Skip to content

chore(deps): bump the uv group across 2 directories with 3 updates - #1042

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/examples/example-ai-crewai/uv-56bb5b6cd7
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/examples/example-ai-crewai/uv-56bb5b6cd7

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 9, 2026

Copy link
Copy Markdown
Contributor

Bumps the uv group with 1 update in the /examples/example-ai-llamaindex directory: banks.
Bumps the uv group with 2 updates in the /examples/example-ai-pydantic-ai directory: pydantic-ai and pydantic-ai-slim.

Updates banks from 2.4.5 to 2.5.1

Release notes

Sourced from banks's releases.

v2.5.1

What's Changed

Full Changelog: masci/banks@v2.5.0...v2.5.1

v2.5.0

What's Changed

Breaking changes

  • Building messages by rendering JSON from data (e.g. {% for m in history %}{{ m | tojson }}{% endfor %}) no longer produces messages — the JSON is returned as literal text. Use {% chat %} blocks instead.
  • The image, audio, video, document, cache_control and tool filters now take the Jinja render context as their first argument. Templates are unaffected; only direct Python calls need updating.
  • banks.types.CONTENT_BLOCK_REGEX is removed, replaced by content_block_start(sentinel) and CONTENT_BLOCK_END.
  • chat_message_from_text() gained a sentinel keyword argument; without it, content blocks are no longer parsed.

Prompt.text() output and the chat_messages() API are unchanged.

Full Changelog: masci/banks@v2.4.5...v2.5.0

Commits
  • e62cf76 chore: set version to 2.5.1 [skip ci]
  • 23ed13e Prevent symlinks in the prompt registry (#79)
  • b1feadd chore: set version to 2.5.0 [skip ci]
  • 02172b8 fix: only parse marked output as chat messages (#78)
  • See full diff in compare view

Updates pydantic-ai from 1.102.0 to 1.107.7

Release notes

Sourced from pydantic-ai's releases.

v1.107.7 (2026-09-29)

🛡️ Security

A maintenance release for the v1 line, carrying the v1 backport of the security fix released in 2.52.0. See the advisory for full details and affected versions.

  • GHSA-v36g-jcw9-x7cw (moderate): converting attacker-controlled HTML with deeply nested elements in the local web_fetch tool could consume excessive CPU and memory. Provider-native web fetching is not affected. Reported by @​SounLabs. (#8985)

Patched in 1.107.7; also patched on the v2 line in 2.52.0.

What's Changed

🐛 Bug Fixes

Full Changelog: pydantic/pydantic-ai@v1.107.6...v1.107.7

v1.107.6 (2026-09-16)

🛡️ Security

A maintenance release for the v1 line, carrying the v1 backports of the four security fixes released in 2.44.0. See each advisory for full details and affected versions.

Also carried over: credentials are now dropped on a safe_download redirect whenever the full origin changes, not only the hostname (#8410). This was fixed on the v2 line some time ago and had never been backported.

Patched in 1.107.6; all four are also patched on the v2 line in 2.44.0.

What's Changed

Every code change in this release is one of the security fixes above. Maintenance alongside them:

Full Changelog: pydantic/pydantic-ai@v1.107.5...v1.107.6

v1.107.5 (2026-08-13)

What's Changed

🛡️ Security

  • GHSA-q2xc-rrxj-58x9: the local dev web chat UI (Agent.to_web(), clai web) didn't validate the Host header, so DNS rebinding from a website you visit could reach it and run the served agent with your local process's tools and credentials. Fixed in pydantic-ai/pydantic-ai-slim 1.107.5 by validating Host against localhost/loopback/LAN addresses by default; deployments reached under a real hostname must opt in with the new allowed_hosts setting. Backport of allowed_hosts by @​DouweM in pydantic/pydantic-ai#7438

Full Changelog: pydantic/pydantic-ai@v1.107.4...v1.107.5

v1.107.4 (2026-08-11)

... (truncated)

Commits
  • 2fd3879 Backport bounded web_fetch HTML conversion to v1 (#8985)
  • ff899b4 Cap genai-prices below 0.1 to keep token usage extraction and limits workin...
  • 6022411 Remove stale harness-compat.yml from v1 (#9074)
  • 7ee27e3 Close two include_content redaction bypasses and make the content sweep pro...
  • 2faa618 Decode web_fetch response bodies in a worker thread and treat non-text char...
  • 6b22270 Check include_content=False over every content channel at once (v1 backport...
  • a9dab92 Compare web_fetch_tool domain lists in the form the resolver uses (v1 backp...
  • a93ea52 Extract the web_fetch page title with a linear scan and convert HTML in lin...
  • 963dec5 Share exception recording between the agent run, tool and model request spans...
  • 84d67aa Pin FastA2A below 1 in the a2a extra (v1) (#8412)
  • Additional commits viewable in compare view

Updates pydantic-ai-slim from 1.102.0 to 1.107.7

Release notes

Sourced from pydantic-ai-slim's releases.

v1.107.7 (2026-09-29)

🛡️ Security

A maintenance release for the v1 line, carrying the v1 backport of the security fix released in 2.52.0. See the advisory for full details and affected versions.

  • GHSA-v36g-jcw9-x7cw (moderate): converting attacker-controlled HTML with deeply nested elements in the local web_fetch tool could consume excessive CPU and memory. Provider-native web fetching is not affected. Reported by @​SounLabs. (#8985)

Patched in 1.107.7; also patched on the v2 line in 2.52.0.

What's Changed

🐛 Bug Fixes

Full Changelog: pydantic/pydantic-ai@v1.107.6...v1.107.7

v1.107.6 (2026-09-16)

🛡️ Security

A maintenance release for the v1 line, carrying the v1 backports of the four security fixes released in 2.44.0. See each advisory for full details and affected versions.

Also carried over: credentials are now dropped on a safe_download redirect whenever the full origin changes, not only the hostname (#8410). This was fixed on the v2 line some time ago and had never been backported.

Patched in 1.107.6; all four are also patched on the v2 line in 2.44.0.

What's Changed

Every code change in this release is one of the security fixes above. Maintenance alongside them:

Full Changelog: pydantic/pydantic-ai@v1.107.5...v1.107.6

v1.107.5 (2026-08-13)

What's Changed

🛡️ Security

  • GHSA-q2xc-rrxj-58x9: the local dev web chat UI (Agent.to_web(), clai web) didn't validate the Host header, so DNS rebinding from a website you visit could reach it and run the served agent with your local process's tools and credentials. Fixed in pydantic-ai/pydantic-ai-slim 1.107.5 by validating Host against localhost/loopback/LAN addresses by default; deployments reached under a real hostname must opt in with the new allowed_hosts setting. Backport of allowed_hosts by @​DouweM in pydantic/pydantic-ai#7438

Full Changelog: pydantic/pydantic-ai@v1.107.4...v1.107.5

v1.107.4 (2026-08-11)

... (truncated)

Commits
  • 2fd3879 Backport bounded web_fetch HTML conversion to v1 (#8985)
  • ff899b4 Cap genai-prices below 0.1 to keep token usage extraction and limits workin...
  • 6022411 Remove stale harness-compat.yml from v1 (#9074)
  • 7ee27e3 Close two include_content redaction bypasses and make the content sweep pro...
  • 2faa618 Decode web_fetch response bodies in a worker thread and treat non-text char...
  • 6b22270 Check include_content=False over every content channel at once (v1 backport...
  • a9dab92 Compare web_fetch_tool domain lists in the form the resolver uses (v1 backp...
  • a93ea52 Extract the web_fetch page title with a linear scan and convert HTML in lin...
  • 963dec5 Share exception recording between the agent run, tool and model request spans...
  • 84d67aa Pin FastA2A below 1 in the a2a extra (v1) (#8412)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps the uv group with 1 update in the /examples/example-ai-llamaindex directory: [banks](https://github.com/masci/banks).
Bumps the uv group with 2 updates in the /examples/example-ai-pydantic-ai directory: [pydantic-ai](https://github.com/pydantic/pydantic-ai) and [pydantic-ai-slim](https://github.com/pydantic/pydantic-ai).


Updates `banks` from 2.4.5 to 2.5.1
- [Release notes](https://github.com/masci/banks/releases)
- [Commits](masci/banks@v2.4.5...v2.5.1)

Updates `pydantic-ai` from 1.102.0 to 1.107.7
- [Release notes](https://github.com/pydantic/pydantic-ai/releases)
- [Changelog](https://github.com/pydantic/pydantic-ai/blob/main/docs/changelog.md)
- [Commits](pydantic/pydantic-ai@v1.102.0...v1.107.7)

Updates `pydantic-ai-slim` from 1.102.0 to 1.107.7
- [Release notes](https://github.com/pydantic/pydantic-ai/releases)
- [Changelog](https://github.com/pydantic/pydantic-ai/blob/main/docs/changelog.md)
- [Commits](pydantic/pydantic-ai@v1.102.0...v1.107.7)

---
updated-dependencies:
- dependency-name: banks
  dependency-version: 2.5.1
  dependency-type: indirect
  dependency-group: uv
- dependency-name: pydantic-ai
  dependency-version: 1.107.7
  dependency-type: direct:production
  dependency-group: uv
- dependency-name: pydantic-ai-slim
  dependency-version: 1.107.7
  dependency-type: indirect
  dependency-group: uv
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot requested a review from a team as a code owner October 9, 2026 09:37
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels Oct 9, 2026
@github-actions

github-actions Bot commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

posthog-python Compliance Report

Date: 2026-10-09T09:43:05.495980+00:00
Duration: 259172ms

✅ All Tests Passed!

121/121 tests passed


Capture_V1 Tests

✅ 95/95 tests passed

View Details
Test Status Duration
Endpoint And Method.Targets V1 Endpoint ✅ 513ms
Endpoint And Method.Does Not Use Legacy Endpoints ✅ 507ms
Required Headers.Has Authorization Bearer Header ✅ 508ms
Required Headers.Has Content Type Json ✅ 508ms
Required Headers.Has Posthog Sdk Info Format ✅ 507ms
Required Headers.Has Posthog Attempt Header ✅ 508ms
Required Headers.Has Posthog Request Id ✅ 507ms
Required Headers.Has Posthog Request Timestamp ✅ 507ms
Required Headers.Has User Agent ✅ 508ms
Body Format.Body Has Created At And Batch ✅ 507ms
Body Format.No Api Key In Body ✅ 506ms
Body Format.No Sent At In Body ✅ 508ms
Event Format.Event Has Required Root Fields ✅ 506ms
Event Format.Event Uuid Is Valid ✅ 508ms
Event Format.Event Timestamp Is Rfc3339 ✅ 507ms
Event Format.Non Utc Event Timestamp Is Converted To Utc ✅ 511ms
Event Format.Distinct Id Is String ✅ 507ms
Event Format.Distinct Id At Root Not Properties ✅ 507ms
Event Format.Custom Properties Preserved ✅ 507ms
Event Format.Set Properties Preserved ✅ 507ms
Event Format.Set Once Properties Preserved ✅ 507ms
Event Format.Groups Properties Preserved ✅ 507ms
Event Format.Sdk Generates Uuid If Not Provided ✅ 507ms
Event Format.Event Has Required Root Fields Batch ✅ 509ms
Event Format.Event Uuid Is Valid Batch ✅ 510ms
Event Format.Event Timestamp Is Rfc3339 Batch ✅ 509ms
Event Format.Distinct Id Is String Batch ✅ 511ms
Event Format.Distinct Id At Root Not Properties Batch ✅ 522ms
Event Format.Custom Properties Preserved Batch ✅ 510ms
Event Format.Set Properties Preserved Batch ✅ 510ms
Event Format.Set Once Properties Preserved Batch ✅ 509ms
Event Format.Groups Properties Preserved Batch ✅ 510ms
Event Format.Sdk Generates Uuid If Not Provided Batch ✅ 510ms
Batch Behavior.Multiple Events In Single Batch ✅ 512ms
Batch Behavior.Batch Envelope Smoke ✅ 511ms
Batch Behavior.Flush With No Events Sends Nothing ✅ 504ms
Batch Behavior.Flush At Triggers Batch ✅ 1007ms
Batch Behavior.Created At Reflects Batch Creation Time ✅ 508ms
Deduplication.Generates Unique Uuids ✅ 511ms
Deduplication.Different Events Same Content Different Uuids ✅ 508ms
Deduplication.Preserves Uuid On Retry ✅ 6515ms
Deduplication.Preserves Timestamp On Retry ✅ 6512ms
Deduplication.Preserves Uuid And Timestamp On Batch Retry ✅ 6519ms
Deduplication.No Duplicate Events In Batch ✅ 513ms
Header Behavior On Retry.Attempt Header Starts At One ✅ 507ms
Header Behavior On Retry.Attempt Header Increments On Retry ✅ 13516ms
Header Behavior On Retry.Request Id Preserved On Retry ✅ 6512ms
Header Behavior On Retry.Different Requests Have Different Request Ids ✅ 3016ms
Header Behavior On Retry.Request Timestamp Changes On Retry ✅ 6516ms
Response Format Validation.Success Response Has Uuid Keyed Results ✅ 509ms
Response Format Validation.Success Response Has Ok For Each Event ✅ 510ms
Response Format Validation.Success No Retry After When All Ok ✅ 509ms
Response Format Validation.Success Retry After Present When Retry Events ✅ 1512ms
Response Format Validation.Success No Retry After When Drop Only ✅ 509ms
Response Format Validation.Response Echoes Request Id ✅ 507ms
Retry Behavior.Retries On 408 ✅ 6517ms
Retry Behavior.Retries On 500 ✅ 6517ms
Retry Behavior.Retries On 503 ✅ 8519ms
Retry Behavior.Retries On 504 ✅ 6516ms
Retry Behavior.Retryable Errors Have Retry After ✅ 3521ms
Retry Behavior.Respects Retry After On Retryable Error ✅ 11519ms
Retry Behavior.Does Not Retry On 400 ✅ 2512ms
Retry Behavior.Does Not Retry On 401 ✅ 2511ms
Retry Behavior.Does Not Retry On 402 ✅ 2510ms
Retry Behavior.Does Not Retry On 413 ✅ 2510ms
Retry Behavior.Does Not Retry On 415 ✅ 2519ms
Retry Behavior.Non Retryable Errors Have No Retry After ✅ 2510ms
Retry Behavior.Implements Backoff ✅ 22522ms
Retry Behavior.Max Retries Respected ✅ 22530ms
Partial Batch Handling.Handles 200 Full Success ✅ 2510ms
Partial Batch Handling.Handles 200 With All Ok ✅ 3512ms
Partial Batch Handling.Does Not Retry Dropped Events ✅ 3521ms
Partial Batch Handling.Does Not Retry Limited Events ✅ 3514ms
Partial Batch Handling.Prunes Ok Events On Partial Retry ✅ 6518ms
Partial Batch Handling.Prunes Dropped Events On Partial Retry ✅ 6515ms
Partial Batch Handling.Retries Only Retry Events From Partial ✅ 6514ms
Partial Batch Handling.Partial Retry Preserves Uuids ✅ 6516ms
Partial Batch Handling.Partial Retry Attempt Header Increments ✅ 6518ms
Partial Batch Handling.Partial Retry Request Id Preserved ✅ 6513ms
Partial Batch Handling.Respects Retry After On Partial ✅ 8518ms
Partial Batch Handling.Unknown Result Treated As Terminal ✅ 3510ms
Partial Batch Handling.Mixed Ok Drop Limited No Retry ✅ 3514ms
Compression.Sends Gzip Content Encoding ✅ 509ms
Compression.No Content Encoding When Disabled ✅ 508ms
Compression.Compressed Body Is Decompressible ✅ 508ms
Error Handling.Does Not Retry On Unknown 4Xx ✅ 2509ms
Event Options.Cookieless Mode Override ✅ 509ms
Event Options.Disable Skew Correction Override ✅ 507ms
Event Options.Process Person Profile Override ✅ 508ms
Event Options.Product Tour Id Override ✅ 507ms
Event Options.Unset Options Omitted ✅ 508ms
Event Options.Options Override In Batch ✅ 509ms
Geoip And Historical Migration.Geoip Disable Injected Into Properties ✅ 508ms
Geoip And Historical Migration.Historical Migration Set In Body ✅ 507ms
Geoip And Historical Migration.Historical Migration Absent By Default ✅ 508ms

Capture_Ai Tests

✅ 5/5 tests passed

View Details
Test Status Duration
Routing.Capture Ai Posts To Ai Endpoint ✅ 507ms
Routing.Capture Does Not Reroute Ai Named Events ✅ 508ms
Identity.Capture Ai Event Has Uuid ✅ 507ms
Identity.Capture Ai Keeps Supplied Uuid ✅ 507ms
Timestamp Format.Non Utc Event Timestamp Is Converted To Utc ✅ 508ms

Feature_Flags Tests

✅ 17/17 tests passed

View Details
Test Status Duration
Request Payload.Request With Person Properties Device Id ✅ 8ms
Request Payload.Flags Request Uses V2 Query Param ✅ 6ms
Request Payload.Flags Request Hits Flags Path Not Decide ✅ 6ms
Request Payload.Flags Request Omits Authorization Header ✅ 5ms
Request Payload.Token In Flags Body Matches Init ✅ 6ms
Request Payload.Groups Round Trip ✅ 6ms
Request Payload.Groups Default To Empty Object ✅ 8ms
Request Payload.Disable Geoip False Propagates As Geoip Disable False ✅ 5ms
Request Payload.Disable Geoip Omitted Defaults To False ✅ 6ms
Request Payload.Flag Keys To Evaluate Contains Only Requested Key ✅ 6ms
Request Lifecycle.No Flags Request On Init Alone ✅ 2ms
Request Lifecycle.No Flags Request On Normal Capture ✅ 506ms
Request Lifecycle.Two Flag Calls Produce Two Remote Requests ✅ 10ms
Request Lifecycle.Mock Response Value Is Returned To Caller ✅ 6ms
Retry Behavior.Retries Flags On 502 ✅ 307ms
Retry Behavior.Retries Flags On 504 ✅ 308ms
Side Effect Events.Get Feature Flag Captures Feature Flag Called Event ✅ 508ms

Feature_Flags_Local_Evaluation Tests

✅ 4/4 tests passed

View Details
Test Status Duration
Versioned Boolean Matching.Matching Version Missing ✅ 46ms
Versioned Boolean Matching.Matching Version 1 ✅ 43ms
Versioned Boolean Matching.Matching Version 2 ✅ 43ms
Versioned Boolean Matching.Version Only Reload 1 2 1 2 Missing ✅ 22ms

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants