Skip to content

build(deps): bump the python group with 4 updates - #433

Merged
RonnyPfannschmidt merged 1 commit into
mainfrom
dependabot/uv/python-8ea2f396e4
Oct 7, 2026
Merged

RonnyPfannschmidt merged 1 commit into
mainfrom
dependabot/uv/python-8ea2f396e4

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 7, 2026

Copy link
Copy Markdown
Contributor

Bumps the python group with 4 updates: tox, hatch, uv and gevent.

Updates tox from 4.60.0 to 4.64.8

Release notes

Sourced from tox's releases.

v4.64.8

What's Changed

New Contributors

Full Changelog: tox-dev/tox@4.64.7...4.64.8

v4.64.7

What's Changed

Full Changelog: tox-dev/tox@4.64.6...4.64.7

v4.64.6

What's Changed

New Contributors

Full Changelog: tox-dev/tox@4.64.5...4.64.6

v4.64.5

What's Changed

New Contributors

Full Changelog: tox-dev/tox@4.64.4...4.64.5

... (truncated)

Changelog

Sourced from tox's changelog.

Bug fixes - 4.64.8

  • tox combines --no-binary and --only-binary across the lines of deps and of requirements files the way pip does, where the last line used to replace the earlier ones. With --only-binary :all: and a --no-binary exception, tox passes --only-binary to pip first, so pip keeps the exception. tox config shows the merged values tox passes to pip - by :user:SulimanAbdulrazzaq. (:issue:4110)
  • tox config shows deps with every global option merged the way tox passes it to pip, a later -i replacing an earlier one and repeated flags shown once, and reports the error tox run would raise for invalid deps. constraints shows the configured files instead of the path of tox.ini, and a comment line in constraints no longer fails the run. deps that give pip nothing to install no longer conflict with pylock. set_env includes PIP_USER, TOX_ENV_DIR, TOX_ENV_NAME, TOX_WORK_DIR and VIRTUAL_ENV, the values tox sets for commands - by :user:gaborbernat. (:issue:4111)
  • A TOML ref to another environment's deps, constraints or commands works in tox config and tox run. It used to fail with 'PythonDeps' object is not iterable or Command(args=[...]) is not list - by :user:gaborbernat. (:issue:4112)
  • In INI commands, commands_pre and commands_post, a reference such as pip install {[testenv:x]deps} that shares its line with other text joins the referenced lines into that one command as arguments, as in tox 3. tox used to run each referenced line after the first as a separate command. A reference alone on its line still expands to one command per referenced line. This changes echo {[testenv:x]commands}, which now runs one echo with every referenced command as its arguments - by :user:gaborbernat. (:issue:4113)
  • The JSON schema described :ref:requires with the text of :ref:provision_tox_env, so editors showed the wrong hover for it - by :user:gaborbernat. (:issue:4115)

Improved documentation - 4.64.8

  • The configuration reference listed wrong defaults for :ref:args_are_paths (True), :ref:pkg_dir ({env_dir}/dist), :ref:skip_missing_interpreters (False), :ref:min_version (unset) and :ref:requires (tox) - by :user:Rodrigo-Palma. (:issue:4114)

v4.64.7 (2026-10-01)


Bug fixes - 4.64.7

  • tox man suggests ~/.profile instead of ~/.zshrc when the shell is not fish, bash, zsh, csh or tcsh, for example sh, ksh or an unset SHELL - by :user:Rodrigo-Palma.

    • tox picks the shell from the executable name, so /home/zshuser/bin/bash gets ~/.bashrc.
    • Outside fish, csh and tcsh, the reload hint reads . <file> instead of source <file>, since dash has no source.
    • The fish line keeps the default man path when MANPATH was unset, instead of hiding every other man page.
    • csh and tcsh get a setenv line for ~/.tcshrc or ~/.cshrc instead of an export line for ~/.profile. (:issue:4109)

v4.64.6 (2026-10-01)

... (truncated)

Commits
  • e2b0ccb release 4.64.8
  • 1df83f1 🐛 fix(config): show deps, constraints and set_env as tox run uses them (#4111)
  • 7ed4d2a 📝 docs(config): fix five wrong defaults in the reference (#4114)
  • 4f6fbe2 🐛 fix(config): describe requires in the JSON schema (#4115)
  • 7b877e6 🐛 fix(config): keep in-line INI references one command (#4113)
  • 3cb3208 🐛 fix(config): let TOML ref read deps and commands (#4112)
  • 21b212b 🐛 fix(pip): combine --no-binary and --only-binary across requirement lines (#...
  • a45f1fa release 4.64.7
  • 3e5db9e fix(man): give each shell a working MANPATH line (#4109)
  • 03160bc release 4.64.6
  • Additional commits viewable in compare view

Updates hatch from 1.18.0 to 1.18.1

Release notes

Sourced from hatch's releases.

Hatch v1.18.1

Added:

  • Apply context formatting to the lock-filename environment option so fields such as {env_name} and {matrix:...} are resolved when computing the lock file path.

Fixed:

  • Consolidate extras and feature resolution into a single code path, fixing regressions where environment and project extras could be dropped or resolved inconsistently, and always validate undefined features.

  • Normalize hyphens in the plugin name when building environment option environment variable names in get_env_var(), so options for hyphenated plugins resolve to the correct variable.

Commits

Updates uv from 0.12.5 to 0.12.23

Release notes

Sourced from uv's releases.

0.12.23

Release Notes

Released on 2026-10-03.

Python

  • Add CPython 3.15.0rc3 (#22164)

Preview features

  • Sync from uv.lock without a workspace manifest using uv sync --frozen with frozen-lockfile (#22018)
  • Export from uv.lock without a workspace manifest using uv export --frozen with frozen-lockfile (#22007)
  • Inspect dependency trees from uv.lock without a workspace manifest using uv tree --frozen with frozen-lockfile (#22016)
  • Inspect workspace metadata and optionally sync its environment from uv.lock without a workspace manifest using uv workspace metadata --frozen with frozen-lockfile (#22017, #22018)

Bug fixes

  • Reject alternate sources for workspace members across conflicting dependency selections, avoiding lockfiles that cannot be installed (#22153)
  • Allow x86-64 Python interpreters running under emulation on Windows ARM64 to install compatible win_amd64 wheels instead of building from source (#22099)

Install uv 0.12.23

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.23/uv-installer.sh | sh

Install prebuilt binaries via powershell script

powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.23/uv-installer.ps1 | iex"

Download uv 0.12.23

File Platform Checksum
uv-aarch64-apple-darwin.tar.gz Apple Silicon macOS checksum
uv-x86_64-apple-darwin.tar.gz Intel macOS checksum
uv-aarch64-pc-windows-msvc.zip ARM64 Windows checksum
uv-i686-pc-windows-msvc.zip x86 Windows checksum
uv-x86_64-pc-windows-msvc.zip x64 Windows checksum
uv-aarch64-unknown-linux-gnu.tar.gz ARM64 Linux checksum
uv-i686-unknown-linux-gnu.tar.gz x86 Linux checksum
uv-powerpc64le-unknown-linux-gnu.tar.gz PPC64LE Linux checksum
uv-riscv64gc-unknown-linux-gnu.tar.gz RISCV Linux checksum
uv-s390x-unknown-linux-gnu.tar.gz S390x Linux checksum
uv-x86_64-unknown-linux-gnu.tar.gz x64 Linux checksum

... (truncated)

Changelog

Sourced from uv's changelog.

0.12.23

Released on 2026-10-03.

Python

  • Add CPython 3.15.0rc3 (#22164)

Preview features

  • Sync from uv.lock without a workspace manifest using uv sync --frozen with frozen-lockfile (#22018)
  • Export from uv.lock without a workspace manifest using uv export --frozen with frozen-lockfile (#22007)
  • Inspect dependency trees from uv.lock without a workspace manifest using uv tree --frozen with frozen-lockfile (#22016)
  • Inspect workspace metadata and optionally sync its environment from uv.lock without a workspace manifest using uv workspace metadata --frozen with frozen-lockfile (#22017, #22018)

Bug fixes

  • Reject alternate sources for workspace members across conflicting dependency selections, avoiding lockfiles that cannot be installed (#22153)
  • Allow x86-64 Python interpreters running under emulation on Windows ARM64 to install compatible win_amd64 wheels instead of building from source (#22099)

0.12.22

Released on 2026-10-01.

Python

  • Add CPython 3.10.22, 3.11.17, 3.12.15, 3.13.16, and 3.14.8 (#22147)

Enhancements

  • Accept uppercase release suffixes in wheel platform tags (#22113)
  • Record workspace-member default groups in lockfiles (#22010, #22103)
  • Record workspace-member dependency-group Python requirements in lockfiles (#22044, #22103)
  • Record default groups for non-project workspace roots in lockfiles (#22104)
  • Record dependency-group Python requirements for non-project workspace roots in lockfiles (#22104)
  • Format URLs and paths consistently in CLI messages (#21937)
  • Hide the unsupported --offline option from uv publish help (#22124)

Preview features

  • Honor --no-default-groups in uv audit (#22090)
  • Report a clear error when uv audit or uv tool audit runs offline and hide the unsupported option from help (#22114)

Configuration

  • Add UV_PYTHON_ARCH to select an interpreter architecture independently of its Python version (#22098)

Performance

  • Reduce uv's binary size by compressing embedded Python download metadata (#22126)

... (truncated)

Commits

Updates gevent from 26.8.0 to 26.9.0

Commits
  • 003c77a Preparing release 26.9.0
  • 725ecc3 Merge pull request #2209 from bojanz/issue2207-resolve-result-on-setup-failure
  • a5b68e8 Adjust the ThreadPool after an unexpected worker exit
  • 67a7256 Resolve the ThreadResult when worker task setup fails
  • a3b307b Add change note for #2211 / #2039 [skip ci]
  • b0ec8d3 Merge pull request #2211 from afonsojanu/fix/subprocess-stdin-mode-missing-bi...
  • 29b0030 Merge pull request #2210 from Shivakarthikeya23/issue-1946
  • 47ea41c Merge pull request #2208 from bojanz/issue2206-skip-missing-hooks
  • 0ee0c83 Report the full binary mode string from FileObjectPosix
  • 3f3dc57 Fix AsyncResult accumulating traceback frames on repeated get()
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the python group with 4 updates: [tox](https://github.com/tox-dev/tox), [hatch](https://github.com/pypa/hatch), [uv](https://github.com/astral-sh/uv) and [gevent](https://github.com/gevent/gevent).


Updates `tox` from 4.60.0 to 4.64.8
- [Release notes](https://github.com/tox-dev/tox/releases)
- [Changelog](https://github.com/tox-dev/tox/blob/main/docs/changelog.rst)
- [Commits](tox-dev/tox@4.60.0...4.64.8)

Updates `hatch` from 1.18.0 to 1.18.1
- [Release notes](https://github.com/pypa/hatch/releases)
- [Commits](pypa/hatch@hatch-v1.18.0...hatch-v1.18.1)

Updates `uv` from 0.12.5 to 0.12.23
- [Release notes](https://github.com/astral-sh/uv/releases)
- [Changelog](https://github.com/astral-sh/uv/blob/main/CHANGELOG.md)
- [Commits](astral-sh/uv@0.12.5...0.12.23)

Updates `gevent` from 26.8.0 to 26.9.0
- [Release notes](https://github.com/gevent/gevent/releases)
- [Changelog](https://github.com/gevent/gevent/blob/master/docs/changelog_pre.rst)
- [Commits](gevent/gevent@26.8.0...26.9.0)

---
updated-dependencies:
- dependency-name: tox
  dependency-version: 4.64.8
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python
- dependency-name: hatch
  dependency-version: 1.18.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python
- dependency-name: uv
  dependency-version: 0.12.23
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python
- dependency-name: gevent
  dependency-version: 26.9.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels Oct 7, 2026
@RonnyPfannschmidt
RonnyPfannschmidt merged commit 0b9851a into main Oct 7, 2026
18 checks passed
@RonnyPfannschmidt
RonnyPfannschmidt deleted the dependabot/uv/python-8ea2f396e4 branch October 7, 2026 06:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant