Skip to content

chore(deps-dev): bump the python-dependencies group across 1 directory with 4 updates - #61

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/python-dependencies-bec9230640
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/python-dependencies-bec9230640

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown
Contributor

Bumps the python-dependencies group with 4 updates in the / directory: ruff, prek, pylint and zensical.

Updates ruff from 0.16.8 to 0.16.9

Release notes

Sourced from ruff's releases.

0.16.9

Release Notes

Released on 2026-09-24.

Preview features

  • [ruff] Avoid false positives for overloaded division (RUF069) (#28309)

Bug fixes

  • [flake8-bugbear] Avoid false positives for calls with keyword arguments (B009, B010, B043) (#28776)
  • [flake8-tidy-imports] Allow lazy imports to be used in deferred annotations (TID255) (#28767)

Rule changes

  • Update LibCST-based fixes for Python 3.15 (#28616)
  • [flake8-pyi] Mention stubs in the diagnostic message (PYI002) (#28542)

Documentation

  • Fix horizontal overflow on the rules documentation page (#28699)
  • Update rules table with category information (#28651)
  • [flake8-annotations] Clarify that ANN401 checks return types in addition to arguments (#28334)
  • [flake8-bugbear] Document type-checker interaction (B010) (#28509)
  • [flake8-comprehensions] Document map/generator exception behavior (C417) (#27794)
  • [ruff] Mention related isort settings (RUF022) (#28719)

Contributors

Install ruff 0.16.9

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/ruff/releases/download/0.16.9/ruff-installer.sh | sh

... (truncated)

Changelog

Sourced from ruff's changelog.

0.16.9

Released on 2026-09-24.

Preview features

  • [ruff] Avoid false positives for overloaded division (RUF069) (#28309)

Bug fixes

  • [flake8-bugbear] Avoid false positives for calls with keyword arguments (B009, B010, B043) (#28776)
  • [flake8-tidy-imports] Allow lazy imports to be used in deferred annotations (TID255) (#28767)

Rule changes

  • Update LibCST-based fixes for Python 3.15 (#28616)
  • [flake8-pyi] Mention stubs in the diagnostic message (PYI002) (#28542)

Documentation

  • Fix horizontal overflow on the rules documentation page (#28699)
  • Update rules table with category information (#28651)
  • [flake8-annotations] Clarify that ANN401 checks return types in addition to arguments (#28334)
  • [flake8-bugbear] Document type-checker interaction (B010) (#28509)
  • [flake8-comprehensions] Document map/generator exception behavior (C417) (#27794)
  • [ruff] Mention related isort settings (RUF022) (#28719)

Contributors

Commits
  • 0be08a2 Bump version to 0.16.9 (#28882)
  • b4920b7 Rename ruff_cli to ruff_command_line (#28881)
  • 47c751b Update dependency astral-sh/uv to v0.12.18 (#28880)
  • 8c244e5 [flake8-comprehensions] Document map/generator exception behavior (C417...
  • 5edf5a1 Use target form in rooster.version_files (#28876)
  • 915bb2b [ty] Prefer existing @ paths over response files in Ruff and ty (#28877)
  • 4710e1a ci(github): update version number in placeholder of issue template (#28871)
  • eedfc62 [ty] Propagate outer type context through cast calls (#28855)
  • ceaa6a0 [ty] Contain rendered code within Markdown fences (#28869)
  • dba0f30 authorize ruff-pre-commit dispatch via OIDC (#28867)
  • Additional commits viewable in compare view

Updates prek from 0.5.3 to 0.5.4

Release notes

Sourced from prek's releases.

0.5.4

Release Notes

Released on 2026-09-28.

Highlights

Faster builtin hooks

In our end-to-end benchmark, prek is about 38% faster than 0.5.3, with some builtin hooks up to 273% faster (check-yaml: 273%, check-json: 80%, check-merge-conflict: 71%).

Enhancements

  • Add include_deleted to allow hooks to include deleted files (#2733)
  • Add --check and simplify end-of-file-fixer (#2764)
  • Add --check to file-contents-sorter (#2765)
  • Add --check to requirements-txt-fixer (#2766)
  • Add --check to trailing-whitespace (#2763)
  • Expose and document prek util generate-shell-completion (#2727)
  • Support hide_status in project and user configuration (#2760)
  • Support look-around regex in builtin pattern hooks (#2732)

Performance

  • Cache the resolved Git executable on macOS (#2726)
  • Combine and cache Git repository path queries (#2724)
  • Optimize common builtin hook execution (#2768)
  • Optimize scanning in mixed-line-ending and trailing-whitespace (#2769)
  • Scan check-merge-conflict files in fixed-size blocks (#2781)
  • Use SIMD UTF-8 validation in check-json, check-toml, and check-yaml (#2770)

Bug fixes

  • Retry transient rename failures on Windows (#2756)
  • Use PATH to resolve prek in completion scripts (#2719)

Documentation

  • Clarify the flow and scope of usage guides (#2710)
  • Reorganize usage guides and reference documentation (#2709)

Other changes

  • Sync latest identify tags (#2762)

Contributors

... (truncated)

Changelog

Sourced from prek's changelog.

0.5.4

Released on 2026-09-28.

Highlights

Faster builtin hooks

In our end-to-end benchmark, prek is about 38% faster than 0.5.3, with some builtin hooks up to 273% faster (check-yaml: 273%, check-json: 80%, check-merge-conflict: 71%).

Enhancements

  • Add include_deleted to allow hooks to include deleted files (#2733)
  • Add --check and simplify end-of-file-fixer (#2764)
  • Add --check to file-contents-sorter (#2765)
  • Add --check to requirements-txt-fixer (#2766)
  • Add --check to trailing-whitespace (#2763)
  • Expose and document prek util generate-shell-completion (#2727)
  • Support hide_status in project and user configuration (#2760)
  • Support look-around regex in builtin pattern hooks (#2732)

Performance

  • Cache the resolved Git executable on macOS (#2726)
  • Combine and cache Git repository path queries (#2724)
  • Optimize common builtin hook execution (#2768)
  • Optimize scanning in mixed-line-ending and trailing-whitespace (#2769)
  • Scan check-merge-conflict files in fixed-size blocks (#2781)
  • Use SIMD UTF-8 validation in check-json, check-toml, and check-yaml (#2770)

Bug fixes

  • Retry transient rename failures on Windows (#2756)
  • Use PATH to resolve prek in completion scripts (#2719)

Documentation

  • Clarify the flow and scope of usage guides (#2710)
  • Reorganize usage guides and reference documentation (#2709)

Other changes

  • Sync latest identify tags (#2762)

Contributors

Commits

Updates pylint from 4.0.8 to 4.0.9

Release notes

Sourced from pylint's releases.

v4.0.9

What's new in Pylint 4.0.9?

Release date: 2026-09-23

Security Fixes

  • Someone without access to the configuration or linted code, but with access to the cache directory (predictable PYLINT_HOME on a multi-user host) can no longer write a crafted pickle that will runs arbitrary code when pylint access its stat cache. The result cache is now stored as JSON instead of pickle, preventing code-execution. The workaround is upgrading or not pointing PYLINT_HOME to an untrusted, shared, or group-writable directory. The default value, ~/.cache/pylint, is writable only by the user running pylint. (CVE with the same information pending)

False Positives Fixed

  • Fixed a false positive for no-self-use on a method that only uses self before a locally defined class (or other nested method), because the checker's could-be-a-function tracking state was not restored after visiting the nested method.

    Closes #3705

  • Fix a false positive for :ref:not-callable when calling functions constructed with types.FunctionType or types.LambdaType.

    Closes #7500

  • Fix a false positive for unnecessary-direct-lambda-call when a directly called lambda in a class body wraps a comprehension containing an assignment expression. PEP 572 makes that a SyntaxError without the lambda's scope, so following the message produced code that would not compile.

    Closes #9294

  • Fix a false positive for :ref:unnecessary-ellipsis when an ellipsis is the sole body statement of a method defined on a Protocol.

    Closes #9319

  • Fix a false positive for :ref:bad-exception-cause when the bases of the class being raised from cannot be inferred, such as an exception deriving from a C extension class. :ref:raising-non-exception and :ref:catching-non-exception already guard the same inherit_from_std_ex

... (truncated)

Commits
  • 303703f Bump pylint to 4.0.9, update changelog (#11448)
  • b342384 Fix block-scoped disable leaking into sibling elif/else blocks (#11429) (#11445)
  • 58c87cf Store the results cache as JSON instead of pickle
  • e3f4942 [Backport maintenance/4.0.x] Fix crash on failed attribute inference (#11443)
  • faf47f9 [Backport maintenance/4.0.x] Fix false positive no-self-use when a method con...
  • 20c7bb9 [Backport maintenance/4.0.x] Fix a crash in method-hidden for methods named a...
  • 47e6757 [Backport maintenance/4.0.x] Fix bad-exception-cause false positive when the ...
  • ae3ee53 [Backport maintenance/4.0.x] Fix not-callable false positive for types.Functi...
  • 3e444be [Backport maintenance/4.0.x] Fix a crash in unnecessary-default-type-args for...
  • 8f2dd4f [Backport maintenance/4.0.x] Fix declare-non-slot false positives for ClassVa...
  • Additional commits viewable in compare view

Updates zensical from 0.0.62 to 0.0.66

Release notes

Sourced from zensical's releases.

0.0.66

Summary

This version adds compatibility with mkdocs-autoapi and mkdocs-api-autonav, making it easier to document Python projects. These plugins discover modules and packages, generate API reference pages, and organize them in your site's navigation. They build on mkdocstrings, which renders the reference content from your code and docstrings, so you can skip manually creating a page for each module.

It also fixes responsive image URLs in raw HTML, ensures sitemaps include all published pages, and adds support for custom InlineHilite formatters configured through TOML.

Additionally, the user interface is updated to v0.0.33, adding styling for mkdocstrings backlinks in both themes, restoring GLightbox styles after instant navigation, respecting custom Mermaid node label colors, and fixing the / search shortcut.

Changelog

Features

  • b2f4de7 zensical, compat – support mkdocs-autoapi and mkdocs-api-autonav plugins

Bug fixes

  • 3d8c0e2 ui – update ui to v0.0.33
  • 7be3d1d compat – resolve custom inline formatters in TOML configuration (#980)
  • e3099ab zensical, compat – include all published pages in sitemap (#977)
  • e24d0fc compat – resolve raw HTML srcset URLs relative to Markdown source (#975)

0.0.65

Summary

This version expands MkDocs compatibility with a native replacement for the rss plugin and support for mkdocstrings backlinks. Zensical can now generate RSS 2.0 and JSON Feed 1.1 feeds for created and updated pages. Python API documentation can also show which pages reference a documented object, with backlinks kept current across cached builds.

Changelog

Features

  • e7876ab zensical, compat – support mike's version_selector setting
  • 25b95e9 zensical, compat – support mkdocstrings' enable_inventory setting
  • 0223fc9 compat – support more macros settings
  • acee89a zensical, compat – support autorefs settings
  • 0291923 zensical, compat – support mkdocstrings backlinks
  • c214988 zensical, compat – add rss plugin replacement (#443)

Bug fixes

  • cf68f6d zensical, compat – resolve source links to published post URLs (#966)

0.0.64

Summary

Many of you have been waiting for this one: Zensical now includes native blog support. As a direct port of the Material for MkDocs blog plugin, it preserves the familiar configuration, metadata, URLs, archives, categories, authors, pagination, and more. We're happy to finally put it into your hands, with more flexible blogging functionality planned for the future.

Changelog

Features

... (truncated)

Commits
  • a85dcbc chore: release v0.0.66
  • 3d8c0e2 fix: update ui to v0.0.33
  • 7be3d1d fix: resolve custom inline formatters in TOML configuration (#980)
  • b2f4de7 feature: support mkdocs-autoapi and mkdocs-api-autonav plugins
  • e3099ab fix: include all published pages in sitemap (#977)
  • e24d0fc fix: resolve raw HTML srcset URLs relative to Markdown source (#975)
  • 27fa310 chore: release v0.0.65
  • 5f7486e Merge pull request #969 from zensical/feature/support-more-plugin-settings
  • 95bd9aa chore: update uv lock file
  • e7876ab feature: support mike's version selector setting
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

…y with 4 updates

Bumps the python-dependencies group with 4 updates in the / directory: [ruff](https://github.com/astral-sh/ruff), [prek](https://github.com/j178/prek), [pylint](https://github.com/pylint-dev/pylint) and [zensical](https://github.com/zensical/zensical).


Updates `ruff` from 0.16.8 to 0.16.9
- [Release notes](https://github.com/astral-sh/ruff/releases)
- [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md)
- [Commits](astral-sh/ruff@0.16.8...0.16.9)

Updates `prek` from 0.5.3 to 0.5.4
- [Release notes](https://github.com/j178/prek/releases)
- [Changelog](https://github.com/j178/prek/blob/master/CHANGELOG.md)
- [Commits](j178/prek@v0.5.3...v0.5.4)

Updates `pylint` from 4.0.8 to 4.0.9
- [Release notes](https://github.com/pylint-dev/pylint/releases)
- [Commits](pylint-dev/pylint@v4.0.8...v4.0.9)

Updates `zensical` from 0.0.62 to 0.0.66
- [Release notes](https://github.com/zensical/zensical/releases)
- [Commits](zensical/zensical@v0.0.62...v0.0.66)

---
updated-dependencies:
- dependency-name: ruff
  dependency-version: 0.16.9
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: python-dependencies
- dependency-name: prek
  dependency-version: 0.5.4
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: python-dependencies
- dependency-name: pylint
  dependency-version: 4.0.9
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: python-dependencies
- dependency-name: zensical
  dependency-version: 0.0.66
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: python-dependencies
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Python dependency updates labels Oct 1, 2026
@codecov

codecov Bot commented Oct 1, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 92.6%. Comparing base (56467b6) to head (3a27770).

Additional details and impacted files
@@          Coverage Diff          @@
##            main     #61   +/-   ##
=====================================
  Coverage   92.6%   92.6%           
=====================================
  Files          4       4           
  Lines        926     926           
  Branches     178     178           
=====================================
  Hits         858     858           
  Misses        39      39           
  Partials      29      29           

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Python dependency updates

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants