Skip to content

build(deps): bump the minor-and-patch group across 1 directory with 17 updates - #571

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/src/minor-and-patch-786943ff42
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/src/minor-and-patch-786943ff42

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 6, 2026

Copy link
Copy Markdown
Contributor

Bumps the minor-and-patch group with 17 updates in the /src directory:

Package From To
langchain-core 1.5.3 1.6.6
langchain-text-splitters 1.1.2 1.1.3
python-dotenv 1.2.2 1.2.4
langchain-openai 1.4.3 1.6.7
tiktoken 0.13.0 0.14.0
pydantic 2.13.4 2.13.5
pydash 8.0.6 8.1.0
spacy 3.8.14 3.8.16
mcp 2.0.0 2.3.0
pypdf 6.15.0 6.19.0
nltk 3.10.2 3.10.3
transformers 5.15.0 5.18.0
sqlalchemy 2.0.51 2.0.54
langchain-anthropic 1.5.4 1.7.5
boto3 1.43.68 1.43.108
flake8 7.3.0 7.4.1
mypy 2.3.0 2.4.0

Updates langchain-core from 1.5.3 to 1.6.6

Release notes

Sourced from langchain-core's releases.

langchain-core==1.6.6

Changes since langchain-core==1.6.5

release(core): 1.6.6 (#40906) fix(anthropic): support Claude Sonnet 5.5 compatibility (#40882) docs(core): fix docstring examples that don't run as copied (#40815)

langchain-core==1.6.5

Changes since langchain-core==1.6.4

release(core): 1.6.5 (#40816) fix(core): abbreviate long tool IDs in XML buffer strings (#40792)

langchain-core==1.6.4

Changes since langchain-core==1.6.3

release(core): 1.6.4 (#40718) chore(core): deprecate chat message history (#40711) chore(deps): bump anyio from 4.12.0 to 4.14.2 in /libs/core (#40634) chore(deps): bump soupsieve from 2.8.4 to 2.9 in /libs/core (#40574)

langchain-core==1.6.3

Changes since langchain-core==1.6.2

release(core): 1.6.3 (#40407) feat(core): Allow model name and provider tracing metadata override based on gateway response (#40406) test(core): cover the deprecated .text() access path (#40243) docs(core): remove stale Args/Raises entries from FileCallbackHandler._write and ChatGeneration.set_text (#40211)

langchain-core==1.6.2

Changes since langchain-core==1.6.1

release(core): 1.6.2 (#40209) feat(openai): support async tools (#40208) chore(deps): bump mistune from 3.3.0 to 3.3.3 in /libs/core (#40150) chore(deps): bump tornado from 6.5.7 to 6.5.8 in /libs/core (#40113) fix(core): avoid mutation in google-genai standard content (#40023) fix(core): avoid mutation in bedrock converse standard content (#40022)

langchain-core==1.6.1

Changes since langchain-core==1.6.0

revert: release(core): 1.6.2 (#39971) release(core): 1.6.2 (#39967) fix(core): shore up indexing in genai v1 streaming content (#39964) fix(core): make StructuredTool JSON-serializable (#39631) chore(deps): bump minor and patch dependencies (#39869) release(core): 1.6.1 (#39832) feat(core): propagate gateway information on error path (#39829)

... (truncated)

Commits

Updates langchain-text-splitters from 1.1.2 to 1.1.3

Release notes

Sourced from langchain-text-splitters's releases.

langchain-text-splitters==1.1.3

Changes since langchain-text-splitters==1.1.2

release(text-splitters): 1.1.3 (#41001) chore(deps): bump the minor-and-patch group across 3 directories with 4 updates (#40969) chore(deps): bump tornado from 6.5.9 to 6.5.10 in /libs/text-splitters (#40971) chore(deps): bump urllib3 from 2.7.0 to 2.8.0 in /libs/text-splitters (#40938) chore(deps): bump tornado from 6.5.8 to 6.5.9 in /libs/text-splitters (#40940) chore(deps): bump anyio from 4.14.2 to 4.15.1 in /libs/text-splitters (#40645) chore(deps): bump anyio from 4.11.0 to 4.14.2 in /libs/text-splitters (#40624) chore(deps): bump soupsieve from 2.8.4 to 2.9 in /libs/text-splitters (#40579) chore(deps): bump the minor-and-patch group across 3 directories with 5 updates (#40566) chore(deps): bump types-requests from 2.33.0.20260712 to 2.33.0.20260906 in /libs/text-splitters (#40568) chore(deps): update lxml requirement from <7.0,>=6.1.2 to >=6.1.3,<7.0 in /libs/text-splitters (#40569) chore(deps): bump mistune from 3.3.0 to 3.3.3 in /libs/text-splitters (#40148) chore(deps): bump the minor-and-patch group across 3 directories with 5 updates (#40085) chore(deps): update lxml requirement from <7.0,>=6.1.0 to >=6.1.2,<7.0 in /libs/text-splitters (#40087) chore(deps): bump tornado from 6.5.7 to 6.5.8 in /libs/text-splitters (#40112) chore: bump the minor-and-patch group across 3 directories with 8 updates (#39863) chore: bump the major group across 2 directories with 2 updates (#39864) chore: bump types-requests from 2.33.0.20260518 to 2.33.0.20260712 in /libs/text-splitters (#39867) fix(text-splitters): raise TypeError for non-dict, non-convertible input to RecursiveJsonSplitter (#39238) chore: bump the minor-and-patch group across 3 directories with 7 updates (#39187) chore(infra): add missing LICENSE files to publishable packages (#39146) chore: bump jupyterlab from 4.5.9 to 4.5.10 in /libs/text-splitters (#39028) chore: bump setuptools from 80.9.0 to 83.0.0 in /libs/text-splitters (#39029) chore: bump torch from 2.12.1 to 2.13.0 in /libs/text-splitters (#38946) chore: bump soupsieve from 2.8 to 2.8.4 in /libs/text-splitters (#38748) chore: bump nltk from 3.9.4 to 3.10.0 in /libs/text-splitters (#38747) chore: bump mistune from 3.2.1 to 3.3.0 in /libs/text-splitters (#38826) chore(deps): refresh lockfiles (#38746) fix(text-splitters): restore lazy imports for heavy optional dependencies (#35469) feat(text-splitters): replace mypy by ty for type checking (#38658) chore: bump the minor-and-patch group across 3 directories with 11 updates (#38587) chore: bump pytest from 9.1.0 to 9.1.1 in /libs/text-splitters (#38299) chore: bump jupyterlab from 4.5.7 to 4.5.9 in /libs/text-splitters (#38296) chore: bump langsmith from 0.8.5 to 0.8.18 in /libs/text-splitters (#38301) chore: bump tornado from 6.5.6 to 6.5.7 in /libs/text-splitters (#38175) chore: bump bleach from 6.2.0 to 6.4.0 in /libs/text-splitters (#38195) chore: bump torch from 2.9.1 to 2.12.1 in /libs/text-splitters (#38231) chore: bump pytest from 9.0.3 to 9.1.0 in /libs/text-splitters (#38232) chore: bump jupyter-server from 2.18.0 to 2.20.0 in /libs/text-splitters (#38250) docs: refresh README installation and resources (#38119) chore: bump tornado from 6.5.5 to 6.5.6 in /libs/text-splitters (#38112) release(core): 1.4.7 (#38111) release(core): 1.4.6 (#38061) chore(infra): bump mypy to 2.1 and unify type-check config across the monorepo (#36470) fix(langchain): tighten structured output model fallbacks (#38042) hotfix(core): bump lockfile(s) (#38032) chore(core): fix some any generics (#34545)

... (truncated)

Commits
  • e2db474 release(text-splitters): 1.1.3 (#41001)
  • 0f13669 chore(model-profiles): refresh model profile data (#40994)
  • ff46bb4 fix(ollama): raise ollama floor to 0.6.3 for thinking levels (#40986)
  • 884d2d6 chore(deps): bump uv to 0.12.21 (#40975)
  • 6f258ae chore(model-profiles): refresh model profile data (#40974)
  • 0904175 chore(deps): bump urllib3 from 2.7.0 to 2.8.0 in /libs/core (#40972)
  • ba41751 chore(deps): bump the minor-and-patch group across 3 directories with 4 updat...
  • dc7b1d8 chore(deps): bump aws-actions/configure-aws-credentials from 6.2.4 to 6.3.0 i...
  • 402dfa6 chore(deps): bump tornado from 6.5.9 to 6.5.10 in /libs/text-splitters (#40971)
  • 79aa9cf chore(deps): bump tornado from 6.5.8 to 6.5.9 in /libs/core (#40970)
  • Additional commits viewable in compare view

Updates python-dotenv from 1.2.2 to 1.2.4

Release notes

Sourced from python-dotenv's releases.

v1.2.4

Fixed

  • dotenv get no longer exits with code 1 for empty string values (KEY=) by [@​ShamikOfficial] in #700
  • An unquoted empty value followed by an inline comment (e.g. KEY= # comment) is now parsed as an empty string instead of the comment text by [@​Noethix55555] in #663
  • dotenv run --no-override now expands variable references with the same precedence as load_dotenv(override=False), so a value like ${BASE}/suffix uses the existing BASE from the environment instead of the one from the .env file by [@​ROTl24] in #698

v1.2.3

Fixed

  • Strip a leading UTF-8 BOM from .env file contents so the first variable is no longer silently lost when the file is saved with BOM (e.g. by some JetBrains IDEs on Windows) by [@​h1whelan] in #640
  • set_key now escapes backslashes, so values containing them (Windows paths, regular expressions) survive a write/read round-trip. Quoted values ending in an escaped backslash are no longer mis-parsed as an escaped quote, which used to swallow the following lines by [@​dchaudhari7177] in #680
  • dotenv run now prints a friendly error instead of a traceback when no command is given by [@​bbc2] in #606
  • Cache the parsed result for empty .env files so repeated dotenv_values/load_dotenv calls no longer re-read the file by [@​ReinerBRO] in #638
Changelog

Sourced from python-dotenv's changelog.

[1.2.4] - 2026-10-01

Fixed

  • dotenv get no longer exits with code 1 for empty string values (KEY=) by [@​ShamikOfficial] in #700
  • An unquoted empty value followed by an inline comment (e.g. KEY= # comment) is now parsed as an empty string instead of the comment text by [@​Noethix55555] in #663
  • dotenv run --no-override now expands variable references with the same precedence as load_dotenv(override=False), so a value like ${BASE}/suffix uses the existing BASE from the environment instead of the one from the .env file by [@​ROTl24] in #698

[1.2.3] - 2026-08-16

Fixed

  • Strip a leading UTF-8 BOM from .env file contents so the first variable is no longer silently lost when the file is saved with BOM (e.g. by some JetBrains IDEs on Windows) by [@​h1whelan] in #640
  • set_key now escapes backslashes, so values containing them (Windows paths, regular expressions) survive a write/read round-trip. Quoted values ending in an escaped backslash are no longer mis-parsed as an escaped quote, which used to swallow the following lines by [@​dchaudhari7177] in #680
  • dotenv run now prints a friendly error instead of a traceback when no command is given by [@​bbc2] in #606
  • Cache the parsed result for empty .env files so repeated dotenv_values/load_dotenv calls no longer re-read the file by [@​ReinerBRO] in #638
Commits
  • a565c2c Bump version: 1.2.3 → 1.2.4
  • 4a7abd0 docs: add 1.2.4 release notes (#663, #698, #700)
  • f215c02 fix: dotenv get exits 0 for empty string values (#700)
  • 58f2d7c test: make test_run_with_command_flags portable and meaningful (#709)
  • e0310e5 fix: honor --no-override when expanding variables in dotenv run (#698)
  • a00cb2e docs: add CHANGELOG entry for #663 (fix #600)
  • f5485a6 fix: parse empty unquoted value with inline comment as empty string
  • 49515af Bump version: 1.2.2 → 1.2.3
  • 8ac846f chore: add release runbook (RELEASING.md) and make release target
  • bb31c94 docs: add 1.2.3 release notes (#606, #638, #680)
  • Additional commits viewable in compare view

Updates langchain-openai from 1.4.3 to 1.6.7

Release notes

Sourced from langchain-openai's releases.

langchain-openai==1.6.7

Changes since langchain-openai==1.6.6

release(openai): 1.6.7 (#40933) chore(model-profiles): refresh model profile data (#40924) test(openai): drop retired completions live tests (#40910) chore(model-profiles): refresh model profile data (#40869) feat(openai): discover Azure workload identity (#40532)

langchain-openai==1.6.6

Changes since langchain-openai==1.6.5

release(openai): 1.6.6 (#40800) fix(openai): raise on error events in stream path (#40791)

langchain-openai==1.6.5

Changes since langchain-openai==1.6.4

release(openai): 1.6.5 (#40787) fix(anthropic): add Opus 5.5 and GPT-6 profile augmentations (#40785) feat(anthropic,openai): mid-conversation tool changes on SystemMessage (#40758)

langchain-openai==1.6.4

Changes since langchain-openai==1.6.3

release(openai): 1.6.4 (#40775) chore(model-profiles): refresh openai model profile data (#40774)

langchain-openai==1.6.3

Changes since langchain-openai==1.6.2

release(openai): 1.6.3 (#40719) fix(openai): expose inferred Responses API routing at initialization (#40715) chore(deps): bump anyio from 4.11.0 to 4.14.2 in /libs/partners/openai (#40629) fix(openai): support GPT-6 request constraints (#40443)

langchain-openai==1.6.2

Changes since langchain-openai==1.6.1

release(openai): 1.6.2 (#40339) fix(openai): add GPT-6 Astra reasoning efforts (#40330) chore(deps): bump httpx2 from 2.10.0 to 2.12.0 in /libs/partners/openai (#40309)

langchain-openai==1.6.1

Changes since langchain-openai==1.6.0

fix(openai): bump max_completion_tokens in cache breakpoint integration test (#40284) release(openai): 1.6.1 (#40268) chore(model-profiles): refresh model profile data (#40217) fix(openai): support Azure AD auth with OpenAI 3.8 (#40190)

... (truncated)

Commits

Updates tiktoken from 0.13.0 to 0.14.0

Changelog

Sourced from tiktoken's changelog.

[v0.14.0]

  • Build wheels for Python 3.15
  • Support looking up more GPT-5 series models
  • Upgrade dependencies
Commits

Updates pydantic from 2.13.4 to 2.13.5

Release notes

Sourced from pydantic's releases.

v2.13.5 (2026-08-28)

What's Changed

Fixes

  • Allow reuse of validators when plugins are set by @​Viicos in #13535
  • Fix missing GC traversal on some pydantic-core struct fields by @​Viicos in #13624
  • Fix missing GC traversal in pydantic-core for GeneralFieldsSerializer by @​Viicos in #13629
  • Count validated model fields once in smart unions by @​tamird in #13731
Changelog

Sourced from pydantic's changelog.

v2.13.5 (2026-08-28)

GitHub release

What's Changed

Fixes

  • Allow reuse of validators when plugins are set by @​Viicos in #13535
  • Fix missing GC traversal on some pydantic-core struct fields by @​Viicos in #13624
  • Fix missing GC traversal in pydantic-core for GeneralFieldsSerializer by @​Viicos in #13629
  • Count validated model fields once in smart unions by @​tamird in #13731
Commits
  • 001dea0 Bump pypa/gh-action-pypi-publish action to v1.14.2
  • 558379f Bump twine to v7.0.0
  • 2cfd5d3 Do not check for docs build
  • a735bee Fix more Clippy lints
  • 7eed4a1 Fix Clippy 0.1.95 warnings
  • b353bbb Prepare release v2.13.5
  • 63d2ccc Count validated model fields once in smart unions
  • a53ec2e Speed up PyPy CI tests
  • d65e0f9 Workaround circular import error in Mypy
  • 47a6dbf Fix missing GC traversal in pydantic-core for GeneralFieldsSerializer
  • Additional commits viewable in compare view

Updates pydash from 8.0.6 to 8.1.0

Changelog

Sourced from pydash's changelog.

v8.1.0 (2026-08-29)

  • Support iterables in take_while and drop_while. Thanks Sai Asish Y!
  • Guard all dunder-path access on objects. Thanks gaoflow_!
  • Fix flattening nested iterables. Thanks gaoflow_!
  • Fix StopIteration leak in iterintersperse on empty iterable. Thanks gaoflow_!
  • Fix in_range to support reversed ranges where start is greater than end by swapping the bounds, matching lodash's documented _.inRange behavior (e.g. in_range(-3, -2, -6) now returns True). Thanks gaoflow_!
  • Fix floor, ceil, and round_ passing index as precision when used as iteratees. Thanks gaoflow_!
  • Fix debounce to delay execution until after wait milliseconds of quiet instead of invoking immediately on the first call. Thanks SeaStarDeng_!
  • Fix to_list returning a dict_values view instead of a list for dicts. Thanks HarperZ9_!
  • Fix chunk to return empty list when size is less than 1. Thanks santhreal_!
  • Fix mishandling of out-of-range indexes in pull_at. Thanks santhreal_!
  • Fix mean, mean_by, and median to return NaN on empty collections. Thanks santhreal_!
  • Fix last_index_of missing a match at index 0. Thanks uttam12331_!
  • Fix empty key handling in deep paths. Thanks CodingFeng101_!
Commits
  • f46de36 release: v8.1.0
  • 5625ed8 docs: update CHANGELOG and AUTHORS for next release
  • 37db753 chore(functions): reduce debounce timing for tests
  • e7f93d7 fix: delay debounce until after wait milliseconds of quiet (#255)
  • d18b5d4 chore(utilities): minor early continue optimization in _to_path_keys
  • 2617072 Preserve empty keys in deep paths (#247)
  • fbab9f9 Fix last_index_of missing a match at index 0 (#256)
  • 4d150cc chore(lint): ignore ruff check PLR0917
  • 7a627f4 fix: return NaN from mean/mean_by on empty collections (#251)
  • 307b82b fix: return NaN from median on empty collections (#254)
  • Additional commits viewable in compare view

Updates spacy from 3.8.14 to 3.8.16

Release notes

Sourced from spacy's releases.

v3.8.16

No release notes provided.

v3.8.15: Fix click requirement

Typer removed click as a dependency in favour of vendoring it, but spaCy imports from Click, so the requirement needs to be added.

Commits
  • 26b4d1d Remove publish_pypi workflow
  • aed14d1 Increment version
  • 66d2948 Fix build directory [ci skip]
  • ca59885 Improve bandwidth usage on Netlify (#14024) [ci skip]
  • f69c32f Install click with previous spaCy in upgrade test
  • 29bc4f2 Fix release smoke/upgrade tests
  • 86edb26 Build linux wheels in manylinux_2_28 containers
  • 7a64151 Cap hypothesis below 6.156 to keep win_arm64 wheel builds working
  • 768e8d5 Fix CI: bump mypy pin for numpy 2.5 stubs, sync confection pin
  • edd3d0f Format tests README code blocks for ruff 0.16 markdown formatting
  • Additional commits viewable in compare view

Updates mcp from 2.0.0 to 2.3.0

Release notes

Sourced from mcp's releases.

v2.3.0

pip install -U mcp. Docs: https://py.sdk.modelcontextprotocol.io/

Mostly fixes, plus three new options. A few things behave differently, so skim these first:

Behaviour changes

httpx2>=2.10.0 is now required (#3600)

  • It was >=2.5.0. The new max_sse_event_size option needs it.
  • Nothing to do unless you pin httpx2 below 2.10.

A tool with an invalid x-mcp-header annotation fails at registration (#3620)

  • @mcp.tool(), add_tool and Tool.from_function raise InvalidSignature, naming the tool and the problem.
  • Until now the server started, and 2026-07-28 clients silently dropped the tool from their listing.
  • Refused: anything other than a plain str, int or bool parameter (so also str | None, float, lists and enums), a header name that isn't a valid token, and two names that differ only by case.
  • For an optional header parameter, give the schema directly: Annotated[str | None, WithJsonSchema({"type": "string", "x-mcp-header": "Region"})] = None.

Empty _meta and params are no longer sent (#3628)

  • On 2025-11-25 and earlier connections, 2.x sent "_meta": {} on every request. Some servers reject that. It is now left out, as in v1.
  • ping and list requests without a cursor go out with no params member.
  • On the receiving side ctx.meta is None rather than {}, and middleware sees ctx.params as None for a request without params.
  • 2026-07-28 connections are unchanged.

initialize leaves out experimental when none is configured (#3614)

  • It used to send "experimental": {}. server/discover already left it out.
  • Client code reading capabilities.experimental on a legacy connection should handle None.

Mcp-Param-* validation looks the tool up by name (#3630)

  • MCPServer no longer runs tools/list for every tools/call, so middleware no longer sees that extra request.
  • The registered schema is what gets checked. Middleware that filters or rewrites tools/list no longer affects it.

An interactive OAuth login no longer counts against request timeouts (#3635)

  • The timeout pauses while OAuthClientProvider waits on redirect_handler and callback_handler.
  • This fixes Client(mode="auto") settling on 2025-11-25 when the login took longer than 10 seconds.
  • A request timeout no longer ends a login nobody finishes. Put a limit inside callback_handler if you need one.

New

  • max_sse_event_size= on streamable_http_client and StreamableHttpParameters. The default stays 1 MiB per SSE event; raise it, or pass None, for larger tool results (#3600).
  • MCPServer(subscriptions=False) stops serving subscriptions/listen and advertises listChanged and subscribe as false (#3626).
  • Server(get_tool_input_schema=...) lets a low-level server supply a tool's schema for header validation without running its tools/list handler (#3630).
  • Client.call_tool re-lists the tools and retries once after a HeaderMismatch (-32020) rejection (#3627).

Fixes

  • ctx: Context[AppState] works on prompts and resource templates, not only on tools (#3624).
  • An explicit "structuredContent": null is checked against the output schema instead of being treated as missing (#3621).
  • A progress_callback that raises no longer fails the call on an in-process Client(server) (#3623).
  • Client OpenTelemetry spans record JSON-RPC error responses. With mode="auto", connecting to a server without server/discover now shows one ERROR span for the probe (#3629).
  • stdio_client resolves the executable off the event loop on Windows (#3510).

... (truncated)

Commits
  • 2118f14 docs: refresh translations for recent English changes (#3636)
  • ed9b2d6 Stop counting an interactive OAuth login against request timeouts (#3635)
  • d5cebd1 Keep inline-snapshot disabled when pytest runs in a terminal (#3634)
  • c15566c Link What's new to the Header parameters page (#3632)
  • 4d29994 Let a newer Deploy Docs run cancel the one in progress (#3633)
  • 0acea60 Bump urllib3 from 2.7.0 to 2.8.0 (#3607)
  • c54075c Look the tool schema up by name for Mcp-Param-* validation instead of running...
  • 9afccae Retry a tool call once after a HeaderMismatch rejection (#3627)
  • cafa33b Record JSON-RPC error responses on the client OpenTelemetry span (#3629)
  • 0b2fd3e Omit an empty _meta and empty params from outbound requests (#3628)
  • Additional commits viewable in compare view

Updates pypdf from 6.15.0 to 6.19.0

Release notes

Sourced from pypdf's releases.

Version 6.19.0, 2026-09-16

What's new

Security (SEC)

Deprecations (DEP)

Performance Improvements (PI)

Bug Fixes (BUG)

Full Changelog

Version 6.18.1, 2026-09-11

What's new

Security (SEC)

Bug Fixes (BUG)

Robustness (ROB)

Documentation (DOC)

Full Changelog

Version 6.18.0, 2026-09-07

What's new

Please note that this release requires users which previously overwrote the default limits to migrate to the new approach: Docs

In short:

  • Use apply_configuration as a context manager to temporarily overwrite configuration values.

... (truncated)

Changelog

Sourced from pypdf's changelog.

Version 6.19.0, 2026-09-16

Security (SEC)

  • Limit size of alphabetical page labels (#4096)

Deprecations (DEP)

  • Replace PdfWriter method add_js (#3979)

Performance Improvements (PI)

  • Move static value out of loop body for appearance stream data (#4087)
  • Reduce number of full data lookups for attachment mapping API (#4081)

Bug Fixes (BUG)

  • Do not copy unrelated pages when appending pages with non-terminal fields (#4078)
  • Use page reference for existing internal link targets (#4076)
  • Arabic-Indic digits are reversed during text extraction (#4077)
  • Parse a string rect for add_uri into a rectangle (#4074)

Full Changelog

Version 6.18.1, 2026-09-11

Security (SEC)

  • Further restrict FlateDecode recovery (#4073)
  • Limit entry count for TrueType and Type1 font /Widths (#4072)
  • Limit allowed length of tokens in parse_bfchar (#4071)

Bug Fixes (BUG)

  • Use current text matrix for visitor_text (#4062)
  • Repeat the letter for /S /A and /S /a page labels past Z (#4065)
  • Use font color for FreeText default appearance (#4051)

Robustness (ROB)

  • Fix compatibility with fonttools < 4.58.0 (#4050, #4059)

Documentation (DOC)

  • Use combined matrix in visitor examples (#4066)

Full Changelog

Version 6.18.0, 2026-09-07

Security (SEC)

  • Limit allowed length of indirect object tokens (#4055)

Deprecations (DEP)

  • Rework configuration value handling (#4044)

New Features (ENH)

  • Draw borders and backgrounds for appearance streams and annotations (#4033)

…7 updates

Bumps the minor-and-patch group with 17 updates in the /src directory:

| Package | From | To |
| --- | --- | --- |
| [langchain-core](https://github.com/langchain-ai/langchain) | `1.5.3` | `1.6.6` |
| [langchain-text-splitters](https://github.com/langchain-ai/langchain) | `1.1.2` | `1.1.3` |
| [python-dotenv](https://github.com/theskumar/python-dotenv) | `1.2.2` | `1.2.4` |
| [langchain-openai](https://github.com/langchain-ai/langchain) | `1.4.3` | `1.6.7` |
| [tiktoken](https://github.com/openai/tiktoken) | `0.13.0` | `0.14.0` |
| [pydantic](https://github.com/pydantic/pydantic) | `2.13.4` | `2.13.5` |
| [pydash](https://github.com/dgilland/pydash) | `8.0.6` | `8.1.0` |
| [spacy](https://github.com/explosion/spaCy) | `3.8.14` | `3.8.16` |
| [mcp](https://github.com/modelcontextprotocol/python-sdk) | `2.0.0` | `2.3.0` |
| [pypdf](https://github.com/py-pdf/pypdf) | `6.15.0` | `6.19.0` |
| [nltk](https://github.com/nltk/nltk) | `3.10.2` | `3.10.3` |
| [transformers](https://github.com/huggingface/transformers) | `5.15.0` | `5.18.0` |
| [sqlalchemy](https://github.com/sqlalchemy/sqlalchemy) | `2.0.51` | `2.0.54` |
| [langchain-anthropic](https://github.com/langchain-ai/langchain) | `1.5.4` | `1.7.5` |
| [boto3](https://github.com/boto/boto3) | `1.43.68` | `1.43.108` |
| [flake8](https://github.com/pycqa/flake8) | `7.3.0` | `7.4.1` |
| [mypy](https://github.com/python/mypy) | `2.3.0` | `2.4.0` |



Updates `langchain-core` from 1.5.3 to 1.6.6
- [Release notes](https://github.com/langchain-ai/langchain/releases)
- [Commits](langchain-ai/langchain@langchain-core==1.5.3...langchain-core==1.6.6)

Updates `langchain-text-splitters` from 1.1.2 to 1.1.3
- [Release notes](https://github.com/langchain-ai/langchain/releases)
- [Commits](langchain-ai/langchain@langchain-text-splitters==1.1.2...langchain-text-splitters==1.1.3)

Updates `python-dotenv` from 1.2.2 to 1.2.4
- [Release notes](https://github.com/theskumar/python-dotenv/releases)
- [Changelog](https://github.com/theskumar/python-dotenv/blob/main/CHANGELOG.md)
- [Commits](theskumar/python-dotenv@v1.2.2...v1.2.4)

Updates `langchain-openai` from 1.4.3 to 1.6.7
- [Release notes](https://github.com/langchain-ai/langchain/releases)
- [Commits](langchain-ai/langchain@langchain-openai==1.4.3...langchain-openai==1.6.7)

Updates `tiktoken` from 0.13.0 to 0.14.0
- [Release notes](https://github.com/openai/tiktoken/releases)
- [Changelog](https://github.com/openai/tiktoken/blob/main/CHANGELOG.md)
- [Commits](openai/tiktoken@0.13.0...0.14.0)

Updates `pydantic` from 2.13.4 to 2.13.5
- [Release notes](https://github.com/pydantic/pydantic/releases)
- [Changelog](https://github.com/pydantic/pydantic/blob/v2.13.5/HISTORY.md)
- [Commits](pydantic/pydantic@v2.13.4...v2.13.5)

Updates `pydash` from 8.0.6 to 8.1.0
- [Changelog](https://github.com/dgilland/pydash/blob/develop/CHANGELOG.rst)
- [Commits](dgilland/pydash@v8.0.6...v8.1.0)

Updates `spacy` from 3.8.14 to 3.8.16
- [Release notes](https://github.com/explosion/spaCy/releases)
- [Changelog](https://github.com/explosion/spaCy/blob/master/RELEASE_NOTES.md)
- [Commits](explosion/spaCy@release-v3.8.14...release-v3.8.16)

Updates `mcp` from 2.0.0 to 2.3.0
- [Release notes](https://github.com/modelcontextprotocol/python-sdk/releases)
- [Changelog](https://github.com/modelcontextprotocol/python-sdk/blob/main/RELEASE.md)
- [Commits](modelcontextprotocol/python-sdk@v2.0.0...v2.3.0)

Updates `pypdf` from 6.15.0 to 6.19.0
- [Release notes](https://github.com/py-pdf/pypdf/releases)
- [Changelog](https://github.com/py-pdf/pypdf/blob/main/CHANGELOG.md)
- [Commits](py-pdf/pypdf@6.15.0...6.19.0)

Updates `nltk` from 3.10.2 to 3.10.3
- [Release notes](https://github.com/nltk/nltk/releases)
- [Changelog](https://github.com/nltk/nltk/blob/develop/ChangeLog)
- [Commits](nltk/nltk@v3.10.2...v3.10.3)

Updates `transformers` from 5.15.0 to 5.18.0
- [Release notes](https://github.com/huggingface/transformers/releases)
- [Commits](huggingface/transformers@v5.15.0...v5.18.0)

Updates `sqlalchemy` from 2.0.51 to 2.0.54
- [Release notes](https://github.com/sqlalchemy/sqlalchemy/releases)
- [Changelog](https://github.com/sqlalchemy/sqlalchemy/blob/main/CHANGES.rst)
- [Commits](https://github.com/sqlalchemy/sqlalchemy/commits)

Updates `langchain-anthropic` from 1.5.4 to 1.7.5
- [Release notes](https://github.com/langchain-ai/langchain/releases)
- [Commits](langchain-ai/langchain@langchain-anthropic==1.5.4...langchain-anthropic==1.7.5)

Updates `boto3` from 1.43.68 to 1.43.108
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](boto/boto3@1.43.68...1.43.108)

Updates `flake8` from 7.3.0 to 7.4.1
- [Commits](PyCQA/flake8@7.3.0...7.4.1)

Updates `mypy` from 2.3.0 to 2.4.0
- [Changelog](https://github.com/python/mypy/blob/master/CHANGELOG.md)
- [Commits](python/mypy@v2.3.0...v2.4.0)

---
updated-dependencies:
- dependency-name: langchain-core
  dependency-version: 1.6.6
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: langchain-text-splitters
  dependency-version: 1.1.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: python-dotenv
  dependency-version: 1.2.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: langchain-openai
  dependency-version: 1.6.7
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: tiktoken
  dependency-version: 0.14.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: pydantic
  dependency-version: 2.13.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: pydash
  dependency-version: 8.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: spacy
  dependency-version: 3.8.16
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: mcp
  dependency-version: 2.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: pypdf
  dependency-version: 6.19.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: nltk
  dependency-version: 3.10.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: transformers
  dependency-version: 5.18.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: sqlalchemy
  dependency-version: 2.0.54
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: langchain-anthropic
  dependency-version: 1.7.5
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: boto3
  dependency-version: 1.43.108
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: flake8
  dependency-version: 7.4.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: mypy
  dependency-version: 2.4.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Oct 6, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants