Skip to content

chore(deps)(deps): bump the dev-tools group with 2 updates - #288

Merged
cryptoxdog merged 5 commits into
mainfrom
dependabot/pip/dev-tools-bdd57b431d
Sep 24, 2026
Merged

cryptoxdog merged 5 commits into
mainfrom
dependabot/pip/dev-tools-bdd57b431d

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 21, 2026

Copy link
Copy Markdown
Contributor

Bumps the dev-tools group with 2 updates: ruff and mypy.

Updates ruff from 0.15.12 to 0.16.8

Release notes

Sourced from ruff's releases.

0.16.8

Release Notes

Released on 2026-09-16.

Bug fixes

  • Visit functional TypedDict keyword arguments correctly (#28584)
  • [flake8-simplify] Detect nested async with under sync parent (SIM117) (#27821)
  • [flake8-simplify] Preserve operand order in SIM109 fix (#27824)
  • [pyupgrade] Preserve required parentheses in multiline UP040 fixes (#28164)
  • [pyupgrade] Skip TypeVarTuple and ParamSpec conversions with bounds or constraints (UP040, UP046, UP047) (#28505)

Rule changes

  • Add support for __lazy_modules__ (#28459)
  • Recognize PEP-728 TypedDict class keywords (#28533)
  • Recognize quoted types in typing.TypeForm (#28507)
  • Support conditional assignment to __lazy_modules__ (#28491)
  • [flake8-type-checking] Prefer lazy imports over TYPE_CHECKING on Python 3.15 and later (TC001, TC002, TC003) (#28541)
  • [pyupgrade] Make the fix for UP040 always unsafe (#28526)
  • [pyupgrade] Stop recommending deprecated ByteString aliases (UP035) (#28498)
  • [ruff, flake8-use-pathlib] Recognize the parent_mode argument (RUF064, PTH103) (#28528)
  • [ruff] Detect \Z in pytest.raises() match patterns (RUF043) (#28598)

CLI

  • Use rule name and code in formatter incompatibility warnings (#28571)

Configuration

  • [flake8-tidy-imports] Add extend-banned-api (#28644)

Contributors

Install ruff 0.16.8

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/ruff/releases/download/0.16.8/ruff-installer.sh | sh
</tr></table> 

... (truncated)

Changelog

Sourced from ruff's changelog.

0.16.8

Released on 2026-09-16.

Bug fixes

  • Visit functional TypedDict keyword arguments correctly (#28584)
  • [flake8-simplify] Detect nested async with under sync parent (SIM117) (#27821)
  • [flake8-simplify] Preserve operand order in SIM109 fix (#27824)
  • [pyupgrade] Preserve required parentheses in multiline UP040 fixes (#28164)
  • [pyupgrade] Skip TypeVarTuple and ParamSpec conversions with bounds or constraints (UP040, UP046, UP047) (#28505)

Rule changes

  • Add support for __lazy_modules__ (#28459)
  • Recognize PEP-728 TypedDict class keywords (#28533)
  • Recognize quoted types in typing.TypeForm (#28507)
  • Support conditional assignment to __lazy_modules__ (#28491)
  • [flake8-type-checking] Prefer lazy imports over TYPE_CHECKING on Python 3.15 and later (TC001, TC002, TC003) (#28541)
  • [pyupgrade] Make the fix for UP040 always unsafe (#28526)
  • [pyupgrade] Stop recommending deprecated ByteString aliases (UP035) (#28498)
  • [ruff, flake8-use-pathlib] Recognize the parent_mode argument (RUF064, PTH103) (#28528)
  • [ruff] Detect \Z in pytest.raises() match patterns (RUF043) (#28598)

CLI

  • Use rule name and code in formatter incompatibility warnings (#28571)

Configuration

  • [flake8-tidy-imports] Add extend-banned-api (#28644)

Contributors

0.16.7

Released on 2026-09-10.

Preview features

  • [ruff] Add rule for default values on method receivers (RUF077) (#26700)

... (truncated)

Commits
  • 62914c4 Bump version to 0.16.8 (#28648)
  • c47e0cd [ty] Bound aliased intersection expansion during inference (#28546)
  • ff4747b renovate: update uv hashes correctly with setup-uv (#28621)
  • 94efeaa [ty] Compact reachable binding and declaration histories (#28349)
  • 50020fb [ty] Avoid storing constraint nodes twice (#28375)
  • 446bb68 [ty] Compare bound-method receivers before signatures (#28384)
  • 304ab86 [flake8-type-checking] Prefer lazy imports over TYPE_CHECKING on 3.15+ (`...
  • d940b24 [ty] Watch script dependencies in CLI watch mode (#28125)
  • fe9f065 [flake8-tidy-imports] Add extend-banned-api (#28644)
  • 31131db [ty] Support type[A & B] (#27124)
  • Additional commits viewable in compare view

Updates mypy from 1.14.0 to 2.3.1

Changelog

Sourced from mypy's changelog.

Mypy 2.3.1

  • Fix mypyc crash on double yielding Iterators (Daniël van Noord, PR 21826)
  • Fix mypyc default_factory for inherited dataclass (Daniël van Noord, PR 21785)
  • Clear mypyc coroutine env on coroutine completion (Piotr Sawicki, PR 21734)
  • Fix crash when unpacking return value from overload (Shantanu, PR 21830)

Acknowledgements

Thanks to all mypy contributors who contributed to this release:

  • Agriya Khetarpal
  • Ethan Sarp
  • Ivan Levkivskyi
  • Jingchen Ye
  • Jukka Lehtosalo
  • Piotr Sawicki
  • Shantanu
  • Tom Bannink
  • Viktor Szépe
  • ygale

I'd also like to thank my employer, Dropbox, for supporting mypy development.

Mypy 2.2

We've just uploaded mypy 2.2.0 to the Python Package Index (PyPI). Mypy is a static type checker for Python. This release includes new features, performance improvements and bug fixes. You can install it as follows:

python3 -m pip install -U mypy

You can read the full documentation for this release on Read the Docs.

Support for Closed TypedDicts (PEP 728)

Mypy now supports closed TypedDicts as specified in PEP 728. A closed TypedDict cannot have extra keys beyond those explicitly defined. This allows the type checker to determine that certain operations are safe when they otherwise wouldn't be due to the potential presence of unknown keys.

You can use the closed keyword argument with TypedDict:

HasName = TypedDict("HasName", {"name": str})
HasOnlyName = TypedDict("HasOnlyName", {"name": str}, closed=True)
Movie = TypedDict("Movie", {"name": str, "year": int})
movie: Movie = {"name": "Nimona", "year": 2023}
has_name: HasName = movie  # OK: HasName is open (default)
has_only_name: HasOnlyName = movie  # Error: HasOnlyName is closed and Movie has extra "year" key
</tr></table>

... (truncated)

Commits
  • d642c44 Bump version to 2.3.1
  • a392429 [mypyc] Fix crash on double yielding Iterators (#21826)
  • 4843e77 [mypyc] Fix default_factory for inherited dataclass (#21785)
  • 14f5df9 [mypyc] Clear coroutine env on coroutine completion (#21734)
  • 6dfa06d Fix crash when unpacking return value from overload (#21830)
  • a385746 Bump version to 2.3.1+dev
  • 8aabf84 Drop +dev from version
  • 4d8ad2a Update changelog for 2.3 release (#21728)
  • 2c21546 [mypyc] Update documentation of race conditions under free threading (#21726)
  • a9f62a3 [mypyc] Make attribute access memory safe on free-threaded builds (#21705)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the dev-tools group with 2 updates: [ruff](https://github.com/astral-sh/ruff) and [mypy](https://github.com/python/mypy).


Updates `ruff` from 0.15.12 to 0.16.8
- [Release notes](https://github.com/astral-sh/ruff/releases)
- [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md)
- [Commits](astral-sh/ruff@0.15.12...0.16.8)

Updates `mypy` from 1.14.0 to 2.3.1
- [Changelog](https://github.com/python/mypy/blob/master/CHANGELOG.md)
- [Commits](python/mypy@v1.14.0...v2.3.1)

---
updated-dependencies:
- dependency-name: ruff
  dependency-version: 0.16.8
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dev-tools
- dependency-name: mypy
  dependency-version: 2.3.1
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: dev-tools
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Sep 21, 2026

Copy link
Copy Markdown
Contributor Author

Assignees

The following users could not be added as assignees: YOUR_GITHUB_USERNAME. Either the username does not exist or it does not have the correct permissions to be added as an assignee.

Labels

The following labels could not be found: automerge-candidate, dependencies, python. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot
dependabot Bot requested a review from cryptoxdog as a code owner September 21, 2026 03:08
@github-actions

github-actions Bot commented Sep 21, 2026 •

Copy link
Copy Markdown

❌ Too Many Reviewable Files Changed
Changed: 58 files
Limit: 50 files
Action Required: Split into multiple focused PRs

⚠️ Large PR Warning
Reviewable lines changed: 1831
Warning threshold: 300 lines
Consider splitting for easier review

📋 Best Practices for Large Changes

  1. Refactoring + Features: Separate into 2 PRs
  2. Multiple Features: One PR per feature
  3. Database + Code: Separate migration from logic
  4. Generated Code: Exclude it from reviewable-size accounting

🚫 This PR is blocked until reviewable size limits are met.

@github-actions

github-actions Bot commented Sep 21, 2026 •

Copy link
Copy Markdown

L9 Audit Harness Report

  • Generated: 2026-09-24T16:21:26.549834+00:00
  • Repo root: /home/runner/work/Cognitive.Engine.Graphs/Cognitive.Engine.Graphs
  • Overall result: ✅ PASSED
  • Exit code: 0

Step Results

Step Status Exit Code Notes
Architecture Audit ✅ Passed 0
Spec Coverage ✅ Passed 0
Contract Wiring ✅ Passed 0

Architecture Audit Findings

Severity Count
🔴 CRITICAL 0
🟠 HIGH 0
🟡 MEDIUM 17
🔵 LOW 0

See artifacts/audit_report.md for full details.

Spec Coverage

  • ✅ Implemented: 37
  • ⚠️ Partial: 9
  • ❌ Missing: 0
  • Total features: 46
Category Implemented Partial Missing Total
gates 10 0 0 10
scoring 7 0 0 7
v1.1_node 2 0 0 2
v1.1_edge 2 0 0 2
v1.1_action 0 2 0 2
v1.1_scoring 1 1 0 2
action_handler 0 6 0 6
gds_algorithm 5 0 0 5
research_pattern 10 0 0 10

See artifacts/coverage_report.md for full details.

Next Steps

All checks passed. Safe to merge.

…sumers

Closes audit finding F-288-001 (contract work unit R1).

The Dependabot bump moved Ruff to 0.16.8 only in pyproject/poetry.lock,
so CI (which installs from requirements-ci.txt, the declared SSOT) still
ran Ruff 0.15.12 and pre-commit still pinned ruff-pre-commit v0.15.5 and
mirrors-mypy v1.14.0.

- requirements-ci.txt, requirements-dev.txt: ruff 0.15.12 -> 0.16.8
- .pre-commit-config.yaml: ruff-pre-commit v0.15.5 -> v0.16.8,
  mirrors-mypy v1.14.0 -> v2.3.1

No rules, ignores, or excludes changed.

Remediation-Cycle: #288/cycle-1

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JuFGxFjdiHKkGEvxDvADD1
Scope extension to R1 approved by the operator: fix the findings Ruff
0.16.8 surfaces (0.15.12 was clean) rather than suppressing them. No rule
ignores, per-file ignores, or excludes were added.

PLR0917 (too-many-positional-arguments, 18 sites): parameters that call
sites already pass by keyword become keyword-only (`*`). Call sites that
passed more than five positionals were converted to keywords:
- tools/contract_scanner.py `_rule`: `remediation` is keyword-only (28 rules)
- tests/test_algorithmic_upgrades.py `_make_fp`: `entropy`, `concentration`
- tools/auditors/log_safety.py `_emit_finding`: all keyword-only
Public engine APIs touched (AuditLogger.log_*, measure_health_impact,
track_conversion_event, MultiHopTraverser) keep every required parameter
positional; only optional defaults became keyword-only, and every in-repo
caller already passes them by keyword.

ISC004 (3 sites): parenthesize the implicit string concatenations in
engine/intake/impact_reporter.py format_impact_summary.

Markdown: Ruff 0.16 formats fenced Python blocks in .md by default, and the
ruff-pre-commit v0.16.8 hook now includes markdown files. Applied
`ruff format` to 37 docs (code-fence changes only). Renamed
`docs/ACTION ITEMS.MD` -> `.md` (reference updated in
tools/l9_meta_injector.py): identify tags `.MD` as markdown but Ruff
infers language case-sensitively and parsed it as Python.

Validation: ruff check / ruff format --check clean; mypy engine/ clean
(2.3.1); pre-commit run --all-files all hooks pass; contract scanner clean;
pytest (non-integration) 2134 passed. The 4 tests/performance errors need
a Docker socket and fail the same way on the unmodified tree.

Remediation-Cycle: #288/cycle-1

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JuFGxFjdiHKkGEvxDvADD1

Copy link
Copy Markdown
Collaborator

Remediation cycle 1: closes audit finding F-288-001 (contract unit R1, with the scope extension the operator approved)

  • 90fe830: Ruff 0.16.8 is now pinned in requirements-ci.txt and requirements-dev.txt, ruff-pre-commit in .pre-commit-config.yaml is v0.16.8, and mirrors-mypy is v2.3.1. CI now actually runs the toolchain this PR targets. This commit also carries the docs/ACTION ITEMS.MD → .md rename; the next commit explains it.
  • 7b3be91: fixes the findings that Ruff 0.16.8 newly exposes. No ignores or excludes were added.
    • 18 × PLR0917: optional parameters are now keyword-only. Every required parameter on the engine APIs is still positional, and all in-repo callers already passed those parameters by keyword. The _rule, _make_fp and _emit_finding call sites were converted to keywords.
    • 3 × ISC004: the string concatenations in impact_reporter.py are now parenthesized.
    • Markdown: Ruff 0.16 formats fenced Python blocks in .md files, and the v0.16.8 hook now includes Markdown files. ruff format was applied to 37 docs, changing only code fences. docs/ACTION ITEMS.MD was renamed to .md because Ruff parsed it as Python.

Validation, run locally:

  • ruff check and ruff format --check are clean.
  • mypy engine/ is clean on 2.3.1.
  • pre-commit run --all-files passes every hook.
  • The contract scanner is clean.
  • 2134 tests passed. The 4 tests/performance errors need a Docker socket, which this container doesn't have.

Per the contract's merge DAG, the lock still has to be refreshed against current state after #286 and #290 land.


Generated by Claude Code

Copy link
Copy Markdown
Collaborator

Enforce PR Policies is red: 58 files against the 50-file reviewable-size limit. The operator approved a split rather than any change to the gate.

The Ruff 0.16 compatibility changes now also sit in two prep PRs off main. Their contents are byte-identical to this PR's files, and both are neutral under the current Ruff 0.15.12 toolchain:

Order: #296, then #297. Then merge main into this branch; no rebase or force-push is needed. The diff then shrinks to the toolchain pins plus the Dependabot lock and pyproject changes, bringing this PR under the limit. All other checks on 7b3be91 are unaffected: lint and pre-commit pass with the fixes present.


Generated by Claude Code

…elds

The "Standard Optional Fields" snippet was an indented continuation of
`class PacketEnvelope`. Ruff 0.16 Markdown formatting dedented it into
top-level assignments, which misstates the contract. Repeat the class
header so the block is valid Python and stays stable under ruff format.

Reported by Copilot review on #296.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JuFGxFjdiHKkGEvxDvADD1
Conflict only in poetry.lock. Resolved by regeneration, not by hand:
took main's lock, then `poetry lock` (Poetry 2.4.1, matching the lock
header) against the merged pyproject. The only package delta vs main is
ruff 0.16.7 -> 0.16.8; hypothesis 6.168.0 / pytest 9.1.1 / uvicorn from
main are preserved. `poetry check --lock` passes.

Validation on the merged tree: ruff check / format --check clean,
mypy engine/ clean, pytest (non-integration, non-performance) 2134
passed, contract scanner clean.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JuFGxFjdiHKkGEvxDvADD1
@sonarqubecloud

Copy link
Copy Markdown

@cryptoxdog
cryptoxdog merged commit 828ffd3 into main Sep 24, 2026
54 of 55 checks passed
@cryptoxdog
cryptoxdog deleted the dependabot/pip/dev-tools-bdd57b431d branch September 24, 2026 16:23
cryptoxdog added a commit that referenced this pull request Sep 24, 2026
…296)

* docs: pre-format Markdown code blocks for Ruff 0.16 (prep for #288)

Ruff 0.16 formats fenced Python blocks in Markdown by default, and the
ruff-pre-commit v0.16.8 hook adds markdown to its file types. #288 moves
the toolchain to Ruff 0.16.8; landing these formatting-only changes first
keeps #288 under the 50-file reviewable-size policy.

- `ruff format` (0.16.8) applied to 37 Markdown files. Only fenced code
  blocks change; the prose is untouched.
- Rename `docs/ACTION ITEMS.MD` -> `docs/ACTION ITEMS.md` and update its
  entry in tools/l9_meta_injector.py. identify tags `.MD` as markdown, but
  Ruff infers the language case-sensitively and parses the file as Python,
  so the v0.16.8 hook fails on it.

Neutral under the current toolchain (Ruff 0.15.12 does not format
Markdown): `ruff check` and `ruff format --check` pass on both 0.15.12 and
0.16.8. Content is byte-identical to the corresponding files on the #288
head (7b3be91), so merging main into #288 afterwards is conflict-free.

Refs: audit finding F-288-001 (contract work unit R1)

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JuFGxFjdiHKkGEvxDvADD1

* docs(contracts): restore class context for PacketEnvelope optional fields

The "Standard Optional Fields" snippet was an indented continuation of
`class PacketEnvelope`. Ruff 0.16 Markdown formatting dedented it into
top-level assignments, which misstates the contract. Repeat the class
header so the block is valid Python and stays stable under ruff format.

Reported by Copilot review on #296.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01JuFGxFjdiHKkGEvxDvADD1

---------

Co-authored-by: Claude <noreply@anthropic.com>
cryptoxdog added a commit that referenced this pull request Sep 24, 2026
) (#297)

Ruff 0.16 stabilizes PLR0917 (too-many-positional-arguments) and ISC004
under the already-selected `PL` and `ISC` families. #288 moves the
toolchain to Ruff 0.16.8; landing these fixes first keeps #288 under the
50-file reviewable-size policy. No rule ignores or excludes are added.

PLR0917 (18 sites): parameters that every in-repo caller already passes
by keyword become keyword-only (`*`). Required parameters of the engine
APIs (AuditLogger.log_*, measure_health_impact, track_conversion_event,
MultiHopTraverser) stay positional. Call sites passing more than five
positionals were converted to keywords: tools/contract_scanner.py `_rule`
(`remediation`, 28 rules), tests/test_algorithmic_upgrades.py `_make_fp`,
tools/auditors/log_safety.py `_emit_finding`.

ISC004 (3 sites): parenthesize the implicit string concatenations in
engine/intake/impact_reporter.py format_impact_summary.

Validation: ruff check / format --check clean on 0.15.12 and 0.16.8;
mypy engine/ clean; pytest (non-integration, non-performance) 2134
passed; contract scanner clean. Content is byte-identical to the
corresponding files on the #288 head (7b3be91).

Refs: audit finding F-288-001 (contract work unit R1)


Claude-Session: https://claude.ai/code/session_01JuFGxFjdiHKkGEvxDvADD1

Co-authored-by: Claude <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants