Repository navigation
fix(deps): update python-dependencies - #11
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
==2.0.52→==2.0.53==1.19.2→==1.20.0==3.32.5→==3.32.6==0.16.6→==0.16.7==1.176.1→==1.177.0==0.52.4→==0.53.0Release Notes
tox-dev/py-filelock (filelock)
v3.32.6Compare Source
What's Changed
New Contributors
Full Changelog: tox-dev/filelock@3.32.5...3.32.6
astral-sh/ruff (ruff)
v0.16.7Compare Source
Released on 2026-09-10.
Preview features
ruff] Add rule for default values on method receivers (RUF077) (#26700)ruff] Recognizere.prefixmatch(RUF039,RUF055) (#28311)Bug fixes
flake8-implicit-str-concat] Mark fix unsafe when it creates a docstring (ISC003) (#27981)flake8-tidy-imports] Skip fixes for multi-member imports (TID254) (#26584)pylint] GateImportCycleErroron Python 3.15 (PLW0133) (#28310)Rule changes
D211andD203rule conflict diagnostic (#28444)sliceandfrozendictgenerics (#28477)__cached__for Python 3.15 (#28476)pyupgrade] Stop recommending removedtyping.no_type_check_decorator(UP035) (#28475)Performance
Documentation
line-lengthpath in--configexample (#28392)Other changes
Contributors
semgrep/semgrep (semgrep)
v1.177.01.177.0 - 2026-09-10
### Added
rules_jvm_external. Semgrep now recognizes amaven_install.jsonpinned lockfile (versions0.1.0and3, as emitted by rules_jvm_external 3.x through current) paired with aMODULE.bazel(or legacyWORKSPACE/WORKSPACE.bazel) marker as a Maven-ecosystem subproject, and attributes findings to the workspace root rather than the lockfile's directory. Workspace-declared root artifacts are identified via__INPUT_ARTIFACTS_HASHfor accurate direct-vs-transitive classification; dependencies are emitted withUnknowntransitivity when that field is not available. This is the first milestone of native Bazel coverage; broader ecosystem support (rules_python,rules_go,rules_js) and Bazel-aware reachability attribution follow. (SC-2008)regex are inefficient to run on our default regex engine (currently PCRE2). For
example, a rule matching
FOOBAR(a+)\1will skip any file that does notcontain
FOOBARwithout running the regex. (scrt-979)### Changed
expensive regex predicates. Since evaluation short-circuits, a file that a
string check already rules in or out no longer pays for regex predicates
(which is what a pattern's prefilter falls back to when no literal substring
can be extracted from it, and which can be slow on files with very long
lines). (prefilter-rank-conjuncts)
--x-gradle-module-attribution. Enabling it can change finding IDs because finding paths change; the ID calculation is unchanged. (SC-2560)### Fixed
Speed up
semgrep cifiltering when a deployment has many triage-ignored findings. (triage-ignored-performance)Semgrep no longer crashes with an OCaml stack trace when a proxy environment
variable holds an unusable value.
HTTP_PROXY,HTTPS_PROXY, orALL_PROXYset to an empty value is now ignored with a warning, and the scan
proceeds without a proxy. A non-empty value that is not a usable proxy URL
now exits with an error message, with any credentials in the URL
redacted, instead of failing inside the HTTP client.
Semgrep also now adds the missing scheme to a proxy URL supplied
without one;
httpsforHTTPS_PROXY andhttp` otherwise. (ENGINE-2208)Supply Chain: lockfileless Gradle scans now report a "Resource Inaccessible"
resolution error when a repository refuses a request (for example a 401 from a
private registry), instead of exiting successfully with a silently incomplete
dependency list. (sc-3358)
### Infra/Release Changes
Kludex/uvicorn (uvicorn)
v0.53.0: Version 0.53.0Compare Source
🌐 Opt-in HTTP/2 support
uvicorn0.53.0 adds experimental HTTP/2 throughzttp, alongside a newzuvloopintegration and connection-handling improvements.uv add uvicorn==0.53.0zttp(#2982, #3101). Installzttp, then enable HTTP/2 with--http zttp --http2. Uvicorn negotiates HTTP/2 over TLS with ALPN and supports cleartext prior knowledge.⚙️ More event loop choice
zuvloop(#3104). Installzuvloopseparately and select it explicitly with--loop zuvloopon CPython 3.14 or newer.🛡️ More reliable connections and proxies
Connection: closetoken lists (#3103). Uvicorn now parses comma-separated tokens case-insensitively across HTTP implementations.FORWARDED_ALLOW_IPSvalue now includes::1.Full changelog: 0.52.4...0.53.0
Configuration
📅 Schedule: (UTC)
* 0-3 * * 1)🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.