build(deps): refresh dependencies and clean up test warnings (#1243)

Consolidates the currently applicable dependency updates into one PR, including the closed Dependabot backlog such as #1241, plus dependency surfaces that were not covered by the repository's previous pip-only Dependabot configuration.

Cleanup of test warnings.

Most importent:

* GitPython + pypdf security hardening.
* Uvicorn WebSocket close/backpressure/header fixes for server/dashboard reliability.
* FastAPI dependency-memory/OpenAPI improvements for the API process.
* Bokeh WebSocket/resource-leak/prefix fixes for EOSdash and proxied deployments.
* cachebox cancellation/lock cleanup fixes for long-running/concurrent work.
* pandas 3.0.5 avoiding the yanked 3.0.4 datetime/segfault build.
* Ruff security-lint and pydocstyle correctness fixes, plus faster release builds via PGO.
* platformdirs malformed-XDG and duplicate-directory fixes for deployment portability.
* CI action modernization, regenerated uv.lock, and expanded Dependabot coverage.

Runtime dependencies

    cachebox: 6.1.2 → 6.2.2
    fastapi: 0.139.2 → 0.141.1
    python-fasthtml: 0.14.9 → 0.14.11
    MonsterUI: 1.0.46 → 1.0.47
    bokeh: 3.9.1 → 3.9.2
    uvicorn: 0.51.0 → 0.52.4 (build(deps): bump uvicorn from 0.51.0 to 0.52.3 #1241, refreshed to latest patch)
    pandas: 3.0.3 → 3.0.5
    platformdirs: 4.11.0 → 4.11.3

Development/test dependencies

    pandas-stubs: 3.0.3.260530 → 3.0.5.260730
    types-PyYAML: 6.0.12.20260518 → 6.0.12.20260724
    GitPython: 3.1.53 → 3.1.58 (security/fix releases)
    coverage: 7.15.2 → 7.15.4
    pypdf: 6.14.2 → 6.16.1 (includes security fixes)

Pre-commit/tooling

    ruff-pre-commit: v0.15.21 → v0.16.3
    synchronize pandas-stubs, types-docutils, and types-PyYAML pins with pyproject.toml

CI / repository dependencies

    Python 3.13.9 → 3.13.15 in CI, Docker, .env, and local Docker Make targets
    actions/checkout → v7 in pytest, pre-commit, CodeQL, and release workflows
    actions/setup-python → v7 in pytest, pre-commit, and release workflows
    actions/upload-artifact → v7 in pytest workflow
    actions/stale: v9.1.0 → v11.0.0 (SHA-pinned)
    regenerate uv.lock from the final dependency pins so locked/frozen installs match pyproject.toml

Future update coverage

Expand Dependabot from pip-only to also monitor:

    GitHub Actions
    Docker

The existing open docutils 0.23 update (#1085) is intentionally excluded because it has separate compatibility/ignore handling and should remain isolated.

docker-build.yml was audited and is already using the newer action generations, so no changes were needed there.

---------

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
This commit is contained in:
Normann
2026-08-21 07:07:34 +02:00
committed by GitHub
co-authored by github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
parent 230698a70d
commit 9eb3c7e483
14 changed files with 391 additions and 443 deletions
+18 -13
View File
@@ -16,27 +16,27 @@ classifiers = [
dependencies = [
"babel==2.18.0",
"beautifulsoup4==4.15.0",
"cachebox==6.1.2",
"cachebox==6.2.2",
"numpy==2.4.6",
"numpydantic==1.10.0",
"matplotlib==3.11.1",
"contourpy==1.3.3",
"fastapi[standard-no-fastapi-cloud-cli]==0.139.2",
"fastapi[standard-no-fastapi-cloud-cli]==0.141.1",
"fastapi_cli==0.0.32",
"rich-toolkit==0.20.3",
"python-fasthtml==0.14.9",
"MonsterUI==1.0.46",
"python-fasthtml==0.14.11",
"MonsterUI==1.0.47",
"markdown-it-py==4.2.0",
"mdit-py-plugins==0.6.1",
"bokeh==3.9.1",
"uvicorn==0.51.0",
"bokeh==3.9.2",
"uvicorn==0.52.4",
"scipy==1.17.1",
"tzfpy==1.3.2",
"deap==1.4.4",
"requests==2.34.2",
"pandas==3.0.3",
"pandas==3.0.5",
"pendulum==3.2.0",
"platformdirs==4.11.0",
"platformdirs==4.11.3",
"psutil==7.2.2",
"pvlib==0.15.2",
"pydantic==2.13.4",
@@ -62,10 +62,10 @@ dev = [
"pre-commit==4.6.1",
"mypy==2.3.0",
"types-requests==2.33.0.20260712", # for mypy
"pandas-stubs==3.0.3.260530", # for mypy
"pandas-stubs==3.0.5.260730", # for mypy
"tokenize-rt==6.2.0", # for mypy
"types-docutils==0.22.3.20260712", # for mypy
"types-PyYaml==6.0.12.20260518", # for mypy
"types-PyYaml==6.0.12.20260724", # for mypy
"commitizen==4.16.5",
"deprecated==1.3.1", # for commitizen
@@ -73,7 +73,7 @@ dev = [
"sphinx==9.0.4",
"sphinx_rtd_theme==3.1.0",
"sphinx-tabs==3.5.0",
"GitPython==3.1.53",
"GitPython==3.1.58",
"myst-parser==5.1.0",
"docutils==0.21.2",
"sphinxcontrib-mermaid==2.1.0 ",
@@ -83,8 +83,8 @@ dev = [
"pytest-asyncio==1.4.0",
"pytest-cov==7.1.0",
"pytest-xprocess==1.0.2",
"coverage==7.15.2",
"pypdf==6.14.2",
"coverage==7.15.4",
"pypdf==6.16.1",
]
[project.urls]
@@ -161,6 +161,11 @@ testpaths = [ "tests", ]
markers = [
"docker: marks tests that require a local Docker engine"
]
filterwarnings = [
# pvlib may exercise SciPy's root solver at night/zero irradiance; the resulting
# PV output is explicitly verified as zero by integration tests.
"ignore:invalid value encountered in divide:RuntimeWarning:scipy\\.optimize\\._chandrupatla",
]
[tool.mypy]
mypy_path= "src"