Skip to content

build(deps): bump the python-dependencies group with 18 updates - #87

Closed
dependabot[bot] wants to merge 2 commits into
mainfrom
dependabot/pip/python-dependencies-43cd783896
Closed

dependabot[bot] wants to merge 2 commits into
mainfrom
dependabot/pip/python-dependencies-43cd783896

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 8, 2026

Copy link
Copy Markdown

Bumps the python-dependencies group with 18 updates:

Package From To
trame 3.12.0 3.13.2
trame-server 3.14.0 3.14.1
trame-vtklocal 0.16.4 1.4.1
vtk 9.6.1 9.7.0
fastapi 0.136.3 0.141.1
uvicorn 0.24.0.post1 0.52.4
pydantic-settings 2.6.0 2.15.0
click 8.4.2 8.5.0
pytest 8.4.2 9.1.1
pytest-cov 3.0.0 7.1.0
pytest-playwright 0.7.2 0.9.0
jupyter-client 8.9.1 8.10.0
nbformat 5.11.0 5.11.1
deepdiff 8.6.2 9.1.0
numpydoc 1.8.0 1.10.0
sphinx-gallery 0.18.0 0.21.0
sphinxcontrib-openapi 0.8.4 0.9.0
sphinx-design 0.6.1 0.7.0

Updates trame from 3.12.0 to 3.13.2

Release notes

Sourced from trame's releases.

v3.13.2 (2026-05-15)

Bug Fixes

  • profiler: Add support for multi trace files (a6b24d3)

Documentation

  • examples: Use cookiecutter's vuetify3 best practices (112680b)

  • tutorial: Change **kwargs with **_kwargs because they are unused (f804fb2)

Ref: Kitware/trame-tutorial@adfd845

  • tutorial: Change vuetify3 with v3 and server with self.server (c2ddaf7)

Ref: Kitware/trame#877

Ref: Kitware/trame#877

  • tutorial: Change AppLayouts class name to ConeApp (10f18ae)

  • tutorial: Change small errors (bae3ad7)

  • indentation errors

  • forgot to put self in class function's arguments

  • self.server.state => self.state

  • one forgotten layout => self.ui

Ref: Kitware/trame#877

Ref: Kitware/trame#877

Ref: Kitware/trame#877

Ref: Kitware/trame#877

Ref: Kitware/trame#877

Ref: Kitware/trame#877

Ref: Kitware/trame#877

  • tutorial: Change the doc to match the trame-tutorial update to vue3 (c4770fb)

  • tutorial: Change the html tutorial page to use trame's best practice (af91dac)

  • tutorial: Correct example code and fix typos (db8b819)

  • tutorial: Make the setup tutorial example use TrameApp (d2b0c4d)

... (truncated)

Changelog

Sourced from trame's changelog.

v3.13.2 (2026-05-15)

Bug Fixes

  • profiler: Add support for multi trace files (a6b24d3)

Documentation

  • examples: Use cookiecutter's vuetify3 best practices (112680b)

  • tutorial: Change **kwargs with **_kwargs because they are unused (f804fb2)

Ref: Kitware/trame-tutorial@adfd845

  • tutorial: Change vuetify3 with v3 and server with self.server (c2ddaf7)

Ref: Kitware/trame#877

Ref: Kitware/trame#877

  • tutorial: Change AppLayouts class name to ConeApp (10f18ae)

  • tutorial: Change small errors (bae3ad7)

  • indentation errors - forgot to put self in class function's arguments - self.server.state => self.state - one forgotten layout => self.ui

Ref: Kitware/trame#877

Ref: Kitware/trame#877

Ref: Kitware/trame#877

Ref: Kitware/trame#877

Ref: Kitware/trame#877

Ref: Kitware/trame#877

Ref: Kitware/trame#877

  • tutorial: Change the doc to match the trame-tutorial update to vue3 (c4770fb)

... (truncated)

Commits
  • 62560d6 3.13.2
  • a6b24d3 fix(profiler): add support for multi trace files
  • c2ddaf7 docs(tutorial): change vuetify3 with v3 and server with self.server
  • 10f18ae docs(tutorial): change AppLayouts class name to ConeApp
  • d2b0c4d docs(tutorial): make the setup tutorial example use TrameApp
  • 718a1b4 docs(tutorial): use AppLayouts instead of AppCone as class name
  • ec26bd9 docs(tutorial): put self.server instead of server
  • bd40c73 docs(tutorial): put helper functions that don't need self out of class
  • 42fc450 docs(tutorial): use icon in VBtn parameter
  • 5908ed0 docs(tutorial): use self.server
  • Additional commits viewable in compare view

Updates trame-server from 3.14.0 to 3.14.1

Release notes

Sourced from trame-server's releases.

v3.14.1 (2026-08-31)

This release is published under the Apache License 2.0 License.

Bug Fixes

  • typed_state: Fix type resolutions (a62fe0d)

Build System

  • deps: Bump relekang/python-semantic-release in the actions group (d7b1d57)

Detailed Changes: v3.14.0...v3.14.1

Commits
  • 66492fe 3.14.1
  • a62fe0d fix(typed_state): fix type resolutions
  • d7b1d57 build(deps): bump relekang/python-semantic-release in the actions group
  • See full diff in compare view

Updates trame-vtklocal from 0.16.4 to 1.4.1

Release notes

Sourced from trame-vtklocal's releases.

v1.4.1 (2026-08-31)

This release is published under the Apache Software License License.

Bug Fixes

  • blob: Update vtk-wasm to fix blob eviction (caac278)

Documentation

  • example: Add live contour example (edff332)

Detailed Changes: v1.4.0...v1.4.1

v1.4.0 (2026-08-27)

This release is published under the Apache Software License License.

Chores

  • deps: Add trame-vuetify which is needed for devs to check examples (4bcc591)

  • deps: Bump vtk dev version (8988b98)

  • deps: Revert dev vtk version bump (fe63e0c)

  • doc: Add example gallery (293d5ee)

  • examples: Add back CLIENT_TYPE selection (8592110)

  • examples: Add render_benchmark.py (8e3638d)

  • examples: Add screenshot for actor_picker.py (0285340)

  • examples: Add screenshot for file_viewer.py (cd3da2c)

  • examples: Add uv script command in preamble (51aefb1)

  • examples: Add wasm64_large_mesh.py (552a849)

  • examples: Fix an unexpected kwarg 'representation' error (7505b6b)

  • examples: Import vtklocal from trame.widgets instead of trame_vtklocal.widgets (6168ddc)

  • examples: Remove obsolete example (72c8de3)

  • examples: Remove unused tests from examples (5e95f99)

... (truncated)

Changelog

Sourced from trame-vtklocal's changelog.

CHANGELOG

v1.3.0 (2026-08-25)

Features

  • deps: Bump vtk-wasm to 3.0 (66515a3)

vtk-wasm v3.0 adds typescript definitions for VTK classes. In order to avoid conflicts, the proxy returned by getVtkObject(id) was amended like:

| old | new | | -- | -- | | id | $id | | obj |$obj | | observe() | $observe() | | set() | $set() | | toJSON() | toJSON() | | toString() | toString() | | unObserve() | $unObserve | | unObserveAll() | $unObserveAll | | userData | $userData |

For this reason, tests and examples which use these, were renamed. If you use getVtkObject() and use any old name in Python (inline JS) or through custom JavaScript, you will need to update the code. See https://kitware.github.io/vtk-wasm/api/@​kitware/vtk-wasm/interfaces/VtkObjectProxyBase.html for the exact API.

v1.2.0 (2026-08-09)

Features

v1.1.1 (2026-08-08)

Bug Fixes

  • invoke: Allow concurrent invokes (4baeb5e)

Continuous Integration

  • Use gpu runner for linux (77fadac)

v1.1.0 (2026-07-31)

Bug Fixes

  • wasm: Handle vtk >= 9.7.20260716 wasm package

... (truncated)

Commits
  • caac278 fix(blob): update vtk-wasm to fix blob eviction
  • edff332 docs(example): add live contour example
  • a45c243 feat(eagerSync): remove eager synchronization
  • 7a0a321 docs(actor-highlight): split js into its own file
  • e17bee1 docs(wasm64_large_mesh): add note for TRAME_WS_MAX_MSG_SIZE
  • 0dcff74 docs(examples): remove examples/vtk/requirements.txt
  • 0bcff8e docs(cone): code cleanup
  • 61f64d5 docs(flow): code cleanup
  • 48b93be docs(glyph): code cleanup
  • bb7b1d8 docs(invoke): code cleanup
  • Additional commits viewable in compare view

Updates vtk from 9.6.1 to 9.7.0

Updates fastapi from 0.136.3 to 0.141.1

Release notes

Sourced from fastapi's releases.

0.141.1

Fixes

  • 🐛 Fix support for background tasks and headers from dependencies in app.frontend(). PR #16105 by @​tiangolo.

Docs

0.141.0

Features

  • ✨ Add app.frontend(check_dir="auto"), to make local development more convenient with fastapi dev. PR #16102 by @​tiangolo.

0.140.13

Fixes

Docs

0.140.12

Fixes

0.140.11

Fixes

  • 🐛 Fix response_model_* params ignored for non-generator endpoints with Iterable[..] return type. PR #15093 by @​YuriiMotov.

0.140.10

Fixes

Internal

0.140.9

Fixes

  • 🐛 Fix exclude_defaults not propagated to dict keys and values in jsonable_encoder. PR #16043 by @​MBGrao.

... (truncated)

Commits
  • 95f8322 🔖 Release version 0.141.1 (#16106)
  • f137944 📝 Update release notes
  • d623544 🐛 Fix support for background tasks and headers from dependencies in `app.fron...
  • 1d211b9 📝 Update release notes
  • 8a1f876 📝 Document FASTAPI_ENV in FastAPI CLI guide (#16104)
  • c7e7b65 🔖 Release version 0.141.0 (#16103)
  • 6bceb84 📝 Update release notes
  • 5429fed ✨ Add app.frontend(check_dir="auto"), to make local development more conven...
  • 628663f 🔖 Release version 0.140.13 (#16096)
  • 0b54fd0 📝 Update release notes
  • Additional commits viewable in compare view

Updates uvicorn from 0.24.0.post1 to 0.52.4

Release notes

Sourced from uvicorn's releases.

Version 0.52.4

Fixed

  • Remove duplicate Date headers from accepted WebSocket handshakes with websockets-sansio (#3078)

Full Changelog: Kludex/uvicorn@0.52.3...0.52.4

Version 0.52.3

Changed

  • Update zttp to 0.0.24 and use its combined receive path, improving HTTP/1.1 request parsing performance (#3067)

Full Changelog: Kludex/uvicorn@0.52.2...0.52.3

Version 0.52.2

Fixed

  • Update zttp to 0.0.22, fixing bodyless request receives and improving HTTP/1 request parsing performance (#3063)

Full Changelog: Kludex/uvicorn@0.52.1...0.52.2

Version 0.52.1

Fixed

  • Complete the closing handshake on server-initiated WebSocket closes in the websockets-sansio and wsproto implementations, waiting for the client's close reply with a 10 second timeout instead of resetting the connection (#3053)
  • Add missing write flow control to the websockets-sansio implementation, preventing data truncation on server-initiated closes with large in-flight payloads (#3048)
  • Handle connection loss while a WebSocket write is waiting on backpressure (#3050)
  • Remove duplicate Content-Type and Content-Length headers from WebSocket denial responses on the websockets-sansio implementation, and deliver non-UTF-8 denial bodies intact (#3041)

Full Changelog: Kludex/uvicorn@0.52.0...0.52.1

Version 0.52.0

This release adds an experimental HTTP/1.1 implementation backed by zttp, a sans-IO HTTP parser I've been developing on the side: a core written in Zig, with bindings to Python. It has been running under a fuzzer for some weeks now, and has been through multiple rounds of security auditing.

It is still experimental, so don't put it in front of production traffic yet. Try it with --http zttp, and please send any feedback to the issue tracker.

Added

  • Add an experimental zttp HTTP/1.1 implementation, selectable with --http zttp (#2979)

Fixed

  • Keep non-ASCII WebSocket request headers intact with websockets 17.0, which encodes them with ISO-8859-1 (#3036)

Full Changelog: Kludex/uvicorn@0.51.0...0.52.0

Version 0.51.0

What's Changed

... (truncated)

Changelog

Sourced from uvicorn's changelog.

0.52.4 (August 18, 2026)

Fixed

  • Remove duplicate Date headers from accepted WebSocket handshakes with websockets-sansio (#3078)

0.52.3 (August 13, 2026)

Changed

  • Update zttp to 0.0.24 and use its combined receive path, improving HTTP/1.1 request parsing performance (#3067)

0.52.2 (August 13, 2026)

Fixed

  • Update zttp to 0.0.22, fixing bodyless request receives and improving HTTP/1 request parsing performance (#3063)

0.52.1 (August 1, 2026)

Fixed

  • Complete the closing handshake on server-initiated WebSocket closes in the websockets-sansio and wsproto implementations, waiting for the client's close reply with a 10 second timeout instead of resetting the connection (#3053)
  • Add missing write flow control to the websockets-sansio implementation, preventing data truncation on server-initiated closes with large in-flight payloads (#3048)
  • Handle connection loss while a WebSocket write is waiting on backpressure (#3050)
  • Remove duplicate Content-Type and Content-Length headers from WebSocket denial responses on the websockets-sansio implementation, and deliver non-UTF-8 denial bodies intact (#3041)

0.52.0 (July 29, 2026)

This release adds an experimental HTTP/1.1 implementation backed by zttp, a sans-IO HTTP parser I've been developing on the side: a core written in Zig, with bindings to Python. It has been running under a fuzzer for some weeks now, and has been through multiple rounds of security auditing.

It is still experimental, so don't put it in front of production traffic yet. Try it with --http zttp, and please send any feedback to the issue tracker.

Added

  • Add an experimental zttp HTTP/1.1 implementation, selectable with --http zttp (#2979)

Fixed

  • Keep non-ASCII WebSocket request headers intact with websockets 17.0, which encodes them with ISO-8859-1 (#3036)

0.51.0 (July 8, 2026)

Added

  • Restart workers one at a time on SIGHUP, bringing each replacement up before retiring the old worker, so reloads no longer drop requests (#3025)

Removed

  • Remove colorama from the standard extra (#3027)

... (truncated)

Commits

Updates pydantic-settings from 2.6.0 to 2.15.0

Release notes

Sourced from pydantic-settings's releases.

v2.15.0

Highlights

Behavior changes

  • case_sensitive now applies to init kwargs and config-file sources (#900). InitSettingsSource and the JSON/TOML/YAML config sources previously ignored case_sensitive. Since it defaults to False, case-insensitive matching is now the default for these sources — e.g. Settings(TeSt=...) now populates a test field where it previously did not. Nested keys are still matched case-sensitively.
  • Fields with unresolved forward references now emit a warning (#901). Settings sources can silently fail to resolve such fields; they now raise IncompleteFieldDefinitionWarning telling you to call model_rebuild(). If you have filterwarnings = error configured, this may surface as a new failure.
  • Non-JSON env values for strict fields now raise ValidationError (#926) instead of a less specific error.

New features

  • Show environment variable names in CLI help via cli_show_env_vars=True (#860), so generated --help output doubles as configuration documentation.
  • PYDANTIC_SETTINGS_DEBUG for debugging settings resolution (#906, #913). Set it to a truthy value with DEBUG logging enabled to see each source's contribution in priority order, which source won for each value, and which env_file/secret files were probed, loaded, or skipped — the long-standing "why isn't my .env being picked up?" question.
  • toml_table_header for regular TOML files (#882, #886, #887), letting you root settings at a nested table in any TOML file, not just pyproject.toml.
  • Traversable support for JSON/TOML/YAML file sources (#902), so you can load config packaged inside a distribution — including files inside a zip or wheel — via importlib.resources.files(...) without casting to Path.
  • GCP: project_id can come from an earlier settings source (#878), rather than only from the constructor or GOOGLE_CLOUD_PROJECT.

Bug fixes

  • Fix env vars not loading on Windows with case_sensitive=True (#894). Windows upper-cases os.environ keys, so fields raised Field required instead of picking up their values.
  • Read secret files as UTF-8 instead of the platform locale encoding (#917). On Windows code pages such as cp1252 this silently corrupted non-ASCII secrets.
  • Fix AliasPath on nested model fields not JSON-decoding env values (#898).
  • Fix case-insensitive matching for optional nested models (#905).
  • Fix dotenv extras being wrongly claimed by a complex field sharing a name prefix (#912) — e.g. dbx_token being swallowed by a db: dict field.
  • Fix nested_model_default_partial_update=True corrupting discriminated unions (#876).
  • Fix Secret subclasses crashing when loaded from the environment (#920).
  • Fix enum names not parsing through nested annotations such as Optional[Annotated[MyEnum, ...]] with env_parse_enums=True (#910).
  • An empty yaml_config_section now falls back to defaults instead of raising AttributeError: 'NoneType' object has no attribute 'keys' (#914).
  • NestedSecretsSettingsSource no longer follows symlinks pointing outside secrets_dir (#889).
  • GCP: skip the list_secrets call when case_sensitive=True (#862), lowering the required IAM permissions to just roles/secretmanager.secretAccessor.
  • AWS: types-boto3[secretsmanager] is no longer required at runtime (#880).

Documentation

  • Document JSON parsing of complex env values, plus a comma-separated-values recipe (#919).
  • Recommend an async settings loading pattern (#908).
  • Clarify behavior when an unprefixed value is present in a dotenv file (#895).
  • Clarify environment variable helper descriptions (#867) and fix assorted typos (#904).

What's Changed

... (truncated)

Commits
  • f725ca1 Prepare release 2.15.0 (#930)
  • 28f35c2 Bump the python-packages group with 4 updates (#929)
  • 9056db0 test: move function-local imports to the top of test modules (#927)
  • f077e3a fix: raise ValidationError for non-JSON env values on strict fields (#926)
  • ae25d70 fix: treat Secret subclasses as non-complex fields (#716) (#920)
  • 798dcea Bump the python-packages group with 4 updates (#924)
  • a190041 Bump the github-actions group with 4 updates (#925)
  • 5d93332 Bump the python-packages group with 4 updates (#921)
  • d2fdeda fix: read secret files as UTF-8 instead of the locale encoding (#917)
  • 2256a4e Bump the python-packages group with 3 updates (#915)
  • Additional commits viewable in compare view

Updates click from 8.4.2 to 8.5.0

Release notes

Sourced from click's releases.

8.5.0

This is the Click 8.5.0 feature release. A feature release may include new features, remove previously deprecated code, add new deprecation, or introduce potentially breaking changes.

We encourage everyone to upgrade. You can read more about our Version Support Policy on our website.

PyPI: https://pypi.org/project/click/8.5.0/ Changes: https://click.palletsprojects.com/page/changes/#version-8-5-0 Milestone https://github.com/pallets/click/milestone/33

  • Add built-in shell completion support for PowerShell (Windows PowerShell 5.1+ and pwsh 7+) alongside the existing bash, zsh, and fish completers. Use _FOO_BAR_COMPLETE=powershell_source foo-bar to generate the completion script. #2672 #3637
  • Supported versions of Windows enable ANSI terminal styles by default. Colorama is no longer a dependency and is not used. #2986 #3505
  • {class}Argument accepts a help parameter, and help output includes a Positional arguments section when argument help is available. #2983 #3473
  • confirm() and prompt() strip ANSI color and style codes from the prompt when the output stream does not support them, matching echo(). This stripping was lost in 8.4.0 when #2969 began writing the prompt with input() directly. #3572 #3653
  • {class}Path with allow_dash=True no longer triggers a BytesWarning, an error under python -bb, when checking a value against the - convention. #2877 #3642
  • Add {func}custom_version_option, a --version option whose output is produced by a callback, covering cases {func}version_option intentionally does not. The feature set of {func}version_option is now frozen; see [discussion #3527](`@version_option` future direction pallets/click#3527). #3581
  • style() and secho() no longer silently drop the 256-color index 0 (black) passed as fg or bg, and now validate color arguments. Invalid colors raise a ValueError instead of a TypeError. #3677
  • The automatic help option stores its value under the reserved name _click_default_help instead of help, so a parameter named help no longer breaks parsing. The new name is visible in {meth}Command.to_info_dict output. Parameters that overwrite each other's value trigger a warning: an argument sharing its name with another parameter, or any parameter claiming the reserved name. Options may still share a name to compete for the same value (feature switches). #2819 #3678
  • unstyle and the ANSI handling behind help-text wrapping now strip the full CSI escape-sequence grammar. #3681
  • Streamline Option flag handling: the flag-kind, type, lazy-default and validation steps in Option.__init__ move into focused helpers, and flag_value and default keep their unset sentinel at construction (resolved lazily on read) so is UNSET reliably tells a user-supplied value from an auto-derived one. Runtime behavior is unchanged, but {meth}Parameter.to_info_dict now resolves default=True on a feature switch to its flag_value, matching what the function receives at call

... (truncated)

Changelog

Sourced from click's changelog.

Version 8.5.0

Released 2026-08-24

  • Add built-in shell completion support for PowerShell (Windows PowerShell 5.1+ and pwsh 7+) alongside the existing bash, zsh, and fish completers. Use _FOO_BAR_COMPLETE=powershell_source foo-bar to generate the completion script. {issue}2672 {pr}3637
  • Supported versions of Windows enable ANSI terminal styles by default. Colorama is no longer a dependency and is not used. {issue}2986 {pr}3505
  • {class}Argument accepts a help parameter, and help output includes a Positional arguments section when argument help is available. {issue}2983 {pr}3473
  • confirm() and prompt() strip ANSI color and style codes from the prompt when the output stream does not support them, matching echo(). This stripping was lost in 8.4.0 when {pr}2969 began writing the prompt with input() directly. {issue}3572 {pr}3653
  • Fix test failures when using pytest >= 9.1. {pr}3656
  • {class}Path with allow_dash=True no longer triggers a BytesWarning, an error under python -bb, when checking a value against the - convention. {issue}2877 {pr}3642
  • Add {func}custom_version_option, a --version option whose output is produced by a callback, covering cases {func}version_option intentionally does not. The feature set of {func}version_option is now frozen; see [discussion #3527](`@version_option` future direction pallets/click#3527). {pr}3581
  • style() and secho() no longer silently drop the 256-color index 0 (black) passed as fg or bg, and now validate color arguments. Invalid colors raise a ValueError instead of a TypeError. {pr}3677
  • The automatic help option stores its value under the reserved name _click_default_help instead of help, so a parameter named help no longer breaks parsing. The new name is visible in {meth}Command.to_info_dict output. Parameters that overwrite each other's value trigger a warning: an argument sharing its name with another parameter, or any parameter claiming the reserved name. Options may still share a name to compete for the same value (feature switches). {issue}2819 {pr}3678
  • unstyle and the ANSI handling behind help-text wrapping now strip the full CSI escape-sequence grammar. {pr}3681
  • Streamline Option flag handling: the flag-kind, type, lazy-default and validation steps in Option.__init__ move into focused helpers, and flag_value and default keep their unset sentinel at construction (resolved lazily on read) so is UNSET reliably tells a user-supplied value from an auto-derived one. Runtime behavior is unchanged, but {meth}Parameter.to_info_dict now resolves default=True on a feature switch to its flag_value, matching what the function receives at call time. {pr}3641
  • {func}get_binary_stream and {func}get_text_stream are deprecated and will be removed in Click 9.0. {issue}3481 {pr}3695
  • The following click.utils names were never intentionally public and are now private (_-prefixed). The old names remain available with a DeprecationWarning until Click 9.0: LazyFile, KeepOpenFile,

... (truncated)

Commits
  • 8b19813 Release version 8.5.0
  • 2c8cd3a Add FAQ entry about UnicodeEncodeError on Windows (#3778)
  • 131c86a Add FAQ entry about UnicodeEncodeError on Windows
  • e1fd594 Add support of pathlib.Path to edit (#3781)
  • a1d8785 Add support of pathlib.Path to edit
  • 2103e15 Forward all user's parameters set in PAGER and improve flag detection (#3777)
  • a6256bf Forwards all user's parameters set in PAGER
  • 61b69e9 Resolve the pager command once, in _pager_contextmanager (#3776)
  • 9835b0f Resolve the pager command once, in _pager_contextmanager
  • f36d58b Refactor pager stream handling (#3767)
  • Additional commits viewable in compare view

Updates pytest from 8.4.2 to 9.1.1

Release notes

Sourced from pytest's releases.

9.1.1

pytest 9.1.1 (2026-06-19)

Bug fixes

  • #14220: Fixed a logic bug in pytest.RaisesGroup which would might cause it to display incorrect "It matches FooError() which was paired with BarError" messages.
  • #14591: Fixed a regression in pytest 9.1.0 which caused overriding a parametrized fixture with an indirect @​pytest.mark.parametrize to fail with "duplicate parametrization of '<fixture name>'".
  • #14606: Fixed list-item typing errors from mypy in @pytest.mark.parametrize <pytest.mark.parametrize ref> argvalues parameter.
  • #14608: Fixed a regression in pytest 9.1.0 where conftest.py files located in <invocation dir>/test* were no longer loaded as initial conftests when invoked without arguments. This could cause certain hooks (like pytest_addoption) in these files to not fire.

9.1.0

pytest 9.1.0 (2026-06-13)

Removals and backward incompatible breaking changes

  • #14533: When using --doctest-modules, autouse fixtures with module, package or session scope that are defined inline in Python test modules (not plugins or conftests) will now possibly execute twice.

    If this is undesirable, move the fixture definition to a conftest.py file if possible.

    Technical explanation for those interested: When using --doctest-modules, pytest possibly collects Python modules twice, once as pytest.Module and once as a DoctestModule (depending on the configuration). Due to improvements in pytest's fixture implementation, if e.g. the DoctestModule collects a fixture, it is now visible to it only, and not to the Module. This means that both need to register the fixtures independently.

Deprecations (removal in next major release)

  • #10819: Added a deprecation warning for class-scoped fixtures defined as instance methods (without @classmethod). Such fixtures set attributes on a different instance than the test methods use, leading to unexpected behavior. Use @classmethod decorator instead -- by yastcher.

    See 10819 and 14011.

  • #12882: Calling request.getfixturevalue() <pytest.FixtureRequest.getfixturevalue> during teardown to request a fixture that was not already requested is now deprecated and will become an error in pytest 10.

    See dynamic-fixture-request-during-teardown for details.

  • #13409: Using non-~collections.abc.Collection iterables (such as generators, iterators, or custom iterable objects) for the argvalues parameter in @pytest.mark.parametrize <pytest.mark.parametrize ref> and metafunc.parametrize <pytest.Metafunc.parametrize> is now deprecated.

    These iterables get exhausted after the first iteration, leading to tests getting unexpectedly skipped in cases such as running pytest.main() multiple times, using class-level parametrize decorators, or collecting tests multiple times.

    See parametrize-iterators for details and suggestions.

Bumps the python-dependencies group with 18 updates:

| Package | From | To |
| --- | --- | --- |
| [trame](https://github.com/Kitware/trame) | `3.12.0` | `3.13.2` |
| [trame-server](https://github.com/Kitware/trame-server) | `3.14.0` | `3.14.1` |
| [trame-vtklocal](https://github.com/Kitware/trame-vtklocal) | `0.16.4` | `1.4.1` |
| [vtk](https://vtk.org) | `9.6.1` | `9.7.0` |
| [fastapi](https://github.com/fastapi/fastapi) | `0.136.3` | `0.141.1` |
| [uvicorn](https://github.com/Kludex/uvicorn) | `0.24.0.post1` | `0.52.4` |
| [pydantic-settings](https://github.com/pydantic/pydantic-settings) | `2.6.0` | `2.15.0` |
| [click](https://github.com/pallets/click) | `8.4.2` | `8.5.0` |
| [pytest](https://github.com/pytest-dev/pytest) | `8.4.2` | `9.1.1` |
| [pytest-cov](https://github.com/pytest-dev/pytest-cov) | `3.0.0` | `7.1.0` |
| [pytest-playwright](https://github.com/microsoft/playwright-pytest) | `0.7.2` | `0.9.0` |
| [jupyter-client](https://github.com/jupyter/jupyter_client) | `8.9.1` | `8.10.0` |
| [nbformat](https://github.com/jupyter/nbformat) | `5.11.0` | `5.11.1` |
| [deepdiff](https://github.com/qlustered/deepdiff) | `8.6.2` | `9.1.0` |
| [numpydoc](https://github.com/numpy/numpydoc) | `1.8.0` | `1.10.0` |
| [sphinx-gallery](https://github.com/sphinx-gallery/sphinx-gallery) | `0.18.0` | `0.21.0` |
| [sphinxcontrib-openapi](https://github.com/sphinx-contrib/openapi) | `0.8.4` | `0.9.0` |
| [sphinx-design](https://github.com/executablebooks/sphinx-design) | `0.6.1` | `0.7.0` |


Updates `trame` from 3.12.0 to 3.13.2
- [Release notes](https://github.com/Kitware/trame/releases)
- [Changelog](https://github.com/Kitware/trame/blob/v3.13.2/CHANGELOG.md)
- [Commits](Kitware/trame@v3.12.0...v3.13.2)

Updates `trame-server` from 3.14.0 to 3.14.1
- [Release notes](https://github.com/Kitware/trame-server/releases)
- [Changelog](https://github.com/Kitware/trame-server/blob/master/CHANGELOG.md)
- [Commits](Kitware/trame-server@v3.14.0...v3.14.1)

Updates `trame-vtklocal` from 0.16.4 to 1.4.1
- [Release notes](https://github.com/Kitware/trame-vtklocal/releases)
- [Changelog](https://github.com/Kitware/trame-vtklocal/blob/master/CHANGELOG.md)
- [Commits](Kitware/trame-vtklocal@v0.16.4...v1.4.1)

Updates `vtk` from 9.6.1 to 9.7.0

Updates `fastapi` from 0.136.3 to 0.141.1
- [Release notes](https://github.com/fastapi/fastapi/releases)
- [Commits](fastapi/fastapi@0.136.3...0.141.1)

Updates `uvicorn` from 0.24.0.post1 to 0.52.4
- [Release notes](https://github.com/Kludex/uvicorn/releases)
- [Changelog](https://github.com/Kludex/uvicorn/blob/main/docs/release-notes.md)
- [Commits](Kludex/uvicorn@0.24.0.post1...0.52.4)

Updates `pydantic-settings` from 2.6.0 to 2.15.0
- [Release notes](https://github.com/pydantic/pydantic-settings/releases)
- [Commits](pydantic/pydantic-settings@v2.6.0...v2.15.0)

Updates `click` from 8.4.2 to 8.5.0
- [Release notes](https://github.com/pallets/click/releases)
- [Changelog](https://github.com/pallets/click/blob/main/CHANGES.md)
- [Commits](pallets/click@8.4.2...8.5.0)

Updates `pytest` from 8.4.2 to 9.1.1
- [Release notes](https://github.com/pytest-dev/pytest/releases)
- [Changelog](https://github.com/pytest-dev/pytest/blob/main/CHANGELOG.rst)
- [Commits](pytest-dev/pytest@8.4.2...9.1.1)

Updates `pytest-cov` from 3.0.0 to 7.1.0
- [Changelog](https://github.com/pytest-dev/pytest-cov/blob/master/CHANGELOG.rst)
- [Commits](pytest-dev/pytest-cov@v3.0.0...v7.1.0)

Updates `pytest-playwright` from 0.7.2 to 0.9.0
- [Release notes](https://github.com/microsoft/playwright-pytest/releases)
- [Commits](microsoft/playwright-pytest@v0.7.2...v0.9.0)

Updates `jupyter-client` from 8.9.1 to 8.10.0
- [Release notes](https://github.com/jupyter/jupyter_client/releases)
- [Changelog](https://github.com/jupyter/jupyter_client/blob/main/CHANGELOG.md)
- [Commits](jupyter/jupyter_client@v8.9.1...v8.10.0)

Updates `nbformat` from 5.11.0 to 5.11.1
- [Release notes](https://github.com/jupyter/nbformat/releases)
- [Changelog](https://github.com/jupyter/nbformat/blob/main/CHANGELOG.md)
- [Commits](jupyter/nbformat@v5.11.0...v5.11.1)

Updates `deepdiff` from 8.6.2 to 9.1.0
- [Release notes](https://github.com/qlustered/deepdiff/releases)
- [Changelog](https://github.com/qlustered/deepdiff/blob/master/CHANGELOG.md)
- [Commits](https://github.com/qlustered/deepdiff/commits)

Updates `numpydoc` from 1.8.0 to 1.10.0
- [Release notes](https://github.com/numpy/numpydoc/releases)
- [Changelog](https://github.com/numpy/numpydoc/blob/main/RELEASE.rst)
- [Commits](numpy/numpydoc@v1.8.0...v1.10.0)

Updates `sphinx-gallery` from 0.18.0 to 0.21.0
- [Release notes](https://github.com/sphinx-gallery/sphinx-gallery/releases)
- [Changelog](https://github.com/sphinx-gallery/sphinx-gallery/blob/master/CHANGES.rst)
- [Commits](sphinx-gallery/sphinx-gallery@v0.18.0...v0.21.0)

Updates `sphinxcontrib-openapi` from 0.8.4 to 0.9.0
- [Changelog](https://github.com/sphinx-contrib/openapi/blob/master/CHANGES)
- [Commits](sphinx-contrib/openapi@0.8.4...0.9.0)

Updates `sphinx-design` from 0.6.1 to 0.7.0
- [Release notes](https://github.com/executablebooks/sphinx-design/releases)
- [Changelog](https://github.com/executablebooks/sphinx-design/blob/main/CHANGELOG.md)
- [Commits](executablebooks/sphinx-design@v0.6.1...v0.7.0)

---
updated-dependencies:
- dependency-name: trame
  dependency-version: 3.13.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-dependencies
- dependency-name: trame-server
  dependency-version: 3.14.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python-dependencies
- dependency-name: trame-vtklocal
  dependency-version: 1.4.1
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: python-dependencies
- dependency-name: vtk
  dependency-version: 9.7.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-dependencies
- dependency-name: fastapi
  dependency-version: 0.141.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-dependencies
- dependency-name: uvicorn
  dependency-version: 0.52.4
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-dependencies
- dependency-name: pydantic-settings
  dependency-version: 2.15.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-dependencies
- dependency-name: click
  dependency-version: 8.5.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-dependencies
- dependency-name: pytest
  dependency-version: 9.1.1
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: python-dependencies
- dependency-name: pytest-cov
  dependency-version: 7.1.0
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: python-dependencies
- dependency-name: pytest-playwright
  dependency-version: 0.9.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: python-dependencies
- dependency-name: jupyter-client
  dependency-version: 8.10.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: python-dependencies
- dependency-name: nbformat
  dependency-version: 5.11.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: python-dependencies
- dependency-name: deepdiff
  dependency-version: 9.1.0
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: python-dependencies
- dependency-name: numpydoc
  dependency-version: 1.10.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: python-dependencies
- dependency-name: sphinx-gallery
  dependency-version: 0.21.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: python-dependencies
- dependency-name: sphinxcontrib-openapi
  dependency-version: 0.9.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: python-dependencies
- dependency-name: sphinx-design
  dependency-version: 0.7.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: python-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Sep 8, 2026

Copy link
Copy Markdown
Author

Labels

The following labels could not be found: dependencies. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot dependabot Bot added the maintenance Operation not directly changing the production code - e.g., updating a devops pipeline label Sep 8, 2026
@dependabot
dependabot Bot requested a review from margalva as a code owner September 8, 2026 15:37
@dependabot dependabot Bot added the maintenance Operation not directly changing the production code - e.g., updating a devops pipeline label Sep 8, 2026
@margalva margalva closed this Sep 8, 2026
@dependabot @github

dependabot Bot commented on behalf of github Sep 8, 2026

Copy link
Copy Markdown
Author

This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests.

To ignore these dependencies, configure ignore rules in dependabot.yml

@dependabot
dependabot Bot deleted the dependabot/pip/python-dependencies-43cd783896 branch September 8, 2026 20:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

maintenance Operation not directly changing the production code - e.g., updating a devops pipeline

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants