Repository navigation
chore(deps): bump the all-dependencies group in /i-oic-wxo-external-agent-observability with 13 updates - #770
Closed
dependabot[bot] wants to merge 1 commit into
Conversation
Updates the requirements on [langgraph](https://github.com/langchain-ai/langgraph), [langchain](https://github.com/langchain-ai/langchain), [langchain-core](https://github.com/langchain-ai/langchain), [langchain-google-genai](https://github.com/langchain-ai/langchain-google), [python-dotenv](https://github.com/theskumar/python-dotenv), [fastapi](https://github.com/fastapi/fastapi), [uvicorn](https://github.com/Kludex/uvicorn), [pydantic](https://github.com/pydantic/pydantic), [httpx](https://github.com/encode/httpx), [opentelemetry-api](https://github.com/open-telemetry/opentelemetry-python), [opentelemetry-sdk](https://github.com/open-telemetry/opentelemetry-python), [opentelemetry-exporter-otlp-proto-http](https://github.com/open-telemetry/opentelemetry-python) and ibm-watsonx-orchestrate to permit the latest version. Updates `langgraph` to 1.2.12 - [Release notes](https://github.com/langchain-ai/langgraph/releases) - [Commits](langchain-ai/langgraph@0.2.0...1.2.12) Updates `langchain` to 1.4.3 - [Release notes](https://github.com/langchain-ai/langchain/releases) - [Commits](langchain-ai/langchain@langchain==0.3.0...langchain==1.4.3) Updates `langchain-core` to 1.6.5 - [Release notes](https://github.com/langchain-ai/langchain/releases) - [Commits](langchain-ai/langchain@langchain-core==0.3.0...langchain-core==1.6.5) Updates `langchain-google-genai` to 4.4.0 - [Release notes](https://github.com/langchain-ai/langchain-google/releases) - [Commits](langchain-ai/langchain-google@libs/genai/v2.0.0...libs/genai/v4.4.0) Updates `python-dotenv` to 1.2.3 - [Release notes](https://github.com/theskumar/python-dotenv/releases) - [Changelog](https://github.com/theskumar/python-dotenv/blob/main/CHANGELOG.md) - [Commits](theskumar/python-dotenv@v1.0.0...v1.2.3) Updates `fastapi` to 0.141.1 - [Release notes](https://github.com/fastapi/fastapi/releases) - [Commits](fastapi/fastapi@0.115.0...0.141.1) Updates `uvicorn` to 0.54.0 - [Release notes](https://github.com/Kludex/uvicorn/releases) - [Changelog](https://github.com/Kludex/uvicorn/blob/main/docs/release-notes.md) - [Commits](Kludex/uvicorn@0.32.0...0.54.0) Updates `pydantic` to 2.13.5 - [Release notes](https://github.com/pydantic/pydantic/releases) - [Changelog](https://github.com/pydantic/pydantic/blob/v2.13.5/HISTORY.md) - [Commits](pydantic/pydantic@v2.9.0...v2.13.5) Updates `httpx` to 0.28.1 - [Release notes](https://github.com/encode/httpx/releases) - [Changelog](https://github.com/encode/httpx/blob/master/CHANGELOG.md) - [Commits](encode/httpx@0.27.0...0.28.1) Updates `opentelemetry-api` to 1.45.0 - [Release notes](https://github.com/open-telemetry/opentelemetry-python/releases) - [Changelog](https://github.com/open-telemetry/opentelemetry-python/blob/main/CHANGELOG.md) - [Commits](open-telemetry/opentelemetry-python@v1.27.0...v1.45.0) Updates `opentelemetry-sdk` to 1.45.0 - [Release notes](https://github.com/open-telemetry/opentelemetry-python/releases) - [Changelog](https://github.com/open-telemetry/opentelemetry-python/blob/main/CHANGELOG.md) - [Commits](open-telemetry/opentelemetry-python@v1.27.0...v1.45.0) Updates `opentelemetry-exporter-otlp-proto-http` to 1.45.0 - [Release notes](https://github.com/open-telemetry/opentelemetry-python/releases) - [Changelog](https://github.com/open-telemetry/opentelemetry-python/blob/main/CHANGELOG.md) - [Commits](open-telemetry/opentelemetry-python@v1.27.0...v1.45.0) Updates `ibm-watsonx-orchestrate` to 2.17.0 --- updated-dependencies: - dependency-name: langgraph dependency-version: 1.2.12 dependency-type: direct:production dependency-group: all-dependencies - dependency-name: langchain dependency-version: 1.4.3 dependency-type: direct:production dependency-group: all-dependencies - dependency-name: langchain-core dependency-version: 1.6.5 dependency-type: direct:production dependency-group: all-dependencies - dependency-name: langchain-google-genai dependency-version: 4.4.0 dependency-type: direct:production dependency-group: all-dependencies - dependency-name: python-dotenv dependency-version: 1.2.3 dependency-type: direct:production dependency-group: all-dependencies - dependency-name: fastapi dependency-version: 0.141.1 dependency-type: direct:production dependency-group: all-dependencies - dependency-name: uvicorn dependency-version: 0.54.0 dependency-type: direct:production dependency-group: all-dependencies - dependency-name: pydantic dependency-version: 2.13.5 dependency-type: direct:production dependency-group: all-dependencies - dependency-name: httpx dependency-version: 0.28.1 dependency-type: direct:production dependency-group: all-dependencies - dependency-name: opentelemetry-api dependency-version: 1.45.0 dependency-type: direct:production dependency-group: all-dependencies - dependency-name: opentelemetry-sdk dependency-version: 1.45.0 dependency-type: direct:production dependency-group: all-dependencies - dependency-name: opentelemetry-exporter-otlp-proto-http dependency-version: 1.45.0 dependency-type: direct:production dependency-group: all-dependencies - dependency-name: ibm-watsonx-orchestrate dependency-version: 2.17.0 dependency-type: direct:production dependency-group: all-dependencies ... Signed-off-by: dependabot[bot] <support@github.com>
|
Thanks, Dependabot! 🤖 This PR is a routine version bump with no associated CVE or security advisory, so it is being closed automatically per our policy. Why? Routine upgrades carry compatibility risk and are reviewed manually as part of planned maintenance — not auto-merged. Security PRs (those fixing a known CVE/GHSA, labelled `security`, or containing CVE references in the description) are merged automatically. To see open security alerts, visit the Security tab. |
Contributor
Author
|
This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests. To ignore these dependencies, configure ignore rules in dependabot.yml |
dependabot
Bot
deleted the
dependabot/pip/i-oic-wxo-external-agent-observability/all-dependencies-d977cb9d8c
branch
October 2, 2026 07:02
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Updates the requirements on langgraph, langchain, langchain-core, langchain-google-genai, python-dotenv, fastapi, uvicorn, pydantic, httpx, opentelemetry-api, opentelemetry-sdk, opentelemetry-exporter-otlp-proto-http and ibm-watsonx-orchestrate to permit the latest version.
Updates
langgraphto 1.2.12Release notes
Sourced from langgraph's releases.
Commits
49cce0crelease(sdk-py): 0.4.5 (#8988)19273farelease(langgraph): 1.2.12 (#8987)ed384f3fix(cli): remediate AnyIO vulnerabilities in example lockfiles (#9022)aa742fbchore(deps): bump anyio from 4.14.2 to 4.15.1 in /libs/sdk-py (#8997)b58044achore(deps): bump anyio from 4.13.0 to 4.14.2 in /libs/cli (#8998)daa514achore(deps): bump anyio from 4.13.0 to 4.14.2 in /libs/checkpoint-conformance...022043achore(deps): bump anyio from 4.12.1 to 4.14.2 in /libs/checkpoint (#8995)d7b99ccchore(deps): bump anyio from 4.12.1 to 4.14.2 in /libs/sdk-py (#8994)b19edd7chore(deps): bump anyio from 4.12.1 to 4.14.2 in /libs/checkpoint-sqlite (#8993)c81c135chore(deps): bump soupsieve from 2.8.4 to 2.9 in /libs/langgraph (#8958)Updates
langchainto 1.4.3Release notes
Sourced from langchain's releases.
Commits
be854a1release(langchain): 1.4.3 (#40888)2ade674fix(langchain): sanitize cache settings for fallback models (#40886)88b9727feat(fireworks): add prompt caching middleware (#38823)60e57f5fix(fireworks): classify mid-stream read timeouts (#40874)42f04f4docs: update OpenWiki (#40781)213f230chore(model-profiles): refresh model profile data (#40869)d750819chore(model-profiles): refresh model profile data (#40833)1ef23d6fix(anthropic): serialize invalid tool calls as tool use on replay (#40864)80b7409feat(langchain): support Bedrock Mantle chat models ininit_chat_model(#40...40fe8d6docs(core): fix docstring examples that don't run as copied (#40815)Updates
langchain-coreto 1.6.5Release notes
Sourced from langchain-core's releases.
Commits
c5ab14drelease(core): 1.6.5 (#40816)5704d9dchore(model-profiles): refresh model profile data (#40804)7622d3drelease(openai): 1.6.6 (#40800)2dd956bdocs(infra): fix AGENTS.md root setup guidance and package doc accuracy (#40794)49f4b40fix(openai): raise on error events in stream path (#40791)19cadaafix(core): abbreviate long tool IDs in XML buffer strings (#40792)798441echore(anthropic): fix integration test cassette (#40790)a476942release(openai): 1.6.5 (#40787)46c6bdfrelease(anthropic): 1.7.4 (#40786)290dabafix(anthropic): add Opus 5.5 and GPT-6 profile augmentations (#40785)Updates
langchain-google-genaito 4.4.0Release notes
Sourced from langchain-google-genai's releases.
Commits
d38d42frelease(genai): 4.4.0 (#1989)e52ace7feat(genai): support agentic video understanding (#1988)3d9e491release(genai): 4.3.7 (#1977)df0901bfix(genai): apply distinct indexes to repeated block types (#1974)9bd41b7chore: bump types-google-cloud-ndb from 2.4.0.20260518 to 2.4.0.20260724 in /...fcbb0d7chore: bump the major group in /libs/community with 3 updates (#1920)71a17cfchore: bump the minor-and-patch group across 1 directory with 6 updates (#1969)a6206c3fix(vertexai): bump pyarrow dependency (#1962)d530f2ffix(genai): remove__del__that closes a potentially shared client (#1963)bd39818fix(genai): sendskip_thought_signature_validatoras a literal string (#1972)Updates
python-dotenvto 1.2.3Release notes
Sourced from python-dotenv's releases.
Changelog
Sourced from python-dotenv's changelog.
... (truncated)
Commits
49515afBump version: 1.2.2 → 1.2.38ac846fchore: add release runbook (RELEASING.md) and make release targetbb31c94docs: add 1.2.3 release notes (#606, #638, #680)f7b18d9fix: round-trip backslashes through set_key (#680)751f8c1ci(deps): bump actions/checkout from 6.0.2 to 6.0.3 in the github-actions gro...f1937b6chore(deps): update mkdocs-include-markdown-plugin requirement from >=6.0.0 t...45b9372chore(deps): update pytest requirement from >=3.9 to >=9.0.3 (#653)72896e9docs: fix broken mkdocs link in CONTRIBUTING.md (#636)72754a1ci(deps): bump peaceiris/actions-gh-pages from 4.0.0 to 4.1.0 in the github-a...078325eci(security): harden CI/CD supply chain with SHA pinning and least-privilege ...Updates
fastapito 0.141.1Release notes
Sourced from fastapi's releases.
Commits
95f8322🔖 Release version 0.141.1 (#16106)f137944📝 Update release notesd623544🐛 Fix support for background tasks and headers from dependencies in `app.fron...1d211b9📝 Update release notes8a1f876📝 DocumentFASTAPI_ENVin FastAPI CLI guide (#16104)c7e7b65🔖 Release version 0.141.0 (#16103)6bceb84📝 Update release notes5429fed✨ Addapp.frontend(check_dir="auto"), to make local development more conven...628663f🔖 Release version 0.140.13 (#16096)0b54fd0📝 Update release notesUpdates
uvicornto 0.54.0Release notes
Sourced from uvicorn's releases.
Changelog
Sourced from uvicorn's changelog.
... (truncated)
Commits
3eb9a9aVersion 0.54.0 (#3161)cd7ef6dRemove races from supervisor tests (#3134)a56c7ccSupport HTTP/2 response trailers (#3146)9bd4404chore(deps): bump anyio from 4.13.0 to 4.14.2 (#3145)21f39efAdd HTTP/2 Early Hints support (#3137)421708fVersion 0.53.0 (#3136)f1a1bffUnset the keep-alive timer when upgrading to WebSocket (#3107)63971edDocument HTTP/2 support (#3130)7d1a005Remove race from multiprocess health check test (#3128)5ac6265Add ::1 to FORWARDED_ALLOW_IPS (#3119)Updates
pydanticto 2.13.5Release notes
Sourced from pydantic's releases.
Changelog
Sourced from pydantic's changelog.
... (truncated)
Commits
001dea0Bumppypa/gh-action-pypi-publishaction to v1.14.2558379fBump twine to v7.0.02cfd5d3Do not check for docs builda735beeFix more Clippy lints7eed4a1Fix Clippy 0.1.95 warningsb353bbbPrepare release v2.13.563d2cccCount validated model fields once in smart unionsa53ec2eSpeed up PyPy CI testsd65e0f9Workaround circular import error in Mypy47a6dbfFix missing GC traversal inpydantic-coreforGeneralFieldsSerializerUpdates
httpxto 0.28.1Release notes
Sourced from httpx's releases.
Changelog
Sourced from httpx's changelog.
... (truncated)
Commits
26d48e0Version 0.28.1 (#3445)89599a9Fixverify=False,cert=...case. (#3442)8ecb86fAdd test for request params behavior changes (#3364) (#3440)0cb7e5aBump the python-packages group with 11 updates (#3434)15e21e9Updating deprecated docstring Client() class (#3426)80960faVersion 0.28.0. (#3419)a33c878Fixextensionstype annotation. (#3380)ce7e14dError on verify as str. (#3418)47f4a96Handle empty zstd responses (#3412)189fc4bUpdate CHANGELOG.md, fix typo(s) (#3406)Updates
opentelemetry-apito 1.45.0Release notes
Sourced from opentelemetry-api's releases.
... (truncated)
Changelog
Sourced from opentelemetry-api's changelog.