Skip to content

chore(deps): bump the package-updates group with 8 updates - #3841

Merged
derkweijers merged 2 commits into
mainfrom
dependabot/uv/package-updates-5ef0c3d8cc
Oct 6, 2026
Merged

derkweijers merged 2 commits into
mainfrom
dependabot/uv/package-updates-5ef0c3d8cc

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 6, 2026

Copy link
Copy Markdown
Contributor

Bumps the package-updates group with 8 updates:

Package From To
markdown 3.10.3 3.11
sentry-sdk 2.69.2 2.71.0
hiredis 3.4.1 3.4.2
commitizen 4.18.1 4.19.0
coverage 7.16.1 7.16.2
pyrefly 1.3.1 1.3.2
python-semantic-release 10.6.2 10.7.0
ruff 0.16.8 0.16.9

Updates markdown from 3.10.3 to 3.11

Release notes

Sourced from markdown's releases.

Release 3.11.0

Changed

  • Inline processors now resume searching after the previous match, improving performance for repeated inline patterns (#1619).
  • Officially support Python 3.15 and drop support for Python 3.10
  • Walk backtick runs in BacktickInlineProcessor without a regex (#1620).
  • Switch static site generator for documentation from MkDocs to Zensical (#1627, #1635, #1637, and #1638).

Fixed

  • Ensure removing Abbreviations does not raise an error (#1634).
  • Fix an issue with excessive backtracking when matching inline code blocks (#1617).
  • md_in_html now honors tags added to Markdown.block_level_elements after the extension is loaded (#1246).
  • Fix quadratic-time regex backtracking in ReferenceProcessor when a link reference definition has no URL, e.g. a line consisting only of [id]: followed by many trailing spaces (#798).
  • Document attr_list usage for def_list (#1123).
Changelog

Sourced from markdown's changelog.


title: Changelog toc_depth: 2

Python-Markdown Changelog

All notable changes to this project will be documented in this file.

The format is based on Keep a Changelog, and this project adheres to the Python Version Specification. See the Contributing Guide for details.

[Unreleased]

  • Update serializer to be non-recursive (#1644).
  • Improve ancestor handling in the inline Treeprocessor (#1646).
  • Fix issue where inline HTML attributes were rejected if they had < or > in the attribute (#1647).
  • Fix issue where an unterminated end tag (</foo) could cause all remaining content to be dropped (#1651).

[3.11.0] - 2026-09-25

Changed

  • Inline processors now resume searching after the previous match, improving performance for repeated inline patterns (#1619).
  • Officially support Python 3.15 and drop support for Python 3.10
  • Walk backtick runs in BacktickInlineProcessor without a regex (#1620).
  • Switch static site generator for documentation from MkDocs to Zensical (#1627, #1635, #1637, and #1638).

Fixed

  • Ensure removing Abbreviations does not raise an error (#1634).
  • Fix an issue with excessive backtracking when matching inline code blocks (#1617).
  • md_in_html now honors tags added to Markdown.block_level_elements after the extension is loaded (#1246).
  • Fix quadratic-time regex backtracking in ReferenceProcessor when a link reference definition has no URL, e.g. a line consisting only of [id]: followed by many trailing spaces (#798).
  • Document attr_list usage for def_list (#1123).
Commits
  • 0ffbf00 Bump version to 3.11.0
  • 547a934 Show adminitions as rendered examples in contrbuting guide
  • 571f050 Cleanup archived changelog
  • a5176b0 Ensure py-render codeblock title in properly escaped.
  • 819fff9 Document the use of attr_list with def_list.
  • 36cdbd3 Final cleanup for Zensical transition
  • 8a96db5 Add py-render custom code block formater
  • 5d1363c Fix quadratic-time backtracking when a reference link has no URL
  • 0d6afd1 Add Markdown renderer as superfences formatter
  • 175fb5a Ensure removing Abbreviations does not raise an error.
  • Additional commits viewable in compare view

Updates sentry-sdk from 2.69.2 to 2.71.0

Release notes

Sourced from sentry-sdk's releases.

2.71.0

New Features ✨

import sentry_sdk
from sentry_sdk.integrations.typesafe import TypeSafeIntegration
sentry_sdk.init(
dsn="...",
traces_sample_rate=1.0,
integrations=[
TypeSafeIntegration(),
]
)

Typesafe

Bug Fixes 🐛

Documentation 📚

Internal Changes 🔧

2.70.0

New Features ✨

... (truncated)

Changelog

Sourced from sentry-sdk's changelog.

2.71.0

New Features ✨

import sentry_sdk
from sentry_sdk.integrations.typesafe import TypeSafeIntegration
sentry_sdk.init(
dsn="...",
traces_sample_rate=1.0,
integrations=[
TypeSafeIntegration(),
]
)

Typesafe

Bug Fixes 🐛

Documentation 📚

Internal Changes 🔧

2.70.0

New Features ✨

... (truncated)

Commits

Updates hiredis from 3.4.1 to 3.4.2

Release notes

Sourced from hiredis's releases.

3.4.2

This is a bugfix release. Users of hiredis-py 3.4.x that receive RESP3 push notifications — pub/sub deliveries or client-side cache invalidations — are encouraged to upgrade.

🐛 Bug Fixes

  • Release the list each push notification is sized from (#239)

PushNotificationType_New pre-sized every PushNotification with a list that PyList_SetSlice only borrows, and the reference was never dropped. Each RESP3 push notification therefore stranded one list object for the lifetime of the process. Because push notifications carry pub/sub deliveries and client-side caching invalidations, the leak grew with message volume rather than with the number of connections, making it unbounded for a long-lived subscriber — roughly 20 MB per 200,000 four-element notifications, and more for larger ones. Dropping the reference also removes an allocation from the parse path, which makes parsing a small notification about 10% faster.

The same change checks PyList_New for failure and guards tryParentize against a NULL reply, so an allocation failure is now reported as an error instead of writing elements past the end of a zero-length notification.

RESP2 array replies were never affected.

Contributors

Thanks to @​mmick78 for finding and fixing this.

Commits
  • b1b2951 [3.4] Release the list each push notification is sized from, release 3.4.2 (#...
  • See full diff in compare view

Updates commitizen from 4.18.1 to 4.19.0

Release notes

Sourced from commitizen's releases.

v4.19.0 (2026-09-22)

Feat

  • add extensible commit filters
Changelog

Sourced from commitizen's changelog.

v4.19.0 (2026-09-22)

Feat

  • add extensible commit filters
Commits
  • 3f5ccc8 bump: version 4.18.1 → 4.19.0
  • 07c9745 feat: add extensible commit filters
  • f0c7c6b ci(deps): bump soupsieve from 2.8.4 to 2.9 (#2091)
  • 100bfe3 ci: remove redundant incremental changelog setting
  • 4967717 ci(deps): bump dawidd6/action-homebrew-bump-formula from 8 to 10 (#2087)
  • 543250f docs(cli/screenshots): update CLI screenshots
  • See full diff in compare view

Updates coverage from 7.16.1 to 7.16.2

Release notes

Sourced from coverage's releases.

7.16.2

Version 7.16.2 — 2026-09-27

  • Fix: on Python 3.14 and later, a for loop completing immediately before a function return could mistakenly report an uncovered branch. This is now fixed, closing issue 2168.
  • Fix: on Python 3.14 and later, the else clause of a try whose body is a with statement could incorrectly be reported as covered when the with raised. This is now fixed, closing issue 2289.
  • Fix: with dynamic_context = test_function, test methods written as @staticmethod or @classmethod were not given a context of their own. Now they are, on Python 3.11 and later. Closes issue 1923.

➡️  PyPI page: coverage 7.16.2. :arrow_right:  To install: python3 -m pip install coverage==7.16.2

Changelog

Sourced from coverage's changelog.

Version 7.16.2 — 2026-09-27

  • Fix: on Python 3.14 and later, a for loop completing immediately before a function return could mistakenly report an uncovered branch. This is now fixed, closing issue 2168_.

  • Fix: on Python 3.14 and later, the else clause of a try whose body is a with statement could incorrectly be reported as covered when the with raised. This is now fixed, closing issue 2289_.

  • Fix: with dynamic_context = test_function, test methods written as @staticmethod or @classmethod were not given a context of their own. Now they are, on Python 3.11 and later. Closes issue 1923_.

.. _issue 1923: coveragepy/coveragepy#1923 .. _issue 2168: coveragepy/coveragepy#2168 .. _issue 2289: coveragepy/coveragepy#2289

.. _changes_7-16-1:

Commits

Updates pyrefly from 1.3.1 to 1.3.2

Release notes

Sourced from pyrefly's releases.

Pyrefly v1.3.2

Release date: September 28, 2026

Pyrefly v1.3.2 is a patch release that fixes regressions in how Pyrefly infers the type of a variable after it is assigned a value of type Any.


🐛 Bug fixes

  • #4846: Fixed several regressions from v1.3.0 in type inference after a variable is reassigned to Any:
    • Assigning an implicit Any (a value with no known type, such as the result of an unannotated function or an unresolved import) to an annotated variable once again produces Unknown. It no longer turns into an explicit Any.
    • When a variable annotated as Optional[T] or T | None is narrowed to None and then reassigned inside that branch, Pyrefly no longer adds the annotation's None back after the branch. For example, x: Any | None followed by if x is None: x = get_any() now gives Any instead of Any | None.
    • When a variable's annotation is a union that contains Any, assigning Any to it now narrows the variable to Any. For example, x: Any | None followed by x = x or get_any() now gives Any instead of Any | None, so later attribute access no longer reports a false missing-attribute error on None.

Thank-you to all our contributors who found these bugs and reported them! Did you know this is one of the most helpful contributions you can make to an open-source project? If you find any bugs in Pyrefly we want to know about them! Please open a bug report issue here.


📦 Upgrade

pip install --upgrade pyrefly==1.3.2

How to safely upgrade your codebase

Upgrading the version of Pyrefly you're using or a third-party library you depend on can reveal new type errors in your code. Fixing them all at once is often unrealistic. We've written scripts to help you temporarily silence them. After upgrading, follow these steps:

  1. pyrefly check --suppress-errors
  2. Run your code formatter of choice
  3. pyrefly check --remove-unused-ignores
  4. Repeat until you achieve a clean formatting run and a clean type check.

This will add # pyrefly: ignore comments to your code, enabling you to silence errors and return to fix them later. This can make the process of upgrading a large codebase much more manageable.

Read more about error suppressions in the Pyrefly documentation.

Commits
  • e46f4f2 cut 1.3.2
  • a1020bf release notes for v1.3.2
  • b4d1cd4 Allow assignment to Any when a name is annotated as Any | ...
  • 03eff73 Merge AnnotationStyle::ForwardedInitial and Forwarded
  • 1a0ac5f Keep a name's annotated type only when it is still active
  • fc131f8 Allow an expression to overwrite a name's AnyStyle
  • 4b261cd Move tests for assignment to Any to their own file
  • See full diff in compare view

Updates python-semantic-release from 10.6.2 to 10.7.0

Release notes

Sourced from python-semantic-release's releases.

v10.7.0 (2026-09-22)

This release is published under the MIT License.

✨ Features

  • cmd-stamp: Expand version stamp mechanism to support typed python variables (PR#1485, 947c57b)

  • cmd-version: Add optional git --signoff to version commits (PR#1492, 3cecbeb)

📖 Documentation

  • configuration: Added signoff_commit setting definition (PR#1492, 3cecbeb)

  • configuration: Document Python type annotation support for version_variables (PR#1485, 947c57b)

⚙️ Build System

  • deps: Correct click range specification for python3.10+ (PR#1486, e4b3bad)

  • deps: Expand click dependency range to include v8.5.* (PR#1489, fa87c95)

💡 Additional Release Information

  • cmd-version: With this release, we added a boolean flag, semantic_release.signoff_commit, as an available configuration option to toggle the addition of the Signed-off-by git trailer/footer message to release commits made by Python Semantic Release. Default is currently set to False but if you want to try this option, set this configuration setting to True. In a future major release, this setting will be set to True by default.

✅ Resolved Issues

  • #1441: feat: add option to signoff commits made by python-semantic-release

  • #1443: feat: extend version_variables to replace vars with python type annotations


Detailed Changes: v10.6.2...v10.7.0


Installable artifacts are available from:

Changelog

Sourced from python-semantic-release's changelog.

v10.7.0 (2026-09-22)

✨ Features

  • cmd-stamp: Expand version stamp mechanism to support typed python variables, closes [#1443](https://github.com/python-semantic-release/python-semantic-release/issues/1443)_ (PR#1485, 947c57b)

  • cmd-version: Add optional git --signoff to version commits, closes [#1441](https://github.com/python-semantic-release/python-semantic-release/issues/1441)_ (PR#1492, 3cecbeb)

📖 Documentation

  • configuration: Added signoff_commit setting definition (PR#1492, 3cecbeb)

  • configuration: Document Python type annotation support for version_variables (PR#1485, 947c57b)

⚙️ Build System

  • deps: Correct click range specification for python3.10+ (PR#1486, e4b3bad)

  • deps: Expand click dependency range to include v8.5.* (PR#1489, fa87c95)

💡 Additional Release Information

  • cmd-version: With this release, we added a boolean flag, semantic_release.signoff_commit, as an available configuration option to toggle the addition of the Signed-off-by git trailer/footer message to release commits made by Python Semantic Release. Default is currently set to False but if you want to try this option, set this configuration setting to True. In a future major release, this setting will be set to True by default.

.. _#1441: python-semantic-release/python-semantic-release#1441 .. _#1443: python-semantic-release/python-semantic-release#1443 .. _3cecbeb: python-semantic-release/python-semantic-release@3cecbeb .. _947c57b: python-semantic-release/python-semantic-release@947c57b .. _e4b3bad: python-semantic-release/python-semantic-release@e4b3bad .. _fa87c95: python-semantic-release/python-semantic-release@fa87c95 .. _PR#1485: python-semantic-release/python-semantic-release#1485 .. _PR#1486: python-semantic-release/python-semantic-release#1486 .. _PR#1489: python-semantic-release/python-semantic-release#1489 .. _PR#1492: python-semantic-release/python-semantic-release#1492

.. _changelog-v10.6.2:

Commits
  • b700dbe chore: release v10.7.0
  • 3cecbeb feat(cmd-version): add optional git --signoff to version commits (#1492)
  • 0f4d414 build(deps-dev): expand filelock compatibility range to include v4.0+ (#1...
  • 35f7674 ci(deps): bump docker/build-push-action@v7.3.0 to v7.4.0 (#1495)
  • fa87c95 build(deps): expand click dependency range to include v8.5.* (#1489)
  • 4e78311 test(fixtures): adjust git monorepo creation fixtures to prevent race conditi...
  • 1d56d3a test(cmd-version): refactor imports to new flatdict variant
  • 1c48576 build(deps-test): swap broken flatdict with cj365-flatdict variant
  • f77ed51 ci(deps): bump mikepenz/action-junit-report@v6.4.2 to v6.5.0 (#1484)
  • 086cf14 test(fixtures): adjust git repo creation fixtures to prevent race conditions ...
  • Additional commits viewable in compare view

Updates ruff from 0.16.8 to 0.16.9

Release notes

Sourced from ruff's releases.

0.16.9

Release Notes

Released on 2026-09-24.

Preview features

  • [ruff] Avoid false positives for overloaded division (RUF069) (#28309)

Bug fixes

  • [flake8-bugbear] Avoid false positives for calls with keyword arguments (B009, B010, B043) (#28776)
  • [flake8-tidy-imports] Allow lazy imports to be used in deferred annotations (TID255) (#28767)

Rule changes

  • Update LibCST-based fixes for Python 3.15 (#28616)
  • [flake8-pyi] Mention stubs in the diagnostic message (PYI002) (#28542)

Documentation

  • Fix horizontal overflow on the rules documentation page (#28699)
  • Update rules table with category information (#28651)
  • [flake8-annotations] Clarify that ANN401 checks return types in addition to arguments (#28334)
  • [flake8-bugbear] Document type-checker interaction (B010) (#28509)
  • [flake8-comprehensions] Document map/generator exception behavior (C417) (#27794)
  • [ruff] Mention related isort settings (RUF022) (#28719)

Contributors

Install ruff 0.16.9

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/ruff/releases/download/0.16.9/ruff-installer.sh | sh

... (truncated)

Changelog

Sourced from ruff's changelog.

0.16.9

Released on 2026-09-24.

Preview features

  • [ruff] Avoid false positives for overloaded division (RUF069) (#28309)

Bug fixes

  • [flake8-bugbear] Avoid false positives for calls with keyword arguments (B009, B010, B043) (#28776)
  • [flake8-tidy-imports] Allow lazy imports to be used in deferred annotations (TID255) (#28767)

Rule changes

  • Update LibCST-based fixes for Python 3.15 (#28616)
  • [flake8-pyi] Mention stubs in the diagnostic message (PYI002) (#28542)

Documentation

  • Fix horizontal overflow on the rules documentation page (#28699)
  • Update rules table with category information (#28651)
  • [flake8-annotations] Clarify that ANN401 checks return types in addition to arguments (#28334)
  • [flake8-bugbear] Document type-checker interaction (B010) (#28509)
  • [flake8-comprehensions] Document map/generator exception behavior (C417) (#27794)
  • [ruff] Mention related isort settings (RUF022) (#28719)

Contributors

Commits
  • 0be08a2 Bump version to 0.16.9 (#28882)
  • b4920b7 Rename ruff_cli to ruff_command_line (#28881)
  • 47c751b Update dependency astral-sh/uv to v0.12.18 (#28880)
  • 8c244e5 [flake8-comprehensions] Document map/generator exception behavior (C417...
  • 5edf5a1 Use target form in rooster.version_files (#28876)
  • 915bb2b [ty] Prefer existing @ paths over response files in Ruff and ty (#28877)
  • 4710e1a ci(github): update version number in placeholder of issue template (#28871)
  • eedfc62 [ty] Propagate outer type context through cast calls (#28855)
  • ceaa6a0 [ty] Contain rendered code within Markdown fences (#28869)
  • dba0f30 authorize ruff-pre-commit dispatch via OIDC (#28867)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the package-updates group with 8 updates:

| Package | From | To |
| --- | --- | --- |
| [markdown](https://github.com/Python-Markdown/markdown) | `3.10.3` | `3.11` |
| [sentry-sdk](https://github.com/getsentry/sentry-python) | `2.69.2` | `2.71.0` |
| [hiredis](https://github.com/redis/hiredis-py) | `3.4.1` | `3.4.2` |
| [commitizen](https://github.com/commitizen-tools/commitizen) | `4.18.1` | `4.19.0` |
| [coverage](https://github.com/coveragepy/coveragepy) | `7.16.1` | `7.16.2` |
| [pyrefly](https://github.com/facebook/pyrefly) | `1.3.1` | `1.3.2` |
| [python-semantic-release](https://github.com/python-semantic-release/python-semantic-release) | `10.6.2` | `10.7.0` |
| [ruff](https://github.com/astral-sh/ruff) | `0.16.8` | `0.16.9` |


Updates `markdown` from 3.10.3 to 3.11
- [Release notes](https://github.com/Python-Markdown/markdown/releases)
- [Changelog](https://github.com/Python-Markdown/markdown/blob/master/docs/changelog.md)
- [Commits](Python-Markdown/markdown@3.10.3...3.11.0)

Updates `sentry-sdk` from 2.69.2 to 2.71.0
- [Release notes](https://github.com/getsentry/sentry-python/releases)
- [Changelog](https://github.com/getsentry/sentry-python/blob/master/CHANGELOG.md)
- [Commits](getsentry/sentry-python@2.69.2...2.71.0)

Updates `hiredis` from 3.4.1 to 3.4.2
- [Release notes](https://github.com/redis/hiredis-py/releases)
- [Changelog](https://github.com/redis/hiredis-py/blob/master/CHANGELOG.md)
- [Commits](redis/hiredis-py@v3.4.1...v3.4.2)

Updates `commitizen` from 4.18.1 to 4.19.0
- [Release notes](https://github.com/commitizen-tools/commitizen/releases)
- [Changelog](https://github.com/commitizen-tools/commitizen/blob/master/CHANGELOG.md)
- [Commits](commitizen-tools/commitizen@v4.18.1...v4.19.0)

Updates `coverage` from 7.16.1 to 7.16.2
- [Release notes](https://github.com/coveragepy/coveragepy/releases)
- [Changelog](https://github.com/coveragepy/coveragepy/blob/main/CHANGES.rst)
- [Commits](coveragepy/coveragepy@7.16.1...7.16.2)

Updates `pyrefly` from 1.3.1 to 1.3.2
- [Release notes](https://github.com/facebook/pyrefly/releases)
- [Commits](facebook/pyrefly@1.3.1...1.3.2)

Updates `python-semantic-release` from 10.6.2 to 10.7.0
- [Release notes](https://github.com/python-semantic-release/python-semantic-release/releases)
- [Changelog](https://github.com/python-semantic-release/python-semantic-release/blob/master/CHANGELOG.rst)
- [Commits](python-semantic-release/python-semantic-release@v10.6.2...v10.7)

Updates `ruff` from 0.16.8 to 0.16.9
- [Release notes](https://github.com/astral-sh/ruff/releases)
- [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md)
- [Commits](astral-sh/ruff@0.16.8...0.16.9)

---
updated-dependencies:
- dependency-name: markdown
  dependency-version: '3.11'
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: package-updates
- dependency-name: sentry-sdk
  dependency-version: 2.71.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: package-updates
- dependency-name: hiredis
  dependency-version: 3.4.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: package-updates
- dependency-name: commitizen
  dependency-version: 4.19.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: package-updates
- dependency-name: coverage
  dependency-version: 7.16.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: package-updates
- dependency-name: pyrefly
  dependency-version: 1.3.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: package-updates
- dependency-name: python-semantic-release
  dependency-version: 10.7.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: package-updates
- dependency-name: ruff
  dependency-version: 0.16.9
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: package-updates
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python:uv Pull requests that update Python:uv code labels Oct 6, 2026
@derkweijers
derkweijers merged commit 8b4466e into main Oct 6, 2026
4 checks passed
@derkweijers
derkweijers deleted the dependabot/uv/package-updates-5ef0c3d8cc branch October 6, 2026 06:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python:uv Pull requests that update Python:uv code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant