Skip to content

chore(deps): bump the all-dependencies group in /i-oic-wxo-external-agent-observability with 13 updates - #770

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/i-oic-wxo-external-agent-observability/all-dependencies-d977cb9d8c
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/i-oic-wxo-external-agent-observability/all-dependencies-d977cb9d8c

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 2, 2026

Copy link
Copy Markdown
Contributor

Updates the requirements on langgraph, langchain, langchain-core, langchain-google-genai, python-dotenv, fastapi, uvicorn, pydantic, httpx, opentelemetry-api, opentelemetry-sdk, opentelemetry-exporter-otlp-proto-http and ibm-watsonx-orchestrate to permit the latest version.
Updates langgraph to 1.2.12

Release notes

Sourced from langgraph's releases.

langgraph==1.2.12

Changes since 1.2.11

  • release(langgraph): 1.2.12 (#8987)
  • chore(deps): bump soupsieve from 2.8.4 to 2.9 in /libs/langgraph (#8958)
  • feat(langgraph): add response_schema to interrupt() (#8886)
  • fix(langgraph): type undeclared v3 stream projections (#8596)
  • chore(langgraph): bump mistune to 3.3.4 (#8804)
  • chore(deps): bump the minor-and-patch group across 1 directory with 7 updates (#8779)
  • chore(deps): bump the minor-and-patch group across 1 directory with 4 updates (#8782)
  • chore(deps): bump tornado from 6.5.7 to 6.5.8 in /libs/langgraph (#8792)
  • chore(deps): bump the major group in /libs/langgraph with 2 updates (#8783)
  • fix(langgraph): detect subgraphs from bytecode instead of source (#8569)
Commits
  • 49cce0c release(sdk-py): 0.4.5 (#8988)
  • 19273fa release(langgraph): 1.2.12 (#8987)
  • ed384f3 fix(cli): remediate AnyIO vulnerabilities in example lockfiles (#9022)
  • aa742fb chore(deps): bump anyio from 4.14.2 to 4.15.1 in /libs/sdk-py (#8997)
  • b58044a chore(deps): bump anyio from 4.13.0 to 4.14.2 in /libs/cli (#8998)
  • daa514a chore(deps): bump anyio from 4.13.0 to 4.14.2 in /libs/checkpoint-conformance...
  • 022043a chore(deps): bump anyio from 4.12.1 to 4.14.2 in /libs/checkpoint (#8995)
  • d7b99cc chore(deps): bump anyio from 4.12.1 to 4.14.2 in /libs/sdk-py (#8994)
  • b19edd7 chore(deps): bump anyio from 4.12.1 to 4.14.2 in /libs/checkpoint-sqlite (#8993)
  • c81c135 chore(deps): bump soupsieve from 2.8.4 to 2.9 in /libs/langgraph (#8958)
  • Additional commits viewable in compare view

Updates langchain to 1.4.3

Release notes

Sourced from langchain's releases.

langchain-fireworks==1.4.3

Changes since langchain-fireworks==1.4.2

release(fireworks): 1.4.3 chore: bump vcrpy from 8.1.1 to 8.2.1 in /libs/partners/fireworks (#38314) chore: bump langsmith from 0.8.16 to 0.8.18 in /libs/partners/fireworks (#38313) chore: bump langsmith from 0.8.14 to 0.8.16 in /libs/partners/fireworks (#38235) chore: bump pytest from 9.0.3 to 9.1.0 in /libs/partners/fireworks (#38233) chore(model-profiles): refresh model profile data (#38210) chore(model-profiles): refresh model profile data (#38191) chore(model-profiles): refresh model profile data (#38133) docs: refresh README installation and resources (#38119) release(core): 1.4.7 (#38111) fix(core,partners): rename package version trace metadata (#38110) style(core,langchain,langchain-classic,partners): replace double backticks in docstrings (#38095) chore: bump langsmith from 0.8.9 to 0.8.14 in /libs/partners/fireworks (#38093) release(core): 1.4.6 (#38061) feat(core,partners): add package version tracking to tracing metadata (#35295) chore(infra): bump mypy to 2.1 and unify type-check config across the monorepo (#36470) feat(standard-tests): validate tool call chunks during streaming (#34707) chore(partners): bump locks (#38052) hotfix(openai): min core dep (#37990) chore(model-profiles): refresh model profile data (#37973) chore(model-profiles): refresh model profile data (#37936) test(langchain,partners): disable pytest-benchmark under xdist to silence PytestBenchmarkWarning (#37901) fix(partners): cap aiohttp below 3.14 for vcrpy compat (#37898) chore(model-profiles): refresh model profile data (#37895) chore: bump aiohttp from 3.13.5 to 3.14.0 in /libs/partners/fireworks (#37882) chore: bump langsmith from 0.8.7 to 0.8.9 in /libs/partners/fireworks (#37883) chore: bump langsmith from 0.8.0 to 0.8.7 in /libs/partners/fireworks (#37781) chore: bump requests from 2.34.0 to 2.34.2 in /libs/partners/fireworks (#37782)

Commits
  • be854a1 release(langchain): 1.4.3 (#40888)
  • 2ade674 fix(langchain): sanitize cache settings for fallback models (#40886)
  • 88b9727 feat(fireworks): add prompt caching middleware (#38823)
  • 60e57f5 fix(fireworks): classify mid-stream read timeouts (#40874)
  • 42f04f4 docs: update OpenWiki (#40781)
  • 213f230 chore(model-profiles): refresh model profile data (#40869)
  • d750819 chore(model-profiles): refresh model profile data (#40833)
  • 1ef23d6 fix(anthropic): serialize invalid tool calls as tool use on replay (#40864)
  • 80b7409 feat(langchain): support Bedrock Mantle chat models in init_chat_model (#40...
  • 40fe8d6 docs(core): fix docstring examples that don't run as copied (#40815)
  • Additional commits viewable in compare view

Updates langchain-core to 1.6.5

Release notes

Sourced from langchain-core's releases.

langchain-core==1.6.5

Changes since langchain-core==1.6.4

release(core): 1.6.5 (#40816) fix(core): abbreviate long tool IDs in XML buffer strings (#40792)

Commits

Updates langchain-google-genai to 4.4.0

Release notes

Sourced from langchain-google-genai's releases.

langchain-google-genai==4.4.0

Changes since libs/genai/v4.3.7

release(genai): 4.4.0 (#1989) feat(genai): support agentic video understanding (#1988)

Commits
  • d38d42f release(genai): 4.4.0 (#1989)
  • e52ace7 feat(genai): support agentic video understanding (#1988)
  • 3d9e491 release(genai): 4.3.7 (#1977)
  • df0901b fix(genai): apply distinct indexes to repeated block types (#1974)
  • 9bd41b7 chore: bump types-google-cloud-ndb from 2.4.0.20260518 to 2.4.0.20260724 in /...
  • fcbb0d7 chore: bump the major group in /libs/community with 3 updates (#1920)
  • 71a17cf chore: bump the minor-and-patch group across 1 directory with 6 updates (#1969)
  • a6206c3 fix(vertexai): bump pyarrow dependency (#1962)
  • d530f2f fix(genai): remove __del__ that closes a potentially shared client (#1963)
  • bd39818 fix(genai): send skip_thought_signature_validator as a literal string (#1972)
  • Additional commits viewable in compare view

Updates python-dotenv to 1.2.3

Release notes

Sourced from python-dotenv's releases.

v1.2.3

Fixed

  • Strip a leading UTF-8 BOM from .env file contents so the first variable is no longer silently lost when the file is saved with BOM (e.g. by some JetBrains IDEs on Windows) by [@​h1whelan] in #640
  • set_key now escapes backslashes, so values containing them (Windows paths, regular expressions) survive a write/read round-trip. Quoted values ending in an escaped backslash are no longer mis-parsed as an escaped quote, which used to swallow the following lines by [@​dchaudhari7177] in #680
  • dotenv run now prints a friendly error instead of a traceback when no command is given by [@​bbc2] in #606
  • Cache the parsed result for empty .env files so repeated dotenv_values/load_dotenv calls no longer re-read the file by [@​ReinerBRO] in #638
Changelog

Sourced from python-dotenv's changelog.

[1.2.3] - 2026-08-16

Fixed

  • Strip a leading UTF-8 BOM from .env file contents so the first variable is no longer silently lost when the file is saved with BOM (e.g. by some JetBrains IDEs on Windows) by [@​h1whelan] in #640
  • set_key now escapes backslashes, so values containing them (Windows paths, regular expressions) survive a write/read round-trip. Quoted values ending in an escaped backslash are no longer mis-parsed as an escaped quote, which used to swallow the following lines by [@​dchaudhari7177] in #680
  • dotenv run now prints a friendly error instead of a traceback when no command is given by [@​bbc2] in #606
  • Cache the parsed result for empty .env files so repeated dotenv_values/load_dotenv calls no longer re-read the file by [@​ReinerBRO] in #638

[1.2.2] - 2026-03-01

Added

  • Support for Python 3.14, including the free-threaded (3.14t) build. (#588)

Changed

  • The dotenv run command now forwards flags directly to the specified command by [@​bbc2] in #607
  • Improved documentation clarity regarding override behavior and the reference page.
  • Updated PyPy support to version 3.11.
  • Documentation for FIFO file support.
  • Dropped Support for Python 3.9.

Fixed

  • Improved set_key and unset_key behavior when interacting with symlinks by [@​bbc2] in [790c5c0]
  • Corrected the license specifier and added missing Python 3.14 classifiers in package metadata by [@​JYOuyang] in #590

Breaking Changes

  • dotenv.set_key and dotenv.unset_key used to follow symlinks in some situations. This is no longer the case. For that behavior to be restored in all cases, follow_symlinks=True should be used.

  • In the CLI, set and unset used to follow symlinks in some situations. This is no longer the case.

  • dotenv.set_key, dotenv.unset_key and the CLI commands set and unset used to reset the file mode of the modified .env file to 0o600 in some situations. This is no longer the case: The original mode of the file is now preserved. Is the file needed to be created or wasn't a regular file, mode 0o600 is used.

[1.2.1] - 2025-10-26

  • Move more config to pyproject.toml, removed setup.cfg
  • Add support for reading .env from FIFOs (Unix) by [@​sidharth-sudhir] in #586

[1.2.0] - 2025-10-26

... (truncated)

Commits
  • 49515af Bump version: 1.2.2 → 1.2.3
  • 8ac846f chore: add release runbook (RELEASING.md) and make release target
  • bb31c94 docs: add 1.2.3 release notes (#606, #638, #680)
  • f7b18d9 fix: round-trip backslashes through set_key (#680)
  • 751f8c1 ci(deps): bump actions/checkout from 6.0.2 to 6.0.3 in the github-actions gro...
  • f1937b6 chore(deps): update mkdocs-include-markdown-plugin requirement from >=6.0.0 t...
  • 45b9372 chore(deps): update pytest requirement from >=3.9 to >=9.0.3 (#653)
  • 72896e9 docs: fix broken mkdocs link in CONTRIBUTING.md (#636)
  • 72754a1 ci(deps): bump peaceiris/actions-gh-pages from 4.0.0 to 4.1.0 in the github-a...
  • 078325e ci(security): harden CI/CD supply chain with SHA pinning and least-privilege ...
  • Additional commits viewable in compare view

Updates fastapi to 0.141.1

Release notes

Sourced from fastapi's releases.

0.141.1

Fixes

  • 🐛 Fix support for background tasks and headers from dependencies in app.frontend(). PR #16105 by @​tiangolo.

Docs

Commits
  • 95f8322 🔖 Release version 0.141.1 (#16106)
  • f137944 📝 Update release notes
  • d623544 🐛 Fix support for background tasks and headers from dependencies in `app.fron...
  • 1d211b9 📝 Update release notes
  • 8a1f876 📝 Document FASTAPI_ENV in FastAPI CLI guide (#16104)
  • c7e7b65 🔖 Release version 0.141.0 (#16103)
  • 6bceb84 📝 Update release notes
  • 5429fed ✨ Add app.frontend(check_dir="auto"), to make local development more conven...
  • 628663f 🔖 Release version 0.140.13 (#16096)
  • 0b54fd0 📝 Update release notes
  • Additional commits viewable in compare view

Updates uvicorn to 0.54.0

Release notes

Sourced from uvicorn's releases.

Version 0.54.0

📨 Send metadata after the response body

uvicorn 0.54.0 adds response trailers and 103 Early Hints to its experimental HTTP/2 implementation through zttp.

uv add uvicorn==0.54.0 "zttp>=0.0.34"
  • Send HTTP/2 response trailers (#3146). The ASGI http.response.trailers extension lets applications send metadata, such as checksums, after the response body. Clients must send TE: trailers to receive them. Multiple trailer messages are combined before completing the response.
  • HTTP/2 remains experimental and opt-in. Enable it with --http zttp --http2. Upgrade-based h2c and WebSockets over HTTP/2 remain unsupported.

💡 Hint at resources before the final response

  • Send 103 Early Hints over HTTP/2 (#3137). Applications can use the ASGI http.response.early_hint extension to send resource hints before the final response. Each supplied link becomes a separate Link header.

Full changelog: 0.53.0...0.54.0

Changelog

Sourced from uvicorn's changelog.

0.54.0 (September 24, 2026)

HTTP/2 support remains experimental. Install zttp>=0.0.34 and enable it with --http zttp --http2.

Added

  • Add HTTP/2 response trailers through the ASGI http.response.trailers extension. Clients must send TE: trailers to receive them (#3146)
  • Add HTTP/2 103 Early Hints through the ASGI http.response.early_hint extension (#3137)

0.53.0 (September 14, 2026)

This release adds experimental HTTP/2 support through zttp. Enable it with --http zttp --http2. Upgrade-based h2c and WebSockets over HTTP/2 are not supported.

Added

  • Add experimental HTTP/2 support through zttp (#2982, #3101)
  • Add support for zuvloop (#3104)

Fixed

  • Handle comma-separated, case-insensitive Connection: close tokens across HTTP implementations (#3103)
  • Trust IPv6 loopback in the default FORWARDED_ALLOW_IPS value (#3119)
  • Cancel the HTTP keep-alive timer when upgrading to WebSocket (#3107)

0.52.4 (August 18, 2026)

Fixed

  • Remove duplicate Date headers from accepted WebSocket handshakes with websockets-sansio (#3078)

0.52.3 (August 13, 2026)

Changed

  • Update zttp to 0.0.24 and use its combined receive path, improving HTTP/1.1 request parsing performance (#3067)

0.52.2 (August 13, 2026)

Fixed

  • Update zttp to 0.0.22, fixing bodyless request receives and improving HTTP/1 request parsing performance (#3063)

0.52.1 (August 1, 2026)

Fixed

  • Complete the closing handshake on server-initiated WebSocket closes in the websockets-sansio and wsproto implementations, waiting for the client's close reply with a 10 second timeout instead of resetting the connection (#3053)
  • Add missing write flow control to the websockets-sansio implementation, preventing data truncation on server-initiated closes with large in-flight payloads (#3048)
  • Handle connection loss while a WebSocket write is waiting on backpressure (#3050)

... (truncated)

Commits

Updates pydantic to 2.13.5

Release notes

Sourced from pydantic's releases.

v2.13.5 (2026-08-28)

What's Changed

Fixes

  • Allow reuse of validators when plugins are set by @​Viicos in #13535
  • Fix missing GC traversal on some pydantic-core struct fields by @​Viicos in #13624
  • Fix missing GC traversal in pydantic-core for GeneralFieldsSerializer by @​Viicos in #13629
  • Count validated model fields once in smart unions by @​tamird in #13731
Changelog

Sourced from pydantic's changelog.

v2.13.5 (2026-08-28)

GitHub release

What's Changed

Fixes

  • Allow reuse of validators when plugins are set by @​Viicos in #13535
  • Fix missing GC traversal on some pydantic-core struct fields by @​Viicos in #13624
  • Fix missing GC traversal in pydantic-core for GeneralFieldsSerializer by @​Viicos in #13629
  • Count validated model fields once in smart unions by @​tamird in #13731

v2.13.4 (2026-05-06)

GitHub release

What's Changed

Packaging

Fixes

v2.13.3 (2026-04-20)

GitHub release

What's Changed

Fixes

v2.13.2 (2026-04-17)

GitHub release

What's Changed

Fixes

  • Fix ValidationInfo.field_name missing with model_validate_json() by @​Viicos in #13084

v2.13.1 (2026-04-15)

... (truncated)

Commits
  • 001dea0 Bump pypa/gh-action-pypi-publish action to v1.14.2
  • 558379f Bump twine to v7.0.0
  • 2cfd5d3 Do not check for docs build
  • a735bee Fix more Clippy lints
  • 7eed4a1 Fix Clippy 0.1.95 warnings
  • b353bbb Prepare release v2.13.5
  • 63d2ccc Count validated model fields once in smart unions
  • a53ec2e Speed up PyPy CI tests
  • d65e0f9 Workaround circular import error in Mypy
  • 47a6dbf Fix missing GC traversal in pydantic-core for GeneralFieldsSerializer
  • Additional commits viewable in compare view

Updates httpx to 0.28.1

Release notes

Sourced from httpx's releases.

Version 0.28.1

0.28.1 (6th December, 2024)

  • Fix SSL case where verify=False together with client side certificates.
Changelog

Sourced from httpx's changelog.

0.28.1 (6th December, 2024)

  • Fix SSL case where verify=False together with client side certificates.

0.28.0 (28th November, 2024)

Be aware that the default JSON request bodies now use a more compact representation. This is generally considered a prefered style, tho may require updates to test suites.

The 0.28 release includes a limited set of deprecations...

Deprecations:

We are working towards a simplified SSL configuration API.

For users of the standard verify=True or verify=False cases, or verify=<ssl_context> case this should require no changes. The following cases have been deprecated...

  • The verify argument as a string argument is now deprecated and will raise warnings.
  • The cert argument is now deprecated and will raise warnings.

Our revised SSL documentation covers how to implement the same behaviour with a more constrained API.

The following changes are also included:

  • The deprecated proxies argument has now been removed.
  • The deprecated app argument has now been removed.
  • JSON request bodies use a compact representation. (#3363)
  • Review URL percent escape sets, based on WHATWG spec. (#3371, #3373)
  • Ensure certifi and httpcore are only imported if required. (#3377)
  • Treat socks5h as a valid proxy scheme. (#3178)
  • Cleanup Request() method signature in line with client.request() and httpx.request(). (#3378)
  • Bugfix: When passing params={}, always strictly update rather than merge with an existing querystring. (#3364)

0.27.2 (27th August, 2024)

Fixed

  • Reintroduced supposedly-private URLTypes shortcut. (#2673)

0.27.1 (27th August, 2024)

Added

  • Support for zstd content decoding using the python zstandard package is added. Installable using httpx[zstd]. (#3139)

Fixed

  • Improved error messaging for InvalidURL exceptions. (#3250)
  • Fix app type signature in ASGITransport. (#3109)

0.27.0 (21st February, 2024)

... (truncated)

Commits

Updates opentelemetry-api to 1.45.0

Release notes

Sourced from opentelemetry-api's releases.

Version 1.45.0/0.66b0

Added

  • opentelemetry-exporter-prometheus: add support to configure Resource attributes as metric labels (#5122)
  • infra: add renovate (#5202)
  • opentelemetry-api, opentelemetry-sdk: add support for extended attribute values everywhere. (#5266)
  • opentelemetry-sdk: wire the top-level log_level field in declarative configuration — when set, maps the OTel SeverityNumber value to a Python logging level and applies it to the opentelemetry logger so SDK internal diagnostics respect the configured severity. (#5351)
  • opentelemetry-sdk: add the new stable AlwaysRecordSampler (#5354)
  • opentelemetry-configuration, opentelemetry-sdk: wire top-level attribute_limits into per-signal providers via declarative config; add log_record_limits support to LoggerProvider (#5365)
  • opentelemetry-exporter-otlp-json-http: add OTLP JSON HTTP exporter package (#5374)
  • opentelemetry-api, opentelemetry-sdk: add enabled() support to the Logger API, SDK, and LogRecordProcessor to let instrumentation skip expensive work when logging is disabled (#5380)
  • opentelemetry-exporter-otlp-json-file: add OTLP JSON file Docker tests (#5412)
  • opentelemetry-configuration: wire the experimental tracer_configurator/development, meter_configurator/development and logger_configurator/development fields into create_tracer_provider, create_meter_provider and create_logger_provider, so per-instrumentation-scope enabled overrides declared in the config file are applied to the provider (previously these fields were parsed but silently discarded). The logger minimum_severity/trace_based fields are not supported by the Python SDK and are ignored with a warning. (#5418)
  • docs/examples: add example on how to manually setup the SDK to get SDK metrics (#5449)
  • opentelemetry-docker-tests: add Prometheus exporter docker tests (#5457)
  • opentelemetry-sdk: count records dropped after shutdown on otel.sdk.processor.{span,log}.processed with error.type=already_shutdown (batch span/log and simple log processors), which the semantic conventions define as a valid value for this metric. (#5509)
  • opentelemetry-semantic-conventions: update semantic conventions to v1.44.0 (#5511)
  • opentelemetry-sdk: add host.id to the host resource detector (#5653)
  • opentelemetry-test-utils: add CapturingSampler to record what samplers receive in instrumentation tests (#5681)

Changed

  • Enable PIE (flake8-pie) ruff rule and fix all violations (#5150)
  • The public opentelemetry.util.types.AttributeValue type in package opentelemetry-api is being expanded to include None, heterogeneous sequences of primitive types (and nested sequences) as opposed to only homogeneous primitive sequences, and Mappings of strings to any primitive types or sequences/mappings (which themselves must only contain primitive types or sequences/mappings validated the same way). If a bytes type is set as an attribute value in the SDK, it will no longer be utf-8 decoded to a string, instead it will be passed along as is in accordance with the OTEL spec, since bytes is a valid type in the OTLP proto. (#5266)
  • opentelemetry-exporter-otlp-proto-http: add a max_request_size argument to the OTLP HTTP exporters (traces, logs, metrics); serialized requests larger than the limit are dropped before sending, measured before compression. Defaults to 64 MiB (enabled); set to 0 to disable. Mirrors opentelemetry-go#8157. (#5369)
  • [BREAKING] opentelemetry-api: subclasses of Logger need to implement the enabled method (#5380)
  • opentelemetry-exporter-otlp-proto-http: refactor to use shared opentelemetry-exporter-otlp-common and opentelemetry-exporter-http-transport packages and switch default HTTP backend to urllib3 (#5389)
  • opentelemetry-sdk: unify logging force_flush timeout defaults to 30000ms (#5438)
  • opentelemetry-python: enable Ruff default ruleset and fix auto-fixable lint issues (#5491)
  • opentelemetry-sdk: SimpleSpanProcessor now drops spans ended after shutdown() instead of passing them to the exporter, and counts them on otel.sdk.processor.span.processed with error.type=already_shutdown. (#5512)
  • Bump pytest to 9.0.3 (#5518)
  • opentelemetry-exporter-otlp-proto-http: clarify that the endpoint= kwarg requires the full signal path (#5633)
  • opentelemetry-sdk: fix typos in SpanLimits docstring (#5658)

Fixed

  • opentelemetry-configuration: perform environment variable substitution on scalar values after parsing the configuration file, so ${VAR} references inside comments and mapping keys are no longer substituted and undefined references in comments no longer abort loading (#5407)
  • opentelemetry-configuration: declarative config environment variable substitution now replaces an unset variable that has no default with an empty value instead of raising an error, per the configuration spec. Resource attributes whose value resolves to null (an unset ${VAR} with no default) are skipped with a warning instead of being inserted as a null value. (#5408)
  • 'scripts/build.sh: add opentelemetry-configurationandopentelemetry-proto-json` to the package to release (#5425)
  • opentelemetry-sdk: fix View instrument-name matching so a view configured with an instrument's real (mixed-case) name is applied; matching is now case-insensitive and platform-independent instead of relying on fnmatch's OS-dependent case handling (#5430)
  • opentelemetry-sdk: fix missing f-prefix in exponential histogram error messages (#5434)
  • opentelemetry-configuration: resolve false-positive warning logs for newer schema minor version (#5436)
  • opentelemetry-sdk: make methods on FixedSizeExemplarReservoirABC thread safe (#5437)
  • opentelemetry-propagator-jaeger: fix typing issues and enable pyright typechecking for the package opentelemetry-propagator-jaeger: skip uberctx- baggage headers with an empty value on extraction instead of raising TypeError (#5440)
  • opentelemetry-sdk: fix TypeError when instantiating a _BaseConfigurator subclass whose __init__ takes arguments (#5441)
  • opentelemetry-sdk: fix TypeError in os.fork() when a BatchProcessor or PeriodicExportingMetricReader is garbage collected (#5453)
  • opentelemetry-configuration: a declarative config key present with an empty (null) value on an object-typed node (e.g. always_on:, a - service: detector, or a metric console: exporter) is now treated the same as an explicit empty config (always_on: {}) instead of failing type dispatch or silently skipping the node. Both dict-typed nodes and dataclasses constructible with no arguments are covered. (#5454)
  • opentelemetry-api: fix copy-pasted log message in SpanContext.__delattr__ (#5455)
  • opentelemetry-sdk: reject views with ExponentialBucketHistogramAggregation for asynchronous instruments instead of silently producing no data (#5461)
  • opentelemetry-sdk: fill every bucket of SimpleFixedSizeExemplarReservoir before random sampling (#5462)

... (truncated)

Changelog

Sourced from opentelemetry-api's changelog.

Version 1.45.0/0.66b0 (2026-09-25)

Added

  • opentelemetry-exporter-prometheus: add support to configure Resource attributes as metric labels (#5122)
  • infra: add renovate (#5202)
  • opentelemetry-api, opentelemetry-sdk: add support for extended attribute values everywhere. (#5266)
  • opentelemetry-sdk: wire the top-level log_level field in declarative configuration — when set, maps the OTel SeverityNumber value to a Python logging level and applies it to the opentelemetry logger so SDK internal diagnostics respect the configured severity. (#5351)
  • opentelemetry-sdk: add the new stable AlwaysRecordSampler (

Updates the requirements on [langgraph](https://github.com/langchain-ai/langgraph), [langchain](https://github.com/langchain-ai/langchain), [langchain-core](https://github.com/langchain-ai/langchain), [langchain-google-genai](https://github.com/langchain-ai/langchain-google), [python-dotenv](https://github.com/theskumar/python-dotenv), [fastapi](https://github.com/fastapi/fastapi), [uvicorn](https://github.com/Kludex/uvicorn), [pydantic](https://github.com/pydantic/pydantic), [httpx](https://github.com/encode/httpx), [opentelemetry-api](https://github.com/open-telemetry/opentelemetry-python), [opentelemetry-sdk](https://github.com/open-telemetry/opentelemetry-python), [opentelemetry-exporter-otlp-proto-http](https://github.com/open-telemetry/opentelemetry-python) and ibm-watsonx-orchestrate to permit the latest version.

Updates `langgraph` to 1.2.12
- [Release notes](https://github.com/langchain-ai/langgraph/releases)
- [Commits](langchain-ai/langgraph@0.2.0...1.2.12)

Updates `langchain` to 1.4.3
- [Release notes](https://github.com/langchain-ai/langchain/releases)
- [Commits](langchain-ai/langchain@langchain==0.3.0...langchain==1.4.3)

Updates `langchain-core` to 1.6.5
- [Release notes](https://github.com/langchain-ai/langchain/releases)
- [Commits](langchain-ai/langchain@langchain-core==0.3.0...langchain-core==1.6.5)

Updates `langchain-google-genai` to 4.4.0
- [Release notes](https://github.com/langchain-ai/langchain-google/releases)
- [Commits](langchain-ai/langchain-google@libs/genai/v2.0.0...libs/genai/v4.4.0)

Updates `python-dotenv` to 1.2.3
- [Release notes](https://github.com/theskumar/python-dotenv/releases)
- [Changelog](https://github.com/theskumar/python-dotenv/blob/main/CHANGELOG.md)
- [Commits](theskumar/python-dotenv@v1.0.0...v1.2.3)

Updates `fastapi` to 0.141.1
- [Release notes](https://github.com/fastapi/fastapi/releases)
- [Commits](fastapi/fastapi@0.115.0...0.141.1)

Updates `uvicorn` to 0.54.0
- [Release notes](https://github.com/Kludex/uvicorn/releases)
- [Changelog](https://github.com/Kludex/uvicorn/blob/main/docs/release-notes.md)
- [Commits](Kludex/uvicorn@0.32.0...0.54.0)

Updates `pydantic` to 2.13.5
- [Release notes](https://github.com/pydantic/pydantic/releases)
- [Changelog](https://github.com/pydantic/pydantic/blob/v2.13.5/HISTORY.md)
- [Commits](pydantic/pydantic@v2.9.0...v2.13.5)

Updates `httpx` to 0.28.1
- [Release notes](https://github.com/encode/httpx/releases)
- [Changelog](https://github.com/encode/httpx/blob/master/CHANGELOG.md)
- [Commits](encode/httpx@0.27.0...0.28.1)

Updates `opentelemetry-api` to 1.45.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-python/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-python/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-python@v1.27.0...v1.45.0)

Updates `opentelemetry-sdk` to 1.45.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-python/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-python/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-python@v1.27.0...v1.45.0)

Updates `opentelemetry-exporter-otlp-proto-http` to 1.45.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-python/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-python/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-python@v1.27.0...v1.45.0)

Updates `ibm-watsonx-orchestrate` to 2.17.0

---
updated-dependencies:
- dependency-name: langgraph
  dependency-version: 1.2.12
  dependency-type: direct:production
  dependency-group: all-dependencies
- dependency-name: langchain
  dependency-version: 1.4.3
  dependency-type: direct:production
  dependency-group: all-dependencies
- dependency-name: langchain-core
  dependency-version: 1.6.5
  dependency-type: direct:production
  dependency-group: all-dependencies
- dependency-name: langchain-google-genai
  dependency-version: 4.4.0
  dependency-type: direct:production
  dependency-group: all-dependencies
- dependency-name: python-dotenv
  dependency-version: 1.2.3
  dependency-type: direct:production
  dependency-group: all-dependencies
- dependency-name: fastapi
  dependency-version: 0.141.1
  dependency-type: direct:production
  dependency-group: all-dependencies
- dependency-name: uvicorn
  dependency-version: 0.54.0
  dependency-type: direct:production
  dependency-group: all-dependencies
- dependency-name: pydantic
  dependency-version: 2.13.5
  dependency-type: direct:production
  dependency-group: all-dependencies
- dependency-name: httpx
  dependency-version: 0.28.1
  dependency-type: direct:production
  dependency-group: all-dependencies
- dependency-name: opentelemetry-api
  dependency-version: 1.45.0
  dependency-type: direct:production
  dependency-group: all-dependencies
- dependency-name: opentelemetry-sdk
  dependency-version: 1.45.0
  dependency-type: direct:production
  dependency-group: all-dependencies
- dependency-name: opentelemetry-exporter-otlp-proto-http
  dependency-version: 1.45.0
  dependency-type: direct:production
  dependency-group: all-dependencies
- dependency-name: ibm-watsonx-orchestrate
  dependency-version: 2.17.0
  dependency-type: direct:production
  dependency-group: all-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Oct 2, 2026
@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown

Thanks, Dependabot! 🤖

This PR is a routine version bump with no associated CVE or security advisory, so it is being closed automatically per our policy.

Why? Routine upgrades carry compatibility risk and are reviewed manually as part of planned maintenance — not auto-merged.

Security PRs (those fixing a known CVE/GHSA, labelled `security`, or containing CVE references in the description) are merged automatically. To see open security alerts, visit the Security tab.

@github-actions github-actions Bot closed this Oct 2, 2026
@dependabot @github

dependabot Bot commented on behalf of github Oct 2, 2026

Copy link
Copy Markdown
Contributor Author

This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests.

To ignore these dependencies, configure ignore rules in dependabot.yml

@dependabot
dependabot Bot deleted the dependabot/pip/i-oic-wxo-external-agent-observability/all-dependencies-d977cb9d8c branch October 2, 2026 07:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants