build(deps): bump setuptools from 80.10.1 to 83.0.0 - #347
Conversation
Bumps [setuptools](https://github.com/pypa/setuptools) from 80.10.1 to 83.0.0. - [Release notes](https://github.com/pypa/setuptools/releases) - [Changelog](https://github.com/pypa/setuptools/blob/main/NEWS.rst) - [Commits](pypa/setuptools@v80.10.1...v83.0.0) --- updated-dependencies: - dependency-name: setuptools dependency-version: 83.0.0 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com>
setuptools 82.0.0 removed the bundled `pkg_resources`, and coverage-badge imports it at module scope, so the "Generate Coverage Badge" step dies with ModuleNotFoundError as soon as setuptools is bumped past 81. That is what fails dependabot's setuptools 83.0.0 PR (#347), which we want: GHSA-h35f-9h28-mq5c is only fixed in 83.0.0, so there is no version of setuptools that is both patched and compatible with coverage-badge. coverage-badge cannot be waited on — its last release is 1.1.2 from August 2024 and the upstream reports (dbrgn/coverage-badge#33, #35) are open and untouched. genbadge reads the same coverage.xml, emits the same shields-style SVG, and was last released in November 2025. Verified locally with setuptools 83.0.0 installed: badge generation, coverage-plot, `ty check ttc` and all 69 tests pass.
* ci: generate the coverage badge with genbadge setuptools 82.0.0 removed the bundled `pkg_resources`, and coverage-badge imports it at module scope, so the "Generate Coverage Badge" step dies with ModuleNotFoundError as soon as setuptools is bumped past 81. That is what fails dependabot's setuptools 83.0.0 PR (#347), which we want: GHSA-h35f-9h28-mq5c is only fixed in 83.0.0, so there is no version of setuptools that is both patched and compatible with coverage-badge. coverage-badge cannot be waited on — its last release is 1.1.2 from August 2024 and the upstream reports (dbrgn/coverage-badge#33, #35) are open and untouched. genbadge reads the same coverage.xml, emits the same shields-style SVG, and was last released in November 2025. Verified locally with setuptools 83.0.0 installed: badge generation, coverage-plot, `ty check ttc` and all 69 tests pass. * chore: update coverage assets
|
Superseded by #358, which lands the same setuptools 80.10.1 → 83.0.0 bump in This PR could not pass on its own: setuptools removed the bundled |
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
Bumps setuptools from 80.10.1 to 83.0.0.
Changelog
Sourced from setuptools's changelog.
... (truncated)
Commits
6519f72Bump version: 82.0.1 → 83.0.0d1151b1Merge pull request #5250 from pypa/feature/distutils-d7633fbeda2df31eCapture removal of dry_run parameter in changelog.00144dcMoved newsfragment to the release where it occurred.a4a5a2bAdd news fragment.77470c2Merge https://github.com/pypa/distutils into feature/distutils-d7633fbed3c43897Merge pull request #5247 from pypa/copilot/fix-pypy-version-issuebb6ea66Bump PyPy from 3.10 to 3.11 in CI workflowa2bc3acFix broken intersphinx reference to build's installation docs2d6a739Use stacked parametrize decorators instead of itertools.productDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.