security(deps): bump the dataviewer-backend-dependencies group in /data-management/viewer/backend with 8 updates#566
Conversation
Bumps the dataviewer-backend-dependencies group in /data-management/viewer/backend with 8 updates: | Package | From | To | | --- | --- | --- | | [fastapi](https://github.com/fastapi/fastapi) | `0.136.0` | `0.136.1` | | [uvicorn[standard]](https://github.com/Kludex/uvicorn) | `0.44.0` | `0.46.0` | | [pyarrow](https://github.com/apache/arrow) | `23.0.1` | `24.0.0` | | [ruff](https://github.com/astral-sh/ruff) | `0.15.11` | `0.15.12` | | [hypothesis](https://github.com/HypothesisWorks/hypothesis) | `6.152.1` | `6.152.3` | | [schemathesis](https://github.com/schemathesis/schemathesis) | `4.15.2` | `4.16.1` | | [huggingface-hub](https://github.com/huggingface/huggingface_hub) | `1.11.0` | `1.12.0` | | [ultralytics](https://github.com/ultralytics/ultralytics) | `8.4.40` | `8.4.41` | Updates `fastapi` from 0.136.0 to 0.136.1 - [Release notes](https://github.com/fastapi/fastapi/releases) - [Commits](fastapi/fastapi@0.136.0...0.136.1) Updates `uvicorn[standard]` from 0.44.0 to 0.46.0 - [Release notes](https://github.com/Kludex/uvicorn/releases) - [Changelog](https://github.com/Kludex/uvicorn/blob/main/docs/release-notes.md) - [Commits](Kludex/uvicorn@0.44.0...0.46.0) Updates `pyarrow` from 23.0.1 to 24.0.0 - [Release notes](https://github.com/apache/arrow/releases) - [Commits](apache/arrow@apache-arrow-23.0.1...apache-arrow-24.0.0) Updates `ruff` from 0.15.11 to 0.15.12 - [Release notes](https://github.com/astral-sh/ruff/releases) - [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md) - [Commits](astral-sh/ruff@0.15.11...0.15.12) Updates `hypothesis` from 6.152.1 to 6.152.3 - [Release notes](https://github.com/HypothesisWorks/hypothesis/releases) - [Commits](HypothesisWorks/hypothesis@hypothesis-python-6.152.1...hypothesis-python-6.152.3) Updates `schemathesis` from 4.15.2 to 4.16.1 - [Release notes](https://github.com/schemathesis/schemathesis/releases) - [Changelog](https://github.com/schemathesis/schemathesis/blob/master/CHANGELOG.md) - [Commits](schemathesis/schemathesis@v4.15.2...v4.16.1) Updates `huggingface-hub` from 1.11.0 to 1.12.0 - [Release notes](https://github.com/huggingface/huggingface_hub/releases) - [Commits](huggingface/huggingface_hub@v1.11.0...v1.12.0) Updates `ultralytics` from 8.4.40 to 8.4.41 - [Release notes](https://github.com/ultralytics/ultralytics/releases) - [Commits](ultralytics/ultralytics@v8.4.40...v8.4.41) --- updated-dependencies: - dependency-name: fastapi dependency-version: 0.136.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: dataviewer-backend-dependencies - dependency-name: uvicorn[standard] dependency-version: 0.46.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: dataviewer-backend-dependencies - dependency-name: pyarrow dependency-version: 24.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: dataviewer-backend-dependencies - dependency-name: ruff dependency-version: 0.15.12 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: dataviewer-backend-dependencies - dependency-name: hypothesis dependency-version: 6.152.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: dataviewer-backend-dependencies - dependency-name: schemathesis dependency-version: 4.16.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: dataviewer-backend-dependencies - dependency-name: huggingface-hub dependency-version: 1.12.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: dataviewer-backend-dependencies - dependency-name: ultralytics dependency-version: 8.4.41 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: dataviewer-backend-dependencies ... Signed-off-by: dependabot[bot] <support@github.com>
Dependency ReviewThe following issues were found:
Snapshot WarningsEnsure that dependencies are being submitted on PR branches and consider enabling retry-on-snapshot-warnings. See the documentation for more information and troubleshooting advice. License Issuesdata-management/viewer/backend/uv.lock
OpenSSF Scorecard
Scanned Files
|
|
✅ AW Dependabot PR Review completed successfully! |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #566 +/- ##
==========================================
+ Coverage 63.91% 66.56% +2.65%
==========================================
Files 250 262 +12
Lines 15409 16639 +1230
Branches 2122 2260 +138
==========================================
+ Hits 9848 11076 +1228
Misses 5274 5274
- Partials 287 289 +2
*This pull request uses carry forward flags. Click here to find out more. 🚀 New features to boost your workflow:
|
There was a problem hiding this comment.
Advisory Review Summary
Surfaces touched: python-runtime (uv ecosystem under data-management/viewer/backend/)
Manifests: data-management/viewer/backend/pyproject.toml (manifest) + data-management/viewer/backend/uv.lock (companion lockfile — not a transitive-only pin)
| Package | From | To | Severity | Surface |
|---|---|---|---|---|
fastapi |
0.136.0 | 0.136.1 | None identified | python-runtime |
uvicorn[standard] |
0.44.0 | 0.46.0 | None identified | python-runtime |
pyarrow |
23.0.1 | 24.0.0 | python-runtime | |
ruff |
0.15.11 | 0.15.12 | None identified | python-runtime (dev) |
hypothesis |
6.152.1 | 6.152.3 | None identified | python-runtime (dev) |
schemathesis |
4.15.2 | 4.16.1 | None identified | python-runtime (dev) |
huggingface-hub |
1.11.0 | 1.12.0 | None identified | python-runtime (optional) |
ultralytics |
8.4.40 | 8.4.41 | None identified | python-runtime (optional) |
fastapi
- No advisory identifiers in the PR body; no GHSA/CVE found.
- v0.136.1: Addresses Pydantic v2 deprecations in FastAPI's internal model handling (fastapi/fastapi#15101); internal tooling updates only.
- Source: https://github.com/fastapi/fastapi/releases/tag/0.136.1
uvicorn[standard]
- No advisory identifiers; no GHSA/CVE found.
- v0.46.0: WebSocket
ws_max_size,ws_ping_interval,ws_ping_timeoutsupport inwsprotoimplementation. - v0.45.0: Proxy headers middleware now preserves forwarded client ports; new
--reset-contextvarsflag; case-insensitivelog_levelstrings; PyYAML-absentImportErrorclarity. - Repo-specific note: The forwarded-port change in v0.45.0 may interact with
slowapirate-limiting if client identity is derived from proxy headers. Confirm key functions remain correct. - Source: Kludex/uvicorn@0.44.0...0.46.0
pyarrow
- No explicit GHSA/CVE identifier cited in the PR body. Advisory enrichment via OSV/NVD could not be completed due to network restrictions in this environment; maintainers should independently verify at (osv.dev/redacted) and (arrow.apache.org/redacted)
- v24.0.0 release notes: Full details at (arrow.apache.org/redacted) Commit range: apache/arrow@apache-arrow-23.0.1...apache-arrow-24.0.0
⚠️ High-risk trigger:pyarrowis in thepython-runtimeABI-sensitivity inventory for this repo. A major version increment (23 → 24) in Apache Arrow can introduce breaking Parquet/IPC serialization changes, C++ extension ABI shifts, and removed deprecated APIs. The data-viewer backend uses pyarrow as a runtime dependency.- Validation advice: Run
ruff checkandpytest tests/indata-management/viewer/backend; validate that Parquet files produced by v23 consumers are still readable under v24.
ruff
- Dev-only dependency (
[project.optional-dependencies].dev). No advisory identifiers. - v0.15.12 (2026-04-24): New preview-mode
#ruff:file-ignoreand#ruff:ignoresuppressions;pandas-vetandpylintrule updates; cache file permission fix. - Source: https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md#01512
hypothesis
- Dev-only dependency. No advisory identifiers.
- Patch bump (6.152.1 → 6.152.3); low risk. Changelog: HypothesisWorks/hypothesis@hypothesis-python-6.152.1...hypothesis-python-6.152.3
schemathesis
- Dev-only dependency. No advisory identifiers.
- Minor bump (4.15.2 → 4.16.1); low risk. Release notes: https://github.com/schemathesis/schemathesis/releases/tag/v4.16.1
huggingface-hub
- Optional dependency (
[project.optional-dependencies].huggingface). No advisory identifiers. - Minor bump (1.11.0 → 1.12.0); low risk. Release notes: https://github.com/huggingface/huggingface_hub/releases/tag/v1.12.0
ultralytics
- Optional dependency (
[project.optional-dependencies].yolo). No advisory identifiers. - Patch bump (8.4.40 → 8.4.41); low risk. Release notes: https://github.com/ultralytics/ultralytics/releases/tag/v8.4.41
Advisory verdict: COMMENT — pyarrow crosses a major version boundary (23 → 24), triggering the python-runtime high-risk flag; maintainers should validate ABI and Parquet/IPC data format compatibility before merging. All other seven packages are patch or minor bumps with no advisory identifiers identified.
Note
🔒 Integrity filter blocked 1 item
The following item was blocked because it doesn't meet the GitHub integrity level.
- #566
pull_request_read: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".
To allow these resources, lower min-integrity in your GitHub frontmatter:
tools:
github:
min-integrity: approved # merged | approved | unapproved | noneGenerated by AW Dependabot PR Review for issue #566 · ● 1.5M
…/dataviewer-backend-dependencies-5b19d53d70
|
✅ AW Dependabot PR Review completed successfully! |
There was a problem hiding this comment.
⚠️ Maintainer review recommended
One high-risk signal fires: pyarrow major version bump (23.0.1 → 24.0.0) on the python-runtime surface — a surface that explicitly flags pyarrow as ABI-sensitive.
Advisory Review Summary
Ecosystems and surfaces touched:
- Ecosystem:
pip/uv - Surface:
python-runtime—data-management/viewer/backend/ - Manifests changed:
data-management/viewer/backend/pyproject.toml,data-management/viewer/backend/uv.lock
No explicit GHSA or CVE identifiers were found in the Dependabot PR body. The security(deps): title prefix indicates Dependabot classified this update as security-relevant, but no advisory IDs were attached. External advisory APIs were unreachable from the review environment; all risk assessments below are based on version-range and surface analysis only.
Package Table
| Package | From | To | Severity | Surface |
|---|---|---|---|---|
pyarrow |
23.0.1 |
24.0.0 |
python-runtime | |
uvicorn[standard] |
0.44.0 |
0.46.0 |
Low | python-runtime |
fastapi |
0.136.0 |
0.136.1 |
Low | python-runtime |
schemathesis |
4.15.2 |
4.16.1 |
Low | python-runtime |
huggingface-hub |
1.11.0 |
1.12.0 |
Low | python-runtime |
ruff |
0.15.11 |
0.15.12 |
None | python-runtime (dev) |
hypothesis |
6.152.1 |
6.152.3 |
None | python-runtime (dev) |
ultralytics |
8.4.40 |
8.4.41 |
None | python-runtime |
pyarrow
- Bump:
23.0.1 → 24.0.0(major version). - Surface trigger:
pyarrowis explicitly listed as high-risk on thepython-runtimesurface due to Isaac Sim / CUDA ABI sensitivity and frequent API changes across major versions. - Risk: Apache Arrow major releases routinely include C++ ABI and Python API changes (schema inference, IPC, Parquet serialisation). Code paths that use
pyarrow.Table,pyarrow.Schema, orpyarrow.parquetshould be validated. - Validation advice: Run
ruff checkand the targetedpytestsuite indata-management/viewer/backend/before merging. - Source: Apache Arrow releases — no advisory ID in PR body.
uvicorn[standard]
- Bump:
0.44.0 → 0.46.0(skips one minor release). - Release highlights:
- 0.45.0: Reverted
http.disconnectemit on shutdown; new--reset-contextvarsflag; proxy-header client-port fix. - 0.46.0: WebSocket buffer now uses
bytearray;ws_max_size/ ping interval/timeout added forwsproto.
- 0.45.0: Reverted
- Risk: The context-vars revert could affect request-isolation in streaming endpoints. Low overall risk.
- Source: uvicorn release notes
fastapi
- Bump:
0.136.0 → 0.136.1(patch). - Release highlights: Updates Pydantic v2 code to address deprecations (#15101). Internal/doc changes only.
- Risk: Negligible. Patch-only, no API changes.
- Source: fastapi releases
schemathesis
- Bump:
4.15.2 → 4.16.1(minor). - Risk: Dev/test dependency only. No production impact.
- Transitive lockfile note:
jsonschema-rsis bumped0.45.0 → 0.46.2inuv.lockas a transitive dependency ofschemathesis. This is a lockfile-only change with no direct manifest pin.
huggingface-hub
- Bump:
1.11.0 → 1.12.0(minor). - Risk: Low. Monitor for any cache-layout or download-API changes if the backend uses model hub endpoints.
- Source: huggingface_hub releases
ruff
- Bump:
0.15.11 → 0.15.12(patch). Dev linting tool only. No runtime impact.
hypothesis
- Bump:
6.152.1 → 6.152.3(patch). Dev/test dependency only. No runtime impact.
ultralytics
- Bump:
8.4.40 → 8.4.41(patch). Minimal risk; patch-level update.
Transitive-only pin note
jsonschema-rs bumps 0.45.0 → 0.46.2 in uv.lock without a corresponding manifest change — this is a transitive-only lockfile pin pulled in by schemathesis. No direct action required.
Advisory verdict: COMMENT — pyarrow crosses a major version boundary on the python-runtime high-risk surface; maintainer validation via pytest in data-management/viewer/backend/ is recommended before merge.
Note
🔒 Integrity filter blocked 1 item
The following item was blocked because it doesn't meet the GitHub integrity level.
- #566
pull_request_read: has lower integrity than agent requires. The agent cannot read data with integrity below "approved".
To allow these resources, lower min-integrity in your GitHub frontmatter:
tools:
github:
min-integrity: approved # merged | approved | unapproved | noneGenerated by AW Dependabot PR Review for issue #566 · ● 809.7K
| "fastapi==0.136.0", | ||
| "uvicorn[standard]==0.44.0", | ||
| "fastapi==0.136.1", | ||
| "uvicorn[standard]==0.46.0", |
There was a problem hiding this comment.
Two minor versions skipped (0.44.0 → 0.46.0)
uvicorn[standard] skips 0.45.0. Notable changes across both versions include:
- 0.45.0: Reversed
http.disconnectemit on shutdown (#2913 revert); added--reset-contextvarsflag; proxy-header client-port preservation fix. - 0.46.0: WebSocket buffer switched to
bytearray;ws_max_size/ws_ping_interval/ws_ping_timeoutnow supported inwsproto.
The context-vars revert in 0.45.0 could affect request-isolation behaviour in streaming endpoints. Verify streaming / WebSocket handlers after upgrade.
Source: uvicorn release notes
| "hypothesis==6.152.1", | ||
| "schemathesis==4.15.2", | ||
| "hypothesis==6.152.3", | ||
| "schemathesis==4.16.1", |
There was a problem hiding this comment.
schemathesis bumped 4.15.2 → 4.16.1. The lockfile also bumps the transitive dependency jsonschema-rs from 0.45.0 → 0.46.2 — this is a lockfile-only transitive change (no direct manifest pin). No breaking changes are expected for this dev/test dependency, but validate with pytest in tests/.
| ] | ||
| huggingface = [ | ||
| "huggingface-hub==1.11.0", | ||
| "huggingface-hub==1.12.0", |
There was a problem hiding this comment.
huggingface-hub bumped 1.11.0 → 1.12.0 (minor). No security advisories identified in the PR body. Monitor the HuggingFace Hub changelog for any changes to model-download or cache-layout APIs used by the backend.
| "aiofiles==25.1.0", | ||
| "numpy==2.4.4", | ||
| "pyarrow==23.0.1", | ||
| "pyarrow==24.0.0", |
There was a problem hiding this comment.
pyarrow is bumped from 23.0.1 to 24.0.0 (major version). pyarrow is explicitly listed as an ABI-sensitive dependency on the python-runtime surface for this repository.
Apache Arrow major releases commonly include breaking C++ ABI and Python API changes. Review the [Apache Arrow 24 migration guide]((arrow.apache.org/redacted) and verify that:
- Any code using
pyarrowAPIs still functions correctly (schema inference, IPC, Parquet read/write). - No import-time or serialization errors occur after upgrade.
Validation: Run ruff check and the targeted pytest suite in data-management/viewer/backend/ before merging.
🤖 I have created a release *beep* *boop* --- ## [0.8.0](v0.7.4...v0.8.0) (2026-05-08) ### ⚠ BREAKING CHANGES * **dataviewer:** bump frontend stack to React 19, Vite 8, Tailwind v4, MSAL 5, ESLint 10 ([#524](#524)) ### ✨ Features * **agents:** add automated validation for high-risk Dependabot bumps ([#574](#574)) ([8c3686a](8c3686a)), closes [#573](#573) * **data:** add camera selector to annotation workspace and fix AV1 frame extraction ([#591](#591)) ([c809d2f](c809d2f)) * **data:** seed dataviewer frontend test foundation and per-section codecov flags ([#594](#594)) ([c06c4e3](c06c4e3)) * **dataviewer:** add OWASP security middleware stack ([#439](#439)) ([239edb9](239edb9)) * **infrastructure:** add conversion pipeline Terraform module ([#542](#542)) ([244531e](244531e)) * **infrastructure:** upgrade OSMO to chart 1.2.1 / image 6.2 with secure auth and skrl 2.0.0 compatibility ([#492](#492)) ([edfd7a5](edfd7a5)) * **pipeline:** add ACSA setup for ROS2 bag sync to Blob ([#451](#451)) ([c271a54](c271a54)) * **workflows:** add advisory Dependabot PR reviewer agentic workflow ([#498](#498)) ([d4bb140](d4bb140)) * **workflows:** trigger AW Dependabot PR reviewer after PR Validation ([#580](#580)) ([7ab3d16](7ab3d16)) ### 🐛 Bug Fixes * **ci:** correct stale version comment for actions/create-github-app-token ([#506](#506)) ([b2e9a54](b2e9a54)) * **ci:** restore data-pipeline and training broken tests by domain folder restructure ([#547](#547)) ([06d8472](06d8472)) * **docs:** update remaining stale 'Coming soon' labels in docs/README.md ([#507](#507)) ([02439d6](02439d6)) * **docs:** update stale coming soon label for Training section ([#472](#472)) ([46db49b](46db49b)) * **evaluation:** scope SIL AzureML validation code path and script reference ([#387](#387)) ([9f138a9](9f138a9)) * **infrastructure:** OSMO workflow execution, PostgreSQL public access, and quickstart corrections ([#477](#477)) ([9ed2da6](9ed2da6)) * **scripts:** exclude CHANGELOG.md from changed-files msdate check ([#644](#644)) ([8133bdc](8133bdc)) * **workflows:** allow dependabot[bot] to activate AW Dependabot PR Review ([#586](#586)) ([39dc022](39dc022)) * **workflows:** correct branches filter on AW Dependabot PR Review workflow_run trigger ([#584](#584)) ([fe06b52](fe06b52)) * **workflows:** normalize validate.yaml placeholder env/compute values ([#510](#510)) ([340ff44](340ff44)) * **workflows:** recompile aw-dependabot-pr-review lock file ([#576](#576)) ([d77c167](d77c167)) * **workflows:** switch AW Dependabot PR Review to pull_request_target ([#589](#589)) ([3f1edd1](3f1edd1)) ### 📚 Documentation * **docs:** Fix deployment guide links ([#614](#614)) ([0070b04](0070b04)) * document dependency-pinning-artifacts directory purpose ([#508](#508)) ([50e0010](50e0010)) ### 📦 Build System * **training:** standardize on Python 3.12 across manifests, containers, and runtime scripts ([#541](#541)) ([7ad014a](7ad014a)) ### 🔧 Operations * **build:** add Copilot cloud agent setup-steps workflow ([#593](#593)) ([c912668](c912668)) ### 🔧 Miscellaneous * **build:** exclude auto-generated CHANGELOG.md from cspell and seed dictionary ([#582](#582)) ([de1dd57](de1dd57)) * **build:** redesign codecov flags and split pytest CI per component ([#520](#520)) ([357e745](357e745)) * **dataviewer:** bump frontend stack to React 19, Vite 8, Tailwind v4, MSAL 5, ESLint 10 ([#524](#524)) ([50f8ad4](50f8ad4)) * **dataviewer:** repoint stale src/dataviewer references to data-management/viewer ([#504](#504)) ([88fa1b4](88fa1b4)), closes [#503](#503) * **deps-dev:** bump basic-ftp from 5.3.0 to 5.3.1 ([#618](#618)) ([ca10f2a](ca10f2a)) * **deps-dev:** bump globals from 15.15.0 to 17.5.0 in /data-management/viewer/frontend ([#527](#527)) ([0e0b2ae](0e0b2ae)) * **deps-dev:** bump ip-address from 10.1.0 to 10.2.0 ([#616](#616)) ([816c9cf](816c9cf)) * **deps-dev:** bump lint-staged from 16.4.0 to 17.0.2 in the root-npm-dependencies group across 1 directory ([#626](#626)) ([0e2f293](0e2f293)) * **deps-dev:** bump pydantic from 2.13.3 to 2.13.4 in the python-dependencies group across 1 directory ([#629](#629)) ([c24f1c1](c24f1c1)) * **deps-dev:** bump the python-dependencies group across 1 directory with 2 updates ([#514](#514)) ([8410f4b](8410f4b)) * **deps:** bump azure-core from 1.39.0 to 1.40.0 in /evaluation in the inference-dependencies group across 1 directory ([#597](#597)) ([6141db4](6141db4)) * **deps:** bump cryptography from 46.0.6 to 46.0.7 in /data-management/viewer ([#424](#424)) ([5fb6d58](5fb6d58)) * **deps:** bump cryptography from 46.0.6 to 46.0.7 in /data-management/viewer/backend ([#423](#423)) ([b516ad5](b516ad5)) * **deps:** bump lucide-react from 0.469.0 to 1.8.0 in /data-management/viewer/frontend ([#528](#528)) ([1bdfc1e](1bdfc1e)) * **deps:** bump nginx from `8aa63af` to `5616878` in /data-management/viewer/frontend ([#511](#511)) ([9e7e20e](9e7e20e)) * **deps:** bump nginx from 1.27-alpine to 1.29-alpine in /data-management/viewer/frontend ([#484](#484)) ([0e5c3dd](0e5c3dd)) * **deps:** bump node from `435f353` to `e49fd70` in /data-management/viewer/frontend ([#560](#560)) ([2884649](2884649)) * **deps:** bump react-is from 18.3.1 to 19.2.5 in /data-management/viewer/frontend ([#530](#530)) ([d51318c](d51318c)) * **deps:** bump tensordict from 0.11.0 to 0.12.1 in /evaluation in the inference-dependencies group across 1 directory ([#456](#456)) ([b24e733](b24e733)) * **deps:** bump the dataviewer-backend-dependencies group across 1 directory with 2 updates ([#531](#531)) ([171a1da](171a1da)) * **deps:** bump the dataviewer-backend-dependencies group across 1 directory with 5 updates ([#516](#516)) ([4f9a577](4f9a577)) * **deps:** bump the dataviewer-backend-dependencies group across 1 directory with 5 updates ([#602](#602)) ([6c27ab5](6c27ab5)) * **deps:** bump the dataviewer-dependencies group across 1 directory with 2 updates ([#529](#529)) ([8646971](8646971)) * **deps:** bump the dataviewer-dependencies group across 1 directory with 3 updates ([#601](#601)) ([d28fb50](d28fb50)) * **deps:** bump the dataviewer-dependencies group across 1 directory with 3 updates ([#632](#632)) ([4ca5f3e](4ca5f3e)) * **deps:** bump the dataviewer-dependencies group across 1 directory with 5 updates ([#515](#515)) ([109ee81](109ee81)) * **deps:** bump the dataviewer-frontend-patch-minor group across 1 directory with 6 updates ([#630](#630)) ([04d5dfd](04d5dfd)) * **deps:** bump the dataviewer-frontend-patch-minor group across 1 directory with 9 updates ([#563](#563)) ([c08f450](c08f450)) * **deps:** bump the docusaurus-dependencies group across 1 directory with 4 updates ([#627](#627)) ([f5825fc](f5825fc)) * **deps:** bump the docusaurus-dependencies group across 1 directory with 6 updates ([#599](#599)) ([b859344](b859344)) * **deps:** bump the github-actions group across 1 directory with 4 updates ([#459](#459)) ([2609c52](2609c52)) * **deps:** bump the github-actions group across 1 directory with 4 updates ([#517](#517)) ([f54bf5d](f54bf5d)) * **deps:** bump the inference-dependencies group across 1 directory with 11 updates ([#562](#562)) ([087f53a](087f53a)) * **deps:** bump the inference-dependencies group across 1 directory with 2 updates ([#628](#628)) ([4a3be47](4a3be47)) * **deps:** bump the pip group across 2 directories with 1 update ([#494](#494)) ([a14b6b0](a14b6b0)) * **docs:** update stale Python 3.11 references to 3.12 ([#575](#575)) ([6f85c95](6f85c95)) * **scripts:** remove redundant SC1091 disables in OSMO deploy scripts ([#509](#509)) ([ae1cb82](ae1cb82)) ### 🔒 Security * **build:** pin dependencies and hash-verify downloads ([#465](#465)) ([0289f49](0289f49)) * **build:** remediate dependency security advisories ([#479](#479)) ([7196d6d](7196d6d)) * **deps-dev:** bump basic-ftp from 5.2.1 to 5.2.2 ([#454](#454)) ([cb158f1](cb158f1)) * **deps-dev:** bump basic-ftp from 5.2.2 to 5.3.0 ([#495](#495)) ([e983b8b](e983b8b)) * **deps-dev:** bump hypothesis from 6.152.3 to 6.152.4 in the python-dependencies group ([#598](#598)) ([83384d2](83384d2)) * **deps-dev:** bump markdownlint-cli2 from 0.22.0 to 0.22.1 in the root-npm-dependencies group ([#559](#559)) ([32bde35](32bde35)) * **deps-dev:** bump picomatch from 2.3.1 to 2.3.2 in /docs/docusaurus ([#455](#455)) ([66f86ca](66f86ca)) * **deps-dev:** bump postcss from 8.5.10 to 8.5.12 in /data-management/viewer/frontend ([#569](#569)) ([a652dba](a652dba)) * **deps-dev:** bump the python-dependencies group with 2 updates ([#457](#457)) ([749d231](749d231)) * **deps-dev:** bump the python-dependencies group with 2 updates ([#485](#485)) ([71b44fd](71b44fd)) * **deps-dev:** bump the python-dependencies group with 3 updates ([#564](#564)) ([9fc52fd](9fc52fd)) * **deps-dev:** bump typescript from 6.0.2 to 6.0.3 in /docs/docusaurus in the docusaurus-dependencies group ([#513](#513)) ([5694dbc](5694dbc)) * **deps:** bump azureml/openmpi4.1.0-ubuntu22.04 from 20260303.v5 to 20260409.v4 in /evaluation/sil/docker ([#480](#480)) ([25d4df8](25d4df8)) * **deps:** bump cryptography from 46.0.6 to 46.0.7 in /evaluation in the uv group across 1 directory ([#538](#538)) ([92c5b2e](92c5b2e)) * **deps:** bump diffusers from 0.35.2 to 0.38.0 in /training/il/lerobot ([#638](#638)) ([6261d19](6261d19)) * **deps:** bump follow-redirects from 1.15.11 to 1.16.0 in /docs/docusaurus ([#469](#469)) ([0458908](0458908)) * **deps:** bump gitpython and mako for lerobot IL training ([#623](#623)) ([9f8022b](9f8022b)) * **deps:** bump node from 24.14.1-slim to 25.9.0-slim in /data-management/viewer/frontend ([#482](#482)) ([1532d09](1532d09)) * **deps:** bump packaging from 26.0 to 26.1 in /evaluation in the inference-dependencies group ([#483](#483)) ([f4afb6c](f4afb6c)) * **deps:** bump pillow from 12.1.1 to 12.2.0 ([#467](#467)) ([39fb663](39fb663)) * **deps:** bump python from 3.11-slim to 3.14-slim in /data-management/viewer/backend ([#481](#481)) ([7af9dfc](7af9dfc)) * **deps:** bump the dataviewer-backend-dependencies group across 1 directory with 15 updates ([#428](#428)) ([e4446a2](e4446a2)) * **deps:** bump the dataviewer-backend-dependencies group in /data-management/viewer/backend with 4 updates ([#487](#487)) ([0f57c5b](0f57c5b)) * **deps:** bump the dataviewer-backend-dependencies group in /data-management/viewer/backend with 8 updates ([#566](#566)) ([d6e7869](d6e7869)) * **deps:** bump the dataviewer-dependencies group across 1 directory with 5 updates ([#464](#464)) ([24c208d](24c208d)) * **deps:** bump the dataviewer-dependencies group in /data-management/viewer with 2 updates ([#486](#486)) ([90149f3](90149f3)) * **deps:** bump the dataviewer-dependencies group in /data-management/viewer with 6 updates ([#565](#565)) ([f0bb36b](f0bb36b)) * **deps:** bump the dataviewer-frontend-patch-minor group across 1 directory with 10 updates ([#613](#613)) ([e481f83](e481f83)) * **deps:** bump the github-actions group across 1 directory with 4 updates ([#534](#534)) ([5478ab6](5478ab6)) * **deps:** bump the github-actions group with 2 updates ([#488](#488)) ([4e6ce98](4e6ce98)) * **deps:** bump the github-actions group with 3 updates ([#567](#567)) ([48c38dc](48c38dc)) * **deps:** bump the github-actions group with 3 updates ([#634](#634)) ([00cfb49](00cfb49)) * **deps:** bump the github-actions group with 6 updates ([#603](#603)) ([73eb79a](73eb79a)) * **deps:** bump the training-dependencies group across 1 directory with 23 updates ([#463](#463)) ([d5a8656](d5a8656)) * **deps:** bump yaml from 2.8.2 to 2.8.3 in /data-management/viewer/frontend ([#453](#453)) ([10449df](10449df)) * pytest harness, dependabot advisories, and OSSF Scorecard remediations ([#501](#501)) ([e8756e8](e8756e8)) * **scripts:** pin and hash-verify all shell script downloads ([#468](#468)) ([0c2bb9c](0c2bb9c)) --- This PR was generated with [Release Please](https://github.com/googleapis/release-please). See [documentation](https://github.com/googleapis/release-please#release-please). --------- Co-authored-by: physical-ai-toolchain-release[bot] <267194360+physical-ai-toolchain-release[bot]@users.noreply.github.com> Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Bumps the dataviewer-backend-dependencies group in /data-management/viewer/backend with 8 updates:
0.136.00.136.10.44.00.46.023.0.124.0.00.15.110.15.126.152.16.152.34.15.24.16.11.11.01.12.08.4.408.4.41Updates
fastapifrom 0.136.0 to 0.136.1Release notes
Sourced from fastapi's releases.
Commits
e54e5a8🔖 Release version 0.136.19a8a5fd📝 Update release notes7815a32⬆️ Update Pydantic v2 code to address deprecations (#15101)ef1c927📝 Update release notes38039e1🔨 Tweak translation script (#15174)4fa826c📝 Update release notesc394156⬆ Bump mkdocs-material from 9.7.1 to 9.7.6 (#15408)ae230ad📝 Update release notesd9eb39d⬆ Bump inline-snapshot from 0.31.1 to 0.32.6 (#15409)4f8b5d1📝 Update release notesUpdates
uvicorn[standard]from 0.44.0 to 0.46.0Release notes
Sourced from uvicorn[standard]'s releases.
Changelog
Sourced from uvicorn[standard]'s changelog.
Commits
b224045Version 0.46.0 (#2918)7375b5bUsebytearrayfor incoming WebSocket message buffer in websockets-sansio (#...d438fb1Supportws_ping_intervalandws_ping_timeoutinwsprotoimplementation ...3e6b964Supportws_max_sizeinwsprotoimplementation (#2915)2c423bdVersion 0.45.0 (#2914)7f027f8Revert "Emithttp.disconnecton server shutdown for streaming responses" (#...73a80c3Add--reset-contextvarsflag to isolate ASGI request context (#2912)45c0b56Revert empty context for ASGI runs (#2911)850d926Raise helpfulImportErrorwhen PyYAML is missing for YAML log config (#2906)fdcacb4Acceptlog_levelstrings case-insensitively (#2907)Updates
pyarrowfrom 23.0.1 to 24.0.0Release notes
Sourced from pyarrow's releases.
Commits
31b4b6cMINOR: [Release] Update versions for 24.0.006dbc17MINOR: [Release] Update .deb/.rpm changelogs for 24.0.0a021d80MINOR: [Release] Update CHANGELOG.md for 24.0.02d6b12cGH-49716: [C++] FixedShapeTensorType::Deserialize should strictly validate se...a74cb6aGH-49697: [C++][CI] Check IPC file body bounds are in sync with decoder outco...871a0c6GH-49676: [Python][Packaging] Fix gRPC docker image layer being too big for h...f9203b3GH-49586: [C++][CI] StructToStructSubset test failure with libc++ 22.1.1 (#49...fe298b4GH-49628: [Python][Interchange protocol] Suppress warnings for pandas 4.0.0 a...1f94910GH-49252: [GLib] Deprecate Feather features (#49673)5ba5c3cGH-49671: [CI][Docs] Don't run jobs for push by Dependabot (#49672)Updates
rufffrom 0.15.11 to 0.15.12Release notes
Sourced from ruff's releases.
... (truncated)
Changelog
Sourced from ruff's changelog.
Commits
66f93cfBump 0.15.12 (#24815)476a4d0[ty] Complete support for more detailed diagnostics on possibly unbound error...ed669eaImplement#ruff:file-ignorefile-level suppressions (#23599)e73d952[ty] Include inferred type ininvalid-keyconcise diagnostic for union/inte...80feb29[ty] report only dead annotation-only locals as unused (#24811)0fbf2bcDrop deprecated license classifier (#24808)43b174c[ty] Infer lambda parameter types withCallabletype context (#24317)4f449ae[ty] Add error context for intersection types (#24772)5b4e753[ty] Add support for goto in literal enum member inlay hint (#24792)e7cc762[ty] Add error context for TypedDict assignments (#24790)Updates
hypothesisfrom 6.152.1 to 6.152.3Release notes
Sourced from hypothesis's releases.
Commits
609de04Bump hypothesis-python version to 6.152.3 and update changelog902f1baMerge pull request #4720 from Liam-DeVoe/urandom-disable-bufferingda81118claude: open /dev/urandom with buffering=0 in URandomProvider80fada3Merge pull request #4714 from HypothesisWorks/DRMacIver/uv634e2beLet tox auto-provision tox-uv instead of pinning it in tools.txt5265564Seed pip into tox-uv envsd6caeb8Use uv instead of pyenv for build-time Python installs and toxc727eadBump hypothesis-python version to 6.152.2 and update changelog36d74b7Merge pull request #4711 from HypothesisWorks/DRMacIver/is-code-ownerbbc8963Merge pull request #4712 from HypothesisWorks/DRMacIver/fix-buildUpdates
schemathesisfrom 4.15.2 to 4.16.1Release notes
Sourced from schemathesis's releases.
... (truncated)
Changelog
Sourced from schemathesis's changelog.
... (truncated)
Commits
99fb9b6chore: Release 4.16.1f0b7e3efix:authAPI onLazySchemato matchBaseSchemae23062cdocs: Fix selective auth exampleb1ec7b0chore: Update pre-commitb314cb4build: Remove unneeded files from source distribution2edad15chore: Release 4.16.007d749efix: Query parameters not serialized whenstyle/explodeare omitted from ...71a1b8etest: Add more tests5b6308cfix: Request timeouts reported as a check failure when a replay made them flakya37cd2cfix: False positive innegative_data_rejectionfor `application/x-www-form-...Updates
huggingface-hubfrom 1.11.0 to 1.12.0Release notes
Sourced from huggingface-hub's releases.
... (truncated)
Commits
16dd546Release: v1.12.043c20f4Release: v1.12.0.rc1a9a4ef8Release: v1.12.0.rc09104623Apply fsspec config in HfFileSystem metaclass (#4062)c3b04aachore: bump doc-builder SHA for main doc build workflow (#4137)871f54e[HfApi] AddmainSizetoExpandDatasetProperty_T(#4136)50444e5[Release] Add social media draft generation to release workflow (#4132)6e9e383[Buckets] Skip local walk for download sync without delete (#4123)f1cd149[CLI] Migrate buckets commands to out singleton (#4111)50013bd[Buckets] Add search param to list_buckets (#4130)Updates
ultralyticsfrom 8.4.40 to 8.4.41Commits
972e135ultralytics 8.4.41Fix SAM3 FP ghost IDs in video tracking (#24249)0bc12fcultralytics 8.4.41Avoid mutable NDJSON dataset cache collisions (#24290)235ebb3Migrate benchmarks CI fromubuntu-latesttocpu-latest(#24286)73fcaecAdd NVIDIA DALI GPU preprocessing guide (#24102)6438ebdRefresh platform docs (#24281)3681717Add fine-tuning guide for YOLO on custom datasets (#24164)8c82434Improve docs platform examples (#24006)de48cc7Add Modal Quickstart Guide (#23414)3d196f0Document cfg arg in configuration reference (#24212)419fbd6Clarify architecture-only yamls and historical framing on model pages (#24233)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions