Skip to content

build(deps): bump the patch-updates group across 1 directory with 3 updates - #81

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/patch-updates-1e90534e30
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/patch-updates-1e90534e30

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 28, 2026

Copy link
Copy Markdown
Contributor

Bumps the patch-updates group with 3 updates in the / directory: ruff, build and agentseam.

Updates ruff from 0.16.6 to 0.16.8

Release notes

Sourced from ruff's releases.

0.16.8

Release Notes

Released on 2026-09-16.

Bug fixes

  • Visit functional TypedDict keyword arguments correctly (#28584)
  • [flake8-simplify] Detect nested async with under sync parent (SIM117) (#27821)
  • [flake8-simplify] Preserve operand order in SIM109 fix (#27824)
  • [pyupgrade] Preserve required parentheses in multiline UP040 fixes (#28164)
  • [pyupgrade] Skip TypeVarTuple and ParamSpec conversions with bounds or constraints (UP040, UP046, UP047) (#28505)

Rule changes

  • Add support for __lazy_modules__ (#28459)
  • Recognize PEP-728 TypedDict class keywords (#28533)
  • Recognize quoted types in typing.TypeForm (#28507)
  • Support conditional assignment to __lazy_modules__ (#28491)
  • [flake8-type-checking] Prefer lazy imports over TYPE_CHECKING on Python 3.15 and later (TC001, TC002, TC003) (#28541)
  • [pyupgrade] Make the fix for UP040 always unsafe (#28526)
  • [pyupgrade] Stop recommending deprecated ByteString aliases (UP035) (#28498)
  • [ruff, flake8-use-pathlib] Recognize the parent_mode argument (RUF064, PTH103) (#28528)
  • [ruff] Detect \Z in pytest.raises() match patterns (RUF043) (#28598)

CLI

  • Use rule name and code in formatter incompatibility warnings (#28571)

Configuration

  • [flake8-tidy-imports] Add extend-banned-api (#28644)

Contributors

Install ruff 0.16.8

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/ruff/releases/download/0.16.8/ruff-installer.sh | sh
</tr></table> 

... (truncated)

Changelog

Sourced from ruff's changelog.

0.16.8

Released on 2026-09-16.

Bug fixes

  • Visit functional TypedDict keyword arguments correctly (#28584)
  • [flake8-simplify] Detect nested async with under sync parent (SIM117) (#27821)
  • [flake8-simplify] Preserve operand order in SIM109 fix (#27824)
  • [pyupgrade] Preserve required parentheses in multiline UP040 fixes (#28164)
  • [pyupgrade] Skip TypeVarTuple and ParamSpec conversions with bounds or constraints (UP040, UP046, UP047) (#28505)

Rule changes

  • Add support for __lazy_modules__ (#28459)
  • Recognize PEP-728 TypedDict class keywords (#28533)
  • Recognize quoted types in typing.TypeForm (#28507)
  • Support conditional assignment to __lazy_modules__ (#28491)
  • [flake8-type-checking] Prefer lazy imports over TYPE_CHECKING on Python 3.15 and later (TC001, TC002, TC003) (#28541)
  • [pyupgrade] Make the fix for UP040 always unsafe (#28526)
  • [pyupgrade] Stop recommending deprecated ByteString aliases (UP035) (#28498)
  • [ruff, flake8-use-pathlib] Recognize the parent_mode argument (RUF064, PTH103) (#28528)
  • [ruff] Detect \Z in pytest.raises() match patterns (RUF043) (#28598)

CLI

  • Use rule name and code in formatter incompatibility warnings (#28571)

Configuration

  • [flake8-tidy-imports] Add extend-banned-api (#28644)

Contributors

0.16.7

Released on 2026-09-10.

Preview features

  • [ruff] Add rule for default values on method receivers (RUF077) (#26700)

... (truncated)

Commits
  • 62914c4 Bump version to 0.16.8 (#28648)
  • c47e0cd [ty] Bound aliased intersection expansion during inference (#28546)
  • ff4747b renovate: update uv hashes correctly with setup-uv (#28621)
  • 94efeaa [ty] Compact reachable binding and declaration histories (#28349)
  • 50020fb [ty] Avoid storing constraint nodes twice (#28375)
  • 446bb68 [ty] Compare bound-method receivers before signatures (#28384)
  • 304ab86 [flake8-type-checking] Prefer lazy imports over TYPE_CHECKING on 3.15+ (`...
  • d940b24 [ty] Watch script dependencies in CLI watch mode (#28125)
  • fe9f065 [flake8-tidy-imports] Add extend-banned-api (#28644)
  • 31131db [ty] Support type[A & B] (#27124)
  • Additional commits viewable in compare view

Updates build from 1.6.0 to 1.6.1

Release notes

Sourced from build's releases.

1.6.1

What's Changed

Full Changelog: pypa/build@1.6.0...1.6.1

Changelog

Sourced from build's changelog.

#################### 1.6.1 (2026-09-10) ####################


Bugfixes


  • Avoid trying to detect symlinks on Windows, regression in 1.6.0 - by :user:henryiii (:issue:1175) (:issue:1175)

Documentation


  • Fix doubled backslashes in the Windows pip config path (%APPDATA%\pip\pip.ini) in the docs - by :user:aroh3006 (:issue:1149)

Miscellaneous


  • :issue:1168, :issue:1170, :issue:1178

#################### 1.6.0 (2026-08-27) ####################


Features


  • Add --report=PATH to write a machine-readable JSON report of built artifacts; --metadata now also accepts .whl files - by :user:gaborbernat (:issue:198)
  • The srcdir argument now accepts .tar.gz source distributions, extracting and building from them - by :user:gaborbernat (:issue:311)
  • The "Unmet dependencies" error from --no-isolation builds now shows the wanted version, found version, and interpreter - by :user:gaborbernat (:issue:504)
  • Add --sdist-extract-dir to extract the intermediate sdist into a persistent directory, enabling compiler cache reuse across rebuilds - by :user:gaborbernat (:issue:614)
  • Add --env-dir to place the isolated build environment at a fixed path, enabling compiler cache reuse across builds
    • by :user:gaborbernat (:issue:655)
  • Print a summary of resolved dependency versions (name==version) after installing them in isolated builds - by :user:gaborbernat (:issue:959)
  • On build failure, print a tip pointing to --env-dir and --sdist-extract-dir for debugging and link to the "Debug a failed build" how-to - reported by :user:dimpase, implemented by :user:gaborbernat (:issue:966)

Bugfixes


... (truncated)

Commits
  • 89cccef chore: prepare for 1.6.1
  • a6f707a ci: support releases from v* branches (#1178)
  • 7785161 docs: fix doubled backslashes in Windows pip config path (#1149)
  • 244b250 fix: always use copies for the isolated venv on Windows (#1176)
  • c93ca6f build(deps): bump re-actors/alls-green from 1.2.2 to 1.3.0 in the github-acti...
  • e02ffd3 pre-commit: bump repositories (#1173)
  • aad39a8 docs: fix changelog page heading levels and sidebar (#1171)
  • 5c3fd46 docs: use PyPI ref directly (#1172)
  • 1c5bd6c 🐛 fix(release): format generated changelog (#1170)
  • 7f0cc7e 🔧 build(type): replace mypy with pyrefly (#1168)
  • See full diff in compare view

Updates agentseam from 0.3.0 to 0.3.1

Changelog

Sourced from agentseam's changelog.

[0.3.1] - 2026-09-20

Fixed

  • A Gemini command's commands/*.toml survives control characters, and a multi-line body no longer gains a trailing newline (packaging.py). _toml_string escaped backslash and quote only, so a body or description carrying a lone carriage return, a form feed, any other C0 control or DEL rendered TOML the extension could not load -- the sibling of the 0.3.0 hook-entry fix, in the other TOML this package writes. It now applies the same escape set (\uXXXX for the rest; a tab stays raw, a line feed only in the triple-quoted form, a carriage return always escaped so a reader's CRLF normalisation cannot change the body). Separately, the triple-quoted form put a newline before its closing delimiter, which a TOML reader keeps as part of the value: every multi-line prompt came back with an extra \n. Pinned by a tomllib round-trip of each hostile body.
  • A * in repo_root is a directory name, not the owner slot (install_config.py). resolve() substituted the owner for every * in the joined path, so a checkout under wild*card/ was wired at wildagentseamcard/.claude/settings.json -- a directory the agent never reads -- and installed() then reported it wired. No shipped CONFIG_PATH carries a *, so the substitution only ever reached paths the caller supplied. It now applies to the adapter's own CONFIG_PATH alone.
  • Kimi Code's config.toml is read and written as UTF-8, and is never truncated by a failed write (install_config.py). write_block() and remove_block() opened the file with no encoding, i.e. the platform locale. Under a Windows code page, or any non-UTF-8 locale, a user's config holding one non-ASCII byte made install and uninstall raise UnicodeDecodeError; a command holding one character the code page lacks (a ✓, a CJK path) raised UnicodeEncodeError after open(path, "w") had truncated the file, leaving the user's whole config zero bytes long. Both reproduced by execution under LC_ALL=C with UTF-8 mode off. Reads now decode UTF-8 (a file that is not UTF-8 raises ConfigUnreadableError untouched, the guarantee the JSON path already gave); writes encode the whole text first and only then open the file, so an unencodable command fails with the config intact. Line endings outside our block are preserved byte-for-byte as the docstring always claimed (text mode rewrote every one to the platform's), and the block takes the file's own ending so a CRLF config stays one kind and uninstall is an exact inverse. dump() says encoding="utf-8" too; its output was already ASCII.
  • An owner name that is a prefix of another's no longer owns that owner's TOML block (install_config.py). block_bounds() found the # >>> agentseam >>> <owner> markers by bare substring, so owner chock matched inside chock-java-security's begin and end markers -- both real consumers of this library. installed(owner="chock") answered yes to a block it never wrote; install(owner="chock") replaced the other owner's block with its own, closed by the other owner's end marker; uninstall(owner="chock") deleted it. Reproduced by execution against Kimi Code's config.toml. A marker now has to occupy a whole line, which also stops one quoted inside a comment from being taken for a block.
  • A handler that raises now refuses in the vendor's own dialect instead of failing open (dispatch.py, data/templates/runtime.py.tmpl). An exception out of the handler escaped run() -- and the bundled main() -- as a traceback and exit 1, which every host reads as a non-blocking hook error and carries on from: the crash trial in data/recordings/ watched Claude Code run the tool. handle() now answers it with Decision.deny, rendered through the adapter like any other deny (the witnessed block path), naming only the exception's class because its message may quote the payload the policy was inspecting; the traceback goes to stderr for the operator, and an in-process caller reads it off decision.evidence. A handler returning the wrong type is refused the same way. A fault past

... (truncated)

Commits
  • 5d5710e Merge pull request #153 from open-coder-ai/claude/epic-gauss-l6f2i4
  • 2774b1c Release 0.3.1
  • 486fea7 Merge pull request #152 from open-coder-ai/claude/agentseam-deep-review
  • b176f9d fix(dispatch): a diagnostic that cannot be written never pre-empts the refusal
  • 664fce1 fix(packaging): escape control characters in Gemini command TOML, drop the tr...
  • b30c645 fix(install): a * in repo_root is a directory name, not the owner slot
  • dc8ad28 fix(install): read and write config.toml as UTF-8, and never truncate it on a...
  • 35d2e01 fix(install): an owner that prefixes another owner's name does not own its block
  • 229c366 fix(dispatch): a handler that raises refuses in dialect instead of failing open
  • efc1340 fix(adapters): parse() and detect() are total over any JSON, not just objects
  • See full diff in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

…pdates

Bumps the patch-updates group with 3 updates in the / directory: [ruff](https://github.com/astral-sh/ruff), [build](https://github.com/pypa/build) and [agentseam](https://github.com/open-coder-ai/agentseam).


Updates `ruff` from 0.16.6 to 0.16.8
- [Release notes](https://github.com/astral-sh/ruff/releases)
- [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md)
- [Commits](astral-sh/ruff@0.16.6...0.16.8)

Updates `build` from 1.6.0 to 1.6.1
- [Release notes](https://github.com/pypa/build/releases)
- [Changelog](https://github.com/pypa/build/blob/main/CHANGELOG.rst)
- [Commits](pypa/build@1.6.0...1.6.1)

Updates `agentseam` from 0.3.0 to 0.3.1
- [Release notes](https://github.com/open-coder-ai/agentseam/releases)
- [Changelog](https://github.com/open-coder-ai/agentseam/blob/main/CHANGELOG.md)
- [Commits](open-coder-ai/agentseam@v0.3.0...v0.3.1)

---
updated-dependencies:
- dependency-name: ruff
  dependency-version: 0.16.8
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: patch-updates
- dependency-name: build
  dependency-version: 1.6.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: patch-updates
- dependency-name: agentseam
  dependency-version: 0.3.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: patch-updates
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Sep 28, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: dependencies. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants