Skip to content

deps: update pydantic requirement from !=2.0.*,!=2.1.*,!=2.2.*,!=2.3.*,!=2.4.0,!=2.4.1,>=1.10.18 to !=2.0.0.dev,!=2.1.0.dev,!=2.2.0.dev,!=2.3.0.dev,!=2.4.0,!=2.4.1,>=2.13.5 - #130

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/pydantic-neq-2.0.0.dev-and-neq-2.1.0.dev-and-neq-2.2.0.dev-and-neq-2.3.0.dev-and-neq-2.4.0-and-neq-2.4.1-and-gte-2.13.5
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/pydantic-neq-2.0.0.dev-and-neq-2.1.0.dev-and-neq-2.2.0.dev-and-neq-2.3.0.dev-and-neq-2.4.0-and-neq-2.4.1-and-gte-2.13.5

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 28, 2026

Copy link
Copy Markdown

Updates the requirements on pydantic to permit the latest version.

Release notes

Sourced from pydantic's releases.

v2.13.5 (2026-08-28)

What's Changed

Fixes

  • Allow reuse of validators when plugins are set by @​Viicos in #13535
  • Fix missing GC traversal on some pydantic-core struct fields by @​Viicos in #13624
  • Fix missing GC traversal in pydantic-core for GeneralFieldsSerializer by @​Viicos in #13629
  • Count validated model fields once in smart unions by @​tamird in #13731
Changelog

Sourced from pydantic's changelog.

v2.13.5 (2026-08-28)

GitHub release

What's Changed

Fixes

  • Allow reuse of validators when plugins are set by @​Viicos in #13535
  • Fix missing GC traversal on some pydantic-core struct fields by @​Viicos in #13624
  • Fix missing GC traversal in pydantic-core for GeneralFieldsSerializer by @​Viicos in #13629
  • Count validated model fields once in smart unions by @​tamird in #13731

v2.13.4 (2026-05-06)

GitHub release

What's Changed

Packaging

Fixes

v2.13.3 (2026-04-20)

GitHub release

What's Changed

Fixes

v2.13.2 (2026-04-17)

GitHub release

What's Changed

Fixes

  • Fix ValidationInfo.field_name missing with model_validate_json() by @​Viicos in #13084

v2.13.1 (2026-04-15)

... (truncated)

Commits
  • 001dea0 Bump pypa/gh-action-pypi-publish action to v1.14.2
  • 558379f Bump twine to v7.0.0
  • 2cfd5d3 Do not check for docs build
  • a735bee Fix more Clippy lints
  • 7eed4a1 Fix Clippy 0.1.95 warnings
  • b353bbb Prepare release v2.13.5
  • 63d2ccc Count validated model fields once in smart unions
  • a53ec2e Speed up PyPy CI tests
  • d65e0f9 Workaround circular import error in Mypy
  • 47a6dbf Fix missing GC traversal in pydantic-core for GeneralFieldsSerializer
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Updates the requirements on [pydantic](https://github.com/pydantic/pydantic) to permit the latest version.
- [Release notes](https://github.com/pydantic/pydantic/releases)
- [Changelog](https://github.com/pydantic/pydantic/blob/v2.13.5/HISTORY.md)
- [Commits](pydantic/pydantic@v1.10.18...v2.13.5)

---
updated-dependencies:
- dependency-name: pydantic
  dependency-version: 2.13.5
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Sep 28, 2026

Copy link
Copy Markdown
Author

Labels

The following labels could not be found: dependencies. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@github-actions

Copy link
Copy Markdown

Dependency Security Audit

Scanned: requirements.txt + requirements-dev.txt, resolved at Python 3.10 (the current resolution, and the lowest versions the published specs permit under each pydantic major)

✅ No known vulnerabilities found.

Both the resolved dependency set and the lowest versions the published specs permit are clean at HIGH and CRITICAL.

@zeevmoney

Copy link
Copy Markdown
Contributor

Closing without merging. This update would change the SDK's supported pydantic range, which is set by hand.

  • It raises the floor to pydantic>=2.13.5. That drops pydantic 1, which permit 3.x still supports (deprecated, to be removed in 4.0), and every pydantic 2 release before 2.13.5.
  • It rewrites the exclusions (!=2.0.* becomes !=2.0.0.dev), so they no longer exclude the 2.0 to 2.3 releases. The CVE-2024-3772 exclusions and the per-Python lines in requirements.txt exist for the reasons in the comments above them.

The pydantic requirement stays as it is. A follow-up change will make Dependabot stop proposing pydantic floor updates.

@zeevmoney zeevmoney closed this Sep 28, 2026
@dependabot @github

dependabot Bot commented on behalf of github Sep 28, 2026

Copy link
Copy Markdown
Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/pip/pydantic-neq-2.0.0.dev-and-neq-2.1.0.dev-and-neq-2.2.0.dev-and-neq-2.3.0.dev-and-neq-2.4.0-and-neq-2.4.1-and-gte-2.13.5 branch September 28, 2026 10:50
zeevmoney added a commit that referenced this pull request Sep 28, 2026
Under the uv ecosystem Dependabot skips any requirement whose marker
contains `<`, so it never read the python_version < "3.13" pydantic line
or the tomli pin. On the pydantic lines it does read, it rewrites each
`!=X.Y.*` exclusion as `!=X.Y.0.dev`, as it did in #130. Ignore pydantic
for every update type, since its floors and exclusions are kept by hand,
and write the tomli marker as == "3.10", which is the same under
requires-python and has no `<`. uv.lock is unchanged.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QoCAyNyBAmzgSkofgvKjEg
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant