Repository navigation
Conversation
Bumps [pyjwt](https://github.com/jpadilla/pyjwt) from 2.12.1 to 2.13.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/jpadilla/pyjwt/releases">pyjwt's releases</a>.</em></p> <blockquote> <h2>2.13.0</h2> <h1>PyJWT 2.13.0 — Security Release</h1> <p>This release bundles five security fixes plus three additional hardening / spec-compliance changes. We recommend all users upgrade.</p> <h2>Security</h2> <ul> <li> <p><strong><a href="https://github.com/jpadilla/pyjwt/security/advisories/GHSA-xgmm-8j9v-c9wx"><code>GHSA-xgmm-8j9v-c9wx</code></a> — JWK JSON accepted as HMAC secret (algorithm confusion).</strong> <code>HMACAlgorithm.prepare_key</code> previously rejected PEM- and SSH-formatted asymmetric keys but did not catch a JWK passed as a raw JSON string. In a verifier configured with both symmetric and asymmetric algorithms in <code>algorithms=[…]</code> and a raw-JSON JWK as the key, an attacker could forge HS256 tokens using the JWK text as the HMAC secret. The guard has been extended to reject any JWK-shaped JSON. <em>Reported by <a href="https://github.com/aradona91"><code>@aradona91</code></a>.</em></p> </li> <li> <p><strong><a href="https://github.com/jpadilla/pyjwt/security/advisories/GHSA-jq35-7prp-9v3f"><code>GHSA-jq35-7prp-9v3f</code></a> — Algorithm allow-list bypass with <code>PyJWK</code> / <code>PyJWKClient</code>.</strong> When verifying with a <code>PyJWK</code>, the caller's <code>algorithms=[…]</code> allow-list was checked against the token header <code>alg</code> as a string only; actual verification used the algorithm bound to the <code>PyJWK</code>. An attacker who controlled a registered JWKS key could sign with one algorithm and advertise another on the header. PyJWT now requires the token header <code>alg</code> to match the <code>PyJWK</code>'s algorithm before verification. <em>Reported by <a href="https://github.com/sushi-gif"><code>@sushi-gif</code></a>.</em></p> </li> <li> <p><strong><a href="https://github.com/jpadilla/pyjwt/security/advisories/GHSA-w7vc-732c-9m39"><code>GHSA-w7vc-732c-9m39</code></a> — DoS via base64 decode of unused payload segment when <code>b64=false</code>.</strong> For detached-payload JWS (<code>b64=false</code>), the compact-form payload segment was base64-decoded before being discarded in favor of the caller-supplied <code>detached_payload</code>. An attacker could inflate the unused segment to force CPU + memory cost without holding a valid signature. The segment is now required to be empty per RFC 7515 Appendix F, and is no longer decoded. <em>Reported by <a href="https://github.com/thesmartshadow"><code>@thesmartshadow</code></a>.</em></p> </li> <li> <p><strong><a href="https://github.com/jpadilla/pyjwt/security/advisories/GHSA-993g-76c3-p5m4"><code>GHSA-993g-76c3-p5m4</code></a> — <code>PyJWKClient</code> accepts non-HTTP(S) URIs.</strong> <code>PyJWKClient.fetch_data</code> passed its URI to <code>urllib.request.urlopen</code>, which by default also handles <code>file://</code>, <code>ftp://</code>, and <code>data:</code> schemes. An application that fed an attacker-influenced URI into <code>PyJWKClient</code> could be coerced into reading local files or reaching other unintended schemes. <code>PyJWKClient</code> now rejects any URI whose scheme isn't <code>http</code> or <code>https</code>. <em>Reported by <a href="https://github.com/KEIJOT"><code>@KEIJOT</code></a>.</em></p> </li> <li> <p><strong><a href="https://github.com/jpadilla/pyjwt/security/advisories/GHSA-fhv5-28vv-h8m8"><code>GHSA-fhv5-28vv-h8m8</code></a> — <code>PyJWKClient</code> cache wiped on fetch error.</strong> A <code>finally</code>-block <code>put(jwk_set=None)</code> cleared the JWK Set cache whenever a fetch raised, turning a transient JWKS-endpoint outage into application-wide auth failure. The cache write was moved into the success path; transient errors no longer evict valid cached keys. <em>Reported by <a href="https://github.com/eddieran"><code>@eddieran</code></a>.</em></p> </li> </ul> <h2>Fixed</h2> <ul> <li>Reject empty HMAC keys outright in <code>HMACAlgorithm.prepare_key</code> with <code>InvalidKeyError</code> instead of accepting them with only a warning. Defends against the <code>os.getenv("JWT_SECRET", "")</code> footgun. <em>Thanks to <a href="https://github.com/SnailSploit"><code>@SnailSploit</code></a> and <a href="https://github.com/spartan8806"><code>@spartan8806</code></a> for the reports.</em></li> <li>Forward per-call <code>options</code> (including <code>enforce_minimum_key_length</code>) from <code>PyJWT.decode</code> through to <code>PyJWS._verify_signature</code>. The option was previously silently dropped between the two layers, so it only took effect when set on the <code>PyJWT</code> instance. <em>Thanks to <a href="https://github.com/WLUB"><code>@WLUB</code></a> for the report.</em></li> <li><strong>RFC 7797 §3 compliance for <code>b64=false</code>:</strong> the encoder now auto-adds <code>"b64"</code> to <code>crit</code>, and the decoder rejects tokens that set <code>b64=false</code> without listing it in <code>crit</code>. <em>Thanks to <a href="https://github.com/MachineLearning-Nerd"><code>@MachineLearning-Nerd</code></a> for the report.</em></li> </ul> <h2>Changed</h2> <ul> <li>Migrate the <code>dev</code>, <code>docs</code>, and <code>tests</code> package extras to dependency groups, by <a href="https://github.com/kurtmckee"><code>@kurtmckee</code></a> in <a href="https://redirect.github.com/jpadilla/pyjwt/pull/1152">#1152</a>.</li> </ul> <h2>Upgrade notes</h2> <p>Most fixes are invisible to correctly-configured callers. A few behavioral changes you may encounter:</p> <ul> <li><strong>Empty HMAC keys now raise.</strong> If your app passed <code>""</code> or <code>b""</code> as a secret (often via a missing env var, e.g. <code>os.getenv("JWT_SECRET", "")</code>), <code>encode</code>/<code>decode</code> will now raise <code>InvalidKeyError</code>. This is the intended behavior — fix the configuration.</li> <li><strong><code>PyJWK</code> decoding now requires the token's <code>alg</code> to match the JWK's algorithm.</strong> Previously a mismatch was silently honored if the header <code>alg</code> appeared in the allow-list. Tokens that relied on this mismatch will now fail with <code>InvalidAlgorithmError</code>.</li> <li><strong><code>PyJWKClient</code> now rejects non-HTTP(S) URIs at construction time.</strong> Tests or dev environments that fetched JWKS from <code>file://</code> URIs need to switch to a local HTTP server or load the JWKS by other means (e.g. construct <code>PyJWKSet.from_dict(...)</code> directly).</li> <li><strong><code>b64=false</code> tokens are now strictly RFC 7515 / 7797 compliant.</strong> Tokens with a non-empty compact-form payload segment, or that omit <code>"b64"</code> from <code>crit</code>, will be rejected. PyJWT-produced tokens always satisfy both invariants, so round-trips through PyJWT are unaffected.</li> <li><strong><code>enforce_minimum_key_length</code> set per-call now takes effect.</strong> Callers who passed <code>options={"enforce_minimum_key_length": True}</code> to <code>jwt.decode()</code> previously got no enforcement; they will now get <code>InvalidKeyError</code> on undersized keys, as documented.</li> </ul> <p><strong>Full changelog:</strong> <a href="https://github.com/jpadilla/pyjwt/compare/2.12.1...2.13.0">https://github.com/jpadilla/pyjwt/compare/2.12.1...2.13.0</a></p> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/jpadilla/pyjwt/blob/master/CHANGELOG.rst">pyjwt's changelog</a>.</em></p> <blockquote> <h2><code>v2.13.0 <https://github.com/jpadilla/pyjwt/compare/2.12.1...2.13.0></code>__</h2> <p>Security</p> <pre><code> - Reject JWK JSON documents passed as raw HMAC secrets in ``HMACAlgorithm.prepare_key`` to close an algorithm-confusion gap that the existing PEM/SSH guard did not cover. Reported by @aradona91 in `GHSA-xgmm-8j9v-c9wx <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-xgmm-8j9v-c9wx>`__. - Bind the JWT header ``alg`` to ``PyJWK.algorithm_name`` during verification so the caller's ``algorithms=[...]`` allow-list cannot be bypassed when decoding with a ``PyJWK`` / ``PyJWKClient`` key. Reported by @sushi-gif in `GHSA-jq35-7prp-9v3f <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-jq35-7prp-9v3f>`__. - Reject non-``http(s)`` URI schemes in ``PyJWKClient`` so attacker- influenced URIs cannot read local files or reach unintended schemes via urllib's default ``file://`` / ``ftp://`` / ``data:`` handlers. Reported by @KEIJOT in `GHSA-993g-76c3-p5m4 <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-993g-76c3-p5m4>`__. - Preserve the cached JWK Set on fetch errors in ``PyJWKClient.fetch_data``. The previous ``finally``-block ``put(None)`` pattern cleared the cache on any transient outage, turning one bad JWKS request into application- wide auth failure. Reported by @eddieran in `GHSA-fhv5-28vv-h8m8 <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-fhv5-28vv-h8m8>`__. - Skip the unconditional base64 decode of the compact-form payload segment when ``b64=false`` is set in the protected header, and require that segment to be empty (RFC 7515 Appendix F detached form). Closes an unauthenticated DoS amplifier. Reported by @thesmartshadow in `GHSA-w7vc-732c-9m39 <https://github.com/jpadilla/pyjwt/security/advisories/GHSA-w7vc-732c-9m39>`__. <p>Fixed</p> <pre><code> - Reject empty HMAC keys outright in ``HMACAlgorithm.prepare_key`` with ``InvalidKeyError`` instead of accepting them with only a warning. Thanks to @SnailSploit and @spartan8806 for independently flagging the footgun. - Forward per-call ``options`` (including ``enforce_minimum_key_length``) from ``PyJWT.decode`` through to ``PyJWS._verify_signature`` so the option actually takes effect when set at the call site rather than only on the ``PyJWT`` instance. Thanks to @WLUB for the report. - RFC 7797 §3 compliance for ``b64=false``: the encoder now auto-adds ``&quot;b64&quot;`` to the ``crit`` header parameter, and the decoder rejects tokens that set ``b64=false`` without listing it in ``crit``. Thanks to @MachineLearning-Nerd for the report. Changed </code></pre> <ul> <li>Migrate the <code>dev</code>, <code>docs</code>, and <code>tests</code> package extras to dependency groups by <a href="https://github.com/kurtmckee"><code>@kurtmckee</code></a> in <code>[#1152](jpadilla/pyjwt#1152) &lt;https://github.com/jpadilla/pyjwt/pull/1152&gt;</code>__ </code></pre></li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/jpadilla/pyjwt/commit/7144e4534c34810f4525dc4578a32addd8212cff"><code>7144e45</code></a> Apply ruff format</li> <li><a href="https://github.com/jpadilla/pyjwt/commit/d2f4bec4963897c0ef96ef64a875894f2c8542ab"><code>d2f4bec</code></a> Restore <code>cast()</code> calls with cross-version <code>type: ignore</code> for <code>prepare_key</code></li> <li><a href="https://github.com/jpadilla/pyjwt/commit/22f478cebddd8294259c30f037ecb92b0b348774"><code>22f478c</code></a> Remove redundant casts in <code>RSAAlgorithm.prepare_key</code> and `ECAlgorithm.prepare...</li> <li><a href="https://github.com/jpadilla/pyjwt/commit/95791b1759b8aa4f2203575d344d5c78564cdc81"><code>95791b1</code></a> Bundle security fixes and hardening into 2.13.0</li> <li><a href="https://github.com/jpadilla/pyjwt/commit/dcc27a9d3182a2349c30b160758785c6ce7a6508"><code>dcc27a9</code></a> [pre-commit.ci] pre-commit autoupdate (<a href="https://redirect.github.com/jpadilla/pyjwt/issues/1155">#1155</a>)</li> <li><a href="https://github.com/jpadilla/pyjwt/commit/9d08a9a1896845ed8eaf88e6f6ac61e5800c3e7a"><code>9d08a9a</code></a> [pre-commit.ci] pre-commit autoupdate (<a href="https://redirect.github.com/jpadilla/pyjwt/issues/1146">#1146</a>)</li> <li><a href="https://github.com/jpadilla/pyjwt/commit/b87c10014d4109f0214fea188d00faaaf8a80e64"><code>b87c100</code></a> Bump codecov/codecov-action from 5 to 6 (<a href="https://redirect.github.com/jpadilla/pyjwt/issues/1154">#1154</a>)</li> <li><a href="https://github.com/jpadilla/pyjwt/commit/40e3147eb5f790d8d041772e5fc00728a176c812"><code>40e3147</code></a> Migrate development extras to dependency groups (<a href="https://redirect.github.com/jpadilla/pyjwt/issues/1152">#1152</a>)</li> <li>See full diff in <a href="https://github.com/jpadilla/pyjwt/compare/2.12.1...2.13.0">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/microsoft/RAMPART/network/alerts). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [starlette](https://github.com/Kludex/starlette) from 1.0.1 to 1.3.1. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/Kludex/starlette/releases">starlette's releases</a>.</em></p> <blockquote> <h2>Version 1.3.1</h2> <h2>What's Changed</h2> <ul> <li>Use <code>StarletteDeprecationWarning</code> instead of <code>DeprecationWarning</code> by <a href="https://github.com/Kludex"><code>@Kludex</code></a> in <a href="https://redirect.github.com/Kludex/starlette/pull/3119">Kludex/starlette#3119</a></li> <li>Enforce <code>max_fields</code> and <code>max_part_size</code> in <code>FormParser</code> by <a href="https://github.com/Kludex"><code>@Kludex</code></a> in <a href="https://redirect.github.com/Kludex/starlette/pull/3329">Kludex/starlette#3329</a></li> <li>Enforce <code>FormParser</code> limits in parser callbacks by <a href="https://github.com/Kludex"><code>@Kludex</code></a> in <a href="https://redirect.github.com/Kludex/starlette/pull/3331">Kludex/starlette#3331</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/Kludex/starlette/compare/1.3.0...1.3.1">https://github.com/Kludex/starlette/compare/1.3.0...1.3.1</a></p> <h2>Version 1.3.0</h2> <h2>What's Changed</h2> <ul> <li>Clamp oversized suffix ranges in <code>FileResponse</code> by <a href="https://github.com/jiyujie2006"><code>@jiyujie2006</code></a> in <a href="https://redirect.github.com/Kludex/starlette/pull/3307">Kludex/starlette#3307</a></li> <li>Catch <code>OSError</code> alongside <code>MultiPartException</code> when closing temp files by <a href="https://github.com/N3XT3R1337"><code>@N3XT3R1337</code></a> in <a href="https://redirect.github.com/Kludex/starlette/pull/3191">Kludex/starlette#3191</a></li> <li>Add <code>httpx2</code> to the <code>full</code> extra by <a href="https://github.com/Kludex"><code>@Kludex</code></a> in <a href="https://redirect.github.com/Kludex/starlette/pull/3323">Kludex/starlette#3323</a></li> <li>Adjust testclient typing and warnings by <a href="https://github.com/waketzheng"><code>@waketzheng</code></a> in <a href="https://redirect.github.com/Kludex/starlette/pull/3322">Kludex/starlette#3322</a></li> <li>Fix IndexError in URL.replace() on a URL with no authority by <a href="https://github.com/LeSingh1"><code>@LeSingh1</code></a> in <a href="https://redirect.github.com/Kludex/starlette/pull/3317">Kludex/starlette#3317</a></li> <li>Annotate URLPath protocol parameter with Literal by <a href="https://github.com/Chang-LeHung"><code>@Chang-LeHung</code></a> in <a href="https://redirect.github.com/Kludex/starlette/pull/3285">Kludex/starlette#3285</a></li> <li>avoid collapsing exception groups from user code by <a href="https://github.com/graingert"><code>@graingert</code></a> in <a href="https://redirect.github.com/Kludex/starlette/pull/2830">Kludex/starlette#2830</a></li> <li>Use <code>removeprefix</code> to strip weak ETag indicator in <code>is_not_modified</code> by <a href="https://github.com/gnosyslambda"><code>@gnosyslambda</code></a> in <a href="https://redirect.github.com/Kludex/starlette/pull/3193">Kludex/starlette#3193</a></li> <li>Build <code>request.url</code> from structured components by <a href="https://github.com/Kludex"><code>@Kludex</code></a> in <a href="https://redirect.github.com/Kludex/starlette/pull/3326">Kludex/starlette#3326</a></li> </ul> <h2>New Contributors</h2> <ul> <li><a href="https://github.com/jiyujie2006"><code>@jiyujie2006</code></a> made their first contribution in <a href="https://redirect.github.com/Kludex/starlette/pull/3307">Kludex/starlette#3307</a></li> <li><a href="https://github.com/N3XT3R1337"><code>@N3XT3R1337</code></a> made their first contribution in <a href="https://redirect.github.com/Kludex/starlette/pull/3191">Kludex/starlette#3191</a></li> <li><a href="https://github.com/leestana01"><code>@leestana01</code></a> made their first contribution in <a href="https://redirect.github.com/Kludex/starlette/pull/3319">Kludex/starlette#3319</a></li> <li><a href="https://github.com/LeSingh1"><code>@LeSingh1</code></a> made their first contribution in <a href="https://redirect.github.com/Kludex/starlette/pull/3317">Kludex/starlette#3317</a></li> <li><a href="https://github.com/EmmanuelNiyonshuti"><code>@EmmanuelNiyonshuti</code></a> made their first contribution in <a href="https://redirect.github.com/Kludex/starlette/pull/3204">Kludex/starlette#3204</a></li> <li><a href="https://github.com/Chang-LeHung"><code>@Chang-LeHung</code></a> made their first contribution in <a href="https://redirect.github.com/Kludex/starlette/pull/3285">Kludex/starlette#3285</a></li> <li><a href="https://github.com/gnosyslambda"><code>@gnosyslambda</code></a> made their first contribution in <a href="https://redirect.github.com/Kludex/starlette/pull/3193">Kludex/starlette#3193</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/Kludex/starlette/compare/1.2.1...1.3.0">https://github.com/Kludex/starlette/compare/1.2.1...1.3.0</a></p> <h2>Version 1.2.1</h2> <h2>What's Changed</h2> <ul> <li>Use <code>httpx2</code> for type checking in the <code>testclient</code> module by <a href="https://github.com/leifwar"><code>@leifwar</code></a> in <a href="https://redirect.github.com/Kludex/starlette/pull/3304">Kludex/starlette#3304</a></li> <li>Add assert error for requires() when request param is not Request type by <a href="https://github.com/KeeganOP"><code>@KeeganOP</code></a> in <a href="https://redirect.github.com/Kludex/starlette/pull/3298">Kludex/starlette#3298</a></li> </ul> <h2>New Contributors</h2> <ul> <li><a href="https://github.com/leifwar"><code>@leifwar</code></a> made their first contribution in <a href="https://redirect.github.com/Kludex/starlette/pull/3304">Kludex/starlette#3304</a></li> <li><a href="https://github.com/diskeu"><code>@diskeu</code></a> made their first contribution in <a href="https://redirect.github.com/Kludex/starlette/pull/3243">Kludex/starlette#3243</a></li> <li><a href="https://github.com/KeeganOP"><code>@KeeganOP</code></a> made their first contribution in <a href="https://redirect.github.com/Kludex/starlette/pull/3298">Kludex/starlette#3298</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/Kludex/starlette/compare/1.2.0...1.2.1">https://github.com/Kludex/starlette/compare/1.2.0...1.2.1</a></p> <h2>Version 1.2.0</h2> <h2>What's Changed</h2> <ul> <li>Support httpx2 in the test client by <a href="https://github.com/Kludex"><code>@Kludex</code></a> in <a href="https://redirect.github.com/Kludex/starlette/pull/3291">Kludex/starlette#3291</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/Kludex/starlette/compare/1.1.0...1.2.0">https://github.com/Kludex/starlette/compare/1.1.0...1.2.0</a></p> <h2>Version 1.1.0</h2> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/Kludex/starlette/blob/main/docs/release-notes.md">starlette's changelog</a>.</em></p> <blockquote> <h2>1.3.1 (June 12, 2026)</h2> <h4>Fixed</h4> <ul> <li>Enforce <code>max_fields</code> and <code>max_part_size</code> in <code>FormParser</code> <a href="https://redirect.github.com/encode/starlette/pull/3329">#3329</a>.</li> <li>Enforce <code>FormParser</code> limits in parser callbacks <a href="https://redirect.github.com/encode/starlette/pull/3331">#3331</a>.</li> </ul> <h2>1.3.0 (June 11, 2026)</h2> <h4>Added</h4> <ul> <li>Add <code>httpx2</code> to the <code>full</code> extra <a href="https://redirect.github.com/encode/starlette/pull/3323">#3323</a>.</li> <li>Annotate the <code>URLPath</code> <code>protocol</code> parameter with <code>Literal</code> <a href="https://redirect.github.com/encode/starlette/pull/3285">#3285</a>.</li> </ul> <h4>Fixed</h4> <ul> <li>Build <code>request.url</code> from structured components <a href="https://redirect.github.com/encode/starlette/pull/3326">#3326</a>.</li> <li>Clamp oversized suffix ranges in <code>FileResponse</code> <a href="https://redirect.github.com/encode/starlette/pull/3307">#3307</a>.</li> <li>Catch <code>OSError</code> alongside <code>MultiPartException</code> when closing temp files <a href="https://redirect.github.com/encode/starlette/pull/3191">#3191</a>.</li> <li>Avoid collapsing exception groups raised from user code <a href="https://redirect.github.com/encode/starlette/pull/2830">#2830</a>.</li> <li>Use <code>removeprefix</code> to strip the weak <code>ETag</code> indicator in <code>is_not_modified</code> <a href="https://redirect.github.com/encode/starlette/pull/3193">#3193</a>.</li> <li>Fix <code>IndexError</code> in <code>URL.replace()</code> on a URL with no authority <a href="https://redirect.github.com/encode/starlette/pull/3317">#3317</a>.</li> <li>Adjust <code>testclient</code> typing and warnings <a href="https://redirect.github.com/encode/starlette/pull/3322">#3322</a>.</li> </ul> <h2>1.2.1 (May 31, 2026)</h2> <h4>Fixed</h4> <ul> <li>Use <code>httpx2</code> for type checking in the <code>testclient</code> module <a href="https://redirect.github.com/encode/starlette/pull/3304">#3304</a>.</li> <li>Add assert error for <code>requires()</code> when the request parameter is not a <code>Request</code> type <a href="https://redirect.github.com/encode/starlette/pull/3298">#3298</a>.</li> </ul> <h2>1.2.0 (May 28, 2026)</h2> <h4>Added</h4> <ul> <li>Support httpx2 in the test client <a href="https://redirect.github.com/encode/starlette/pull/3291">#3291</a>.</li> </ul> <h2>1.1.0 (May 23, 2026)</h2> <h4>Added</h4> <ul> <li>Use <code>"application/octet-stream"</code> as the <code>FileResponse</code> media type fallback <a href="https://redirect.github.com/encode/starlette/pull/3283">#3283</a>.</li> </ul> <h4>Fixed</h4> <ul> <li>Only dispatch standard HTTP verbs in <code>HTTPEndpoint</code> <a href="https://redirect.github.com/encode/starlette/pull/3286">#3286</a>.</li> <li>Reject absolute paths in <code>StaticFiles.lookup_path</code> <a href="https://redirect.github.com/encode/starlette/pull/3287">#3287</a>.</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/Kludex/starlette/commit/8ebffd0678570ddd5d5bb11c6f3c3c7fd4682ab9"><code>8ebffd0</code></a> Version 1.3.1 (<a href="https://redirect.github.com/Kludex/starlette/issues/3330">#3330</a>)</li> <li><a href="https://github.com/Kludex/starlette/commit/25b8e179d8d7ed86769c02f648772dd5fb43dc3c"><code>25b8e17</code></a> Enforce <code>FormParser</code> limits in parser callbacks (<a href="https://redirect.github.com/Kludex/starlette/issues/3331">#3331</a>)</li> <li><a href="https://github.com/Kludex/starlette/commit/dba1c4babc4f99ad2622bb913d87045775dda735"><code>dba1c4b</code></a> Enforce <code>max_fields</code> and <code>max_part_size</code> in <code>FormParser</code> (<a href="https://redirect.github.com/Kludex/starlette/issues/3329">#3329</a>)</li> <li><a href="https://github.com/Kludex/starlette/commit/45e51dcf99f3a270b0bcec1aec5410b4345863a9"><code>45e51dc</code></a> Use <code>StarletteDeprecationWarning</code> instead of <code>DeprecationWarning</code> (<a href="https://redirect.github.com/Kludex/starlette/issues/3119">#3119</a>)</li> <li><a href="https://github.com/Kludex/starlette/commit/5f8610c386e13de1d80d36efa961e1486a1d2d01"><code>5f8610c</code></a> Version 1.3.0 (<a href="https://redirect.github.com/Kludex/starlette/issues/3327">#3327</a>)</li> <li><a href="https://github.com/Kludex/starlette/commit/167b5850e809f38b27fbfed62d58bf6442855975"><code>167b585</code></a> Build <code>request.url</code> from structured components (<a href="https://redirect.github.com/Kludex/starlette/issues/3326">#3326</a>)</li> <li><a href="https://github.com/Kludex/starlette/commit/37309255b4c1b9c381a2d24a1eaf83100984a16a"><code>3730925</code></a> Use <code>removeprefix</code> to strip weak ETag indicator in <code>is_not_modified</code> (<a href="https://redirect.github.com/Kludex/starlette/issues/3193">#3193</a>)</li> <li><a href="https://github.com/Kludex/starlette/commit/e6f7ad1ab85efb27ab7910d8007b3f4531f7b083"><code>e6f7ad1</code></a> avoid collapsing exception groups from user code (<a href="https://redirect.github.com/Kludex/starlette/issues/2830">#2830</a>)</li> <li><a href="https://github.com/Kludex/starlette/commit/115228fcdca0e0ef5bf4a95a40ddce5a9fced428"><code>115228f</code></a> Annotate URLPath protocol parameter with Literal (<a href="https://redirect.github.com/Kludex/starlette/issues/3285">#3285</a>)</li> <li><a href="https://github.com/Kludex/starlette/commit/113f193a34353c9153857028c1074351d22fad07"><code>113f193</code></a> docs: replace inline ASGI server list with link to canonical implemen… (<a href="https://redirect.github.com/Kludex/starlette/issues/3204">#3204</a>)</li> <li>Additional commits viewable in <a href="https://github.com/Kludex/starlette/compare/1.0.1...1.3.1">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/microsoft/RAMPART/network/alerts). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [cryptography](https://github.com/pyca/cryptography) from 48.0.0 to 48.0.1. <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst">cryptography's changelog</a>.</em></p> <blockquote> <p>48.0.1 - 2026-06-09</p> <pre><code> * Updated Windows, macOS, and Linux wheels to be compiled with OpenSSL 4.0.1. <p>.. _v48-0-0:<br /> </code></pre></p> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/pyca/cryptography/commit/de987ce48ccfeb1abca41efa23b2bf73ec704f74"><code>de987ce</code></a> 48.0.1 version bump and changelog (<a href="https://redirect.github.com/pyca/cryptography/issues/14996">#14996</a>)</li> <li>See full diff in <a href="https://github.com/pyca/cryptography/compare/48.0.0...48.0.1">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/microsoft/RAMPART/network/alerts). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [pypdf](https://github.com/py-pdf/pypdf) from 6.12.0 to 6.13.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/py-pdf/pypdf/releases">pypdf's releases</a>.</em></p> <blockquote> <h2>Version 6.13.0, 2026-06-05</h2> <h2>What's new</h2> <h3>Security (SEC)</h3> <ul> <li>Avoid infinite loops for outlines and text extraction (<a href="https://redirect.github.com/py-pdf/pypdf/issues/3830">#3830</a>) by <a href="https://github.com/stefan6419846"><code>@stefan6419846</code></a></li> </ul> <h3>New Features (ENH)</h3> <ul> <li>Add Japanese predefined CMaps (<a href="https://redirect.github.com/py-pdf/pypdf/issues/3800">#3800</a>) by <a href="https://github.com/yasuhiroiwaki"><code>@yasuhiroiwaki</code></a></li> <li>Font: Collect all character widths, not only those that can be unicode mapped (<a href="https://redirect.github.com/py-pdf/pypdf/issues/3798">#3798</a>) by <a href="https://github.com/PJBrs"><code>@PJBrs</code></a></li> </ul> <h3>Robustness (ROB)</h3> <ul> <li>Recover a corrupt trailing startxref pointer (closes <a href="https://redirect.github.com/py-pdf/pypdf/issues/3238">#3238</a>) (<a href="https://redirect.github.com/py-pdf/pypdf/issues/3826">#3826</a>) by <a href="https://github.com/gaoflow"><code>@gaoflow</code></a></li> <li>Handle /Pages node without /Kids during flattening (<a href="https://redirect.github.com/py-pdf/pypdf/issues/3825">#3825</a>) by <a href="https://github.com/gaoflow"><code>@gaoflow</code></a></li> <li>Accept inline image EI marker at the end of a content stream (<a href="https://redirect.github.com/py-pdf/pypdf/issues/3827">#3827</a>) by <a href="https://github.com/gaoflow"><code>@gaoflow</code></a></li> </ul> <h3>Maintenance (MAINT)</h3> <ul> <li>Type the always-raising deprecation helpers as <code>NoReturn</code> (<a href="https://redirect.github.com/py-pdf/pypdf/issues/3819">#3819</a>) by <a href="https://github.com/estelledc"><code>@estelledc</code></a></li> </ul> <p><a href="https://github.com/py-pdf/pypdf/compare/6.12.2...6.13.0">Full Changelog</a></p> <h2>Version 6.12.2, 2026-05-26</h2> <h2>What's new</h2> <h3>Security (SEC)</h3> <ul> <li>Optimize _decode_png_prediction regarding memory and speed (<a href="https://redirect.github.com/py-pdf/pypdf/issues/3806">#3806</a>) by <a href="https://github.com/stefan6419846"><code>@stefan6419846</code></a></li> <li>Improve loop control in text extraction (<a href="https://redirect.github.com/py-pdf/pypdf/issues/3805">#3805</a>) by <a href="https://github.com/stefan6419846"><code>@stefan6419846</code></a></li> </ul> <p><a href="https://github.com/py-pdf/pypdf/compare/6.12.1...6.12.2">Full Changelog</a></p> <h2>Version 6.12.1, 2026-05-22</h2> <h2>What's new</h2> <h3>Security (SEC)</h3> <ul> <li>Limit input size and element count for XMP metadata (<a href="https://redirect.github.com/py-pdf/pypdf/issues/3796">#3796</a>) by <a href="https://github.com/stefan6419846"><code>@stefan6419846</code></a></li> </ul> <h3>Robustness (ROB)</h3> <ul> <li>Prevent cyclic parent hierarchies for inherited dictionaries (<a href="https://redirect.github.com/py-pdf/pypdf/issues/3795">#3795</a>) by <a href="https://github.com/stefan6419846"><code>@stefan6419846</code></a></li> <li>Deal with invalid first code in LZW decoder (<a href="https://redirect.github.com/py-pdf/pypdf/issues/3794">#3794</a>) by <a href="https://github.com/stefan6419846"><code>@stefan6419846</code></a></li> </ul> <p><a href="https://github.com/py-pdf/pypdf/compare/6.12.0...6.12.1">Full Changelog</a></p> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/py-pdf/pypdf/blob/main/CHANGELOG.md">pypdf's changelog</a>.</em></p> <blockquote> <h2>Version 6.13.0, 2026-06-05</h2> <h3>Security (SEC)</h3> <ul> <li>Avoid infinite loops for outlines and text extraction (<a href="https://redirect.github.com/py-pdf/pypdf/issues/3830">#3830</a>)</li> </ul> <h3>New Features (ENH)</h3> <ul> <li>Add Japanese predefined CMaps (<a href="https://redirect.github.com/py-pdf/pypdf/issues/3800">#3800</a>)</li> <li>Font: Collect all character widths, not only those that can be unicode mapped (<a href="https://redirect.github.com/py-pdf/pypdf/issues/3798">#3798</a>)</li> </ul> <h3>Robustness (ROB)</h3> <ul> <li>Recover a corrupt trailing startxref pointer (closes <a href="https://redirect.github.com/py-pdf/pypdf/issues/3238">#3238</a>) (<a href="https://redirect.github.com/py-pdf/pypdf/issues/3826">#3826</a>)</li> <li>Handle /Pages node without /Kids during flattening (<a href="https://redirect.github.com/py-pdf/pypdf/issues/3825">#3825</a>)</li> <li>Accept inline image EI marker at the end of a content stream (<a href="https://redirect.github.com/py-pdf/pypdf/issues/3827">#3827</a>)</li> </ul> <h3>Maintenance (MAINT)</h3> <ul> <li>Type the always-raising deprecation helpers as <code>NoReturn</code> (<a href="https://redirect.github.com/py-pdf/pypdf/issues/3819">#3819</a>)</li> </ul> <p><a href="https://github.com/py-pdf/pypdf/compare/6.12.2...6.13.0">Full Changelog</a></p> <h2>Version 6.12.2, 2026-05-26</h2> <h3>Security (SEC)</h3> <ul> <li>Optimize _decode_png_prediction regarding memory and speed (<a href="https://redirect.github.com/py-pdf/pypdf/issues/3806">#3806</a>)</li> <li>Improve loop control in text extraction (<a href="https://redirect.github.com/py-pdf/pypdf/issues/3805">#3805</a>)</li> </ul> <p><a href="https://github.com/py-pdf/pypdf/compare/6.12.1...6.12.2">Full Changelog</a></p> <h2>Version 6.12.1, 2026-05-22</h2> <h3>Security (SEC)</h3> <ul> <li>Limit input size and element count for XMP metadata (<a href="https://redirect.github.com/py-pdf/pypdf/issues/3796">#3796</a>)</li> </ul> <h3>Robustness (ROB)</h3> <ul> <li>Prevent cyclic parent hierarchies for inherited dictionaries (<a href="https://redirect.github.com/py-pdf/pypdf/issues/3795">#3795</a>)</li> <li>Deal with invalid first code in LZW decoder (<a href="https://redirect.github.com/py-pdf/pypdf/issues/3794">#3794</a>)</li> </ul> <p><a href="https://github.com/py-pdf/pypdf/compare/6.12.0...6.12.1">Full Changelog</a></p> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/py-pdf/pypdf/commit/98afb457f1ab423c6f07975ccc418cbabc40665d"><code>98afb45</code></a> REL: 6.13.0</li> <li><a href="https://github.com/py-pdf/pypdf/commit/68822ded066f1bd21113b177e039f7930d57b6ff"><code>68822de</code></a> SEC: Avoid infinite loops for outlines and text extraction (<a href="https://redirect.github.com/py-pdf/pypdf/issues/3830">#3830</a>)</li> <li><a href="https://github.com/py-pdf/pypdf/commit/ddd34856173be64950759c0b8c19723fedd69b95"><code>ddd3485</code></a> ROB: Recover a corrupt trailing startxref pointer (closes <a href="https://redirect.github.com/py-pdf/pypdf/issues/3238">#3238</a>) (<a href="https://redirect.github.com/py-pdf/pypdf/issues/3826">#3826</a>)</li> <li><a href="https://github.com/py-pdf/pypdf/commit/5cebe5ed13da5df593dc4171b236e5adc5e201df"><code>5cebe5e</code></a> ROB: Handle /Pages node without /Kids during flattening (<a href="https://redirect.github.com/py-pdf/pypdf/issues/3825">#3825</a>)</li> <li><a href="https://github.com/py-pdf/pypdf/commit/be173fe0d4d403ee9b09b580ef3269e5805c8d5f"><code>be173fe</code></a> ROB: Accept inline image EI marker at the end of a content stream (<a href="https://redirect.github.com/py-pdf/pypdf/issues/3827">#3827</a>)</li> <li><a href="https://github.com/py-pdf/pypdf/commit/e0d443c552bc395bf3407f834a1204890006b489"><code>e0d443c</code></a> ROB: Handle object numbers above 2**31 in _make_crypt_filter (<a href="https://redirect.github.com/py-pdf/pypdf/issues/3824">#3824</a>)</li> <li><a href="https://github.com/py-pdf/pypdf/commit/dad0f5e66a7b850092a42ea29baaed390f417a0d"><code>dad0f5e</code></a> ROB: Stop reading past truncated /Nums in get_label_from_nums (<a href="https://redirect.github.com/py-pdf/pypdf/issues/3823">#3823</a>)</li> <li><a href="https://github.com/py-pdf/pypdf/commit/52545c5d3fdfef11c8c8d33d8378cab24698aaec"><code>52545c5</code></a> ROB: Pad truncated data in bits2byte instead of reading out of bounds (<a href="https://redirect.github.com/py-pdf/pypdf/issues/3820">#3820</a>)</li> <li><a href="https://github.com/py-pdf/pypdf/commit/56e078441bf51580d3633b4e278a3eea20b2f85a"><code>56e0784</code></a> ENH: Add Japanese predefined CMaps (<a href="https://redirect.github.com/py-pdf/pypdf/issues/3800">#3800</a>)</li> <li><a href="https://github.com/py-pdf/pypdf/commit/0d048eebbeae29db28f30a3d51338edd07f56d16"><code>0d048ee</code></a> MAINT: Add ABC as a base class (<a href="https://redirect.github.com/py-pdf/pypdf/issues/3818">#3818</a>)</li> <li>Additional commits viewable in <a href="https://github.com/py-pdf/pypdf/compare/6.12.0...6.13.0">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/microsoft/RAMPART/network/alerts). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
[](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/microsoft/RAMPART/network/alerts). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps the minor-and-patch group with 2 updates: [pytest](https://github.com/pytest-dev/pytest) and [ruff](https://github.com/astral-sh/ruff). Updates `pytest` from 9.0.3 to 9.1.0 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/pytest-dev/pytest/releases">pytest's releases</a>.</em></p> <blockquote> <h2>9.1.0</h2> <h1>pytest 9.1.0 (2026-06-13)</h1> <h2>Removals and backward incompatible breaking changes</h2> <ul> <li> <p><a href="https://redirect.github.com/pytest-dev/pytest/issues/14533">#14533</a>: When using <code>--doctest-modules</code>, autouse fixtures with <code>module</code>, <code>package</code> or <code>session</code> scope that are defined inline in Python test modules (not plugins or conftests) will now possibly execute twice.</p> <p>If this is undesirable, move the fixture definition to a <code>conftest.py</code> file if possible.</p> <p>Technical explanation for those interested: When using <!-- raw HTML omitted -->--doctest-modules<!-- raw HTML omitted -->, pytest possibly collects Python modules twice, once as <code>pytest.Module</code> and once as a <code>DoctestModule</code> (depending on the configuration). Due to improvements in pytest's fixture implementation, if e.g. the <code>DoctestModule</code> collects a fixture, it is now visible to it only, and not to the <code>Module</code>. This means that both need to register the fixtures independently.</p> </li> </ul> <h2>Deprecations (removal in next major release)</h2> <ul> <li> <p><a href="https://redirect.github.com/pytest-dev/pytest/issues/10819">#10819</a>: Added a deprecation warning for class-scoped fixtures defined as instance methods (without <code>@classmethod</code>). Such fixtures set attributes on a different instance than the test methods use, leading to unexpected behavior. Use <code>@classmethod</code> decorator instead -- by <code>yastcher</code>.</p> <p>See <code>10819</code> and <code>14011</code>.</p> </li> <li> <p><a href="https://redirect.github.com/pytest-dev/pytest/issues/12882">#12882</a>: Calling <code>request.getfixturevalue() <pytest.FixtureRequest.getfixturevalue></code> during teardown to request a fixture that was not already requested is now deprecated and will become an error in pytest 10.</p> <p>See <code>dynamic-fixture-request-during-teardown</code> for details.</p> </li> <li> <p><a href="https://redirect.github.com/pytest-dev/pytest/issues/13409">#13409</a>: Using non-<code>~collections.abc.Collection</code> iterables (such as generators, iterators, or custom iterable objects) for the <code>argvalues</code> parameter in <code>@pytest.mark.parametrize <pytest.mark.parametrize ref></code> and <code>metafunc.parametrize <pytest.Metafunc.parametrize></code> is now deprecated.</p> <p>These iterables get exhausted after the first iteration, leading to tests getting unexpectedly skipped in cases such as running <code>pytest.main()</code> multiple times, using class-level parametrize decorators, or collecting tests multiple times.</p> <p>See <code>parametrize-iterators</code> for details and suggestions.</p> </li> <li> <p><a href="https://redirect.github.com/pytest-dev/pytest/issues/13946">#13946</a>: The private <code>config.inicfg</code> attribute is now deprecated. Use <code>config.getini() <pytest.Config.getini></code> to access configuration values instead.</p> <p>See <code>config-inicfg</code> for more details.</p> </li> <li> <p><a href="https://redirect.github.com/pytest-dev/pytest/issues/14004">#14004</a>: Passing <code>baseid</code> to <code>~pytest.FixtureDef</code> or <code>nodeid</code> strings to fixture registration APIs is now deprecated. These are internal pytest APIs that are used by some plugins.</p> <p>Use the <code>node</code> parameter instead for fixture scoping. This enables more robust node-based matching instead of string prefix matching. If you've used <code>nodeid=None</code>, pass <code>node=session</code> instead.</p> <p>This will be removed in pytest 10.</p> </li> <li> <p><a href="https://redirect.github.com/pytest-dev/pytest/issues/14335">#14335</a>: The method of configuring hooks using markers, deprecated since pytest 7.2, is now scheduled to be removed in pytest 10. See <code>hook-markers</code> for more details.</p> </li> <li> <p><a href="https://redirect.github.com/pytest-dev/pytest/issues/14434">#14434</a>: The <code>--pastebin</code> option is now deprecated.</p> </li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/pytest-dev/pytest/commit/b2522cf0b11fb33ecc1f4895fa1dffbb9252a63d"><code>b2522cf</code></a> Prepare release version 9.1.0</li> <li><a href="https://github.com/pytest-dev/pytest/commit/368d2fca78e86ac79ec269bb078fcb1259a94fed"><code>368d2fc</code></a> [refactor] Tighten <code>SetComparisonFunction</code> to <code>Iterator[str]</code> (<a href="https://redirect.github.com/pytest-dev/pytest/issues/14587">#14587</a>)</li> <li><a href="https://github.com/pytest-dev/pytest/commit/ff77cd8b66b43a88c26ca54384bbcab72d079497"><code>ff77cd8</code></a> [refactor] Make base assertion comparisons return an iterator instead of a li...</li> <li><a href="https://github.com/pytest-dev/pytest/commit/0d8491a4ecf971800de0479ef55c7f5292c54937"><code>0d8491a</code></a> build(deps): Bump actions/stale from 10.2.0 to 10.3.0</li> <li><a href="https://github.com/pytest-dev/pytest/commit/4a809d9c892f6abb5ba92b77b06f1dd878f4660a"><code>4a809d9</code></a> Merge pull request <a href="https://redirect.github.com/pytest-dev/pytest/issues/14568">#14568</a> from pytest-dev/register-fixture</li> <li><a href="https://github.com/pytest-dev/pytest/commit/5dfa38541becfb77d0f52cac4cc8cce71849ab61"><code>5dfa385</code></a> Fix recursion traceback test to cover all styles (<a href="https://redirect.github.com/pytest-dev/pytest/issues/14582">#14582</a>)</li> <li><a href="https://github.com/pytest-dev/pytest/commit/f52ff0c1778c15038cf2bbb00b7668dac674cc26"><code>f52ff0c</code></a> Add <code>pytest.register_fixture</code></li> <li><a href="https://github.com/pytest-dev/pytest/commit/a8ac094e80df788aec844794170b126eab0be7a4"><code>a8ac094</code></a> Merge pull request <a href="https://redirect.github.com/pytest-dev/pytest/issues/14567">#14567</a> from pytest-dev/more-visibility-deprecate</li> <li><a href="https://github.com/pytest-dev/pytest/commit/e5620cd21ec62f5a5f9a5141a3c76fb3953729b6"><code>e5620cd</code></a> [pre-commit.ci] pre-commit autoupdate (<a href="https://redirect.github.com/pytest-dev/pytest/issues/14577">#14577</a>)</li> <li><a href="https://github.com/pytest-dev/pytest/commit/2ce9c6d94eb691ea4da7f91f330602cbb67a6daf"><code>2ce9c6d</code></a> Merge pull request <a href="https://redirect.github.com/pytest-dev/pytest/issues/14540">#14540</a> from minbang930/fix-14533-doctest-module-fixtures</li> <li>Additional commits viewable in <a href="https://github.com/pytest-dev/pytest/compare/9.0.3...9.1.0">compare view</a></li> </ul> </details> <br /> Updates `ruff` from 0.15.16 to 0.15.17 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/astral-sh/ruff/releases">ruff's releases</a>.</em></p> <blockquote> <h2>0.15.17</h2> <h2>Release Notes</h2> <p>Released on 2026-06-11.</p> <h3>Preview features</h3> <ul> <li>Allow human-readable names in suppression comments (<a href="https://redirect.github.com/astral-sh/ruff/pull/25614">#25614</a>)</li> <li>Fix handling of <code>ignore</code> comments within a <code>disable</code>/<code>enable</code> pair (<a href="https://redirect.github.com/astral-sh/ruff/pull/25845">#25845</a>)</li> <li>Prioritize human-readable names in CLI output (<a href="https://redirect.github.com/astral-sh/ruff/pull/25869">#25869</a>)</li> <li>Respect diagnostic start and parent ranges and trailing comments in <code>ruff:ignore</code> suppressions (<a href="https://redirect.github.com/astral-sh/ruff/pull/25673">#25673</a>)</li> <li>[<code>flake8-async</code>] Add <code>trio.as_safe_channel</code> to safe decorators (<code>ASYNC119</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/25775">#25775</a>)</li> <li>[<code>flake8-pytest-style</code>] Also check <code>pytest_asyncio</code> fixtures (<a href="https://redirect.github.com/astral-sh/ruff/pull/25375">#25375</a>)</li> <li>[<code>ruff</code>] Ban <code>pytest</code> autouse fixtures (<code>RUF076</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/25477">#25477</a>)</li> <li>[<code>pyupgrade</code>] Add <code>from __future__ import annotations</code> automatically (<code>UP007</code>, <code>UP045</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/23259">#23259</a>)</li> </ul> <h3>Bug fixes</h3> <ul> <li>Fix diagnostic when <code>ruff:enable</code> or <code>ruff:disable</code> appears where <code>ruff:ignore</code> is expected (<a href="https://redirect.github.com/astral-sh/ruff/pull/25700">#25700</a>)</li> <li>[<code>pyupgrade</code>] Preserve leading empty literals to avoid syntax errors (<code>UP032</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/25491">#25491</a>)</li> </ul> <h3>Rule changes</h3> <ul> <li>[<code>flake8-pytest-style</code>] Clarify diagnostic message for single parameters (<code>PT007</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/25592">#25592</a>)</li> <li>[<code>numpy</code>] Drop autofix for <code>np.in1d</code> (<code>NPY201</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/25612">#25612</a>)</li> <li>[<code>pylint</code>] Exempt Python version comparisons (<code>PLR2004</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/25743">#25743</a>)</li> </ul> <h3>Performance</h3> <ul> <li>Reserve AST <code>Vec</code>s with correct capacity for common cases (<a href="https://redirect.github.com/astral-sh/ruff/pull/25451">#25451</a>)</li> </ul> <h3>Formatter</h3> <ul> <li>Preserve whitespace for Quarto cell option comments (<a href="https://redirect.github.com/astral-sh/ruff/pull/25641">#25641</a>)</li> </ul> <h3>CLI</h3> <ul> <li>Allow rule names in <code>ruff rule</code> (<a href="https://redirect.github.com/astral-sh/ruff/pull/25640">#25640</a>)</li> </ul> <h3>Other changes</h3> <ul> <li>Fix playground diagnostics scrollbars (<a href="https://redirect.github.com/astral-sh/ruff/pull/25642">#25642</a>)</li> </ul> <h3>Contributors</h3> <ul> <li><a href="https://github.com/SuryanshSS1011"><code>@SuryanshSS1011</code></a></li> <li><a href="https://github.com/anishgirianish"><code>@anishgirianish</code></a></li> <li><a href="https://github.com/romero-deshaw"><code>@romero-deshaw</code></a></li> <li><a href="https://github.com/karlhillx"><code>@karlhillx</code></a></li> <li><a href="https://github.com/carljm"><code>@carljm</code></a></li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md">ruff's changelog</a>.</em></p> <blockquote> <h2>0.15.17</h2> <p>Released on 2026-06-11.</p> <h3>Preview features</h3> <ul> <li>Allow human-readable names in suppression comments (<a href="https://redirect.github.com/astral-sh/ruff/pull/25614">#25614</a>)</li> <li>Fix handling of <code>ignore</code> comments within a <code>disable</code>/<code>enable</code> pair (<a href="https://redirect.github.com/astral-sh/ruff/pull/25845">#25845</a>)</li> <li>Prioritize human-readable names in CLI output (<a href="https://redirect.github.com/astral-sh/ruff/pull/25869">#25869</a>)</li> <li>Respect diagnostic start and parent ranges and trailing comments in <code>ruff:ignore</code> suppressions (<a href="https://redirect.github.com/astral-sh/ruff/pull/25673">#25673</a>)</li> <li>[<code>flake8-async</code>] Add <code>trio.as_safe_channel</code> to safe decorators (<code>ASYNC119</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/25775">#25775</a>)</li> <li>[<code>flake8-pytest-style</code>] Also check <code>pytest_asyncio</code> fixtures (<a href="https://redirect.github.com/astral-sh/ruff/pull/25375">#25375</a>)</li> <li>[<code>ruff</code>] Ban <code>pytest</code> autouse fixtures (<code>RUF076</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/25477">#25477</a>)</li> <li>[<code>pyupgrade</code>] Add <code>from __future__ import annotations</code> automatically (<code>UP007</code>, <code>UP045</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/23259">#23259</a>)</li> </ul> <h3>Bug fixes</h3> <ul> <li>Fix diagnostic when <code>ruff:enable</code> or <code>ruff:disable</code> appears where <code>ruff:ignore</code> is expected (<a href="https://redirect.github.com/astral-sh/ruff/pull/25700">#25700</a>)</li> <li>[<code>pyupgrade</code>] Preserve leading empty literals to avoid syntax errors (<code>UP032</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/25491">#25491</a>)</li> </ul> <h3>Rule changes</h3> <ul> <li>[<code>flake8-pytest-style</code>] Clarify diagnostic message for single parameters (<code>PT007</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/25592">#25592</a>)</li> <li>[<code>numpy</code>] Drop autofix for <code>np.in1d</code> (<code>NPY201</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/25612">#25612</a>)</li> <li>[<code>pylint</code>] Exempt Python version comparisons (<code>PLR2004</code>) (<a href="https://redirect.github.com/astral-sh/ruff/pull/25743">#25743</a>)</li> </ul> <h3>Performance</h3> <ul> <li>Reserve AST <code>Vec</code>s with correct capacity for common cases (<a href="https://redirect.github.com/astral-sh/ruff/pull/25451">#25451</a>)</li> </ul> <h3>Formatter</h3> <ul> <li>Preserve whitespace for Quarto cell option comments (<a href="https://redirect.github.com/astral-sh/ruff/pull/25641">#25641</a>)</li> </ul> <h3>CLI</h3> <ul> <li>Allow rule names in <code>ruff rule</code> (<a href="https://redirect.github.com/astral-sh/ruff/pull/25640">#25640</a>)</li> </ul> <h3>Other changes</h3> <ul> <li>Fix playground diagnostics scrollbars (<a href="https://redirect.github.com/astral-sh/ruff/pull/25642">#25642</a>)</li> </ul> <h3>Contributors</h3> <ul> <li><a href="https://github.com/SuryanshSS1011"><code>@SuryanshSS1011</code></a></li> <li><a href="https://github.com/anishgirianish"><code>@anishgirianish</code></a></li> <li><a href="https://github.com/romero-deshaw"><code>@romero-deshaw</code></a></li> <li><a href="https://github.com/karlhillx"><code>@karlhillx</code></a></li> <li><a href="https://github.com/carljm"><code>@carljm</code></a></li> <li><a href="https://github.com/ntBre"><code>@ntBre</code></a></li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/astral-sh/ruff/commit/7c645a9a1be8258b9f9e005208a55a0b7e8e18f0"><code>7c645a9</code></a> Bump 0.15.17 (<a href="https://redirect.github.com/astral-sh/ruff/issues/25872">#25872</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/f381eb1d54997cfbfa6f63c15dd2d760f70e85e1"><code>f381eb1</code></a> Prioritize human-readable names in CLI output (<a href="https://redirect.github.com/astral-sh/ruff/issues/25869">#25869</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/b9b4546ad27d8fd12acc979e312a3ee25ef8ac4f"><code>b9b4546</code></a> Minor workflow simplification (<a href="https://redirect.github.com/astral-sh/ruff/issues/25870">#25870</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/1e77ba02570bbe4952f7cf0e4ebb97b8b4e6e58d"><code>1e77ba0</code></a> [ty] Move <code>PreformattedBlockScanner</code> to format-agnostic location. (<a href="https://redirect.github.com/astral-sh/ruff/issues/25856">#25856</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/6f2b772285aa478e8aee3f4b54dfa9ce903a0ce1"><code>6f2b772</code></a> [ty] Preserve nominal type of enum.property instances (<a href="https://redirect.github.com/astral-sh/ruff/issues/25849">#25849</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/be4777c8766a38d405a69948989cdfa2674adaae"><code>be4777c</code></a> [ty] Fix site-package error when multiple versions of pythons are installed i...</li> <li><a href="https://github.com/astral-sh/ruff/commit/53f6ff7200983a67778fcba7106019d2615846f0"><code>53f6ff7</code></a> Allow human-readable names in suppression comments (<a href="https://redirect.github.com/astral-sh/ruff/issues/25614">#25614</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/67403254192f3541bd7e1027c8f1805cf7a9c2be"><code>6740325</code></a> [ty] Restrict uncached raw signature access (<a href="https://redirect.github.com/astral-sh/ruff/issues/25866">#25866</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/970b1bf4a4d83359c9e28cad5f127ebbd6769682"><code>970b1bf</code></a> Auto-update snapshots when syncing typeshed (<a href="https://redirect.github.com/astral-sh/ruff/issues/25841">#25841</a>)</li> <li><a href="https://github.com/astral-sh/ruff/commit/0785793750fd6c74124a189259822f1a28eb5c13"><code>0785793</code></a> Fix handling of <code>ignore</code> comments within a <code>disable</code>/<code>enable</code> pair (<a href="https://redirect.github.com/astral-sh/ruff/issues/25845">#25845</a>)</li> <li>Additional commits viewable in <a href="https://github.com/astral-sh/ruff/compare/0.15.16...0.15.17">compare view</a></li> </ul> </details> <br /> Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore <dependency name> major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself) - `@dependabot ignore <dependency name> minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself) - `@dependabot ignore <dependency name>` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself) - `@dependabot unignore <dependency name>` will remove all of the ignore conditions of the specified dependency - `@dependabot unignore <dependency name> <ignore condition>` will remove the ignore condition of the specified dependency and ignore conditions </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
….16 to 0.15.17 (microsoft#93) Bumps [https://github.com/astral-sh/ruff-pre-commit](https://github.com/astral-sh/ruff-pre-commit) from v0.15.16 to 0.15.17. This release includes the previously tagged commit. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/astral-sh/ruff-pre-commit/releases">https://github.com/astral-sh/ruff-pre-commit's releases</a>.</em></p> <blockquote> <h2>v0.15.17</h2> <p>See: <a href="https://github.com/astral-sh/ruff/releases/tag/0.15.17">https://github.com/astral-sh/ruff/releases/tag/0.15.17</a></p> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/astral-sh/ruff-pre-commit/commit/3b3f7c3f57fe9925356faf5fe6230835138be230"><code>3b3f7c3</code></a> Mirror: 0.15.17</li> <li><a href="https://github.com/astral-sh/ruff-pre-commit/commit/99e6029223026d6fa76813c17277c704c11db2a0"><code>99e6029</code></a> Various hardenings (<a href="https://redirect.github.com/astral-sh/ruff-pre-commit/issues/170">#170</a>)</li> <li><a href="https://github.com/astral-sh/ruff-pre-commit/commit/f69224b9a09036deb0588511bbec7ee97a8324a8"><code>f69224b</code></a> Bump the github-actions group with 2 updates (<a href="https://redirect.github.com/astral-sh/ruff-pre-commit/issues/169">#169</a>)</li> <li>See full diff in <a href="https://github.com/astral-sh/ruff-pre-commit/compare/22f0422809455ec89ffdcf5a00170ba816e42ddb...3b3f7c3f57fe9925356faf5fe6230835138be230">compare view</a></li> </ul> </details> <br /> Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
## Description Adds explicit Dependabot `security-minor-and-patch` groups for configured ecosystems so minor and patch security updates can be grouped separately from normal version updates. Mirrors microsoft/PyRIT#2018. This follows up on the recent separate Dependabot security PRs microsoft#85, microsoft#87, microsoft#88, microsoft#89, and microsoft#90. Those PRs were opened one dependency at a time because Dependabot `groups.applies-to` defaults to `version-updates` when omitted. GitHub's Dependabot options reference documents that `applies-to` supports both `version-updates` and `security-updates`. The existing `uv` `minor-and-patch` group is preserved for normal version updates. This change adds a matching security-only minor/patch group for `uv`, plus security-only minor/patch groups for `github-actions` and `pre-commit`. Major security updates are intentionally left ungrouped so higher-risk updates remain isolated for review. References: - Dependabot `groups` option: https://docs.github.com/en/code-security/reference/supply-chain-security/dependabot-options-reference#groups-- - Dependabot `applies-to` behavior: https://docs.github.com/en/code-security/reference/supply-chain-security/dependabot-options-reference#groups-- - Dependabot security updates: https://docs.github.com/en/code-security/dependabot/dependabot-security-updates ## Breaking changes None. ## Checklist - [X] `pre-commit run --all-files` passes - [ ] Tests added or updated for changes - [ ] Documentation updated
## Description Migrate type checker from pyright to ty to align with PyRIT (microsoft/PyRIT#1319). ### Typing fixes prompted by ty **`InjectionHandle` and `Session` now inherit `AbstractAsyncContextManager`** (rampart/core/injection.py, rampart/core/adapter.py). ty rejected `AsyncExitStack.enter_async_context(handle)` because a `Protocol` with `__aenter__ -> Self` doesn't unify with `AbstractAsyncContextManager[Handle, _ExitT_co]`'s covariant `_T_co` without an explicit subtype relationship. ```python class InjectionHandle(AbstractAsyncContextManager["InjectionHandle", None], Protocol): class Session(AbstractAsyncContextManager["Session"], Protocol): ``` Notes: - typeshed declares `AbstractAsyncContextManager` as both `ABC` and `Protocol` ([stdlib/contextlib.pyi](https://github.com/python/typeshed/blob/main/stdlib/contextlib.pyi)) - it's on the type-checker allowlist, so a `Protocol` may legally inherit from it. - Base order matters for C3 linearization: the ABC must precede `Protocol`. - Generic args `[InjectionHandle, None]`: `_T_co` = `__aenter__` return; `_ExitT_co` = `None` because cleanup never suppresses exceptions (`closing`/`nullcontext` family, not `suppress`). - `__aexit__` aligned with stdlib conventions: positional-only `/`, canonical `exc_value`/`traceback` names. **`Attacks.xpia` and `coerce_driver` narrowing reordered** (rampart/attacks/__init__.py, rampart/drivers/_utils.py). ty cannot yet narrow element type through `isinstance(x, list)` over `list[A] | list[B]`. Reordering to check the protocol/scalar branch first eliminates the need for `cast` and `# type: ignore`. **`ResponseContains` branch order tightened** (rampart/evaluators/response_contains.py). `callable()` doesn't narrow against a union containing `str` (every str is callable for ty's purposes here). Reordering to `re.Pattern` -> `str` -> `callable` and using `if found is True:` makes the dispatch unambiguous. **`pytest_plugin/plugin.py`** (rampart/pytest_plugin/plugin.py): replaced a `register_default_handler_factory` lambda with a typed module-level `_default_handler_factory` so `list[ExecutionEventHandler]` aligns under list invariance. `pytest.Item` user-attribute writes now use `# ty: ignore[unresolved-attribute]`. ### Test changes - tests/unit/attacks/test_xpia.py: `_mock_handle` and `_mock_evaluator` now use `spec=InjectionHandle` / `spec=Evaluator`. With the reordered narrowing in `Attacks.xpia` (`isinstance(inject, InjectionHandle)` first), bare `AsyncMock()` becomes ambiguous because runtime-checkable protocols treat any Mock as matching (every `hasattr` returns True). `spec=` makes `isinstance` deterministic. - tests/unit/core/test_adapter.py: `@abstractmethod` added to a protocol-conformance test fixture so ty doesn't flag the `...` body. - Test-only `# pyright: ignore` -> `# ty: ignore` (e.g., tests/unit/core/test_llm.py). ### Docs Five contributing pages updated to reference ty: docs/contributing/index.md, development-setup.md, code-style.md, architecture.md, pull-requests.md. ## Breaking changes None for users. Contributors will need to run `uv sync` to install ty (pyright is removed from the dev group) and update editor integrations - call out in development-setup.md. ## Checklist - [x] `pre-commit run --all-files` passes - [x] Tests added or updated for changes - `tests/unit/attacks/test_xpia.py` mocks gain `spec=` for deterministic protocol `isinstance`; pyright ignore strings ported in `tests/unit/core/test_llm.py`, test_execution.py, `test_protocols.py`, test_types.py, etc. - [x] Documentation updated - 5 contributing pages --- ### Verification - `uv run ty check`: All checks passed - `uv run ruff check . && uv run ruff format --check .`: clean - `uv run pytest`: 491 passed, 5 skipped - `uv run pre-commit run --all-files`: all hooks pass
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
Fixups from microsoft#86 into microsoft#73.
Breaking changes
None
Checklist
pre-commit run --all-filespasses