Skip to content

Bump the pip-dependencies group with 7 updates - #488

Merged
chadlwilson merged 1 commit into
masterfrom
dependabot/pip/pip-dependencies-491cc78fb3
Oct 1, 2026
Merged

chadlwilson merged 1 commit into
masterfrom
dependabot/pip/pip-dependencies-491cc78fb3

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown
Contributor

Bumps the pip-dependencies group with 7 updates:

Package From To
debugpy 1.8.21 1.8.22
grpcio 1.83.1 1.84.0
protobuf 7.36.0 7.36.2
grpcio-tools 1.83.1 1.84.0
coverage 7.16.0 7.16.2
idna 3.19 3.20
urllib3 2.7.0 2.8.0

Updates debugpy from 1.8.21 to 1.8.22

Release notes

Sourced from debugpy's releases.

debugpy v1.8.22

Fixes

Enhancements

Infrastructure work

Thanks to @​pdepetro, @​rchiodo, @​nshepperd, @​aperez, @​karandhaodiyal28-hash, @​danfiedler-msft, and @​finnagin for the commits.

Full Changelog: microsoft/debugpy@v1.8.21...v1.8.22

Commits
  • e220805 Add python 3.15 to tests (#2069)
  • e5743d3 Pin GitHub Actions to full-length commit SHAs (#2063)
  • 7959635 Respect isolated mode when patching sys.path (#2050)
  • 6dd019a Add debugpy release agent (#2062)
  • d98001c Fix thread identity when the first traced call is another thread's is_alive()...
  • 7ca4578 Return the endpoint from listen() with the in-process adapter (#2051)
  • 9832f3f Add more typing to debugpy and switch to 'standard' type checking mode (#1637)
  • 2f73444 Populate hitBreakpointIds in the DAP stopped event (#2060)
  • 7d3f861 Avoid exceptions in environment diagnostics (#2059)
  • f77d448 Fix duplicate stopped event when two threads hit a breakpoint at once (#2056)
  • Additional commits viewable in compare view

Updates grpcio from 1.83.1 to 1.84.0

Release notes

Sourced from grpcio's releases.

Release v1.84.0

This is release 1.84.0 (gimbal) of gRPC Core.

For gRPC documentation, see grpc.io. For previous releases, see Releases.

This release contains refinements, improvements, and bug fixes, with highlights listed below.

Core

  • [promise_based_filter] enable v2_non_owning_waker_implementation experiment. (#43253)
  • [xDS] allow server listener address to match wildcard port. (#43247)
  • [WRR] remove env var guard for custom backend metrics. (#43198)
  • [subchannel] enable connection scaling service config fields. (#43116)
  • [subchannel] add metrics as per A94. (#43140)
  • Fix incorrect hostname suffix matching in no_proxy handling (prevents proxy bypass). (#41915)

C#

  • [C# Grpc.Tools] Add native macOS ARM64 support via universal binaries. (#41222)

Python

  • [Python] Fix -Werror=unused-result error triggered by Cythonized code. (#43313)
  • [Python] Release Python 3.15 wheels publicly. (#43259)
  • [Python][AsyncIO] Fixed reference cycles. (#43121)
  • [Python] fix: remove ghost key in grpc.aio.Metadata.delitem when last value is deleted. (#42974)
  • [Python] Fix the StatusCode Enums to be int. (#43167)
  • [Python] Fixed the parenthesis placement. (#43111)
  • [Python] Removed UsageError exception from registered method. (#43086)
  • [Python] Added registered methods support in AsyncIO stack . (#41796)
  • [Python] AIO Part 4 - Typehints fixes and add Pyright for aio/_channel.py. (#42736)
  • [Python] grpc-status: Relax protobuf dependency lower bound to allow 6.x. (#43000)
  • [Python] Observability plugin fixes. (#42785)

Ruby

  • [Ruby] Fix: Addressed Array of strings passed as metadata. (#42827)

Release v1.84.0-pre2

This is a prerelease of gRPC Core 1.84.0 (gimbal).

For gRPC documentation, see grpc.io. For previous releases, see Releases.

This is a Python-only pre-release that introduces pre-built wheels for Python 3.15.

... (truncated)

Commits
  • 3252a89 Bump release version to 1.84.0 on v1.84.x branch (#43405)
  • c633e39 [Release] Bump version to 1.84.0-pre2 (on v1.84.x branch) (#43401)
  • 12cafee [Backport][v1.84.x] Revert "[Python] Revert Python 3.15 changes due to sanity...
  • 56e86cb Bump release version to 1.84.0-pre1 on v1.84.x branch (#43327)
  • 7ef6a9e [build] Source reflection and channelz v1 schemas from BCR (@​grpc_proto) (#43...
  • c337c3e [core][filters] Unit test framework for v3 filter (#42969)
  • ce22bb4 [PH2][CHTTP2] Retire stream flow control delta early to avoid data race
  • 25c16f9 [PH2][Test] Add destructor tests for the Seq promise combinator.
  • a7fabec [Python] Fix -Werror=unused-result error triggered by Cythonized code (#43313)
  • d92ee43 [util] remove LoadFile() option to append null byte (#41478)
  • Additional commits viewable in compare view

Updates protobuf from 7.36.0 to 7.36.2

Updates grpcio-tools from 1.83.1 to 1.84.0

Release notes

Sourced from grpcio-tools's releases.

Release v1.84.0

This is release 1.84.0 (gimbal) of gRPC Core.

For gRPC documentation, see grpc.io. For previous releases, see Releases.

This release contains refinements, improvements, and bug fixes, with highlights listed below.

Core

  • [promise_based_filter] enable v2_non_owning_waker_implementation experiment. (#43253)
  • [xDS] allow server listener address to match wildcard port. (#43247)
  • [WRR] remove env var guard for custom backend metrics. (#43198)
  • [subchannel] enable connection scaling service config fields. (#43116)
  • [subchannel] add metrics as per A94. (#43140)
  • Fix incorrect hostname suffix matching in no_proxy handling (prevents proxy bypass). (#41915)

C#

  • [C# Grpc.Tools] Add native macOS ARM64 support via universal binaries. (#41222)

Python

  • [Python] Fix -Werror=unused-result error triggered by Cythonized code. (#43313)
  • [Python] Release Python 3.15 wheels publicly. (#43259)
  • [Python][AsyncIO] Fixed reference cycles. (#43121)
  • [Python] fix: remove ghost key in grpc.aio.Metadata.delitem when last value is deleted. (#42974)
  • [Python] Fix the StatusCode Enums to be int. (#43167)
  • [Python] Fixed the parenthesis placement. (#43111)
  • [Python] Removed UsageError exception from registered method. (#43086)
  • [Python] Added registered methods support in AsyncIO stack . (#41796)
  • [Python] AIO Part 4 - Typehints fixes and add Pyright for aio/_channel.py. (#42736)
  • [Python] grpc-status: Relax protobuf dependency lower bound to allow 6.x. (#43000)
  • [Python] Observability plugin fixes. (#42785)

Ruby

  • [Ruby] Fix: Addressed Array of strings passed as metadata. (#42827)

Release v1.84.0-pre2

This is a prerelease of gRPC Core 1.84.0 (gimbal).

For gRPC documentation, see grpc.io. For previous releases, see Releases.

This is a Python-only pre-release that introduces pre-built wheels for Python 3.15.

... (truncated)

Commits
  • 3252a89 Bump release version to 1.84.0 on v1.84.x branch (#43405)
  • c633e39 [Release] Bump version to 1.84.0-pre2 (on v1.84.x branch) (#43401)
  • 12cafee [Backport][v1.84.x] Revert "[Python] Revert Python 3.15 changes due to sanity...
  • 56e86cb Bump release version to 1.84.0-pre1 on v1.84.x branch (#43327)
  • 5646e4c [Python] Revert Python 3.15 changes due to sanity failure (#43293)
  • f311bf0 [Python] Release Python 3.15 wheels publicly (#43259)
  • 8f3bb34 [Release] Bump version to 1.84.0-dev (on master branch) (#42935)
  • See full diff in compare view

Updates coverage from 7.16.0 to 7.16.2

Release notes

Sourced from coverage's releases.

7.16.2

Version 7.16.2 — 2026-09-27

  • Fix: on Python 3.14 and later, a for loop completing immediately before a function return could mistakenly report an uncovered branch. This is now fixed, closing issue 2168.
  • Fix: on Python 3.14 and later, the else clause of a try whose body is a with statement could incorrectly be reported as covered when the with raised. This is now fixed, closing issue 2289.
  • Fix: with dynamic_context = test_function, test methods written as @staticmethod or @classmethod were not given a context of their own. Now they are, on Python 3.11 and later. Closes issue 1923.

➡️  PyPI page: coverage 7.16.2. :arrow_right:  To install: python3 -m pip install coverage==7.16.2

7.16.1

Version 7.16.1 — 2026-09-13

  • Fix: when the body of an irrefutable case (like case _:) is entirely excluded, the case line is now excluded too, just as an excluded else: body removes the else: line. Previously the case line was left behind and reported as missing. Closes issue 1563 with pull 2269.
  • Fix: using CoverageData.update() twice on an in-memory database would fail, as described in issue 2279. This is now fixed.

➡️  PyPI page: coverage 7.16.1. :arrow_right:  To install: python3 -m pip install coverage==7.16.1

Changelog

Sourced from coverage's changelog.

Version 7.16.2 — 2026-09-27

  • Fix: on Python 3.14 and later, a for loop completing immediately before a function return could mistakenly report an uncovered branch. This is now fixed, closing issue 2168_.

  • Fix: on Python 3.14 and later, the else clause of a try whose body is a with statement could incorrectly be reported as covered when the with raised. This is now fixed, closing issue 2289_.

  • Fix: with dynamic_context = test_function, test methods written as @staticmethod or @classmethod were not given a context of their own. Now they are, on Python 3.11 and later. Closes issue 1923_.

.. _issue 1923: coveragepy/coveragepy#1923 .. _issue 2168: coveragepy/coveragepy#2168 .. _issue 2289: coveragepy/coveragepy#2289

.. _changes_7-16-1:

Version 7.16.1 — 2026-09-13

  • Fix: when the body of an irrefutable case (like case _:) is entirely excluded, the case line is now excluded too, just as an excluded else: body removes the else: line. Previously the case line was left behind and reported as missing. Closes issue 1563_ with pull 2269_.

  • Fix: using :meth:.CoverageData.update twice on an in-memory database would fail, as described in issue 2279_. This is now fixed.

.. _issue 1563: coveragepy/coveragepy#1563 .. _pull 2269: coveragepy/coveragepy#2269 .. _issue 2279: coveragepy/coveragepy#2279

.. _changes_7-16-0:

Commits

Updates idna from 3.19 to 3.20

Release notes

Sourced from idna's releases.

v3.20

  • Update to Unicode 18.0.0.
  • Better enforcement of the domain length limit in the incremental codec.
  • Add support for Python 3.15.
Changelog

Sourced from idna's changelog.

3.20 (2026-09-17)

  • Update to Unicode 18.0.0.
  • Better enforcement of the domain length limit in the incremental codec.
  • Add support for Python 3.15.
Commits
  • d55e65e Release 3.20
  • 0c0824a Pre-release 3.20rc0
  • bd7c316 Note Python 3.15 support in the 3.20 changelog
  • b6cce85 Merge pull request #276 from kjd/unicode-18
  • 9a4bc59 Update to Unicode 18.0.0
  • dfab5a0 Merge branch 'python-3.15'
  • 417c354 Read the latest Unicode version from the DerivedAge.txt header instead of the...
  • cd17392 Merge pull request #274 from kjd/fix-decode-length-check
  • c5796d7 Skip the decode round-trip check for domains past encode's length limit
  • d6ee690 Update to Python 3.15 release candidate in CI and add trove classifier
  • Additional commits viewable in compare view

Updates urllib3 from 2.7.0 to 2.8.0

Release notes

Sourced from urllib3's releases.

2.8.0

🚀 urllib3 is fundraising for HTTP/2 support

urllib3 is raising ~$40,000 USD to release HTTP/2 support and ensure long-term sustainable maintenance of the project. If your company or organization uses Python and would benefit from HTTP/2 support in Requests, pip, cloud SDKs, and thousands of other projects please consider contributing financially to ensure HTTP/2 support is developed sustainably and maintained for the long-haul.

Thank you for your support.

Security

Fixed the following security issues:

  • The TLS configuration for HTTPS proxies could be ignored or overridden. (High severity, GHSA-8988-9cw3-xx77)
  • HTTPResponse.stream() and read_chunked() could buffer a chunk-size line of unbounded length in memory. (High severity, GHSA-vxq7-64xx-v4gw)
  • Chunked Deflate streaming could enter an infinite loop. (Medium severity, GHSA-gh4c-6fx4-qh6g)

[!IMPORTANT] urllib3 2.8.0 fixes HTTPS proxy TLS configuration being ignored or overridden by destination settings. Configurations relying on that behavior may require changes.

Configure proxy CA certificates and client certificates in proxy_ssl_context, and proxy identity checks with proxy_assert_hostname or proxy_assert_fingerprint. Destination client certificates and identity overrides no longer apply to HTTPS forwarding proxy connections.

[!NOTE] CVE IDs had not yet been assigned to these advisories at the time of release due to a backlog at GitHub's CNA.

Deprecations & Removals

  • Deprecated using an empty collection as the Retry option allowed_methods to retry any verb. (#5044)

Features

  • Added Url.auth_decoded and Url.auth_decoded_joined convenience properties to the result of parse_url(). (#4945)
  • Added basic_auth_encoding and proxy_basic_auth_encoding parameters to urllib3.util.make_headers(). (#5092)

Bugfixes

  • Fixed response header handling to replace obsolete folded header lines (obs-fold) with spaces in accordance with RFC 9112, preventing raw CRLF sequences from appearing in header values such as Set-Cookie. (#1362)

  • Fixed usage of proxy_ssl_context with ProxyManager when use_forwarding_for_https=True. Passing ssl_context instead of proxy_ssl_context for HTTPS proxies in this configuration now emits a FutureWarning and will raise an error in v3.0. (#2577)

  • Changed behavior of the default ConnectionPool.pool initialization. LifoQueue is now resolved from the queue module after the ConnectionPool is instantiated instead of using the default cached QueueCls class property. This is done because sometimes the queue.LifoQueue is monkey-patched late in the program, such as by gevent. (#3289)

  • Raised UnrewindableBodyError instead of ValueError when retrying a request whose body had tell() but not seek(). (#3779)

  • Decoded percent-encoded SOCKS proxy credentials before authenticating with the proxy server. (#3785)

  • Fixed HTTPResponse.drain_conn() to discard unread response data in 64 KiB chunks (same as the default amt when doing HTTPResponse.stream(...)). (#5019)

  • Fixed is_ipaddress() to detect non-standard IPv4 forms accepted by socket.connect, such as hex (0x7f000001), octal (0177.0.0.1), and decimal integers (2130706433), ensuring SSL certificate verification uses the correct mode for these addresses. (#5029)

  • Fixed HTTPConnectionPool.urlopen raising a misleading FullPoolError instead of ValueError when called with an invalid timeout argument on a pool created with block=True. (#5059)

  • Fixed port-zero handling to preserve explicit :0 values instead of substituting the default ports 80 or 443 in URL parsing, pool selection, proxy configuration, connection_from_url(), and HTTP/2 request authority. (#5071, #5101)

  • Fixed a bug where PoolManager passed the assert_hostname and assert_fingerprint parameters to HTTP connection pools. (#5077)

  • Fixed HTTPConnectionPool.urlopen() and HTTP proxy forwarding to strip URL fragments from absolute request targets before sending requests. (#5079)

  • Added safeguards to the proxy tunneling code to prevent potential security issues when handling invalid characters in the proxy host and HTTP headers. This change affects users of Python 3.10, Python 3.11, and Python 3.12 when the standard library does not contain the fix; those on newer Python versions should upgrade to 3.13.14+ or 3.14.5+ to get the same security fixes. (#5091)

  • Fixed HTTPSConnection.connect() overriding ProxyConfig.ssl_context's certificate policy and proxy identity checks with the target connection's TLS settings when forwarding through an HTTPS proxy.

    HTTPSConnection no longer applies target SNI, assertions, or client credentials to forwarding proxy handshakes and continues to use its ssl_context as a fallback when an HTTPS proxy forwards an HTTP target. (#5093)

  • Fixed URL parsing to more strictly enforce RFC 3986 host syntax, rejecting invalid host input such as raw spaces and control characters, malformed percent-encodings, and percent-encoded control characters in HTTP(S) hosts and IPv6 zone identifiers, including proxy CONNECT tunnel targets. Host normalization now also follows RFC 3986 normalization rules for percent-encoded octets by decoding percent-encoded unreserved characters and uppercasing the hexadecimal digits of retained percent-encoded octets. (#5095)

... (truncated)

Changelog

Sourced from urllib3's changelog.

2.8.0 (2026-09-15)

Security

Fixed the following security issues:

  • The TLS configuration for HTTPS proxies could be ignored or overridden. (High severity, GHSA-8988-9cw3-xx77 <https://github.com/urllib3/urllib3/security/advisories/GHSA-8988-9cw3-xx77>__)
  • HTTPResponse.stream() and read_chunked() could buffer a chunk-size line of unbounded length in memory. (High severity, GHSA-vxq7-64xx-v4gw <https://github.com/urllib3/urllib3/security/advisories/GHSA-vxq7-64xx-v4gw>__)
  • Chunked Deflate streaming could enter an infinite loop. (Medium severity, GHSA-gh4c-6fx4-qh6g <https://github.com/urllib3/urllib3/security/advisories/GHSA-gh4c-6fx4-qh6g>__)

.. caution::

urllib3 2.8.0 fixes HTTPS proxy TLS configuration being ignored or
overridden by destination settings. Configurations relying on that
behavior may require changes.

Configure proxy CA certificates and client certificates in proxy_ssl_context, and proxy identity checks with proxy_assert_hostname or proxy_assert_fingerprint. Destination client certificates and identity overrides no longer apply to HTTPS forwarding proxy connections.

Deprecations & Removals

  • Deprecated using an empty collection as the Retry option allowed_methods to retry any verb. ([#5044](https://github.com/urllib3/urllib3/issues/5044) <https://github.com/urllib3/urllib3/issues/5044>__)

Features

  • Added Url.auth_decoded and Url.auth_decoded_joined convenience properties to the result of parse_url(). ([#4945](https://github.com/urllib3/urllib3/issues/4945) <https://github.com/urllib3/urllib3/issues/4945>__)
  • Added basic_auth_encoding and proxy_basic_auth_encoding parameters to urllib3.util.make_headers(). ([#5092](https://github.com/urllib3/urllib3/issues/5092) <https://github.com/urllib3/urllib3/issues/5092>__)

Bugfixes

... (truncated)

Commits
  • b1d30ab Release 2.8.0
  • 9016d7e Skip test_read_chunked_with_trailing_data_does_not_hang for brotlicffi (#5258)
  • 9101f58 Fix nox -s docs warning (#5256)
  • cd770b0 Merge commit from fork
  • ea2ad7b Merge commit from fork
  • 0716e31 Fix loading unencrypted client keys with a password in pyOpenSSL (#5255)
  • 43c68c8 Test pickling of InvalidChunkLength (#5247)
  • 308b279 Share security policy between GitHub and Read the Docs (#5253)
  • 53fa073 Add policy on duplicate pull requests (#5252)
  • 5f2a6a8 Assert on the ALPN extension in test_tunnel_sets_http_11_alpn (#5232)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the pip-dependencies group with 7 updates:

| Package | From | To |
| --- | --- | --- |
| [debugpy](https://github.com/microsoft/debugpy) | `1.8.21` | `1.8.22` |
| [grpcio](https://github.com/grpc/grpc) | `1.83.1` | `1.84.0` |
| [protobuf](https://developers.google.com/protocol-buffers/) | `7.36.0` | `7.36.2` |
| [grpcio-tools](https://github.com/grpc/grpc) | `1.83.1` | `1.84.0` |
| [coverage](https://github.com/coveragepy/coveragepy) | `7.16.0` | `7.16.2` |
| [idna](https://github.com/kjd/idna) | `3.19` | `3.20` |
| [urllib3](https://github.com/urllib3/urllib3) | `2.7.0` | `2.8.0` |


Updates `debugpy` from 1.8.21 to 1.8.22
- [Release notes](https://github.com/microsoft/debugpy/releases)
- [Commits](microsoft/debugpy@v1.8.21...v1.8.22)

Updates `grpcio` from 1.83.1 to 1.84.0
- [Release notes](https://github.com/grpc/grpc/releases)
- [Commits](grpc/grpc@v1.83.1...v1.84.0)

Updates `protobuf` from 7.36.0 to 7.36.2

Updates `grpcio-tools` from 1.83.1 to 1.84.0
- [Release notes](https://github.com/grpc/grpc/releases)
- [Commits](grpc/grpc@v1.83.1...v1.84.0)

Updates `coverage` from 7.16.0 to 7.16.2
- [Release notes](https://github.com/coveragepy/coveragepy/releases)
- [Changelog](https://github.com/coveragepy/coveragepy/blob/main/CHANGES.rst)
- [Commits](coveragepy/coveragepy@7.16.0...7.16.2)

Updates `idna` from 3.19 to 3.20
- [Release notes](https://github.com/kjd/idna/releases)
- [Changelog](https://github.com/kjd/idna/blob/master/HISTORY.md)
- [Commits](kjd/idna@v3.19...v3.20)

Updates `urllib3` from 2.7.0 to 2.8.0
- [Release notes](https://github.com/urllib3/urllib3/releases)
- [Changelog](https://github.com/urllib3/urllib3/blob/main/CHANGES.rst)
- [Commits](urllib3/urllib3@2.7.0...2.8.0)

---
updated-dependencies:
- dependency-name: debugpy
  dependency-version: 1.8.22
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: pip-dependencies
- dependency-name: grpcio
  dependency-version: 1.84.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: pip-dependencies
- dependency-name: protobuf
  dependency-version: 7.36.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: pip-dependencies
- dependency-name: grpcio-tools
  dependency-version: 1.84.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: pip-dependencies
- dependency-name: coverage
  dependency-version: 7.16.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: pip-dependencies
- dependency-name: idna
  dependency-version: '3.20'
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: pip-dependencies
- dependency-name: urllib3
  dependency-version: 2.8.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: pip-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update Python code labels Oct 1, 2026
@chadlwilson
chadlwilson merged commit 70f37e2 into master Oct 1, 2026
15 checks passed
@chadlwilson
chadlwilson deleted the dependabot/pip/pip-dependencies-491cc78fb3 branch October 1, 2026 16:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update Python code

Development

Successfully merging this pull request may close these issues.

1 participant