build(deps): bump the pip group with 11 updates#80
Closed
dependabot[bot] wants to merge 1 commit intodevelopfrom
Closed
build(deps): bump the pip group with 11 updates#80dependabot[bot] wants to merge 1 commit intodevelopfrom
dependabot[bot] wants to merge 1 commit intodevelopfrom
Conversation
Bumps the pip group with 11 updates: | Package | From | To | | --- | --- | --- | | [tzdata](https://github.com/python/tzdata) | `2025.2` | `2025.3` | | [mypy](https://github.com/python/mypy) | `1.18.2` | `1.19.1` | | [ruff](https://github.com/astral-sh/ruff) | `0.14.6` | `0.14.14` | | [bandit](https://github.com/PyCQA/bandit) | `1.9.2` | `1.9.3` | | [zizmor](https://github.com/zizmorcore/zizmor) | `1.17.0` | `1.22.0` | | [semgrep](https://github.com/semgrep/semgrep) | `1.144.0` | `1.149.0` | | [basedpyright](https://github.com/detachhead/basedpyright) | `1.34.0` | `1.37.2` | | [types-setuptools](https://github.com/typeshed-internal/stub_uploader) | `80.9.0.20250822` | `80.10.0.20260124` | | [pytest](https://github.com/pytest-dev/pytest) | `8.4.2` | `9.0.2` | | [coverage[toml]](https://github.com/coveragepy/coveragepy) | `7.12.0` | `7.13.2` | | [pre-commit](https://github.com/pre-commit/pre-commit) | `4.5.0` | `4.5.1` | Updates `tzdata` from 2025.2 to 2025.3 - [Release notes](https://github.com/python/tzdata/releases) - [Changelog](https://github.com/python/tzdata/blob/master/NEWS.md) - [Commits](python/tzdata@2025.2...2025.3) Updates `mypy` from 1.18.2 to 1.19.1 - [Changelog](https://github.com/python/mypy/blob/master/CHANGELOG.md) - [Commits](python/mypy@v1.18.2...v1.19.1) Updates `ruff` from 0.14.6 to 0.14.14 - [Release notes](https://github.com/astral-sh/ruff/releases) - [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md) - [Commits](astral-sh/ruff@0.14.6...0.14.14) Updates `bandit` from 1.9.2 to 1.9.3 - [Release notes](https://github.com/PyCQA/bandit/releases) - [Commits](PyCQA/bandit@1.9.2...1.9.3) Updates `zizmor` from 1.17.0 to 1.22.0 - [Release notes](https://github.com/zizmorcore/zizmor/releases) - [Changelog](https://github.com/zizmorcore/zizmor/blob/main/docs/release-notes.md) - [Commits](zizmorcore/zizmor@v1.17.0...v1.22.0) Updates `semgrep` from 1.144.0 to 1.149.0 - [Release notes](https://github.com/semgrep/semgrep/releases) - [Changelog](https://github.com/semgrep/semgrep/blob/develop/CHANGELOG.md) - [Commits](semgrep/semgrep@v1.144.0...v1.149.0) Updates `basedpyright` from 1.34.0 to 1.37.2 - [Release notes](https://github.com/detachhead/basedpyright/releases) - [Commits](DetachHead/basedpyright@v1.34.0...v1.37.2) Updates `types-setuptools` from 80.9.0.20250822 to 80.10.0.20260124 - [Commits](https://github.com/typeshed-internal/stub_uploader/commits) Updates `pytest` from 8.4.2 to 9.0.2 - [Release notes](https://github.com/pytest-dev/pytest/releases) - [Changelog](https://github.com/pytest-dev/pytest/blob/main/CHANGELOG.rst) - [Commits](pytest-dev/pytest@8.4.2...9.0.2) Updates `coverage[toml]` from 7.12.0 to 7.13.2 - [Release notes](https://github.com/coveragepy/coveragepy/releases) - [Changelog](https://github.com/coveragepy/coveragepy/blob/main/CHANGES.rst) - [Commits](coveragepy/coveragepy@7.12.0...7.13.2) Updates `pre-commit` from 4.5.0 to 4.5.1 - [Release notes](https://github.com/pre-commit/pre-commit/releases) - [Changelog](https://github.com/pre-commit/pre-commit/blob/main/CHANGELOG.md) - [Commits](pre-commit/pre-commit@v4.5.0...v4.5.1) --- updated-dependencies: - dependency-name: tzdata dependency-version: '2025.3' dependency-type: direct:production update-type: version-update:semver-minor dependency-group: pip - dependency-name: mypy dependency-version: 1.19.1 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: pip - dependency-name: ruff dependency-version: 0.14.14 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: pip - dependency-name: bandit dependency-version: 1.9.3 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: pip - dependency-name: zizmor dependency-version: 1.22.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: pip - dependency-name: semgrep dependency-version: 1.149.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: pip - dependency-name: basedpyright dependency-version: 1.37.2 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: pip - dependency-name: types-setuptools dependency-version: 80.10.0.20260124 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: pip - dependency-name: pytest dependency-version: 9.0.2 dependency-type: direct:development update-type: version-update:semver-major dependency-group: pip - dependency-name: coverage[toml] dependency-version: 7.13.2 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: pip - dependency-name: pre-commit dependency-version: 4.5.1 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: pip ... Signed-off-by: dependabot[bot] <support@github.com>
Contributor
Author
|
This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests. To ignore these dependencies, configure ignore rules in dependabot.yml |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the pip group with 11 updates:
2025.22025.31.18.21.19.10.14.60.14.141.9.21.9.31.17.01.22.01.144.01.149.01.34.01.37.280.9.0.2025082280.10.0.202601248.4.29.0.27.12.07.13.24.5.04.5.1Updates
tzdatafrom 2025.2 to 2025.3Release notes
Sourced from tzdata's releases.
Changelog
Sourced from tzdata's changelog.
Commits
d14cebcUpdate tzdata to version '2025c'4045188Bump actions/checkout from 5 to 6 in the actions group (#117)9b58dd1Stop requiringpytest-subtestsfor python>3.9, it has been incorporated int...7dc1b6cUpdate pre-commit reposa9c68aeAdd newlines to update PR description and commit (#106)d619f31Test Python 3.14tb5ab93fVerify signatures of tarballs (#108)6f866b8Use raw strings for regexb1b3051Fix dependabot configdddc234CommitUpdates
mypyfrom 1.18.2 to 1.19.1Changelog
Sourced from mypy's changelog.
... (truncated)
Commits
412c19aBump version to 1.19.120aea0aUpdate changelog for 1.19.1 (#20414)2b23b50Serialize raw errors in cache metas (#20372)f60f90fFail on PyPy in main instead of setup.py (#20389)58d485bFail with an explicit error on PyPy (#20384)a4b31a2Allowtypes.NoneTypein match cases (#20383)8a6eff4[mypyc] fix generator regression with empty tuple (#20371)70eceeaFix noncommutative joins with bounded TypeVars (#20345)3890fc4Fix crash involving Unpack-ed TypeVarTuple (#20323)c93d917Fix crash on star import of redefinition (#20333)Updates
rufffrom 0.14.6 to 0.14.14Release notes
Sourced from ruff's releases.
... (truncated)
Changelog
Sourced from ruff's changelog.
... (truncated)
Commits
8b2e7b3Prepare release v0.14.14 (#22813)4c7d1f5[ty] InferTypedDicttypes with >=1 required key as being always truthy (#2...b7de434add CCfW hooks (#22803)b912dfc[pyupgrade] ApplyUP045to string arguments oftyping.cast(#22320)1ff062d[ty] Improve completion rankings for raise-from/except contexts (#22775)7e408a5Update dependency wrangler to v4.59.1 (#22793)ceb876b[flake8-pyi] Fix inconsistent handling of forward references for__new__,...c5b4ee6[ty] Support solving generics involving PEP 695 type aliases (#22678)b9a6129[ty] Improve support for kwarg splats in dictionary literals (#22781)f516d47Update contributing guide for adding a new rule (#22779)Updates
banditfrom 1.9.2 to 1.9.3Release notes
Sourced from bandit's releases.
Commits
765f00dLimit B614 to torch.load deserializers (#1348)06fbbabBump docker/setup-buildx-action from 3.11.1 to 3.12.0 (#1347)36d6f3cUpdate tox tests for Python 3.10 (#1346)da0d338[pre-commit.ci] pre-commit autoupdate (#1341)649b9bdAdd check for hardcoded passwords in dicts. (#1338)3c56109Fix B608 to detectVALUES(without space (#1337)b790ce2[pre-commit.ci] pre-commit autoupdate (#1335)0b73bbeBump actions/checkout from 5 to 6 (#1334)Updates
zizmorfrom 1.17.0 to 1.22.0Release notes
Sourced from zizmor's releases.
... (truncated)
Changelog
Sourced from zizmor's changelog.
... (truncated)
Commits
94308f6zizmor 1.22.0 (#1539)951d2c8Add 'crater' tests (#1538)13c1b65Handle CRLF in EmplaceComment (#1536)601bbbaBump trophies (#1535)de617a2Drop 'custom shell' finding to auditor persona (#1532)5175a6czizmor 1.21.0 (#1529)b3f84f4yamlpatch 0.10.0 (#1528)20b24ffyamlpath 0.33.0 (#1527)4815c16Support auto-fixes for unpinned-uses (#1525)e611eaeDocument hk integration (#1522)Updates
semgrepfrom 1.144.0 to 1.149.0Release notes
Sourced from semgrep's releases.
... (truncated)
Changelog
Sourced from semgrep's changelog.
... (truncated)
Commits
50257f6chore: release version 1.149.0c8c60d5semgrep/semgrep-proprietary#54232a8672dchore: removetoxsemgrep/semgrep-proprietary#542123c3421chore: don't versionsemgrep.opam/OSS/dune-project. (semgrep/semgrep-prop...b91705afix(ci): Update setup-ocaml action for Cygwin issue (semgrep/semgrep-propriet...203b28dfix(ci): fix jsonnet templating s.t env isn't at job-level (semgrep/semgrep-p...1a1017dfix(ci): Fix benchmarking regression PR comment (semgrep/semgrep-proprietary#...b7584b8feat(perf): cacheTargetsemgrep/semgrep-proprietary#54077e33fcfsemgrep/semgrep-proprietary#5382e922050Cron - update semgrep-rules and semgrep-rules-pro submodules (semgrep/semgrep...Updates
basedpyrightfrom 1.34.0 to 1.37.2Commits
80b91e21.37.2ff32e9bbump python dependencies1e3c703No hover messages or jump-to-definition for literals (#1706)c94cbcafix reference to non-existent baseline mode in the docsb5a482d1.37.1532288fignore lint errors in new script from upstreama3c2773fixfix:syncpacknpm scriptb9a3d2ffix mismatched npm package versions6bfe3fcfix type errors/lint erros from mergeac32e65update npm lockfileUpdates
types-setuptoolsfrom 80.9.0.20250822 to 80.10.0.20260124Commits
Updates
pytestfrom 8.4.2 to 9.0.2Release notes
Sourced from pytest's releases.
... (truncated)
Commits
3d10b51Prepare release version 9.0.2188750bMerge pull request #14030 from pytest-dev/patchback/backports/9.0.x/1e4b01d1f...b7d7befMerge pull request #14014 from bluetech/compat-notebd08e85Merge pull request #14013 from pytest-dev/patchback/backports/9.0.x/922b60377...bc78386Add CLI options reference documentation (#13930)5a4e398Fix docs typo (#14005) (#14008)d7ae6dfMerge pull request #14006 from pytest-dev/maintenance/update-plugin-list-tmpl...556f6a2pre-commit: fix rst-lint after new release (#13999) (#14001)c60fbe6Fix quadratic-time behavior when handlingunittestsubtests in Python 3.10 ...73d9b01Merge pull request #13995 from nicoddemus/patchback/backports/9.0.x/1b5200c0f...Updates
coverage[toml]from 7.12.0 to 7.13.2Release notes
Sourced from coverage[toml]'s releases.
Changelog
Sourced from coverage[toml]'s changelog.
... (truncated)
Commits
513e971docs: sample HTML for 7.13.227a8230docs: prep for 7.13.227d8daarefactor: plural does morea2f248cfix: stdlib might be through a symlink. #2115bc52a22debug: re-organize Matchers to sho...Description has been truncated