dependabot[bot] opened a new pull request, #44938: URL: https://github.com/apache/superset/pull/44938
Bumps [sqlalchemy](https://github.com/sqlalchemy/sqlalchemy) from 2.0.52 to 2.1.1. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/sqlalchemy/sqlalchemy/releases">sqlalchemy's releases</a>.</em></p> <blockquote> <h1>2.1.1</h1> <p>Released: September 25, 2026</p> <h2>platform</h2> <ul> <li> <p><strong>[platform] [bug]</strong> Removed the legacy underscore-separated extra names such as <code>mssql_pymssql</code> and <code>postgresql_psycopg</code> from <code>pyproject.toml</code>. They normalize to the same names as the existing dash-separated extras, which is disallowed by <a href="https://peps.python.org/pep-0685">PEP 685</a>, and caused the 2.1.0 source distribution to fail to build with installers that enforce this rule, such as uv. The underscore spellings continue to work when installing, as installers normalize extra names before matching them.</p> <p>References: <a href="https://www.sqlalchemy.org/trac/ticket/13604">#13604</a></p> </li> </ul> <h1>2.1.0</h1> <p>Released: September 24, 2026</p> <h2>orm</h2> <ul> <li> <p><strong>[orm] [feature]</strong> Added <code>_orm.composite.column_template</code> parameter to <code>_orm.composite()</code>. When the composite class is a dataclass, this parameter accepts a string template such as <code>"person_%s"</code>, containing exactly one <code>%s</code> placeholder, that's used to generate column names for dataclass fields that don't otherwise have an explicit name, rather than using the bare field name. This removes the need to hand-write a <code>_orm.mapped_column()</code> for each field when the same composite dataclass is mapped multiple times on the same class with different column-name prefixes. Pull request courtesy Leonardo Rosa.</p> <p>References: <a href="https://www.sqlalchemy.org/trac/ticket/12575">#12575</a></p> </li> <li> <p><strong>[orm] [bug]</strong> Fixed issue where pickling an ORM object that had an instance level lazy loader established, such as when the <code>_orm.raiseload()</code> option is used, would emit a spurious warning regarding the loader containing additional criteria, if the object had itself been unpickled from a previous serialization. This would occur for objects that cross more than one serialization boundary, such as when using multiprocessing.</p> <p>This change is also <strong>backported</strong> to: 2.0.53</p> <p>References: <a href="https://www.sqlalchemy.org/trac/ticket/13574">#13574</a></p> </li> <li> <p><strong>[orm] [bug]</strong> Fixed issue where calling <code>_orm.aliased()</code> against an existing <code>_orm.aliased()</code> construct, without passing an explicit selectable, would disregard the selectable of the existing construct and produce an</p> </li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li>See full diff in <a href="https://github.com/sqlalchemy/sqlalchemy/commits">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected] --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
