/astral-sh/ruff) | `0.16.8` | `0.16.9` | | [starlette](https://github.com/Kludex/starlette) | `1.6.0` | `1.7.0` | | [coverage](https://github.com/coveragepy/coveragepy) | `7.16.1` | `7.16.2` | | [librt](https://github.com/mypyc/librt) | `0.15.0` | `0.16.0` | Updates `fastapi` from 0.141.1 to 0.142.0 - [Release notes](https://github.com/fastapi/fastapi/releases) - [Commits](https://github.com/fastapi/fastapi/compare/0.141.1...0.142.0) Updates `uvicorn` from 0.53.0 to 0.54.0 - [Release notes](https://github.com/Kludex/uvicorn/releases) - [Changelog](https://github.com/Kludex/uvicorn/blob/main/docs/release-notes.md) - [Commits](https://github.com/Kludex/uvicorn/compare/0.53.0...0.54.0) Updates `pyjwt` from 2.14.0 to 2.15.1 - [Release notes](https://github.com/jpadilla/pyjwt/releases) - [Changelog](https://github.com/jpadilla/pyjwt/blob/master/CHANGELOG.rst) - [Commits](https://github.com/jpadilla/pyjwt/compare/2.14.0...2.15.1) Updates `sqlalchemy` from 2.0.54 to 2.1.1 - [Release notes](https://github.com/sqlalchemy/sqlalchemy/releases) - [Changelog](https://github.com/sqlalchemy/sqlalchemy/blob/main/CHANGES.rst) - [Commits](https://github.com/sqlalchemy/sqlalchemy/commits) Updates `xhtml2pdf` from 0.2.20 to 0.2.21 - [Release notes](https://github.com/xhtml2pdf/xhtml2pdf/releases) - [Commits](https://github.com/xhtml2pdf/xhtml2pdf/compare/v0.2.20...v0.2.21) Updates `ruff` from 0.16.8 to 0.16.9 - [Release notes](https://github.com/astral-sh/ruff/releases) - [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md) - [Commits](https://github.com/astral-sh/ruff/compare/0.16.8...0.16.9) Updates `starlette` from 1.6.0 to 1.7.0 - [Release notes](https://github.com/Kludex/starlette/releases) - [Changelog](https://github.com/Kludex/starlette/blob/main/docs/release-notes.md) - [Commits](https://github.com/Kludex/starlette/compare/1.6.0...1.7.0) Updates `coverage` from 7.16.1 to 7.16.2 - [Release notes](https://github.com/coveragepy/coveragepy/releases) - [Changelog](https://github.com/coveragepy/coveragepy/blob/main/CHANGES.rst) - [Commits](https://github.com/coveragepy/coveragepy/compare/7.16.1...7.16.2) Updates `librt` from 0.15.0 to 0.16.0 - [Commits](https://github.com/mypyc/librt/compare/v0.15.0...v0.16.0) --- updated-dependencies: - dependency-name: fastapi dependency-version: 0.142.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: backend-minor-and-patch - dependency-name: uvicorn dependency-version: 0.54.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: backend-minor-and-patch - dependency-name: pyjwt dependency-version: 2.15.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: backend-minor-and-patch - dependency-name: sqlalchemy dependency-version: 2.1.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: backend-minor-and-patch - dependency-name: xhtml2pdf dependency-version: 0.2.21 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: backend-minor-and-patch - dependency-name: ruff dependency-version: 0.16.9 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: backend-minor-and-patch - dependency-name: starlette dependency-version: 1.7.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: backend-minor-and-patch - dependency-name: coverage dependency-version: 7.16.2 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: backend-minor-and-patch - dependency-name: librt dependency-version: 0.16.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: backend-minor-and-patch ... Signed-off-by: dependabot[bot] --- apps/backend/pyproject.toml | 2 +- apps/backend/requirements-dev.txt | 6 +++--- apps/backend/requirements.txt | 12 ++++++------ 3 files changed, 10 insertions(+), 10 deletions(-) diff --git a/apps/backend/pyproject.toml b/apps/backend/pyproject.toml index 52312c6..97fd122 100644 --- a/apps/backend/pyproject.toml +++ b/apps/backend/pyproject.toml @@ -39,7 +39,7 @@ test = [ ] dev = [ "mypy==2.3.1", - "ruff==0.16.8", + "ruff==0.16.9", ] [tool.setuptools.packages.find] diff --git a/apps/backend/requirements-dev.txt b/apps/backend/requirements-dev.txt index 6b09ff0..7b069cb 100644 --- a/apps/backend/requirements-dev.txt +++ b/apps/backend/requirements-dev.txt @@ -4,13 +4,13 @@ # only requirements.txt; pytest must never ship in runtime dependencies (issue #185). -r requirements.txt ast-serialize==0.11.2 -coverage==7.16.1 +coverage==7.16.2 iniconfig==2.3.0 -librt==0.15.0 +librt==0.16.0 mypy==2.3.1 mypy_extensions==1.1.0 pathspec==1.1.1 pluggy==1.6.0 pytest==9.1.1 pytest-cov==7.1.0 -ruff==0.16.8 +ruff==0.16.9 diff --git a/apps/backend/requirements.txt b/apps/backend/requirements.txt index 3b03272..71ba91a 100644 --- a/apps/backend/requirements.txt +++ b/apps/backend/requirements.txt @@ -22,7 +22,7 @@ cryptography==50.0.1 cssselect2==0.10.1 dnspython==2.8.0 email-validator==2.3.0 -fastapi==0.141.1 +fastapi==0.142.0 greenlet==3.5.6 h11==0.16.0 html5lib==1.1 @@ -45,7 +45,7 @@ pydantic_core==2.46.5 Pygments==2.21.0 pyhanko-certvalidator==0.32.1 pyHanko==0.37.0 -PyJWT==2.14.0 +PyJWT==2.15.1 pypdf==6.19.0 python-bidi==0.6.11 python-dotenv==1.2.3 @@ -55,8 +55,8 @@ redis==8.1.0 reportlab==4.5.1 requests==2.34.2 six==1.17.0 -SQLAlchemy==2.0.54 -starlette==1.6.0 +SQLAlchemy==2.1.1 +starlette==1.7.0 svglib==2.2.0 tinycss2==1.5.1 tree-sitter==0.26.0 @@ -67,8 +67,8 @@ tzdata==2026.4 tzlocal==5.4.4 uritools==6.1.3 urllib3==2.8.0 -uvicorn==0.53.0 +uvicorn==0.54.0 watchfiles==1.3.0 webencodings==0.6.1 websockets==17.1 -xhtml2pdf==0.2.20 +xhtml2pdf==0.2.21 From 28b49f53f76e407bbf279d80ee0fa6c607ba1dba Mon Sep 17 00:00:00 2001 From: PARTH J ROHIT Date: Sun, 4 Oct 2026 16:43:54 +0100 Subject: [PATCH 2/2] fix(backend): narrow nullable observation_ref for SQLAlchemy 2.1 typing SQLAlchemy 2.1 types the joined RiEvidence.observation_ref column as int | None, so mypy rejects it as a dict key. The inner join already excludes nulls; make that explicit. --- apps/backend/app/insights/relationship_diagnostics.py | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/apps/backend/app/insights/relationship_diagnostics.py b/apps/backend/app/insights/relationship_diagnostics.py index 8e1a1a9..38e1804 100644 --- a/apps/backend/app/insights/relationship_diagnostics.py +++ b/apps/backend/app/insights/relationship_diagnostics.py @@ -205,6 +205,10 @@ def load_unresolved_relationship_context(db: Session, snapshot_id: str) -> Unres RiObservation.observed_kind == "import_binding", ) ).all(): + # The inner join already excludes a null observation_ref; this + # narrows the nullable column type SQLAlchemy 2.1 now reports. + if observation_ref is None: + continue referent = binding_referent_by_pk.get(observation_ref) if referent is None or not path: continue