Skip to content

chore(deps): bump the all-deps group across 1 directory with 2 updates - #65

Merged
fmoorhof merged 1 commit into
mainfrom
dependabot/uv/all-deps-32d736f8f4
Sep 23, 2026
Merged

fmoorhof merged 1 commit into
mainfrom
dependabot/uv/all-deps-32d736f8f4

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 23, 2026

Copy link
Copy Markdown
Contributor

Bumps the all-deps group with 2 updates in the / directory: plotly and huggingface-hub.

Updates plotly from 7.0.0 to 7.1.0

Release notes

Sourced from plotly's releases.

v7.1.0

Added

  • Support marginal_x/marginal_y="heatmap" in density_heatmap, drawing a single-row/column heatmap strip in the margin colored by the same z/histfunc aggregate as the main plot and sharing its color scale [#5706], with thanks to @​lucasjamar for the contribution!
  • Add support for custom tick values in mpl_to_plotly when the matplotlib tick positions don't follow an arithmetic progression, including custom tick labels and tick values on date axes [#5262], with thanks to @​robertoffmoura for the contribution!

Fixed

  • Fix Plotly Express treating unsigned integer columns (uint8, uint16, uint32, uint64) in pandas DataFrames as categorical, which caused px.bar and other functions to pick the wrong orientation and render unexpected plots [#4291, #4344], with thanks to @​Belagum for the contribution!
  • Fix mpl_to_plotly not setting paper_bgcolor and plot_bgcolor from the matplotlib figure and axes backgrounds, so converted figures match the source figure's background colors [#5285], with thanks to @​robertoffmoura for the contribution!
  • Fix rendering issue causing a too-large div when calling Figure.show() in Google Colab [#5718]
  • Fix the sphinx-gallery scraper so that it generates thumbnails for figures shown with fig.show() or displayed as the last expression of a code block [#5701], with thanks to @​larsoner for the contribution!
    • The scaper now warns once (instead of failing the build) when static image export is unavailable
  • The sphinx-gallery scraper no longer scrapes files belonging to other examples during parallel builds [#5701], with thanks to @​larsoner for the contribution!

Updated

  • Update plotly.js from version 4.0.0 to version 4.1.1 [#5722, #5730]. See the plotly.js release notes for v4.1.0 and v4.1.1 for details. Notable changes include:
    • Add an opt-in modebar button for downloading Plotly figures as JSON [#7990, #8022]
    • Add legend.groupdoubleclick to set the group behavior for a legend double-click [#7997]
    • Increase default double-click delay threshold to 500ms (from 300) [#8014]
    • Fix issue with per-point marker color for hover labels in scattergl, quiver traces [#8027]
    • Update maplibre-gl to v6 to address CVE-2026-85061 [#8035]
      • Note: Safari 15, Chrome 56, Firefox 51 and later are now required for map traces
  • Update hex_to_rgb function to raise error for invalid-length hex codes, and emit warning for hex codes containing alpha [#5729], with thanks to @​dylanpulver for the contribution!
Changelog

Sourced from plotly's changelog.

[7.1.0] - 2026-09-15

Added

  • Support marginal_x/marginal_y="heatmap" in density_heatmap, drawing a single-row/column heatmap strip in the margin colored by the same z/histfunc aggregate as the main plot and sharing its color scale [#5706], with thanks to @​lucasjamar for the contribution!
  • Add support for custom tick values in mpl_to_plotly when the matplotlib tick positions don't follow an arithmetic progression, including custom tick labels and tick values on date axes [#5262], with thanks to @​robertoffmoura for the contribution!

Fixed

  • Fix Plotly Express treating unsigned integer columns (uint8, uint16, uint32, uint64) in pandas DataFrames as categorical, which caused px.bar and other functions to pick the wrong orientation and render unexpected plots [#4291, #4344], with thanks to @​Belagum for the contribution!
  • Fix mpl_to_plotly not setting paper_bgcolor and plot_bgcolor from the matplotlib figure and axes backgrounds, so converted figures match the source figure's background colors [#5285], with thanks to @​robertoffmoura for the contribution!
  • Fix rendering issue causing a too-large div when calling Figure.show() in Google Colab [#5718]
  • Fix the sphinx-gallery scraper so that it generates thumbnails for figures shown with fig.show() or displayed as the last expression of a code block [#5701], with thanks to @​larsoner for the contribution!
    • The scaper now warns once (instead of failing the build) when static image export is unavailable
  • The sphinx-gallery scraper no longer scrapes files belonging to other examples during parallel builds [#5701], with thanks to @​larsoner for the contribution!

Updated

  • Update plotly.js from version 4.0.0 to version 4.1.1 [#5722, #5730]. See the plotly.js release notes for v4.1.0 and v4.1.1 for details. Notable changes include:
    • Add an opt-in modebar button for downloading Plotly figures as JSON [#7990, #8022]
    • Add legend.groupdoubleclick to set the group behavior for a legend double-click [#7997]
    • Increase default double-click delay threshold to 500ms (from 300) [#8014]
    • Fix issue with per-point marker color for hover labels in scattergl, quiver traces [#8027]
    • Update maplibre-gl to v6 to address CVE-2026-85061 [#8035]
      • Note: Safari 15, Chrome 56, Firefox 51 and later are now required for map traces
  • Update hex_to_rgb function to raise error for invalid-length hex codes, and emit warning for hex codes containing alpha [#5729], with thanks to @​dylanpulver for the contribution!
Commits
  • 243bfd0 version changes for v7.1.0
  • 9b3c4da Merge pull request #5729 from dylanpulver/hex-to-rgb-rejects-invalid-length
  • 3aa898c Merge branch 'main' into hex-to-rgb-rejects-invalid-length
  • a93dcc0 update changelog
  • 7c85d48 add test for hex_to_rgb 4- and 8-character hex codes
  • 80a94ec accept 4- and 8- character hex codes with a warning
  • ac78b8b Merge pull request #5726 from Belagum/px-unsigned-int-continuous
  • 1cf7756 Merge branch 'main' into px-unsigned-int-continuous
  • ec79917 add attribution
  • ac7bc28 edit changelog entry
  • Additional commits viewable in compare view

Updates huggingface-hub from 1.29.0 to 1.32.0

Release notes

Sourced from huggingface-hub's releases.

[v1.32.0] Shared blob store, sandbox security hardening and faster imports

📂 [Cache] Shared blob store: deduplicate Xet files across repos

The cache now deduplicates Xet files across repos. A Xet file downloaded through hf_xet is stored once at <CACHE_DIR>/blobs/<prefix>/<xet_hash> and every repo that needs it gets a relative symlink instead of a download: no bytes are transferred and no extra space is used, even across different repos — or after the repo that first downloaded the file was deleted. The per-repo snapshot layout is unchanged, older clients keep reading and downloading normally, and any failure to share silently falls back to regular repo-local storage. Set HF_HUB_DISABLE_SHARED_BLOBS=1 to opt out entirely. Shared files carry a <xet_hash>.refs manifest listing the repo blobs referencing them, which hf cache rm consults on deletion and hf cache prune sweeps to reclaim payloads that no cached repo uses anymore.

📚 Documentation: Manage your cache

💻 [Jobs] Ship config inside UV scripts

A UV script that only runs correctly on a specific runtime can now carry that runtime with it. An optional [tool.hf-jobs] table in the script's PEP 723 header accepts image, flavor, python, timeout, name, namespace, env, secrets, labels, volumes, network_group and network_aliases, and hf jobs uv run reads it at submit time. CLI flags always win, and env/secrets/labels/volumes merge entry by entry instead of being replaced, so -e/-v add to what the script declares. Typos and unknown keys are rejected with the list of valid options, secrets are passed by name only (values come from your environment), and every run prints a config summary with script-sourced values marked and secrets redacted. Note that the table is read by the CLI only: run_uv_job() and create_scheduled_uv_job() ignore it.

# /// script
# requires-python = ">=3.11"
# dependencies = ["vllm", "datasets"]
#
# [tool.hf-jobs]
# image   = "vllm/vllm-openai:unlimited-ocr"
# flavor  = "l4x1"
# python  = "/usr/bin/python3"
# secrets = ["HF_TOKEN"]
# ///

📚 Documentation: Run and manage Jobs

  • [CLI] Read a UV script's [tool.hf-jobs] launch config (opus-generated) by @​Wauplin in #4598

🛡️ [Sandbox] security hardening

An internal security review of the Sandbox API resulted in a 9-PR hardening series. Pooled sandboxes now use their own per-sandbox capability token instead of the host-wide credential, pool hosts are fully validated (initiator, namespace, image, flavor, command, URL) before any credential is sent to them, the sbx-server binary is pinned by digest and verified before being run as PID 1, and the local pool cache is bound to the endpoint, credential and namespace that wrote it. Secret values no longer end up in argv when using hf sandbox exec --secrets, background processes are addressed by their server-assigned id (so kill() actually stops them and reports honestly), transfers and command output are bounded to avoid unbounded memory usage in the client, and pool ownership is decided per host so a with SandboxPool(...) block never again tears down a colleague's discovered host. The security documentation was also rewritten to state precisely what the sandbox contract is — and what it is not — including a new "Known limitations" section.

📚 Documentation: Sandboxes

  • [sandbox audit] Make the sandbox security contract match the implementation by @​Wauplin in #4831
  • [sandbox audit] Use each pooled sandbox's own capability token by @​Wauplin in #4832
  • [sandbox audit] Validate a pool host before sending it a credential by @​Wauplin in #4834
  • [sandbox audit] Bind the sandbox pool cache to the endpoint, credential and namespace that wrote it by @​Wauplin in #4838
  • [sandbox audit] Bound what a transfer or a command's output costs the client by @​Wauplin in #4839
  • [sandbox audit] Decide host teardown per host, and report it honestly by @​Wauplin in #4840
  • [sandbox audit] Address background processes by their server-assigned id by @​Wauplin in #4836
  • [sandbox audit] Pin the sandbox server binary by digest and verify it before running it by @​Wauplin in #4837
  • [sandbox audit] Keep secret values out of argv in the CLI and fix the env/secrets docs by @​Wauplin in #4835

🔒 Security hardening for serialization and validation

Three changes make the library safer against malicious or malformed inputs, with a stricter behavior worth noting. Torch checkpoint deserialization was hardened across 11 reported vulnerabilities: load_state_dict_from_file now defaults to safe=True (always using the safetensors loader), the pickle path defaults to weights_only=True, and unsafe combinations raise explicit errors instead of silently falling through. Path validation now rejects .. segments anywhere in path_in_repo (previously only a leading one was caught), so uploads like "a/../../etc/passwd" are refused. Finally, repo_id validation is restricted to ASCII word characters as documented, so non-ASCII ids like café are rejected client-side instead of failing later on the Hub.

... (truncated)

Commits
  • 8814aab Release: v1.32.0
  • 4457706 Release: v1.32.0.rc0
  • b064a14 [Download] Send X-HF-Download-Counter header on download calls (#4613)
  • 79dd41e [Docs] Fix hf discussions info options that do not exist (#4886)
  • d7b62c7 [CLI] Fix card data serialization (#4882)
  • f94ea55 [Buckets] Send mtime when copying files (#4920)
  • 6e3d21f [Cache] Add cross-repo shared blob store (#4498)
  • 5a9cdda [Core] Speed up package imports (#4914)
  • 2075fd6 [Cache] Support kernel repos in hf cache commands (#4905)
  • af6b41e [Core] Reject path traversal via embedded ".." segments in path_in_repo (#4884)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the all-deps group with 2 updates in the / directory: [plotly](https://github.com/plotly/plotly.py) and [huggingface-hub](https://github.com/huggingface/huggingface_hub).


Updates `plotly` from 7.0.0 to 7.1.0
- [Release notes](https://github.com/plotly/plotly.py/releases)
- [Changelog](https://github.com/plotly/plotly.py/blob/main/CHANGELOG.md)
- [Commits](plotly/plotly.py@v7.0.0...v7.1.0)

Updates `huggingface-hub` from 1.29.0 to 1.32.0
- [Release notes](https://github.com/huggingface/huggingface_hub/releases)
- [Commits](huggingface/huggingface_hub@v1.29.0...v1.32.0)

---
updated-dependencies:
- dependency-name: plotly
  dependency-version: 7.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-deps
- dependency-name: huggingface-hub
  dependency-version: 1.32.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-deps
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels Sep 23, 2026
@fmoorhof
fmoorhof merged commit a389ab1 into main Sep 23, 2026
3 checks passed
@dependabot
dependabot Bot deleted the dependabot/uv/all-deps-32d736f8f4 branch September 23, 2026 10:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant