Skip to content

chore(deps): bump the python-minor-patch group across 1 directory with 6 updates - #390

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/python-minor-patch-50bad41824
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/python-minor-patch-50bad41824

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the python-minor-patch group with 6 updates in the / directory:

Package From To
gitpython 3.1.62 3.2.0
python-dotenv 1.2.3 1.2.4
markdown 3.10.3 3.11
pytest-mock 3.15.1 3.16.0
ruff 0.16.9 0.16.10
uv 0.12.18 0.12.22

Updates gitpython from 3.1.62 to 3.2.0

Release notes

Sourced from gitpython's releases.

3.2.0 - Security

What's Changed

New Contributors

Full Changelog: gitpython-developers/GitPython@3.1.62...3.2.0

Commits
  • 6a7180a prepare for next release, v3.2
  • 25a1a69 Merge pull request #2259 from radhika1314/config-option-line-bound
  • a3e1ea4 Merge pull request #2258 from gitpython-developers/sec-audit
  • 1a2117c fix(remote): validate protocols in rendered transport arguments
  • 2235723 fix(config): bound option-line parsing
  • cc02e45 ci: remove codespell checks and configuration
  • f2dfa9f fix(index): confine staging reads to worktree files
  • d1576c4 fix(tree): validate entry names and record boundaries
  • a75aedf fix(index): validate paths at native index boundaries
  • 428d205 fix(repo): validate rendered archive remote options
  • Additional commits viewable in compare view

Updates python-dotenv from 1.2.3 to 1.2.4

Release notes

Sourced from python-dotenv's releases.

v1.2.4

Fixed

  • dotenv get no longer exits with code 1 for empty string values (KEY=) by [@​ShamikOfficial] in #700
  • An unquoted empty value followed by an inline comment (e.g. KEY= # comment) is now parsed as an empty string instead of the comment text by [@​Noethix55555] in #663
  • dotenv run --no-override now expands variable references with the same precedence as load_dotenv(override=False), so a value like ${BASE}/suffix uses the existing BASE from the environment instead of the one from the .env file by [@​ROTl24] in #698
Changelog

Sourced from python-dotenv's changelog.

[1.2.4] - 2026-10-01

Fixed

  • dotenv get no longer exits with code 1 for empty string values (KEY=) by [@​ShamikOfficial] in #700
  • An unquoted empty value followed by an inline comment (e.g. KEY= # comment) is now parsed as an empty string instead of the comment text by [@​Noethix55555] in #663
  • dotenv run --no-override now expands variable references with the same precedence as load_dotenv(override=False), so a value like ${BASE}/suffix uses the existing BASE from the environment instead of the one from the .env file by [@​ROTl24] in #698
Commits
  • a565c2c Bump version: 1.2.3 → 1.2.4
  • 4a7abd0 docs: add 1.2.4 release notes (#663, #698, #700)
  • f215c02 fix: dotenv get exits 0 for empty string values (#700)
  • 58f2d7c test: make test_run_with_command_flags portable and meaningful (#709)
  • e0310e5 fix: honor --no-override when expanding variables in dotenv run (#698)
  • a00cb2e docs: add CHANGELOG entry for #663 (fix #600)
  • f5485a6 fix: parse empty unquoted value with inline comment as empty string
  • See full diff in compare view

Updates markdown from 3.10.3 to 3.11

Release notes

Sourced from markdown's releases.

Release 3.11.0

Changed

  • Inline processors now resume searching after the previous match, improving performance for repeated inline patterns (#1619).
  • Officially support Python 3.15 and drop support for Python 3.10
  • Walk backtick runs in BacktickInlineProcessor without a regex (#1620).
  • Switch static site generator for documentation from MkDocs to Zensical (#1627, #1635, #1637, and #1638).

Fixed

  • Ensure removing Abbreviations does not raise an error (#1634).
  • Fix an issue with excessive backtracking when matching inline code blocks (#1617).
  • md_in_html now honors tags added to Markdown.block_level_elements after the extension is loaded (#1246).
  • Fix quadratic-time regex backtracking in ReferenceProcessor when a link reference definition has no URL, e.g. a line consisting only of [id]: followed by many trailing spaces (#798).
  • Document attr_list usage for def_list (#1123).
Changelog

Sourced from markdown's changelog.


title: Changelog toc_depth: 2

Python-Markdown Changelog

All notable changes to this project will be documented in this file.

The format is based on Keep a Changelog, and this project adheres to the Python Version Specification. See the Contributing Guide for details.

[Unreleased]

  • Update serializer to be non-recursive (#1644).
  • Improve ancestor handling in the inline Treeprocessor (#1646).
  • Keep a raw HTML comment inside an inline HTML element that closes in the same paragraph, instead of splitting the paragraph around it (#1643).
  • Fix issue where inline HTML attributes were rejected if they had < or > in the attribute (#1647).
  • Fix issue where an unterminated end tag (</foo) could cause all remaining content to be dropped (#1651).

[3.11.0] - 2026-09-25

Changed

  • Inline processors now resume searching after the previous match, improving performance for repeated inline patterns (#1619).
  • Officially support Python 3.15 and drop support for Python 3.10
  • Walk backtick runs in BacktickInlineProcessor without a regex (#1620).
  • Switch static site generator for documentation from MkDocs to Zensical (#1627, #1635, #1637, and #1638).

Fixed

  • Ensure removing Abbreviations does not raise an error (#1634).
  • Fix an issue with excessive backtracking when matching inline code blocks (#1617).
  • md_in_html now honors tags added to Markdown.block_level_elements after the extension is loaded (#1246).
  • Fix quadratic-time regex backtracking in ReferenceProcessor when a link reference definition has no URL, e.g. a line consisting only of [id]: followed by many trailing spaces (#798).
  • Document attr_list usage for def_list (#1123).
Commits
  • 0ffbf00 Bump version to 3.11.0
  • 547a934 Show adminitions as rendered examples in contrbuting guide
  • 571f050 Cleanup archived changelog
  • a5176b0 Ensure py-render codeblock title in properly escaped.
  • 819fff9 Document the use of attr_list with def_list.
  • 36cdbd3 Final cleanup for Zensical transition
  • 8a96db5 Add py-render custom code block formater
  • 5d1363c Fix quadratic-time backtracking when a reference link has no URL
  • 0d6afd1 Add Markdown renderer as superfences formatter
  • 175fb5a Ensure removing Abbreviations does not raise an error.
  • Additional commits viewable in compare view

Updates pytest-mock from 3.15.1 to 3.16.0

Release notes

Sourced from pytest-mock's releases.

v3.16.0

2026-09-27

  • #604: Fixed duplicate_iterators=True for async functions spied with mocker.spy.
  • #611: Fixed async mock assertion introspection to use awaited arguments instead of the latest call's arguments.
  • #606: mocker.resetall(return_value=True, side_effect=True) now also applies to non-callable mocks, such as those returned by mocker.create_autospec(SomeClass, instance=True). Previously both arguments were silently ignored for them.
  • #547: Added SpyType for annotating mocker.spy results.
  • Dropped support for EOL Python 3.9.
  • #147: Removed handling of RuntimeError: stop called on unstarted patcher, which can no longer occur in the supported Python versions.
  • Added support for Python 3.15.
Changelog

Sourced from pytest-mock's changelog.

3.16.0

2026-09-27

  • [#604](https://github.com/pytest-dev/pytest-mock/issues/604) <https://github.com/pytest-dev/pytest-mock/pull/604>_: Fixed duplicate_iterators=True for async functions spied with mocker.spy.
  • [#611](https://github.com/pytest-dev/pytest-mock/issues/611) <https://github.com/pytest-dev/pytest-mock/pull/611>_: Fixed async mock assertion introspection to use awaited arguments instead of the latest call's arguments.
  • [#606](https://github.com/pytest-dev/pytest-mock/issues/606) <https://github.com/pytest-dev/pytest-mock/pull/606>_: mocker.resetall(return_value=True, side_effect=True) now also applies to non-callable mocks, such as those returned by mocker.create_autospec(SomeClass, instance=True). Previously both arguments were silently ignored for them.
  • [#547](https://github.com/pytest-dev/pytest-mock/issues/547) <https://github.com/pytest-dev/pytest-mock/issues/547>_: Added SpyType for annotating mocker.spy results.
  • Dropped support for EOL Python 3.9.
  • [#147](https://github.com/pytest-dev/pytest-mock/issues/147) <https://github.com/pytest-dev/pytest-mock/issues/147>_: Removed handling of RuntimeError: stop called on unstarted patcher, which can no longer occur in the supported Python versions.
  • Added support for Python 3.15.
Commits

Updates ruff from 0.16.9 to 0.16.10

Release notes

Sourced from ruff's releases.

0.16.10

Release Notes

Released on 2026-10-01.

Preview features

  • Add a migration guide for categories (#28087)
  • [pyupgrade] Add rule for context manager iterator annotations (UP052) (#29000)

Performance

  • Reduce memory used by diagnostics (#28951)

Server

  • Avoid running uv format in untrusted workspaces (#28873)

Documentation

  • Fix links to moved changelog sections and renamed mdtests (#28941)
  • Add Python 3.15 as a supported version (#28907)
  • Add ty as a type checker example (#28906)

Other changes

  • Update Rust toolchain to 1.99 and MSRV to 1.97 (#29047)

Contributors

Install ruff 0.16.10

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/ruff/releases/download/0.16.10/ruff-installer.sh | sh

Install prebuilt binaries via powershell script

powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/ruff/releases/download/0.16.10/ruff-installer.ps1 | iex"

Download ruff 0.16.10

... (truncated)

Changelog

Sourced from ruff's changelog.

0.16.10

Released on 2026-10-01.

Preview features

  • Add a migration guide for categories (#28087)
  • [pyupgrade] Add rule for context manager iterator annotations (UP052) (#29000)

Performance

  • Reduce memory used by diagnostics (#28951)

Server

  • Avoid running uv format in untrusted workspaces (#28873)

Documentation

  • Fix links to moved changelog sections and renamed mdtests (#28941)
  • Add Python 3.15 as a supported version (#28907)
  • Add ty as a type checker example (#28906)

Other changes

  • Update Rust toolchain to 1.99 and MSRV to 1.97 (#29047)

Contributors

Commits
  • 3265ed1 Bump version to 0.16.10 (#29055)
  • e786964 Authorize shared PR security-review workflow to publish findings (#29052)
  • a81291e [ty] Defer uv workspace discovery until after project configuration (#28525)
  • b6a74d2 [ty] Refresh uv project metadata when uv files change (#28529)
  • 41d30df Update Rust toolchain to 1.99 and MSRV to 1.97 (#29047)
  • 317e0a3 [ty] Bound nested callable signature display (#29049)
  • 8546752 [ty] Fix member lookup on union-bounded type variables (#29018)
  • 56180bc [ty] Specialize instance members once (#29043)
  • aa9a1ff [ty] Avoid stale I/O diagnostics when closing deleted files (#28988)
  • 2d25346 [ty] Improve unresolved-import documentation (#29039)
  • Additional commits viewable in compare view

Updates uv from 0.12.18 to 0.12.22

Release notes

Sourced from uv's releases.

0.12.22

Release Notes

Released on 2026-10-01.

Python

  • Add CPython 3.10.22, 3.11.17, 3.12.15, 3.13.16, and 3.14.8 (#22147)

Enhancements

  • Accept uppercase release suffixes in wheel platform tags (#22113)
  • Record workspace-member default groups in lockfiles (#22010, #22103)
  • Record workspace-member dependency-group Python requirements in lockfiles (#22044, #22103)
  • Record default groups for non-project workspace roots in lockfiles (#22104)
  • Record dependency-group Python requirements for non-project workspace roots in lockfiles (#22104)
  • Format URLs and paths consistently in CLI messages (#21937)
  • Hide the unsupported --offline option from uv publish help (#22124)

Preview features

  • Honor --no-default-groups in uv audit (#22090)
  • Report a clear error when uv audit or uv tool audit runs offline and hide the unsupported option from help (#22114)

Configuration

  • Add UV_PYTHON_ARCH to select an interpreter architecture independently of its Python version (#22098)

Performance

  • Reduce uv's binary size by compressing embedded Python download metadata (#22126)

Bug fixes

  • Verify unchanged requirements against existing lockfile hashes when relocking (#22083)
  • Honor dependency-group Python requirements at non-project workspace roots (#22101)
  • Use each selected workspace member's recorded default groups during frozen sync (#22015)
  • Avoid false entry-point warnings for required workspace members (#22112)

Other changes

  • Raise the minimum supported Rust version for building uv to 1.97 and update the toolchain to Rust 1.99 (#22121)

Install uv 0.12.22

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.22/uv-installer.sh | sh

... (truncated)

Changelog

Sourced from uv's changelog.

0.12.22

Released on 2026-10-01.

Python

  • Add CPython 3.10.22, 3.11.17, 3.12.15, 3.13.16, and 3.14.8 (#22147)

Enhancements

  • Accept uppercase release suffixes in wheel platform tags (#22113)
  • Record workspace-member default groups in lockfiles (#22010, #22103)
  • Record workspace-member dependency-group Python requirements in lockfiles (#22044, #22103)
  • Record default groups for non-project workspace roots in lockfiles (#22104)
  • Record dependency-group Python requirements for non-project workspace roots in lockfiles (#22104)
  • Format URLs and paths consistently in CLI messages (#21937)
  • Hide the unsupported --offline option from uv publish help (#22124)

Preview features

  • Honor --no-default-groups in uv audit (#22090)
  • Report a clear error when uv audit or uv tool audit runs offline and hide the unsupported option from help (#22114)

Configuration

  • Add UV_PYTHON_ARCH to select an interpreter architecture independently of its Python version (#22098)

Performance

  • Reduce uv's binary size by compressing embedded Python download metadata (#22126)

Bug fixes

  • Verify unchanged requirements against existing lockfile hashes when relocking (#22083)
  • Honor dependency-group Python requirements at non-project workspace roots (#22101)
  • Use each selected workspace member's recorded default groups during frozen sync (#22015)
  • Avoid false entry-point warnings for required workspace members (#22112)

Other changes

  • Raise the minimum supported Rust version for building uv to 1.97 and update the toolchain to Rust 1.99 (#22121)

0.12.21

Released on 2026-09-29.

Python

  • Update CPython to use OpenSSL 3.5.9 (#22076)

... (truncated)

Commits

@dependabot
dependabot Bot requested a review from a team as a code owner October 9, 2026 00:25
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels Oct 9, 2026
@socket-security

socket-security Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedpypi/​gitpython@​3.1.62 ⏵ 3.2.093 +1100100100100
Updatedpypi/​python-dotenv@​1.2.3 ⏵ 1.2.499 +1100100100100
Updatedpypi/​markdown@​3.10.3 ⏵ 3.11100 +1100100100100
Updatedpypi/​uv@​0.12.18 ⏵ 0.12.22100 +1100100100100
Updatedpypi/​ruff@​0.16.9 ⏵ 0.16.10100100100100100
Updatedpypi/​pytest-mock@​3.15.1 ⏵ 3.16.0100100100100100

View full report

…h 6 updates

Bumps the python-minor-patch group with 6 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [gitpython](https://github.com/gitpython-developers/GitPython) | `3.1.62` | `3.2.0` |
| [python-dotenv](https://github.com/theskumar/python-dotenv) | `1.2.3` | `1.2.4` |
| [markdown](https://github.com/Python-Markdown/markdown) | `3.10.3` | `3.11` |
| [pytest-mock](https://github.com/pytest-dev/pytest-mock) | `3.15.1` | `3.16.0` |
| [ruff](https://github.com/astral-sh/ruff) | `0.16.9` | `0.16.10` |
| [uv](https://github.com/astral-sh/uv) | `0.12.18` | `0.12.22` |



Updates `gitpython` from 3.1.62 to 3.2.0
- [Release notes](https://github.com/gitpython-developers/GitPython/releases)
- [Changelog](https://github.com/gitpython-developers/GitPython/blob/main/CHANGES)
- [Commits](gitpython-developers/GitPython@3.1.62...3.2.0)

Updates `python-dotenv` from 1.2.3 to 1.2.4
- [Release notes](https://github.com/theskumar/python-dotenv/releases)
- [Changelog](https://github.com/theskumar/python-dotenv/blob/main/CHANGELOG.md)
- [Commits](theskumar/python-dotenv@v1.2.3...v1.2.4)

Updates `markdown` from 3.10.3 to 3.11
- [Release notes](https://github.com/Python-Markdown/markdown/releases)
- [Changelog](https://github.com/Python-Markdown/markdown/blob/master/docs/changelog.md)
- [Commits](Python-Markdown/markdown@3.10.3...3.11.0)

Updates `pytest-mock` from 3.15.1 to 3.16.0
- [Release notes](https://github.com/pytest-dev/pytest-mock/releases)
- [Changelog](https://github.com/pytest-dev/pytest-mock/blob/main/CHANGELOG.rst)
- [Commits](pytest-dev/pytest-mock@v3.15.1...v3.16.0)

Updates `ruff` from 0.16.9 to 0.16.10
- [Release notes](https://github.com/astral-sh/ruff/releases)
- [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md)
- [Commits](astral-sh/ruff@0.16.9...0.16.10)

Updates `uv` from 0.12.18 to 0.12.22
- [Release notes](https://github.com/astral-sh/uv/releases)
- [Changelog](https://github.com/astral-sh/uv/blob/main/CHANGELOG.md)
- [Commits](astral-sh/uv@0.12.18...0.12.22)

---
updated-dependencies:
- dependency-name: gitpython
  dependency-version: 3.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-minor-patch
- dependency-name: markdown
  dependency-version: '3.11'
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-minor-patch
- dependency-name: pytest-mock
  dependency-version: 3.16.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-minor-patch
- dependency-name: python-dotenv
  dependency-version: 1.2.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python-minor-patch
- dependency-name: ruff
  dependency-version: 0.16.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python-minor-patch
- dependency-name: uv
  dependency-version: 0.12.22
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python-minor-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title chore(deps): bump the python-minor-patch group with 6 updates chore(deps): bump the python-minor-patch group across 1 directory with 6 updates Oct 9, 2026
@dependabot
dependabot Bot force-pushed the dependabot/uv/python-minor-patch-50bad41824 branch from b5147bb to 05e5626 Compare October 9, 2026 12:19
@socket-security-staging

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedpypi/​gitpython@​3.1.62 ⏵ 3.2.093 +1100100100100
Updatedpypi/​python-dotenv@​1.2.3 ⏵ 1.2.499 +1100100100100
Updatedpypi/​markdown@​3.10.3 ⏵ 3.11100 +1100100100100
Updatedpypi/​uv@​0.12.18 ⏵ 0.12.22100 +1100100100100
Updatedpypi/​ruff@​0.16.9 ⏵ 0.16.10100 +1100100100100

View full report

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants