Skip to content

build(deps): bump the python-dependencies group with 3 updates - #30

Merged
github-actions[bot] merged 1 commit into
mainfrom
dependabot/uv/python-dependencies-c4106f2c1f
Sep 28, 2026
Merged

github-actions[bot] merged 1 commit into
mainfrom
dependabot/uv/python-dependencies-c4106f2c1f

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 28, 2026

Copy link
Copy Markdown
Contributor

Bumps the python-dependencies group with 3 updates: filelock, niquests and ruff.

Updates filelock from 4.0.0 to 4.0.3

Release notes

Sourced from filelock's releases.

4.0.3

What's Changed

Full Changelog: tox-dev/filelock@4.0.2...4.0.3

4.0.2

What's Changed

New Contributors

Full Changelog: tox-dev/filelock@4.0.1...4.0.2

4.0.1

What's Changed

New Contributors

Full Changelog: tox-dev/filelock@4.0.0...4.0.1

Changelog

Sourced from filelock's changelog.

########### Changelog ###########

.. towncrier-draft-entries:: Unreleased

.. towncrier release notes start


4.0.5 (2026-09-28)


  • Fix MarkerSoftFileLock acquisition and prevent contenders from evicting live protocol-2 owners after two seconds. Reclaim recognized records after owner death; preserve unknown contracts. :pr:749
  • Honor instance timeout and blocking settings in sync and async ReadWriteLock acquisition, including waits between tasks on one instance. Preserve explicit per-call overrides. :pr:750
  • Skip access-denial checks when the process can read mode-0o000 files. Keep mode-bit checks enabled for privileged processes on filesystems that support POSIX permissions. :pr:753
  • Skip vanished StrictSoftFileLock claims after a read-permission retry expires. Recheck the directory before raising a protocol error so concurrent removal does not turn a stale claim listing into an acquisition failure. :pr:754
  • Reject negative timeouts other than -1 in blocking AsyncReadWriteLock and AsyncSoftReadWriteLock acquisitions. Keep -1 as an unlimited wait and ignore timeouts when blocking=False. :pr:755

4.0.4 (2026-09-26)


  • Hostnames that still differ after their first 253 escaped characters now publish distinct owners, so a soft lock no longer takes another such host's live holder for its own and reclaims its marker. :pr:748

4.0.3 (2026-09-23)


  • Importing filelock on CPython 3.10 or 3.11 no longer makes new threads fail with RuntimeError: Cannot install a trace function while another trace function is being installed under coverage or a debugger. filelock skips its fork-safety audit hook there, so forking from inside a thread's own lock-state transition no longer raises immediately on those versions. :pr:747

4.0.2 (2026-09-23)


  • Concurrent acquire() and release() on a thread_local=False lock no longer leak the OS lock, close a descriptor twice, drop a lease token, or leave a false deadlock after a cross-thread release (:issue:744). :pr:745
  • :class:~filelock.AsyncReadWriteLock and :class:~filelock.AsyncSoftReadWriteLock now give each asyncio task its own hold, so tasks sharing one instance no longer enter the write lock together. :pr:746
  • Correct the async cache example to create its data directory and clarify automatic creation of lock-file parent directories. :pr:740
  • Exclude sphinx-llm 1.1.0 from documentation dependencies because its Markdown builder emits unknown-node warnings. :pr:742

... (truncated)

Commits
  • 5283806 Release 4.0.3
  • fd10e07 🐛 fix(api): skip the fork audit hook on CPython <3.12 (#747)
  • 2d4530f Release 4.0.2
  • 6c46312 🐛 fix(async-rw): give each task its own hold (#746)
  • fe0e99d 🐛 fix(api): serialize concurrent transitions on shared locks (#745)
  • b26beda build(deps): bump astral-sh/setup-uv from 10.0.1 to 10.1.0 in the github-acti...
  • 10572ec fix: ignore broken sphinx-llm release (#742)
  • 6c10af3 [pre-commit.ci] pre-commit autoupdate (#741)
  • 9380408 docs: create the data directory in the async cache example (#740)
  • b5016c4 Release 4.0.1
  • Additional commits viewable in compare view

Updates niquests from 3.21.1 to 3.21.2

Release notes

Sourced from niquests's releases.

Version 3.21.2

3.21.2 (2026-09-23)

Changed

  • Minor performance improvement in CaseInsensitiveDict, with an expected gain of up to 1%.
  • Reduced overhead in response attribute access and request preparation.
  • python -m niquests.help now reports the WebSocket backend and version through websocket.backend and websocket.version, replacing websocket.wsproto.

Fixed

  • Fixed a quadratic performance issue in iter_lines() when processing long lines.
  • Corrected the generic key type in CaseInsensitiveDict to require str or bytes.
  • Fixed an intermittent WASI HTTP 0.2 upload failure when the host closes the output stream after the request body is written.

Misc

  • Officially recognized websockets as a supported WebSocket backend alongside wsproto. Requires Python 3.9 or newer and urllib3-future 2.25.900 or newer. Install it with pip install "niquests[ws-fast]". When both backends are installed, use wss+fast://example.org/ to explicitly select websockets. Run python -m niquests.help to check which backend is selected by default.
  • Documented full-duplex WebSocket communication over HTTP/1.1 with urllib3-future 2.25.900 or newer.
  • Documented installation via a prebuilt alternative wheel that isolates urllib3-future, with no local build required.
Changelog

Sourced from niquests's changelog.

3.21.2 (2026-09-23)

Changed

  • Minor performance improvement in CaseInsensitiveDict, with an expected gain of up to 1%.
  • Reduced overhead in response attribute access and request preparation.
  • python -m niquests.help now reports the WebSocket backend and version through websocket.backend and websocket.version, replacing websocket.wsproto.

Fixed

  • Fixed a quadratic performance issue in iter_lines() when processing long lines.
  • Corrected the generic key type in CaseInsensitiveDict to require str or bytes.
  • Fixed an intermittent WASI HTTP 0.2 upload failure when the host closes the output stream after the request body is written.

Misc

  • Officially recognized websockets as a supported WebSocket backend alongside wsproto. Requires Python 3.9 or newer and urllib3-future 2.25.900 or newer. Install it with pip install "niquests[ws-fast]". When both backends are installed, use wss+fast://example.org/ to explicitly select websockets. Run python -m niquests.help to check which backend is selected by default.
  • Documented full-duplex WebSocket communication over HTTP/1.1 with urllib3-future 2.25.900 or newer.
  • Documented installation via a prebuilt alternative wheel that isolates urllib3-future, with no local build required.
Commits
  • fd4cf2a Release 3.21.2 (#467)
  • ffe109e fix: unrelated bug in cert_store_stats upstream
  • 113e829 fix: wasi http p2 intermittent stream upload failure
  • 78548e5 test: windows raise timeouterror for local probe
  • 85f35a8 chore: simplify README.md
  • bbb4087 docs: write changelog for 3.21.2
  • 691c4bf docs: mention alt whl for u3f isolation
  • 779c6a7 docs: mention support for alt ws backend "websockets"
  • 96843bf test: faster lima startup
  • 730135a test: ensure stability to iter_lines
  • Additional commits viewable in compare view

Updates ruff from 0.16.8 to 0.16.9

Release notes

Sourced from ruff's releases.

0.16.9

Release Notes

Released on 2026-09-24.

Preview features

  • [ruff] Avoid false positives for overloaded division (RUF069) (#28309)

Bug fixes

  • [flake8-bugbear] Avoid false positives for calls with keyword arguments (B009, B010, B043) (#28776)
  • [flake8-tidy-imports] Allow lazy imports to be used in deferred annotations (TID255) (#28767)

Rule changes

  • Update LibCST-based fixes for Python 3.15 (#28616)
  • [flake8-pyi] Mention stubs in the diagnostic message (PYI002) (#28542)

Documentation

  • Fix horizontal overflow on the rules documentation page (#28699)
  • Update rules table with category information (#28651)
  • [flake8-annotations] Clarify that ANN401 checks return types in addition to arguments (#28334)
  • [flake8-bugbear] Document type-checker interaction (B010) (#28509)
  • [flake8-comprehensions] Document map/generator exception behavior (C417) (#27794)
  • [ruff] Mention related isort settings (RUF022) (#28719)

Contributors

Install ruff 0.16.9

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/ruff/releases/download/0.16.9/ruff-installer.sh | sh

... (truncated)

Changelog

Sourced from ruff's changelog.

0.16.9

Released on 2026-09-24.

Preview features

  • [ruff] Avoid false positives for overloaded division (RUF069) (#28309)

Bug fixes

  • [flake8-bugbear] Avoid false positives for calls with keyword arguments (B009, B010, B043) (#28776)
  • [flake8-tidy-imports] Allow lazy imports to be used in deferred annotations (TID255) (#28767)

Rule changes

  • Update LibCST-based fixes for Python 3.15 (#28616)
  • [flake8-pyi] Mention stubs in the diagnostic message (PYI002) (#28542)

Documentation

  • Fix horizontal overflow on the rules documentation page (#28699)
  • Update rules table with category information (#28651)
  • [flake8-annotations] Clarify that ANN401 checks return types in addition to arguments (#28334)
  • [flake8-bugbear] Document type-checker interaction (B010) (#28509)
  • [flake8-comprehensions] Document map/generator exception behavior (C417) (#27794)
  • [ruff] Mention related isort settings (RUF022) (#28719)

Contributors

Commits
  • 0be08a2 Bump version to 0.16.9 (#28882)
  • b4920b7 Rename ruff_cli to ruff_command_line (#28881)
  • 47c751b Update dependency astral-sh/uv to v0.12.18 (#28880)
  • 8c244e5 [flake8-comprehensions] Document map/generator exception behavior (C417...
  • 5edf5a1 Use target form in rooster.version_files (#28876)
  • 915bb2b [ty] Prefer existing @ paths over response files in Ruff and ty (#28877)
  • 4710e1a ci(github): update version number in placeholder of issue template (#28871)
  • eedfc62 [ty] Propagate outer type context through cast calls (#28855)
  • ceaa6a0 [ty] Contain rendered code within Markdown fences (#28869)
  • dba0f30 authorize ruff-pre-commit dispatch via OIDC (#28867)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the python-dependencies group with 3 updates: [filelock](https://github.com/tox-dev/py-filelock), [niquests](https://github.com/jawah/niquests) and [ruff](https://github.com/astral-sh/ruff).


Updates `filelock` from 4.0.0 to 4.0.3
- [Release notes](https://github.com/tox-dev/py-filelock/releases)
- [Changelog](https://github.com/tox-dev/filelock/blob/main/docs/changelog.rst)
- [Commits](tox-dev/filelock@4.0.0...4.0.3)

Updates `niquests` from 3.21.1 to 3.21.2
- [Release notes](https://github.com/jawah/niquests/releases)
- [Changelog](https://github.com/jawah/niquests/blob/main/HISTORY.md)
- [Commits](jawah/niquests@v3.21.1...v3.21.2)

Updates `ruff` from 0.16.8 to 0.16.9
- [Release notes](https://github.com/astral-sh/ruff/releases)
- [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md)
- [Commits](astral-sh/ruff@0.16.8...0.16.9)

---
updated-dependencies:
- dependency-name: filelock
  dependency-version: 4.0.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python-dependencies
- dependency-name: niquests
  dependency-version: 3.21.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python-dependencies
- dependency-name: ruff
  dependency-version: 0.16.9
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: python-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels Sep 28, 2026
@github-actions
github-actions Bot enabled auto-merge (squash) September 28, 2026 06:55
@github-actions
github-actions Bot merged commit c8441a4 into main Sep 28, 2026
6 checks passed
@dependabot
dependabot Bot deleted the dependabot/uv/python-dependencies-c4106f2c1f branch September 28, 2026 06:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants