Skip to content

[FIX]: ty merge conflicts for microsoft#73 - #1

Closed
spencrr wants to merge 10 commits into
nina-msft:dev/nina-msft/8259from
spencrr:dev/spencrr/73-merge
Closed

spencrr wants to merge 10 commits into
nina-msft:dev/nina-msft/8259from
spencrr:dev/spencrr/73-merge

Conversation

@spencrr

@spencrr spencrr commented Jun 19, 2026

Copy link
Copy Markdown

Description

Fixups from microsoft#86 into microsoft#73.

Breaking changes

None

Checklist

  • pre-commit run --all-files passes
  • Tests added or updated for changes
  • Documentation updated

dependabot Bot and others added 10 commits June 17, 2026 09:21
Bumps [pyjwt](https://github.com/jpadilla/pyjwt) from 2.12.1 to 2.13.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/jpadilla/pyjwt/releases">pyjwt's
releases</a>.</em></p>
<blockquote>
<h2>2.13.0</h2>
<h1>PyJWT 2.13.0 — Security Release</h1>
<p>This release bundles five security fixes plus three additional
hardening / spec-compliance changes. We recommend all users upgrade.</p>
<h2>Security</h2>
<ul>
<li>
<p><strong><a
href="https://github.com/jpadilla/pyjwt/security/advisories/GHSA-xgmm-8j9v-c9wx"><code>GHSA-xgmm-8j9v-c9wx</code></a>
— JWK JSON accepted as HMAC secret (algorithm confusion).</strong>
<code>HMACAlgorithm.prepare_key</code> previously rejected PEM- and
SSH-formatted asymmetric keys but did not catch a JWK passed as a raw
JSON string. In a verifier configured with both symmetric and asymmetric
algorithms in <code>algorithms=[…]</code> and a raw-JSON JWK as the key,
an attacker could forge HS256 tokens using the JWK text as the HMAC
secret. The guard has been extended to reject any JWK-shaped JSON.
<em>Reported by <a
href="https://github.com/aradona91"><code>@​aradona91</code></a>.</em></p>
</li>
<li>
<p><strong><a
href="https://github.com/jpadilla/pyjwt/security/advisories/GHSA-jq35-7prp-9v3f"><code>GHSA-jq35-7prp-9v3f</code></a>
— Algorithm allow-list bypass with <code>PyJWK</code> /
<code>PyJWKClient</code>.</strong> When verifying with a
<code>PyJWK</code>, the caller's <code>algorithms=[…]</code> allow-list
was checked against the token header <code>alg</code> as a string only;
actual verification used the algorithm bound to the <code>PyJWK</code>.
An attacker who controlled a registered JWKS key could sign with one
algorithm and advertise another on the header. PyJWT now requires the
token header <code>alg</code> to match the <code>PyJWK</code>'s
algorithm before verification. <em>Reported by <a
href="https://github.com/sushi-gif"><code>@​sushi-gif</code></a>.</em></p>
</li>
<li>
<p><strong><a
href="https://github.com/jpadilla/pyjwt/security/advisories/GHSA-w7vc-732c-9m39"><code>GHSA-w7vc-732c-9m39</code></a>
— DoS via base64 decode of unused payload segment when
<code>b64=false</code>.</strong> For detached-payload JWS
(<code>b64=false</code>), the compact-form payload segment was
base64-decoded before being discarded in favor of the caller-supplied
<code>detached_payload</code>. An attacker could inflate the unused
segment to force CPU + memory cost without holding a valid signature.
The segment is now required to be empty per RFC 7515 Appendix F, and is
no longer decoded. <em>Reported by <a
href="https://github.com/thesmartshadow"><code>@​thesmartshadow</code></a>.</em></p>
</li>
<li>
<p><strong><a
href="https://github.com/jpadilla/pyjwt/security/advisories/GHSA-993g-76c3-p5m4"><code>GHSA-993g-76c3-p5m4</code></a>
— <code>PyJWKClient</code> accepts non-HTTP(S) URIs.</strong>
<code>PyJWKClient.fetch_data</code> passed its URI to
<code>urllib.request.urlopen</code>, which by default also handles
<code>file://</code>, <code>ftp://</code>, and <code>data:</code>
schemes. An application that fed an attacker-influenced URI into
<code>PyJWKClient</code> could be coerced into reading local files or
reaching other unintended schemes. <code>PyJWKClient</code> now rejects
any URI whose scheme isn't <code>http</code> or <code>https</code>.
<em>Reported by <a
href="https://github.com/KEIJOT"><code>@​KEIJOT</code></a>.</em></p>
</li>
<li>
<p><strong><a
href="https://github.com/jpadilla/pyjwt/security/advisories/GHSA-fhv5-28vv-h8m8"><code>GHSA-fhv5-28vv-h8m8</code></a>
— <code>PyJWKClient</code> cache wiped on fetch error.</strong> A
<code>finally</code>-block <code>put(jwk_set=None)</code> cleared the
JWK Set cache whenever a fetch raised, turning a transient JWKS-endpoint
outage into application-wide auth failure. The cache write was moved
into the success path; transient errors no longer evict valid cached
keys. <em>Reported by <a
href="https://github.com/eddieran"><code>@​eddieran</code></a>.</em></p>
</li>
</ul>
<h2>Fixed</h2>
<ul>
<li>Reject empty HMAC keys outright in
<code>HMACAlgorithm.prepare_key</code> with <code>InvalidKeyError</code>
instead of accepting them with only a warning. Defends against the
<code>os.getenv(&quot;JWT_SECRET&quot;, &quot;&quot;)</code> footgun.
<em>Thanks to <a
href="https://github.com/SnailSploit"><code>@​SnailSploit</code></a> and
<a href="https://github.com/spartan8806"><code>@​spartan8806</code></a>
for the reports.</em></li>
<li>Forward per-call <code>options</code> (including
<code>enforce_minimum_key_length</code>) from <code>PyJWT.decode</code>
through to <code>PyJWS._verify_signature</code>. The option was
previously silently dropped between the two layers, so it only took
effect when set on the <code>PyJWT</code> instance. <em>Thanks to <a
href="https://github.com/WLUB"><code>@​WLUB</code></a> for the
report.</em></li>
<li><strong>RFC 7797 §3 compliance for <code>b64=false</code>:</strong>
the encoder now auto-adds <code>&quot;b64&quot;</code> to
<code>crit</code>, and the decoder rejects tokens that set
<code>b64=false</code> without listing it in <code>crit</code>.
<em>Thanks to <a
href="https://github.com/MachineLearning-Nerd"><code>@​MachineLearning-Nerd</code></a>
for the report.</em></li>
</ul>
<h2>Changed</h2>
<ul>
<li>Migrate the <code>dev</code>, <code>docs</code>, and
<code>tests</code> package extras to dependency groups, by <a
href="https://github.com/kurtmckee"><code>@​kurtmckee</code></a> in <a
href="https://redirect.github.com/jpadilla/pyjwt/pull/1152">#1152</a>.</li>
</ul>
<h2>Upgrade notes</h2>
<p>Most fixes are invisible to correctly-configured callers. A few
behavioral changes you may encounter:</p>
<ul>
<li><strong>Empty HMAC keys now raise.</strong> If your app passed
<code>&quot;&quot;</code> or <code>b&quot;&quot;</code> as a secret
(often via a missing env var, e.g.
<code>os.getenv(&quot;JWT_SECRET&quot;, &quot;&quot;)</code>),
<code>encode</code>/<code>decode</code> will now raise
<code>InvalidKeyError</code>. This is the intended behavior — fix the
configuration.</li>
<li><strong><code>PyJWK</code> decoding now requires the token's
<code>alg</code> to match the JWK's algorithm.</strong> Previously a
mismatch was silently honored if the header <code>alg</code> appeared in
the allow-list. Tokens that relied on this mismatch will now fail with
<code>InvalidAlgorithmError</code>.</li>
<li><strong><code>PyJWKClient</code> now rejects non-HTTP(S) URIs at
construction time.</strong> Tests or dev environments that fetched JWKS
from <code>file://</code> URIs need to switch to a local HTTP server or
load the JWKS by other means (e.g. construct
<code>PyJWKSet.from_dict(...)</code> directly).</li>
<li><strong><code>b64=false</code> tokens are now strictly RFC 7515 /
7797 compliant.</strong> Tokens with a non-empty compact-form payload
segment, or that omit <code>&quot;b64&quot;</code> from
<code>crit</code>, will be rejected. PyJWT-produced tokens always
satisfy both invariants, so round-trips through PyJWT are
unaffected.</li>
<li><strong><code>enforce_minimum_key_length</code> set per-call now
takes effect.</strong> Callers who passed
<code>options={&quot;enforce_minimum_key_length&quot;: True}</code> to
<code>jwt.decode()</code> previously got no enforcement; they will now
get <code>InvalidKeyError</code> on undersized keys, as documented.</li>
</ul>
<p><strong>Full changelog:</strong> <a
href="https://github.com/jpadilla/pyjwt/compare/2.12.1...2.13.0">https://github.com/jpadilla/pyjwt/compare/2.12.1...2.13.0</a></p>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/jpadilla/pyjwt/blob/master/CHANGELOG.rst">pyjwt's
changelog</a>.</em></p>
<blockquote>
<h2><code>v2.13.0
&lt;https://github.com/jpadilla/pyjwt/compare/2.12.1...2.13.0&gt;</code>__</h2>
<p>Security</p>
<pre><code>
- Reject JWK JSON documents passed as raw HMAC secrets in
  ``HMACAlgorithm.prepare_key`` to close an algorithm-confusion gap that
  the existing PEM/SSH guard did not cover. Reported by @aradona91 in
`GHSA-xgmm-8j9v-c9wx
&lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-xgmm-8j9v-c9wx&gt;`__.
- Bind the JWT header ``alg`` to ``PyJWK.algorithm_name`` during
  verification so the caller's ``algorithms=[...]`` allow-list cannot be
bypassed when decoding with a ``PyJWK`` / ``PyJWKClient`` key. Reported
by @sushi-gif in `GHSA-jq35-7prp-9v3f
&lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-jq35-7prp-9v3f&gt;`__.
- Reject non-``http(s)`` URI schemes in ``PyJWKClient`` so attacker-
influenced URIs cannot read local files or reach unintended schemes via
urllib's default ``file://`` / ``ftp://`` / ``data:`` handlers. Reported
by @KEIJOT in `GHSA-993g-76c3-p5m4
&lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-993g-76c3-p5m4&gt;`__.
- Preserve the cached JWK Set on fetch errors in
``PyJWKClient.fetch_data``.
  The previous ``finally``-block ``put(None)`` pattern cleared the cache
on any transient outage, turning one bad JWKS request into application-
wide auth failure. Reported by @eddieran in `GHSA-fhv5-28vv-h8m8
&lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-fhv5-28vv-h8m8&gt;`__.
- Skip the unconditional base64 decode of the compact-form payload
segment
  when ``b64=false`` is set in the protected header, and require that
  segment to be empty (RFC 7515 Appendix F detached form). Closes an
  unauthenticated DoS amplifier. Reported by @thesmartshadow in
`GHSA-w7vc-732c-9m39
&lt;https://github.com/jpadilla/pyjwt/security/advisories/GHSA-w7vc-732c-9m39&gt;`__.
<p>Fixed</p>
<pre><code>
- Reject empty HMAC keys outright in ``HMACAlgorithm.prepare_key`` with
  ``InvalidKeyError`` instead of accepting them with only a warning.
  Thanks to @SnailSploit and @spartan8806 for independently flagging the
  footgun.
- Forward per-call ``options`` (including
``enforce_minimum_key_length``)
  from ``PyJWT.decode`` through to ``PyJWS._verify_signature`` so the
option actually takes effect when set at the call site rather than only
  on the ``PyJWT`` instance. Thanks to @WLUB for the report.
- RFC 7797 §3 compliance for ``b64=false``: the encoder now auto-adds
``&amp;quot;b64&amp;quot;`` to the ``crit`` header parameter, and the
decoder rejects
tokens that set ``b64=false`` without listing it in ``crit``. Thanks to
  @MachineLearning-Nerd for the report.

Changed
</code></pre>
<ul>
<li>Migrate the <code>dev</code>, <code>docs</code>, and
<code>tests</code> package extras to dependency groups by <a
href="https://github.com/kurtmckee"><code>@​kurtmckee</code></a> in
<code>[#1152](jpadilla/pyjwt#1152)
&amp;lt;https://github.com/jpadilla/pyjwt/pull/1152&amp;gt;</code>__
</code></pre></li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/jpadilla/pyjwt/commit/7144e4534c34810f4525dc4578a32addd8212cff"><code>7144e45</code></a>
Apply ruff format</li>
<li><a
href="https://github.com/jpadilla/pyjwt/commit/d2f4bec4963897c0ef96ef64a875894f2c8542ab"><code>d2f4bec</code></a>
Restore <code>cast()</code> calls with cross-version <code>type:
ignore</code> for <code>prepare_key</code></li>
<li><a
href="https://github.com/jpadilla/pyjwt/commit/22f478cebddd8294259c30f037ecb92b0b348774"><code>22f478c</code></a>
Remove redundant casts in <code>RSAAlgorithm.prepare_key</code> and
`ECAlgorithm.prepare...</li>
<li><a
href="https://github.com/jpadilla/pyjwt/commit/95791b1759b8aa4f2203575d344d5c78564cdc81"><code>95791b1</code></a>
Bundle security fixes and hardening into 2.13.0</li>
<li><a
href="https://github.com/jpadilla/pyjwt/commit/dcc27a9d3182a2349c30b160758785c6ce7a6508"><code>dcc27a9</code></a>
[pre-commit.ci] pre-commit autoupdate (<a
href="https://redirect.github.com/jpadilla/pyjwt/issues/1155">#1155</a>)</li>
<li><a
href="https://github.com/jpadilla/pyjwt/commit/9d08a9a1896845ed8eaf88e6f6ac61e5800c3e7a"><code>9d08a9a</code></a>
[pre-commit.ci] pre-commit autoupdate (<a
href="https://redirect.github.com/jpadilla/pyjwt/issues/1146">#1146</a>)</li>
<li><a
href="https://github.com/jpadilla/pyjwt/commit/b87c10014d4109f0214fea188d00faaaf8a80e64"><code>b87c100</code></a>
Bump codecov/codecov-action from 5 to 6 (<a
href="https://redirect.github.com/jpadilla/pyjwt/issues/1154">#1154</a>)</li>
<li><a
href="https://github.com/jpadilla/pyjwt/commit/40e3147eb5f790d8d041772e5fc00728a176c812"><code>40e3147</code></a>
Migrate development extras to dependency groups (<a
href="https://redirect.github.com/jpadilla/pyjwt/issues/1152">#1152</a>)</li>
<li>See full diff in <a
href="https://github.com/jpadilla/pyjwt/compare/2.12.1...2.13.0">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=pyjwt&package-manager=uv&previous-version=2.12.1&new-version=2.13.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/microsoft/RAMPART/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [starlette](https://github.com/Kludex/starlette) from 1.0.1 to
1.3.1.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/Kludex/starlette/releases">starlette's
releases</a>.</em></p>
<blockquote>
<h2>Version 1.3.1</h2>
<h2>What's Changed</h2>
<ul>
<li>Use <code>StarletteDeprecationWarning</code> instead of
<code>DeprecationWarning</code> by <a
href="https://github.com/Kludex"><code>@​Kludex</code></a> in <a
href="https://redirect.github.com/Kludex/starlette/pull/3119">Kludex/starlette#3119</a></li>
<li>Enforce <code>max_fields</code> and <code>max_part_size</code> in
<code>FormParser</code> by <a
href="https://github.com/Kludex"><code>@​Kludex</code></a> in <a
href="https://redirect.github.com/Kludex/starlette/pull/3329">Kludex/starlette#3329</a></li>
<li>Enforce <code>FormParser</code> limits in parser callbacks by <a
href="https://github.com/Kludex"><code>@​Kludex</code></a> in <a
href="https://redirect.github.com/Kludex/starlette/pull/3331">Kludex/starlette#3331</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/Kludex/starlette/compare/1.3.0...1.3.1">https://github.com/Kludex/starlette/compare/1.3.0...1.3.1</a></p>
<h2>Version 1.3.0</h2>
<h2>What's Changed</h2>
<ul>
<li>Clamp oversized suffix ranges in <code>FileResponse</code> by <a
href="https://github.com/jiyujie2006"><code>@​jiyujie2006</code></a> in
<a
href="https://redirect.github.com/Kludex/starlette/pull/3307">Kludex/starlette#3307</a></li>
<li>Catch <code>OSError</code> alongside <code>MultiPartException</code>
when closing temp files by <a
href="https://github.com/N3XT3R1337"><code>@​N3XT3R1337</code></a> in <a
href="https://redirect.github.com/Kludex/starlette/pull/3191">Kludex/starlette#3191</a></li>
<li>Add <code>httpx2</code> to the <code>full</code> extra by <a
href="https://github.com/Kludex"><code>@​Kludex</code></a> in <a
href="https://redirect.github.com/Kludex/starlette/pull/3323">Kludex/starlette#3323</a></li>
<li>Adjust testclient typing and warnings by <a
href="https://github.com/waketzheng"><code>@​waketzheng</code></a> in <a
href="https://redirect.github.com/Kludex/starlette/pull/3322">Kludex/starlette#3322</a></li>
<li>Fix IndexError in URL.replace() on a URL with no authority by <a
href="https://github.com/LeSingh1"><code>@​LeSingh1</code></a> in <a
href="https://redirect.github.com/Kludex/starlette/pull/3317">Kludex/starlette#3317</a></li>
<li>Annotate URLPath protocol parameter with Literal by <a
href="https://github.com/Chang-LeHung"><code>@​Chang-LeHung</code></a>
in <a
href="https://redirect.github.com/Kludex/starlette/pull/3285">Kludex/starlette#3285</a></li>
<li>avoid collapsing exception groups from user code by <a
href="https://github.com/graingert"><code>@​graingert</code></a> in <a
href="https://redirect.github.com/Kludex/starlette/pull/2830">Kludex/starlette#2830</a></li>
<li>Use <code>removeprefix</code> to strip weak ETag indicator in
<code>is_not_modified</code> by <a
href="https://github.com/gnosyslambda"><code>@​gnosyslambda</code></a>
in <a
href="https://redirect.github.com/Kludex/starlette/pull/3193">Kludex/starlette#3193</a></li>
<li>Build <code>request.url</code> from structured components by <a
href="https://github.com/Kludex"><code>@​Kludex</code></a> in <a
href="https://redirect.github.com/Kludex/starlette/pull/3326">Kludex/starlette#3326</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a
href="https://github.com/jiyujie2006"><code>@​jiyujie2006</code></a>
made their first contribution in <a
href="https://redirect.github.com/Kludex/starlette/pull/3307">Kludex/starlette#3307</a></li>
<li><a
href="https://github.com/N3XT3R1337"><code>@​N3XT3R1337</code></a> made
their first contribution in <a
href="https://redirect.github.com/Kludex/starlette/pull/3191">Kludex/starlette#3191</a></li>
<li><a
href="https://github.com/leestana01"><code>@​leestana01</code></a> made
their first contribution in <a
href="https://redirect.github.com/Kludex/starlette/pull/3319">Kludex/starlette#3319</a></li>
<li><a href="https://github.com/LeSingh1"><code>@​LeSingh1</code></a>
made their first contribution in <a
href="https://redirect.github.com/Kludex/starlette/pull/3317">Kludex/starlette#3317</a></li>
<li><a
href="https://github.com/EmmanuelNiyonshuti"><code>@​EmmanuelNiyonshuti</code></a>
made their first contribution in <a
href="https://redirect.github.com/Kludex/starlette/pull/3204">Kludex/starlette#3204</a></li>
<li><a
href="https://github.com/Chang-LeHung"><code>@​Chang-LeHung</code></a>
made their first contribution in <a
href="https://redirect.github.com/Kludex/starlette/pull/3285">Kludex/starlette#3285</a></li>
<li><a
href="https://github.com/gnosyslambda"><code>@​gnosyslambda</code></a>
made their first contribution in <a
href="https://redirect.github.com/Kludex/starlette/pull/3193">Kludex/starlette#3193</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/Kludex/starlette/compare/1.2.1...1.3.0">https://github.com/Kludex/starlette/compare/1.2.1...1.3.0</a></p>
<h2>Version 1.2.1</h2>
<h2>What's Changed</h2>
<ul>
<li>Use <code>httpx2</code> for type checking in the
<code>testclient</code> module by <a
href="https://github.com/leifwar"><code>@​leifwar</code></a> in <a
href="https://redirect.github.com/Kludex/starlette/pull/3304">Kludex/starlette#3304</a></li>
<li>Add assert error for requires() when request param is not Request
type by <a
href="https://github.com/KeeganOP"><code>@​KeeganOP</code></a> in <a
href="https://redirect.github.com/Kludex/starlette/pull/3298">Kludex/starlette#3298</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a href="https://github.com/leifwar"><code>@​leifwar</code></a> made
their first contribution in <a
href="https://redirect.github.com/Kludex/starlette/pull/3304">Kludex/starlette#3304</a></li>
<li><a href="https://github.com/diskeu"><code>@​diskeu</code></a> made
their first contribution in <a
href="https://redirect.github.com/Kludex/starlette/pull/3243">Kludex/starlette#3243</a></li>
<li><a href="https://github.com/KeeganOP"><code>@​KeeganOP</code></a>
made their first contribution in <a
href="https://redirect.github.com/Kludex/starlette/pull/3298">Kludex/starlette#3298</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/Kludex/starlette/compare/1.2.0...1.2.1">https://github.com/Kludex/starlette/compare/1.2.0...1.2.1</a></p>
<h2>Version 1.2.0</h2>
<h2>What's Changed</h2>
<ul>
<li>Support httpx2 in the test client by <a
href="https://github.com/Kludex"><code>@​Kludex</code></a> in <a
href="https://redirect.github.com/Kludex/starlette/pull/3291">Kludex/starlette#3291</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/Kludex/starlette/compare/1.1.0...1.2.0">https://github.com/Kludex/starlette/compare/1.1.0...1.2.0</a></p>
<h2>Version 1.1.0</h2>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/Kludex/starlette/blob/main/docs/release-notes.md">starlette's
changelog</a>.</em></p>
<blockquote>
<h2>1.3.1 (June 12, 2026)</h2>
<h4>Fixed</h4>
<ul>
<li>Enforce <code>max_fields</code> and <code>max_part_size</code> in
<code>FormParser</code> <a
href="https://redirect.github.com/encode/starlette/pull/3329">#3329</a>.</li>
<li>Enforce <code>FormParser</code> limits in parser callbacks <a
href="https://redirect.github.com/encode/starlette/pull/3331">#3331</a>.</li>
</ul>
<h2>1.3.0 (June 11, 2026)</h2>
<h4>Added</h4>
<ul>
<li>Add <code>httpx2</code> to the <code>full</code> extra <a
href="https://redirect.github.com/encode/starlette/pull/3323">#3323</a>.</li>
<li>Annotate the <code>URLPath</code> <code>protocol</code> parameter
with <code>Literal</code> <a
href="https://redirect.github.com/encode/starlette/pull/3285">#3285</a>.</li>
</ul>
<h4>Fixed</h4>
<ul>
<li>Build <code>request.url</code> from structured components <a
href="https://redirect.github.com/encode/starlette/pull/3326">#3326</a>.</li>
<li>Clamp oversized suffix ranges in <code>FileResponse</code> <a
href="https://redirect.github.com/encode/starlette/pull/3307">#3307</a>.</li>
<li>Catch <code>OSError</code> alongside <code>MultiPartException</code>
when closing temp files <a
href="https://redirect.github.com/encode/starlette/pull/3191">#3191</a>.</li>
<li>Avoid collapsing exception groups raised from user code <a
href="https://redirect.github.com/encode/starlette/pull/2830">#2830</a>.</li>
<li>Use <code>removeprefix</code> to strip the weak <code>ETag</code>
indicator in <code>is_not_modified</code> <a
href="https://redirect.github.com/encode/starlette/pull/3193">#3193</a>.</li>
<li>Fix <code>IndexError</code> in <code>URL.replace()</code> on a URL
with no authority <a
href="https://redirect.github.com/encode/starlette/pull/3317">#3317</a>.</li>
<li>Adjust <code>testclient</code> typing and warnings <a
href="https://redirect.github.com/encode/starlette/pull/3322">#3322</a>.</li>
</ul>
<h2>1.2.1 (May 31, 2026)</h2>
<h4>Fixed</h4>
<ul>
<li>Use <code>httpx2</code> for type checking in the
<code>testclient</code> module <a
href="https://redirect.github.com/encode/starlette/pull/3304">#3304</a>.</li>
<li>Add assert error for <code>requires()</code> when the request
parameter is not a <code>Request</code> type <a
href="https://redirect.github.com/encode/starlette/pull/3298">#3298</a>.</li>
</ul>
<h2>1.2.0 (May 28, 2026)</h2>
<h4>Added</h4>
<ul>
<li>Support httpx2 in the test client <a
href="https://redirect.github.com/encode/starlette/pull/3291">#3291</a>.</li>
</ul>
<h2>1.1.0 (May 23, 2026)</h2>
<h4>Added</h4>
<ul>
<li>Use <code>&quot;application/octet-stream&quot;</code> as the
<code>FileResponse</code> media type fallback <a
href="https://redirect.github.com/encode/starlette/pull/3283">#3283</a>.</li>
</ul>
<h4>Fixed</h4>
<ul>
<li>Only dispatch standard HTTP verbs in <code>HTTPEndpoint</code> <a
href="https://redirect.github.com/encode/starlette/pull/3286">#3286</a>.</li>
<li>Reject absolute paths in <code>StaticFiles.lookup_path</code> <a
href="https://redirect.github.com/encode/starlette/pull/3287">#3287</a>.</li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/Kludex/starlette/commit/8ebffd0678570ddd5d5bb11c6f3c3c7fd4682ab9"><code>8ebffd0</code></a>
Version 1.3.1 (<a
href="https://redirect.github.com/Kludex/starlette/issues/3330">#3330</a>)</li>
<li><a
href="https://github.com/Kludex/starlette/commit/25b8e179d8d7ed86769c02f648772dd5fb43dc3c"><code>25b8e17</code></a>
Enforce <code>FormParser</code> limits in parser callbacks (<a
href="https://redirect.github.com/Kludex/starlette/issues/3331">#3331</a>)</li>
<li><a
href="https://github.com/Kludex/starlette/commit/dba1c4babc4f99ad2622bb913d87045775dda735"><code>dba1c4b</code></a>
Enforce <code>max_fields</code> and <code>max_part_size</code> in
<code>FormParser</code> (<a
href="https://redirect.github.com/Kludex/starlette/issues/3329">#3329</a>)</li>
<li><a
href="https://github.com/Kludex/starlette/commit/45e51dcf99f3a270b0bcec1aec5410b4345863a9"><code>45e51dc</code></a>
Use <code>StarletteDeprecationWarning</code> instead of
<code>DeprecationWarning</code> (<a
href="https://redirect.github.com/Kludex/starlette/issues/3119">#3119</a>)</li>
<li><a
href="https://github.com/Kludex/starlette/commit/5f8610c386e13de1d80d36efa961e1486a1d2d01"><code>5f8610c</code></a>
Version 1.3.0 (<a
href="https://redirect.github.com/Kludex/starlette/issues/3327">#3327</a>)</li>
<li><a
href="https://github.com/Kludex/starlette/commit/167b5850e809f38b27fbfed62d58bf6442855975"><code>167b585</code></a>
Build <code>request.url</code> from structured components (<a
href="https://redirect.github.com/Kludex/starlette/issues/3326">#3326</a>)</li>
<li><a
href="https://github.com/Kludex/starlette/commit/37309255b4c1b9c381a2d24a1eaf83100984a16a"><code>3730925</code></a>
Use <code>removeprefix</code> to strip weak ETag indicator in
<code>is_not_modified</code> (<a
href="https://redirect.github.com/Kludex/starlette/issues/3193">#3193</a>)</li>
<li><a
href="https://github.com/Kludex/starlette/commit/e6f7ad1ab85efb27ab7910d8007b3f4531f7b083"><code>e6f7ad1</code></a>
avoid collapsing exception groups from user code (<a
href="https://redirect.github.com/Kludex/starlette/issues/2830">#2830</a>)</li>
<li><a
href="https://github.com/Kludex/starlette/commit/115228fcdca0e0ef5bf4a95a40ddce5a9fced428"><code>115228f</code></a>
Annotate URLPath protocol parameter with Literal (<a
href="https://redirect.github.com/Kludex/starlette/issues/3285">#3285</a>)</li>
<li><a
href="https://github.com/Kludex/starlette/commit/113f193a34353c9153857028c1074351d22fad07"><code>113f193</code></a>
docs: replace inline ASGI server list with link to canonical implemen…
(<a
href="https://redirect.github.com/Kludex/starlette/issues/3204">#3204</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/Kludex/starlette/compare/1.0.1...1.3.1">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=starlette&package-manager=uv&previous-version=1.0.1&new-version=1.3.1)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/microsoft/RAMPART/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [cryptography](https://github.com/pyca/cryptography) from 48.0.0
to 48.0.1.
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst">cryptography's
changelog</a>.</em></p>
<blockquote>
<p>48.0.1 - 2026-06-09</p>
<pre><code>
* Updated Windows, macOS, and Linux wheels to be compiled with OpenSSL
4.0.1.
<p>.. _v48-0-0:<br />
</code></pre></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/pyca/cryptography/commit/de987ce48ccfeb1abca41efa23b2bf73ec704f74"><code>de987ce</code></a>
48.0.1 version bump and changelog (<a
href="https://redirect.github.com/pyca/cryptography/issues/14996">#14996</a>)</li>
<li>See full diff in <a
href="https://github.com/pyca/cryptography/compare/48.0.0...48.0.1">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=cryptography&package-manager=uv&previous-version=48.0.0&new-version=48.0.1)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/microsoft/RAMPART/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [pypdf](https://github.com/py-pdf/pypdf) from 6.12.0 to 6.13.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/py-pdf/pypdf/releases">pypdf's
releases</a>.</em></p>
<blockquote>
<h2>Version 6.13.0, 2026-06-05</h2>
<h2>What's new</h2>
<h3>Security (SEC)</h3>
<ul>
<li>Avoid infinite loops for outlines and text extraction (<a
href="https://redirect.github.com/py-pdf/pypdf/issues/3830">#3830</a>)
by <a
href="https://github.com/stefan6419846"><code>@​stefan6419846</code></a></li>
</ul>
<h3>New Features (ENH)</h3>
<ul>
<li>Add Japanese predefined CMaps (<a
href="https://redirect.github.com/py-pdf/pypdf/issues/3800">#3800</a>)
by <a
href="https://github.com/yasuhiroiwaki"><code>@​yasuhiroiwaki</code></a></li>
<li>Font: Collect all character widths, not only those that can be
unicode mapped (<a
href="https://redirect.github.com/py-pdf/pypdf/issues/3798">#3798</a>)
by <a href="https://github.com/PJBrs"><code>@​PJBrs</code></a></li>
</ul>
<h3>Robustness (ROB)</h3>
<ul>
<li>Recover a corrupt trailing startxref pointer (closes <a
href="https://redirect.github.com/py-pdf/pypdf/issues/3238">#3238</a>)
(<a
href="https://redirect.github.com/py-pdf/pypdf/issues/3826">#3826</a>)
by <a href="https://github.com/gaoflow"><code>@​gaoflow</code></a></li>
<li>Handle /Pages node without /Kids during flattening (<a
href="https://redirect.github.com/py-pdf/pypdf/issues/3825">#3825</a>)
by <a href="https://github.com/gaoflow"><code>@​gaoflow</code></a></li>
<li>Accept inline image EI marker at the end of a content stream (<a
href="https://redirect.github.com/py-pdf/pypdf/issues/3827">#3827</a>)
by <a href="https://github.com/gaoflow"><code>@​gaoflow</code></a></li>
</ul>
<h3>Maintenance (MAINT)</h3>
<ul>
<li>Type the always-raising deprecation helpers as <code>NoReturn</code>
(<a
href="https://redirect.github.com/py-pdf/pypdf/issues/3819">#3819</a>)
by <a
href="https://github.com/estelledc"><code>@​estelledc</code></a></li>
</ul>
<p><a
href="https://github.com/py-pdf/pypdf/compare/6.12.2...6.13.0">Full
Changelog</a></p>
<h2>Version 6.12.2, 2026-05-26</h2>
<h2>What's new</h2>
<h3>Security (SEC)</h3>
<ul>
<li>Optimize _decode_png_prediction regarding memory and speed (<a
href="https://redirect.github.com/py-pdf/pypdf/issues/3806">#3806</a>)
by <a
href="https://github.com/stefan6419846"><code>@​stefan6419846</code></a></li>
<li>Improve loop control in text extraction (<a
href="https://redirect.github.com/py-pdf/pypdf/issues/3805">#3805</a>)
by <a
href="https://github.com/stefan6419846"><code>@​stefan6419846</code></a></li>
</ul>
<p><a
href="https://github.com/py-pdf/pypdf/compare/6.12.1...6.12.2">Full
Changelog</a></p>
<h2>Version 6.12.1, 2026-05-22</h2>
<h2>What's new</h2>
<h3>Security (SEC)</h3>
<ul>
<li>Limit input size and element count for XMP metadata (<a
href="https://redirect.github.com/py-pdf/pypdf/issues/3796">#3796</a>)
by <a
href="https://github.com/stefan6419846"><code>@​stefan6419846</code></a></li>
</ul>
<h3>Robustness (ROB)</h3>
<ul>
<li>Prevent cyclic parent hierarchies for inherited dictionaries (<a
href="https://redirect.github.com/py-pdf/pypdf/issues/3795">#3795</a>)
by <a
href="https://github.com/stefan6419846"><code>@​stefan6419846</code></a></li>
<li>Deal with invalid first code in LZW decoder (<a
href="https://redirect.github.com/py-pdf/pypdf/issues/3794">#3794</a>)
by <a
href="https://github.com/stefan6419846"><code>@​stefan6419846</code></a></li>
</ul>
<p><a
href="https://github.com/py-pdf/pypdf/compare/6.12.0...6.12.1">Full
Changelog</a></p>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/py-pdf/pypdf/blob/main/CHANGELOG.md">pypdf's
changelog</a>.</em></p>
<blockquote>
<h2>Version 6.13.0, 2026-06-05</h2>
<h3>Security (SEC)</h3>
<ul>
<li>Avoid infinite loops for outlines and text extraction (<a
href="https://redirect.github.com/py-pdf/pypdf/issues/3830">#3830</a>)</li>
</ul>
<h3>New Features (ENH)</h3>
<ul>
<li>Add Japanese predefined CMaps (<a
href="https://redirect.github.com/py-pdf/pypdf/issues/3800">#3800</a>)</li>
<li>Font: Collect all character widths, not only those that can be
unicode mapped (<a
href="https://redirect.github.com/py-pdf/pypdf/issues/3798">#3798</a>)</li>
</ul>
<h3>Robustness (ROB)</h3>
<ul>
<li>Recover a corrupt trailing startxref pointer (closes <a
href="https://redirect.github.com/py-pdf/pypdf/issues/3238">#3238</a>)
(<a
href="https://redirect.github.com/py-pdf/pypdf/issues/3826">#3826</a>)</li>
<li>Handle /Pages node without /Kids during flattening (<a
href="https://redirect.github.com/py-pdf/pypdf/issues/3825">#3825</a>)</li>
<li>Accept inline image EI marker at the end of a content stream (<a
href="https://redirect.github.com/py-pdf/pypdf/issues/3827">#3827</a>)</li>
</ul>
<h3>Maintenance (MAINT)</h3>
<ul>
<li>Type the always-raising deprecation helpers as <code>NoReturn</code>
(<a
href="https://redirect.github.com/py-pdf/pypdf/issues/3819">#3819</a>)</li>
</ul>
<p><a
href="https://github.com/py-pdf/pypdf/compare/6.12.2...6.13.0">Full
Changelog</a></p>
<h2>Version 6.12.2, 2026-05-26</h2>
<h3>Security (SEC)</h3>
<ul>
<li>Optimize _decode_png_prediction regarding memory and speed (<a
href="https://redirect.github.com/py-pdf/pypdf/issues/3806">#3806</a>)</li>
<li>Improve loop control in text extraction (<a
href="https://redirect.github.com/py-pdf/pypdf/issues/3805">#3805</a>)</li>
</ul>
<p><a
href="https://github.com/py-pdf/pypdf/compare/6.12.1...6.12.2">Full
Changelog</a></p>
<h2>Version 6.12.1, 2026-05-22</h2>
<h3>Security (SEC)</h3>
<ul>
<li>Limit input size and element count for XMP metadata (<a
href="https://redirect.github.com/py-pdf/pypdf/issues/3796">#3796</a>)</li>
</ul>
<h3>Robustness (ROB)</h3>
<ul>
<li>Prevent cyclic parent hierarchies for inherited dictionaries (<a
href="https://redirect.github.com/py-pdf/pypdf/issues/3795">#3795</a>)</li>
<li>Deal with invalid first code in LZW decoder (<a
href="https://redirect.github.com/py-pdf/pypdf/issues/3794">#3794</a>)</li>
</ul>
<p><a
href="https://github.com/py-pdf/pypdf/compare/6.12.0...6.12.1">Full
Changelog</a></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/py-pdf/pypdf/commit/98afb457f1ab423c6f07975ccc418cbabc40665d"><code>98afb45</code></a>
REL: 6.13.0</li>
<li><a
href="https://github.com/py-pdf/pypdf/commit/68822ded066f1bd21113b177e039f7930d57b6ff"><code>68822de</code></a>
SEC: Avoid infinite loops for outlines and text extraction (<a
href="https://redirect.github.com/py-pdf/pypdf/issues/3830">#3830</a>)</li>
<li><a
href="https://github.com/py-pdf/pypdf/commit/ddd34856173be64950759c0b8c19723fedd69b95"><code>ddd3485</code></a>
ROB: Recover a corrupt trailing startxref pointer (closes <a
href="https://redirect.github.com/py-pdf/pypdf/issues/3238">#3238</a>)
(<a
href="https://redirect.github.com/py-pdf/pypdf/issues/3826">#3826</a>)</li>
<li><a
href="https://github.com/py-pdf/pypdf/commit/5cebe5ed13da5df593dc4171b236e5adc5e201df"><code>5cebe5e</code></a>
ROB: Handle /Pages node without /Kids during flattening (<a
href="https://redirect.github.com/py-pdf/pypdf/issues/3825">#3825</a>)</li>
<li><a
href="https://github.com/py-pdf/pypdf/commit/be173fe0d4d403ee9b09b580ef3269e5805c8d5f"><code>be173fe</code></a>
ROB: Accept inline image EI marker at the end of a content stream (<a
href="https://redirect.github.com/py-pdf/pypdf/issues/3827">#3827</a>)</li>
<li><a
href="https://github.com/py-pdf/pypdf/commit/e0d443c552bc395bf3407f834a1204890006b489"><code>e0d443c</code></a>
ROB: Handle object numbers above 2**31 in _make_crypt_filter (<a
href="https://redirect.github.com/py-pdf/pypdf/issues/3824">#3824</a>)</li>
<li><a
href="https://github.com/py-pdf/pypdf/commit/dad0f5e66a7b850092a42ea29baaed390f417a0d"><code>dad0f5e</code></a>
ROB: Stop reading past truncated /Nums in get_label_from_nums (<a
href="https://redirect.github.com/py-pdf/pypdf/issues/3823">#3823</a>)</li>
<li><a
href="https://github.com/py-pdf/pypdf/commit/52545c5d3fdfef11c8c8d33d8378cab24698aaec"><code>52545c5</code></a>
ROB: Pad truncated data in bits2byte instead of reading out of bounds
(<a
href="https://redirect.github.com/py-pdf/pypdf/issues/3820">#3820</a>)</li>
<li><a
href="https://github.com/py-pdf/pypdf/commit/56e078441bf51580d3633b4e278a3eea20b2f85a"><code>56e0784</code></a>
ENH: Add Japanese predefined CMaps (<a
href="https://redirect.github.com/py-pdf/pypdf/issues/3800">#3800</a>)</li>
<li><a
href="https://github.com/py-pdf/pypdf/commit/0d048eebbeae29db28f30a3d51338edd07f56d16"><code>0d048ee</code></a>
MAINT: Add ABC as a base class (<a
href="https://redirect.github.com/py-pdf/pypdf/issues/3818">#3818</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/py-pdf/pypdf/compare/6.12.0...6.13.0">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=pypdf&package-manager=uv&previous-version=6.12.0&new-version=6.13.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/microsoft/RAMPART/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=aiohttp&package-manager=uv&previous-version=3.14.0&new-version=3.14.1)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts
page](https://github.com/microsoft/RAMPART/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps the minor-and-patch group with 2 updates:
[pytest](https://github.com/pytest-dev/pytest) and
[ruff](https://github.com/astral-sh/ruff).

Updates `pytest` from 9.0.3 to 9.1.0
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/pytest-dev/pytest/releases">pytest's
releases</a>.</em></p>
<blockquote>
<h2>9.1.0</h2>
<h1>pytest 9.1.0 (2026-06-13)</h1>
<h2>Removals and backward incompatible breaking changes</h2>
<ul>
<li>
<p><a
href="https://redirect.github.com/pytest-dev/pytest/issues/14533">#14533</a>:
When using <code>--doctest-modules</code>, autouse fixtures with
<code>module</code>, <code>package</code> or <code>session</code> scope
that are defined inline in Python test modules (not plugins or
conftests) will now possibly execute twice.</p>
<p>If this is undesirable, move the fixture definition to a
<code>conftest.py</code> file if possible.</p>
<p>Technical explanation for those interested:
When using <!-- raw HTML omitted -->--doctest-modules<!-- raw HTML
omitted -->, pytest possibly collects Python modules twice, once as
<code>pytest.Module</code> and once as a <code>DoctestModule</code>
(depending on the configuration).
Due to improvements in pytest's fixture implementation, if e.g. the
<code>DoctestModule</code> collects a fixture, it is now visible to it
only, and not to the <code>Module</code>.
This means that both need to register the fixtures independently.</p>
</li>
</ul>
<h2>Deprecations (removal in next major release)</h2>
<ul>
<li>
<p><a
href="https://redirect.github.com/pytest-dev/pytest/issues/10819">#10819</a>:
Added a deprecation warning for class-scoped fixtures defined as
instance methods (without <code>@classmethod</code>). Such fixtures set
attributes on a different instance than the test methods use, leading to
unexpected behavior. Use <code>@classmethod</code> decorator instead --
by <code>yastcher</code>.</p>
<p>See <code>10819</code> and <code>14011</code>.</p>
</li>
<li>
<p><a
href="https://redirect.github.com/pytest-dev/pytest/issues/12882">#12882</a>:
Calling <code>request.getfixturevalue()
&lt;pytest.FixtureRequest.getfixturevalue&gt;</code> during teardown to
request a fixture that was not already requested is now deprecated and
will become an error in pytest 10.</p>
<p>See <code>dynamic-fixture-request-during-teardown</code> for
details.</p>
</li>
<li>
<p><a
href="https://redirect.github.com/pytest-dev/pytest/issues/13409">#13409</a>:
Using non-<code>~collections.abc.Collection</code> iterables (such as
generators, iterators, or custom iterable objects) for the
<code>argvalues</code> parameter in <code>@pytest.mark.parametrize
&lt;pytest.mark.parametrize ref&gt;</code> and
<code>metafunc.parametrize &lt;pytest.Metafunc.parametrize&gt;</code> is
now deprecated.</p>
<p>These iterables get exhausted after the first iteration,
leading to tests getting unexpectedly skipped in cases such as running
<code>pytest.main()</code> multiple times,
using class-level parametrize decorators,
or collecting tests multiple times.</p>
<p>See <code>parametrize-iterators</code> for details and
suggestions.</p>
</li>
<li>
<p><a
href="https://redirect.github.com/pytest-dev/pytest/issues/13946">#13946</a>:
The private <code>config.inicfg</code> attribute is now deprecated.
Use <code>config.getini() &lt;pytest.Config.getini&gt;</code> to access
configuration values instead.</p>
<p>See <code>config-inicfg</code> for more details.</p>
</li>
<li>
<p><a
href="https://redirect.github.com/pytest-dev/pytest/issues/14004">#14004</a>:
Passing <code>baseid</code> to <code>~pytest.FixtureDef</code> or
<code>nodeid</code> strings to fixture registration APIs is now
deprecated. These are internal pytest APIs that are used by some
plugins.</p>
<p>Use the <code>node</code> parameter instead for fixture scoping. This
enables more robust node-based
matching instead of string prefix matching.
If you've used <code>nodeid=None</code>, pass <code>node=session</code>
instead.</p>
<p>This will be removed in pytest 10.</p>
</li>
<li>
<p><a
href="https://redirect.github.com/pytest-dev/pytest/issues/14335">#14335</a>:
The method of configuring hooks using markers, deprecated since pytest
7.2, is now scheduled to be removed in pytest 10.
See <code>hook-markers</code> for more details.</p>
</li>
<li>
<p><a
href="https://redirect.github.com/pytest-dev/pytest/issues/14434">#14434</a>:
The <code>--pastebin</code> option is now deprecated.</p>
</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/pytest-dev/pytest/commit/b2522cf0b11fb33ecc1f4895fa1dffbb9252a63d"><code>b2522cf</code></a>
Prepare release version 9.1.0</li>
<li><a
href="https://github.com/pytest-dev/pytest/commit/368d2fca78e86ac79ec269bb078fcb1259a94fed"><code>368d2fc</code></a>
[refactor] Tighten <code>SetComparisonFunction</code> to
<code>Iterator[str]</code> (<a
href="https://redirect.github.com/pytest-dev/pytest/issues/14587">#14587</a>)</li>
<li><a
href="https://github.com/pytest-dev/pytest/commit/ff77cd8b66b43a88c26ca54384bbcab72d079497"><code>ff77cd8</code></a>
[refactor] Make base assertion comparisons return an iterator instead of
a li...</li>
<li><a
href="https://github.com/pytest-dev/pytest/commit/0d8491a4ecf971800de0479ef55c7f5292c54937"><code>0d8491a</code></a>
build(deps): Bump actions/stale from 10.2.0 to 10.3.0</li>
<li><a
href="https://github.com/pytest-dev/pytest/commit/4a809d9c892f6abb5ba92b77b06f1dd878f4660a"><code>4a809d9</code></a>
Merge pull request <a
href="https://redirect.github.com/pytest-dev/pytest/issues/14568">#14568</a>
from pytest-dev/register-fixture</li>
<li><a
href="https://github.com/pytest-dev/pytest/commit/5dfa38541becfb77d0f52cac4cc8cce71849ab61"><code>5dfa385</code></a>
Fix recursion traceback test to cover all styles (<a
href="https://redirect.github.com/pytest-dev/pytest/issues/14582">#14582</a>)</li>
<li><a
href="https://github.com/pytest-dev/pytest/commit/f52ff0c1778c15038cf2bbb00b7668dac674cc26"><code>f52ff0c</code></a>
Add <code>pytest.register_fixture</code></li>
<li><a
href="https://github.com/pytest-dev/pytest/commit/a8ac094e80df788aec844794170b126eab0be7a4"><code>a8ac094</code></a>
Merge pull request <a
href="https://redirect.github.com/pytest-dev/pytest/issues/14567">#14567</a>
from pytest-dev/more-visibility-deprecate</li>
<li><a
href="https://github.com/pytest-dev/pytest/commit/e5620cd21ec62f5a5f9a5141a3c76fb3953729b6"><code>e5620cd</code></a>
[pre-commit.ci] pre-commit autoupdate (<a
href="https://redirect.github.com/pytest-dev/pytest/issues/14577">#14577</a>)</li>
<li><a
href="https://github.com/pytest-dev/pytest/commit/2ce9c6d94eb691ea4da7f91f330602cbb67a6daf"><code>2ce9c6d</code></a>
Merge pull request <a
href="https://redirect.github.com/pytest-dev/pytest/issues/14540">#14540</a>
from minbang930/fix-14533-doctest-module-fixtures</li>
<li>Additional commits viewable in <a
href="https://github.com/pytest-dev/pytest/compare/9.0.3...9.1.0">compare
view</a></li>
</ul>
</details>
<br />

Updates `ruff` from 0.15.16 to 0.15.17
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/astral-sh/ruff/releases">ruff's
releases</a>.</em></p>
<blockquote>
<h2>0.15.17</h2>
<h2>Release Notes</h2>
<p>Released on 2026-06-11.</p>
<h3>Preview features</h3>
<ul>
<li>Allow human-readable names in suppression comments (<a
href="https://redirect.github.com/astral-sh/ruff/pull/25614">#25614</a>)</li>
<li>Fix handling of <code>ignore</code> comments within a
<code>disable</code>/<code>enable</code> pair (<a
href="https://redirect.github.com/astral-sh/ruff/pull/25845">#25845</a>)</li>
<li>Prioritize human-readable names in CLI output (<a
href="https://redirect.github.com/astral-sh/ruff/pull/25869">#25869</a>)</li>
<li>Respect diagnostic start and parent ranges and trailing comments in
<code>ruff:ignore</code> suppressions (<a
href="https://redirect.github.com/astral-sh/ruff/pull/25673">#25673</a>)</li>
<li>[<code>flake8-async</code>] Add <code>trio.as_safe_channel</code> to
safe decorators (<code>ASYNC119</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/25775">#25775</a>)</li>
<li>[<code>flake8-pytest-style</code>] Also check
<code>pytest_asyncio</code> fixtures (<a
href="https://redirect.github.com/astral-sh/ruff/pull/25375">#25375</a>)</li>
<li>[<code>ruff</code>] Ban <code>pytest</code> autouse fixtures
(<code>RUF076</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/25477">#25477</a>)</li>
<li>[<code>pyupgrade</code>] Add <code>from __future__ import
annotations</code> automatically (<code>UP007</code>,
<code>UP045</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/23259">#23259</a>)</li>
</ul>
<h3>Bug fixes</h3>
<ul>
<li>Fix diagnostic when <code>ruff:enable</code> or
<code>ruff:disable</code> appears where <code>ruff:ignore</code> is
expected (<a
href="https://redirect.github.com/astral-sh/ruff/pull/25700">#25700</a>)</li>
<li>[<code>pyupgrade</code>] Preserve leading empty literals to avoid
syntax errors (<code>UP032</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/25491">#25491</a>)</li>
</ul>
<h3>Rule changes</h3>
<ul>
<li>[<code>flake8-pytest-style</code>] Clarify diagnostic message for
single parameters (<code>PT007</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/25592">#25592</a>)</li>
<li>[<code>numpy</code>] Drop autofix for <code>np.in1d</code>
(<code>NPY201</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/25612">#25612</a>)</li>
<li>[<code>pylint</code>] Exempt Python version comparisons
(<code>PLR2004</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/25743">#25743</a>)</li>
</ul>
<h3>Performance</h3>
<ul>
<li>Reserve AST <code>Vec</code>s with correct capacity for common cases
(<a
href="https://redirect.github.com/astral-sh/ruff/pull/25451">#25451</a>)</li>
</ul>
<h3>Formatter</h3>
<ul>
<li>Preserve whitespace for Quarto cell option comments (<a
href="https://redirect.github.com/astral-sh/ruff/pull/25641">#25641</a>)</li>
</ul>
<h3>CLI</h3>
<ul>
<li>Allow rule names in <code>ruff rule</code> (<a
href="https://redirect.github.com/astral-sh/ruff/pull/25640">#25640</a>)</li>
</ul>
<h3>Other changes</h3>
<ul>
<li>Fix playground diagnostics scrollbars (<a
href="https://redirect.github.com/astral-sh/ruff/pull/25642">#25642</a>)</li>
</ul>
<h3>Contributors</h3>
<ul>
<li><a
href="https://github.com/SuryanshSS1011"><code>@​SuryanshSS1011</code></a></li>
<li><a
href="https://github.com/anishgirianish"><code>@​anishgirianish</code></a></li>
<li><a
href="https://github.com/romero-deshaw"><code>@​romero-deshaw</code></a></li>
<li><a
href="https://github.com/karlhillx"><code>@​karlhillx</code></a></li>
<li><a href="https://github.com/carljm"><code>@​carljm</code></a></li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md">ruff's
changelog</a>.</em></p>
<blockquote>
<h2>0.15.17</h2>
<p>Released on 2026-06-11.</p>
<h3>Preview features</h3>
<ul>
<li>Allow human-readable names in suppression comments (<a
href="https://redirect.github.com/astral-sh/ruff/pull/25614">#25614</a>)</li>
<li>Fix handling of <code>ignore</code> comments within a
<code>disable</code>/<code>enable</code> pair (<a
href="https://redirect.github.com/astral-sh/ruff/pull/25845">#25845</a>)</li>
<li>Prioritize human-readable names in CLI output (<a
href="https://redirect.github.com/astral-sh/ruff/pull/25869">#25869</a>)</li>
<li>Respect diagnostic start and parent ranges and trailing comments in
<code>ruff:ignore</code> suppressions (<a
href="https://redirect.github.com/astral-sh/ruff/pull/25673">#25673</a>)</li>
<li>[<code>flake8-async</code>] Add <code>trio.as_safe_channel</code> to
safe decorators (<code>ASYNC119</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/25775">#25775</a>)</li>
<li>[<code>flake8-pytest-style</code>] Also check
<code>pytest_asyncio</code> fixtures (<a
href="https://redirect.github.com/astral-sh/ruff/pull/25375">#25375</a>)</li>
<li>[<code>ruff</code>] Ban <code>pytest</code> autouse fixtures
(<code>RUF076</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/25477">#25477</a>)</li>
<li>[<code>pyupgrade</code>] Add <code>from __future__ import
annotations</code> automatically (<code>UP007</code>,
<code>UP045</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/23259">#23259</a>)</li>
</ul>
<h3>Bug fixes</h3>
<ul>
<li>Fix diagnostic when <code>ruff:enable</code> or
<code>ruff:disable</code> appears where <code>ruff:ignore</code> is
expected (<a
href="https://redirect.github.com/astral-sh/ruff/pull/25700">#25700</a>)</li>
<li>[<code>pyupgrade</code>] Preserve leading empty literals to avoid
syntax errors (<code>UP032</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/25491">#25491</a>)</li>
</ul>
<h3>Rule changes</h3>
<ul>
<li>[<code>flake8-pytest-style</code>] Clarify diagnostic message for
single parameters (<code>PT007</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/25592">#25592</a>)</li>
<li>[<code>numpy</code>] Drop autofix for <code>np.in1d</code>
(<code>NPY201</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/25612">#25612</a>)</li>
<li>[<code>pylint</code>] Exempt Python version comparisons
(<code>PLR2004</code>) (<a
href="https://redirect.github.com/astral-sh/ruff/pull/25743">#25743</a>)</li>
</ul>
<h3>Performance</h3>
<ul>
<li>Reserve AST <code>Vec</code>s with correct capacity for common cases
(<a
href="https://redirect.github.com/astral-sh/ruff/pull/25451">#25451</a>)</li>
</ul>
<h3>Formatter</h3>
<ul>
<li>Preserve whitespace for Quarto cell option comments (<a
href="https://redirect.github.com/astral-sh/ruff/pull/25641">#25641</a>)</li>
</ul>
<h3>CLI</h3>
<ul>
<li>Allow rule names in <code>ruff rule</code> (<a
href="https://redirect.github.com/astral-sh/ruff/pull/25640">#25640</a>)</li>
</ul>
<h3>Other changes</h3>
<ul>
<li>Fix playground diagnostics scrollbars (<a
href="https://redirect.github.com/astral-sh/ruff/pull/25642">#25642</a>)</li>
</ul>
<h3>Contributors</h3>
<ul>
<li><a
href="https://github.com/SuryanshSS1011"><code>@​SuryanshSS1011</code></a></li>
<li><a
href="https://github.com/anishgirianish"><code>@​anishgirianish</code></a></li>
<li><a
href="https://github.com/romero-deshaw"><code>@​romero-deshaw</code></a></li>
<li><a
href="https://github.com/karlhillx"><code>@​karlhillx</code></a></li>
<li><a href="https://github.com/carljm"><code>@​carljm</code></a></li>
<li><a href="https://github.com/ntBre"><code>@​ntBre</code></a></li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/astral-sh/ruff/commit/7c645a9a1be8258b9f9e005208a55a0b7e8e18f0"><code>7c645a9</code></a>
Bump 0.15.17 (<a
href="https://redirect.github.com/astral-sh/ruff/issues/25872">#25872</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/f381eb1d54997cfbfa6f63c15dd2d760f70e85e1"><code>f381eb1</code></a>
Prioritize human-readable names in CLI output (<a
href="https://redirect.github.com/astral-sh/ruff/issues/25869">#25869</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/b9b4546ad27d8fd12acc979e312a3ee25ef8ac4f"><code>b9b4546</code></a>
Minor workflow simplification (<a
href="https://redirect.github.com/astral-sh/ruff/issues/25870">#25870</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/1e77ba02570bbe4952f7cf0e4ebb97b8b4e6e58d"><code>1e77ba0</code></a>
[ty] Move <code>PreformattedBlockScanner</code> to format-agnostic
location. (<a
href="https://redirect.github.com/astral-sh/ruff/issues/25856">#25856</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/6f2b772285aa478e8aee3f4b54dfa9ce903a0ce1"><code>6f2b772</code></a>
[ty] Preserve nominal type of enum.property instances (<a
href="https://redirect.github.com/astral-sh/ruff/issues/25849">#25849</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/be4777c8766a38d405a69948989cdfa2674adaae"><code>be4777c</code></a>
[ty] Fix site-package error when multiple versions of pythons are
installed i...</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/53f6ff7200983a67778fcba7106019d2615846f0"><code>53f6ff7</code></a>
Allow human-readable names in suppression comments (<a
href="https://redirect.github.com/astral-sh/ruff/issues/25614">#25614</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/67403254192f3541bd7e1027c8f1805cf7a9c2be"><code>6740325</code></a>
[ty] Restrict uncached raw signature access (<a
href="https://redirect.github.com/astral-sh/ruff/issues/25866">#25866</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/970b1bf4a4d83359c9e28cad5f127ebbd6769682"><code>970b1bf</code></a>
Auto-update snapshots when syncing typeshed (<a
href="https://redirect.github.com/astral-sh/ruff/issues/25841">#25841</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff/commit/0785793750fd6c74124a189259822f1a28eb5c13"><code>0785793</code></a>
Fix handling of <code>ignore</code> comments within a
<code>disable</code>/<code>enable</code> pair (<a
href="https://redirect.github.com/astral-sh/ruff/issues/25845">#25845</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/astral-sh/ruff/compare/0.15.16...0.15.17">compare
view</a></li>
</ul>
</details>
<br />


Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore <dependency name> major version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's major version (unless you unignore this specific
dependency's major version or upgrade to it yourself)
- `@dependabot ignore <dependency name> minor version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's minor version (unless you unignore this specific
dependency's minor version or upgrade to it yourself)
- `@dependabot ignore <dependency name>` will close this group update PR
and stop Dependabot creating any more for the specific dependency
(unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore <dependency name>` will remove all of the ignore
conditions of the specified dependency
- `@dependabot unignore <dependency name> <ignore condition>` will
remove the ignore condition of the specified dependency and ignore
conditions


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
….16 to 0.15.17 (microsoft#93)

Bumps
[https://github.com/astral-sh/ruff-pre-commit](https://github.com/astral-sh/ruff-pre-commit)
from v0.15.16 to 0.15.17. This release includes the previously tagged
commit.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/astral-sh/ruff-pre-commit/releases">https://github.com/astral-sh/ruff-pre-commit's
releases</a>.</em></p>
<blockquote>
<h2>v0.15.17</h2>
<p>See: <a
href="https://github.com/astral-sh/ruff/releases/tag/0.15.17">https://github.com/astral-sh/ruff/releases/tag/0.15.17</a></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/astral-sh/ruff-pre-commit/commit/3b3f7c3f57fe9925356faf5fe6230835138be230"><code>3b3f7c3</code></a>
Mirror: 0.15.17</li>
<li><a
href="https://github.com/astral-sh/ruff-pre-commit/commit/99e6029223026d6fa76813c17277c704c11db2a0"><code>99e6029</code></a>
Various hardenings (<a
href="https://redirect.github.com/astral-sh/ruff-pre-commit/issues/170">#170</a>)</li>
<li><a
href="https://github.com/astral-sh/ruff-pre-commit/commit/f69224b9a09036deb0588511bbec7ee97a8324a8"><code>f69224b</code></a>
Bump the github-actions group with 2 updates (<a
href="https://redirect.github.com/astral-sh/ruff-pre-commit/issues/169">#169</a>)</li>
<li>See full diff in <a
href="https://github.com/astral-sh/ruff-pre-commit/compare/22f0422809455ec89ffdcf5a00170ba816e42ddb...3b3f7c3f57fe9925356faf5fe6230835138be230">compare
view</a></li>
</ul>
</details>
<br />


Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
## Description

Adds explicit Dependabot `security-minor-and-patch` groups for
configured ecosystems so minor and patch security updates can be grouped
separately from normal version updates. Mirrors microsoft/PyRIT#2018.

This follows up on the recent separate Dependabot security PRs microsoft#85, microsoft#87,
microsoft#88, microsoft#89, and microsoft#90. Those PRs were opened one dependency at a time
because Dependabot `groups.applies-to` defaults to `version-updates`
when omitted. GitHub's Dependabot options reference documents that
`applies-to` supports both `version-updates` and `security-updates`.

The existing `uv` `minor-and-patch` group is preserved for normal
version updates. This change adds a matching security-only minor/patch
group for `uv`, plus security-only minor/patch groups for
`github-actions` and `pre-commit`.

Major security updates are intentionally left ungrouped so higher-risk
updates remain isolated for review.

References:

- Dependabot `groups` option:
https://docs.github.com/en/code-security/reference/supply-chain-security/dependabot-options-reference#groups--
- Dependabot `applies-to` behavior:
https://docs.github.com/en/code-security/reference/supply-chain-security/dependabot-options-reference#groups--
- Dependabot security updates:
https://docs.github.com/en/code-security/dependabot/dependabot-security-updates

## Breaking changes

None.

## Checklist

- [X] `pre-commit run --all-files` passes
- [ ] Tests added or updated for changes
- [ ] Documentation updated
## Description

Migrate type checker from pyright to ty to align with PyRIT
(microsoft/PyRIT#1319).

### Typing fixes prompted by ty

**`InjectionHandle` and `Session` now inherit
`AbstractAsyncContextManager`** (rampart/core/injection.py,
rampart/core/adapter.py). ty rejected
`AsyncExitStack.enter_async_context(handle)` because a `Protocol` with
`__aenter__ -> Self` doesn't unify with
`AbstractAsyncContextManager[Handle, _ExitT_co]`'s covariant `_T_co`
without an explicit subtype relationship.

```python
class InjectionHandle(AbstractAsyncContextManager["InjectionHandle", None], Protocol):
class Session(AbstractAsyncContextManager["Session"], Protocol):
```

Notes:
- typeshed declares `AbstractAsyncContextManager` as both `ABC` and
`Protocol`
([stdlib/contextlib.pyi](https://github.com/python/typeshed/blob/main/stdlib/contextlib.pyi))
- it's on the type-checker allowlist, so a `Protocol` may legally
inherit from it.
- Base order matters for C3 linearization: the ABC must precede
`Protocol`.
- Generic args `[InjectionHandle, None]`: `_T_co` = `__aenter__` return;
`_ExitT_co` = `None` because cleanup never suppresses exceptions
(`closing`/`nullcontext` family, not `suppress`).
- `__aexit__` aligned with stdlib conventions: positional-only `/`,
canonical `exc_value`/`traceback` names.

**`Attacks.xpia` and `coerce_driver` narrowing reordered**
(rampart/attacks/__init__.py, rampart/drivers/_utils.py). ty cannot yet
narrow element type through `isinstance(x, list)` over `list[A] |
list[B]`. Reordering to check the protocol/scalar branch first
eliminates the need for `cast` and `# type: ignore`.

**`ResponseContains` branch order tightened**
(rampart/evaluators/response_contains.py). `callable()` doesn't narrow
against a union containing `str` (every str is callable for ty's
purposes here). Reordering to `re.Pattern` -> `str` -> `callable` and
using `if found is True:` makes the dispatch unambiguous.

**`pytest_plugin/plugin.py`** (rampart/pytest_plugin/plugin.py):
replaced a `register_default_handler_factory` lambda with a typed
module-level `_default_handler_factory` so `list[ExecutionEventHandler]`
aligns under list invariance. `pytest.Item` user-attribute writes now
use `# ty: ignore[unresolved-attribute]`.

### Test changes

- tests/unit/attacks/test_xpia.py: `_mock_handle` and `_mock_evaluator`
now use `spec=InjectionHandle` / `spec=Evaluator`. With the reordered
narrowing in `Attacks.xpia` (`isinstance(inject, InjectionHandle)`
first), bare `AsyncMock()` becomes ambiguous because runtime-checkable
protocols treat any Mock as matching (every `hasattr` returns True).
`spec=` makes `isinstance` deterministic.
- tests/unit/core/test_adapter.py: `@abstractmethod` added to a
protocol-conformance test fixture so ty doesn't flag the `...` body.
- Test-only `# pyright: ignore` -> `# ty: ignore` (e.g.,
tests/unit/core/test_llm.py).

### Docs

Five contributing pages updated to reference ty:
docs/contributing/index.md, development-setup.md, code-style.md,
architecture.md, pull-requests.md.

## Breaking changes

None for users. Contributors will need to run `uv sync` to install ty
(pyright is removed from the dev group) and update editor integrations -
call out in development-setup.md.

## Checklist

- [x] `pre-commit run --all-files` passes
- [x] Tests added or updated for changes -
`tests/unit/attacks/test_xpia.py` mocks gain `spec=` for deterministic
protocol `isinstance`; pyright ignore strings ported in
`tests/unit/core/test_llm.py`, test_execution.py, `test_protocols.py`,
test_types.py, etc.
- [x] Documentation updated - 5 contributing pages

---

### Verification

- `uv run ty check`: All checks passed
- `uv run ruff check . && uv run ruff format --check .`: clean
- `uv run pytest`: 491 passed, 5 skipped
- `uv run pre-commit run --all-files`: all hooks pass
@spencrr spencrr closed this Jun 30, 2026
@spencrr
spencrr deleted the dev/spencrr/73-merge branch July 29, 2026 01:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant