diff --git a/book/requirements.txt b/book/requirements.txt index 958947f2..1c6b3ff7 100644 --- a/book/requirements.txt +++ b/book/requirements.txt @@ -1,5 +1,5 @@ -Markdown>=3.7,<4 -Pygments>=2.18,<3 +Markdown>=3.11,<4 +Pygments>=2.21.0,<3 PyYAML>=6,<7 -WeasyPrint>=68,<70 -pymdown-extensions>=10,<13 +WeasyPrint>=70.0,<71 +pymdown-extensions>=12.1,<13 diff --git a/pyproject.toml b/pyproject.toml index 20c47434..b3a41cf3 100644 --- a/pyproject.toml +++ b/pyproject.toml @@ -26,7 +26,7 @@ classifiers = [ "Typing :: Typed", ] dependencies = [ - "pydantic>=2.13.3", + "pydantic>=2.13.5", "pyyaml>=6.0.3", ] @@ -40,31 +40,31 @@ Issues = "https://github.com/fireflyframework/fireflyframework-pyfly/issues" templates = ["jinja2>=3.1.6"] webapp = ["pyfly[web,templates,security]"] web = [ - "starlette>=1.0.0", - "uvicorn[standard]>=0.46.0", - "python-multipart>=0.0.27", + "starlette>=1.7.0", + "uvicorn[standard]>=0.54.0", + "python-multipart>=0.0.32", ] data-relational = [ - # Requires SQLAlchemy >= 2.0.50 (2.0.49 broke pool pre-ping on the MySQL/MariaDB async drivers, C089) and is + # Requires SQLAlchemy >= 2.1.1 (2.0.49 broke pool pre-ping on the MySQL/MariaDB async drivers, C089) and is # tested on the 2.0 and 2.1 lines: the lock holds the latest release, and CI runs the suite on the newest 2.0 # release too (test-sqlalchemy-2-0). No upper bound; what differs between the lines is bridged in # pyfly.data.relational.sqlalchemy.compat. "sqlalchemy[asyncio]>=2.0.50", - "alembic>=1.18.4", + "alembic>=1.20.0", "aiosqlite>=0.22.1", ] testing = [ "jsonpath-ng>=1.8.0", ] argon2 = [ - "argon2-cffi>=23.1.0", # Argon2PasswordEncoder (OWASP-preferred password hashing) + "argon2-cffi>=25.1.0", # Argon2PasswordEncoder (OWASP-preferred password hashing) ] testcontainers = [ - "testcontainers>=4.0.0", - "pika>=1.3.0", # testcontainers' RabbitMqContainer imports pika for its readiness probe + "testcontainers>=4.15.0", + "pika>=1.4.4", # testcontainers' RabbitMqContainer imports pika for its readiness probe ] data-document = [ - "beanie>=2.1.0", + "beanie>=2.2.0", ] postgresql = [ "asyncpg>=0.31.0", @@ -75,17 +75,17 @@ mysql = [ # checkout raised TypeError (C089); asyncmy's pre-ping worked there and works on every later 2.0.x. # 0.2.11 is the oldest release the MySQL/MariaDB lanes were run on (with SQLAlchemy 2.0.50) and the # oldest with wheels for Python 3.12 and 3.13. - "asyncmy>=0.2.11", + "asyncmy>=0.2.15", ] eda = [ "aiokafka>=0.14.0", - "aio-pika>=9.6.2", + "aio-pika>=10.0.4", ] fastapi = [ - "fastapi>=0.136.1", + "fastapi>=0.141.1", ] granian = [ - "granian>=2.7.4", + "granian>=2.8.3", ] hypercorn = [ "hypercorn>=0.18.0", @@ -94,26 +94,26 @@ kafka = [ "aiokafka>=0.14.0", ] rabbitmq = [ - "aio-pika>=9.6.2", + "aio-pika>=10.0.4", ] redis = [ - "redis[hiredis]>=7.4.0", + "redis[hiredis]>=8.1.0", ] cache = [ - "redis[hiredis]>=7.4.0", + "redis[hiredis]>=8.1.0", ] oauth2-client = ["httpx>=0.28.1"] client = [ "httpx>=0.28.1", ] config-server-git = [ - "GitPython>=3.1", + "GitPython>=3.1.62", ] grpc = [ - "grpcio>=1.60.0", + "grpcio>=1.84.0", ] websocket = [ - "websockets>=12.0", + "websockets>=17.1", ] idp-azure = [ "httpx>=0.28.1", @@ -122,45 +122,45 @@ idp-keycloak = [ "httpx>=0.28.1", ] idp-cognito = [ - "boto3>=1.34.0", + "boto3>=1.43.103", ] ecm-aws = [ - "boto3>=1.34.0", + "boto3>=1.43.103", ] ecm-azure = [ - "azure-storage-blob>=12.19.0", + "azure-storage-blob>=12.30.3", ] observability = [ - "prometheus-client>=0.25.0", - "opentelemetry-api>=1.41.1", - "opentelemetry-sdk>=1.41.1", - "opentelemetry-instrumentation-starlette>=0.62b1", - "structlog>=25.5.0", + "prometheus-client>=0.26.0", + "opentelemetry-api>=1.45.0", + "opentelemetry-sdk>=1.45.0", + "opentelemetry-instrumentation-starlette>=0.66b0", + "structlog>=26.1.0", ] scheduling = [ - "croniter>=6.2.2", + "croniter>=6.2.4", ] pii = [ - "presidio-analyzer>=2.2", - "presidio-anonymizer>=2.2", + "presidio-analyzer>=2.2.364", + "presidio-anonymizer>=2.2.364", ] security = [ - "pyjwt[crypto]>=2.12.1", + "pyjwt[crypto]>=2.15.0", "bcrypt>=5.0.0", - "cryptography>=48.0.0", - "pyotp>=2.9.0", + "cryptography>=50.0.1", + "pyotp>=2.10.0", ] notifications = [ "jinja2>=3.1.6", ] cli = [ - "click>=8.3.3", + "click>=8.5.0", "rich>=15.0.0", "jinja2>=3.1.6", "questionary>=2.1.1", ] shell = [ - "click>=8.3.3", + "click>=8.5.0", ] web-fast = [ "pyfly[web,granian]", @@ -177,20 +177,20 @@ full = [ [dependency-groups] browser = ["playwright>=1.63.0"] dev = [ - "pytest>=9.0.3", - "pytest-asyncio>=1.3.0", + "pytest>=9.1.1", + "pytest-asyncio>=1.4.0", "pytest-cov>=7.1.0", - "coverage[toml]>=7.13.5", - "mypy>=1.20.2", - "ruff>=0.15.12", + "coverage[toml]>=7.16.1", + "mypy>=2.3.1", + "ruff>=0.16.9", "jsonpath-ng>=1.8.0", - "respx>=0.21.0", - "aiosmtpd>=1.4", + "respx>=0.23.1", + "aiosmtpd>=1.4.6", # The OTLP exporter is the DEFAULT tracing exporter (auto_configuration selects it as soon as an # endpoint is configured), yet it appears in no extra, so nothing in CI ever imported it and the # whole OTLP path — including how the endpoint is built — went unexercised. It is a dev dependency # rather than a new runtime one: applications choose their exporter and pay for it deliberately. - "opentelemetry-exporter-otlp-proto-http>=1.41.1", + "opentelemetry-exporter-otlp-proto-http>=1.45.0", # The second MySQL/MariaDB async driver the docs name (mysql+aiomysql://). The integration lanes run # pool pre-ping through both drivers, so neither can regress unseen (C089). "aiomysql>=0.3.2", diff --git a/requirements-docs.txt b/requirements-docs.txt index 8c5b0c4c..9a8b931a 100644 --- a/requirements-docs.txt +++ b/requirements-docs.txt @@ -1,4 +1,4 @@ # Documentation site toolchain (PyFly GitHub Pages). # Used by scripts/build_site.py and the GitHub Actions Pages workflow. # pip install -r requirements-docs.txt -mkdocs-material>=9.5,<10 +mkdocs-material>=9.7.7,<10