Skip to content

Bump python-dotenv from 1.1.1 to 1.2.1 in /backend-agent#140

Merged
marcorosa merged 1 commit intodevelopfrom
dependabot/uv/backend-agent/develop/python-dotenv-1.2.1
Nov 4, 2025
Merged

Bump python-dotenv from 1.1.1 to 1.2.1 in /backend-agent#140
marcorosa merged 1 commit intodevelopfrom
dependabot/uv/backend-agent/develop/python-dotenv-1.2.1

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot bot commented on behalf of github Oct 26, 2025

Bumps python-dotenv from 1.1.1 to 1.2.1.

Release notes

Sourced from python-dotenv's releases.

v1.2.1

What's Changed

New Contributors

Full Changelog: theskumar/python-dotenv@v1.2.0...v1.2.1

v1.2.0

What's Changed

New Contributors

Full Changelog: theskumar/python-dotenv@v1.1.1...v1.2.0

Changelog

Sourced from python-dotenv's changelog.

[1.2.1] - 2025-10-26

  • Move more config to pyproject.toml, removed setup.cfg
  • Add support for reading .env from FIFOs (Unix) by [@​sidharth-sudhir] in #586

[1.2.0] - 2025-10-26

Commits
  • eaf2a91 Do not remove .coverage file
  • 8716196 Bump version: 1.2.0 → 1.2.1
  • b87807f Update changelog
  • 3af77d3 Support reading .env from FIFOs (Unix) (#586)
  • 467ee22 Fix test failures after moving config to pyproject.toml
  • 76999e7 Move more config pyproject.toml
  • 222ce2c Update to use trusted publisher on pypi
  • 8ed4f79 Update docs requirements
  • 5bf8822 Bump version: 1.1.1 → 1.2.0
  • 1fe11cc upadate changelog
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

@dependabot dependabot bot added backend Related to the flask backend and general Python stuff dependencies Pull requests that update a dependency file labels Oct 26, 2025
@dependabot dependabot bot requested a review from a team as a code owner October 26, 2025 19:06
@dependabot dependabot bot added backend Related to the flask backend and general Python stuff dependencies Pull requests that update a dependency file labels Oct 26, 2025
@github-actions
Copy link
Copy Markdown
Contributor

This update modifies the pyproject.toml file by adjusting the version requirements for the python-dotenv dependency, upgrading it from version 1.1.1 to 1.2.1. This change ensures compatibility with potential new features or bug fixes in the updated python-dotenv library while maintaining dependencies for other packages.

Walkthrough

  • Dependency Update: The version of the python-dotenv package has been updated from 1.1.1 to 1.2.1. This may provide improved functionality or security enhancements, benefiting the backend agent's environment management.

This change is internal and does not directly affect end-user features but supports overall code maintenance and reliability.

Model: gpt-4o | Prompt Tokens: 303 | Completion Tokens: 146

Copy link
Copy Markdown
Contributor

@github-actions github-actions bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Here's a supportive code review enhanced by AI assistance. These suggestions offer potential improvements, though they're recommendations rather than requirements. You're the expert on your project's needs, so please adapt any insights that align with your goals. AI simply provides additional perspective to complement your technical judgment and decision-making.


Always critique what AI says. Do not let AI replace YOUR I.
Model: anthropic--claude-4-sonnet | Prompt Tokens: 855 | Completion Tokens: 235

dependencies = [
'sap-ai-sdk-gen[all]==5.7.5',
'python-dotenv==1.1.1',
'python-dotenv==1.2.1',
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Consider using version ranges instead of pinning exact versions for non-critical dependencies. This allows for automatic security updates and bug fixes while maintaining compatibility:

'python-dotenv>=1.2.0,<2.0.0',

However, if you need exact version pinning for reproducible builds, consider documenting the reason for this constraint in a comment or maintaining a separate requirements-dev.txt file with looser constraints for development.

Bumps [python-dotenv](https://github.com/theskumar/python-dotenv) from 1.1.1 to 1.2.1.
- [Release notes](https://github.com/theskumar/python-dotenv/releases)
- [Changelog](https://github.com/theskumar/python-dotenv/blob/main/CHANGELOG.md)
- [Commits](theskumar/python-dotenv@v1.1.1...v1.2.1)

---
updated-dependencies:
- dependency-name: python-dotenv
  dependency-version: 1.2.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot force-pushed the dependabot/uv/backend-agent/develop/python-dotenv-1.2.1 branch from 8fdbc05 to cf64574 Compare November 4, 2025 09:02
@marcorosa marcorosa merged commit b3f9c78 into develop Nov 4, 2025
3 checks passed
@marcorosa marcorosa deleted the dependabot/uv/backend-agent/develop/python-dotenv-1.2.1 branch November 4, 2025 09:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

backend Related to the flask backend and general Python stuff dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant