Skip to content

chore(deps): Update schemathesis requirement from >=4.27.1 to >=4.29.0 in /compose-configs/egeria-quickstart/PyegeriaWebHandler - #574

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/compose-configs/egeria-quickstart/PyegeriaWebHandler/schemathesis-gte-4.28.0
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/compose-configs/egeria-quickstart/PyegeriaWebHandler/schemathesis-gte-4.28.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Updates the requirements on schemathesis to permit the latest version.

Release notes

Sourced from schemathesis's releases.

Release 4.29.0

🚀 Added

  • WFC Report output via --report wfc or --report-wfc-path.
  • Dependency inference links body fields named after a collection to its items' code.
  • st replay options -H/--header, --auth, --auth-wfc and --auth-wfc-user for replayed requests.
  • Coverage Content-Type probes for malformed multipart and undeclared request media types.
  • format: binary values include small valid PNG, JPEG, GIF, WebP, PDF and ZIP files.
  • Multipart file names carry the extension of the detected file format, e.g. image.png.
  • use_after_free and ensure_resource_availability failures note responses served from a cache.

🔧 Changed

  • Negative test cases break a random subset of request locations instead of all of them.
  • Name the pattern that stops the analysis when test data cannot be generated.
  • BREAKING: st run and st fuzz fail with exit code 2 when nothing is tested.
  • BREAKING: st run and st fuzz exit 2 on schema, configuration and internal errors.
  • BREAKING: st run, st fuzz and st replay exit 130 when interrupted with Ctrl+C.
  • Linked stateful steps send negative requests as often as scenario-starting steps.
  • st replay step chains show each linked value as recorded -> replayed.
  • st replay removes fixed crash files with masked credentials once config or CLI supplies them.
  • Fuzzing and pytest seed each operation separately, so operations with identical parameters explore different inputs.
  • Stateful testing targets only metrics from generation.maximize or explicit hypothesis.target() calls.
  • ignored_auth stops probing an operation once it rejects missing and invalid credentials.
  • missing_deserializer warning names the response media types that go unvalidated.

🐛 Fixed

st run and st fuzz

  • Fuzzing phase dropping data generation errors when several distinct errors occur.
  • st fuzz --help omitting that fuzzing stops at the first failure without --continue-on-failure.
  • st fuzz omitting schema errors of individual operations.
  • st fuzz workers continuing after the first failure and reporting Stop reason: Completed.
  • Stop reason: Time limit reached for runs stopped by a failure shortly before the deadline.
  • continue-on-failure in the config file ignored.
  • WFC auth skipping users in the coverage phase and settling operations on the wrong one.
  • WFC auth never retrying users rejected before the API created their accounts.
  • Crash when writing a baseline file into a directory that does not exist.
  • Raw traceback for unreadable or malformed baseline files.
  • Python spelling in config type errors, e.g. bool: True instead of boolean: true.
  • Crash on TOML dates and times in the config file.

st replay

  • Ignoring auth providers and [auth.openapi] credentials, resending masked values instead.
  • Reporting a crash as fixed when its credentials were missing or rejected.
  • Deleting fixed crash files that sent a masked request body value.
  • Reproduce commands for stateful chains using stale recorded IDs.

... (truncated)

Changelog

Sourced from schemathesis's changelog.

4.29.0 - 2026-10-02

🚀 Added

  • WFC Report output via --report wfc or --report-wfc-path.
  • Dependency inference links body fields named after a collection to its items' code.
  • st replay options -H/--header, --auth, --auth-wfc and --auth-wfc-user for replayed requests.
  • Coverage Content-Type probes for malformed multipart and undeclared request media types.
  • format: binary values include small valid PNG, JPEG, GIF, WebP, PDF and ZIP files.
  • Multipart file names carry the extension of the detected file format, e.g. image.png.
  • use_after_free and ensure_resource_availability failures note responses served from a cache.

🔧 Changed

  • Negative test cases break a random subset of request locations instead of all of them.
  • Name the pattern that stops the analysis when test data cannot be generated.
  • BREAKING: st run and st fuzz fail with exit code 2 when nothing is tested.
  • BREAKING: st run and st fuzz exit 2 on schema, configuration and internal errors.
  • BREAKING: st run, st fuzz and st replay exit 130 when interrupted with Ctrl+C.
  • Linked stateful steps send negative requests as often as scenario-starting steps.
  • st replay step chains show each linked value as recorded -> replayed.
  • st replay removes fixed crash files with masked credentials once config or CLI supplies them.
  • Fuzzing and pytest seed each operation separately, so operations with identical parameters explore different inputs.
  • Stateful testing targets only metrics from generation.maximize or explicit hypothesis.target() calls.
  • ignored_auth stops probing an operation once it rejects missing and invalid credentials.
  • missing_deserializer warning names the response media types that go unvalidated.

🐛 Fixed

st run and st fuzz

  • Fuzzing phase dropping data generation errors when several distinct errors occur.
  • st fuzz --help omitting that fuzzing stops at the first failure without --continue-on-failure.
  • st fuzz omitting schema errors of individual operations.
  • st fuzz workers continuing after the first failure and reporting Stop reason: Completed.
  • Stop reason: Time limit reached for runs stopped by a failure shortly before the deadline.
  • continue-on-failure in the config file ignored.
  • WFC auth skipping users in the coverage phase and settling operations on the wrong one.
  • WFC auth never retrying users rejected before the API created their accounts.
  • Crash when writing a baseline file into a directory that does not exist.
  • Raw traceback for unreadable or malformed baseline files.
  • Python spelling in config type errors, e.g. bool: True instead of boolean: true.
  • Crash on TOML dates and times in the config file.

st replay

  • Ignoring auth providers and [auth.openapi] credentials, resending masked values instead.
  • Reporting a crash as fixed when its credentials were missing or rejected.
  • Deleting fixed crash files that sent a masked request body value.
  • Reproduce commands for stateful chains using stale recorded IDs.

... (truncated)

Commits
  • d5be23e chore: Release 4.29.0
  • 7dd8fed chore: Update tracecov to 0.25.0
  • 305adf3 fix: Operations with schema errors missing from pytest Allure and JUnit results
  • ba0a69b fix: Oversized curl reproduction commands for non-ASCII request data
  • f0c0af2 fix: Ignored apply_to / skip_for filters on hooks registered by name
  • 2ec9dfb chore: Content-Type probe control request keeps set_from_requests auth
  • d39b8b4 chore: WFC report script runs in the shell its curl commands are escaped for
  • 7d3ba29 chore: Equal test cases hash equally regardless of header name case
  • e59b568 fix: False positive ignored_auth with credentials in an undeclared `Authori...
  • 1192afb docs: Tighten documentation prose
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Sep 30, 2026
@dependabot
dependabot Bot force-pushed the dependabot/pip/compose-configs/egeria-quickstart/PyegeriaWebHandler/schemathesis-gte-4.28.0 branch from 1270cef to 8e9f212 Compare October 1, 2026 14:22
Updates the requirements on [schemathesis](https://github.com/schemathesis/schemathesis) to permit the latest version.
- [Release notes](https://github.com/schemathesis/schemathesis/releases)
- [Changelog](https://github.com/schemathesis/schemathesis/blob/master/CHANGELOG.md)
- [Commits](schemathesis/schemathesis@v4.27.1...v4.29.0)

---
updated-dependencies:
- dependency-name: schemathesis
  dependency-version: 4.28.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title chore(deps): Update schemathesis requirement from >=4.27.1 to >=4.28.0 in /compose-configs/egeria-quickstart/PyegeriaWebHandler chore(deps): Update schemathesis requirement from >=4.27.1 to >=4.29.0 in /compose-configs/egeria-quickstart/PyegeriaWebHandler Oct 5, 2026
@dependabot
dependabot Bot force-pushed the dependabot/pip/compose-configs/egeria-quickstart/PyegeriaWebHandler/schemathesis-gte-4.28.0 branch from 8e9f212 to bb12a61 Compare October 5, 2026 08:55
@dependabot @github

dependabot Bot commented on behalf of github Oct 7, 2026

Copy link
Copy Markdown
Contributor Author

Superseded by #615.

@dependabot dependabot Bot closed this Oct 7, 2026
@dependabot
dependabot Bot deleted the dependabot/pip/compose-configs/egeria-quickstart/PyegeriaWebHandler/schemathesis-gte-4.28.0 branch October 7, 2026 17:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants