Skip to content

deps(deps): update tox requirement from <5.0.0,>=4.61.2 to >=4.64.3,<5.0.0 - #306

Merged
docdyhr merged 1 commit into
mainfrom
dependabot/pip/tox-gte-4.64.3-and-lt-5.0.0
Sep 30, 2026
Merged

docdyhr merged 1 commit into
mainfrom
dependabot/pip/tox-gte-4.64.3-and-lt-5.0.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 29, 2026

Copy link
Copy Markdown
Contributor

Updates the requirements on tox to permit the latest version.

Release notes

Sourced from tox's releases.

v4.64.3

What's Changed

New Contributors

Full Changelog: tox-dev/tox@4.64.2...4.64.3

Changelog

Sourced from tox's changelog.

Bug fixes - 4.64.3

  • A set_env written as a list of tables in TOML now keeps every file entry and honors the order of the entries, so merging one environment's set_env into another no longer drops the environment file it referenced (:issue:4093) - by :user:Rodrigo-Palma.

    • Each { file = "..." } entry is read; previously only the last one survived, because the entries were merged into a single table first and a table cannot hold the key twice.
    • A variable set after a file entry wins over the value the file provides, matching the file| form in INI; previously a repeated variable was pulled back to its first position, letting the file override it.
    • A later entry that sets a variable without a marker clears the marker an earlier entry gave it, again matching the INI form. (:issue:4093)
  • Create the package build environment change_dir directory before running the build commands, as the documentation already promises. (:issue:4095)


v4.64.2 (2026-09-24)


Bug fixes - 4.64.2

  • A tox environment with env_dir = "{tox_root}/.venv" no longer crashes with FileExistsError after another environment ran (:issue:4090) - by :user:gaborbernat.

    • With :ref:venv_redirect unset, the new default, tox writes the redirect file unless a tox environment lives at .venv; with true, tox fails the run with an error naming that environment.
    • tox deletes a redirect file it wrote where an environment should live, and fails the environment with an error naming any other file there. (:issue:4091)
  • The :PEP:832 .venv redirect file now names a deliberate development environment - by :user:gaborbernat.

    • tox picks :ref:venv_redirect_env, else an environment named dev, else the first that installs the project in development mode, and writes nothing without one, so a project that uses tox for tests alone gets no file.
    • tox devenv points the redirect at the environment it creates, and later runs leave it in place.
    • tox tells virtualenv to write no redirect file of its own beside the environments it builds. (:issue:4092)

v4.64.1 (2026-09-24)


Bug fixes - 4.64.1

  • Apply -x/--override and TOX_OVERRIDE values that target a section the configuration file does not define, such as tox.skip_missing_interpreters on a tox.ini without a [tox] section, instead of dropping them - by :user:gaborbernat. (:issue:4089)

... (truncated)

Commits
  • f46060e release 4.64.3
  • ca35bdb Keep every file entry of a set_env list of tables (#4094)
  • 31ed8d9 Create change_dir before running the external package build command (#4095)
  • 9cd0f4e release 4.64.2
  • c2b87d2 🐛 fix(run): point .venv at a deliberate dev env (#4092)
  • a8fa8cc 🐛 fix(run): keep .venv redirect off for a .venv env (#4091)
  • e40e8e6 release 4.64.1
  • eacd4e9 🐛 fix(config): apply overrides to sections the file lacks (#4089)
  • fff62f6 release 4.64.0
  • 5c56ce0 ✨ feat(config): write a PEP 832 .venv redirect file (#4013)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Updates the requirements on [tox](https://github.com/tox-dev/tox) to permit the latest version.
- [Release notes](https://github.com/tox-dev/tox/releases)
- [Changelog](https://github.com/tox-dev/tox/blob/main/docs/changelog.rst)
- [Commits](tox-dev/tox@4.61.2...4.64.3)

---
updated-dependencies:
- dependency-name: tox
  dependency-version: 4.64.3
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot requested a review from docdyhr as a code owner September 29, 2026 09:05
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Sep 29, 2026
@strix-security

Copy link
Copy Markdown

Strix is installed on this repository, but we couldn't run this PR security review because this workspace's trial has ended. Add a card to resume code reviews here.

So far, Strix has reviewed 30 pull requests across this workspace.

@codecov

codecov Bot commented Sep 29, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@docdyhr
docdyhr merged commit 8a59a51 into main Sep 30, 2026
25 checks passed
@docdyhr
docdyhr deleted the dependabot/pip/tox-gte-4.64.3-and-lt-5.0.0 branch September 30, 2026 12:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant