Skip to content

⬆ Bump the python-packages group across 1 directory with 5 updates - #503

Merged
YuriiMotov merged 2 commits into
mainfrom
dependabot/uv/python-packages-128ae6e5a4
Oct 5, 2026
Merged

YuriiMotov merged 2 commits into
mainfrom
dependabot/uv/python-packages-128ae6e5a4

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the python-packages group with 5 updates in the / directory:

Package From To
ruff 0.16.4 0.16.9
uvicorn 0.52.4 0.54.0
ty 0.0.74 0.0.84
prek 0.4.14 0.5.4
zizmor 1.29.0 1.30.1

Updates ruff from 0.16.4 to 0.16.9

Release notes

Sourced from ruff's releases.

0.16.9

Release Notes

Released on 2026-09-24.

Preview features

  • [ruff] Avoid false positives for overloaded division (RUF069) (#28309)

Bug fixes

  • [flake8-bugbear] Avoid false positives for calls with keyword arguments (B009, B010, B043) (#28776)
  • [flake8-tidy-imports] Allow lazy imports to be used in deferred annotations (TID255) (#28767)

Rule changes

  • Update LibCST-based fixes for Python 3.15 (#28616)
  • [flake8-pyi] Mention stubs in the diagnostic message (PYI002) (#28542)

Documentation

  • Fix horizontal overflow on the rules documentation page (#28699)
  • Update rules table with category information (#28651)
  • [flake8-annotations] Clarify that ANN401 checks return types in addition to arguments (#28334)
  • [flake8-bugbear] Document type-checker interaction (B010) (#28509)
  • [flake8-comprehensions] Document map/generator exception behavior (C417) (#27794)
  • [ruff] Mention related isort settings (RUF022) (#28719)

Contributors

Install ruff 0.16.9

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/ruff/releases/download/0.16.9/ruff-installer.sh | sh

... (truncated)

Changelog

Sourced from ruff's changelog.

0.16.9

Released on 2026-09-24.

Preview features

  • [ruff] Avoid false positives for overloaded division (RUF069) (#28309)

Bug fixes

  • [flake8-bugbear] Avoid false positives for calls with keyword arguments (B009, B010, B043) (#28776)
  • [flake8-tidy-imports] Allow lazy imports to be used in deferred annotations (TID255) (#28767)

Rule changes

  • Update LibCST-based fixes for Python 3.15 (#28616)
  • [flake8-pyi] Mention stubs in the diagnostic message (PYI002) (#28542)

Documentation

  • Fix horizontal overflow on the rules documentation page (#28699)
  • Update rules table with category information (#28651)
  • [flake8-annotations] Clarify that ANN401 checks return types in addition to arguments (#28334)
  • [flake8-bugbear] Document type-checker interaction (B010) (#28509)
  • [flake8-comprehensions] Document map/generator exception behavior (C417) (#27794)
  • [ruff] Mention related isort settings (RUF022) (#28719)

Contributors

0.16.8

Released on 2026-09-16.

Bug fixes

  • Visit functional TypedDict keyword arguments correctly (#28584)
  • [flake8-simplify] Detect nested async with under sync parent (SIM117) (#27821)
  • [flake8-simplify] Preserve operand order in SIM109 fix (#27824)

... (truncated)

Commits
  • 0be08a2 Bump version to 0.16.9 (#28882)
  • b4920b7 Rename ruff_cli to ruff_command_line (#28881)
  • 47c751b Update dependency astral-sh/uv to v0.12.18 (#28880)
  • 8c244e5 [flake8-comprehensions] Document map/generator exception behavior (C417...
  • 5edf5a1 Use target form in rooster.version_files (#28876)
  • 915bb2b [ty] Prefer existing @ paths over response files in Ruff and ty (#28877)
  • 4710e1a ci(github): update version number in placeholder of issue template (#28871)
  • eedfc62 [ty] Propagate outer type context through cast calls (#28855)
  • ceaa6a0 [ty] Contain rendered code within Markdown fences (#28869)
  • dba0f30 authorize ruff-pre-commit dispatch via OIDC (#28867)
  • Additional commits viewable in compare view

Updates uvicorn from 0.52.4 to 0.54.0

Release notes

Sourced from uvicorn's releases.

Version 0.54.0

📨 Send metadata after the response body

uvicorn 0.54.0 adds response trailers and 103 Early Hints to its experimental HTTP/2 implementation through zttp.

uv add uvicorn==0.54.0 "zttp>=0.0.34"
  • Send HTTP/2 response trailers (#3146). The ASGI http.response.trailers extension lets applications send metadata, such as checksums, after the response body. Clients must send TE: trailers to receive them. Multiple trailer messages are combined before completing the response.
  • HTTP/2 remains experimental and opt-in. Enable it with --http zttp --http2. Upgrade-based h2c and WebSockets over HTTP/2 remain unsupported.

💡 Hint at resources before the final response

  • Send 103 Early Hints over HTTP/2 (#3137). Applications can use the ASGI http.response.early_hint extension to send resource hints before the final response. Each supplied link becomes a separate Link header.

Full changelog: 0.53.0...0.54.0

Version 0.53.0

🌐 Opt-in HTTP/2 support

uvicorn 0.53.0 adds experimental HTTP/2 through zttp, alongside a new zuvloop integration and connection-handling improvements.

uv add uvicorn==0.53.0
  • Serve HTTP/1.1 and HTTP/2 with zttp (#2982, #3101). Install zttp, then enable HTTP/2 with --http zttp --http2. Uvicorn negotiates HTTP/2 over TLS with ALPN and supports cleartext prior knowledge.
  • HTTP/2 remains experimental. Upgrade-based h2c and WebSockets over HTTP/2 are not supported.

⚙️ More event loop choice

  • Run Uvicorn with zuvloop (#3104). Install zuvloop separately and select it explicitly with --loop zuvloop on CPython 3.14 or newer.

🛡️ More reliable connections and proxies

  • Honor Connection: close token lists (#3103). Uvicorn now parses comma-separated tokens case-insensitively across HTTP implementations.
  • Trust IPv6 loopback proxies by default (#3119). The default FORWARDED_ALLOW_IPS value now includes ::1.
  • Keep upgraded WebSockets alive (#3107). Uvicorn cancels the HTTP keep-alive timer when the connection becomes a WebSocket.

Full changelog: 0.52.4...0.53.0

Changelog

Sourced from uvicorn's changelog.

0.54.0 (September 24, 2026)

HTTP/2 support remains experimental. Install zttp>=0.0.34 and enable it with --http zttp --http2.

Added

  • Add HTTP/2 response trailers through the ASGI http.response.trailers extension. Clients must send TE: trailers to receive them (#3146)
  • Add HTTP/2 103 Early Hints through the ASGI http.response.early_hint extension (#3137)

0.53.0 (September 14, 2026)

This release adds experimental HTTP/2 support through zttp. Enable it with --http zttp --http2. Upgrade-based h2c and WebSockets over HTTP/2 are not supported.

Added

  • Add experimental HTTP/2 support through zttp (#2982, #3101)
  • Add support for zuvloop (#3104)

Fixed

  • Handle comma-separated, case-insensitive Connection: close tokens across HTTP implementations (#3103)
  • Trust IPv6 loopback in the default FORWARDED_ALLOW_IPS value (#3119)
  • Cancel the HTTP keep-alive timer when upgrading to WebSocket (#3107)
Commits

Updates ty from 0.0.74 to 0.0.84

Release notes

Sourced from ty's releases.

0.0.84

Release Notes

Released on 2026-09-24.

This release addresses GHSA-vxvm-j4xq-q7m4, a use-after-free vulnerability during incremental type checking that can result in arbitrary code execution when analyzing a specially crafted Python project. Users who run ty on untrusted code should upgrade to 0.0.84 or newer.

Bug fixes

  • Fix stale diagnostics from the LSP server after toggling showSyntaxErrors (#28759)

LSP server

  • Complete string keys from dictionary initializers (#28820)
  • Support LSP requests against closed documents (#28595)
  • Select projects for external files using import search paths (#28594)
  • Use workspace editor settings for external files (#28639)

Performance

  • Avoid repeated subtyping checks for materialized recursive protocols (#28774)
  • Skip reading notebooks when discovering scripts (#28781)

Core type checking

  • Avoid incorrect simplification of TypeIs materializations (#28817)
  • Fix disjointness of generic class types (#28787)
  • Fix staticmethod shadowing through generic receivers and unions (#28766)
  • Infer callable signatures from bounded type variables (#28599)
  • Infer constant membership in inline list and set literals (e.g. "foo" in ["foo"] is now inferred as Literal[True]) (#28676)
  • Infer through optional generic containers in the legacy solver (#28791)
  • Preserve call narrowing during cyclic inference (#28708)
  • Preserve intersections of type guard return types (#28796)
  • Use subtyping for constraint-set implication (#28657)

Configuration

  • Disable invalid-legacy-positional-parameter by default (#28834)

Other changes

  • Only consider reachable definitions when determining whether a condition should be exempted from redundant-condition(-strict) due to the condition being defined relative to sys.version_info, sys.platform, os.name or typing.TYPE_CHECKING (#28788)

Contributors

... (truncated)

Changelog

Sourced from ty's changelog.

0.0.84

Released on 2026-09-24.

This release addresses GHSA-vxvm-j4xq-q7m4, a use-after-free vulnerability during incremental type checking that can result in arbitrary code execution when analyzing a specially crafted Python project. Users who run ty on untrusted code should upgrade to 0.0.84 or newer.

Bug fixes

  • Fix stale diagnostics from the LSP server after toggling showSyntaxErrors (#28759)

LSP server

  • Complete string keys from dictionary initializers (#28820)
  • Support LSP requests against closed documents (#28595)
  • Select projects for external files using import search paths (#28594)
  • Use workspace editor settings for external files (#28639)

Performance

  • Avoid repeated subtyping checks for materialized recursive protocols (#28774)
  • Skip reading notebooks when discovering scripts (#28781)

Core type checking

  • Avoid incorrect simplification of TypeIs materializations (#28817)
  • Fix disjointness of generic class types (#28787)
  • Fix staticmethod shadowing through generic receivers and unions (#28766)
  • Infer callable signatures from bounded type variables (#28599)
  • Infer constant membership in inline list and set literals (e.g. "foo" in ["foo"] is now inferred as Literal[True]) (#28676)
  • Infer through optional generic containers in the legacy solver (#28791)
  • Preserve call narrowing during cyclic inference (#28708)
  • Preserve intersections of type guard return types (#28796)
  • Use subtyping for constraint-set implication (#28657)

Configuration

  • Disable invalid-legacy-positional-parameter by default (#28834)

Other changes

  • Only consider reachable definitions when determining whether a condition should be exempted from redundant-condition(-strict) due to the condition being defined relative to sys.version_info, sys.platform, os.name or typing.TYPE_CHECKING (#28788)

Contributors

... (truncated)

Commits

Updates prek from 0.4.14 to 0.5.4

Release notes

Sourced from prek's releases.

0.5.4

Release Notes

Released on 2026-09-28.

Highlights

Faster builtin hooks

In our end-to-end benchmark, prek is about 38% faster than 0.5.3, with some builtin hooks up to 273% faster (check-yaml: 273%, check-json: 80%, check-merge-conflict: 71%).

Enhancements

  • Add include_deleted to allow hooks to include deleted files (#2733)
  • Add --check and simplify end-of-file-fixer (#2764)
  • Add --check to file-contents-sorter (#2765)
  • Add --check to requirements-txt-fixer (#2766)
  • Add --check to trailing-whitespace (#2763)
  • Expose and document prek util generate-shell-completion (#2727)
  • Support hide_status in project and user configuration (#2760)
  • Support look-around regex in builtin pattern hooks (#2732)

Performance

  • Cache the resolved Git executable on macOS (#2726)
  • Combine and cache Git repository path queries (#2724)
  • Optimize common builtin hook execution (#2768)
  • Optimize scanning in mixed-line-ending and trailing-whitespace (#2769)
  • Scan check-merge-conflict files in fixed-size blocks (#2781)
  • Use SIMD UTF-8 validation in check-json, check-toml, and check-yaml (#2770)

Bug fixes

  • Retry transient rename failures on Windows (#2756)
  • Use PATH to resolve prek in completion scripts (#2719)

Documentation

  • Clarify the flow and scope of usage guides (#2710)
  • Reorganize usage guides and reference documentation (#2709)

Other changes

  • Sync latest identify tags (#2762)

Contributors

... (truncated)

Changelog

Sourced from prek's changelog.

0.5.4

Released on 2026-09-28.

Highlights

Faster builtin hooks

In our end-to-end benchmark, prek is about 38% faster than 0.5.3, with some builtin hooks up to 273% faster (check-yaml: 273%, check-json: 80%, check-merge-conflict: 71%).

Enhancements

  • Add include_deleted to allow hooks to include deleted files (#2733)
  • Add --check and simplify end-of-file-fixer (#2764)
  • Add --check to file-contents-sorter (#2765)
  • Add --check to requirements-txt-fixer (#2766)
  • Add --check to trailing-whitespace (#2763)
  • Expose and document prek util generate-shell-completion (#2727)
  • Support hide_status in project and user configuration (#2760)
  • Support look-around regex in builtin pattern hooks (#2732)

Performance

  • Cache the resolved Git executable on macOS (#2726)
  • Combine and cache Git repository path queries (#2724)
  • Optimize common builtin hook execution (#2768)
  • Optimize scanning in mixed-line-ending and trailing-whitespace (#2769)
  • Scan check-merge-conflict files in fixed-size blocks (#2781)
  • Use SIMD UTF-8 validation in check-json, check-toml, and check-yaml (#2770)

Bug fixes

  • Retry transient rename failures on Windows (#2756)
  • Use PATH to resolve prek in completion scripts (#2719)

Documentation

  • Clarify the flow and scope of usage guides (#2710)
  • Reorganize usage guides and reference documentation (#2709)

Other changes

  • Sync latest identify tags (#2762)

Contributors

... (truncated)

Commits

Updates zizmor from 1.29.0 to 1.30.1

Release notes

Sourced from zizmor's releases.

v1.30.1

Sponsorship is appreciated!

Bug Fixes 🐛🔗

  • Fixed a bug where zizmor would crash on pre-commit inputs that reference a GitHub URL with an explicit .git suffix (#2363)

  • Fixed a bug where self-repository auto-fixes were incorrectly marked as "safe" instead of "unsafe" (#2373)

v1.30.0

Sponsorship is appreciated!

New Features 🌈🔗

Bug Fixes 🐛🔗

... (truncated)

Changelog

Sourced from zizmor's changelog.

1.30.1

Bug Fixes 🐛

  • Fixed a bug where zizmor would crash on pre-commit inputs that reference a GitHub URL with an explicit .git suffix (#2363)

  • Fixed a bug where [self-repository] auto-fixes were incorrectly marked as "safe" instead of "unsafe" (#2373)

1.30.0

New Features 🌈

  • New audit: [self-repository] detects usages of the old "workspace-relative" form for local reusable workflows and actions and recommends the new "self-repository" form instead (#2271)

Enhancements 🌱

  • The [impostor-commit] audit now supports pre-commit config inputs (#2256)

  • The [forbidden-uses] audit now supports pre-commit config inputs (#2263)

  • The [adhoc-packages] audit now detects more ad-hoc package management patterns, including bundle add and yarn add

    Many thanks to @​connorshea for proposing and implementing this enhancement!

  • The [archived-uses] audit now supports pre-commit config inputs (#2272)

  • The [ref-confusion] audit now supports pre-commit config inputs (#2274)

  • The [cache-poisoning] audit now produces more detailed and more precise diagnostics (#2330)

  • The [cache-poisoning] audit now handles and exposes auto-fixes in a more general manner (#2332)

  • zizmor now recognizes @​sethvargo/ratchet version comments when evaluating ref pinning (#2319)

    Many thanks to @​njgudman for proposing and implementing this enhancement!

  • The [unpinned-tools] audit now produces more detailed and more precise diagnostics (#2339)

  • The [unpinned-tools] audit now detects usages of @​extractions/setup-just (#2339)

  • The [unpinned-tools] audit now detects usages of @​extractions/setup-crate (#2340)

  • The [archived-uses] audit now detects several more archived repositories (#2340)

  • The [ref-version-mismatch] audit now supports #!yaml uses: that reference

... (truncated)

Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels Oct 1, 2026
@latest-changes latest-changes Bot added the internal Internal changes label Oct 1, 2026
@dependabot dependabot Bot changed the title ⬆ Bump the python-packages group with 5 updates ⬆ Bump the python-packages group across 1 directory with 5 updates Oct 5, 2026
@dependabot
dependabot Bot force-pushed the dependabot/uv/python-packages-128ae6e5a4 branch from 7f7c027 to f5cafe3 Compare October 5, 2026 15:08
Bumps the python-packages group with 5 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [ruff](https://github.com/astral-sh/ruff) | `0.16.4` | `0.16.9` |
| [uvicorn](https://github.com/Kludex/uvicorn) | `0.52.4` | `0.54.0` |
| [ty](https://github.com/astral-sh/ty) | `0.0.74` | `0.0.84` |
| [prek](https://github.com/j178/prek) | `0.4.14` | `0.5.4` |
| [zizmor](https://github.com/zizmorcore/zizmor) | `1.29.0` | `1.30.1` |



Updates `ruff` from 0.16.4 to 0.16.9
- [Release notes](https://github.com/astral-sh/ruff/releases)
- [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md)
- [Commits](astral-sh/ruff@0.16.4...0.16.9)

Updates `uvicorn` from 0.52.4 to 0.54.0
- [Release notes](https://github.com/Kludex/uvicorn/releases)
- [Changelog](https://github.com/Kludex/uvicorn/blob/main/docs/release-notes.md)
- [Commits](Kludex/uvicorn@0.52.4...0.54.0)

Updates `ty` from 0.0.74 to 0.0.84
- [Release notes](https://github.com/astral-sh/ty/releases)
- [Changelog](https://github.com/astral-sh/ty/blob/main/CHANGELOG.md)
- [Commits](astral-sh/ty@0.0.74...0.0.84)

Updates `prek` from 0.4.14 to 0.5.4
- [Release notes](https://github.com/j178/prek/releases)
- [Changelog](https://github.com/j178/prek/blob/master/CHANGELOG.md)
- [Commits](j178/prek@v0.4.14...v0.5.4)

Updates `zizmor` from 1.29.0 to 1.30.1
- [Release notes](https://github.com/zizmorcore/zizmor/releases)
- [Changelog](https://github.com/zizmorcore/zizmor/blob/main/docs/release-notes.md)
- [Commits](zizmorcore/zizmor@v1.29.0...v1.30.1)

---
updated-dependencies:
- dependency-name: prek
  dependency-version: 0.5.3
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: python-packages
- dependency-name: ruff
  dependency-version: 0.16.8
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: python-packages
- dependency-name: ty
  dependency-version: 0.0.83
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: python-packages
- dependency-name: uvicorn
  dependency-version: 0.53.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: python-packages
- dependency-name: zizmor
  dependency-version: 1.30.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: python-packages
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/uv/python-packages-128ae6e5a4 branch from f5cafe3 to d1432cc Compare October 5, 2026 15:15
uv.lock
- name: Bump pre-commit hooks
run: uv run prek auto-update --freeze --cooldown-days 7
run: uv run prek update --freeze --cooldown-days 7

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

prek auto-update was removed in prek 0.5.0 in favor of prek update.

See https://github.com/j178/prek/releases#release-v0.5.0

@YuriiMotov
YuriiMotov merged commit 251b9a8 into main Oct 5, 2026
24 checks passed
@YuriiMotov
YuriiMotov deleted the dependabot/uv/python-packages-128ae6e5a4 branch October 5, 2026 15:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file internal Internal changes python:uv Pull requests that update python:uv code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants