Skip to content

Bump the python group across 1 directory with 5 updates - #2

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/python-9fa0edc639
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/python-9fa0edc639

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 27, 2026 •

Copy link
Copy Markdown

Bumps the python group with 5 updates in the / directory:

Package From To
cyclopts 4.25.2 5.0.0
platformdirs 4.11.8 4.12.1
hypothesis 6.168.0 6.168.3
ruff 0.16.7 0.16.9
ty 0.0.80 0.0.84

Updates cyclopts from 4.25.2 to 5.0.0

Release notes

Sourced from cyclopts's releases.

v5.0.0

Check out the new "Migrating to v5" docs page, covering each intentional breaking change with before/after examples.

All v4 features up to 4.25.3 have been merged into this release.

Breaking

  • Dropped Python 3.10 support (Python 3.10 EoL is Oct 31, 2026) BrianPugh/cyclopts#889

  • Removed fuzzy command-matching. Command names must match exactly.

    • It was a temporary v4 backwards-compat shim (#666) for the PascalCase → pascal-case name-transform change, retrying by stripping dashes/underscores on no exact match. Removed as cleanup for the major release.
    @app.command
    def MyCommand(): ...   # registers as "my-command"
    # v4: `mycommand` fuzzy-matched -> my-command
    # v5: `mycommand` no longer resolves; use `my-command`
  • Fallthrough parsing: child wins. Previously a meta app claimed any keyword parameter it recognized regardless of token position — even after a subcommand, and even if the subcommand defined the same name. In v5 (default parse_mode="fallthrough"), when both levels define the same name, the subcommand wins for tokens placed after it.

    @app.meta.default
    def main(
        *tokens: Annotated[str, Parameter(show=False, allow_leading_hyphen=True)],
        verbose: Annotated[bool, Parameter(alias="-v")] = False,
    ):
        app(tokens)
    @​app.command
    def greet(name: str, *, version: Annotated[bool, Parameter(alias="-v")] = False):
    ...

    $ myapp greet -v Alice          # after the subcommand: CHANGED
    # v4: meta verbose=True;  greet version=False
    # v5: meta verbose=False; greet version=True   (child wins)
    

    $ myapp -v greet Alice # before the subcommand: unchanged

    v4: meta verbose=True; greet version=False

    v5: meta verbose=True; greet version=False

    Only placement after the subcommand changed. To reject parent-level parameters placed after a subcommand entirely, use parse_mode="strict".

  • Forwarded *tokens preserve the -- delimiter. A forwarding meta's raw-stream capture parameter (*tokens with allow_leading_hyphen=True) now keeps a user-typed end-of-options delimiter, so the re-parse inside app(tokens) still treats the trailing tokens as positional.

    $ myapp sub -- -x

... (truncated)

Commits
  • ad0e968 chore(deps): bump rich-rst from 2.0.1 to 2.1.0
  • d1c8962 chore(deps): bump docstring-parser from 0.17.0 to 0.18.0
  • b1b1511 chore(deps): bump sphinx-rtd-theme from 3.0.2 to 3.1.0
  • deda088 chore(deps): bump pymdown-extensions from 11.0.2 to 12.0.1
  • 8acc353 chore(deps): update myst-parser[linkify] requirement
  • 5bddc53 chore: bump lockfile deps to clear dependabot security alerts
  • c3435cc Merge pull request #959 from BrianPugh/v5-develop
  • 1ff9947 Merge branch 'main' into v5-develop
  • 83213cc Merge pull request #956 from BrianPugh/fix-set-unhashable-element-diagnostic
  • 38f420c test: cover frozenset in the unhashable-element diagnostic test
  • Additional commits viewable in compare view

Updates platformdirs from 4.11.8 to 4.12.1

Release notes

Sourced from platformdirs's releases.

4.12.1

What's Changed

Full Changelog: tox-dev/platformdirs@4.12.0...4.12.1

4.12.0

What's Changed

Full Changelog: tox-dev/platformdirs@4.11.15...4.12.0

4.11.15

What's Changed

Full Changelog: tox-dev/platformdirs@4.11.14...4.11.15

4.11.14

What's Changed

... (truncated)

Changelog

Sourced from platformdirs's changelog.

########### Changelog ###########

.. towncrier-draft-entries:: Unreleased

.. towncrier release notes start


4.12.2 (2026-09-29)


  • Keep os.pathsep in site_applications_path under multipath=True on platforms with one applications directory. :pr:604

4.12.1 (2026-09-28)


  • Avoid PytestAssertRewriteWarning when importing platformdirs before invoking pytest. :pr:601

4.12.0 (2026-09-26)


  • Add place_*_file methods that return a file path under a user directory and create its missing parents with mode 0o700. :pr:585
  • Add find_<kind>_file and find_<kind>_files to look up an existing file across the user and site directories of each kind that has an iter_<kind>_paths method. :pr:586
  • Add :func:platformdirs.testing.isolated_dirs and the platformdirs_isolated pytest fixture to resolve every directory under one test root. :pr:590
  • Emit :class:~platformdirs.RuntimeDirWarning when the Unix :func:~platformdirs.user_runtime_dir falls back from XDG_RUNTIME_DIR. :pr:599
  • Read user_templates_dir, user_publicshare_dir and user_bin_dir on Windows from their known folders. :pr:587
  • Create missing user app directories and their parents with mode 0700 under ensure_exists on POSIX platforms. :pr:588
  • Raise RuntimeError for a Unix or macOS directory under the home when no home resolves, and read the password database for an empty HOME. :pr:589
  • Skip an XDG_RUNTIME_DIR or /run/user/<uid> that is not a private directory of the user, and reject a symlink or file as the runtime-<uid> fallback. :pr:599
  • Use the app container layout on iOS, such as ~/Library/Application Support for data. :pr:600
  • Document that a Homebrew Python puts the Homebrew prefix first in the macOS shared directories, with or without multipath. :pr:591
  • Document that the macOS media directories honor the XDG_*_DIR variables. :pr:592
  • Document the WIN_PD_OVERRIDE_COMMON_PROGRAMS variable. :pr:593
  • Document /usr/local/share/applications as the Linux site_applications_dir default. :pr:594
  • Correct the BSD user_runtime_dir defaults and describe the temporary directory fallback. :pr:595
  • Describe how platformdirs detects Android, finds the app folder and places the shared folders. :pr:596
  • Document that Microsoft Store Python redirects only new files and folders under AppData. :pr:597

... (truncated)

Commits
  • 0a50795 Release 4.12.1
  • 72e93ff fix(pytest): allow import before pytest startup (#602)
  • ea7be87 Release 4.12.0
  • de46f51 🐛 fix(unix): validate XDG_RUNTIME_DIR and warn on fallback (#599)
  • ca2b313 🐛 fix(dirs): raise when no home directory resolves (#589)
  • c34e758 🐛 fix(dirs): create user directories with mode 0700 (#588)
  • f88693c ✨ feat(api): add find_*_file methods for user and site lookup (#586)
  • ba1cc1e 🐛 fix(windows): resolve templates, public and bin dirs by known folder (#587)
  • 9f2ee08 ✨ feat(testing): redirect every directory under a test root (#590)
  • dfaeabf ✨ feat(api): add place_*_file methods that create parents as 0700 (#585)
  • Additional commits viewable in compare view

Updates hypothesis from 6.168.0 to 6.168.3

Commits
  • 44b82b2 Bump hypothesis version to 6.168.3 and update changelog
  • aeaafb5 Merge pull request #4888 from gpacix/fix-quadratic-statistics
  • f3f4a29 wording, remove hardcoded test
  • 7fabb94 Add RELEASE.rst and AUTHORS.rst changes
  • 0ab4e38 Summarize statistics events in linear time
  • 32ebeb2 Bump hypothesis version to 6.168.2 and update changelog
  • ff7e800 Merge pull request #4886 from pschanely/atomic-constants-cache
  • e57fd12 Isolate the constants cache test from existing cache files
  • c8981a0 Write the local constants cache atomically
  • 9c55f97 Merge pull request #4877 from HypothesisWorks/create-pull-request/patch
  • Additional commits viewable in compare view

Updates ruff from 0.16.7 to 0.16.9

Release notes

Sourced from ruff's releases.

0.16.9

Release Notes

Released on 2026-09-24.

Preview features

  • [ruff] Avoid false positives for overloaded division (RUF069) (#28309)

Bug fixes

  • [flake8-bugbear] Avoid false positives for calls with keyword arguments (B009, B010, B043) (#28776)
  • [flake8-tidy-imports] Allow lazy imports to be used in deferred annotations (TID255) (#28767)

Rule changes

  • Update LibCST-based fixes for Python 3.15 (#28616)
  • [flake8-pyi] Mention stubs in the diagnostic message (PYI002) (#28542)

Documentation

  • Fix horizontal overflow on the rules documentation page (#28699)
  • Update rules table with category information (#28651)
  • [flake8-annotations] Clarify that ANN401 checks return types in addition to arguments (#28334)
  • [flake8-bugbear] Document type-checker interaction (B010) (#28509)
  • [flake8-comprehensions] Document map/generator exception behavior (C417) (#27794)
  • [ruff] Mention related isort settings (RUF022) (#28719)

Contributors

Install ruff 0.16.9

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/ruff/releases/download/0.16.9/ruff-installer.sh | sh

... (truncated)

Changelog

Sourced from ruff's changelog.

0.16.9

Released on 2026-09-24.

Preview features

  • [ruff] Avoid false positives for overloaded division (RUF069) (#28309)

Bug fixes

  • [flake8-bugbear] Avoid false positives for calls with keyword arguments (B009, B010, B043) (#28776)
  • [flake8-tidy-imports] Allow lazy imports to be used in deferred annotations (TID255) (#28767)

Rule changes

  • Update LibCST-based fixes for Python 3.15 (#28616)
  • [flake8-pyi] Mention stubs in the diagnostic message (PYI002) (#28542)

Documentation

  • Fix horizontal overflow on the rules documentation page (#28699)
  • Update rules table with category information (#28651)
  • [flake8-annotations] Clarify that ANN401 checks return types in addition to arguments (#28334)
  • [flake8-bugbear] Document type-checker interaction (B010) (#28509)
  • [flake8-comprehensions] Document map/generator exception behavior (C417) (#27794)
  • [ruff] Mention related isort settings (RUF022) (#28719)

Contributors

0.16.8

Released on 2026-09-16.

Bug fixes

  • Visit functional TypedDict keyword arguments correctly (#28584)
  • [flake8-simplify] Detect nested async with under sync parent (SIM117) (#27821)
  • [flake8-simplify] Preserve operand order in SIM109 fix (#27824)

... (truncated)

Commits
  • 0be08a2 Bump version to 0.16.9 (#28882)
  • b4920b7 Rename ruff_cli to ruff_command_line (#28881)
  • 47c751b Update dependency astral-sh/uv to v0.12.18 (#28880)
  • 8c244e5 [flake8-comprehensions] Document map/generator exception behavior (C417...
  • 5edf5a1 Use target form in rooster.version_files (#28876)
  • 915bb2b [ty] Prefer existing @ paths over response files in Ruff and ty (#28877)
  • 4710e1a ci(github): update version number in placeholder of issue template (#28871)
  • eedfc62 [ty] Propagate outer type context through cast calls (#28855)
  • ceaa6a0 [ty] Contain rendered code within Markdown fences (#28869)
  • dba0f30 authorize ruff-pre-commit dispatch via OIDC (#28867)
  • Additional commits viewable in compare view

Updates ty from 0.0.80 to 0.0.84

Release notes

Sourced from ty's releases.

0.0.84

Release Notes

Released on 2026-09-24.

This release addresses GHSA-vxvm-j4xq-q7m4, a use-after-free vulnerability during incremental type checking that can result in arbitrary code execution when analyzing a specially crafted Python project. Users who run ty on untrusted code should upgrade to 0.0.84 or newer.

Bug fixes

  • Fix stale diagnostics from the LSP server after toggling showSyntaxErrors (#28759)

LSP server

  • Complete string keys from dictionary initializers (#28820)
  • Support LSP requests against closed documents (#28595)
  • Select projects for external files using import search paths (#28594)
  • Use workspace editor settings for external files (#28639)

Performance

  • Avoid repeated subtyping checks for materialized recursive protocols (#28774)
  • Skip reading notebooks when discovering scripts (#28781)

Core type checking

  • Avoid incorrect simplification of TypeIs materializations (#28817)
  • Fix disjointness of generic class types (#28787)
  • Fix staticmethod shadowing through generic receivers and unions (#28766)
  • Infer callable signatures from bounded type variables (#28599)
  • Infer constant membership in inline list and set literals (e.g. "foo" in ["foo"] is now inferred as Literal[True]) (#28676)
  • Infer through optional generic containers in the legacy solver (#28791)
  • Preserve call narrowing during cyclic inference (#28708)
  • Preserve intersections of type guard return types (#28796)
  • Use subtyping for constraint-set implication (#28657)

Configuration

  • Disable invalid-legacy-positional-parameter by default (#28834)

Other changes

  • Only consider reachable definitions when determining whether a condition should be exempted from redundant-condition(-strict) due to the condition being defined relative to sys.version_info, sys.platform, os.name or typing.TYPE_CHECKING (#28788)

Contributors

... (truncated)

Changelog

Sourced from ty's changelog.

0.0.84

Released on 2026-09-24.

This release addresses GHSA-vxvm-j4xq-q7m4, a use-after-free vulnerability during incremental type checking that can result in arbitrary code execution when analyzing a specially crafted Python project. Users who run ty on untrusted code should upgrade to 0.0.84 or newer.

Bug fixes

  • Fix stale diagnostics from the LSP server after toggling showSyntaxErrors (#28759)

LSP server

  • Complete string keys from dictionary initializers (#28820)
  • Support LSP requests against closed documents (#28595)
  • Select projects for external files using import search paths (#28594)
  • Use workspace editor settings for external files (#28639)

Performance

  • Avoid repeated subtyping checks for materialized recursive protocols (#28774)
  • Skip reading notebooks when discovering scripts (#28781)

Core type checking

  • Avoid incorrect simplification of TypeIs materializations (#28817)
  • Fix disjointness of generic class types (#28787)
  • Fix staticmethod shadowing through generic receivers and unions (#28766)
  • Infer callable signatures from bounded type variables (#28599)
  • Infer constant membership in inline list and set literals (e.g. "foo" in ["foo"] is now inferred as Literal[True]) (#28676)
  • Infer through optional generic containers in the legacy solver (#28791)
  • Preserve call narrowing during cyclic inference (#28708)
  • Preserve intersections of type guard return types (#28796)
  • Use subtyping for constraint-set implication (#28657)

Configuration

  • Disable invalid-legacy-positional-parameter by default (#28834)

Other changes

  • Only consider reachable definitions when determining whether a condition should be exempted from redundant-condition(-strict) due to the condition being defined relative to sys.version_info, sys.platform, os.name or typing.TYPE_CHECKING (#28788)

Contributors

... (truncated)

Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels Sep 27, 2026
@dependabot
dependabot Bot requested a review from 0ndrec as a code owner September 27, 2026 19:24
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels Sep 27, 2026
@dependabot dependabot Bot changed the title Bump the python group with 5 updates Bump the python group across 1 directory with 5 updates Sep 27, 2026
@dependabot
dependabot Bot force-pushed the dependabot/uv/python-9fa0edc639 branch 3 times, most recently from e892918 to 03fe46b Compare October 2, 2026 10:20
Bumps the python group with 5 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [cyclopts](https://github.com/BrianPugh/cyclopts) | `4.25.2` | `5.0.0` |
| [platformdirs](https://github.com/tox-dev/platformdirs) | `4.11.8` | `4.12.1` |
| [hypothesis](https://github.com/HypothesisWorks/hypothesis) | `6.168.0` | `6.168.3` |
| [ruff](https://github.com/astral-sh/ruff) | `0.16.7` | `0.16.9` |
| [ty](https://github.com/astral-sh/ty) | `0.0.80` | `0.0.84` |



Updates `cyclopts` from 4.25.2 to 5.0.0
- [Release notes](https://github.com/BrianPugh/cyclopts/releases)
- [Commits](BrianPugh/cyclopts@v4.25.2...v5.0.0)

Updates `platformdirs` from 4.11.8 to 4.12.1
- [Release notes](https://github.com/tox-dev/platformdirs/releases)
- [Changelog](https://github.com/tox-dev/platformdirs/blob/main/docs/changelog.rst)
- [Commits](tox-dev/platformdirs@4.11.8...4.12.1)

Updates `hypothesis` from 6.168.0 to 6.168.3
- [Release notes](https://github.com/HypothesisWorks/hypothesis/releases)
- [Commits](HypothesisWorks/hypothesis@v6.168.0...v6.168.3)

Updates `ruff` from 0.16.7 to 0.16.9
- [Release notes](https://github.com/astral-sh/ruff/releases)
- [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md)
- [Commits](astral-sh/ruff@0.16.7...0.16.9)

Updates `ty` from 0.0.80 to 0.0.84
- [Release notes](https://github.com/astral-sh/ty/releases)
- [Changelog](https://github.com/astral-sh/ty/blob/main/CHANGELOG.md)
- [Commits](astral-sh/ty@0.0.80...0.0.84)

---
updated-dependencies:
- dependency-name: cyclopts
  dependency-version: 5.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: python
- dependency-name: hypothesis
  dependency-version: 6.168.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: python
- dependency-name: platformdirs
  dependency-version: 4.11.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python
- dependency-name: ruff
  dependency-version: 0.16.8
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: python
- dependency-name: ty
  dependency-version: 0.0.84
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: python
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/uv/python-9fa0edc639 branch from 03fe46b to f3b61b2 Compare October 2, 2026 10:33

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants