deps: Bump the python-minor-and-patch group across 1 directory with 7 updates - #35
Closed
dependabot[bot] wants to merge 1 commit into
Closed
deps: Bump the python-minor-and-patch group across 1 directory with 7 updates#35dependabot[bot] wants to merge 1 commit into
dependabot[bot] wants to merge 1 commit into
Conversation
dependabot
Bot
force-pushed
the
dependabot/uv/python-minor-and-patch-b24ceffd02
branch
2 times, most recently
from
August 4, 2026 15:03
a75cc7f to
115032e
Compare
… updates Bumps the python-minor-and-patch group with 7 updates in the / directory: | Package | From | To | | --- | --- | --- | | [boto3](https://github.com/boto/boto3) | `1.43.56` | `1.43.62` | | [filelock](https://github.com/tox-dev/py-filelock) | `3.32.0` | `3.32.2` | | [pymdown-extensions](https://github.com/facelessuser/pymdown-extensions) | `11.0` | `11.0.1` | | [mutmut](https://github.com/boxed/mutmut) | `3.6.0` | `3.7.0` | | [ruff](https://github.com/astral-sh/ruff) | `0.16.0` | `0.16.1` | | [ty](https://github.com/astral-sh/ty) | `0.0.63` | `0.0.65` | | [hypothesis](https://github.com/HypothesisWorks/hypothesis) | `6.161.6` | `6.165.0` | Updates `boto3` from 1.43.56 to 1.43.62 - [Release notes](https://github.com/boto/boto3/releases) - [Commits](boto/boto3@1.43.56...1.43.62) Updates `filelock` from 3.32.0 to 3.32.2 - [Release notes](https://github.com/tox-dev/py-filelock/releases) - [Changelog](https://github.com/tox-dev/filelock/blob/main/docs/changelog.rst) - [Commits](tox-dev/filelock@3.32.0...3.32.2) Updates `pymdown-extensions` from 11.0 to 11.0.1 - [Release notes](https://github.com/facelessuser/pymdown-extensions/releases) - [Commits](facelessuser/pymdown-extensions@11.0...11.0.1) Updates `mutmut` from 3.6.0 to 3.7.0 - [Changelog](https://github.com/boxed/mutmut/blob/main/HISTORY.rst) - [Commits](boxed/mutmut@3.6.0...3.7.0) Updates `ruff` from 0.16.0 to 0.16.1 - [Release notes](https://github.com/astral-sh/ruff/releases) - [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md) - [Commits](astral-sh/ruff@0.16.0...0.16.1) Updates `ty` from 0.0.63 to 0.0.65 - [Release notes](https://github.com/astral-sh/ty/releases) - [Changelog](https://github.com/astral-sh/ty/blob/main/CHANGELOG.md) - [Commits](astral-sh/ty@0.0.63...0.0.65) Updates `hypothesis` from 6.161.6 to 6.165.0 - [Release notes](https://github.com/HypothesisWorks/hypothesis/releases) - [Commits](HypothesisWorks/hypothesis@v6.161.6...v6.165.0) --- updated-dependencies: - dependency-name: boto3 dependency-version: 1.43.61 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: python-minor-and-patch - dependency-name: filelock dependency-version: 3.32.2 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: python-minor-and-patch - dependency-name: hypothesis dependency-version: 6.164.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: python-minor-and-patch - dependency-name: mutmut dependency-version: 3.7.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: python-minor-and-patch - dependency-name: pymdown-extensions dependency-version: 11.0.1 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: python-minor-and-patch - dependency-name: ruff dependency-version: 0.16.1 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: python-minor-and-patch - dependency-name: ty dependency-version: 0.0.65 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: python-minor-and-patch ... Signed-off-by: dependabot[bot] <support@github.com>
dependabot
Bot
force-pushed
the
dependabot/uv/python-minor-and-patch-b24ceffd02
branch
from
August 5, 2026 13:51
115032e to
80efd64
Compare
rustyconover
added a commit
that referenced
this pull request
Aug 5, 2026
`uv lock --upgrade` across the tree, landing a superset of the two open Dependabot PRs (#34 pyarrow, #35 the python-minor-and-patch group) and 38 package moves in total. Nothing remains outdated afterwards. The one worth naming is pyarrow 24.0.0 -> 25.0.0. vgi-python moved to 25 in its own dependency pass, so the two repos were resolving different majors of the single library the whole protocol sits on -- this package's tests were exercising an Arrow surface no vgi-python user runs. Suite passes unchanged at 4042. No security content: this repo has zero open Dependabot alerts, and the advisories that drove vgi-python's pass were already satisfied here (cryptography 50.0.0, aiohttp 3.14.3). ty is capped at <0.0.64 rather than upgraded. At 0.0.66 `ty check` stopped terminating on the sibling vgi-python tree -- ten minutes locally, and in CI it hung until the step was cancelled, which `continue-on-error` does not rescue, so a check that gates nothing turned the whole Lint job red. vgi-python dropped the tool outright; here it is merely pinned, because the cap is what stops the next routine `uv lock --upgrade` from silently walking back into it. Lift once upstream terminates again. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Collaborator
|
Superseded by e2ae9d8, which ran |
Contributor
Author
|
This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests. To ignore these dependencies, configure ignore rules in dependabot.yml |
dependabot
Bot
deleted the
dependabot/uv/python-minor-and-patch-b24ceffd02
branch
August 5, 2026 13:55
rustyconover
added a commit
that referenced
this pull request
Aug 5, 2026
…python No shipped code changes; this is the version marker for e2ae9d8, which ran `uv lock --upgrade` across the tree and landed a superset of Dependabot #34 and #35 -- 38 package moves, nothing outdated left afterwards. The one that mattered is pyarrow 24.0.0 -> 25.0.0. vgi-python had already moved to 25, so this package's tests were exercising a different major of the library the whole protocol sits on than any vgi-python user runs. Both repos now resolve the same Arrow. No security content: zero open Dependabot alerts here, and the advisories behind vgi-python's pass were already satisfied (cryptography 50.0.0, aiohttp 3.14.3). ty is capped at <0.0.64 rather than upgraded. At 0.0.66 `ty check` stopped terminating -- ten minutes locally, and in CI it hung until the step was cancelled, which `continue-on-error` does not rescue, so a check that gates nothing turned the Lint job red. The cap is what stops the next routine `uv lock --upgrade` from walking back into it. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the python-minor-and-patch group with 7 updates in the / directory:
1.43.561.43.623.32.03.32.211.011.0.13.6.03.7.00.16.00.16.10.0.630.0.656.161.66.165.0Updates
boto3from 1.43.56 to 1.43.62Commits
f3e9c52Merge branch 'release-1.43.62'47765b7Bumping version to 1.43.622f4f5fbAdd changelog entries from botocore8cd8552Merge branch 'release-1.43.61'53d9670Merge branch 'release-1.43.61' into develop74101e1Bumping version to 1.43.617faedb5Add changelog entries from botocore785f6ffMerge branch 'release-1.43.60'550ff07Merge branch 'release-1.43.60' into develop68f5316Bumping version to 1.43.60Updates
filelockfrom 3.32.0 to 3.32.2Release notes
Sourced from filelock's releases.
Changelog
Sourced from filelock's changelog.
... (truncated)
Commits
9a6cc43Release 3.32.256879c7🧪 test(unix): deflake sticky-bit concurrent-unlink on graalpy (#695)ecf5be0hand back the claim when a heartbeat thread fails to start (#691)ee70d2e🧪 test(soft-rw): deflake writer phase-2 peer-marker test (#694)1eb14ddFix test failures on NetBSD (#689) (#693)d81e859build(deps): bump astral-sh/setup-uv from 8.3.2 to 9.0.0 (#692)6fbc905[pre-commit.ci] pre-commit autoupdate (#690)34d1c38build(deps): bump pypa/gh-action-pypi-publish from 1.14.0 to 1.14.1 (#688)bf13ec7Release 3.32.1887f114build(deps): bump actions/checkout from 7.0.0 to 7.0.1 (#687)Updates
pymdown-extensionsfrom 11.0 to 11.0.1Release notes
Sourced from pymdown-extensions's releases.
Commits
c684985Merge commit from forkUpdates
mutmutfrom 3.6.0 to 3.7.0Changelog
Sourced from mutmut's changelog.
Commits
4f12080Release 3.7.0f5156fdUpdated authors0092be2fix: forward generator return value through the trampoline (#542)9e4af73Read mutants from a line span index instead of parsing the mutated file (#543)32f0b42chore(readme): fix typo (#537)523a19cupdate changelog70b26fflockfiles1d11c1bmisc: update authors (#532)8799708fix(#525): implement full async-gen wrapper (#530)c01561bfix record_trampoline_hit when tmpdir changed working directoryUpdates
rufffrom 0.16.0 to 0.16.1Release notes
Sourced from ruff's releases.
... (truncated)
Changelog
Sourced from ruff's changelog.
... (truncated)
Commits
80790b3Bump 0.16.1 (#27330)63830f3[ty] Borrow from constraint set storage less often (#27328)f40dca9[ty] Preserve forwarded expanded-variadic diagnostic sources (#27266)0d80497Lint TOML files in the LSP (#26862)d91586bUpdate prek dependencies (#27293)7da4b8b[ty] Respect bounds and constraints in generic materializations (#27228)b20daf7[ty] refactor: add helper function to send partial results (#27249)4d4c8fa[ty] Emit diagnostic when specializing a non-generic class (#26883)7c3e2db[ty] Fix enum class container assignability (#27318)d5ef97f[flake8-return] Fix false positive when variable is read infinallyclaus...Updates
tyfrom 0.0.63 to 0.0.65Release notes
Sourced from ty's releases.
... (truncated)
Changelog
Sourced from ty's changelog.
... (truncated)
Commits
87de836Bump version to 0.0.65 (#4113)d784badREADME: Add link to Stable milestone (#4112)b4c1978Update actions/setup-python action to v7 (#4110)8d216a3Update actions/checkout action to v7.0.1 (#4107)06f44e9Update dependency prek to v0.4.10 (#4108)b3665fdUpdate prek dependencies (#4109)5e64a13Bump version to 0.0.64 (#4097)Updates
hypothesisfrom 6.161.6 to 6.165.0Commits
a11e4b4Bump hypothesis version to 6.165.0 and update changelog2e08ef3Merge pull request #4831 from Zac-HD/claude/codec-non-round-tripping-chars-hh...72bfab7Merge pull request #4838 from Zac-HD/website-fixtures-article6f1a14cOnly enforce 100% combined coverage when the python tests actually ran9153fd1Warn rather than raise for non-round-tripping characters1815cabWrite pytest consistently, and fix code block renderingcbcd1ccUpdate the pytest-fixtures article for the function-scoped health checkce7ef4aMerge pull request #4840 from Zac-HD/website-preview-pr-lookup8a4c803Fix PR lookup in the website preview workflowf94aae1Merge pull request #4836 from Zac-HD/claude/pr-build-live-preview-15crof