Bump the python-security group across 1 directory with 2 updates - #3645
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps the python-security group with 2 updates in the / directory: [datamodel-code-generator](https://github.com/datamodel-code-generator/datamodel-code-generator) and [httpx2](https://github.com/pydantic/httpx2). Updates `datamodel-code-generator` from 0.57.0 to 0.64.0 - [Release notes](https://github.com/datamodel-code-generator/datamodel-code-generator/releases) - [Changelog](https://github.com/datamodel-code-generator/datamodel-code-generator/blob/main/CHANGELOG.md) - [Commits](datamodel-code-generator/datamodel-code-generator@0.57.0...0.64.0) Updates `httpx2` from 2.10.0 to 2.12.0 - [Release notes](https://github.com/pydantic/httpx2/releases) - [Changelog](https://github.com/pydantic/httpx2/blob/main/src/httpx2/CHANGELOG.md) - [Commits](pydantic/httpx2@v2.10.0...v2.12.0) --- updated-dependencies: - dependency-name: datamodel-code-generator dependency-version: 0.64.0 dependency-type: direct:development dependency-group: python-security - dependency-name: httpx2 dependency-version: 2.12.0 dependency-type: direct:production dependency-group: python-security ... Signed-off-by: dependabot[bot] <support@github.com>
There was a problem hiding this comment.
I reviewed this PR and found no bugs; because the generator jumps seven minor versions and I could not run the codegen reproducibility check locally, the CI gen_surface_types.py --check result is the one thing worth a human confirming before merge.
What was reviewed:
- Only the dev-only
codegenexact pin moves (pyproject.toml line 113); the runtimehttpx2>=2.10.0floor is unchanged and the 2.12.0 lock resolution stays within it, consistent with DEPENDENCY_POLICY. - uv.lock entries, hashes, and the
requires-devspecifier all match the new pin. - Checked whether the new
black/isortemscripten markers could change generated output: no, the script strips the generator header and re-formats withruff format, so only semantic generator changes could cause drift.
Extended reasoning...
The change is a Dependabot bump touching only pyproject.toml and uv.lock: the codegen dev group's exact pin goes from datamodel-code-generator 0.57.0 to 0.64.0, and the locked (not floored) versions of httpx2 and httpcore2 move from 2.10.0 to 2.12.0. No source code, runtime dependency floors, or security-sensitive surface (auth, crypto, data handling) is touched, and no CODEOWNERS file exists. Approval was withheld only because the merge gate for this bump is whether the new generator still reproduces the committed surface types under scripts/gen_surface_types.py --check, and that command could not be executed in this review environment, so it rests on CI rather than on a result I observed. The hunt exited on dry_streak with no findings.
Bumps the python-security group with 2 updates in the / directory: datamodel-code-generator and httpx2.
Updates
datamodel-code-generatorfrom 0.57.0 to 0.64.0Release notes
Sourced from datamodel-code-generator's releases.
... (truncated)
Changelog
Sourced from datamodel-code-generator's changelog.
... (truncated)
Commits
53a25abFast path schema output (#3410)ee2087fSkip discriminator import scan (#3411)bdf5ddffix: quote self-referencing fields when --disable-future-imports is set (#3387)ad4ec87Cache payload validation strategies (#3409)b191d52Shard Python tests (#3408)29dd6d7Cache parsed sources (#3407)93e2fe3Defer generation refresh (#3406)bb01d9cLazy root format exports (#3405)48237edFast path JSON schemas (#3404)b21d106Slot generation facts (#3403)Updates
httpx2from 2.10.0 to 2.12.0Release notes
Sourced from httpx2's releases.
... (truncated)
Changelog
Sourced from httpx2's changelog.
Commits
71ae23bVersion 2.12.0 (#1147)4fd0c70Decode compressed response bodies incrementally (#1126)d588e52Usebackports.zstdon Python 3.13 and earlier (#1146)344589dVersion 2.11.0 (#1143)de96d81Validate multipart part headers (#1142)51c3269Require brotli 1.2.0 in the brotli extra (#1141)829b93aRespect explicit Transfer-Encoding headers (#1137)4fa6c8eFix changelog extraction regex for H2 release headings (#1136)8a6f370Restore deprecated status code aliases (#1135)d03f1ecAdd public Origin API (#1134)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditionsYou can disable automated security fix PRs for this repo from the Security Alerts page.