Skip to content

Bump the python group across 1 directory with 5 updates - #3721

Merged
lorengordon merged 2 commits into
mainfrom
dependabot/pip/python-a6c398512a
Aug 11, 2026
Merged

Bump the python group across 1 directory with 5 updates#3721
lorengordon merged 2 commits into
mainfrom
dependabot/pip/python-a6c398512a

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 3, 2026

Copy link
Copy Markdown
Contributor

Updates the requirements on uv-build, ruff, twine, uv and boto3 to permit the latest version.
Updates uv-build to 0.12.2

Release notes

Sourced from uv-build's releases.

0.12.2

Release Notes

Released on 2026-08-05.

Python

  • Add CPython 3.15.0rc1 (#20948)
  • Add CPython 3.14.7 (#20971)

Enhancements

  • Ensure diagnostic hints end with a newline to prevent malformed terminal output (#20959)

Preview features

  • Audit one or all installed tools with uv tool audit (#20921)
  • Report physically reclaimed disk space during cache cleanup with the cache-physical-space preview feature (#20925)

Configuration

  • Add UV_RUN_RLIMIT_NOFILE to set the open-file limit for commands launched by uv run (#20926)

Performance

  • Speed up uv.lock parsing for wheel entries (#20881)
  • Speed up uv.lock parsing for source distribution entries (#20882)
  • Speed up filename extraction from distribution URLs (#20879)
  • Reduce filesystem metadata lookups during bytecode compilation (#20928)
  • Reuse file metadata when building source distributions (#20927)

Bug fixes

  • Preserve compatibility with older uv versions when recording artifact sizes in cached wheels and source distributions (#20963)
  • Avoid including workspace-root default dependency groups when syncing or exporting a selected workspace member unless explicitly requested (#20930)

Documentation

  • Separate build and publish jobs in the GitHub Actions publishing guide (#20946)
  • Ensure the GitHub Actions publishing example waits for the build job to finish (#20957)
  • Correct typos in the Docker integration guide (#20970)

Install uv 0.12.2

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.2/uv-installer.sh | sh

... (truncated)

Changelog

Sourced from uv-build's changelog.

0.12.2

Released on 2026-08-05.

Python

  • Add CPython 3.15.0rc1 (#20948)
  • Add CPython 3.14.7 (#20971)

Enhancements

  • Ensure diagnostic hints end with a newline to prevent malformed terminal output (#20959)

Preview features

  • Audit one or all installed tools with uv tool audit (#20921)
  • Report physically reclaimed disk space during cache cleanup with the cache-physical-space preview feature (#20925)

Configuration

  • Add UV_RUN_RLIMIT_NOFILE to set the open-file limit for commands launched by uv run (#20926)

Performance

  • Speed up uv.lock parsing for wheel entries (#20881)
  • Speed up uv.lock parsing for source distribution entries (#20882)
  • Speed up filename extraction from distribution URLs (#20879)
  • Reduce filesystem metadata lookups during bytecode compilation (#20928)
  • Reuse file metadata when building source distributions (#20927)

Bug fixes

  • Preserve compatibility with older uv versions when recording artifact sizes in cached wheels and source distributions (#20963)
  • Avoid including workspace-root default dependency groups when syncing or exporting a selected workspace member unless explicitly requested (#20930)

Documentation

  • Separate build and publish jobs in the GitHub Actions publishing guide (#20946)
  • Ensure the GitHub Actions publishing example waits for the build job to finish (#20957)
  • Correct typos in the Docker integration guide (#20970)

0.12.1

Released on 2026-07-31.

Enhancements

  • Add package-specific pre-release policies with --prerelease-package (#20837)
  • Support local HTML files as flat indexes (#20802)
  • Add Xonsh virtual environment activation scripts (activate.xsh) (#19740)

... (truncated)

Commits

Updates ruff from 0.15.22 to 0.16.1

Release notes

Sourced from ruff's releases.

0.16.1

Release Notes

Released on 2026-07-30.

Preview features

  • Add an option to opt out of human-readable names (#27160)
  • [flake8-pytest-style] Make fixes safe by default and unsafe only when comments are present (PT018) (#27201)
  • [pyupgrade] Skip fix when a defaulted TypeVar precedes a non-defaulted one (UP040, UP046, UP047) (#27133)
  • [ruff] Fix false positive with unpacked arguments (RUF065) (#26959)

Bug fixes

  • Bump gen-lsp-types to gracefully handle unknown enumeration values in LSP messages (#27230)
  • [flake8-bugbear] Mark range as immutable (B008) (#27247)
  • [flake8-comprehensions] NFKC-normalize keyword names in C408 fix (#26813)
  • [flake8-return] Fix false positive when variable is read in finally clause (RET504) (#25441)
  • [pydocstyle] Skip section detection inside RST directive bodies (D214, D405, D413) (#23635)
  • [refurb] Parenthesize yield arguments in the FURB192 fix (#27192)

Rule changes

  • [flake8-pytest-style] Mark PT022 fixes as unsafe (#26440)
  • [refurb] Mark fixes that remove unknown separators as unsafe (FURB105) (#27200)

Server

  • Fix indexing of excluded nested Ruff workspaces (#27303)
  • Lint TOML files in the LSP (#26862)

Documentation

  • Cover pycon Markdown formatting (#27153)
  • [flake8-bandit] Document TYPE_CHECKING exception (S101) (#27004)
  • [flake8-import-conventions] Document that extend-aliases can override default aliases (#27191)
  • [pylint] Add missing fix safety gotchas for non-augmented-assignment (PLR6104) (#27250)

Other changes

  • Reduce syntax error noise by swallowing dedents like indents (#27170)
  • Vendor latest annotate-snippets (#27033)

Contributors

... (truncated)

Changelog

Sourced from ruff's changelog.

0.16.1

Released on 2026-07-30.

Preview features

  • Add an option to opt out of human-readable names (#27160)
  • [flake8-pytest-style] Make fixes safe by default and unsafe only when comments are present (PT018) (#27201)
  • [pyupgrade] Skip fix when a defaulted TypeVar precedes a non-defaulted one (UP040, UP046, UP047) (#27133)
  • [ruff] Fix false positive with unpacked arguments (RUF065) (#26959)

Bug fixes

  • Bump gen-lsp-types to gracefully handle unknown enumeration values in LSP messages (#27230)
  • [flake8-bugbear] Mark range as immutable (B008) (#27247)
  • [flake8-comprehensions] NFKC-normalize keyword names in C408 fix (#26813)
  • [flake8-return] Fix false positive when variable is read in finally clause (RET504) (#25441)
  • [pydocstyle] Skip section detection inside RST directive bodies (D214, D405, D413) (#23635)
  • [refurb] Parenthesize yield arguments in the FURB192 fix (#27192)

Rule changes

  • [flake8-pytest-style] Mark PT022 fixes as unsafe (#26440)
  • [refurb] Mark fixes that remove unknown separators as unsafe (FURB105) (#27200)

Server

  • Fix indexing of excluded nested Ruff workspaces (#27303)
  • Lint TOML files in the LSP (#26862)

Documentation

  • Cover pycon Markdown formatting (#27153)
  • [flake8-bandit] Document TYPE_CHECKING exception (S101) (#27004)
  • [flake8-import-conventions] Document that extend-aliases can override default aliases (#27191)
  • [pylint] Add missing fix safety gotchas for non-augmented-assignment (PLR6104) (#27250)

Other changes

  • Reduce syntax error noise by swallowing dedents like indents (#27170)
  • Vendor latest annotate-snippets (#27033)

Contributors

... (truncated)

Commits
  • 80790b3 Bump 0.16.1 (#27330)
  • 63830f3 [ty] Borrow from constraint set storage less often (#27328)
  • f40dca9 [ty] Preserve forwarded expanded-variadic diagnostic sources (#27266)
  • 0d80497 Lint TOML files in the LSP (#26862)
  • d91586b Update prek dependencies (#27293)
  • 7da4b8b [ty] Respect bounds and constraints in generic materializations (#27228)
  • b20daf7 [ty] refactor: add helper function to send partial results (#27249)
  • 4d4c8fa [ty] Emit diagnostic when specializing a non-generic class (#26883)
  • 7c3e2db [ty] Fix enum class container assignability (#27318)
  • d5ef97f [flake8-return] Fix false positive when variable is read in finally claus...
  • Additional commits viewable in compare view

Updates twine from 6.2.0 to 7.0.0

Changelog

Sourced from twine's changelog.

twine 7.0.0 (2026-07-27)

Bugfixes ^^^^^^^^

  • Specify UTF-8 encoding when reading .pypirc files. ([#1268](https://github.com/pypa/twine/issues/1268) <https://github.com/pypa/twine/issues/1268>_)
  • Add missing subdependencies to --version output. ([#1275](https://github.com/pypa/twine/issues/1275) <https://github.com/pypa/twine/issues/1275>_)
  • The dependency on rich has been bumped to avoid a hang in some environments. ([#1308](https://github.com/pypa/twine/issues/1308) <https://github.com/pypa/twine/issues/1308>_)
  • Indices that respond with non-standard HTTP codes are now handled more gracefully. ([#1309](https://github.com/pypa/twine/issues/1309) <https://github.com/pypa/twine/issues/1309>_)

Deprecations and Removals ^^^^^^^^^^^^^^^^^^^^^^^^^

  • Fix uploading packages with metadata version 2.5. The fix no longer allows metadata version 2.0, which was never officially standardised. ([#1317](https://github.com/pypa/twine/issues/1317) <https://github.com/pypa/twine/issues/1317>_)

Misc ^^^^

  • [#1298](https://github.com/pypa/twine/issues/1298) <https://github.com/pypa/twine/issues/1298>_
Commits
  • fdb86cb Update changelog for 7.0.0 (#1344)
  • bfa7f7f changelog: backfill entries from PRs (#1330)
  • 4f20c0d Remove monkeypatch allowing Metadata 2.0 (#1317)
  • 1df249e build(deps): bump github/codeql-action from 4.35.2 to 4.35.3 (#1318)
  • bea9607 fix: bump minimum rich dependency to 14.3.3 to prevent verbose hang (#1308)
  • ac17a17 build(deps): bump actions/upload-artifact from 7.0.0 to 7.0.1 (#1311)
  • 039cedf build(deps): bump github/codeql-action from 4.35.1 to 4.35.2 (#1313)
  • d465cb0 Handle non-standard HTTP status codes (#1309)
  • cab618f Bump packaging >= 26.1 (#1310)
  • 2d06e11 build(deps): bump pypa/gh-action-pypi-publish from 1.13.0 to 1.14.0 (#1307)
  • Additional commits viewable in compare view

Updates uv from 0.11.29 to 0.12.2

Release notes

Sourced from uv's releases.

0.12.2

Release Notes

Released on 2026-08-05.

Python

  • Add CPython 3.15.0rc1 (#20948)
  • Add CPython 3.14.7 (#20971)

Enhancements

  • Ensure diagnostic hints end with a newline to prevent malformed terminal output (#20959)

Preview features

  • Audit one or all installed tools with uv tool audit (#20921)
  • Report physically reclaimed disk space during cache cleanup with the cache-physical-space preview feature (#20925)

Configuration

  • Add UV_RUN_RLIMIT_NOFILE to set the open-file limit for commands launched by uv run (#20926)

Performance

  • Speed up uv.lock parsing for wheel entries (#20881)
  • Speed up uv.lock parsing for source distribution entries (#20882)
  • Speed up filename extraction from distribution URLs (#20879)
  • Reduce filesystem metadata lookups during bytecode compilation (#20928)
  • Reuse file metadata when building source distributions (#20927)

Bug fixes

  • Preserve compatibility with older uv versions when recording artifact sizes in cached wheels and source distributions (#20963)
  • Avoid including workspace-root default dependency groups when syncing or exporting a selected workspace member unless explicitly requested (#20930)

Documentation

  • Separate build and publish jobs in the GitHub Actions publishing guide (#20946)
  • Ensure the GitHub Actions publishing example waits for the build job to finish (#20957)
  • Correct typos in the Docker integration guide (#20970)

Install uv 0.12.2

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.2/uv-installer.sh | sh

... (truncated)

Changelog

Sourced from uv's changelog.

0.12.2

Released on 2026-08-05.

Python

  • Add CPython 3.15.0rc1 (#20948)
  • Add CPython 3.14.7 (#20971)

Enhancements

  • Ensure diagnostic hints end with a newline to prevent malformed terminal output (#20959)

Preview features

  • Audit one or all installed tools with uv tool audit (#20921)
  • Report physically reclaimed disk space during cache cleanup with the cache-physical-space preview feature (#20925)

Configuration

  • Add UV_RUN_RLIMIT_NOFILE to set the open-file limit for commands launched by uv run (#20926)

Performance

  • Speed up uv.lock parsing for wheel entries (#20881)
  • Speed up uv.lock parsing for source distribution entries (#20882)
  • Speed up filename extraction from distribution URLs (#20879)
  • Reduce filesystem metadata lookups during bytecode compilation (#20928)
  • Reuse file metadata when building source distributions (#20927)

Bug fixes

  • Preserve compatibility with older uv versions when recording artifact sizes in cached wheels and source distributions (#20963)
  • Avoid including workspace-root default dependency groups when syncing or exporting a selected workspace member unless explicitly requested (#20930)

Documentation

  • Separate build and publish jobs in the GitHub Actions publishing guide (#20946)
  • Ensure the GitHub Actions publishing example waits for the build job to finish (#20957)
  • Correct typos in the Docker integration guide (#20970)

0.12.1

Released on 2026-07-31.

Enhancements

  • Add package-specific pre-release policies with --prerelease-package (#20837)
  • Support local HTML files as flat indexes (#20802)
  • Add Xonsh virtual environment activation scripts (activate.xsh) (#19740)

... (truncated)

Commits

Updates boto3 from 1.43.51 to 1.43.66

Commits
  • f53e30a Merge branch 'release-1.43.66'
  • 7ac6cf8 Bumping version to 1.43.66
  • c69aee1 Add changelog entries from botocore
  • b74eb20 Merge branch 'release-1.43.65'
  • 75469d6 Merge branch 'release-1.43.65' into develop
  • d25fa39 Bumping version to 1.43.65
  • 6081dfd Add changelog entries from botocore
  • 06a2e1b Merge branch 'release-1.43.64'
  • c7b4afa Merge branch 'release-1.43.64' into develop
  • f2f83e3 Bumping version to 1.43.64
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update Python code labels Aug 3, 2026
mergify[bot]
mergify Bot previously approved these changes Aug 3, 2026
Updates the requirements on [uv-build](https://github.com/astral-sh/uv), [ruff](https://github.com/astral-sh/ruff), [twine](https://github.com/pypa/twine), [uv](https://github.com/astral-sh/uv) and [boto3](https://github.com/boto/boto3) to permit the latest version.

Updates `uv-build` to 0.12.2
- [Release notes](https://github.com/astral-sh/uv/releases)
- [Changelog](https://github.com/astral-sh/uv/blob/main/CHANGELOG.md)
- [Commits](astral-sh/uv@0.0.5...0.12.2)

Updates `ruff` from 0.15.22 to 0.16.1
- [Release notes](https://github.com/astral-sh/ruff/releases)
- [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md)
- [Commits](astral-sh/ruff@0.15.22...0.16.1)

Updates `twine` from 6.2.0 to 7.0.0
- [Release notes](https://github.com/pypa/twine/releases)
- [Changelog](https://github.com/pypa/twine/blob/main/docs/changelog.rst)
- [Commits](pypa/twine@6.2.0...7.0.0)

Updates `uv` from 0.11.29 to 0.12.2
- [Release notes](https://github.com/astral-sh/uv/releases)
- [Changelog](https://github.com/astral-sh/uv/blob/main/CHANGELOG.md)
- [Commits](astral-sh/uv@0.11.29...0.12.2)

Updates `boto3` from 1.43.51 to 1.43.66
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](boto/boto3@1.43.51...1.43.66)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.61
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python
- dependency-name: ruff
  dependency-version: 0.16.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python
- dependency-name: twine
  dependency-version: 7.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: python
- dependency-name: uv
  dependency-version: 0.12.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python
- dependency-name: uv-build
  dependency-version: 0.12.0
  dependency-type: direct:development
  dependency-group: python
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/pip/python-a6c398512a branch from e4edeee to 06b7da1 Compare August 10, 2026 12:24
@lorengordon
lorengordon merged commit ae7a3df into main Aug 11, 2026
35 checks passed
@lorengordon
lorengordon deleted the dependabot/pip/python-a6c398512a branch August 11, 2026 21:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update Python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant