Skip to content

fix(deps): update all major updates (major) - #386

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/major-all-major-updates
Open

fix(deps): update all major updates (major)#386
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/major-all-major-updates

Conversation

@renovate

@renovate renovate Bot commented Apr 17, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change Age Confidence
actions/checkout action major v6v7 age confidence
actions/setup-node action major v6v7 age confidence
actions/setup-python action major v6v7 age confidence
chalk dependencies major ^5.0.0^6.0.0 age confidence
codecov/codecov-action action major v6v7 age confidence
commander dependencies major ^14.0.2^15.0.0 age confidence
dotenv-expand dependencies major ^12.0.3^13.0.0 age confidence
execa dependencies major ^9.0.0^10.0.0 age confidence
gunicorn (changelog) project.dependencies major ==25.3.0==26.2.0 age confidence
isort (changelog) dependency-groups major ==8.0.1==9.0.1 age confidence
public.ecr.aws/amazonlinux/amazonlinux final major 2023.11.20260413.02027.0.20260903.0 age confidence
structlog (changelog) project.dependencies major ==25.5.0==26.1.0 age confidence

Release Notes

actions/checkout (actions/checkout)

v7.0.1

Compare Source

v7.0.0

Compare Source

actions/setup-node (actions/setup-node)

v7.0.0

Compare Source

What's Changed
Enhancements:
Bug fixes:
Documentation updates:
Dependency update:
New Contributors

Full Changelog: actions/setup-node@v6...v7.0.0

actions/setup-python (actions/setup-python)

v7.0.0

Compare Source

chalk/chalk (chalk)

v6.0.0

Compare Source

codecov/codecov-action (codecov/codecov-action)

v7.0.0

Compare Source

⚠️ Due to migration issues with keybase, we are unable to update our keys under the codecovsecurity account. We have deleted the account and are using codecovsecops with the original gpg key

What's Changed

Full Changelog: codecov/codecov-action@v6.0.1...v7.0.0

tj/commander.js (commander)

v15.0.0

Compare Source

Commander 15 is ESM only. This is expected to be seamless for ESM consumers, but some CommonJS consumers may hit issues with tooling requiring configuration for ESM-only dependencies. See Migration Tips below.

The release of Commander 15 moves Commander 14 into maintenance. Commander 14 will get security updates for
12 months (to May 2027). For more info see Release Policy.

Added
  • show excess command-arguments in error message ([#​2384])
Fixed
  • Breaking: only lone --no-* option sets default option value to true, default not implicitly set when define both positive and negative option in either order ([#​2405])
  • update example to use compatible character for MINGW64 ([#​2475])
Changed
  • Breaking: migrated Commander implementation from CommonJS to ESM ([#​2464])
  • Breaking: Commander 15 requires Node.js v22.12.0 or higher (for require(esm)).
  • dev: switch tests from Jest to node:test test runner ([#​2463])
Deleted
  • Breaking: removed deprecated export of commander/esm.mjs ([#​2464])
Migration Tips

Commander 15 is ESM only, but this does not mean you need to migrate to ESM to use it. Importing ESM from CommonJS is
supported by Node.js, and Bun, and Deno. Hopefully it Just Works for you! However, you may be using a different runtime or
some other part of your setup that may not yet natively support importing ESM from CommonJS, such as your testing framework
or bundler.

If you have problems using Commander 15 in your environment, one option is stay on Commander 14 for now. Commander 14 will
get security updates until May 2027 and things will hopefully improve for your setup in the meantime.

dotenvx/dotenv-expand (dotenv-expand)

v13.0.0

Compare Source

Changed
  • bump dotenv to v17
sindresorhus/execa (execa)

v10.0.1

Compare Source

  • Fix preferLocal argument escaping edge-case on Windows (#​1259) e771733

v10.0.0

Compare Source

Breaking
const subprocess = execa('node', ['file.js']);
- subprocess.on('spawn', onSpawn);
+ subprocess.nodeChildProcess.on('spawn', onSpawn);
- await execaCommand('npm run build');
+ await execa`npm run build`;

- await execaCommand(commandString);
+ await execa`${parseCommandString(commandString)}`;
- await execa('node', ['file.js'], {stdio: ['pipe', 'pipe', 'pipe', 'ipc']});
+ await execa('node', ['file.js'], {ipc: true});
  • When the input or inputFile option is combined with an inherited stdin (for example stdio: 'inherit'), the explicit input is now used, instead of being ignored. To combine multiple inputs, pass an array like stdin: ['inherit', {string: 'input'}]. (#​1232) 3ed0544
Improvements
await execa('npm', ['run', 'build'], {killDescendants: true, timeout: 5000});
await execa`npm run build`
	.readableStream()
	.pipeTo(writableWebStream);
for await (const line of execa`npm run build`.pipe`sort`) {
	console.log(line);
}
const subprocess = execa({stdio: ['pipe', 'pipe', 'pipe', {value: 'pipe', input: true}]})`npm run scaffold`;

const writable = subprocess.writable({to: 'fd3'});
Fixes

benoitc/gunicorn (gunicorn)

v26.2.0: gunicorn 26.2.0

Compare Source

Cleartext HTTP/2 lands, and an HTTP/2 security fix.

Cleartext HTTP/2 (h2c)

http2_cleartext accepts prior-knowledge, upgrade, both or off (the
default). Prior knowledge serves a connection that opens with the HTTP/2
preface; upgrade honours an HTTP/1.1 Upgrade: h2c request. Both work on the
gthread, gevent and asgi workers.

This is for deployments where TLS is terminated by a proxy that speaks HTTP/2
upstream, so the hop into gunicorn no longer drops to HTTP/1.1. Only peers in
forwarded_allow_ips are considered; everyone else is served HTTP/1.x exactly
as if the setting were off. Each mechanism is enabled separately, so turning one
on does not turn the other on.

Do not expose a cleartext HTTP/2 port to the internet.

Security

HTTP2Request built its headers straight from the stream, so nothing the HTTP/1
path enforces applied over HTTP/2: the underscore and header_map policy,
duplicate Host and Content-Type, control characters in values, and the
forwarded_allow_ips trust gate. An untrusted client could set SCRIPT_NAME
and forge HTTP_* entries in the WSGI environ, and decide wsgi.url_scheme
through :scheme. Both request classes now share one policy mixin, and the
scheme comes from the transport.

If you serve HTTP/2, this is the reason to upgrade.

Other HTTP/2 fixes

WSGI responses were buffered whole before anything was sent; they stream now.
HEAD, 204 and 304 no longer carry a body. Events read while blocked on a
flow-control window were discarded, losing requests and body data outright.
sendfile() is refused on HTTP/2 responses rather than bypassing framing.

Request bodies dropped on Upgrade requests

On the ASGI worker with the fast parser, any request carrying an Upgrade
header reached the application with an empty body, whatever the header's value
and with HTTP/2 switched off entirely. Fixed in gunicorn_h1c 0.6.9, which the
fast extra now requires.

Full changelog: https://gunicorn.org/news/

v26.1.0: gunicorn 26.1.0

Compare Source

New Features
  • Glob patterns in reload_extra_files: entries containing *, ? or [
    are treated as patterns, so ui/*/config.json watches every view's config
    without listing them one by one. Patterns are re-expanded on every reload
    check rather than once at startup, so a file created later starts being
    watched without restarting gunicorn, and ** recurses. A pattern matching
    nothing warns instead of failing, since with live expansion it may match later
    (#​1643,
    #​3662).
Security
  • Dependency floors raised past known advisories: every declared floor was
    checked against the advisory database. tornado, h2, setuptools and
    pymdown-extensions permitted vulnerable versions and now require the first
    clean release; pytest and httpx were unpinned and now carry floors. The
    tornado example pinned tornado<6, which was both the source of several
    advisories and older than the >=6.5.0 the tornado worker needs, so the
    example could not run as pinned.
Bug Fixes
  • SIGHUP did not reload the logger configuration: Arbiter.reload()
    re-read the configuration file but kept using the logger built at startup,
    calling only reopen_files() on its existing handlers. Changes to
    logconfig, logconfig_dict, logconfig_json and loglevel were ignored
    until a full restart, which in containers meant replacing the pod. The
    existing logger now re-runs its setup on reload, so new handlers, formats
    and levels take effect while the process identity and its listeners are
    preserved, and re-running the setup no longer stacks duplicate syslog
    handlers. An invalid log configuration on reload is not fatal either: the
    error is reported on stderr, the previous working configuration is restored
    and the master keeps running with it
    (#​3353).

  • Truncated chunked bodies accepted: RFC 9112 section 7.1.2 ends a chunked
    body with 0 CRLF CRLF, the second CRLF being the mandatory empty trailer
    section. ChunkedReader.parse_chunk_size() swallowed the NoMoreData raised
    while scanning for it, so a body cut short right after the last chunk line was
    treated as complete instead of rejected. It now raises
    ChunkMissingTerminator
    (#​3382,
    #​3685).

  • --spew crashed on dynamically generated code: the trace hook indexed the
    2-tuple returned by inspect.getsourcelines() by line number rather than
    indexing the list of lines, so a frame with no __file__ raised
    AttributeError: 'int' object has no attribute 'rstrip' on line 1 and
    IndexError beyond it. The tuple is now unpacked and offset by the source's
    starting line (#​3344,
    #​3495).

  • Duplicate Host and Content-Type headers accepted: RFC 9110 section 5.3
    allows only one of each, and a repeat cannot be merged into a list, so the
    message means different things to gunicorn and to anything downstream. Both
    are now rejected with InvalidHeader. The check lives in the policy hook
    shared by both parsers, so the pure-Python and fast parsers agree. Duplicate
    Content-Length was already rejected and is unchanged
    (#​3366,
    #​3548).

  • Non-worker children reported as failed workers: reap_workers() reaps
    every child through waitpid(-1), including processes the kernel reparented
    onto gunicorn when it runs as PID 1 in a container, but it logged the exit
    status before checking whether the pid was ever a worker. An unrelated process
    produced Worker (pid:N) exited with code M and triggered alerts. More
    seriously, such a process exiting with code 3 or 4 raised HaltServer and shut
    the server down. Ownership is now established first: the dirty arbiter is
    reported as itself, unknown children are reaped silently at debug level, and
    only real workers can halt the server
    (#​3220,
    #​3566).

  • Dirty arbiter exits were invisible on SIGCHLD: handle_chld() called
    reap_workers() first, whose waitpid(-1) claimed the dirty arbiter before
    reap_dirty_arbiter() could identify it, so the latter always hit ECHILD and
    its reporting never ran. The dirty arbiter is now reaped first, and
    reap_workers() recognises it if it exits mid-loop.

  • Dirty arbiter returned stale responses after a worker timeout: when a
    request reached dirty_timeout the arbiter answered the client with a timeout
    error but kept the worker connection open. The worker's late response was then
    the first message waiting on that socket, so the next request routed to the
    same worker received the previous request's result, and every request after it
    stayed one response behind. The connection is now closed on timeout, so the
    late answer is discarded with it
    (#​3626).

  • ASGI connection count leaked on server-initiated close: nr_conns was
    only decremented in connection_lost(), behind a guard keyed on the same
    flag _close_transport() sets first. Every close the server started (a
    Connection: close response, a keepalive timeout, an error abort) leaked one
    count, so ASGIWorker._shutdown() ran the full graceful_timeout and warned
    about connections that were already gone. The guard now uses its own flag, so
    the decrement and the rest of the cleanup run exactly once whichever side
    closes first (#​3661).

  • Inotify reloader on cwd-relative extra files: reload_extra_files entries
    with no directory part (for example .env) produced an empty dirname, and
    watching it raised InotifyError with ENOENT. The current directory is now
    watched as . (#​3377,
    #​3667).

  • StatsD zero-valued metrics: gauges, counters, histograms and timers
    reporting 0 were silently dropped because the value was tested for
    truthiness. Only None is skipped now
    (#​3676).

  • Spurious no-body warning from sendfile(): a HEAD, 204 or 304 response
    served through sendfile() warned about dropped body bytes even when the
    file was empty and nothing was dropped. It now warns only when there are
    bytes to drop, matching write()
    (#​3684).

  • Bare except in the gevent websocket example: narrowed to
    except Exception (#​3683).

  • ASGI receive() cancellation: Let asyncio.CancelledError propagate
    from BodyReceiver instead of swallowing it and returning
    http.disconnect. Frameworks that cancel their disconnect listener after
    the response completes (Django) no longer see the cancel masked, so
    request_finished fires and close_old_connections() runs. Fixes idle
    database connections leaking since 25.1.0
    (#​3627,
    #​3654).

  • Control socket leak on SIGHUP reload: The control thread is now marked
    ready once its loop and server are live, and the stop paths wait on that
    readiness before scheduling shutdown. Reloads no longer leak one thread and
    its selector fd plus unix socket per worker, which eventually raised
    "too many open files"
    (#​3648).

  • WSGI body framing on HEAD/1xx/204/304: Mirror the ASGI strip-and-warn
    behavior on the WSGI path. Content-Length is stripped on 1xx/204 per
    RFC 9110 section 6.4.2, body bytes are dropped for no-body responses in
    both write() and sendfile(), and a single warning is logged per request
    (#​3413).

Refactoring
  • Pass log arguments to the logger instead of pre-formatting the worker
    termination message in Arbiter.reap_workers()
    (#​3678).
Changes
  • packaging is no longer a runtime dependency: it was only ever imported by
    the gevent worker, to compare gevent's version. It moved to the gevent and
    testing extras, so a plain pip install gunicorn pulls in nothing
    (#​3643).

  • Fast HTTP Parser: Require gunicorn_h1c >= 0.6.6, which rejects duplicate
    Host and Content-Type headers in the C parser itself. Gunicorn already
    refuses them on both the WSGI and ASGI paths, so this changes nothing that is
    reachable; it moves the rejection to where the bytes are read and lets the
    ASGI corpus exercise those cases against the fast parser directly.

Full changelog: https://gunicorn.org/2026-news/

v26.0.0

Compare Source

Breaking Changes

  • Eventlet worker removed: The eventlet worker class has been dropped. Migrate to gevent, gthread, or tornado.

New Features

  • ASGI Framework Compatibility Suite: New end-to-end compatibility test harness covering Starlette, FastAPI, Litestar, Quart, Sanic, and BlackSheep. Current grid passes 438/444 tests (98%).
  • ASGI Test Suite Expansion: 134 additional ASGI unit tests covering protocol semantics, lifespan, websockets, and chunked framing.

Security

  • HTTP/1.1 Request-Target Validation (RFC 9112 sections 3.2.3, 3.2.4):
    • Reject authority-form request-target outside CONNECT
    • Reject asterisk-form request-target outside OPTIONS
    • Reject relative-reference request-targets
  • Header Field Hardening (RFC 9110):
    • Reject control characters in header field-value (section 5.5)
    • Reject forbidden trailer field-names (section 6.5.1)
    • Reject Content-Length list form (RFC 9112 section 6.3)
  • Request Smuggling Hardening:
    • Tighten keepalive gate and scope finish_body byte cap
    • Keep _body_receiver alive across the keepalive smuggling gate so pipelined requests cannot re-enter a closed body
    • Address parser/protocol findings from a six-point WSGI/ASGI audit
  • PROXY Protocol (ASGI): Enforce proxy_allow_ips and tighten v1/v2 parsing in the ASGI callback parser.
  • Connection Draining: Drain the connection on close per RFC 9112 section 9.6 to prevent reset-on-close truncation.

Bug Fixes

  • Body Framing on HEAD/204/304:
    • Keep Content-Length on HEAD and 304 responses (#​3621)
    • Drop body framing on HEAD/204/304 even when the framework set it
    • Warn once when an ASGI app emits a body for a no-body response
  • HTTP/2 ASGI:
    • Fix _handle_stream_ended to set _body_complete in the async HTTP/2 handler so request bodies finalize correctly on stream end
    • Add InvalidChunkExtension mapping and fast-parser support in ASGI tests (#​3565)
  • HTTP/1.1 100-Continue: Stop adding Transfer-Encoding: chunked to 100-Continue interim responses.
  • WebSocket Close Handshake (RFC 6455):
    • Comply with the close handshake state machine
    • Close the transport after the close handshake completes
    • Fix binary send when the text key is None
  • Early Hints: Validate headers in the early_hints callback to match process_headers; pass only the header name to InvalidHeader (#​3588).
  • ASGI Framework Fixes:
    • Fix ASGI disconnect handling for Django-style apps
    • Fix Litestar request handling (use raw ASGI receive for body/headers)
    • Fix Litestar HTTP endpoints for compatibility tests
    • Fix Quart headers endpoint to normalize keys to lowercase
    • Fix Quart WebSocket close test app (missing accept())
    • Fix duplicate Transfer-Encoding header for BlackSheep streaming

Refactoring

  • Split BodyReceiver._closed into separate transport and body-wait flags for clearer keepalive/EOF semantics.

Changes

  • Fast HTTP Parser: Require gunicorn_h1c >= 0.6.5. Drop the last python_only test markers; the C extension is now used wherever available (CPython only; PyPy continues to use the Python parser).
  • Test Dependencies: Add h2 and uvloop to the testing extra; remove eventlet.
  • Docker Build: Bump GitHub Actions docker/setup-qemu-action, docker/setup-buildx-action, docker/login-action, docker/build-push-action, and docker/metadata-action to current major versions.

Full changelog: benoitc/gunicorn@25.3.0...26.0.0

PyCQA/isort (isort)

v9.0.1

Compare Source

🪲 Fixes

Other changes

Full Changelog: PyCQA/isort@9.0.0...9.0.1

v9.0.0

Compare Source

hynek/structlog (structlog)

v26.1.0

Compare Source

Removed
  • Python 3.8 and 3.9 support.
Deprecated
Added
  • Python 3.15 support.
    #​813

  • structlog.dev.rich_monochrome_traceback for Rich-based monochrome exception rendering and add support for it throughout structlog.dev.ConsoleRenderer when the user asks for no colors.
    #​794

  • structlog.BytesLogger now has a name attribute which allows you to use it with the structlog.stdlib.add_logger_name() processor without using the standard library integration.
    #​786

  • structlog.processors.CallsiteParameterAdder now supports CallsiteParameter.QUAL_MODULE that adds the qualified import name of the module of the callsite, or __main__ if the module is the entry point.
    This is only available for structlog-originated events since the standard library has no equivalent (except for the convention of setting the logger's name to __name__).
    #​812

  • structlog.stdlib.BoundLogger now has is_enabled_for() and get_effective_level() methods that are snake_case aliases for its isEnabledFor() and getEffectiveLevel() methods.
    This makes it more compatible with the native structlog.typing.FilteringBoundLogger, so you can swap configurations without changing your call sites.
    #​818

Changed
  • structlog.dev.ConsoleRenderer does not warn anymore when the exception key has a rendered value despite having a fancy formatter configured.
    #​790
Fixed
  • structlog.BytesLogger, structlog.PrintLogger, and structlog.WriteLogger now hold weak references to the files they use for output.
    This prevents their leakage in long-running processes that open many logfiles, such as task executors that create a per-task BytesLogger or WriteLogger.
    #​807

  • structlog.WriteLogger is usable after unpickling.
    #​787

  • structlog.processors.CallsiteParameterAdder now reports the calling thread's id and name for async log methods, instead of the thread from the executor pool that runs the underlying sync logger.
    #​710
    #​805


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot changed the title fix(deps): update dependency dotenv-expand to v13 fix(deps): update all major updates (major) May 5, 2026
@renovate
renovate Bot force-pushed the renovate/major-all-major-updates branch from 6d9d945 to cb67ffd Compare May 5, 2026 10:51
@renovate
renovate Bot force-pushed the renovate/major-all-major-updates branch from cb67ffd to d01e404 Compare May 29, 2026 09:48
@renovate
renovate Bot force-pushed the renovate/major-all-major-updates branch 2 times, most recently from 951e142 to aa0ecd2 Compare June 7, 2026 06:12
@renovate
renovate Bot force-pushed the renovate/major-all-major-updates branch from aa0ecd2 to 882d335 Compare June 18, 2026 20:58
@renovate
renovate Bot force-pushed the renovate/major-all-major-updates branch 4 times, most recently from ab877b8 to e6af1a4 Compare July 17, 2026 01:52
@renovate
renovate Bot force-pushed the renovate/major-all-major-updates branch 3 times, most recently from 27a2ad6 to 85b0567 Compare July 26, 2026 17:50
@renovate
renovate Bot force-pushed the renovate/major-all-major-updates branch from 85b0567 to 136b34c Compare July 31, 2026 06:57
@renovate
renovate Bot force-pushed the renovate/major-all-major-updates branch 4 times, most recently from 028eae8 to 17ffb98 Compare August 28, 2026 00:10
@renovate
renovate Bot force-pushed the renovate/major-all-major-updates branch from 17ffb98 to ff650f4 Compare September 3, 2026 20:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants