Skip to content

deps: bump the python-dependencies group across 1 directory with 6 updates - #108

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/python-dependencies-55d5c1863e
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/python-dependencies-55d5c1863e

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 28, 2026

Copy link
Copy Markdown
Contributor

Updates the requirements on ccxt, databento, hatchling, setuptools-scm, trove-classifiers and vcs-versioning to permit the latest version.
Updates ccxt to 4.5.84

Commits

Updates databento from 0.86.0 to 0.87.0

Release notes

Sourced from databento's releases.

databento 0.87.0

Release notes

Enhancements

  • Added new venue, dataset, and publishers for Databento Core Indices
  • Asynchronous iteration of Live no longer waits for records on a thread pool executor, reducing per-record overhead
  • Upgraded databento-dbn to 0.70.0

Bug fixes

  • Fixed an issue where cancelling asynchronous iteration of Live could drop a record
Changelog

Sourced from databento's changelog.

0.87.0 - 2026-09-22

Enhancements

  • Added new venue, dataset, and publishers for Databento Core Indices
  • Asynchronous iteration of Live no longer waits for records on a thread pool executor, reducing per-record overhead
  • Upgraded databento-dbn to 0.70.0

Bug fixes

  • Fixed an issue where cancelling asynchronous iteration of Live could drop a record
Commits
  • 25eef4e VER: Release 0.87.0
  • 6dacf66 VER: Release 0.87.0
  • a9062a5 MOD: Upgrade databento-dbn to 0.70.0
  • a40b3c1 OPT: Remove threadpool executor from async next
  • d97027f FIX: Leftover fixes for CGIF bundling
  • a83c5f0 MOD: Bundle CGIF datasets into DBIX
  • See full diff in compare view

Updates hatchling from 1.32.0 to 1.32.4

Release notes

Sourced from hatchling's releases.

Hatchling v1.32.4

Fixed:

  • Revert the extra type parameter added to BuildHookInterface in 1.32.3, which broke plugins that subscripted the interface with a single argument (e.g. BuildHookInterface[MyConfig]) by raising TypeError at import time. BuilderConfig is likewise no longer generic, restoring the pre-1.32.3 plugin interface.
  • Strip spaces around version metadata when using original input for CalVer to keep leading zeroes.

Hatchling v1.32.3

Fixed:

  • Preserve the version string exactly as written in core metadata, so stylized versions such as CalVer 2026.08.10 are no longer stripped of leading zeros. Distribution file names and .dist-info directories continue to use the PEP 440 normalized form.
Commits

Updates setuptools-scm from 10.2.3 to 10.3.4

Release notes

Sourced from setuptools-scm's releases.

setuptools-scm v10.3.4

Fixed

  • Ship the tracked files of projects whose pyproject.toml sits in a subdirectory of the checkout. root defaults to the project directory, so version inference correctly finds no SCM there and answers from SETUPTOOLS_SCM_PRETEND_VERSION or fallback_version -- but that says nothing about which files git tracks, and the sdist and wheel came out with none of them. This was the 10.3.0 regression fixed in 10.3.3, surviving in the subdirectory layout.

    File discovery now follows the checkout the project sits in, independently of the root that scopes versioning, and records scm_file_list.json in the egg-info as a root-level project already did. (#1543)

  • Require vcs-versioning>=2.5.0. The subdirectory file-discovery fix (#1543) imports discover_file_workdir, which no earlier release has, while the declared floor still named 2.4.0 -- an install against a published vcs-versioning raised ImportError during the build. (#1546)

setuptools-scm v10.3.3

Fixed

  • Keep file discovery working when the version is pretended. SETUPTOOLS_SCM_PRETEND_VERSION and its scoped _FOR_<DIST> form made version inference return before discovering a workdir, and the egg_info mixin read the absent workdir as "searched, found no checkout" -- the signal it acts on by suppressing the setuptools.file_finders chain. Every SCM-tracked file that setuptools' own package discovery does not find was then dropped from the sdist and the wheel, silently, since the build succeeded and the version was correct.

    A pretended version still skips discovery, because most builds only want a version and probing for a checkout nobody asks about costs subprocesses for nothing. What no longer happens is passing that off as an answer: "nobody looked yet" is now distinct from "looked and found nothing", and the workdir is discovered on demand the first time a consumer needs a file list.

    scm_file_list.json is now written to the egg-info for pretended builds as well. It describes which files the checkout tracks, which a pretended version says nothing about. scm_version.json stays absent there, because a pretended version must not be recorded as what the SCM said. (#1540)

setuptools-scm v10.3.2

Fixed

  • Stop the command mixins from reordering a project's own build_py, egg_info or bdist_wheel MRO. ScmVersionFileMixin and friends inherited from the corresponding setuptools command, so wrapping a project class built on a disjoint hierarchy -- distutils.command.build_py, or the standalone wheel package's bdist_wheel -- placed setuptools' command ahead of the project's class. setuptools.build_py.run() does not delegate any further, so the project's

... (truncated)

Commits
  • b27f597 Merge pull request #1545 from pypa/release/main
  • aa18322 Prepare release: setuptools-scm v10.3.4, vcs-versioning v2.5.0
  • e40176e Merge pull request #1551 from RonnyPfannschmidt/fix/version-missing-accepts-tool
  • 873d4b3 fix(vcs-versioning): accept tool= in _version_missing again
  • 5173a1e Merge pull request #1546 from RonnyPfannschmidt/fix/dependency-floor-runs-the...
  • cbcd429 fix(deps): require vcs-versioning>=2.5.0.dev0
  • 5f95612 ci(dependency-floor): run the testsuite, not just the imports
  • e377730 Merge pull request #1544 from RonnyPfannschmidt/fix/file-discovery-follows-th...
  • 98fa24d fix(file-discovery): follow the checkout, not the versioning root
  • 41edffe Merge pull request #1538 from pypa/release/main
  • Additional commits viewable in compare view

Updates trove-classifiers from 2026.6.1.19 to 2026.9.21.13

Commits

Updates vcs-versioning from 2.3.4 to 2.5.0

Release notes

Sourced from vcs-versioning's releases.

vcs-versioning v2.5.0

Added

  • Add discover_file_workdir(), which finds the checkout a project sits in for the purpose of listing files. discover_workdir() answers which checkout defines the version, scoped by root and search_parent_directories; which files a project ships is a separate question, and a project in a subdirectory of a checkout still ships that checkout's files. (#1543)

Fixed

  • Accept the tool keyword in _version_missing() again. setuptools-scm 10.1.0 through 10.2.3 pass it and allow any vcs-versioning<3; since 2.4.1 removed it, a build without a detectable version failed with TypeError: _version_missing() got an unexpected keyword argument 'tool' instead of the LookupError that says how to set a version. The keyword is ignored; the tool is taken from the configuration's environment. (#1550)

vcs-versioning v2.4.1

Fixed

  • The error raised when a .jj/ directory is found but jj is not installed now names the environment variables that actually disable jj discovery (SETUPTOOLS_SCM_DISABLE_JJ=1 / VCS_VERSIONING_DISABLE_JJ=1) instead of an unprefixed DISABLE_JJ=1, which was never read. (#1537)

  • The "unable to detect version" error now names the environment variables the running integration actually reads. It previously suggested SETUPTOOLS_SCM_PRETEND_VERSION_FOR_${NORMALIZED_DIST_NAME} unconditionally, which is not read by vcs-versioning on its own (or by any other integrator), and it named setuptools-scm as the failing tool regardless of which one ran.

    When the distribution name is known the suggested variable is spelled out in full. When it is not, the generic variables are suggested instead, with a note that the per-distribution ..._FOR_<DIST> form needs a dist name to match -- the previous message offered a ${NORMALIZED_DIST_NAME} template that could never be filled in. (#1539)

  • Warn when file discovery is suppressed while a VCS marker sits in the project directory. scm_search_known_failed() means an integrator already looked and found no checkout, so a .git, .hg or .jj right there contradicts it and the artifact is about to lose every tracked file. That combination was the signature of the pretend-version regression and stayed invisible for three releases. Parent directories are not searched, since an unpacked sdist inside an unrelated checkout is the case the suppression exists for, and roots listed in IGNORE_VCS_ROOTS are skipped. (#1540)

Miscellaneous

  • Environment variable names are now built in one place (env_var_name / EnvReader.candidate_names), shared by the lookup in EnvReader.read and by every error message that suggests a variable, so a message cannot name a variable the lookup would not honour.

... (truncated)

Commits
  • b27f597 Merge pull request #1545 from pypa/release/main
  • aa18322 Prepare release: setuptools-scm v10.3.4, vcs-versioning v2.5.0
  • e40176e Merge pull request #1551 from RonnyPfannschmidt/fix/version-missing-accepts-tool
  • 873d4b3 fix(vcs-versioning): accept tool= in _version_missing again
  • 5173a1e Merge pull request #1546 from RonnyPfannschmidt/fix/dependency-floor-runs-the...
  • cbcd429 fix(deps): require vcs-versioning>=2.5.0.dev0
  • 5f95612 ci(dependency-floor): run the testsuite, not just the imports
  • e377730 Merge pull request #1544 from RonnyPfannschmidt/fix/file-discovery-follows-th...
  • 98fa24d fix(file-discovery): follow the checkout, not the versioning root
  • 41edffe Merge pull request #1538 from pypa/release/main
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

…dates

Updates the requirements on [ccxt](https://github.com/ccxt/ccxt), [databento](https://github.com/databento/databento-python), [hatchling](https://github.com/pypa/hatch), [setuptools-scm](https://github.com/pypa/setuptools-scm), [trove-classifiers](https://github.com/pypa/trove-classifiers) and [vcs-versioning](https://github.com/pypa/setuptools-scm) to permit the latest version.

Updates `ccxt` to 4.5.84
- [Release notes](https://github.com/ccxt/ccxt/releases)
- [Commits](ccxt/ccxt@v4.5.31...v4.5.84)

Updates `databento` from 0.86.0 to 0.87.0
- [Release notes](https://github.com/databento/databento-python/releases)
- [Changelog](https://github.com/databento/databento-python/blob/main/CHANGELOG.md)
- [Commits](databento/databento-python@v0.86.0...v0.87.0)

Updates `hatchling` from 1.32.0 to 1.32.4
- [Release notes](https://github.com/pypa/hatch/releases)
- [Commits](pypa/hatch@hatchling-v1.32.0...hatchling-v1.32.4)

Updates `setuptools-scm` from 10.2.3 to 10.3.4
- [Release notes](https://github.com/pypa/setuptools-scm/releases)
- [Changelog](https://github.com/pypa/setuptools-scm/blob/main/RELEASE_SYSTEM.md)
- [Commits](pypa/setuptools-scm@setuptools-scm-v10.2.3...setuptools-scm-v10.3.4)

Updates `trove-classifiers` from 2026.6.1.19 to 2026.9.21.13
- [Release notes](https://github.com/pypa/trove-classifiers/releases)
- [Commits](pypa/trove-classifiers@2026.6.1.19...2026.9.21.13)

Updates `vcs-versioning` from 2.3.4 to 2.5.0
- [Release notes](https://github.com/pypa/setuptools-scm/releases)
- [Changelog](https://github.com/pypa/setuptools-scm/blob/main/RELEASE_SYSTEM.md)
- [Commits](pypa/setuptools-scm@vcs-versioning-v2.3.4...vcs-versioning-v2.5.0)

---
updated-dependencies:
- dependency-name: ccxt
  dependency-version: 4.5.84
  dependency-type: direct:production
  dependency-group: python-dependencies
- dependency-name: databento
  dependency-version: 0.87.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: python-dependencies
- dependency-name: hatchling
  dependency-version: 1.32.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python-dependencies
- dependency-name: setuptools-scm
  dependency-version: 10.3.4
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-dependencies
- dependency-name: trove-classifiers
  dependency-version: 2026.9.21.13
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-dependencies
- dependency-name: vcs-versioning
  dependency-version: 2.5.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-dependencies
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot Bot added dependencies Dependency updates python Python dependencies labels Sep 28, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Dependency updates python Python dependencies

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants