Skip to content

deps: bump the dependencies group across 1 directory with 5 updates - #139

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/dependencies-68a5f6bd43
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/dependencies-68a5f6bd43

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown
Contributor

Bumps the dependencies group with 5 updates in the / directory:

Package From To
mcp 2.1.1 2.2.0
qdrant-client 1.19.0 1.19.1
tree-sitter-language-pack 1.16.2 1.20.0
fastembed 0.8.0 0.8.1
cachetools 7.1.8 7.2.0

Updates mcp from 2.1.1 to 2.2.0

Release notes

Sourced from mcp's releases.

v2.2.0

pip install -U mcp. Docs: https://py.sdk.modelcontextprotocol.io/

A few defaults changed in this release. If you run a server or client on 2.x, skim these first:

Behaviour changes

HTTP client redirects are only followed within the endpoint's origin (#3397)

  • Client("https://..."), streamable_http_client and sse_client follow a redirect only if it stays on the same scheme, host and port (or upgrades http to https on the same host).
  • A redirect anywhere else is not followed: the call fails with MCPError and the session stays usable (an SSE connect fails with httpx2.HTTPStatusError). If that other URL is the server you meant, use it as the endpoint URL.
  • The follow_redirects setting on an httpx2.AsyncClient you pass in is no longer used for MCP requests, so you don't need it for the trailing-slash redirect any more.
  • The OAuth providers apply the same rule to their own requests.

Idle Streamable HTTP sessions now expire (legacy <=2025-11-25 spec( (#3395)

  • A stateful session with nothing in flight for 30 minutes is closed. The client's next request gets a 404 and it has to initialize again.
  • Clients that keep the GET stream open (the SDK's Client does) are not affected. Neither are stateless servers or 2026-07-28 connections.
  • A server also holds at most 10 000 sessions at once; beyond that, new sessions get a 503.
  • To turn either off: mcp.run(transport="streamable-http", session_idle_timeout=None, max_sessions=None) (also on streamable_http_app() and run_streamable_http_async()).

The OAuth client checks the authorization server's issuer on the legacy path too (#3398)

  • For servers without protected resource metadata, authorization server metadata whose issuer isn't the server's own origin is now rejected with OAuthFlowError: Authorization server metadata issuer mismatch. The protected-resource-metadata path has done this since 2.0.
  • A 403 that isn't an insufficient_scope challenge is returned to the caller instead of retried.
  • If protected resource metadata can't be fetched because of a 5xx/429, the flow now stops instead of falling back to the legacy endpoints.

Two new MCPDeprecationWarnings (#3435, #3447)

  • ClientCredentialsOAuthProvider / PrivateKeyJWTOAuthProvider without issuer=. Pass your authorization server's issuer URL; 3.0 will require it.
  • AuthSettings with resource_server_url set but validate_token_resource unset. Set it to True or False; 3.0 defaults it to True.
  • Both keep working as before in 2.x; this mostly matters if your tests turn warnings into errors.

New

  • AuthSettings.validate_token_resource: only accept tokens your TokenVerifier reports as issued for this server (#3447).
  • issuer= on ClientCredentialsOAuthProvider and PrivateKeyJWTOAuthProvider (#3398).
  • session_idle_timeout= and max_sessions= on the Streamable HTTP server entry points (#3395).

Fixes

  • A client DELETE frees its session immediately, and a refused opening request no longer leaves a session behind (#2455, #3228, #3300).
  • $refs in a tool's outputSchema resolve within that schema only; an unresolvable one surfaces as RuntimeError: Invalid schema for tool ... (#3394).

Known gaps

The tasks extension (SEP-2663), DPoP (SEP-1932) and the jwt-bearer grant are not implemented yet; https://github.com/modelcontextprotocol/python-sdk/blob/main/ROADMAP.md tracks them.

What's Changed

... (truncated)

Commits
  • 9972c21 Replace RootModel wrappers with type aliases and TypeAdapter validation (#3470)
  • fd66270 docs: refresh translations, and translate pages in parallel (#3458)
  • 08a3bc8 docs: ask for AI disclosure on comments too (#3459)
  • 7bb486a docs: stop presenting the in-memory client as the way to connect (#3443)
  • 0c91368 Add AuthSettings.validate_token_resource to check a bearer token's resource (...
  • 9771e6b Keep following a relative redirect when the endpoint URL carries userinfo (#3...
  • a925e55 Bump the locked versions of eight dev and test dependencies (#3449)
  • e8b9486 Bump pymdown-extensions from 11.0 to 11.0.1 (#3285)
  • c6762e8 Follow redirects only within the MCP endpoint's origin (#3397)
  • 5fd3abc Skip automatic docs previews for fork PRs and drop the setup-uv retry steps (...
  • Additional commits viewable in compare view

Updates qdrant-client from 1.19.0 to 1.19.1

Release notes

Sourced from qdrant-client's releases.

v1.19.1

Change Log

Features 🌊

  • #1419 - token-aware MatchAny in local mode, matching the server by @​joein

Fixes 🧑‍🔧

... (truncated)

Commits
  • cf747f4 bump version to v1.19.1
  • f13a440 tests: update qdrant latest to v1.19.1
  • 24b2a27 fix: add version guards for the tests which require qdrant 1.19.2 (#1443)
  • 6859fef tests: disable text filter test before 1.19.2 (#1441)
  • b5a6bb2 fix: fix async client timeout (#1440)
  • e0dcd93 fix(local): isolate payload values across wildcard targets (#1438)
  • d5ef5cc fix(local): update IDF statistics on deletion (#1427)
  • 51e5192 docs: align fix branch instructions with PR template (#1436)
  • d6f79fd fix(local): isolate sparse vectors at storage boundaries (#1424)
  • 27a5563 fix(local): apply MMR offset to the re-ranked output, not the candidates (#1420)
  • Additional commits viewable in compare view

Updates tree-sitter-language-pack from 1.16.2 to 1.20.0

Release notes

Sourced from tree-sitter-language-pack's releases.

Release v1.20.0

What's Changed

Full Changelog: xberg-io/tree-sitter-language-pack@v1.16.0...v1.20.0

Release v1.19.1

What's Changed

Full Changelog: xberg-io/tree-sitter-language-pack@v1.16.0...v1.19.1

Release v1.19.0

Changed

  • Upgraded the tree-sitter runtime to 0.27, moving tree-sitter-language to 0.1.8 in the same step. The two pins are not independent: 0.27 requires tree-sitter-language ^0.1.8, and 0.1.8 relocates the 0.26 WASM shims under wasm/unsupported/ so they no longer compile against the older runtime. The grammar ABI is unchanged -- both 0.26 and 0.27 are TREE_SITTER_LANGUAGE_VERSION 15 with a minimum compatible version of 13 -- so every bundled grammar loads exactly as before and no regeneration is implied.
  • Consumers that also depend on tree-sitter directly must move to 0.27 in the same step. The tree-sitter crate declares links = "tree-sitter", and Cargo permits only one package per links value in a dependency graph, so pairing this release with a 0.26 pin fails to resolve rather than failing to compile. Nothing this crate exports changed: the requirement is a dependency floor, not a break in its own API.
  • Grammar scanners now compile with NDEBUG on wasm32. 0.27's WASM libc is a documented subset that excludes assert, so a scanner keeping its assertions emitted an unresolved __assert_fail. That became an env module import rather than a link error, and the package then failed to load at runtime with Cannot find module 'env'. Native builds keep their assertions.
  • Dropped this crate's own WASM libc shims (memchr, strcmp, iswalnum and friends) now that 0.27 defines them. Keeping both made the two definitions collide at link time, which broke the WASM package under the split-codegen-unit settings the release build uses.
  • Replaced the 0.26 WASM integration, which used a separate non-thread-safe allocator and an incomplete libc. 0.27 supplies its own WASM libc and forwards C allocation to the Rust application's global allocator.

Fixed

  • Swift binaries again link a single tree-sitter C runtime. SwiftPM builds tree-sitter 0.25.10 for SwiftTreeSitter as loose object files, while this package's Rust staticlib carries the 0.27 runtime in one archive member. Archive members load only to resolve an undefined symbol, and

... (truncated)

Changelog

Sourced from tree-sitter-language-pack's changelog.

[1.20.0] - 2026-09-14

Changed

  • BREAKING (Java): enum constants are now UPPER_SNAKE_CASE. StructureKind.Function becomes StructureKind.FUNCTION, and likewise across CommentKind, DataNodeKind, DiagnosticSeverity, DocstringFormat, ExportKind and SymbolKind. The serialized wire values are unchanged, so no data migration is needed and persisted JSON stays readable; only Java source naming the old identifiers has to be updated.
  • BREAKING (Swift): process() returns typed value types instead of opaque Rust handles. ProcessResult, StructureItem, DataNode and fifteen other types are now Codable structs with stored properties rather than typealiases to swift-bridge handles. Field access moves from method to property syntax (result.structure, not result.structure()), collections are real Swift arrays, and StructureKind / SymbolKind / DocstringFormat are Swift enums with associated values rather than strings. Values now cross the bridge as JSON and are decoded in Swift, so process() is throws on malformed input rather than returning a handle that fails on first access.
  • Regenerate all bindings, fixtures, documentation and release workflows with Alef 0.87.1 (was 0.85.15), lifting the hold recorded in 1.19.1. 0.86.1 promoted the Swift binding to value types but left the Swift e2e suite it generates calling the old method syntax; 0.87.0 fixed that but emitted enums whose Codable conformance could not read serde's wire format. Both are resolved in 0.87.1.

Added

  • Swift structure-extraction test coverage. Every test in the Swift package suite previously read only scalar fields off process(), leaving the structure path unexercised — all seventeen passed against an Alef 0.87.0 build whose process() threw on any source containing structure. The new test asserts the decoded StructureKind cases and item names, which is what exercises the element decoder; nim cannot cover this (its grammar uses none of the node kind names structure_kind_at() matches) so it goes through mojo, already in the package's statically compiled language set.

Fixed

  • Swift enums with associated values decode serde's externally tagged wire format. Unit variants serialize as a bare string ("Function") and payload variants as a single-keyed object ({"Other": "macro"}); the generated conformance previously fell through to Swift's synthesized Codable, which expects {"function": {}} and matched neither form. (Alef 0.87.1)
  • Node and WebAssembly e2e suites read internally tagged FormatMetadata as the flattened shape serde actually emits, with the sibling-field form asserted directly so a regression to the nested form fails loudly instead of silently degrading to the variant name. (Alef 0.87.1)
  • The Go binding pairs native error messages with their sentinels, so callers can match with errors.Is while still reading the detail the native layer produced. (Alef 0.87.1)

[1.19.1] - 2026-09-13

Changed

  • Alef stays pinned at 0.85.15. 0.86.1 rewrites the Swift binding to real value types -- DataNode, ProcessResult and StructureItem become Codable structs with typed properties instead of typealiases to opaque Rust handles -- but does not update the Swift e2e suite it generates alongside them, which still calls result.language() and result.structure() on

... (truncated)

Commits
  • f4b24ec chore(swift): update Package.swift with checksum for v1.20.0
  • 5472338 chore(release): prepare 1.20.0 with alef 0.87.1
  • 3b85261 test(swift): cover structure extraction via mojo
  • 312106b fix(release): stage alef.toml in the zig hash refresh
  • e12c872 chore(zig): refresh test_apps package hashes for v1.19.1
  • 481753f fix(swift): include stddef.h for NULL in the RustBridgeC shim
  • f5f9f78 fix(swift): re-stamp the RustBridge files alef owns
  • e57a51f fix(swift): restore the alef stamps the swift-bridge build strips
  • 1605195 fix(alef): hold the generator at 0.85.15 for 1.19.1
  • f070230 chore(release): 1.19.1
  • Additional commits viewable in compare view

Updates fastembed from 0.8.0 to 0.8.1

Release notes

Sourced from fastembed's releases.

v0.8.1

Changelog

Features 🏎️

  • #592 - add google/embeddinggemma-300m by @​joein
  • #651 - add nomic-ai/nomic-embed-vision-v1.5 and nomic-ai/nomic-embed-vision-v1.5-Q, which share an embedding space with nomic-ai/nomic-embed-text-v1.5 for text-to-image search by @​Dylancouzon
  • #652 - add inference-free SPLADE opensearch-project/opensearch-neural-sparse-encoding-doc-v3-gte, which runs the model on documents only and encodes queries without inference by @​joein
  • #678, #680 - add Qwen/Qwen3-Embedding-0.6B and Qwen/Qwen3-Embedding-0.6B-Q (the quantized model requires onnxruntime>=1.23), plus PoolingType.LAST_TOKEN for custom models by @​joein
  • #683 - add google/siglip2-base-patch16-224 to TextEmbedding and ImageEmbedding by @​joein
  • #692 - add Model2Vec static models minishlab/potion-base-8M, minishlab/potion-retrieval-32M, and minishlab/potion-multilingual-128M by @​stephantul @​Dylancouzon

Fixes 🔧

  • #593, #707 - use canonical Hugging Face repo IDs for BAAI/bge-base-en-v1.5 and BAAI/bge-small-en-v1.5 to avoid a redirect that broke downloads behind some proxies (see Upgrade Notes) by @​Harnas @​rastagan-git @​joein
  • #623 - run the fp32 version of jinaai/jina-embeddings-v2-base-de instead of fp16, which fails on onnxruntime>=1.23 (the download grows from 0.32 GB to 0.64 GB) by @​joein
  • #624 - check that model files exist before using a cached model, so several variants of one repo (for example fp32 and quantized) can share a cache dir by @​joein
  • #629 - add a timeout to downloads from Google Cloud Storage (GCS), so a stalled connection fails instead of hanging indefinitely by @​joein
  • #645 - fix a KeyError when loading a custom text model with different casing than it was registered with by @​CODING-DARSH @​joein
  • #647 - fix a path traversal vulnerability in model archive extraction that could write files outside the cache dir by @​he-yufeng @​joein
  • #682 - fix normalization of batched (N, C, H, W) image arrays, which ran along the wrong axis by @​serhiizghama @​joein
  • #693 - make config.json and special_tokens_map.json optional when loading a tokenizer by @​libaojiang @​joein
  • #697 - fix the Resize transform swapping height and width for non-square sizes by @​Ramnath0521 @​joein
  • #714 - fix custom text embedding and cross-encoder models (add_custom_model) failing when parallel is set by @​joein @​S0rryHorizon
  • #716, #717 - always pad a batch to its longest sequence, fixing a ValueError on mixed-length batches for models whose tokenizer ships a fixed padding length, such as thenlper/gte-base (regression in 0.8.0) by @​joein @​mohmedmm
  • #718 - stage each GCS download in its own temporary dir, so a failed or concurrent download can't delete files from other downloads by @​joein

Upgrade Notes

  • BAAI/bge-small-en-v1.5 (the default model) and BAAI/bge-base-en-v1.5 now resolve to Qdrant/bge-small-en-v1.5-onnx-Q and Qdrant/bge-base-en-v1.5-onnx-Q. The cache dir name follows the repo ID's casing, so on case-sensitive filesystems (typically Linux) the existing cache isn't reused and both models download again once. Offline setups (HF_HUB_OFFLINE=1 or local_files_only=True) need to refresh their cache before upgrading. You can delete the old models--qdrant--bge-*-onnx-q dirs afterwards.
  • jinaai/jina-embeddings-v2-base-de now loads onnx/model.onnx instead of onnx/model_fp16.onnx, so offline setups need to download it first.

Thanks to everyone who contributed to this release @​CODING-DARSH @​Dylancouzon @​Harnas @​he-yufeng @​libaojiang @​mohmedmm @​Ramnath0521 @​rastagan-git @​S0rryHorizon @​serhiizghama @​stephantul @​joein

Commits
  • 8de28b8 fix: fix mypy (#720)
  • a2bef98 bump version to v0.8.1
  • fb68e86 fix: stage GCS downloads instead of deleting the caller's cache dir (#718)
  • 0c63b6a fix: block unsafe tar extraction paths (#647)
  • cbe60bf fix(image): normalize batched (N, C, H, W) input along the channel axis (#682)
  • 40cca63 fix: make tokenizer metadata files optional (#693)
  • 5c4d9b0 fix: pass (width, height) to Pillow in the Resize transform (#697)
  • a3a798f fix: preserve pad_to_multiple_of when normalizing padding (#717)
  • bdf6816 fix: normalize tokenizer padding to batch-longest (#716)
  • 5dc53eb chore(deps-dev): bump the security-updates group across 1 directory with 2 up...
  • Additional commits viewable in compare view

Updates cachetools from 7.1.8 to 7.2.0

Changelog

Sourced from cachetools's changelog.

v7.2.0 (2026-09-16)

  • Deprecate use of cache=None to suppress caching with the @cached decorator.

  • Add support for Python 3.15.

  • Minor test improvements.

  • Minor documentation updates.

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the dependencies group with 5 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [mcp](https://github.com/modelcontextprotocol/python-sdk) | `2.1.1` | `2.2.0` |
| [qdrant-client](https://github.com/qdrant/qdrant-client) | `1.19.0` | `1.19.1` |
| [tree-sitter-language-pack](https://github.com/xberg-io/tree-sitter-language-pack) | `1.16.2` | `1.20.0` |
| [fastembed](https://github.com/qdrant/fastembed) | `0.8.0` | `0.8.1` |
| [cachetools](https://github.com/tkem/cachetools) | `7.1.8` | `7.2.0` |



Updates `mcp` from 2.1.1 to 2.2.0
- [Release notes](https://github.com/modelcontextprotocol/python-sdk/releases)
- [Changelog](https://github.com/modelcontextprotocol/python-sdk/blob/main/RELEASE.md)
- [Commits](modelcontextprotocol/python-sdk@v2.1.1...v2.2.0)

Updates `qdrant-client` from 1.19.0 to 1.19.1
- [Release notes](https://github.com/qdrant/qdrant-client/releases)
- [Commits](qdrant/qdrant-client@v1.19.0...v1.19.1)

Updates `tree-sitter-language-pack` from 1.16.2 to 1.20.0
- [Release notes](https://github.com/xberg-io/tree-sitter-language-pack/releases)
- [Changelog](https://github.com/xberg-io/tree-sitter-language-pack/blob/main/CHANGELOG.md)
- [Commits](xberg-io/tree-sitter-language-pack@v1.16.2...v1.20.0)

Updates `fastembed` from 0.8.0 to 0.8.1
- [Release notes](https://github.com/qdrant/fastembed/releases)
- [Changelog](https://github.com/qdrant/fastembed/blob/main/RELEASE.md)
- [Commits](qdrant/fastembed@v0.8.0...v0.8.1)

Updates `cachetools` from 7.1.8 to 7.2.0
- [Changelog](https://github.com/tkem/cachetools/blob/master/CHANGELOG.rst)
- [Commits](tkem/cachetools@v7.1.8...v7.2.0)

---
updated-dependencies:
- dependency-name: mcp
  dependency-version: 2.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dependencies
- dependency-name: qdrant-client
  dependency-version: 1.19.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: tree-sitter-language-pack
  dependency-version: 1.20.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dependencies
- dependency-name: fastembed
  dependency-version: 0.8.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: cachetools
  dependency-version: 7.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels Oct 1, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants