build(deps): bump the python-deps group across 1 directory with 5 updates - #66
Closed
dependabot[bot] wants to merge 2 commits into
Closed
build(deps): bump the python-deps group across 1 directory with 5 updates#66dependabot[bot] wants to merge 2 commits into
dependabot[bot] wants to merge 2 commits into
Conversation
wshallwshall
added a commit
that referenced
this pull request
Jul 30, 2026
PR #80 appended eight Steps-view items to docs/BACKLOG.md without the status banner every numbered item must carry, so tests/test_backlog_status_check.py::test_the_real_backlog_satisfies_the_invariant began failing on main itself (8 errors, first at line 6905). Because GitHub tests each PR merged into main, every open PR inherited the failure: #81, #74, #71, #66 and #60 were all blocked, three of them with auto-merge armed and unable to fire. Adds exactly one leading banner per item. Seven use the open/prioritized form; #239 uses the partial form, because its measurement ran and is recorded on PR #81 while the re-runnable scripts/quality/lens_coverage.py is still unmerged -- the number is not yet reproducible from main. The banners are deliberately minimal and do not re-litigate any item's verdict. #234 in particular is left explicitly unsettled rather than entrenched: it was filed as "revisit, not a bug" after the owner asked for a fix, and that framing is still open. Verified: scripts/docs/backlog_status_check.py exits 0 (237 items) and tests/test_backlog_status_check.py is 15 passed, was 14 passed 1 failed. Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
…ates Bumps the python-deps group with 5 updates in the / directory: | Package | From | To | | --- | --- | --- | | [annotated-types](https://github.com/annotated-types/annotated-types) | `0.7.0` | `0.8.0` | | [fastapi](https://github.com/fastapi/fastapi) | `0.139.2` | `0.140.0` | | [prometheus-client](https://github.com/prometheus/client_python) | `0.25.0` | `0.26.0` | | [ruff](https://github.com/astral-sh/ruff) | `0.15.22` | `0.16.0` | | [zizmor](https://github.com/zizmorcore/zizmor) | `1.5.2` | `1.28.0` | Updates `annotated-types` from 0.7.0 to 0.8.0 - [Release notes](https://github.com/annotated-types/annotated-types/releases) - [Commits](annotated-types/annotated-types@v0.7.0...v0.8.0) Updates `fastapi` from 0.139.2 to 0.140.0 - [Release notes](https://github.com/fastapi/fastapi/releases) - [Commits](fastapi/fastapi@0.139.2...0.140.0) Updates `prometheus-client` from 0.25.0 to 0.26.0 - [Release notes](https://github.com/prometheus/client_python/releases) - [Commits](prometheus/client_python@v0.25.0...v0.26.0) Updates `ruff` from 0.15.22 to 0.16.0 - [Release notes](https://github.com/astral-sh/ruff/releases) - [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md) - [Commits](astral-sh/ruff@0.15.22...0.16.0) Updates `zizmor` from 1.5.2 to 1.28.0 - [Release notes](https://github.com/zizmorcore/zizmor/releases) - [Changelog](https://github.com/zizmorcore/zizmor/blob/main/docs/release-notes.md) - [Commits](zizmorcore/zizmor@v1.5.2...v1.28.0) --- updated-dependencies: - dependency-name: annotated-types dependency-version: 0.8.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: python-deps - dependency-name: fastapi dependency-version: 0.140.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: python-deps - dependency-name: prometheus-client dependency-version: 0.26.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: python-deps - dependency-name: ruff dependency-version: 0.16.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: python-deps - dependency-name: zizmor dependency-version: 1.28.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: python-deps ... Signed-off-by: dependabot[bot] <support@github.com>
dependabot
Bot
force-pushed
the
dependabot/uv/python-deps-eb7932d1b9
branch
from
August 1, 2026 04:58
7d591e4 to
f066c2b
Compare
wshallwshall
added a commit
that referenced
this pull request
Aug 1, 2026
… that asked the wrong question, and a test that measured the scheduler (#121) * ci(dependabot): the uv ecosystem widened the caps it was supposed to respect Dependabot rewrites a declared upper bound rather than respecting it, so a load-bearing cap in pyproject.toml is decorative unless it is restated as an ignore range here. PR #66 widened `annotated-types<0.8` -> `<0.9` (both declaration sites) and `ruff>=0.4,<0.16` -> `<0.17`; the lock resync then propagated 0.8.0/0.16.0 into constraints.lock, so ci.yml's `--constraint` pinned CI *to* the broken versions — 8 FHIR ImportErrors on windows-2022 and 868 ruff findings on ubuntu. `python-deps` groups on `*`, so the two of them red the whole batch and hold every benign bump in it hostage. The ignore entries suppress the security track for the named RANGE too; that is accepted and recorded inline, because detection does not depend on Dependabot — the required `pip-audit -r requirements.lock` gate reds within ~24h and a human lifts the pyproject cap, which is the real ceiling either way. Also corrects two comments the evidence retired: the header still claimed no committed lockfile exists, and the PEP 735 question is settled — PR #66 bumped `zizmor` inside `[dependency-groups].ci-scanners`, so the uv ecosystem does reach it. * docs(deps): three cap comments describe an install command CI no longer runs Both annotated-types and ruff caps said "CI installs with a FRESH resolve (uv pip install -e ...)" in the present tense. It does not: every uv install in ci.yml, quality-advisory.yml and dast.yml passes `--constraint constraints.lock`. That mattered for more than tidiness — it framed the cap as a CI workaround with "or once CI installs from the hashed lock" as an exit condition, which is wrong in both directions. The cap bounds the RESOLVER, and the lock carries whatever the resolver already chose, so installing from the lock would not retire it; meanwhile it is also what bounds every resolve CI never sees (an end user's `pip install messagefoundry[fhir]`, the local dev venv, dispatch-only legs). The fhir extra additionally claimed the cap "lives here rather than in [project.dependencies]" while an identical cap sat 67 lines above it. Stops restating the ruff finding count: 626, ~525 and 868 were three numbers for one fact at two different scopes. States it once, as a bound, dated. No version specifier changed and no lock is touched — comments only. * ci(zizmor): a zizmor version bump never runs zizmor The paths filter listed only `.github/**`, but zizmor's own pinned version lives in pyproject.toml's [dependency-groups].ci-scanners and reaches the install step through ci/locks/ci-scanners.lock — outside the filter. So PR #66, which bumps zizmor 1.5.2 -> 1.28.0, ran 33 check contexts and not one of them was zizmor: a 23-minor jump against a deliberately clean baseline would have been adjudicated by the 06:00 cron, against main, after merge. Adds the lock to the filter and corrects the header, whose "a Python / docs / test PR cannot change its result" is precisely what a lock-only bump disproves. The lock also carries bandit and pip-audit, so their bumps now trigger this workflow too (~1 billed min) — arguably correct, since bandit is the other clean-baseline gate. Also states the filter once: three docs restated its contents verbatim, which is three things to forget when it changes. They now point at the workflow. * ci(dependabot): the published-GHSA gate asked about the wrong versions fetch-metadata's scalar `previous-version` is the FIRST dependency's, even on a grouped PR — output.ts:27 reads `firstDependency?.prevVersion` (verified at the pinned SHA 25dd0e34, v3.1.0). The gate applied it to every name in the group, so on a five-dep PR it asked about four versions the PR does not touch. That fails in the PERMISSIVE direction: advisory ranges are mostly open at the bottom, so a low first-dep version confirms almost anything. Demonstrated on the real shape — a group of aiohttp 3.9.0 + Pillow 10.2.0 queries `pillow@3.9.0` (a 2016 release) and returns a confirmation. Switches to `updated-dependencies-json`, which carries a per-dependency prevVersion, and closes a fail-open case the scalar never had: update_metadata.ts:101 falls back to an EMPTY prevVersion for index > 0, and an unknown previous version must deny rather than skip on a gate whose contract is to fail closed. Verified by executing the step against a stubbed advisories endpoint: each dep is queried at its own version; no-advisory, empty-prevVersion, malformed-metadata and version-track all deny. The old loop was run against the same input first, to confirm the test can see the defect. Also adds a 5-day cooldown to github-actions — the one ecosystem where auto-merge demonstrably fires, and the one where a compromised release runs inside CI with the job's token. SHA-pinning stops tag mutation, not a malicious new release. And scopes the IN SCOPE header, which read as though uv routinely auto-merges; in practice `patterns: ["*"]` plus the deny-list makes it review-by-default. * test(coord): the eight-claimant test asserted a timing artifact, not mutual exclusion The lock is correct. `test_only_one_of_eight_concurrent_claimants_wins` counted winners, which measures the scheduler: the barrier releases the cohort together, but each process then runs Enter-CoordLock's own prologue — a `git rev-parse` spawn at lock.ps1:47 — before its deadline is set at lock.ps1:56, and nothing synchronizes that. A winner count tolerates only (hold - timeout) = 500 ms of that skew. So a straggler that arrives after the winner released acquires legitimately and is counted as a violation. That is what failed on windows-2025 in run 30672004091, and it is not a flake: under 40 CPU burners on a 20-core box the old assertion fails 6/6 (2-3 winners), the new one passes 6/6. Asserts occupancy instead — a CreateNew sentinel taken under the lock, the same atomic test-and-set the lock itself uses, with no reference to a clock. Validated both directions: with Enter-CoordLock stubbed to a no-op it fails with 7 simultaneous holders, so the assertion can see the defect class it claims to exclude. Cost: hold_ms 1500 -> 8000 to keep a ~3.3x margin over the measured skew, so this test's floor wall-time is ~9 s. * ci: give the unconstrained install legs the same version floor as ci.yml Every uv install in ci.yml, quality-advisory.yml and dast.yml passes `--constraint constraints.lock`; the four plain-pip legs did not, so they re-resolved from pyproject's `>=` floors and would have adopted ruff 0.16.0 and annotated-types 0.8.0 on the day those shipped, exactly as PR #66 did. A benchmark leg is the worst place for that — a silent dependency change reads as a performance regression. freethread-smoke stays unconstrained on purpose and now says so. The lock records what resolved for the GIL build; pinning it there can leave a dep with no cp314t wheel at that version and send pip to a source build, so the canary would stop measuring free-threading and start measuring the lock. * docs(ci): the zizmor filter pointer pointed at the line it was on The earlier "state it once, link to it" edit replaced the restated filter contents with "(see `zizmor.yml`)" at four sites — but every one of those lines already has zizmor.yml as its subject, so the pointer was circular. CI.md:147 was the worst: "`zizmor.yml` (which is already paths-filtered (see `zizmor.yml`))". Drops the pointer instead. The subject is already named, so plain "paths-filtered" states the fact without restating its contents, which is what the rule was after.
Contributor
Author
|
Looks like these dependencies are updatable in another way, so this is no longer needed. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the python-deps group with 5 updates in the / directory:
0.7.00.8.00.139.20.140.00.25.00.26.00.15.220.16.01.5.21.28.0Updates
annotated-typesfrom 0.7.0 to 0.8.0Release notes
Sourced from annotated-types's releases.
Commits
9eb9668Prepare for 0.8.0 release (#103)10b7764Fix typo inLendocstring (#100)955f757Add support for Python 3.14 and drop EOL 3.8-3.9 (#97)bd280feAdded Python 3.14 to the test matrix (#96)a471bb7Add SPDX license expression (#92)eab91d9Fix string predicate names in doc (#90)03ad9c3add CI for PyPy3.11 and fix test (issue 71) (#88)5ae6043fix: typo in README.md (#87)b60ad7bUpdate license-files to be PEP-639 compliant (#85) (#86)3fbeb6dFix docstring ofTimezone(#84)Updates
fastapifrom 0.139.2 to 0.140.0Release notes
Sourced from fastapi's releases.
Commits
255b912🔖 Release version 0.140.0 (#16050)892eacd📝 Update release notes0270829⚡️ Reduce memory usage in dependencies (#16049)ae031be📝 Update release notesf3644b3📝 Fix links in docs (#15967)1e24ca0📝 Update release notes513c396👷 Add CI memory benchmark (#16046)a64dfbb📝 Update release notes4f15548📝 Add Library Skills documentation (#16041)704fbe1📝 Update release notesUpdates
prometheus-clientfrom 0.25.0 to 0.26.0Release notes
Sourced from prometheus-client's releases.
Commits
9b6b971Release v0.26.0fb072c2Fix operator precedence allowing exemplars on any metric type (#1188)6e22fb5Remove nameless collectors from the registry on unregister (#1191)5b09479Parse the native histogram sum as a float (#1192)769b415fix: make test suite pass on Windows and Python 3.12+ (#1185)d0b497fUpdate common Prometheus files (#1195)75603d7Update common Prometheus files (#1194)fb2351fDo not emit a leading zero in floatToGoString exponents >= 10 (#1190)a39a697Validate Enum arguments before registering the collector (#1189)a96f6f4Add TLS version parameters for start_wsgi_server (#1178)Updates
rufffrom 0.15.22 to 0.16.0Release notes
Sourced from ruff's releases.
... (truncated)
Changelog
Sourced from ruff's changelog.
... (truncated)
Commits
a2635fdBump 0.16.0 (#27136)3433449[ty] Reuse full call diagnostics for implicit setter calls (#27115)2240070Reflectruff: ignoreand--add-ignorestabilization in documentation (#27...17ef711Stabilize--add-ignore(#27125)ef912bbAdd newly stabilized rules to defaults (#27055)b30f040Stabilize new default rules (#27035)bcd70c5Exclude Markdown files fromformat-devruns (#27052)87e51e2Fixformat --checkspans for syntax errors (#27045)afe2723[flake8-gettext] Stabilize qualified-name and built-in binding resolution (...a9702d8[flake8-bandit] Stabilize string literal binding resolution (S310) (#26944)Updates
zizmorfrom 1.5.2 to 1.28.0Release notes
Sourced from zizmor's releases.
... (truncated)
Changelog
Sourced from zizmor's changelog.
... (truncated)
Commits
4381cc6Prep zizmor 1.28.0 (#2214)724d0e8Remove a redundant debug log (#2213)5a01aad[BOT] update JSON schemas from SchemaStore (#2208)6138a6dAddsbtto known Dependabot ecosystems (#2211)23878aachore(deps): bump the cargo group with 4 updates (#2206)5e839dbchore(deps): bump the github-actions group with 3 updates (#2207)297975adependabot-cooldown: honor GitHub's new default (#2193)b648e57Improve error message on remote ambiguous input refs (#2205)d06c823Dedupe a function in the GitHub APIs (#2204)82f5bf6github-env: don't flag all-literal printf arguments (#2201)