Skip to content

chore(deps-dev): bump the dev-dependencies group with 2 updates - #73

Merged
eggplants merged 2 commits into
masterfrom
dependabot/uv/dev-dependencies-33a007cf4b
Oct 2, 2026
Merged

eggplants merged 2 commits into
masterfrom
dependabot/uv/dev-dependencies-33a007cf4b

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the dev-dependencies group with 2 updates: pymarkdownlnt and pyproject-fmt.

Updates pymarkdownlnt from 0.9.39 to 0.9.40

Release notes

Sourced from pymarkdownlnt's releases.

Version 0.9.40 - 2026-09-13

Following last release's focus on cementing our documentation and rule plugins, this release adds support for six missing rules and includes a complete overhaul of the rule plugin documentation. Reachable from the main Rules Page, each individual rule page now includes multiple examples that trigger the rule alongside examples that don't. Our team verified all of these by hand, and we'll continue updating them to keep them current. Please check out the new rules and documentation and let us know if you find any issues!

Added

  • Issue 1650
    • Rules for Md049 (consistent emphasis) and Md050 (consistent strong emphasis)
  • Issue 1652
    • Rule for Md051 (valid local link fragments)
  • Issue 1656
    • Rule for Md059 (descriptive-link-text)
  • Issue 1658
    • Rule for Md053 (link-image-reference-definitions)
  • Issue 1660
    • Rule for Md054 (link-image-style)
  • Issue 1669
    • Rule for Md060 (table-column-style)

Fixed

  • Issue 1639
    • extensions and plugins commands were not case insensitive
  • Issue 1684
    • Rule Plugin MD011 was not handling tables properly.
  • Issue 1685
    • Rule Plugin MD011 was not reporting reversed links properly on lines that have more than one link/reverse-link.
  • Issue 1686
    • Rule Plugin MD011 was not reporting multiple failures on the same line

Changed

  • Issue 1681
    • Extensive updating of Rule Plugins docs
Commits

Updates pyproject-fmt from 2.28.2 to 2.29.4

Release notes

Sourced from pyproject-fmt's releases.

pyproject-fmt/2.29.4

Fixed

  • Keep the classifiers a bound admits. (#463)

pyproject-fmt/2.29.3

Fixed

  • The test suite the source distribution ships passes from the unpacked sdist. The backend read the project metadata from beside itself, and the sdist keeps a copy of that file next to the tests, a directory below the pyproject.toml it belongs to, so eight tests ended on the file it could not find. It reads the metadata from either place. (#454, #457)

pyproject-fmt/2.29.2

Fixed

  • A build from the source distribution runs on what that distribution carries. 2.29.0 named toml-fmt-common as a dependency and resolved it from PyPI, where the newest release dates from May; 2.29.1 dropped the dependency before the sdist carried the sources, so a build from it failed on the import. This release carries them, and its metadata requires nothing. (#450, #452)

The wheels held their vendored copy throughout, so an install that takes a wheel was never affected.

pyproject-fmt/2.29.1

Fixed

  • The source distribution no longer names toml-fmt-common as a dependency. The newest release of that package on PyPI dates from May, months behind this one, so a build from the sdist ran an old settings reader against the current formatter and failed a large part of its own test suite. (#450, #451)

Known issue

  • This release's source distribution carries no toml-fmt-common, so a build from it fails on the import. 2.29.2 carries it. The wheels hold their vendored copy and install as before. (#452)

pyproject-fmt/2.29.0

Changed

  • A string measures from the start of its key. A long key can be what pushes a value past column_width; measuring the value alone left lines running past the column the setting asks for. (#448)
  • Deep input comes back as an error rather than a crash. Reading a value, writing it and dropping it each walk it by calling themselves, so the model caps nesting at 256 levels. A 12,000-deep value used to end the process. (#448)

Fixed

  • A requirement written with a space after its operator reads as a requirement. requires-python = ">= 3.12" did not parse as a version bound, so the generated classifiers fell back to the configured floor and ceiling. pypa/build carried a 3.9 classifier it does not support. (#448)
  • The classifier window works at patch precision. requires-python = "<3.10.1" lost the whole 3.10 series, and claimed Programming Language :: Python :: 3 :: Only for a bound that admits Python 2. (#448)
  • A literal string sorts with the values around it. 'zz' and 'aa' held their order while the same values in double quotes sorted. (#448)
  • A comment written before a member's comma stays on that member's line. The comma is what says which member a comment belongs to: one written before it closes that member's line, one written after it leads the next member. Both used to end up on a line of their own, leaving the comma stranded below. (#448)
  • classifiers written as a string stays as written. Asking for generated classifiers replaced the string with an array, losing what the file said. (#448)
  • Folding sub-tables into their parent no longer depends on the order the file wrote them in. (#448)
  • The key order covers pyrefly's documented option names. It spells them with hyphens, the order listed only the underscore forms, and a file using the documented spelling fell through to alphabetical order. (#448)
  • A dependency group keeps its include-group entries where the file wrote them. An include-group pulls its group in at the point it sits, so moving it changes what the group resolves to. (#448)
  • Free-form license text stays as written. license = "MIT or later" came back rewritten as though it were an SPDX expression; the formatter now rewrites the value only once it parses as one over registered identifiers. (#448)
  • The * catch-all in a setuptools data table matches the way the file spells it. * is not a name TOML reads bare, so a file writes it quoted; the catch-all led the table only because a quote happens to sort before a letter. (#448)

Performance

  • The quadratic walks the old parse tree forced are gone. 32,000 interleaved root keys under two tables took 618 seconds and now take 4.8; scaling is close to linear. (#448)

... (truncated)

Commits
  • 5c2c87c Release pyproject-fmt 2.29.4 [skip ci]
  • ed4af96 🐛 fix(pyproject-fmt): keep the classifiers a bound admits (#463)
  • 2946fc3 build(deps): bump taiki-e/install-action from 2.86.7 to 2.87.3 in the github-...
  • 95529cc [pre-commit.ci] pre-commit autoupdate (#461)
  • 7c729de ♻️ refactor(project): apply the house style (#459)
  • 77655bb Release tox-toml-fmt 1.10.3 [skip ci]
  • e6cbb18 Release pyproject-fmt 2.29.3 [skip ci]
  • 32f9e33 build(deps): bump taiki-e/install-action from 2.86.3 to 2.86.7 in the github-...
  • 2dfd00e Update Python dependencies (#455)
  • f1b5863 🐛 fix(build): read the project metadata from the sdist (#457)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Summary by cubic

Bumps the dev-dependencies group in uv.lock and adds the Python 3.15 classifier to pyproject.toml.

  • pymarkdownlnt 0.9.39 → 0.9.40 adds support for six new Markdown rules (Md049, Md050, Md051, Md053, Md054, Md059, Md060) and fixes MD011 reporting.
  • pyproject-fmt 2.28.2 → 2.29.4 fixes formatting edge cases and removes the quadratic parse-tree walks; it no longer depends on tomli for Python < 3.11.
  • Adds the Programming Language :: Python :: 3.15 classifier and fixes a resulting lint error.

Written for commit af4c4aa. Summary will update on new commits.

Review in cubic

Bumps the dev-dependencies group with 2 updates: [pymarkdownlnt](https://github.com/jackdewinter/pymarkdown) and [pyproject-fmt](https://github.com/tox-dev/toml-fmt).


Updates `pymarkdownlnt` from 0.9.39 to 0.9.40
- [Release notes](https://github.com/jackdewinter/pymarkdown/releases)
- [Changelog](https://github.com/jackdewinter/pymarkdown/blob/main/changelog.md)
- [Commits](jackdewinter/pymarkdown@v0.9.39...v0.9.40)

Updates `pyproject-fmt` from 2.28.2 to 2.29.4
- [Release notes](https://github.com/tox-dev/toml-fmt/releases)
- [Commits](tox-dev/toml-fmt@pyproject-fmt/2.28.2...pyproject-fmt/2.29.4)

---
updated-dependencies:
- dependency-name: pymarkdownlnt
  dependency-version: 0.9.40
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: dev-dependencies
- dependency-name: pyproject-fmt
  dependency-version: 2.29.4
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dev-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels Oct 1, 2026
@github-actions

github-actions Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

Coverage

Coverage Report
FileStmtsMissCoverMissing
__init__.py31584%34, 38–39, 45, 72
TOTAL31584% 

Tests Skipped Failures Errors Time
4 0 💤 0 ❌ 0 🔥 3.699s ⏱️

@eggplants
eggplants merged commit 260f296 into master Oct 2, 2026
7 checks passed
@dependabot
dependabot Bot deleted the dependabot/uv/dev-dependencies-33a007cf4b branch October 2, 2026 21:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant