Skip to content

chore(deps): bump the python-dependencies group in /sdk/python with 3 updates - #876

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/sdk/python/python-dependencies-9828b4e949
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/sdk/python/python-dependencies-9828b4e949

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 5, 2026

Copy link
Copy Markdown
Contributor

Bumps the python-dependencies group in /sdk/python with 3 updates: langchain-core, crewai and pydantic-ai-slim.

Updates langchain-core from 1.6.5 to 1.6.6

Release notes

Sourced from langchain-core's releases.

langchain-core==1.6.6

Changes since langchain-core==1.6.5

release(core): 1.6.6 (#40906) fix(anthropic): support Claude Sonnet 5.5 compatibility (#40882) docs(core): fix docstring examples that don't run as copied (#40815)

Commits

Updates crewai from 1.15.22 to 1.15.23

Release notes

Sourced from crewai's releases.

1.15.23

What's Changed

Features

  • Add support for native Gemini 3.8 Flash
  • Implement evaluation of the last traced run through AMP in crewai eval
  • Record the last traced run for crewai eval instead of printing it
  • Improve platform integration setup UX
  • Prioritize popular platform integrations
  • Enhance tracing task spans to include declared output format and results

Bug Fixes

  • Fix visibility of the panel for viewing traces
  • Resolve issue with turning tracing on and add an Evaluate button in the TUI
  • Retry throttled provider calls in LLM
  • Fall back to synchronous calls from acall in Bedrock
  • Print areas graded by the evaluation in CLI
  • Ensure link is shown after finalizing traces
  • Keep Selenium driver reusable
  • Close S3 response bodies properly
  • Collapse multimodal content with shared helper
  • Match roles in LLM overlay that differ only by surrounding whitespace
  • Close SQLite connections in flow persistence and SQLite provider
  • Preserve directory listing paths

Documentation

  • Update guides for assistants to platform tools

Contributors

@​Copilot, @​Mairaarshad19, @​SharoonSharif, @​Vidit-Ostwal, @​gaoanze888, @​joaomdmoura, @​lorenzejay, @​sclfcz, @​stepchanges, @​vinibrsl

Commits
  • deaa71e [docs-freeze] docs: snapshot and changelog for v1.15.23 (#7805)
  • c018da6 feat: bump versions to 1.15.23 (#7804)
  • d183aed ensure panel for viewing traces is visible (#7803)
  • 4dcd19a fix(tracing): turning tracing on is the answer, and an Evaluate button in the...
  • 4ed2abc fix(llm): retry throttled provider calls (#7677)
  • 0e6440b docs(cli): guide assistants to platform tools (#7581)
  • a2ea278 feat(cli): prioritize popular platform integrations (#7573)
  • dd4a106 fix(bedrock): fall back to sync calls from acall (#7680)
  • 7060bf8 Merge pull request #7717 from crewAIInc/security-policy-update
  • 6536114 fix(deps): pin instructor <1.16 to keep OpenAI Mode.TOOLS registered (#7719)
  • Additional commits viewable in compare view

Updates pydantic-ai-slim from 2.50.0 to 2.53.0

Release notes

Sourced from pydantic-ai-slim's releases.

v2.53.0 (2026-10-01)

🛡️ Security

This release fixes one security issue in ConcurrencyLimitedModel. See the advisory for full details and affected versions.

  • GHSA-6fqq-452j-qhrp (high): a streamed request through ConcurrencyLimitedModel or limit_model_concurrency could keep its concurrency slot when the slot was released on a different task than the one that acquired it: after an early exit (the consumer stopped iterating, raised, or was cancelled), and also after fully consuming stream_text() with its default debouncing. Repeated streams could then block every request sharing the limiter. Agent-level max_concurrency and non-streaming requests are not affected. Reported by @​lche511. (#9478)

The fix also changes how limiters are shared: a model wrapper now raises UserError when it shares a limiter with the agent making the request or with an enclosing model wrapper, ConcurrencyLimiter.acquire() takes a slot on every call, even on the same task, and a custom AbstractConcurrencyLimiter must allow release() from another task.

Patched in 2.53.0. v1 is not affected.

What's Changed

⚠️ Compatibility Notes

🚀 Features

🐛 Bug Fixes

... (truncated)

Commits
  • b38ab5d Document that InlineDefsJsonSchemaTransformer only walks object and array k...
  • c50e223 Keep the test suite passing on anthropic 1.11.0, dbos 3.2.0 and `google-g...
  • 453f19f Fix RuntimeError and a leaked slot when streaming through `ConcurrencyLimit...
  • d63315d Let GoogleRealtimeModel declare tools whose dict values are recursive mod...
  • ce6b675 Allow unschemable types in the derived Temporal ActivityConfig schema (#9577)
  • f596e4b Keep the launch-directory workspace in clai2 when capability functions supp...
  • 5b5a414 Fix the TOML disk sub-agent test that still expected the removed effort floor...
  • 1013241 Make Logfire Temporal spans replay-safe (#7006)
  • 9da37d4 Expose the message-history repair pipeline as repair_messages (#8370)
  • aba3e75 Say native tools aren't routed to OpenAI realtime yet, rather than unsupporte...
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the python-dependencies group in /sdk/python with 3 updates: [langchain-core](https://github.com/langchain-ai/langchain), [crewai](https://github.com/crewAIInc/crewAI) and [pydantic-ai-slim](https://github.com/pydantic/pydantic-ai).


Updates `langchain-core` from 1.6.5 to 1.6.6
- [Release notes](https://github.com/langchain-ai/langchain/releases)
- [Commits](langchain-ai/langchain@langchain-core==1.6.5...langchain-core==1.6.6)

Updates `crewai` from 1.15.22 to 1.15.23
- [Release notes](https://github.com/crewAIInc/crewAI/releases)
- [Commits](crewAIInc/crewAI@1.15.22...1.15.23)

Updates `pydantic-ai-slim` from 2.50.0 to 2.53.0
- [Release notes](https://github.com/pydantic/pydantic-ai/releases)
- [Changelog](https://github.com/pydantic/pydantic-ai/blob/main/docs/changelog.md)
- [Commits](pydantic/pydantic-ai@v2.50.0...v2.53.0)

---
updated-dependencies:
- dependency-name: langchain-core
  dependency-version: 1.6.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python-dependencies
- dependency-name: crewai
  dependency-version: 1.15.23
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python-dependencies
- dependency-name: pydantic-ai-slim
  dependency-version: 2.53.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels Oct 5, 2026
@coderabbitai

coderabbitai Bot commented Oct 5, 2026

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 8d28f550-dc41-49af-9cd3-8d1dcd7a5ee0

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

Thanks @dependabot[bot] for keeping our dependencies current! 🙌

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants