Skip to content

chore(deps): update jsonschema requirement from <5,>=4.20.0 to >=4.26.0,<5 - #2407

Merged
JSv4 merged 1 commit into
mainfrom
dependabot/pip/jsonschema-gte-4.26.0-and-lt-5
Oct 9, 2026
Merged

JSv4 merged 1 commit into
mainfrom
dependabot/pip/jsonschema-gte-4.26.0-and-lt-5

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 23, 2026 •

Copy link
Copy Markdown
Contributor

Updates the requirements on jsonschema to permit the latest version.

Release notes

Sourced from jsonschema's releases.

v4.26.0

What's Changed

New Contributors

Full Changelog: python-jsonschema/jsonschema@v4.25.1...v4.26.0

Changelog

Sourced from jsonschema's changelog.

v4.26.0

  • Decrease import time by delaying importing of urllib.request (#1416).

v4.25.1

  • Fix an incorrect required argument in the Validator protocol's type annotations (#1396).

v4.25.0

  • Add support for the iri and iri-reference formats to the format-nongpl extra via the MIT-licensed rfc3987-syntax. They were alread supported by the format extra. (#1388).

v4.24.1

  • Properly escape segments in ValidationError.json_path (#139).

v4.24.0

  • Fix improper handling of unevaluatedProperties in the presence of additionalProperties (#1351).
  • Support for Python 3.8 has been dropped, as it is end-of-life.

v4.23.0

  • Do not reorder dictionaries (schemas, instances) that are printed as part of validation errors.
  • Declare support for Py3.13

v4.22.0

  • Improve best_match (and thereby error messages from jsonschema.validate) in cases where there are multiple sibling errors from applying anyOf / allOf -- i.e. when multiple elements of a JSON array have errors, we now do prefer showing errors from earlier elements rather than simply showing an error for the full array (#1250).
  • (Micro-)optimize equality checks when comparing for JSON Schema equality by first checking for object identity, as == would.

v4.21.1

  • Slightly speed up the contains keyword by removing some unnecessary validator (re-)creation.

v4.21.0

  • Fix the behavior of enum in the presence of 0 or 1 to properly consider True and False unequal (#1208).
  • Special case the error message for {min,max}{Items,Length,Properties} when they're checking for emptiness rather than true length.

... (truncated)

Commits
  • a727743 Add a changelog entry for 4.26.
  • 6d28c13 Update the lockfile.
  • 739499e Update pre-commit hooks.
  • cb2d779 Merge pull request #1443 from python-jsonschema/pre-commit-ci-update-config
  • e6bbbb7 [pre-commit.ci] pre-commit autoupdate
  • d56037a Merge pull request #1442 from python-jsonschema/dependabot/github_actions/ast...
  • e54ce13 Bump astral-sh/setup-uv from 7.1.4 to 7.1.6
  • 1f7c9fb Partially update docs requirements.
  • 241aec9 Merge pull request #1441 from python-jsonschema/pre-commit-ci-update-config
  • 2818efb Apache-2.0 -> nongpl
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update Python code labels Sep 23, 2026
@claude

claude Bot commented Sep 23, 2026

Copy link
Copy Markdown

Review

This is a routine Dependabot bump widening the jsonschema pin in requirements/base.txt from >=4.20.0,<5 to >=4.26.0,<5. Single line change, no code changes required.

Compatibility check: I checked all in-repo usages of jsonschema:

  • opencontractserver/mcp/server.py — uses jsonschema.validate(), jsonschema.ValidationError, jsonschema.SchemaError for MCP tool-argument validation
  • opencontractserver/mcp/tests/test_mcp.py — uses jsonschema.validators.validator_for(schema).check_schema(schema)
  • opencontractserver/llms/agents/timeline_schema.py — references jsonschema.validate in a docstring only

All of these are stable, long-standing public APIs unaffected by the 4.20→4.26 changelog (import-time urllib.request removal, unevaluatedProperties fix, json_path escaping, Python 3.8 support drop — none of which touch this codebase's usage or Python version).

Verdict: Safe to merge. No code quality, security, performance, or test coverage concerns — the comment on the pin (pinned explicitly so it cannot vanish under us) remains accurate and the upper bound (<5) is preserved, so this stays a low-risk minor-version bump.

@JSv4

JSv4 commented Oct 9, 2026

Copy link
Copy Markdown
Collaborator

@dependabot rebase

Updates the requirements on [jsonschema](https://github.com/python-jsonschema/jsonschema) to permit the latest version.
- [Release notes](https://github.com/python-jsonschema/jsonschema/releases)
- [Changelog](https://github.com/python-jsonschema/jsonschema/blob/main/CHANGELOG.rst)
- [Commits](python-jsonschema/jsonschema@v4.20.0...v4.26.0)

---
updated-dependencies:
- dependency-name: jsonschema
  dependency-version: 4.26.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/pip/jsonschema-gte-4.26.0-and-lt-5 branch from ddbd35a to 5a83ff3 Compare October 9, 2026 13:23
@claude

claude Bot commented Oct 9, 2026

Copy link
Copy Markdown

Review: LGTM. This is a one-line lower-bound raise of jsonschema from >=4.20.0 to >=4.26.0 in requirements/base.txt. It keeps the <5 cap, so there is no major-version risk.

  • Compatibility: The 4.21–4.26 releases are minor. The changes are enum 0/1 vs True/False equality (4.21), better best_match errors (4.22), json_path escaping (4.24.1), and lazy urllib.request import (4.26). We use jsonschema for MCP tool-argument validation in opencontractserver/mcp/server.py. The enum fix could change validation outcomes for schemas whose enums mix booleans and integers, but that makes validation more correct. Error message text may also differ slightly, so any test that asserts exact validation error strings could be affected.
  • Other files: No other requirements files (local.txt, production.txt) or lockfiles are touched, and this PR changes none of them. I didn't check whether any exist.
  • Convention: Per CLAUDE.md, a dependency bump doesn't strictly need a changelog fragment. Add one under changelog.d/ if you track dependency changes.
  • Before merging: Make sure CI is green, especially the MCP tests (opencontractserver/tests/ MCP suites).

@JSv4
JSv4 merged commit cd99d3b into main Oct 9, 2026
8 checks passed
@dependabot
dependabot Bot deleted the dependabot/pip/jsonschema-gte-4.26.0-and-lt-5 branch October 9, 2026 13:55
@github-actions github-actions Bot locked and limited conversation to collaborators Oct 9, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

dependencies Pull requests that update a dependency file python Pull requests that update Python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant