Skip to content

Update all dependencies - #5692

Merged
jtraglia merged 1 commit into
masterfrom
renovate/all
Sep 28, 2026
Merged

jtraglia merged 1 commit into
masterfrom
renovate/all

Conversation

@renovate

@renovate renovate Bot commented Sep 28, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change Age Confidence
astral-sh/setup-uv action minor v10.1.0 → v10.2.0 age confidence
ty (changelog) project.optional-dependencies patch ==0.0.82 → ==0.0.84 age confidence
zensical (changelog) project.optional-dependencies patch ==0.0.63 → ==0.0.65 age confidence

Release Notes

astral-sh/setup-uv (astral-sh/setup-uv)

v10.2.0

Compare Source

astral-sh/ty (ty)

v0.0.84

Compare Source

Released on 2026-09-24.

This release addresses GHSA-vxvm-j4xq-q7m4, a use-after-free vulnerability during incremental type checking that can result in arbitrary code execution when analyzing a specially crafted Python project. Users who run ty on untrusted code should upgrade to 0.0.84 or newer.

Bug fixes
  • Fix stale diagnostics from the LSP server after toggling showSyntaxErrors (#​28759)
LSP server
  • Complete string keys from dictionary initializers (#​28820)
  • Support LSP requests against closed documents (#​28595)
  • Select projects for external files using import search paths (#​28594)
  • Use workspace editor settings for external files (#​28639)
Performance
  • Avoid repeated subtyping checks for materialized recursive protocols (#​28774)
  • Skip reading notebooks when discovering scripts (#​28781)
Core type checking
  • Avoid incorrect simplification of TypeIs materializations (#​28817)
  • Fix disjointness of generic class types (#​28787)
  • Fix staticmethod shadowing through generic receivers and unions (#​28766)
  • Infer callable signatures from bounded type variables (#​28599)
  • Infer constant membership in inline list and set literals (e.g. "foo" in ["foo"] is now inferred as Literal[True]) (#​28676)
  • Infer through optional generic containers in the legacy solver (#​28791)
  • Preserve call narrowing during cyclic inference (#​28708)
  • Preserve intersections of type guard return types (#​28796)
  • Use subtyping for constraint-set implication (#​28657)
Configuration
  • Disable invalid-legacy-positional-parameter by default (#​28834)
Other changes
  • Only consider reachable definitions when determining whether a condition should be exempted from redundant-condition(-strict) due to the condition being defined relative to sys.version_info, sys.platform, os.name or typing.TYPE_CHECKING (#​28788)
Contributors

v0.0.83

Compare Source

Released on 2026-09-21.

Bug fixes
  • Fix hangs from repeated partial application (#​28754)
  • Preserve PEP 695 bindings across nested classes (#​28723)
LSP server
  • Include required imports in every inlay hint (#​28724)
  • Preserve fast name filtering for normalized Unicode source (#​28701)
  • Refresh diagnostics after workspace configuration changes (#​28755)
Diagnostic improvements
  • Expand unreachable-code annotations for redundant conditions (#​28674)
  • Improve diagnostics for async generator stubs (#​28692)
  • Improve primary diagnostic annotations for redundant-condition(-strict) diagnostics (#​28666)
  • Point misplaced tuple ellipsis diagnostics at each ellipsis (#​28709)
Other changes
  • Add rules that detect suspicious uses of Callable, Iterable, Iterator or Generator types in a boolean context (#​28554)
  • Allow slots to override abstract properties (#​28698)
  • Avoid leaking Unknown from unconstrained collection use-sites (#​28659)
  • Diagnose unguarded cycles in implicit and PEP 613 aliases (#​28704)
  • Eagerly bind unused Self receivers (#​28662)
  • Generalize receiver binding for wrapped callables (#​28725)
  • More faithful representation of bound methods (#​28410)
  • Only classify evidence bounds for constrained type variables (#​28700)
  • Preserve inferred bindings during annotation cycles (#​28717)
  • Preserve quoted aliases during cycle recovery (#​28710)
  • Reject class-scoped type variables in init receivers (#​28706)
  • Reject unsafe TypedDict updates from hidden fields (#​28711)
  • Respect fixed caller type variables when selecting constraints (#​28652)
  • Reuse cached type alias inference for diagnostics (#​28696)
  • Simplify unions of disjoint exclusions (#​28684)
  • Update typing conformance suite (#​28718)
Contributors
zensical/zensical (zensical)

v0.0.65: 0.0.65

Compare Source

Summary

This version expands MkDocs compatibility with a native replacement for the rss plugin and support for mkdocstrings backlinks. Zensical can now generate RSS 2.0 and JSON Feed 1.1 feeds for created and updated pages. Python API documentation can also show which pages reference a documented object, with backlinks kept current across cached builds.

Changelog

Features
  • e7876ab zensical, compat – support mike's version_selector setting
  • 25b95e9 zensical, compat – support mkdocstrings' enable_inventory setting
  • 0223fc9 compat – support more macros settings
  • acee89a zensical, compat – support autorefs settings
  • 0291923 zensical, compat – support mkdocstrings backlinks
  • c214988 zensical, compat – add rss plugin replacement (#​443)
Bug fixes
  • cf68f6d zensical, compat – resolve source links to published post URLs (#​966)

v0.0.64: 0.0.64

Compare Source

Summary

Many of you have been waiting for this one: Zensical now includes native blog support. As a direct port of the Material for MkDocs blog plugin, it preserves the familiar configuration, metadata, URLs, archives, categories, authors, pagination, and more. We're happy to finally put it into your hands, with more flexible blogging functionality planned for the future.

Changelog
Features
  • 5825381 zensical, compat, ui – add blog plugin replacement
Bug fixes
  • a85875e ui – update ui to v0.0.32

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • "before 12pm on monday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the dependencies A dependency update label Sep 28, 2026
@jtraglia
jtraglia merged commit e5f71d3 into master Sep 28, 2026
19 checks passed
@jtraglia
jtraglia deleted the renovate/all branch September 28, 2026 01:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies A dependency update

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant