Skip to content

⬆ Bump the python-packages group with 5 updates - #503

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/python-packages-128ae6e5a4
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/python-packages-128ae6e5a4

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown
Contributor

Bumps the python-packages group with 5 updates:

Package From To
ruff 0.16.4 0.16.8
uvicorn 0.52.4 0.53.0
ty 0.0.74 0.0.83
prek 0.4.14 0.5.3
zizmor 1.29.0 1.30.1

Updates ruff from 0.16.4 to 0.16.8

Release notes

Sourced from ruff's releases.

0.16.8

Release Notes

Released on 2026-09-16.

Bug fixes

  • Visit functional TypedDict keyword arguments correctly (#28584)
  • [flake8-simplify] Detect nested async with under sync parent (SIM117) (#27821)
  • [flake8-simplify] Preserve operand order in SIM109 fix (#27824)
  • [pyupgrade] Preserve required parentheses in multiline UP040 fixes (#28164)
  • [pyupgrade] Skip TypeVarTuple and ParamSpec conversions with bounds or constraints (UP040, UP046, UP047) (#28505)

Rule changes

  • Add support for __lazy_modules__ (#28459)
  • Recognize PEP-728 TypedDict class keywords (#28533)
  • Recognize quoted types in typing.TypeForm (#28507)
  • Support conditional assignment to __lazy_modules__ (#28491)
  • [flake8-type-checking] Prefer lazy imports over TYPE_CHECKING on Python 3.15 and later (TC001, TC002, TC003) (#28541)
  • [pyupgrade] Make the fix for UP040 always unsafe (#28526)
  • [pyupgrade] Stop recommending deprecated ByteString aliases (UP035) (#28498)
  • [ruff, flake8-use-pathlib] Recognize the parent_mode argument (RUF064, PTH103) (#28528)
  • [ruff] Detect \Z in pytest.raises() match patterns (RUF043) (#28598)

CLI

  • Use rule name and code in formatter incompatibility warnings (#28571)

Configuration

  • [flake8-tidy-imports] Add extend-banned-api (#28644)

Contributors

Install ruff 0.16.8

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/ruff/releases/download/0.16.8/ruff-installer.sh | sh
</tr></table> 

... (truncated)

Changelog

Sourced from ruff's changelog.

0.16.8

Released on 2026-09-16.

Bug fixes

  • Visit functional TypedDict keyword arguments correctly (#28584)
  • [flake8-simplify] Detect nested async with under sync parent (SIM117) (#27821)
  • [flake8-simplify] Preserve operand order in SIM109 fix (#27824)
  • [pyupgrade] Preserve required parentheses in multiline UP040 fixes (#28164)
  • [pyupgrade] Skip TypeVarTuple and ParamSpec conversions with bounds or constraints (UP040, UP046, UP047) (#28505)

Rule changes

  • Add support for __lazy_modules__ (#28459)
  • Recognize PEP-728 TypedDict class keywords (#28533)
  • Recognize quoted types in typing.TypeForm (#28507)
  • Support conditional assignment to __lazy_modules__ (#28491)
  • [flake8-type-checking] Prefer lazy imports over TYPE_CHECKING on Python 3.15 and later (TC001, TC002, TC003) (#28541)
  • [pyupgrade] Make the fix for UP040 always unsafe (#28526)
  • [pyupgrade] Stop recommending deprecated ByteString aliases (UP035) (#28498)
  • [ruff, flake8-use-pathlib] Recognize the parent_mode argument (RUF064, PTH103) (#28528)
  • [ruff] Detect \Z in pytest.raises() match patterns (RUF043) (#28598)

CLI

  • Use rule name and code in formatter incompatibility warnings (#28571)

Configuration

  • [flake8-tidy-imports] Add extend-banned-api (#28644)

Contributors

0.16.7

Released on 2026-09-10.

Preview features

  • [ruff] Add rule for default values on method receivers (RUF077) (#26700)

... (truncated)

Commits
  • 62914c4 Bump version to 0.16.8 (#28648)
  • c47e0cd [ty] Bound aliased intersection expansion during inference (#28546)
  • ff4747b renovate: update uv hashes correctly with setup-uv (#28621)
  • 94efeaa [ty] Compact reachable binding and declaration histories (#28349)
  • 50020fb [ty] Avoid storing constraint nodes twice (#28375)
  • 446bb68 [ty] Compare bound-method receivers before signatures (#28384)
  • 304ab86 [flake8-type-checking] Prefer lazy imports over TYPE_CHECKING on 3.15+ (`...
  • d940b24 [ty] Watch script dependencies in CLI watch mode (#28125)
  • fe9f065 [flake8-tidy-imports] Add extend-banned-api (#28644)
  • 31131db [ty] Support type[A & B] (#27124)
  • Additional commits viewable in compare view

Updates uvicorn from 0.52.4 to 0.53.0

Release notes

Sourced from uvicorn's releases.

Version 0.53.0

🌐 Opt-in HTTP/2 support

uvicorn 0.53.0 adds experimental HTTP/2 through zttp, alongside a new zuvloop integration and connection-handling improvements.

uv add uvicorn==0.53.0
  • Serve HTTP/1.1 and HTTP/2 with zttp (#2982, #3101). Install zttp, then enable HTTP/2 with --http zttp --http2. Uvicorn negotiates HTTP/2 over TLS with ALPN and supports cleartext prior knowledge.
  • HTTP/2 remains experimental. Upgrade-based h2c and WebSockets over HTTP/2 are not supported.

⚙️ More event loop choice

  • Run Uvicorn with zuvloop (#3104). Install zuvloop separately and select it explicitly with --loop zuvloop on CPython 3.14 or newer.

🛡️ More reliable connections and proxies

  • Honor Connection: close token lists (#3103). Uvicorn now parses comma-separated tokens case-insensitively across HTTP implementations.
  • Trust IPv6 loopback proxies by default (#3119). The default FORWARDED_ALLOW_IPS value now includes ::1.
  • Keep upgraded WebSockets alive (#3107). Uvicorn cancels the HTTP keep-alive timer when the connection becomes a WebSocket.

Full changelog: 0.52.4...0.53.0

Changelog

Sourced from uvicorn's changelog.

0.53.0 (September 14, 2026)

This release adds experimental HTTP/2 support through zttp. Enable it with --http zttp --http2. Upgrade-based h2c and WebSockets over HTTP/2 are not supported.

Added

  • Add experimental HTTP/2 support through zttp (#2982, #3101)
  • Add support for zuvloop (#3104)

Fixed

  • Handle comma-separated, case-insensitive Connection: close tokens across HTTP implementations (#3103)
  • Trust IPv6 loopback in the default FORWARDED_ALLOW_IPS value (#3119)
  • Cancel the HTTP keep-alive timer when upgrading to WebSocket (#3107)
Commits
  • 421708f Version 0.53.0 (#3136)
  • f1a1bff Unset the keep-alive timer when upgrading to WebSocket (#3107)
  • 63971ed Document HTTP/2 support (#3130)
  • 7d1a005 Remove race from multiprocess health check test (#3128)
  • 5ac6265 Add ::1 to FORWARDED_ALLOW_IPS (#3119)
  • 098b206 Remove timing race from SIGHUP supervisor test (#3127)
  • 968f15e chore(deps): bump the github-actions group with 4 updates (#3113)
  • 7d4c08c chore(deps): bump the python-packages group across 1 directory with 11 update...
  • fe528a4 Require explicit opt-in for zttp HTTP/2 (#3101)
  • fa324a4 chore(deps-dev): bump httpx2 from 2.10.0 to 2.12.0 (#3121)
  • Additional commits viewable in compare view

Updates ty from 0.0.74 to 0.0.83

Release notes

Sourced from ty's releases.

0.0.83

Release Notes

Released on 2026-09-21.

Bug fixes

  • Fix hangs from repeated partial application (#28754)
  • Preserve PEP 695 bindings across nested classes (#28723)

LSP server

  • Include required imports in every inlay hint (#28724)
  • Preserve fast name filtering for normalized Unicode source (#28701)
  • Refresh diagnostics after workspace configuration changes (#28755)

Diagnostic improvements

  • Expand unreachable-code annotations for redundant conditions (#28674)
  • Improve diagnostics for async generator stubs (#28692)
  • Improve primary diagnostic annotations for redundant-condition(-strict) diagnostics (#28666)
  • Point misplaced tuple ellipsis diagnostics at each ellipsis (#28709)

Other changes

  • Add rules that detect suspicious uses of Callable, Iterable, Iterator or Generator types in a boolean context (#28554)
  • Allow slots to override abstract properties (#28698)
  • Avoid leaking Unknown from unconstrained collection use-sites (#28659)
  • Diagnose unguarded cycles in implicit and PEP 613 aliases (#28704)
  • Eagerly bind unused Self receivers (#28662)
  • Generalize receiver binding for wrapped callables (#28725)
  • More faithful representation of bound methods (#28410)
  • Only classify evidence bounds for constrained type variables (#28700)
  • Preserve inferred bindings during annotation cycles (#28717)
  • Preserve quoted aliases during cycle recovery (#28710)
  • Reject class-scoped type variables in init receivers (#28706)
  • Reject unsafe TypedDict updates from hidden fields (#28711)
  • Respect fixed caller type variables when selecting constraints (#28652)
  • Reuse cached type alias inference for diagnostics (#28696)
  • Simplify unions of disjoint exclusions (#28684)
  • Update typing conformance suite (#28718)

Contributors

... (truncated)

Changelog

Sourced from ty's changelog.

0.0.83

Released on 2026-09-21.

Bug fixes

  • Fix hangs from repeated partial application (#28754)
  • Preserve PEP 695 bindings across nested classes (#28723)

LSP server

  • Include required imports in every inlay hint (#28724)
  • Preserve fast name filtering for normalized Unicode source (#28701)
  • Refresh diagnostics after workspace configuration changes (#28755)

Diagnostic improvements

  • Expand unreachable-code annotations for redundant conditions (#28674)
  • Improve diagnostics for async generator stubs (#28692)
  • Improve primary diagnostic annotations for redundant-condition(-strict) diagnostics (#28666)
  • Point misplaced tuple ellipsis diagnostics at each ellipsis (#28709)

Other changes

  • Add rules that detect suspicious uses of Callable, Iterable, Iterator or Generator types in a boolean context (#28554)
  • Allow slots to override abstract properties (#28698)
  • Avoid leaking Unknown from unconstrained collection use-sites (#28659)
  • Diagnose unguarded cycles in implicit and PEP 613 aliases (#28704)
  • Eagerly bind unused Self receivers (#28662)
  • Generalize receiver binding for wrapped callables (#28725)
  • More faithful representation of bound methods (#28410)
  • Only classify evidence bounds for constrained type variables (#28700)
  • Preserve inferred bindings during annotation cycles (#28717)
  • Preserve quoted aliases during cycle recovery (#28710)
  • Reject class-scoped type variables in init receivers (#28706)
  • Reject unsafe TypedDict updates from hidden fields (#28711)
  • Respect fixed caller type variables when selecting constraints (#28652)
  • Reuse cached type alias inference for diagnostics (#28696)
  • Simplify unions of disjoint exclusions (#28684)
  • Update typing conformance suite (#28718)

Contributors

... (truncated)

Commits

Updates prek from 0.4.14 to 0.5.3

Release notes

Sourced from prek's releases.

0.5.3

Release Notes

Released on 2026-09-13.

Enhancements

  • Add PEP 740 attestations for PyPI releases (#2705)
  • Add a check-jsonc builtin hook (#2682)
  • Allow disabling automatic uv installation (#2702)

Bug fixes

  • Fix Julia additional dependency specifiers (#2703)
  • Update granit-parser to fix YAML flow indentation (#2707)

Contributors

Install prek 0.5.3

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://github.com/j178/prek/releases/download/v0.5.3/prek-installer.sh | sh

Install prebuilt binaries via powershell script

powershell -ExecutionPolicy Bypass -c "irm https://github.com/j178/prek/releases/download/v0.5.3/prek-installer.ps1 | iex"

Install prebuilt binaries via Homebrew

brew install prek

Download prek 0.5.3

File Platform Checksum
prek-aarch64-apple-darwin.tar.gz Apple Silicon macOS checksum
prek-x86_64-apple-darwin.tar.gz Intel macOS checksum
prek-aarch64-pc-windows-msvc.zip ARM64 Windows checksum
prek-x86_64-pc-windows-msvc.zip x64 Windows checksum

... (truncated)

Changelog

Sourced from prek's changelog.

0.5.3

Released on 2026-09-13.

Enhancements

  • Add PEP 740 attestations for PyPI releases (#2705)
  • Add a check-jsonc builtin hook (#2682)
  • Allow disabling automatic uv installation (#2702)

Bug fixes

  • Fix Julia additional dependency specifiers (#2703)
  • Update granit-parser to fix YAML flow indentation (#2707)

Contributors

0.5.2

Released on 2026-09-03.

Enhancements

  • Allow unknown tags by default in check-yaml (#2678)

Contributors

0.5.1

Released on 2026-09-01.

Enhancements

  • Add --hide-status <passed|failed|skipped> for hook reports (#2644)
  • Add prek init for repository setup (#2636)
  • Apply hook env during environment creation (#2650)
  • Disable error snippets in check-yaml diagnostics (#2664)
  • Show hooks excluded by skip selectors (#2645)
  • Support Pixi for Conda environments (#2667)
  • Support cargo-binstall for Rust CLI dependencies (#2658)
  • Warn about unused keys in user settings (#2665)

Bug fixes

... (truncated)

Commits

Updates zizmor from 1.29.0 to 1.30.1

Release notes

Sourced from zizmor's releases.

v1.30.1

Sponsorship is appreciated!

Bug Fixes 🐛🔗

  • Fixed a bug where zizmor would crash on pre-commit inputs that reference a GitHub URL with an explicit .git suffix (#2363)

  • Fixed a bug where self-repository auto-fixes were incorrectly marked as "safe" instead of "unsafe" (#2373)

v1.30.0

Sponsorship is appreciated!

New Features 🌈🔗

Bug Fixes 🐛🔗

... (truncated)

Changelog

Sourced from zizmor's changelog.

1.30.1

Bug Fixes 🐛

  • Fixed a bug where zizmor would crash on pre-commit inputs that reference a GitHub URL with an explicit .git suffix (#2363)

  • Fixed a bug where [self-repository] auto-fixes were incorrectly marked as "safe" instead of "unsafe" (#2373)

1.30.0

New Features 🌈

  • New audit: [self-repository] detects usages of the old "workspace-relative" form for local reusable workflows and actions and recommends the new "self-repository" form instead (#2271)

Enhancements 🌱

  • The [impostor-commit] audit now supports pre-commit config inputs (#2256)

  • The [forbidden-uses] audit now supports pre-commit config inputs (#2263)

  • The [adhoc-packages] audit now detects more ad-hoc package management patterns, including bundle add and yarn add

    Many thanks to @​connorshea for proposing and implementing this enhancement!

  • The [archived-uses] audit now supports pre-commit config inputs (#2272)

  • The [ref-confusion] audit now supports pre-commit config inputs (#2274)

  • The [cache-poisoning] audit now produces more detailed and more precise diagnostics (#2330)

  • The [cache-poisoning] audit now handles and exposes auto-fixes in a more general manner (#2332)

  • zizmor now recognizes @​sethvargo/ratchet version comments when evaluating ref pinning (#2319)

    Many thanks to @​njgudman for proposing and implementing this enhancement!

  • The [unpinned-tools] audit now produces more detailed and more precise diagnostics (#2339)

  • The [unpinned-tools] audit now detects usages of @​extractions/setup-just (#2339)

  • The [unpinned-tools] audit now detects usages of @​extractions/setup-crate (#2340)

  • The [archived-uses] audit now detects several more archived repositories (#2340)

  • The [ref-version-mismatch] audit now supports #!yaml uses: that reference

... (truncated)

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the python-packages group with 5 updates:

| Package | From | To |
| --- | --- | --- |
| [ruff](https://github.com/astral-sh/ruff) | `0.16.4` | `0.16.8` |
| [uvicorn](https://github.com/Kludex/uvicorn) | `0.52.4` | `0.53.0` |
| [ty](https://github.com/astral-sh/ty) | `0.0.74` | `0.0.83` |
| [prek](https://github.com/j178/prek) | `0.4.14` | `0.5.3` |
| [zizmor](https://github.com/zizmorcore/zizmor) | `1.29.0` | `1.30.1` |


Updates `ruff` from 0.16.4 to 0.16.8
- [Release notes](https://github.com/astral-sh/ruff/releases)
- [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md)
- [Commits](astral-sh/ruff@0.16.4...0.16.8)

Updates `uvicorn` from 0.52.4 to 0.53.0
- [Release notes](https://github.com/Kludex/uvicorn/releases)
- [Changelog](https://github.com/Kludex/uvicorn/blob/main/docs/release-notes.md)
- [Commits](Kludex/uvicorn@0.52.4...0.53.0)

Updates `ty` from 0.0.74 to 0.0.83
- [Release notes](https://github.com/astral-sh/ty/releases)
- [Changelog](https://github.com/astral-sh/ty/blob/main/CHANGELOG.md)
- [Commits](astral-sh/ty@0.0.74...0.0.83)

Updates `prek` from 0.4.14 to 0.5.3
- [Release notes](https://github.com/j178/prek/releases)
- [Changelog](https://github.com/j178/prek/blob/master/CHANGELOG.md)
- [Commits](j178/prek@v0.4.14...v0.5.3)

Updates `zizmor` from 1.29.0 to 1.30.1
- [Release notes](https://github.com/zizmorcore/zizmor/releases)
- [Changelog](https://github.com/zizmorcore/zizmor/blob/main/docs/release-notes.md)
- [Commits](zizmorcore/zizmor@v1.29.0...v1.30.1)

---
updated-dependencies:
- dependency-name: ruff
  dependency-version: 0.16.8
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: python-packages
- dependency-name: uvicorn
  dependency-version: 0.53.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: python-packages
- dependency-name: ty
  dependency-version: 0.0.83
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: python-packages
- dependency-name: prek
  dependency-version: 0.5.3
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: python-packages
- dependency-name: zizmor
  dependency-version: 1.30.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: python-packages
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels Oct 1, 2026
@latest-changes latest-changes Bot added the internal Internal changes label Oct 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file internal Internal changes python:uv Pull requests that update python:uv code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants