Skip to content

deps: bump ruff from 0.16.4 to 0.16.5 - #45

Merged
helebest merged 1 commit into
mainfrom
dependabot/uv/ruff-0.16.5
Aug 31, 2026
Merged

deps: bump ruff from 0.16.4 to 0.16.5#45
helebest merged 1 commit into
mainfrom
dependabot/uv/ruff-0.16.5

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 31, 2026

Copy link
Copy Markdown
Contributor

Bumps ruff from 0.16.4 to 0.16.5.

Release notes

Sourced from ruff's releases.

0.16.5

Release Notes

Released on 2026-08-27.

Preview features

  • Allow rules without codes (#28049)
  • Introduce category selectors (#27666)
  • Update preview default rules and categories (#27877)

Bug fixes

  • [flake8-async] Detect blocking generic HTTP requests (ASYNC210) (#28024)
  • [flake8-datetimez] Allow timezone-safe strptime chains (DTZ007) (#28023)
  • [flake8-simplify] Respect side effects in lambda defaults (SIM401) (#28000)

Server

  • Fix duplicated "of" in ClientOptions doc comment (#27978)

Documentation

  • Document rule acceptance guidelines (#27910)
  • Document the new category selectors (#27906)

Contributors

Install ruff 0.16.5

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/ruff/releases/download/0.16.5/ruff-installer.sh | sh

Install prebuilt binaries via powershell script

powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/ruff/releases/download/0.16.5/ruff-installer.ps1 | iex"

Download ruff 0.16.5

... (truncated)

Changelog

Sourced from ruff's changelog.

0.16.5

Released on 2026-08-27.

Preview features

  • Allow rules without codes (#28049)
  • Introduce category selectors (#27666)
  • Update preview default rules and categories (#27877)

Bug fixes

  • [flake8-async] Detect blocking generic HTTP requests (ASYNC210) (#28024)
  • [flake8-datetimez] Allow timezone-safe strptime chains (DTZ007) (#28023)
  • [flake8-simplify] Respect side effects in lambda defaults (SIM401) (#28000)

Server

  • Fix duplicated "of" in ClientOptions doc comment (#27978)

Documentation

  • Document rule acceptance guidelines (#27910)
  • Document the new category selectors (#27906)

Contributors

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [ruff](https://github.com/astral-sh/ruff) from 0.16.4 to 0.16.5.
- [Release notes](https://github.com/astral-sh/ruff/releases)
- [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md)
- [Commits](astral-sh/ruff@0.16.4...0.16.5)

---
updated-dependencies:
- dependency-name: ruff
  dependency-version: 0.16.5
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Aug 31, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: deps. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

Copy link
Copy Markdown
Contributor

Automated review: ruff 0.16.4 → 0.16.5

Step 1 — Code review

  • Consistency: PR description matches the diff exactly — the only change is uv.lock, bumping ruff from 0.16.4 to 0.16.5 (registry source, hashes, and wheel URLs all updated consistently).
  • Correctness: Lockfile-only change; no source files touched. The workspace root pyproject.toml pins ruff>=0.16.3, so 0.16.5 remains within the declared constraint — no manifest edit required.
  • Conventions: Follows repo convention of Dependabot-driven lockfile bumps for dev tooling.
  • Security: Reviewed the 0.16.5 release notes/changelog — only preview-feature additions, three targeted bug fixes (ASYNC210, DTZ007, SIM401), a server doc-comment fix, and docs. No CVEs or security advisories associated with this release; no breaking changes for a dev-only lint dependency.
  • Effectiveness: Achieves the stated purpose (keeps ruff current).
  • Test coverage: No functional code changes, so no new test cases are expected or needed for this bump.

Step 2 — Regression verification (local, against the PR branch at 9e6f2ba)

  • uv sync --all-packages --all-extras — resolves cleanly with ruff==0.16.5
  • uv run ruff check . — all checks passed
  • uv run mypy packages/*/src — no issues found in 14 source files
  • uv run pytest --ignore=tests/packaging — 107 passed
  • uv run pytest tests/packaging — 27 passed
  • uv build --all-packages — all three packages built successfully

No regressions from the version bump.

Step 3 — CI
All checks green on 9e6f2ba: test (3.12), test (3.13), analyze (CodeQL), and the top-level CodeQL check. mergeable_state is clean.

Step 4 — Decision
All gates passed. Proceeding with squash merge.


Generated by Claude Code

@helebest
helebest merged commit 7bc9660 into main Aug 31, 2026
4 checks passed
@helebest
helebest deleted the dependabot/uv/ruff-0.16.5 branch August 31, 2026 23:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant