Skip to content

Bump the python group with 4 updates - #3754

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/python-2bda410d18
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/python-2bda410d18

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 2, 2026

Copy link
Copy Markdown
Contributor

Bumps the python group with 4 updates: boto3, pytest-mock, ruff and uv.

Updates boto3 from 1.43.99 to 1.43.104

Commits
  • ca37987 Merge branch 'release-1.43.104'
  • c468e3d Bumping version to 1.43.104
  • f2d1bac Add changelog entries from botocore
  • 0470368 Merge branch 'release-1.43.103'
  • 378d670 Merge branch 'release-1.43.103' into develop
  • 1b65309 Bumping version to 1.43.103
  • 655adc5 Add changelog entries from botocore
  • da00dd2 Merge branch 'release-1.43.102'
  • 76d6266 Merge branch 'release-1.43.102' into develop
  • 551d660 Bumping version to 1.43.102
  • Additional commits viewable in compare view

Updates pytest-mock from 3.15.1 to 3.16.0

Release notes

Sourced from pytest-mock's releases.

v3.16.0

2026-09-27

  • #604: Fixed duplicate_iterators=True for async functions spied with mocker.spy.
  • #611: Fixed async mock assertion introspection to use awaited arguments instead of the latest call's arguments.
  • #606: mocker.resetall(return_value=True, side_effect=True) now also applies to non-callable mocks, such as those returned by mocker.create_autospec(SomeClass, instance=True). Previously both arguments were silently ignored for them.
  • #547: Added SpyType for annotating mocker.spy results.
  • Dropped support for EOL Python 3.9.
  • #147: Removed handling of RuntimeError: stop called on unstarted patcher, which can no longer occur in the supported Python versions.
  • Added support for Python 3.15.
Changelog

Sourced from pytest-mock's changelog.

3.16.0

2026-09-27

  • [#604](https://github.com/pytest-dev/pytest-mock/issues/604) <https://github.com/pytest-dev/pytest-mock/pull/604>_: Fixed duplicate_iterators=True for async functions spied with mocker.spy.
  • [#611](https://github.com/pytest-dev/pytest-mock/issues/611) <https://github.com/pytest-dev/pytest-mock/pull/611>_: Fixed async mock assertion introspection to use awaited arguments instead of the latest call's arguments.
  • [#606](https://github.com/pytest-dev/pytest-mock/issues/606) <https://github.com/pytest-dev/pytest-mock/pull/606>_: mocker.resetall(return_value=True, side_effect=True) now also applies to non-callable mocks, such as those returned by mocker.create_autospec(SomeClass, instance=True). Previously both arguments were silently ignored for them.
  • [#547](https://github.com/pytest-dev/pytest-mock/issues/547) <https://github.com/pytest-dev/pytest-mock/issues/547>_: Added SpyType for annotating mocker.spy results.
  • Dropped support for EOL Python 3.9.
  • [#147](https://github.com/pytest-dev/pytest-mock/issues/147) <https://github.com/pytest-dev/pytest-mock/issues/147>_: Removed handling of RuntimeError: stop called on unstarted patcher, which can no longer occur in the supported Python versions.
  • Added support for Python 3.15.
Commits

Updates ruff from 0.16.8 to 0.16.9

Release notes

Sourced from ruff's releases.

0.16.9

Release Notes

Released on 2026-09-24.

Preview features

  • [ruff] Avoid false positives for overloaded division (RUF069) (#28309)

Bug fixes

  • [flake8-bugbear] Avoid false positives for calls with keyword arguments (B009, B010, B043) (#28776)
  • [flake8-tidy-imports] Allow lazy imports to be used in deferred annotations (TID255) (#28767)

Rule changes

  • Update LibCST-based fixes for Python 3.15 (#28616)
  • [flake8-pyi] Mention stubs in the diagnostic message (PYI002) (#28542)

Documentation

  • Fix horizontal overflow on the rules documentation page (#28699)
  • Update rules table with category information (#28651)
  • [flake8-annotations] Clarify that ANN401 checks return types in addition to arguments (#28334)
  • [flake8-bugbear] Document type-checker interaction (B010) (#28509)
  • [flake8-comprehensions] Document map/generator exception behavior (C417) (#27794)
  • [ruff] Mention related isort settings (RUF022) (#28719)

Contributors

Install ruff 0.16.9

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/ruff/releases/download/0.16.9/ruff-installer.sh | sh

... (truncated)

Changelog

Sourced from ruff's changelog.

0.16.9

Released on 2026-09-24.

Preview features

  • [ruff] Avoid false positives for overloaded division (RUF069) (#28309)

Bug fixes

  • [flake8-bugbear] Avoid false positives for calls with keyword arguments (B009, B010, B043) (#28776)
  • [flake8-tidy-imports] Allow lazy imports to be used in deferred annotations (TID255) (#28767)

Rule changes

  • Update LibCST-based fixes for Python 3.15 (#28616)
  • [flake8-pyi] Mention stubs in the diagnostic message (PYI002) (#28542)

Documentation

  • Fix horizontal overflow on the rules documentation page (#28699)
  • Update rules table with category information (#28651)
  • [flake8-annotations] Clarify that ANN401 checks return types in addition to arguments (#28334)
  • [flake8-bugbear] Document type-checker interaction (B010) (#28509)
  • [flake8-comprehensions] Document map/generator exception behavior (C417) (#27794)
  • [ruff] Mention related isort settings (RUF022) (#28719)

Contributors

Commits
  • 0be08a2 Bump version to 0.16.9 (#28882)
  • b4920b7 Rename ruff_cli to ruff_command_line (#28881)
  • 47c751b Update dependency astral-sh/uv to v0.12.18 (#28880)
  • 8c244e5 [flake8-comprehensions] Document map/generator exception behavior (C417...
  • 5edf5a1 Use target form in rooster.version_files (#28876)
  • 915bb2b [ty] Prefer existing @ paths over response files in Ruff and ty (#28877)
  • 4710e1a ci(github): update version number in placeholder of issue template (#28871)
  • eedfc62 [ty] Propagate outer type context through cast calls (#28855)
  • ceaa6a0 [ty] Contain rendered code within Markdown fences (#28869)
  • dba0f30 authorize ruff-pre-commit dispatch via OIDC (#28867)
  • Additional commits viewable in compare view

Updates uv from 0.12.17 to 0.12.20

Release notes

Sourced from uv's releases.

0.12.20

Release Notes

Released on 2026-09-28.

Enhancements

  • Reuse lockfiles when dependency declarations are semantically equivalent (#21951)
  • Preserve second-line encoding declarations when installing wheel scripts with CRLF shebangs (#21990)

Preview features

  • Write normalized requirement declarations with the lockfile-normalization preview feature (#21951)
  • Honor synthetic default groups when installing or syncing from pylock.toml (#22003)
  • Resolve local paths in exported pylock.toml files relative to the output file (#22042)
  • Install each package only once when repeated tool-install-locks requirements resolve to the same package (#22000)
  • Reuse lock-without-metadata lockfiles for conflicting groups with distinct base and extra requirement specifiers (#22055)
  • Use consistent root-package paths in uv workspace metadata and uv tree --format json output (#22050)

Configuration

  • Continue searching XDG_CONFIG_DIRS after empty entries (#21987)

Performance

  • Restore the previous HTTP cache-write scheduling while investigating severe cache-revalidation stalls on ext4 filesystems (#22051)

Bug fixes

  • Apply hash constraints to every repeated requirement under --require-hashes and --verify-hashes (#21996)
  • Allow metadata builds for first-party workspace projects under --no-build (#21988)
  • Honor project exclusion flags with --all-packages, including --no-install-project and --no-emit-project (#21994)
  • Restore pyproject.toml if uv upgrade fails or is interrupted (#21983)
  • Generate working Nushell activation scripts for relocatable virtual environments (#21979)
  • Prevent commands from running and changing state after displaying --show-settings (#21989)
  • Treat UTF-16 requirements files containing only a byte-order mark as empty (#21991)
  • Ignore unrecognized managed-Python implementation directories during uv python list and uv python upgrade instead of panicking (#22033)
  • Avoid panics and incorrect rewriting when managed Python sysconfig paths merely start with /install (#22036)
  • Report whitespace-only non-ASCII requirements as invalid instead of panicking (#22035)
  • Avoid a resolver panic when trace logging an always-false constraint (#22034)

Install uv 0.12.20

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.20/uv-installer.sh | sh

Install prebuilt binaries via powershell script

... (truncated)

Changelog

Sourced from uv's changelog.

0.12.20

Released on 2026-09-28.

Enhancements

  • Reuse lockfiles when dependency declarations are semantically equivalent (#21951)
  • Preserve second-line encoding declarations when installing wheel scripts with CRLF shebangs (#21990)

Preview features

  • Write normalized requirement declarations with the lockfile-normalization preview feature (#21951)
  • Honor synthetic default groups when installing or syncing from pylock.toml (#22003)
  • Resolve local paths in exported pylock.toml files relative to the output file (#22042)
  • Install each package only once when repeated tool-install-locks requirements resolve to the same package (#22000)
  • Reuse lock-without-metadata lockfiles for conflicting groups with distinct base and extra requirement specifiers (#22055)
  • Use consistent root-package paths in uv workspace metadata and uv tree --format json output (#22050)

Configuration

  • Continue searching XDG_CONFIG_DIRS after empty entries (#21987)

Performance

  • Restore the previous HTTP cache-write scheduling while investigating severe cache-revalidation stalls on ext4 filesystems (#22051)

Bug fixes

  • Apply hash constraints to every repeated requirement under --require-hashes and --verify-hashes (#21996)
  • Allow metadata builds for first-party workspace projects under --no-build (#21988)
  • Honor project exclusion flags with --all-packages, including --no-install-project and --no-emit-project (#21994)
  • Restore pyproject.toml if uv upgrade fails or is interrupted (#21983)
  • Generate working Nushell activation scripts for relocatable virtual environments (#21979)
  • Prevent commands from running and changing state after displaying --show-settings (#21989)
  • Treat UTF-16 requirements files containing only a byte-order mark as empty (#21991)
  • Ignore unrecognized managed-Python implementation directories during uv python list and uv python upgrade instead of panicking (#22033)
  • Avoid panics and incorrect rewriting when managed Python sysconfig paths merely start with /install (#22036)
  • Report whitespace-only non-ASCII requirements as invalid instead of panicking (#22035)
  • Avoid a resolver panic when trace logging an always-false constraint (#22034)

0.12.19

Released on 2026-09-24.

Python

  • Add PyPy 3.11.16 and 3.12.14 (#21847)
  • Update GraalPy 3.13.0 to build 25.4.4 (#21847)

Enhancements

... (truncated)

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the python group with 4 updates: [boto3](https://github.com/boto/boto3), [pytest-mock](https://github.com/pytest-dev/pytest-mock), [ruff](https://github.com/astral-sh/ruff) and [uv](https://github.com/astral-sh/uv).


Updates `boto3` from 1.43.99 to 1.43.104
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](boto/boto3@1.43.99...1.43.104)

Updates `pytest-mock` from 3.15.1 to 3.16.0
- [Release notes](https://github.com/pytest-dev/pytest-mock/releases)
- [Changelog](https://github.com/pytest-dev/pytest-mock/blob/main/CHANGELOG.rst)
- [Commits](pytest-dev/pytest-mock@v3.15.1...v3.16.0)

Updates `ruff` from 0.16.8 to 0.16.9
- [Release notes](https://github.com/astral-sh/ruff/releases)
- [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md)
- [Commits](astral-sh/ruff@0.16.8...0.16.9)

Updates `uv` from 0.12.17 to 0.12.20
- [Release notes](https://github.com/astral-sh/uv/releases)
- [Changelog](https://github.com/astral-sh/uv/blob/main/CHANGELOG.md)
- [Commits](astral-sh/uv@0.12.17...0.12.20)

---
updated-dependencies:
- dependency-name: boto3
  dependency-version: 1.43.104
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python
- dependency-name: pytest-mock
  dependency-version: 3.16.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python
- dependency-name: ruff
  dependency-version: 0.16.9
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python
- dependency-name: uv
  dependency-version: 0.12.20
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update Python code labels Oct 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update Python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants