Skip to content

build(deps-dev): bump the pip group with 4 updates - #35

Closed
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/uv/pip-1e569de5ed
Closed

dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/uv/pip-1e569de5ed

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 21, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the pip group with 4 updates: ruff, semgrep, zizmor and prek.

Updates ruff from 0.16.4 to 0.16.7

Release notes

Sourced from ruff's releases.

0.16.7

Release Notes

Released on 2026-09-10.

Preview features

  • [ruff] Add rule for default values on method receivers (RUF077) (#26700)
  • [ruff] Recognize re.prefixmatch (RUF039, RUF055) (#28311)

Bug fixes

  • Alternate nested quotes inside format spec interpolations (#28259)
  • [flake8-implicit-str-concat] Mark fix unsafe when it creates a docstring (ISC003) (#27981)
  • [flake8-tidy-imports] Skip fixes for multi-member imports (TID254) (#26584)
  • [pylint] Gate ImportCycleError on Python 3.15 (PLW0133) (#28310)

Rule changes

  • Correct D211 and D203 rule conflict diagnostic (#28444)
  • Recognize slice and frozendict generics (#28477)
  • Stop defining __cached__ for Python 3.15 (#28476)
  • [pyupgrade] Stop recommending removed typing.no_type_check_decorator (UP035) (#28475)

Performance

  • Reuse parser name lookups when interning (#28399)
  • Speed up inherited configuration resolution (#28299)

Documentation

  • Fix line-length path in --config example (#28392)
  • Remove the "Who’s Using Ruff?" list (#28455)

Other changes

  • Embed archive checksums in the shell installer (#28281)

Contributors

... (truncated)

Changelog

Sourced from ruff's changelog.

0.16.7

Released on 2026-09-10.

Preview features

  • [ruff] Add rule for default values on method receivers (RUF077) (#26700)
  • [ruff] Recognize re.prefixmatch (RUF039, RUF055) (#28311)

Bug fixes

  • Alternate nested quotes inside format spec interpolations (#28259)
  • [flake8-implicit-str-concat] Mark fix unsafe when it creates a docstring (ISC003) (#27981)
  • [flake8-tidy-imports] Skip fixes for multi-member imports (TID254) (#26584)
  • [pylint] Gate ImportCycleError on Python 3.15 (PLW0133) (#28310)

Rule changes

  • Correct D211 and D203 rule conflict diagnostic (#28444)
  • Recognize slice and frozendict generics (#28477)
  • Stop defining __cached__ for Python 3.15 (#28476)
  • [pyupgrade] Stop recommending removed typing.no_type_check_decorator (UP035) (#28475)

Performance

  • Reuse parser name lookups when interning (#28399)
  • Speed up inherited configuration resolution (#28299)

Documentation

  • Fix line-length path in --config example (#28392)
  • Remove the "Who’s Using Ruff?" list (#28455)

Other changes

  • Embed archive checksums in the shell installer (#28281)

Contributors

... (truncated)

Commits

Updates semgrep from 1.174.0 to 1.177.0

Release notes

Sourced from semgrep's releases.

Release v1.177.0

1.177.0 - 2026-09-10

### Added

  • Added native Supply Chain support for Bazel workspaces using rules_jvm_external. Semgrep now recognizes a maven_install.json pinned lockfile (versions 0.1.0 and 3, as emitted by rules_jvm_external 3.x through current) paired with a MODULE.bazel (or legacy WORKSPACE / WORKSPACE.bazel) marker as a Maven-ecosystem subproject, and attributes findings to the workspace root rather than the lockfile's directory. Workspace-declared root artifacts are identified via __INPUT_ARTIFACTS_HASH for accurate direct-vs-transitive classification; dependencies are emitted with Unknown transitivity when that field is not available. This is the first milestone of native Bazel coverage; broader ecosystem support (rules_python, rules_go, rules_js) and Bazel-aware reachability attribution follow. (SC-2008)
  • Several performance improvements for regex-only rules where the underlying regex are inefficient to run on our default regex engine (currently PCRE2). For example, a rule matching FOOBAR(a+)\1 will skip any file that does not contain FOOBAR without running the regex. (scrt-979)

### Changed

  • Prefilter conditions now evaluate their cheap string predicates before their expensive regex predicates. Since evaluation short-circuits, a file that a string check already rules in or out no longer pays for regex predicates (which is what a pattern's prefilter falls back to when no literal substring can be extracted from it, and which can be slow on files with very long lines). (prefilter-rank-conjuncts)
  • Supply Chain scans can report dependencies from their Gradle module build files instead of the root manifest. This behavior is disabled by default during rollout and can be tested with --x-gradle-module-attribution. Enabling it can change finding IDs because finding paths change; the ID calculation is unchanged. (SC-2560)

### Fixed

  • Speed up semgrep ci filtering when a deployment has many triage-ignored findings. (triage-ignored-performance)

  • Semgrep no longer crashes with an OCaml stack trace when a proxy environment variable holds an unusable value. HTTP_PROXY, HTTPS_PROXY, or ALL_PROXY set to an empty value is now ignored with a warning, and the scan proceeds without a proxy. A non-empty value that is not a usable proxy URL now exits with an error message, with any credentials in the URL redacted, instead of failing inside the HTTP client.

    Semgrep also now adds the missing scheme to a proxy URL supplied without one; https for HTTPS_PROXY and http` otherwise. (ENGINE-2208)

  • Supply Chain: lockfileless Gradle scans now report a "Resource Inaccessible" resolution error when a repository refuses a request (for example a 401 from a private registry), instead of exiting successfully with a silently incomplete dependency list. (sc-3358)

### Infra/Release Changes

  • Improves shutdown time during scans with --trace. (otel-shutdown-flush)

Release v1.176.0

1.176.0 - 2026-09-01

### Changed

  • Homebrew installs of Semgrep are no longer supported on Intel Macs. (ENGINE-2951)

Release v1.175.0

... (truncated)

Changelog

Sourced from semgrep's changelog.

1.177.0 - 2026-09-10

### Added

  • Added native Supply Chain support for Bazel workspaces using rules_jvm_external. Semgrep now recognizes a maven_install.json pinned lockfile (versions 0.1.0 and 3, as emitted by rules_jvm_external 3.x through current) paired with a MODULE.bazel (or legacy WORKSPACE / WORKSPACE.bazel) marker as a Maven-ecosystem subproject, and attributes findings to the workspace root rather than the lockfile's directory. Workspace-declared root artifacts are identified via __INPUT_ARTIFACTS_HASH for accurate direct-vs-transitive classification; dependencies are emitted with Unknown transitivity when that field is not available. This is the first milestone of native Bazel coverage; broader ecosystem support (rules_python, rules_go, rules_js) and Bazel-aware reachability attribution follow. (SC-2008)
  • Several performance improvements for regex-only rules where the underlying regex are inefficient to run on our default regex engine (currently PCRE2). For example, a rule matching FOOBAR(a+)\1 will skip any file that does not contain FOOBAR without running the regex. (scrt-979)

### Changed

  • Prefilter conditions now evaluate their cheap string predicates before their expensive regex predicates. Since evaluation short-circuits, a file that a string check already rules in or out no longer pays for regex predicates (which is what a pattern's prefilter falls back to when no literal substring can be extracted from it, and which can be slow on files with very long lines). (prefilter-rank-conjuncts)
  • Supply Chain scans can report dependencies from their Gradle module build files instead of the root manifest. This behavior is disabled by default during rollout and can be tested with --x-gradle-module-attribution. Enabling it can change finding IDs because finding paths change; the ID calculation is unchanged. (SC-2560)

### Fixed

  • Speed up semgrep ci filtering when a deployment has many triage-ignored findings. (triage-ignored-performance)

  • Semgrep no longer crashes with an OCaml stack trace when a proxy environment variable holds an unusable value. HTTP_PROXY, HTTPS_PROXY, or ALL_PROXY set to an empty value is now ignored with a warning, and the scan proceeds without a proxy. A non-empty value that is not a usable proxy URL now exits with an error message, with any credentials in the URL redacted, instead of failing inside the HTTP client.

    Semgrep also now adds the missing scheme to a proxy URL supplied without one; https for HTTPS_PROXY and http` otherwise. (ENGINE-2208)

  • Supply Chain: lockfileless Gradle scans now report a "Resource Inaccessible" resolution error when a repository refuses a request (for example a 401 from a private registry), instead of exiting successfully with a silently incomplete dependency list. (sc-3358)

### Infra/Release Changes

  • Improves shutdown time during scans with --trace. (otel-shutdown-flush)

1.176.0 - 2026-09-01

### Changed

  • Homebrew installs of Semgrep are no longer supported on Intel Macs. (ENGINE-2951)

1.175.1 - 2026-09-03

... (truncated)

Commits
  • e279a88 chore: release 1.177.0
  • c843af6 fix: non-recursive checkouts in sync-with-OSS workflow (semgrep/semgrep-propr...
  • 0516c0fsemgrep/semgrep-proprietary#7052
  • cd7517a fix(sca): Scope Gradle reachable findings to the source file's module (semgre...
  • 177f2d9 feat(sca): Name the build file of each Gradle dependency child (semgrep/semgr...
  • adef05d fix(sca): Report Gradle dependencies from their module build files (semgrep/s...
  • 29d561a feat(sca): Add Gradle attribution configuration fields (semgrep/semgrep-propr...
  • f159572 fix(sca): Preserve Gradle dependencies per module (semgrep/semgrep-proprietar...
  • 144c0e0 chore: Mark more semgrep-interfaces files as generated (semgrep/semgrep-propr...
  • 2ac4302semgrep/semgrep-proprietary#7036
  • Additional commits viewable in compare view

Updates zizmor from 1.29.0 to 1.30.1

Release notes

Sourced from zizmor's releases.

v1.30.1

Sponsorship is appreciated!

Bug Fixes 🐛🔗

  • Fixed a bug where zizmor would crash on pre-commit inputs that reference a GitHub URL with an explicit .git suffix (#2363)

  • Fixed a bug where self-repository auto-fixes were incorrectly marked as "safe" instead of "unsafe" (#2373)

v1.30.0

Sponsorship is appreciated!

New Features 🌈🔗

Bug Fixes 🐛🔗

... (truncated)

Changelog

Sourced from zizmor's changelog.

1.30.1

Bug Fixes 🐛

  • Fixed a bug where zizmor would crash on pre-commit inputs that reference a GitHub URL with an explicit .git suffix (#2363)

  • Fixed a bug where [self-repository] auto-fixes were incorrectly marked as "safe" instead of "unsafe" (#2373)

1.30.0

New Features 🌈

  • New audit: [self-repository] detects usages of the old "workspace-relative" form for local reusable workflows and actions and recommends the new "self-repository" form instead (#2271)

Enhancements 🌱

  • The [impostor-commit] audit now supports pre-commit config inputs (#2256)

  • The [forbidden-uses] audit now supports pre-commit config inputs (#2263)

  • The [adhoc-packages] audit now detects more ad-hoc package management patterns, including bundle add and yarn add

    Many thanks to @​connorshea for proposing and implementing this enhancement!

  • The [archived-uses] audit now supports pre-commit config inputs (#2272)

  • The [ref-confusion] audit now supports pre-commit config inputs (#2274)

  • The [cache-poisoning] audit now produces more detailed and more precise diagnostics (#2330)

  • The [cache-poisoning] audit now handles and exposes auto-fixes in a more general manner (#2332)

  • zizmor now recognizes @​sethvargo/ratchet version comments when evaluating ref pinning (#2319)

    Many thanks to @​njgudman for proposing and implementing this enhancement!

  • The [unpinned-tools] audit now produces more detailed and more precise diagnostics (#2339)

  • The [unpinned-tools] audit now detects usages of @​extractions/setup-just (#2339)

  • The [unpinned-tools] audit now detects usages of @​extractions/setup-crate (#2340)

  • The [archived-uses] audit now detects several more archived repositories (#2340)

  • The [ref-version-mismatch] audit now supports #!yaml uses: that reference

... (truncated)

Commits

Updates prek from 0.4.14 to 0.5.3

Release notes

Sourced from prek's releases.

0.5.3

Release Notes

Released on 2026-09-13.

Enhancements

  • Add PEP 740 attestations for PyPI releases (#2705)
  • Add a check-jsonc builtin hook (#2682)
  • Allow disabling automatic uv installation (#2702)

Bug fixes

  • Fix Julia additional dependency specifiers (#2703)
  • Update granit-parser to fix YAML flow indentation (#2707)

Contributors

Install prek 0.5.3

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://github.com/j178/prek/releases/download/v0.5.3/prek-installer.sh | sh

Install prebuilt binaries via powershell script

powershell -ExecutionPolicy Bypass -c "irm https://github.com/j178/prek/releases/download/v0.5.3/prek-installer.ps1 | iex"

Install prebuilt binaries via Homebrew

brew install prek

Download prek 0.5.3

File Platform Checksum
prek-aarch64-apple-darwin.tar.gz Apple Silicon macOS checksum
prek-x86_64-apple-darwin.tar.gz Intel macOS checksum
prek-aarch64-pc-windows-msvc.zip ARM64 Windows checksum
prek-x86_64-pc-windows-msvc.zip x64 Windows checksum

... (truncated)

Changelog

Sourced from prek's changelog.

0.5.3

Released on 2026-09-13.

Enhancements

  • Add PEP 740 attestations for PyPI releases (#2705)
  • Add a check-jsonc builtin hook (#2682)
  • Allow disabling automatic uv installation (#2702)

Bug fixes

  • Fix Julia additional dependency specifiers (#2703)
  • Update granit-parser to fix YAML flow indentation (#2707)

Contributors

0.5.2

Released on 2026-09-03.

Enhancements

  • Allow unknown tags by default in check-yaml (#2678)

Contributors

0.5.1

Released on 2026-09-01.

Enhancements

  • Add --hide-status <passed|failed|skipped> for hook reports (#2644)
  • Add prek init for repository setup (#2636)
  • Apply hook env during environment creation (#2650)
  • Disable error snippets in check-yaml diagnostics (#2664)
  • Show hooks excluded by skip selectors (#2645)
  • Support Pixi for Conda environments (#2667)
  • Support cargo-binstall for Rust CLI dependencies (#2658)
  • Warn about unused keys in user settings (#2665)

Bug fixes

... (truncated)

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the pip group with 4 updates: [ruff](https://github.com/astral-sh/ruff), [semgrep](https://github.com/semgrep/semgrep), [zizmor](https://github.com/zizmorcore/zizmor) and [prek](https://github.com/j178/prek).


Updates `ruff` from 0.16.4 to 0.16.7
- [Release notes](https://github.com/astral-sh/ruff/releases)
- [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md)
- [Commits](astral-sh/ruff@0.16.4...0.16.7)

Updates `semgrep` from 1.174.0 to 1.177.0
- [Release notes](https://github.com/semgrep/semgrep/releases)
- [Changelog](https://github.com/semgrep/semgrep/blob/v1.177.0/CHANGELOG.md)
- [Commits](semgrep/semgrep@v1.174.0...v1.177.0)

Updates `zizmor` from 1.29.0 to 1.30.1
- [Release notes](https://github.com/zizmorcore/zizmor/releases)
- [Changelog](https://github.com/zizmorcore/zizmor/blob/main/docs/release-notes.md)
- [Commits](zizmorcore/zizmor@v1.29.0...v1.30.1)

Updates `prek` from 0.4.14 to 0.5.3
- [Release notes](https://github.com/j178/prek/releases)
- [Changelog](https://github.com/j178/prek/blob/master/CHANGELOG.md)
- [Commits](j178/prek@v0.4.14...v0.5.3)

---
updated-dependencies:
- dependency-name: ruff
  dependency-version: 0.16.7
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: pip
- dependency-name: semgrep
  dependency-version: 1.177.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: pip
- dependency-name: zizmor
  dependency-version: 1.30.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: pip
- dependency-name: prek
  dependency-version: 0.5.3
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: pip
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels Sep 21, 2026
@dependabot @github

dependabot Bot commented on behalf of github Sep 28, 2026

Copy link
Copy Markdown
Contributor Author

Looks like these dependencies are updatable in another way, so this is no longer needed.

@dependabot dependabot Bot closed this Sep 28, 2026
@dependabot
dependabot Bot deleted the dependabot/uv/pip-1e569de5ed branch September 28, 2026 09:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants