Skip to content

chore(deps): update dev-dependencies - #448

Merged
renovate[bot] merged 1 commit into
mainfrom
renovate/dev-dependencies
Oct 10, 2026
Merged

renovate[bot] merged 1 commit into
mainfrom
renovate/dev-dependencies

Conversation

@renovate

@renovate renovate Bot commented Oct 10, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence Type Update
ruff (source, changelog) ==0.16.10 → ==0.17.0 age confidence dependency-groups minor
uv 0.12.24 → 0.13.0 age confidence tools minor

Release Notes

astral-sh/ruff (ruff)

v0.17.0

Compare Source

Released on 2026-10-09.

The executables in our macOS and Windows release archives and ruff wheels are now code-signed.
macOS executables are signed with an Apple Developer ID certificate and notarized by Apple. Windows
executables have timestamped Authenticode signatures from Azure Artifact Signing. This enables
verification of the release publisher and binary integrity, supports publisher-based allowlisting,
and should reduce security warnings and antivirus false positives.

Breaking changes
  • Update the default and latest Python versions for 3.15 (#​28792)

    Ruff now defaults to Python 3.11 instead of 3.10 when no Python version is configured through
    target-version or
    requires-python. When
    checking for syntax errors without a configured Python version, Ruff now defaults to Python 3.15
    instead of 3.14.

  • Update the default rule set (#​28786)

    Several of the flake8-datetimez rules
    (DTZ001,
    DTZ005,
    DTZ006,
    DTZ007,
    DTZ011,
    DTZ012, and
    DTZ901) are no longer enabled by default,
    while undefined-local-with-nested-import-star-usage
    (F406), which corresponds to a syntax error, is now enabled by default.

  • Update Rust crate quick-junit to 0.8.0 (#​27295)

    JUnit output now uses a skipped attribute instead of disabled on <testsuite> elements and
    includes a skipped attribute on the root <testsuites> element.

  • [flake8-import-conventions] Add datetime as dt as a conventional alias (ICN001) (#​28790)

  • Support Unicode dummy variable names (#​28722)

    The default lint.dummy-variable-rgx
    now recognizes underscore-prefixed Unicode names, such as _次, as dummy variables.

  • Update to Unicode 17 (#​21229, #​28784)

    Ruff now uses Unicode 17 data for identifier normalization and named character escapes ("\N{...}").

  • Always show unsafe and display-only fixes in the CLI (#​27810)

    The default full output format now shows unsafe fixes and suggestions requiring manual review,
    regardless of the unsafe-fixes setting.
    Actually applying unsafe fixes still requires explicit opt-in.

  • Remove the Python dependency from conda-forge builds (conda-forge/ruff-feedstock#361)

    The conda-forge build no longer depends on Python, now supports linux-riscv64, win-arm64, and
    linux-ppc64le platforms, and now includes shell completions. However, no longer depending on
    Python means that python -m ruff and import ruff will no longer work. Use ruff directly from
    PATH instead. PyPI installations and those from the standalone installer are unaffected.

  • Remove support for ruff-lsp (#​28750)

    Support for ruff-lsp, the legacy Python language server deprecated in Ruff
    v0.9.5
    , has been removed. The Ruff VS Code
    extension now always uses the native language server; ruff.nativeServer is deprecated and
    ignored. See the migration guide.

Stabilization

The following rules have been stabilized and are no longer in preview:

The following behaviors have been stabilized:

  • The formatter, unsorted-imports (I001),
    line-too-long (E501), and
    doc-line-too-long (W505) now
    consistently ignore trailing pragma comments when computing line length. This resolved several
    bugs involving interactions between these rules
    (#​27313) but may also cause existing imports to be
    reformatted and was thus classified as a breaking change.
Preview features
  • [flake8-bugbear] Report the method name and a more precise range (B005) (#​27050)
  • [refurb] Mark fix unsafe and move to suspicious (FURB152) (#​28405)
  • [ruff] Allow docstrings in strict mode (RUF067) (#​28679)
Bug fixes
  • [flake8-builtins] Expand checks in class scopes (A001) (#​29076)
  • [flake8-self] Allow private access on object.__new__(cls) instances (SLF001) (#​29001)
  • [flake8-tidy-imports] Skip lazy-import-mismatch in stubs (TID254) (#​29095)
  • [flake8-type-checking] Add the notion of runtime-ambiguous references (#​26508)
  • [flake8-type-checking] Never flag annotations in function scopes (#​29183)
  • [pyflakes] Mark the fix as unsafe when it creates a docstring (F541) (#​28258)
  • [pylint] Preserve trailing comments in useless-return fix (PLR1711) (#​29180)
  • [ruff] Avoid false positive when pytest.raises is used in a with statement (RUF061) (#​28186)
Rule changes
  • [pyupgrade] Suggest typing.TypeForm on Python 3.15 (UP035) (#​29084)
Contributors
astral-sh/uv (uv)

v0.13.0

Compare Source

Released on 2026-10-09.

uv 0.13.0 makes Python 3.15 the default stable Python version. We've also included several breaking changes to improve correctness, performance, and compatibility, described below.

We expect most users to be able to upgrade without making changes.

While not a breaking change, this release also updates the format of many of uv's cache entries to improve performance. uv may download or rebuild dependencies after upgrading, because some cached entries from earlier versions cannot be reused. Multiple versions of uv can still safely share the same cache directory.

There are no breaking changes to the configuration of the uv build backend. If your [build-system] table includes an upper bound on uv_build, update it to allow uv_build 0.13, e.g., uv_build>=0.13.0,<0.14.

Breaking changes
  • Use Python 3.15 as the default stable version

    The default stable Python version has changed from 3.14 to 3.15. This affects Python downloads when no version is requested or pinned, e.g., when running uv python install.

    uv continues to use compatible Python installations that are already present. For example, uv venv can still use an installed Python 3.14. If no suitable interpreter is installed and automatic downloads are enabled, commands such as uv venv and uvx python can now download Python 3.15.

    You can opt out of this behavior by requesting Python 3.14 explicitly, e.g., uv venv --python 3.14. For projects, use uv python pin 3.14 to record the version in .python-version.

  • Honor --require-hashes in included constraints files (#​22275)

    Previously, uv ignored --require-hashes in constraints files included with -c from a requirements file. Now, uv honors the directive and requires hashes for all requirements in the installation. Installs that previously succeeded can now fail if a requirement is missing a hash.

    You cannot opt out while the directive is present. Add the missing hashes to your requirements, or remove the --require-hashes directive from the included constraints file if hash checking is not intended.

  • Prefer native Python on Windows ARM64 (#​22100)

    Previously, ARM64 builds of uv preferred emulated x86_64 Python installations because native wheel support was limited. Now, uv prefers native ARM64 (aarch64) interpreters across Python versions.

    This follows similar changes in CPython, the official Windows Python install manager, and GitHub's actions/setup-python.

    When a native interpreter is unavailable, uv continues to fall back to x86_64, then 32-bit x86.

    You can opt out of this behavior by setting UV_PYTHON_ARCH=x86_64 or requesting an explicit architecture, e.g., cpython-3.14-windows-x86_64. If you are using setup-uv, you can set python-arch: x86_64 instead.

  • Reject editable requirements in included constraints files (#​22282)

    Previously, uv silently ignored editable (-e) requirements in constraints files included with -c from a requirements file. Now, uv rejects these requirements with an error, matching pip's behavior.

    You cannot opt out of this behavior. Move editable requirements to a requirements file passed with -r, or pass them directly with --editable, instead of including them in a constraints file.

  • Omit the distutils startup patch on Python 3.10 and later (#​22096)

    Previously, uv installed _virtualenv.py and _virtualenv.pth into every new virtual environment to prevent distutils configuration from changing installation paths. Now, like virtualenv 21.6.0, uv omits these files on Python 3.10 and later, which already ignore the affected configuration keys. This reduces Python startup overhead. Python 3.9 and earlier retain the patch.

    You cannot opt out of this behavior. Existing virtual environments are not modified automatically. Recreate an environment with Python 3.10 or later to remove the patch.

    This stabilizes the no-distutils-patch preview feature.

  • Treat requirement-file option values as single paths (#​22290)

    Previously, uv split values passed to --constraint, --override, --exclude, and --build-constraint on spaces, even when quoted. Now, each value is treated as a single path, allowing file paths containing spaces.

    You cannot opt out of this behavior. Repeat the option to provide multiple files. For example, replace -c "a.txt b.txt" with -c a.txt -c b.txt.

    Space-separated lists in UV_CONSTRAINT, UV_OVERRIDE, UV_EXCLUDE, and UV_BUILD_CONSTRAINT remain supported.

  • Use tar-codec for tar archives by default (#​22094)

    Previously, uv used astral-tokio-tar to extract tar archives, build source distributions with uv_build, and read their metadata for uv publish. Now, uv uses tar-codec, which applies stricter validation when reading archives.

    uv may now reject archives containing hard links or unsupported tar extensions that previous versions accepted. Source distributions created by uv_build can also have different archive bytes and hashes.

    You can opt out of this behavior by setting UV_LEGACY_TAR_BACKEND=1.

    This stabilizes the tar-codec preview feature.

  • Reject uv build --clear output directories that contain a build source
    (#​22276)

    Previously, uv build --clear could delete a project or input source distribution when the
    output directory contained the source. Now, uv rejects these output directories, including
    equivalent paths reached through symlinks, before clearing any build output.

    Select an output directory that does not contain any build sources, or omit --clear.

Python
Preview features
  • Require hashes for build dependencies, including transitive dependencies, with --require-build-hashes (#​21411)
Performance
  • Speed up revalidation of cached HTTP responses by avoiding rewrites of unchanged payloads (#​22130)
  • Reduce allocations when reading cached HTTP responses (#​22136)
  • Reduce cache storage for HTTP policies and package records (#​22135, #​22133)
  • Reduce allocations for cached source distribution revisions (#​22131)
Bug fixes
  • Fix incorrect dependency resolution when reusing source metadata with different build settings (#​22404)
  • Avoid overlong wheel cache lock filenames on Windows (#​22134)

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot enabled auto-merge (squash) October 10, 2026 01:25
@coderabbitai

coderabbitai Bot commented Oct 10, 2026

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: e89bf57c-25a7-41fd-a2a4-7f600d8a81ea

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autofix · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@renovate
renovate Bot merged commit 04481f9 into main Oct 10, 2026
27 checks passed
@renovate
renovate Bot deleted the renovate/dev-dependencies branch October 10, 2026 01:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants