Skip to content
Permalink

Comparing changes

Choose two branches to see what’s changed or to start a new pull request. If you need to, you can also or learn more about diff comparisons.

Open a pull request

Create a new pull request by comparing changes across two branches. If you need to, you can also . Learn more about diff comparisons here.
base repository: openai/openai-python
Failed to load repositories. Confirm that selected base ref is valid, then try again.
Loading
base: v3.5.0
Choose a base ref
...
head repository: openai/openai-python
Failed to load repositories. Confirm that selected head ref is valid, then try again.
Loading
compare: v3.6.0
Choose a head ref
  • 16 commits
  • 39 files changed
  • 6 contributors

Commits on Aug 27, 2026

  1. ci: add security-aware Dependabot updates for Python and GitHub Actio…

    …ns (#3641)
    
    - [x] I understand that this repository is auto-generated and my pull
    request may not be merged
    
    ## Changes being requested
    
    - Add the missing repository-level Dependabot v2 configuration for the
    root PEP 621 Python project and GitHub Actions workflows.
    - Schedule low-noise Monday UTC updates with separate Python/Actions
    windows, an eight-day cooldown for routine version updates, and
    three/five open-PR limits; security updates remain independently
    eligible without that cooldown.
    - Group Python minor/patch maintenance separately from security
    remediations, and update coupled CodeQL init/analyze actions together
    while leaving unrelated SHA-pinned actions independently reviewable.
    - Avoid a duplicate `uv` updater: the repository installs Rye-generated
    `requirements.lock` and `requirements-dev.lock`, and Dependabot cannot
    regenerate those files. The config explicitly instructs maintainers to
    run `rye lock --all-features` and `uv lock` before merging any Python
    dependency update.
    
    ## Verification
    
    - Parsed the YAML and validated it against the current Dependabot v2
    JSON Schema.
    - Validated exact supported ecosystems, root manifest discovery,
    staggered weekly schedules, cooldowns, PR limits, maintenance/security
    group semantics, CodeQL grouping, and absence of
    reviewers/assignees/target-branch overrides.
    - Confirmed all eight runtime dependencies satisfy `pyproject.toml`
    across `uv.lock`, `requirements.lock`, and `requirements-dev.lock`;
    verified the existing uv lockfile is structurally valid offline.
    - Verified all 46 GitHub Actions references remain pinned to full commit
    SHAs and both PyPI release workflows retain isolated build/upload jobs
    and publishing-only OIDC.
    - `python scripts/check-python-version-policy.py`
    - `git diff origin/main...HEAD --check`
    
    ## Additional context & links
    
    Only `.github/dependabot.yml` is added. Rye-only development
    dependencies and Rye lock regeneration remain manual because Dependabot
    has no supported Rye ecosystem.
    HAYDEN-OAI authored Aug 27, 2026
    Configuration menu
    Copy the full SHA
    f3f9631 View commit details
    Browse the repository at this point in the history
  2. ci: remove the Agents SDK downstream check (#3750)

    ## Summary
    
    Remove the Agents SDK compatibility check from this repository's CI,
    matching
    [openai-node#2033](openai/openai-node#2033).
    Downstream compatibility is useful signal, but it belongs outside the
    SDK repository, where failures can be handled without holding up
    unrelated SDK changes.
    
    Intentional type changes can create a chicken-and-egg problem: Agents
    needs the SDK change before it can adapt, while SDK CI waits for Agents
    to compile. Requiring a pinned downstream checkout also adds ongoing
    maintenance and can keep reporting incompatibilities that Agents has
    already fixed.
    
    This removes the Agents job, its dedicated pins and build exceptions,
    and the tests that only supported it. The SDK's own breaking-change
    checks and dependency protections remain unchanged.
    
    For security reasons we added pins in
    #3641 but makes it very
    difficult to maintain this check
    apcha-oai authored Aug 27, 2026
    Configuration menu
    Copy the full SHA
    910b316 View commit details
    Browse the repository at this point in the history
  3. feat(api): add compute_units to Responses and Chat Completions usage (#…

    …3749)
    
    Adds `compute_units` to Responses and Chat Completions usage.
    
    Co-authored-by: apcha-oai <228803254+apcha-oai@users.noreply.github.com>
    apcha-oai and apcha-oai authored Aug 27, 2026
    Configuration menu
    Copy the full SHA
    52421d1 View commit details
    Browse the repository at this point in the history
  4. ci: make dependency guards portable to macOS Bash (#3751)

    ## Summary
    
    Make the dependency workflow's guards behave consistently on macOS and
    Linux so contributors can run the same checks locally that run in CI.
    
    macOS ships Bash 3.2, which does not stop at a failed `[[ ... ]]` guard
    just because `set -e` is enabled. This causes three existing rejection
    tests to fail locally even though they pass on Linux. Exit explicitly
    when a guard fails, keeping the accepted base SHAs and repository URLs
    unchanged.
    apcha-oai authored Aug 27, 2026
    Configuration menu
    Copy the full SHA
    550c7c1 View commit details
    Browse the repository at this point in the history
  5. fix(auth): harden X.509 workload identity integration (#3740)

    ## Summary
    
    - Make X.509 workload identity consistent across synchronous and
    asynchronous clients, supported data-residency regions, client copies,
    and explicit authentication configuration.
    - Preserve caller-owned HTTP clients, request hooks, custom HTTPS
    origins and TLS configuration, retry behavior, token refresh, and
    request replay compatibility.
    - Add focused synchronous, asynchronous, concurrent, legacy-HTTPX, and
    workload-identity regression coverage without changing the public API or
    custom-code budget policy.
    
    ## Validation
    
    - Full repository tests: **9,425 passed, 32 skipped**.
    - Focused X.509 and compatibility tests: **340 passed, 2 skipped**.
    - Legacy HTTPX compatibility tests: **137 passed**.
    - Large-payload compatibility regression passed.
    - Ruff, whole-repository pyright, and mypy across 1,576 files passed.
    - Wheel and source distributions built successfully; package metadata
    and Bedrock packaging validated.
    - Existing custom-code budget passed: **6,574 / 10,000**.
    jbeckwith-oai authored Aug 27, 2026
    Configuration menu
    Copy the full SHA
    fc3ad6c View commit details
    Browse the repository at this point in the history
  6. chore(deps): bump actions/download-artifact from 6.0.0 to 8.0.1 (#3669)

    Bumps
    [actions/download-artifact](https://github.com/actions/download-artifact)
    from 6.0.0 to 8.0.1.
    <details>
    <summary>Release notes</summary>
    <p><em>Sourced from <a
    href="https://github.com/actions/download-artifact/releases">actions/download-artifact's
    releases</a>.</em></p>
    <blockquote>
    <h2>v8.0.1</h2>
    <h2>What's Changed</h2>
    <ul>
    <li>Support for CJK characters in the artifact name by <a
    href="https://github.com/danwkennedy"><code>@​danwkennedy</code></a> in
    <a
    href="https://redirect.github.com/actions/download-artifact/pull/471">actions/download-artifact#471</a></li>
    <li>Add a regression test for artifact name + content-type mismatches by
    <a href="https://github.com/danwkennedy"><code>@​danwkennedy</code></a>
    in <a
    href="https://redirect.github.com/actions/download-artifact/pull/472">actions/download-artifact#472</a></li>
    </ul>
    <p><strong>Full Changelog</strong>: <a
    href="https://github.com/actions/download-artifact/compare/v8...v8.0.1">https://github.com/actions/download-artifact/compare/v8...v8.0.1</a></p>
    <h2>v8.0.0</h2>
    <h2>v8 - What's new</h2>
    <blockquote>
    <p>[!IMPORTANT]
    actions/download-artifact@v8 has been migrated to an ESM module. This
    should be transparent to the caller but forks might need to make
    significant changes.</p>
    </blockquote>
    <blockquote>
    <p>[!IMPORTANT]
    Hash mismatches will now error by default. Users can override this
    behavior with a setting change (see below).</p>
    </blockquote>
    <h3>Direct downloads</h3>
    <p>To support direct uploads in <code>actions/upload-artifact</code>,
    the action will no longer attempt to unzip all downloaded files.
    Instead, the action checks the <code>Content-Type</code> header ahead of
    unzipping and skips non-zipped files. Callers wishing to download a
    zipped file as-is can also set the new <code>skip-decompress</code>
    parameter to <code>true</code>.</p>
    <h3>Enforced checks (breaking)</h3>
    <p>A previous release introduced digest checks on the download. If a
    download hash didn't match the expected hash from the server, the action
    would log a warning. Callers can now configure the behavior on mismatch
    with the <code>digest-mismatch</code> parameter. To be secure by
    default, we are now defaulting the behavior to <code>error</code> which
    will fail the workflow run.</p>
    <h3>ESM</h3>
    <p>To support new versions of the @actions/* packages, we've upgraded
    the package to ESM.</p>
    <h2>What's Changed</h2>
    <ul>
    <li>Don't attempt to un-zip non-zipped downloads by <a
    href="https://github.com/danwkennedy"><code>@​danwkennedy</code></a> in
    <a
    href="https://redirect.github.com/actions/download-artifact/pull/460">actions/download-artifact#460</a></li>
    <li>Add a setting to specify what to do on hash mismatch and default it
    to <code>error</code> by <a
    href="https://github.com/danwkennedy"><code>@​danwkennedy</code></a> in
    <a
    href="https://redirect.github.com/actions/download-artifact/pull/461">actions/download-artifact#461</a></li>
    </ul>
    <p><strong>Full Changelog</strong>: <a
    href="https://github.com/actions/download-artifact/compare/v7...v8.0.0">https://github.com/actions/download-artifact/compare/v7...v8.0.0</a></p>
    <h2>v7.0.0</h2>
    <h2>v7 - What's new</h2>
    <blockquote>
    <p>[!IMPORTANT]
    actions/download-artifact@v7 now runs on Node.js 24 (<code>runs.using:
    node24</code>) and requires a minimum Actions Runner version of 2.327.1.
    If you are using self-hosted runners, ensure they are updated before
    upgrading.</p>
    </blockquote>
    <h3>Node.js 24</h3>
    <p>This release updates the runtime to Node.js 24. v6 had preliminary
    support for Node 24, however this action was by default still running on
    Node.js 20. Now this action by default will run on Node.js 24.</p>
    <h2>What's Changed</h2>
    <ul>
    <li>Update GHES guidance to include reference to Node 20 version by <a
    href="https://github.com/patrikpolyak"><code>@​patrikpolyak</code></a>
    in <a
    href="https://redirect.github.com/actions/download-artifact/pull/440">actions/download-artifact#440</a></li>
    <li>Download Artifact Node24 support by <a
    href="https://github.com/salmanmkc"><code>@​salmanmkc</code></a> in <a
    href="https://redirect.github.com/actions/download-artifact/pull/415">actions/download-artifact#415</a></li>
    <li>fix: update <code>@​actions/artifact</code> to fix Node.js 24
    punycode deprecation by <a
    href="https://github.com/salmanmkc"><code>@​salmanmkc</code></a> in <a
    href="https://redirect.github.com/actions/download-artifact/pull/451">actions/download-artifact#451</a></li>
    <li>prepare release v7.0.0 for Node.js 24 support by <a
    href="https://github.com/salmanmkc"><code>@​salmanmkc</code></a> in <a
    href="https://redirect.github.com/actions/download-artifact/pull/452">actions/download-artifact#452</a></li>
    </ul>
    <!-- raw HTML omitted -->
    </blockquote>
    <p>... (truncated)</p>
    </details>
    <details>
    <summary>Commits</summary>
    <ul>
    <li><a
    href="https://github.com/actions/download-artifact/commit/3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c"><code>3e5f45b</code></a>
    Add regression tests for CJK characters (<a
    href="https://redirect.github.com/actions/download-artifact/issues/471">#471</a>)</li>
    <li><a
    href="https://github.com/actions/download-artifact/commit/e6d03f67377d4412c7aa56a8e2e4988e6ec479dd"><code>e6d03f6</code></a>
    Add a regression test for artifact name + content-type mismatches (<a
    href="https://redirect.github.com/actions/download-artifact/issues/472">#472</a>)</li>
    <li><a
    href="https://github.com/actions/download-artifact/commit/70fc10c6e5e1ce46ad2ea6f2b72d43f7d47b13c3"><code>70fc10c</code></a>
    Merge pull request <a
    href="https://redirect.github.com/actions/download-artifact/issues/461">#461</a>
    from actions/danwkennedy/digest-mismatch-behavior</li>
    <li><a
    href="https://github.com/actions/download-artifact/commit/f258da9a506b755b84a09a531814700b86ccfc62"><code>f258da9</code></a>
    Add change docs</li>
    <li><a
    href="https://github.com/actions/download-artifact/commit/ccc058e5fbb0bb2352213eaec3491e117cbc4a5c"><code>ccc058e</code></a>
    Fix linting issues</li>
    <li><a
    href="https://github.com/actions/download-artifact/commit/bd7976ba57ecea96e6f3df575eb922d11a12a9fd"><code>bd7976b</code></a>
    Add a setting to specify what to do on hash mismatch and default it to
    <code>error</code></li>
    <li><a
    href="https://github.com/actions/download-artifact/commit/ac21fcf45e0aaee541c0f7030558bdad38d77d6c"><code>ac21fcf</code></a>
    Merge pull request <a
    href="https://redirect.github.com/actions/download-artifact/issues/460">#460</a>
    from actions/danwkennedy/download-no-unzip</li>
    <li><a
    href="https://github.com/actions/download-artifact/commit/15999bff51058bc7c19b50ebbba518eaef7c26c0"><code>15999bf</code></a>
    Add note about package bumps</li>
    <li><a
    href="https://github.com/actions/download-artifact/commit/974686ed5098c7f9c9289ec946b9058e496a2561"><code>974686e</code></a>
    Bump the version to <code>v8</code> and add release notes</li>
    <li><a
    href="https://github.com/actions/download-artifact/commit/fbe48b1d2756394be4cd4358ed3bc1343b330e75"><code>fbe48b1</code></a>
    Update test names to make it clearer what they do</li>
    <li>Additional commits viewable in <a
    href="https://github.com/actions/download-artifact/compare/v6...3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c">compare
    view</a></li>
    </ul>
    </details>
    <br />
    
    Signed-off-by: dependabot[bot] <support@github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    dependabot[bot] authored Aug 27, 2026
    Configuration menu
    Copy the full SHA
    f627619 View commit details
    Browse the repository at this point in the history
  7. build(deps): bump actions/setup-python from 5.6.0 to 7.0.0 (#3672)

    Bumps [actions/setup-python](https://github.com/actions/setup-python)
    from 5.6.0 to 7.0.0.
    <details>
    <summary>Release notes</summary>
    <p><em>Sourced from <a
    href="https://github.com/actions/setup-python/releases">actions/setup-python's
    releases</a>.</em></p>
    <blockquote>
    <h2>v7.0.0</h2>
    <h2>What's Changed</h2>
    <h3>Enhancements</h3>
    <ul>
    <li>Migrate to ESM and upgrade dependencies by <a
    href="https://github.com/priyagupta108"><code>@​priyagupta108</code></a>
    in <a
    href="https://redirect.github.com/actions/setup-python/pull/1330">actions/setup-python#1330</a></li>
    <li>Pin SHA commits and update docs with latest versions by <a
    href="https://github.com/HarithaVattikuti"><code>@​HarithaVattikuti</code></a>
    in <a
    href="https://redirect.github.com/actions/setup-python/pull/1338">actions/setup-python#1338</a></li>
    <li>Remove the pip-install input by <a
    href="https://github.com/gowridurgad"><code>@​gowridurgad</code></a> in
    <a
    href="https://redirect.github.com/actions/setup-python/pull/1336">actions/setup-python#1336</a></li>
    </ul>
    <h3>Bug Fix</h3>
    <ul>
    <li>Fix to Classify stderr warning messages as warnings instead of
    errors in annotations by <a
    href="https://github.com/lmvysakh"><code>@​lmvysakh</code></a> in <a
    href="https://redirect.github.com/actions/setup-python/pull/1335">actions/setup-python#1335</a></li>
    <li>Validate and retry manifest fetch to prevent silent failures by <a
    href="https://github.com/priyagupta108"><code>@​priyagupta108</code></a>
    in <a
    href="https://redirect.github.com/actions/setup-python/pull/1332">actions/setup-python#1332</a></li>
    </ul>
    <h3>Dependency Upgrade</h3>
    <ul>
    <li>Bump certifi from 2020.6.20 to 2024.7.4 in
    /<strong>tests</strong>/data by <a
    href="https://github.com/dependabot"><code>@​dependabot</code></a> in <a
    href="https://redirect.github.com/actions/setup-python/pull/1328">actions/setup-python#1328</a></li>
    <li>Remove EOL Python versions and Bumps numpy text fixture by <a
    href="https://github.com/priya-kinthali"><code>@​priya-kinthali</code></a>
    in <a
    href="https://redirect.github.com/actions/setup-python/pull/1333">actions/setup-python#1333</a></li>
    <li>Upgrade <code>@​actions/cache</code> to 6.2.0 by <a
    href="https://github.com/philip-gai"><code>@​philip-gai</code></a> in <a
    href="https://redirect.github.com/actions/setup-python/pull/1337">actions/setup-python#1337</a></li>
    </ul>
    <h2>New Contributors</h2>
    <ul>
    <li><a href="https://github.com/lmvysakh"><code>@​lmvysakh</code></a>
    made their first contribution in <a
    href="https://redirect.github.com/actions/setup-python/pull/1335">actions/setup-python#1335</a></li>
    <li><a
    href="https://github.com/philip-gai"><code>@​philip-gai</code></a> made
    their first contribution in <a
    href="https://redirect.github.com/actions/setup-python/pull/1337">actions/setup-python#1337</a></li>
    </ul>
    <p><strong>Full Changelog</strong>: <a
    href="https://github.com/actions/setup-python/compare/v6...v7.0.0">https://github.com/actions/setup-python/compare/v6...v7.0.0</a></p>
    <h2>v6.3.0</h2>
    <h2>What's Changed</h2>
    <h3>Enhancement</h3>
    <ul>
    <li>Add RHEL support and include Linux distro in cache keys by <a
    href="https://github.com/priyagupta108"><code>@​priyagupta108</code></a>
    in <a
    href="https://redirect.github.com/actions/setup-python/pull/1323">actions/setup-python#1323</a></li>
    <li>Fix pip cache error handling on Windows by <a
    href="https://github.com/priyagupta108"><code>@​priyagupta108</code></a>
    in <a
    href="https://redirect.github.com/actions/setup-python/pull/1040">actions/setup-python#1040</a></li>
    </ul>
    <h3>Dependency update</h3>
    <ul>
    <li>Upgrade minimatch from 3.1.2 to 3.1.5 by <a
    href="https://github.com/dependabot"><code>@​dependabot</code></a> in <a
    href="https://redirect.github.com/actions/setup-python/pull/1281">actions/setup-python#1281</a></li>
    <li>Upgrade actions dependencies by <a
    href="https://github.com/gowridurgad"><code>@​gowridurgad</code></a>
    with <a href="https://github.com/Copilot"><code>@​Copilot</code></a> in
    <a
    href="https://redirect.github.com/actions/setup-python/pull/1303">actions/setup-python#1303</a></li>
    <li>Upgrade <code>@​actions/cache</code> to 5.1.0, log cache write
    denied by <a
    href="https://github.com/jasongin"><code>@​jasongin</code></a> in <a
    href="https://redirect.github.com/actions/setup-python/pull/1324">actions/setup-python#1324</a></li>
    <li>Upgrade dependency versions and test workflow configuration by <a
    href="https://github.com/HarithaVattikuti"><code>@​HarithaVattikuti</code></a>
    in <a
    href="https://redirect.github.com/actions/setup-python/pull/1322">actions/setup-python#1322</a></li>
    </ul>
    <h3>Documentation</h3>
    <ul>
    <li>Update advanced-usage.md by <a
    href="https://github.com/Dunky-Z"><code>@​Dunky-Z</code></a> in <a
    href="https://redirect.github.com/actions/setup-python/pull/811">actions/setup-python#811</a></li>
    </ul>
    <h2>New Contributors</h2>
    <ul>
    <li><a
    href="https://github.com/gowridurgad"><code>@​gowridurgad</code></a>
    with <a href="https://github.com/Copilot"><code>@​Copilot</code></a>
    made their first contribution in <a
    href="https://redirect.github.com/actions/setup-python/pull/1303">actions/setup-python#1303</a></li>
    <li><a href="https://github.com/jasongin"><code>@​jasongin</code></a>
    made their first contribution in <a
    href="https://redirect.github.com/actions/setup-python/pull/1324">actions/setup-python#1324</a></li>
    <li><a href="https://github.com/Dunky-Z"><code>@​Dunky-Z</code></a> made
    their first contribution in <a
    href="https://redirect.github.com/actions/setup-python/pull/811">actions/setup-python#811</a></li>
    </ul>
    <p><strong>Full Changelog</strong>: <a
    href="https://github.com/actions/setup-python/compare/v6.2.0...v6.3.0">https://github.com/actions/setup-python/compare/v6.2.0...v6.3.0</a></p>
    <h2>v6.2.0</h2>
    <h2>What's Changed</h2>
    <h3>Dependency Upgrades</h3>
    <ul>
    <li>Upgrade dependencies to Node 24 compatible versions by <a
    href="https://github.com/salmanmkc"><code>@​salmanmkc</code></a> in <a
    href="https://redirect.github.com/actions/setup-python/pull/1259">actions/setup-python#1259</a></li>
    </ul>
    <!-- raw HTML omitted -->
    </blockquote>
    <p>... (truncated)</p>
    </details>
    <details>
    <summary>Commits</summary>
    <ul>
    <li><a
    href="https://github.com/actions/setup-python/commit/5fda3b95a4ea91299a34e894583c3862153e4b97"><code>5fda3b9</code></a>
    Pin SHA commits and update docs with latest versions (<a
    href="https://redirect.github.com/actions/setup-python/issues/1338">#1338</a>)</li>
    <li><a
    href="https://github.com/actions/setup-python/commit/4ab7e95f05e168b4356aebde89dd84f59c283d8e"><code>4ab7e95</code></a>
    Merge pull request <a
    href="https://redirect.github.com/actions/setup-python/issues/1337">#1337</a>
    from actions/philip-gai/bump-actions-cache-6-2-0</li>
    <li><a
    href="https://github.com/actions/setup-python/commit/0f3a009f475dbea83c0371cd85d099690fee8c5c"><code>0f3a009</code></a>
    Remove the pip-install input (<a
    href="https://redirect.github.com/actions/setup-python/issues/1336">#1336</a>)</li>
    <li><a
    href="https://github.com/actions/setup-python/commit/f8cf4291c8b8e273ddd26e569454615c7315d932"><code>f8cf429</code></a>
    Migrate to ESM and upgrade dependencies (<a
    href="https://redirect.github.com/actions/setup-python/issues/1330">#1330</a>)</li>
    <li><a
    href="https://github.com/actions/setup-python/commit/54baeea5b34417d10a7479663a23cca53ea209b5"><code>54baeea</code></a>
    Validate and retry manifest fetch to prevent silent failures (<a
    href="https://redirect.github.com/actions/setup-python/issues/1332">#1332</a>)</li>
    <li><a
    href="https://github.com/actions/setup-python/commit/c7092773a316760f4ecfe498e4af668a4dafeac5"><code>c709277</code></a>
    Annotation code fix (<a
    href="https://redirect.github.com/actions/setup-python/issues/1335">#1335</a>)</li>
    <li><a
    href="https://github.com/actions/setup-python/commit/6849080452e69b330395e8a6d23cf90f56d76a1a"><code>6849080</code></a>
    remove EOL Python versions and Bumps numpy text fixture (<a
    href="https://redirect.github.com/actions/setup-python/issues/1333">#1333</a>)</li>
    <li><a
    href="https://github.com/actions/setup-python/commit/0903b469fbf4441aadfe4f4b249dc5b1fba3a73e"><code>0903b46</code></a>
    Bump certifi from 2020.6.20 to 2024.7.4 in /<strong>tests</strong>/data
    (<a
    href="https://redirect.github.com/actions/setup-python/issues/1328">#1328</a>)</li>
    <li><a
    href="https://github.com/actions/setup-python/commit/ece7cb06caefa5fff74198d8649806c4678c61a1"><code>ece7cb0</code></a>
    Fix pip cache error handling on Windows. (<a
    href="https://redirect.github.com/actions/setup-python/issues/1040">#1040</a>)</li>
    <li><a
    href="https://github.com/actions/setup-python/commit/1d18d7af5f767c1259ede05a0a5bcc30f3dcf1cf"><code>1d18d7a</code></a>
    Update advanced-usage.md (<a
    href="https://redirect.github.com/actions/setup-python/issues/811">#811</a>)</li>
    <li>Additional commits viewable in <a
    href="https://github.com/actions/setup-python/compare/a26af69be951a213d495a4c3e4e4022e16d87065...5fda3b95a4ea91299a34e894583c3862153e4b97">compare
    view</a></li>
    </ul>
    </details>
    <br />
    
    
    [![Dependabot compatibility
    score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=actions/setup-python&package-manager=github_actions&previous-version=5.6.0&new-version=7.0.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
    
    Dependabot will resolve any conflicts with this PR as long as you don't
    alter it yourself. You can also trigger a rebase manually by commenting
    `@dependabot rebase`.
    
    [//]: # (dependabot-automerge-start)
    [//]: # (dependabot-automerge-end)
    
    ---
    
    <details>
    <summary>Dependabot commands and options</summary>
    <br />
    
    You can trigger Dependabot actions by commenting on this PR:
    - `@dependabot rebase` will rebase this PR
    - `@dependabot recreate` will recreate this PR, overwriting any edits
    that have been made to it
    - `@dependabot show <dependency name> ignore conditions` will show all
    of the ignore conditions of the specified dependency
    - `@dependabot ignore this major version` will close this PR and stop
    Dependabot creating any more for this major version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this minor version` will close this PR and stop
    Dependabot creating any more for this minor version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this dependency` will close this PR and stop
    Dependabot creating any more for this dependency (unless you reopen the
    PR or upgrade to it yourself)
    
    
    </details>
    
    <!-- Trigger the trusted Castiron checks for the reviewed PR head. -->
    
    Signed-off-by: dependabot[bot] <support@github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    Co-authored-by: Justin Beckwith <jbeckwith@openai.com>
    dependabot[bot] and jbeckwith-oai authored Aug 27, 2026
    Configuration menu
    Copy the full SHA
    d765db7 View commit details
    Browse the repository at this point in the history
  8. build(deps): bump pypa/gh-action-pypi-publish from 1.14.0 to 1.14.2 (#…

    …3666)
    
    Bumps
    [pypa/gh-action-pypi-publish](https://github.com/pypa/gh-action-pypi-publish)
    from 1.14.0 to 1.14.2.
    <details>
    <summary>Release notes</summary>
    <p><em>Sourced from <a
    href="https://github.com/pypa/gh-action-pypi-publish/releases">pypa/gh-action-pypi-publish's
    releases</a>.</em></p>
    <blockquote>
    <h2>v1.14.2</h2>
    <!-- raw HTML omitted -->
    <h2>🛠️ Urgh… Another release!? Again? Explain yourself!</h2>
    <p>Looking at the diff, you'll only witness updates across the
    dependency tree. That's it! It's not a security fix or anything like
    that even, no. But you'll want this update.</p>
    <blockquote>
    <p>[!tip]
    So what <em>most</em> people will find useful is <a
    href="https://github.com/takluyver"><code>@​takluyver</code></a><a
    href="https://github.com/sponsors/takluyver">💰</a>'s update of Twine to
    v7 that we use internally (<a
    href="https://redirect.github.com/pypa/gh-action-pypi-publish/issues/416">#416</a>).
    This version will let them upload their sdists and wheels containing
    core packaging metadata v2.5 to (Test)PyPI.</p>
    </blockquote>
    <h2>🧐 Tell me why..</h2>
    <!-- raw HTML omitted -->
    <!-- raw HTML omitted -->
    <p>TL;DR non-pure-python projects with C-extensions tend to have dozens
    (sometimes hundreds) wheels to upload to PyPI per release. They are
    often quite big and take time to transfer over the network. People
    started noticing problems and coming up with DIY sharding workarounds
    like <a
    href="https://redirect.github.com/aio-libs/aiohttp/pull/13226">aio-libs/aiohttp#13226</a>
    around July 23.
    On this date, projects with a good amount of bytes to publish would
    start getting timeouts 5 minutes after the PyPI publishing job begun.
    The same job that worked just fine before.</p>
    <p>I had to start pinging upstream library and ecosystem people, on
    GitHub and privately, to start making sense of what was happening.
    Eventually, we collectively concluded that GitHub must've shortened the
    lifetime of their OIDC identity — it seems to have used to be 10 minutes
    long (at some point in the past) and is now 5 minutes, apparently. It's
    not documented clearly, and we have not been able to get any clarity by
    attempting to contact GitHub through private channels, using personal
    connections.</p>
    <p>Over the course of investigation, <a
    href="https://github.com/facutuesca"><code>@​facutuesca</code></a><a
    href="https://github.com/sponsors/facutuesca">💰</a> found and fixed a
    related underlying cache invalidation bug in <a
    href="https://redirect.github.com/sigstore/sigstore-python/pull/1838">sigstore/sigstore-python#1838</a>,
    which he then coordinated propagation through the dependency chain
    updates in sigstore-python, pypi-attestations, gh-action-pypi-publish
    and gh-action-sigstore-python.</p>
    <p>Mike's also discovered that Sigstore's Rekor slowdown seems to have
    become the main contributing cause of the last week's incident. He's
    collected some data to support this claim: <a
    href="https://publishing-five-minute-timeout.tiiny.site">https://publishing-five-minute-timeout.tiiny.site</a>.</p>
    <!-- raw HTML omitted -->
    <!-- raw HTML omitted -->
    <h2>🫶 New Contributors</h2>
    <ul>
    <li><a
    href="https://github.com/davidbrochart"><code>@​davidbrochart</code></a>
    made their first contribution in <a
    href="https://redirect.github.com/pypa/gh-action-pypi-publish/issues/415">#415</a></li>
    <li><a href="https://github.com/takluyver"><code>@​takluyver</code></a>
    made their first contribution in <a
    href="https://redirect.github.com/pypa/gh-action-pypi-publish/issues/416">#416</a></li>
    </ul>
    <p><strong>🪞 Full Diff</strong>: <a
    href="https://github.com/pypa/gh-action-pypi-publish/compare/v1.14.1...v1.14.2">https://github.com/pypa/gh-action-pypi-publish/compare/v1.14.1...v1.14.2</a></p>
    <p><strong>🧔‍♂️ Release Manager:</strong> <a
    href="https://github.com/sponsors/webknjaz"><code>@​webknjaz</code></a>
    <a href="https://stand-with-ukraine.pp.ua">🇺🇦</a></p>
    <p><strong>🙏 Special Thanks</strong> to <a
    href="https://github.com/davidbrochart"><code>@​davidbrochart</code></a><a
    href="https://github.com/sponsors/davidbrochart">💰</a> and <a
    href="https://github.com/Dreamsorcerer"><code>@​Dreamsorcerer</code></a><a
    href="https://github.com/sponsors/Dreamsorcerer">💰</a> for turning my
    attention (in <a
    href="https://redirect.github.com/pypa/gh-action-pypi-publish/issues/415">#415</a>
    and in private) to the newly surfaced corner case in GitHub's behavior
    that only affected a narrow category of projects while many others
    remained blissfully unaware. <a
    href="https://github.com/bdraco"><code>@​bdraco</code></a><a
    href="https://github.com/sponsors/bdraco">💰</a> came up with a DIY
    sharding workaround for aiohttp that served as a demo for other
    projects. <a
    href="https://github.com/miketheman"><code>@​miketheman</code></a><a
    href="https://github.com/sponsors/miketheman">💰</a> confirmed the
    Warehouse-side details. Also, <a
    href="https://github.com/jku"><code>@​jku</code></a><a
    href="https://github.com/sponsors/jku">💰</a> and <a
    href="https://github.com/woodruffw"><code>@​woodruffw</code></a><a
    href="https://github.com/sponsors/woodruffw">💰</a> helped work through,
    review and release the Sigstore ecosystem upstream libs.</p>
    <p><strong>💬 Discuss</strong> <a
    href="https://bsky.app/profile/did:plc:ve6s3mxkefjaxty3m4fdqumn/post/3mrsqy2xba22j">on
    Bluesky 🦋</a>, <a
    href="https://mastodon.social/@webknjaz/117005132816750073">on Mastodon
    🐘</a> and [on GitHub][release discussion].</p>
    <p>[![GH Sponsors badge]][GH Sponsors URL]</p>
    <!-- raw HTML omitted -->
    </blockquote>
    <p>... (truncated)</p>
    </details>
    <details>
    <summary>Commits</summary>
    <ul>
    <li><a
    href="https://github.com/pypa/gh-action-pypi-publish/commit/dc37677b2e1c63e2034f94d8a5b11f265b73ba33"><code>dc37677</code></a>
    Merge pull request <a
    href="https://redirect.github.com/pypa/gh-action-pypi-publish/issues/417">#417</a>
    from trail-of-forks/ft/bump-deps</li>
    <li><a
    href="https://github.com/pypa/gh-action-pypi-publish/commit/8b2f23418f024937cf97f77534a597947105e772"><code>8b2f234</code></a>
    Bump <code>pypi-attestations</code> and <code>sigstore</code></li>
    <li><a
    href="https://github.com/pypa/gh-action-pypi-publish/commit/78b72dbfed6e025eb89577c059edc936f8a2df14"><code>78b72db</code></a>
    Merge pull request <a
    href="https://redirect.github.com/pypa/gh-action-pypi-publish/issues/416">#416</a>
    from takluyver/twine-v7</li>
    <li><a
    href="https://github.com/pypa/gh-action-pypi-publish/commit/92f4d2a159875dd135a7e56b7b3262f502b23a13"><code>92f4d2a</code></a>
    Update twine to v7</li>
    <li><a
    href="https://github.com/pypa/gh-action-pypi-publish/commit/ba38be9e461d3875417946c167d0b5f3d385a247"><code>ba38be9</code></a>
    Merge pull request <a
    href="https://redirect.github.com/pypa/gh-action-pypi-publish/issues/408">#408</a>
    from adisivaprasad/bump-setup-python-v6</li>
    <li><a
    href="https://github.com/pypa/gh-action-pypi-publish/commit/a6c5088d60d08ef54b70075735d25df696e5ccaa"><code>a6c5088</code></a>
    Bump actions/setup-python from v5.6.0 to v6.2.0</li>
    <li>See full diff in <a
    href="https://github.com/pypa/gh-action-pypi-publish/compare/cef221092ed1bacb1cc03d23a2d87d1d172e277b...dc37677b2e1c63e2034f94d8a5b11f265b73ba33">compare
    view</a></li>
    </ul>
    </details>
    <br />
    
    
    [![Dependabot compatibility
    score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=pypa/gh-action-pypi-publish&package-manager=github_actions&previous-version=1.14.0&new-version=1.14.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
    
    Dependabot will resolve any conflicts with this PR as long as you don't
    alter it yourself. You can also trigger a rebase manually by commenting
    `@dependabot rebase`.
    
    [//]: # (dependabot-automerge-start)
    [//]: # (dependabot-automerge-end)
    
    ---
    
    <details>
    <summary>Dependabot commands and options</summary>
    <br />
    
    You can trigger Dependabot actions by commenting on this PR:
    - `@dependabot rebase` will rebase this PR
    - `@dependabot recreate` will recreate this PR, overwriting any edits
    that have been made to it
    - `@dependabot show <dependency name> ignore conditions` will show all
    of the ignore conditions of the specified dependency
    - `@dependabot ignore this major version` will close this PR and stop
    Dependabot creating any more for this major version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this minor version` will close this PR and stop
    Dependabot creating any more for this minor version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this dependency` will close this PR and stop
    Dependabot creating any more for this dependency (unless you reopen the
    PR or upgrade to it yourself)
    
    
    </details>
    
    <!-- castiron-required-check-refresh: 2026-08-27 -->
    
    Signed-off-by: dependabot[bot] <support@github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    dependabot[bot] authored Aug 27, 2026
    Configuration menu
    Copy the full SHA
    dacbb66 View commit details
    Browse the repository at this point in the history
  9. chore(deps): bump actions/checkout from 6.0.2 to 7.0.1 (#3665)

    Bumps [actions/checkout](https://github.com/actions/checkout) from 6.0.2
    to 7.0.1.
    <details>
    <summary>Release notes</summary>
    <p><em>Sourced from <a
    href="https://github.com/actions/checkout/releases">actions/checkout's
    releases</a>.</em></p>
    <blockquote>
    <h2>v7.0.1</h2>
    <h2>What's Changed</h2>
    <ul>
    <li>skip running unsafe pr check if input is default by <a
    href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2518">actions/checkout#2518</a></li>
    <li>trim only ascii whitespace for branch by <a
    href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2521">actions/checkout#2521</a></li>
    <li>escape values passed to --unset by <a
    href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2530">actions/checkout#2530</a></li>
    <li>Various dependency updates</li>
    </ul>
    <p><strong>Full Changelog</strong>: <a
    href="https://github.com/actions/checkout/compare/v7...v7.0.1">https://github.com/actions/checkout/compare/v7...v7.0.1</a></p>
    <h2>v7.0.0</h2>
    <h2>What's Changed</h2>
    <ul>
    <li>block checking out fork pr for pull_request_target and workflow_run
    by <a href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2454">actions/checkout#2454</a></li>
    <li>Bump actions/publish-immutable-action from 0.0.3 to 0.0.4 in the
    minor-actions-dependencies group across 1 directory by <a
    href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
    in <a
    href="https://redirect.github.com/actions/checkout/pull/2458">actions/checkout#2458</a></li>
    <li>Bump flatted from 3.3.1 to 3.4.2 by <a
    href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
    in <a
    href="https://redirect.github.com/actions/checkout/pull/2460">actions/checkout#2460</a></li>
    <li>Bump js-yaml from 4.1.0 to 4.2.0 by <a
    href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
    in <a
    href="https://redirect.github.com/actions/checkout/pull/2461">actions/checkout#2461</a></li>
    <li>Bump <code>@​actions/core</code> and
    <code>@​actions/tool-cache</code> and Remove uuid by <a
    href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
    in <a
    href="https://redirect.github.com/actions/checkout/pull/2459">actions/checkout#2459</a></li>
    <li>upgrade module to esm and update dependencies by <a
    href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2463">actions/checkout#2463</a></li>
    <li>Bump the minor-npm-dependencies group across 1 directory with 3
    updates by <a
    href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
    in <a
    href="https://redirect.github.com/actions/checkout/pull/2462">actions/checkout#2462</a></li>
    <li>getting ready for checkout v7 release by <a
    href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2464">actions/checkout#2464</a></li>
    <li>update error wording by <a
    href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2467">actions/checkout#2467</a></li>
    </ul>
    <h2>New Contributors</h2>
    <ul>
    <li><a href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> made
    their first contribution in <a
    href="https://redirect.github.com/actions/checkout/pull/2454">actions/checkout#2454</a></li>
    </ul>
    <p><strong>Full Changelog</strong>: <a
    href="https://github.com/actions/checkout/compare/v6.0.3...v7.0.0">https://github.com/actions/checkout/compare/v6.0.3...v7.0.0</a></p>
    <h2>v6.1.0</h2>
    <h2>What's Changed</h2>
    <ul>
    <li><strong>[BREAKING]</strong> backport
    <code>allow-unsafe-pr-checkout</code> to v6 by <a
    href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2500">actions/checkout#2500</a></li>
    <li>backport fixes to releases-v6 by <a
    href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2527">actions/checkout#2527</a></li>
    </ul>
    <p><a
    href="https://github.blog/changelog/2026-06-18-safer-pull_request_target-defaults-for-github-actions-checkout/">https://github.blog/changelog/2026-06-18-safer-pull_request_target-defaults-for-github-actions-checkout/</a>
    for more details about this breaking change</p>
    <p><strong>Full Changelog</strong>: <a
    href="https://github.com/actions/checkout/compare/v6.0.3...v6.1.0">https://github.com/actions/checkout/compare/v6.0.3...v6.1.0</a></p>
    <h2>v6.0.3</h2>
    <h2>What's Changed</h2>
    <ul>
    <li>Update changelog by <a
    href="https://github.com/ericsciple"><code>@​ericsciple</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2357">actions/checkout#2357</a></li>
    <li>fix: expand merge commit SHA regex and add SHA-256 test cases by <a
    href="https://github.com/yaananth"><code>@​yaananth</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2414">actions/checkout#2414</a></li>
    <li>Fix checkout init for SHA-256 repositories by <a
    href="https://github.com/yaananth"><code>@​yaananth</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2439">actions/checkout#2439</a></li>
    <li>Update changelog for v6.0.3 by <a
    href="https://github.com/yaananth"><code>@​yaananth</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2446">actions/checkout#2446</a></li>
    </ul>
    <h2>New Contributors</h2>
    <ul>
    <li><a href="https://github.com/yaananth"><code>@​yaananth</code></a>
    made their first contribution in <a
    href="https://redirect.github.com/actions/checkout/pull/2414">actions/checkout#2414</a></li>
    </ul>
    <p><strong>Full Changelog</strong>: <a
    href="https://github.com/actions/checkout/compare/v6...v6.0.3">https://github.com/actions/checkout/compare/v6...v6.0.3</a></p>
    </blockquote>
    </details>
    <details>
    <summary>Changelog</summary>
    <p><em>Sourced from <a
    href="https://github.com/actions/checkout/blob/main/CHANGELOG.md">actions/checkout's
    changelog</a>.</em></p>
    <blockquote>
    <h1>Changelog</h1>
    <h2>v7.0.1</h2>
    <ul>
    <li>Skip running unsafe pr check if input is default by <a
    href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2518">actions/checkout#2518</a></li>
    <li>Trim only ascii whitespace for branch by <a
    href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2521">actions/checkout#2521</a></li>
    <li>Escape values passed to --unset by <a
    href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2530">actions/checkout#2530</a></li>
    <li>Various dependency updates</li>
    </ul>
    <h2>v7.0.0</h2>
    <ul>
    <li>Block checking out fork PR for pull_request_target and workflow_run
    by <a href="https://github.com/aiqiaoy"><code>@​aiqiaoy</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2454">actions/checkout#2454</a></li>
    <li>Various dependency updates</li>
    </ul>
    <h2>v6.0.3</h2>
    <ul>
    <li>Fix checkout init for SHA-256 repositories by <a
    href="https://github.com/yaananth"><code>@​yaananth</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2439">actions/checkout#2439</a></li>
    <li>fix: expand merge commit SHA regex and add SHA-256 test cases by <a
    href="https://github.com/yaananth"><code>@​yaananth</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2414">actions/checkout#2414</a></li>
    </ul>
    <h2>v6.0.2</h2>
    <ul>
    <li>Fix tag handling: preserve annotations and explicit fetch-tags by <a
    href="https://github.com/ericsciple"><code>@​ericsciple</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2356">actions/checkout#2356</a></li>
    </ul>
    <h2>v6.0.1</h2>
    <ul>
    <li>Add worktree support for persist-credentials includeIf by <a
    href="https://github.com/ericsciple"><code>@​ericsciple</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2327">actions/checkout#2327</a></li>
    </ul>
    <h2>v6.0.0</h2>
    <ul>
    <li>Persist creds to a separate file by <a
    href="https://github.com/ericsciple"><code>@​ericsciple</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2286">actions/checkout#2286</a></li>
    <li>Update README to include Node.js 24 support details and requirements
    by <a href="https://github.com/salmanmkc"><code>@​salmanmkc</code></a>
    in <a
    href="https://redirect.github.com/actions/checkout/pull/2248">actions/checkout#2248</a></li>
    </ul>
    <h2>v5.0.1</h2>
    <ul>
    <li>Port v6 cleanup to v5 by <a
    href="https://github.com/ericsciple"><code>@​ericsciple</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2301">actions/checkout#2301</a></li>
    </ul>
    <h2>v5.0.0</h2>
    <ul>
    <li>Update actions checkout to use node 24 by <a
    href="https://github.com/salmanmkc"><code>@​salmanmkc</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2226">actions/checkout#2226</a></li>
    </ul>
    <h2>v4.3.1</h2>
    <ul>
    <li>Port v6 cleanup to v4 by <a
    href="https://github.com/ericsciple"><code>@​ericsciple</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2305">actions/checkout#2305</a></li>
    </ul>
    <h2>v4.3.0</h2>
    <ul>
    <li>docs: update README.md by <a
    href="https://github.com/motss"><code>@​motss</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/1971">actions/checkout#1971</a></li>
    <li>Add internal repos for checking out multiple repositories by <a
    href="https://github.com/mouismail"><code>@​mouismail</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/1977">actions/checkout#1977</a></li>
    <li>Documentation update - add recommended permissions to Readme by <a
    href="https://github.com/benwells"><code>@​benwells</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2043">actions/checkout#2043</a></li>
    <li>Adjust positioning of user email note and permissions heading by <a
    href="https://github.com/joshmgross"><code>@​joshmgross</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2044">actions/checkout#2044</a></li>
    <li>Update README.md by <a
    href="https://github.com/nebuk89"><code>@​nebuk89</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2194">actions/checkout#2194</a></li>
    <li>Update CODEOWNERS for actions by <a
    href="https://github.com/TingluoHuang"><code>@​TingluoHuang</code></a>
    in <a
    href="https://redirect.github.com/actions/checkout/pull/2224">actions/checkout#2224</a></li>
    <li>Update package dependencies by <a
    href="https://github.com/salmanmkc"><code>@​salmanmkc</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/2236">actions/checkout#2236</a></li>
    </ul>
    <h2>v4.2.2</h2>
    <ul>
    <li><code>url-helper.ts</code> now leverages well-known environment
    variables by <a href="https://github.com/jww3"><code>@​jww3</code></a>
    in <a
    href="https://redirect.github.com/actions/checkout/pull/1941">actions/checkout#1941</a></li>
    <li>Expand unit test coverage for <code>isGhes</code> by <a
    href="https://github.com/jww3"><code>@​jww3</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/1946">actions/checkout#1946</a></li>
    </ul>
    <h2>v4.2.1</h2>
    <ul>
    <li>Check out other refs/* by commit if provided, fall back to ref by <a
    href="https://github.com/orhantoy"><code>@​orhantoy</code></a> in <a
    href="https://redirect.github.com/actions/checkout/pull/1924">actions/checkout#1924</a></li>
    </ul>
    <!-- raw HTML omitted -->
    </blockquote>
    <p>... (truncated)</p>
    </details>
    <details>
    <summary>Commits</summary>
    <ul>
    <li><a
    href="https://github.com/actions/checkout/commit/3d3c42e5aac5ba805825da76410c181273ba90b1"><code>3d3c42e</code></a>
    prep v7.0.1 release (<a
    href="https://redirect.github.com/actions/checkout/issues/2531">#2531</a>)</li>
    <li><a
    href="https://github.com/actions/checkout/commit/28802689a136bfcdb721715abd713740beecbe07"><code>2880268</code></a>
    escape values passed to --unset (<a
    href="https://redirect.github.com/actions/checkout/issues/2530">#2530</a>)</li>
    <li><a
    href="https://github.com/actions/checkout/commit/12cd2235efa0937479335606d7c3ac9f6c0973b1"><code>12cd223</code></a>
    trim only ascii whitespace for branch (<a
    href="https://redirect.github.com/actions/checkout/issues/2521">#2521</a>)</li>
    <li><a
    href="https://github.com/actions/checkout/commit/62661c4e71a304b2823ed026347b8d34c3eac541"><code>62661c4</code></a>
    skip running unsafe pr check if input is default (<a
    href="https://redirect.github.com/actions/checkout/issues/2518">#2518</a>)</li>
    <li><a
    href="https://github.com/actions/checkout/commit/e8d4307400f9427dba7cb98e488d6ab85f1cec5f"><code>e8d4307</code></a>
    Bump the minor-actions-dependencies group with 2 updates (<a
    href="https://redirect.github.com/actions/checkout/issues/2499">#2499</a>)</li>
    <li><a
    href="https://github.com/actions/checkout/commit/631c942040754b6e095e929c1677c07e10ed4f87"><code>631c942</code></a>
    eslint 9 (<a
    href="https://redirect.github.com/actions/checkout/issues/2474">#2474</a>)</li>
    <li><a
    href="https://github.com/actions/checkout/commit/4f1f4aec02e41874fa0262ea8ff5172d7978ad1e"><code>4f1f4ae</code></a>
    Bump actions/upload-artifact from 4 to 7 (<a
    href="https://redirect.github.com/actions/checkout/issues/2476">#2476</a>)</li>
    <li><a
    href="https://github.com/actions/checkout/commit/ba097532fb203f7e88c9c3c0b899b49469908a92"><code>ba09753</code></a>
    Bump actions/checkout from 6 to 7 (<a
    href="https://redirect.github.com/actions/checkout/issues/2488">#2488</a>)</li>
    <li><a
    href="https://github.com/actions/checkout/commit/b9e0990d219a03df7633c93f6f005a8fecbcab22"><code>b9e0990</code></a>
    Bump docker/login-action from 3.3.0 to 4.2.0 (<a
    href="https://redirect.github.com/actions/checkout/issues/2479">#2479</a>)</li>
    <li><a
    href="https://github.com/actions/checkout/commit/e8cb398be4a550817e382abf69e4c12c76fce1f2"><code>e8cb398</code></a>
    Bump docker/build-push-action from 6.5.0 to 7.2.0 (<a
    href="https://redirect.github.com/actions/checkout/issues/2478">#2478</a>)</li>
    <li>Additional commits viewable in <a
    href="https://github.com/actions/checkout/compare/v6.0.2...3d3c42e5aac5ba805825da76410c181273ba90b1">compare
    view</a></li>
    </ul>
    </details>
    <br />
    
    ---------
    
    Signed-off-by: dependabot[bot] <support@github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    Co-authored-by: Justin Beckwith <jbeckwith@openai.com>
    dependabot[bot] and jbeckwith-oai authored Aug 27, 2026
    Configuration menu
    Copy the full SHA
    d0a2550 View commit details
    Browse the repository at this point in the history
  10. chore(deps-dev): bump rich from 14.2.0 to 15.0.0 (#3717)

    Bumps [rich](https://github.com/Textualize/rich) from 14.2.0 to 15.0.0.
    <details>
    <summary>Release notes</summary>
    <p><em>Sourced from <a
    href="https://github.com/Textualize/rich/releases">rich's
    releases</a>.</em></p>
    <blockquote>
    <h2>The So Long 3.8 Release</h2>
    <p>A few fixes. The major version bump is to honor the passing of 3.8
    support which reached its EOL in October 7, 2024</p>
    <h2>[15.0.0] - 2026-04-12</h2>
    <h3>Changed</h3>
    <ul>
    <li>Breaking change: Dropped support for Python3.8</li>
    </ul>
    <h3>Fixed</h3>
    <ul>
    <li>Fixed empty print ignoring the <code>end</code> parameter <a
    href="https://redirect.github.com/Textualize/rich/pull/4075">Textualize/rich#4075</a></li>
    <li>Fixed <code>Text.from_ansi</code> removing newlines <a
    href="https://redirect.github.com/Textualize/rich/pull/4076">Textualize/rich#4076</a></li>
    <li>Fixed <code>FileProxy.isatty</code> not proxying <a
    href="https://redirect.github.com/Textualize/rich/pull/4077">Textualize/rich#4077</a></li>
    <li>Fixed inline code in Markdown tables cells <a
    href="https://redirect.github.com/Textualize/rich/pull/4079">Textualize/rich#4079</a></li>
    </ul>
    <h2>The Faster Startup Release</h2>
    <p>No new features in this release, but there should be improved startup
    time for Rich apps, and potentially improved runtime if you have a lot
    of links.</p>
    <h2>[14.3.4] - 2026-04-11</h2>
    <h3>Changed</h3>
    <ul>
    <li>Improved import time with lazy loading <a
    href="https://redirect.github.com/Textualize/rich/pull/4070">Textualize/rich#4070</a></li>
    <li>Changed link id generation to avoid random number generation at
    runtime <a
    href="https://redirect.github.com/Textualize/rich/pull/3845">Textualize/rich#3845</a></li>
    </ul>
    <h2>The infinite Release</h2>
    <p>Fixed a infinite loop in split_graphemes</p>
    <h2>[14.3.3] - 2026-02-19</h2>
    <h3>Fixed</h3>
    <ul>
    <li>Fixed infinite loop with <code>cells.split_graphemes</code> <a
    href="https://redirect.github.com/Textualize/rich/pull/4006">Textualize/rich#4006</a></li>
    </ul>
    <h2>The ZWJy release</h2>
    <p>A fix for <code>cell_len</code> edge cases</p>
    <h2>[14.3.2] - 2026-02-01</h2>
    <h3>Fixed</h3>
    <ul>
    <li>Fixed solo ZWJ crash <a
    href="https://redirect.github.com/Textualize/rich/pull/3953">Textualize/rich#3953</a></li>
    <li>Fixed control codes reporting width of 1 <a
    href="https://redirect.github.com/Textualize/rich/pull/3953">Textualize/rich#3953</a></li>
    </ul>
    <h2>The Nerdy Fix release</h2>
    <p>Fixed issue with characters outside of unicode range reporting 0 cell
    size</p>
    <h2>[14.3.1] - 2026-01-24</h2>
    <!-- raw HTML omitted -->
    </blockquote>
    <p>... (truncated)</p>
    </details>
    <details>
    <summary>Changelog</summary>
    <p><em>Sourced from <a
    href="https://github.com/Textualize/rich/blob/main/CHANGELOG.md">rich's
    changelog</a>.</em></p>
    <blockquote>
    <h2>[15.0.0] - 2026-04-12</h2>
    <h3>Changed</h3>
    <ul>
    <li>Breaking change: Dropped support for Python3.8</li>
    </ul>
    <h3>Fixed</h3>
    <ul>
    <li>Fixed empty print ignoring the <code>end</code> parameter <a
    href="https://redirect.github.com/Textualize/rich/pull/4075">Textualize/rich#4075</a></li>
    <li>Fixed <code>Text.from_ansi</code> removing newlines <a
    href="https://redirect.github.com/Textualize/rich/pull/4076">Textualize/rich#4076</a></li>
    <li>Fixed <code>FileProxy.isatty</code> not proxying <a
    href="https://redirect.github.com/Textualize/rich/pull/4077">Textualize/rich#4077</a></li>
    <li>Fixed inline code in Markdown tables cells <a
    href="https://redirect.github.com/Textualize/rich/pull/4079">Textualize/rich#4079</a></li>
    </ul>
    <h2>[14.3.4] - 2026-04-11</h2>
    <h3>Changed</h3>
    <ul>
    <li>Improved import time with lazy loading <a
    href="https://redirect.github.com/Textualize/rich/pull/4070">Textualize/rich#4070</a></li>
    <li>Changed link id generation to avoid random number generation at
    runtime <a
    href="https://redirect.github.com/Textualize/rich/pull/3845">Textualize/rich#3845</a></li>
    </ul>
    <h2>[14.3.3] - 2026-02-19</h2>
    <h3>Fixed</h3>
    <ul>
    <li>Fixed infinite loop with <code>cells.split_graphemes</code> <a
    href="https://redirect.github.com/Textualize/rich/pull/4006">Textualize/rich#4006</a></li>
    </ul>
    <h2>[14.3.2] - 2026-02-01</h2>
    <h3>Fixed</h3>
    <ul>
    <li>Fixed solo ZWJ crash <a
    href="https://redirect.github.com/Textualize/rich/pull/3953">Textualize/rich#3953</a></li>
    <li>Fixed control codes reporting width of 1 <a
    href="https://redirect.github.com/Textualize/rich/pull/3953">Textualize/rich#3953</a></li>
    </ul>
    <h2>[14.3.1] - 2026-01-24</h2>
    <h3>Fixed</h3>
    <ul>
    <li>Fixed characters out of unicode range reporting a cell size if 0 <a
    href="https://redirect.github.com/Textualize/rich/pull/3944">Textualize/rich#3944</a></li>
    </ul>
    <h2>[14.3.0] - 2026-01-24</h2>
    <h3>Fixed</h3>
    <ul>
    <li>IPython now respects when a <code>Console</code> instance is passed
    to <code>pretty.install</code> <a
    href="https://redirect.github.com/Textualize/rich/pull/3915">Textualize/rich#3915</a></li>
    <li>Fixed extraneous blank line on non-interactive disabled
    <code>Progress</code> <a
    href="https://redirect.github.com/Textualize/rich/pull/3905">Textualize/rich#3905</a></li>
    <li>Fixed extra padding on first cell in columns <a
    href="https://redirect.github.com/Textualize/rich/pull/3935">Textualize/rich#3935</a></li>
    <li>Fixed trailing whitespace removed when soft_wrap=True <a
    href="https://redirect.github.com/Textualize/rich/pull/3937">Textualize/rich#3937</a></li>
    <li>Fixed style new-lines when soft_wrap = True and a print style is set
    <a
    href="https://redirect.github.com/Textualize/rich/pull/3938">Textualize/rich#3938</a></li>
    </ul>
    <h3>Added</h3>
    <!-- raw HTML omitted -->
    </blockquote>
    <p>... (truncated)</p>
    </details>
    <details>
    <summary>Commits</summary>
    <ul>
    <li><a
    href="https://github.com/Textualize/rich/commit/6ac483cbea39cab124dfd3483bba70ffafb71050"><code>6ac483c</code></a>
    correction</li>
    <li><a
    href="https://github.com/Textualize/rich/commit/458a9109c8b7da81c17b2270ea8a88f3e8c0465a"><code>458a910</code></a>
    Merge pull request <a
    href="https://redirect.github.com/Textualize/rich/issues/4080">#4080</a>
    from Textualize/bump1500</li>
    <li><a
    href="https://github.com/Textualize/rich/commit/82e06e0d9985fd8cce456dc3977e0d2d9e84b4d8"><code>82e06e0</code></a>
    changelog</li>
    <li><a
    href="https://github.com/Textualize/rich/commit/d6556bc44881b9904f29f5d9d69a0812b30675d1"><code>d6556bc</code></a>
    bump to 15.0.0</li>
    <li><a
    href="https://github.com/Textualize/rich/commit/ffe2edc5968eac19d5493c2d7b27965031a692e9"><code>ffe2edc</code></a>
    Merge pull request <a
    href="https://redirect.github.com/Textualize/rich/issues/4079">#4079</a>
    from Textualize/inline-table-code</li>
    <li><a
    href="https://github.com/Textualize/rich/commit/cf3b5a16f7a76b2e8c4921d3314021bb72a6c5c1"><code>cf3b5a1</code></a>
    changelog</li>
    <li><a
    href="https://github.com/Textualize/rich/commit/77f0edbdef71f2a895cd0ab1481e9a1fc79d42e6"><code>77f0edb</code></a>
    remove comments</li>
    <li><a
    href="https://github.com/Textualize/rich/commit/7ef2d05ca8aa3cb405dab2fdf3282e69cf8089e3"><code>7ef2d05</code></a>
    fix inline code in table cells</li>
    <li><a
    href="https://github.com/Textualize/rich/commit/19c67b9a3479841e9133bea94607c89ee931d3fc"><code>19c67b9</code></a>
    Merge pull request <a
    href="https://redirect.github.com/Textualize/rich/issues/4077">#4077</a>
    from Textualize/isattry</li>
    <li><a
    href="https://github.com/Textualize/rich/commit/494b795031782c694297d2db78bd04fb8c82f590"><code>494b795</code></a>
    changelog</li>
    <li>Additional commits viewable in <a
    href="https://github.com/Textualize/rich/compare/v14.2.0...v15.0.0">compare
    view</a></li>
    </ul>
    </details>
    <br />
    
    ---------
    
    Signed-off-by: dependabot[bot] <support@github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    Co-authored-by: Justin Beckwith <jbeckwith@openai.com>
    dependabot[bot] and jbeckwith-oai authored Aug 27, 2026
    Configuration menu
    Copy the full SHA
    7a5484d View commit details
    Browse the repository at this point in the history
  11. chore(deps): bump github/codeql-action/init from 4.37.1 to 4.37.7 (#3745

    )
    
    Bumps
    [github/codeql-action/init](https://github.com/github/codeql-action)
    from 4.37.1 to 4.37.7.
    <details>
    <summary>Release notes</summary>
    <p><em>Sourced from <a
    href="https://github.com/github/codeql-action/releases">github/codeql-action/init's
    releases</a>.</em></p>
    <blockquote>
    <h2>v4.37.7</h2>
    <ul>
    <li>Update default CodeQL bundle version to <a
    href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.3">2.26.3</a>.
    <a
    href="https://redirect.github.com/github/codeql-action/pull/4085">#4085</a></li>
    </ul>
    <h2>v4.37.6</h2>
    <ul>
    <li>Changed the default filepath for the new remote file address format
    that was introduced in CodeQL Action 4.37.0 / 3.37.0 to
    <code>.github/codeql-config.yml</code> to align it with the suggested
    path that is used elsewhere. <a
    href="https://redirect.github.com/github/codeql-action/pull/4070">#4070</a></li>
    </ul>
    <h2>v4.37.5</h2>
    <ul>
    <li>Fixed a bug where a network error while streaming the download of
    the CodeQL bundle could terminate the <code>init</code> Action instead
    of falling back to downloading the bundle before extracting it. <a
    href="https://redirect.github.com/github/codeql-action/pull/4061">#4061</a></li>
    </ul>
    <h2>v4.37.4</h2>
    <ul>
    <li>This version of the CodeQL Action adds support for the
    <code>tools</code> input for the <code>codeql-action/init</code> step to
    be specified using a <code>github-codeql-tools</code> <a
    href="https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization">repository
    property</a>. This feature will gradually be rolled out following the
    release of this version. Once rolled out, this allows for the CodeQL CLI
    version that is used in GitHub-managed workflows, such as Default Setup,
    to be set to a custom value. For example, customers who run into issues
    with rate limits when a new CodeQL CLI version is released can set the
    value to <code>toolcache</code> to always use the CodeQL CLI version
    that is available in the runner toolcache. For Advanced Setup workflows,
    the value provided for <code>tools</code> in the workflow definition
    always takes precedence unless the value of the repository property
    starts with <code>!</code>. <a
    href="https://redirect.github.com/github/codeql-action/pull/4037">#4037</a></li>
    <li>Update default CodeQL bundle version to <a
    href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.2">2.26.2</a>.
    <a
    href="https://redirect.github.com/github/codeql-action/pull/4051">#4051</a></li>
    </ul>
    <h2>v4.37.3</h2>
    <p>No user facing changes.</p>
    <h2>v4.37.2</h2>
    <ul>
    <li>The new address format for the <code>config-file</code> input that
    was introduced in CodeQL Action 4.37.0 is now enabled by default. In
    addition to the format described there, the <code>remote=</code> prefix
    can now be used to explicitly indicate that the input refers to a remote
    file. All previous input formats continue to be accepted as well. <a
    href="https://redirect.github.com/github/codeql-action/pull/4023">#4023</a></li>
    <li>The CodeQL Action can now make use of <a
    href="https://docs.github.com/en/code-security/how-tos/secure-at-scale/configure-organization-security/manage-usage-and-access/giving-org-access-private-registries">configured
    private registries</a> in Default Setup to retrieve CodeQL configuration
    files from remote repositories that require authentication. This will
    allow customers to store their CodeQL configuration in a single
    repository that can then be referenced by Default Setup workflows in
    other repositories. We expect to roll this and other, related changes
    out to everyone in July. <a
    href="https://redirect.github.com/github/codeql-action/pull/4007">#4007</a></li>
    </ul>
    </blockquote>
    </details>
    <details>
    <summary>Changelog</summary>
    <p><em>Sourced from <a
    href="https://github.com/github/codeql-action/blob/main/CHANGELOG.md">github/codeql-action/init's
    changelog</a>.</em></p>
    <blockquote>
    <h1>CodeQL Action Changelog</h1>
    <p>See the <a
    href="https://github.com/github/codeql-action/releases">releases
    page</a> for the relevant changes to the CodeQL CLI and language
    packs.</p>
    <h2>[UNRELEASED]</h2>
    <p>No user facing changes.</p>
    <h2>4.37.9 - 26 Aug 2026</h2>
    <ul>
    <li>Update default CodeQL bundle version to <a
    href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.4">2.26.4</a>.
    <a
    href="https://redirect.github.com/github/codeql-action/pull/4106">#4106</a></li>
    </ul>
    <h2>4.37.8 - 21 Aug 2026</h2>
    <p>No user facing changes.</p>
    <h2>4.37.7 - 13 Aug 2026</h2>
    <ul>
    <li>Update default CodeQL bundle version to <a
    href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.3">2.26.3</a>.
    <a
    href="https://redirect.github.com/github/codeql-action/pull/4085">#4085</a></li>
    </ul>
    <h2>4.37.6 - 04 Aug 2026</h2>
    <ul>
    <li>Changed the default filepath for the new remote file address format
    that was introduced in CodeQL Action 4.37.0 / 3.37.0 to
    <code>.github/codeql-config.yml</code> to align it with the suggested
    path that is used elsewhere. <a
    href="https://redirect.github.com/github/codeql-action/pull/4070">#4070</a></li>
    </ul>
    <h2>4.37.5 - 03 Aug 2026</h2>
    <ul>
    <li>Fixed a bug where a network error while streaming the download of
    the CodeQL bundle could terminate the <code>init</code> Action instead
    of falling back to downloading the bundle before extracting it. <a
    href="https://redirect.github.com/github/codeql-action/pull/4061">#4061</a></li>
    </ul>
    <h2>4.37.4 - 29 Jul 2026</h2>
    <ul>
    <li>This version of the CodeQL Action adds support for the
    <code>tools</code> input for the <code>codeql-action/init</code> step to
    be specified using a <code>github-codeql-tools</code> <a
    href="https://docs.github.com/en/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization">repository
    property</a>. This feature will gradually be rolled out following the
    release of this version. Once rolled out, this allows for the CodeQL CLI
    version that is used in GitHub-managed workflows, such as Default Setup,
    to be set to a custom value. For example, customers who run into issues
    with rate limits when a new CodeQL CLI version is released can set the
    value to <code>toolcache</code> to always use the CodeQL CLI version
    that is available in the runner toolcache. For Advanced Setup workflows,
    the value provided for <code>tools</code> in the workflow definition
    always takes precedence unless the value of the repository property
    starts with <code>!</code>. <a
    href="https://redirect.github.com/github/codeql-action/pull/4037">#4037</a></li>
    <li>Update default CodeQL bundle version to <a
    href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.2">2.26.2</a>.
    <a
    href="https://redirect.github.com/github/codeql-action/pull/4051">#4051</a></li>
    </ul>
    <h2>4.37.3 - 22 Jul 2026</h2>
    <p>No user facing changes.</p>
    <h2>4.37.2 - 21 Jul 2026</h2>
    <ul>
    <li>The new address format for the <code>config-file</code> input that
    was introduced in CodeQL Action 4.37.0 is now enabled by default. In
    addition to the format described there, the <code>remote=</code> prefix
    can now be used to explicitly indicate that the input refers to a remote
    file. All previous input formats continue to be accepted as well. <a
    href="https://redirect.github.com/github/codeql-action/pull/4023">#4023</a></li>
    <li>The CodeQL Action can now make use of <a
    href="https://docs.github.com/en/code-security/how-tos/secure-at-scale/configure-organization-security/manage-usage-and-access/giving-org-access-private-registries">configured
    private registries</a> in Default Setup to retrieve CodeQL configuration
    files from remote repositories that require authentication. This will
    allow customers to store their CodeQL configuration in a single
    repository that can then be referenced by Default Setup workflows in
    other repositories. We expect to roll this and other, related changes
    out to everyone in July. <a
    href="https://redirect.github.com/github/codeql-action/pull/4007">#4007</a></li>
    </ul>
    <h2>4.37.1 - 16 Jul 2026</h2>
    <ul>
    <li><em>Upcoming breaking change</em>: Add a deprecation warning for
    customers using CodeQL version 2.20.6 and earlier. These versions of
    CodeQL were discontinued on 1 July 2026 alongside GitHub Enterprise
    Server 3.16, and will be unsupported by the next minor release of the
    CodeQL Action. <a
    href="https://redirect.github.com/github/codeql-action/pull/3956">#3956</a></li>
    <li>Update default CodeQL bundle version to <a
    href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.1">2.26.1</a>.
    <a
    href="https://redirect.github.com/github/codeql-action/pull/4019">#4019</a></li>
    </ul>
    <h2>4.37.0 - 08 Jul 2026</h2>
    <ul>
    <li>Update default CodeQL bundle version to <a
    href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.26.0">2.26.0</a>.
    <a
    href="https://redirect.github.com/github/codeql-action/pull/3995">#3995</a></li>
    </ul>
    <!-- raw HTML omitted -->
    </blockquote>
    <p>... (truncated)</p>
    </details>
    <details>
    <summary>Commits</summary>
    <ul>
    <li><a
    href="https://github.com/github/codeql-action/commit/ff2f1c621b7f889edc0d3c761ac2e6a3f8cdb0dd"><code>ff2f1c6</code></a>
    Merge pull request <a
    href="https://redirect.github.com/github/codeql-action/issues/4093">#4093</a>
    from github/update-v4.37.7-be7a3dbb8</li>
    <li><a
    href="https://github.com/github/codeql-action/commit/951a133f96aa2114dd747e9e437305335d0bde16"><code>951a133</code></a>
    Update changelog for v4.37.7</li>
    <li><a
    href="https://github.com/github/codeql-action/commit/be7a3dbb8147b82cd6d27e0707105b36aa190fc1"><code>be7a3db</code></a>
    Merge pull request <a
    href="https://redirect.github.com/github/codeql-action/issues/4087">#4087</a>
    from github/dependabot/npm_and_yarn/npm-minor-0aa561...</li>
    <li><a
    href="https://github.com/github/codeql-action/commit/9310334b11405b305d9444edfa56cd86e2f1e4fe"><code>9310334</code></a>
    Merge pull request <a
    href="https://redirect.github.com/github/codeql-action/issues/4086">#4086</a>
    from github/mbg/thread-action-state-to-codeql</li>
    <li><a
    href="https://github.com/github/codeql-action/commit/b4d8a54218a8792de9af2f6f32e33af899ca5212"><code>b4d8a54</code></a>
    Rebuild</li>
    <li><a
    href="https://github.com/github/codeql-action/commit/ab5db2519c3344f2fa61c711fa2d6ad135829200"><code>ab5db25</code></a>
    Bump the npm-minor group across 1 directory with 8 updates</li>
    <li><a
    href="https://github.com/github/codeql-action/commit/38055a3c3cf3979323eaf70fc6c73a8690250bde"><code>38055a3</code></a>
    Drop <code>logger</code> from <code>databaseInitCluster</code> in
    interface</li>
    <li><a
    href="https://github.com/github/codeql-action/commit/1f87aed5e66849f0c43ae147377cc77f2d98ac99"><code>1f87aed</code></a>
    Merge pull request <a
    href="https://redirect.github.com/github/codeql-action/issues/4085">#4085</a>
    from github/update-bundle/codeql-bundle-v2.26.3</li>
    <li><a
    href="https://github.com/github/codeql-action/commit/dc1b98ad1c2f13ccf9fc33fb82f32fc76f944253"><code>dc1b98a</code></a>
    Make <code>logger</code> available to <code>getCodeQLForCmd</code></li>
    <li><a
    href="https://github.com/github/codeql-action/commit/6f0220ee37121218af472efbde25f06907a4da4f"><code>6f0220e</code></a>
    Merge pull request <a
    href="https://redirect.github.com/github/codeql-action/issues/4084">#4084</a>
    from github/navntoft/bump-undici</li>
    <li>Additional commits viewable in <a
    href="https://github.com/github/codeql-action/compare/7188fc363630916deb702c7fdcf4e481b751f97a...ff2f1c621b7f889edc0d3c761ac2e6a3f8cdb0dd">compare
    view</a></li>
    </ul>
    </details>
    <br />
    
    
    [![Dependabot compatibility
    score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=github/codeql-action/init&package-manager=github_actions&previous-version=4.37.1&new-version=4.37.7)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
    
    Dependabot will resolve any conflicts with this PR as long as you don't
    alter it yourself. You can also trigger a rebase manually by commenting
    `@dependabot rebase`.
    
    [//]: # (dependabot-automerge-start)
    [//]: # (dependabot-automerge-end)
    
    ---
    
    <details>
    <summary>Dependabot commands and options</summary>
    <br />
    
    You can trigger Dependabot actions by commenting on this PR:
    - `@dependabot rebase` will rebase this PR
    - `@dependabot recreate` will recreate this PR, overwriting any edits
    that have been made to it
    - `@dependabot show <dependency name> ignore conditions` will show all
    of the ignore conditions of the specified dependency
    - `@dependabot ignore this major version` will close this PR and stop
    Dependabot creating any more for this major version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this minor version` will close this PR and stop
    Dependabot creating any more for this minor version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this dependency` will close this PR and stop
    Dependabot creating any more for this dependency (unless you reopen the
    PR or upgrade to it yourself)
    
    
    </details>
    
    ---------
    
    Signed-off-by: dependabot[bot] <support@github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    Co-authored-by: Justin Beckwith <jbeckwith@openai.com>
    dependabot[bot] and jbeckwith-oai authored Aug 27, 2026
    Configuration menu
    Copy the full SHA
    a36010d View commit details
    Browse the repository at this point in the history
  12. chore(deps-dev): bump pandas-stubs from 2.2.2.240807 to 2.3.3.260113 (#…

    …3659)
    
    Bumps [pandas-stubs](https://github.com/pandas-dev/pandas-stubs) from
    2.2.2.240807 to 2.3.3.260113.
    <details>
    <summary>Commits</summary>
    <ul>
    <li><a
    href="https://github.com/pandas-dev/pandas-stubs/commit/0cb16c482b2350047d51e5954e9d8bc5ff40f4d0"><code>0cb16c4</code></a>
    Version 2.3.3.260113</li>
    <li><a
    href="https://github.com/pandas-dev/pandas-stubs/commit/bf9a74aa3092f59193f3ca26aae2d9e0c63a813f"><code>bf9a74a</code></a>
    TYP: bump <code>ty</code> (<a
    href="https://redirect.github.com/pandas-dev/pandas-stubs/issues/1630">#1630</a>)</li>
    <li><a
    href="https://github.com/pandas-dev/pandas-stubs/commit/db79b540b34c76ec5a710d366638d2b4949f5bc4"><code>db79b54</code></a>
    TST: numeric arrays (<a
    href="https://redirect.github.com/pandas-dev/pandas-stubs/issues/1618">#1618</a>)</li>
    <li><a
    href="https://github.com/pandas-dev/pandas-stubs/commit/a0d8f9cedd7b1af11ad344b1717402425f403551"><code>a0d8f9c</code></a>
    GH1614 Add more agg func methods for pivot_table (<a
    href="https://redirect.github.com/pandas-dev/pandas-stubs/issues/1623">#1623</a>)</li>
    <li><a
    href="https://github.com/pandas-dev/pandas-stubs/commit/2c83c1fca90b14b2439d3312494642d7c52fd45e"><code>2c83c1f</code></a>
    BUG: regression on <a
    href="https://redirect.github.com/pandas-dev/pandas-stubs/issues/1594">#1594</a>
    for nightly (<a
    href="https://redirect.github.com/pandas-dev/pandas-stubs/issues/1620">#1620</a>)</li>
    <li><a
    href="https://github.com/pandas-dev/pandas-stubs/commit/78fcc5b9da0aba3dda336624bf12f29b9b1214c4"><code>78fcc5b</code></a>
    TYP: GH1614 Add more agg func methods for <code>pivot_table</code> (<a
    href="https://redirect.github.com/pandas-dev/pandas-stubs/issues/1615">#1615</a>)</li>
    <li><a
    href="https://github.com/pandas-dev/pandas-stubs/commit/cf423fdf17933fbf546cb129e9fc4df08c780724"><code>cf423fd</code></a>
    CLN: move tests for <code>Series.astype</code> (<a
    href="https://redirect.github.com/pandas-dev/pandas-stubs/issues/1611">#1611</a>)</li>
    <li><a
    href="https://github.com/pandas-dev/pandas-stubs/commit/0954c0db562e7e868b1839b4adcb2b049e9136e0"><code>0954c0d</code></a>
    BUG: rename to <code>NoDefaultDoNotUse</code> (<a
    href="https://redirect.github.com/pandas-dev/pandas-stubs/issues/1616">#1616</a>)</li>
    <li><a
    href="https://github.com/pandas-dev/pandas-stubs/commit/b54625adb16fad269b0ea420436a95f24002e5c7"><code>b54625a</code></a>
    TST: <code>xStringArray</code> and <code>NumpyExtensionArray</code> (<a
    href="https://redirect.github.com/pandas-dev/pandas-stubs/issues/1594">#1594</a>)</li>
    <li><a
    href="https://github.com/pandas-dev/pandas-stubs/commit/df2ebd03248496f309cfdb87719de3f659530eb7"><code>df2ebd0</code></a>
    DEPR: <code>ravel</code> in <code>Index</code> and <code>Series</code>
    <a
    href="https://redirect.github.com/pandas-dev/pandas/issues/36900">pandas-dev/pandas#36900</a>
    pandas-dev/pand...</li>
    <li>Additional commits viewable in <a
    href="https://github.com/pandas-dev/pandas-stubs/compare/v2.2.2.240807...v2.3.3.260113">compare
    view</a></li>
    </ul>
    </details>
    <br />
    
    ---------
    
    Signed-off-by: dependabot[bot] <support@github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    Co-authored-by: Justin Beckwith <jbeckwith@openai.com>
    dependabot[bot] and jbeckwith-oai authored Aug 27, 2026
    Configuration menu
    Copy the full SHA
    95f0b43 View commit details
    Browse the repository at this point in the history
  13. chore(deps-dev): bump @stdy/cli from 0.22.1 to 0.22.2 (#3719)

    Bumps [@stdy/cli](https://github.com/dgellow/steady) from 0.22.1 to
    0.22.2.
    <details>
    <summary>Release notes</summary>
    <p><em>Sourced from <a
    href="https://github.com/dgellow/steady/releases">@​stdy/cli's
    releases</a>.</em></p>
    <blockquote>
    <h2>Release v0.22.2</h2>
    <h2>Changes</h2>
    <ul>
    <li>chore: change license to MIT</li>
    </ul>
    </blockquote>
    </details>
    <details>
    <summary>Changelog</summary>
    <p><em>Sourced from <a
    href="https://github.com/dgellow/steady/blob/main/CHANGELOG.md">@​stdy/cli's
    changelog</a>.</em></p>
    <blockquote>
    <h2>0.22.2</h2>
    <h3>Chores</h3>
    <ul>
    <li>change license to MIT</li>
    </ul>
    </blockquote>
    </details>
    <details>
    <summary>Commits</summary>
    <ul>
    <li><a
    href="https://github.com/dgellow/steady/commit/983ba871c94a6628c64568252bb2b61d753bcff1"><code>983ba87</code></a>
    chore: release v0.22.2</li>
    <li><a
    href="https://github.com/dgellow/steady/commit/7c0c5c4ee5e903e8541f8f650cedaa36cbbbe337"><code>7c0c5c4</code></a>
    chore: change license to MIT</li>
    <li>See full diff in <a
    href="https://github.com/dgellow/steady/compare/v0.22.1...v0.22.2">compare
    view</a></li>
    </ul>
    </details>
    <br />
    
    
    [![Dependabot compatibility
    score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=@stdy/cli&package-manager=npm_and_yarn&previous-version=0.22.1&new-version=0.22.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
    
    Dependabot will resolve any conflicts with this PR as long as you don't
    alter it yourself. You can also trigger a rebase manually by commenting
    `@dependabot rebase`.
    
    [//]: # (dependabot-automerge-start)
    [//]: # (dependabot-automerge-end)
    
    ---
    
    <details>
    <summary>Dependabot commands and options</summary>
    <br />
    
    You can trigger Dependabot actions by commenting on this PR:
    - `@dependabot rebase` will rebase this PR
    - `@dependabot recreate` will recreate this PR, overwriting any edits
    that have been made to it
    - `@dependabot show <dependency name> ignore conditions` will show all
    of the ignore conditions of the specified dependency
    - `@dependabot ignore this major version` will close this PR and stop
    Dependabot creating any more for this major version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this minor version` will close this PR and stop
    Dependabot creating any more for this minor version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this dependency` will close this PR and stop
    Dependabot creating any more for this dependency (unless you reopen the
    PR or upgrade to it yourself)
    
    
    </details>
    
    ---------
    
    Signed-off-by: dependabot[bot] <support@github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    Co-authored-by: Justin Beckwith <jbeckwith@openai.com>
    dependabot[bot] and jbeckwith-oai authored Aug 27, 2026
    Configuration menu
    Copy the full SHA
    4f5598c View commit details
    Browse the repository at this point in the history
  14. chore(deps-dev): bump mypy from 1.17 to 2.3.1 (#3747)

    Bumps [mypy](https://github.com/python/mypy) from 1.17 to 2.3.1.
    <details>
    <summary>Changelog</summary>
    <p><em>Sourced from <a
    href="https://github.com/python/mypy/blob/master/CHANGELOG.md">mypy's
    changelog</a>.</em></p>
    <blockquote>
    <h3>Mypy 2.3.1</h3>
    <ul>
    <li>Fix mypyc crash on double yielding Iterators (Daniël van Noord, PR
    <a
    href="https://redirect.github.com/python/mypy/pull/21826">21826</a>)</li>
    <li>Fix mypyc <code>default_factory</code> for inherited dataclass
    (Daniël van Noord, PR <a
    href="https://redirect.github.com/python/mypy/pull/21785">21785</a>)</li>
    <li>Clear mypyc coroutine env on coroutine completion (Piotr Sawicki, PR
    <a
    href="https://redirect.github.com/python/mypy/pull/21734">21734</a>)</li>
    <li>Fix crash when unpacking return value from overload (Shantanu, PR <a
    href="https://redirect.github.com/python/mypy/pull/21830">21830</a>)</li>
    </ul>
    <h3>Acknowledgements</h3>
    <p>Thanks to all mypy contributors who contributed to this release:</p>
    <ul>
    <li>Agriya Khetarpal</li>
    <li>Ethan Sarp</li>
    <li>Ivan Levkivskyi</li>
    <li>Jingchen Ye</li>
    <li>Jukka Lehtosalo</li>
    <li>Piotr Sawicki</li>
    <li>Shantanu</li>
    <li>Tom Bannink</li>
    <li>Viktor Szépe</li>
    <li>ygale</li>
    </ul>
    <p>I'd also like to thank my employer, Dropbox, for supporting mypy
    development.</p>
    <h2>Mypy 2.2</h2>
    <p>We've just uploaded mypy 2.2.0 to the Python Package Index (<a
    href="https://pypi.org/project/mypy/">PyPI</a>).
    Mypy is a static type checker for Python. This release includes new
    features, performance
    improvements and bug fixes. You can install it as follows:</p>
    <pre><code>python3 -m pip install -U mypy
    </code></pre>
    <p>You can read the full documentation for this release on <a
    href="http://mypy.readthedocs.io">Read the Docs</a>.</p>
    <h3>Support for Closed TypedDicts (PEP 728)</h3>
    <p>Mypy now supports closed TypedDicts as specified in PEP 728. A closed
    TypedDict cannot have extra
    keys beyond those explicitly defined. This allows the type checker to
    determine that certain
    operations are safe when they otherwise wouldn't be due to the potential
    presence of unknown keys.</p>
    <p>You can use the <code>closed</code> keyword argument with
    <code>TypedDict</code>:</p>
    <pre lang="python"><code>HasName = TypedDict(&quot;HasName&quot;,
    {&quot;name&quot;: str})
    HasOnlyName = TypedDict(&quot;HasOnlyName&quot;, {&quot;name&quot;:
    str}, closed=True)
    Movie = TypedDict(&quot;Movie&quot;, {&quot;name&quot;: str,
    &quot;year&quot;: int})
    <p>movie: Movie = {&quot;name&quot;: &quot;Nimona&quot;,
    &quot;year&quot;: 2023}
    has_name: HasName = movie  # OK: HasName is open (default)
    has_only_name: HasOnlyName = movie # Error: HasOnlyName is closed and
    Movie has extra &quot;year&quot; key
    &lt;/tr&gt;&lt;/table&gt;
    </code></pre></p>
    </blockquote>
    <p>... (truncated)</p>
    </details>
    <details>
    <summary>Commits</summary>
    <ul>
    <li><a
    href="https://github.com/python/mypy/commit/d642c4478e9e3acbe9233edbe17ffc569a1a778c"><code>d642c44</code></a>
    Bump version to 2.3.1</li>
    <li><a
    href="https://github.com/python/mypy/commit/a39242983d3c2cb85886a1eb6d5869180672784c"><code>a392429</code></a>
    [mypyc] Fix crash on double yielding Iterators (<a
    href="https://redirect.github.com/python/mypy/issues/21826">#21826</a>)</li>
    <li><a
    href="https://github.com/python/mypy/commit/4843e7773e7dc8fe3f1fd1319277d6d11cd6cdb3"><code>4843e77</code></a>
    [mypyc] Fix <code>default_factory</code> for inherited dataclass (<a
    href="https://redirect.github.com/python/mypy/issues/21785">#21785</a>)</li>
    <li><a
    href="https://github.com/python/mypy/commit/14f5df93ed8d1be4f4cc9c447eb2e6e619362e05"><code>14f5df9</code></a>
    [mypyc] Clear coroutine env on coroutine completion (<a
    href="https://redirect.github.com/python/mypy/issues/21734">#21734</a>)</li>
    <li><a
    href="https://github.com/python/mypy/commit/6dfa06dda6e34912279e498d35a43ba6dc30bfee"><code>6dfa06d</code></a>
    Fix crash when unpacking return value from overload (<a
    href="https://redirect.github.com/python/mypy/issues/21830">#21830</a>)</li>
    <li><a
    href="https://github.com/python/mypy/commit/a3857467da126d28b55724e8bb682019df9a503e"><code>a385746</code></a>
    Bump version to 2.3.1+dev</li>
    <li><a
    href="https://github.com/python/mypy/commit/8aabf8435357eaffceca7237f371e293b8168e54"><code>8aabf84</code></a>
    Drop +dev from version</li>
    <li><a
    href="https://github.com/python/mypy/commit/4d8ad2ab5e86c99581b73775f2c00b9b8265b589"><code>4d8ad2a</code></a>
    Update changelog for 2.3 release (<a
    href="https://redirect.github.com/python/mypy/issues/21728">#21728</a>)</li>
    <li><a
    href="https://github.com/python/mypy/commit/2c2154672040c52e481f423854d104e6cf172585"><code>2c21546</code></a>
    [mypyc] Update documentation of race conditions under free threading (<a
    href="https://redirect.github.com/python/mypy/issues/21726">#21726</a>)</li>
    <li><a
    href="https://github.com/python/mypy/commit/a9f62a3cf98a58a7a2607b7c81695802b39f5edc"><code>a9f62a3</code></a>
    [mypyc] Make attribute access memory safe on free-threaded builds (<a
    href="https://redirect.github.com/python/mypy/issues/21705">#21705</a>)</li>
    <li>Additional commits viewable in <a
    href="https://github.com/python/mypy/compare/v1.17.0...v2.3.1">compare
    view</a></li>
    </ul>
    </details>
    <br />
    
    
    [![Dependabot compatibility
    score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=mypy&package-manager=uv&previous-version=1.17&new-version=2.3.1)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
    
    Dependabot will resolve any conflicts with this PR as long as you don't
    alter it yourself. You can also trigger a rebase manually by commenting
    `@dependabot rebase`.
    
    [//]: # (dependabot-automerge-start)
    [//]: # (dependabot-automerge-end)
    
    ---
    
    <details>
    <summary>Dependabot commands and options</summary>
    <br />
    
    You can trigger Dependabot actions by commenting on this PR:
    - `@dependabot rebase` will rebase this PR
    - `@dependabot recreate` will recreate this PR, overwriting any edits
    that have been made to it
    - `@dependabot show <dependency name> ignore conditions` will show all
    of the ignore conditions of the specified dependency
    - `@dependabot ignore this major version` will close this PR and stop
    Dependabot creating any more for this major version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this minor version` will close this PR and stop
    Dependabot creating any more for this minor version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this dependency` will close this PR and stop
    Dependabot creating any more for this dependency (unless you reopen the
    PR or upgrade to it yourself)
    
    
    </details>
    
    ---------
    
    Signed-off-by: dependabot[bot] <support@github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    Co-authored-by: Justin Beckwith <jbeckwith@openai.com>
    dependabot[bot] and jbeckwith-oai authored Aug 27, 2026
    Configuration menu
    Copy the full SHA
    0b52c9e View commit details
    Browse the repository at this point in the history
  15. chore(deps-dev): bump pyright from 1.1.399 to 1.1.413 (#3744)

    Bumps
    [pyright](https://github.com/Microsoft/pyright/tree/HEAD/packages/pyright)
    from 1.1.399 to 1.1.413.
    <details>
    <summary>Release notes</summary>
    <p><em>Sourced from <a
    href="https://github.com/Microsoft/pyright/releases">pyright's
    releases</a>.</em></p>
    <blockquote>
    <h2>Published 1.1.412</h2>
    <h2>Changes:</h2>
    <ul>
    <li>fceca4d133a83034fc195dbba8b3814992b0b26b Use shared authenticated
    npm config in pipelines (<a
    href="https://github.com/Microsoft/pyright/tree/HEAD/packages/pyright/issues/11626">#11626</a>)</li>
    <li>e814a5e480d0076b5eef25c570fdc1b7e29dcab0 Align pyright-typeserver
    version with 1.1.412 (<a
    href="https://github.com/Microsoft/pyright/tree/HEAD/packages/pyright/issues/11625">#11625</a>)</li>
    <li>8df447d6083456f57631bba0ba3e1746edd13523 Bump version to 1.1.412 (<a
    href="https://github.com/Microsoft/pyright/tree/HEAD/packages/pyright/issues/11624">#11624</a>)</li>
    <li>27001c2eb6540135dd09f625505f0cccc961715f Preserve union-expanded
    constructor types (<a
    href="https://github.com/Microsoft/pyright/tree/HEAD/packages/pyright/issues/11621">#11621</a>)</li>
    <li>870afb084c8620a68cd2a2f1dd7bac7de4d9ae40 Narrow closed TypedDicts on
    a key membership check (<a
    href="https://github.com/Microsoft/pyright/tree/HEAD/packages/pyright/issues/11620">#11620</a>)</li>
    <li>69c1b12356cbf3155add14d50be2563eebd3da8d Complete TypeForm
    conformance (<a
    href="https://github.com/Microsoft/pyright/tree/HEAD/packages/pyright/issues/11599">#11599</a>)</li>
    <li>eefd22541da12c4d5e7703c4ab9d1561131cacd9 Expand conditional
    TypedDict test coverage (<a
    href="https://github.com/Microsoft/pyright/tree/HEAD/packages/pyright/issues/11617">#11617</a>)</li>
    <li>273a1a8a9d0ea6589228ffaecab28e2ff425c1d2 Fix defaulted subclass type
    specialization (<a
    href="https://github.com/Microsoft/pyright/tree/HEAD/packages/pyright/issues/11596">#11596</a>)</li>
    <li>25641ef11dbe11371b4e3f026a731a1b0a58bd0e Apply overload
    materialization to nested Any (<a
    href="https://github.com/Microsoft/pyright/tree/HEAD/packages/pyright/issues/11601">#11601</a>)</li>
    <li>30e847056d8aaf4044412e5fb606e43eb5301a07 Implement PEP 800
    disjoint-base semantics (<a
    href="https://github.com/Microsoft/pyright/tree/HEAD/packages/pyright/issues/11593">#11593</a>)</li>
    </ul>
    <!-- raw HTML omitted -->
    <ul>
    <li>6b7f4c7df0d523cd2e4b2146a55dbf5714d3f625 Fix heterogeneous
    TypeVarTuple constraint solving (<a
    href="https://github.com/Microsoft/pyright/tree/HEAD/packages/pyright/issues/11595">#11595</a>)</li>
    <li>fd9ddadbf7c73046dc0e29c1367d4f82c7843328 Support complete enum
    literal union equivalence (<a
    href="https://github.com/Microsoft/pyright/tree/HEAD/packages/pyright/issues/11597">#11597</a>)</li>
    <li>623b043b9ee221e81ef7ef57505b0c98e4f61a7d docs: mention MegaLinter in
    CI integration page (<a
    href="https://github.com/Microsoft/pyright/tree/HEAD/packages/pyright/issues/11604">#11604</a>)</li>
    <li>e8af042e988f9b06b0c6da77b2269a8bd73e5d8d Support conditional
    TypedDict fields (<a
    href="https://github.com/Microsoft/pyright/tree/HEAD/packages/pyright/issues/11594">#11594</a>)</li>
    <li>dde0aae19c91db78d9a5b9e71564a2ed18595e5f Adapt stubPath
    special-casing to latest changes (<a
    href="https://github.com/Microsoft/pyright/tree/HEAD/packages/pyright/issues/11532">#11532</a>)</li>
    <li>de94b525d69e6b9554f39947d6c1eaefab5c41ab Bump brace-expansion from
    5.0.6 to 5.0.8 in /packages/vscode-pyright (<a
    href="https://github.com/Microsoft/pyright/tree/HEAD/packages/pyright/issues/11569">#11569</a>)</li>
    <li>491ade18bc464bd58bd2a6ab82785e21f51c4c69 Bump fast-uri from 3.1.2 to
    3.1.4 in /packages/pyright-internal (<a
    href="https://github.com/Microsoft/pyright/tree/HEAD/packages/pyright/issues/11566">#11566</a>)</li>
    <li>925dee8c790474f743fcd4bbf7a4c2b5e3edb382 Bump axios from 1.16.1 to
    1.18.1 (<a
    href="https://github.com/Microsoft/pyright/tree/HEAD/packages/pyright/issues/11555">#11555</a>)</li>
    <li>1e680297f9c018b035a0dfa2bbb7428cb204d504 Bump undici from 7.27.2 to
    7.28.0 in /packages/vscode-pyright (<a
    href="https://github.com/Microsoft/pyright/tree/HEAD/packages/pyright/issues/11512">#11512</a>)</li>
    <li>559a73706750cfb34c08209c0373dbe8ddbe8601 Fix bool narrowing for
    numeric literal patterns (<a
    href="https://github.com/Microsoft/pyright/tree/HEAD/packages/pyright/issues/11570">#11570</a>)</li>
    <li>729aabfa3c117bf9323edd19154d356cababd0ce Fix implicit
    <strong>class</strong> binding in lambdas (<a
    href="https://github.com/Microsoft/pyright/tree/HEAD/packages/pyright/issues/11541">#11541</a>)</li>
    <li>84711a8787101a472f4ed9e862286f46c685d57c Fix narrowing of walrus RHS
    under is/is not None (<a
    href="https://github.com/Microsoft/pyright/tree/HEAD/packages/pyright/issues/11564">#11564</a>)</li>
    <li>33bc458021aac4000b1a653e6cdd63cd2f71dae5 Fix false positive when
    assigning to attribute of union with divergent member types (<a
    href="https://github.com/Microsoft/pyright/tree/HEAD/packages/pyright/issues/11560">#11560</a>)
    [ <a
    href="https://github.com/Microsoft/pyright/tree/HEAD/packages/pyright/issues/11559">#11559</a>
    ]</li>
    <li>93ea6468a40c7c8cdab5643f66411da5e0414742 Fix <a
    href="https://github.com/Microsoft/pyright/tree/HEAD/packages/pyright/issues/11450">#11450</a>:
    [FR]: <code>struct.unpack</code> type inference (<a
    href="https://github.com/Microsoft/pyright/tree/HEAD/packages/pyright/issues/11494">#11494</a>)</li>
    <li>5fc16373b9e9d56cb8e57e707e9cc35c00bc3a6d Fix <a
    href="https://github.com/Microsoft/pyright/tree/HEAD/packages/pyright/issues/11475">#11475</a>:
    Cannot override a class's callable variable with a method (<a
    href="https://github.com/Microsoft/pyright/tree/HEAD/packages/pyright/issues/11500">#11500</a>)</li>
    <li>231b66e3429fbf4fa92f4396a83192a10e31b880 Fix <a
    href="https://github.com/Microsoft/pyright/tree/HEAD/packages/pyright/issues/11478">#11478</a>:
    Support overloads on property setters (<a
    href="https://github.com/Microsoft/pyright/tree/HEAD/packages/pyright/issues/11499">#11499</a>)</li>
    <li>4c60ea9967d2633894e873c1b53145a28106f9a8 Add standalone Type Server
    Protocol (TSP) server to Pyright (<a
    href="https://github.com/Microsoft/pyright/tree/HEAD/packages/pyright/issues/11537">#11537</a>)</li>
    <li>433e84d82d7944d129dbc239499d13eaae5f81ac Fix <a
    href="https://github.com/Microsoft/pyright/tree/HEAD/packages/pyright/issues/11453">#11453</a>:
    no error on accessing <strong>qualname</strong> of instance (<a
    href="https://github.com/Microsoft/pyright/tree/HEAD/packages/pyright/issues/11503">#11503</a>)</li>
    <li>da05559314c5e5171c95b1193ae627b96bb44aaf Skip unknown/missing
    parameter type checks for overload implementations (<a
    href="https://github.com/Microsoft/pyright/tree/HEAD/packages/pyright/issues/11498">#11498</a>)</li>
    <li>035fa623fdfc351aa0ba8e64a8fea127b62c13ee Report duplicate KW_ONLY
    separators in dataclasses (<a
    href="https://github.com/Microsoft/pyright/tree/HEAD/packages/pyright/issues/11495">#11495</a>)
    [ <a
    href="https://github.com/Microsoft/pyright/tree/HEAD/packages/pyright/issues/11486">#11486</a>
    ]</li>
    <li>155a25f14a8cafc458c9fbdedc516b17178200a1 Fix <a
    href="https://github.com/Microsoft/pyright/tree/HEAD/packages/pyright/issues/11472">#11472</a>:
    TypeVarTuple escapes method with very nested recursive tuple aliases (<a
    href="https://github.com/Microsoft/pyright/tree/HEAD/packages/pyright/issues/11497">#11497</a>)</li>
    <li>ffe1973e5db7c181819dfb049335490b3b868cf2 Fix <a
    href="https://github.com/Microsoft/pyright/tree/HEAD/packages/pyright/issues/11481">#11481</a>:
    1.1.410 detects type as module (<a
    href="https://github.com/Microsoft/pyright/tree/HEAD/packages/pyright/issues/11501">#11501</a>)
    [ <a
    href="https://github.com/Microsoft/pyright/tree/HEAD/packages/pyright/issues/11396">#11396</a>
    ]</li>
    <li>e1f6805d25ec12725a04d8f315845bedd7328ea4 Fix bounded type var match
    narrowing widening solved type args (<a
    href="https://github.com/Microsoft/pyright/tree/HEAD/packages/pyright/issues/11527">#11527</a>)
    [ <a
    href="https://github.com/Microsoft/pyright/tree/HEAD/packages/pyright/issues/11489">#11489</a>,
    <a
    href="https://github.com/Microsoft/pyright/tree/HEAD/packages/pyright/issues/11526">#11526</a>
    ]</li>
    <li>ab5cb1aeabf8225c86ea4f647a3c163fa14d342c Enable TypeForm support by
    default (<a
    href="https://github.com/Microsoft/pyright/tree/HEAD/packages/pyright/issues/11412">#11412</a>)
    [ <a
    href="https://github.com/Microsoft/pyright/tree/HEAD/packages/pyright/issues/2">#2</a>
    ]</li>
    </ul>
    <p>This list of changes was <a
    href="https://devdiv.visualstudio.com/DevDiv/_build/results?buildId=14944137&amp;view=logs">auto
    generated</a>.<!-- raw HTML omitted --></p>
    <h2>Published 1.1.411</h2>
    <h2>Changes:</h2>
    <ul>
    <li>9a9205fc32a2685767f38f348f5d9232701d4b0b fix Agentless jobs error in
    release (<a
    href="https://github.com/Microsoft/pyright/tree/HEAD/packages/pyright/issues/11524">#11524</a>)</li>
    <li>c9315a27b70339fb8e2124cd60c6227630668896 Bump version to 1.1.411 (<a
    href="https://github.com/Microsoft/pyright/tree/HEAD/packages/pyright/issues/11523">#11523</a>)</li>
    </ul>
    <!-- raw HTML omitted -->
    </blockquote>
    <p>... (truncated)</p>
    </details>
    <details>
    <summary>Commits</summary>
    <ul>
    <li><a
    href="https://github.com/microsoft/pyright/commit/71f676089137f1a7c6cf3a858fb9df5dce8d57a5"><code>71f6760</code></a>
    Bump version to 1.1.413 (<a
    href="https://github.com/Microsoft/pyright/tree/HEAD/packages/pyright/issues/11636">#11636</a>)</li>
    <li><a
    href="https://github.com/microsoft/pyright/commit/8df447d6083456f57631bba0ba3e1746edd13523"><code>8df447d</code></a>
    Bump version to 1.1.412 (<a
    href="https://github.com/Microsoft/pyright/tree/HEAD/packages/pyright/issues/11624">#11624</a>)</li>
    <li><a
    href="https://github.com/microsoft/pyright/commit/c9315a27b70339fb8e2124cd60c6227630668896"><code>c9315a2</code></a>
    Bump version to 1.1.411 (<a
    href="https://github.com/Microsoft/pyright/tree/HEAD/packages/pyright/issues/11523">#11523</a>)</li>
    <li><a
    href="https://github.com/microsoft/pyright/commit/a147f88b1e107c5fb826b12c38d6bc9475febccb"><code>a147f88</code></a>
    Pull Pylance with Pyright 1.1.410 (<a
    href="https://github.com/Microsoft/pyright/tree/HEAD/packages/pyright/issues/11522">#11522</a>)</li>
    <li><a
    href="https://github.com/microsoft/pyright/commit/de5220a32dc46997d0d7940633cdcf963e443a77"><code>de5220a</code></a>
    Pull Pylance with Pyright 1.1.410 (<a
    href="https://github.com/Microsoft/pyright/tree/HEAD/packages/pyright/issues/11506">#11506</a>)</li>
    <li><a
    href="https://github.com/microsoft/pyright/commit/92235e059ebe7805df8dd9cbc0a82cc7a3e4b1f2"><code>92235e0</code></a>
    Publish version 1.1.410 (<a
    href="https://github.com/Microsoft/pyright/tree/HEAD/packages/pyright/issues/11461">#11461</a>)</li>
    <li><a
    href="https://github.com/microsoft/pyright/commit/4cc1392284c66116b8bb13a6e2965faa152c77a6"><code>4cc1392</code></a>
    Update rspack dependencies to version 2.0.4 (<a
    href="https://github.com/Microsoft/pyright/tree/HEAD/packages/pyright/issues/11458">#11458</a>)</li>
    <li><a
    href="https://github.com/microsoft/pyright/commit/4243a1b36c91204720c4cf80e5bbcb4a0737a759"><code>4243a1b</code></a>
    Bump node-forge from 1.3.3 to 1.4.0 in /packages/pyright (<a
    href="https://github.com/Microsoft/pyright/tree/HEAD/packages/pyright/issues/11422">#11422</a>)</li>
    <li><a
    href="https://github.com/microsoft/pyright/commit/8f9807eefb292b4b66cd787b22ef5c4916358842"><code>8f9807e</code></a>
    Bump fast-uri from 3.1.0 to 3.1.2 in /packages/pyright (<a
    href="https://github.com/Microsoft/pyright/tree/HEAD/packages/pyright/issues/11428">#11428</a>)</li>
    <li><a
    href="https://github.com/microsoft/pyright/commit/53969cf1e39498f097437b4ee92cc2fad00cf641"><code>53969cf</code></a>
    fix: restore axios 1.16.0 and correct minimatch/npm-check-updates
    regressions...</li>
    <li>Additional commits viewable in <a
    href="https://github.com/Microsoft/pyright/commits/1.1.413/packages/pyright">compare
    view</a></li>
    </ul>
    </details>
    <details>
    <summary>Maintainer changes</summary>
    <p>This version was pushed to npm by <a
    href="https://www.npmjs.com/~microsoft1es">microsoft1es</a>, a new
    releaser for pyright since your current version.</p>
    </details>
    <br />
    
    
    [![Dependabot compatibility
    score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=pyright&package-manager=npm_and_yarn&previous-version=1.1.399&new-version=1.1.413)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
    
    Dependabot will resolve any conflicts with this PR as long as you don't
    alter it yourself. You can also trigger a rebase manually by commenting
    `@dependabot rebase`.
    
    [//]: # (dependabot-automerge-start)
    [//]: # (dependabot-automerge-end)
    
    ---
    
    <details>
    <summary>Dependabot commands and options</summary>
    <br />
    
    You can trigger Dependabot actions by commenting on this PR:
    - `@dependabot rebase` will rebase this PR
    - `@dependabot recreate` will recreate this PR, overwriting any edits
    that have been made to it
    - `@dependabot show <dependency name> ignore conditions` will show all
    of the ignore conditions of the specified dependency
    - `@dependabot ignore this major version` will close this PR and stop
    Dependabot creating any more for this major version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this minor version` will close this PR and stop
    Dependabot creating any more for this minor version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this dependency` will close this PR and stop
    Dependabot creating any more for this dependency (unless you reopen the
    PR or upgrade to it yourself)
    
    
    </details>
    
    ---------
    
    Signed-off-by: dependabot[bot] <support@github.com>
    Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
    Co-authored-by: Justin Beckwith <jbeckwith@openai.com>
    dependabot[bot] and jbeckwith-oai authored Aug 27, 2026
    Configuration menu
    Copy the full SHA
    9917c6e View commit details
    Browse the repository at this point in the history

Commits on Aug 28, 2026

  1. release: 3.6.0 (#3752)

    Automated Release PR
    ---
    
    
    ##
    [3.6.0](v3.5.0...v3.6.0)
    (2026-08-27)
    
    
    ### Features
    
    * **api:** add compute_units to Responses and Chat Completions usage
    ([#3749](#3749))
    ([52421d1](52421d1))
    
    
    ### Bug Fixes
    
    * **auth:** harden X.509 workload identity integration
    ([#3740](#3740))
    ([fc3ad6c](fc3ad6c))
    
    
    ### Chores
    
    * **deps-dev:** bump @stdy/cli from 0.22.1 to 0.22.2
    ([#3719](#3719))
    ([4f5598c](4f5598c))
    * **deps-dev:** bump mypy from 1.17 to 2.3.1
    ([#3747](#3747))
    ([0b52c9e](0b52c9e))
    * **deps-dev:** bump pandas-stubs from 2.2.2.240807 to 2.3.3.260113
    ([#3659](#3659))
    ([95f0b43](95f0b43))
    * **deps-dev:** bump pyright from 1.1.399 to 1.1.413
    ([#3744](#3744))
    ([9917c6e](9917c6e))
    * **deps-dev:** bump rich from 14.2.0 to 15.0.0
    ([#3717](#3717))
    ([7a5484d](7a5484d))
    * **deps:** bump actions/checkout from 6.0.2 to 7.0.1
    ([#3665](#3665))
    ([d0a2550](d0a2550))
    * **deps:** bump actions/download-artifact from 6.0.0 to 8.0.1
    ([#3669](#3669))
    ([f627619](f627619))
    * **deps:** bump github/codeql-action/init from 4.37.1 to 4.37.7
    ([#3745](#3745))
    ([a36010d](a36010d))
    
    
    ### Build System
    
    * **deps:** bump actions/setup-python from 5.6.0 to 7.0.0
    ([#3672](#3672))
    ([d765db7](d765db7))
    * **deps:** bump pypa/gh-action-pypi-publish from 1.14.0 to 1.14.2
    ([#3666](#3666))
    ([dacbb66](dacbb66))
    
    ---
    This PR was generated with [Release
    Please](https://github.com/googleapis/release-please). See
    [documentation](https://github.com/googleapis/release-please#release-please).
    
    Co-authored-by: openai-sdks[bot] <284451331+openai-sdks[bot]@users.noreply.github.com>
    openai-sdks[bot] authored Aug 28, 2026
    Configuration menu
    Copy the full SHA
    1cfa80a View commit details
    Browse the repository at this point in the history
Loading