Skip to content

chore(deps)(deps-dev): bump the python-linters group across 1 directory with 3 updates - #1038

Open
dependabot[bot] wants to merge 3 commits into
mainfrom
dependabot/uv/python-linters-31726f3ca0
Open

dependabot[bot] wants to merge 3 commits into
mainfrom
dependabot/uv/python-linters-31726f3ca0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 13, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the python-linters group with 3 updates in the / directory: pyproject-fmt, ruff and ty.

Updates pyproject-fmt from 2.25.1 to 2.29.4

Release notes

Sourced from pyproject-fmt's releases.

pyproject-fmt/2.29.4

Fixed

  • Keep the classifiers a bound admits. (#463)

pyproject-fmt/2.29.3

Fixed

  • The test suite the source distribution ships passes from the unpacked sdist. The backend read the project metadata from beside itself, and the sdist keeps a copy of that file next to the tests, a directory below the pyproject.toml it belongs to, so eight tests ended on the file it could not find. It reads the metadata from either place. (#454, #457)

pyproject-fmt/2.29.2

Fixed

  • A build from the source distribution runs on what that distribution carries. 2.29.0 named toml-fmt-common as a dependency and resolved it from PyPI, where the newest release dates from May; 2.29.1 dropped the dependency before the sdist carried the sources, so a build from it failed on the import. This release carries them, and its metadata requires nothing. (#450, #452)

The wheels held their vendored copy throughout, so an install that takes a wheel was never affected.

pyproject-fmt/2.29.1

Fixed

  • The source distribution no longer names toml-fmt-common as a dependency. The newest release of that package on PyPI dates from May, months behind this one, so a build from the sdist ran an old settings reader against the current formatter and failed a large part of its own test suite. (#450, #451)

Known issue

  • This release's source distribution carries no toml-fmt-common, so a build from it fails on the import. 2.29.2 carries it. The wheels hold their vendored copy and install as before. (#452)

pyproject-fmt/2.29.0

Changed

  • A string measures from the start of its key. A long key can be what pushes a value past column_width; measuring the value alone left lines running past the column the setting asks for. (#448)
  • Deep input comes back as an error rather than a crash. Reading a value, writing it and dropping it each walk it by calling themselves, so the model caps nesting at 256 levels. A 12,000-deep value used to end the process. (#448)

Fixed

  • A requirement written with a space after its operator reads as a requirement. requires-python = ">= 3.12" did not parse as a version bound, so the generated classifiers fell back to the configured floor and ceiling. pypa/build carried a 3.9 classifier it does not support. (#448)
  • The classifier window works at patch precision. requires-python = "<3.10.1" lost the whole 3.10 series, and claimed Programming Language :: Python :: 3 :: Only for a bound that admits Python 2. (#448)
  • A literal string sorts with the values around it. 'zz' and 'aa' held their order while the same values in double quotes sorted. (#448)
  • A comment written before a member's comma stays on that member's line. The comma is what says which member a comment belongs to: one written before it closes that member's line, one written after it leads the next member. Both used to end up on a line of their own, leaving the comma stranded below. (#448)
  • classifiers written as a string stays as written. Asking for generated classifiers replaced the string with an array, losing what the file said. (#448)
  • Folding sub-tables into their parent no longer depends on the order the file wrote them in. (#448)
  • The key order covers pyrefly's documented option names. It spells them with hyphens, the order listed only the underscore forms, and a file using the documented spelling fell through to alphabetical order. (#448)
  • A dependency group keeps its include-group entries where the file wrote them. An include-group pulls its group in at the point it sits, so moving it changes what the group resolves to. (#448)
  • Free-form license text stays as written. license = "MIT or later" came back rewritten as though it were an SPDX expression; the formatter now rewrites the value only once it parses as one over registered identifiers. (#448)
  • The * catch-all in a setuptools data table matches the way the file spells it. * is not a name TOML reads bare, so a file writes it quoted; the catch-all led the table only because a quote happens to sort before a letter. (#448)

Performance

  • The quadratic walks the old parse tree forced are gone. 32,000 interleaved root keys under two tables took 618 seconds and now take 4.8; scaling is close to linear. (#448)

... (truncated)

Commits
  • 5c2c87c Release pyproject-fmt 2.29.4 [skip ci]
  • ed4af96 🐛 fix(pyproject-fmt): keep the classifiers a bound admits (#463)
  • 2946fc3 build(deps): bump taiki-e/install-action from 2.86.7 to 2.87.3 in the github-...
  • 95529cc [pre-commit.ci] pre-commit autoupdate (#461)
  • 7c729de ♻️ refactor(project): apply the house style (#459)
  • 77655bb Release tox-toml-fmt 1.10.3 [skip ci]
  • e6cbb18 Release pyproject-fmt 2.29.3 [skip ci]
  • 32f9e33 build(deps): bump taiki-e/install-action from 2.86.3 to 2.86.7 in the github-...
  • 2dfd00e Update Python dependencies (#455)
  • f1b5863 🐛 fix(build): read the project metadata from the sdist (#457)
  • Additional commits viewable in compare view

Updates ruff from 0.15.20 to 0.16.8

Release notes

Sourced from ruff's releases.

0.16.8

Release Notes

Released on 2026-09-16.

Bug fixes

  • Visit functional TypedDict keyword arguments correctly (#28584)
  • [flake8-simplify] Detect nested async with under sync parent (SIM117) (#27821)
  • [flake8-simplify] Preserve operand order in SIM109 fix (#27824)
  • [pyupgrade] Preserve required parentheses in multiline UP040 fixes (#28164)
  • [pyupgrade] Skip TypeVarTuple and ParamSpec conversions with bounds or constraints (UP040, UP046, UP047) (#28505)

Rule changes

  • Add support for __lazy_modules__ (#28459)
  • Recognize PEP-728 TypedDict class keywords (#28533)
  • Recognize quoted types in typing.TypeForm (#28507)
  • Support conditional assignment to __lazy_modules__ (#28491)
  • [flake8-type-checking] Prefer lazy imports over TYPE_CHECKING on Python 3.15 and later (TC001, TC002, TC003) (#28541)
  • [pyupgrade] Make the fix for UP040 always unsafe (#28526)
  • [pyupgrade] Stop recommending deprecated ByteString aliases (UP035) (#28498)
  • [ruff, flake8-use-pathlib] Recognize the parent_mode argument (RUF064, PTH103) (#28528)
  • [ruff] Detect \Z in pytest.raises() match patterns (RUF043) (#28598)

CLI

  • Use rule name and code in formatter incompatibility warnings (#28571)

Configuration

  • [flake8-tidy-imports] Add extend-banned-api (#28644)

Contributors

Install ruff 0.16.8

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/ruff/releases/download/0.16.8/ruff-installer.sh | sh
</tr></table> 

... (truncated)

Changelog

Sourced from ruff's changelog.

0.16.8

Released on 2026-09-16.

Bug fixes

  • Visit functional TypedDict keyword arguments correctly (#28584)
  • [flake8-simplify] Detect nested async with under sync parent (SIM117) (#27821)
  • [flake8-simplify] Preserve operand order in SIM109 fix (#27824)
  • [pyupgrade] Preserve required parentheses in multiline UP040 fixes (#28164)
  • [pyupgrade] Skip TypeVarTuple and ParamSpec conversions with bounds or constraints (UP040, UP046, UP047) (#28505)

Rule changes

  • Add support for __lazy_modules__ (#28459)
  • Recognize PEP-728 TypedDict class keywords (#28533)
  • Recognize quoted types in typing.TypeForm (#28507)
  • Support conditional assignment to __lazy_modules__ (#28491)
  • [flake8-type-checking] Prefer lazy imports over TYPE_CHECKING on Python 3.15 and later (TC001, TC002, TC003) (#28541)
  • [pyupgrade] Make the fix for UP040 always unsafe (#28526)
  • [pyupgrade] Stop recommending deprecated ByteString aliases (UP035) (#28498)
  • [ruff, flake8-use-pathlib] Recognize the parent_mode argument (RUF064, PTH103) (#28528)
  • [ruff] Detect \Z in pytest.raises() match patterns (RUF043) (#28598)

CLI

  • Use rule name and code in formatter incompatibility warnings (#28571)

Configuration

  • [flake8-tidy-imports] Add extend-banned-api (#28644)

Contributors

0.16.7

Released on 2026-09-10.

Preview features

  • [ruff] Add rule for default values on method receivers (RUF077) (#26700)

... (truncated)

Commits
  • 62914c4 Bump version to 0.16.8 (#28648)
  • c47e0cd [ty] Bound aliased intersection expansion during inference (#28546)
  • ff4747b renovate: update uv hashes correctly with setup-uv (#28621)
  • 94efeaa [ty] Compact reachable binding and declaration histories (#28349)
  • 50020fb [ty] Avoid storing constraint nodes twice (#28375)
  • 446bb68 [ty] Compare bound-method receivers before signatures (#28384)
  • 304ab86 [flake8-type-checking] Prefer lazy imports over TYPE_CHECKING on 3.15+ (`...
  • d940b24 [ty] Watch script dependencies in CLI watch mode (#28125)
  • fe9f065 [flake8-tidy-imports] Add extend-banned-api (#28644)
  • 31131db [ty] Support type[A & B] (#27124)
  • Additional commits viewable in compare view

Updates ty from 0.0.55 to 0.0.84

Release notes

Sourced from ty's releases.

0.0.84

Release Notes

Released on 2026-09-24.

This release addresses GHSA-vxvm-j4xq-q7m4, a use-after-free vulnerability during incremental type checking that can result in arbitrary code execution when analyzing a specially crafted Python project. Users who run ty on untrusted code should upgrade to 0.0.84 or newer.

Bug fixes

  • Fix stale diagnostics from the LSP server after toggling showSyntaxErrors (#28759)

LSP server

  • Complete string keys from dictionary initializers (#28820)
  • Support LSP requests against closed documents (#28595)
  • Select projects for external files using import search paths (#28594)
  • Use workspace editor settings for external files (#28639)

Performance

  • Avoid repeated subtyping checks for materialized recursive protocols (#28774)
  • Skip reading notebooks when discovering scripts (#28781)

Core type checking

  • Avoid incorrect simplification of TypeIs materializations (#28817)
  • Fix disjointness of generic class types (#28787)
  • Fix staticmethod shadowing through generic receivers and unions (#28766)
  • Infer callable signatures from bounded type variables (#28599)
  • Infer constant membership in inline list and set literals (e.g. "foo" in ["foo"] is now inferred as Literal[True]) (#28676)
  • Infer through optional generic containers in the legacy solver (#28791)
  • Preserve call narrowing during cyclic inference (#28708)
  • Preserve intersections of type guard return types (#28796)
  • Use subtyping for constraint-set implication (#28657)

Configuration

  • Disable invalid-legacy-positional-parameter by default (#28834)

Other changes

  • Only consider reachable definitions when determining whether a condition should be exempted from redundant-condition(-strict) due to the condition being defined relative to sys.version_info, sys.platform, os.name or typing.TYPE_CHECKING (#28788)

Contributors

... (truncated)

Changelog

Sourced from ty's changelog.

0.0.84

Released on 2026-09-24.

This release addresses GHSA-vxvm-j4xq-q7m4, a use-after-free vulnerability during incremental type checking that can result in arbitrary code execution when analyzing a specially crafted Python project. Users who run ty on untrusted code should upgrade to 0.0.84 or newer.

Bug fixes

  • Fix stale diagnostics from the LSP server after toggling showSyntaxErrors (#28759)

LSP server

  • Complete string keys from dictionary initializers (#28820)
  • Support LSP requests against closed documents (#28595)
  • Select projects for external files using import search paths (#28594)
  • Use workspace editor settings for external files (#28639)

Performance

  • Avoid repeated subtyping checks for materialized recursive protocols (#28774)
  • Skip reading notebooks when discovering scripts (#28781)

Core type checking

  • Avoid incorrect simplification of TypeIs materializations (#28817)
  • Fix disjointness of generic class types (#28787)
  • Fix staticmethod shadowing through generic receivers and unions (#28766)
  • Infer callable signatures from bounded type variables (#28599)
  • Infer constant membership in inline list and set literals (e.g. "foo" in ["foo"] is now inferred as Literal[True]) (#28676)
  • Infer through optional generic containers in the legacy solver (#28791)
  • Preserve call narrowing during cyclic inference (#28708)
  • Preserve intersections of type guard return types (#28796)
  • Use subtyping for constraint-set implication (#28657)

Configuration

  • Disable invalid-legacy-positional-parameter by default (#28834)

Other changes

  • Only consider reachable definitions when determining whether a condition should be exempted from redundant-condition(-strict) due to the condition being defined relative to sys.version_info, sys.platform, os.name or typing.TYPE_CHECKING (#28788)

Contributors

... (truncated)

Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels Jul 13, 2026
@dependabot
dependabot Bot requested a review from a team July 13, 2026 04:23
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels Jul 13, 2026
@dependabot
dependabot Bot force-pushed the dependabot/uv/python-linters-31726f3ca0 branch 2 times, most recently from c7b8cf6 to 0f63db8 Compare July 22, 2026 04:14
@dependabot
dependabot Bot force-pushed the dependabot/uv/python-linters-31726f3ca0 branch 2 times, most recently from 056063c to acaafef Compare August 17, 2026 04:20
@dependabot
dependabot Bot force-pushed the dependabot/uv/python-linters-31726f3ca0 branch 2 times, most recently from cfa149d to eb1cd08 Compare August 20, 2026 04:13
@dependabot
dependabot Bot force-pushed the dependabot/uv/python-linters-31726f3ca0 branch from eb1cd08 to e3a30f9 Compare August 26, 2026 04:15
@dependabot
dependabot Bot force-pushed the dependabot/uv/python-linters-31726f3ca0 branch 5 times, most recently from f66d567 to 5f300a1 Compare September 16, 2026 04:13
@dependabot
dependabot Bot force-pushed the dependabot/uv/python-linters-31726f3ca0 branch 2 times, most recently from 845d369 to 7c74e86 Compare September 22, 2026 04:11
@dependabot
dependabot Bot force-pushed the dependabot/uv/python-linters-31726f3ca0 branch 2 times, most recently from aef25f9 to 9050858 Compare September 25, 2026 16:22
@MvLieshout

Copy link
Copy Markdown
Collaborator

@dependabot rebase

…ry with 3 updates

Bumps the python-linters group with 3 updates in the / directory: [pyproject-fmt](https://github.com/tox-dev/toml-fmt), [ruff](https://github.com/astral-sh/ruff) and [ty](https://github.com/astral-sh/ty).


Updates `pyproject-fmt` from 2.25.1 to 2.29.4
- [Release notes](https://github.com/tox-dev/toml-fmt/releases)
- [Commits](tox-dev/toml-fmt@pyproject-fmt/2.25.1...pyproject-fmt/2.29.4)

Updates `ruff` from 0.15.20 to 0.16.8
- [Release notes](https://github.com/astral-sh/ruff/releases)
- [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md)
- [Commits](astral-sh/ruff@0.15.20...0.16.8)

Updates `ty` from 0.0.55 to 0.0.84
- [Release notes](https://github.com/astral-sh/ty/releases)
- [Changelog](https://github.com/astral-sh/ty/blob/main/CHANGELOG.md)
- [Commits](astral-sh/ty@0.0.55...0.0.84)

---
updated-dependencies:
- dependency-name: pyproject-fmt
  dependency-version: 2.25.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: python-linters
- dependency-name: ruff
  dependency-version: 0.15.21
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: python-linters
- dependency-name: ty
  dependency-version: 0.0.58
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: python-linters
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/uv/python-linters-31726f3ca0 branch from 9050858 to 5f687ba Compare September 28, 2026 14:11
The bumped ruff, ty and pyproject-fmt versions surface real issues that
were previously masked by looser checks:

- ty (0.0.55 to 0.0.84): fix ~65 new diagnostics across openstef-core,
  openstef-beam and openstef-models (and their tests): untyped
  third-party returns (pandas, pvlib, joblib, optuna) now need explicit
  casts, TimeSeriesDataset subclasses were missing is_sorted and
  check_frequency in their __init__ overrides (LSP violation), redundant
  casts and conditions, and mock typing in tests.
- ruff (0.15.20 to 0.16.8): suppress the new PLR0917 positional-argument
  rule on an existing testing helper.
- pyproject-fmt (2.25.1 to 2.29.4): its new default max-supported-python
  is 3.15, but it silently only honors the first file's tool.pyproject-fmt
  config when formatting multiple files in one invocation. Changed the
  format-pyproject poe task to invoke pyproject-fmt once per file so each
  package's config is respected, and added Python 3.15 to the supported
  classifiers everywhere.

Also bumped pandas-stubs to 3.0.5.260914 (dependabot PR 1101) while
already touching typing-related config.

Signed-off-by: Marnix van Lieshout <marnix.van.lieshout@alliander.com>
CI's ty 0.0.84 (real pypi.org resolution) does not flag
unsound-return-statement on this return, unlike the 0.0.83 build that
was resolvable in my local environment. Remove the now-stale ignore
comment per CI's unused-ignore-comment diagnostic.

Signed-off-by: Marnix van Lieshout <marnix.van.lieshout@alliander.com>
@sonarqubecloud

Copy link
Copy Markdown

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant