Skip to content

build(deps): bump the patch-and-minor group across 1 directory with 10 updates - #306

Open
dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/pip/patch-and-minor-f03c42ffa7
Open

dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/pip/patch-and-minor-f03c42ffa7

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 9, 2026

Copy link
Copy Markdown
Contributor

Bumps the patch-and-minor group with 10 updates in the / directory:

Package From To
urllib3 2.7.0 2.8.0
werkzeug 3.1.8 3.1.9
mypy 2.3.1 2.4.0
build 1.6.0 1.6.1
tox 4.60.1 4.64.7
coverage 7.15.4 7.16.2
ruff 0.16.5 0.16.10
boto3 1.43.83 1.43.108
charset-normalizer 3.5.1 3.5.2
idna 3.19 3.20

Updates urllib3 from 2.7.0 to 2.8.0

Release notes

Sourced from urllib3's releases.

2.8.0

🚀 urllib3 is fundraising for HTTP/2 support

urllib3 is raising ~$40,000 USD to release HTTP/2 support and ensure long-term sustainable maintenance of the project. If your company or organization uses Python and would benefit from HTTP/2 support in Requests, pip, cloud SDKs, and thousands of other projects please consider contributing financially to ensure HTTP/2 support is developed sustainably and maintained for the long-haul.

Thank you for your support.

Security

Fixed the following security issues:

  • The TLS configuration for HTTPS proxies could be ignored or overridden. (High severity, GHSA-8988-9cw3-xx77)
  • HTTPResponse.stream() and read_chunked() could buffer a chunk-size line of unbounded length in memory. (High severity, GHSA-vxq7-64xx-v4gw)
  • Chunked Deflate streaming could enter an infinite loop. (Medium severity, GHSA-gh4c-6fx4-qh6g)

[!IMPORTANT] urllib3 2.8.0 fixes HTTPS proxy TLS configuration being ignored or overridden by destination settings. Configurations relying on that behavior may require changes.

Configure proxy CA certificates and client certificates in proxy_ssl_context, and proxy identity checks with proxy_assert_hostname or proxy_assert_fingerprint. Destination client certificates and identity overrides no longer apply to HTTPS forwarding proxy connections.

[!NOTE] CVE IDs had not yet been assigned to these advisories at the time of release due to a backlog at GitHub's CNA.

Deprecations & Removals

  • Deprecated using an empty collection as the Retry option allowed_methods to retry any verb. (#5044)

Features

  • Added Url.auth_decoded and Url.auth_decoded_joined convenience properties to the result of parse_url(). (#4945)
  • Added basic_auth_encoding and proxy_basic_auth_encoding parameters to urllib3.util.make_headers(). (#5092)

Bugfixes

  • Fixed response header handling to replace obsolete folded header lines (obs-fold) with spaces in accordance with RFC 9112, preventing raw CRLF sequences from appearing in header values such as Set-Cookie. (#1362)

  • Fixed usage of proxy_ssl_context with ProxyManager when use_forwarding_for_https=True. Passing ssl_context instead of proxy_ssl_context for HTTPS proxies in this configuration now emits a FutureWarning and will raise an error in v3.0. (#2577)

  • Changed behavior of the default ConnectionPool.pool initialization. LifoQueue is now resolved from the queue module after the ConnectionPool is instantiated instead of using the default cached QueueCls class property. This is done because sometimes the queue.LifoQueue is monkey-patched late in the program, such as by gevent. (#3289)

  • Raised UnrewindableBodyError instead of ValueError when retrying a request whose body had tell() but not seek(). (#3779)

  • Decoded percent-encoded SOCKS proxy credentials before authenticating with the proxy server. (#3785)

  • Fixed HTTPResponse.drain_conn() to discard unread response data in 64 KiB chunks (same as the default amt when doing HTTPResponse.stream(...)). (#5019)

  • Fixed is_ipaddress() to detect non-standard IPv4 forms accepted by socket.connect, such as hex (0x7f000001), octal (0177.0.0.1), and decimal integers (2130706433), ensuring SSL certificate verification uses the correct mode for these addresses. (#5029)

  • Fixed HTTPConnectionPool.urlopen raising a misleading FullPoolError instead of ValueError when called with an invalid timeout argument on a pool created with block=True. (#5059)

  • Fixed port-zero handling to preserve explicit :0 values instead of substituting the default ports 80 or 443 in URL parsing, pool selection, proxy configuration, connection_from_url(), and HTTP/2 request authority. (#5071, #5101)

  • Fixed a bug where PoolManager passed the assert_hostname and assert_fingerprint parameters to HTTP connection pools. (#5077)

  • Fixed HTTPConnectionPool.urlopen() and HTTP proxy forwarding to strip URL fragments from absolute request targets before sending requests. (#5079)

  • Added safeguards to the proxy tunneling code to prevent potential security issues when handling invalid characters in the proxy host and HTTP headers. This change affects users of Python 3.10, Python 3.11, and Python 3.12 when the standard library does not contain the fix; those on newer Python versions should upgrade to 3.13.14+ or 3.14.5+ to get the same security fixes. (#5091)

  • Fixed HTTPSConnection.connect() overriding ProxyConfig.ssl_context's certificate policy and proxy identity checks with the target connection's TLS settings when forwarding through an HTTPS proxy.

    HTTPSConnection no longer applies target SNI, assertions, or client credentials to forwarding proxy handshakes and continues to use its ssl_context as a fallback when an HTTPS proxy forwards an HTTP target. (#5093)

  • Fixed URL parsing to more strictly enforce RFC 3986 host syntax, rejecting invalid host input such as raw spaces and control characters, malformed percent-encodings, and percent-encoded control characters in HTTP(S) hosts and IPv6 zone identifiers, including proxy CONNECT tunnel targets. Host normalization now also follows RFC 3986 normalization rules for percent-encoded octets by decoding percent-encoded unreserved characters and uppercasing the hexadecimal digits of retained percent-encoded octets. (#5095)

... (truncated)

Changelog

Sourced from urllib3's changelog.

2.8.0 (2026-09-15)

Security

Fixed the following security issues:

  • The TLS configuration for HTTPS proxies could be ignored or overridden. (High severity, GHSA-8988-9cw3-xx77 <https://github.com/urllib3/urllib3/security/advisories/GHSA-8988-9cw3-xx77>__)
  • HTTPResponse.stream() and read_chunked() could buffer a chunk-size line of unbounded length in memory. (High severity, GHSA-vxq7-64xx-v4gw <https://github.com/urllib3/urllib3/security/advisories/GHSA-vxq7-64xx-v4gw>__)
  • Chunked Deflate streaming could enter an infinite loop. (Medium severity, GHSA-gh4c-6fx4-qh6g <https://github.com/urllib3/urllib3/security/advisories/GHSA-gh4c-6fx4-qh6g>__)

.. caution::

urllib3 2.8.0 fixes HTTPS proxy TLS configuration being ignored or
overridden by destination settings. Configurations relying on that
behavior may require changes.

Configure proxy CA certificates and client certificates in proxy_ssl_context, and proxy identity checks with proxy_assert_hostname or proxy_assert_fingerprint. Destination client certificates and identity overrides no longer apply to HTTPS forwarding proxy connections.

Deprecations & Removals

  • Deprecated using an empty collection as the Retry option allowed_methods to retry any verb. ([#5044](https://github.com/urllib3/urllib3/issues/5044) <https://github.com/urllib3/urllib3/issues/5044>__)

Features

  • Added Url.auth_decoded and Url.auth_decoded_joined convenience properties to the result of parse_url(). ([#4945](https://github.com/urllib3/urllib3/issues/4945) <https://github.com/urllib3/urllib3/issues/4945>__)
  • Added basic_auth_encoding and proxy_basic_auth_encoding parameters to urllib3.util.make_headers(). ([#5092](https://github.com/urllib3/urllib3/issues/5092) <https://github.com/urllib3/urllib3/issues/5092>__)

Bugfixes

... (truncated)

Commits
  • b1d30ab Release 2.8.0
  • 9016d7e Skip test_read_chunked_with_trailing_data_does_not_hang for brotlicffi (#5258)
  • 9101f58 Fix nox -s docs warning (#5256)
  • cd770b0 Merge commit from fork
  • ea2ad7b Merge commit from fork
  • 0716e31 Fix loading unencrypted client keys with a password in pyOpenSSL (#5255)
  • 43c68c8 Test pickling of InvalidChunkLength (#5247)
  • 308b279 Share security policy between GitHub and Read the Docs (#5253)
  • 53fa073 Add policy on duplicate pull requests (#5252)
  • 5f2a6a8 Assert on the ALPN extension in test_tunnel_sets_http_11_alpn (#5232)
  • Additional commits viewable in compare view

Updates werkzeug from 3.1.8 to 3.1.9

Release notes

Sourced from werkzeug's releases.

3.1.9

This is the Werkzeug 3.1.9 security fix release, which fixes security issues and bugs but does not otherwise change behavior and should not result in breaking changes compared to the latest feature release.

PyPI: https://pypi.org/project/Werkzeug/3.1.9/ Changes: https://werkzeug.palletsprojects.com/page/changes/#version-3-1-9 Milestone: https://github.com/pallets/werkzeug/milestone/46?closed=1

  • safe_join on Windows does not allow special devices names with empty ADS markers on NTFS. GHSA-g6x2-hccm-hh4m
  • ProfilerMiddleware uses profiling.tracing on Python 3.15. #3207
  • uri_to_iri and iri_to_uri preserve empty username, password, and port 0. #3189
  • Improve performance of parse_options_header. #3231
  • Improve performance of parse_etags. #3231
  • Improve performance of parse_cookie. #3231
  • get_host also checks that the port is in the valid range. #3236
  • The int URL converter returns a 404 instead of 500 error when the value is longer than sys.get_int_max_str_digits(). #3237
  • Improve debugger PIN generation from cgroup data inside Podman. #3245
  • Authorization parsing basic auth disallows non-base64 characters. #3248
  • application/x-www-form-urlencoded form data is no longer limited to max_form_memory_size, only max_content_length. #3251
  • LimitedStream.readinto does not resize the buffer when it reads less than the remaining size. #3253
  • Rules with 10 or more converters in a single part assign matched values correctly. #3254
  • The invalid Range suffix length -0 is no longer accepted. #3255
Changelog

Sourced from werkzeug's changelog.

Version 3.1.9

Released 2026-09-27

  • safe_join on Windows does not allow special devices names with empty ADS markers on NTFS. :ghsa:g6x2-hccm-hh4m
  • ProfilerMiddleware uses profiling.tracing on Python 3.15. :issue:3207
  • uri_to_iri and iri_to_uri preserve empty username, password, and port 0. :issue:3189
  • Improve performance of parse_options_header. :pr:3231
  • Improve performance of parse_etags. :pr:3231
  • Improve performance of parse_cookie. :pr:3231
  • get_host also checks that the port is in the valid range. :pr:3236
  • The int URL converter returns a 404 instead of 500 error when the value is longer than sys.get_int_max_str_digits(). :issue:3237
  • Improve debugger PIN generation from cgroup data inside Podman. :issue:3245
  • Authorization parsing basic auth disallows non-base64 characters. :pr:3248
  • application/x-www-form-urlencoded form data is no longer limited to max_form_memory_size, only max_content_length. :pr:3251
  • LimitedStream.readinto does not resize the buffer when it reads less than the remaining size. :pr:3253
  • Rules with 10 or more converters in a single part assign matched values correctly. :pr:3254
  • The invalid Range suffix length -0 is no longer accepted. :pr:3255
Commits

Updates mypy from 2.3.1 to 2.4.0

Changelog

Sourced from mypy's changelog.

Mypy Release Notes

Next Release

Mypy 2.4

We've just uploaded mypy 2.4.0 to the Python Package Index (PyPI). Mypy is a static type checker for Python. This release includes new features, performance improvements and bug fixes. You can install it as follows:

python3 -m pip install -U mypy

You can read the full documentation for this release on Read the Docs.

Python 3.15 Support

Mypy 2.4 supports running on Python 3.15 and type checking most Python 3.15 features. This includes the new builtin sentinel type for sentinel values (PEP 661), which mypy now supports (see below for details). Lazy imports (PEP 810) and unpacking in comprehensions (PEP 798) are also supported. Closed TypedDicts (PEP 728) have been supported since mypy 2.2, but the extra_items TypedDict argument, also introduced in PEP 728, is still unsupported. Support for extra_items will be added in a future mypy release.

Native Parser Enabled by Default

Mypy now uses the new native parser by default. It's based on the Ruff parser, and it's significantly faster than the legacy parser, which uses the stdlib ast module. The native parser also has other benefits:

  • You can target newer Python versions and use recent Python syntax even when running mypy on an older Python version. For example, you can use --python-version 3.15 when running mypy on Python 3.14.
  • Stub files can use syntax that is newer than the target Python version. For example, stubs can use the PEP 695 generic class syntax (class Box[T]: ...) when running on or targeting Python 3.10.
  • Parallel type checking requires the native parser.

The legacy parser is still available through --no-native-parser, or native_parser = False in the config file (native_parser = false under [tool.mypy] in pyproject.toml). We are planning to remove the legacy parser in early 2027. If you run into a problem with the native parser, please report it on the issue tracker.

Unlike the legacy parser, the native parser doesn't support type comments for variables defined by for and with statements. These type comments are silently ignored, and the types of the variables are

... (truncated)

Commits

Updates build from 1.6.0 to 1.6.1

Release notes

Sourced from build's releases.

1.6.1

What's Changed

Full Changelog: pypa/build@1.6.0...1.6.1

Changelog

Sourced from build's changelog.

#################### 1.6.1 (2026-09-10) ####################


Bugfixes


  • Avoid trying to detect symlinks on Windows, regression in 1.6.0 - by :user:henryiii (:issue:1175) (:issue:1175)

Documentation


  • Fix doubled backslashes in the Windows pip config path (%APPDATA%\pip\pip.ini) in the docs - by :user:aroh3006 (:issue:1149)

Miscellaneous


  • :issue:1168, :issue:1170, :issue:1178

#################### 1.6.0 (2026-08-27) ####################


Features


  • Add --report=PATH to write a machine-readable JSON report of built artifacts; --metadata now also accepts .whl files - by :user:gaborbernat (:issue:198)
  • The srcdir argument now accepts .tar.gz source distributions, extracting and building from them - by :user:gaborbernat (:issue:311)
  • The "Unmet dependencies" error from --no-isolation builds now shows the wanted version, found version, and interpreter - by :user:gaborbernat (:issue:504)
  • Add --sdist-extract-dir to extract the intermediate sdist into a persistent directory, enabling compiler cache reuse across rebuilds - by :user:gaborbernat (:issue:614)
  • Add --env-dir to place the isolated build environment at a fixed path, enabling compiler cache reuse across builds
    • by :user:gaborbernat (:issue:655)
  • Print a summary of resolved dependency versions (name==version) after installing them in isolated builds - by :user:gaborbernat (:issue:959)
  • On build failure, print a tip pointing to --env-dir and --sdist-extract-dir for debugging and link to the "Debug a failed build" how-to - reported by :user:dimpase, implemented by :user:gaborbernat (:issue:966)

Bugfixes


... (truncated)

Commits
  • 89cccef chore: prepare for 1.6.1
  • a6f707a ci: support releases from v* branches (#1178)
  • 7785161 docs: fix doubled backslashes in Windows pip config path (#1149)
  • 244b250 fix: always use copies for the isolated venv on Windows (#1176)
  • c93ca6f build(deps): bump re-actors/alls-green from 1.2.2 to 1.3.0 in the github-acti...
  • e02ffd3 pre-commit: bump repositories (#1173)
  • aad39a8 docs: fix changelog page heading levels and sidebar (#1171)
  • 5c3fd46 docs: use PyPI ref directly (#1172)
  • 1c5bd6c 🐛 fix(release): format generated changelog (#1170)
  • 7f0cc7e 🔧 build(type): replace mypy with pyrefly (#1168)
  • See full diff in compare view

Updates tox from 4.60.1 to 4.64.7

Release notes

Sourced from tox's releases.

v4.64.7

What's Changed

Full Changelog: tox-dev/tox@4.64.6...4.64.7

v4.64.6

What's Changed

New Contributors

Full Changelog: tox-dev/tox@4.64.5...4.64.6

v4.64.5

What's Changed

New Contributors

Full Changelog: tox-dev/tox@4.64.4...4.64.5

v4.64.4

What's Changed

New Contributors

Full Changelog: tox-dev/tox@4.64.3...4.64.4

v4.64.3

... (truncated)

Changelog

Sourced from tox's changelog.

Bug fixes - 4.64.7

  • tox man suggests ~/.profile instead of ~/.zshrc when the shell is not fish, bash, zsh, csh or tcsh, for example sh, ksh or an unset SHELL - by :user:Rodrigo-Palma.

    • tox picks the shell from the executable name, so /home/zshuser/bin/bash gets ~/.bashrc.
    • Outside fish, csh and tcsh, the reload hint reads . <file> instead of source <file>, since dash has no source.
    • The fish line keeps the default man path when MANPATH was unset, instead of hiding every other man page.
    • csh and tcsh get a setenv line for ~/.tcshrc or ~/.cshrc instead of an export line for ~/.profile. (:issue:4109)

v4.64.6 (2026-10-01)


Bug fixes - 4.64.6

  • tox -e and TOXENV accept every interpreter name that picks a base_python for an environment the configuration does not declare - by :user:breken-ai.

    • cpython313, cpython-3.13, graalpy311, jython2.7, rustpython3 and ironpython3 select that interpreter instead of failing with "provided environments not found".
    • The d debug-build suffix works too, for example py313d.
    • cython313 now fails as an unknown environment; it used to run on the Python that tox runs under. (:issue:4106)
  • A set_env block pulled in with {[section]set_env} now applies a PEP-508 marker only to the value it came with, as the inline and TOML forms already do - by :user:feiiiiii5. A false marker on an earlier line no longer hides a value that the inheriting environment, a later unconditional line or an environment file supplies. (:issue:4107)

  • set_env values resolve when tox reads them, so {env:KEY} sees the keys a block pulls in with {[section]set_env}, and a { replace = "env" } table sees the keys next to it - by :user:gaborbernat, found by :user:breken-ai. Configurations that see a difference:

    • A value pulled in from another section that refers to a key of the same block now gets the block's value instead of the host variable.
    • A pulled-in line that refers to its own key, such as PYTHONHASHSEED = {env:PYTHONHASHSEED:0}, reads the host variable or its default, as the same line written in place does. It used to read the value tox sets.
    • A key written in an INI set_env wins over the same key pulled in from another section, and a later pulled-in section wins over an earlier one, at every nesting level. A nested section could override the section that included it before.
    • tox config shows the keys of every pulled-in section that tox run sets.
    • A section that pulls itself in, a TOML ref to itself, and values that refer to each other fail the environment with the cycle. They used to fail with a traceback or "could not find python interpreter", and values that referred to each other inside a pulled-in section read the host variables without a warning. (:issue:4108)

v4.64.5 (2026-09-29)


... (truncated)

Commits
  • a45f1fa release 4.64.7
  • 3e5db9e fix(man): give each shell a working MANPATH line (#4109)
  • 03160bc release 4.64.6
  • 8cbdb50 fix(config): resolve set_env values when read (#4108)
  • b3e69e4 fix(env): accept every documented interpreter name with -e (#4106)
  • 66ec58c fix(config): tie spliced set_env markers to their value (#4107)
  • 24f433b release 4.64.5
  • d254559 fix(config): fail on an invalid platform regex (#4104)
  • 1845eed build(deps): bump astral-sh/setup-uv from 10.1.0 to 10.2.0 in the github-acti...
  • 2d2ef9f [pre-commit.ci] pre-commit autoupdate (#4101)
  • Additional commits viewable in compare view

Updates coverage from 7.15.4 to 7.16.2

Release notes

Sourced from coverage's releases.

7.16.2

Version 7.16.2 — 2026-09-27

  • Fix: on Python 3.14 and later, a for loop completing immediately before a function return could mistakenly report an uncovered branch. This is now fixed, closing issue 2168.
  • Fix: on Python 3.14 and later, the else clause of a try whose body is a with statement could incorrectly be reported as covered when the with raised. This is now fixed, closing issue 2289.
  • Fix: with dynamic_context = test_function, test methods written as @staticmethod or @classmethod were not given a context of their own. Now they are, on Python 3.11 and later. Closes issue 1923.

➡️  PyPI page: coverage 7.16.2. :arrow_right:  To install: python3 -m pip install coverage==7.16.2

7.16.1

Version 7.16.1 — 2026-09-13

  • Fix: when the body of an irrefutable case (like case _:) is entirely excluded, the case line is now excluded too, just as an excluded else: body removes the else: line. Previously the case line was left behind and reported as missing. Closes issue 1563 with pull 2269.
  • Fix: using CoverageData.update() twice on an in-memory database would fail, as described in issue 2279. This is now fixed.

➡️  PyPI page: coverage 7.16.1. :arrow_right:  To install: python3 -m pip install coverage==7.16.1

7.16.0

Version 7.16.0 — 2026-08-28

  • When combining files, now path separator slashes will automatically be converted to the local file system style. This makes it less necessary to define [paths] configuration to combine data across operating systems. Fixes issue 2266.
  • The Coverage.switch_context() method now returns the previous context.
  • Fix: previously, a [paths] pattern would be replaced everywhere in a file path when it was only meant to be replaced once, in the leading portion of the path. This is now fixed, in pull 2268.
  • Fixes to validation of options and configuration settings:
    • Negative precision settings now always cause useful error messages (pull 2261).
    • An invalid regex in the --contexts option (or the [report] contexts setting) reported a confusing “Couldn’t use data file …: user-defined function raised exception” error. Now it raises a proper configuration error naming the bad regex, like other regex settings do (pull 2262).
    • Non-string values in TOML configuration settings now produce a helpful error message instead of a traceback. This affects list settings whose elements aren’t strings (like omit, exclude_lines, or a [paths] entry), file settings like data_file, and any wrong-typed value in the [paths] section (pull 2263).
    • coverage run refuses run-affecting command-line options like --branch alongside --concurrency=multiprocessing, since they can’t reach the subprocesses. The check only recognized multiprocessing as the entire option value, so --concurrency=multiprocessing,thread slipped through and failed later with “Can’t combine statement coverage data with branch data”. Each named concurrency library is now properly considered (pull 2270).
  • Fix: coverage annotate -d DIR raised an AssertionError if any measured file had an extension other than .py, such as a .pyw file on Windows. The original extension is now restored on the annotated copy (pull 2265).

➡️  PyPI page: coverage 7.16.0. :arrow_right:  To install: python3 -m pip install coverage==7.16.0

Changelog

Sourced from coverage's changelog.

Version 7.16.2 — 2026-09-27

  • Fix: on Python 3.14 and later, a for loop completing immediately before a function return could mistakenly report an uncovered branch. This is now fixed, closing issue 2168_.

  • Fix: on Python 3.14 and later, the else clause of a try whose body is a with statement could incorrectly be reported as covered when the with raised. This is now fixed, closing issue 2289_.

  • Fix: with dynamic_context = test_function, test methods written as @staticmethod or @classmethod were not given a context of their own. Now they are, on Python 3.11 and later. Closes issue 1923_.

.. _issue 1923: coveragepy/coveragepy#1923 .. _issue 2168: coveragepy/coveragepy#2168 .. _issue 2289: coveragepy/coveragepy#2289

.. _changes_7-16-1:

Version 7.16.1 — 2026-09-13

  • Fix: when the body of an irrefutable case (like case _:) is entirely excluded, the case line is now excluded too, just as an excluded else: body removes the else: line. Previously the case line was left behind and reported as missing. Closes issue 1563_ with pull 2269_.

  • Fix: using :meth:.CoverageData.update twice on an in-memory database would fail, as described in issue 2279_. This is now fixed.

.. _issue 1563: coveragepy/coveragepy#1563 .. _pull 2269: coveragepy/coveragepy#2269 .. _issue 2279: coveragepy/coveragepy#2279

.. _changes_7-16-0:

Version 7.16.0 — 2026-08-28

  • When combining files, now path separator slashes will automatically be converted to the local file system style. This makes it less necessary to define [paths] configuration to combine data across operating systems. Fixes issue 2266_.

  • The :meth:.Coverage.switch_context method now returns the previous context.

  • Fix: previously, a [paths] pattern would be replaced everywhere in a file

... (truncated)

Commits

Updates ruff from 0.16.5 to 0.16.10

Release notes

Sourced from ruff's releases.

0.16.10

Release Notes

Released on 2026-10-01.

Preview features

  • Add a migration guide for categories (#28087)
  • [pyupgrade] Add rule for context manager iterator annotations (UP052) (#29000)

Performance

  • Reduce memory used by diagnostics (#28951)

Server

  • Avoid running uv format in untrusted workspaces (#28873)

Documentation

  • Fix links to moved changelog sections and renamed mdtests (#28941)
  • Add Python 3.15 as a supported version (#28907)
  • Add ty as a type checker example (#28906)

Other changes

  • Update Rust toolchain to 1.99 and MSRV to 1.97 (#29047)

Contributors

Install ruff 0.16.10

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/ruff/releases/download/0.16.10/ruff-installer.sh | sh

Install prebuilt binaries via powershell script

powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/ruff/releases/download/0.16.10/ruff-installer.ps1 | iex"

Download ruff 0.16.10

... (truncated)

Changelog

Sourced from ruff's changelog.

0.16.10

Released on 2026-10-01.

Preview features

  • Add a migration guide for categories (#28087)
  • [pyupgrade] Add rule for context manager iterator annotations (UP052) (#29000)

Performance

  • Reduce memory used by diagnostics (#28951)

Server

  • Avoid running uv format in untrusted workspaces (#28873)

Documentation

  • Fix links to moved changelog sections and renamed mdtests (#28941)
  • Add Python 3.15 as a supported version (#28907)
  • Add ty as a type checker example (#28906)

Other changes

  • Update Rust toolchain to 1.99 and MSRV to 1.97 (#29047)

Contributors

0.16.9

Released on 2026-09-24.

Preview features

  • [ruff] Avoid false positives for overloaded division (RUF069) (#28309)

Bug fixes

  • [flake8-bugbear] Avoid false positives for calls with keyword arguments (B009, B010, B043) (#28776)
  • [flake8-tidy-imports] Allow lazy imports to be used in deferred annotations (TID255) (#28767)

Rule changes

  • Update LibCST-based fixes for Python 3.15 (#28616)

... (truncated)

Commits
  • 3265ed1 Bump version to 0.16.10 (#29055)
  • e786964 Authorize shared PR security-review workflow to publish findings (#29052)
  • a81291e [ty] Defer uv workspace discovery until after project configuration (#28525)
  • b6a74d2 [ty] Refresh uv project metadata when uv files change (#28529)
  • 41d30df Update Rust toolchain to 1.99 and MSRV to 1.97 (#29047)
  • 317e0a3 [ty] Bound nested callable signature display (#29049)
  • 8546752 [ty] Fix member lookup on union-bounded type variables (#29018)
  • 56180bc [ty] Specialize instance members once (#29043)
  • aa9a1ff [ty] Avoid stale I/O diagnostics when closing deleted files (#28988)
  • 2d25346 [ty] Improve unresolved-import documentation (#29039)
  • Additional commits viewable in compare view

Updates boto3 from 1.43.83 to 1.43.108

Commits

Updates charset-normalizer from 3.5.1 to 3.5.2

Release notes

Sourced from charset-normalizer's releases.

Version 3.5.2

3.5.2 (2026-09-29)

Changed

  • Raised the Cython upper bound to <3.4 for native builds. The bound remains <3.3 for abi3 builds to preserve compatibility with the Python 3.7 Limited API.

Fixed

  • Valid UTF-8 Chinese JSON incorrectly detected as PTCP154 due to excessive noise penalties for uncommon CJK characters. (#796)
  • Supported encodings without aliases failing name resolution or being ignored in charset declarations. (#800)
Changelog

Sourced from charset-normalizer's changelog.

3.5.2 (2026-09-29)

Changed

  • Raised the Cython upper bound to <3.4 for native builds. The bound remains <3.3 for abi3 builds to preserve compatibility with the Python 3.7 Limited API.

Fixed

  • Valid UTF-8 Chinese JSON incorrectly detected as PTCP154 due to excessive noise penalties for uncommon CJK characters. (#796)
  • Supported encodings without aliases failing name resolution or being ignored in charset declarations. (#800)
Commits
  • 935c29a Release 3.5.2 (#805)
  • 9d3238a test: disable traefik...

    Description has been truncated

…0 updates

Bumps the patch-and-minor group with 10 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [urllib3](https://github.com/urllib3/urllib3) | `2.7.0` | `2.8.0` |
| [werkzeug](https://github.com/pallets/werkzeug) | `3.1.8` | `3.1.9` |
| [mypy](https://github.com/python/mypy) | `2.3.1` | `2.4.0` |
| [build](https://github.com/pypa/build) | `1.6.0` | `1.6.1` |
| [tox](https://github.com/tox-dev/tox) | `4.60.1` | `4.64.7` |
| [coverage](https://github.com/coveragepy/coveragepy) | `7.15.4` | `7.16.2` |
| [ruff](https://github.com/astral-sh/ruff) | `0.16.5` | `0.16.10` |
| [boto3](https://github.com/boto/boto3) | `1.43.83` | `1.43.108` |
| [charset-normalizer](https://github.com/jawah/charset_normalizer) | `3.5.1` | `3.5.2` |
| [idna](https://github.com/kjd/idna) | `3.19` | `3.20` |



Updates `urllib3` from 2.7.0 to 2.8.0
- [Release notes](https://github.com/urllib3/urllib3/releases)
- [Changelog](https://github.com/urllib3/urllib3/blob/main/CHANGES.rst)
- [Commits](urllib3/urllib3@2.7.0...2.8.0)

Updates `werkzeug` from 3.1.8 to 3.1.9
- [Release notes](https://github.com/pallets/werkzeug/releases)
- [Changelog](https://github.com/pallets/werkzeug/blob/main/CHANGES.rst)
- [Commits](pallets/werkzeug@3.1.8...3.1.9)

Updates `mypy` from 2.3.1 to 2.4.0
- [Changelog](https://github.com/python/mypy/blob/master/CHANGELOG.md)
- [Commits](python/mypy@v2.3.1...v2.4.0)

Updates `build` from 1.6.0 to 1.6.1
- [Release notes](https://github.com/pypa/build/releases)
- [Changelog](https://github.com/pypa/build/blob/main/CHANGELOG.rst)
- [Commits](pypa/build@1.6.0...1.6.1)

Updates `tox` from 4.60.1 to 4.64.7
- [Release notes](https://github.com/tox-dev/tox/releases)
- [Changelog](https://github.com/tox-dev/tox/blob/main/docs/changelog.rst)
- [Commits](tox-dev/tox@4.60.1...4.64.7)

Updates `coverage` from 7.15.4 to 7.16.2
- [Release notes](https://github.com/coveragepy/coveragepy/releases)
- [Changelog](https://github.com/coveragepy/coveragepy/blob/main/CHANGES.rst)
- [Commits](coveragepy/coveragepy@7.15.4...7.16.2)

Updates `ruff` from 0.16.5 to 0.16.10
- [Release notes](https://github.com/astral-sh/ruff/releases)
- [Changelog](https://github.com/astral-sh/ruff/blob/0.16.10/CHANGELOG.md)
- [Commits](astral-sh/ruff@0.16.5...0.16.10)

Updates `boto3` from 1.43.83 to 1.43.108
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](boto/boto3@1.43.83...1.43.108)

Updates `charset-normalizer` from 3.5.1 to 3.5.2
- [Release notes](https://github.com/jawah/charset_normalizer/releases)
- [Changelog](https://github.com/jawah/charset_normalizer/blob/master/CHANGELOG.md)
- [Commits](jawah/charset_normalizer@3.5.1...3.5.2)

Updates `idna` from 3.19 to 3.20
- [Release notes](https://github.com/kjd/idna/releases)
- [Changelog](https://github.com/kjd/idna/blob/master/HISTORY.md)
- [Commits](kjd/idna@v3.19...v3.20)

---
updated-dependencies:
- dependency-name: urllib3
  dependency-version: 2.8.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: patch-and-minor
- dependency-name: werkzeug
  dependency-version: 3.1.9
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: patch-and-minor
- dependency-name: mypy
  dependency-version: 2.4.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: patch-and-minor
- dependency-name: build
  dependency-version: 1.6.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: patch-and-minor
- dependency-name: tox
  dependency-version: 4.64.7
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: patch-and-minor
- dependency-name: coverage
  dependency-version: 7.16.2
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: patch-and-minor
- dependency-name: ruff
  dependency-version: 0.16.10
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: patch-and-minor
- dependency-name: boto3
  dependency-version: 1.43.108
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: patch-and-minor
- dependency-name: charset-normalizer
  dependency-version: 3.5.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: patch-and-minor
- dependency-name: idna
  dependency-version: '3.20'
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: patch-and-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update Python code labels Oct 9, 2026
@shared-merge-writeback
shared-merge-writeback Bot enabled auto-merge (squash) October 9, 2026 20:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update Python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants