Skip to content

chore(deps): bump the python-dev group across 1 directory with 3 updates - #251

Open
dependabot[bot] wants to merge 1 commit into
devfrom
dependabot/pip/dev/python-dev-8cc1e7271f
Open

dependabot[bot] wants to merge 1 commit into
devfrom
dependabot/pip/dev/python-dev-8cc1e7271f

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 27, 2026 •

Copy link
Copy Markdown
Contributor

Updates the requirements on litellm, deepgram-sdk and elevenlabs to permit the latest version.
Updates litellm to 1.103.1

Release notes

Sourced from litellm's releases.

v1.103.1

Verify Docker Image Signature

All LiteLLM Docker images are signed with cosign. Every release is signed with the same key introduced in commit 0112e53.

Verify using the pinned commit hash (recommended):

A commit hash is cryptographically immutable, so this is the strongest way to ensure you are using the original signing key:

cosign verify \
  --key https://raw.githubusercontent.com/BerriAI/litellm/0112e53046018d726492c814b3644b7d376029d0/cosign.pub \
  ghcr.io/berriai/litellm:v1.103.1

Verify using the release tag (convenience):

Tags are protected in this repository and resolve to the same key. This option is easier to read but relies on tag protection rules:

cosign verify \
  --key https://raw.githubusercontent.com/BerriAI/litellm/v1.103.1/cosign.pub \
  ghcr.io/berriai/litellm:v1.103.1

Expected output:

The following checks were performed on each of these signatures:
  - The cosign claims were validated
  - The signatures were verified against the specified public key

Full Changelog: BerriAI/litellm@v1.103.0...v1.103.1

Commits
  • 580bde9 Merge pull request #13 from BerriAI/litellm_session_token_1_103_x
  • d3bf006 chore(lint): scope a TRY004 suppression to the bearer-token salt key check
  • a80eaca refactor(auth): bind UI/CLI session tokens to their own AES-GCM context
  • e7d8bbc Merge pull request #6 from BerriAI/litellm_bump_1_103_1
  • bf02f06 bump: litellm 1.103.0 -> 1.103.1
  • c991f4b fix(proxy): unregister logging callbacks removed from the stored config (#43429)
  • cc111d1 fix(streaming): backport text-completion usage fix and e2e provider-flake tol...
  • 4dbbe6e test(ci): fix the e2e and integration reds left on rc/1.103.0 after #43382 an...
  • 8aca86a test(e2e): clear the two rc/1.103.0 e2e reds owned by upstream providers (#43...
  • e640c0e test(integration): make rc/1.103.0 integration groups collect and pass again ...
  • Additional commits viewable in compare view

Updates deepgram-sdk to 7.11.0

Release notes

Sourced from deepgram-sdk's releases.

v7.11.0

7.11.0 (2026-09-23)

Features

  • Listen v2 (Flux): change numerals during an active connection with connection.send_configure(ListenV2Configure(numerals=True)). Numerals convert written numbers to numerical format for turns transcribed after the update. (#794) (c7c1b3f)
Changelog

Sourced from deepgram-sdk's changelog.

7.11.0 (2026-09-23)

Features

  • Listen v2 (Flux): change numerals during an active connection with connection.send_configure(ListenV2Configure(numerals=True)). Numerals convert written numbers to numerical format for turns transcribed after the update. (#794) (c7c1b3f)

7.10.0 (2026-09-17)

Features

  • Voice Agent: Add typed FunctionCallCancelled WebSocket events. Events identify function calls that are no longer valid; do not send a FunctionCallResponse for the listed call IDs. (#790) (7f5b642)
  • Voice Agent: Add the optional defer_until_eot function setting. When enabled, it holds a function call until the user's turn is confirmed and discards the deferred call if the turn resumes. Defaults to false. (#790) (7f5b642)

7.9.0 (2026-09-14)

Features

  • Voice Agent: Adds send_force_end_turn() and typed ForceEndTurn messages for V2 Flux listen providers. (#783) (ff49864)
  • Voice Agent: Adds integer expressivity from -2 through 2 for Deepgram Flux TTS providers. (#783) (ff49864)
  • Flux TTS: speed accepts 0.5 through 1.5 in 0.05 increments, replacing the previously documented 0.85 through 1.15 range. (#783) (ff49864)

Model Catalog

  • Speak V1: Removes aura-2-perseo-it from model literals. The API never served the model and returns 400 No such model/version combination found for it. (#783) (ff49864)

7.8.1 (2026-09-03)

Bug Fixes

  • TextBuilder: ssml_to_deepgram() now preserves a <phoneme> pronunciation when its valid ph and alphabet attributes appear in either order. (#741) (7fd4b63)
  • Credentials: Explicitly passing api_key=None continues to disable ambient DEEPGRAM_API_KEY lookup, which is important for multi-tenant and test environments. (#778) (e675990)
  • Credentials: DeepgramClient() and AsyncDeepgramClient() now resolve DEEPGRAM_API_KEY when constructed, so load_dotenv() can run after importing the SDK. Closes #734. (#767) (ec362ec)
  • Custom transports: Speak V2 WebSocket connections now honor transport_factory, matching the routing behavior of other WebSocket APIs for proxies, test doubles, and custom-hosted transports. (#766) (0980663)

Documentation

  • Transcription: Clarified that Nova-3 assumes English when language is omitted; non-English and multilingual audio require an explicit language such as fr or multi. (#771) (4574337)
  • Examples: Added Listen V1 live microphone transcription with optional sounddevice, device selection, bounded audio buffering, transcript output, and clean Ctrl-C shutdown. (#780) (08f0471)
  • Examples: Added a resilient Listen V1 live transcription pattern with exponential backoff, reconnect-aware audio buffering, timestamp continuity, and clean shutdown. (#776) (96b2d11)
  • Examples: Added an application-owned Voice Agent session recorder that serializes received transcripts, function calls, and latency reports as JSON while leaving consent, redaction, retention, and storage policy to the application. Closes #775. (#781) (30ad152)
  • Text-to-Speech: Corrected streaming synthesis snippets to iterate the response byte chunks instead of accessing a nonexistent .stream attribute. (#749) (178724e)

7.8.0 (2026-08-28)

... (truncated)

Commits

Updates elevenlabs to 2.70.0

Release notes

Sourced from elevenlabs's releases.

v2.70.0

What's Changed

Full Changelog: elevenlabs/elevenlabs-python@v2.69.0...v2.70.0

Commits
  • 963b4a5 SDK regeneration (#881)
  • 39d7bc9 SDK regeneration (#879)
  • 916322f Add transcript_edit to the realtime speech-to-text wrapper (#871)
  • fd6d5c2 fix(speech-engine): strip residency suffix from API key before JWT verificati...
  • 06db161 fix(play): raise when ffplay exits with an error (#869)
  • See full diff in compare view

@dependabot @github

dependabot Bot commented on behalf of github Sep 27, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: dependencies. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot
dependabot Bot requested a review from eldonm as a code owner September 27, 2026 20:54
Updates the requirements on [litellm](https://github.com/BerriAI/litellm), [deepgram-sdk](https://github.com/deepgram/deepgram-python-sdk) and [elevenlabs](https://github.com/elevenlabs/elevenlabs-python) to permit the latest version.

Updates `litellm` to 1.103.1
- [Release notes](https://github.com/BerriAI/litellm/releases)
- [Commits](BerriAI/litellm@v1.101.0...v1.103.1)

Updates `deepgram-sdk` to 7.11.0
- [Release notes](https://github.com/deepgram/deepgram-python-sdk/releases)
- [Changelog](https://github.com/deepgram/deepgram-python-sdk/blob/main/CHANGELOG.md)
- [Commits](deepgram/deepgram-python-sdk@v7.9.0...v7.11.0)

Updates `elevenlabs` to 2.70.0
- [Release notes](https://github.com/elevenlabs/elevenlabs-python/releases)
- [Commits](elevenlabs/elevenlabs-python@v2.68.0...v2.70.0)

---
updated-dependencies:
- dependency-name: deepgram-sdk
  dependency-version: 7.10.0
  dependency-type: direct:production
  dependency-group: python-dev
- dependency-name: elevenlabs
  dependency-version: 2.69.0
  dependency-type: direct:production
  dependency-group: python-dev
- dependency-name: litellm
  dependency-version: 1.102.1
  dependency-type: direct:production
  dependency-group: python-dev
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/pip/dev/python-dev-8cc1e7271f branch from c2df8e2 to 381081b Compare October 4, 2026 04:55

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants