chore(deps)(deps): bump the dev-tools group with 2 updates - #288
Conversation
Bumps the dev-tools group with 2 updates: [ruff](https://github.com/astral-sh/ruff) and [mypy](https://github.com/python/mypy). Updates `ruff` from 0.15.12 to 0.16.8 - [Release notes](https://github.com/astral-sh/ruff/releases) - [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md) - [Commits](astral-sh/ruff@0.15.12...0.16.8) Updates `mypy` from 1.14.0 to 2.3.1 - [Changelog](https://github.com/python/mypy/blob/master/CHANGELOG.md) - [Commits](python/mypy@v1.14.0...v2.3.1) --- updated-dependencies: - dependency-name: ruff dependency-version: 0.16.8 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: dev-tools - dependency-name: mypy dependency-version: 2.3.1 dependency-type: direct:production update-type: version-update:semver-major dependency-group: dev-tools ... Signed-off-by: dependabot[bot] <support@github.com>
AssigneesThe following users could not be added as assignees: LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
|
❌ Too Many Reviewable Files Changed
📋 Best Practices for Large Changes
🚫 This PR is blocked until reviewable size limits are met. |
L9 Audit Harness Report
Step Results
Architecture Audit Findings
See Spec Coverage
See Next StepsAll checks passed. Safe to merge. |
…sumers Closes audit finding F-288-001 (contract work unit R1). The Dependabot bump moved Ruff to 0.16.8 only in pyproject/poetry.lock, so CI (which installs from requirements-ci.txt, the declared SSOT) still ran Ruff 0.15.12 and pre-commit still pinned ruff-pre-commit v0.15.5 and mirrors-mypy v1.14.0. - requirements-ci.txt, requirements-dev.txt: ruff 0.15.12 -> 0.16.8 - .pre-commit-config.yaml: ruff-pre-commit v0.15.5 -> v0.16.8, mirrors-mypy v1.14.0 -> v2.3.1 No rules, ignores, or excludes changed. Remediation-Cycle: #288/cycle-1 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01JuFGxFjdiHKkGEvxDvADD1
Scope extension to R1 approved by the operator: fix the findings Ruff 0.16.8 surfaces (0.15.12 was clean) rather than suppressing them. No rule ignores, per-file ignores, or excludes were added. PLR0917 (too-many-positional-arguments, 18 sites): parameters that call sites already pass by keyword become keyword-only (`*`). Call sites that passed more than five positionals were converted to keywords: - tools/contract_scanner.py `_rule`: `remediation` is keyword-only (28 rules) - tests/test_algorithmic_upgrades.py `_make_fp`: `entropy`, `concentration` - tools/auditors/log_safety.py `_emit_finding`: all keyword-only Public engine APIs touched (AuditLogger.log_*, measure_health_impact, track_conversion_event, MultiHopTraverser) keep every required parameter positional; only optional defaults became keyword-only, and every in-repo caller already passes them by keyword. ISC004 (3 sites): parenthesize the implicit string concatenations in engine/intake/impact_reporter.py format_impact_summary. Markdown: Ruff 0.16 formats fenced Python blocks in .md by default, and the ruff-pre-commit v0.16.8 hook now includes markdown files. Applied `ruff format` to 37 docs (code-fence changes only). Renamed `docs/ACTION ITEMS.MD` -> `.md` (reference updated in tools/l9_meta_injector.py): identify tags `.MD` as markdown but Ruff infers language case-sensitively and parsed it as Python. Validation: ruff check / ruff format --check clean; mypy engine/ clean (2.3.1); pre-commit run --all-files all hooks pass; contract scanner clean; pytest (non-integration) 2134 passed. The 4 tests/performance errors need a Docker socket and fail the same way on the unmodified tree. Remediation-Cycle: #288/cycle-1 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01JuFGxFjdiHKkGEvxDvADD1
|
Remediation cycle 1: closes audit finding F-288-001 (contract unit R1, with the scope extension the operator approved)
Validation, run locally:
Per the contract's merge DAG, the lock still has to be refreshed against current state after #286 and #290 land. Generated by Claude Code |
|
The Ruff 0.16 compatibility changes now also sit in two prep PRs off
Order: #296, then #297. Then merge Generated by Claude Code |
…elds The "Standard Optional Fields" snippet was an indented continuation of `class PacketEnvelope`. Ruff 0.16 Markdown formatting dedented it into top-level assignments, which misstates the contract. Repeat the class header so the block is valid Python and stays stable under ruff format. Reported by Copilot review on #296. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01JuFGxFjdiHKkGEvxDvADD1
Conflict only in poetry.lock. Resolved by regeneration, not by hand: took main's lock, then `poetry lock` (Poetry 2.4.1, matching the lock header) against the merged pyproject. The only package delta vs main is ruff 0.16.7 -> 0.16.8; hypothesis 6.168.0 / pytest 9.1.1 / uvicorn from main are preserved. `poetry check --lock` passes. Validation on the merged tree: ruff check / format --check clean, mypy engine/ clean, pytest (non-integration, non-performance) 2134 passed, contract scanner clean. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01JuFGxFjdiHKkGEvxDvADD1
|
…296) * docs: pre-format Markdown code blocks for Ruff 0.16 (prep for #288) Ruff 0.16 formats fenced Python blocks in Markdown by default, and the ruff-pre-commit v0.16.8 hook adds markdown to its file types. #288 moves the toolchain to Ruff 0.16.8; landing these formatting-only changes first keeps #288 under the 50-file reviewable-size policy. - `ruff format` (0.16.8) applied to 37 Markdown files. Only fenced code blocks change; the prose is untouched. - Rename `docs/ACTION ITEMS.MD` -> `docs/ACTION ITEMS.md` and update its entry in tools/l9_meta_injector.py. identify tags `.MD` as markdown, but Ruff infers the language case-sensitively and parses the file as Python, so the v0.16.8 hook fails on it. Neutral under the current toolchain (Ruff 0.15.12 does not format Markdown): `ruff check` and `ruff format --check` pass on both 0.15.12 and 0.16.8. Content is byte-identical to the corresponding files on the #288 head (7b3be91), so merging main into #288 afterwards is conflict-free. Refs: audit finding F-288-001 (contract work unit R1) Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01JuFGxFjdiHKkGEvxDvADD1 * docs(contracts): restore class context for PacketEnvelope optional fields The "Standard Optional Fields" snippet was an indented continuation of `class PacketEnvelope`. Ruff 0.16 Markdown formatting dedented it into top-level assignments, which misstates the contract. Repeat the class header so the block is valid Python and stays stable under ruff format. Reported by Copilot review on #296. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01JuFGxFjdiHKkGEvxDvADD1 --------- Co-authored-by: Claude <noreply@anthropic.com>
) (#297) Ruff 0.16 stabilizes PLR0917 (too-many-positional-arguments) and ISC004 under the already-selected `PL` and `ISC` families. #288 moves the toolchain to Ruff 0.16.8; landing these fixes first keeps #288 under the 50-file reviewable-size policy. No rule ignores or excludes are added. PLR0917 (18 sites): parameters that every in-repo caller already passes by keyword become keyword-only (`*`). Required parameters of the engine APIs (AuditLogger.log_*, measure_health_impact, track_conversion_event, MultiHopTraverser) stay positional. Call sites passing more than five positionals were converted to keywords: tools/contract_scanner.py `_rule` (`remediation`, 28 rules), tests/test_algorithmic_upgrades.py `_make_fp`, tools/auditors/log_safety.py `_emit_finding`. ISC004 (3 sites): parenthesize the implicit string concatenations in engine/intake/impact_reporter.py format_impact_summary. Validation: ruff check / format --check clean on 0.15.12 and 0.16.8; mypy engine/ clean; pytest (non-integration, non-performance) 2134 passed; contract scanner clean. Content is byte-identical to the corresponding files on the #288 head (7b3be91). Refs: audit finding F-288-001 (contract work unit R1) Claude-Session: https://claude.ai/code/session_01JuFGxFjdiHKkGEvxDvADD1 Co-authored-by: Claude <noreply@anthropic.com>



Bumps the dev-tools group with 2 updates: ruff and mypy.
Updates
rufffrom 0.15.12 to 0.16.8Release notes
Sourced from ruff's releases.
... (truncated)
Changelog
Sourced from ruff's changelog.
... (truncated)
Commits
62914c4Bump version to 0.16.8 (#28648)c47e0cd[ty] Bound aliased intersection expansion during inference (#28546)ff4747brenovate: update uv hashes correctly with setup-uv (#28621)94efeaa[ty] Compact reachable binding and declaration histories (#28349)50020fb[ty] Avoid storing constraint nodes twice (#28375)446bb68[ty] Compare bound-method receivers before signatures (#28384)304ab86[flake8-type-checking] Prefer lazy imports overTYPE_CHECKINGon 3.15+ (`...d940b24[ty] Watch script dependencies in CLI watch mode (#28125)fe9f065[flake8-tidy-imports] Addextend-banned-api(#28644)31131db[ty] Supporttype[A & B](#27124)Updates
mypyfrom 1.14.0 to 2.3.1Changelog
Sourced from mypy's changelog.
... (truncated)
Commits
d642c44Bump version to 2.3.1a392429[mypyc] Fix crash on double yielding Iterators (#21826)4843e77[mypyc] Fixdefault_factoryfor inherited dataclass (#21785)14f5df9[mypyc] Clear coroutine env on coroutine completion (#21734)6dfa06dFix crash when unpacking return value from overload (#21830)a385746Bump version to 2.3.1+dev8aabf84Drop +dev from version4d8ad2aUpdate changelog for 2.3 release (#21728)2c21546[mypyc] Update documentation of race conditions under free threading (#21726)a9f62a3[mypyc] Make attribute access memory safe on free-threaded builds (#21705)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions