Skip to content

chore(deps): bump the uv group across 6 directories with 6 updates - #142

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/apps/cyber-llm-server/uv-68840c061e
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/apps/cyber-llm-server/uv-68840c061e

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown
Contributor

Bumps the uv group with 1 update in the /apps/cyber-llm-server directory: vllm.
Bumps the uv group with 1 update in the /apps/infrastructure-llm-server directory: vllm.
Bumps the uv group with 1 update in the /apps/mtg-llm-server directory: vllm.
Bumps the uv group with 2 updates in the /features/chroma-mcp directory: anyio and oauthlib.
Bumps the uv group with 3 updates in the /features/commander-spellbook-backend/backend directory: oauthlib, cryptography and pyjwt.
Bumps the uv group with 2 updates in the /features/commander-spellbook-backend/bot/telegram directory: anyio and hpack.

Updates vllm from 0.11.0 to 0.28.0

Release notes

Sourced from vllm's releases.

v0.28.0

Highlights

This release features 584 commits from 270 contributors (76 new)!

  • Kimi-K3 performance push: a major optimization effort for Kimi-K3 across the stack — Decode Context Parallel (DCP) support (#50484), fused FlashKDA decode and prefill kernels (#50654, #51311, #52458), SiTU activation support for MegaMoE (#50510), GEMM-RS for sequence parallelism (#52079), combined all-gathers with 1.5~3x kernel-level speedup (#51070), an adaptive speculative token budget delivering ~60% better DSpark TTFT (#51725), and optional shared-expert sharding saving ~17 GiB of memory per GPU (#50912). Kimi-K3 also now runs on ROCm with the V2 model runner (#51653).
  • DeepSeek V4: sparse MLA now works end-to-end for plain decode, MTP, and DSpark speculative decoding (#51538), joined by AMD Quark NVFP4 support (#47972), reasoning-effort prompts and mappings (#50580), sparse top-k metadata kernel optimizations (#52084, #51967), narrowed eager CUDA graph regions (#51430, #52401), and ROCm enablement on gfx11 and gfx950 (#47017, #52212).
  • Speculative decoding advances: DFlash2 with local convolution and a candidate selector (#52816), DSpark confidence-scheduled verification (#47808), and async scheduling auto-enabled for draft models (#48341).
  • Model Runner V2 maturation: E/P/D disaggregation (#38390), weight offloading (#51413), multi-layer MTP KV cache support (#50062), encoder CUDA graphs (#49852), decoder token-wise pooling (#50931) plus Transformers pooling models (#52425), attention-free models (#52374), and thinking_token_budget support (#46727).
  • Tiered KV cache offloading: disk offloading support (#49644), out-of-tree secondary tier managers via module_path (#51007), partial secondary-tier load results (#50321), tiering metrics (#48798), and a canonical CPU layout for parallelism-agnostic offload (#48414).
  • Rust frontend & gRPC: a standalone renderer (#50289), multimodal image inference over gRPC (#50368), explicit data-parallel rank routing (#51178), and RL lifecycle control (#51316), with protobuf schemas now published to Buf (#51276).
  • New defaults: max_num_batched_tokens raised from 8192 to 16384 (#51726), prefix caching enabled by default for Mamba models (#50991), and the Blackwell CUDA graph capture default raised to 1024 (#49390).
  • Breaking changes: bitsandbytes support migrated to an out-of-tree plugin (#43529); Transformers bumped to 5.15.0 (#51668); the deprecated calculate_kv_scales runtime KV scale calculation was removed (#49389); override_attention_dtype was removed (#48684).

Release Artifacts

Python Wheels

Platform Install
PyPI (CUDA 13.0) pip install vllm
PyPI (CUDA 13.0, uv) uv pip install vllm --torch-backend=auto
ROCm pip install vllm --extra-index-url https://wheels.vllm.ai/rocm/0.28.0/rocm722

Docker Images

Platform Docker Image
CUDA 13.0 (Default) docker pull vllm/vllm-openai:v0.28.0 (v0.28.0-cu130 also works)
CUDA 12.9 docker pull vllm/vllm-openai:v0.28.0-cu129
CUDA 13.0 + Ubuntu 24.04 docker pull vllm/vllm-openai:v0.28.0-ubuntu2404
CUDA 12.9 + Ubuntu 24.04 docker pull vllm/vllm-openai:v0.28.0-cu129-ubuntu2404
ROCm docker pull vllm/vllm-openai-rocm:v0.28.0
CPU docker pull vllm/vllm-openai-cpu:v0.28.0
XPU docker pull vllm/vllm-openai-xpu:v0.28.0

Other Artifacts

Pre-built release artifacts are available in the Assets section at the bottom of this page, including:

  • Source distribution tarball
  • CUDA 12.9 Python wheels for x86_64 and arm64
  • CUDA 13.0 Python wheels for x86_64 and arm64
  • CPU Python wheels for x86_64, arm64, and macOS

Model Support

  • New models: Muse Glimmer (#51655), Ling 3.0 Flash with BF16, MTP, and parser support (#51045) plus an FP8 variant (#51265) and hybrid MXFP4 routed experts (#52114), Dots3 NOTE native multimodal support (#51255), and Interns2mobius (#51149).
  • Qwen: Qwen3.8 enabled on AMD ROCm (#50068), fused CUDA post-conv MTP decode kernel for Qwen3.5 GDN (#51674), GDN gates aligned with speculative tokens (#51812), and Qwen3.5 fixes for text-only checkpoints (#50734, #50355).
  • Transformers modeling backend: MLA support (#48250), hardware-agnostic model definition (#49458), fully generalized input embedding handling (#51247), logit softcapping (#52173), and a hardened multimodal path (#51408, #51657).
  • LoRA: vision tower LoRA for Gemma4 (#42662), tower/connector LoRA for Keye (#51780) and Ultravox (#48215).

... (truncated)

Commits
  • 2cf0a69 [CI/Build] Pin Cython below 3.3 for arm64 tilelang sdist (#53358)
  • 9991487 Revert "[Kernel] Gemma-4 FA4 FP8 Kernel" (#52987)
  • 1af5a38 [CI][Release] Extend DSv4 engine readiness timeout (#53252)
  • 74a6576 [Spec Decode] DFlash2: local convolution + candidate selector (#52816)
  • cf902bd [CI/Build] Fix accident pre-commit breakage due to concurrent merge (#52578)
  • cd6ae1e [Bugfix][Security] Guard _load_ov2_processor with resolve_trust_remote_code (...
  • b7d8e0f [kv_offload] fix(metrics): rename kv_offload_tiering_block_{queries,hits} → c...
  • c0eac6f [ROCm]: Bump triton 3.7 commit (#52819)
  • 855e09e [Kernel] SM120: stop routing misaligned-M blockwise FP8 GEMMs to the small-M ...
  • 1b6ed9b [EPD] Allow KV consumers to omit MM embeddings (#52697)
  • Additional commits viewable in compare view

Updates vllm from 0.11.0 to 0.28.0

Release notes

Sourced from vllm's releases.

v0.28.0

Highlights

This release features 584 commits from 270 contributors (76 new)!

  • Kimi-K3 performance push: a major optimization effort for Kimi-K3 across the stack — Decode Context Parallel (DCP) support (#50484), fused FlashKDA decode and prefill kernels (#50654, #51311, #52458), SiTU activation support for MegaMoE (#50510), GEMM-RS for sequence parallelism (#52079), combined all-gathers with 1.5~3x kernel-level speedup (#51070), an adaptive speculative token budget delivering ~60% better DSpark TTFT (#51725), and optional shared-expert sharding saving ~17 GiB of memory per GPU (#50912). Kimi-K3 also now runs on ROCm with the V2 model runner (#51653).
  • DeepSeek V4: sparse MLA now works end-to-end for plain decode, MTP, and DSpark speculative decoding (#51538), joined by AMD Quark NVFP4 support (#47972), reasoning-effort prompts and mappings (#50580), sparse top-k metadata kernel optimizations (#52084, #51967), narrowed eager CUDA graph regions (#51430, #52401), and ROCm enablement on gfx11 and gfx950 (#47017, #52212).
  • Speculative decoding advances: DFlash2 with local convolution and a candidate selector (#52816), DSpark confidence-scheduled verification (#47808), and async scheduling auto-enabled for draft models (#48341).
  • Model Runner V2 maturation: E/P/D disaggregation (#38390), weight offloading (#51413), multi-layer MTP KV cache support (#50062), encoder CUDA graphs (#49852), decoder token-wise pooling (#50931) plus Transformers pooling models (#52425), attention-free models (#52374), and thinking_token_budget support (#46727).
  • Tiered KV cache offloading: disk offloading support (#49644), out-of-tree secondary tier managers via module_path (#51007), partial secondary-tier load results (#50321), tiering metrics (#48798), and a canonical CPU layout for parallelism-agnostic offload (#48414).
  • Rust frontend & gRPC: a standalone renderer (#50289), multimodal image inference over gRPC (#50368), explicit data-parallel rank routing (#51178), and RL lifecycle control (#51316), with protobuf schemas now published to Buf (#51276).
  • New defaults: max_num_batched_tokens raised from 8192 to 16384 (#51726), prefix caching enabled by default for Mamba models (#50991), and the Blackwell CUDA graph capture default raised to 1024 (#49390).
  • Breaking changes: bitsandbytes support migrated to an out-of-tree plugin (#43529); Transformers bumped to 5.15.0 (#51668); the deprecated calculate_kv_scales runtime KV scale calculation was removed (#49389); override_attention_dtype was removed (#48684).

Release Artifacts

Python Wheels

Platform Install
PyPI (CUDA 13.0) pip install vllm
PyPI (CUDA 13.0, uv) uv pip install vllm --torch-backend=auto
ROCm pip install vllm --extra-index-url https://wheels.vllm.ai/rocm/0.28.0/rocm722

Docker Images

Platform Docker Image
CUDA 13.0 (Default) docker pull vllm/vllm-openai:v0.28.0 (v0.28.0-cu130 also works)
CUDA 12.9 docker pull vllm/vllm-openai:v0.28.0-cu129
CUDA 13.0 + Ubuntu 24.04 docker pull vllm/vllm-openai:v0.28.0-ubuntu2404
CUDA 12.9 + Ubuntu 24.04 docker pull vllm/vllm-openai:v0.28.0-cu129-ubuntu2404
ROCm docker pull vllm/vllm-openai-rocm:v0.28.0
CPU docker pull vllm/vllm-openai-cpu:v0.28.0
XPU docker pull vllm/vllm-openai-xpu:v0.28.0

Other Artifacts

Pre-built release artifacts are available in the Assets section at the bottom of this page, including:

  • Source distribution tarball
  • CUDA 12.9 Python wheels for x86_64 and arm64
  • CUDA 13.0 Python wheels for x86_64 and arm64
  • CPU Python wheels for x86_64, arm64, and macOS

Model Support

  • New models: Muse Glimmer (#51655), Ling 3.0 Flash with BF16, MTP, and parser support (#51045) plus an FP8 variant (#51265) and hybrid MXFP4 routed experts (#52114), Dots3 NOTE native multimodal support (#51255), and Interns2mobius (#51149).
  • Qwen: Qwen3.8 enabled on AMD ROCm (#50068), fused CUDA post-conv MTP decode kernel for Qwen3.5 GDN (#51674), GDN gates aligned with speculative tokens (#51812), and Qwen3.5 fixes for text-only checkpoints (#50734, #50355).
  • Transformers modeling backend: MLA support (#48250), hardware-agnostic model definition (#49458), fully generalized input embedding handling (#51247), logit softcapping (#52173), and a hardened multimodal path (#51408, #51657).
  • LoRA: vision tower LoRA for Gemma4 (#42662), tower/connector LoRA for Keye (#51780) and Ultravox (#48215).

... (truncated)

Commits
  • 2cf0a69 [CI/Build] Pin Cython below 3.3 for arm64 tilelang sdist (#53358)
  • 9991487 Revert "[Kernel] Gemma-4 FA4 FP8 Kernel" (#52987)
  • 1af5a38 [CI][Release] Extend DSv4 engine readiness timeout (#53252)
  • 74a6576 [Spec Decode] DFlash2: local convolution + candidate selector (#52816)
  • cf902bd [CI/Build] Fix accident pre-commit breakage due to concurrent merge (#52578)
  • cd6ae1e [Bugfix][Security] Guard _load_ov2_processor with resolve_trust_remote_code (...
  • b7d8e0f [kv_offload] fix(metrics): rename kv_offload_tiering_block_{queries,hits} → c...
  • c0eac6f [ROCm]: Bump triton 3.7 commit (#52819)
  • 855e09e [Kernel] SM120: stop routing misaligned-M blockwise FP8 GEMMs to the small-M ...
  • 1b6ed9b [EPD] Allow KV consumers to omit MM embeddings (#52697)
  • Additional commits viewable in compare view

Updates vllm from 0.11.0 to 0.28.0

Release notes

Sourced from vllm's releases.

v0.28.0

Highlights

This release features 584 commits from 270 contributors (76 new)!

  • Kimi-K3 performance push: a major optimization effort for Kimi-K3 across the stack — Decode Context Parallel (DCP) support (#50484), fused FlashKDA decode and prefill kernels (#50654, #51311, #52458), SiTU activation support for MegaMoE (#50510), GEMM-RS for sequence parallelism (#52079), combined all-gathers with 1.5~3x kernel-level speedup (#51070), an adaptive speculative token budget delivering ~60% better DSpark TTFT (#51725), and optional shared-expert sharding saving ~17 GiB of memory per GPU (#50912). Kimi-K3 also now runs on ROCm with the V2 model runner (#51653).
  • DeepSeek V4: sparse MLA now works end-to-end for plain decode, MTP, and DSpark speculative decoding (#51538), joined by AMD Quark NVFP4 support (#47972), reasoning-effort prompts and mappings (#50580), sparse top-k metadata kernel optimizations (#52084, #51967), narrowed eager CUDA graph regions (#51430, #52401), and ROCm enablement on gfx11 and gfx950 (#47017, #52212).
  • Speculative decoding advances: DFlash2 with local convolution and a candidate selector (#52816), DSpark confidence-scheduled verification (#47808), and async scheduling auto-enabled for draft models (#48341).
  • Model Runner V2 maturation: E/P/D disaggregation (#38390), weight offloading (#51413), multi-layer MTP KV cache support (#50062), encoder CUDA graphs (#49852), decoder token-wise pooling (#50931) plus Transformers pooling models (#52425), attention-free models (#52374), and thinking_token_budget support (#46727).
  • Tiered KV cache offloading: disk offloading support (#49644), out-of-tree secondary tier managers via module_path (#51007), partial secondary-tier load results (#50321), tiering metrics (#48798), and a canonical CPU layout for parallelism-agnostic offload (#48414).
  • Rust frontend & gRPC: a standalone renderer (#50289), multimodal image inference over gRPC (#50368), explicit data-parallel rank routing (#51178), and RL lifecycle control (#51316), with protobuf schemas now published to Buf (#51276).
  • New defaults: max_num_batched_tokens raised from 8192 to 16384 (#51726), prefix caching enabled by default for Mamba models (#50991), and the Blackwell CUDA graph capture default raised to 1024 (#49390).
  • Breaking changes: bitsandbytes support migrated to an out-of-tree plugin (#43529); Transformers bumped to 5.15.0 (#51668); the deprecated calculate_kv_scales runtime KV scale calculation was removed (#49389); override_attention_dtype was removed (#48684).

Release Artifacts

Python Wheels

Platform Install
PyPI (CUDA 13.0) pip install vllm
PyPI (CUDA 13.0, uv) uv pip install vllm --torch-backend=auto
ROCm pip install vllm --extra-index-url https://wheels.vllm.ai/rocm/0.28.0/rocm722

Docker Images

Platform Docker Image
CUDA 13.0 (Default) docker pull vllm/vllm-openai:v0.28.0 (v0.28.0-cu130 also works)
CUDA 12.9 docker pull vllm/vllm-openai:v0.28.0-cu129
CUDA 13.0 + Ubuntu 24.04 docker pull vllm/vllm-openai:v0.28.0-ubuntu2404
CUDA 12.9 + Ubuntu 24.04 docker pull vllm/vllm-openai:v0.28.0-cu129-ubuntu2404
ROCm docker pull vllm/vllm-openai-rocm:v0.28.0
CPU docker pull vllm/vllm-openai-cpu:v0.28.0
XPU docker pull vllm/vllm-openai-xpu:v0.28.0

Other Artifacts

Pre-built release artifacts are available in the Assets section at the bottom of this page, including:

  • Source distribution tarball
  • CUDA 12.9 Python wheels for x86_64 and arm64
  • CUDA 13.0 Python wheels for x86_64 and arm64
  • CPU Python wheels for x86_64, arm64, and macOS

Model Support

  • New models: Muse Glimmer (#51655), Ling 3.0 Flash with BF16, MTP, and parser support (#51045) plus an FP8 variant (#51265) and hybrid MXFP4 routed experts (#52114), Dots3 NOTE native multimodal support (#51255), and Interns2mobius (#51149).
  • Qwen: Qwen3.8 enabled on AMD ROCm (#50068), fused CUDA post-conv MTP decode kernel for Qwen3.5 GDN (#51674), GDN gates aligned with speculative tokens (#51812), and Qwen3.5 fixes for text-only checkpoints (#50734, #50355).
  • Transformers modeling backend: MLA support (#48250), hardware-agnostic model definition (#49458), fully generalized input embedding handling (#51247), logit softcapping (#52173), and a hardened multimodal path (#51408, #51657).
  • LoRA: vision tower LoRA for Gemma4 (#42662), tower/connector LoRA for Keye (#51780) and Ultravox (#48215).

... (truncated)

Commits
  • 2cf0a69 [CI/Build] Pin Cython below 3.3 for arm64 tilelang sdist (#53358)
  • 9991487 Revert "[Kernel] Gemma-4 FA4 FP8 Kernel" (#52987)
  • 1af5a38 [CI][Release] Extend DSv4 engine readiness timeout (#53252)
  • 74a6576 [Spec Decode] DFlash2: local convolution + candidate selector (#52816)
  • cf902bd [CI/Build] Fix accident pre-commit breakage due to concurrent merge (#52578)
  • cd6ae1e [Bugfix][Security] Guard _load_ov2_processor with resolve_trust_remote_code (...
  • b7d8e0f [kv_offload] fix(metrics): rename kv_offload_tiering_block_{queries,hits} → c...
  • c0eac6f [ROCm]: Bump triton 3.7 commit (#52819)
  • 855e09e [Kernel] SM120: stop routing misaligned-M blockwise FP8 GEMMs to the small-M ...
  • 1b6ed9b [EPD] Allow KV consumers to omit MM embeddings (#52697)
  • Additional commits viewable in compare view

Updates anyio from 4.9.0 to 4.14.2

Release notes

Sourced from anyio's releases.

4.14.2

  • Changed ByteReceiveStream.receive() implementations to raise a ValueError when max_bytes is not a positive integer (#1191)
  • Fixed CapacityLimiter.total_tokens rejecting float("inf") when the limiter was instantiated outside of an event loop. The adapter setter checked for infinity by identity (value is math.inf), so only the exact math.inf singleton was accepted, while every backend setter (using math.isinf()) accepts any positive infinity (#1189; PR by @​greymoth-jp).
  • Fixed to_process.run_sync() deadlocking when the worker function writes enough data to sys.stderr to fill the (undrained) pipe buffer. The worker process now redirects sys.stderr to os.devnull as well, matching the documented behavior
  • Fixed TLSStream.wrap() matching an internationalized (unicode) host name against the peer certificate using IDNA 2003 (via the standard library) instead of IDNA 2008, which could cause the host name to be matched against the wrong certificate (#1208)
  • Fixed anyio.open_process() (and run_process()) ignoring the extra_groups argument, as it mistakenly passed the value of the group argument instead (#1209)
  • Fixed CapacityLimiter.acquire_nowait() and CapacityLimiter.acquire_nowait_on_behalf_of() raising trio.WouldBlock instead of anyio.WouldBlock on the trio backend when there are no tokens available (#1218)
  • Fixed CapacityLimiter on the asyncio backend over-granting tokens (borrowed_tokens exceeding total_tokens and available_tokens going negative) when a non-blocking acquire was made in the window between a token being released and the notified waiter resuming. The freed token is now reserved for the woken waiter right away, so the non-blocking acquire correctly raises WouldBlock (#1170; PR by @​gaoflow)
  • Fixed unnecessary CPU spin when delivering cancellation from CancelScope on asyncio under certain conditions, including improper cancel scope nesting (#1111)

4.14.1

  • Fixed teardown of higher-scoped async fixtures failing on asyncio with RuntimeError: Attempted to exit cancel scope in a different task than it was entered in when an async test raise an outcome exception (e.g., pytest.skip(), pytest.xfail(), or pytest.fail()) (#1179; PR by @​EmmanuelNiyonshuti)
  • Fixed CapacityLimiter.total_tokens rejecting a value of 0 when the limiter was instantiated outside of an event loop, contradicting the documented behavior of allowing 0 total tokens (#1183; PR by @​nyxst4ck)

4.14.0

  • Added support for Python 3.15

  • Added an asynchronous implementation of the itertools module (#998; PR by @​11kkw)

  • Added the local_port parameter to connect_tcp() to allow binding to a specific local port before connecting (#1067; PR by @​nullwiz)

  • Added support for custom capacity limiters in async path and file I/O functions and classes

  • Added the create_task() task group method for easier asyncio migration (returns a TaskHandle) (#1098)

  • Changed TaskGroup.start_soon() to return a TaskHandle

  • Added an option for TaskGroup.start() to return a TaskHandle (which then contains the start value in the start_value property)

  • Added the cancel() convenience method to TaskGroup as a shortcut for cancelling the task group's cancel scope

  • Improved the error message when a known backend is not installed to suggest the install command (#1115; PR by @​EmmanuelNiyonshuti)

  • Improved anyio.Path to preserve subclass types by returning Self in methods that return path objects (#1130; PR by @​EmmanuelNiyonshuti)

  • Changed the parameter type annotation in anyio.Path.write_bytes() to accept any ReadableBuffer, thus allowing it to accept bytearray and memoryview to match pathlib.Path.write_bytes() (#1135; PR by @​SAY-5)

  • Changed several type annotations to only accept callables returning coroutine-like objects instead of arbitrary awaitables:

    • TaskGroup.start_soon()
    • TaskGroup.start()
    • anyio.from_thread.run()

    This reverts an earlier change from v3.7.0 which was made in error. (#1153)

  • Changed anyio.run to support callables returning arbitrary awaitables at runtime on all backends. Previously, this only worked on asyncio (#1171; PR by @​gschaffner)

  • Changed several classes (and their subclasses) to have __slots__ (with __weakref__):

    • anyio.CancelScope

... (truncated)

Commits
  • c384f99 Bumped up the version
  • dbba29d Fixed 100% CPU spin on cancel scope misuse (#1217)
  • 6bbc6c3 Fix CapacityLimiter over-granting tokens on asyncio (#1172)
  • 6f82b25 Refactored TestTLSStream.test_receive_invalid_max_bytes() to be less flaky
  • be24b04 Relaxed timeouts to fix test flakiness
  • 8113506 Fix test flakiness caused by slow callback duration logging
  • 1e988b6 Fixed CapacityLimiter raising trio.WouldBlock instead of anyio.WouldBlock (#1...
  • 44713f3 Pin setup-uv to a commit sha across downstream jobs (#1213)
  • f1b7301 Fixed stderr writes in a worker subprocess causing a deadlock (#1207)
  • 212be93 Fix flaky test_tcp_listener_same_port using a hardcoded port (#1206)
  • Additional commits viewable in compare view

Updates oauthlib from 3.2.2 to 4.0.0

Release notes

Sourced from oauthlib's releases.

4.0.0

Introduction

The release 4.0.0 defines the foundation that enables AI contributions and will improve the maintenance of oauthlib by using AI agents, skills, code for both contributors and maintainers. It includes devcontainer, skills and cleanup of instructions.

What's Changed

Important: this release contains 2 breaking changes. See CHANGELOG.rst for details:

  • Removed JSONP support from token revocation endpoint (#951)
  • Client authentication validation reorganized across grants (#919, #920): the grant_type parameter is now validated before client authentication.

New Contributors

Full Changelog: oauthlib/oauthlib@v3.3.1...v4.0.0

3.3.1

What's Changed

Full Changelog: oauthlib/oauthlib@v3.3.0...v3.3.1

... (truncated)

Changelog

Sourced from oauthlib's changelog.

4.0.0 (2026-09-28):

OAuth2.0 Provider:

  • Breaking: #951: Removed JSONP support from token revocation endpoint. JSONP has been superseded by CORS for cross-origin requests. The enable_jsonp parameter has been removed from RevocationEndpoint and the callback parameter has been removed from prepare_token_revocation_request.
  • Breaking: #919, #920: Fixed DeviceCodeGrant.validate_token_request trying to authenticate public clients. Client authentication validation has been reorganized and is now shared across AuthorizationCodeGrant, DeviceCodeGrant, RefreshTokenGrant and ResourceOwnerPasswordCredentialsGrant: the grant_type parameter is validated before client authentication, so requests missing grant_type now return 400 invalid_request instead of 401 invalid_client.
  • #963: Improved PKCE code comparison

Misc:

  • #904: Stop installing examples into site-packages.
  • #930: Add devcontainer, Add Python3.14, Python3.14t.
  • #931: Fix ruff checks about unused variables.
  • #932: Dropped EOL Python 3.8 from CI.
  • #934: Pre-commit hooks autoupdate.
  • #938: Fix typos discovered by typos.
  • Add OAuthLib Maintainer agent for automated issue/PR triage and release management.

3.3.1 (2025-06-19):

OAuth2.0 Client:

  • #906: fix regression of expires_in parsing when float in string.

3.3.0 (2025-06-17):

OAuth2.0 Provider:

  • OIDC: #879 Changed in how ui_locales is parsed
  • RFC8628: Added OAuth2.0 Device Authorization Grant support
  • PKCE: #876, #893 Fixed create_code_verifier length
  • OIDC: Pre-configured OIDC server to use Refresh Token by default

OAuth2.0 Common:

  • OAuth2Error: Allow 0 to be a valid state

OAuth2.0 Client:

  • #745: expires_at is forced to be an int
  • #899: expires_at clarification

General:

... (truncated)

Commits
  • 145a9a4 Release 4.0.0: clarify changelog breaking changes and reformat entries
  • c8344d6 Update CHANGELOG.rst
  • e172830 Release 4.0.0: bump version to 4.0.0 and update changelog
  • 40b0ab5 Merge pull request #963 from oauthlib/ft/pkcecode
  • 1b68cea Merge pull request #920 from hekhuisk/validate-client-authentication
  • c951a1d Organized validate_client functions for all grant to avoid mistake in grnat i...
  • 74664d3 Improve PKCE code comparison
  • 9859b05 Merge pull request #950 from oauthlib/feature/3.4.0-maintainer-agent
  • 9bf9b97 Merge branch 'master' into feature/3.4.0-maintainer-agent
  • 1ba7429 Clarify agent instructions
  • Additional commits viewable in compare view

Updates oauthlib from 3.2.2 to 4.0.0

Release notes

Sourced from oauthlib's releases.

4.0.0

Introduction

The release 4.0.0 defines the foundation that enables AI contributions and will improve the maintenance of oauthlib by using AI agents, skills, code for both contributors and maintainers. It includes devcontainer, skills and cleanup of instructions.

What's Changed

Important: this release contains 2 breaking changes. See CHANGELOG.rst for details:

  • Removed JSONP support from token revocation endpoint (#951)
  • Client authentication validation reorganized across grants (#919, #920): the grant_type parameter is now validated before client authentication.

Bumps the uv group with 1 update in the /apps/cyber-llm-server directory: [vllm](https://github.com/vllm-project/vllm).
Bumps the uv group with 1 update in the /apps/infrastructure-llm-server directory: [vllm](https://github.com/vllm-project/vllm).
Bumps the uv group with 1 update in the /apps/mtg-llm-server directory: [vllm](https://github.com/vllm-project/vllm).
Bumps the uv group with 2 updates in the /features/chroma-mcp directory: [anyio](https://github.com/agronholm/anyio) and [oauthlib](https://github.com/oauthlib/oauthlib).
Bumps the uv group with 3 updates in the /features/commander-spellbook-backend/backend directory: [oauthlib](https://github.com/oauthlib/oauthlib), [cryptography](https://github.com/pyca/cryptography) and [pyjwt](https://github.com/jpadilla/pyjwt).
Bumps the uv group with 2 updates in the /features/commander-spellbook-backend/bot/telegram directory: [anyio](https://github.com/agronholm/anyio) and [hpack](https://github.com/python-hyper/hpack).


Updates `vllm` from 0.11.0 to 0.28.0
- [Release notes](https://github.com/vllm-project/vllm/releases)
- [Commits](vllm-project/vllm@v0.11.0...v0.28.0)

Updates `vllm` from 0.11.0 to 0.28.0
- [Release notes](https://github.com/vllm-project/vllm/releases)
- [Commits](vllm-project/vllm@v0.11.0...v0.28.0)

Updates `vllm` from 0.11.0 to 0.28.0
- [Release notes](https://github.com/vllm-project/vllm/releases)
- [Commits](vllm-project/vllm@v0.11.0...v0.28.0)

Updates `anyio` from 4.9.0 to 4.14.2
- [Release notes](https://github.com/agronholm/anyio/releases)
- [Commits](agronholm/anyio@4.9.0...4.14.2)

Updates `oauthlib` from 3.2.2 to 4.0.0
- [Release notes](https://github.com/oauthlib/oauthlib/releases)
- [Changelog](https://github.com/oauthlib/oauthlib/blob/master/CHANGELOG.rst)
- [Commits](oauthlib/oauthlib@v3.2.2...v4.0.0)

Updates `oauthlib` from 3.2.2 to 4.0.0
- [Release notes](https://github.com/oauthlib/oauthlib/releases)
- [Changelog](https://github.com/oauthlib/oauthlib/blob/master/CHANGELOG.rst)
- [Commits](oauthlib/oauthlib@v3.2.2...v4.0.0)

Updates `cryptography` from 46.0.3 to 50.0.0
- [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst)
- [Commits](pyca/cryptography@46.0.3...50.0.0)

Updates `pyjwt` from 2.8.0 to 2.15.0
- [Release notes](https://github.com/jpadilla/pyjwt/releases)
- [Changelog](https://github.com/jpadilla/pyjwt/blob/master/CHANGELOG.rst)
- [Commits](jpadilla/pyjwt@2.8.0...2.15.0)

Updates `anyio` from 4.10.0 to 4.14.2
- [Release notes](https://github.com/agronholm/anyio/releases)
- [Commits](agronholm/anyio@4.9.0...4.14.2)

Updates `hpack` from 4.1.0 to 4.2.0
- [Changelog](https://github.com/python-hyper/hpack/blob/master/CHANGELOG.rst)
- [Commits](python-hyper/hpack@v4.1.0...v4.2.0)

---
updated-dependencies:
- dependency-name: vllm
  dependency-version: 0.28.0
  dependency-type: direct:production
  dependency-group: uv
- dependency-name: vllm
  dependency-version: 0.28.0
  dependency-type: direct:production
  dependency-group: uv
- dependency-name: vllm
  dependency-version: 0.28.0
  dependency-type: direct:production
  dependency-group: uv
- dependency-name: anyio
  dependency-version: 4.14.2
  dependency-type: indirect
  dependency-group: uv
- dependency-name: oauthlib
  dependency-version: 4.0.0
  dependency-type: indirect
  dependency-group: uv
- dependency-name: oauthlib
  dependency-version: 4.0.0
  dependency-type: indirect
  dependency-group: uv
- dependency-name: cryptography
  dependency-version: 50.0.0
  dependency-type: indirect
  dependency-group: uv
- dependency-name: pyjwt
  dependency-version: 2.15.0
  dependency-type: indirect
  dependency-group: uv
- dependency-name: anyio
  dependency-version: 4.14.2
  dependency-type: indirect
  dependency-group: uv
- dependency-name: hpack
  dependency-version: 4.2.0
  dependency-type: indirect
  dependency-group: uv
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels Oct 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants