Skip to content

chore(deps): update pydantic-ai-slim requirement from <2,>=1.107.5 to >=1.107.7,<2 - #2410

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/pydantic-ai-slim-gte-1.107.6-and-lt-2
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/pydantic-ai-slim-gte-1.107.6-and-lt-2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 24, 2026 •

Copy link
Copy Markdown
Contributor

Updates the requirements on pydantic-ai-slim to permit the latest version.

Release notes

Sourced from pydantic-ai-slim's releases.

v1.107.7 (2026-09-29)

🛡️ Security

A maintenance release for the v1 line, carrying the v1 backport of the security fix released in 2.52.0. See the advisory for full details and affected versions.

  • GHSA-v36g-jcw9-x7cw (moderate): converting attacker-controlled HTML with deeply nested elements in the local web_fetch tool could consume excessive CPU and memory. Provider-native web fetching is not affected. Reported by @​SounLabs. (#8985)

Patched in 1.107.7; also patched on the v2 line in 2.52.0.

What's Changed

🐛 Bug Fixes

Full Changelog: pydantic/pydantic-ai@v1.107.6...v1.107.7

Changelog

Sourced from pydantic-ai-slim's changelog.


description: "Pydantic AI upgrade guide and changelog: the breaking changes in each release, how to install V2, and the recommended path to migrate your code from V1."

Upgrade Guide

In September 2025, Pydantic AI reached V1 and committed to API stability: no changes that break your code until V2. V2 is now available, collecting the breaking and behavior changes that stability guarantee didn't allow. This guide is the canonical place to learn what's in V2, how to install it, and how to upgrade; for the guarantees behind these version numbers, see the Version Policy.

Breaking Changes

Here's a filtered list of the breaking changes for each version to help you upgrade Pydantic AI.

v2.0.0 (2026-06-23)

The stable V2.0 release. There are no new breaking or behavior changes since the betas; the full breaking-change list and recommended upgrade path are in the v2.0.0b1 entry below. Install it with:

uv add pydantic-ai

v2.0.0b7 (2026-06-10)

The seventh V2 beta, forked from v1.107.0. There are no new V2 breaking or behavior changes since v2.0.0b6 below — everything in that entry applies unchanged — but this beta picks up the latest V1 release on top, which adds Claude Fable 5 / Mythos 5 model support and OpenRouter prompt caching (CachePoint), plus known_model_names() and Anthropic fixes; see the v1.107.0 release notes for the full list.

Install it the same way, pinning the exact pre-release version:

pip/uv-add "pydantic-ai==2.0.0b7"

For the full breaking-change list and the recommended upgrade path, see the v2.0.0b1 entry below; the only difference is that the latest V1 to upgrade through first is now v1.107.0.

v2.0.0b6 (2026-06-04)

The sixth V2 beta, forked from v1.106.0. There are no new V2 breaking or behavior changes since v2.0.0b5 below — everything in that entry applies unchanged — but this beta picks up the latest V1 release on top, which adds api_host/timeout configuration and base seed mapping for the xAI provider, plus streaming and data-URI handling fixes; see the v1.106.0 release notes for the full list.

Install it the same way, pinning the exact pre-release version:

pip/uv-add "pydantic-ai==2.0.0b6"

For the full breaking-change list and the recommended upgrade path, see the v2.0.0b1 entry below; the only difference is that the latest V1 to upgrade through first is now v1.106.0.

v2.0.0b5 (2026-06-02)

The fifth V2 beta, forked from v1.105.0. There are no new V2 breaking or behavior changes since v2.0.0b4 below — everything in that entry (including the prepare-callbacks change) still applies — but this beta picks up the latest V1 release on top, which adds on-demand (deferred-loading) capabilities and Grok 4.3 reasoning_effort support, plus GoogleModelSettings.google_cached_content and Temporal gateway/ fixes; see the v1.105.0 release notes for the full list.

Install it the same way, pinning the exact pre-release version:

... (truncated)

Commits
  • 2fd3879 Backport bounded web_fetch HTML conversion to v1 (#8985)
  • ff899b4 Cap genai-prices below 0.1 to keep token usage extraction and limits workin...
  • 6022411 Remove stale harness-compat.yml from v1 (#9074)
  • 7ee27e3 Close two include_content redaction bypasses and make the content sweep pro...
  • 2faa618 Decode web_fetch response bodies in a worker thread and treat non-text char...
  • 6b22270 Check include_content=False over every content channel at once (v1 backport...
  • a9dab92 Compare web_fetch_tool domain lists in the form the resolver uses (v1 backp...
  • a93ea52 Extract the web_fetch page title with a linear scan and convert HTML in lin...
  • 963dec5 Share exception recording between the agent run, tool and model request spans...
  • 84d67aa Pin FastA2A below 1 in the a2a extra (v1) (#8412)
  • Additional commits viewable in compare view

Most Recent Ignore Conditions Applied to This Pull Request
Dependency Name Ignore Conditions
pydantic-ai-slim [>= 2.dev0, < 3]

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update Python code labels Sep 24, 2026
@claude

claude Bot commented Sep 24, 2026

Copy link
Copy Markdown

Review

This is a Dependabot-authored patch bump: pydantic-ai-slim >=1.107.5,<2 → >=1.107.6,<2 (one line, requirements/base.txt). No application code changes.

What 1.107.6 contains (per the release notes): it's a security-only maintenance release on the v1 line, backporting four fixes from 2.44.0:

  • IPv6 zone-identifier bypass of the cloud-metadata/private-IP blocklist (moderate, GHSA-vmxc-h2x2-jmf3)
  • Superlinear web_fetch response processing — HTML conversion + charset decode — that could block the event loop (moderate, GHSA-fpf4-vwcp-v4hp)
  • web_fetch_tool domain-list comparison bug (low, GHSA-22h6-qm39-v87j)
  • OpenTelemetry spans leaking exception/error/instruction content under include_content=False (low, GHSA-4x9p-g9wm-8q7f)

Assessment: Recommend merging.

  • These are genuine (if moderate/low severity) security fixes; taking the patch is the right call and low-risk given it's a same-minor bump.
  • The upper bound (<2) guarded by the issue #1451 comment a few lines up (requirements/base.txt:59) is untouched — this only moves the floor, so the instructions= vs system_prompt= precedence concern documented there (CLAUDE.md pitfall Bump coverage from 6.2 to 6.5.0 #14) doesn't apply to this bump.
  • I checked the 1.107.6 changelog against the two other version-sensitive traps called out in CLAUDE.md (opencontractserver/llms/history_processors.py's dataclass-shape assertion on ThinkingPart/ModelRequest/ModelResponse, and the Responses-API routing in llms/model_factory.py): none of the listed changes in this release touch message/dataclass shapes or model routing, so those code paths should be unaffected.
  • No test or code changes accompany the bump, which is appropriate here since nothing in this diff touches the surfaces the existing regression tests (test_pydantic_ai_factory.py) are pinned against — CI running that suite is sufficient signal before merge.

No blocking issues found.

@JSv4

JSv4 commented Oct 9, 2026

Copy link
Copy Markdown
Collaborator

@dependabot rebase

Updates the requirements on [pydantic-ai-slim](https://github.com/pydantic/pydantic-ai) to permit the latest version.
- [Release notes](https://github.com/pydantic/pydantic-ai/releases)
- [Changelog](https://github.com/pydantic/pydantic-ai/blob/main/docs/changelog.md)
- [Commits](pydantic/pydantic-ai@v1.107.5...v1.107.7)

---
updated-dependencies:
- dependency-name: pydantic-ai-slim
  dependency-version: 1.107.6
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title chore(deps): update pydantic-ai-slim requirement from <2,>=1.107.5 to >=1.107.6,<2 chore(deps): update pydantic-ai-slim requirement from <2,>=1.107.5 to >=1.107.7,<2 Oct 9, 2026
@dependabot
dependabot Bot force-pushed the dependabot/pip/pydantic-ai-slim-gte-1.107.6-and-lt-2 branch from bcbaa87 to 4df61bd Compare October 9, 2026 13:23
@claude

claude Bot commented Oct 9, 2026

Copy link
Copy Markdown

Review: one-line lower-bound bump of pydantic-ai-slim from 1.107.5 to 1.107.7 in requirements/base.txt. The <2 cap is kept, which matches the # see issue #1451 note.

Looks good

  • 1.107.7 is a patch release on the v1 line. It carries a moderate security fix (GHSA-v36g-jcw9-x7cw: nested-HTML DoS in the local web_fetch tool) and caps genai-prices below 0.1.
  • I didn't find any web_fetch usage from the diff alone, so the advisory probably doesn't affect us. The bump is harmless either way.

Things to check before merging

  • CLAUDE.md pitfall Bump pytz from 2021.3 to 2022.5 #17: history_processors.py asserts at import time that ToolReturnPart, ModelRequest and ModelResponse are stdlib dataclasses. A patch release is unlikely to change that, but CI should confirm the app still starts and the LLM tests pass.
  • The genai-prices<0.1 cap is new transitive behaviour. If anything else in the requirements pins genai-prices, the resolver could conflict. I'd confirm that the Docker image build resolves cleanly.

Not applicable

  • No code or tests are changed, so there are no test-coverage concerns.
  • A changelog fragment isn't needed for a dependency-only bump, though one is optional.

I haven't run the build or tests myself. Approve once CI is green.

@JSv4

JSv4 commented Oct 9, 2026

Copy link
Copy Markdown
Collaborator

Closing: this bump can't be installed.

pydantic-ai-slim 1.107.6+ capped its [mcp] extra at fastmcp-slim[client]>=3.3.0,<4 (1.107.5 had it uncapped). Every fastmcp-slim 3.x requires mcp>=1.24.0,<2.0, but requirements/base.txt requires mcp>=2.2.0 (python-sdk 2.x; opencontractserver/mcp/server.py targets the 2.x handler API). pip spends ~20 min backtracking and then fails with resolution-too-deep. uv pip compile reports the conflict directly:

pydantic-ai-slim[mcp]>=1.107.7,<2 depends on mcp>=1.24.0,<2.0
... you require pydantic-ai-slim[mcp]>=1.107.7,<2 and mcp>=2.2.0 → unsatisfiable

main still resolves because 1.107.5 lets fastmcp-slim float to 4.x, which supports mcp 2. Revisit once pydantic-ai-slim ships a release whose [mcp] extra allows fastmcp-slim 4 / mcp 2.

@JSv4 JSv4 closed this Oct 9, 2026
@dependabot @github

dependabot Bot commented on behalf of github Oct 9, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@github-actions github-actions Bot locked and limited conversation to collaborators Oct 9, 2026
@dependabot
dependabot Bot deleted the dependabot/pip/pydantic-ai-slim-gte-1.107.6-and-lt-2 branch October 9, 2026 13:56
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

dependencies Pull requests that update a dependency file python Pull requests that update Python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant