Skip to content

chore(deps): Bump the minor-and-patch group across 1 directory with 13 updates - #875

Merged
mrsabath merged 1 commit into
mainfrom
dependabot/uv/a2a/image_service/minor-and-patch-9ebb0ff7b0
Oct 2, 2026
Merged

mrsabath merged 1 commit into
mainfrom
dependabot/uv/a2a/image_service/minor-and-patch-9ebb0ff7b0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the minor-and-patch group with 13 updates in the /a2a/image_service directory:

Package From To
langgraph 1.2.9 1.2.12
langchain-core 1.4.9 1.6.6
langchain-openai 1.3.4 1.6.6
openinference-instrumentation-langchain 0.1.67 0.1.76
pydantic-settings 2.14.2 2.15.0
langchain-mcp-adapters 0.3.0 0.3.2
opentelemetry-exporter-otlp 1.43.0 1.45.0
opentelemetry-proto 1.43.0 1.45.0
urllib3 2.7.0 2.8.0
aiohttp 3.14.1 3.14.3
orjson 3.11.9 3.12.0
pyjwt 2.13.0 2.15.1
langsmith 0.10.1 0.14.1

Updates langgraph from 1.2.9 to 1.2.12

Release notes

Sourced from langgraph's releases.

langgraph==1.2.12

Changes since 1.2.11

  • release(langgraph): 1.2.12 (#8987)
  • chore(deps): bump soupsieve from 2.8.4 to 2.9 in /libs/langgraph (#8958)
  • feat(langgraph): add response_schema to interrupt() (#8886)
  • fix(langgraph): type undeclared v3 stream projections (#8596)
  • chore(langgraph): bump mistune to 3.3.4 (#8804)
  • chore(deps): bump the minor-and-patch group across 1 directory with 7 updates (#8779)
  • chore(deps): bump the minor-and-patch group across 1 directory with 4 updates (#8782)
  • chore(deps): bump tornado from 6.5.7 to 6.5.8 in /libs/langgraph (#8792)
  • chore(deps): bump the major group in /libs/langgraph with 2 updates (#8783)
  • fix(langgraph): detect subgraphs from bytecode instead of source (#8569)

langgraph==1.2.11

Changes since 1.2.10

  • release(langgraph): 1.2.11 (#8595)
  • feat(langgraph): expose trace_policy on add_node (#8523)
  • chore(deps): bump the minor-and-patch group across 1 directory with 7 updates (#8533)
  • chore(deps): bump the minor-and-patch group across 1 directory with 5 updates (#8532)
  • release(checkpoint-postgres): 3.1.2 (#8565)
  • release(checkpoint): 4.2.0 (#8563)
  • fix(checkpoint): collect writes at plain-value seed in delta channel history (#8526)
  • chore: enforce PLC0415 in tests for the remaining packages (#8547)
  • test(checkpoint-postgres,checkpoint-sqlite): run the conformance suite (#8537)
  • chore: enable RUF100 and clear unused noqa directives (#8546)
  • chore(deps-dev): bump types-requests from 2.33.0.20260518 to 2.33.0.20260712 in /libs/langgraph (#8502)
  • chore(deps): bump cryptography from 48.0.1 to 50.0.0 in /libs/langgraph (#8528)
  • release(checkpoint-sqlite): 3.1.1 (#8481)
  • release(checkpoint-postgres): 3.1.1 (#8480)

langgraph==1.2.10

Changes since 1.2.9

  • release(langgraph): 1.2.10 (#8462)
  • chore(deps): bump jupyterlab from 4.5.9 to 4.5.10 in /libs/langgraph (#8440)
  • chore(deps): bump setuptools from 80.9.0 to 83.0.0 in /libs/langgraph (#8435)
  • feat(langgraph): type v3 stream_events return and native projections (#8389)
  • revert(langgraph): delete TracePolicy (#8403)
  • feat(langgraph): drop tags from TracePolicy (#8402)
  • feat(langgraph): expose trace_policy on add_node (#8362)
  • chore(deps): bump mistune from 3.2.1 to 3.3.0 in /libs/langgraph (#8317)
  • chore(deps): bump soupsieve from 2.8.1 to 2.8.4 in /libs/langgraph (#8318)
  • chore(cli): allow langgraph-api versions up to 1.0.0 (#8319)
Commits
  • 49cce0c release(sdk-py): 0.4.5 (#8988)
  • 19273fa release(langgraph): 1.2.12 (#8987)
  • ed384f3 fix(cli): remediate AnyIO vulnerabilities in example lockfiles (#9022)
  • aa742fb chore(deps): bump anyio from 4.14.2 to 4.15.1 in /libs/sdk-py (#8997)
  • b58044a chore(deps): bump anyio from 4.13.0 to 4.14.2 in /libs/cli (#8998)
  • daa514a chore(deps): bump anyio from 4.13.0 to 4.14.2 in /libs/checkpoint-conformance...
  • 022043a chore(deps): bump anyio from 4.12.1 to 4.14.2 in /libs/checkpoint (#8995)
  • d7b99cc chore(deps): bump anyio from 4.12.1 to 4.14.2 in /libs/sdk-py (#8994)
  • b19edd7 chore(deps): bump anyio from 4.12.1 to 4.14.2 in /libs/checkpoint-sqlite (#8993)
  • c81c135 chore(deps): bump soupsieve from 2.8.4 to 2.9 in /libs/langgraph (#8958)
  • Additional commits viewable in compare view

Updates langchain-core from 1.4.9 to 1.6.6

Release notes

Sourced from langchain-core's releases.

langchain-core==1.6.6

Changes since langchain-core==1.6.5

release(core): 1.6.6 (#40906) fix(anthropic): support Claude Sonnet 5.5 compatibility (#40882) docs(core): fix docstring examples that don't run as copied (#40815)

langchain-core==1.6.5

Changes since langchain-core==1.6.4

release(core): 1.6.5 (#40816) fix(core): abbreviate long tool IDs in XML buffer strings (#40792)

langchain-core==1.6.4

Changes since langchain-core==1.6.3

release(core): 1.6.4 (#40718) chore(core): deprecate chat message history (#40711) chore(deps): bump anyio from 4.12.0 to 4.14.2 in /libs/core (#40634) chore(deps): bump soupsieve from 2.8.4 to 2.9 in /libs/core (#40574)

langchain-core==1.6.3

Changes since langchain-core==1.6.2

release(core): 1.6.3 (#40407) feat(core): Allow model name and provider tracing metadata override based on gateway response (#40406) test(core): cover the deprecated .text() access path (#40243) docs(core): remove stale Args/Raises entries from FileCallbackHandler._write and ChatGeneration.set_text (#40211)

langchain-core==1.6.2

Changes since langchain-core==1.6.1

release(core): 1.6.2 (#40209) feat(openai): support async tools (#40208) chore(deps): bump mistune from 3.3.0 to 3.3.3 in /libs/core (#40150) chore(deps): bump tornado from 6.5.7 to 6.5.8 in /libs/core (#40113) fix(core): avoid mutation in google-genai standard content (#40023) fix(core): avoid mutation in bedrock converse standard content (#40022)

langchain-core==1.6.1

Changes since langchain-core==1.6.0

revert: release(core): 1.6.2 (#39971) release(core): 1.6.2 (#39967) fix(core): shore up indexing in genai v1 streaming content (#39964) fix(core): make StructuredTool JSON-serializable (#39631) chore(deps): bump minor and patch dependencies (#39869) release(core): 1.6.1 (#39832) feat(core): propagate gateway information on error path (#39829)

... (truncated)

Commits

Updates langchain-openai from 1.3.4 to 1.6.6

Release notes

Sourced from langchain-openai's releases.

langchain-openai==1.6.6

Changes since langchain-openai==1.6.5

release(openai): 1.6.6 (#40800) fix(openai): raise on error events in stream path (#40791)

langchain-openai==1.6.5

Changes since langchain-openai==1.6.4

release(openai): 1.6.5 (#40787) fix(anthropic): add Opus 5.5 and GPT-6 profile augmentations (#40785) feat(anthropic,openai): mid-conversation tool changes on SystemMessage (#40758)

langchain-openai==1.6.4

Changes since langchain-openai==1.6.3

release(openai): 1.6.4 (#40775) chore(model-profiles): refresh openai model profile data (#40774)

langchain-openai==1.6.3

Changes since langchain-openai==1.6.2

release(openai): 1.6.3 (#40719) fix(openai): expose inferred Responses API routing at initialization (#40715) chore(deps): bump anyio from 4.11.0 to 4.14.2 in /libs/partners/openai (#40629) fix(openai): support GPT-6 request constraints (#40443)

langchain-openai==1.6.2

Changes since langchain-openai==1.6.1

release(openai): 1.6.2 (#40339) fix(openai): add GPT-6 Astra reasoning efforts (#40330) chore(deps): bump httpx2 from 2.10.0 to 2.12.0 in /libs/partners/openai (#40309)

langchain-openai==1.6.1

Changes since langchain-openai==1.6.0

fix(openai): bump max_completion_tokens in cache breakpoint integration test (#40284) release(openai): 1.6.1 (#40268) chore(model-profiles): refresh model profile data (#40217) fix(openai): support Azure AD auth with OpenAI 3.8 (#40190) feat(openai): support async tools (#40208) feat(openai): support configuration_update (#40201) chore(model-profiles): refresh model profile data (#40171) fix(openai): route gpt-5.6-sol to responses API (#40133) chore(openai): fix tests (#39972) fix(openai): correct reasoning_effort_levels for gpt-5 and gpt-5.1 profiles (#39936) chore(model-profiles): refresh model profile data (#39954)

langchain-openai==1.6.0

... (truncated)

Commits
  • 7622d3d release(openai): 1.6.6 (#40800)
  • 2dd956b docs(infra): fix AGENTS.md root setup guidance and package doc accuracy (#40794)
  • 49f4b40 fix(openai): raise on error events in stream path (#40791)
  • 19cadaa fix(core): abbreviate long tool IDs in XML buffer strings (#40792)
  • 798441e chore(anthropic): fix integration test cassette (#40790)
  • a476942 release(openai): 1.6.5 (#40787)
  • 46c6bdf release(anthropic): 1.7.4 (#40786)
  • 290daba fix(anthropic): add Opus 5.5 and GPT-6 profile augmentations (#40785)
  • 59baeb2 feat(anthropic,openai): mid-conversation tool changes on SystemMessage (#40...
  • 4b65996 chore(model-profiles): refresh model profile data (#40780)
  • Additional commits viewable in compare view

Updates openinference-instrumentation-langchain from 0.1.67 to 0.1.76

Release notes

Sourced from openinference-instrumentation-langchain's releases.

python-openinference-instrumentation: v0.1.70

0.1.70 (2026-10-01)

Bug Fixes

  • bump openinference-semantic-conventions minimum to >=0.1.41 (#3907) (04fe33f)

python-openinference-instrumentation: v0.1.69

0.1.69 (2026-10-01)

Features

  • add decision span decorators and attribute helpers (JS + Python) (#3897) (0d26a59)

python-openinference-instrumentation: v0.1.68

0.1.68 (2026-10-01)

Features

Commits
  • 3729ab4 chore: release main (#3712)
  • 2cc4ee2 chore(openai): support OpenAI Python SDK 3.x (#3647)
  • a3b5b6c fix: bump openinference-semantic-conventions minimum to >=0.1.37 (#3711)
  • a2e7ff6 chore: release main (#3707)
  • adaf9e7 feat(openai_agents): record file_search and web_search tool calls (#1726) (#3...
  • 2e04736 chore(deps): update llama-index-llms-anthropic requirement from <0.12.0,>=0.1...
  • ad0903e chore(deps): update anthropic requirement from <1.1 to <1.3 in /python/instru...
  • 029ca88 chore: release main (#3704)
  • 971e3db feat(openai_agents): record computer_call and computer_call_output (#1726) (#...
  • 8abaf89 chore: release main (#3681)
  • Additional commits viewable in compare view

Updates pydantic-settings from 2.14.2 to 2.15.0

Release notes

Sourced from pydantic-settings's releases.

v2.15.0

Highlights

Behavior changes

  • case_sensitive now applies to init kwargs and config-file sources (#900). InitSettingsSource and the JSON/TOML/YAML config sources previously ignored case_sensitive. Since it defaults to False, case-insensitive matching is now the default for these sources — e.g. Settings(TeSt=...) now populates a test field where it previously did not. Nested keys are still matched case-sensitively.
  • Fields with unresolved forward references now emit a warning (#901). Settings sources can silently fail to resolve such fields; they now raise IncompleteFieldDefinitionWarning telling you to call model_rebuild(). If you have filterwarnings = error configured, this may surface as a new failure.
  • Non-JSON env values for strict fields now raise ValidationError (#926) instead of a less specific error.

New features

  • Show environment variable names in CLI help via cli_show_env_vars=True (#860), so generated --help output doubles as configuration documentation.
  • PYDANTIC_SETTINGS_DEBUG for debugging settings resolution (#906, #913). Set it to a truthy value with DEBUG logging enabled to see each source's contribution in priority order, which source won for each value, and which env_file/secret files were probed, loaded, or skipped — the long-standing "why isn't my .env being picked up?" question.
  • toml_table_header for regular TOML files (#882, #886, #887), letting you root settings at a nested table in any TOML file, not just pyproject.toml.
  • Traversable support for JSON/TOML/YAML file sources (#902), so you can load config packaged inside a distribution — including files inside a zip or wheel — via importlib.resources.files(...) without casting to Path.
  • GCP: project_id can come from an earlier settings source (#878), rather than only from the constructor or GOOGLE_CLOUD_PROJECT.

Bug fixes

  • Fix env vars not loading on Windows with case_sensitive=True (#894). Windows upper-cases os.environ keys, so fields raised Field required instead of picking up their values.
  • Read secret files as UTF-8 instead of the platform locale encoding (#917). On Windows code pages such as cp1252 this silently corrupted non-ASCII secrets.
  • Fix AliasPath on nested model fields not JSON-decoding env values (#898).
  • Fix case-insensitive matching for optional nested models (#905).
  • Fix dotenv extras being wrongly claimed by a complex field sharing a name prefix (#912) — e.g. dbx_token being swallowed by a db: dict field.
  • Fix nested_model_default_partial_update=True corrupting discriminated unions (#876).
  • Fix Secret subclasses crashing when loaded from the environment (#920).
  • Fix enum names not parsing through nested annotations such as Optional[Annotated[MyEnum, ...]] with env_parse_enums=True (#910).
  • An empty yaml_config_section now falls back to defaults instead of raising AttributeError: 'NoneType' object has no attribute 'keys' (#914).
  • NestedSecretsSettingsSource no longer follows symlinks pointing outside secrets_dir (#889).
  • GCP: skip the list_secrets call when case_sensitive=True (#862), lowering the required IAM permissions to just roles/secretmanager.secretAccessor.
  • AWS: types-boto3[secretsmanager] is no longer required at runtime (#880).

Documentation

  • Document JSON parsing of complex env values, plus a comma-separated-values recipe (#919).
  • Recommend an async settings loading pattern (#908).
  • Clarify behavior when an unprefixed value is present in a dotenv file (#895).
  • Clarify environment variable helper descriptions (#867) and fix assorted typos (#904).

What's Changed

... (truncated)

Commits
  • f725ca1 Prepare release 2.15.0 (#930)
  • 28f35c2 Bump the python-packages group with 4 updates (#929)
  • 9056db0 test: move function-local imports to the top of test modules (#927)
  • f077e3a fix: raise ValidationError for non-JSON env values on strict fields (#926)
  • ae25d70 fix: treat Secret subclasses as non-complex fields (#716) (#920)
  • 798dcea Bump the python-packages group with 4 updates (#924)
  • a190041 Bump the github-actions group with 4 updates (#925)
  • 5d93332 Bump the python-packages group with 4 updates (#921)
  • d2fdeda fix: read secret files as UTF-8 instead of the locale encoding (#917)
  • 2256a4e Bump the python-packages group with 3 updates (#915)
  • Additional commits viewable in compare view

Updates langchain-mcp-adapters from 0.3.0 to 0.3.2

Release notes

Sourced from langchain-mcp-adapters's releases.

langchain-mcp-adapters==0.3.2

What's Changed

New Contributors

Full Changelog: langchain-ai/langchain-mcp-adapters@langchain-mcp-adapters==0.3.1...langchain-mcp-adapters==0.3.2

langchain-mcp-adapters==0.3.1

What's Changed

New Contributors

Full Changelog: langchain-ai/langchain-mcp-adapters@langchain-mcp-adapters==0.3.0...langchain-mcp-adapters==0.3.1

Commits
  • cc0f284 release: 0.3.2 (#604)
  • d4a1caa fix(deps): cap mcp below 2.0.0 to prevent import failures (#590)
  • a060231 build(deps): bump cryptography from 48.0.1 to 50.0.0 (#599)
  • c50072a build(deps): bump cryptography from 48.0.1 to 50.0.0 in /examples/servers/str...
  • e81a81b release: 0.3.1 (#587)
  • d4c6611 feat: add get_server_info to retrieve MCP server metadata (#430)
  • 9735d27 build(deps): bump the minor-and-patch group with 3 updates (#585)
  • 04e2703 build(deps): bump pypa/gh-action-pypi-publish from 1.14.0 to 1.14.1 in the mi...
  • 4f17623 build(deps): bump the minor-and-patch group in /examples/servers/streamable-h...
  • e5c7e5f build(deps-dev): bump types-setuptools from 82.0.0.20260518 to 83.0.0.2026072...
  • Additional commits viewable in compare view

Updates opentelemetry-exporter-otlp from 1.43.0 to 1.45.0

Release notes

Sourced from opentelemetry-exporter-otlp's releases.

Version 1.45.0/0.66b0

Added

  • opentelemetry-exporter-prometheus: add support to configure Resource attributes as metric labels (#5122)
  • infra: add renovate (#5202)
  • opentelemetry-api, opentelemetry-sdk: add support for extended attribute values everywhere. (#5266)
  • opentelemetry-sdk: wire the top-level log_level field in declarative configuration — when set, maps the OTel SeverityNumber value to a Python logging level and applies it to the opentelemetry logger so SDK internal diagnostics respect the configured severity. (#5351)
  • opentelemetry-sdk: add the new stable AlwaysRecordSampler (#5354)
  • opentelemetry-configuration, opentelemetry-sdk: wire top-level attribute_limits into per-signal providers via declarative config; add log_record_limits support to LoggerProvider (#5365)
  • opentelemetry-exporter-otlp-json-http: add OTLP JSON HTTP exporter package (#5374)
  • opentelemetry-api, opentelemetry-sdk: add enabled() support to the Logger API, SDK, and LogRecordProcessor to let instrumentation skip expensive work when logging is disabled (#5380)
  • opentelemetry-exporter-otlp-json-file: add OTLP JSON file Docker tests (#5412)
  • opentelemetry-configuration: wire the experimental tracer_configurator/development, meter_configurator/development and logger_configurator/development fields into create_tracer_provider, create_meter_provider and create_logger_provider, so per-instrumentation-scope enabled overrides declared in the config file are applied to the provider (previously these fields were parsed but silently discarded). The logger minimum_severity/trace_based fields are not supported by the Python SDK and are ignored with a warning. (#5418)
  • docs/examples: add example on how to manually setup the SDK to get SDK metrics (#5449)
  • opentelemetry-docker-tests: add Prometheus exporter docker tests (#5457)
  • opentelemetry-sdk: count records dropped after shutdown on otel.sdk.processor.{span,log}.processed with error.type=already_shutdown (batch span/log and simple log processors), which the semantic conventions define as a valid value for this metric. (#5509)
  • opentelemetry-semantic-conventions: update semantic conventions to v1.44.0 (#5511)
  • opentelemetry-sdk: add host.id to the host resource detector (#5653)
  • opentelemetry-test-utils: add CapturingSampler to record what samplers receive in instrumentation tests (#5681)

Changed

  • Enable PIE (flake8-pie) ruff rule and fix all violations (#5150)
  • The public opentelemetry.util.types.AttributeValue type in package opentelemetry-api is being expanded to include None, heterogeneous sequences of primitive types (and nested sequences) as opposed to only homogeneous primitive sequences, and Mappings of strings to any primitive types or sequences/mappings (which themselves must only contain primitive types or sequences/mappings validated the same way). If a bytes type is set as an attribute value in the SDK, it will no longer be utf-8 decoded to a string, instead it will be passed along as is in accordance with the OTEL spec, since bytes is a valid type in the OTLP proto. (#5266)
  • opentelemetry-exporter-otlp-proto-http: add a max_request_size argument to the OTLP HTTP exporters (traces, logs, metrics); serialized requests larger than the limit are dropped before sending, measured before compression. Defaults to 64 MiB (enabled); set to 0 to disable. Mirrors opentelemetry-go#8157. (#5369)
  • [BREAKING] opentelemetry-api: subclasses of Logger need to implement the enabled method (#5380)
  • opentelemetry-exporter-otlp-proto-http: refactor to use shared opentelemetry-exporter-otlp-common and opentelemetry-exporter-http-transport packages and switch default HTTP backend to urllib3 (#5389)
  • opentelemetry-sdk: unify logging force_flush timeout defaults to 30000ms (#5438)
  • opentelemetry-python: enable Ruff default ruleset and fix auto-fixable lint issues (#5491)
  • opentelemetry-sdk: SimpleSpanProcessor now drops spans ended after shutdown() instead of passing them to the exporter, and counts them on otel.sdk.processor.span.processed with error.type=already_shutdown. (#5512)
  • Bump pytest to 9.0.3 (#5518)
  • opentelemetry-exporter-otlp-proto-http: clarify that the endpoint= kwarg requires the full signal path (#5633)
  • opentelemetry-sdk: fix typos in SpanLimits docstring (#5658)

Fixed

  • opentelemetry-configuration: perform environment variable substitution on scalar values after parsing the configuration file, so ${VAR} references inside comments and mapping keys are no longer substituted and undefined references in comments no longer abort loading (#5407)
  • opentelemetry-configuration: declarative config environment variable substitution now replaces an unset variable that has no default with an empty value instead of raising an error, per the configuration spec. Resource attributes whose value resolves to null (an unset ${VAR} with no default) are skipped with a warning instead of being inserted as a null value. (#5408)
  • 'scripts/build.sh: add opentelemetry-configurationandopentelemetry-proto-json` to the package to release (#5425)
  • opentelemetry-sdk: fix View instrument-name matching so a view configured with an instrument's real (mixed-case) name is applied; matching is now case-insensitive and platform-independent instead of relying on fnmatch's OS-dependent case handling (#5430)
  • opentelemetry-sdk: fix missing f-prefix in exponential histogram error messages (#5434)
  • opentelemetry-configuration: resolve false-positive warning logs for newer schema minor version (#5436)
  • opentelemetry-sdk: make methods on FixedSizeExemplarReservoirABC thread safe (#5437)
  • opentelemetry-propagator-jaeger: fix typing issues and enable pyright typechecking for the package opentelemetry-propagator-jaeger: skip uberctx- baggage headers with an empty value on extraction instead of raising TypeError (#5440)
  • opentelemetry-sdk: fix TypeError when instantiating a _BaseConfigurator subclass whose __init__ takes arguments (#5441)
  • opentelemetry-sdk: fix TypeError in os.fork() when a BatchProcessor or PeriodicExportingMetricReader is garbage collected (#5453)
  • opentelemetry-configuration: a declarative config key present with an empty (null) value on an object-typed node (e.g. always_on:, a - service: detector, or a metric console: exporter) is now treated the same as an explicit empty config (always_on: {}) instead of failing type dispatch or silently skipping the node. Both dict-typed nodes and dataclasses constructible with no arguments are covered. (#5454)
  • opentelemetry-api: fix copy-pasted log message in SpanContext.__delattr__ (#5455)
  • opentelemetry-sdk: reject views with ExponentialBucketHistogramAggregation for asynchronous instruments instead of silently producing no data (#5461)
  • opentelemetry-sdk: fill every bucket of SimpleFixedSizeExemplarReservoir before random sampling (#5462)

... (truncated)

Changelog

Sourced from opentelemetry-exporter-otlp's changelog.

Description has been truncated

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels Sep 25, 2026
@dependabot
dependabot Bot force-pushed the dependabot/uv/a2a/image_service/minor-and-patch-9ebb0ff7b0 branch from 873ed8b to 9fdab64 Compare October 2, 2026 05:13
@mrsabath

mrsabath commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

@dependabot rebase

…3 updates

---
updated-dependencies:
- dependency-name: aiohttp
  dependency-version: 3.14.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: langchain-core
  dependency-version: 1.6.4
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: langchain-mcp-adapters
  dependency-version: 0.3.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: langchain-openai
  dependency-version: 1.6.3
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: langgraph
  dependency-version: 1.2.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: langsmith
  dependency-version: 0.14.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: openinference-instrumentation-langchain
  dependency-version: 0.1.76
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: opentelemetry-exporter-otlp
  dependency-version: 1.44.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: opentelemetry-proto
  dependency-version: 1.44.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: orjson
  dependency-version: 3.12.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: pydantic-settings
  dependency-version: 2.15.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: pyjwt
  dependency-version: 2.14.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: urllib3
  dependency-version: 2.8.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/uv/a2a/image_service/minor-and-patch-9ebb0ff7b0 branch from 9fdab64 to 1271d57 Compare October 2, 2026 20:56
@mrsabath

mrsabath commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

@dependabot rebase

@mrsabath mrsabath left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Re-tested after the Dependabot rebase — the rebase changed content: openai is now 3.24.0 (not the 3.23.0 originally reviewed) and pyproject.toml is now in scope.

Re-verified against the rebased head: uv lock --check (112 packages), uv sync --locked, and imports of langchain-openai / a2a / openai (confirmed 3.24.0). image_service has no raw openai SDK import, so the 3.x major is mediated entirely through langchain-openai.

@mrsabath
mrsabath merged commit d9677dd into main Oct 2, 2026
10 of 11 checks passed
@dependabot
dependabot Bot deleted the dependabot/uv/a2a/image_service/minor-and-patch-9ebb0ff7b0 branch October 2, 2026 20:59
@dependabot @github

dependabot Bot commented on behalf of github Oct 2, 2026

Copy link
Copy Markdown
Contributor Author

Oh no! Something went wrong on our end. Please try again later.

If the problem persists, please contact GitHub support for assistance 🙇

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

2 participants