chore(deps): update all dependencies #28
Loading…
Reference in a new issue
No description provided.
Delete branch "renovate/all"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
This PR contains the following updates:
1.18.4→1.19.08.4.0→8.4.20.136.1→0.141.1606e70c→cf4eedc606e70c→cf4eedc3.0.1→3.3.40.3.5→0.3.61.41.1→1.44.01.41.1→1.44.01.41.1→1.44.03a82e1f→d129b951.0.8→1.2.19.0.3→9.1.1cea0e60→7bec7dde8eb6f2→978f0e00.1.9→0.1.100.25.1→0.30.02.0.49→2.0.51Release Notes
pallets/click (click)
v8.4.2Compare Source
Released 2026-06-24
8.4.0by {pr}3126. Newlines andtabs in option help text are now escaped, keeping the original completion
format while still supporting multi-line help. {issue}
3502{issue}
3043{pr}3504{pr}3508render a stray leading space before the
(DEPRECATED)label. {pr}3509Groupwithinvoke_without_command=Truemarks its subcommand asoptional in the usage help, showing
[COMMAND]instead ofCOMMAND.{issue}
3059{pr}3507echo_via_pagerflushes after each write, so passing a generator streamsoutput to the pager incrementally instead of staying hidden until the pipe
buffer fills. {issue}
3242{issue}2542{pr}3534echo_via_pagerandget_pager_fileno longer close a borrowed stdoutstream when no external pager runs, completing the partial
I/O operation on closed filefix from {pr}3482. {issue}3449{pr}
3533[[a|b|c]]...whose type already brackets their metavar. {pr}3578version_optionresolves apackage_namethat does not match aninstalled distribution as an import (top-level module) name via
{func}
importlib.metadata.packages_distributions. Packages whosetop-level module name differs from their distribution name (
PILvsPillow,jwtvsPyJWT) no longer raiseRuntimeErrorout of thebox. {issue}
2331{issue}1884{issue}3125{pr}3582v8.4.1Compare Source
Released 2026-05-21
get_parameter_source()is available during eager callbacks and typeconversion again. {issue}
3458{pr}34843277{pr}3466Enumvalues used asChoiceoptions produces avalid completion result. {issue}
3015{pr}34713487{pr}3493echo_via_pager. {issue}3449{pr}3482open_urlon Windows when the file path contains spaces.{issue}
2994{pr}3478fastapi/fastapi (fastapi)
v0.141.1Compare Source
Fixes
app.frontend(). PR #16105 by @tiangolo.Docs
FASTAPI_ENVin FastAPI CLI guide. PR #16104 by @tiangolo.v0.141.0Compare Source
Features
app.frontend(check_dir="auto"), to make local development more convenient withfastapi dev. PR #16102 by @tiangolo.v0.140.13Compare Source
Fixes
status_codebeing ignored for SSE and JSONL streaming endpoints. PR #15937 by @SAURABHSALVE.Docs
format_sse_eventdocstring rendering of\n\nterminator. PR #15613 by @AshNicolus.v0.140.12Compare Source
Fixes
format_sse_eventto comply with SSE spec. PR #15515 by @Zawwarsami16.v0.140.11Compare Source
Fixes
response_model_*params ignored for non-generator endpoints withIterable[..]return type. PR #15093 by @YuriiMotov.v0.140.10Compare Source
Fixes
Internal
v0.140.9Compare Source
Fixes
exclude_defaultsnot propagated to dict keys and values injsonable_encoder. PR #16043 by @MBGrao.Internal
v0.140.8Compare Source
Fixes
include_router(). PR #15077 by @alex-raw.v0.140.7Compare Source
Refactors
Internal
v0.140.6Compare Source
Refactors
v0.140.5Compare Source
Refactors
v0.140.4Compare Source
Refactors
v0.140.3Compare Source
Refactors
v0.140.2Compare Source
Refactors
Internal
v0.140.1Compare Source
Refactors
v0.140.0Compare Source
Refactors
Docs
Internal
v0.139.2Compare Source
Fixes
v0.139.1Compare Source
Fixes
/users/john.doe. PR #16011 by @tiangolo.Docs
skip_usersnot being applied. PR #15995 by @YuriiMotov.Translations
llm-prompt.mdfor Hindi. PR #15810 by @YuriiMotov.Internal
FASTAPI_LATEST_CHANGEStoken inbump-pre-commit-hooksworkflow. PR #15984 by @YuriiMotov.v0.139.0Compare Source
Features
app.frontend(), e.g. for automatic cookie authentication for the frontend. PR #15908 by @tiangolo.Translations
Internal
allow-unsafe-pr-checkout: true. PR #15876 by @YuriiMotov.v0.138.2Compare Source
Refactors
app.frontend()return 404 for methods other thanGETorHEADwith no static file matches. PR #15863 by @tiangolo.Internal
v0.138.1Compare Source
Refactors
Internal
v0.138.0Compare Source
Features
app.frontend("/", directory="dist")androuter.frontend("/", directory="dist"). PR #15800 by @tiangolo.Docs
app.frontend()instructions to Agent Library Skill. PR #15805 by @tiangolo.Translations
Internal
release-notes.mdfor typos. PR #15796 by @YuriiMotov.gpt-5.5model intranslate.py, specify-chatto avoid warnings. PR #15792 by @YuriiMotov.v0.137.2Compare Source
Features
iter_route_contexts()for advanced use cases that used to userouter.routes(e.g. Jupyverse). PR #15785 by @tiangolo.Translations
Internal
coverage.sh. PR #15772 by @tiangolo.v0.137.1Compare Source
Fixes
v0.137.0Compare Source
Breaking Changes
APIRouterandAPIRouteinstances. PR #15745 by @tiangolo.Unblocks ✨ SO MANY THINGS ✨
Before this,
router.include_router(other_router)would take each path operation fromother_routerand "clone" it, or recreate it from scratch.This would mean that in the end there was only one top level router, part of the app.
The way it is structured here is that there are a few additional classes to handle intermediate metadata for router and route inclusion. That way the information of "router X includes Y and Y includes Z" is stored somewhere, without affecting (recreating / clonning) the final route.
Non Objectives
Dependencies for 404: previously I intended to support dependencies that would be executed even for 404, but that would conflict with the fact that a router could not find a match, but the next router did find a match. Executing dependencies in the router that did not find a match would not make sense, they could consume the request, body, etc. This original idea was discarded.
Specific Breaking Changes
Now
router.routesis no longer a plain list ofAPIRouteobjects, it can contain these intermediate objects that can contain additional routers, forming a tree.Any logic that depended on iterating on the
router.routesdirectly would be affected, that logic cannot expect to be able to extract data from a plain list of routes, as it's no longer a plain list but a tree.Additionally, any logic that iterated on
router.routesto modify them would now also see these new objects, and would not see all the routes in the app.router.routesshould be considered an internal implementation detail, only passed around to the FastAPI functions that need it.Features
subrouterinmainroutercan be done before adding routes (path operations) tosubrouter, because now the the entire object is stored instead of copying the routes.Alpha Features
This is not documented yet, so it's not officially supported yet and could change in the future.
But, as
APIRouteandAPIRouterinstances are now preserved, they could be customized.APIRouterhas two new methods,.matches()and.handle(), counterpart to the existing ones inAPIRoute. With this a router could customize how it matches and handles requests. For example, it could match only requests that include some specific header, for example for handling versions in headers.Still, for now, consider this very experimental and potentially changing and breaking in the future.
Future Features Enabled
APIRoutesubclasses (undocumented, but alraedy works as desccribed above)APIRoutersubclasses (undocumented, but already works as described above)Docs
Annotatedin inline example indocs/en/docs/tutorial/body-multiple-params.md. PR #15591 by @TheArchons.docs/en/docs/tutorial/security/oauth2-jwt.md. PR #14781 by @zadevhub.Translations
Internal
changing_dirinstead ofCLIRunner.isolated_filesystemto set working dir. PR #15616 by @YuriiMotov.httpx2test dependency to avoid deprecation warning. PR #15603 by @YuriiMotov.v0.136.3Compare Source
Refactors
convert_underscores=True(the default). PR #15589 by @tiangolo.coleifer/huey (huey)
v3.3.4Compare Source
DoubleFieldfor the statsts,durationandstartedcolumns.On PG & MySQL the old
FloatFieldwas a 32-bit-shitter which lost a lot ofseconds of precision. Existing PG/MySQL tables will need to run the SQL below
to migrate OR just drop the tables and allow them to be rebuilt next run.
SQLite was not affected. Fixes #909.
View commits
v3.3.3Compare Source
OPTIONSwhen setting up the stats recorderconnection. Fixes / replaces #907.
sqlite3access at module scope, #908.View commits
v3.3.2Compare Source
workers might drop some writes.
in sorted order. Concurrent writers (one per process worker) could deadlock
in Postgres, and the failed flush dropped its whole batch of events.
FileLockfd per-thread. Under thread contention the shared fdwas clobbered and released by the wrong thread, leaking a held flock and
wedging every process using that storage path.
FileHueywith the defaultthread workers deadlocked on first contention.
View commits
v3.3.1Compare Source
os.register_at_fork.Previously the writer thread existed only in the process that called
enable_stats(), so a consumer w/worker_type='process'(or a preforkingweb server that loads the app before forking) buffered task events in its
workers but never wrote them, and the dashboard showed tasks stuck on
"enqueued".
View commits
v3.3.0Compare Source
retry_backoffparameter totask()andperiodic_task(). The firstretry waits
retry_delayseconds and each subsequent delay is multiplied byretry_backoff, giving exponentially-growing waits between retries.create_tables=False, which crashedSqliteHueyat connect and wassilently ignored by the peewee
SqlHuey.SqlStoragealso gainsinitialize_schema()so thecreate_huey_tablescommand supports it.FileStorageby truncating to int. Previouslythey raised a TypeError.
ResultTimeoutfrom blockingResult.get()when the wait ends w/o anobtainable result, e.g. a dropped connection. Previously the internal
EmptyDatasentinel could be returned.retry_backoffwhen a task is rescheduled viaResult.reschedule().works on
RedisExpireHueywhere destructive reads do not remove data.scheduled_items()that returned limit+1items.
SqlHueycounter methods, which run inthe consumer via chords and rate limits.
TaskLock.__enter__(), sowith huey.lock_task('x') as lock:binds the lock instead of None.init issued an INFO round-trip.
ukt CI dependency.
backend_classalias forhuey_class(deprecated since2.0) and the Django <1.2
settings.DATABASE_NAMEqueue-name fallback.failed, revoked, or expired stage now contributes for the member, where
previously the chord counter stayed short and the callback never ran.
CySqliteHuey, which drives the sqlite storage w/cysqliteinstead ofthe stdlib
sqlite3module and takes an open-endedpragmasdict in placeof a fixed set of tuning parameters.
View commits
v3.2.1Compare Source
huey.contrib.djhuey.statstoINSTALLED_APPSstarts thehuey.contrib.statsrecorder in every process (incl. the consumer) and addsa Huey section to the admin: a dashboard w/ the same live stats and controls
as the flask-peewee panel, plus a filterable event log. Stats are stored via
peewee in the default Django database and require no migrations.
View commits
v3.2.0Compare Source
store_intermediate_errorsoption (default true, preserving currentbehavior). When false, a task that fails with retries remaining no longer
writes its exception to the result store or runs its
on_errorhandler untilthe retries are exhausted, so a blocking
Result.get()waits for the finaloutcome instead of raising on the first failed attempt.
create_tablesoption to the SQL storage backends (default true). Passcreate_tables=Falseto skip the automaticcreate table if not existsatinit, e.g. to manage huey's schema via Django migrations rather than have
every web worker attempt DDL on import.
create_huey_tablesDjango management command to create the tables whencreate_tables=False.on_errorhandlers accumulating one exception argument per failed attemptacross retries. Handlers now receives only the current attempt's exception.
huey.contrib.stats, a task-statistics engine:enable_stats(huey, db)records task signals into two peewee tables (
huey_event,huey_inflight)and exposes a
HueyStatsquery API for throughput, per-task timing,error-rates, in-flight and recent-event views. Depends only on peewee, so it
can back a custom dashboard or exporter. Enable it in the consumer to capture
task execution.
huey.contrib.flask_admin.HueyPanel,registered w/
admin.register_panel('Huey', HueyPanel, huey). It renders therecorded stats as a dashboard card plus a standalone page with live queue
depths, throughput, per-task stats, running tasks and recent events. Has
controls to revoke/restore tasks and flush the queue, schedule, results or
locks. Requires flask-peewee 4.0.1+.
View commits
v3.1.1Compare Source
limit on the channel name.
w/Postgres.
View commits
v3.1.0Compare Source
PostgresHuey. Workers use LISTEN/NOTIFYwhen a task is enqueued, giving Redis-like dequeue latency without polling,
and dequeues use
select ... for update skip lockedso any number ofconsumers can share one database (requires psycopg 3.2+).
django-tasksbackport package, extending support to pre-6.0 Django.
forkmultiprocessing context for process workers, ratherthan setting the global start-method from the consumer entry-points. Fixes
-k processon MacOS 3.8+ / Linux 3.14+ when the consumer is started viathe
huey_consumerconsole-script or a programmaticcreate_consumer().run().View commits
v3.0.3Compare Source
Django integration works (manage.py run_huey), but using Django's canonical
APIs and decorator. Docs here.
View commits
v3.0.2Compare Source
ConnectionError: the errorpropagates to the worker, which logs it and applies exponential backoff.
Previously a downed redis server caused workers to busy-loop silently.
by a pre-execute hook. The skipped member contributes a
Noneplaceholderresult. Previously the callback was silently lost.
instead of running them back-to-back, which enqueued duplicate periodic
tasks for the current minute.
wait_result()when usingnotify_resultwith redis < 6 (or an unknown server version): timeouts over one second were
cut to 1s, and sub-second timeouts blocked indefinitely.
put_if_empty()is now atomic for the memory and file storage backends,restoring
lock_task()mutual exclusion on those backends.FileLockno longer unlinks an existing lock file at construction time,which broke mutual exclusion for any process already holding the lock.
signal.setitimer(), so float / sub-secondtimeouts work. Previously a timeout less than 1 second was silently ignored
(
alarm(0)cancels the timer) and fractional seconds were truncated.happen in the main loop, avoiding re-entrant I/O from signal context.
taskis no longer dropped duringserialization. Context tasks (
context=True) inject the task instance intoa copy of the kwargs rather than mutating the task's data.
MemoryStorage.dequeue()andadd_to_schedule()acquire the storage lock,like the other mutating methods.
normalize_time()treatsdelay=0as "now" rather than ignoring it, soe.g.
expires=0means "expires immediately" instead of "never expires".enqueued_items(limit)returnedlimit + 1items from the producerend of the queue. It now returns the next-
limititems to be dequeued,matching the other storage backends.
instead of failing at import time.
View commits
messense/nh3 (nh3)
v0.3.6Compare Source
What's Changed
Full Changelog: https://github.com/messense/nh3/compare/v0.3.5...v0.3.6
open-telemetry/opentelemetry-python (opentelemetry-api)
v1.44.0Compare Source
Added
opentelemetry-docker-tests: Refactor Docker tests to properly validatecontents of exported telemetry
(#5220)
opentelemetry-exporter-otlp-common: add shared package for common OTLPutilities
(#5252)
opentelemetry-sdk: addMissingDependencyErrorexception for declarativeconfiguration and use it for missing optional dependency errors
(#5265)
opentelemetry-sdk: Add ability to refresh process dependent Resourceattributes
(#5280)
opentelemetry-sdk: addforce_flushmethod toLogRecordExporterABC(#5294)
opentelemetry-sdk: Make it possible to limit the size of stored spans inInMemorySpanExporter
(#5296)
opentelemetry-sdk: add log record limits environment variablesOTEL_LOGRECORD_ATTRIBUTE_COUNT_LIMITandOTEL_LOGRECORD_ATTRIBUTE_VALUE_LENGTH_LIMIT(#5300)
opentelemetry-sdk: add support for file exporter with declarative config(#5311)
opentelemetry-sdk: exposeSynchronousMultiLogRecordProcessorandConcurrentMultiLogRecordProcessorpublicly(#5327)
opentelemetry-sdk: point the declarative configuration package README atthe shared language support status
matrix
in the
opentelemetry-configurationrepo, so Python conformance status livesalongside the other languages instead of being duplicated per language SDK.
(#5347)
opentelemetry-sdk: document that Python-implementation extensions(
OTEL_PYTHON_*variables) are bypassed whenOTEL_CONFIG_FILEis set. Theenv-var initialisation path is skipped entirely in favour of the declarative
file; honouring these alongside a config file is tracked as a follow-up.
(#5353)
opentelemetry-sdk: wire id_generator from declarative configuration toTracerProvider
(#5363)
opentelemetry-sdk: Add support for activating instrumentors from adeclarative configuration file via the
instrumentation/development.pythonsection. Instrumentors can declare a
configurationattribute to have theiroptions validated through the same type-coercion pipeline used for SDK
component configuration.
(#5372)
opentelemetry-sdk: addrecord_min_maxoption toExponentialBucketHistogramAggregation, matching the option alreadyavailable on
ExplicitBucketHistogramAggregationand required by thespecification
(#5377)
Changed
(#5329)
opentelemetry-instrumentation-logging(#5344)
opentelemetry-sdk: bump declarative configuration schema to v1.1.0(#5345)
opentelemetry-configuration: declarative configuration moves fromopentelemetry.sdk._configurationinto the new publicopentelemetry-configurationpackage (opentelemetry.configurationnamespace), published experimentally.
opentelemetry-sdk[file-configuration]continues to work as an alias that installs
opentelemetry-configurationalongside the SDK.
(#5356)
opentelemetry-api: remove env carrier environment snapshot caching, you nowhave to pass explicitly the mapping where to get the environment variables
from as the
EnvironmentGetter.getfirst argument.(#5366)
opentelemetry-semantic-conventions: bump to 1.42.0(#5410)
opentelemetry-semantic-conventions: bump to 1.43.0(#5413)
Removed
opentelemetry-api,opentelemetry-sdk: Removed deprecated Events API/SDK.Use
LogRecordwith theevent_namefield set instead.(#5293)
Fixed
opentelemetry-sdk: OptimizeLogRecordmemory inBatchLogRecordProcessorby clearing the
Contextobject before buffering. This is a potentiallybreaking change for custom log exporters that access
contextfrom theexported
ReadableLogRecord, as the context will now be an emptyContext()instead of the original.
(#4977)
opentelemetry-sdk: drop non-finite measurements (NaN and Inf) at theinstrument level to prevent permanent aggregation poisoning
(#5336)
opentelemetry-sdk: raiseValueErrorwhenExplicitBucketHistogramAggregationboundaries are not strictly increasingor finite
(#5340)
opentelemetry-sdk:ProcessResourceDetectorno longer collects or emitsprocess.command_argsandprocess.command_lineby default since the valuesare not sanitized and may contain sensitive information. Users who depend
on these resource attributes must pass
include_command_args=True.(#5364)
opentelemetry-exporter-otlp-proto-http: fix the OTLP HTTP metric exporterself-observability metrics over-counting data points when
max_export_batch_sizesplits a batch; each split now reports its owndata-point count instead of the whole-batch count.
(#5370)
opentelemetry-api: Prevent in-place mutation ofContextvia inheriteddictmethods(#5399)
v1.43.0Compare Source
Added
opentelemetry-sdk: addadd_metric_reader/remove_metric_readerpublicAPIs to register / unregister metric readers at runtime.
(#4863)
opentelemetry-exporter-prometheus: add support for configuring metric scopelabels
(#5123)
opentelemetry-exporter-otlp-proto-grpc: Add grpc error details to the logmessage that's written when the grpc call fails.
(#5143)
opentelemetry-exporter-http-transport: add'opentelemetry-exporter-http-transport' package for HTTP exporters
(#5194)
opentelemetry-sdk: Addcomposite/developmentsamplers support todeclarative file configuration
(#5201)
opentelemetry-exporter-otlp-json-file: Add OTLP JSON File exporterimplementation
(#5207)
opentelemetry-sdk: add_resolve_componentshared utility for declarativeconfig plugin loading, reducing boilerplate in exporter factory functions
(#5215)
opentelemetry-sdk: add pull metric reader support to declarative fileconfiguration, including Prometheus metric reader via the
prometheus_developmentconfig field(#5216)
opentelemetry-proto-json: update to use opentelemetry-proto v1.10.0(#5224)
opentelemetry-proto: bump maximum supported protobuf version to 7.x.x(#5251)
opentelemetry-sdk: addServiceInstanceIdResourceDetectorfor populatingservice.instance.id(#5259)
opentelemetry-sdk: declarative config loader now recursively convertsparsed dicts into typed dataclass instances, including nested dataclasses,
lists of dataclasses, and enum values. End-to-end YAML/JSON → SDK
configuration now works via the factory functions.
(#5269)
opentelemetry-sdk: addconfigure_sdk(config)to the declarativeconfiguration API. Single entry point that takes a parsed
OpenTelemetryConfiguration, builds the resource, and applies thetracer/meter/logger providers and propagator globally. Honors the top-level
disabledflag.(#5270)
opentelemetry-sdk: the SDK configurator now honors theOTEL_CONFIG_FILEenvironment variable. When set, the SDK loads and applies the referenced
declarative configuration file (YAML or JSON) in place of the env-var-based
init path.
(#5271)
opentelemetry-sdk: update declarative config to useServiceInstanceIdResourceDetector(#5299)
opentelemetry-exporter-otlp-proto-common,opentelemetry-exporter-otlp-json-common: encoders now always accept null,and encode it as an empty
AnyValuein accordance with the spec.(#5305)
opentelemetry-sdk: validate the declarative configfile_formatversion —reject an unsupported major version and warn on a newer minor version, per
the configuration spec versioning rules
(#5315)
opentelemetry-exporter-http-transport: enable entry-point loading oftransport implementations
(#5320)
Changed
opentelemetry-sdk: introduce experimental entry points for OpAMP agentintegration
(#4646)
opentelemetry-api: conditionally import entrypoints foropentelemetry_contextonly if theOTEL_PYTHON_CONTEXTenv variable isdefined, return
ContextVarsRuntimeContextotherwise(#5144)
opentelemetry-sdk: rename "known/unknown" to "built-in/user-defined"terminology in declarative config component loading code
(#5214)
opentelemetry-proto: regenerate protobuf code from opentelemetry-protov1.10.0
(#5223)
opentelemetry-sdk: remove unnecessarycopyin Span creation(#5272)
(#5274)
opentelemetry-sdk: inline the method_clean_attribute_value(#5275)
typing.Unionandtyping.Optionalwith|.(#5277)
(#5287)
(#5288)
opentelemetry-api: updateEnvironmentGetterto ignore non-normalizedenvironment variable names
(#5289)
(#5297)
(#5298)
(#5326)
opentelemetry-api: normalize empty environment propagation names to_inEnvironmentSetterandEnvironmentGetter(#5328)
Fixed
.rstfiles to Sphinx documentation build for SDK logs,propagators, and exporter submodules.
(#5017)
setting the random trace id bit depending on the available trace id
generator.
(#5241)
opentelemetry-api: fix SelectableGroups deprecation warning(#5250)
opentelemetry-sdk: makeSynchronousMeasurementConsumer.consume_measurementlock free to avoiddeadlocks
(#5321)
v1.42.1Compare Source
Fixed
setting the random trace id bit depending on the available trace id
generator.
(#5241)
v1.42.0Compare Source
Added
opentelemetry-api,opentelemetry-sdk: add support for 'random-trace-id'flags in W3C traceparent header trace flags. Implementations of
IdGeneratorthat do randomly generate the 56 least significant bits, should also
implement a
is_trace_id_randommethods that returnsTrue.(#4854)
(#4908)
opentelemetry-exporter-otlp-proto-grpc: make retryable gRPC error codesconfigurable for gRPC exporters
(#4917)
opentelemetry-sdk: Addcreate_logger_provider/configure_logger_providerto declarative file configuration, enabling LoggerProvider instantiation from
config files without reading env vars
(#4990)
opentelemetry-exporter-otlp-json-common: add'opentelemetry-exporter-otlp-json-common' package for OTLP JSON exporters
(#4996)
opentelemetry-sdk: Addserviceresource detector support to declarativefile configuration via
detection_development.detectors[].service(#5003)
opentelemetry-docker-tests: add docker-tests coverage ofopentelemetry-exporter-otlp-proto-grpcandopentelemetry-exporter-otlp-proto-httpmetrics export(#5030)
registrykeyword argument toPrometheusMetricReaderto allow passinga custom Prometheus registry
(#5055)
(#5088)
opentelemetry-sdk: addload_entry_pointshared utility to declarativefile configuration for loading plugins via entry points; refactor propagator
loading to use it
(#5093)
opentelemetry-sdk: add sampler plugin loading to declarative fileconfiguration via the
opentelemetry_samplerentry point group, matching thespec's PluginComponentProvider mechanism
(#5095)
opentelemetry-sdk: add propagator plugin loading to declarative fileconfiguration via the
opentelemetry_propagatorentry point group, matchingthe spec's PluginComponentProvider mechanism
(#5098)
opentelemetry-sdk: add exporter plugin loading to declarative fileconfiguration for all three signals (traces, metrics, logs) via the
opentelemetry_*_exporterentry point groups, matching the spec'sPluginComponentProvider mechanism
(#5128)
opentelemetry-sdk: add generic resource detector plugin loading todeclarative file configuration via the
opentelemetry_resource_detectorentry point group, matching the spec's PluginComponentProvider mechanism
(#5129)
opentelemetry-sdk: addadditional_propertiessupport to generated configmodels via custom
datamodel-codegentemplate, enabling plugin/customcomponent names to flow through typed dataclasses
(#5131)
OTEL_PYTHON_SDK_INTERNAL_METRICS_ENABLEDenvironment variable.(#5151)
Changed
opentelemetry-semantic-conventions: useX | Yunion annotation(#5096)
opentelemetry-api: updateEnvironmentGetterandEnvironmentSettertouse normalized environment variable names
(#5119)
UPruff rule(#5133)
opentelemetry-sdk: only load entrypoints for resource detectors if they areconfigured via
OTEL_EXPERIMENTAL_RESOURCE_DETECTORS(#5145)
scripts/tracecontext-integration-test.sh(#5149)
(#5177)
opentelemetry-semantic-conventions: Bump semantic conventions to 1.41.1,this changes the metrics name of
K8S_CONTAINER_CPU_LIMIT_UTILIZATIONandK8S_CONTAINER_CPU_REQUEST_UTILIZATION.(#5200)
Removed
opentelemetry-api: remove third-party importlib-metadata in favor ofstandard library since Python >= 3.10 is now required
(#3234)
(#5076)
Fixed
opentelemetry-sdk: Allow declarative OTLP HTTP exporters to mapcompression: deflateinstead of rejecting it as unsupported.(#5075)
create_tracer()docstring(#5077)
opentelemetry-sdk: FixProcessResourceDetectorto usesys.orig_argvsothat
process.command,process.command_line, andprocess.command_argsreflect the original invocation for
python -m <module>runs (wheresys.argv[0]is rewritten to the module path)(#5083)
opentelemetry-sdk: fix YAML structure injection via environment variablesubstitution in declarative file configuration; values containing newlines
are now emitted as quoted YAML scalars per spec requirement
(#5091)
opentelemetry-sdk: Fix mutable attributes reference in metrics, attributespassed to instrument
add/recordare now copied so that subsequentmutations do not affect recorded data points
(#5106)
opentelemetry-sdk: make resource detector ordering deterministic(#5120)
detectorsparameter ofget_aggregated_resources(#5135)
opentelemetry-api: Enforce W3C Baggage size limits on outbound propagationin
W3CBaggagePropagator.inject(). Previously only inbound extractionenforced limits; now inject also caps entries at 180, individual pairs at
4096 bytes, and total header at 8192 bytes per the W3C Baggage spec. The
extract path max_pairs limit now counts all size-valid entries rather than
only successfully parsed ones.
(#5163)
opentelemetry-sdk: fix multi-processorforce_flushskipping remainingprocessors when one returns
None(#5179)
opentelemetry-test-utils: fix weaver live check hanging when weaver logoutput fills the pipe buffer
(#5208)
pytest-dev/pytest (pytest)
v9.1.1Compare Source
pytest 9.1.1 (2026-06-19)
Bug fixes
pytest.RaisesGroupwhich would might cause it to display incorrect "It matches FooError() which was paired with BarError" messages.list-itemtyping errors from mypy in@pytest.mark.parametrize <pytest.mark.parametrize ref>argvaluesparameter.conftest.pyfiles located in<invocation dir>/test*were no longer loaded as initial conftests when invoked without arguments.This could cause certain hooks (like
pytest_addoption) in these files to not fire.v9.1.0Compare Source
pytest 9.1.0 (2026-06-13)
Removals and backward incompatible breaking changes
#14533: When using
--doctest-modules, autouse fixtures withmodule,packageorsessionscope that are defined inline in Python test modules (not plugins or conftests) will now possibly execute twice.If this is undesirable, move the fixture definition to a
conftest.pyfile if possible.Technical explanation for those interested:
When using --doctest-modules, pytest possibly collects Python modules twice, once as
pytest.Moduleand once as aDoctestModule(depending on the configuration).Due to improvements in pytest's fixture implementation, if e.g. the
DoctestModulecollects a fixture, it is now visible to it only, and not to theModule.This means that both need to register the fixtures independently.
Deprecations (removal in next major release)
#10819: Added a deprecation warning for class-scoped fixtures defined as instance methods (without
@classmethod). Such fixtures set attributes on a different instance than the test methods use, leading to unexpected behavior. Use@classmethoddecorator instead -- byyastcher.See
10819and14011.#12882: Calling
request.getfixturevalue() <pytest.FixtureRequest.getfixturevalue>during teardown to request a fixture that was not already requested is now deprecated and will become an error in pytest 10.See
dynamic-fixture-request-during-teardownfor details.#13409: Using non-
~collections.abc.Collectioniterables (such as generators, iterators, or custom iterable objects) for theargvaluesparameter in@pytest.mark.parametrize <pytest.mark.parametrize ref>andmetafunc.parametrize <pytest.Metafunc.parametrize>is now deprecated.These iterables get exhausted after the first iteration,
leading to tests getting unexpectedly skipped in cases such as running
pytest.main()multiple times,using class-level parametrize decorators,
or collecting tests multiple times.
See
parametrize-iteratorsfor details and suggestions.#13946: The private
config.inicfgattribute is now deprecated.Use
config.getini() <pytest.Config.getini>to access configuration values instead.See
config-inicfgfor more details.#14004: Passing
baseidto~pytest.FixtureDefornodeidstrings to fixture registration APIs is now deprecated. These are internal pytest APIs that are used by some plugins.Use the
nodeparameter instead for fixture scoping. This enables more robust node-basedmatching instead of string prefix matching.
If you've used
nodeid=None, passnode=sessioninstead.This will be removed in pytest 10.
#14335: The method of configuring hooks using markers, deprecated since pytest 7.2, is now scheduled to be removed in pytest 10.
See
hook-markersfor more details.#14434: The
--pastebinoption is now deprecated.The same functionality is now available in an external plugin,
pytest-pastebin.See
pastebin-deprecatedfor more details.#14513: The private
FixtureDef.has_locationattribute is now deprecated and will be removed in pytest 10.See
fixturedef-has-location-deprecatedfor details.#1764:
pytest.console_mainis now deprecated and will be removed in pytest 10.It was never intended for programmatic use; use
pytest.maininstead.New features
#12376: Added
pytest.register_fixture()to register fixtures using an imperative interface.This is an advanced function intended for use by plugins.
Normally, fixtures should be registered declaratively using the
@pytest.fixture <pytest.fixture>decorator.Pytest looks for these fixture definitions during the collection phase and registers them automatically.
For some plugin usecases the declarative interface can be cumbersome or unviable, in which case this imperative interface can be used.
#14023: Added --report-chars long CLI option.
#14371: Added
--max-warningscommand-line option andmax_warningsconfiguration option to fail the test run when the number of warnings exceeds a given threshold -- bymiketheman.#6757: Added the
assertion_text_diff_styleconfiguration option, allowingstring equality failures to be rendered as separate
Left:andRight:blocks instead of
ndiffoutput.#8395: Added support for
~datetime.datetimeand~datetime.timedeltacomparisons withpytest.approx. An explicitabsorreltolerance as a~datetime.timedeltais required and relative tolerance is not supported for datetime comparisons -- byhamza-mobeen.Improvements in existing functionality
#11225:
pytest.warnsnow shows "Regex pattern did not match" instead of "DID NOT WARN" when warnings were emitted but thematchpattern did not match.#11295: Improved output of
--fixtures-per-testby excluding internal-implementation fixtures generated by@pytest.mark.parametrizeand similar.#13241:
pytest.raises,pytest.warnsandpytest.deprecated_callnow usesParamSpecfor the type hint to the (old and not recommended) callable overload, instead ofAny. This allows type checkers to raise errors when passing incorrect function parameters.funccan now also be passed as a kwarg, which the type hint previously showed as possible but didn't accept.#13862: Improved the readability of "DID NOT RAISE" error messages by using the exception type's name instead of its repr.
#14026: Added test coverage for compiled regex patterns in
pytest.raisesmatch parameter.#14137: pytest.ScopeName is now public to allow using it in function signatures.
#14342: Marked
yield_fixtureas deprecated to type checkers using thedeprecateddecorator. Note ithas originally been deprecated <yield-fixture-deprecated>in pytest 6.2 already.#14373: Added type annotations for
pytest.approx.#14430: When using
--setup-show, a space is now printed after the test name (and possibly used fixtures), to separate it from the test result.#14441: Reduced the default number of
gc.collect()passes in theunraisableexceptionplugin from 5 to 1 on CPython, where reference counting makes a single pass sufficient. PyPy retains 5 passes due to object resurrection via__del__. This can noticeably speed up test suites that trigger many pytester runs.#14461: Improved assertion failure explanations for equality comparisons between mapping objects that are not
dictinstances.#14513: The order in which fixture definitions overriding each other are resolved is now determined first by their visibility in the collection tree rather than by the order in which they are registered.
A fixture defined for a more specific node (e.g. a module or an item) now always takes precedence over one with the same name defined for a more general node (e.g. the session), even when the more general one was registered later.
Fixtures with non-comparable visibility or the same visibility keep the existing behavior of "last registered wins".
This change is supposed to only affect plugins which register multiple fixtures programmatically with the same name.
#14524: Add official Python 3.15 support.
#1764: Improved argparse program name to show
pytest,python -m pytest, orpytest.main()based on how pytest was invoked, making help and error messages clearer.#8265: Emit a
PytestCollectionWarningwhen a module-level__getattr__returnsNoneforpytestmarkinstead of raisingAttributeError.Previously this caused a cryptic
TypeError: got None instead of Markerror.Now pytest issues a helpful warning and continues collecting the module normally.
Bug fixes
#13192: Fixed | (pipe) not being treated as a regex meta-character that needs escaping in
pytest.raises(match=...) <pytest.raises>.#13484: Fixed
-Woption values being duplicated inConfig.known_args_namespace.#13626: Fixed function-scoped fixture values being kept alive after a test was interrupted by
KeyboardInterruptor early exit,allowing them to potentially be released more promptly.
#13784: Fixed
capteesysproducing doubled output when used with--capture=no(-s).#13817: Fixed a secondary AttributeError masking the original error when an option argument fails to initialize.
#13884: Fixed rare internal IndexError caused by builtins.compile being overridden in client code.
#13885: Fixed autouse fixtures defined inside a
unittest.TestCaseclass running even when the class is decorated withunittest.skiporunittest.skipIf-- regression since pytest 8.1.0.#13917:
unittest.SkipTestis no longer considered an interactive exception, i.e.pytest_exception_interactis no longer called for it.#13963: Fixed subtests running with
pytest-xdistwhen their contexts contain objects that are not JSON-serializable.Fixes pytest-dev/pytest-xdist#1273.
#14004: Fixed conftest.py fixture scoping when
testpathspoints outside of therootdir <rootdir>.Previously, fixtures from nested conftest.py files would incorrectly leak to sibling directories
when using a relative
testpathslike../tests/sdk.Conftest fixtures are now parsed during
Directory <pytest.Directory>collection, using theDirectorynode for proper scoping.#14050: Display dictionary differences in assertion failures using the original key insertion order instead of sorted order.
#14080: fix missing type annotations on
Pytester.makepyfileandPytester.maketxtfilemethods.#14114: An exception from
pytest_fixture_post_finalizerno longer prevents fixtures from being torn down, causing additional errors in the following tests.#14161: Fixed
monkeypatch.setattr() <pytest.MonkeyPatch.setattr>leaving a stale entry on the undo stack when the underlyingsetattr()call fails (e.g. on immutable targets), causing anAttributeErrorcrash during teardown.#14214: Fixed
-vhint inpytest.raisesmatch diff not working because assertion verbosity was not propagated.#14234: Allow
pytest.HIDDEN_PARAM <hidden-param>in@pytest.mark.parametrize(ids=...) <pytest.mark.parametrize ref>typing.#14248: Fixed direct parametrization causing the static fixture closure (as reflected in
request.fixturenames <pytest.FixtureRequest.fixturenames>) to omit fixtures that are requested transitively from overridden fixtures.#14263: Unraisable exceptions from finalizers are now collected during
pytest_unconfigure, before pytest tears down the warning filters installed for the session. Previously the collection ran from a cleanup callback whose order relative to other plugins' cleanups was not guaranteed, so an activeerrorfilter could be removed before the exception surfaced and a late resource leak would pass silently. A-W errorfilter, or any filter matchingpytest.PytestUnraisableExceptionWarning, now promotes these exceptions to failures regardless of plugin cleanup order.#14377: Fixed crash in Config.get_terminal_writer when an assertion fails with the
terminalreporterplugin disabled.#14381: Fixed
-V(short form of--version) to properly display the current version.#14389: Improved
pytest.raises(..., match=...) <pytest.raises>failures to suppress the mismatched exception as a cause of the resultingAssertionError.#14392: Fixed a bug in
pytest.raises(match=...) <pytest.raises>"fully escaped" detection, causing the regex diff display to be shown in some instances when the raw string diff display should be shown instead.#14442: Fixed a regression in pytest 9.0 where
--strict-markersand--strict-configspecified throughaddoptswere silently ignored.Note that when targeting pytest >= 9.0, it's nicer to use
strict_markersandstrict_config, orstrict mode <strict mode>.#14456: Fixed
pytest.approxnot recognizing types with__array_interface__as numpy-like arrays.#14474: Fixed a regression where
-kand-mexpressions containing both backslash characters in identifiers and string literal arguments would incorrectly raise aSyntaxErrorabout escaping.#14483: Fixed JUnit XML report incorrectly escaping high Unicode codepoints (supplementary plane characters like emoji) in test failure messages. -- by
EternalRights#14492: Fixed
Code.getargs()incorrectly including local variable names in the returned argument tuple for functions with*argsand/or**kwargs. The method was usingco_flagsbitmask values (4and8) directly as counts instead of converting them to1viabool(), and was not accounting forco_kwonlyargcountwhenvar=True.#3697: Logging capture now works for non-propagating loggers.
Previously only logs which reached the root logger were captured.
This includes
caplogand the "Captured log calls" test reporting.#3850: Fixed JUnit XML report: the
testsattribute of the<testsuite>element now always matches the number of<testcase>elements in the file. In some cases (test passes but fails during teardown) thetestsattribute would report an incorrect number of testcases in the XML file.#5848:
pytest_fixture_post_finalizeris no longer called extra times for the same fixture teardown in some cases.#719: Fixed
@pytest.mark.parametrize <pytest.mark.parametrize ref>not unpacking single-element tuple values when using a string argnames with a trailing comma (e.g.,"arg,").The trailing comma form now correctly behaves like the tuple form
("arg",), treating argvalues as a list of tuples to unpack.Improved documentation
@pytest.hookimpl(specname=...)only works for function names starting withpytest_.requestfixture provides indirect parametrization values viarequest.param.conftest.pyfiles are not available to other plugins during theirpytest_addoption()execution, as conftest files are discovered and loaded after builtin and third-party plugins have been initialized. However, initial conftest files themselves can implementpytest_addoption()to add their own command-line options.ini options refsection of the API Reference now specified the type and default value of every configuration option.pytestconfig.cacheaccess pattern when thecacheproviderplugin is disabled.newhooks.pyfile inpytest-xdistat tagv3.8.0instead of an unrelated 2017-era commit under the old layout. Pointing at a tag keeps the example in sync with the version users actually install, while remaining stable when the project's main branch moves on.Miscellaneous internal changes
laurents/slowapi (slowapi)
v0.1.10Compare Source
Changed
smithyhq/sqladmin (sqladmin)
v0.30.0Compare Source
Added
check_can_createpermission hook by @maxim-f1 in #1102Changed
Fixed
get_object_identifierby @pctablet505 in #1092bootstrapglobal is undefined by @ebencollins in #1100TemplateResponseby @haykeminyan in #1094New Contributors
Full Changelog: 0.29.0...0.30.0
v0.29.0Compare Source
Added
check_can_createpermission hook by @maxim-f1 in #1102Changed
Fixed
get_object_identifierby @pctablet505 in #1092bootstrapglobal is undefined by @ebencollins in #1100TemplateResponseby @haykeminyan in #1094New Contributors
Full Changelog: 0.29.0...0.30.0
v0.28.0Compare Source
DEPRECATIONS
Added
column_type_formatters_detailby @maxim-f1/@mmzeynalli in #999default_valueto filters by @wnowicki/@mmzeynalli in #1004Changed
AuthenticationBackend.loginto returnResponseby @sheldygg/@mmzeynalli in #935Fixed
selectinloadfor AJAX relations on edit page by @arturbent0/@mmzeynalli in #1059New Contributors
Full Changelog: 0.28.0...0.29.0
v0.27.2Compare Source
Added
rich_text_fieldsfor pluggable rich text editors by @vahidzhe in #1074requestto column formatters by @Dexter2099 in #1077Changed
tabler-icons.min.css.mapby @CHC383 in #1071Fixed
Upgrade notes
_build_url_forand_url_for_deleteuseself.identitywhen the target object is an instance of the view's model (including polymorphic subclasses), and the object's class identity otherwise. Overrides of either helper apply to built-in templates.requestargument to opt in.New Contributors
Full Changelog: 0.27.2...0.28.0
v0.27.1Compare Source
Changed
Fixed
New Contributors
Full Changelog: 0.27.1...0.27.2
v0.27.0Compare Source
Security
GHSA-ccg5-9c8w-xh6v: restrictModelView.sort_query()to the configuredcolumn_sortable_listallow-list (self._sort_fields) and reject invalidsortByvalues with HTTP 400, preventing attacker-controlled ordering across arbitrary model and related-model columns and avoiding uncaughtAttributeError(HTTP 500) by @aminalaee.Full Changelog: 0.27.0...0.27.1
v0.26.0Compare Source
Added
after_model_changeresponse by @dhcsousa in #1030Fixed
Docs
New Contributors
Full Changelog: 0.26.0...0.27.0
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR has been generated by Mend Renovate CLI.
ea1c0ec2739c54bfb5989c54bfb598832d28a022832d28a02223c94861c523c94861c5c9f9873a79c9f9873a79fc3c81547c