Skip to content

[pip] (deps): Bump the dev-dependencies group across 1 directory with 13 updates - #172

Merged
alanvivona merged 1 commit into
mainfrom
dependabot/pip/dev-dependencies-cdd3574fa4
Oct 5, 2026
Merged

alanvivona merged 1 commit into
mainfrom
dependabot/pip/dev-dependencies-cdd3574fa4

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 4, 2026

Copy link
Copy Markdown
Contributor

Bumps the dev-dependencies group with 13 updates in the / directory:

Package From To
charset-normalizer 3.5.1 3.5.2
idna 3.19 3.20
urllib3 2.7.0 2.8.0
coverage 7.16.0 7.16.2
filelock 3.32.5 4.0.8
identify 2.6.19 2.6.20
nodeenv 1.10.0 1.11.0
platformdirs 4.11.7 4.12.2
pyright 1.1.411 1.1.414
pytest-mock 3.15.1 3.16.0
python-discovery 1.6.0 1.6.1
ruff 0.16.6 0.16.10
virtualenv 21.7.8 21.14.2

Updates charset-normalizer from 3.5.1 to 3.5.2

Release notes

Sourced from charset-normalizer's releases.

Version 3.5.2

3.5.2 (2026-09-29)

Changed

  • Raised the Cython upper bound to <3.4 for native builds. The bound remains <3.3 for abi3 builds to preserve compatibility with the Python 3.7 Limited API.

Fixed

  • Valid UTF-8 Chinese JSON incorrectly detected as PTCP154 due to excessive noise penalties for uncommon CJK characters. (#796)
  • Supported encodings without aliases failing name resolution or being ignored in charset declarations. (#800)
Changelog

Sourced from charset-normalizer's changelog.

3.5.2 (2026-09-29)

Changed

  • Raised the Cython upper bound to <3.4 for native builds. The bound remains <3.3 for abi3 builds to preserve compatibility with the Python 3.7 Limited API.

Fixed

  • Valid UTF-8 Chinese JSON incorrectly detected as PTCP154 due to excessive noise penalties for uncommon CJK characters. (#796)
  • Supported encodings without aliases failing name resolution or being ignored in charset declarations. (#800)
Commits
  • 935c29a Release 3.5.2 (#805)
  • 9d3238a test: disable traefik in downstream niquests
  • b4c0368 docs: write changelog entry for 3.5.2
  • 717da31 chore: bump version to 3.5.2
  • 264895d chore: update pypa/cibuildwheel and pypa/gh-action-pypi-publish
  • 41e28b6 chore: raise Cython upper bound to 3.3
  • b130b7d Fix valid UTF-8 Chinese JSON misdetected as PTCP154 (#796)
  • f6afd31 Make the IANA_NO_ALIASES encodings resolvable by name (#800)
  • See full diff in compare view

Updates idna from 3.19 to 3.20

Release notes

Sourced from idna's releases.

v3.20

  • Update to Unicode 18.0.0.
  • Better enforcement of the domain length limit in the incremental codec.
  • Add support for Python 3.15.
Changelog

Sourced from idna's changelog.

3.20 (2026-09-17)

  • Update to Unicode 18.0.0.
  • Better enforcement of the domain length limit in the incremental codec.
  • Add support for Python 3.15.
Commits
  • d55e65e Release 3.20
  • 0c0824a Pre-release 3.20rc0
  • bd7c316 Note Python 3.15 support in the 3.20 changelog
  • b6cce85 Merge pull request #276 from kjd/unicode-18
  • 9a4bc59 Update to Unicode 18.0.0
  • dfab5a0 Merge branch 'python-3.15'
  • 417c354 Read the latest Unicode version from the DerivedAge.txt header instead of the...
  • cd17392 Merge pull request #274 from kjd/fix-decode-length-check
  • c5796d7 Skip the decode round-trip check for domains past encode's length limit
  • d6ee690 Update to Python 3.15 release candidate in CI and add trove classifier
  • Additional commits viewable in compare view

Updates urllib3 from 2.7.0 to 2.8.0

Release notes

Sourced from urllib3's releases.

2.8.0

🚀 urllib3 is fundraising for HTTP/2 support

urllib3 is raising ~$40,000 USD to release HTTP/2 support and ensure long-term sustainable maintenance of the project. If your company or organization uses Python and would benefit from HTTP/2 support in Requests, pip, cloud SDKs, and thousands of other projects please consider contributing financially to ensure HTTP/2 support is developed sustainably and maintained for the long-haul.

Thank you for your support.

Security

Fixed the following security issues:

  • The TLS configuration for HTTPS proxies could be ignored or overridden. (High severity, GHSA-8988-9cw3-xx77)
  • HTTPResponse.stream() and read_chunked() could buffer a chunk-size line of unbounded length in memory. (High severity, GHSA-vxq7-64xx-v4gw)
  • Chunked Deflate streaming could enter an infinite loop. (Medium severity, GHSA-gh4c-6fx4-qh6g)

[!IMPORTANT] urllib3 2.8.0 fixes HTTPS proxy TLS configuration being ignored or overridden by destination settings. Configurations relying on that behavior may require changes.

Configure proxy CA certificates and client certificates in proxy_ssl_context, and proxy identity checks with proxy_assert_hostname or proxy_assert_fingerprint. Destination client certificates and identity overrides no longer apply to HTTPS forwarding proxy connections.

[!NOTE] CVE IDs had not yet been assigned to these advisories at the time of release due to a backlog at GitHub's CNA.

Deprecations & Removals

  • Deprecated using an empty collection as the Retry option allowed_methods to retry any verb. (#5044)

Features

  • Added Url.auth_decoded and Url.auth_decoded_joined convenience properties to the result of parse_url(). (#4945)
  • Added basic_auth_encoding and proxy_basic_auth_encoding parameters to urllib3.util.make_headers(). (#5092)

Bugfixes

  • Fixed response header handling to replace obsolete folded header lines (obs-fold) with spaces in accordance with RFC 9112, preventing raw CRLF sequences from appearing in header values such as Set-Cookie. (#1362)

  • Fixed usage of proxy_ssl_context with ProxyManager when use_forwarding_for_https=True. Passing ssl_context instead of proxy_ssl_context for HTTPS proxies in this configuration now emits a FutureWarning and will raise an error in v3.0. (#2577)

  • Changed behavior of the default ConnectionPool.pool initialization. LifoQueue is now resolved from the queue module after the ConnectionPool is instantiated instead of using the default cached QueueCls class property. This is done because sometimes the queue.LifoQueue is monkey-patched late in the program, such as by gevent. (#3289)

  • Raised UnrewindableBodyError instead of ValueError when retrying a request whose body had tell() but not seek(). (#3779)

  • Decoded percent-encoded SOCKS proxy credentials before authenticating with the proxy server. (#3785)

  • Fixed HTTPResponse.drain_conn() to discard unread response data in 64 KiB chunks (same as the default amt when doing HTTPResponse.stream(...)). (#5019)

  • Fixed is_ipaddress() to detect non-standard IPv4 forms accepted by socket.connect, such as hex (0x7f000001), octal (0177.0.0.1), and decimal integers (2130706433), ensuring SSL certificate verification uses the correct mode for these addresses. (#5029)

  • Fixed HTTPConnectionPool.urlopen raising a misleading FullPoolError instead of ValueError when called with an invalid timeout argument on a pool created with block=True. (#5059)

  • Fixed port-zero handling to preserve explicit :0 values instead of substituting the default ports 80 or 443 in URL parsing, pool selection, proxy configuration, connection_from_url(), and HTTP/2 request authority. (#5071, #5101)

  • Fixed a bug where PoolManager passed the assert_hostname and assert_fingerprint parameters to HTTP connection pools. (#5077)

  • Fixed HTTPConnectionPool.urlopen() and HTTP proxy forwarding to strip URL fragments from absolute request targets before sending requests. (#5079)

  • Added safeguards to the proxy tunneling code to prevent potential security issues when handling invalid characters in the proxy host and HTTP headers. This change affects users of Python 3.10, Python 3.11, and Python 3.12 when the standard library does not contain the fix; those on newer Python versions should upgrade to 3.13.14+ or 3.14.5+ to get the same security fixes. (#5091)

  • Fixed HTTPSConnection.connect() overriding ProxyConfig.ssl_context's certificate policy and proxy identity checks with the target connection's TLS settings when forwarding through an HTTPS proxy.

    HTTPSConnection no longer applies target SNI, assertions, or client credentials to forwarding proxy handshakes and continues to use its ssl_context as a fallback when an HTTPS proxy forwards an HTTP target. (#5093)

  • Fixed URL parsing to more strictly enforce RFC 3986 host syntax, rejecting invalid host input such as raw spaces and control characters, malformed percent-encodings, and percent-encoded control characters in HTTP(S) hosts and IPv6 zone identifiers, including proxy CONNECT tunnel targets. Host normalization now also follows RFC 3986 normalization rules for percent-encoded octets by decoding percent-encoded unreserved characters and uppercasing the hexadecimal digits of retained percent-encoded octets. (#5095)

... (truncated)

Changelog

Sourced from urllib3's changelog.

2.8.0 (2026-09-15)

Security

Fixed the following security issues:

  • The TLS configuration for HTTPS proxies could be ignored or overridden. (High severity, GHSA-8988-9cw3-xx77 <https://github.com/urllib3/urllib3/security/advisories/GHSA-8988-9cw3-xx77>__)
  • HTTPResponse.stream() and read_chunked() could buffer a chunk-size line of unbounded length in memory. (High severity, GHSA-vxq7-64xx-v4gw <https://github.com/urllib3/urllib3/security/advisories/GHSA-vxq7-64xx-v4gw>__)
  • Chunked Deflate streaming could enter an infinite loop. (Medium severity, GHSA-gh4c-6fx4-qh6g <https://github.com/urllib3/urllib3/security/advisories/GHSA-gh4c-6fx4-qh6g>__)

.. caution::

urllib3 2.8.0 fixes HTTPS proxy TLS configuration being ignored or
overridden by destination settings. Configurations relying on that
behavior may require changes.

Configure proxy CA certificates and client certificates in proxy_ssl_context, and proxy identity checks with proxy_assert_hostname or proxy_assert_fingerprint. Destination client certificates and identity overrides no longer apply to HTTPS forwarding proxy connections.

Deprecations & Removals

  • Deprecated using an empty collection as the Retry option allowed_methods to retry any verb. ([#5044](https://github.com/urllib3/urllib3/issues/5044) <https://github.com/urllib3/urllib3/issues/5044>__)

Features

  • Added Url.auth_decoded and Url.auth_decoded_joined convenience properties to the result of parse_url(). ([#4945](https://github.com/urllib3/urllib3/issues/4945) <https://github.com/urllib3/urllib3/issues/4945>__)
  • Added basic_auth_encoding and proxy_basic_auth_encoding parameters to urllib3.util.make_headers(). ([#5092](https://github.com/urllib3/urllib3/issues/5092) <https://github.com/urllib3/urllib3/issues/5092>__)

Bugfixes

... (truncated)

Commits
  • b1d30ab Release 2.8.0
  • 9016d7e Skip test_read_chunked_with_trailing_data_does_not_hang for brotlicffi (#5258)
  • 9101f58 Fix nox -s docs warning (#5256)
  • cd770b0 Merge commit from fork
  • ea2ad7b Merge commit from fork
  • 0716e31 Fix loading unencrypted client keys with a password in pyOpenSSL (#5255)
  • 43c68c8 Test pickling of InvalidChunkLength (#5247)
  • 308b279 Share security policy between GitHub and Read the Docs (#5253)
  • 53fa073 Add policy on duplicate pull requests (#5252)
  • 5f2a6a8 Assert on the ALPN extension in test_tunnel_sets_http_11_alpn (#5232)
  • Additional commits viewable in compare view

Updates coverage from 7.16.0 to 7.16.2

Release notes

Sourced from coverage's releases.

7.16.2

Version 7.16.2 — 2026-09-27

  • Fix: on Python 3.14 and later, a for loop completing immediately before a function return could mistakenly report an uncovered branch. This is now fixed, closing issue 2168.
  • Fix: on Python 3.14 and later, the else clause of a try whose body is a with statement could incorrectly be reported as covered when the with raised. This is now fixed, closing issue 2289.
  • Fix: with dynamic_context = test_function, test methods written as @staticmethod or @classmethod were not given a context of their own. Now they are, on Python 3.11 and later. Closes issue 1923.

➡️  PyPI page: coverage 7.16.2. :arrow_right:  To install: python3 -m pip install coverage==7.16.2

7.16.1

Version 7.16.1 — 2026-09-13

  • Fix: when the body of an irrefutable case (like case _:) is entirely excluded, the case line is now excluded too, just as an excluded else: body removes the else: line. Previously the case line was left behind and reported as missing. Closes issue 1563 with pull 2269.
  • Fix: using CoverageData.update() twice on an in-memory database would fail, as described in issue 2279. This is now fixed.

➡️  PyPI page: coverage 7.16.1. :arrow_right:  To install: python3 -m pip install coverage==7.16.1

Changelog

Sourced from coverage's changelog.

Version 7.16.2 — 2026-09-27

  • Fix: on Python 3.14 and later, a for loop completing immediately before a function return could mistakenly report an uncovered branch. This is now fixed, closing issue 2168_.

  • Fix: on Python 3.14 and later, the else clause of a try whose body is a with statement could incorrectly be reported as covered when the with raised. This is now fixed, closing issue 2289_.

  • Fix: with dynamic_context = test_function, test methods written as @staticmethod or @classmethod were not given a context of their own. Now they are, on Python 3.11 and later. Closes issue 1923_.

.. _issue 1923: coveragepy/coveragepy#1923 .. _issue 2168: coveragepy/coveragepy#2168 .. _issue 2289: coveragepy/coveragepy#2289

.. _changes_7-16-1:

Version 7.16.1 — 2026-09-13

  • Fix: when the body of an irrefutable case (like case _:) is entirely excluded, the case line is now excluded too, just as an excluded else: body removes the else: line. Previously the case line was left behind and reported as missing. Closes issue 1563_ with pull 2269_.

  • Fix: using :meth:.CoverageData.update twice on an in-memory database would fail, as described in issue 2279_. This is now fixed.

.. _issue 1563: coveragepy/coveragepy#1563 .. _pull 2269: coveragepy/coveragepy#2269 .. _issue 2279: coveragepy/coveragepy#2279

.. _changes_7-16-0:

Commits

Updates filelock from 3.32.5 to 4.0.8

Release notes

Sourced from filelock's releases.

4.0.8

What's Changed

Full Changelog: tox-dev/filelock@4.0.7...4.0.8

4.0.7

What's Changed

Full Changelog: tox-dev/filelock@4.0.6...4.0.7

4.0.6

What's Changed

Full Changelog: tox-dev/filelock@4.0.5...4.0.6

4.0.5

What's Changed

New Contributors

Full Changelog: tox-dev/filelock@4.0.4...4.0.5

4.0.4

What's Changed

... (truncated)

Changelog

Sourced from filelock's changelog.

########### Changelog ###########

.. towncrier-draft-entries:: Unreleased

.. towncrier release notes start


4.0.10 (2026-10-03)


  • Reusing a singleton AsyncFileLock with another loop, executor or run_in_executor, or a singleton SoftFileLease with another lease_duration, heartbeat_interval or on_compromise, now raises ValueError instead of returning the lock with its original options. :pr:765

4.0.9 (2026-10-01)


  • ReadWriteLock and AsyncReadWriteLock close the descriptor that checks the database path once SQLite has connected, so on PyPy a dropped lock leaves no descriptor open until garbage collection runs. :pr:763
  • ReadWriteLock and AsyncReadWriteLock refuse a symlink at the database path instead of following it, so a user who can create names in a shared lock directory cannot point the lock at another file (GHSA-j8f7-rjxc-mr56).

4.0.8 (2026-10-01)


  • ReadWriteLock.release() and SoftReadWriteLock.release() from a thread that does not hold the write lock now raise RuntimeError instead of dropping the holder's lock and letting a second writer in. :pr:761

4.0.7 (2026-09-29)


  • File locks now raise ValueError at construction when mode denies the owner read or write, such as mode=0o444, instead of failing on a later acquire and staying broken until someone deletes the lock file. :pr:760

4.0.6 (2026-09-28)


  • Reject negative blocking timeouts other than -1 before reentrant ReadWriteLock and SoftReadWriteLock acquisition. Preserve unlimited waits and nonblocking acquisition. :pr:756

4.0.5 (2026-09-28)


... (truncated)

Commits
  • 9376e9b Release 4.0.8
  • 34f4657 🐛 fix(read-write): refuse cross-thread write release (#761)
  • 9ed62ac Release 4.0.7
  • 2f2c4a7 🐛 fix(mode): require owner read and write (#760)
  • d4ffe9c build(deps): bump astral-sh/setup-uv from 10.1.0 to 10.2.0 in the github-acti...
  • 61ce360 Release 4.0.6
  • d9dedd5 [pre-commit.ci] pre-commit autoupdate (#757)
  • b5fae95 fix(read-write): validate reentrant timeouts (#756)
  • bbb843e Release 4.0.5
  • 83fa216 test(read-write): cover omitted arguments (#754)
  • Additional commits viewable in compare view

Updates identify from 2.6.19 to 2.6.20

Commits
  • aa34031 v2.6.20
  • 116099f Merge pull request #609 from Malix-Labs/feat/add-nushell
  • 971546c Merge pull request #610 from pre-commit/lock-file-tags
  • da45cb1 Add support for 'nu' extension and Nushell interpreters
  • a35b99b Merge pull request #608 from steovd/profile-sh
  • bd5cdb7 Merge pull request #601 from ngie-eign/issue-258
  • 66faf04 Merge pull request #597 from edgarrmondragon/patch-1
  • c75a0a2 Merge pull request #593 from NinjaMandalorian/main
  • ea6c9f9 Add support for 'luau' file extension
  • d28c571 Merge pull request #585 from Kvan7/patch-1
  • Additional commits viewable in compare view

Updates nodeenv from 1.10.0 to 1.11.0

Release notes

Sourced from nodeenv's releases.

1.11.0

What's Changed

New Features 🎉

Fixed bugs 🐛

Improvements 🛠

Documentation 📄

Other Changes

New Contributors

Full Changelog: ekalinin/nodeenv@1.10.0...1.11.0

Changelog

Sourced from nodeenv's changelog.

Version 1.11.0

  • Fixed zsh source bin/activate aborting on the direct-call guard [#398](https://github.com/ekalinin/nodeenv/issues/398) <https://github.com/ekalinin/nodeenv/issues/398>_
  • Added check for how activate is called [#384](https://github.com/ekalinin/nodeenv/issues/384) <https://github.com/ekalinin/nodeenv/pull/384>_
  • Addressed the tarfile.extractall deprecation on Python >= 3.12 by setting filter='data', which also prevents writing files via ".." or absolute paths [#380](https://github.com/ekalinin/nodeenv/issues/380) <https://github.com/ekalinin/nodeenv/pull/380>_
  • Added support for Solaris/illumos [#360](https://github.com/ekalinin/nodeenv/issues/360) <https://github.com/ekalinin/nodeenv/issues/360>_
  • Added predeactivate hooks for Windows
  • Added error handling and tests for the node installation [#336](https://github.com/ekalinin/nodeenv/issues/336) <https://github.com/ekalinin/nodeenv/issues/336>_
  • Removed the leftover debug print that leaked a dict to stdout on every version detection [#390](https://github.com/ekalinin/nodeenv/issues/390) <https://github.com/ekalinin/nodeenv/issues/390>_
  • Added --with-certifi to download packages with the certifi certificate bundle [#388](https://github.com/ekalinin/nodeenv/issues/388) <https://github.com/ekalinin/nodeenv/pull/388>_
  • --node accepts npm-style semver ranges [#393](https://github.com/ekalinin/nodeenv/issues/393) <https://github.com/ekalinin/nodeenv/pull/393>_
  • Added --prefer-system to use system-wide node.js when available and install one otherwise [#153](https://github.com/ekalinin/nodeenv/issues/153) <https://github.com/ekalinin/nodeenv/issues/153>_
  • Added --isolate-npm to keep npm cache, userconfig and init-module inside the environment [#154](https://github.com/ekalinin/nodeenv/issues/154) <https://github.com/ekalinin/nodeenv/issues/154>_
  • Added tests that run the activation scripts in sh, dash, bash, zsh and fish.
  • -p no longer reinstalls node when the requested version is already in the virtualenv [#159](https://github.com/ekalinin/nodeenv/issues/159) <https://github.com/ekalinin/nodeenv/issues/159>_
  • Repeated -p runs no longer duplicate the predeactivate hook [#159](https://github.com/ekalinin/nodeenv/issues/159) <https://github.com/ekalinin/nodeenv/issues/159>_
  • -p accepts an optional virtualenv directory and prefers the activated VIRTUAL_ENV over the virtualenv nodeenv itself is installed in [#156](https://github.com/ekalinin/nodeenv/issues/156) <https://github.com/ekalinin/nodeenv/issues/156>_
  • -r/--requirements may now be given more than once, and the new --local-requirements installs the packages of a file locally, into "node_modules" of the current directory, which is what freeze -l writes. Under npm < 1.0.0, which has no -g, a local file is still installed the old way [#206](https://github.com/ekalinin/nodeenv/issues/206) <https://github.com/ekalinin/nodeenv/issues/206>_
  • The "src" directory is now removed after installation by default, which halves the size of an environment. Added --no-clean-src to keep it: with --source that is what lets a repeated --force build reuse the downloaded source tree [#205](https://github.com/ekalinin/nodeenv/issues/205) <https://github.com/ekalinin/nodeenv/issues/205>_
  • Documented that --mirror takes a file:// URL, so a local directory can serve as the download source [#193](https://github.com/ekalinin/nodeenv/issues/193) <https://github.com/ekalinin/nodeenv/issues/193>_
  • The posix activate is now written on Windows too, into "Scripts", so git-bash and the other posix shells there can activate an environment [#226](https://github.com/ekalinin/nodeenv/issues/226) <https://github.com/ekalinin/nodeenv/issues/226>_
  • A download that reaches nothing at all, which a broken http_proxy or https_proxy usually causes, now reports the url and the proxy settings instead of a traceback

... (truncated)

Commits
  • e745358 Merge pull request #418 from ekalinin/chore/release-1.11.0
  • fd19956 chore(release): bump nodeenv version to 1.11.0
  • 1767015 Merge pull request #415 from ekalinin/fix/nodejs-exe-link
  • 55df3ce Merge pull request #417 from r3wretrhy/fix/zsh-activate-source-guard
  • bb15c5c fix: allow zsh to source bin/activate
  • 152cd3d fix(nodeenv): link nodejs.exe without mklink
  • d163302 Merge pull request #414 from ekalinin/fix/freeze-requirements
  • ef5ec35 fix(nodeenv): read npm's parseable listing in freeze
  • b1f0c54 Merge pull request #413 from ekalinin/fix/musl-vendor-detection
  • aadf307 fix(nodeenv): detect musl regardless of the host triplet vendor
  • Additional commits viewable in compare view

Updates platformdirs from 4.11.7 to 4.12.2

Release notes

Sourced from platformdirs's releases.

4.12.2

What's Changed

New Contributors

Full Changelog: tox-dev/platformdirs@4.12.1...4.12.2

4.12.1

What's Changed

Full Changelog: tox-dev/platformdirs@4.12.0...4.12.1

4.12.0

What's Changed

Full Changelog: tox-dev/platformdirs@4.11.15...4.12.0

4.11.15

What's Changed

... (truncated)

Changelog

Sourced from platformdirs's changelog.

########### Changelog ###########

.. towncrier-draft-entries:: Unreleased

.. towncrier release notes start


4.12.3 (2026-10-03)


  • Place files from place_config_file and place_data_file in the first site directory for root on Unix with use_site_for_root=True and multipath=True, where find_config_file and find_data_file look for them. :pr:607

4.12.2 (2026-09-29)


  • Keep os.pathsep in site_applications_path under multipath=True on platforms with one applications directory. :pr:604

4.12.1 (2026-09-28)


  • Avoid PytestAssertRewriteWarning when importing platformdirs before invoking pytest. :pr:601

4.12.0 (2026-09-26)


  • Add place_*_file methods that return a file path under a user directory and create its missing parents with mode 0o700. :pr:585
  • Add find_<kind>_file and find_<kind>_files to look up an existing file across the user and site directories of each kind that has an iter_<kind>_paths method. :pr:586
  • Add :func:platformdirs.testing.isolated_dirs and the platformdirs_isolated pytest fixture to resolve every directory under one test root. :pr:590
  • Emit :class:~platformdirs.RuntimeDirWarning when the Unix :func:~platformdirs.user_runtime_dir falls back from XDG_RUNTIME_DIR. :pr:599
  • Read user_templates_dir, user_publicshare_dir and user_bin_dir on Windows from their known folders. :pr:587
  • Create missing user app directories and their parents with mode 0700 under ensure_exists on POSIX platforms. :pr:588
  • Raise RuntimeError for a Unix or macOS directory under the home when no home resolves, and read the password database for an empty HOME. :pr:589
  • Skip an XDG_RUNTIME_DIR or /run/user/<uid> that is not a private directory of the user, and reject a symlink or file as the runtime-<uid> fallback. :pr:599
  • Use the app container layout on iOS, such as ~/Library/Application Support for data. :pr:600

... (truncated)

Commits
  • af2fc7f Release 4.12.2
  • bdafa67 ♻️ refactor(api): share use_site iteration (#606)
  • d5ff75c 🐛 fix(api): keep os.pathsep in site_applications_path (#604)
  • d545744 build(deps): bump astral-sh/setup-uv from 10.1.0 to 10.2.0 in the all group (...
  • 9fd89a7 [pre-commit.ci] pre-commit autoupdate (#603)
  • 0a50795 Release 4.12.1
  • 72e93ff fix(pytest): allow import before pytest startup (#602)
  • ea7be87 Release 4.12.0
  • de46f51 🐛 fix(unix): validate XDG_RUNTIME_DIR and warn on fallback (#599)
  • ca2b313 🐛 fix(dirs): raise when no home directory resolves (#589)
  • Additional commits viewable in compare view

Updates pyright from 1.1.411 to 1.1.414

Commits

… 13 updates

Bumps the dev-dependencies group with 13 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [charset-normalizer](https://github.com/jawah/charset_normalizer) | `3.5.1` | `3.5.2` |
| [idna](https://github.com/kjd/idna) | `3.19` | `3.20` |
| [urllib3](https://github.com/urllib3/urllib3) | `2.7.0` | `2.8.0` |
| [coverage](https://github.com/coveragepy/coveragepy) | `7.16.0` | `7.16.2` |
| [filelock](https://github.com/tox-dev/py-filelock) | `3.32.5` | `4.0.8` |
| [identify](https://github.com/pre-commit/identify) | `2.6.19` | `2.6.20` |
| [nodeenv](https://github.com/ekalinin/nodeenv) | `1.10.0` | `1.11.0` |
| [platformdirs](https://github.com/tox-dev/platformdirs) | `4.11.7` | `4.12.2` |
| [pyright](https://github.com/RobertCraigie/pyright-python) | `1.1.411` | `1.1.414` |
| [pytest-mock](https://github.com/pytest-dev/pytest-mock) | `3.15.1` | `3.16.0` |
| [python-discovery](https://github.com/tox-dev/python-discovery) | `1.6.0` | `1.6.1` |
| [ruff](https://github.com/astral-sh/ruff) | `0.16.6` | `0.16.10` |
| [virtualenv](https://github.com/pypa/virtualenv) | `21.7.8` | `21.14.2` |



Updates `charset-normalizer` from 3.5.1 to 3.5.2
- [Release notes](https://github.com/jawah/charset_normalizer/releases)
- [Changelog](https://github.com/jawah/charset_normalizer/blob/master/CHANGELOG.md)
- [Commits](jawah/charset_normalizer@3.5.1...3.5.2)

Updates `idna` from 3.19 to 3.20
- [Release notes](https://github.com/kjd/idna/releases)
- [Changelog](https://github.com/kjd/idna/blob/master/HISTORY.md)
- [Commits](kjd/idna@v3.19...v3.20)

Updates `urllib3` from 2.7.0 to 2.8.0
- [Release notes](https://github.com/urllib3/urllib3/releases)
- [Changelog](https://github.com/urllib3/urllib3/blob/main/CHANGES.rst)
- [Commits](urllib3/urllib3@2.7.0...2.8.0)

Updates `coverage` from 7.16.0 to 7.16.2
- [Release notes](https://github.com/coveragepy/coveragepy/releases)
- [Changelog](https://github.com/coveragepy/coveragepy/blob/main/CHANGES.rst)
- [Commits](coveragepy/coveragepy@7.16.0...7.16.2)

Updates `filelock` from 3.32.5 to 4.0.8
- [Release notes](https://github.com/tox-dev/py-filelock/releases)
- [Changelog](https://github.com/tox-dev/filelock/blob/main/docs/changelog.rst)
- [Commits](tox-dev/filelock@3.32.5...4.0.8)

Updates `identify` from 2.6.19 to 2.6.20
- [Commits](pre-commit/identify@v2.6.19...v2.6.20)

Updates `nodeenv` from 1.10.0 to 1.11.0
- [Release notes](https://github.com/ekalinin/nodeenv/releases)
- [Changelog](https://github.com/ekalinin/nodeenv/blob/master/CHANGES)
- [Commits](ekalinin/nodeenv@1.10.0...1.11.0)

Updates `platformdirs` from 4.11.7 to 4.12.2
- [Release notes](https://github.com/tox-dev/platformdirs/releases)
- [Changelog](https://github.com/tox-dev/platformdirs/blob/main/docs/changelog.rst)
- [Commits](tox-dev/platformdirs@4.11.7...4.12.2)

Updates `pyright` from 1.1.411 to 1.1.414
- [Release notes](https://github.com/RobertCraigie/pyright-python/releases)
- [Commits](RobertCraigie/pyright-python@v1.1.411...v1.1.414)

Updates `pytest-mock` from 3.15.1 to 3.16.0
- [Release notes](https://github.com/pytest-dev/pytest-mock/releases)
- [Changelog](https://github.com/pytest-dev/pytest-mock/blob/main/CHANGELOG.rst)
- [Commits](pytest-dev/pytest-mock@v3.15.1...v3.16.0)

Updates `python-discovery` from 1.6.0 to 1.6.1
- [Release notes](https://github.com/tox-dev/python-discovery/releases)
- [Changelog](https://github.com/tox-dev/python-discovery/blob/main/docs/changelog.rst)
- [Commits](tox-dev/python-discovery@1.6.0...1.6.1)

Updates `ruff` from 0.16.6 to 0.16.10
- [Release notes](https://github.com/astral-sh/ruff/releases)
- [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md)
- [Commits](astral-sh/ruff@0.16.6...0.16.10)

Updates `virtualenv` from 21.7.8 to 21.14.2
- [Release notes](https://github.com/pypa/virtualenv/releases)
- [Changelog](https://github.com/pypa/virtualenv/blob/main/docs/changelog.rst)
- [Commits](pypa/virtualenv@21.7.8...21.14.2)

---
updated-dependencies:
- dependency-name: charset-normalizer
  dependency-version: 3.5.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dev-dependencies
- dependency-name: idna
  dependency-version: '3.20'
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dev-dependencies
- dependency-name: urllib3
  dependency-version: 2.8.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dev-dependencies
- dependency-name: coverage
  dependency-version: 7.16.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: dev-dependencies
- dependency-name: filelock
  dependency-version: 4.0.8
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: dev-dependencies
- dependency-name: identify
  dependency-version: 2.6.20
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: dev-dependencies
- dependency-name: nodeenv
  dependency-version: 1.11.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dev-dependencies
- dependency-name: platformdirs
  dependency-version: 4.12.2
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dev-dependencies
- dependency-name: pyright
  dependency-version: 1.1.414
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: dev-dependencies
- dependency-name: pytest-mock
  dependency-version: 3.16.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dev-dependencies
- dependency-name: python-discovery
  dependency-version: 1.6.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: dev-dependencies
- dependency-name: ruff
  dependency-version: 0.16.10
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: dev-dependencies
- dependency-name: virtualenv
  dependency-version: 21.14.2
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dev-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot requested a review from a team as a code owner October 4, 2026 21:05
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update Python code labels Oct 4, 2026
@github-actions

github-actions Bot commented Oct 4, 2026

Copy link
Copy Markdown

Coverage report

This PR does not seem to contain any modification to coverable code.

@alanvivona
alanvivona merged commit 4f60536 into main Oct 5, 2026
23 checks passed
@alanvivona
alanvivona deleted the dependabot/pip/dev-dependencies-cdd3574fa4 branch October 5, 2026 12:07

This branch was successfully deployed

1 active deployment
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update Python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant