Skip to content

Bump the python-dependencies group across 1 directory with 2 updates - #620

Merged
edmorley merged 2 commits into
mainfrom
dependabot/pip/python-dependencies-88dada5d40
Oct 1, 2026
Merged

edmorley merged 2 commits into
mainfrom
dependabot/pip/python-dependencies-88dada5d40

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the python-dependencies group with 2 updates in the / directory: poetry and uv.

Updates poetry from 2.4.2 to 2.5.1

Release notes

Sourced from poetry's releases.

2.5.1

Fixed

  • Fix an issue where uninstalling a package with installer.builtin-uninstall set failed with a TypeError (#11077).

2.5.0

Added

  • Add an installer.builtin-uninstall setting to uninstall packages with a built-in uninstaller instead of invoking pip uninstall (#10931).
  • Add official support for Python 3.15 (#11046).

Changed

  • Do not send credentials configured for an https repository via http (#11073).
  • Fail with an error when the current Python version is not compatible with the project and virtualenvs.create is false (#10941).
  • Validate version constraints that are entered interactively in poetry init (#10909).
  • Include the path of the pyproject.toml file in the message about already present packages in poetry add (#10908).
  • Improve performance of processing package links and repository pages (#10895, #10896, #10903, #10949, #10951, #10953).
  • Improve performance of dependency resolution (#10907, #10954).
  • Improve performance of choosing and installing wheels (#10905, #10958).
  • Improve performance by avoiding redundant keyring lookups for repositories without credentials (#10959).
  • Improve performance by reducing the number of subprocesses to discover virtual environment data (#11042).
  • Improve performance of poetry search for single-token queries (#10906).
  • Improve startup time by deferring the import of requests (#11004).
  • Improve performance of schema validation by caching compiled JSON schema validators (#11033).

Fixed

  • Fix an issue where credentials of the wrong repository were used under certain circumstances when multiple repositories were configured on the same host (#11072).
  • Fix an issue where credentials of a repository on another host were used for git dependencies if the path of the URL was the same (#11074).
  • Fix an issue where dependency resolution failed for conflicting requirements of different packages even though the requirements had mutually exclusive markers (#10944).
  • Fix an issue where dependency resolution failed when the same package was required with different extras in several optional dependencies or dependency groups (#10943).
  • Fix an issue where dependency resolution failed with a KeyError (#11008).
  • Fix an issue where the dependencies of an extra were missing in the lock file after adding the extra to a locked dependency, e.g. a git dependency, in the pyproject.toml file (#10987).
  • Fix an issue where a path or git dependency was not reinstalled when its develop setting changed (#11022).
  • Fix an issue where scripts of type file were not installed when installing the project (#10736).
  • Fix an issue where GUI scripts were not installed when installing the project (#10973).
  • Fix an issue where a relative path was written to direct_url.json for path dependencies (#10917).
  • Fix an issue where poetry show <package> showed a version that was not relevant for the current environment if there were multiple versions of the package in the lock file (#11003).
  • Fix an issue where poetry show --outdated did not find newer versions of packages from sources with explicit priority (#10982).
  • Fix an issue where poetry env activate ignored the environment that was determined by the application, e.g. when using --directory (#10916).
  • Fix an issue where poetry init proposed an invalid package name if the directory name was not a valid package name (#10975).

Docs

  • Document the --license option of poetry init and poetry new (#11064).
  • Clarify which dependencies are locked when running poetry update with dependency groups (#11024).
  • Clarify the portability of path dependencies (#11020).
  • Clarify the usage of poetry run with console scripts (#10984).

... (truncated)

Changelog

Sourced from poetry's changelog.

[2.5.1] - 2026-09-20

Fixed

  • Fix an issue where uninstalling a package with installer.builtin-uninstall set failed with a TypeError (#11077).

[2.5.0] - 2026-09-19

Added

  • Add an installer.builtin-uninstall setting to uninstall packages with a built-in uninstaller instead of invoking pip uninstall (#10931).
  • Add official support for Python 3.15 (#11046).

Changed

  • Do not send credentials configured for an https repository via http (#11073).
  • Fail with an error when the current Python version is not compatible with the project and virtualenvs.create is false (#10941).
  • Validate version constraints that are entered interactively in poetry init (#10909).
  • Include the path of the pyproject.toml file in the message about already present packages in poetry add (#10908).
  • Improve performance of processing package links and repository pages (#10895, #10896, #10903, #10949, #10951, #10953).
  • Improve performance of dependency resolution (#10907, #10954).
  • Improve performance of choosing and installing wheels (#10905, #10958).
  • Improve performance by avoiding redundant keyring lookups for repositories without credentials (#10959).
  • Improve performance by reducing the number of subprocesses to discover virtual environment data (#11042).
  • Improve performance of poetry search for single-token queries (#10906).
  • Improve startup time by deferring the import of requests (#11004).
  • Improve performance of schema validation by caching compiled JSON schema validators (#11033).

Fixed

  • Fix an issue where credentials of the wrong repository were used under certain circumstances when multiple repositories were configured on the same host (#11072).
  • Fix an issue where credentials of a repository on another host were used for git dependencies if the path of the URL was the same (#11074).
  • Fix an issue where dependency resolution failed for conflicting requirements of different packages even though the requirements had mutually exclusive markers (#10944).
  • Fix an issue where dependency resolution failed when the same package was required with different extras in several optional dependencies or dependency groups (#10943).
  • Fix an issue where dependency resolution failed with a KeyError (#11008).
  • Fix an issue where the dependencies of an extra were missing in the lock file after adding the extra to a locked dependency, e.g. a git dependency, in the pyproject.toml file (#10987).
  • Fix an issue where a path or git dependency was not reinstalled when its develop setting changed (#11022).
  • Fix an issue where scripts of type file were not installed when installing the project (#10736).
  • Fix an issue where GUI scripts were not installed when installing the project (#10973).
  • Fix an issue where a relative path was written to direct_url.json for path dependencies (#10917).
  • Fix an issue where poetry show <package> showed a version that was not relevant for the current environment if there were multiple versions of the package in the lock file (#11003).
  • Fix an issue where poetry show --outdated did not find newer versions of packages from sources with explicit priority (#10982).

... (truncated)

Commits
  • 94b6e35 release: bump version to 2.5.1
  • f8408ca fix TypeError when using installer.builtin-uninstall (#11077)
  • 165fb4b release: bump version to 2.5.0
  • c93fd63 update poetry-core (#10921)
  • 32356ae chore: update dependencies (#11075)
  • d266d45 test: accept compatible extension wheel tags (#11014)
  • c8790a3 add Python 3.15 to tests matrix (#11046)
  • a416efd authenticator: match host when looking up git credentials (#11074)
  • e078ebf authenticator: do not send credentials configured for https with http (#11073)
  • 8711c83 authenticator: sort candidates by common path segments instead of prefixes (#...
  • Additional commits viewable in compare view

Updates uv from 0.12.9 to 0.12.21

Release notes

Sourced from uv's releases.

0.12.21

Release Notes

Released on 2026-09-29.

Python

  • Update CPython to use OpenSSL 3.5.9 (#22076)

Enhancements

  • Omit empty [manifest] tables from lockfiles that contain only manifest subtables (#22070)

Preview features

  • Omit redundant runtime constraints from uv.lock, including those involving pre-releases, with the resolution-inputs preview feature (#22004, #22068)

Bug fixes

  • Prevent uv python pin --rm from removing a global .python-versions file without --global (#21992)
  • Fix installed-package checks incorrectly reporting post-releases as incompatible with exclusive lower bounds on pre-releases (#22049)

Install uv 0.12.21

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.21/uv-installer.sh | sh

Install prebuilt binaries via powershell script

powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.21/uv-installer.ps1 | iex"

Download uv 0.12.21

File Platform Checksum
uv-aarch64-apple-darwin.tar.gz Apple Silicon macOS checksum
uv-x86_64-apple-darwin.tar.gz Intel macOS checksum
uv-aarch64-pc-windows-msvc.zip ARM64 Windows checksum
uv-i686-pc-windows-msvc.zip x86 Windows checksum
uv-x86_64-pc-windows-msvc.zip x64 Windows checksum
uv-aarch64-unknown-linux-gnu.tar.gz ARM64 Linux checksum
uv-i686-unknown-linux-gnu.tar.gz x86 Linux checksum
uv-powerpc64le-unknown-linux-gnu.tar.gz PPC64LE Linux checksum
uv-riscv64gc-unknown-linux-gnu.tar.gz RISCV Linux checksum
uv-s390x-unknown-linux-gnu.tar.gz S390x Linux checksum

... (truncated)

Changelog

Sourced from uv's changelog.

0.12.21

Released on 2026-09-29.

Python

  • Update CPython to use OpenSSL 3.5.9 (#22076)

Enhancements

  • Omit empty [manifest] tables from lockfiles that contain only manifest subtables (#22070)

Preview features

  • Omit redundant runtime constraints from uv.lock, including those involving pre-releases, with the resolution-inputs preview feature (#22004, #22068)

Bug fixes

  • Prevent uv python pin --rm from removing a global .python-versions file without --global (#21992)
  • Fix installed-package checks incorrectly reporting post-releases as incompatible with exclusive lower bounds on pre-releases (#22049)

0.12.20

Released on 2026-09-28.

Enhancements

  • Reuse lockfiles when dependency declarations are semantically equivalent (#21951)
  • Preserve second-line encoding declarations when installing wheel scripts with CRLF shebangs (#21990)

Preview features

  • Write normalized requirement declarations with the lockfile-normalization preview feature (#21951)
  • Honor synthetic default groups when installing or syncing from pylock.toml (#22003)
  • Resolve local paths in exported pylock.toml files relative to the output file (#22042)
  • Install each package only once when repeated tool-install-locks requirements resolve to the same package (#22000)
  • Reuse lock-without-metadata lockfiles for conflicting groups with distinct base and extra requirement specifiers (#22055)
  • Use consistent root-package paths in uv workspace metadata and uv tree --format json output (#22050)

Configuration

  • Continue searching XDG_CONFIG_DIRS after empty entries (#21987)

Performance

  • Restore the previous HTTP cache-write scheduling while investigating severe cache-revalidation stalls on ext4 filesystems (#22051)

Bug fixes

  • Apply hash constraints to every repeated requirement under --require-hashes and --verify-hashes (#21996)

... (truncated)

Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Dependabot PRs that update Python dependencies labels Oct 1, 2026
@dependabot
dependabot Bot requested a review from edmorley as a code owner October 1, 2026 13:13
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Dependabot PRs that update Python dependencies labels Oct 1, 2026
@edmorley

edmorley commented Oct 1, 2026

Copy link
Copy Markdown
Member

@dependabot recreate

@dependabot dependabot Bot changed the title Bump the python-dependencies group with 2 updates Bump the python-dependencies group across 1 directory with 2 updates Oct 1, 2026
@dependabot
dependabot Bot force-pushed the dependabot/pip/python-dependencies-88dada5d40 branch from 8ebda7b to 2c536b6 Compare October 1, 2026 13:36
@edmorley

edmorley commented Oct 1, 2026

Copy link
Copy Markdown
Member

@dependabot rebase

Bumps the python-dependencies group with 2 updates in the / directory: [poetry](https://github.com/python-poetry/poetry) and [uv](https://github.com/astral-sh/uv).


Updates `poetry` from 2.4.2 to 2.5.1
- [Release notes](https://github.com/python-poetry/poetry/releases)
- [Changelog](https://github.com/python-poetry/poetry/blob/main/CHANGELOG.md)
- [Commits](python-poetry/poetry@2.4.2...2.5.1)

Updates `uv` from 0.12.9 to 0.12.21
- [Release notes](https://github.com/astral-sh/uv/releases)
- [Changelog](https://github.com/astral-sh/uv/blob/main/CHANGELOG.md)
- [Commits](astral-sh/uv@0.12.9...0.12.21)

---
updated-dependencies:
- dependency-name: poetry
  dependency-version: 2.5.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-dependencies
- dependency-name: uv
  dependency-version: 0.12.21
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/pip/python-dependencies-88dada5d40 branch from 2c536b6 to 60b20a2 Compare October 1, 2026 20:40
@edmorley
edmorley merged commit 4ae57f9 into main Oct 1, 2026
13 checks passed
@edmorley
edmorley deleted the dependabot/pip/python-dependencies-88dada5d40 branch October 1, 2026 21:01
@heroku-linguist heroku-linguist Bot mentioned this pull request Oct 2, 2026
edmorley pushed a commit that referenced this pull request Oct 2, 2026
## heroku/python

### Changed

- Updated Poetry from 2.4.2 to 2.5.1. ([#620](#620))
- Updated uv from 0.12.9 to 0.12.21. ([#620](#620))

Co-authored-by: heroku-linguist[bot] <136119646+heroku-linguist[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Dependabot PRs that update Python dependencies

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant