dependabot[bot] opened a new pull request, #44938:
URL: https://github.com/apache/superset/pull/44938

   Bumps [sqlalchemy](https://github.com/sqlalchemy/sqlalchemy) from 2.0.52 to 
2.1.1.
   <details>
   <summary>Release notes</summary>
   <p><em>Sourced from <a 
href="https://github.com/sqlalchemy/sqlalchemy/releases";>sqlalchemy's 
releases</a>.</em></p>
   <blockquote>
   <h1>2.1.1</h1>
   <p>Released: September 25, 2026</p>
   <h2>platform</h2>
   <ul>
   <li>
   <p><strong>[platform] [bug]</strong> Removed the legacy underscore-separated 
extra names such as
   <code>mssql_pymssql</code> and <code>postgresql_psycopg</code> from 
<code>pyproject.toml</code>.
   They normalize to the same names as the existing dash-separated extras,
   which is disallowed by <a href="https://peps.python.org/pep-0685";>PEP 
685</a>, and caused the 2.1.0 source
   distribution to fail to build with installers that enforce this rule,
   such as uv. The underscore spellings continue to work when installing,
   as installers normalize extra names before matching them.</p>
   <p>References: <a 
href="https://www.sqlalchemy.org/trac/ticket/13604";>#13604</a></p>
   </li>
   </ul>
   <h1>2.1.0</h1>
   <p>Released: September 24, 2026</p>
   <h2>orm</h2>
   <ul>
   <li>
   <p><strong>[orm] [feature]</strong> Added 
<code>_orm.composite.column_template</code> parameter to
   <code>_orm.composite()</code>.  When the composite class is a dataclass, this
   parameter accepts a string template such as 
<code>&quot;person_%s&quot;</code>, containing
   exactly one <code>%s</code> placeholder, that's used to generate column 
names for
   dataclass fields that don't otherwise have an explicit name, rather than
   using the bare field name.  This removes the need to hand-write a
   <code>_orm.mapped_column()</code> for each field when the same composite 
dataclass
   is mapped multiple times on the same class with different column-name
   prefixes.  Pull request courtesy Leonardo Rosa.</p>
   <p>References: <a 
href="https://www.sqlalchemy.org/trac/ticket/12575";>#12575</a></p>
   </li>
   <li>
   <p><strong>[orm] [bug]</strong> Fixed issue where pickling an ORM object 
that had an instance level lazy
   loader established, such as when the <code>_orm.raiseload()</code> option is 
used,
   would emit a spurious warning regarding the loader containing additional
   criteria, if the object had itself been unpickled from a previous
   serialization.  This would occur for objects that cross more than one
   serialization boundary, such as when using multiprocessing.</p>
   <p>This change is also <strong>backported</strong> to: 2.0.53</p>
   <p>References: <a 
href="https://www.sqlalchemy.org/trac/ticket/13574";>#13574</a></p>
   </li>
   <li>
   <p><strong>[orm] [bug]</strong> Fixed issue where calling 
<code>_orm.aliased()</code> against an existing
   <code>_orm.aliased()</code> construct, without passing an explicit 
selectable,
   would disregard the selectable of the existing construct and produce an</p>
   </li>
   </ul>
   <!-- raw HTML omitted -->
   </blockquote>
   <p>... (truncated)</p>
   </details>
   <details>
   <summary>Commits</summary>
   <ul>
   <li>See full diff in <a 
href="https://github.com/sqlalchemy/sqlalchemy/commits";>compare view</a></li>
   </ul>
   </details>
   <br />
   
   
   [![Dependabot compatibility 
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=sqlalchemy&package-manager=pip&previous-version=2.0.52&new-version=2.1.1)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
   
   Dependabot will resolve any conflicts with this PR as long as you don't 
alter it yourself. You can also trigger a rebase manually by commenting 
`@dependabot rebase`.
   
   [//]: # (dependabot-automerge-start)
   [//]: # (dependabot-automerge-end)
   
   ---
   
   <details>
   <summary>Dependabot commands and options</summary>
   <br />
   
   You can trigger Dependabot actions by commenting on this PR:
   - `@dependabot rebase` will rebase this PR
   - `@dependabot recreate` will recreate this PR, overwriting any edits that 
have been made to it
   - `@dependabot show <dependency name> ignore conditions` will show all of 
the ignore conditions of the specified dependency
   - `@dependabot ignore this major version` will close this PR and stop 
Dependabot creating any more for this major version (unless you reopen the PR 
or upgrade to it yourself)
   - `@dependabot ignore this minor version` will close this PR and stop 
Dependabot creating any more for this minor version (unless you reopen the PR 
or upgrade to it yourself)
   - `@dependabot ignore this dependency` will close this PR and stop 
Dependabot creating any more for this dependency (unless you reopen the PR or 
upgrade to it yourself)
   
   
   </details>


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to