Skip to content

Bump the python group across 1 directory with 13 updates - #24

Merged
MattFisher merged 1 commit into
mainfrom
dependabot/uv/python-6913b7a1a3
Sep 14, 2026
Merged

MattFisher merged 1 commit into
mainfrom
dependabot/uv/python-6913b7a1a3

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 15, 2026 •

Copy link
Copy Markdown
Contributor

⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


Updates the requirements on aiohttp, click, rich, datasets, openai, inspect-ai, inspect-evals, playwright, pytest, pytest-asyncio, pytest-playwright, ruff and uv-build to permit the latest version.
Updates aiohttp from 3.13.5 to 3.14.3

Changelog

Sourced from aiohttp's changelog.

3.14.3 (2026-07-22)

Bug fixes

  • Fixed the client dropping only the first Authorization, Cookie and Proxy-Authorization header when a redirect crossed an origin -- by :user:arshsmith1.

    Related issues and pull requests on GitHub: :issue:13180.

  • Fixed error message construction in the C HTTP parser -- by :user:bdraco.

    Related issues and pull requests on GitHub: :issue:13222.


3.14.2 (2026-07-20)

Bug fixes

  • Fixed :py:attr:~aiohttp.web.StreamResponse.last_modified rounding a :class:datetime.datetime with a fractional second down.

    Related issues and pull requests on GitHub: :issue:5303.

  • Fixed resolving localhost on Windows to fall back without AI_ADDRCONFIG when the first lookup fails, so localhost still works without an active network.

    Related issues and pull requests on GitHub: :issue:5357.

... (truncated)

Commits

Updates click from 8.3.1 to 8.4.2

Release notes

Sourced from click's releases.

8.4.2

This is the Click 8.4.1 fix release, which fixes bugs but does not otherwise change behavior and should not result in breaking changes compared to the latest feature release.

PyPI: https://pypi.org/project/click/8.4.2/ Changes: https://click.palletsprojects.com/page/changes/#version-8-4-2 Milestone: https://github.com/pallets/click/milestone/34

  • Fix Fish shell completion broken in 8.4.0 by #3126. Newlines and tabs in option help text are now escaped, keeping the original completion format while still supporting multi-line help. #3502 #3043 #3504 #3508
  • Deprecated commands and options with empty or missing help text no longer render a stray leading space before the (DEPRECATED) label. #3509
  • A {class}Group with invoke_without_command=True marks its subcommand as optional in the usage help, showing [COMMAND] instead of COMMAND. #3059 #3507
  • echo_via_pager flushes after each write, so passing a generator streams output to the pager incrementally instead of staying hidden until the pipe buffer fills. #3242 #2542 #3534
  • echo_via_pager and get_pager_file no longer close a borrowed stdout stream when no external pager runs, completing the partial I/O operation on closed file fix from #3482. #3449 #3533
  • Fix CLI usage symopsis for optional arguments producing double square brackets [[a|b|c]]... whose type already brackets their metavar. #3578
  • {func}version_option resolves a package_name that does not match an installed distribution as an import (top-level module) name via {func}importlib.metadata.packages_distributions. Packages whose top-level module name differs from their distribution name (PIL vs Pillow, jwt vs PyJWT) no longer raise RuntimeError out of the box. #2331 #1884 #3125 #3582

8.4.1

This is the Click 8.4.1 fix release, which fixes bugs but does not otherwise change behavior and should not result in breaking changes compared to the latest feature release.

PyPI: https://pypi.org/project/click/8.4.1/ Changes: https://click.palletsprojects.com/page/changes/#version-8-4-1 Milestone: https://github.com/pallets/click/milestone/32

  • get_parameter_source() is available during eager callbacks and type conversion again. #3458 #3484
  • Zsh completion scripts parse correctly on Windows. #3277 # 3466
  • Shell completion of Choice Enum values produces a valid completion result. #3015
  • Fix empty byte-string handling in echo. #3487
  • Fix closed file error with echo_via_pager. #3449

8.4.0

This is the Click 8.4.0 feature release. A feature release may include new features, remove previously deprecated code, add new deprecation, or introduce potentially breaking changes.

We encourage everyone to upgrade. You can read more about our [Version Support Policy][version] on our website.

... (truncated)

Changelog

Sourced from click's changelog.

Version 8.4.2

Released 2026-06-24

  • Fix Fish shell completion broken in 8.4.0 by {pr}3126. Newlines and tabs in option help text are now escaped, keeping the original completion format while still supporting multi-line help. {issue}3502 {issue}3043 {pr}3504 {pr}3508
  • Deprecated commands and options with empty or missing help text no longer render a stray leading space before the (DEPRECATED) label. {pr}3509
  • A {class}Group with invoke_without_command=True marks its subcommand as optional in the usage help, showing [COMMAND] instead of COMMAND. {issue}3059 {pr}3507
  • echo_via_pager flushes after each write, so passing a generator streams output to the pager incrementally instead of staying hidden until the pipe buffer fills. {issue}3242 {issue}2542 {pr}3534
  • echo_via_pager and get_pager_file no longer close a borrowed stdout stream when no external pager runs, completing the partial I/O operation on closed file fix from {pr}3482. {issue}3449 {pr}3533
  • Fix CLI usage symopsis for optional arguments producing double square brackets [[a|b|c]]... whose type already brackets their metavar. {pr}3578
  • {func}version_option resolves a package_name that does not match an installed distribution as an import (top-level module) name via {func}importlib.metadata.packages_distributions. Packages whose top-level module name differs from their distribution name (PIL vs Pillow, jwt vs PyJWT) no longer raise RuntimeError out of the box. {issue}2331 {issue}1884 {issue}3125 {pr}3582

Version 8.4.1

Released 2026-05-21

  • get_parameter_source() is available during eager callbacks and type conversion again. {issue}3458 {pr}3484
  • Zsh completion scripts parse correctly on Windows. {issue}3277 {pr}3466
  • Shell completion of Enum values used as Choice options produces a valid completion result. {issue}3015 {pr}3471
  • Fix empty byte-string handling in echo. {issue}3487 {pr}3493
  • Fix closed file error with echo_via_pager. {issue}3449 {pr}3482
  • Fix open_url on Windows when the file path contains spaces. {issue}2994 {pr}3478

Version 8.4.0

Released 2026-05-17

  • {class}ParamType typing improvements. {pr}3371

    • {class}ParamType is now a generic abstract base class,

... (truncated)

Commits
  • b2e30a1 Release version 8.4.2
  • 7a16b20 Fix package_name resolution when module differs from distribution name (#3582)
  • bec5928 Fix package_name resolution when top-level module differs from distribution...
  • 916883a Fix tests to not rely on -Wdefault option (#3591)
  • 09195f6 Fix double-bracketing of choices in synopsis (#3578)
  • 1557e26 Check for warning exception with idiomatic context manager
  • d9ff133 Static typing improvements in click.shell_completion (#3460)
  • 762c97e Fix double-bracketing of choices in synopsis
  • 8929d39 Convert changes to markdown. (#3559)
  • 237be50 Move changes headings down a level.
  • Additional commits viewable in compare view

Updates rich from 14.3.3 to 15.0.0

Release notes

Sourced from rich's releases.

The So Long 3.8 Release

A few fixes. The major version bump is to honor the passing of 3.8 support which reached its EOL in October 7, 2024

[15.0.0] - 2026-04-12

Changed

  • Breaking change: Dropped support for Python3.8

Fixed

The Faster Startup Release

No new features in this release, but there should be improved startup time for Rich apps, and potentially improved runtime if you have a lot of links.

[14.3.4] - 2026-04-11

Changed

Changelog

Sourced from rich's changelog.

[15.0.0] - 2026-04-12

Changed

  • Breaking change: Dropped support for Python3.8

Fixed

[14.3.4] - 2026-04-11

Changed

Commits

Updates datasets from 4.8.4 to 5.0.1

Release notes

Sourced from datasets's releases.

5.0.1

Bug fixes

Docs

New Contributors

... (truncated)

Commits
  • 921c2a7 release: 5.0.1 (#8370)
  • c6fc5cd Preserve nullable integer columns in to_json/to_csv/to_sql (#8366)
  • 6747b87 Fix DatasetDict.push_to_hub leaving removed splits in the dataset card (#8367)
  • b305031 fix buckets on windows (#8369)
  • 030a3e5 Decode Json() columns in Dataset.to_pandas() (#8344)
  • 0f207a0 Rebatch arrow source before formatting in IterableDataset.filter to fix resum...
  • adad35d Keep integers on the python read path for fixed-shape ArrayXD columns with nu...
  • 8966746 Fix CSV loader dropping on_bad_lines/encoding_errors on pandas 2.0-2.2 (#8358)
  • b8e861a Fix bucket dataset card handling and push metadata accounting (#8354)
  • 521a590 Keep flat numeric columns with nulls numeric in numpy format (#8352)
  • Additional commits viewable in compare view

Updates openai from 2.30.0 to 2.53.0

Release notes

Sourced from openai's releases.

v2.53.0

2.53.0 (2026-08-03)

Features

  • api: Add gpt-5.5 and tool name/namespace to Responses types (#3569) (dd1202d)

Bug Fixes

  • ci: avoid NumPy source builds and duplicate HTTPX coverage (#3573) (b58332f)

v2.52.1

2.52.1 (2026-07-31)

Full Changelog: v2.52.0...v2.52.1

Chores

  • ci: pin setup-uv v5 to its underlying commit (#3560) (cbdc98b)

v2.52.0

2.52.0 (2026-07-31)

Full Changelog: v2.51.0...v2.52.0

Features

  • api: content provenance checks (1d6c118)

Bug Fixes

  • client: honor Retry-After delays up to two minutes (#3555) (7fa7946)

Documentation

v2.51.0

2.51.0 (2026-07-30)

Full Changelog: v2.50.0...v2.51.0

Features

... (truncated)

Changelog

Sourced from openai's changelog.

2.53.0 (2026-08-03)

Features

  • api: Add gpt-5.5 and tool name/namespace to Responses types (#3569) (dd1202d)

Bug Fixes

  • ci: avoid NumPy source builds and duplicate HTTPX coverage (#3573) (b58332f)

2.52.1 (2026-07-31)

Full Changelog: v2.52.0...v2.52.1

Chores

  • ci: pin setup-uv v5 to its underlying commit (#3560) (cbdc98b)

2.52.0 (2026-07-31)

Full Changelog: v2.51.0...v2.52.0

Features

  • api: content provenance checks (1d6c118)

Bug Fixes

  • client: honor Retry-After delays up to two minutes (#3555) (7fa7946)

Documentation

2.51.0 (2026-07-30)

Full Changelog: v2.50.0...v2.51.0

Features

Bug Fixes

  • api: add fast tier to helper methods (6064126)

... (truncated)

Commits

Updates inspect-ai from 0.3.145 to 0.3.252

Changelog

Sourced from inspect-ai's changelog.

0.3.252 (04 August 2026)

  • Grok: Unknown (predeployment) model names are now treated as the latest Grok model for context window (compaction) and capability detection.
  • Analysis: string values for bool-typed columns now coerce via YAML, so "false"/"0"/"no"/"off" parse to False instead of every non-empty string becoming True.
  • Sandbox: Large sandbox-tool responses are transferred intact instead of corrupting JSON-RPC frames when they exceed the sandbox exec output limit.
  • Sandbox: Service method errors no longer include the host-side traceback in the response delivered into the sandbox; the traceback is logged host-side instead. (#4673)
  • Agent Bridge: Fix for message_limit/token_limit/cost_limit errors not being properly raised when running in a sandbox.
  • Approval: Model inference performed inside a tool approver no longer counts against active token and turn limits.
  • Bugfix: Reading eval logs with field exclusion (e.g. header-only reads) no longer crashes under a trio event loop; the pure-Python ijson backend is now selected when the C backend's asyncio-only async parser is unavailable. (#4589)
  • Logging: Reading .eval logs with exclude_fields no longer fails with "integer overflow" when a sample contains a JSON integer larger than 2⁶³−1.
  • Control Channel: inspect ctl sample list/show now report a running sample's in-flight activity (generating 7:12, bash 0:41, retrying in 0:45), and sample events renders pending events, so long model calls and retry backoffs no longer read as silent idle.
  • Retry: Samples reused from a prior attempt no longer stay resident in memory awaiting a flush, and are written to the new attempt's log (readable by inspect ctl and viewers) as soon as the reuse sweep completes.
  • Control Channel: Paginating or polling a finished sample's events or messages no longer re-parses the whole sample per request (resolved terminal sources are briefly cached).
  • Control Channel: A cancel arriving just after a sample errored with retries remaining now resolves the sample as cancelled, instead of counting it errored without logging it.
  • Control Channel: The control server now rejects socket connections from other users (SO_PEERCRED / LOCAL_PEERCRED peer-UID check), as defence-in-depth alongside the socket file permissions.
  • Control Channel: inspect ctl sample events --tail (including the default first page) now counts events matching the --typemeridianlabs-ai/inspect_ai#162
  • Control Channel: Where the CLI already shows a stall — a long-idle running sample in inspect ctl sample list, or a busy-skipped process — it now points at inspect ctl process anomalies as the escalation.
  • Control Channel: inspect eval now prints a one-line pointer to inspect ctl monitoring at launch, eval/ctl help text cross-links the two surfaces, and inspect ctl task list flags errored samples.
  • Registry: @task, @solver, and @agent decorators now retain their return annotation on Python 3.14 even when re-wrapped by user decorators, so registry_create() and signature introspection keep working. (#4554)
  • Registry: registry_create() can now create @scorer and @tool objects whose decorated function omits its return annotation (previously this silently failed). (#4554)
  • Bugfix: Async APIs (eval_async, recover_eval_log_async, recoverable-log discovery, and accessing EvalLog.samples from their results) no longer raise "read_eval_log cannot be called from a trio async context" under a trio event loop.
  • Bugfix: Filestore sample buffer directories are now cleaned up after evals run under a trio event loop (cleanup previously failed with a warning).
  • Bugfix: Eval logs containing a sample_init event with a null state can now be re-read (the null was previously dropped on write and failed validation on read).
  • Added list_eval_logs_async(), an async equivalent of list_eval_logs() that is safe to call from any async context (including trio); calling list_eval_logs() with a filter under trio now raises an error directing to it.
  • Bugfix: The google web search provider now returns results in search rank order rather than page-fetch completion order.
  • ACP: The transport now exposes has_client and wait_for_client(), letting agents check for or wait until a fully bound ACP client is attached.
  • Bugfix: EvalResults.completed_samples now counts samples that completed without error rather than scored samples, so score-on-error samples no longer inflate it. (#4602)
  • Bugfix: Solvers, tasks, scorers, and metrics that declare **kwargs now survive replay from logs (e.g. eval_retry, inspect score), including keyword arguments named name. (#4375)
  • Bugfix: Registry objects (@solver, @agent, @tool, …) that declare **kwargs no longer crash at registration when a keyword argument is named type, o, or info, and approval-policy params named type/name no longer collide on creation. (#4504)
  • Bugfix: Safe JSON serialization now preserves field exclusions when escaping invalid Unicode surrogates.
  • Analysis: frontier() no longer errors when a model release date group has only missing (NA) headline scores; those rows are now skipped instead of crashing idxmax().
  • Models: bounded count_tokens() concurrency (adaptive, like generate()) so large token-count fan-outs no longer overwhelm the provider connection pool.
  • Model: generate() now retries the anyio transport-close race (AttributeError: 'NoneType' object has no attribute 'call_soon' during response cleanup) instead of failing the sample.
  • Inspect View: Improved log parsing performance; added real-payload benchmarks. (#384)
  • Inspect View: Fixed timeline discarding a solver span containing a single agent span child when it also contains other displayed events. (#443)
  • Inspect View: Timeline now requires a tool-calling loop for utility-agent classification and surfaces the hidden event count. (#425)
  • Inspect View: Added connection limit history display to the Stats tab. (#447)
  • Inspect View: Fixed viewer to show the Action tab first for annotated browser actions. (#429)
  • Inspect View: Downloads of large local log files no longer fail, and the view server stays responsive while reading or listing large local logs.
  • MCP: Support the mcp 2.0 package (in addition to mcp 1.x), whose breaking API redesign previously made all mcp_server_*()meridianlabs-ai/inspect_ai#170
  • MCP: mcp_server_http() no longer ignores its name argument (the server was always named after the URL).
  • OpenAI: Web search find/find_in_page actions missing a url or pattern now degrade to a search action instead of crashing the sample with a validation error. (#4119)
  • Performance: Message preparation for providers that extract tool-result media into user messages now scales linearly with conversation length rather than quadratically.
  • Smaller downloads: the wheel no longer includes the accidentally-bundled log viewer TypeScript source, and the sdist no longer includes tests, docs, or lockfiles.
  • Bugfix: OpenAI: A tool call with an oversized arguments string no longer poisons the conversation, which previously failed every subsequent request with a 400 "string too long" error. (#4682)
  • Control Channel: New inspect ctl model pause|resume commands pause one model's dispatch (including not-yet-started eval-set tasks) while the rest of the run continues.
  • Control Channel: inspect ctl task list now suggests only the resume commands for latches actually holding a paused task, instead of always listing all three.
  • Control Channel: Added inspect ctl sample requeue to re-run one errored/cancelled sample inside the still-running eval.
  • Control Channel: Samples resolved via --action error now log the error message Sample errored: interrupted by operator and report status error (previously the raw cancellation message, misreported as cancelled).
  • Bugfix: text_editor() paths containing a null byte now return a tool error to the model instead of crashing the tool. (#4659)

... (truncated)

Commits
  • d105c61 update chanelog for release
  • 4c0a2f3 Merge pull request #4737 from UKGovernmentBEIS/feature/approver-limits
  • 0e85fcb approval: model inference performed inside a tool approver no longer counts a...
  • 0ec4ac9 Merge pull request #4736 from UKGovernmentBEIS/feature/grok-unreleased
  • 6441c51 grok: unknown model names are now treated as the latest grok model for contex...
  • a745c56 Fall back to json.loads on ijson integer overflow in exclude_fields reads (#4...
  • a96e10a Adapt to agent-client-protocol 0.12 / mypy 2.x; raise minimum versions (#4729)
  • c8480c7 fix(docker): account for start_period and fractional durations in healthcheck...
  • 9c352f7 fix(_util): support standalone signed Unicode fractions in str_to_float (#471...
  • aa57129 fix(analysis): handle empty DataFrames and missing model column in model_info...
  • Additional commits viewable in compare view

Updates inspect-evals from 0.3.103 to 0.16.0

Release notes

Sourced from inspect-evals's releases.

v0.16.0

Existing Evals

  • KernelBench (v5-B): Scorer now distinguishes infrastructure failures from verdicts on the generated kernel.

  • OSWorld: Scorer failure messages improved (evaluator-crash raises now include the container's error and traceback; unparseable or incomplete evaluator output raises with a descriptive message instead of RuntimeError/KeyError). Scoring semantics are unchanged: evaluator crashes still error the sample, matching upstream OSWorld, which excludes evaluator exceptions from its reported average.

  • CyberGym (v3-A): Cap oversized program output in the executor and parse the executor response defensively in the scorer, so a proof-of-concept that prints more than the sandbox stdout limit no longer truncates the response to invalid JSON and errors the sample. An unparseable executor response now raises rather than being counted as not reproduced, since it is an executor-side failure, not the model's (#1644).

  • SimpleQA (v5-C): Grader-instrument failures now yield Score.unscored() (excluded from metrics) instead of raising RuntimeError, with metadata["reason"] identifying the failure mode.

  • VQA-RAD (v3-B): Same grader-failure handling via the shared schema_tool_graded_scorer helper.

  • CTI-REALM: the MITRE ATT&CK bundles were fetched with a bare requests.get, so a transient failure ended the run and nothing verified what came back. They now go through download_and_verify, which retries with backoff and checks a pinned checksum (#1943).

Other

  • schema_tool_graded_scorer: Route grader-instrument failures (refusal, no tool call, schema mismatch, invalid grade) to Score.unscored() instead of raising RuntimeError. Add ScoreReason type and GRADER_* constants for structured failure metadata.

  • Add gdown to the dev dependency group (for DownloadError and 6.x retry semantics) so the Google Drive download retry tests run in CI.

  • Add a gdown extra pinning gdown>=6 (needed for the DownloadError retry path in gdown_and_verify) and reference it from the scicode, sciknoweval, and AbstentionBench dependency declarations. Add a new usaco extra so USACO's Google Drive download dependency is installable via pip install inspect-evals[usaco].

v0.15.0

Existing Evals

  • SciKnowEval (v3-A): Fix relation-extraction scoring — metrics_by_task grouped scores under a domain-prefixed key (e.g. biology.drug_drug_relation_extraction) but tested it against the bare-name RE_TASKS list, so the check never matched and all three relation-extraction subtasks fell through to accuracy() over a placeholder Score(0), scoring 0.0 even for correct answers. The check now strips the domain prefix so re_f1_score runs as intended. (@​Le0nX)

  • AbstentionBench (v3-A): Fix abstention scoring. (1) Predictions compared the raw score text against "1.0", but the grader's verdict is the string "Yes"/"No", so predictions were always non-abstention and recall/F1 were 0 for every model; predictions now convert the verdict with value_to_float ("yes" → 1.0). (2) The judge grade_pattern=r"(?i)(yes|no)" bound to the first yes/no and had no word boundaries (matching no inside know/cannot/not/unknown); it now binds to the grader's final Yes/No verdict with word boundaries (r"(?is).*\b(yes|no)\b"). (@​Le0nX)

  • StereoSet: Fix scorer metadata (gold_labels/bias_type/target) being dropped on the no-answer and out-of-range return paths; both scorers now attach sample metadata on every return path, matching the success path. No score values change. (@​WatchTree-19)

  • b3: Backbone Breaker Benchmark (v3-A): Fix profanity_metric raising ZeroDivisionError on a non-empty but whitespace-only model response; such responses are now scored 0.0 instead of erroring the sample. (@​WatchTree-19)

Other

  • gdown_and_verify: retry on gdown's own DownloadError. The retry only listed requests.exceptions.RequestException, but gdown raises DownloadError/FileURLRetrievalError, so a rate-limited or interstitial Google Drive response was never retried. Affects usaco, scicode, sciknoweval and abstention_bench. (@​mkzung)

v0.14.4

Existing Evals

  • AgentHarm: Harmfulness Potential in AI Agents (v2-B): Fix realtime log serialization when AgentHarm scorers use a semantic judge model.

  • XSTest (v3-A): Fix the grader grade-pattern to bind to the model grader's final GRADE: verdict instead of the first GRADE: token in its step-by-step reasoning. The scorer previously passed a custom leftmost-matching pattern; it now relies on Inspect's DEFAULT_GRADE_PATTERN, which greedily binds to the final grade. (@​Le0nX)

  • GDM Dangerous Capabilities: Self-reasoning (v4-A): Move the system prompt and required tool selection into setup so they remain applied when callers override the solver.

  • AssistantBench: Can Web Agents Solve Realistic and Time-Consuming Tasks? (v4-A): Move system prompts into setup for the closed-book and web-search tasks so they remain applied when callers override the solver.

... (truncated)

Changelog

Sourced from inspect-evals's changelog.

[0.16.0] — 2026-07-23

Existing Evals

  • KernelBench (v5-B): Scorer now distinguishes infrastructure failures from verdicts on the generated kernel.

  • OSWorld: Scorer failure messages improved (evaluator-crash raises now include the container's error and traceback; unparseable or incomplete evaluator output raises with a descriptive message instead of RuntimeError/KeyError). Scoring semantics are unchanged: evaluator crashes still error the sample, matching upstream OSWorld, which excludes evaluator exceptions from its reported average.

  • CyberGym (v3-A): Cap oversized program output in the executor and parse the executor response defensively in the scorer, so a proof-of-concept that prints more than the sandbox stdout limit no longer truncates the response to invalid JSON and errors the sample. An unparseable executor response now raises rather than being counted as not reproduced, since it is an executor-side failure, not the model's (#1644).

  • SimpleQA (v5-C): Grader-instrument failures now yield Score.unscored() (excluded from metrics) instead of raising RuntimeError, with metadata["reason"] identifying the failure mode.

  • VQA-RAD (v3-B): Same grader-failure handling via the shared schema_tool_graded_scorer helper.

  • CTI-REALM: the MITRE ATT&CK bundles were fetched with a bare requests.get, so a transient failure ended the run and nothing verified what came back. They now go through download_and_verify, which retries with backoff and checks a pinned checksum (Description has been truncated

Updates the requirements on [aiohttp](https://github.com/aio-libs/aiohttp), [click](https://github.com/pallets/click), [rich](https://github.com/Textualize/rich), [datasets](https://github.com/huggingface/datasets), [openai](https://github.com/openai/openai-python), [inspect-ai](https://github.com/UKGovernmentBEIS/inspect_ai), [inspect-evals](https://github.com/UKGovernmentBEIS/inspect_evals), [playwright](https://github.com/microsoft/playwright-python), [pytest](https://github.com/pytest-dev/pytest), [pytest-asyncio](https://github.com/pytest-dev/pytest-asyncio), [pytest-playwright](https://github.com/microsoft/playwright-pytest), [ruff](https://github.com/astral-sh/ruff) and [uv-build](https://github.com/astral-sh/uv) to permit the latest version.

Updates `aiohttp` from 3.13.5 to 3.14.3
- [Changelog](https://github.com/aio-libs/aiohttp/blob/master/CHANGES.rst)
- [Commits](aio-libs/aiohttp@v3.13.5...v3.14.3)

Updates `click` from 8.3.1 to 8.4.2
- [Release notes](https://github.com/pallets/click/releases)
- [Changelog](https://github.com/pallets/click/blob/main/CHANGES.md)
- [Commits](pallets/click@8.3.1...8.4.2)

Updates `rich` from 14.3.3 to 15.0.0
- [Release notes](https://github.com/Textualize/rich/releases)
- [Changelog](https://github.com/Textualize/rich/blob/main/CHANGELOG.md)
- [Commits](Textualize/rich@v14.3.3...v15.0.0)

Updates `datasets` from 4.8.4 to 5.0.1
- [Release notes](https://github.com/huggingface/datasets/releases)
- [Commits](huggingface/datasets@4.8.4...5.0.1)

Updates `openai` from 2.30.0 to 2.53.0
- [Release notes](https://github.com/openai/openai-python/releases)
- [Changelog](https://github.com/openai/openai-python/blob/main/CHANGELOG.md)
- [Commits](openai/openai-python@v2.30.0...v2.53.0)

Updates `inspect-ai` from 0.3.145 to 0.3.252
- [Changelog](https://github.com/UKGovernmentBEIS/inspect_ai/blob/main/CHANGELOG.md)
- [Commits](UKGovernmentBEIS/inspect_ai@0.3.145...0.3.252)

Updates `inspect-evals` from 0.3.103 to 0.16.0
- [Release notes](https://github.com/UKGovernmentBEIS/inspect_evals/releases)
- [Changelog](https://github.com/UKGovernmentBEIS/inspect_evals/blob/main/CHANGELOG.md)
- [Commits](UKGovernmentBEIS/inspect_evals@0.3.103...v0.16.0)

Updates `playwright` from 1.58.0 to 1.62.0
- [Release notes](https://github.com/microsoft/playwright-python/releases)
- [Commits](microsoft/playwright-python@v1.58.0...v1.62.0)

Updates `pytest` from 9.0.2 to 9.1.1
- [Release notes](https://github.com/pytest-dev/pytest/releases)
- [Changelog](https://github.com/pytest-dev/pytest/blob/main/CHANGELOG.rst)
- [Commits](pytest-dev/pytest@9.0.2...9.1.1)

Updates `pytest-asyncio` from 1.3.0 to 1.4.0
- [Release notes](https://github.com/pytest-dev/pytest-asyncio/releases)
- [Commits](pytest-dev/pytest-asyncio@v1.3.0...v1.4.0)

Updates `pytest-playwright` from 0.7.2 to 0.8.0
- [Release notes](https://github.com/microsoft/playwright-pytest/releases)
- [Commits](microsoft/playwright-pytest@v0.7.2...v0.8.0)

Updates `ruff` from 0.15.8 to 0.16.2
- [Release notes](https://github.com/astral-sh/ruff/releases)
- [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md)
- [Commits](astral-sh/ruff@0.15.8...0.16.2)

Updates `uv-build` to 0.12.3
- [Release notes](https://github.com/astral-sh/uv/releases)
- [Changelog](https://github.com/astral-sh/uv/blob/main/CHANGELOG.md)
- [Commits](astral-sh/uv@0.8.17...0.12.3)

---
updated-dependencies:
- dependency-name: aiohttp
  dependency-version: 3.14.3
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python
- dependency-name: click
  dependency-version: 8.4.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python
- dependency-name: rich
  dependency-version: 15.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: python
- dependency-name: datasets
  dependency-version: 5.0.1
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: python
- dependency-name: openai
  dependency-version: 2.53.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python
- dependency-name: inspect-ai
  dependency-version: 0.3.252
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python
- dependency-name: inspect-evals
  dependency-version: 0.16.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: python
- dependency-name: playwright
  dependency-version: 1.62.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: python
- dependency-name: pytest
  dependency-version: 9.1.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: python
- dependency-name: pytest-asyncio
  dependency-version: 1.4.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: python
- dependency-name: pytest-playwright
  dependency-version: 0.8.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: python
- dependency-name: ruff
  dependency-version: 0.16.2
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: python
- dependency-name: uv-build
  dependency-version: 0.12.3
  dependency-type: direct:development
  dependency-group: python
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels Aug 15, 2026
@dependabot @github

dependabot Bot commented on behalf of github Aug 22, 2026

Copy link
Copy Markdown
Contributor Author

Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting @dependabot recreate.

1 similar comment
@dependabot @github

dependabot Bot commented on behalf of github Aug 29, 2026

Copy link
Copy Markdown
Contributor Author

Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting @dependabot recreate.

@MattFisher
MattFisher merged commit afbc94c into main Sep 14, 2026
1 check passed
@dependabot
dependabot Bot deleted the dependabot/uv/python-6913b7a1a3 branch September 14, 2026 00:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants