Skip to content

chore(deps): bump the python-version-updates group across 1 directory with 4 updates - #64

Merged
blackaxgit merged 1 commit into
mainfrom
dependabot/uv/python-version-updates-5cdb71f4d2
Sep 30, 2026
Merged

blackaxgit merged 1 commit into
mainfrom
dependabot/uv/python-version-updates-5cdb71f4d2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 28, 2026

Copy link
Copy Markdown
Contributor

Bumps the python-version-updates group with 4 updates in the / directory: mcp, hypothesis, opentelemetry-sdk and ruff.

Updates mcp from 2.1.1 to 2.2.0

Release notes

Sourced from mcp's releases.

v2.2.0

pip install -U mcp. Docs: https://py.sdk.modelcontextprotocol.io/

A few defaults changed in this release. If you run a server or client on 2.x, skim these first:

Behaviour changes

HTTP client redirects are only followed within the endpoint's origin (#3397)

  • Client("https://..."), streamable_http_client and sse_client follow a redirect only if it stays on the same scheme, host and port (or upgrades http to https on the same host).
  • A redirect anywhere else is not followed: the call fails with MCPError and the session stays usable (an SSE connect fails with httpx2.HTTPStatusError). If that other URL is the server you meant, use it as the endpoint URL.
  • The follow_redirects setting on an httpx2.AsyncClient you pass in is no longer used for MCP requests, so you don't need it for the trailing-slash redirect any more.
  • The OAuth providers apply the same rule to their own requests.

Idle Streamable HTTP sessions now expire (legacy <=2025-11-25 spec( (#3395)

  • A stateful session with nothing in flight for 30 minutes is closed. The client's next request gets a 404 and it has to initialize again.
  • Clients that keep the GET stream open (the SDK's Client does) are not affected. Neither are stateless servers or 2026-07-28 connections.
  • A server also holds at most 10 000 sessions at once; beyond that, new sessions get a 503.
  • To turn either off: mcp.run(transport="streamable-http", session_idle_timeout=None, max_sessions=None) (also on streamable_http_app() and run_streamable_http_async()).

The OAuth client checks the authorization server's issuer on the legacy path too (#3398)

  • For servers without protected resource metadata, authorization server metadata whose issuer isn't the server's own origin is now rejected with OAuthFlowError: Authorization server metadata issuer mismatch. The protected-resource-metadata path has done this since 2.0.
  • A 403 that isn't an insufficient_scope challenge is returned to the caller instead of retried.
  • If protected resource metadata can't be fetched because of a 5xx/429, the flow now stops instead of falling back to the legacy endpoints.

Two new MCPDeprecationWarnings (#3435, #3447)

  • ClientCredentialsOAuthProvider / PrivateKeyJWTOAuthProvider without issuer=. Pass your authorization server's issuer URL; 3.0 will require it.
  • AuthSettings with resource_server_url set but validate_token_resource unset. Set it to True or False; 3.0 defaults it to True.
  • Both keep working as before in 2.x; this mostly matters if your tests turn warnings into errors.

New

  • AuthSettings.validate_token_resource: only accept tokens your TokenVerifier reports as issued for this server (#3447).
  • issuer= on ClientCredentialsOAuthProvider and PrivateKeyJWTOAuthProvider (#3398).
  • session_idle_timeout= and max_sessions= on the Streamable HTTP server entry points (#3395).

Fixes

  • A client DELETE frees its session immediately, and a refused opening request no longer leaves a session behind (#2455, #3228, #3300).
  • $refs in a tool's outputSchema resolve within that schema only; an unresolvable one surfaces as RuntimeError: Invalid schema for tool ... (#3394).

Known gaps

The tasks extension (SEP-2663), DPoP (SEP-1932) and the jwt-bearer grant are not implemented yet; https://github.com/modelcontextprotocol/python-sdk/blob/main/ROADMAP.md tracks them.

What's Changed

... (truncated)

Commits
  • 9972c21 Replace RootModel wrappers with type aliases and TypeAdapter validation (#3470)
  • fd66270 docs: refresh translations, and translate pages in parallel (#3458)
  • 08a3bc8 docs: ask for AI disclosure on comments too (#3459)
  • 7bb486a docs: stop presenting the in-memory client as the way to connect (#3443)
  • 0c91368 Add AuthSettings.validate_token_resource to check a bearer token's resource (...
  • 9771e6b Keep following a relative redirect when the endpoint URL carries userinfo (#3...
  • a925e55 Bump the locked versions of eight dev and test dependencies (#3449)
  • e8b9486 Bump pymdown-extensions from 11.0 to 11.0.1 (#3285)
  • c6762e8 Follow redirects only within the MCP endpoint's origin (#3397)
  • 5fd3abc Skip automatic docs previews for fork PRs and drop the setup-uv retry steps (...
  • Additional commits viewable in compare view

Updates hypothesis from 6.167.1 to 6.168.1

Commits
  • 6cee8ce Bump hypothesis version to 6.168.1 and update changelog
  • d97fdf3 Merge pull request #4879 from Liam-DeVoe/more-wheels
  • 37da03c publish wheels for s390x and i686+musl
  • cd434f2 Bump hypothesis version to 6.168.0 and update changelog
  • 3187fb9 Merge pull request #4868 from Zac-HD/claude/hypothesis-datetime-strategy-ajzai0
  • a60dc77 Reduce rate of tricky datetimes
  • 67e5c04 Merge pull request #4875 from HypothesisWorks/create-pull-request/patch
  • ecaed93 Merge remote-tracking branch 'upstream/master' into plait/review-hypothesis-4868
  • 116ef84 Probe backwards for bound windows before the scan range
  • ef17651 Bound the cache of probed timezone transitions
  • Additional commits viewable in compare view

Updates opentelemetry-sdk from 1.44.0 to 1.45.0

Release notes

Sourced from opentelemetry-sdk's releases.

Version 1.45.0/0.66b0

Added

  • opentelemetry-exporter-prometheus: add support to configure Resource attributes as metric labels (#5122)
  • infra: add renovate (#5202)
  • opentelemetry-api, opentelemetry-sdk: add support for extended attribute values everywhere. (#5266)
  • opentelemetry-sdk: wire the top-level log_level field in declarative configuration — when set, maps the OTel SeverityNumber value to a Python logging level and applies it to the opentelemetry logger so SDK internal diagnostics respect the configured severity. (#5351)
  • opentelemetry-sdk: add the new stable AlwaysRecordSampler (#5354)
  • opentelemetry-configuration, opentelemetry-sdk: wire top-level attribute_limits into per-signal providers via declarative config; add log_record_limits support to LoggerProvider (#5365)
  • opentelemetry-exporter-otlp-json-http: add OTLP JSON HTTP exporter package (#5374)
  • opentelemetry-api, opentelemetry-sdk: add enabled() support to the Logger API, SDK, and LogRecordProcessor to let instrumentation skip expensive work when logging is disabled (#5380)
  • opentelemetry-exporter-otlp-json-file: add OTLP JSON file Docker tests (#5412)
  • opentelemetry-configuration: wire the experimental tracer_configurator/development, meter_configurator/development and logger_configurator/development fields into create_tracer_provider, create_meter_provider and create_logger_provider, so per-instrumentation-scope enabled overrides declared in the config file are applied to the provider (previously these fields were parsed but silently discarded). The logger minimum_severity/trace_based fields are not supported by the Python SDK and are ignored with a warning. (#5418)
  • docs/examples: add example on how to manually setup the SDK to get SDK metrics (#5449)
  • opentelemetry-docker-tests: add Prometheus exporter docker tests (#5457)
  • opentelemetry-sdk: count records dropped after shutdown on otel.sdk.processor.{span,log}.processed with error.type=already_shutdown (batch span/log and simple log processors), which the semantic conventions define as a valid value for this metric. (#5509)
  • opentelemetry-semantic-conventions: update semantic conventions to v1.44.0 (#5511)
  • opentelemetry-sdk: add host.id to the host resource detector (#5653)
  • opentelemetry-test-utils: add CapturingSampler to record what samplers receive in instrumentation tests (#5681)

Changed

  • Enable PIE (flake8-pie) ruff rule and fix all violations (#5150)
  • The public opentelemetry.util.types.AttributeValue type in package opentelemetry-api is being expanded to include None, heterogeneous sequences of primitive types (and nested sequences) as opposed to only homogeneous primitive sequences, and Mappings of strings to any primitive types or sequences/mappings (which themselves must only contain primitive types or sequences/mappings validated the same way). If a bytes type is set as an attribute value in the SDK, it will no longer be utf-8 decoded to a string, instead it will be passed along as is in accordance with the OTEL spec, since bytes is a valid type in the OTLP proto. (#5266)
  • opentelemetry-exporter-otlp-proto-http: add a max_request_size argument to the OTLP HTTP exporters (traces, logs, metrics); serialized requests larger than the limit are dropped before sending, measured before compression. Defaults to 64 MiB (enabled); set to 0 to disable. Mirrors opentelemetry-go#8157. (#5369)
  • [BREAKING] opentelemetry-api: subclasses of Logger need to implement the enabled method (#5380)
  • opentelemetry-exporter-otlp-proto-http: refactor to use shared opentelemetry-exporter-otlp-common and opentelemetry-exporter-http-transport packages and switch default HTTP backend to urllib3 (#5389)
  • opentelemetry-sdk: unify logging force_flush timeout defaults to 30000ms (#5438)
  • opentelemetry-python: enable Ruff default ruleset and fix auto-fixable lint issues (#5491)
  • opentelemetry-sdk: SimpleSpanProcessor now drops spans ended after shutdown() instead of passing them to the exporter, and counts them on otel.sdk.processor.span.processed with error.type=already_shutdown. (#5512)
  • Bump pytest to 9.0.3 (#5518)
  • opentelemetry-exporter-otlp-proto-http: clarify that the endpoint= kwarg requires the full signal path (#5633)
  • opentelemetry-sdk: fix typos in SpanLimits docstring (#5658)

Fixed

  • opentelemetry-configuration: perform environment variable substitution on scalar values after parsing the configuration file, so ${VAR} references inside comments and mapping keys are no longer substituted and undefined references in comments no longer abort loading (#5407)
  • opentelemetry-configuration: declarative config environment variable substitution now replaces an unset variable that has no default with an empty value instead of raising an error, per the configuration spec. Resource attributes whose value resolves to null (an unset ${VAR} with no default) are skipped with a warning instead of being inserted as a null value. (#5408)
  • 'scripts/build.sh: add opentelemetry-configurationandopentelemetry-proto-json` to the package to release (#5425)
  • opentelemetry-sdk: fix View instrument-name matching so a view configured with an instrument's real (mixed-case) name is applied; matching is now case-insensitive and platform-independent instead of relying on fnmatch's OS-dependent case handling (#5430)
  • opentelemetry-sdk: fix missing f-prefix in exponential histogram error messages (#5434)
  • opentelemetry-configuration: resolve false-positive warning logs for newer schema minor version (#5436)
  • opentelemetry-sdk: make methods on FixedSizeExemplarReservoirABC thread safe (#5437)
  • opentelemetry-propagator-jaeger: fix typing issues and enable pyright typechecking for the package opentelemetry-propagator-jaeger: skip uberctx- baggage headers with an empty value on extraction instead of raising TypeError (#5440)
  • opentelemetry-sdk: fix TypeError when instantiating a _BaseConfigurator subclass whose __init__ takes arguments (#5441)
  • opentelemetry-sdk: fix TypeError in os.fork() when a BatchProcessor or PeriodicExportingMetricReader is garbage collected (#5453)
  • opentelemetry-configuration: a declarative config key present with an empty (null) value on an object-typed node (e.g. always_on:, a - service: detector, or a metric console: exporter) is now treated the same as an explicit empty config (always_on: {}) instead of failing type dispatch or silently skipping the node. Both dict-typed nodes and dataclasses constructible with no arguments are covered. (#5454)
  • opentelemetry-api: fix copy-pasted log message in SpanContext.__delattr__ (#5455)
  • opentelemetry-sdk: reject views with ExponentialBucketHistogramAggregation for asynchronous instruments instead of silently producing no data (#5461)
  • opentelemetry-sdk: fill every bucket of SimpleFixedSizeExemplarReservoir before random sampling (#5462)

... (truncated)

Changelog

Sourced from opentelemetry-sdk's changelog.

Version 1.45.0/0.66b0 (2026-09-25)

Added

  • opentelemetry-exporter-prometheus: add support to configure Resource attributes as metric labels (#5122)
  • infra: add renovate (#5202)
  • opentelemetry-api, opentelemetry-sdk: add support for extended attribute values everywhere. (#5266)
  • opentelemetry-sdk: wire the top-level log_level field in declarative configuration — when set, maps the OTel SeverityNumber value to a Python logging level and applies it to the opentelemetry logger so SDK internal diagnostics respect the configured severity. (#5351)
  • opentelemetry-sdk: add the new stable AlwaysRecordSampler (#5354)
  • opentelemetry-configuration, opentelemetry-sdk: wire top-level attribute_limits into per-signal providers via declarative config; add log_record_limits support to LoggerProvider (#5365)
  • opentelemetry-exporter-otlp-json-http: add OTLP JSON HTTP exporter package (#5374)
  • opentelemetry-api, opentelemetry-sdk: add enabled() support to the Logger API, SDK, and LogRecordProcessor to let instrumentation skip expensive work when logging is disabled (#5380)
  • opentelemetry-exporter-otlp-json-file: add OTLP JSON file Docker tests (#5412)
  • opentelemetry-configuration: wire the experimental tracer_configurator/development, meter_configurator/development and logger_configurator/development fields into create_tracer_provider, create_meter_provider and create_logger_provider, so per-instrumentation-scope enabled overrides declared in the config file are applied to the provider (previously these fields were parsed but silently discarded). The logger minimum_severity/trace_based fields are not supported by the Python SDK and are ignored with a warning. (#5418)
  • docs/examples: add example on how to manually setup the SDK to get SDK metrics (#5449)
  • opentelemetry-docker-tests: add Prometheus exporter docker tests (#5457)
  • opentelemetry-sdk: count records dropped after shutdown on otel.sdk.processor.{span,log}.processed with error.type=already_shutdown (batch span/log and simple log processors), which the semantic conventions

... (truncated)

Commits
  • 4f0fcfa Prepare release 1.45.0/0.66b0 (#5690)
  • 9406f34 opentelemetry-test-utils: add CapturingSampler for instrumentation tests (#5681)
  • 1fe31a9 fix: update W3CBaggagePropagator to properly handle whitespace (#5680)
  • 008b5b0 feat(config): wire top-level attribute_limits into per-signal providers (#5365)
  • edfad0c [opentelemetry-sdk] Fix overwriting of the service.instance.id which has been...
  • f5e0f62 opentelemetry-sdk: unify logging force_flush timeout defaults to 30000ms (#5438)
  • e4021aa chore(ci): update ci (#5677)
  • 0c6508c ci: restrict checkout credential persistence (#5589)
  • 2e88971 Add host.id to host resource attributes (#5653)
  • 5f851d2 opentelemetry-exporter-otlp-proto-grpc: fix incorrect default port for gRPC i...
  • Additional commits viewable in compare view

Updates ruff from 0.16.6 to 0.16.9

Release notes

Sourced from ruff's releases.

0.16.9

Release Notes

Released on 2026-09-24.

Preview features

  • [ruff] Avoid false positives for overloaded division (RUF069) (#28309)

Bug fixes

  • [flake8-bugbear] Avoid false positives for calls with keyword arguments (B009, B010, B043) (#28776)
  • [flake8-tidy-imports] Allow lazy imports to be used in deferred annotations (TID255) (#28767)

Rule changes

  • Update LibCST-based fixes for Python 3.15 (#28616)
  • [flake8-pyi] Mention stubs in the diagnostic message (PYI002) (#28542)

Documentation

  • Fix horizontal overflow on the rules documentation page (#28699)
  • Update rules table with category information (#28651)
  • [flake8-annotations] Clarify that ANN401 checks return types in addition to arguments (#28334)
  • [flake8-bugbear] Document type-checker interaction (B010) (#28509)
  • [flake8-comprehensions] Document map/generator exception behavior (C417) (#27794)
  • [ruff] Mention related isort settings (RUF022) (#28719)

Contributors

Install ruff 0.16.9

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/ruff/releases/download/0.16.9/ruff-installer.sh | sh

... (truncated)

Changelog

Sourced from ruff's changelog.

0.16.9

Released on 2026-09-24.

Preview features

  • [ruff] Avoid false positives for overloaded division (RUF069) (#28309)

Bug fixes

  • [flake8-bugbear] Avoid false positives for calls with keyword arguments (B009, B010, B043) (#28776)
  • [flake8-tidy-imports] Allow lazy imports to be used in deferred annotations (TID255) (#28767)

Rule changes

  • Update LibCST-based fixes for Python 3.15 (#28616)
  • [flake8-pyi] Mention stubs in the diagnostic message (PYI002) (#28542)

Documentation

  • Fix horizontal overflow on the rules documentation page (#28699)
  • Update rules table with category information (#28651)
  • [flake8-annotations] Clarify that ANN401 checks return types in addition to arguments (#28334)
  • [flake8-bugbear] Document type-checker interaction (B010) (#28509)
  • [flake8-comprehensions] Document map/generator exception behavior (C417) (#27794)
  • [ruff] Mention related isort settings (RUF022) (#28719)

Contributors

0.16.8

Released on 2026-09-16.

Bug fixes

  • Visit functional TypedDict keyword arguments correctly (#28584)
  • [flake8-simplify] Detect nested async with under sync parent (SIM117) (#27821)
  • [flake8-simplify] Preserve operand order in SIM109 fix (#27824)

... (truncated)

Commits
  • 0be08a2 Bump version to 0.16.9 (#28882)
  • b4920b7 Rename ruff_cli to ruff_command_line (#28881)
  • 47c751b Update dependency astral-sh/uv to v0.12.18 (#28880)
  • 8c244e5 [flake8-comprehensions] Document map/generator exception behavior (C417...
  • 5edf5a1 Use target form in rooster.version_files (#28876)
  • 915bb2b [ty] Prefer existing @ paths over response files in Ruff and ty (#28877)
  • 4710e1a ci(github): update version number in placeholder of issue template (#28871)
  • eedfc62 [ty] Propagate outer type context through cast calls (#28855)
  • ceaa6a0 [ty] Contain rendered code within Markdown fences (#28869)
  • dba0f30 authorize ruff-pre-commit dispatch via OIDC (#28867)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

… with 4 updates

Bumps the python-version-updates group with 4 updates in the / directory: [mcp](https://github.com/modelcontextprotocol/python-sdk), [hypothesis](https://github.com/HypothesisWorks/hypothesis), [opentelemetry-sdk](https://github.com/open-telemetry/opentelemetry-python) and [ruff](https://github.com/astral-sh/ruff).


Updates `mcp` from 2.1.1 to 2.2.0
- [Release notes](https://github.com/modelcontextprotocol/python-sdk/releases)
- [Changelog](https://github.com/modelcontextprotocol/python-sdk/blob/main/RELEASE.md)
- [Commits](modelcontextprotocol/python-sdk@v2.1.1...v2.2.0)

Updates `hypothesis` from 6.167.1 to 6.168.1
- [Release notes](https://github.com/HypothesisWorks/hypothesis/releases)
- [Commits](HypothesisWorks/hypothesis@v6.167.1...v6.168.1)

Updates `opentelemetry-sdk` from 1.44.0 to 1.45.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-python/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-python/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-python@v1.44.0...v1.45.0)

Updates `ruff` from 0.16.6 to 0.16.9
- [Release notes](https://github.com/astral-sh/ruff/releases)
- [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md)
- [Commits](astral-sh/ruff@0.16.6...0.16.9)

---
updated-dependencies:
- dependency-name: mcp
  dependency-version: 2.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-version-updates
- dependency-name: hypothesis
  dependency-version: 6.168.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-version-updates
- dependency-name: opentelemetry-sdk
  dependency-version: 1.45.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-version-updates
- dependency-name: ruff
  dependency-version: 0.16.9
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python-version-updates
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels Sep 28, 2026
@blackaxgit
blackaxgit merged commit 64ddc7d into main Sep 30, 2026
7 checks passed
@blackaxgit
blackaxgit deleted the dependabot/uv/python-version-updates-5cdb71f4d2 branch September 30, 2026 03:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant