Skip to content

chore(deps): bump the python-dependencies group across 1 directory with 3 updates - #758

Merged
ian-flores merged 1 commit into
mainfrom
dependabot/uv/python-dependencies-9c182833f6
Oct 2, 2026
Merged

ian-flores merged 1 commit into
mainfrom
dependabot/uv/python-dependencies-9c182833f6

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown
Contributor

Bumps the python-dependencies group with 3 updates in the / directory: filelock, mako and ruff.

Updates filelock from 4.0.0 to 4.0.3

Release notes

Sourced from filelock's releases.

4.0.3

What's Changed

Full Changelog: tox-dev/filelock@4.0.2...4.0.3

4.0.2

What's Changed

New Contributors

Full Changelog: tox-dev/filelock@4.0.1...4.0.2

4.0.1

What's Changed

New Contributors

Full Changelog: tox-dev/filelock@4.0.0...4.0.1

Changelog

Sourced from filelock's changelog.

########### Changelog ###########

.. towncrier-draft-entries:: Unreleased

.. towncrier release notes start


4.0.9 (2026-10-01)


  • ReadWriteLock and AsyncReadWriteLock close the descriptor that checks the database path once SQLite has connected, so on PyPy a dropped lock leaves no descriptor open until garbage collection runs. :pr:763
  • ReadWriteLock and AsyncReadWriteLock refuse a symlink at the database path instead of following it, so a user who can create names in a shared lock directory cannot point the lock at another file (GHSA-j8f7-rjxc-mr56).

4.0.8 (2026-10-01)


  • ReadWriteLock.release() and SoftReadWriteLock.release() from a thread that does not hold the write lock now raise RuntimeError instead of dropping the holder's lock and letting a second writer in. :pr:761

4.0.7 (2026-09-29)


  • File locks now raise ValueError at construction when mode denies the owner read or write, such as mode=0o444, instead of failing on a later acquire and staying broken until someone deletes the lock file. :pr:760

4.0.6 (2026-09-28)


  • Reject negative blocking timeouts other than -1 before reentrant ReadWriteLock and SoftReadWriteLock acquisition. Preserve unlimited waits and nonblocking acquisition. :pr:756

4.0.5 (2026-09-28)


  • Fix MarkerSoftFileLock acquisition and prevent contenders from evicting live protocol-2 owners after two seconds. Reclaim recognized records after owner death; preserve unknown contracts. :pr:749
  • Honor instance timeout and blocking settings in sync and async ReadWriteLock acquisition, including waits between tasks on one instance. Preserve explicit per-call overrides. :pr:750
  • Skip access-denial checks when the process can read mode-0o000 files. Keep mode-bit checks enabled for privileged processes on filesystems that support POSIX permissions. :pr:753
  • Skip vanished StrictSoftFileLock claims after a read-permission retry expires. Recheck the directory before raising a protocol error so concurrent removal does not turn a stale claim listing into an acquisition failure. :pr:754

... (truncated)

Commits
  • 5283806 Release 4.0.3
  • fd10e07 🐛 fix(api): skip the fork audit hook on CPython <3.12 (#747)
  • 2d4530f Release 4.0.2
  • 6c46312 🐛 fix(async-rw): give each task its own hold (#746)
  • fe0e99d 🐛 fix(api): serialize concurrent transitions on shared locks (#745)
  • b26beda build(deps): bump astral-sh/setup-uv from 10.0.1 to 10.1.0 in the github-acti...
  • 10572ec fix: ignore broken sphinx-llm release (#742)
  • 6c10af3 [pre-commit.ci] pre-commit autoupdate (#741)
  • 9380408 docs: create the data directory in the async cache example (#740)
  • b5016c4 Release 4.0.1
  • Additional commits viewable in compare view

Updates mako from 1.4.1 to 1.4.3

Release notes

Sourced from mako's releases.

1.4.3

Released: Tue Sep 22 2026

bug

  • [bug] [tests] Fixed regression caused in 1.4.2 where tests added to the suite were unable to run directly on Windows, due to posix mechanics: the tests force os.path to posixpath, whereas TemplateLookup.get_template() converts the configured directory using os.path.sep. These tests are now skipped on that platform, where the traversal check is instead exercised against ntpath natively.

    References: #441

1.4.2

Released: Tue Sep 22 2026

bug

  • [bug] [tests] Adjusted the test suite to accommodate for a change in Pygments 2.21.0 where the HtmlFormatter now renders " and ' characters literally rather than as HTML entities, which caused failures in tests that assert against the rendered output of html_error_template().

    References: #440

  • [bug] [template] Fixed issue in TemplateLookup where a URI beginning with a drive designator (e.g. C:/../../secret.txt) could bypass the directory traversal check on Windows, allowing reads of arbitrary files outside of the template directory. The check in Template normalized the URI using os.path, which on Windows is ntpath; as ntpath splits the drive designator off and treats the remainder as rooted, the .. segments were absorbed before the check could inspect them. Normalization is now performed with posixpath, which is the same module used by TemplateLookup.get_template() to resolve the URI to a file.

    References: #441

Commits

Updates ruff from 0.16.8 to 0.16.9

Release notes

Sourced from ruff's releases.

0.16.9

Release Notes

Released on 2026-09-24.

Preview features

  • [ruff] Avoid false positives for overloaded division (RUF069) (#28309)

Bug fixes

  • [flake8-bugbear] Avoid false positives for calls with keyword arguments (B009, B010, B043) (#28776)
  • [flake8-tidy-imports] Allow lazy imports to be used in deferred annotations (TID255) (#28767)

Rule changes

  • Update LibCST-based fixes for Python 3.15 (#28616)
  • [flake8-pyi] Mention stubs in the diagnostic message (PYI002) (#28542)

Documentation

  • Fix horizontal overflow on the rules documentation page (#28699)
  • Update rules table with category information (#28651)
  • [flake8-annotations] Clarify that ANN401 checks return types in addition to arguments (#28334)
  • [flake8-bugbear] Document type-checker interaction (B010) (#28509)
  • [flake8-comprehensions] Document map/generator exception behavior (C417) (#27794)
  • [ruff] Mention related isort settings (RUF022) (#28719)

Contributors

Install ruff 0.16.9

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/ruff/releases/download/0.16.9/ruff-installer.sh | sh

... (truncated)

Changelog

Sourced from ruff's changelog.

0.16.9

Released on 2026-09-24.

Preview features

  • [ruff] Avoid false positives for overloaded division (RUF069) (#28309)

Bug fixes

  • [flake8-bugbear] Avoid false positives for calls with keyword arguments (B009, B010, B043) (#28776)
  • [flake8-tidy-imports] Allow lazy imports to be used in deferred annotations (TID255) (#28767)

Rule changes

  • Update LibCST-based fixes for Python 3.15 (#28616)
  • [flake8-pyi] Mention stubs in the diagnostic message (PYI002) (#28542)

Documentation

  • Fix horizontal overflow on the rules documentation page (#28699)
  • Update rules table with category information (#28651)
  • [flake8-annotations] Clarify that ANN401 checks return types in addition to arguments (#28334)
  • [flake8-bugbear] Document type-checker interaction (B010) (#28509)
  • [flake8-comprehensions] Document map/generator exception behavior (C417) (#27794)
  • [ruff] Mention related isort settings (RUF022) (#28719)

Contributors

Commits
  • 0be08a2 Bump version to 0.16.9 (#28882)
  • b4920b7 Rename ruff_cli to ruff_command_line (#28881)
  • 47c751b Update dependency astral-sh/uv to v0.12.18 (#28880)
  • 8c244e5 [flake8-comprehensions] Document map/generator exception behavior (C417...
  • 5edf5a1 Use target form in rooster.version_files (#28876)
  • 915bb2b [ty] Prefer existing @ paths over response files in Ruff and ty (#28877)
  • 4710e1a ci(github): update version number in placeholder of issue template (#28871)
  • eedfc62 [ty] Propagate outer type context through cast calls (#28855)
  • ceaa6a0 [ty] Contain rendered code within Markdown fences (#28869)
  • dba0f30 authorize ruff-pre-commit dispatch via OIDC (#28867)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

…th 3 updates

Bumps the python-dependencies group with 3 updates in the / directory: [filelock](https://github.com/tox-dev/py-filelock), [mako](https://github.com/sqlalchemy/mako) and [ruff](https://github.com/astral-sh/ruff).


Updates `filelock` from 4.0.0 to 4.0.3
- [Release notes](https://github.com/tox-dev/py-filelock/releases)
- [Changelog](https://github.com/tox-dev/filelock/blob/main/docs/changelog.rst)
- [Commits](tox-dev/filelock@4.0.0...4.0.3)

Updates `mako` from 1.4.1 to 1.4.3
- [Release notes](https://github.com/sqlalchemy/mako/releases)
- [Changelog](https://github.com/sqlalchemy/mako/blob/main/CHANGES)
- [Commits](https://github.com/sqlalchemy/mako/commits)

Updates `ruff` from 0.16.8 to 0.16.9
- [Release notes](https://github.com/astral-sh/ruff/releases)
- [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md)
- [Commits](astral-sh/ruff@0.16.8...0.16.9)

---
updated-dependencies:
- dependency-name: filelock
  dependency-version: 4.0.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python-dependencies
- dependency-name: mako
  dependency-version: 1.4.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python-dependencies
- dependency-name: ruff
  dependency-version: 0.16.9
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels Oct 1, 2026
@dependabot
dependabot Bot requested review from ian-flores and statik as code owners October 1, 2026 23:22
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Oct 1, 2026
@dependabot
dependabot Bot requested a review from bdeitte as a code owner October 1, 2026 23:22
@dependabot dependabot Bot added the python:uv Pull requests that update python:uv code label Oct 1, 2026
@ian-flores
ian-flores merged commit 5ddcad8 into main Oct 2, 2026
48 checks passed
@ian-flores
ian-flores deleted the dependabot/uv/python-dependencies-9c182833f6 branch October 2, 2026 00:04
@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor
PR Preview Action v1.8.1
Preview removed because the pull request was closed.
2026-10-02 00:04 UTC

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant