Skip to content

deps(python): Update uvicorn[standard] requirement from >=0.50.0 to >=0.51.0#9648

Merged
MarkusNeusinger merged 1 commit into
mainfrom
dependabot/uv/uvicorn-standard--gte-0.51.0
Jul 24, 2026
Merged

deps(python): Update uvicorn[standard] requirement from >=0.50.0 to >=0.51.0#9648
MarkusNeusinger merged 1 commit into
mainfrom
dependabot/uv/uvicorn-standard--gte-0.51.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 20, 2026

Copy link
Copy Markdown
Contributor

Updates the requirements on uvicorn[standard] to permit the latest version.

Release notes

Sourced from uvicorn[standard]'s releases.

Version 0.51.0

What's Changed

Full Changelog: Kludex/uvicorn@0.50.2...0.51.0

Changelog

Sourced from uvicorn[standard]'s changelog.

0.51.0 (July 8, 2026)

Added

  • Restart workers one at a time on SIGHUP, bringing each replacement up before retiring the old worker, so reloads no longer drop requests (#3025)

Removed

  • Remove colorama from the standard extra (#3027)

0.50.2 (July 6, 2026)

Fixed

  • Require websockets>=13.0, which the default websockets-sansio implementation needs (#3021)

0.50.1 (July 6, 2026)

Fixed

  • Split comma-separated Sec-WebSocket-Protocol values in the websockets-sansio implementation (#3019)

0.50.0 (July 4, 2026)

If you use WebSockets, note that --ws auto now picks the websockets-sansio implementation. You shouldn't need it, but you can pin --ws websockets to get the deprecated legacy one back.

Changed

  • Exit with the dedicated code 3 on any startup failure: app loading, socket bind and lifespan startup errors previously exited with a mix of 0, 1 and 3 (#3001)
  • Stop the multiprocess supervisor when a worker exits with code 3 instead of restarting it forever (#3001)
  • Default --ws auto to websockets-sansio when websockets is installed (#2985)
  • Skip the eager app import in the parent process with --reload or --workers, fixing a memory regression introduced in 0.47.0 (#3012)
  • Build a fresh asgi scope dict per request (#2977)
  • Cache the asgi scope sub-dict per connection (#2976)
  • Avoid copying single-frame WebSocket payloads in websockets-sansio (#2983)
  • Memoize trusted host checks in ProxyHeadersMiddleware (#2970)
  • Replace click.style with an internal ANSI style helper (#2981)

Deprecated

  • Deprecate the legacy websockets implementation; use websockets-sansio or wsproto instead (#2985)

0.49.0 (June 3, 2026)

Changed

  • Bump httptools minimum version to 0.8.0 (#2962)
  • Consume duplicate forwarding headers in ProxyHeadersMiddleware (reverses the 0.48.0 behavior of ignoring them) (#2971)

0.48.0 (May 24, 2026)

... (truncated)

Commits
  • e4d0b05 Version 0.51.0 (#3028)
  • 944e43d Remove colorama from the standard extra (#3027)
  • 2e78770 Restart workers with overlap on SIGHUP for near-zero-downtime reloads (#3025)
  • a1b570c Version 0.50.2 (#3022)
  • 83c7da7 Require websockets>=13.0 for the default sansio implementation (#3021)
  • b4d0116 Version 0.50.1 (#3020)
  • 2a9151d Split comma-separated Sec-WebSocket-Protocol values in the websockets-sansi...
  • 1bf3ab4 Cover the excluded-directory branch in FileFilter with a direct test (#3014)
  • 837b5f9 Deflake multiprocess, reload, and signal supervisor tests (#2975)
  • See full diff in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python labels Jul 20, 2026
@MarkusNeusinger
MarkusNeusinger enabled auto-merge (squash) July 23, 2026 21:59
@MarkusNeusinger
MarkusNeusinger disabled auto-merge July 23, 2026 22:10
@dependabot @github

dependabot Bot commented on behalf of github Jul 23, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@MarkusNeusinger
MarkusNeusinger enabled auto-merge (squash) July 23, 2026 22:11
MarkusNeusinger added a commit that referenced this pull request Jul 24, 2026
…illed (#9772)

## What happened

On **2026-07-24, ~16:05–16:26 UTC** GitHub's API browned out — HTTP 502
on the
workflow-dispatch endpoint, HTTP 504 on GraphQL, HTTP 429 on codeload.
Four `radar-basic`
PRs fell out of the pipeline and stayed out, because the calls that hand
work to the next
workflow had no retry:

| PR | Library | State it was left in | Call that died |
|---|---|---|---|
| #9742 | seaborn | `ai-approved` q90 | `impl-merge` → `gh pr view` →
**504** |
| #9744 | pygal | `ai-rejected` q87 | repair dispatch → **504**;
`ai-attempt-1` also lost |
| #9749 | makie | `ai-rejected` q88 | repair dispatch → **502** |
| #9751 | highcharts | `ai-rejected` q88 | repair dispatch → **502** |

`impl-review`'s verdict step is the pipeline's **only hand-off point** —
every downstream
workflow starts from a call made there. So an unretried blip doesn't
merely fail a step; it
leaves a PR carrying a verdict label with nothing listening.

All four have since been recovered manually and merged; this PR stops it
recurring.

## Changes

**`impl-review.yml` — the verdict step**
- every API call retries 3× with linear backoff (same shape as the
existing `Extract PR info`
  retry, added 2026-05-06 for this same class of failure)
- the repair is **dispatched before** the attempt label is added, and
the label can no longer
gate it. Losing the label costs one over-strict review; losing the
dispatch costs the whole PR
- if the dispatch still exhausts its retries, the step drops
`ai-rejected` on the way out:
`ai-rejected` + `ai-attempt-N` matches **no** watchdog case (Case 2
excludes any verdict
label, Case 4 excludes PRs that already have an attempt label), while
the label-less state is
exactly Case 2 — which re-dispatches the repair at the attempt number
the remaining label
  still encodes
- the label read tracks success explicitly instead of inferring it from
empty output, and a
successful read with no verdict label now fails loudly instead of ending
the step green

**Two bugs found while verifying the above**
- **`ai-attempt-4` never existed as a label.** The attempt label encodes
the cascading
threshold (90 → 80 → 70 → 60 → 50), but the repo only has
`ai-attempt-1..3`, so on the 4th
repair the add failed every time and `|| true` swallowed it — #7268 and
#7039 both reached
"Repair Attempt 4/4" carrying only `ai-attempt-1..3`. Every 4th review
therefore re-applied
the ≥ 90 attempt-0 bar, and the attempts-exhausted branch (close PR,
remove stale
implementation) could never be reached. Labels are now created on
demand.
*This also means my first draft of this PR was a hard blocker:* with the
label add fatal, the
  4th repair would never have been dispatched at all.
- **That newly-reachable branch rendered a literal `$SCORE/100`** —
quoted heredoc. Now
expands, with the markdown backticks escaped so they can't become
command substitution.

**`impl-merge.yml`**
- the 5× merge retry re-reads PR state first. A merge that succeeded
server-side but lost its
HTTP response used to fail four more times with "already merged" and
exit 1 — and because
every post-merge step is gated on `should_run == 'true'` (implicit
`success()`), that skipped
GCS promotion, the `impl:{lib}:done` label, closing the issue and the
Postgres sync. A merged
PR with none of its bookkeeping: exactly the silent partial completion
CLAUDE.md warns about

**`auto-update-pr-branches.yml` — Dependabot PRs could never merge while
the pipeline ran**
- the workflow called `update-branch` on Dependabot PRs. That push is
authored by
`github-actions[bot]`, so GitHub gates the resulting runs behind manual
approval
(`action_required`) — and because `main` advances every few minutes
during impl merges, each
branch was re-updated long before anyone could approve. **PR #9674
accumulated 174 runs in
22 h: 162 `action_required` against only 4 green** (the original
`dependabot[bot]` push)
- Dependabot branches are now skipped. They merge fine while behind —
the `main` ruleset is
**not** strict (`strict_required_status_checks_policy: false`); the
file's header claimed the
  opposite and is corrected
- `/dependabot`'s playbook told operators to run that same harmful
`update-branch` by hand; it
  now says the opposite and documents the `@dependabot recreate` remedy

## Verification

`.github/workflows/` has no verification loop (CLAUDE.md), so this was
reviewed by a 4-lens
adversarial pass with an independent refutation round (regression /
shell-under-`bash -e` / retry idempotency / the Dependabot
premise), and every claim was re-checked against the live repo before
acting. That pass is what
caught the `ai-attempt-4` blocker and the false Dependabot-rebase
premise in my first draft.

- YAML parses; `bash -n` clean on the extracted steps
- `gh_retry` semantics exercised under `bash -e`: succeeds first try /
recovers after 2
  failures / multi-arg passthrough / hard failure aborts the step
- the corrected control flow tested for all three cases — normal,
**attempt 4 with a
permanently failing label add (dispatch must still fire)**, and dispatch
exhaustion
  (`ai-rejected` dropped, exit 1)
- confirmed the CI runner's `gh` adds labels fine; only the
locally-installed gh 2.45.0 hits
the `projectCards` GraphQL deprecation, so hard-failing on `--add-label`
is safe in CI
- ruleset strictness, the `ai-attempt-*` label set, and the poisoned
Dependabot head commits
  were all read from the live repo, not assumed

## Follow-up (not in this PR)

- #9674, #9648 and #8820 already have a `github-actions[bot]` merge
commit as their head. Once
this merges their head stops moving, so approving each gated run
**once** is enough — verified
that the required contexts do report as SUCCESS on a bot-authored head
after approval (#9674,
commit `59545076`). Doing it before this merges would just get re-gated
by the next push to
`main`. (`@dependabot recreate` is an equivalent alternative; it also
restores a clean
  `dependabot[bot]` head but re-resolves the versions.)
- Whether `auto-update-pr-branches.yml` should exist at all now that the
ruleset is non-strict
is worth deciding separately — it affects every auto-merge PR, so it
isn't folded in here.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

---------

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
@codecov

codecov Bot commented Jul 24, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@MarkusNeusinger

Copy link
Copy Markdown
Owner

@dependabot recreate

Updates the requirements on [uvicorn[standard]](https://github.com/Kludex/uvicorn) to permit the latest version.
- [Release notes](https://github.com/Kludex/uvicorn/releases)
- [Changelog](https://github.com/Kludex/uvicorn/blob/main/docs/release-notes.md)
- [Commits](Kludex/uvicorn@0.50.0...0.51.0)

---
updated-dependencies:
- dependency-name: uvicorn[standard]
  dependency-version: 0.51.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/uv/uvicorn-standard--gte-0.51.0 branch from f0d9c2b to 7a3d3ea Compare July 24, 2026 21:15
@MarkusNeusinger
MarkusNeusinger merged commit f47a6c7 into main Jul 24, 2026
4 checks passed
@MarkusNeusinger
MarkusNeusinger deleted the dependabot/uv/uvicorn-standard--gte-0.51.0 branch July 24, 2026 21:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant