Skip to content

deps: bump mypy from 2.3.0 to 2.3.1 - #42

Merged
helebest merged 2 commits into
mainfrom
dependabot/uv/mypy-2.3.1
Aug 24, 2026
Merged

deps: bump mypy from 2.3.0 to 2.3.1#42
helebest merged 2 commits into
mainfrom
dependabot/uv/mypy-2.3.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 24, 2026

Copy link
Copy Markdown
Contributor

Bumps mypy from 2.3.0 to 2.3.1.

Changelog

Sourced from mypy's changelog.

Mypy 2.3.1

  • Fix mypyc crash on double yielding Iterators (Daniël van Noord, PR 21826)
  • Fix mypyc default_factory for inherited dataclass (Daniël van Noord, PR 21785)
  • Clear mypyc coroutine env on coroutine completion (Piotr Sawicki, PR 21734)
  • Fix crash when unpacking return value from overload (Shantanu, PR 21830)

Acknowledgements

Thanks to all mypy contributors who contributed to this release:

  • Agriya Khetarpal
  • Ethan Sarp
  • Ivan Levkivskyi
  • Jingchen Ye
  • Jukka Lehtosalo
  • Piotr Sawicki
  • Shantanu
  • Tom Bannink
  • Viktor Szépe
  • ygale

I'd also like to thank my employer, Dropbox, for supporting mypy development.

Mypy 2.2

We've just uploaded mypy 2.2.0 to the Python Package Index (PyPI). Mypy is a static type checker for Python. This release includes new features, performance improvements and bug fixes. You can install it as follows:

python3 -m pip install -U mypy

You can read the full documentation for this release on Read the Docs.

Support for Closed TypedDicts (PEP 728)

Mypy now supports closed TypedDicts as specified in PEP 728. A closed TypedDict cannot have extra keys beyond those explicitly defined. This allows the type checker to determine that certain operations are safe when they otherwise wouldn't be due to the potential presence of unknown keys.

You can use the closed keyword argument with TypedDict:

HasName = TypedDict("HasName", {"name": str})
HasOnlyName = TypedDict("HasOnlyName", {"name": str}, closed=True)
Movie = TypedDict("Movie", {"name": str, "year": int})
movie: Movie = {"name": "Nimona", "year": 2023}
has_name: HasName = movie  # OK: HasName is open (default)
has_only_name: HasOnlyName = movie  # Error: HasOnlyName is closed and Movie has extra "year" key
</tr></table>

... (truncated)

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [mypy](https://github.com/python/mypy) from 2.3.0 to 2.3.1.
- [Changelog](https://github.com/python/mypy/blob/master/CHANGELOG.md)
- [Commits](python/mypy@v2.3.0...v2.3.1)

---
updated-dependencies:
- dependency-name: mypy
  dependency-version: 2.3.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Aug 24, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: deps. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

Copy link
Copy Markdown
Contributor

Automated review: deps: bump mypy from 2.3.0 to 2.3.1

Step 1 — Code review

  • Consistency: PR description matches the diff — the only change is uv.lock re-pinning mypy from 2.3.0 to 2.3.1 (sdist/wheel URLs + hashes, including new cp315/cp315t wheels published for this release). No other files touched.
  • Correctness: pyproject.toml already constrains mypy>=2.3.0, so 2.3.1 satisfies the existing range; no manifest change was needed.
  • Conventions: Matches repo convention of dependency bumps living in uv.lock only when the version range already covers the new version.
  • Security: Reviewed mypy 2.3.1's changelog — it's a pure bug-fix patch release (mypyc crash fixes for double-yielding iterators, inherited dataclass default_factory, coroutine env clearing, and an overload-unpacking crash). No CVEs or security advisories associated with this release, and no behavior change affects dikw-plugins since mypy is a dev-only type-checking tool, not a runtime dependency.
  • Effectiveness: Achieves its stated purpose — picks up the patch release.
  • Test coverage: N/A — dev-tooling version bump with no application code change; no new tests required.

Step 2 — Regression verification
Ran locally against the PR branch:

  • uv sync --all-packages — resolves cleanly, mypy==2.3.1 installed.
  • uv run mypy packages/*/srcSuccess: no issues found in 14 source files (strict mode, no new type errors surfaced under 2.3.1).
  • uv run pytest -q — full workspace suite passes (135 passed, 0 failed).

No regressions found.

Step 3 — CI
Monitoring the PR's CI checks until green.


Generated by Claude Code

Copy link
Copy Markdown
Contributor

Code Review — Step 1

Change: Bumps mypy from 2.3.0 → 2.3.1 in uv.lock only (patch release). No pyproject.toml changes — the existing constraint mypy>=2.3.0 already permits this version, so the lockfile-only diff is expected and correct.

  • Consistency: PR description (Dependabot changelog) matches the actual diff — only uv.lock hash/version/wheel-metadata entries for mypy changed. ✅
  • Correctness: This is a patch release fixing mypyc crashes (double-yielding iterators, default_factory on inherited dataclasses, coroutine env clearing, overload unpacking crash) — no typing-rule or API changes that would affect this project's type-checked source. ✅
  • Conventions: Follows the repo's dependency-bump pattern (lockfile-managed via uv, dev-only tool dependency). ✅
  • Security: No CVEs or security advisories associated with mypy 2.3.1; release notes are bug-fix only. ✅
  • Effectiveness: Achieves its stated purpose — updates the pinned dev tool. ✅
  • Test coverage: N/A — this is a dev-tooling dependency bump with no source code changes, so no new test cases are required.

Proceeding to regression verification (running the full test suite, mypy, and ruff locally against this branch).


Generated by Claude Code

Copy link
Copy Markdown
Contributor

Regression Verification — Step 2

Ran the full workspace test suite locally against this branch (head 71d30e0) with mypy 2.3.1 installed:

uv sync --frozen --all-packages
uv run pytest        # 134 passed in 48.28s
uv run mypy packages/*/src   # Success: no issues found in 14 source files
uv run ruff check .          # All checks passed!

No regressions — all tests pass, and mypy 2.3.1 reports zero new type errors across the workspace's source packages. Proceeding to CI monitoring.


Generated by Claude Code

@helebest
helebest merged commit d25d44c into main Aug 24, 2026
4 checks passed
@helebest
helebest deleted the dependabot/uv/mypy-2.3.1 branch August 24, 2026 23:19

Copy link
Copy Markdown
Contributor

Step 3 — CI: All checks passed on the up-to-date branch (CodeQL, analyze, test (3.12), test (3.13)). ✅

Step 4 — Merge: Squash-merged into main.


Generated by Claude Code

Copy link
Copy Markdown
Contributor

CI Monitoring — Step 3

Note: Dependabot rebased this PR onto main after PR #43 (ruff bump) merged, moving the head to 82e562b. Re-ran the full local verification (pytest/mypy/ruff) against the new head — results unchanged, still clean.

GitHub Actions checks on 82e562b, all green:

Check Result
test (3.12) ✅ success
test (3.13) ✅ success
analyze ✅ success
CodeQL ✅ success

All checks passed. Proceeding to squash merge.


Generated by Claude Code

Copy link
Copy Markdown
Contributor

Final Decision — Step 4

All gates passed:

  • ✅ Code review (consistency, correctness, conventions, security, effectiveness)
  • ✅ Regression verification (134 tests passed, mypy/ruff clean)
  • ✅ CI green on the rebased head

Squash-merged as d25d44c.


Generated by Claude Code

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant