Skip to content

deps(plugin-eval): bump the python-minor-and-patch group across 1 directory with 4 updates - #27

Merged
twistedmelonman merged 1 commit into
mainfrom
dependabot/uv/plugins/plugin-eval/python-minor-and-patch-6b8d25e6ad
Oct 5, 2026
Merged

twistedmelonman merged 1 commit into
mainfrom
dependabot/uv/plugins/plugin-eval/python-minor-and-patch-6b8d25e6ad

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 21, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the python-minor-and-patch group with 4 updates in the /plugins/plugin-eval directory: claude-agent-sdk, anthropic, ruff and ty.

Updates claude-agent-sdk from 0.2.152 to 0.2.161

Release notes

Sourced from claude-agent-sdk's releases.

v0.2.161

Internal/Other Changes

  • Updated bundled Claude CLI to version 2.1.284

PyPI: https://pypi.org/project/claude-agent-sdk/0.2.161/

pip install claude-agent-sdk==0.2.161

v0.2.160

Bug Fixes

  • Fixed follow-up turns failing after background subagents: When using query() with hooks, can_use_tool, or SDK MCP servers, stdin was closed too early if a subagent finished just before the turn's result arrived. Follow-up turns would then fail with "Stream closed" and the model would report the tool as refused. The SDK now listens for the CLI's session_state_changed messages and keeps stdin open until the CLI reports idle, matching the TypeScript SDK's behavior. A bounded wait ceiling (configurable via CLAUDE_CODE_PRINT_BG_WAIT_CEILING_MS, default 10 minutes) prevents indefinite hangs. Older CLIs without state events fall back to the previous close-at-first-result behavior. (#1190, #1279)

Documentation

  • Aligned docstrings with the code and fixed docstring formatting (#1293)

Internal/Other Changes

  • Updated bundled Claude CLI to version 2.1.283
  • CI: skip wheels over PyPI's per-file limit instead of failing the release (#1309)

PyPI: https://pypi.org/project/claude-agent-sdk/0.2.160/

pip install claude-agent-sdk==0.2.160

v0.2.159

Internal/Other Changes

  • Updated bundled Claude CLI to version 2.1.281
  • Pinned default model for e2e tests to claude-opus-5 to work around CI failures with the CLI's new default model (#1287)

PyPI: https://pypi.org/project/claude-agent-sdk/0.2.159/

... (truncated)

Changelog

Sourced from claude-agent-sdk's changelog.

0.2.161

Internal/Other Changes

  • Updated bundled Claude CLI to version 2.1.284

0.2.160

Bug Fixes

  • Fixed follow-up turns failing after background subagents: When using query() with hooks, can_use_tool, or SDK MCP servers, stdin was closed too early if a subagent finished just before the turn's result arrived. Follow-up turns would then fail with "Stream closed" and the model would report the tool as refused. The SDK now listens for the CLI's session_state_changed messages and keeps stdin open until the CLI reports idle, matching the TypeScript SDK's behavior. A bounded wait ceiling (configurable via CLAUDE_CODE_PRINT_BG_WAIT_CEILING_MS, default 10 minutes) prevents indefinite hangs. Older CLIs without state events fall back to the previous close-at-first-result behavior. (#1190, #1279)

Documentation

  • Aligned docstrings with the code and fixed docstring formatting (#1293)

Internal/Other Changes

  • Updated bundled Claude CLI to version 2.1.283
  • CI: skip wheels over PyPI's per-file limit instead of failing the release (#1309)

0.2.159

Internal/Other Changes

  • Updated bundled Claude CLI to version 2.1.281
  • Pinned default model for e2e tests to claude-opus-5 to work around CI failures with the CLI's new default model (#1287)

0.2.158

New Features

  • verbatim_prompts option: Added ClaudeAgentOptions.verbatim_prompts (default False). When True, user messages are delivered to the CLI exactly as written — no @path file expansion and no slash-command dispatch. This prevents untrusted text inlined into prompts from triggering unintended file reads or command execution. Works with query(), ClaudeSDKClient.connect(), and ClaudeSDKClient.query() for both string and async-iterable prompts. Requires CLI 2.1.248+; a warning is logged on older CLIs. (#1269)

Internal/Other Changes

  • Updated bundled Claude CLI to version 2.1.280
  • CI improvements: recompressed wheels and raised the PyPI pre-flight threshold (#1283)

0.2.156

Internal/Other Changes

  • Updated bundled Claude CLI to version 2.1.276

0.2.155

Internal/Other Changes

  • Updated bundled Claude CLI to version 2.1.275

... (truncated)

Commits
  • 37422c2 docs: update changelog for v0.2.161
  • 86f74a5 chore: release v0.2.161
  • 75f3af2 chore: bump bundled CLI version to 2.1.284
  • 36f9548 docs: update changelog for v0.2.160
  • a076a6a chore: release v0.2.160
  • 0615c04 chore: bump bundled CLI version to 2.1.283
  • dbc975e fix: keep stdin open until the CLI reports idle so follow-up turns are served...
  • 6c3df98 ci: skip wheels over PyPI's per-file limit instead of failing the release (#1...
  • 5889056 docs: align docstrings with the code and fix docstring formatting (#1293)
  • 3aeceed chore: bump bundled CLI version to 2.1.282
  • Additional commits viewable in compare view

Updates anthropic from 1.4.0 to 1.9.0

Release notes

Sourced from anthropic's releases.

v1.9.0

1.9.0 (2026-09-28)

Full Changelog: v1.8.0...v1.9.0

Features

  • api: add between_tools thinking type (a9a577d)
  • api: add claude-sonnet-5-5 (a5a25e9)
  • api: add include_inherited and source to workspace rate limits (0bf4af8)
  • api: add typed event type values to the Managed Agents events list filter (1b82cd9)
  • api: cache diagnostics GA — diagnostics on Message / MessageCreateParams (22062b8)
  • tools: optionally run tool calls while the reply streams (26d0812)

Bug Fixes

  • client: send no placeholder filename for unnamed file uploads (9e9709d)
  • helpers: degrade between_tools thinking to disabled on fallback hops (#952) (a3834d4)
  • messages: accept diagnostics in stream() and parse() (#929) (fad840c)

Chores

  • api: list the known model ids first in the Model types (e5a082a)
  • ci: choose the CI runner by repository (39ccf62)
  • client: stop sending beta header from parse and tool runner (#907) (1428100)
  • docs: clarify that stream: true returns the raw event stream (82918fa)
  • docs: make Managed Agents actor descriptions resource-neutral (34ef524)
  • docs: restore the research-preview notice on the Dream type (f03e32e)

Documentation

  • add field docstring spacing rule to CLAUDE.md (e5c35f4)
  • api: prefer each field's own description over its shared type's (d79a2e7)
  • claude.md: add function body spacing rule (3174f8f)
  • list importable type names in api.md (56a42ab)

v1.8.0

1.8.0 (2026-09-22)

Full Changelog: v1.7.0...v1.8.0

Features

  • api: add support for claude-opus-5-5, inline tool definitions and MCP tool-list pinning (beta) (b5cc700)

Bug Fixes

... (truncated)

Changelog

Sourced from anthropic's changelog.

1.9.0 (2026-09-28)

Full Changelog: v1.8.0...v1.9.0

Features

  • api: add between_tools thinking type (a9a577d)
  • api: add claude-sonnet-5-5 (a5a25e9)
  • api: add include_inherited and source to workspace rate limits (0bf4af8)
  • api: add typed event type values to the Managed Agents events list filter (1b82cd9)
  • api: cache diagnostics GA — diagnostics on Message / MessageCreateParams (22062b8)
  • tools: optionally run tool calls while the reply streams (26d0812)

Bug Fixes

  • client: send no placeholder filename for unnamed file uploads (9e9709d)
  • helpers: degrade between_tools thinking to disabled on fallback hops (#952) (a3834d4)
  • messages: accept diagnostics in stream() and parse() (#929) (fad840c)

Chores

  • api: list the known model ids first in the Model types (e5a082a)
  • ci: choose the CI runner by repository (39ccf62)
  • client: stop sending beta header from parse and tool runner (#907) (1428100)
  • docs: clarify that stream: true returns the raw event stream (82918fa)
  • docs: make Managed Agents actor descriptions resource-neutral (34ef524)
  • docs: restore the research-preview notice on the Dream type (f03e32e)

Documentation

  • add field docstring spacing rule to CLAUDE.md (e5c35f4)
  • api: prefer each field's own description over its shared type's (d79a2e7)
  • claude.md: add function body spacing rule (3174f8f)
  • list importable type names in api.md (56a42ab)

1.8.0 (2026-09-22)

Full Changelog: v1.7.0...v1.8.0

Features

  • api: add support for claude-opus-5-5, inline tool definitions and MCP tool-list pinning (beta) (b5cc700)

Bug Fixes

  • api: share one evaluated_permission enum across Managed Agents events (f4f51c8)

... (truncated)

Commits
  • a7285e9 Merge pull request #1958 from anthropics/release-please--branches--main--chan...
  • 3e2ac95 release: 1.9.0
  • 24b1d55 codegen metadata
  • a5a25e9 feat(api): add claude-sonnet-5-5
  • 2264bd8 codegen metadata
  • 9e9709d fix(client): send no placeholder filename for unnamed file uploads
  • 1b82cd9 feat(api): add typed event type values to the Managed Agents events list filter
  • 26d0812 feat(tools): optionally run tool calls while the reply streams
  • ebb8239 codegen metadata
  • a3834d4 fix(helpers): degrade between_tools thinking to disabled on fallback hops (#952)
  • Additional commits viewable in compare view

Updates ruff from 0.16.6 to 0.16.9

Release notes

Sourced from ruff's releases.

0.16.9

Release Notes

Released on 2026-09-24.

Preview features

  • [ruff] Avoid false positives for overloaded division (RUF069) (#28309)

Bug fixes

  • [flake8-bugbear] Avoid false positives for calls with keyword arguments (B009, B010, B043) (#28776)
  • [flake8-tidy-imports] Allow lazy imports to be used in deferred annotations (TID255) (#28767)

Rule changes

  • Update LibCST-based fixes for Python 3.15 (#28616)
  • [flake8-pyi] Mention stubs in the diagnostic message (PYI002) (#28542)

Documentation

  • Fix horizontal overflow on the rules documentation page (#28699)
  • Update rules table with category information (#28651)
  • [flake8-annotations] Clarify that ANN401 checks return types in addition to arguments (#28334)
  • [flake8-bugbear] Document type-checker interaction (B010) (#28509)
  • [flake8-comprehensions] Document map/generator exception behavior (C417) (#27794)
  • [ruff] Mention related isort settings (RUF022) (#28719)

Contributors

Install ruff 0.16.9

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/ruff/releases/download/0.16.9/ruff-installer.sh | sh

... (truncated)

Changelog

Sourced from ruff's changelog.

0.16.9

Released on 2026-09-24.

Preview features

  • [ruff] Avoid false positives for overloaded division (RUF069) (#28309)

Bug fixes

  • [flake8-bugbear] Avoid false positives for calls with keyword arguments (B009, B010, B043) (#28776)
  • [flake8-tidy-imports] Allow lazy imports to be used in deferred annotations (TID255) (#28767)

Rule changes

  • Update LibCST-based fixes for Python 3.15 (#28616)
  • [flake8-pyi] Mention stubs in the diagnostic message (PYI002) (#28542)

Documentation

  • Fix horizontal overflow on the rules documentation page (#28699)
  • Update rules table with category information (#28651)
  • [flake8-annotations] Clarify that ANN401 checks return types in addition to arguments (#28334)
  • [flake8-bugbear] Document type-checker interaction (B010) (#28509)
  • [flake8-comprehensions] Document map/generator exception behavior (C417) (#27794)
  • [ruff] Mention related isort settings (RUF022) (#28719)

Contributors

0.16.8

Released on 2026-09-16.

Bug fixes

  • Visit functional TypedDict keyword arguments correctly (#28584)
  • [flake8-simplify] Detect nested async with under sync parent (SIM117) (#27821)
  • [flake8-simplify] Preserve operand order in SIM109 fix (#27824)

... (truncated)

Commits
  • 0be08a2 Bump version to 0.16.9 (#28882)
  • b4920b7 Rename ruff_cli to ruff_command_line (#28881)
  • 47c751b Update dependency astral-sh/uv to v0.12.18 (#28880)
  • 8c244e5 [flake8-comprehensions] Document map/generator exception behavior (C417...
  • 5edf5a1 Use target form in rooster.version_files (#28876)
  • 915bb2b [ty] Prefer existing @ paths over response files in Ruff and ty (#28877)
  • 4710e1a ci(github): update version number in placeholder of issue template (#28871)
  • eedfc62 [ty] Propagate outer type context through cast calls (#28855)
  • ceaa6a0 [ty] Contain rendered code within Markdown fences (#28869)
  • dba0f30 authorize ruff-pre-commit dispatch via OIDC (#28867)
  • Additional commits viewable in compare view

Updates ty from 0.0.79 to 0.0.84

Release notes

Sourced from ty's releases.

0.0.84

Release Notes

Released on 2026-09-24.

This release addresses GHSA-vxvm-j4xq-q7m4, a use-after-free vulnerability during incremental type checking that can result in arbitrary code execution when analyzing a specially crafted Python project. Users who run ty on untrusted code should upgrade to 0.0.84 or newer.

Bug fixes

  • Fix stale diagnostics from the LSP server after toggling showSyntaxErrors (#28759)

LSP server

  • Complete string keys from dictionary initializers (#28820)
  • Support LSP requests against closed documents (#28595)
  • Select projects for external files using import search paths (#28594)
  • Use workspace editor settings for external files (#28639)

Performance

  • Avoid repeated subtyping checks for materialized recursive protocols (#28774)
  • Skip reading notebooks when discovering scripts (#28781)

Core type checking

  • Avoid incorrect simplification of TypeIs materializations (#28817)
  • Fix disjointness of generic class types (#28787)
  • Fix staticmethod shadowing through generic receivers and unions (#28766)
  • Infer callable signatures from bounded type variables (#28599)
  • Infer constant membership in inline list and set literals (e.g. "foo" in ["foo"] is now inferred as Literal[True]) (#28676)
  • Infer through optional generic containers in the legacy solver (#28791)
  • Preserve call narrowing during cyclic inference (#28708)
  • Preserve intersections of type guard return types (#28796)
  • Use subtyping for constraint-set implication (#28657)

Configuration

  • Disable invalid-legacy-positional-parameter by default (#28834)

Other changes

  • Only consider reachable definitions when determining whether a condition should be exempted from redundant-condition(-strict) due to the condition being defined relative to sys.version_info, sys.platform, os.name or typing.TYPE_CHECKING (#28788)

Contributors

... (truncated)

Changelog

Sourced from ty's changelog.

0.0.84

Released on 2026-09-24.

This release addresses GHSA-vxvm-j4xq-q7m4, a use-after-free vulnerability during incremental type checking that can result in arbitrary code execution when analyzing a specially crafted Python project. Users who run ty on untrusted code should upgrade to 0.0.84 or newer.

Bug fixes

  • Fix stale diagnostics from the LSP server after toggling showSyntaxErrors (#28759)

LSP server

  • Complete string keys from dictionary initializers (#28820)
  • Support LSP requests against closed documents (#28595)
  • Select projects for external files using import search paths (#28594)
  • Use workspace editor settings for external files (#28639)

Performance

  • Avoid repeated subtyping checks for materialized recursive protocols (#28774)
  • Skip reading notebooks when discovering scripts (#28781)

Core type checking

  • Avoid incorrect simplification of TypeIs materializations (#28817)
  • Fix disjointness of generic class types (#28787)
  • Fix staticmethod shadowing through generic receivers and unions (#28766)
  • Infer callable signatures from bounded type variables (#28599)
  • Infer constant membership in inline list and set literals (e.g. "foo" in ["foo"] is now inferred as Literal[True]) (#28676)
  • Infer through optional generic containers in the legacy solver (#28791)
  • Preserve call narrowing during cyclic inference (#28708)
  • Preserve intersections of type guard return types (#28796)
  • Use subtyping for constraint-set implication (#28657)

Configuration

  • Disable invalid-legacy-positional-parameter by default (#28834)

Other changes

  • Only consider reachable definitions when determining whether a condition should be exempted from redundant-condition(-strict) due to the condition being defined relative to sys.version_info, sys.platform, os.name or typing.TYPE_CHECKING (#28788)

Contributors

... (truncated)

Commits

@dependabot
dependabot Bot force-pushed the dependabot/uv/plugins/plugin-eval/python-minor-and-patch-6b8d25e6ad branch from 7249405 to 456c255 Compare September 28, 2026 06:29
@twistedmelonman

Copy link
Copy Markdown
Member

@dependabot rebase

@dependabot
dependabot Bot force-pushed the dependabot/uv/plugins/plugin-eval/python-minor-and-patch-6b8d25e6ad branch 3 times, most recently from 890ddb8 to e5fb3d9 Compare October 2, 2026 17:24
…ectory with 4 updates

Bumps the python-minor-and-patch group with 4 updates in the /plugins/plugin-eval directory: [claude-agent-sdk](https://github.com/anthropics/claude-agent-sdk-python), [anthropic](https://github.com/anthropics/anthropic-sdk-python), [ruff](https://github.com/astral-sh/ruff) and [ty](https://github.com/astral-sh/ty).


Updates `claude-agent-sdk` from 0.2.152 to 0.2.161
- [Release notes](https://github.com/anthropics/claude-agent-sdk-python/releases)
- [Changelog](https://github.com/anthropics/claude-agent-sdk-python/blob/main/CHANGELOG.md)
- [Commits](anthropics/claude-agent-sdk-python@v0.2.152...v0.2.161)

Updates `anthropic` from 1.4.0 to 1.9.0
- [Release notes](https://github.com/anthropics/anthropic-sdk-python/releases)
- [Changelog](https://github.com/anthropics/anthropic-sdk-python/blob/main/CHANGELOG.md)
- [Commits](anthropics/anthropic-sdk-python@v1.4.0...v1.9.0)

Updates `ruff` from 0.16.6 to 0.16.9
- [Release notes](https://github.com/astral-sh/ruff/releases)
- [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md)
- [Commits](astral-sh/ruff@0.16.6...0.16.9)

Updates `ty` from 0.0.79 to 0.0.84
- [Release notes](https://github.com/astral-sh/ty/releases)
- [Changelog](https://github.com/astral-sh/ty/blob/main/CHANGELOG.md)
- [Commits](astral-sh/ty@0.0.79...0.0.84)

---
updated-dependencies:
- dependency-name: anthropic
  dependency-version: 1.6.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-minor-and-patch
- dependency-name: claude-agent-sdk
  dependency-version: 0.2.156
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python-minor-and-patch
- dependency-name: ruff
  dependency-version: 0.16.8
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python-minor-and-patch
- dependency-name: ty
  dependency-version: 0.0.82
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python-minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/uv/plugins/plugin-eval/python-minor-and-patch-6b8d25e6ad branch from e5fb3d9 to 860df79 Compare October 2, 2026 17:26
@twistedmelonman
twistedmelonman merged commit 03db08b into main Oct 5, 2026
10 checks passed
@twistedmelonman
twistedmelonman deleted the dependabot/uv/plugins/plugin-eval/python-minor-and-patch-6b8d25e6ad branch October 5, 2026 15:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant