security(deps): bump the training-dependencies group in /training/rl with 14 updates#394
Merged
WilliamBerryiii merged 2 commits intoApr 6, 2026
Conversation
Bumps the training-dependencies group in /training/rl with 14 updates: | Package | From | To | | --- | --- | --- | | [marshmallow](https://github.com/marshmallow-code/marshmallow) | `4.2.3` | `4.3.0` | | [azure-monitor-opentelemetry-exporter](https://github.com/Azure/azure-sdk-for-python) | `1.0.0b49` | `1.0.0b50` | | [charset-normalizer](https://github.com/jawah/charset_normalizer) | `3.4.6` | `3.4.7` | | [click](https://github.com/pallets/click) | `8.3.1` | `8.3.2` | | [cuda-pathfinder](https://github.com/NVIDIA/cuda-python) | `1.5.0` | `1.5.1` | | [fastapi](https://github.com/fastapi/fastapi) | `0.135.2` | `0.135.3` | | [orjson](https://github.com/ijl/orjson) | `3.11.7` | `3.11.8` | | [pandas](https://github.com/pandas-dev/pandas) | `3.0.1` | `3.0.2` | | [pillow](https://github.com/python-pillow/Pillow) | `12.1.1` | `12.2.0` | | [pydantic-core](https://github.com/pydantic/pydantic-core) | `2.44.0` | `2.45.0` | | [sqlalchemy](https://github.com/sqlalchemy/sqlalchemy) | `2.0.48` | `2.0.49` | | [tzdata](https://github.com/python/tzdata) | `2025.3` | `2026.1` | | [uvicorn](https://github.com/Kludex/uvicorn) | `0.42.0` | `0.43.0` | | [werkzeug](https://github.com/pallets/werkzeug) | `3.1.7` | `3.1.8` | Updates `marshmallow` from 4.2.3 to 4.3.0 - [Changelog](https://github.com/marshmallow-code/marshmallow/blob/dev/CHANGELOG.rst) - [Commits](marshmallow-code/marshmallow@4.2.3...4.3.0) Updates `azure-monitor-opentelemetry-exporter` from 1.0.0b49 to 1.0.0b50 - [Release notes](https://github.com/Azure/azure-sdk-for-python/releases) - [Commits](Azure/azure-sdk-for-python@azure-monitor-opentelemetry-exporter_1.0.0b49...azure-monitor-opentelemetry-exporter_1.0.0b50) Updates `charset-normalizer` from 3.4.6 to 3.4.7 - [Release notes](https://github.com/jawah/charset_normalizer/releases) - [Changelog](https://github.com/jawah/charset_normalizer/blob/master/CHANGELOG.md) - [Commits](jawah/charset_normalizer@3.4.6...3.4.7) Updates `click` from 8.3.1 to 8.3.2 - [Release notes](https://github.com/pallets/click/releases) - [Changelog](https://github.com/pallets/click/blob/main/CHANGES.rst) - [Commits](pallets/click@8.3.1...8.3.2) Updates `cuda-pathfinder` from 1.5.0 to 1.5.1 - [Release notes](https://github.com/NVIDIA/cuda-python/releases) - [Commits](NVIDIA/cuda-python@cuda-pathfinder-v1.5.0...cuda-pathfinder-v1.5.1) Updates `fastapi` from 0.135.2 to 0.135.3 - [Release notes](https://github.com/fastapi/fastapi/releases) - [Commits](fastapi/fastapi@0.135.2...0.135.3) Updates `orjson` from 3.11.7 to 3.11.8 - [Release notes](https://github.com/ijl/orjson/releases) - [Changelog](https://github.com/ijl/orjson/blob/master/CHANGELOG.md) - [Commits](ijl/orjson@3.11.7...3.11.8) Updates `pandas` from 3.0.1 to 3.0.2 - [Release notes](https://github.com/pandas-dev/pandas/releases) - [Commits](pandas-dev/pandas@v3.0.1...v3.0.2) Updates `pillow` from 12.1.1 to 12.2.0 - [Release notes](https://github.com/python-pillow/Pillow/releases) - [Changelog](https://github.com/python-pillow/Pillow/blob/main/CHANGES.rst) - [Commits](python-pillow/Pillow@12.1.1...12.2.0) Updates `pydantic-core` from 2.44.0 to 2.45.0 - [Release notes](https://github.com/pydantic/pydantic-core/releases) - [Commits](https://github.com/pydantic/pydantic-core/commits) Updates `sqlalchemy` from 2.0.48 to 2.0.49 - [Release notes](https://github.com/sqlalchemy/sqlalchemy/releases) - [Changelog](https://github.com/sqlalchemy/sqlalchemy/blob/main/CHANGES.rst) - [Commits](https://github.com/sqlalchemy/sqlalchemy/commits) Updates `tzdata` from 2025.3 to 2026.1 - [Release notes](https://github.com/python/tzdata/releases) - [Changelog](https://github.com/python/tzdata/blob/master/NEWS.md) - [Commits](python/tzdata@2025.3...2026.1) Updates `uvicorn` from 0.42.0 to 0.43.0 - [Release notes](https://github.com/Kludex/uvicorn/releases) - [Changelog](https://github.com/Kludex/uvicorn/blob/main/docs/release-notes.md) - [Commits](Kludex/uvicorn@0.42.0...0.43.0) Updates `werkzeug` from 3.1.7 to 3.1.8 - [Release notes](https://github.com/pallets/werkzeug/releases) - [Changelog](https://github.com/pallets/werkzeug/blob/main/CHANGES.rst) - [Commits](pallets/werkzeug@3.1.7...3.1.8) --- updated-dependencies: - dependency-name: marshmallow dependency-version: 4.3.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: training-dependencies - dependency-name: azure-monitor-opentelemetry-exporter dependency-version: 1.0.0b50 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: training-dependencies - dependency-name: charset-normalizer dependency-version: 3.4.7 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: training-dependencies - dependency-name: click dependency-version: 8.3.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: training-dependencies - dependency-name: cuda-pathfinder dependency-version: 1.5.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: training-dependencies - dependency-name: fastapi dependency-version: 0.135.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: training-dependencies - dependency-name: orjson dependency-version: 3.11.8 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: training-dependencies - dependency-name: pandas dependency-version: 3.0.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: training-dependencies - dependency-name: pillow dependency-version: 12.2.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: training-dependencies - dependency-name: pydantic-core dependency-version: 2.45.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: training-dependencies - dependency-name: sqlalchemy dependency-version: 2.0.49 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: training-dependencies - dependency-name: tzdata dependency-version: '2026.1' dependency-type: direct:production update-type: version-update:semver-major dependency-group: training-dependencies - dependency-name: uvicorn dependency-version: 0.43.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: training-dependencies - dependency-name: werkzeug dependency-version: 3.1.8 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: training-dependencies ... Signed-off-by: dependabot[bot] <support@github.com>
Contributor
Dependency ReviewThe following issues were found:
Snapshot WarningsEnsure that dependencies are being submitted on PR branches and consider enabling retry-on-snapshot-warnings. See the documentation for more information and troubleshooting advice. License Issuestraining/rl/pyproject.toml
training/rl/requirements.txt
OpenSSF ScorecardScorecard details
Scanned Files
|
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #394 +/- ##
=======================================
Coverage 50.46% 50.46%
=======================================
Files 267 267
Lines 18098 18098
Branches 1903 1855 -48
=======================================
Hits 9134 9134
Misses 8674 8674
Partials 290 290
*This pull request uses carry forward flags. Click here to find out more. 🚀 New features to boost your workflow:
|
WilliamBerryiii
approved these changes
Apr 6, 2026
WilliamBerryiii
added a commit
that referenced
this pull request
Apr 7, 2026
- keep equality-pinned versions over Dependabot range operators from #394 🔀 - Generated by Copilot
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the training-dependencies group in /training/rl with 14 updates:
4.2.34.3.01.0.0b491.0.0b503.4.63.4.78.3.18.3.21.5.01.5.10.135.20.135.33.11.73.11.83.0.13.0.212.1.112.2.02.44.02.45.02.0.482.0.492025.32026.10.42.00.43.03.1.73.1.8Updates
marshmallowfrom 4.2.3 to 4.3.0Changelog
Sourced from marshmallow's changelog.
Commits
b596fdbBump version and update changelog256f0aaAdd pre/post_load parameters to Field (#2799)c847ad4Typing improvements to marshmallow.validate (#2940)eb86322Remove redundant docs job (#2939)a44ad62Avoid infinite recursion in nesting docs (#2938)3360e34Bump version and update changelog7b9ce45Fix changelog typos and update releasing docsf07eadcFix validate.Email to accept IDNs (#2937)4acb783Fix Unreachable Warning (#2935)3492faeRemove redundant python-version (#2932)Updates
azure-monitor-opentelemetry-exporterfrom 1.0.0b49 to 1.0.0b50Release notes
Sourced from azure-monitor-opentelemetry-exporter's releases.
Commits
24212d1Exporter release 1.0.0b50 (#46054)087778fRevert custom properties limit to 8kb (#46066)d8bed7e[monitor-opentelemetry] Fix duplicate auth policy in live metrics exporter (#...de23b45Suppress internal sdkstats HTTP pipeline logs from appearing in user's traces...ce28bf7Modify logic to ensure that the cloud_RoleInstance gets populated with the k8...5fe509bRemove deprecated events package and methods (#45684)faf2a72Increment package version after release of azure-monitor-opentelemetry (#45811)77b2899Distro release 1.8.7 (#45801)4b5be11Change import path for LoggingHandler to accommodate upstream breaking change...9950092Increment package version after release of azure-monitor-opentelemetry-export...Updates
charset-normalizerfrom 3.4.6 to 3.4.7Release notes
Sourced from charset-normalizer's releases.
Changelog
Sourced from charset-normalizer's changelog.
Commits
0f07891Merge pull request #729 from jawah/release-3.4.7fdbeb29chore: update dev, and ci requirementsb66f922chore: add ft classifierf94249dchore: add test cases for utf_7 recent fix95c866fchore: bump version to 3.4.74f429bbchore: bump mypy pre-commit to v1.20b579cd6fix: correctly remove SIG remnant in utf-7 decoded string58bf944⬆️ Bump github/codeql-action from 4.32.4 to 4.35.1 (#728)44cf8a1⬆️ Bump actions/download-artifact from 8.0.0 to 8.0.1 (#726)362bc20⬆️ Bump docker/setup-qemu-action from 3.7.0 to 4.0.0 (#725)Updates
clickfrom 8.3.1 to 8.3.2Release notes
Sourced from click's releases.
Changelog
Sourced from click's changelog.
Commits
052c006Change update release date.502b7ceMerge branch 'stable' of https://github.com/pallets/click into release-8.3.2a0a37e4Change publish to werkzeug latest. (#3301)57be6fcChange publish to werkzeug latest.781d6a8Update publish workflows (#3266)ff795b6Update precommit pins with toxdd87ef4Update github action pins with tox93d3f9dRelease version 8.3.23299ba1Add missing PR to changelog. (#3264)b7f62c4Add missing PR to changelog.Updates
cuda-pathfinderfrom 1.5.0 to 1.5.1Release notes
Sourced from cuda-pathfinder's releases.
Commits
1c8f297docs(pathfinder): prepare 1.5.1 release notes (#1854)1476822[FEA]: Add support forpathfinder.find_bitcode_lib("nvshmem_device")(#1828)900cd2eClaim cuda-python repository in context7 (#1757)6a7d08cpathfinder: extended bin search paths with nvidia/cu13/bin (#1846)64b8c07bench: Initial cuda.bindings latency benchmarks structure (#1736)56edbb0Extract requires() test mark to eliminate repeated numpy version checks (#1844)fa25626build(deps): bump the actions-monthly group with 5 updates (#1848)66a687cEnhance Graph.update() and add whole-graph update tests (#1843)6211c5apathfinder: support cusolverMp dynamic loading and header searching (#1845)682182bImprove cuda_bindings examples (#1842)Updates
fastapifrom 0.135.2 to 0.135.3Release notes
Sourced from fastapi's releases.
Commits
1f442c4🔖 Release version 0.135.38f5d157📝 Update release notes428452a📝 Update release notes70580da✨ Add support for@app.vibe()(#15280)6ee8747📝 Update release notes3e72c09👥 Update FastAPI People - Experts (#15279)96df35f📝 Update release notes6c81125⬆ Bump orjson from 3.11.7 to 3.11.8 (#15276)428f82c📝 Update release notes5599c59⬆ Bump ruff from 0.15.0 to 0.15.8 (#15277)Updates
orjsonfrom 3.11.7 to 3.11.8Release notes
Sourced from orjson's releases.
Changelog
Sourced from orjson's changelog.
Commits
5cbb3d03.11.84195d7fwriter::halfd00641bwriter::uuidc84d9b4build and compatibility misc4547234ffi::numpy0d4a5addatetime PyRef idiome93a13dCross-compile avoids maturin v1.12 build-details.json errorUpdates
pandasfrom 3.0.1 to 3.0.2Release notes
Sourced from pandas's releases.
Commits
ab90747RLS: 3.0.2 (#64934)6f27013Backport PR #64931 on branch 3.0.x (DOC/BLD: temporary disable upload of docs...48ddc60Backport PR #64664 on branch 3.0.x (BUG: DataFrame.sum() crashes on empty Dat...8774488[backport 3.0.x] PERF: fix slow python loop in validation for ArrowStringArra...33af6ccBackport PR #64133 on branch 3.0.x (BUG: str.find returns byte offset instead...4ef49d8[backport 3.0.x] BUG: fix convert_dtypes dropping values from sliced mixed-dt...0668f34[backport 3.0.x] BUG: Fix HDFStore.put with StringDtype columns and compressi...23f2f44[backport 3.0.x] BUG: Suppress unnecessary RuntimeWarning in to_datetime with...83ba804Backport PR #64886: BUG: Compute Variance of Complex Numbers Correctly (#64892)bb5ca1aBackport PR #64386 on branch 3.0.x (BUG: fix sort_index AssertionError with R...Updates
pillowfrom 12.1.1 to 12.2.0Release notes
Sourced from pillow's releases.
... (truncated)
Commits
3c41c0912.2.0 version bumpcdaa29eCheck calloc return value (#9527)585b2f5Check calloc return valueecf011eCheck all allocs in the Arrow tree (#9488)cf6de8cReject non-numeric elements inside list coords (#9526)ffdcedeUpdate 12.2.0 release notes (#9522)7929d77Added security release notes (#149)c4f7aa5Added security release notes22cdb5fMove variable declaration inside define (#9525)fc15b3bResize tall images vertically first (#9524)Updates
pydantic-corefrom 2.44.0 to 2.45.0Commits
Updates
sqlalchemyfrom 2.0.48 to 2.0.49Release notes
Sourced from sqlalchemy's releases.
... (truncated)
Commits
Updates
tzdatafrom 2025.3 to 2026.1Release notes
Sourced from tzdata's releases.
Changelog
Sourced from tzdata's changelog.
Commits
4997cabUpdate tzdata to version '2026a' (#123)4d6c41fUpdate development status to 'Production/Stable' (#127)7c1ce85Remove 'v' from tags in auto-tag.yml77a9c09Update docs links totzdata.python.org(#125)11148f6Remove quotes from update branch names98fa430Bump actions/checkout from 5 to 6 in the actions group (#122)7ef7c61Add auto-tag workflow (#110)3fec560Update tzdata to version '2025c'Updates
uvicornfrom 0.42.0 to 0.43.0Release notes
Sourced from uvicorn's releases.
Changelog
Sourced from uvicorn's changelog.
Commits
8d397c7Version 0.43.0 (#2885)587042d🐛 Emithttp.disconnectASGIreceive()event on server shutting down for s...c9a75fbchore(deps): bump the github-actions group with 3 updates (#2878)84fd578chore(deps): bump pygments from 2.19.2 to 2.20.0 (#2877)cd52d34Use nativecontextparameter forcreate_taskon Python 3.11+ (#2859)5211880Drop cast in ASGI types (#2875)1cb8e74Add websocket 500 fallback header test (#2874)28efbb2chore(deps-dev): bump cryptography from 46.0.5 to 46.0.6 (#2873)042ffebci: add zizmor (#2872)c61f9d4chore(deps): bump requests from 2.32.5 to 2.33.0 (#2871)Updates
werkzeugfrom 3.1.7 to 3.1.8Release notes
Sourced from werkzeug's releases.
Changelog
Sourced from werkzeug's changelog.
Commits
c1a26b4release version 3.1.87926f0brelax get_host strictness (#3148)deab88frelax get_host strictness65eb639start version 3.1.87720b76release version 3.1.7 (#3135)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions