Skip to content

chore(deps): Bump the minor-and-patch group across 1 directory with 12 updates - #873

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/a2a/generic_agent/minor-and-patch-644966e65f
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/a2a/generic_agent/minor-and-patch-644966e65f

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 25, 2026

Copy link
Copy Markdown
Contributor

Bumps the minor-and-patch group with 12 updates in the /a2a/generic_agent directory:

Package From To
a2a-sdk 1.1.0 1.1.5
langgraph 1.2.9 1.2.12
langchain-core 1.4.9 1.6.4
langchain-openai 1.3.4 1.6.3
openinference-instrumentation-langchain 0.1.67 0.1.76
pydantic-settings 2.14.2 2.15.0
langchain-mcp-adapters 0.3.0 0.3.2
opentelemetry-exporter-otlp 1.43.0 1.44.0
urllib3 2.7.0 2.8.0
langsmith 0.10.1 0.14.0
starlette 1.3.1 1.6.0
aiohttp 3.14.1 3.14.3

Updates a2a-sdk from 1.1.0 to 1.1.5

Release notes

Sourced from a2a-sdk's releases.

v1.1.5

1.1.5 (2026-09-21)

Bug Fixes

  • deps: support protobuf 7 (#1260) (67ba0a4)
  • replace deprecated FieldDescriptor.label with is_repeated in proto_utils (#1158) (4554e2d)
  • server: avoid out-of-range datetime task ordering (#1220) (d55a3d3)

v1.1.4

1.1.4 (2026-09-07)

Features

  • itk: register itk-python-v10-agent as a uv workspace member and update dependency version markers (#1203) (6eee895)
  • itk: use shared scenarios (#1201) (b4a0b21)

Bug Fixes

  • make event queue sink removal idempotent (#1134) (58c72c6)
  • omit artifacts from list tasks responses (#1212) (35ef52e)
  • owner-scope cancel/subscribe and write terminal state on cancel (#1159, #1170) (#1172) (ddbf853)
  • prevent first-owner write loss in in-memory stores (#1194) (bcc489c)
  • server: let subscriber taps evict on full instead of wedging dispatch (#1137) (0c2126f)
  • server: surface producer errors after failed tasks (#1229) (bc32d7e)
  • server: validate push-notification URLs at config creation (#1173) (3eb88e2)
  • server: validate push-notification URLs before dispatch (SSRF hardening) (#1164) (57a9df3)
  • server: warn when queue_manager is ignored in DefaultRequestHandlerV2 (#1153) (08fd223)

Documentation

  • server: say what the evict-on-full check actually tests (#1209) (4b7b242)

v1.1.3

1.1.3 (2026-08-18)

Bug Fixes

  • use threading.RLock for in-memory server singletons (#1162) (5bae35b)

v1.1.2

1.1.2 (2026-07-20)

Features

... (truncated)

Changelog

Sourced from a2a-sdk's changelog.

1.1.5 (2026-09-21)

Bug Fixes

  • deps: support protobuf 7 (#1260) (67ba0a4)
  • replace deprecated FieldDescriptor.label with is_repeated in proto_utils (#1158) (4554e2d)
  • server: avoid out-of-range datetime task ordering (#1220) (d55a3d3)

1.1.4 (2026-09-07)

Features

  • itk: register itk-python-v10-agent as a uv workspace member and update dependency version markers (#1203) (6eee895)
  • itk: use shared scenarios (#1201) (b4a0b21)

Bug Fixes

  • make event queue sink removal idempotent (#1134) (58c72c6)
  • omit artifacts from list tasks responses (#1212) (35ef52e)
  • owner-scope cancel/subscribe and write terminal state on cancel (#1159, #1170) (#1172) (ddbf853)
  • prevent first-owner write loss in in-memory stores (#1194) (bcc489c)
  • server: let subscriber taps evict on full instead of wedging dispatch (#1137) (0c2126f)
  • server: surface producer errors after failed tasks (#1229) (bc32d7e)
  • server: validate push-notification URLs at config creation (#1173) (3eb88e2)
  • server: validate push-notification URLs before dispatch (SSRF hardening) (#1164) (57a9df3)
  • server: warn when queue_manager is ignored in DefaultRequestHandlerV2 (#1153) (08fd223)

Documentation

  • server: say what the evict-on-full check actually tests (#1209) (4b7b242)

1.1.3 (2026-08-18)

Bug Fixes

  • use threading.RLock for in-memory server singletons (#1162) (5bae35b)

1.1.2 (2026-07-20)

Features

  • server: add aclose() to drain ActiveTask background tasks (#1101) (#1105) (9801f46)

... (truncated)

Commits
  • 9f0f00c chore(main): release 1.1.5 (#1235)
  • 67ba0a4 fix(deps): support protobuf 7 (#1260)
  • 9a00f9b chore(deps): bump the github-actions group across 1 directory with 5 updates ...
  • c232f50 chore: revert "ci: simulate release failure to exercise notify-failure" (#1257)
  • 944542c ci: simulate release failure to exercise notify-failure (#1255)
  • d92f350 ci: create issue on release failures (#1254)
  • 0db0e7b ci: add A2A protocol authentication support and integrate ACTS conformance te...
  • 9ea4b60 chore(revert): revert "ci: allow publishing from existing tags" (#1252)
  • 5926871 ci: allow publishing from existing tags (#1251)
  • 45b92bc ci: upgrade pypa/gh-action-pypi-publish to 1.14.2 (#1250)
  • Additional commits viewable in compare view

Updates langgraph from 1.2.9 to 1.2.12

Release notes

Sourced from langgraph's releases.

langgraph==1.2.12

Changes since 1.2.11

  • release(langgraph): 1.2.12 (#8987)
  • chore(deps): bump soupsieve from 2.8.4 to 2.9 in /libs/langgraph (#8958)
  • feat(langgraph): add response_schema to interrupt() (#8886)
  • fix(langgraph): type undeclared v3 stream projections (#8596)
  • chore(langgraph): bump mistune to 3.3.4 (#8804)
  • chore(deps): bump the minor-and-patch group across 1 directory with 7 updates (#8779)
  • chore(deps): bump the minor-and-patch group across 1 directory with 4 updates (#8782)
  • chore(deps): bump tornado from 6.5.7 to 6.5.8 in /libs/langgraph (#8792)
  • chore(deps): bump the major group in /libs/langgraph with 2 updates (#8783)
  • fix(langgraph): detect subgraphs from bytecode instead of source (#8569)

langgraph==1.2.11

Changes since 1.2.10

  • release(langgraph): 1.2.11 (#8595)
  • feat(langgraph): expose trace_policy on add_node (#8523)
  • chore(deps): bump the minor-and-patch group across 1 directory with 7 updates (#8533)
  • chore(deps): bump the minor-and-patch group across 1 directory with 5 updates (#8532)
  • release(checkpoint-postgres): 3.1.2 (#8565)
  • release(checkpoint): 4.2.0 (#8563)
  • fix(checkpoint): collect writes at plain-value seed in delta channel history (#8526)
  • chore: enforce PLC0415 in tests for the remaining packages (#8547)
  • test(checkpoint-postgres,checkpoint-sqlite): run the conformance suite (#8537)
  • chore: enable RUF100 and clear unused noqa directives (#8546)
  • chore(deps-dev): bump types-requests from 2.33.0.20260518 to 2.33.0.20260712 in /libs/langgraph (#8502)
  • chore(deps): bump cryptography from 48.0.1 to 50.0.0 in /libs/langgraph (#8528)
  • release(checkpoint-sqlite): 3.1.1 (#8481)
  • release(checkpoint-postgres): 3.1.1 (#8480)

langgraph==1.2.10

Changes since 1.2.9

  • release(langgraph): 1.2.10 (#8462)
  • chore(deps): bump jupyterlab from 4.5.9 to 4.5.10 in /libs/langgraph (#8440)
  • chore(deps): bump setuptools from 80.9.0 to 83.0.0 in /libs/langgraph (#8435)
  • feat(langgraph): type v3 stream_events return and native projections (#8389)
  • revert(langgraph): delete TracePolicy (#8403)
  • feat(langgraph): drop tags from TracePolicy (#8402)
  • feat(langgraph): expose trace_policy on add_node (#8362)
  • chore(deps): bump mistune from 3.2.1 to 3.3.0 in /libs/langgraph (#8317)
  • chore(deps): bump soupsieve from 2.8.1 to 2.8.4 in /libs/langgraph (#8318)
  • chore(cli): allow langgraph-api versions up to 1.0.0 (#8319)
Commits
  • 49cce0c release(sdk-py): 0.4.5 (#8988)
  • 19273fa release(langgraph): 1.2.12 (#8987)
  • ed384f3 fix(cli): remediate AnyIO vulnerabilities in example lockfiles (#9022)
  • aa742fb chore(deps): bump anyio from 4.14.2 to 4.15.1 in /libs/sdk-py (#8997)
  • b58044a chore(deps): bump anyio from 4.13.0 to 4.14.2 in /libs/cli (#8998)
  • daa514a chore(deps): bump anyio from 4.13.0 to 4.14.2 in /libs/checkpoint-conformance...
  • 022043a chore(deps): bump anyio from 4.12.1 to 4.14.2 in /libs/checkpoint (#8995)
  • d7b99cc chore(deps): bump anyio from 4.12.1 to 4.14.2 in /libs/sdk-py (#8994)
  • b19edd7 chore(deps): bump anyio from 4.12.1 to 4.14.2 in /libs/checkpoint-sqlite (#8993)
  • c81c135 chore(deps): bump soupsieve from 2.8.4 to 2.9 in /libs/langgraph (#8958)
  • Additional commits viewable in compare view

Updates langchain-core from 1.4.9 to 1.6.4

Release notes

Sourced from langchain-core's releases.

langchain-core==1.6.4

Changes since langchain-core==1.6.3

release(core): 1.6.4 (#40718) chore(core): deprecate chat message history (#40711) chore(deps): bump anyio from 4.12.0 to 4.14.2 in /libs/core (#40634) chore(deps): bump soupsieve from 2.8.4 to 2.9 in /libs/core (#40574)

langchain-core==1.6.3

Changes since langchain-core==1.6.2

release(core): 1.6.3 (#40407) feat(core): Allow model name and provider tracing metadata override based on gateway response (#40406) test(core): cover the deprecated .text() access path (#40243) docs(core): remove stale Args/Raises entries from FileCallbackHandler._write and ChatGeneration.set_text (#40211)

langchain-core==1.6.2

Changes since langchain-core==1.6.1

release(core): 1.6.2 (#40209) feat(openai): support async tools (#40208) chore(deps): bump mistune from 3.3.0 to 3.3.3 in /libs/core (#40150) chore(deps): bump tornado from 6.5.7 to 6.5.8 in /libs/core (#40113) fix(core): avoid mutation in google-genai standard content (#40023) fix(core): avoid mutation in bedrock converse standard content (#40022)

langchain-core==1.6.1

Changes since langchain-core==1.6.0

revert: release(core): 1.6.2 (#39971) release(core): 1.6.2 (#39967) fix(core): shore up indexing in genai v1 streaming content (#39964) fix(core): make StructuredTool JSON-serializable (#39631) chore(deps): bump minor and patch dependencies (#39869) release(core): 1.6.1 (#39832) feat(core): propagate gateway information on error path (#39829)

langchain-core==1.6.0

Changes since langchain-core==1.5.6

release(core): 1.6.0 (#39760) fix(core): resolve postponed annotations in StructuredTool._injected_args_keys (#39602) feat(core): add standard model exception types (#39538) fix(core): allow deserializing RunnablePick (#39753) fix(core): make convert_to_openai_function handle callables and non-dict mappings (#39750) fix(core): make subprocess and temporary file tests portable on Windows (#39664) fix(core): fail fast when tool schemas can't resolve forward refs during serialization (#39570) test(core): avoid version-dependent runnable snapshots (#39705) fix(core): require all nested properties for strict tool schemas (#39306) fix(core): remove stale sync-stream xfail [closes #39720] (#39723)

... (truncated)

Commits

Updates langchain-openai from 1.3.4 to 1.6.3

Release notes

Sourced from langchain-openai's releases.

langchain-openai==1.6.3

Changes since langchain-openai==1.6.2

release(openai): 1.6.3 (#40719) fix(openai): expose inferred Responses API routing at initialization (#40715) chore(deps): bump anyio from 4.11.0 to 4.14.2 in /libs/partners/openai (#40629) fix(openai): support GPT-6 request constraints (#40443)

langchain-openai==1.6.2

Changes since langchain-openai==1.6.1

release(openai): 1.6.2 (#40339) fix(openai): add GPT-6 Astra reasoning efforts (#40330) chore(deps): bump httpx2 from 2.10.0 to 2.12.0 in /libs/partners/openai (#40309)

langchain-openai==1.6.1

Changes since langchain-openai==1.6.0

fix(openai): bump max_completion_tokens in cache breakpoint integration test (#40284) release(openai): 1.6.1 (#40268) chore(model-profiles): refresh model profile data (#40217) fix(openai): support Azure AD auth with OpenAI 3.8 (#40190) feat(openai): support async tools (#40208) feat(openai): support configuration_update (#40201) chore(model-profiles): refresh model profile data (#40171) fix(openai): route gpt-5.6-sol to responses API (#40133) chore(openai): fix tests (#39972) fix(openai): correct reasoning_effort_levels for gpt-5 and gpt-5.1 profiles (#39936) chore(model-profiles): refresh model profile data (#39954)

langchain-openai==1.6.0

Changes since langchain-openai==1.5.2

release(openai): 1.6.0 (#39762) feat(core): add standard model exception types (#39538) fix(openai): raise clear error on unexpected response type in _create_chat_result (#39731)

langchain-openai==1.5.2

Changes since langchain-openai==1.5.1

release(openai): 1.5.2 (#39719) fix(openai): preserve reasoning item boundaries (#39278) release(openai): 1.5.2a1 (#39709) feat(openai): extract gateway metadata from response headers when available (#39706) chore(openai): update snapshots (#39657) fix(openai): support o-series models in get_num_tokens_from_messages (#38710)

langchain-openai==1.5.2a1

Initial release

... (truncated)

Commits

Updates openinference-instrumentation-langchain from 0.1.67 to 0.1.76

Release notes

Sourced from openinference-instrumentation-langchain's releases.

python-openinference-instrumentation-langchain: v0.1.76

0.1.76 (2026-09-10)

Bug Fixes

  • bump openinference-semantic-conventions minimum to >=0.1.37 (#3711) (a3b5b6c)
Commits
  • 3729ab4 chore: release main (#3712)
  • 2cc4ee2 chore(openai): support OpenAI Python SDK 3.x (#3647)
  • a3b5b6c fix: bump openinference-semantic-conventions minimum to >=0.1.37 (#3711)
  • a2e7ff6 chore: release main (#3707)
  • adaf9e7 feat(openai_agents): record file_search and web_search tool calls (#1726) (#3...
  • 2e04736 chore(deps): update llama-index-llms-anthropic requirement from <0.12.0,>=0.1...
  • ad0903e chore(deps): update anthropic requirement from <1.1 to <1.3 in /python/instru...
  • 029ca88 chore: release main (#3704)
  • 971e3db feat(openai_agents): record computer_call and computer_call_output (#1726) (#...
  • 8abaf89 chore: release main (#3681)
  • Additional commits viewable in compare view

Updates pydantic-settings from 2.14.2 to 2.15.0

Release notes

Sourced from pydantic-settings's releases.

v2.15.0

Highlights

Behavior changes

  • case_sensitive now applies to init kwargs and config-file sources (#900). InitSettingsSource and the JSON/TOML/YAML config sources previously ignored case_sensitive. Since it defaults to False, case-insensitive matching is now the default for these sources — e.g. Settings(TeSt=...) now populates a test field where it previously did not. Nested keys are still matched case-sensitively.
  • Fields with unresolved forward references now emit a warning (#901). Settings sources can silently fail to resolve such fields; they now raise IncompleteFieldDefinitionWarning telling you to call model_rebuild(). If you have filterwarnings = error configured, this may surface as a new failure.
  • Non-JSON env values for strict fields now raise ValidationError (#926) instead of a less specific error.

New features

  • Show environment variable names in CLI help via cli_show_env_vars=True (#860), so generated --help output doubles as configuration documentation.
  • PYDANTIC_SETTINGS_DEBUG for debugging settings resolution (#906, #913). Set it to a truthy value with DEBUG logging enabled to see each source's contribution in priority order, which source won for each value, and which env_file/secret files were probed, loaded, or skipped — the long-standing "why isn't my .env being picked up?" question.
  • toml_table_header for regular TOML files (#882, #886, #887), letting you root settings at a nested table in any TOML file, not just pyproject.toml.
  • Traversable support for JSON/TOML/YAML file sources (#902), so you can load config packaged inside a distribution — including files inside a zip or wheel — via importlib.resources.files(...) without casting to Path.
  • GCP: project_id can come from an earlier settings source (#878), rather than only from the constructor or GOOGLE_CLOUD_PROJECT.

Bug fixes

  • Fix env vars not loading on Windows with case_sensitive=True (#894). Windows upper-cases os.environ keys, so fields raised Field required instead of picking up their values.
  • Read secret files as UTF-8 instead of the platform locale encoding (#917). On Windows code pages such as cp1252 this silently corrupted non-ASCII secrets.
  • Fix AliasPath on nested model fields not JSON-decoding env values (#898).
  • Fix case-insensitive matching for optional nested models (#905).
  • Fix dotenv extras being wrongly claimed by a complex field sharing a name prefix (#912) — e.g. dbx_token being swallowed by a db: dict field.
  • Fix nested_model_default_partial_update=True corrupting discriminated unions (#876).
  • Fix Secret subclasses crashing when loaded from the environment (#920).
  • Fix enum names not parsing through nested annotations such as Optional[Annotated[MyEnum, ...]] with env_parse_enums=True (#910).
  • An empty yaml_config_section now falls back to defaults instead of raising AttributeError: 'NoneType' object has no attribute 'keys' (#914).
  • NestedSecretsSettingsSource no longer follows symlinks pointing outside secrets_dir (#889).
  • GCP: skip the list_secrets call when case_sensitive=True (#862), lowering the required IAM permissions to just roles/secretmanager.secretAccessor.
  • AWS: types-boto3[secretsmanager] is no longer required at runtime (#880).

Documentation

  • Document JSON parsing of complex env values, plus a comma-separated-values recipe (#919).
  • Recommend an async settings loading pattern (#908).
  • Clarify behavior when an unprefixed value is present in a dotenv file (#895).
  • Clarify environment variable helper descriptions (#867) and fix assorted typos (#904).

What's Changed

... (truncated)

Commits
  • f725ca1 Prepare release 2.15.0 (#930)
  • 28f35c2 Bump the python-packages group with 4 updates (#929)
  • 9056db0 test: move function-local imports to the top of test modules (#927)
  • f077e3a fix: raise ValidationError for non-JSON env values on strict fields (#926)
  • ae25d70 fix: treat Secret subclasses as non-complex fields (#716) (#920)
  • 798dcea Bump the python-packages group with 4 updates (#924)
  • a190041 Bump the github-actions group with 4 updates (#925)
  • 5d93332 Bump the python-packages group with 4 updates (#921)
  • d2fdeda fix: read secret files as UTF-8 instead of the locale encoding (#917)
  • 2256a4e Bump the python-packages group with 3 updates (#915)
  • Additional commits viewable in compare view

Updates langchain-mcp-adapters from 0.3.0 to 0.3.2

Release notes

Sourced from langchain-mcp-adapters's releases.

langchain-mcp-adapters==0.3.2

What's Changed

New Contributors

Full Changelog: langchain-ai/langchain-mcp-adapters@langchain-mcp-adapters==0.3.1...langchain-mcp-adapters==0.3.2

langchain-mcp-adapters==0.3.1

What's Changed

New Contributors

Full Changelog: langchain-ai/langchain-mcp-adapters@langchain-mcp-adapters==0.3.0...langchain-mcp-adapters==0.3.1

Commits
  • cc0f284 release: 0.3.2 (#604)
  • d4a1caa fix(deps): cap mcp below 2.0.0 to prevent import failures (#590)
  • a060231 build(deps): bump cryptography from 48.0.1 to 50.0.0 (#599)
  • c50072a build(deps): bump cryptography from 48.0.1 to 50.0.0 in /examples/servers/str...
  • e81a81b release: 0.3.1 (#587)
  • d4c6611 feat: add get_server_infoDescription has been truncated

…2 updates

---
updated-dependencies:
- dependency-name: a2a-sdk
  dependency-version: 1.1.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: langgraph
  dependency-version: 1.2.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: langchain-core
  dependency-version: 1.6.4
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: langchain-openai
  dependency-version: 1.6.3
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: openinference-instrumentation-langchain
  dependency-version: 0.1.76
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: pydantic-settings
  dependency-version: 2.15.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: langchain-mcp-adapters
  dependency-version: 0.3.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: opentelemetry-exporter-otlp
  dependency-version: 1.44.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: urllib3
  dependency-version: 2.8.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: langsmith
  dependency-version: 0.14.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: starlette
  dependency-version: 1.6.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: aiohttp
  dependency-version: 3.14.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels Sep 25, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code

Projects

Status: New/ToDo

Development

Successfully merging this pull request may close these issues.

1 participant