Skip to content

build(deps): bump the python-dependencies group across 1 directory with 4 updates - #7

Closed
dependabot[bot] wants to merge 4 commits into
mainfrom
dependabot/uv/python-dependencies-2919d3c195
Closed

build(deps): bump the python-dependencies group across 1 directory with 4 updates#7
dependabot[bot] wants to merge 4 commits into
mainfrom
dependabot/uv/python-dependencies-2919d3c195

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 12, 2026

Copy link
Copy Markdown

Updates the requirements on typer, pyhanko[image-support], hypothesis and ruff to permit the latest version.
Updates typer from 0.27.0 to 0.27.1

Release notes

Sourced from typer's releases.

0.27.1

Features

  • ✨ Make epilog formatting consistent with other parts of the help string. PR #1405 by @​svlandeg.

Docs

Internal

Changelog

Sourced from typer's changelog.

0.27.1 (2026-08-03)

Features

  • ✨ Make epilog formatting consistent with other parts of the help string. PR #1405 by @​svlandeg.

Docs

Internal

Commits
  • fe2aa0e 🔖 Release version 0.27.1 (#1919)
  • 680dc99 📝 Update release notes
  • ac3efd5 ✨ Make epilog formatting consistent with other parts of the help string (#1...
  • 32d80ef 📝 Update release notes
  • 10cb3c9 ⬆️ Upgrade latest-changes to 0.7.1 (#1909)
  • ac329a0 📝 Update release notes
  • c37ae2f 📝 Add Library Skills documentation (#1906)
  • 0974a7e 📝 Update release notes
  • 951178c 🐛 Prevent scroll-to-top on restart/fast buttons in the documentation (#1904)
  • 9051baa 📝 Update release notes
  • Additional commits viewable in compare view

Updates pyhanko[image-support] to 0.36.2

Release notes

Sourced from pyhanko[image-support]'s releases.

pyhanko 0.36.2 beta

The release artifacts have been published to PyPI. Documentation is available on ReadTheDocs.

Change log

The release notes for the 0.36.2 release are available on the Release History page

Changelog

Sourced from pyhanko[image-support]'s changelog.

0.36.2

Release date: 2026-07-27

Bugs fixed

  • Prevent new signature fields from reusing old signature objects during difference analysis.

.. _release-0.36.1:

0.36.1

Release date: 2026-07-26

No functional changes, this release adopts the new :ref:attestation strategy <release-authenticity>.

.. _release-0.36.0:

0.36.0

Release date: 2026-07-25

Dependency changes

  • Bump the minimal signxml version to 5.1.0 (in the [etsi] group) to accommodate its point-in-time validation API.
  • Relax upper bound for uharfbuzz to <0.56.0.
  • Drop the direct dependency on pyyaml, which was no longer used.

New features and enhancements

Signing ^^^^^^^

  • Support signing with ML-DSA through the PKCS#11 signer.

... (truncated)

Commits
  • 0945f9b pyHanko 0.36.2 release
  • 1f31537 Prevent new sig fields from reusing old sigs
  • 39d3b74 Rename is_ref_available -> is_ref_unassignable
  • 8eaffab Artifact authenticity docs restructuring
  • dae7ec6 Add provenance data fetching to attestation script
  • aa81b12 Joint release with new attestations
  • a2a050a Additionally drop unnecessary download step
  • 405e412 Split off publish-github-release
  • 92a3ad5 Switch to GitHub attestations for provenance
  • 04711cf Typos in docstring
  • Additional commits viewable in compare view

Updates hypothesis from 6.161.2 to 6.165.2

Commits
  • deb4d49 Bump hypothesis version to 6.165.2 and update changelog
  • a9eff28 Merge pull request #4842 from HypothesisWorks/claude/invert-everything
  • c555e58 Cover the remaining _invert error paths in tests
  • f9882a3 Apply review feedback: type ValueHole.value as object, polish docs and tests
  • 8dca9e1 Restructure timezones() so its draws can be re-encoded
  • 7e309df Invert dictionaries, unique lists with tuple_suffixes, and fixed_dictionaries
  • 77ca292 Implement _invert for most remaining strategy combinators
  • 5b20755 Bump hypothesis version to 6.165.1 and update changelog
  • b4f2e92 Merge pull request #4806 from HypothesisWorks/claude/widening-shrinks
  • 9431e20 Apply suggestions from code review
  • Additional commits viewable in compare view

Updates ruff from 0.16.0 to 0.16.2

Release notes

Sourced from ruff's releases.

0.16.2

Release Notes

Released on 2026-08-06.

Bug fixes

  • [flake8-pyi] Avoid false positives on singledispatch functions (PYI041) (#27335)

Server

  • Register formatting capabilities dynamically to exclude TOML files (#27332)

Contributors

Install ruff 0.16.2

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/ruff/releases/download/0.16.2/ruff-installer.sh | sh

Install prebuilt binaries via powershell script

powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/ruff/releases/download/0.16.2/ruff-installer.ps1 | iex"

Download ruff 0.16.2

File Platform Checksum
ruff-aarch64-apple-darwin.tar.gz Apple Silicon macOS checksum
ruff-x86_64-apple-darwin.tar.gz Intel macOS checksum
ruff-aarch64-pc-windows-msvc.zip ARM64 Windows checksum
ruff-i686-pc-windows-msvc.zip x86 Windows checksum
ruff-x86_64-pc-windows-msvc.zip x64 Windows checksum
ruff-aarch64-unknown-linux-gnu.tar.gz ARM64 Linux checksum
ruff-i686-unknown-linux-gnu.tar.gz x86 Linux checksum
ruff-powerpc64-unknown-linux-gnu.tar.gz PPC64 Linux checksum
ruff-powerpc64le-unknown-linux-gnu.tar.gz PPC64LE Linux checksum
ruff-riscv64gc-unknown-linux-gnu.tar.gz RISCV Linux checksum
ruff-s390x-unknown-linux-gnu.tar.gz S390x Linux checksum

... (truncated)

Changelog

Sourced from ruff's changelog.

0.16.2

Released on 2026-08-06.

Bug fixes

  • [flake8-pyi] Avoid false positives on singledispatch functions (PYI041) (#27335)

Server

  • Register formatting capabilities dynamically to exclude TOML files (#27332)

Contributors

0.16.1

Released on 2026-07-30.

Preview features

  • Add an option to opt out of human-readable names (#27160)
  • [flake8-pytest-style] Make fixes safe by default and unsafe only when comments are present (PT018) (#27201)
  • [pyupgrade] Skip fix when a defaulted TypeVar precedes a non-defaulted one (UP040, UP046, UP047) (#27133)
  • [ruff] Fix false positive with unpacked arguments (RUF065) (#26959)

Bug fixes

  • Bump gen-lsp-types to gracefully handle unknown enumeration values in LSP messages (#27230)
  • [flake8-bugbear] Mark range as immutable (B008) (#27247)
  • [flake8-comprehensions] NFKC-normalize keyword names in C408 fix (#26813)
  • [flake8-return] Fix false positive when variable is read in finally clause (RET504) (#25441)
  • [pydocstyle] Skip section detection inside RST directive bodies (D214, D405, D413) (#23635)
  • [refurb] Parenthesize yield arguments in the FURB192 fix (#27192)

Rule changes

  • [flake8-pytest-style] Mark PT022 fixes as unsafe (#26440)
  • [refurb] Mark fixes that remove unknown separators as unsafe (FURB105) (#27200)

Server

  • Fix indexing of excluded nested Ruff workspaces (#27303)
  • Lint TOML files in the LSP (#26862)

... (truncated)

Commits
  • 5b48a04 Bump 0.16.2 (#27555)
  • 1b9e5fc Update Swatinem/rust-cache action to v2.9.2 (#27568)
  • c4e86fc [ty] Add helper extension methods for half-range and equality constraints (#2...
  • 17a00de [ty] Reuse primer commands in memory reports (#27553)
  • 6ea296b [ty] Normalize type labels in structured docstrings (#26923)
  • 2fc445f [ty] Diagnose invalid getattr calls (#27502)
  • 22c7823 [ty] Enable (but downrank) auto-import completion suggestions from stub-only ...
  • 05160d5 [ty] Diagnose invalid descriptor __get__ calls (#27400)
  • baea3d0 [ty] Expose strict analysis options in the playground (#27543)
  • c88946e [ty] Bump ecosystem-analyzer for strict project settings (#27542)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

evrenverse and others added 4 commits July 26, 2026 19:53
Machine-readable profile (status, goal, next_step, updated, team, check) so the
repo state is readable without parsing README or AGENTS.md. Part of a contract
now shared across the active repos.

No TODO.md or LEDGER.md yet — those get created on first entry, not upfront.
pip-audit failed CI on three advisories: PYSEC-2026-3552 (cryptography 49.0.0)
and PYSEC-2026-3655/3656 (pypdf 6.14.2). cryptography is not imported directly —
pdfminer-six, pyhanko and pypdfform all pull it in — so it is declared as a
security floor rather than a real dependency.

247 tests pass, pip-audit reports no known vulnerabilities.
…th 4 updates

Updates the requirements on [typer](https://github.com/fastapi/typer), [pyhanko[image-support]](https://github.com/MatthiasValvekens/pyHanko), [hypothesis](https://github.com/HypothesisWorks/hypothesis) and [ruff](https://github.com/astral-sh/ruff) to permit the latest version.

Updates `typer` from 0.27.0 to 0.27.1
- [Release notes](https://github.com/fastapi/typer/releases)
- [Changelog](https://github.com/fastapi/typer/blob/master/docs/release-notes.md)
- [Commits](fastapi/typer@0.27.0...0.27.1)

Updates `pyhanko[image-support]` to 0.36.2
- [Release notes](https://github.com/MatthiasValvekens/pyHanko/releases)
- [Changelog](https://github.com/MatthiasValvekens/pyHanko/blob/master/docs/changelog.rst)
- [Commits](MatthiasValvekens/pyHanko@v0.35.2...v0.36.2)

Updates `hypothesis` from 6.161.2 to 6.165.2
- [Release notes](https://github.com/HypothesisWorks/hypothesis/releases)
- [Commits](HypothesisWorks/hypothesis@v6.161.2...v6.165.2)

Updates `ruff` from 0.16.0 to 0.16.2
- [Release notes](https://github.com/astral-sh/ruff/releases)
- [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md)
- [Commits](astral-sh/ruff@0.16.0...0.16.2)

---
updated-dependencies:
- dependency-name: typer
  dependency-version: 0.27.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python-dependencies
- dependency-name: pyhanko[image-support]
  dependency-version: 0.36.2
  dependency-type: direct:production
  dependency-group: python-dependencies
- dependency-name: hypothesis
  dependency-version: 6.165.2
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: python-dependencies
- dependency-name: ruff
  dependency-version: 0.16.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: python-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels Aug 12, 2026
@dependabot
dependabot Bot requested a review from evrenverse as a code owner August 12, 2026 13:03
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels Aug 12, 2026
@dependabot @github

dependabot Bot commented on behalf of github Aug 17, 2026

Copy link
Copy Markdown
Author

Looks like these dependencies are updatable in another way, so this is no longer needed.

@dependabot dependabot Bot closed this Aug 17, 2026
@dependabot
dependabot Bot deleted the dependabot/uv/python-dependencies-2919d3c195 branch August 17, 2026 01:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant