Skip to content

Scheduled weekly dependency update for week 21 - #1023

Merged
rokm merged 30 commits into
masterfrom
pyup-scheduled-update-2026-05-25
May 26, 2026
Merged

rokm merged 30 commits into
masterfrom
pyup-scheduled-update-2026-05-25

Conversation

@pyup-bot

Copy link
Copy Markdown
Collaborator

Update boto3 from 1.43.9 to 1.43.14.

Changelog

1.43.14

=======

* api-change:``datazone``: [``botocore``] Add support for VPC connection
* api-change:``ec2``: [``botocore``] The ModifyInstanceAttribute API now supports modification of EnclaveOptions for the instance as a typed parameter.
* api-change:``gameliftstreams``: [``botocore``] Added new Gen6 stream classes based on the EC2 G6e instance family. These classes are designed for streaming high-fidelity, graphically demanding games and applications that benefit from additional GPU memory and performance.
* api-change:``invoicing``: [``botocore``] Adds support for idempotency with a new ClientToken field for the CreateInvoiceUnit, DeleteInvoiceUnit, UpdateInvoiceUnit, DeleteProcurementPortalPreference, PutProcurementPortalPreference, and UpdateProcurementPortalPreferenceStatus APIs.
* api-change:``pi``: [``botocore``] Added ListPerformanceAnalysisReportRecommendations API to retrieve recommendations for a performance analysis report. Added analysis configuration support to CreatePerformanceAnalysisReport for enhanced analysis types such as vacuum analysis.
* api-change:``qconnect``: [``botocore``] Added guardrail assessment results to inference spans in the ListSpans API. You can now see which AI Guardrail policies were evaluated, whether content was blocked or masked, and per-policy details for each Bedrock Converse call
* api-change:``securityagent``: [``botocore``] Adds support for verification scripts on penetration test findings. Customers can now download executable scripts to independently reproduce confirmed vulnerabilities, with instructions and required environment variables provided for each finding.
* enhancement:``s3``: [``botocore``] Improve caching of S3 endpoints, which should improve performance when working with multiple keys in the same bucket

1.43.13

=======

* api-change:``batch``: [``botocore``] Clarified CreateComputeEnvironment parameter requirements - serviceRole is required for UNMANAGED compute environments, allocationStrategy is required for EKS compute environments, and compute environments must be created in the ENABLED state.
* api-change:``bedrock-agentcore-control``: [``botocore``] Adds dataset management APIs for creating, versioning, and managing evaluation datasets.
* api-change:``cleanrooms``: [``botocore``] Collaboration creators can update payment configurations without recreating the collaboration. When multiple payer candidates are configured for a cost type, analysis runners can specify the actual payer at submission time, providing granular control over billing.
* api-change:``cleanroomsml``: [``botocore``] Collaboration creators can update payment configurations without recreating the collaboration. When multiple payer candidates are configured for a cost type, analysis runners can specify the actual payer at submission time, providing granular control over billing.
* api-change:``evs``: [``botocore``] A new GetDepotUrl API has been added to retrieve a URL for accessing Amazon EVS custom addon packages. Customers can use this URL to configure vSphere Lifecycle Manager (vLCM) as an online depot source, enabling upgrades of addon components across ESXi hosts.
* api-change:``mediaconnect``: [``botocore``] Adds support for controlling the timecode source of NDI flow outputs.
* api-change:``sagemaker``: [``botocore``] Add support for disabling home EFS file system creation on SageMaker domains.
* api-change:``verifiedpermissions``: [``botocore``] Support hard deleting policy store aliases. Users can now delete an alias and immediately reassign it to a different policy store without waiting for the soft-delete retention period.

1.43.12

=======

* api-change:``bedrock-runtime``: [``botocore``] Supporting Request Metadata for Invoke Model and Invoke Model with Response Stream
* api-change:``customer-profiles``: [``botocore``] Amazon Connect Customer Profiles adds support for item catalog columns in RecommenderSchema, ExcludedColumns in Create and Update Recommender to specify columns to exclude from training, and the ability to disable automatic retraining by setting TrainingFrequency to 0.
* api-change:``kms``: [``botocore``] AWS KMS now supports creating grants for AWS service principals using new GranteeServicePrincipal and RetiringServicePrincipal parameters. This release adds SourceArn grant constraint and three condition keys for controlling CreateGrant access. For more information, see Grants in AWS KMS.
* api-change:``mwaa``: [``botocore``] Updated API documentation to describe the PublicAndPrivate webserver access mode.
* api-change:``payment-cryptography-data``: [``botocore``] GenerateAuthRequestCryptogram API launch.

1.43.11

=======

* api-change:``bedrock-agentcore``: [``botocore``] Add RetryableConflictException (HTTP 409) to InvokeAgentRuntime and StopRuntimeSession to prevent orphaned VMs during concurrent session access. The SDK automatically retries this exception with backoff. Enforcement is not yet active and will be enabled in a future service update.
* api-change:``devops-agent``: [``botocore``] Added a new serviceType mcpserversigv4 service and association. This provides feature to register MCP sigv4 authorization based MCPs
* api-change:``grafana``: [``botocore``] Introduce degraded workspace status as a possible Amazon Managed Grafana workspace status, and a new field named degraded workspace reason which informs customers why the workspace is degraded in the DescribeWorkspace API response.
* api-change:``guardduty``: [``botocore``] Adding support for exposure and vulnerability context from AWS Security Hub in GuardDuty Extended Threat Detection attack sequence findings.
* api-change:``rtbfabric``: [``botocore``] This release is to deprecate 'inboundLinksCount' field in GetResponderGateway response and introduce the new field 'linksRequestedCount' to replace it.
* api-change:``sagemaker``: [``botocore``] Add support for ml.p5.4xlarge and ml.p5en.48xlarge instances on SageMaker Notebook Instances Platform.

1.43.10

=======

* api-change:``accessanalyzer``: [``botocore``] Services manage service-linked analyzers through dedicated APIs - CreateServiceLinkedAnalyzer and DeleteServiceLinkedAnalyzer that separate service-linked specific operations from customer-managed operations. It also shows up in ListAnalyzers and GetAnalyzer responses.
* api-change:``connect``: [``botocore``] Amazon Connect Cases now supports SLA durations of up to 2 years (1,051,200 minutes), increased from the previous maximum of 90 days (129,600 minutes). This enables you to track long-running service level agreements for cases that require extended resolution timelines.
* api-change:``ec2``: [``botocore``] Amazon VPC IP Address Manager (IPAM) now supports tags on IPAM pool allocations, enabling all standard tagging features for allocations including tag-on-create.
* api-change:``ecs``: [``botocore``] Amazon ECS now supports Pause lifecycle hooks for service deployments, allowing customers to automatically pause deployments at specified stages and use the new ContinueServiceDeployment API to continue or roll back with confidence.
* api-change:``evs``: [``botocore``] Amazon EVS now supports up to 32 hosts per EVS environment, increasing the previous host limit to allow a larger scale of VMware workload deployments and reduce operational overhead.
* api-change:``ivs``: [``botocore``] Adds support for up to 3 mediaTailorPlaybackConfiguration objects in an ad configuration resource
* api-change:``quicksight``: [``botocore``] Support for dataset enrichment and geo spatial in new data preparation experience
Links

Update botocore from 1.43.9 to 1.43.14.

Changelog

1.43.14

=======

* api-change:``datazone``: Add support for VPC connection
* api-change:``ec2``: The ModifyInstanceAttribute API now supports modification of EnclaveOptions for the instance as a typed parameter.
* api-change:``gameliftstreams``: Added new Gen6 stream classes based on the EC2 G6e instance family. These classes are designed for streaming high-fidelity, graphically demanding games and applications that benefit from additional GPU memory and performance.
* api-change:``invoicing``: Adds support for idempotency with a new ClientToken field for the CreateInvoiceUnit, DeleteInvoiceUnit, UpdateInvoiceUnit, DeleteProcurementPortalPreference, PutProcurementPortalPreference, and UpdateProcurementPortalPreferenceStatus APIs.
* api-change:``pi``: Added ListPerformanceAnalysisReportRecommendations API to retrieve recommendations for a performance analysis report. Added analysis configuration support to CreatePerformanceAnalysisReport for enhanced analysis types such as vacuum analysis.
* api-change:``qconnect``: Added guardrail assessment results to inference spans in the ListSpans API. You can now see which AI Guardrail policies were evaluated, whether content was blocked or masked, and per-policy details for each Bedrock Converse call
* api-change:``securityagent``: Adds support for verification scripts on penetration test findings. Customers can now download executable scripts to independently reproduce confirmed vulnerabilities, with instructions and required environment variables provided for each finding.
* enhancement:``s3``: Improve caching of S3 endpoints, which should improve performance when working with multiple keys in the same bucket

1.43.13

=======

* api-change:``batch``: Clarified CreateComputeEnvironment parameter requirements - serviceRole is required for UNMANAGED compute environments, allocationStrategy is required for EKS compute environments, and compute environments must be created in the ENABLED state.
* api-change:``bedrock-agentcore-control``: Adds dataset management APIs for creating, versioning, and managing evaluation datasets.
* api-change:``cleanrooms``: Collaboration creators can update payment configurations without recreating the collaboration. When multiple payer candidates are configured for a cost type, analysis runners can specify the actual payer at submission time, providing granular control over billing.
* api-change:``cleanroomsml``: Collaboration creators can update payment configurations without recreating the collaboration. When multiple payer candidates are configured for a cost type, analysis runners can specify the actual payer at submission time, providing granular control over billing.
* api-change:``evs``: A new GetDepotUrl API has been added to retrieve a URL for accessing Amazon EVS custom addon packages. Customers can use this URL to configure vSphere Lifecycle Manager (vLCM) as an online depot source, enabling upgrades of addon components across ESXi hosts.
* api-change:``mediaconnect``: Adds support for controlling the timecode source of NDI flow outputs.
* api-change:``sagemaker``: Add support for disabling home EFS file system creation on SageMaker domains.
* api-change:``verifiedpermissions``: Support hard deleting policy store aliases. Users can now delete an alias and immediately reassign it to a different policy store without waiting for the soft-delete retention period.

1.43.12

=======

* api-change:``bedrock-runtime``: Supporting Request Metadata for Invoke Model and Invoke Model with Response Stream
* api-change:``customer-profiles``: Amazon Connect Customer Profiles adds support for item catalog columns in RecommenderSchema, ExcludedColumns in Create and Update Recommender to specify columns to exclude from training, and the ability to disable automatic retraining by setting TrainingFrequency to 0.
* api-change:``kms``: AWS KMS now supports creating grants for AWS service principals using new GranteeServicePrincipal and RetiringServicePrincipal parameters. This release adds SourceArn grant constraint and three condition keys for controlling CreateGrant access. For more information, see Grants in AWS KMS.
* api-change:``mwaa``: Updated API documentation to describe the PublicAndPrivate webserver access mode.
* api-change:``payment-cryptography-data``: GenerateAuthRequestCryptogram API launch.

1.43.11

=======

* api-change:``bedrock-agentcore``: Add RetryableConflictException (HTTP 409) to InvokeAgentRuntime and StopRuntimeSession to prevent orphaned VMs during concurrent session access. The SDK automatically retries this exception with backoff. Enforcement is not yet active and will be enabled in a future service update.
* api-change:``devops-agent``: Added a new serviceType mcpserversigv4 service and association. This provides feature to register MCP sigv4 authorization based MCPs
* api-change:``grafana``: Introduce degraded workspace status as a possible Amazon Managed Grafana workspace status, and a new field named degraded workspace reason which informs customers why the workspace is degraded in the DescribeWorkspace API response.
* api-change:``guardduty``: Adding support for exposure and vulnerability context from AWS Security Hub in GuardDuty Extended Threat Detection attack sequence findings.
* api-change:``rtbfabric``: This release is to deprecate 'inboundLinksCount' field in GetResponderGateway response and introduce the new field 'linksRequestedCount' to replace it.
* api-change:``sagemaker``: Add support for ml.p5.4xlarge and ml.p5en.48xlarge instances on SageMaker Notebook Instances Platform.

1.43.10

=======

* api-change:``accessanalyzer``: Services manage service-linked analyzers through dedicated APIs - CreateServiceLinkedAnalyzer and DeleteServiceLinkedAnalyzer that separate service-linked specific operations from customer-managed operations. It also shows up in ListAnalyzers and GetAnalyzer responses.
* api-change:``connect``: Amazon Connect Cases now supports SLA durations of up to 2 years (1,051,200 minutes), increased from the previous maximum of 90 days (129,600 minutes). This enables you to track long-running service level agreements for cases that require extended resolution timelines.
* api-change:``ec2``: Amazon VPC IP Address Manager (IPAM) now supports tags on IPAM pool allocations, enabling all standard tagging features for allocations including tag-on-create.
* api-change:``ecs``: Amazon ECS now supports Pause lifecycle hooks for service deployments, allowing customers to automatically pause deployments at specified stages and use the new ContinueServiceDeployment API to continue or roll back with confidence.
* api-change:``evs``: Amazon EVS now supports up to 32 hosts per EVS environment, increasing the previous host limit to allow a larger scale of VMware workload deployments and reduce operational overhead.
* api-change:``ivs``: Adds support for up to 3 mediaTailorPlaybackConfiguration objects in an ad configuration resource
* api-change:``quicksight``: Support for dataset enrichment and geo spatial in new data preparation experience
Links

Update capstone from 5.0.7 to 5.0.8.

The bot wasn't able to find a changelog for this release. Got an idea?

Links

Update duckdb from 1.5.2 to 1.5.3.

Changelog

1.5.3

This is a bugfix release for various issues discovered after we released v1.5.2.

Please also refer to the announcement blog post: https://duckdb.org/2026/05/20/announcing-duckdb-153

What's Changed
* Use DB serialization compatibility for json_serialize_sql by kryonix in https://github.com/duckdb/duckdb/pull/22004
* DuckLake Bump by pdet in https://github.com/duckdb/duckdb/pull/22014
* fix: resolve current catalog in ADBC Ingest to avoid temp table shadowing by eitsupi in https://github.com/duckdb/duckdb/pull/22020
* Fix TIMESTAMPFORMAT being ignored for TIMESTAMPTZ columns in copy to json by DinosL in https://github.com/duckdb/duckdb/pull/21992
* Provide BWC support for join filter pushdowns by ywelsch in https://github.com/duckdb/duckdb/pull/22029
* Add iceberg copy function autoload by NiclasHaderer in https://github.com/duckdb/duckdb/pull/22037
* Fix DISABLE_EXTENSION_LOAD by mlafeldt in https://github.com/duckdb/duckdb/pull/22019
* Fix `INSERT OR REPLACE BY NAME` regression by excluding conflict columns from `SET` list by DinosL in https://github.com/duckdb/duckdb/pull/22049
* Git-ignore generated extension loader by mlafeldt in https://github.com/duckdb/duckdb/pull/22056
* Fix constant struct args in lateral table in-out functions by AlfieJones in https://github.com/duckdb/duckdb/pull/21827
* Avoid handling Ctrl+C during shutdown (state might be already gone) by carlopi in https://github.com/duckdb/duckdb/pull/22059
* Add `DISABLE_BUILTIN_HTTPLIB` option by carlopi in https://github.com/duckdb/duckdb/pull/22054
* Set `query` field for statements in `ALTER TABLE ... ADD COLUMN ... DEFAULT ...` workaround by yan-alex in https://github.com/duckdb/duckdb/pull/22057
* Coorporative tasks might lead to busy spinning in `TaskExecutor::WorkOnTasks` by NiclasHaderer in https://github.com/duckdb/duckdb/pull/22092
* Row group append by evertlammerts in https://github.com/duckdb/duckdb/pull/22060
* Fix empty parquet child schema by dentiny in https://github.com/duckdb/duckdb/pull/22105
* Issue 22096: TopN Window Casts by hawkfish in https://github.com/duckdb/duckdb/pull/22098
* Add support for reading `VARIANT` using C API by Dtenwolde in https://github.com/duckdb/duckdb/pull/22065
* Bump Julia to v1.5.2 by taniabogatsch in https://github.com/duckdb/duckdb/pull/22121
* fix commit iteration offset bug + relax RemoveFromIndexes assertion by artjomPlaunov in https://github.com/duckdb/duckdb/pull/22094
* Internal 8812: From TIMESTAMPTZ Casts by hawkfish in https://github.com/duckdb/duckdb/pull/22000
* Only build plan_serializer when building the main DuckDB library by rustyconover in https://github.com/duckdb/duckdb/pull/22100
* Fix Row Group Pruner Distinct Bug by d-justen in https://github.com/duckdb/duckdb/pull/22132
* Correctly skip preprocessing PIVOT MultiStatements by yan-alex in https://github.com/duckdb/duckdb/pull/22141
* fix(adbc): report the table name if the table doesn't exist when appending by eitsupi in https://github.com/duckdb/duckdb/pull/22146
* [v1.5 patch] Attempt to fix cache read by dentiny in https://github.com/duckdb/duckdb/pull/22126
* Also execute auto-rollback on CLI ClientContext::Query() query by yan-alex in https://github.com/duckdb/duckdb/pull/22159
* Fix window self join optimizer by kryonix in https://github.com/duckdb/duckdb/pull/22164
* Account for ROW_GROUP_SIZE when deciding whether to append to an existing row group by evertlammerts in https://github.com/duckdb/duckdb/pull/22109
* Use the latest storage version for temp storage by Mytherin in https://github.com/duckdb/duckdb/pull/22169
* Fix: Add pg_catalog.pg_collation compatibility view for SQLAlchemy 2.0.45 reflection by alonfaraj in https://github.com/duckdb/duckdb/pull/22160
* Fix CSV escape by dentiny in https://github.com/duckdb/duckdb/pull/22176
* Fix union_by_name remap for non-nested parquet columns by feichai0017 in https://github.com/duckdb/duckdb/pull/22177
* User-facing `enable_caching_operators` setting by lnkuiper in https://github.com/duckdb/duckdb/pull/22191
* Fix bignum sum Combine to correctly take over memory ownership of state by Mytherin in https://github.com/duckdb/duckdb/pull/22209
* CompressedFile::Close -> calls Close on its child_handle by benfleis in https://github.com/duckdb/duckdb/pull/22149
* ISSUE-22061: Fix JSON shell output: emit BOOLEAN as true/false, not strings by herbenderbler in https://github.com/duckdb/duckdb/pull/22073
* [Bugfix] Reset pg_err_pos in pg_parser_init to prevent stale error position leaking by p1p1bear in https://github.com/duckdb/duckdb/pull/22239
* Bump httpfs to 3139e40a by carlopi in https://github.com/duckdb/duckdb/pull/22248
* Correctly use new row group when checkpointing, and avoid incorrectly re-using metadata when targeting older storage versions and row ids have changed by Mytherin in https://github.com/duckdb/duckdb/pull/22253
* Fix: release ParquetReader when a file is marked SKIPPED in multi-file scan by J-Meyers in https://github.com/duckdb/duckdb/pull/22261
* Fix UTC±NN00 cannot be parsed in SQL by tianjq16 in https://github.com/duckdb/duckdb/pull/22244
* Defer Bloom Filter Pushdown until it's done by lnkuiper in https://github.com/duckdb/duckdb/pull/22218
* [v1.5] Backport ADBC memleak fix on error path by dentiny in https://github.com/duckdb/duckdb/pull/22216
* Allow package builds to choose linked extensions by mlafeldt in https://github.com/duckdb/duckdb/pull/22305
* Fix UTC+HHMM time zone was parsed incorrectly by tianjq16 in https://github.com/duckdb/duckdb/pull/22297
* Bump httpfs by carlopi in https://github.com/duckdb/duckdb/pull/22312
* Exception format: accept string literals by carlopi in https://github.com/duckdb/duckdb/pull/22314
* Skip schema analysis even if no shredding for rowgroup by rgernhardt in https://github.com/duckdb/duckdb/pull/21937
* Use batch limit for table scans with filters by Mytherin in https://github.com/duckdb/duckdb/pull/22315
* Also redacting bearer token for HTTP secrets by hannes in https://github.com/duckdb/duckdb/pull/22323
* First initialize system, then load extensions (to peek at file to be opened) by carlopi in https://github.com/duckdb/duckdb/pull/22341
* Node Handle Scoping fix  by artjomPlaunov in https://github.com/duckdb/duckdb/pull/22344
* Enable windows_amd64 for lance extension by carlopi in https://github.com/duckdb/duckdb/pull/22367
* Internal 9003: TIMETZ Parsing Limit by hawkfish in https://github.com/duckdb/duckdb/pull/22378
* Downcasting decimal fix incorrect out of range error by Dtenwolde in https://github.com/duckdb/duckdb/pull/22386
* GetLocalFileSystem improvements by carlopi in https://github.com/duckdb/duckdb/pull/21983
* Fix double decrement of evicted_data_per_tag in .block read-back by krleonid in https://github.com/duckdb/duckdb/pull/22394
* RowGroup Operator metrics: sequentially scanned row groups + total row groups + cumulative counterparts by artjomPlaunov in https://github.com/duckdb/duckdb/pull/22339
* PostgreSQL compatability: in `pg_catalog.pg_database` simulate columns datallowconn, datistemplate  by muayyad-alsadi in https://github.com/duckdb/duckdb/pull/22302
* Fix eviction size metrics report by dentiny in https://github.com/duckdb/duckdb/pull/22452
* Fix enable_logging() silently resetting logging_storage by guillesd in https://github.com/duckdb/duckdb/pull/22475
* Avoid 3 instances of idx_t - idx_t > 0, and avoid unnecessary check on zLine by carlopi in https://github.com/duckdb/duckdb/pull/22518
* Fix RESET my_global_extension_setting to actually be GLOBAL by carlopi in https://github.com/duckdb/duckdb/pull/22520
* Fix BlockAllocator invalid memory access by dentiny in https://github.com/duckdb/duckdb/pull/22503
* Patch httplib by making ThreadPool constructor more solid on pthread_create failures by carlopi in https://github.com/duckdb/duckdb/pull/22516
* Fix duck fuzz 4430 by dentiny in https://github.com/duckdb/duckdb/pull/22435
* Test runner: avoid running clean-up routine if there is no database to run it in by Mytherin in https://github.com/duckdb/duckdb/pull/22540
* Fix bare numeric interval parsing at end of string on v1.5 by M1llerF in https://github.com/duckdb/duckdb/pull/22534
* Fix parquet metadata cache validation by dentiny in https://github.com/duckdb/duckdb/pull/22547
* ExtensionInstall: Remove use of IsHTTP to IsRemoteFile by carlopi in https://github.com/duckdb/duckdb/pull/21900
* Fix variant write small decimal by dentiny in https://github.com/duckdb/duckdb/pull/22544
* Move http_proxy setting to global setting, and use GetEnvVariable('HTTP_PROXY') as default by carlopi in https://github.com/duckdb/duckdb/pull/22541
* Bump httpfs and remove patches by carlopi in https://github.com/duckdb/duckdb/pull/22556
* Bump Postgres, MySQL and ODBC by staticlibs in https://github.com/duckdb/duckdb/pull/22579
* Bump avro, azure, delta, ducklake, spatial, unity_catalog and vortex by carlopi in https://github.com/duckdb/duckdb/pull/22554
* Fix variant selection vector index by dentiny in https://github.com/duckdb/duckdb/pull/22573
* Fix for SIGABRT in setting size on zero-capacity vector by ccfelius in https://github.com/duckdb/duckdb/pull/22571
* Fix incorrect profiling results when using `LIMIT` by sebastiaan-dev in https://github.com/duckdb/duckdb/pull/22561
* Move Jemalloc into core by Maxxen in https://github.com/duckdb/duckdb/pull/22558
* Allow json ts format variation across columns - issue 22103 by benfleis in https://github.com/duckdb/duckdb/pull/22559
* Limit parallel linker jobs to avoid out-of-memory errors by smvv in https://github.com/duckdb/duckdb/pull/22588
* ARTOperator::Delete return false if rowid not found in nested ART leaf by artjomPlaunov in https://github.com/duckdb/duckdb/pull/22591
* Enable/disable jemalloc linking through BUILD/SKIP_EXTENSIONS by Maxxen in https://github.com/duckdb/duckdb/pull/22594
* Bump AWS extension by staticlibs in https://github.com/duckdb/duckdb/pull/22600
* bump spatial again by Maxxen in https://github.com/duckdb/duckdb/pull/22602
* Jemalloc is not an extension anymore by carlopi in https://github.com/duckdb/duckdb/pull/22603
* bump iceberg by Tmonster in https://github.com/duckdb/duckdb/pull/22608
* CUMULATIVE_VACUUM_TIME metric by artjomPlaunov in https://github.com/duckdb/duckdb/pull/22425
* parser_tools is apparently now a dependency for postgres by carlopi in https://github.com/duckdb/duckdb/pull/22619
* Bump DuckLake for release by pdet in https://github.com/duckdb/duckdb/pull/22651
* Bump lance to 533e0ee6cf419e4be2af3af56182fb04b87978e1 by carlopi in https://github.com/duckdb/duckdb/pull/22640
* Add storage informations for v1.5.3 by carlopi in https://github.com/duckdb/duckdb/pull/22638
* Add quack autoloading by carlopi in https://github.com/duckdb/duckdb/pull/22631
* Add `quack` extension by carlopi in https://github.com/duckdb/duckdb/pull/22614
* bump aws extension by samansmink in https://github.com/duckdb/duckdb/pull/22623
* bump avro+iceberg+vcpkg-duckdb-ports by Tishj in https://github.com/duckdb/duckdb/pull/22621
* optimizer: don't return truncated VARCHAR MIN/MAX from statistics by nahomar in https://github.com/duckdb/duckdb/pull/22538
* Bump excel / remove patch by carlopi in https://github.com/duckdb/duckdb/pull/22633
* Bump sqlsmith, remove patch by carlopi in https://github.com/duckdb/duckdb/pull/22622
* Fix free block for temporary file manageer by dentiny in https://github.com/duckdb/duckdb/pull/22616
* Add dummy cmake target for jemalloc by evertlammerts in https://github.com/duckdb/duckdb/pull/22632
* Bump quack by carlopi in https://github.com/duckdb/duckdb/pull/22659
* Fix invalid access for file row number by dentiny in https://github.com/duckdb/duckdb/pull/22662
* Fix enum type write to parquet by dentiny in https://github.com/duckdb/duckdb/pull/22677
* Add `write_buffer_row_group_memory_limit` setting which controls when to flush row groups based on memory instead of only based on row group count by Mytherin in https://github.com/duckdb/duckdb/pull/22666
* Fix max file row number by dentiny in https://github.com/duckdb/duckdb/pull/22688
* Fix new jemalloc plumbing by mlafeldt in https://github.com/duckdb/duckdb/pull/22628
* Bump DuckLake by pdet in https://github.com/duckdb/duckdb/pull/22698
* Fix timer lifetime/timing issues by taniabogatsch in https://github.com/duckdb/duckdb/pull/22697
* Enable jemalloc heap profiling with the libgcc unwinder by mlafeldt in https://github.com/duckdb/duckdb/pull/22630
* Fix jemalloc thread flush threshold check by xuke-hat in https://github.com/duckdb/duckdb/pull/22670
* Make several storage internals public by samansmink in https://github.com/duckdb/duckdb/pull/22718
* Fix GCC jemalloc symbol leakage CI failure by lnkuiper in https://github.com/duckdb/duckdb/pull/22729
* Fix iterator invalidation in ConnectionManager::GetConnectionList by bleskes in https://github.com/duckdb/duckdb/pull/22719
* Bump quack, fixes quack_serve on wasm by carlopi in https://github.com/duckdb/duckdb/pull/22722
* bump iceberg again by Tmonster in https://github.com/duckdb/duckdb/pull/22723
* fix: list_zip SEGFAULT with empty / NULL argument by carlopi in https://github.com/duckdb/duckdb/pull/22726
* Fix .sanitizer-thread-suppressions.txt jemalloc ref by carlopi in https://github.com/duckdb/duckdb/pull/22736
* Revert "Enable jemalloc heap profiling with the libgcc unwinder" by carlopi in https://github.com/duckdb/duckdb/pull/22740
* RowGroupPruner: treat UNSET LIMIT as unbounded by ColtenOuO in https://github.com/duckdb/duckdb/pull/22744
* Return an error if a negative number is passed to the factorial function by DinosL in https://github.com/duckdb/duckdb/pull/22731

**Full Changelog**: https://github.com/duckdb/duckdb/compare/v1.5.2...v1.5.3
Links

Update nicegui from 3.12.0 to 3.12.1.

Changelog

3.12.1

Bugfixes

- Fix auto-prune timers being skipped in [script mode](https://nicegui.io/documentation/section_pages_routing#script_mode) (6072, 6074 by evnchn, falkoschindler)
- Fix RuntimeError in [native mode](https://nicegui.io/documentation/section_configuration_deployment) on Python 3.14+ Linux (#6062, 6065 by noafilou, evnchn, falkoschindler)
- Fix [`ui.upload`](https://nicegui.io/documentation/upload) routes listed in `/docs` and `/openapi.json` (#6063 by jsb-zz, falkoschindler, evnchn)

Documentation

- Add a note on how to fix non-working [`ui.aggrid`](https://nicegui.io/documentation/aggrid) events (#2878, 6067 by BlankAdventure, KrilleGH, evnchn, falkoschindler)

---

Special thanks to our top sponsors [DiscoLike Inc.](https://github.com/Discolike), [Lechler GmbH](https://github.com/lechler-gmbh) and [joet-s](https://github.com/joet-s) ✨

and all our other [sponsors](https://github.com/sponsors/zauberzeug) and [contributors](https://github.com/zauberzeug/nicegui/graphs/contributors) for supporting this project!

🙏 _Want to support this project? Check out our [GitHub Sponsors page](https://github.com/sponsors/zauberzeug) to help us keep building amazing features!_
Links

Update panel from 1.8.10 to 1.9.1.

Changelog

1.9.1

A quick patch release addressing regressions in 1.9.0, fixing `Button` color styling and resolves several issues with ESM and React component lifecycle handling. Many thanks to philippjfr and hoxbro for their contributions to this release.

🐛 Bug Fixes

* Fix `Button` color not being respected ([8600](https://github.com/holoviz/panel/pull/8600))
* Fix ESM component `ready` and `has_finished` compliance ([8602](https://github.com/holoviz/panel/pull/8602))
* Improve `ReactComponent` ready promise handling ([8603](https://github.com/holoviz/panel/pull/8603))
* Avoid hacky `IconMixin` rename override ([8604](https://github.com/holoviz/panel/pull/8604))

📚 Documentation

* Update gallery environment ([8601](https://github.com/holoviz/panel/pull/8601))

1.9.0

Panel 1.9.0 delivers full typing compatibility with Param 2.4.0, finally ensuring that all parameters are fully typed. Additionally this release makes it possible to provide wildcard routes to `pn.serve` making it possible to support dynamic routing. It also includes a significant modernization of the widget API, introducing `Widget.label` as the canonical display label parameter and renaming `button_type`/`button_style` to `color`/`variant` for better alignment with `panel-material-ui`, which will be integrated within Panel in upcoming releases. The release also includes a range of `Tabulator` improvements, chat enhancements, security updates, and numerous bug fixes. Lastly, this release drops support for Bokeh 3.7.

Many thanks to the contributors to this release including: philippjfr, hoxbro, ghostiee-11, ahuang11, AtharvaJaiswal005, SKlerk, TheoMathurin, chucklay, zhangdomi, mvanhorn, SuMayaBee, forman, and omyaaa1.

🚀 Features

* Add type compatibility for param 2.4.0 ([8573](https://github.com/holoviz/panel/pull/8573))
* Add support for wildcard route handling ([8588](https://github.com/holoviz/panel/pull/8588))

✨ Enhancements

* Introduce `Widget.label` parameter and treat `name` as an alias ([8328](https://github.com/holoviz/panel/pull/8328))
* Rename `button_type` -> `color` and `button_style` -> `variant` ([8577](https://github.com/holoviz/panel/pull/8577))
* Make `Feed` type configurable on `ChatFeed` ([8582](https://github.com/holoviz/panel/pull/8582))
* Add `selection` and `value_input` to `TextEditor` widget ([8560](https://github.com/holoviz/panel/pull/8560))
* Add dark theme support for `JSONEditor` widget ([8444](https://github.com/holoviz/panel/pull/8444))

🐛 Bug Fixes

* Fix `widget.disabled` getting stuck after rapid toggling ([8507](https://github.com/holoviz/panel/pull/8507))
* Fix `Trend` indicator not working with `date_range` x-axis ([8509](https://github.com/holoviz/panel/pull/8509))
* Fix `ReactComponent` initialization issues ([8552](https://github.com/holoviz/panel/pull/8552))
* Fix `DataFrame` comparison in `Tabulator.from_param` ([8539](https://github.com/holoviz/panel/pull/8539))
* Fix `Tabulator` scroll reset when filtering on patch ([8531](https://github.com/holoviz/panel/pull/8531))
* Prevent `Tabulator` from overwriting scroll position on style update ([8420](https://github.com/holoviz/panel/pull/8420))
* Fix `Gauge`/`ECharts` crash when the ECharts library is not yet loaded ([8515](https://github.com/holoviz/panel/pull/8515))
* Make OAuth token refreshes more robust ([8518](https://github.com/holoviz/panel/pull/8518))
* Sanitize JavaScript string replacement tokens in Python code ([8566](https://github.com/holoviz/panel/pull/8566))
* Fix string formatting in `NotImplementedError` message ([8536](https://github.com/holoviz/panel/pull/8536))

🎨 UI Improvements

* Update Tabulator to version 6.4 ([8568](https://github.com/holoviz/panel/pull/8568))
* Optimize `Tabulator` resize events ([8528](https://github.com/holoviz/panel/pull/8528))
* Improve Pyodide badge appearance ([8519](https://github.com/holoviz/panel/pull/8519))
* General rendering and performance optimizations ([8547](https://github.com/holoviz/panel/pull/8547))

⚠️ Deprecations

* `Widget.name` was renamed to `Widget.label`
* `Button.button_type` was renamed to `Button.color`
* `Button.button_style` was renamed to `Button.variant`
* Dropped support for Bokeh 3.7

📚 Documentation
* Update reference gallery to use `panel-material-ui` ([8596](https://github.com/holoviz/panel/pull/8596))
* Add Outerbounds deployment guide ([8587](https://github.com/holoviz/panel/pull/8587))
* Add Functions vs Classes explanation ([8581](https://github.com/holoviz/panel/pull/8581))
* Add Panel extensions documentation page ([8529](https://github.com/holoviz/panel/pull/8529))
* Document `pn.state.sync_busy` in the busy indicator how-to guide ([8564](https://github.com/holoviz/panel/pull/8564))

🔒 Security

* Switch HTML sanitization from `bleach` to `nh3` ([8503](https://github.com/holoviz/panel/pull/8503))
* Add `zizmor` for GitHub Actions security scanning ([8584](https://github.com/holoviz/panel/pull/8584))
* Validate `next_url` for basic auth and raise an error if invalid ([8575](https://github.com/holoviz/panel/pull/8575))
Links

Update phonenumbers from 9.0.30 to 9.0.31.

Changelog

9.0.31

Metadata changes:
- Updated alternate formatting data for country calling code(s): 84
- Updated phone metadata for region code(s):
AI, BO, DZ, ET, GE, GM, IN, TR, UG, VN
- Updated short number metadata for region code(s): IT
- Updated geocoding data for country calling code(s): 213 (en)
- Updated carrier data for country calling code(s):
34 (en), 43 (en), 84 (en), 90 (en), 220 (en), 251 (en), 256 (en), 354 (en),
591 (en), 1264 (en)
Links

Update pythonnet from 3.0.5 to 3.1.0.

Changelog

3.1.0

Added

- Support `del obj[...]` for types derived from `IList<T>` and `IDictionary<K, V>` (2533)
- Support for .NET Framework 4.6.1 (2701)
- Context manager protocol for .NET `IDisposable` types, allowing use of `with` statements
for `IDisposable` objects (2568)
- Support for Python 3.14 (2611)
- Implement support for DLR get/set (2706)

Changed

- Derive Python (virtual) environment information (2652)

Fixed

- Fixed crash when trying to `del clrObj[...]` for non-arrays
- ci: properly exclude job (2542)
- Properly detect availability of `BinaryFormatter` (2639)
- Support for .NET 10 SDK (2684)
- Fix wheel tags (2716)
- Name missing from `__all__` on re-import (2717)

Removed

- Support for Python 3.7 to 3.9 (2639)

[3.0.5](https://github.com/pythonnet/pythonnet/releases/tag/v3.0.5) - 2024-12-13

Added

- Support for Python 3.13 (2454)

[3.0.4](https://github.com/pythonnet/pythonnet/releases/tag/v3.0.4) - 2024-09-19

Added

- Added `ToPythonAs<T>()` extension method to allow for explicit conversion
 using a specific type. ([2311][i2311])
- Added `IComparable` and `IEquatable` implementations to `PyInt`, `PyFloat`,
 and `PyString` to compare with primitive .NET types like `long`.

Changed

- Added a `FormatterFactory` member in RuntimeData to create formatters with
 parameters. For compatibility, the `FormatterType` member is still present
 and has precedence when defining both `FormatterFactory` and `FormatterType`
- Added a post-serialization and a pre-deserialization step callbacks to
 extend (de)serialization process
- Added an API to stash serialized data on Python capsules

Fixed

- Fixed RecursionError for reverse operators on C operable types from python. See 2240
- Fixed crash when .NET event has no `AddMethod`
- Fixed probing for assemblies in `sys.path` failing when a path in `sys.path`
 has invalid characters. See 2376
- Fixed possible access violation exception on shutdown. See ([1977][i1977])

[3.0.3](https://github.com/pythonnet/pythonnet/releases/tag/v3.0.3) - 2023-10-11

Added

- Support for Python 3.12

Changed

- Use enum name in `repr`

[3.0.2](https://github.com/pythonnet/pythonnet/releases/tag/v3.0.2) - 2023-08-29

Fixed

- Fixed error occuring when inheriting a class containing a virtual generic method
- Make a second call to `pythonnet.load` a no-op, as it was intended
- Added support for multiple inheritance when inheriting from a class and/or multiple interfaces
- Fixed error occuring when calling `GetBuffer` for anything other than `PyBUF.SIMPLE`
- Bumped `clr_loader` dependency to incorporate patches

[3.0.1](https://github.com/pythonnet/pythonnet/releases/tag/v3.0.1) - 2022-11-03

Added

- Support for Python 3.11

Changed

- Allow decoders to override conversion of types derived from primitive types

Fixed

- Fixed objects leaking when Python attached event handlers to them even if they were later removed
- Fixed `PyInt` conversion to `BigInteger` and `System.String` produced incorrect result for values between 128 and 255.
- Fixed implementing a generic interface with a Python class

[3.0.0](https://github.com/pythonnet/pythonnet/releases/tag/v3.0.0) - 2022-09-29

Added

- Ability to instantiate new .NET arrays using `Array[T](dim1, dim2, ...)` syntax
- Python operator method will call C operator method for supported binary and unary operators ([1324][p1324]).
- Add GetPythonThreadID and Interrupt methods in PythonEngine
- Ability to implement delegates with `ref` and `out` parameters in Python, by returning the modified parameter values in a tuple. ([1355][i1355])
- Ability to override .NET methods that have `out` or `ref` in Python by returning the modified parameter values in a tuple. ([1481][i1481])
- `PyType` - a wrapper for Python type objects, that also permits creating new heap types from `TypeSpec`
- Improved exception handling:

- exceptions can now be converted with codecs
- `InnerException` and `__cause__` are propagated properly

- `__name__` and `__signature__` to reflected .NET methods
- .NET collection types now implement standard Python collection interfaces from `collections.abc`.
See [Mixins/collections.py](src/runtime/Mixins/collections.py).
- you can cast objects to generic .NET interfaces without specifying generic arguments as long as there is no ambiguity.
- .NET arrays implement Python buffer protocol
- Python integer interoperability with `System.Numerics.BigInteger`
- Python.NET will correctly resolve .NET methods, that accept `PyList`, `PyInt`,
and other `PyObject` derived types when called from Python.
- .NET classes, that have `__call__` method are callable from Python
- `PyIterable` type, that wraps any iterable object in Python
- `PythonEngine` properties for supported Python versions: `MinSupportedVersion`, `MaxSupportedVersion`, and `IsSupportedVersion`
- The runtime that is loaded on `import clr` can now be configured via environment variables

Changed

- Drop support for Python 2, 3.4, 3.5, and 3.6
- `wchar_t` size aka `Runtime.UCS` is now determined at runtime
- `clr.AddReference` may now throw errors besides `FileNotFoundException`, that provide more
details about the cause of the failure
- `clr.AddReference` no longer adds ".dll" implicitly
- `PyIter(PyObject)` constructor replaced with static `PyIter.GetIter(PyObject)` method
- Python runtime can no longer be shut down if the Python error indicator is set, as it would have unpredictable behavior
- BREAKING: Return values from .NET methods that return an interface are now automatically
  wrapped in that interface. This is a breaking change for users that rely on being
  able to access members that are part of the implementation class, but not the
  interface.  Use the new `__implementation__` or `__raw_implementation__` properties to
  if you need to "downcast" to the implementation class.
- BREAKING: `==` and `!=` operators on `PyObject` instances now use Python comparison
  (previously was equivalent to `object.ReferenceEquals(,)`)
- BREAKING: Parameters marked with `ParameterAttributes.Out` are no longer returned in addition
  to the regular method return value (unless they are passed with `ref` or `out` keyword).
- BREAKING: Drop support for the long-deprecated CLR.* prefix.
- `PyObject` now implements `IEnumerable<PyObject>` in addition to `IEnumerable`
- floating point values passed from Python are no longer silently truncated
when .NET expects an integer [1342][i1342]
- More specific error messages for method argument mismatch
- members of `PyObject` inherited from `System.Object and`DynamicObject` now autoacquire GIL
- BREAKING: when inheriting from .NET types in Python if you override `__init__` you
must explicitly call base constructor using `super().__init__(.....)`. Not doing so will lead
to undefined behavior.
- BREAKING: most `PyScope` methods will never return `null`. Instead, `PyObject` `None` will be returned.
- BREAKING: `PyScope` was renamed to `PyModule`
- BREAKING: Methods with `ref` or `out` parameters and void return type return a tuple of only the `ref` and `out` parameters.
- BREAKING: to call Python from .NET `Runtime.PythonDLL` property must be set to Python DLL name
or the DLL must be loaded in advance. This must be done before calling any other Python.NET functions.
- BREAKING: `PyObject.Length()` now raises a `PythonException` when object does not support a concept of length.
- BREAKING: disabled implicit conversion from C enums to Python `int` and back.
One must now either use enum members (e.g. `MyEnum.Option`), or use enum constructor
(e.g. `MyEnum(42)` or `MyEnum(42, True)` when `MyEnum` does not have a member with value 42).
- BREAKING: disabled implicit conversion from Python objects implementing sequence protocol to
.NET arrays when the target .NET type is `System.Object`. The conversion is still attempted when the
target type is a `System.Array`.
- Sign Runtime DLL with a strong name
- Implement loading through `clr_loader` instead of the included `ClrModule`, enables
 support for .NET Core
- BREAKING: .NET and Python exceptions are preserved when crossing Python/.NET boundary
- BREAKING: custom encoders are no longer called for instances of `System.Type`
- `PythonException.Restore` no longer clears `PythonException` instance.
- Replaced the old `__import__` hook hack with a PEP302-style Meta Path Loader
- BREAKING: Names of .NET types (e.g. `str(__class__)`) changed to better support generic types
- BREAKING: overload resolution will no longer prefer basic types. Instead, first matching overload will
be chosen.
- BREAKING: acquiring GIL using `Py.GIL` no longer forces `PythonEngine` to initialize
- BREAKING: `Exec` and `Eval` from `PythonEngine` no longer accept raw pointers.
- BREAKING: .NET collections and arrays are no longer automatically converted to
Python collections. Instead, they implement standard Python
collection interfaces from `collections.abc`.
See [Mixins/collections.py](src/runtime/Mixins/collections.py).
- BREAKING: When trying to convert Python `int` to `System.Object`, result will
be of type `PyInt` instead of `System.Int32` due to possible loss of information.
Python `float` will continue to be converted to `System.Double`.
- BREAKING: Python.NET will no longer implicitly convert types like `numpy.float64`, that implement `__float__` to
`System.Single` and `System.Double`. An explicit conversion is required on Python or .NET side.
- BREAKING: `PyObject.GetHashCode` can fail.
- BREAKING: Python.NET will no longer implicitly convert any Python object to `System.Boolean`.
- BREAKING: `PyObject.GetAttr(name, default)` now only ignores `AttributeError` (previously ignored all exceptions).
- BREAKING: `PyObject` no longer implements `IEnumerable<PyObject>`.
Instead, `PyIterable` does that.
- BREAKING: `IPyObjectDecoder.CanDecode` `objectType` parameter type changed from `PyObject` to `PyType`

Fixed

- Fix incorrect dereference of wrapper object in `tp_repr`, which may result in a program crash
- Fixed parameterless .NET constructor being silently called when a matching constructor overload is not found ([238][i238])
- Fix incorrect dereference in params array handling
- Fixes issue with function resolution when calling overloaded function with keyword arguments from python ([1097][i1097])
- Fix `object[]` parameters taking precedence when should not in overload resolution
- Fixed a bug where all .NET class instances were considered Iterable
- Fix incorrect choice of method to invoke when using keyword arguments.
- Fix non-delegate types incorrectly appearing as callable.
- Indexers can now be used with interface objects
- Fixed a bug where indexers could not be used if they were inherited
- Made it possible to use `__len__` also on `ICollection<>` interface objects
- Fixed issue when calling PythonException.Format where another exception would be raise for unnormalized exceptions
- Made it possible to call `ToString`, `GetHashCode`, and `GetType` on inteface objects
- Fixed objects returned by enumerating `PyObject` being disposed too soon
- Incorrectly using a non-generic type with type parameters now produces a helpful Python error instead of throwing NullReferenceException
- `import` may now raise errors with more detail than "No module named X"
- Exception stacktraces on `PythonException.StackTrace` are now properly formatted
- Providing an invalid type parameter to a generic type or method produces a helpful Python error
- Empty parameter names (as can be generated from F) do not cause crashes
- Unicode strings with surrogates were truncated when converting from Python
- `Reload` mode now supports generic methods (previously Python would stop seeing them after reload)
- Temporarily fixed issue resolving method overload when method signature has `out` parameters ([1672](i1672))
- Decimal default parameters are now correctly taken into account

Removed

- `ShutdownMode` has been removed. The only shutdown mode supported now is an equivalent of `ShutdownMode.Reload`.
There is no need to specify it.
- implicit assembly loading (you have to explicitly `clr.AddReference` before doing import)
- messages in `PythonException` no longer start with exception type
- `PyScopeManager`, `PyScopeException`, `PyScope` (use `PyModule` instead)
- support for .NET Framework 4.0-4.6; Mono before 5.4. Python.NET now requires .NET Standard 2.0
(see [the matrix](https://docs.microsoft.com/en-us/dotnet/standard/net-standard#net-implementation-support))

[2.5.2](https://github.com/pythonnet/pythonnet/releases/tag/v2.5.2) - 2021-02-05

Bugfix release.

Fixed

- Fix `object[]` parameters taking precedence when should not in overload resolution
- Empty parameter names (as can be generated from F) do not cause crashes

[2.5.1](https://github.com/pythonnet/pythonnet/releases/tag/v2.5.1) - 2020-06-18

Bugfix release.

Fixed

- Fix incorrect dereference of wrapper object in `tp_repr`, which may result in a program crash
- Fix incorrect dereference in params array handling

[2.5.0](https://github.com/pythonnet/pythonnet/releases/tag/v2.5.0) - 2020-06-14

This version improves performance on benchmarks significantly compared to 2.3.

Added

- Automatic NuGet package generation in appveyor and local builds
- Function that sets `Py_NoSiteFlag` to 1.
- Support for Jetson Nano.
- Support for `__len__` for .NET classes that implement ICollection
- `PyExport` attribute to hide .NET types from Python
- `PythonException.Format` method to format exceptions the same as
 `traceback.format_exception`
- `Runtime.None` to be able to pass `None` as parameter into Python from .NET
- `PyObject.IsNone()` to check if a Python object is None in .NET.
- Support for Python 3.8
- Codecs as the designated way to handle automatic conversions between
 .NET and Python types
- Added Python 3 buffer api support and PyBuffer interface for fast byte and numpy array read/write ([980][p980])

Changed

- Added argument types information to "No method matches given arguments" message
- Moved wheel import in setup.py inside of a try/except to prevent pip collection failures
- Removes `PyLong_GetMax` and `PyClass_New` when targetting Python3
- Improved performance of calls from Python to C
- Added support for converting python iterators to C arrays
- Changed usage of the obsolete function
 `GetDelegateForFunctionPointer(IntPtr, Type)` to
 `GetDelegateForFunctionPointer<TDelegate>(IntPtr)`
- When calling C from Python, enable passing argument of any type to a
 parameter of C type `object` by wrapping it into `PyObject` instance.
 ([881][i881])
- Added support for kwarg parameters when calling .NET methods from Python
- Changed method for finding MSBuild using vswhere
- Reworked `Finalizer`. Now objects drop into its queue upon finalization,
 which is periodically drained when new objects are created.
- Marked `Runtime.OperatingSystemName` and `Runtime.MachineName` as
 `Obsolete`, should never have been `public` in the first place. They also
 don't necessarily return a result that matches the `platform` module's.
- Unconditionally depend on `pycparser` for the interop module generation

Fixed

- Fixed runtime that fails loading when using pythonnet in an environment
 together with Nuitka
- Fixes bug where delegates get casts (dotnetcore)
- Determine size of interpreter longs at runtime
- Handling exceptions ocurred in ModuleObject's getattribute
- Fill `__classcell__` correctly for Python subclasses of .NET types
- Fixed issue with params methods that are not passed an array.
- Use UTF8 to encode strings passed to `PyRun_String` on Python 3
Links

Update trame-server from 3.12.3 to 3.12.4.

The bot wasn't able to find a changelog for this release. Got an idea?

Links

Update urllib3-future from 2.20.905 to 2.20.907.

Changelog

2.20.907

=====================

- Fixed certs retrieval when using HTTPS proxy (Python 3.10+) in a synchronous context. (375)

2.20.906

=====================

- Fixed TLS connection to some server that requires OP_NO_RENEGOTIATION enabled (legacy TLS1.2 server). (https://github.com/jawah/niquests/issues/402)
- Fixed automatic fallback to single datagram send when GSO is available for UDP I/O but the physical NIC don't support it. (373)
- Fixed automatic fallback tls/quic to tls/tcp when the discrete upgrade failed. (372)
- Fixed broken connection handling in (contrib) webextension wsproto that lead to hangs. (371)
Links

Update vtk from 9.6.1 to 9.6.2.

The bot wasn't able to find a changelog for this release. Got an idea?

Links

Update litestar from 2.21.1 to 2.22.0.

The bot wasn't able to find a changelog for this release. Got an idea?

Links

Update z3c.rml from 5.0.1 to 5.1.1.

Changelog

5.1.1

------------------

- Make ``rlPyCairo`` an optional test dependency instead of a required install
dependency, matching its optional status in ``reportlab >= 4``.
(`135 <https://github.com/zopefoundation/z3c.rml/issues/135>`_)

5.1

----------------

- Drop deprecated ``backports.tempfile`` dependency in favor of the standard
library ``tempfile`` module (requires Python 3.4+, project requires 3.9+).
(`136 <https://github.com/zopefoundation/z3c.rml/issues/136>`_)

- Fix compatibility with ``reportlab >= 4.3`` by using the proper PostScript
font name ``Times-Roman`` instead of the informal ``Times`` shorthand.
(`127 <https://github.com/zopefoundation/z3c.rml/issues/127>`_)

- Fix index callback registration to use ``setNamedCB`` API, required by
``reportlab >= 4.5``.

- Remove the ``Pillow < 11`` upper version bound. Pillow >= 11 changed how
EPS images are loaded: the image mode can change after rasterization (e.g.
from RGB to 1-bit), which caused ``ValueError: No packer found from 1 to
RGB`` in reportlab's ``ImageReader``. Fix by pre-loading images and
converting them back to their initial mode when Pillow changes it during
load.
(`125 <https://github.com/zopefoundation/z3c.rml/issues/125>`_)

- Move package metadata from setup.py to pyproject.toml.

- Add support for Python 3.14.

- Drop support for Python 3.9.
Links

Update opentelemetry-sdk from 1.41.1 to 1.42.1.

The bot wasn't able to find a changelog for this release. Got an idea?

Links

Update globus-sdk from 4.6.0 to 4.7.0.

Changelog

4.7.0

===================

Added
-----

- Add a ``per_page`` parameter to the ``FlowsClient.list_registered_apis()`` method. (:pr:`1390`)

.. _changelog-4.6.0:
Links

Update dbus-fast from 4.3.0 to 5.0.10.

Changelog

5.0.10

Bug Fixes

- **aio**: Drop stray %s format token from message-reader error log
([715](https://github.com/Bluetooth-Devices/dbus-fast/pull/715),
[`1c5543e`](https://github.com/Bluetooth-Devices/dbus-fast/commit/1c5543e00670a3a11134bd4d7e1353954a9aefc2))

Documentation

- **validators**: Allow hyphens in member names
([718](https://github.com/Bluetooth-Devices/dbus-fast/pull/718),
[`b1ed99b`](https://github.com/Bluetooth-Devices/dbus-fast/commit/b1ed99b5cfba6cbacd32424b18309e2b5351910c))

Refactoring

- **service**: Drop unused _get_handler accessor
([714](https://github.com/Bluetooth-Devices/dbus-fast/pull/714),
[`8fc84d5`](https://github.com/Bluetooth-Devices/dbus-fast/commit/8fc84d5928f09d07bc39827501d9691991512382))

Testing

- **benchmarks**: Add isolated bluez manufacturer-data unmarshall benchmark
([717](https://github.com/Bluetooth-Devices/dbus-fast/pull/717),
[`b6668b9`](https://github.com/Bluetooth-Devices/dbus-fast/commit/b6668b9d7ded53bf5f6bea9a1dbd32123a3b7788))

5.0.9

Bug Fixes

- **unmarshaller**: Ignore header fields with an unknown field code
([706](https://github.com/Bluetooth-Devices/dbus-fast/pull/706),
[`8ac9948`](https://github.com/Bluetooth-Devices/dbus-fast/commit/8ac994801b7cc1141ca7a5d51151ce63e06f2187))

5.0.8

Bug Fixes

- **unmarshaller**: Reject messages with an unknown type byte
([703](https://github.com/Bluetooth-Devices/dbus-fast/pull/703),
[`64f7390`](https://github.com/Bluetooth-Devices/dbus-fast/commit/64f739016ae217c58a3439e3cc37e055c4dfa66d))

5.0.7

Performance Improvements

- **marshaller**: Write dict entries without a throwaway list
([713](https://github.com/Bluetooth-Devices/dbus-fast/pull/713),
[`5c57241`](https://github.com/Bluetooth-Devices/dbus-fast/commit/5c57241ff5c8f69a59d956a33186262fa50fa2f5))

Testing

- **benchmarks**: Add dict-heavy marshall benchmarks
([712](https://github.com/Bluetooth-Devices/dbus-fast/pull/712),
[`7fdd405`](https://github.com/Bluetooth-Devices/dbus-fast/commit/7fdd405ad149a4f8b6213e38c5f7e838930df4a1))

5.0.6

Performance Improvements

- **unmarshaller**: Build struct results without a generator object
([710](https://github.com/Bluetooth-Devices/dbus-fast/pull/710),
[`47073b9`](https://github.com/Bluetooth-Devices/dbus-fast/commit/47073b9945bcab054a8bcca54da493a34e174b75))

- **unpack**: Build unpacked tuples without a generator object
([711](https://github.com/Bluetooth-Devices/dbus-fast/pull/711),
[`9368c90`](https://github.com/Bluetooth-Devices/dbus-fast/commit/9368c90239279a8bf31109d776edb0db5d098f5c))

5.0.5

Bug Fixes

- **auth**: Raise AuthError on unknown server response
([702](https://github.com/Bluetooth-Devices/dbus-fast/pull/702),
[`28af8ea`](https://github.com/Bluetooth-Devices/dbus-fast/commit/28af8ea4c97b6539124421f4001b5ade48027a36))

Refactoring

- **marshaller**: Drop unused align() and buffer wrappers
([707](https://github.com/Bluetooth-Devices/dbus-fast/pull/707),
[`16b952b`](https://github.com/Bluetooth-Devices/dbus-fast/commit/16b952beb9be5e770598d9d265aca3677bebdc94))

Testing

- **benchmarks**: Add systemd ListUnits array-of-structs unmarshall benchmark
([708](https://github.com/Bluetooth-Devices/dbus-fast/pull/708),
[`0edbfee`](https://github.com/Bluetooth-Devices/dbus-fast/commit/0edbfee177498062fbede6ef97acb8972e069bdf))

- **benchmarks**: Add unpack_variants benchmark
([709](https://github.com/Bluetooth-Devices/dbus-fast/pull/709),
[`5d4f2d1`](https://github.com/Bluetooth-Devices/dbus-fast/commit/5d4f2d1cc46356b8d8ca484fa7b98adf139cc88d))

5.0.4

Bug Fixes

- **signature**: Bound container nesting depth during parsing
([699](https://github.com/Bluetooth-Devices/dbus-fast/pull/699),
[`4c5a927`](https://github.com/Bluetooth-Devices/dbus-fast/commit/4c5a927f79b1fb5434951efc626c0ca9020cfcde))

5.0.3

Bug Fixes

- **unmarshaller**: Cap container nesting depth to prevent stack overflow DoS
([698](https://github.com/Bluetooth-Devices/dbus-fast/pull/698),
[`ef528a6`](https://github.com/Bluetooth-Devices/dbus-fast/commit/ef528a61b46bf85713e6a0ae83b8427e9c3bb8f3))

5.0.2

Bug Fixes

- **introspection**: Bound <node> nesting depth to prevent DoS
([697](https://github.com/Bluetooth-Devices/dbus-fast/pull/697),
[`6870443`](https://github.com/Bluetooth-Devices/dbus-fast/commit/6870443978cbf0232a1943519522213d601e275d))

Refactoring

- **aio**: Drop dead self._stream.flush() in _authenticate()
([694](https://github.com/Bluetooth-Devices/dbus-fast/pull/694),
[`27e1fd2`](https://github.com/Bluetooth-Devices/dbus-fast/commit/27e1fd2a3decb07fa4c6c648861b617b08983f1e))

Testing

- Drop blocking sendall in auth_readline peer-side setup
([692](https://github.com/Bluetooth-Devices/dbus-fast/pull/692),
[`c754780`](https://github.com/Bluetooth-Devices/dbus-fast/commit/c754780d8e0486a3483d909e8617858ed1490f66))

5.0.1

Bug Fixes

- **aio**: Send hello via sock_sendall to keep connect off the event loop
([691](https://github.com/Bluetooth-Devices/dbus-fast/pull/691),
[`03a2a2e`](https://github.com/Bluetooth-Devices/dbus-fast/commit/03a2a2e080a8039bb1e9b7e3becfe4e098014571))

Continuous Integration

- Key venv cache on resolved python patch version
([687](https://github.com/Bluetooth-Devices/dbus-fast/pull/687),
[`6c391ae`](https://github.com/Bluetooth-Devices/dbus-fast/commit/6c391aea25c88a0366daf5afdb97af0f162b18d5))

Documentation

- Add PSR insertion-flag marker to CHANGELOG
([689](https://github.com/Bluetooth-Devices/dbus-fast/pull/689),
[`af2dc25`](https://github.com/Bluetooth-Devices/dbus-fast/commit/af2dc257349a6dcb9132d8ee76f1bfdbba043e2b))

5.0.0

Bug Fixes

- Defer socket.connect() from __init__ to connect()
([570](https://github.com/Bluetooth-Devices/dbus-fast/pull/570),
[`5c9ddd9`](https://github.com/Bluetooth-Devices/dbus-fast/commit/5c9ddd930f5cf3dfe0aa5120737bcb10f04c0b7f))

Chores

- **ci**: Pin action comments to full semver
([673](https://github.com/Bluetooth-Devices/dbus-fast/pull/673),
[`5ee2f95`](https://github.com/Bluetooth-Devices/dbus-fast/commit/5ee2f9574b24a7307b3cae50d1671911e8d45300))

- **deps-dev**: Bump idna from 3.10 to 3.15 in the p

pyup-bot and others added 30 commits May 25, 2026 19:59
... and supports python 3.14.
Since `pythonnet` 3.1.0 supports python 3.14, `toga` (and `toga-winforms`)
should now also work on Windows with python 3.14.
`pygwalker` 0.5.01 dropped dependency on `quickjs` (which imposed
python < 3.13 limit on Windows). Contemporary versions of `pyarrow`,
a dependency which prevously imposed python < 3.14 limit on all OSes,
should now support 3.14.
Contemporary versions of `vtk` support python 3.14, so we can
remove the `python_version < "3.14"` restriction for `pyvista`
(which depends on `vtk`).
Try to remove `python_version < 3.14` restriction from `trame`
and all `trame-*` packages.
`ckzg`, a dependency of `web3` that imposed `python_version < "3.14"`
restriction on Windows, seems to support python 3.14 now...
Add `python_version >= 3.9` restriction to all `trame-*` packages
that do not already have it...
Remove additional conditions that allowed `trame-mesh-streamer` to
be installed under python 3.8; this does not work anymore, because
contemporary `trame` / `trame-client` implicitly require python >=
3.9...
Avoid failing this CI due to known issues with contemporary toga
versions on macOS. Instead, add a TODO so we can revisit this
next time that toga is updated.
`litestar` depends on `multipart`, whose `multipart` module
conflicts with `multipart` package from `python-multipart`, a
dependency of `fastapi` (which, in turn, is a dependency of
`nicegui` that was also updated). This results in spurious test
failures, so defer the update until next week...
@rokm
rokm merged commit e9bef8a into master May 26, 2026
30 checks passed
@rokm
rokm deleted the pyup-scheduled-update-2026-05-25 branch May 26, 2026 08:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants