Skip to content

Bump the production-dependencies group across 1 directory with 11 updates - #2661

Open
dependabot[bot] wants to merge 2 commits into
developfrom
dependabot/pip/production-dependencies-daa988af0a
Open

Bump the production-dependencies group across 1 directory with 11 updates#2661
dependabot[bot] wants to merge 2 commits into
developfrom
dependabot/pip/production-dependencies-daa988af0a

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 1, 2026

Copy link
Copy Markdown
Contributor

Bumps the production-dependencies group with 11 updates in the / directory:

Package From To
azure-keyvault-certificates 4.11.1 4.11.2
azure-keyvault-keys 4.11.1 4.11.2
azure-keyvault-secrets 4.11.0 4.11.2
azure-mgmt-compute 38.2.0 38.3.0
azure-storage-blob 12.30.0 12.30.1
click 8.4.2 8.5.0
cryptography 49.0.0 50.0.1
pulumi-azure-native 3.23.0 3.26.0
pulumi 3.254.0 3.260.0
pydantic 2.13.4 2.13.5
typer 0.27.0 0.27.2

Updates azure-keyvault-certificates from 4.11.1 to 4.11.2

Release notes

Sourced from azure-keyvault-certificates's releases.

azure-keyvault-certificates_4.11.2

4.11.2 (2026-08-25)

Bugs Fixed

  • Fixed the challenge authentication policy to cache the authentication challenge only after the challenge resource is verified, so that a rejected challenge is not cached and reused by subsequent requests.
Commits
  • da0f69c [KeyVault] Scope certificates hotfix pipeline to certificates only (#48754)
  • 9f29b0b Limit certificates hotfix pipeline artifacts (#48748)
  • bafb676 Hotfix: cache Key Vault challenge only after validation (certificates 4.11.2)...
  • See full diff in compare view

Updates azure-keyvault-keys from 4.11.1 to 4.11.2

Release notes

Sourced from azure-keyvault-keys's releases.

azure-keyvault-keys_4.11.2

4.11.2 (2026-08-25)

Bugs Fixed

  • Fixed the challenge authentication policy to cache the authentication challenge only after the challenge resource is verified, so that a rejected challenge is not cached and reused by subsequent requests.
Commits
  • ffc5327 [KeyVault] Disable verifytypes for administration on the hotfix branch (#48755)
  • 6f4097b Hotfix: cache Key Vault challenge only after validation (keys 4.11.2, adminis...
  • See full diff in compare view

Updates azure-keyvault-secrets from 4.11.0 to 4.11.2

Release notes

Sourced from azure-keyvault-secrets's releases.

azure-keyvault-secrets_4.11.2

4.11.2 (2026-08-25)

Bugs Fixed

  • Fixed the challenge authentication policy to cache the authentication challenge only after the challenge resource is verified, so that a rejected challenge is not cached and reused by subsequent requests.

azure-keyvault-secrets_4.11.1

4.11.1 (2026-08-12)

Bugs Fixed

  • Fixed a replay bug in the challenge authentication policy where a request copy stashed on the shared policy instance was never cleared, allowing one request's method, URL, and body to leak into a later, unrelated request made by the same client (for example, after an Entra ID Continuous Access Evaluation challenge). The original request is now stored per-request instead of on the policy instance. This mirrors the fix already applied to azure-keyvault-keys and azure-keyvault-administration in #47742.
Commits
  • 5c95cf1 Hotfix: cache Key Vault challenge only after validation (secrets 4.11.2) (#48...
  • 63f9d76 [KeyVault] Fix Challenge Auth replay bug in secrets, certificates (#48537)
  • 8050793 Don't use sparse chekout for private repos (#47776)
  • 19001b1 Update helper function to print nested exception details. (#48520)
  • c9e6a74 Enable CFSClean network isolation for Python pipelines (#48483)
  • 23a9d53 [Storage] Bump versions after STG 104 beta release (#48528)
  • 0c2dca4 Sync eng/common directory with azure-sdk-tools for PR 16685 (#48522)
  • fab4548 [AutoPR azure-mgmt-fabric]-generated-from-SDK Generation - Python-6671798 (#4...
  • 833b8c5 [AutoPR azure-mgmt-netapp]-generated-from-SDK Generation - Python-6620664 (#4...
  • 529ae05 [AgentServer] Set StateStore release dates (#48532)
  • Additional commits viewable in compare view

Updates azure-mgmt-compute from 38.2.0 to 38.3.0

Release notes

Sourced from azure-mgmt-compute's releases.

azure-mgmt-compute_38.3.0

38.3.0 (2026-08-12)

Features Added

  • Client ComputeManagementClient added operation group virtual_machine_diagnostic_run_commands
  • Client ComputeManagementClient added operation group virtual_machine_scale_set_vm_diagnostic_run_commands
  • Model CapacityReservationInstanceView added property reservation_state_info
  • Model CapacityReservationInstanceViewWithName added property reservation_state_info
  • Model CapacityReservationProfile added property disable_capacity_reservation_assignment
  • Model CapacityReservationUtilization added property used_reserved_count_by_subscription
  • Model HardwareProfile added property processor_mode
  • Model HostEndpointSettings added property use_local_file_rules
  • Model ManagedDiskParameters added property additional_disk_properties
  • Enum ReservationType added member OPEN
  • Model ScheduleProfile added property minimum_commitment_days
  • Model ScheduleProfile added property modifiable_until
  • Model StorageProfile added property disk_api_version
  • Model VirtualMachineExtensionImageProperties added property extension_feature_metadata
  • Model VirtualMachineExtensionImageProperties added property release_category
  • Model VirtualMachineExtensionImageProperties added property release_notes
  • Model VirtualMachineExtensionImageProperties added property run_profile
  • Model VirtualMachineExtensionImageProperties added property urgency_level
  • Model VirtualMachineInstanceView added property capacity_reservation_type
  • Model VirtualMachineIpTag added property first_party_service_tag_id
  • Enum VirtualMachinePriorityTypes added member SPOT_PLUS
  • Model VirtualMachineScaleSetHardwareProfile added property processor_mode
  • Model VirtualMachineScaleSetIpTag added property first_party_service_tag_id
  • Model VirtualMachineScaleSetManagedDiskParameters added property additional_disk_properties
  • Model VirtualMachineScaleSetStorageProfile added property disk_api_version
  • Model VirtualMachineScaleSetUpdateStorageProfile added property disk_api_version
  • Model VirtualMachineScaleSetVMInstanceView added property capacity_reservation_type
  • Model VirtualMachineScaleSetVMProperties added property capacity_reservation
  • Added model AdditionalDiskProperties
  • Added model CapacityReservationStateInfo
  • Added enum CapacityReservationType
  • Added enum DiskApiVersion
  • Added model DiskAvailabilityPolicy
  • Added model ExtensionFeatureMetadata
  • Added model ExtensionFeatureTag
  • Added enum ListVersionsExpandOptions
  • Added model MigrateVMAvailabilityZoneInput
  • Added enum ProcessorMode
  • Added enum ReleaseCategory
  • Added enum ReservationState
  • Added enum RunProfile
  • Added enum UrgencyLevel
  • Added model VirtualMachineDiagnosticRunCommand
  • Added enum VirtualMachineDiskDelayAction
  • Added enum VirtualMachineDiskNetworkAccessPolicy

... (truncated)

Commits
  • 1c9bfde Adding fix workflow to failing pipelines (#48554)
  • 0a6617d [Service Bus] Send server-timeout on management operations (#48563)
  • f5f77ab Bump fast-uri from 3.1.4 to 3.1.5 in /eng/common/tsp-client (#48615)
  • 7a96990 Configurations: 'specification/management/resource-manager/Microsoft.Managem...
  • f1f45db [AutoPR azure-mgmt-compute]-generated-from-SDK Generation - Python-6692529 (#...
  • ec6daf8 Prepare azure-ai-agentserver-core 2.1.0b2 release (#48619)
  • a94a8aa [agentserver-core] Update task client to Routines=V2Preview opt-in header (#4...
  • c24957f Restore durable Responses request context (#48605)
  • 329591b Add asyncpg SQLAlchemy engine factory for Entra authentication (#48368)
  • a038f49 Howie/dispatch 2 (#48606)
  • Additional commits viewable in compare view

Updates azure-storage-blob from 12.30.0 to 12.30.1

Release notes

Sourced from azure-storage-blob's releases.

azure-storage-blob_12.30.1

12.30.1 (2026-08-24)

Bugs Fixed

  • Fixed a bug where client-side encryption 2.0 could not detect a rearrangement of otherwise-untampered authenticated regions in blob content. This is now detected and exceptions are thrown. For data recovery purposes, this behavior can be reverted by setting the "AZURE_STORAGE_CSE_V2_ALLOW_MISORDERED_AUTH_REGIONS" environment variable.
  • Fixed a bug in client-side encryption where version downgrades, and other metadata tampering, was only detected at the start of a download.
Commits

Updates click from 8.4.2 to 8.5.0

Release notes

Sourced from click's releases.

8.5.0

This is the Click 8.5.0 feature release. A feature release may include new features, remove previously deprecated code, add new deprecation, or introduce potentially breaking changes.

We encourage everyone to upgrade. You can read more about our Version Support Policy on our website.

PyPI: https://pypi.org/project/click/8.5.0/ Changes: https://click.palletsprojects.com/page/changes/#version-8-5-0 Milestone https://github.com/pallets/click/milestone/33

  • Add built-in shell completion support for PowerShell (Windows PowerShell 5.1+ and pwsh 7+) alongside the existing bash, zsh, and fish completers. Use _FOO_BAR_COMPLETE=powershell_source foo-bar to generate the completion script. #2672 #3637
  • Supported versions of Windows enable ANSI terminal styles by default. Colorama is no longer a dependency and is not used. #2986 #3505
  • {class}Argument accepts a help parameter, and help output includes a Positional arguments section when argument help is available. #2983 #3473
  • confirm() and prompt() strip ANSI color and style codes from the prompt when the output stream does not support them, matching echo(). This stripping was lost in 8.4.0 when #2969 began writing the prompt with input() directly. #3572 #3653
  • {class}Path with allow_dash=True no longer triggers a BytesWarning, an error under python -bb, when checking a value against the - convention. #2877 #3642
  • Add {func}custom_version_option, a --version option whose output is produced by a callback, covering cases {func}version_option intentionally does not. The feature set of {func}version_option is now frozen; see [discussion #3527](`@version_option` future direction pallets/click#3527). #3581
  • style() and secho() no longer silently drop the 256-color index 0 (black) passed as fg or bg, and now validate color arguments. Invalid colors raise a ValueError instead of a TypeError. #3677
  • The automatic help option stores its value under the reserved name _click_default_help instead of help, so a parameter named help no longer breaks parsing. The new name is visible in {meth}Command.to_info_dict output. Parameters that overwrite each other's value trigger a warning: an argument sharing its name with another parameter, or any parameter claiming the reserved name. Options may still share a name to compete for the same value (feature switches). #2819 #3678
  • unstyle and the ANSI handling behind help-text wrapping now strip the full CSI escape-sequence grammar. #3681
  • Streamline Option flag handling: the flag-kind, type, lazy-default and validation steps in Option.__init__ move into focused helpers, and flag_value and default keep their unset sentinel at construction (resolved lazily on read) so is UNSET reliably tells a user-supplied value from an auto-derived one. Runtime behavior is unchanged, but {meth}Parameter.to_info_dict now resolves default=True on a feature switch to its flag_value, matching what the function receives at call

... (truncated)

Changelog

Sourced from click's changelog.

Version 8.5.0

Released 2026-08-24

  • Add built-in shell completion support for PowerShell (Windows PowerShell 5.1+ and pwsh 7+) alongside the existing bash, zsh, and fish completers. Use _FOO_BAR_COMPLETE=powershell_source foo-bar to generate the completion script. {issue}2672 {pr}3637
  • Supported versions of Windows enable ANSI terminal styles by default. Colorama is no longer a dependency and is not used. {issue}2986 {pr}3505
  • {class}Argument accepts a help parameter, and help output includes a Positional arguments section when argument help is available. {issue}2983 {pr}3473
  • confirm() and prompt() strip ANSI color and style codes from the prompt when the output stream does not support them, matching echo(). This stripping was lost in 8.4.0 when {pr}2969 began writing the prompt with input() directly. {issue}3572 {pr}3653
  • Fix test failures when using pytest >= 9.1. {pr}3656
  • {class}Path with allow_dash=True no longer triggers a BytesWarning, an error under python -bb, when checking a value against the - convention. {issue}2877 {pr}3642
  • Add {func}custom_version_option, a --version option whose output is produced by a callback, covering cases {func}version_option intentionally does not. The feature set of {func}version_option is now frozen; see [discussion #3527](`@version_option` future direction pallets/click#3527). {pr}3581
  • style() and secho() no longer silently drop the 256-color index 0 (black) passed as fg or bg, and now validate color arguments. Invalid colors raise a ValueError instead of a TypeError. {pr}3677
  • The automatic help option stores its value under the reserved name _click_default_help instead of help, so a parameter named help no longer breaks parsing. The new name is visible in {meth}Command.to_info_dict output. Parameters that overwrite each other's value trigger a warning: an argument sharing its name with another parameter, or any parameter claiming the reserved name. Options may still share a name to compete for the same value (feature switches). {issue}2819 {pr}3678
  • unstyle and the ANSI handling behind help-text wrapping now strip the full CSI escape-sequence grammar. {pr}3681
  • Streamline Option flag handling: the flag-kind, type, lazy-default and validation steps in Option.__init__ move into focused helpers, and flag_value and default keep their unset sentinel at construction (resolved lazily on read) so is UNSET reliably tells a user-supplied value from an auto-derived one. Runtime behavior is unchanged, but {meth}Parameter.to_info_dict now resolves default=True on a feature switch to its flag_value, matching what the function receives at call time. {pr}3641
  • {func}get_binary_stream and {func}get_text_stream are deprecated and will be removed in Click 9.0. {issue}3481 {pr}3695
  • The following click.utils names were never intentionally public and are now private (_-prefixed). The old names remain available with a DeprecationWarning until Click 9.0: LazyFile, KeepOpenFile,

... (truncated)

Commits
  • 8b19813 Release version 8.5.0
  • 2c8cd3a Add FAQ entry about UnicodeEncodeError on Windows (#3778)
  • 131c86a Add FAQ entry about UnicodeEncodeError on Windows
  • e1fd594 Add support of pathlib.Path to edit (#3781)
  • a1d8785 Add support of pathlib.Path to edit
  • 2103e15 Forward all user's parameters set in PAGER and improve flag detection (#3777)
  • a6256bf Forwards all user's parameters set in PAGER
  • 61b69e9 Resolve the pager command once, in _pager_contextmanager (#3776)
  • 9835b0f Resolve the pager command once, in _pager_contextmanager
  • f36d58b Refactor pager stream handling (#3767)
  • Additional commits viewable in compare view

Updates cryptography from 49.0.0 to 50.0.1

Changelog

Sourced from cryptography's changelog.

50.0.1 - 2026-08-25


* Updated Windows, macOS, and Linux wheels to be compiled with OpenSSL 4.0.2.

.. _v50-0-0:

50.0.0 - 2026-07-31

  • SECURITY ISSUE: :func:~cryptography.hazmat.primitives.serialization.pkcs7.pkcs7_decrypt_der and its PEM and S/MIME variants no longer expose distinguishable errors or timing when unwrapping a RecipientInfo's encryptedKey, which could act as a Bleichenbacher oracle for callers that decrypt untrusted messages. A random key is now substituted on failure, as described in :rfc:3218. Credit to @​X1AOxiang for reporting the issue. CVE-2026-69247
  • Deprecated Diffie-Hellman key exchange over finite fields (FFDH). Everything FFDH is deprecated, including the types in cryptography.hazmat.primitives.asymmetric.dh and loading FFDH keys or parameters with the key loading APIs. Users should migrate to a more modern key exchange algorithm.
  • Added xof() class methods to :class:~cryptography.hazmat.primitives.hashes.SHAKE128 and :class:~cryptography.hazmat.primitives.hashes.SHAKE256 for constructing algorithm instances configured for use with :class:~cryptography.hazmat.primitives.hashes.XOFHash.
  • The :mod:X.509 verification <cryptography.x509.verification> APIs are now considered stable and are subject to our API stability policy.
  • Added the :doc:/cobblestone recipe, an implementation of the Cobblestone-128 and Cobblestone-256 instantiations of the C2SP chunked-encryption specification <https://c2sp.org/chunked-encryption>_ for streaming authenticated encryption of large messages.
  • Parsing a Signed Certificate Timestamp list now rejects encodings that carry trailing bytes after the list or after an individual SCT, instead of silently ignoring them.
  • Added support for using :class:~cryptography.x509.Name as a field type in the :doc:/hazmat/asn1/index module.
  • Loading a public key or an EC private key now rejects DER where the subjectPublicKey (or EC publicKey) BIT STRING declares a non-zero number of unused bits, instead of silently ignoring it.
  • Parsing a CRL entry's InvalidityDate extension now rejects a GeneralizedTime that carries fractional seconds or another non-DER form, matching the strict encoding already required for every other X.509 time field.
  • :func:~cryptography.x509.ocsp.load_der_ocsp_request and :func:~cryptography.x509.ocsp.load_der_ocsp_response now reject a request or response whose version field is not v1, the only version defined by RFC 6960, matching the version validation already performed when loading

... (truncated)

Commits

Updates pulumi-azure-native from 3.23.0 to 3.26.0

Release notes

Sourced from pulumi-azure-native's releases.

v3.26.0

Does the PR have any schema changes?

Generated by schema-tools v0.8.1.

Found 45 breaking changes:

Types

  • 🔴 "azure-native:monitor:AzureAppPushReceiver" missing
  • 🔴 "azure-native:monitor:EmailReceiver" missing
  • 🔴 "azure-native:monitor:LogSettings" missing
  • 🔴 "azure-native:monitor:LogSettingsResponse" missing
  • 🔴 "azure-native:monitor:MetricSettings" missing
  • 🔴 "azure-native:monitor:MetricSettingsResponse" missing
  • 🔴 "azure-native:monitor:PrivateEndpointConnectionPrivateLinkScopeResponse" missing
  • 🔴 "azure-native:monitor:RetentionPolicy" missing
  • 🔴 "azure-native:monitor:SmsReceiver" missing
  • 🔴 "azure-native:monitor:VoiceReceiver" missing
  • 🔴 "azure-native:network:CommonAddressSpace" missing
  • 🔴 "azure-native:network:CommonApplicationGatewayIPConfiguration" missing
  • 🔴 "azure-native:network:CommonApplicationSecurityGroup" missing
  • 🔴 "azure-native:network:CommonDelegation" missing
  • 🔴 "azure-native:network:CommonDhcpOptions" missing
  • 🔴 "azure-native:network:CommonExtendedLocation" missing
  • 🔴 "azure-native:network:CommonIpamPoolPrefixAllocation" missing
  • 🔴 "azure-native:network:CommonNetworkSecurityGroup" missing
  • 🔴 "azure-native:network:CommonRoute" missing
  • 🔴 "azure-native:network:CommonRouteTable" missing
  • 🔴 "azure-native:network:CommonSecurityRule" missing
  • 🔴 "azure-native:network:CommonServiceEndpointPolicy" missing
  • 🔴 "azure-native:network:CommonServiceEndpointPolicyDefinition" missing
  • 🔴 "azure-native:network:CommonServiceEndpointPropertiesFormat" missing
  • 🔴 "azure-native:network:CommonSubnet" missing
  • 🔴 "azure-native:network:CommonVirtualNetwork" missing
  • 🔴 "azure-native:network:CommonVirtualNetworkBgpCommunities" missing
  • 🔴 "azure-native:network:CommonVirtualNetworkEncryption" missing
  • 🔴 "azure-native:network:CommonVirtualNetworkPeering" missing
  • 🟡 "azure-native:network:RouteTargetAddressPropertiesFormat":
    • properties:
      • 🟡 "subnet" type changed from "#/types/azure-native:network:CommonSubnet" to "#/types/azure-native:network:Subnet"

Resources

  • 🟡 "azure-native:monitor:ActionGroup":
    • inputs:
      • 🟡 "azureAppPushReceivers" type changed from "#/types/azure-native:monitor:AzureAppPushReceiver" to "#/types/azure-native:monitor:MicrosoftCommonAzureAppPushReceiver"
      • 🟡 "emailReceivers" type changed from "#/types/azure-native:monitor:EmailReceiver" to "#/types/azure-native:monitor:MicrosoftCommonEmailReceiver"
      • 🟡 "smsReceivers" type changed from "#/types/azure-native:monitor:SmsReceiver" to "#/types/azure-native:monitor:MicrosoftCommonSmsReceiver"
      • 🟡 "voiceReceivers" type changed from "#/types/azure-native:monitor:VoiceReceiver" to "#/types/azure-native:monitor:MicrosoftCommonVoiceReceiver"
  • 🟡 "azure-native:monitor:DiagnosticSetting":
    • inputs:

... (truncated)

Commits
  • 653cdfe Skip TestAccKeyVaultTs_ClientCert temporarily (#4794)
  • c60993c Skip TestAccKeyVaultTs_ClientCert temporarily
  • c7b2288 Fix #1684: search.Service hostingMode diffs case-insensitively (#4793)
  • bcfc23e Fix #1684: search.Service hostingMode diffs case-insensitively
  • eaf2575 Add Security DataScanner resource (fixes #4784), bump submodule to latest (#4...
  • 8bc82e7 Add Security DataScanner resource (API version 2026-08-01)
  • 98f2541 Merge branch 'master' into explore/submodule-bump-latest-4784
  • 9a4c901 Fix #2248: deleted ForceNew property still forces a replace (#4789)
  • 8a63a85 Skip TestAzidentity/SP_clientcert until #4791 is resolved
  • 0c96103 Bump azure-rest-api-specs submodule to latest main tip (32dc345ab7, 2026-08-07)
  • Additional commits viewable in compare view

Updates pulumi from 3.254.0 to 3.260.0

Release notes

Sourced from pulumi's releases.

v3.260.0

3.260.0 (2026-08-28)

Features

  • [cli/deployment] Make pulumi deployment settings get render every source kind and show environment variable values, changing the --output=json shape of environmentVariables from a list of names to a list of objects #24284
  • [sdk/go] Support Go 1.27 #24401
  • [cli/state] Add pulumi state promote to turn stateful snippets into Pulumi program code #24453

Bug Fixes

  • [engine] Replace resources whose deletedWith target is being replaced, instead of leaving them orphaned in state #23818
  • [sdk/python] Serialize typed object stack outputs with their wire-format (camelCase) property names, matching other language SDKs #24246
  • [cli/neo] Cancelling a task now interrupts a running local tool call instead of waiting for it to finish #24268
  • [programgen/python] Access schema properties whose names contain hyphens as attributes under their Python names instead of subscripting #24300
  • [programgen/go] Generate valid struct field names for properties whose names contain hyphens #24300
  • [sdkgen/nodejs] Quote property names that are not legal identifiers (e.g. kebab-case) in generated declarations and use bracket access for them #24300
  • [cli/neo] Cancelling a local tool call no longer leaves the TUI stuck on "Thinking..." with input blocked #24318
  • [sdk/go] Use resolved environment names when evaluating ESC imports #24375
  • [codegen/pcl] Allow output-typed values for the id attribute of a read resource #24386
  • [sdkgen/nodejs] Register resolvers for output-only properties in generated Resource.get so they resolve as unknown during preview when the id is unknown #24386
  • [engine] Avoid replacing imported resources when an input changes from plain to a secret or output-wrapped value with the same inner value #24387
  • [backend/diy] Keep DIY backend stacks readable when checkpoint compression transitions fail #24383
  • [cli/stack] Give a clearer error message when selecting a stack by name outside a directory with a Pulumi.yaml project file #24394
  • [sdk/python] Propagate runtime context across thread boundaries #24403
  • [programgen/python] Name plain function input object types without the Args suffix, matching the name the generated SDK exports #24440
  • [cli/new] Reject zip template entries that resolve outside the extraction directory #24447
  • [cli/package] Keep a package's pluginDownloadURL in SDKs regenerated by pulumi install #24432
  • [sdk/python] Preserve all providers passed to remote components in Python programs #24443
  • [sdkgen] Apply schema defaults to generated Python and Node.js function inputs #24452
  • [programgen/python] Mark required component inputs as required in generated Python TypedDicts #24459
  • [programgen/python] Add type annotations for config variables default values coming from invokes #24464
  • [programgen/python] Generate valid Python when a component with inputs instantiates another component #24466
  • [cli/neo] Stop the running local tool immediately when a Neo task is cancelled and report it as cancelled #24470
  • [programgen/python] Support final argument expansion for min and max in Python programs #24471

Improvements

  • [cli] Treat adjacent character swaps as a single typo when suggesting commands #23899
  • [sdk/python] Correctly resolve discriminated unions by their tag #24352
  • [sdk/python] Allow transforms to be mocked #24406
  • [sdk/nodejs] Allow transforms to be mocked #24415
  • [sdk/go] Allow transforms to be mocked #24416
  • [sdkgen] Allow hyphens in the member segment of tokens, so resource, object type and function names can be kebab-case #24440
  • [cli] Print secret provider information with other stack information #24430
  • [auto/python] Allow refresh, preview_refresh, and preview_destroy to request rich diffs #24445
  • [engine] Cache provider mapping results on disk so repeated plans do not boot a provider to re-fetch an unchanged mapping #24462
  • [sdk/python] Improve stack traces for providers #24465

Miscellaneous

... (truncated)

Changelog

Sourced from pulumi's changelog.

3.260.0 (2026-08-28)

Features

  • [cli/deployment] Make pulumi deployment settings get render every source kind and show environment variable values, changing the --output=json shape of environmentVariables from a list of names to a list of objects #24284
  • [sdk/go] Support Go 1.27 #24401
  • [cli/state] Add pulumi state promote to turn stateful snippets into Pulumi program code #24453

Bug Fixes

  • [engine] Replace resources whose deletedWith target is being replaced, instead of leaving them orphaned in state #23818
  • [sdk/python] Serialize typed object stack outputs with their wire-format (camelCase) property names, matching other language SDKs #24246
  • [cli/neo] Cancelling a task now interrupts a running local tool call instead of waiting for it to finish #24268
  • [programgen/python] Access schema properties whose names contain hyphens as attributes under their Python names instead of subscripting #24300
  • [programgen/go] Generate valid struct field names for properties whose names contain hyphens #24300
  • [sdkgen/nodejs] Quote property names that are not legal identifiers (e.g. kebab-case) in generated declarations and use bracket access for them #24300
  • [cli/neo] Cancelling a local tool call no longer leaves the TUI stuck on "Thinking..." with input blocked #24318
  • [sdk/go] Use resolved environment names when evaluating ESC imports #24375
  • [codegen/pcl] Allow output-typed values for the id attribute of a read resource #24386
  • [sdkgen/nodejs] Register resolvers for output-only properties in generated Resource.get so they resolve as unknown during preview when the id is unknown #24386
  • [engine] Avoid replacing imported resources when an input changes from plain to a secret or output-wrapped value with the same inner value #24387
  • [backend/diy] Keep DIY backend stacks readable when checkpoint compression transitions fail #24383
  • [cli/stack] Give a clearer error message when selecting a stack by name outside a directory with a Pulumi.yaml project file #24394
  • [sdk/python] Propagate runtime context across thread boundaries #24403
  • [programgen/python] Name plain function input object types without the Args suffix, matching the name the generated SDK exports #24440
  • [cli/new] Reject zip template entries that resolve outside the extraction directory #24447
  • [cli/package] Keep a package's pluginDownloadURL in SDKs regenerated by pulumi install #24432
  • [sdk/python] Preserve all providers passed to remote components in Python programs #24443
  • [sdkgen] Apply schema defaults to generated Python and Node.js function inputs #24452
  • [programgen/python] Mark required component inputs as required in generated Python TypedDicts #24459
  • [programgen/python] Add type annotations for config variables default values coming from invokes #24464
  • [programgen/python] Generate valid Python when a component with inputs instantiates another component #24466
  • [cli/neo] Stop the running local tool immediately when a Neo task is cancelled and report it as cancelled #24470
  • [programgen/python] Support final argument expansion for min and max in Python programs #24471

Improvements

  • [cli] Treat adjacent character swaps as a single typo when suggesting commands #23899
  • [sdk/python] Correctly resolve discriminated unions by their tag #24352
  • [sdk/python] Allow transforms to be mocked #24406
  • [sdk/nodejs] Allow transforms to be mocked #24415
  • [sdk/go] Allow transforms to be mocked #24416
  • [sdkgen] Allow hyphens in the member segment of tokens, so resource, object type and function names can be kebab-case #24440
  • [cli] Print secret provider information with other stack information #24430
  • [auto/python] Allow refresh, preview_refresh, and preview_destroy to request rich diffs #24445
  • [engine] Cache provider mapping results on disk so repeated plans do not boot a provider to re-fetch an unchanged mapping #24462
  • [sdk/python] Improve stack traces for providers #24465

Miscellaneous

... (truncated)

Commits

Updates pydantic from 2.13.4 to 2.13.5

Release notes

Sourced from pydantic's releases.

v2.13.5 (2026-08-28)

What's Changed

Fixes

  • Allow reuse of validators when plugins are set by @​Viicos in #13535
  • Fix missing GC traversal on some pydantic-core struct fields by @​Viicos in #13624
  • Fix missing GC traversal in pydantic-core for GeneralFieldsSerializer by @​Viicos in #13629
  • Count validated model fields once in smart unions by @​tamird in #13731
Changelog

Sourced from pydantic's changelog.

v2.13.5 (2026-08-28)

GitHub release

What's Changed

Fixes

  • Allow reuse of validators when plugins are set by @​Viicos in #13535
  • Fix missing GC traversal on some pydantic-core struct fields by @​Viicos in #13624
  • Fix missing GC traversal in pydantic-core for GeneralFieldsSerializer by @​Viicos in #13629
  • Count validated model fields once in smart unions by @​tamird in #13731
Commits
  • 001dea0 Bump pypa/gh-action-pypi-publish action to v1.14.2
  • 558379f Bump twine to v7.0.0
  • 2cfd5d3 Do not check for docs build
  • a735bee Fix more Clippy lints
  • 7eed4a1 Fix Clippy 0.1.95 warnings
  • b353bbb Prepare release v2.13.5
  • 63d2ccc Count validated model fields once in smart unions
  • a53ec2e Speed up PyPy CI tests
  • d65e0f9 Workaround circular import error in Mypy
  • 47a6dbf Fix missing GC traversal in pydantic-core for GeneralFieldsSerializer
  • Additional commits viewable in compare view

Updates typer from 0.27.0 to 0.27.2

Release notes

Sourced from typer's releases.

0.27.2

Refactors

  • ♻️ Create exceptions module and TyperException base class. PR #1942 by @​svlandeg.

Docs

  • 🐛 Fix showing fast button as external link in animated terminals in docs. PR #1912 by @​phalberg.

Internal

…ates

Bumps the production-dependencies group with 11 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [azure-keyvault-certificates](https://github.com/Azure/azure-sdk-for-python) | `4.11.1` | `4.11.2` |
| [azure-keyvault-keys](https://github.com/Azure/azure-sdk-for-python) | `4.11.1` | `4.11.2` |
| [azure-keyvault-secrets](https://github.com/Azure/azure-sdk-for-python) | `4.11.0` | `4.11.2` |
| [azure-mgmt-compute](https://github.com/Azure/azure-sdk-for-python) | `38.2.0` | `38.3.0` |
| [azure-storage-blob](https://github.com/Azure/azure-sdk-for-python) | `12.30.0` | `12.30.1` |
| [click](https://github.com/pallets/click) | `8.4.2` | `8.5.0` |
| [cryptography](https://github.com/pyca/cryptography) | `49.0.0` | `50.0.1` |
| [pulumi-azure-native](https://github.com/pulumi/pulumi-azure-native) | `3.23.0` | `3.26.0` |
| [pulumi](https://github.com/pulumi/pulumi) | `3.254.0` | `3.260.0` |
| [pydantic](https://github.com/pydantic/pydantic) | `2.13.4` | `2.13.5` |
| [typer](https://github.com/fastapi/typer) | `0.27.0` | `0.27.2` |



Updates `azure-keyvault-certificates` from 4.11.1 to 4.11.2
- [Release notes](https://github.com/Azure/azure-sdk-for-python/releases)
- [Commits](Azure/azure-sdk-for-python@azure-keyvault-certificates_4.11.1...azure-keyvault-certificates_4.11.2)

Updates `azure-keyvault-keys` from 4.11.1 to 4.11.2
- [Release notes](https://github.com/Azure/azure-sdk-for-python/releases)
- [Commits](Azure/azure-sdk-for-python@azure-keyvault-keys_4.11.1...azure-keyvault-keys_4.11.2)

Updates `azure-keyvault-secrets` from 4.11.0 to 4.11.2
- [Release notes](https://github.com/Azure/azure-sdk-for-python/releases)
- [Commits](Azure/azure-sdk-for-python@azure-keyvault-secrets_4.11.0...azure-keyvault-secrets_4.11.2)

Updates `azure-mgmt-compute` from 38.2.0 to 38.3.0
- [Release notes](https://github.com/Azure/azure-sdk-for-python/releases)
- [Commits](Azure/azure-sdk-for-python@azure-mgmt-compute_38.2.0...azure-mgmt-compute_38.3.0)

Updates `azure-storage-blob` from 12.30.0 to 12.30.1
- [Release notes](https://github.com/Azure/azure-sdk-for-python/releases)
- [Commits](Azure/azure-sdk-for-python@azure-storage-blob_12.30.0...azure-storage-blob_12.30.1)

Updates `click` from 8.4.2 to 8.5.0
- [Release notes](https://github.com/pallets/click/releases)
- [Changelog](https://github.com/pallets/click/blob/main/CHANGES.md)
- [Commits](pallets/click@8.4.2...8.5.0)

Updates `cryptography` from 49.0.0 to 50.0.1
- [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst)
- [Commits](pyca/cryptography@49.0.0...50.0.1)

Updates `pulumi-azure-native` from 3.23.0 to 3.26.0
- [Release notes](https://github.com/pulumi/pulumi-azure-native/releases)
- [Changelog](https://github.com/pulumi/pulumi-azure-native/blob/master/CHANGELOG_OLD.md)
- [Commits](pulumi/pulumi-azure-native@v3.23.0...v3.26.0)

Updates `pulumi` from 3.254.0 to 3.260.0
- [Release notes](https://github.com/pulumi/pulumi/releases)
- [Changelog](https://github.com/pulumi/pulumi/blob/master/CHANGELOG.md)
- [Commits](pulumi/pulumi@v3.254.0...v3.260.0)

Updates `pydantic` from 2.13.4 to 2.13.5
- [Release notes](https://github.com/pydantic/pydantic/releases)
- [Changelog](https://github.com/pydantic/pydantic/blob/v2.13.5/HISTORY.md)
- [Commits](pydantic/pydantic@v2.13.4...v2.13.5)

Updates `typer` from 0.27.0 to 0.27.2
- [Release notes](https://github.com/fastapi/typer/releases)
- [Changelog](https://github.com/fastapi/typer/blob/master/docs/release-notes.md)
- [Commits](fastapi/typer@0.27.0...0.27.2)

---
updated-dependencies:
- dependency-name: azure-keyvault-certificates
  dependency-version: 4.11.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: azure-keyvault-keys
  dependency-version: 4.11.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: azure-keyvault-secrets
  dependency-version: 4.11.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: azure-mgmt-compute
  dependency-version: 38.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: azure-storage-blob
  dependency-version: 12.30.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: click
  dependency-version: 8.5.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: cryptography
  dependency-version: 50.0.1
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: production-dependencies
- dependency-name: pulumi-azure-native
  dependency-version: 3.26.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: pulumi
  dependency-version: 3.260.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: pydantic
  dependency-version: 2.13.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: typer
  dependency-version: 0.27.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update Python code labels Sep 1, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner September 1, 2026 03:57
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update Python code labels Sep 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update Python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants