Skip to content

build(deps-dev): bump the pip-all group across 1 directory with 4 updates - #60

Merged
030 merged 1 commit into
mainfrom
dependabot/pip/pip-all-98b5ece1d3
Oct 10, 2026
Merged

030 merged 1 commit into
mainfrom
dependabot/pip/pip-all-98b5ece1d3

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 20, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the pip-all group with 4 updates in the / directory: coverage, mypy, types-requests and validate-pyproject.

Updates coverage from 7.15.2 to 7.16.2

Release notes

Sourced from coverage's releases.

7.16.2

Version 7.16.2 — 2026-09-27

  • Fix: on Python 3.14 and later, a for loop completing immediately before a function return could mistakenly report an uncovered branch. This is now fixed, closing issue 2168.
  • Fix: on Python 3.14 and later, the else clause of a try whose body is a with statement could incorrectly be reported as covered when the with raised. This is now fixed, closing issue 2289.
  • Fix: with dynamic_context = test_function, test methods written as @staticmethod or @classmethod were not given a context of their own. Now they are, on Python 3.11 and later. Closes issue 1923.

➡️  PyPI page: coverage 7.16.2. :arrow_right:  To install: python3 -m pip install coverage==7.16.2

7.16.1

Version 7.16.1 — 2026-09-13

  • Fix: when the body of an irrefutable case (like case _:) is entirely excluded, the case line is now excluded too, just as an excluded else: body removes the else: line. Previously the case line was left behind and reported as missing. Closes issue 1563 with pull 2269.
  • Fix: using CoverageData.update() twice on an in-memory database would fail, as described in issue 2279. This is now fixed.

➡️  PyPI page: coverage 7.16.1. :arrow_right:  To install: python3 -m pip install coverage==7.16.1

7.16.0

Version 7.16.0 — 2026-08-28

  • When combining files, now path separator slashes will automatically be converted to the local file system style. This makes it less necessary to define [paths] configuration to combine data across operating systems. Fixes issue 2266.
  • The Coverage.switch_context() method now returns the previous context.
  • Fix: previously, a [paths] pattern would be replaced everywhere in a file path when it was only meant to be replaced once, in the leading portion of the path. This is now fixed, in pull 2268.
  • Fixes to validation of options and configuration settings:
    • Negative precision settings now always cause useful error messages (pull 2261).
    • An invalid regex in the --contexts option (or the [report] contexts setting) reported a confusing “Couldn’t use data file …: user-defined function raised exception” error. Now it raises a proper configuration error naming the bad regex, like other regex settings do (pull 2262).
    • Non-string values in TOML configuration settings now produce a helpful error message instead of a traceback. This affects list settings whose elements aren’t strings (like omit, exclude_lines, or a [paths] entry), file settings like data_file, and any wrong-typed value in the [paths] section (pull 2263).
    • coverage run refuses run-affecting command-line options like --branch alongside --concurrency=multiprocessing, since they can’t reach the subprocesses. The check only recognized multiprocessing as the entire option value, so --concurrency=multiprocessing,thread slipped through and failed later with “Can’t combine statement coverage data with branch data”. Each named concurrency library is now properly considered (pull 2270).
  • Fix: coverage annotate -d DIR raised an AssertionError if any measured file had an extension other than .py, such as a .pyw file on Windows. The original extension is now restored on the annotated copy (pull 2265).

➡️  PyPI page: coverage 7.16.0. :arrow_right:  To install: python3 -m pip install coverage==7.16.0

7.15.4

Version 7.15.4 — 2026-08-06

  • Fix: in the HTML report, a source file name containing a double quote (legal on POSIX) wasn’t escaped where it’s dropped into the href of the index and prev/next links, so it could close the attribute early and inject markup. Page URLs are now escaped. Thanks, Rajath Mohare.
  • Fix: the LCOV report wrote file names and other fields into its line-oriented records without neutralizing control characters. A measured file whose name contained a newline (legal on POSIX) could forge extra records, inflating the coverage seen by tools that read the report. Control characters in a field are now replaced. Thanks, Rajath Mohare.
  • Wheels are now provided for Python 3.15.

➡️  PyPI page: coverage 7.15.4. :arrow_right:  To install: python3 -m pip install coverage==7.15.4

7.15.3

Version 7.15.3 — 2026-08-02

  • Fix: the sysmon core is incompatible with dynamic contexts. Previously, the combination would be prevented when read from the coverage.py configuration. But using the context API as pytest-cov does, contexts would be silently dropped. Now a warning is issued, thanks to Jisang Han. Closes issue 2200.
  • A performance improvement in the low-level line number bookkeeping when combining data files, thanks to Kevin Turcios.

... (truncated)

Changelog

Sourced from coverage's changelog.

Version 7.16.2 — 2026-09-27

  • Fix: on Python 3.14 and later, a for loop completing immediately before a function return could mistakenly report an uncovered branch. This is now fixed, closing issue 2168_.

  • Fix: on Python 3.14 and later, the else clause of a try whose body is a with statement could incorrectly be reported as covered when the with raised. This is now fixed, closing issue 2289_.

  • Fix: with dynamic_context = test_function, test methods written as @staticmethod or @classmethod were not given a context of their own. Now they are, on Python 3.11 and later. Closes issue 1923_.

.. _issue 1923: coveragepy/coveragepy#1923 .. _issue 2168: coveragepy/coveragepy#2168 .. _issue 2289: coveragepy/coveragepy#2289

.. _changes_7-16-1:

Version 7.16.1 — 2026-09-13

  • Fix: when the body of an irrefutable case (like case _:) is entirely excluded, the case line is now excluded too, just as an excluded else: body removes the else: line. Previously the case line was left behind and reported as missing. Closes issue 1563_ with pull 2269_.

  • Fix: using :meth:.CoverageData.update twice on an in-memory database would fail, as described in issue 2279_. This is now fixed.

.. _issue 1563: coveragepy/coveragepy#1563 .. _pull 2269: coveragepy/coveragepy#2269 .. _issue 2279: coveragepy/coveragepy#2279

.. _changes_7-16-0:

Version 7.16.0 — 2026-08-28

  • When combining files, now path separator slashes will automatically be converted to the local file system style. This makes it less necessary to define [paths] configuration to combine data across operating systems. Fixes issue 2266_.

  • The :meth:.Coverage.switch_context method now returns the previous context.

  • Fix: previously, a [paths] pattern would be replaced everywhere in a file

... (truncated)

Commits

Updates mypy from 2.3.0 to 2.4.0

Changelog

Sourced from mypy's changelog.

Mypy Release Notes

Next Release

Mypy 2.4

We've just uploaded mypy 2.4.0 to the Python Package Index (PyPI). Mypy is a static type checker for Python. This release includes new features, performance improvements and bug fixes. You can install it as follows:

python3 -m pip install -U mypy

You can read the full documentation for this release on Read the Docs.

Python 3.15 Support

Mypy 2.4 supports running on Python 3.15 and type checking most Python 3.15 features. This includes the new builtin sentinel type for sentinel values (PEP 661), which mypy now supports (see below for details). Lazy imports (PEP 810) and unpacking in comprehensions (PEP 798) are also supported. Closed TypedDicts (PEP 728) have been supported since mypy 2.2, but the extra_items TypedDict argument, also introduced in PEP 728, is still unsupported. Support for extra_items will be added in a future mypy release.

Native Parser Enabled by Default

Mypy now uses the new native parser by default. It's based on the Ruff parser, and it's significantly faster than the legacy parser, which uses the stdlib ast module. The native parser also has other benefits:

  • You can target newer Python versions and use recent Python syntax even when running mypy on an older Python version. For example, you can use --python-version 3.15 when running mypy on Python 3.14.
  • Stub files can use syntax that is newer than the target Python version. For example, stubs can use the PEP 695 generic class syntax (class Box[T]: ...) when running on or targeting Python 3.10.
  • Parallel type checking requires the native parser.

The legacy parser is still available through --no-native-parser, or native_parser = False in the config file (native_parser = false under [tool.mypy] in pyproject.toml). We are planning to remove the legacy parser in early 2027. If you run into a problem with the native parser, please report it on the issue tracker.

Unlike the legacy parser, the native parser doesn't support type comments for variables defined by for and with statements. These type comments are silently ignored, and the types of the variables are

... (truncated)

Commits

Updates types-requests from 2.33.0.20260712 to 2.33.0.20260906

Commits

Updates validate-pyproject from 0.25 to 0.26

Release notes

Sourced from validate-pyproject's releases.

0.26

What's Changed

New Features

Main Fixes and Improvements

  • Allowed multiple schemas describing the same tool when the schema definitions are identical, by @​henryiii (#303).
  • Improved SchemaStore compatibility by supporting relative schema URLs, by @​henryiii (#306).
  • Fixed filtering of multi_schema entry points before loading, by @​henryiii (#318).
  • Added network request timeouts to avoid indefinite blocking, by @​henryiii (#319).

Contributors

Special thanks to @​henryiii, as well as @​DimitriPapadopoulos and all other contributors who helped improve the project.

Full Changelog: abravalheri/validate-pyproject@v0.25...0.26

Changelog

Sourced from validate-pyproject's changelog.

Version 0.26

  • Add support for :pep:808 partially dynamic metadata by :user:henryiii (:pr:314)
  • Allow multiple schemas describing the same tool when the schema definitions are identical by :user:henryiii (:pr:303)
  • Improve SchemaStore compatibility by supporting relative schema URLs by :user:henryiii (:pr:306)
  • Apply filtering before loading validate_pyproject.multi_schema entry points by :user:henryiii (:pr:318)
  • Add timeouts to network requests to avoid indefinite blocking by :user:henryiii (:pr:319)
Commits
  • 17e1277 Update CHANGELOG for version 0.26
  • d097f4b chore(deps): bump astral-sh/setup-uv in the actions group (#332)
  • 14f4cdc Populate changelog for upcoming version
  • c2f3d75 feat: implement PEP 808 (partially dynamic metadata)
  • a6441c6 refactor: clarify PEP 808 error message and add fixtures
  • 04032da fix: revert URL now that the guidelines are updated
  • 7c0b759 style: pre-commit fixes
  • a8b20a4 feat: implement PEP 808 — partially dynamic metadata
  • 0076413 chore(deps): update pre-commit hooks (#331)
  • 92829d8 chore(deps): bump astral-sh/setup-uv in the actions group (#330)
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Sep 20, 2026

@sbp-bvanb sbp-bvanb left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🤖 pr-reviewer report

Verdict: ✅ Approved

Bumps coverage 7.15.2 → 7.16.0, mypy 2.3.0 → 2.3.1, types-requests 2.33.0.20260712 → 2.33.0.20260906 and validate-pyproject 0.25 → 0.26 (dev only). All upgrades, exact pins kept, fastjsonschema<2.23 still fits validate-pyproject 0.26, CI green.

Nits

  • [git] PR title / commit: Dependabot's build(deps…) subject uses build (not in feat|fix|docs|style|refactor|test|chore|ci) and is over 72 characters. Both repos accept build today, so this is a Nit. To align with the standard, set commit-message: {prefix: chore, prefix-development: chore, include: scope} per ecosystem in .github/dependabot.yml.

🤖 doc-reviewer report

Verdict: ⚠️ No findings from this diff

The root README has no ## Quickstart, keeps configuration/development/test material inline and there is no docs/. This exists on main already and is tracked in #69, so it is not repeated here.

🤖 dependency-reviewer report

Verdict: ⚠️ Approved with comments

Should fix

  • [outdated] pyproject.toml:15: coverage 7.16.0 → 7.16.2
  • [outdated] pyproject.toml:16: mypy 2.3.1 → 2.4.0
  • [outdated] pyproject.toml:19: types-requests 2.33.0.20260906 → 2.33.0.20261006

These releases came out after Dependabot opened the PR; @dependabot recreate picks them up.

Up to date: mypy-extensions 1.1.0, pytest-cov 7.1.0, validate-pyproject 0.26.


Generated by mcvs_review 3.1.0 (pr-reviewer, doc-reviewer, dependency-reviewer) at commit 560838d.

Comment thread pyproject.toml Outdated
Comment thread pyproject.toml Outdated
Comment thread pyproject.toml
@030

030 commented Oct 10, 2026

Copy link
Copy Markdown
Owner

@dependabot rebase

…ates

Bumps the pip-all group with 4 updates in the / directory: [coverage](https://github.com/coveragepy/coveragepy), [mypy](https://github.com/python/mypy), [types-requests](https://github.com/python/typeshed) and [validate-pyproject](https://github.com/abravalheri/validate-pyproject).


Updates `coverage` from 7.15.2 to 7.16.2
- [Release notes](https://github.com/coveragepy/coveragepy/releases)
- [Changelog](https://github.com/coveragepy/coveragepy/blob/main/CHANGES.rst)
- [Commits](coveragepy/coveragepy@7.15.2...7.16.2)

Updates `mypy` from 2.3.0 to 2.4.0
- [Changelog](https://github.com/python/mypy/blob/master/CHANGELOG.md)
- [Commits](python/mypy@v2.3.0...v2.4.0)

Updates `types-requests` from 2.33.0.20260712 to 2.33.0.20260906
- [Commits](https://github.com/python/typeshed/commits)

Updates `validate-pyproject` from 0.25 to 0.26
- [Release notes](https://github.com/abravalheri/validate-pyproject/releases)
- [Changelog](https://github.com/abravalheri/validate-pyproject/blob/main/CHANGELOG.rst)
- [Commits](abravalheri/validate-pyproject@v0.25...0.26)

---
updated-dependencies:
- dependency-name: coverage
  dependency-version: 7.16.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: pip-all
- dependency-name: mypy
  dependency-version: 2.3.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: pip-all
- dependency-name: types-requests
  dependency-version: 2.33.0.20260906
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: pip-all
- dependency-name: validate-pyproject
  dependency-version: '0.26'
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: pip-all
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/pip/pip-all-98b5ece1d3 branch from 560838d to 96a6fab Compare October 10, 2026 17:26
@030
030 merged commit 720767a into main Oct 10, 2026
9 checks passed
@030
030 deleted the dependabot/pip/pip-all-98b5ece1d3 branch October 10, 2026 17:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants