Skip to content

build(deps): bump the linters group across 1 directory with 5 updates - #695

Merged
jodal merged 1 commit into
mainfrom
dependabot/uv/linters-d2af90f67c
Sep 4, 2026
Merged

jodal merged 1 commit into
mainfrom
dependabot/uv/linters-d2af90f67c

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 1, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the linters group with 5 updates in the / directory:

Package From To
django-stubs-ext 6.0.7 6.1.0
tox 4.58.0 4.60.1
ruff 0.16.0 0.16.5
basedpyright 1.39.9 1.39.10
zizmor 1.28.0 1.29.0

Updates django-stubs-ext from 6.0.7 to 6.1.0

Commits

Updates tox from 4.58.0 to 4.60.1

Release notes

Sourced from tox's releases.

v4.60.1

What's Changed

New Contributors

Full Changelog: tox-dev/tox@4.60.0...4.60.1

v4.60.0

What's Changed

New Contributors

Full Changelog: tox-dev/tox@4.59.0...4.60.0

v4.59.0

What's Changed

... (truncated)

Changelog

Sourced from tox's changelog.

Bug fixes - 4.60.1

  • Report a malformed tox.ini or setup.cfg as a handled error during config discovery instead of raising an unhandled :class:configparser.Error traceback - by :user:VXNCXNX (:issue:4027)
  • Report an invalid value in the ini [tox] core section (such as min_version, requires or env_list) as a handled error instead of an unhandled traceback, matching the existing TOML loader behavior - by :user:VXNCXNX (:issue:4028)
  • Report an invalid --skip-env/TOX_SKIP_ENV regular expression as a handled error instead of raising an unhandled re.error traceback - by :user:VXNCXNX (:issue:4029)
  • Keep ; inside values read from a set_env environment file (file|.env). Environment file lines are plain KEY=VALUE pairs and were incorrectly parsed with the PEP-508 marker splitter, which truncated values such as DATABASE_URL=postgresql://host/db?opt=1;sslmode=require at the first semicolon - by :user:VXNCXNX (:issue:4030)
  • Report a handled configuration error instead of leaking a traceback when the selected configuration file exists but cannot be read - by :user:SirHegel. (:issue:4031)
  • Report an empty install_command or list_dependencies_command in a TOML configuration as a handled error instead of an unhandled traceback - by :user:dylanpulver (:issue:4041)

Contributor-facing changes - 4.60.1

  • Pre-seed the setuptools wheel image alongside pip before the test session and give integration tests a 240s budget on Windows, so pytest-timeout no longer kills Windows CI workers - by :user:gaborbernat. (:issue:4026)

v4.60.0 (2026-08-13)


Features - 4.60.0

  • Add {home} and {tox_root_name} substitutions; set :ref:work_dir to e.g. "{home}/.local/state/tox/{tox_root_name}" to keep environments outside of the project tree - by :user:WhyNotHugo. (:issue:4020)

Bug fixes - 4.60.0

  • Provision the requested tox version before reading env_list, allowing configuration syntax introduced by that version - by :user:CAOShurong (:issue:4021)

Improved documentation - 4.60.0

  • Fix nine source-code links in the onboarding guide that pointed at paths which no longer exist, and correct the class names of the TOML configuration sources and loaders they refer to - by :user:Yusuf-Gadelrab. (:issue:4024)

v4.59.0 (2026-08-10)

... (truncated)

Commits
  • e91ca3b release 4.60.1
  • 59e984f Report an empty TOML command value as a handled error (#4041)
  • fcb513e [pre-commit.ci] pre-commit autoupdate (#4040)
  • e753137 Report a bad ini core value as a handled error (#4028)
  • 79a45b4 🔧 chore: batch dependency updates weekly on Tuesday (#4038)
  • e388aeb 🔧 chore: drop the now-unused ty ignore directive (#4039)
  • 76baa0a docs: drop the claim that tox -e py skips tests with missing dependencies (#4...
  • 0250664 build(deps): bump astral-sh/setup-uv from 10.0.0 to 10.0.1 (#4037)
  • 8527c61 fix: report an invalid --skip-env regex as a handled error (#4029)
  • fb859dc fix: a semicolon truncates a value read from a set_env file (#4030)
  • Additional commits viewable in compare view

Updates ruff from 0.16.0 to 0.16.5

Release notes

Sourced from ruff's releases.

0.16.5

Release Notes

Released on 2026-08-27.

Preview features

  • Allow rules without codes (#28049)
  • Introduce category selectors (#27666)
  • Update preview default rules and categories (#27877)

Bug fixes

  • [flake8-async] Detect blocking generic HTTP requests (ASYNC210) (#28024)
  • [flake8-datetimez] Allow timezone-safe strptime chains (DTZ007) (#28023)
  • [flake8-simplify] Respect side effects in lambda defaults (SIM401) (#28000)

Server

  • Fix duplicated "of" in ClientOptions doc comment (#27978)

Documentation

  • Document rule acceptance guidelines (#27910)
  • Document the new category selectors (#27906)

Contributors

Install ruff 0.16.5

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/ruff/releases/download/0.16.5/ruff-installer.sh | sh

Install prebuilt binaries via powershell script

powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/ruff/releases/download/0.16.5/ruff-installer.ps1 | iex"

Download ruff 0.16.5

... (truncated)

Changelog

Sourced from ruff's changelog.

0.16.5

Released on 2026-08-27.

Preview features

  • Allow rules without codes (#28049)
  • Introduce category selectors (#27666)
  • Update preview default rules and categories (#27877)

Bug fixes

  • [flake8-async] Detect blocking generic HTTP requests (ASYNC210) (#28024)
  • [flake8-datetimez] Allow timezone-safe strptime chains (DTZ007) (#28023)
  • [flake8-simplify] Respect side effects in lambda defaults (SIM401) (#28000)

Server

  • Fix duplicated "of" in ClientOptions doc comment (#27978)

Documentation

  • Document rule acceptance guidelines (#27910)
  • Document the new category selectors (#27906)

Contributors

0.16.4

Released on 2026-08-20.

Preview features

  • [flake8-use-pathlib] Add autofix for PTH116 (#26460)
  • [refurb] Restrict delete-full-slice to lists (FURB131) (#27711)
  • [refurb] Skip FURB101 and FURB103 when the open argument is a file descriptor (#27643)

Bug fixes

  • Fix InvalidInstruction on Windows CPUs that do not support POPCNT (#27803)
  • [pyflakes] Emit semantic syntax errors in string type definitions as F722 (#27835)
  • [pylint] Allow os._exit imports in import-private-name (PLC2701) (#27738)

... (truncated)

Commits

Updates basedpyright from 1.39.9 to 1.39.10

Release notes

Sourced from basedpyright's releases.

v1.39.10 (pyright 1.1.412)

What's Changed

New Contributors

Full Changelog: DetachHead/basedpyright@v1.39.9...v1.39.10

Commits
  • 6d830ba 1.39.10
  • a34496c fix redundant workspace/configuration request
  • b3074fe fix links in tsp docs
  • 979a3fc add nodejs-wheel back as a dev dependency
  • 2852250 ignore mypy_primer/build in bpr
  • 5c4427f baseline type errors from new upstream python file
  • ae420b5 try to fix primer
  • 0e5c88e fixes from merge
  • 78adf4f don't support TSP
  • eff463d Merge tag '1.1.412' into merge-1.1.412
  • Additional commits viewable in compare view

Updates zizmor from 1.28.0 to 1.29.0

Release notes

Sourced from zizmor's releases.

v1.29.0

New Features 🌈🔗

  • zizmor now has experimental support for auditing pre-commit inputs, meaning both pre-commit configuration and hook definitions (#2209)

  • New audit: insecure-url-scheme detects usages of insecure (i.e. plaintext) protocols when making network requests. The initial version of this audit is limited to pre-commit inputs only (#2228)

  • zizmor now supports GitHub's "self-repository" reference syntax for local actions, e.g. uses: $/foo/bar instead of a manual checkout and uses: ./foo/bar (#2248)

Changes ⚠️🔗

Removals 🌅🔗

  • --collect=workflows-only and --collect=actions-only have been fully removed. Use --collect=workflows and --collect=actions for the replacement behavior (#2242)

Bug Fixes 🐛🔗

  • Fixed a bug where zizmor would reject a valid workflow definition for containing a literal jobs..outputs. value for being a non-string (#2220)

  • Fixed a bug where the github-app audit would incorrectly flag some usages as needing a repositories: key, despite requesting organization-level-only permissions (#2227)

  • Fixed a class of bugs where zizmor would discover the user's configuration in unintuitive ways. When auditing from a Git repository, zizmor now uses the repository root to discover configuration consistently (#2234)

Changelog

Sourced from zizmor's changelog.

1.29.0

New Features 🌈

  • zizmor now has experimental support for auditing pre-commit inputs, meaning both pre-commit configuration and hook definitions (#2209)

  • New audit: [insecure-url-scheme] detects usages of insecure (i.e. plaintext) protocols when making network requests. The initial version of this audit is limited to pre-commit inputs only (#2228)

  • zizmor now supports GitHub's "self-repository" reference syntax for local actions, e.g. #!yaml uses: $/foo/bar instead of a manual checkout and #!yaml uses: ./foo/bar (#2248)

Changes ⚠️

  • The [unpinned-uses] and [unpinned-images] audits have been separated more cleanly: [unpinned-uses] is now principally responsible for Git-style #!yaml uses: clauses, whereas [unpinned-images] is now responsible for docker://-style #!yaml uses: clauses (in addition to already checking other image references) (#2222)

Removals 🌅

  • --collect=workflows-only and --collect=actions-only have been fully removed. Use --collect=workflows and --collect=actions for the replacement behavior (#2242)

Bug Fixes 🐛

  • Fixed a bug where zizmor would reject a valid workflow definition for containing a literal jobs.<job>.outputs.<name> value for being a non-string (#2220)

  • Fixed a bug where the [github-app] audit would incorrectly flag some usages as needing a #!yaml repositories: key, despite requesting organization-level-only permissions (#2227)

  • Fixed a class of bugs where zizmor would discover the user's configuration in unintuitive ways. When auditing from a Git repository, zizmor now uses the repository root to discover configuration consistently (#2234)

Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels Sep 1, 2026
@codecov

codecov Bot commented Sep 1, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 68.97%. Comparing base (28a3c83) to head (21200aa).
⚠️ Report is 2 commits behind head on main.

Additional details and impacted files
@@           Coverage Diff           @@
##             main     #695   +/-   ##
=======================================
  Coverage   68.97%   68.97%           
=======================================
  Files          46       46           
  Lines        2069     2069           
=======================================
  Hits         1427     1427           
  Misses        642      642           

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@dependabot dependabot Bot changed the title build(deps): bump the linters group with 5 updates build(deps): bump the linters group across 1 directory with 5 updates Sep 4, 2026
@dependabot
dependabot Bot force-pushed the dependabot/uv/linters-d2af90f67c branch 2 times, most recently from 06b13f6 to 74eb58d Compare September 4, 2026 10:24
Bumps the linters group with 5 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [django-stubs-ext](https://github.com/typeddjango/django-stubs) | `6.0.7` | `6.1.0` |
| [tox](https://github.com/tox-dev/tox) | `4.58.0` | `4.60.1` |
| [ruff](https://github.com/astral-sh/ruff) | `0.16.0` | `0.16.5` |
| [basedpyright](https://github.com/detachhead/basedpyright) | `1.39.9` | `1.39.10` |
| [zizmor](https://github.com/zizmorcore/zizmor) | `1.28.0` | `1.29.0` |



Updates `django-stubs-ext` from 6.0.7 to 6.1.0
- [Release notes](https://github.com/typeddjango/django-stubs/releases)
- [Commits](typeddjango/django-stubs@6.0.7...6.1.0)

Updates `tox` from 4.58.0 to 4.60.1
- [Release notes](https://github.com/tox-dev/tox/releases)
- [Changelog](https://github.com/tox-dev/tox/blob/main/docs/changelog.rst)
- [Commits](tox-dev/tox@4.58.0...4.60.1)

Updates `ruff` from 0.16.0 to 0.16.5
- [Release notes](https://github.com/astral-sh/ruff/releases)
- [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md)
- [Commits](astral-sh/ruff@0.16.0...0.16.5)

Updates `basedpyright` from 1.39.9 to 1.39.10
- [Release notes](https://github.com/detachhead/basedpyright/releases)
- [Commits](DetachHead/basedpyright@v1.39.9...v1.39.10)

Updates `zizmor` from 1.28.0 to 1.29.0
- [Release notes](https://github.com/zizmorcore/zizmor/releases)
- [Changelog](https://github.com/zizmorcore/zizmor/blob/main/docs/release-notes.md)
- [Commits](zizmorcore/zizmor@v1.28.0...v1.29.0)

---
updated-dependencies:
- dependency-name: basedpyright
  dependency-version: 1.39.10
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: linters
- dependency-name: django-stubs-ext
  dependency-version: 6.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: linters
- dependency-name: ruff
  dependency-version: 0.16.4
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: linters
- dependency-name: tox
  dependency-version: 4.60.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: linters
- dependency-name: zizmor
  dependency-version: 1.29.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: linters
...

Signed-off-by: dependabot[bot] <support@github.com>
@jodal
jodal force-pushed the dependabot/uv/linters-d2af90f67c branch from 74eb58d to 21200aa Compare September 4, 2026 10:28
@jodal
jodal merged commit 81b4208 into main Sep 4, 2026
8 checks passed
@jodal
jodal deleted the dependabot/uv/linters-d2af90f67c branch September 4, 2026 10:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant