Latest Results
Bump multidict from 6.9.1 to 7.0.0 (#13879)
Bumps [multidict](https://github.com/aio-libs/multidict) from 6.9.1 to
7.0.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/aio-libs/multidict/releases">multidict's
releases</a>.</em></p>
<blockquote>
<p>7.0.0 is a major release. It makes <code>istr</code> final, adds a
public C API for third-party extensions, and makes the C extension
substantially faster across the board.</p>
<p><strong>Breaking change.</strong> <code>istr</code> can no longer be
subclassed,
on either backend. Code that subclassed it has to wrap or convert
instead.
The C extension also started rejecting an argument passed both
positionally and by name with <code>TypeError</code>, where it used to
silently
misbehave.</p>
<p><strong>Public C and Cython API.</strong> Other C extensions and
Cython modules can now
create, read and mutate multidicts through a capsule, without going
through
the Python-level API. The capsule comes with
<code>multidict_capi.h</code>, a
<code>cimport</code>-able <code>multidict/__init__.pxd</code> and
<code>multidict.get_include()</code>. The API includes
<code>MultiDict_ForEach()</code> and
a watchers API modeled on CPython's dict watchers. See the <a
href="https://multidict.aio-libs.org/en/stable/capi.html">C API</a> and
<a href="https://multidict.aio-libs.org/en/stable/cyapi.html">Cython
API</a> references.</p>
<p><strong>Performance.</strong> On CodSpeed's GIL-build benchmarks
against 6.9.1, 82
C-extension benchmarks got faster and none got slower. Rough
figures:</p>
<ul>
<li><code>CIMultiDict</code> keyed by plain <code>str</code>:
construction,
<code>add()</code>, <code>extend()</code>, <code>update()</code> and
item assignment got 2 to 3.8
times faster, and lookups about 2 times faster.</li>
<li><code>CIMultiDict</code> keyed by <code>istr</code>, and
case-sensitive <code>MultiDict</code>: lookups, insertion and
deletion got 10% to 70% faster.</li>
<li><code>getall()</code> and iterating
<code>items()</code> got about 35% faster, and the view set
operations 10% to 85% faster.</li>
<li><code>popitem()</code> on a whole mapping went from
quadratic to linear time.</li>
<li>On the free-threaded build, measured in instructions against 6.9.1,
lookups got 24% to 33% cheaper on <code>MultiDict</code> and 4 to 5
times cheaper on <code>CIMultiDict</code> with lowercase
<code>str</code>
keys, and item assignment 15% to 19% cheaper. Construction and deletion
on
<code>MultiDict</code> cost 2% to 7% more. With several threads
mutating at once, a <code>d[key] = value</code> got about four times
faster.</li>
</ul>
<p>The pure-Python backend is unchanged in speed.</p>
<p><strong>Robustness.</strong> This release fixed several crashes and
leaks in the C
extension, including use-after-free bugs when a key's
<code>lower()</code> or a
value's <code>__eq__</code> mutated a multidict, a crash at interpreter
shutdown,
and table and reference leaks on the free-threaded build.</p>
<h2>Bug fixes</h2>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/aio-libs/multidict/blob/master/CHANGES.rst">multidict's
changelog</a>.</em></p>
<blockquote>
<h1>7.0.0</h1>
<p><em>(2026-09-26)</em></p>
<p>7.0.0 is a major release. It makes
:class:<code>~multidict.istr</code> final, adds a
public C API for third-party extensions, and makes the C extension
substantially faster across the board.</p>
<p><strong>Breaking change.</strong> :class:<code>~multidict.istr</code>
can no longer be subclassed,
on either backend. Code that subclassed it has to wrap or convert
instead.
The C extension also started rejecting an argument passed both
positionally and by name with :exc:<code>TypeError</code>, where it used
to silently
misbehave.</p>
<p><strong>Public C and Cython API.</strong> Other C extensions and
Cython modules can now
create, read and mutate multidicts through a capsule, without going
through
the Python-level API. The capsule comes with
<code>multidict_capi.h</code>, a
<code>cimport</code>-able <code>multidict/__init__.pxd</code> and
:func:<code>multidict.get_include</code>. The API includes
<code>MultiDict_ForEach()</code> and
a watchers API modeled on CPython's dict watchers. See the :doc:<code>C
API <capi></code> and
:doc:<code>Cython API <cyapi></code> references.</p>
<p><strong>Performance.</strong> On CodSpeed's GIL-build benchmarks
against 6.9.1, 82
C-extension benchmarks got faster and none got slower. Rough
figures:</p>
<ul>
<li>:class:<code>~multidict.CIMultiDict</code> keyed by plain
:class:<code>str</code>: construction,
<code>add()</code>, <code>extend()</code>, <code>update()</code> and
item assignment got 2 to 3.8
times faster, and lookups about 2 times faster.</li>
<li>:class:<code>~multidict.CIMultiDict</code> keyed by
:class:<code>~multidict.istr</code>, and
case-sensitive :class:<code>~multidict.MultiDict</code>: lookups,
insertion and
deletion got 10% to 70% faster.</li>
<li>:meth:<code>~multidict.MultiDict.getall</code> and iterating
:meth:<code>~multidict.MultiDict.items</code> got about 35% faster, and
the view set
operations 10% to 85% faster.</li>
<li>:meth:<code>~multidict.MultiDict.popitem</code> on a whole mapping
went from
quadratic to linear time.</li>
<li>On the free-threaded build, measured in instructions against 6.9.1,
lookups got 24% to 33% cheaper on
:class:<code>~multidict.MultiDict</code> and 4 to 5
times cheaper on :class:<code>~multidict.CIMultiDict</code> with
lowercase :class:<code>str</code>
keys, and item assignment 15% to 19% cheaper. Construction and deletion
on
:class:<code>~multidict.MultiDict</code> cost 2% to 7% more. With
several threads
mutating at once, a <code>d[key] = value</code> got about four times
faster.</li>
</ul>
<p>The pure-Python backend is unchanged in speed.</p>
<p><strong>Robustness.</strong> This release fixed several crashes and
leaks in the C
extension, including use-after-free bugs when a key's
<code>lower()</code> or a
value's <code>__eq__</code> mutated a multidict, a crash at interpreter
shutdown,
and table and reference leaks on the free-threaded build.</p>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/aio-libs/multidict/commit/72f7c3c49503c8c6c0cd4c933257611b6afbed73"><code>72f7c3c</code></a>
Release 7.0.0 (<a
href="https://redirect.github.com/aio-libs/multidict/issues/1603">#1603</a>)</li>
<li><a
href="https://github.com/aio-libs/multidict/commit/2f84475e940f3041c20f685ed8aadbff39b7a539"><code>2f84475</code></a>
Fold new fragments and refresh benchmark tables for 7.0.0 (<a
href="https://redirect.github.com/aio-libs/multidict/issues/1602">#1602</a>)</li>
<li><a
href="https://github.com/aio-libs/multidict/commit/d66879bf6524c52c75d3456de8ce896425a1ae40"><code>d66879b</code></a>
Keep slot-level operations out of line (<a
href="https://redirect.github.com/aio-libs/multidict/issues/1600">#1600</a>)</li>
<li><a
href="https://github.com/aio-libs/multidict/commit/8708f360dcf6a4d884474ad598fa5e3221ced028"><code>8708f36</code></a>
Keep the insert-path resize out of line (<a
href="https://redirect.github.com/aio-libs/multidict/issues/1601">#1601</a>)</li>
<li><a
href="https://github.com/aio-libs/multidict/commit/39ac5df607fddb2fa625702d425d5ea64159f933"><code>39ac5df</code></a>
Take references in update() from a dict only when lower() can run code
(<a
href="https://redirect.github.com/aio-libs/multidict/issues/1598">#1598</a>)</li>
<li><a
href="https://github.com/aio-libs/multidict/commit/b5d4053919e8335bf27a3fe3d081f85f9fafb275"><code>b5d4053</code></a>
Keep one thread-local version counter on free-threaded builds (<a
href="https://redirect.github.com/aio-libs/multidict/issues/1599">#1599</a>)</li>
<li><a
href="https://github.com/aio-libs/multidict/commit/602dedc931689f040c28ebd07a15d65de163c65a"><code>602dedc</code></a>
Render changelog roles as Markdown in GitHub Release notes (<a
href="https://redirect.github.com/aio-libs/multidict/issues/1596">#1596</a>)</li>
<li><a
href="https://github.com/aio-libs/multidict/commit/d02502adb09b0b50bf9135887d141f5f7aeaf96f"><code>d02502a</code></a>
Tidy news fragments for 7.0.0 (<a
href="https://redirect.github.com/aio-libs/multidict/issues/1597">#1597</a>)</li>
<li><a
href="https://github.com/aio-libs/multidict/commit/91d5329923ed6414765e24299349116aee0e4a97"><code>91d5329</code></a>
Forbid instantiating views and iterators with
Py_TPFLAGS_DISALLOW_INSTANTIATI...</li>
<li><a
href="https://github.com/aio-libs/multidict/commit/27fec2d0dea21c73d7e88860ea8078a90c635a45"><code>27fec2d</code></a>
Name slot-only C functions after the slot they fill (<a
href="https://redirect.github.com/aio-libs/multidict/issues/1594">#1594</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/aio-libs/multidict/compare/v6.9.1...v7.0.0">compare
view</a></li>
</ul>
</details>
<br />
[](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
</details>
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
(cherry picked from commit 4685f328759634dd6a7e970dad518da683ad345e)patchback/backports/3.14/4685f328759634dd6a7e970dad518da683ad345e/pr-13879 Latest Branches
0%
patchback/backports/3.14/4685f328759634dd6a7e970dad518da683ad345e/pr-13879 0%
dependabot/pip/3.15/mypy-2.4.0 0%
dependabot/pip/mypy-2.4.0 © 2026 CodSpeed Technology