Skip to content

chore(deps-dev): bump the python-deps group across 1 directory with 4 updates - #36

Merged
wlix13 merged 1 commit into
mainfrom
dependabot/uv/python-deps-ae88ef595c
Oct 1, 2026
Merged

wlix13 merged 1 commit into
mainfrom
dependabot/uv/python-deps-ae88ef595c

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the python-deps group with 4 updates in the / directory: prek, ruff, ty and zensical.

Updates prek from 0.5.3 to 0.5.4

Release notes

Sourced from prek's releases.

0.5.4

Release Notes

Released on 2026-09-28.

Highlights

Faster builtin hooks

In our end-to-end benchmark, prek is about 38% faster than 0.5.3, with some builtin hooks up to 273% faster (check-yaml: 273%, check-json: 80%, check-merge-conflict: 71%).

Enhancements

  • Add include_deleted to allow hooks to include deleted files (#2733)
  • Add --check and simplify end-of-file-fixer (#2764)
  • Add --check to file-contents-sorter (#2765)
  • Add --check to requirements-txt-fixer (#2766)
  • Add --check to trailing-whitespace (#2763)
  • Expose and document prek util generate-shell-completion (#2727)
  • Support hide_status in project and user configuration (#2760)
  • Support look-around regex in builtin pattern hooks (#2732)

Performance

  • Cache the resolved Git executable on macOS (#2726)
  • Combine and cache Git repository path queries (#2724)
  • Optimize common builtin hook execution (#2768)
  • Optimize scanning in mixed-line-ending and trailing-whitespace (#2769)
  • Scan check-merge-conflict files in fixed-size blocks (#2781)
  • Use SIMD UTF-8 validation in check-json, check-toml, and check-yaml (#2770)

Bug fixes

  • Retry transient rename failures on Windows (#2756)
  • Use PATH to resolve prek in completion scripts (#2719)

Documentation

  • Clarify the flow and scope of usage guides (#2710)
  • Reorganize usage guides and reference documentation (#2709)

Other changes

  • Sync latest identify tags (#2762)

Contributors

... (truncated)

Changelog

Sourced from prek's changelog.

0.5.4

Released on 2026-09-28.

Highlights

Faster builtin hooks

In our end-to-end benchmark, prek is about 38% faster than 0.5.3, with some builtin hooks up to 273% faster (check-yaml: 273%, check-json: 80%, check-merge-conflict: 71%).

Enhancements

  • Add include_deleted to allow hooks to include deleted files (#2733)
  • Add --check and simplify end-of-file-fixer (#2764)
  • Add --check to file-contents-sorter (#2765)
  • Add --check to requirements-txt-fixer (#2766)
  • Add --check to trailing-whitespace (#2763)
  • Expose and document prek util generate-shell-completion (#2727)
  • Support hide_status in project and user configuration (#2760)
  • Support look-around regex in builtin pattern hooks (#2732)

Performance

  • Cache the resolved Git executable on macOS (#2726)
  • Combine and cache Git repository path queries (#2724)
  • Optimize common builtin hook execution (#2768)
  • Optimize scanning in mixed-line-ending and trailing-whitespace (#2769)
  • Scan check-merge-conflict files in fixed-size blocks (#2781)
  • Use SIMD UTF-8 validation in check-json, check-toml, and check-yaml (#2770)

Bug fixes

  • Retry transient rename failures on Windows (#2756)
  • Use PATH to resolve prek in completion scripts (#2719)

Documentation

  • Clarify the flow and scope of usage guides (#2710)
  • Reorganize usage guides and reference documentation (#2709)

Other changes

  • Sync latest identify tags (#2762)

Contributors

Commits

Updates ruff from 0.16.7 to 0.16.9

Release notes

Sourced from ruff's releases.

0.16.9

Release Notes

Released on 2026-09-24.

Preview features

  • [ruff] Avoid false positives for overloaded division (RUF069) (#28309)

Bug fixes

  • [flake8-bugbear] Avoid false positives for calls with keyword arguments (B009, B010, B043) (#28776)
  • [flake8-tidy-imports] Allow lazy imports to be used in deferred annotations (TID255) (#28767)

Rule changes

  • Update LibCST-based fixes for Python 3.15 (#28616)
  • [flake8-pyi] Mention stubs in the diagnostic message (PYI002) (#28542)

Documentation

  • Fix horizontal overflow on the rules documentation page (#28699)
  • Update rules table with category information (#28651)
  • [flake8-annotations] Clarify that ANN401 checks return types in addition to arguments (#28334)
  • [flake8-bugbear] Document type-checker interaction (B010) (#28509)
  • [flake8-comprehensions] Document map/generator exception behavior (C417) (#27794)
  • [ruff] Mention related isort settings (RUF022) (#28719)

Contributors

Install ruff 0.16.9

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/ruff/releases/download/0.16.9/ruff-installer.sh | sh

... (truncated)

Changelog

Sourced from ruff's changelog.

0.16.9

Released on 2026-09-24.

Preview features

  • [ruff] Avoid false positives for overloaded division (RUF069) (#28309)

Bug fixes

  • [flake8-bugbear] Avoid false positives for calls with keyword arguments (B009, B010, B043) (#28776)
  • [flake8-tidy-imports] Allow lazy imports to be used in deferred annotations (TID255) (#28767)

Rule changes

  • Update LibCST-based fixes for Python 3.15 (#28616)
  • [flake8-pyi] Mention stubs in the diagnostic message (PYI002) (#28542)

Documentation

  • Fix horizontal overflow on the rules documentation page (#28699)
  • Update rules table with category information (#28651)
  • [flake8-annotations] Clarify that ANN401 checks return types in addition to arguments (#28334)
  • [flake8-bugbear] Document type-checker interaction (B010) (#28509)
  • [flake8-comprehensions] Document map/generator exception behavior (C417) (#27794)
  • [ruff] Mention related isort settings (RUF022) (#28719)

Contributors

0.16.8

Released on 2026-09-16.

Bug fixes

  • Visit functional TypedDict keyword arguments correctly (#28584)
  • [flake8-simplify] Detect nested async with under sync parent (SIM117) (#27821)
  • [flake8-simplify] Preserve operand order in SIM109 fix (#27824)

... (truncated)

Commits
  • 0be08a2 Bump version to 0.16.9 (#28882)
  • b4920b7 Rename ruff_cli to ruff_command_line (#28881)
  • 47c751b Update dependency astral-sh/uv to v0.12.18 (#28880)
  • 8c244e5 [flake8-comprehensions] Document map/generator exception behavior (C417...
  • 5edf5a1 Use target form in rooster.version_files (#28876)
  • 915bb2b [ty] Prefer existing @ paths over response files in Ruff and ty (#28877)
  • 4710e1a ci(github): update version number in placeholder of issue template (#28871)
  • eedfc62 [ty] Propagate outer type context through cast calls (#28855)
  • ceaa6a0 [ty] Contain rendered code within Markdown fences (#28869)
  • dba0f30 authorize ruff-pre-commit dispatch via OIDC (#28867)
  • Additional commits viewable in compare view

Updates ty from 0.0.81 to 0.0.84

Release notes

Sourced from ty's releases.

0.0.84

Release Notes

Released on 2026-09-24.

This release addresses GHSA-vxvm-j4xq-q7m4, a use-after-free vulnerability during incremental type checking that can result in arbitrary code execution when analyzing a specially crafted Python project. Users who run ty on untrusted code should upgrade to 0.0.84 or newer.

Bug fixes

  • Fix stale diagnostics from the LSP server after toggling showSyntaxErrors (#28759)

LSP server

  • Complete string keys from dictionary initializers (#28820)
  • Support LSP requests against closed documents (#28595)
  • Select projects for external files using import search paths (#28594)
  • Use workspace editor settings for external files (#28639)

Performance

  • Avoid repeated subtyping checks for materialized recursive protocols (#28774)
  • Skip reading notebooks when discovering scripts (#28781)

Core type checking

  • Avoid incorrect simplification of TypeIs materializations (#28817)
  • Fix disjointness of generic class types (#28787)
  • Fix staticmethod shadowing through generic receivers and unions (#28766)
  • Infer callable signatures from bounded type variables (#28599)
  • Infer constant membership in inline list and set literals (e.g. "foo" in ["foo"] is now inferred as Literal[True]) (#28676)
  • Infer through optional generic containers in the legacy solver (#28791)
  • Preserve call narrowing during cyclic inference (#28708)
  • Preserve intersections of type guard return types (#28796)
  • Use subtyping for constraint-set implication (#28657)

Configuration

  • Disable invalid-legacy-positional-parameter by default (#28834)

Other changes

  • Only consider reachable definitions when determining whether a condition should be exempted from redundant-condition(-strict) due to the condition being defined relative to sys.version_info, sys.platform, os.name or typing.TYPE_CHECKING (#28788)

Contributors

... (truncated)

Changelog

Sourced from ty's changelog.

0.0.84

Released on 2026-09-24.

This release addresses GHSA-vxvm-j4xq-q7m4, a use-after-free vulnerability during incremental type checking that can result in arbitrary code execution when analyzing a specially crafted Python project. Users who run ty on untrusted code should upgrade to 0.0.84 or newer.

Bug fixes

  • Fix stale diagnostics from the LSP server after toggling showSyntaxErrors (#28759)

LSP server

  • Complete string keys from dictionary initializers (#28820)
  • Support LSP requests against closed documents (#28595)
  • Select projects for external files using import search paths (#28594)
  • Use workspace editor settings for external files (#28639)

Performance

  • Avoid repeated subtyping checks for materialized recursive protocols (#28774)
  • Skip reading notebooks when discovering scripts (#28781)

Core type checking

  • Avoid incorrect simplification of TypeIs materializations (#28817)
  • Fix disjointness of generic class types (#28787)
  • Fix staticmethod shadowing through generic receivers and unions (#28766)
  • Infer callable signatures from bounded type variables (#28599)
  • Infer constant membership in inline list and set literals (e.g. "foo" in ["foo"] is now inferred as Literal[True]) (#28676)
  • Infer through optional generic containers in the legacy solver (#28791)
  • Preserve call narrowing during cyclic inference (#28708)
  • Preserve intersections of type guard return types (#28796)
  • Use subtyping for constraint-set implication (#28657)

Configuration

  • Disable invalid-legacy-positional-parameter by default (#28834)

Other changes

  • Only consider reachable definitions when determining whether a condition should be exempted from redundant-condition(-strict) due to the condition being defined relative to sys.version_info, sys.platform, os.name or typing.TYPE_CHECKING (#28788)

Contributors

... (truncated)

Commits

Updates zensical from 0.0.62 to 0.0.66

Release notes

Sourced from zensical's releases.

0.0.66

Summary

This version adds compatibility with mkdocs-autoapi and mkdocs-api-autonav, making it easier to document Python projects. These plugins discover modules and packages, generate API reference pages, and organize them in your site's navigation. They build on mkdocstrings, which renders the reference content from your code and docstrings, so you can skip manually creating a page for each module.

It also fixes responsive image URLs in raw HTML, ensures sitemaps include all published pages, and adds support for custom InlineHilite formatters configured through TOML.

Additionally, the user interface is updated to v0.0.33, adding styling for mkdocstrings backlinks in both themes, restoring GLightbox styles after instant navigation, respecting custom Mermaid node label colors, and fixing the / search shortcut.

Changelog

Features

  • b2f4de7 zensical, compat – support mkdocs-autoapi and mkdocs-api-autonav plugins

Bug fixes

  • 3d8c0e2 ui – update ui to v0.0.33
  • 7be3d1d compat – resolve custom inline formatters in TOML configuration (#980)
  • e3099ab zensical, compat – include all published pages in sitemap (#977)
  • e24d0fc compat – resolve raw HTML srcset URLs relative to Markdown source (#975)

0.0.65

Summary

This version expands MkDocs compatibility with a native replacement for the rss plugin and support for mkdocstrings backlinks. Zensical can now generate RSS 2.0 and JSON Feed 1.1 feeds for created and updated pages. Python API documentation can also show which pages reference a documented object, with backlinks kept current across cached builds.

Changelog

Features

  • e7876ab zensical, compat – support mike's version_selector setting
  • 25b95e9 zensical, compat – support mkdocstrings' enable_inventory setting
  • 0223fc9 compat – support more macros settings
  • acee89a zensical, compat – support autorefs settings
  • 0291923 zensical, compat – support mkdocstrings backlinks
  • c214988 zensical, compat – add rss plugin replacement (#443)

Bug fixes

  • cf68f6d zensical, compat – resolve source links to published post URLs (#966)

0.0.64

Summary

Many of you have been waiting for this one: Zensical now includes native blog support. As a direct port of the Material for MkDocs blog plugin, it preserves the familiar configuration, metadata, URLs, archives, categories, authors, pagination, and more. We're happy to finally put it into your hands, with more flexible blogging functionality planned for the future.

Changelog

Features

... (truncated)

Commits
  • a85dcbc chore: release v0.0.66
  • 3d8c0e2 fix: update ui to v0.0.33
  • 7be3d1d fix: resolve custom inline formatters in TOML configuration (#980)
  • b2f4de7 feature: support mkdocs-autoapi and mkdocs-api-autonav plugins
  • e3099ab fix: include all published pages in sitemap (#977)
  • e24d0fc fix: resolve raw HTML srcset URLs relative to Markdown source (#975)
  • 27fa310 chore: release v0.0.65
  • 5f7486e Merge pull request #969 from zensical/feature/support-more-plugin-settings
  • 95bd9aa chore: update uv lock file
  • e7876ab feature: support mike's version selector setting
  • Additional commits viewable in compare view

@dependabot dependabot Bot added the dependencies Changes to dependencies label Oct 1, 2026
@dependabot
dependabot Bot requested a review from wlix13 as a code owner October 1, 2026 06:18
@dependabot dependabot Bot added the dependencies Changes to dependencies label Oct 1, 2026
@coderabbitai

coderabbitai Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 66f87f1e-235d-4f24-8c67-ff78998f58ed

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@wlix13

wlix13 commented Oct 1, 2026

Copy link
Copy Markdown
Owner

@dependabot rebase

… updates

Bumps the python-deps group with 4 updates in the / directory: [prek](https://github.com/j178/prek), [ruff](https://github.com/astral-sh/ruff), [ty](https://github.com/astral-sh/ty) and [zensical](https://github.com/zensical/zensical).


Updates `prek` from 0.5.3 to 0.5.4
- [Release notes](https://github.com/j178/prek/releases)
- [Changelog](https://github.com/j178/prek/blob/master/CHANGELOG.md)
- [Commits](j178/prek@v0.5.3...v0.5.4)

Updates `ruff` from 0.16.7 to 0.16.9
- [Release notes](https://github.com/astral-sh/ruff/releases)
- [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md)
- [Commits](astral-sh/ruff@0.16.7...0.16.9)

Updates `ty` from 0.0.81 to 0.0.84
- [Release notes](https://github.com/astral-sh/ty/releases)
- [Changelog](https://github.com/astral-sh/ty/blob/main/CHANGELOG.md)
- [Commits](astral-sh/ty@0.0.81...0.0.84)

Updates `zensical` from 0.0.62 to 0.0.66
- [Release notes](https://github.com/zensical/zensical/releases)
- [Commits](zensical/zensical@v0.0.62...v0.0.66)

---
updated-dependencies:
- dependency-name: prek
  dependency-version: 0.5.4
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: python-deps
- dependency-name: ruff
  dependency-version: 0.16.9
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: python-deps
- dependency-name: ty
  dependency-version: 0.0.84
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: python-deps
- dependency-name: zensical
  dependency-version: 0.0.65
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: python-deps
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title chore(deps-dev): bump the python-deps group with 4 updates chore(deps-dev): bump the python-deps group across 1 directory with 4 updates Oct 1, 2026
@dependabot
dependabot Bot force-pushed the dependabot/uv/python-deps-ae88ef595c branch from bfde708 to 17fac7b Compare October 1, 2026 11:24
@wlix13
wlix13 merged commit 5c81df1 into main Oct 1, 2026
14 checks passed
@wlix13
wlix13 deleted the dependabot/uv/python-deps-ae88ef595c branch October 1, 2026 11:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Changes to dependencies

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant