Skip to content

Bump pylint from 4.0.8 to 4.0.9 in /dev_requirements - #223

Closed
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/pip/dev_requirements/pylint-4.0.9
Closed

dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/pip/dev_requirements/pylint-4.0.9

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Bumps pylint from 4.0.8 to 4.0.9.

Release notes

Sourced from pylint's releases.

v4.0.9

What's new in Pylint 4.0.9?

Release date: 2026-09-23

Security Fixes

  • Someone without access to the configuration or linted code, but with access to the cache directory (predictable PYLINT_HOME on a multi-user host) can no longer write a crafted pickle that will runs arbitrary code when pylint access its stat cache. The result cache is now stored as JSON instead of pickle, preventing code-execution. The workaround is upgrading or not pointing PYLINT_HOME to an untrusted, shared, or group-writable directory. The default value, ~/.cache/pylint, is writable only by the user running pylint. (CVE with the same information pending)

False Positives Fixed

  • Fixed a false positive for no-self-use on a method that only uses self before a locally defined class (or other nested method), because the checker's could-be-a-function tracking state was not restored after visiting the nested method.

    Closes #3705

  • Fix a false positive for :ref:not-callable when calling functions constructed with types.FunctionType or types.LambdaType.

    Closes #7500

  • Fix a false positive for unnecessary-direct-lambda-call when a directly called lambda in a class body wraps a comprehension containing an assignment expression. PEP 572 makes that a SyntaxError without the lambda's scope, so following the message produced code that would not compile.

    Closes #9294

  • Fix a false positive for :ref:unnecessary-ellipsis when an ellipsis is the sole body statement of a method defined on a Protocol.

    Closes #9319

  • Fix a false positive for :ref:bad-exception-cause when the bases of the class being raised from cannot be inferred, such as an exception deriving from a C extension class. :ref:raising-non-exception and :ref:catching-non-exception already guard the same inherit_from_std_ex

... (truncated)

Commits
  • 303703f Bump pylint to 4.0.9, update changelog (#11448)
  • b342384 Fix block-scoped disable leaking into sibling elif/else blocks (#11429) (#11445)
  • 58c87cf Store the results cache as JSON instead of pickle
  • e3f4942 [Backport maintenance/4.0.x] Fix crash on failed attribute inference (#11443)
  • faf47f9 [Backport maintenance/4.0.x] Fix false positive no-self-use when a method con...
  • 20c7bb9 [Backport maintenance/4.0.x] Fix a crash in method-hidden for methods named a...
  • 47e6757 [Backport maintenance/4.0.x] Fix bad-exception-cause false positive when the ...
  • ae3ee53 [Backport maintenance/4.0.x] Fix not-callable false positive for types.Functi...
  • 3e444be [Backport maintenance/4.0.x] Fix a crash in unnecessary-default-type-args for...
  • 8f2dd4f [Backport maintenance/4.0.x] Fix declare-non-slot false positives for ClassVa...
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [pylint](https://github.com/pylint-dev/pylint) from 4.0.8 to 4.0.9.
- [Release notes](https://github.com/pylint-dev/pylint/releases)
- [Commits](pylint-dev/pylint@v4.0.8...v4.0.9)

---
updated-dependencies:
- dependency-name: pylint
  dependency-version: 4.0.9
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Sep 28, 2026
@dependabot @github

dependabot Bot commented on behalf of github Sep 29, 2026

Copy link
Copy Markdown
Contributor Author

Looks like pylint is up-to-date now, so this is no longer needed.

@dependabot dependabot Bot closed this Sep 29, 2026
@dependabot
dependabot Bot deleted the dependabot/pip/dev_requirements/pylint-4.0.9 branch September 29, 2026 17:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants