Skip to content

chore(deps): bump pypdf from 6.15.0 to 6.16.1 in the uv group across 1 directory - #783

Closed
dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/uv/uv-2a840bf68d
Closed

chore(deps): bump pypdf from 6.15.0 to 6.16.1 in the uv group across 1 directory#783
dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/uv/uv-2a840bf68d

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 2, 2026

Copy link
Copy Markdown
Contributor

Verified successor disposition — 2026-09-05

Fresh exact-tree verification:

  • base: develop@e06b1f3fb10903569124af011da213951e6e2473
  • exact head: a72c9a0607b32e330e0a05fee90156e2316b26ba
  • effective diff: only uv.lock
  • unique change: pypdf 6.15.0 -> 6.16.1 (sdist/wheel hashes updated accordingly)

Canonical successor #787 at exact head ebd6c71ba17151228c23d32705687097290c0c89 fully and more strongly inherits this valid dependency/security delta:

  • declares pypdf>=6.16.2,<7.0 in pyproject.toml rather than relying on a lock-only change;
  • locks 6.16.2, which includes the 6.16.0/6.16.1 security fixes represented here;
  • adds the dependency-floor/security regression and doctoring/traceability;
  • keeps the canonical request-body/form-validation/security lineage in one Draft PR.

There is no other source, test, fixture, contract, documentation, workflow, or release delta in this Dependabot PR to preserve. No check/review/status evidence from this branch transfers to #787.

Closing under the fleet rule for a verified successor that completely inherits every valid semantic delta. This is not a merge, bypass, force-push, destructive rebase, or count-only cleanup; #787 remains Draft until its own unchanged exact head satisfies then-live checks, review, and protection.

Bumps the uv group with 1 update in the / directory: [pypdf](https://github.com/py-pdf/pypdf).


Updates `pypdf` from 6.15.0 to 6.16.1
- [Release notes](https://github.com/py-pdf/pypdf/releases)
- [Changelog](https://github.com/py-pdf/pypdf/blob/main/CHANGELOG.md)
- [Commits](py-pdf/pypdf@6.15.0...6.16.1)

---
updated-dependencies:
- dependency-name: pypdf
  dependency-version: 6.16.1
  dependency-type: direct:production
  dependency-group: uv
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Sep 2, 2026
@dependabot
dependabot Bot requested a review from seonghobae as a code owner September 2, 2026 09:49
@dependabot dependabot Bot added the python:uv Pull requests that update python:uv code label Sep 2, 2026

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Devin Review: No Issues Found

Devin Review analyzed this PR and found no bugs or issues to report.

Devin Review

@cwl-noema-review cwl-noema-review Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Noema LLM review

The PR updates the pypdf dependency from 6.15.0 to 6.16.1 in the uv.lock file. This is a routine dependency bump. The changes are limited to the version string, sdist URL/hash, and wheel URL/hash, which are consistent with a standard package update.

Reviewed changed lines

  • uv.lock:932 (LEFT): Updating pypdf version from 6.15.0 to 6.16.1.
  • uv.lock:937 (LEFT): Updating sdist source and hash for pypdf 6.16.1.
  • uv.lock:939 (LEFT): Updating wheel source and hash for pypdf 6.16.1.

Adversarial validation

  • uv.lock:932 (LEFT) falsified: The version bump introduces a breaking change or security regression in PDF processing. — The change is a minor version bump (6.15.0 -> 6.16.1) which typically contains bug fixes and features without breaking the public API.
  • Residual risk: Low. Dependency updates can introduce behavioral changes in PDF parsing, but this is a minor version bump.

Findings

  • No blocking findings.
  • Result: APPROVE
  • Head SHA: a72c9a0607b32e330e0a05fee90156e2316b26ba
  • Reviewer credential: noema-review-github-app-refresh
  • Actor: cwl-noema-review[bot]

@seonghobae seonghobae closed this Sep 5, 2026
@dependabot @github

dependabot Bot commented on behalf of github Sep 5, 2026

Copy link
Copy Markdown
Contributor Author

This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests.

To ignore these dependencies, configure ignore rules in dependabot.yml

@dependabot
dependabot Bot deleted the dependabot/uv/uv-2a840bf68d branch September 5, 2026 07:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant