Skip to content

Keep selenium/redis bumps, hold black & pylint for Python 3.9 - #3991

Merged
T4rk1n merged 3 commits into
devfrom
deps/pip-group-py39-hold-linters
Sep 21, 2026
Merged

T4rk1n merged 3 commits into
devfrom
deps/pip-group-py39-hold-linters

Conversation

@T4rk1n

@T4rk1n T4rk1n commented Sep 21, 2026

Copy link
Copy Markdown
Contributor

Supersedes #3990.

Problem

The Dependabot group in #3990 bumped four pip deps at once. It failed every Python 3.9 CI job at pip install (before any test ran):

ERROR: No matching distribution found for black==26.5.1; extra == "ci"

black==26.5.1 and pylint==4.0.8 both dropped Python 3.9 (they require >=3.10). Because they are exact == pins, pip cannot fall back to an older release, so the install aborts. Dash still supports and tests Python 3.9 (python_requires=">=3.9", 3.9 in the CI matrix).

Selenium was not the cause: its <=4.48.0 bump is a range cap, so pip resolves a 3.9-compatible build. That is why only the 3.9 jobs failed, and only at install. The redis <=8.1.0 bump is the same (resolves to redis 7.0.0 on 3.9).

Change

  • requirements/ci.txt: keep black==22.3.0 and pylint==3.0.3 (current versions). Bumping these to the latest releases would force a repo-wide reformat and new lint findings, and drops 3.9 support; that should be a deliberate change, not a Dependabot bump.
  • requirements/testing.txt / requirements/redis.txt: keep the selenium and redis cap bumps from Bump the pip-dependencies group with 4 updates #3990 (harmless on 3.9).
  • .github/dependabot.yml: ignore black >=25.12.0 and pylint >=4.0.0 (the first releases that require Python >=3.10) so they stop being re-proposed while Dash supports 3.9.

Notes

The ignore is scoped to the Python-3.10-only versions. It still permits a future bump to black 25.11.0 / pylint 3.3.9 (last 3.9-compatible releases), which would need a deliberate reformat / lint pass; broaden the ignore later if we want to hold the linters completely.

dependabot Bot and others added 2 commits September 21, 2026 16:48
Updates the requirements on [selenium](https://github.com/SeleniumHQ/Selenium), [black](https://github.com/psf/black), [pylint](https://github.com/pylint-dev/pylint) and [redis](https://github.com/redis/redis-py) to permit the latest version.

Updates `selenium` to 4.48.0
- [Release notes](https://github.com/SeleniumHQ/Selenium/releases)
- [Commits](SeleniumHQ/selenium@selenium-4.11.0...selenium-4.48.0)

Updates `black` from 22.3.0 to 26.5.1
- [Release notes](https://github.com/psf/black/releases)
- [Changelog](https://github.com/psf/black/blob/main/CHANGES.md)
- [Commits](psf/black@22.3.0...26.5.1)

Updates `pylint` from 3.0.3 to 4.0.8
- [Release notes](https://github.com/pylint-dev/pylint/releases)
- [Commits](pylint-dev/pylint@v3.0.3...v4.0.8)

Updates `redis` to 8.1.0
- [Release notes](https://github.com/redis/redis-py/releases)
- [Changelog](https://github.com/redis/redis-py/blob/master/CHANGES)
- [Commits](redis/redis-py@3.5.3...v8.1.0)

---
updated-dependencies:
- dependency-name: selenium
  dependency-version: 4.48.0
  dependency-type: direct:production
  dependency-group: pip-dependencies
- dependency-name: black
  dependency-version: 26.5.1
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: pip-dependencies
- dependency-name: pylint
  dependency-version: 4.0.8
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: pip-dependencies
- dependency-name: redis
  dependency-version: 8.1.0
  dependency-type: direct:production
  dependency-group: pip-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
The Dependabot group bumped black to 26.5.1 and pylint to 4.0.8, both of
which require Python >=3.10 and cannot install on the Python 3.9 CI jobs
(Dash still supports 3.9), so every 3.9 job failed at pip install. Revert
those two pins to their current versions and keep the selenium and redis
range-cap bumps, which resolve to 3.9-compatible builds. Add a Dependabot
ignore so the py3.10-only black/pylint versions stop being re-proposed.
@sonarqubecloud

Copy link
Copy Markdown

@T4rk1n
T4rk1n merged commit c426abd into dev Sep 21, 2026
107 of 113 checks passed
@T4rk1n
T4rk1n deleted the deps/pip-group-py39-hold-linters branch September 21, 2026 20:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant