Skip to content

chore(deps): bump the all-dependencies group in /siri-watsonx-orchestrate with 6 updates - #771

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/siri-watsonx-orchestrate/all-dependencies-a469c15e06
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/siri-watsonx-orchestrate/all-dependencies-a469c15e06

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 2, 2026

Copy link
Copy Markdown
Contributor

Bumps the all-dependencies group in /siri-watsonx-orchestrate with 6 updates:

Package From To
fqdn 1.5.1 1.6.0
ibm-cloud-sdk-core 3.26.1 3.26.2
ibm-watsonx-orchestrate-evaluation-framework 1.6.3 1.6.4
langsmith 0.14.0 0.14.1
platformdirs 4.11.13 4.12.1
pyjwt 2.15.0 2.15.1

Updates fqdn from 1.5.1 to 1.6.0

Release notes

Sourced from fqdn's releases.

v1.6.0

Added

  • fqdn/__init__.pyi type stubs and a py.typed marker, so type checkers resolve the public API.
  • A CI matrix over Linux, macOS and Windows on Python 3.10 through 3.14, plus a compatibility job that installs the built wheel on Python 3.8 and 3.9.
  • CodeQL, OSSAR, OpenSSF Scorecard, Snyk and FOSSA scanning workflows.
  • A release workflow that publishes to PyPI over trusted publishing when a v* tag is pushed, and opens a GitHub release from the matching changelog section.
  • Read the Docs configuration and a Sphinx build for the existing docs.
  • CONTRIBUTING.md, AGENTS.md and issue and pull request templates.
  • Renovate configuration for security updates and lock file maintenance.

Changed

  • Packaging moved from setup.py/setup.cfg/bumpversion to pyproject.toml with setuptools_scm; the version is derived from the git tag.
  • Linting moved from flake8, black and prospector to ruff, and mypy now checks the package.
  • The README is Markdown and carries a full badge wall.
  • tests/test_fqdn.py import block is sorted to satisfy ruff.

Removed

  • setup.py, setup.cfg, .bumpversion.cfg, tox.ini, .flake8 and .prospector.yml.

Notes

  • The published metadata still advertises Python 2.7 and newer, and the wheel still installs there. The source distribution no longer builds on interpreters older than 3.9, which the build backend requires.
Changelog

Sourced from fqdn's changelog.

[1.6.0] - 2026-09-28

Added

  • fqdn/__init__.pyi type stubs and a py.typed marker, so type checkers resolve the public API.
  • A CI matrix over Linux, macOS and Windows on Python 3.10 through 3.14, plus a compatibility job that installs the built wheel on Python 3.8 and 3.9.
  • CodeQL, OSSAR, OpenSSF Scorecard, Snyk and FOSSA scanning workflows.
  • A release workflow that publishes to PyPI over trusted publishing when a v* tag is pushed, and opens a GitHub release from the matching changelog section.
  • Read the Docs configuration and a Sphinx build for the existing docs.
  • CONTRIBUTING.md, AGENTS.md and issue and pull request templates.
  • Renovate configuration for security updates and lock file maintenance.

Changed

  • Packaging moved from setup.py/setup.cfg/bumpversion to pyproject.toml with setuptools_scm; the version is derived from the git tag.
  • Linting moved from flake8, black and prospector to ruff, and mypy now checks the package.
  • The README is Markdown and carries a full badge wall.
  • tests/test_fqdn.py import block is sorted to satisfy ruff.

Removed

  • setup.py, setup.cfg, .bumpversion.cfg, tox.ini, .flake8 and .prospector.yml.

Notes

  • The published metadata still advertises Python 2.7 and newer, and the wheel still installs there. The source distribution no longer builds on interpreters older than 3.9, which the build backend requires.
Commits
  • a71a6c0 Release 1.6.0
  • 90ddcb3 Snyk: scan a marker-free pip freeze of the installed environment (#53)
  • 18c8a43 Snyk: scan the locked pip set instead of a malformed --command
  • 03aed15 SECURITY: direct vulnerability reports to GitHub private advisories
  • 47359e5 mailmap: map ypcrts commits to hgto
  • a887863 Community: contributing, agents, templates, pre-commit and Renovate
  • 3b44989 Release: publish to PyPI on tags via trusted publishing
  • 36409b2 Security: add OSSAR, Scorecard, Snyk and FOSSA scanning
  • a724795 CI: cross-OS Python matrix, lint/type/package jobs, current CodeQL
  • fe889e2 Docs: convert README to Markdown, revive the Sphinx build for Read the Docs
  • Additional commits viewable in compare view

Updates ibm-cloud-sdk-core from 3.26.1 to 3.26.2

Release notes

Sourced from ibm-cloud-sdk-core's releases.

v3.26.2

3.26.2 (2026-09-28)

Bug Fixes

  • prevent secret redaction from bleeding past EOL (#246) (6da3b21)
Changelog

Sourced from ibm-cloud-sdk-core's changelog.

3.26.2 (2026-09-28)

Bug Fixes

  • prevent secret redaction from bleeding past EOL (#246) (6da3b21)
Commits

Updates ibm-watsonx-orchestrate-evaluation-framework from 1.6.3 to 1.6.4

Updates langsmith from 0.14.0 to 0.14.1

Release notes

Sourced from langsmith's releases.

v0.14.1

What's Changed

Full Changelog: langchain-ai/langsmith-sdk@v0.14.0...v0.14.1

Commits
  • c51e722 release(py): 0.14.1 (#3595)
  • 8bf29ab feat(sandbox): verify service URL user tokens and proxy callbacks (#3593)
  • 7401954 fix(py): trace ClaudeSDKClient.receive_messages() (#3576)
  • b78314f fix(py): fix missing OTel exports for tool_call_id and tool_definitions (#3584)
  • 6cd0d6e fix(py): select s3_urls so list_runs and list_threads return attachments (#3590)
  • 9207dfb ci: drop the push-based mirror workflow, staging pulls instead (#3580)
  • 1d3e54a ci: mirror merges to the staging repos (#3578)
  • ad399f1 release(js): 0.10.5 (#3575)
  • See full diff in compare view

Updates platformdirs from 4.11.13 to 4.12.1

Release notes

Sourced from platformdirs's releases.

4.12.1

What's Changed

Full Changelog: tox-dev/platformdirs@4.12.0...4.12.1

4.12.0

What's Changed

Full Changelog: tox-dev/platformdirs@4.11.15...4.12.0

4.11.15

What's Changed

Full Changelog: tox-dev/platformdirs@4.11.14...4.11.15

4.11.14

What's Changed

... (truncated)

Changelog

Sourced from platformdirs's changelog.

########### Changelog ###########

.. towncrier-draft-entries:: Unreleased

.. towncrier release notes start


4.12.2 (2026-09-29)


  • Keep os.pathsep in site_applications_path under multipath=True on platforms with one applications directory. :pr:604

4.12.1 (2026-09-28)


  • Avoid PytestAssertRewriteWarning when importing platformdirs before invoking pytest. :pr:601

4.12.0 (2026-09-26)


  • Add place_*_file methods that return a file path under a user directory and create its missing parents with mode 0o700. :pr:585
  • Add find_<kind>_file and find_<kind>_files to look up an existing file across the user and site directories of each kind that has an iter_<kind>_paths method. :pr:586
  • Add :func:platformdirs.testing.isolated_dirs and the platformdirs_isolated pytest fixture to resolve every directory under one test root. :pr:590
  • Emit :class:~platformdirs.RuntimeDirWarning when the Unix :func:~platformdirs.user_runtime_dir falls back from XDG_RUNTIME_DIR. :pr:599
  • Read user_templates_dir, user_publicshare_dir and user_bin_dir on Windows from their known folders. :pr:587
  • Create missing user app directories and their parents with mode 0700 under ensure_exists on POSIX platforms. :pr:588
  • Raise RuntimeError for a Unix or macOS directory under the home when no home resolves, and read the password database for an empty HOME. :pr:589
  • Skip an XDG_RUNTIME_DIR or /run/user/<uid> that is not a private directory of the user, and reject a symlink or file as the runtime-<uid> fallback. :pr:599
  • Use the app container layout on iOS, such as ~/Library/Application Support for data. :pr:600
  • Document that a Homebrew Python puts the Homebrew prefix first in the macOS shared directories, with or without multipath. :pr:591
  • Document that the macOS media directories honor the XDG_*_DIR variables. :pr:592
  • Document the WIN_PD_OVERRIDE_COMMON_PROGRAMS variable. :pr:593
  • Document /usr/local/share/applications as the Linux site_applications_dir default. :pr:594
  • Correct the BSD user_runtime_dir defaults and describe the temporary directory fallback. :pr:595
  • Describe how platformdirs detects Android, finds the app folder and places the shared folders. :pr:596
  • Document that Microsoft Store Python redirects only new files and folders under AppData. :pr:597

... (truncated)

Commits
  • 0a50795 Release 4.12.1
  • 72e93ff fix(pytest): allow import before pytest startup (#602)
  • ea7be87 Release 4.12.0
  • de46f51 🐛 fix(unix): validate XDG_RUNTIME_DIR and warn on fallback (#599)
  • ca2b313 🐛 fix(dirs): raise when no home directory resolves (#589)
  • c34e758 🐛 fix(dirs): create user directories with mode 0700 (#588)
  • f88693c ✨ feat(api): add find_*_file methods for user and site lookup (#586)
  • ba1cc1e 🐛 fix(windows): resolve templates, public and bin dirs by known folder (#587)
  • 9f2ee08 ✨ feat(testing): redirect every directory under a test root (#590)
  • dfaeabf ✨ feat(api): add place_*_file methods that create parents as 0700 (#585)
  • Additional commits viewable in compare view

Updates pyjwt from 2.15.0 to 2.15.1

Release notes

Sourced from pyjwt's releases.

2.15.1

See the 2.15.1 changelog for complete release details.

Changelog

Sourced from pyjwt's changelog.

v2.15.1 <https://github.com/jpadilla/pyjwt/compare/2.15.0...2.15.1>__

Fixed


- Accept trailing Base64URL ``=`` padding when decoding JWS segments, so
  tokens issued by AWS ALB and similar systems verify instead of raising
  ``DecodeError: Invalid crypto padding``. Non-alphabet junk such as
  ``!!!!`` remains rejected (`[#1209](https://github.com/jpadilla/pyjwt/issues/1209) <https://github.com/jpadilla/pyjwt/issues/1209>`__).
Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the all-dependencies group in /siri-watsonx-orchestrate with 6 updates:

| Package | From | To |
| --- | --- | --- |
| [fqdn](https://github.com/ypcrts/fqdn) | `1.5.1` | `1.6.0` |
| [ibm-cloud-sdk-core](https://github.com/IBM/python-sdk-core) | `3.26.1` | `3.26.2` |
| ibm-watsonx-orchestrate-evaluation-framework | `1.6.3` | `1.6.4` |
| [langsmith](https://github.com/langchain-ai/langsmith-sdk) | `0.14.0` | `0.14.1` |
| [platformdirs](https://github.com/tox-dev/platformdirs) | `4.11.13` | `4.12.1` |
| [pyjwt](https://github.com/jpadilla/pyjwt) | `2.15.0` | `2.15.1` |


Updates `fqdn` from 1.5.1 to 1.6.0
- [Release notes](https://github.com/ypcrts/fqdn/releases)
- [Changelog](https://github.com/ypcrts/fqdn/blob/develop/CHANGELOG.md)
- [Commits](ypcrts/fqdn@v1.5.1...v1.6.0)

Updates `ibm-cloud-sdk-core` from 3.26.1 to 3.26.2
- [Release notes](https://github.com/IBM/python-sdk-core/releases)
- [Changelog](https://github.com/IBM/python-sdk-core/blob/main/CHANGELOG.md)
- [Commits](IBM/python-sdk-core@v3.26.1...v3.26.2)

Updates `ibm-watsonx-orchestrate-evaluation-framework` from 1.6.3 to 1.6.4

Updates `langsmith` from 0.14.0 to 0.14.1
- [Release notes](https://github.com/langchain-ai/langsmith-sdk/releases)
- [Commits](langchain-ai/langsmith-sdk@v0.14.0...v0.14.1)

Updates `platformdirs` from 4.11.13 to 4.12.1
- [Release notes](https://github.com/tox-dev/platformdirs/releases)
- [Changelog](https://github.com/tox-dev/platformdirs/blob/main/docs/changelog.rst)
- [Commits](tox-dev/platformdirs@4.11.13...4.12.1)

Updates `pyjwt` from 2.15.0 to 2.15.1
- [Release notes](https://github.com/jpadilla/pyjwt/releases)
- [Changelog](https://github.com/jpadilla/pyjwt/blob/master/CHANGELOG.rst)
- [Commits](jpadilla/pyjwt@2.15.0...2.15.1)

---
updated-dependencies:
- dependency-name: fqdn
  dependency-version: 1.6.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-dependencies
- dependency-name: ibm-cloud-sdk-core
  dependency-version: 3.26.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all-dependencies
- dependency-name: ibm-watsonx-orchestrate-evaluation-framework
  dependency-version: 1.6.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all-dependencies
- dependency-name: langsmith
  dependency-version: 0.14.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all-dependencies
- dependency-name: platformdirs
  dependency-version: 4.12.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-dependencies
- dependency-name: pyjwt
  dependency-version: 2.15.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Oct 2, 2026
@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown

Thanks, Dependabot! 🤖

This PR is a routine version bump with no associated CVE or security advisory, so it is being closed automatically per our policy.

Why? Routine upgrades carry compatibility risk and are reviewed manually as part of planned maintenance — not auto-merged.

Security PRs (those fixing a known CVE/GHSA, labelled `security`, or containing CVE references in the description) are merged automatically. To see open security alerts, visit the Security tab.

@github-actions github-actions Bot closed this Oct 2, 2026
@dependabot @github

dependabot Bot commented on behalf of github Oct 2, 2026

Copy link
Copy Markdown
Contributor Author

This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests.

To ignore these dependencies, configure ignore rules in dependabot.yml

@dependabot
dependabot Bot deleted the dependabot/pip/siri-watsonx-orchestrate/all-dependencies-a469c15e06 branch October 2, 2026 07:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants