Skip to content

Update all non-major dependencies - #1185

Merged
renovate[bot] merged 1 commit into
mainfrom
renovate/all-nonmajor
Oct 5, 2026
Merged

renovate[bot] merged 1 commit into
mainfrom
renovate/all-nonmajor

Conversation

@renovate

@renovate renovate Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change Age Confidence
astral-sh/uv uses-with patch 0.12.19 → 0.12.23 age confidence
boto3 project.optional-dependencies patch ==1.43.103 → ==1.43.108 age confidence
boto3 dependency-groups patch ==1.43.103 → ==1.43.108 age confidence
duckdb (changelog) dependency-groups patch ==1.5.5 → ==1.5.6 age confidence
mypy (changelog) dependency-groups minor ==2.3.1,<3 → ==2.4.0,<3 age confidence

Release Notes

astral-sh/uv (astral-sh/uv)

v0.12.23

Compare Source

Released on 2026-10-03.

Python
Preview features
  • Sync from uv.lock without a workspace manifest using uv sync --frozen with frozen-lockfile (#​22018)
  • Export from uv.lock without a workspace manifest using uv export --frozen with frozen-lockfile (#​22007)
  • Inspect dependency trees from uv.lock without a workspace manifest using uv tree --frozen with frozen-lockfile (#​22016)
  • Inspect workspace metadata and optionally sync its environment from uv.lock without a workspace manifest using uv workspace metadata --frozen with frozen-lockfile (#​22017, #​22018)
Bug fixes
  • Reject alternate sources for workspace members across conflicting dependency selections, avoiding lockfiles that cannot be installed (#​22153)
  • Allow x86-64 Python interpreters running under emulation on Windows ARM64 to install compatible win_amd64 wheels instead of building from source (#​22099)

v0.12.22

Compare Source

Released on 2026-10-01.

Python
  • Add CPython 3.10.22, 3.11.17, 3.12.15, 3.13.16, and 3.14.8 (#​22147)
Enhancements
  • Accept uppercase release suffixes in wheel platform tags (#​22113)
  • Record workspace-member default groups in lockfiles (#​22010, #​22103)
  • Record workspace-member dependency-group Python requirements in lockfiles (#​22044, #​22103)
  • Record default groups for non-project workspace roots in lockfiles (#​22104)
  • Record dependency-group Python requirements for non-project workspace roots in lockfiles (#​22104)
  • Format URLs and paths consistently in CLI messages (#​21937)
  • Hide the unsupported --offline option from uv publish help (#​22124)
Preview features
  • Honor --no-default-groups in uv audit (#​22090)
  • Report a clear error when uv audit or uv tool audit runs offline and hide the unsupported option from help (#​22114)
Configuration
  • Add UV_PYTHON_ARCH to select an interpreter architecture independently of its Python version (#​22098)
Performance
  • Reduce uv's binary size by compressing embedded Python download metadata (#​22126)
Bug fixes
  • Verify unchanged requirements against existing lockfile hashes when relocking (#​22083)
  • Honor dependency-group Python requirements at non-project workspace roots (#​22101)
  • Use each selected workspace member's recorded default groups during frozen sync (#​22015)
  • Avoid false entry-point warnings for required workspace members (#​22112)
Other changes
  • Raise the minimum supported Rust version for building uv to 1.97 and update the toolchain to Rust 1.99 (#​22121)

v0.12.21

Compare Source

Released on 2026-09-29.

Python
  • Update CPython to use OpenSSL 3.5.9 (#​22076)
Enhancements
  • Omit empty [manifest] tables from lockfiles that contain only manifest subtables (#​22070)
Preview features
  • Omit redundant runtime constraints from uv.lock, including those involving pre-releases, with the resolution-inputs preview feature (#​22004, #​22068)
Bug fixes
  • Prevent uv python pin --rm from removing a global .python-versions file without --global (#​21992)
  • Fix installed-package checks incorrectly reporting post-releases as incompatible with exclusive lower bounds on pre-releases (#​22049)

v0.12.20

Compare Source

Released on 2026-09-28.

Enhancements
  • Reuse lockfiles when dependency declarations are semantically equivalent (#​21951)
  • Preserve second-line encoding declarations when installing wheel scripts with CRLF shebangs (#​21990)
Preview features
  • Write normalized requirement declarations with the lockfile-normalization preview feature (#​21951)
  • Honor synthetic default groups when installing or syncing from pylock.toml (#​22003)
  • Resolve local paths in exported pylock.toml files relative to the output file (#​22042)
  • Install each package only once when repeated tool-install-locks requirements resolve to the same package (#​22000)
  • Reuse lock-without-metadata lockfiles for conflicting groups with distinct base and extra requirement specifiers (#​22055)
  • Use consistent root-package paths in uv workspace metadata and uv tree --format json output (#​22050)
Configuration
  • Continue searching XDG_CONFIG_DIRS after empty entries (#​21987)
Performance
  • Restore the previous HTTP cache-write scheduling while investigating severe cache-revalidation stalls on ext4 filesystems (#​22051)
Bug fixes
  • Apply hash constraints to every repeated requirement under --require-hashes and --verify-hashes (#​21996)
  • Allow metadata builds for first-party workspace projects under --no-build (#​21988)
  • Honor project exclusion flags with --all-packages, including --no-install-project and --no-emit-project (#​21994)
  • Restore pyproject.toml if uv upgrade fails or is interrupted (#​21983)
  • Generate working Nushell activation scripts for relocatable virtual environments (#​21979)
  • Prevent commands from running and changing state after displaying --show-settings (#​21989)
  • Treat UTF-16 requirements files containing only a byte-order mark as empty (#​21991)
  • Ignore unrecognized managed-Python implementation directories during uv python list and uv python upgrade instead of panicking (#​22033)
  • Avoid panics and incorrect rewriting when managed Python sysconfig paths merely start with /install (#​22036)
  • Report whitespace-only non-ASCII requirements as invalid instead of panicking (#​22035)
  • Avoid a resolver panic when trace logging an always-false constraint (#​22034)
boto/boto3 (boto3)

v1.43.108

Compare Source

========

  • api-change:cognito-idp: [botocore] Amazon Cognito User Pools now supports the OIDC-standard authentication context class reference (ACR) and authentication methods reference (AMR) claims on issued access and Id tokens. Amazon Cognito User Pools also now supports step-up authentication via our existing authentication APIs.
  • api-change:glue: [botocore] Added refresh token grant type to Glue Connection supported OAuth 2.0 grant types
  • api-change:invoicing: [botocore] API and doc updates related to adding MarketplacePunchOutEnabled and MarketplacePunchOutPreference fields to ProcurementPortalPreferences related APIs
  • api-change:lambda-web: [botocore] Documentation update for AWS Lambda Web Functions, clarifies that the LambdaWeb APIs are experimental and not yet available to external customers.
  • api-change:mediapackagev2: [botocore] Dynamic Multiview enables viewers to watch multiple live video streams in a single combined output. Static filter configuration allows users to configure endpoints with layouts and sources without using query parameters. The number of sources per multiview channel has been increased to 50.
  • api-change:pinpoint-sms-voice-v2: [botocore] AWS End User Messaging SMS CarrierLookup API now supports phone number cleansing on customer opt-in. when selected, the response includes the additional field "OriginalPhoneNumber". It can also return additional PhoneNumberType enums, VOIP and PREPAID.
  • api-change:securityagent: [botocore] Adds trigger filters that control which pull request events, target branches, and labels start an automatic code review.

v1.43.107

Compare Source

========

  • api-change:bedrock-agent: [botocore] Adds an optional textReadyAt field to ListIngestionJobs and GetIngestionJob for Managed Knowledge Bases data source sync jobs. The field denotes the timestamp at which all the documents in the scope of a sync job had their text content indexed and are available for retrieval.
  • api-change:cloudfront: [botocore] Added always-amz-auth as a supported signing behavior for Origin Access Control (OAC), enabling CloudFront to authenticate requests to Lambda-Web origins.
  • api-change:ec2: [botocore] This release launches the AMI tag sharing feature, which lets AMI owners share tags alongside their AMIs, eliminating the need to build and maintain custom tag replication workflows.
  • api-change:endpoint-rules: [botocore] Update endpoint-rules client to latest version
  • api-change:endusermessaging: [botocore] AWS End User Messaging now supports Brand profiles and Notify code configurations. Brand profiles capture your sender details once to reuse across phone number registrations. Notify code configurations let you define your OTP policy and delivery settings to send passcodes in minutes.
  • api-change:health: [botocore] Adds DescribeServiceLifecycle operation returning lifecycle information for AWS services, including end-of-support dates, version recommendations, and lifecycle events.
  • api-change:lambda-web: [botocore] Lambda Web Functions GA launch. Lambda Web Functions enable customers to run web applications and API backends
  • api-change:quicksight: [botocore] This release adds HierarchyFilter support for Amazon QuickSight analysis and dashboard and 2 legged OAuth for databricks datasources.
  • api-change:sagemaker: [botocore] Release support for c8a.16xlarge and m8a.16xlarge instance types for SageMaker HyperPod
  • api-change:securityhub: [botocore] Adds GetRemediationsV2 and ListExposuresByRemediationV2 APIs. This feature allows customers to see their highest priority remediations for their Exposure findings. Remediations target key changes customers can make to resources to drive finding resolution.
  • api-change:transfer: [botocore] AWS Transfer Family Workflows adds support for the structuredLogDestinations option, enabling customers to specify a custom Amazon CloudWatch Logs log group for managed workflow execution logs.

v1.43.106

Compare Source

========

  • api-change:account: [botocore] This release adds support for verifying an AWS account's primary contact phone number. SendPhoneNumberVerification sends a one-time code by SMS, VerifyPhoneNumber validates it, and GetContactInformation now returns the verification status.
  • api-change:agent-registry: [botocore] Minor doc update for the AWS Agent Registry Custom metadata SearchDiscoverableRegistryRecords API
  • api-change:batch: [botocore] AWS Batch adds support for Amazon EKS access entries on EKS compute environments through the new accessEntry setting in CreateComputeEnvironment and UpdateComputeEnvironment.
  • api-change:bedrock: [botocore] Amazon Bedrock Automated Reasoning policies now accept Unicode letters in identifier names such as type names, type value names, and variable names. You can now author policies in non-English languages using accented or non-Latin characters.
  • api-change:bedrock-agentcore-control: [botocore] This release adds support for private certificate authorities on Amazon Bedrock AgentCore Gateway targets. The new certificateConfigurations parameter on CreateGatewayTarget and UpdateGatewayTarget references a PEM-encoded CA certificate in Amazon S3 or AWS Secrets Manager.
  • api-change:connect: [botocore] Amazon Connect Rules can now trigger in-app notifications to users as a rule action. Notification character limit was increased to 500 visible characters.
  • api-change:datazone: [botocore] Support for setting notebook run notification configurations
  • api-change:dynamodb: [botocore] Adds support for filtering exported table data using FilterExpression, ProjectionExpression and KeyConditionExpression with ExportTableToPointInTime.
  • api-change:ecs: [botocore] Releasing VPCL for BlueGreen ecs deployments.
  • api-change:globalaccelerator: [botocore] IpSets now include the Network Zone for each Static IP address.
  • api-change:glue: [botocore] Enable Catalog ID for crawler, column statistics and materialized views.
  • api-change:guardduty: [botocore] GuardDuty AWS Organizations policy integration. GetDetector and GetMemberDetectors now show whether a GuardDuty policy manages a feature.
  • api-change:logs: [botocore] Amazon CloudWatch Logs now supports an optional roleArn parameter on PutDeliveryDestination for X-Ray trace delivery destinations, specifying the IAM role to assume when delivering traces.
  • api-change:observabilityadmin: [botocore] Enablement for Bedrock PaymentManager logs via Observability Admin Telemetry Rule
  • api-change:organizations: [botocore] Add support for policy operations on the GUARDDUTY POLICY policy type.
  • api-change:s3: [botocore] Amazon S3 adds a new optional S3 Inventory field, IntelligentTieringReferenceDate, reporting the reference date S3 Intelligent-Tiering uses to evaluate an object's tier-transition eligibility. The value is populated for objects in the Intelligent-Tiering storage class and left blank for others.
  • api-change:s3vectors: [botocore] Amazon S3 Vectors now supports metadata prefiltering, providing higher recall on filtered queries.
  • api-change:sagemaker: [botocore] This feature enables customers to modify their accounting database via API.

v1.43.105

Compare Source

========

  • api-change:appstream: [botocore] Add support for NVIDIA GRID driver version metadata in Workspace Applications image responses through the new ImageSoftwareMetadata field.
  • api-change:bedrock-agent-runtime: [botocore] Amazon Bedrock Agentic Retrieve now supports the Bedrock Mantle (OpenAI Responses) endpoint via a new MantleFoundationModel configuration with an optional projectId.
  • api-change:deadline: [botocore] AWS Deadline Cloud now supports Docker software add-ons on service-managed fleets. Adds support for Open Job Description EXPR and Feature Bundle 1 job templates with typed job parameters and job, step, and parameter names up to 512 characters.
  • api-change:ec2: [botocore] Adds the LaunchStatus field to CapacityReservation in the DescribeCapacityReservations response. This field indicates whether you can currently launch instances into an UltraServer.
  • api-change:elasticache: [botocore] Amazon ElastiCache Serverless now supports public endpoints for Valkey caches. With the new Connection Type parameter, you can create a serverless cache accessible over the internet without any VPC configuration. Public endpoint caches require IAM authentication.
  • api-change:elementalinference: [botocore] Adds an extendedAnalysis setting to contextual metadata outputs to control detection of people, environments, brands, and on-screen text, and updates the summaryGeneration documentation.
  • api-change:glue: [botocore] Add support for Glue system-managed materialized views.
  • api-change:identitystore: [botocore] Add support for network access controls to restrict Identity Store API and SCIM access to trusted networks, optimistic locking for users and groups via resource revisions, and resource ARNs as identifiers in requests.
  • api-change:inspector2: [botocore] The ListFindingAggregations API now includes Low, Informational, and Untriaged counts alongside the existing severity counts in SeverityCounts.
  • api-change:mediatailor: [botocore] AWS Elemental MediaTailor now supports beaconing configuration on playback configurations. In Insights reporting mode, MediaTailor will now gather client side beaconing metrics. Set the reporting mode to Disabled to turn this off.
  • api-change:opensearch: [botocore] Amazon OpenSearch Service now supports advisory pre-validations for domain config changes. Non-critical checks now surface as warnings you can acknowledge (via the new AcceptedWarnings parameter) and proceed, instead of hard-blocking. Severity is reported in change-progress and dry-run results.
  • api-change:rds: [botocore] Adds the TargetResourceConfigurations parameter to CreateBlueGreenDeployment, letting you specify a target KMS key for each resource in the green environment.
  • api-change:sagemaker: [botocore] Adds support for cpu flex type instances on SageMaker Training and Processing. Also contains minor updates to DescribeTrainingPlan to support ARN inputs.
  • api-change:securityagent: [botocore] Adds support for Azure DevOps and Bitbucket Data Center integration providers.
  • api-change:sesv2: [botocore] Added Filter support for ListTenants, ListEmailIdentities, and ListConfigurationSets APIs.
  • api-change:transfer: [botocore] AWS Transfer Family now supports configuring up to three custom ports on public SFTP servers, instead of the single default port 22. You can also set each port's communication mode (server-talk-first or client-talk-first) so legacy and modern SFTP clients connect reliably.

v1.43.104

Compare Source

========

  • api-change:agent-registry: [botocore] AWS Agent Registry adds support for custom metadata. Discovery APIs now return custom metadata on registry records and support filtering by metadata fields. Semantic search includes custom metadata for improved relevance. Filter customMetadata fields using eq, ne, and in operators.
  • api-change:agent-registry-control: [botocore] AWS Agent Registry adds support for custom metadata. Define a typed metadata schema on your registry and attach structured key-value metadata to registry records. Schemas are additive only. Enforcement is progressive. Records show a compliance status computed against the current schema.
  • api-change:bedrock-agentcore-control: [botocore] Amazon Bedrock AgentCore Gateway now supports returning the complete MCP tools list in a single response by disabling pagination for the tools list operation. This feature is available in limited preview.
  • api-change:billing: [botocore] Adds support for (a) listing Business Support account charges via ListBusinessSupportAccountCharges and (b) subscription history via ListBusinessSupportSubscriptionHistory through the AWS Billing API.
  • api-change:connect: [botocore] This release adds ConnectionTypes and ChatStreamingConfiguration to StartChatContact, and ConnectionCredentials, Websocket, and StreamingId to its response, so customers can request connection information and chat streaming in the same call that starts the chat.
  • api-change:ec2: [botocore] API changes to AWS Client VPN to support device posture assessment and Cedar authorization policies
  • api-change:eks: [botocore] An optional customer provided prefix used to construct the hostname of the Argo CD server endpoint for EKS Argo CD Capability.
  • api-change:fsx: [botocore] Amazon FSx has expanded the model-level maximum on the ThroughputCapacity, ThroughputCapacityPerHAPair, and Iops API parameters. Actual supported values are unchanged and depend on file system type and configuration.
  • api-change:glue: [botocore] Added a new exception to several batch APIs
  • api-change:guardduty: [botocore] Adding awsServiceName field to GuardDuty Findings
  • api-change:securityagent: [botocore] Run automated penetration tests directly from your CI-CD pipeline to scan code changes before they ship, gating deployments on the findings
  • api-change:ssm: [botocore] Add support for sharing SSM documents with organizations and OUs using RAM.
duckdb/duckdb-python (duckdb)

v1.5.6: Bugfix Release

Compare Source

See DuckDB's changelog for all changes in DuckDB.

python/mypy (mypy)

v2.4.0

Compare Source


Configuration

📅 Schedule: (in timezone America/New_York)

  • Branch creation
    • "before 6am on monday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot enabled auto-merge (squash) October 5, 2026 05:49
@renovate
renovate Bot merged commit 2c6e7b2 into main Oct 5, 2026
32 checks passed
@renovate
renovate Bot deleted the renovate/all-nonmajor branch October 5, 2026 10:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants