Skip to content

[dependency]: Bump the pip-dependencies group across 2 directories with 2 updates - #2466

Open
dependabot[bot] wants to merge 1 commit into
devfrom
dependabot/pip/bridge/dev/pip-dependencies-8d8cc8139e
Open

[dependency]: Bump the pip-dependencies group across 2 directories with 2 updates#2466
dependabot[bot] wants to merge 1 commit into
devfrom
dependabot/pip/bridge/dev/pip-dependencies-8d8cc8139e

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 2, 2026

Copy link
Copy Markdown
Contributor

Bumps the pip-dependencies group with 1 update in the /bridge directory: filelock.
Bumps the pip-dependencies group with 1 update in the /explorer/rest directory: aiohttp.

Updates filelock from 3.32.0 to 3.32.2

Release notes

Sourced from filelock's releases.

3.32.2

What's Changed

Full Changelog: tox-dev/filelock@3.32.1...3.32.2

Changelog

Sourced from filelock's changelog.

########### Changelog ###########

.. towncrier-draft-entries:: Unreleased

.. towncrier release notes start


3.32.2 (2026-07-29)


  • A SoftReadWriteLock or SoftFileLease acquire whose heartbeat thread fails to start now unlinks its marker and hands the claim back, instead of leaving an unrefreshed marker a peer takes while the caller believes it still holds the lock. :pr:691

3.32.1 (2026-07-26)


  • Canceling an AsyncSoftReadWriteLock acquire now releases the claim instead of leaking a marker whose heartbeat wedges every contender. :pr:686

3.32.0 (2026-07-21)


  • SoftReadWriteLock closes the directory handle it opens to scan for readers as soon as a scan stops early, rather than holding it until the generator is collected. :pr:685
  • Declare support for Python 3.15 and run the test suite against it and its free-threaded build, both currently in beta. :pr:683
  • The source distribution ships the capability probes the tests import, and reading one no longer needs coverage installed, so the suite runs from an unpacked sdist instead of failing on a missing coverage_pragmas. :pr:685

3.31.2 (2026-07-21)


  • filelock imports again on runtimes whose errno omits ENOTSUP, such as GraalPy, where importing the package raised ImportError. It probes the code instead, preferring ENOTSUP, falling back to EOPNOTSUPP where that name is absent, and dropping to ENOSYS/EXDEV where neither exists. Platforms defining ENOTSUP keep their behavior. :pr:681

3.31.1 (2026-07-20)


  • A SoftFileLease acquired on one thread keeps its claim when another thread fails to acquire the same lease object, so its heartbeat carries on refreshing the marker instead of being torn down and letting a peer take the live claim. :pr:680

... (truncated)

Commits
  • 9a6cc43 Release 3.32.2
  • 56879c7 🧪 test(unix): deflake sticky-bit concurrent-unlink on graalpy (#695)
  • ecf5be0 hand back the claim when a heartbeat thread fails to start (#691)
  • ee70d2e 🧪 test(soft-rw): deflake writer phase-2 peer-marker test (#694)
  • 1eb14dd Fix test failures on NetBSD (#689) (#693)
  • d81e859 build(deps): bump astral-sh/setup-uv from 8.3.2 to 9.0.0 (#692)
  • 6fbc905 [pre-commit.ci] pre-commit autoupdate (#690)
  • 34d1c38 build(deps): bump pypa/gh-action-pypi-publish from 1.14.0 to 1.14.1 (#688)
  • bf13ec7 Release 3.32.1
  • 887f114 build(deps): bump actions/checkout from 7.0.0 to 7.0.1 (#687)
  • Additional commits viewable in compare view

Updates aiohttp from 3.14.1 to 3.14.3

Changelog

Sourced from aiohttp's changelog.

3.14.3 (2026-07-22)

Bug fixes

  • Fixed the client dropping only the first Authorization, Cookie and Proxy-Authorization header when a redirect crossed an origin -- by :user:arshsmith1.

    Related issues and pull requests on GitHub: :issue:13180.

  • Fixed error message construction in the C HTTP parser -- by :user:bdraco.

    Related issues and pull requests on GitHub: :issue:13222.


3.14.2 (2026-07-20)

Bug fixes

  • Fixed :py:attr:~aiohttp.web.StreamResponse.last_modified rounding a :class:datetime.datetime with a fractional second down.

    Related issues and pull requests on GitHub: :issue:5303.

  • Fixed resolving localhost on Windows to fall back without AI_ADDRCONFIG when the first lookup fails, so localhost still works without an active network.

    Related issues and pull requests on GitHub: :issue:5357.

... (truncated)

Commits

@codecov

codecov Bot commented Aug 2, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 95.68%. Comparing base (3bc2370) to head (ae87538).

Additional details and impacted files

Impacted file tree graph

@@            Coverage Diff             @@
##              dev    #2466      +/-   ##
==========================================
- Coverage   96.87%   95.68%   -1.19%     
==========================================
  Files         320      723     +403     
  Lines       22212    54647   +32435     
  Branches      221     1414    +1193     
==========================================
+ Hits        21518    52290   +30772     
- Misses        687     2299    +1612     
- Partials        7       58      +51     
Flag Coverage Δ
bridge 99.65% <ø> (ø)
explorer-frontend 94.59% <ø> (ø)
explorer-nodewatch 98.57% <ø> (ø)
explorer-puller 100.00% <ø> (?)
explorer-rest 99.59% <ø> (?)
faucet-authenticator 100.00% <ø> (ø)
faucet-backend 98.75% <ø> (ø)
faucet-frontend 100.00% <ø> (ø)
lightapi-python 98.69% <ø> (ø)
tools-shoestring 97.14% <ø> (ø)
wallet-common-core 97.76% <ø> (+0.09%) ⬆️
wallet-common-ethereum 99.11% <ø> (-0.89%) ⬇️
wallet-common-nem 95.05% <ø> (ø)
wallet-common-symbol 96.68% <ø> (ø)
wallet-common-transport 95.41% <ø> (ø)
wallet-mobile-symbol 94.24% <ø> (?)

Flags with carried forward coverage won't be shown. Click here to find out more.
see 410 files with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

…th 2 updates

Bumps the pip-dependencies group with 1 update in the /bridge directory: [filelock](https://github.com/tox-dev/py-filelock).
Bumps the pip-dependencies group with 1 update in the /explorer/rest directory: [aiohttp](https://github.com/aio-libs/aiohttp).


Updates `filelock` from 3.32.0 to 3.32.2
- [Release notes](https://github.com/tox-dev/py-filelock/releases)
- [Changelog](https://github.com/tox-dev/filelock/blob/main/docs/changelog.rst)
- [Commits](tox-dev/filelock@3.32.0...3.32.2)

Updates `aiohttp` from 3.14.1 to 3.14.3
- [Changelog](https://github.com/aio-libs/aiohttp/blob/master/CHANGES.rst)
- [Commits](aio-libs/aiohttp@v3.14.1...v3.14.3)

---
updated-dependencies:
- dependency-name: aiohttp
  dependency-version: 3.14.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: pip-dependencies
- dependency-name: filelock
  dependency-version: 3.32.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: pip-dependencies
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot
dependabot Bot force-pushed the dependabot/pip/bridge/dev/pip-dependencies-8d8cc8139e branch from a3fd862 to ae87538 Compare August 7, 2026 00:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants