Skip to content

Bump the python-dev-dependencies group with 5 updates - #53

Open
dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/uv/develop/python-dev-dependencies-99aef909d8
Open

dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/uv/develop/python-dev-dependencies-99aef909d8

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 3, 2026

Copy link
Copy Markdown
Contributor

Updates the requirements on coverage, ruff, pyrefly, tox and uv-build to permit the latest version.
Updates coverage to 7.16.1

Release notes

Sourced from coverage's releases.

7.16.1

Version 7.16.1 — 2026-09-13

  • Fix: when the body of an irrefutable case (like case _:) is entirely excluded, the case line is now excluded too, just as an excluded else: body removes the else: line. Previously the case line was left behind and reported as missing. Closes issue 1563 with pull 2269.
  • Fix: using CoverageData.update() twice on an in-memory database would fail, as described in issue 2279. This is now fixed.

➡️  PyPI page: coverage 7.16.1. :arrow_right:  To install: python3 -m pip install coverage==7.16.1

Changelog

Sourced from coverage's changelog.

Version 7.16.1 — 2026-09-13

  • Fix: when the body of an irrefutable case (like case _:) is entirely excluded, the case line is now excluded too, just as an excluded else: body removes the else: line. Previously the case line was left behind and reported as missing. Closes issue 1563_ with pull 2269_.

  • Fix: using :meth:.CoverageData.update twice on an in-memory database would fail, as described in issue 2279_. This is now fixed.

.. _issue 1563: coveragepy/coveragepy#1563 .. _pull 2269: coveragepy/coveragepy#2269 .. _issue 2279: coveragepy/coveragepy#2279

.. _changes_7-16-0:

Version 7.16.0 — 2026-08-28

  • When combining files, now path separator slashes will automatically be converted to the local file system style. This makes it less necessary to define [paths] configuration to combine data across operating systems. Fixes issue 2266_.

  • The :meth:.Coverage.switch_context method now returns the previous context.

  • Fix: previously, a [paths] pattern would be replaced everywhere in a file path when it was only meant to be replaced once, in the leading portion of the path. This is now fixed, in pull 2268_.

  • Fixes to validation of options and configuration settings:

    • Negative precision settings now always cause useful error messages (pull 2261_).

    • An invalid regex in the --contexts option (or the [report] contexts setting) reported a confusing "Couldn't use data file ...: user-defined function raised exception" error. Now it raises a proper configuration error naming the bad regex, like other regex settings do (pull 2262_).

    • Non-string values in TOML configuration settings now produce a helpful error message instead of a traceback. This affects list settings whose elements aren't strings (like omit, exclude_lines, or a [paths] entry), file settings like data_file, and any wrong-typed value in the [paths] section (pull 2263_).

    • coverage run refuses run-affecting command-line options like --branch alongside --concurrency=multiprocessing, since they can't

... (truncated)

Commits
  • ccbb992 docs: prep for 7.16.1
  • 0697ccc chore: make upgrade
  • 12f3595 chore: bump docker/setup-qemu-action in the action-dependencies group (#2280)
  • 35b58d3 fix: CoverageData.update() can be called twice on an in-memory database. #2279
  • 92e1ce9 chore: bump the action-dependencies group with 4 updates (#2278)
  • bf07310 build: quote var expansion (actionlint SC2086)
  • 3c434f5 quality: use shellcheck-py to get shellcheck in GitHub CI
  • 632f397 build: use .txt instead of .pip, even though it's a stupid extension
  • ffc6a4a test: only run diff-cover on pull requests
  • 33553b3 fix: exclude the case line when an irrefutable case body is excluded (#2269)
  • Additional commits viewable in compare view

Updates ruff to 0.16.8

Release notes

Sourced from ruff's releases.

0.16.8

Release Notes

Released on 2026-09-16.

Bug fixes

  • Visit functional TypedDict keyword arguments correctly (#28584)
  • [flake8-simplify] Detect nested async with under sync parent (SIM117) (#27821)
  • [flake8-simplify] Preserve operand order in SIM109 fix (#27824)
  • [pyupgrade] Preserve required parentheses in multiline UP040 fixes (#28164)
  • [pyupgrade] Skip TypeVarTuple and ParamSpec conversions with bounds or constraints (UP040, UP046, UP047) (#28505)

Rule changes

  • Add support for __lazy_modules__ (#28459)
  • Recognize PEP-728 TypedDict class keywords (#28533)
  • Recognize quoted types in typing.TypeForm (#28507)
  • Support conditional assignment to __lazy_modules__ (#28491)
  • [flake8-type-checking] Prefer lazy imports over TYPE_CHECKING on Python 3.15 and later (TC001, TC002, TC003) (#28541)
  • [pyupgrade] Make the fix for UP040 always unsafe (#28526)
  • [pyupgrade] Stop recommending deprecated ByteString aliases (UP035) (#28498)
  • [ruff, flake8-use-pathlib] Recognize the parent_mode argument (RUF064, PTH103) (#28528)
  • [ruff] Detect \Z in pytest.raises() match patterns (RUF043) (#28598)

CLI

  • Use rule name and code in formatter incompatibility warnings (#28571)

Configuration

  • [flake8-tidy-imports] Add extend-banned-api (#28644)

Contributors

Install ruff 0.16.8

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/ruff/releases/download/0.16.8/ruff-installer.sh | sh
</tr></table> 

... (truncated)

Changelog

Sourced from ruff's changelog.

0.16.8

Released on 2026-09-16.

Bug fixes

  • Visit functional TypedDict keyword arguments correctly (#28584)
  • [flake8-simplify] Detect nested async with under sync parent (SIM117) (#27821)
  • [flake8-simplify] Preserve operand order in SIM109 fix (#27824)
  • [pyupgrade] Preserve required parentheses in multiline UP040 fixes (#28164)
  • [pyupgrade] Skip TypeVarTuple and ParamSpec conversions with bounds or constraints (UP040, UP046, UP047) (#28505)

Rule changes

  • Add support for __lazy_modules__ (#28459)
  • Recognize PEP-728 TypedDict class keywords (#28533)
  • Recognize quoted types in typing.TypeForm (#28507)
  • Support conditional assignment to __lazy_modules__ (#28491)
  • [flake8-type-checking] Prefer lazy imports over TYPE_CHECKING on Python 3.15 and later (TC001, TC002, TC003) (#28541)
  • [pyupgrade] Make the fix for UP040 always unsafe (#28526)
  • [pyupgrade] Stop recommending deprecated ByteString aliases (UP035) (#28498)
  • [ruff, flake8-use-pathlib] Recognize the parent_mode argument (RUF064, PTH103) (#28528)
  • [ruff] Detect \Z in pytest.raises() match patterns (RUF043) (#28598)

CLI

  • Use rule name and code in formatter incompatibility warnings (#28571)

Configuration

  • [flake8-tidy-imports] Add extend-banned-api (#28644)

Contributors

0.16.7

Released on 2026-09-10.

Preview features

  • [ruff] Add rule for default values on method receivers (RUF077) (#26700)

... (truncated)

Commits
  • 62914c4 Bump version to 0.16.8 (#28648)
  • c47e0cd [ty] Bound aliased intersection expansion during inference (#28546)
  • ff4747b renovate: update uv hashes correctly with setup-uv (#28621)
  • 94efeaa [ty] Compact reachable binding and declaration histories (#28349)
  • 50020fb [ty] Avoid storing constraint nodes twice (#28375)
  • 446bb68 [ty] Compare bound-method receivers before signatures (#28384)
  • 304ab86 [flake8-type-checking] Prefer lazy imports over TYPE_CHECKING on 3.15+ (`...
  • d940b24 [ty] Watch script dependencies in CLI watch mode (#28125)
  • fe9f065 [flake8-tidy-imports] Add extend-banned-api (#28644)
  • 31131db [ty] Support type[A & B] (#27124)
  • Additional commits viewable in compare view

Updates pyrefly to 1.3.1

Release notes

Sourced from pyrefly's releases.

Pyrefly v1.3.1

Release date: September 14, 2026

Pyrefly v1.3.1 is a patch release with a single bug fix.


🐛 Bug fixes

  • #4909: Fixed a critical issue where Pyrefly would immediately crash on startup with a thread panic when empty or relative base paths were encountered during configuration. The server now safely resolves these paths against the working directory, preventing the crash and allowing normal operation.

Thank-you to all our contributors who found these bugs and reported them! Did you know this is one of the most helpful contributions you can make to an open-source project? If you find any bugs in Pyrefly we want to know about them! Please open a bug report issue here.


📦 Upgrade

pip install --upgrade pyrefly==1.3.1

How to safely upgrade your codebase

Upgrading the version of Pyrefly you're using or a third-party library you depend on can reveal new type errors in your code. Fixing them all at once is often unrealistic. We've written scripts to help you temporarily silence them. After upgrading, follow these steps:

  1. pyrefly check --suppress-errors
  2. Run your code formatter of choice
  3. pyrefly check --remove-unused-ignores
  4. Repeat until you achieve a clean formatting run and a clean type check.

This will add # pyrefly: ignore comments to your code, enabling you to silence errors and return to fix them later. This can make the process of upgrading a large codebase much more manageable.

Read more about error suppressions in the Pyrefly documentation.

Commits

Updates tox to 4.62.0

Release notes

Sourced from tox's releases.

v4.62.0

What's Changed

Full Changelog: tox-dev/tox@4.61.5...4.62.0

Changelog

Sourced from tox's changelog.

Features - 4.62.0

  • Plugins can read a configuration value that may be unset through ConfigSet.get_optional, which verifies the value against its declared type and returns None when it is not set - by :user:gaborbernat. (:issue:4075)

Bug fixes - 4.62.0

  • Setting TOX_FACTOR_<label> to an empty value now resolves {factor:<label>} to an empty string instead of being ignored - by :user:gaborbernat. (:issue:4073)

Contributor-facing changes - 4.62.0

  • Contributors running the type checks get a clean pass again with the latest ty release, and the checks now cover more: configuration values are read through the type-verified accessors instead of as Any, and every method that overrides a parent is marked with @override - by :user:gaborbernat. (:issue:4075)

v4.61.5 (2026-09-17)


Bug fixes - 4.61.5

  • An empty set_env list in TOML no longer fails to load; like an empty table, it clears inherited variables - by :user:yuefdev. (:issue:4065)
  • A TOML factor range now rejects true or false as start or stop instead of reading them as 1 and 0 - by :user:yuefdev. (:issue:4066)
  • Preserve an explicitly empty {factor:label:} fallback instead of using the declared factor group default. (:issue:4072)

Improved documentation - 4.61.5

  • Loader.build documented a future parameter it no longer takes and left factory undocumented, so the plugin API reference listed a parameter that does not exist - by :user:hxperl. (:issue:4070)

Contributor-facing changes - 4.61.5

  • Restore COVERAGE_PROCESS_START in the test environments; a mangled key had left it unset since the move to tox.toml - by :user:yuefdev. (:issue:4067)

v4.61.4 (2026-09-09)


Bug fixes - 4.61.4

... (truncated)

Commits
  • 99f4421 release 4.62.0
  • 176c68f 🐛 fix(config): honor an empty TOX_FACTOR override (#4074)
  • e521d6e 🐛 fix(type): pass the latest ty and close Any gaps (#4075)
  • 40a5d2b release 4.61.5
  • c504e48 fix(config): let empty factor fallbacks override TOML group defaults (#4072)
  • a5a7ce6 fix: correct coverage startup environment variable (#4067)
  • 3632978 fix(config): accept empty set_env lists (#4065)
  • b429bcc fix(config): reject boolean TOML range bounds (#4066)
  • 0975be8 [pre-commit.ci] pre-commit autoupdate (#4068)
  • 7b5068b docs: fix the parameter list on Loader.build (#4070)
  • Additional commits viewable in compare view

Updates uv-build to 0.12.17

Release notes

Sourced from uv-build's releases.

0.12.17

Release Notes

Released on 2026-09-18.

Enhancements

  • Reject unsupported Git archive paths in lockfiles with a clear error instead of panicking during frozen exports (#21780)

Preview features

  • Set minimum glibc and musl versions that universal resolutions must support with minimum-libc-version (#21651)
  • Reject pylock.toml files whose wheel filenames do not match their declared package names or versions (#20746)
  • Keep uv workspace metadata read-only unless --sync is provided (#21821)
  • Apply uv check lock modes when retrieving workspace metadata (#21821)

Performance

  • Speed up builds with many exclusion patterns by avoiding quadratic deduplication (#21650)
  • Reduce resolver allocations when deduplicating package and distribution requests (#21810)

Bug fixes

  • Prevent required-environments from selecting package versions whose wheels require a newer macOS version than the configured Darwin baseline (#21825)

Documentation

  • Clarify the 0.12.14 and 0.12.15 release notes (#21817)

Install uv 0.12.17

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.17/uv-installer.sh | sh

Install prebuilt binaries via powershell script

powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.17/uv-installer.ps1 | iex"

Download uv 0.12.17

File Platform Checksum
uv-aarch64-apple-darwin.tar.gz Apple Silicon macOS checksum
uv-x86_64-apple-darwin.tar.gz Intel macOS checksum
uv-aarch64-pc-windows-msvc.zip ARM64 Windows checksum

... (truncated)

Changelog

Sourced from uv-build's changelog.

0.12.17

Released on 2026-09-18.

Enhancements

  • Reject unsupported Git archive paths in lockfiles with a clear error instead of panicking during frozen exports (#21780)

Preview features

  • Set minimum glibc and musl versions that universal resolutions must support with minimum-libc-version (#21651)
  • Reject pylock.toml files whose wheel filenames do not match their declared package names or versions (#20746)
  • Keep uv workspace metadata read-only unless --sync is provided (#21821)
  • Apply uv check lock modes when retrieving workspace metadata (#21821)

Performance

  • Speed up builds with many exclusion patterns by avoiding quadratic deduplication (#21650)
  • Reduce resolver allocations when deduplicating package and distribution requests (#21810)

Bug fixes

  • Prevent required-environments from selecting package versions whose wheels require a newer macOS version than the configured Darwin baseline (#21825)

Documentation

  • Clarify the 0.12.14 and 0.12.15 release notes (#21817)

0.12.16

Released on 2026-09-17.

Python

  • Add Pyodide 314.0.7, 0.29.5, and 0.27.8 (#21741)

Enhancements

  • Verify downloaded wheels and source distributions against hashes supplied by package indexes (#21562)
  • Allow build-constraint-dependencies entries to include hashes for verifying downloaded build dependencies (#21467)
  • Honor Darwin platform_release markers in required-environments using macOS wheel deployment targets (#21766)
  • Reject unsupported Git URL schemes while parsing lockfiles instead of panicking during frozen exports (#21779)

Preview features

  • Support lock-without-metadata across all dependency types while retaining package.metadata for remote URL dependencies to enable offline validation (#21163)
  • Honor configured and command-line index settings, including credentials, in uv upgrade (#21776)
  • Allow uv check to run in projects that are not managed by uv and outside workspaces (#21777)
  • Respect --python and UV_PYTHON when selecting the Python version for uv check (#21744)

... (truncated)

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Updates the requirements on [coverage](https://github.com/coveragepy/coveragepy), [ruff](https://github.com/astral-sh/ruff), [pyrefly](https://github.com/facebook/pyrefly), [tox](https://github.com/tox-dev/tox) and [uv-build](https://github.com/astral-sh/uv) to permit the latest version.

Updates `coverage` to 7.16.1
- [Release notes](https://github.com/coveragepy/coveragepy/releases)
- [Changelog](https://github.com/coveragepy/coveragepy/blob/main/CHANGES.rst)
- [Commits](coveragepy/coveragepy@7.16.0...7.16.1)

Updates `ruff` to 0.16.8
- [Release notes](https://github.com/astral-sh/ruff/releases)
- [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md)
- [Commits](astral-sh/ruff@0.16.7...0.16.8)

Updates `pyrefly` to 1.3.1
- [Release notes](https://github.com/facebook/pyrefly/releases)
- [Commits](facebook/pyrefly@1.3.0...1.3.1)

Updates `tox` to 4.62.0
- [Release notes](https://github.com/tox-dev/tox/releases)
- [Changelog](https://github.com/tox-dev/tox/blob/main/docs/changelog.rst)
- [Commits](tox-dev/tox@4.61.4...4.62.0)

Updates `uv-build` to 0.12.17
- [Release notes](https://github.com/astral-sh/uv/releases)
- [Changelog](https://github.com/astral-sh/uv/blob/main/CHANGELOG.md)
- [Commits](astral-sh/uv@0.12.13...0.12.17)

---
updated-dependencies:
- dependency-name: coverage
  dependency-version: 7.16.1
  dependency-type: direct:production
  dependency-group: python-dev-dependencies
- dependency-name: ruff
  dependency-version: 0.16.8
  dependency-type: direct:production
  dependency-group: python-dev-dependencies
- dependency-name: pyrefly
  dependency-version: 1.3.1
  dependency-type: direct:production
  dependency-group: python-dev-dependencies
- dependency-name: tox
  dependency-version: 4.62.0
  dependency-type: direct:production
  dependency-group: python-dev-dependencies
- dependency-name: uv-build
  dependency-version: 0.12.17
  dependency-type: direct:development
  dependency-group: python-dev-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels Oct 3, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants