Skip to content

chore(deps): bump the all-version-updates group with 9 updates - #20

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/uv/all-version-updates-4a8e496cf7
Open

dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/uv/all-version-updates-4a8e496cf7

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown
Contributor

Updates the requirements on basedpyright, ruff, hatchling, dateparser, lxml, pytz, regex, tzdata and urllib3 to permit the latest version.
Updates basedpyright from 1.39.10 to 1.40.1

Release notes

Sourced from basedpyright's releases.

v1.40.1 (pyright 1.1.414)

What's Changed

Full Changelog: DetachHead/basedpyright@v1.40.0...v1.40.1

v1.40.0 (pyright 1.1.412)

What's Changed

New Contributors

Full Changelog: DetachHead/basedpyright@v1.39.10...v1.40.0

Commits
  • e7fca69 1.40.1
  • f7b6ad0 add checks when there are multiline indents for doc strings, update (#1882)
  • 1bc4879 fix broken docs links
  • 845bfe1 move and baseline basedpyright errors in new build scripts from upstream
  • a9189ef prettier fix
  • 756bfaa fix build:extension:dev script
  • a7a2efd syncpack fix
  • 5f6749f fix tests
  • bb9b24f fix zizmor errors in new workflows from upstream
  • b8ccd0e fix compile errors from merge
  • Additional commits viewable in compare view

Updates ruff from 0.16.5 to 0.16.9

Release notes

Sourced from ruff's releases.

0.16.9

Release Notes

Released on 2026-09-24.

Preview features

  • [ruff] Avoid false positives for overloaded division (RUF069) (#28309)

Bug fixes

  • [flake8-bugbear] Avoid false positives for calls with keyword arguments (B009, B010, B043) (#28776)
  • [flake8-tidy-imports] Allow lazy imports to be used in deferred annotations (TID255) (#28767)

Rule changes

  • Update LibCST-based fixes for Python 3.15 (#28616)
  • [flake8-pyi] Mention stubs in the diagnostic message (PYI002) (#28542)

Documentation

  • Fix horizontal overflow on the rules documentation page (#28699)
  • Update rules table with category information (#28651)
  • [flake8-annotations] Clarify that ANN401 checks return types in addition to arguments (#28334)
  • [flake8-bugbear] Document type-checker interaction (B010) (#28509)
  • [flake8-comprehensions] Document map/generator exception behavior (C417) (#27794)
  • [ruff] Mention related isort settings (RUF022) (#28719)

Contributors

Install ruff 0.16.9

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/ruff/releases/download/0.16.9/ruff-installer.sh | sh

... (truncated)

Changelog

Sourced from ruff's changelog.

0.16.9

Released on 2026-09-24.

Preview features

  • [ruff] Avoid false positives for overloaded division (RUF069) (#28309)

Bug fixes

  • [flake8-bugbear] Avoid false positives for calls with keyword arguments (B009, B010, B043) (#28776)
  • [flake8-tidy-imports] Allow lazy imports to be used in deferred annotations (TID255) (#28767)

Rule changes

  • Update LibCST-based fixes for Python 3.15 (#28616)
  • [flake8-pyi] Mention stubs in the diagnostic message (PYI002) (#28542)

Documentation

  • Fix horizontal overflow on the rules documentation page (#28699)
  • Update rules table with category information (#28651)
  • [flake8-annotations] Clarify that ANN401 checks return types in addition to arguments (#28334)
  • [flake8-bugbear] Document type-checker interaction (B010) (#28509)
  • [flake8-comprehensions] Document map/generator exception behavior (C417) (#27794)
  • [ruff] Mention related isort settings (RUF022) (#28719)

Contributors

0.16.8

Released on 2026-09-16.

Bug fixes

  • Visit functional TypedDict keyword arguments correctly (#28584)
  • [flake8-simplify] Detect nested async with under sync parent (SIM117) (#27821)
  • [flake8-simplify] Preserve operand order in SIM109 fix (#27824)

... (truncated)

Commits
  • 0be08a2 Bump version to 0.16.9 (#28882)
  • b4920b7 Rename ruff_cli to ruff_command_line (#28881)
  • 47c751b Update dependency astral-sh/uv to v0.12.18 (#28880)
  • 8c244e5 [flake8-comprehensions] Document map/generator exception behavior (C417...
  • 5edf5a1 Use target form in rooster.version_files (#28876)
  • 915bb2b [ty] Prefer existing @ paths over response files in Ruff and ty (#28877)
  • 4710e1a ci(github): update version number in placeholder of issue template (#28871)
  • eedfc62 [ty] Propagate outer type context through cast calls (#28855)
  • ceaa6a0 [ty] Contain rendered code within Markdown fences (#28869)
  • dba0f30 authorize ruff-pre-commit dispatch via OIDC (#28867)
  • Additional commits viewable in compare view

Updates hatchling to 1.32.4

Release notes

Sourced from hatchling's releases.

Hatchling v1.32.4

Fixed:

  • Revert the extra type parameter added to BuildHookInterface in 1.32.3, which broke plugins that subscripted the interface with a single argument (e.g. BuildHookInterface[MyConfig]) by raising TypeError at import time. BuilderConfig is likewise no longer generic, restoring the pre-1.32.3 plugin interface.
  • Strip spaces around version metadata when using original input for CalVer to keep leading zeroes.
Commits

Updates dateparser from 1.4.2 to 1.4.3

Release notes

Sourced from dateparser's releases.

1.4.3

Fixes:

  • Make parsing thread-safe: parsing from several threads no longer raises an intermittent KeyError from the shared language caches, and a DATE_ORDER or RELATIVE_BASE value meant for one parse no longer leaks into the settings that other parses read, where it could make them return a wrong date (#1346)
  • Do not share the language detector and the detected locale between search_dates() calls, so concurrent searches over text in different languages no longer return None or a date read in the wrong locale (#1371)
  • Resolve the BST and HDT timezone abbreviations to the offsets the tz database gives them, UTC+1 (British Summer Time) and UTC-9 (Hawaii-Aleutian Daylight Time), instead of +11 and -9:30, which no zone goes by those names today; abbreviations that the tz database maps to more than one offset, such as CST and IST, keep their current offset. Text carrying these abbreviations keeps its wall clock but moves by 10 hours for BST and 30 minutes for HDT, which can put the parsed instant on a different day (#1366)
  • Reject a %j (day of year) value that the parsed year does not have, instead of rolling it over into the next year, so "1999366" with date_formats=["%Y%j"] returns None rather than 2000-01-01. A format with no year directive is checked against the year strptime defaults to, 1900, which is not a leap year, so "366" with date_formats=["%j"] now returns None where it used to return January 1 (#1370)

Cleanups and internal improvements:

  • Add CodSpeed benchmarks and a workflow that runs them, so a performance regression such as the quadratic backtracking fixed in 1.4.1 is reported on the pull request that introduces it (#1365)
Changelog

Sourced from dateparser's changelog.

1.4.3 (2026-09-03)

Fixes:

  • Make parsing thread-safe: parsing from several threads no longer raises an intermittent KeyError from the shared language caches, and a DATE_ORDER or RELATIVE_BASE value meant for one parse no longer leaks into the settings that other parses read, where it could make them return a wrong date (#1346)
  • Do not share the language detector and the detected locale between search_dates() calls, so concurrent searches over text in different languages no longer return None or a date read in the wrong locale (#1371)
  • Resolve the BST and HDT timezone abbreviations to the offsets the tz database gives them, UTC+1 (British Summer Time) and UTC-9 (Hawaii-Aleutian Daylight Time), instead of +11 and -9:30, which no zone goes by those names today; abbreviations that the tz database maps to more than one offset, such as CST and IST, keep their current offset. Text carrying these abbreviations keeps its wall clock but moves by 10 hours for BST and 30 minutes for HDT, which can put the parsed instant on a different day (#1366)
  • Reject a %j (day of year) value that the parsed year does not have, instead of rolling it over into the next year, so "1999366" with date_formats=["%Y%j"] returns None rather than 2000-01-01. A format with no year directive is checked against the year strptime defaults to, 1900, which is not a leap year, so "366" with date_formats=["%j"] now returns None where it used to return January 1 (#1370)

Cleanups and internal improvements:

  • Add CodSpeed benchmarks and a workflow that runs them, so a performance regression such as the quadratic backtracking fixed in 1.4.1 is reported on the pull request that introduces it (#1365)
Commits

Updates lxml from 6.1.2 to 6.1.3

Changelog

Sourced from lxml's changelog.

6.1.3 (2026-09-02)

Bugs fixed

  • LP#2165901: External parameter entity parsing was allowed by default (with resolve_entities="internal"). Issue found by Tomer Fichman.
Commits
  • 3c1a4c7 Prepare release of 6.1.3.
  • c1191fc Update changelog.
  • 03ec312 Disable parameter entity parsing when internal-only entity parsing is requested.
  • 11d03e9 Build: Prevent duplicate Py3.8 wheel builds.
  • 9efc586 Build: Exclude musllinux-ARM from Py3.8 wheel building to prevent slow emulat...
  • 9716fb1 Build: Include older PyPy versions.
  • 0f3327d Build: Exclude Win-Aarch64 from wheel build.
  • 6967c96 Build: Make all built wheels downloadable even if they don't pass the release...
  • 061218d Build: Exclude Py3.15 i686 wheels from validation (because they are intention...
  • ce9fe0d Build: Fix Py3.8 windows build.
  • See full diff in compare view

Updates pytz from 2026.3.post1 to 2026.4

Commits
  • 1ac6e51 Bump version numbers to 2026.4 (2026d)
  • 1672798 IANA 2026d
  • 0b5995b Squashed 'tz/' changes from 71f28b9ab3..bac9223f4b
  • e96461b Make deprecation notice louder
  • 3c7af58 Merge branch 'nicoleman0-fix/timezone-non-string-input' into 2026d
  • 234a247 Merge branch 'nicoleman0-fix/fixedoffset-basetzinfo' into 2026d
  • 8f8a588 Raise UnknownTimeZoneError for non-string zone arguments
  • 1f0f27e Make _FixedOffset a BaseTzInfo exposing _utcoffset
  • See full diff in compare view

Updates regex from 2026.7.19 to 2026.9.10

Changelog

Sourced from regex's changelog.

Version: 2026.9.29

Updated to Unicode 18.0.0.

Switched to using stdbool.h and stdint.h.

Version: 2026.9.19

Git issue 619: `Match.expand()` segfaults after `detach_string()` when the template references a group

Version: 2026.9.10

Fixed version.

Version: 2026.9.9

PR [#615](https://github.com/mrabarnett/mrab-regex/issues/615): Fix Python API error propagation in match helpers

PR #616: Preserve Python Exceptions in Input Decoding and String Detachment

PR #617: Prevent Invalid Pointer Use and Exception State Corruption in Byte String Joining

PR #618: Propagate Allocation and Internal Errors During Pattern Compilation and Scanner Execution

Version: 2026.9.3

New version of cibuildwheel no longer supports building for free-threaded Python 3.13.

Version: 2026.9.2

New version of cibuildwheel no longer needs nor supports cpython-freethreading option.

Version: 2026.9.1

Updated cibuildwheel.
Support Python 3.15.

Version: 2026.8.31

Fixed version.

Version: 2026.8.30

Git issue 611: Heap out-of-bounds write at compile time
Git issue 612: count_one() size underflow through the stale required-string cache
Git issue 613: (*SKIP) inside an atomic group, plus an equality-only scan stop
Git issue 614: build_GROUP() does not propagate the match direction

Version: 2026.8.12

... (truncated)

Commits
  • 7dd71c1 Fixed version.
  • 59124d6 PR #615: Fix Python API error propagation in match helpers
  • 25e1521 Merge pull request #618 from dynapx/fix-compiler-error-propagation
  • 3ad78cf Merge pull request #616 from dynapx/fix-detach-string-error-propagation
  • f54253c Merge pull request #615 from dynapx/fix-python-api-error-propagation
  • c442244 Propagate scanner internal errors
  • 68837e7 Propagate node stack allocation failures
  • f1df538 Propagate check stack allocation failures
  • d8873b1 Preserve Python exceptions in input decoding
  • 910784f Propagate detach_string slicing errors
  • Additional commits viewable in compare view

Updates tzdata from 2026.3 to 2026.4

Release notes

Sourced from tzdata's releases.

2026.4: Release of upstream tzdata 2026d

Version 2026.4

Upstream version 2026d released 2026-09-11T22:21:07+00:00

Briefly:

Canada’s Northwest Territories moved to permanent -06 on 2026-08-21. Obsolescent settings like TZ="EST5EDT" now conform better to POSIX. Fix security, performance and porting bugs in zic and localtime.

Changes to future timestamps

Canada’s Northwest Territories will not fall back on 2026-11-01 and will stay on -06 year-round, matching Alberta’s recent change. Model this with its traditional abbreviation CST. Although the change to permanent -06 legally took place on 2026-08-21, temporarily model the change to occur on 2026-11-01 at 02:00 for the same reason as other recent temporary hacks. (Caution: see “NOTE FOR 2026b TEMPORARY HACK FOR CLDR AND CANADA” below.) This affects only America/Inuvik as the rest of the territory is covered by America/Edmonton, for which the equivalent change was released in 2026c.

Changes to past timestamps

Colombia’s 1992-05-02 spring forward was at 00:00, not 24:00.

Iran’s 1979-05-26 spring forward was at 00:00, not 24:00. (Thanks to N.F. Hase.)

The backward-compatibility names EST5EDT, CST6CDT, MST7MDT, and PST8PDT now conform better to POSIX. For example, EST5EDT now always uses the abbreviation "EST" for standard time (now always 5 hours behind UT) and "EDT" for daylight saving time, whereas it formerly had different UT offsets before standard time was introduced and sometimes used abbreviations like "LMT", "EWT" and "EPT", all contrary to POSIX. Also, though not required by POSIX these names now use US federal rules rather than rules of places like New York, reverting to 2024a behavior. This change affects only timestamps before 1966-10-30 at 01:00 standard time.

Other data changes

The temporary hacks used for North American timekeeping changes now work around a libstdc++ std::chrono bug in GCC 14.1-14.4, 15.1-15.2, and 16.1; see GCC bug 124851. This data change does not affect TZif files or timestamps. The change does not work around the related but less serious GCC bugs 116110 and 124513. These GCC bugs are all fixed in GCC 16.2.

Changes to documentation

URLs for release tarballs in tz-link.html have been updated to reflect their new canonical URLs on data.iana.org.

Changelog

Sourced from tzdata's changelog.

Version 2026.4

Upstream version 2026d released 2026-09-11T22:21:07+00:00

Briefly:

Canada’s Northwest Territories moved to permanent -06 on 2026-08-21. Obsolescent settings like TZ="EST5EDT" now conform better to POSIX. Fix security, performance and porting bugs in zic and localtime.

Changes to future timestamps

Canada’s Northwest Territories will not fall back on 2026-11-01 and will stay on -06 year-round, matching Alberta’s recent change. Model this with its traditional abbreviation CST. Although the change to permanent -06 legally took place on 2026-08-21, temporarily model the change to occur on 2026-11-01 at 02:00 for the same reason as other recent temporary hacks. (Caution: see “NOTE FOR 2026b TEMPORARY HACK FOR CLDR AND CANADA” below.) This affects only America/Inuvik as the rest of the territory is covered by America/Edmonton, for which the equivalent change was released in 2026c.

Changes to past timestamps

Colombia’s 1992-05-02 spring forward was at 00:00, not 24:00.

Iran’s 1979-05-26 spring forward was at 00:00, not 24:00. (Thanks to N.F. Hase.)

The backward-compatibility names EST5EDT, CST6CDT, MST7MDT, and PST8PDT now conform better to POSIX. For example, EST5EDT now always uses the abbreviation "EST" for standard time (now always 5 hours behind UT) and "EDT" for daylight saving time, whereas it formerly had different UT offsets before standard time was introduced and sometimes used abbreviations like "LMT", "EWT" and "EPT", all contrary to POSIX. Also, though not required by POSIX these names now use US federal rules rather than rules of places like New York, reverting to 2024a behavior. This change affects only timestamps before 1966-10-30 at 01:00 standard time.

Other data changes

The temporary hacks used for North American timekeeping changes now work around a libstdc++ std::chrono bug in GCC 14.1-14.4, 15.1-15.2, and 16.1; see GCC bug 124851. This data change does not affect TZif files or timestamps. The change does not work around the related but less serious GCC bugs 116110 and 124513. These GCC bugs are all fixed in GCC 16.2.

Changes to documentation

URLs for release tarballs in tz-link.html have been updated to reflect their new canonical URLs on data.iana.org.


Commits

Updates urllib3 from 2.7.0 to 2.8.0

Release notes

Sourced from urllib3's releases.

2.8.0

🚀 urllib3 is fundraising for HTTP/2 support

urllib3 is raising ~$40,000 USD to release HTTP/2 support and ensure long-term sustainable maintenance of the project. If your company or organization uses Python and would benefit from HTTP/2 support in Requests, pip, cloud SDKs, and thousands of other projects please consider contributing financially to ensure HTTP/2 support is developed sustainably and maintained for the long-haul.

Thank you for your support.

Security

Fixed the following security issues:

  • The TLS configuration for HTTPS proxies could be ignored or overridden. (High severity, GHSA-8988-9cw3-xx77)
  • HTTPResponse.stream() and read_chunked() could buffer a chunk-size line of unbounded length in memory. (High severity, GHSA-vxq7-64xx-v4gw)
  • Chunked Deflate streaming could enter an infinite loop. (Medium severity, GHSA-gh4c-6fx4-qh6g)

[!IMPORTANT] urllib3 2.8.0 fixes HTTPS proxy TLS configuration being ignored or overridden by destination settings. Configurations relying on that behavior may require changes.

Configure proxy CA certificates and client certificates in proxy_ssl_context, and proxy identity checks with proxy_assert_hostname or proxy_assert_fingerprint. Destination client certificates and identity overrides no longer apply to HTTPS forwarding proxy connections.

[!NOTE] CVE IDs had not yet been assigned to these advisories at the time of release due to a backlog at GitHub's CNA.

Deprecations & Removals

  • Deprecated using an empty collection as the Retry option allowed_methods to retry any verb. (#5044)

Features

  • Added Url.auth_decoded and Url.auth_decoded_joined convenience properties to the result of parse_url(). (#4945)
  • Added basic_auth_encoding and proxy_basic_auth_encoding parameters to urllib3.util.make_headers(). (#5092)

Bugfixes

  • Fixed response header handling to replace obsolete folded header lines (obs-fold) with spaces in accordance with RFC 9112, preventing raw CRLF sequences from appearing in header values such as Set-Cookie. (#1362)

  • Fixed usage of proxy_ssl_context with ProxyManager when use_forwarding_for_https=True. Passing ssl_context instead of proxy_ssl_context for HTTPS proxies in this configuration now emits a FutureWarning and will raise an error in v3.0. (#2577)

  • Changed behavior of the default ConnectionPool.pool initialization. LifoQueue is now resolved from the queue module after the ConnectionPool is instantiated instead of using the default cached QueueCls class property. This is done because sometimes the queue.LifoQueue is monkey-patched late in the program, such as by gevent. (#3289)

  • Raised UnrewindableBodyError instead of ValueError when retrying a request whose body had tell() but not seek(). (#3779)

  • Decoded percent-encoded SOCKS proxy credentials before authenticating with the proxy server. (#3785)

  • Fixed HTTPResponse.drain_conn() to discard unread response data in 64 KiB chunks (same as the default amt when doing HTTPResponse.stream(...)). (#5019)

  • Fixed is_ipaddress() to detect non-standard IPv4 forms accepted by socket.connect, such as hex (0x7f000001), octal (0177.0.0.1), and decimal integers (2130706433), ensuring SSL certificate verification uses the correct mode for these addresses. (#5029)

  • Fixed HTTPConnectionPool.urlopen raising a misleading FullPoolError instead of ValueError when called with an invalid timeout argument on a pool created with block=True. (#5059)

  • Fixed port-zero handling to preserve explicit :0 values instead of substituting the default ports 80 or 443 in URL parsing, pool selection, proxy configuration, connection_from_url(), and HTTP/2 request authority. (#5071, #5101)

  • Fixed a bug where PoolManager passed the assert_hostname and assert_fingerprint parameters to HTTP connection pools. (#5077)

  • Fixed HTTPConnectionPool.urlopen() and HTTP proxy forwarding to strip URL fragments from absolute request targets before sending requests. (#5079)

  • Added safeguards to the proxy tunneling code to prevent potential security issues when handling invalid characters in the proxy host and HTTP headers. This change affects users of Python 3.10, Python 3.11, and Python 3.12 when the standard library does not contain the fix; those on newer Python versions should upgrade to 3.13.14+ or 3.14.5+ to get the same security fixes. (#5091)

  • Fixed HTTPSConnection.connect() overriding ProxyConfig.ssl_context's certificate policy and proxy identity checks with the target connection's TLS settings when forwarding through an HTTPS proxy.

    HTTPSConnection no longer applies target SNI, assertions, or client credentials to forwarding proxy handshakes and continues to use its ssl_context as a fallback when an HTTPS proxy forwards an HTTP target. (#5093)

  • Fixed URL parsing to more strictly enforce RFC 3986 host syntax, rejecting invalid host input such as raw spaces and control characters, malformed percent-encodings, and percent-encoded control characters in HTTP(S) hosts and IPv6 zone identifiers, including proxy CONNECT tunnel targets. Host normalization now also follows RFC 3986 normalization rules for percent-encoded octets by decoding percent-encoded unreserved characters and uppercasing the hexadecimal digits of retained percent-encoded octets. (#5095)

... (truncated)

Changelog

Sourced from urllib3's changelog.

2.8.0 (2026-09-15)

Security

Fixed the following security issues:

  • The TLS configuration for HTTPS proxies could be ignored or overridden. (High severity, GHSA-8988-9cw3-xx77 <https://github.com/urllib3/urllib3/security/advisories/GHSA-8988-9cw3-xx77>__)
  • HTTPResponse.stream() and read_chunked() could buffer a chunk-size line of unbounded length in memory. (High severity, GHSA-vxq7-64xx-v4gw <https://github.com/urllib3/urllib3/security/advisories/GHSA-vxq7-64xx-v4gw>__)
  • Chunked Deflate streaming could enter an infinite loop. (Medium severity, GHSA-gh4c-6fx4-qh6g <https://github.com/urllib3/urllib3/security/advisories/GHSA-gh4c-6fx4-qh6g>__)

.. caution::

urllib3 2.8.0 fixes HTTPS proxy TLS configuration being ignored or
overridden by destination settings. Configurations relying on that
behavior may require changes.

Configure proxy CA certificates and client certificates in proxy_ssl_context, and proxy identity checks with proxy_assert_hostname or proxy_assert_fingerprint. Destination client certificates and identity overrides no longer apply to HTTPS forwarding proxy connections.

Deprecations & Removals

  • Deprecated using an empty collection as the Retry option allowed_methods to retry any verb. ([#5044](https://github.com/urllib3/urllib3/issues/5044) <https://github.com/urllib3/urllib3/issues/5044>__)

Features

  • Added Url.auth_decoded and Url.auth_decoded_joined convenience properties to the result of parse_url(). ([#4945](https://github.com/urllib3/urllib3/issues/4945) <https://github.com/urllib3/urllib3/issues/4945>__)
  • Added basic_auth_encoding and proxy_basic_auth_encoding parameters to urllib3.util.make_headers(). ([#5092](https://github.com/urllib3/urllib3/issues/5092) <https://github.com/urllib3/urllib3/issues/5092>__)

Bugfixes

... (truncated)

Commits
  • b1d30ab Release 2.8.0
  • 9016d7e Skip test_read_chunked_with_trailing_data_does_not_hang for brotlicffi (#5258)
  • 9101f58 Fix nox -s docs warning (#5256)
  • cd770b0 Merge commit from fork
  • ea2ad7b Merge commit from fork
  • 0716e31 Fix loading unencrypted client keys with a password in pyOpenSSL (#5255)
  • 43c68c8 Test pickling of InvalidChunkLength (#5247)
  • 308b279 Share security policy between GitHub and Read the Docs (#5253)
  • 53fa073 Add policy on duplicate pull requests (#5252)
  • 5f2a6a8 Assert on the ALPN extension in test_tunnel_sets_http_11_alpn (#5232)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Updates the requirements on [basedpyright](https://github.com/detachhead/basedpyright), [ruff](https://github.com/astral-sh/ruff), [hatchling](https://github.com/pypa/hatch), [dateparser](https://github.com/scrapinghub/dateparser), [lxml](https://github.com/lxml/lxml), [pytz](https://github.com/stub42/pytz), [regex](https://github.com/mrabarnett/mrab-regex), [tzdata](https://github.com/python/tzdata) and [urllib3](https://github.com/urllib3/urllib3) to permit the latest version.

Updates `basedpyright` from 1.39.10 to 1.40.1
- [Release notes](https://github.com/detachhead/basedpyright/releases)
- [Commits](DetachHead/basedpyright@v1.39.10...v1.40.1)

Updates `ruff` from 0.16.5 to 0.16.9
- [Release notes](https://github.com/astral-sh/ruff/releases)
- [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md)
- [Commits](astral-sh/ruff@0.16.5...0.16.9)

Updates `hatchling` to 1.32.4
- [Release notes](https://github.com/pypa/hatch/releases)
- [Commits](pypa/hatch@hatchling-v1.28.0...hatchling-v1.32.4)

Updates `dateparser` from 1.4.2 to 1.4.3
- [Release notes](https://github.com/scrapinghub/dateparser/releases)
- [Changelog](https://github.com/scrapinghub/dateparser/blob/master/HISTORY.rst)
- [Commits](scrapinghub/dateparser@v1.4.2...v1.4.3)

Updates `lxml` from 6.1.2 to 6.1.3
- [Release notes](https://github.com/lxml/lxml/releases)
- [Changelog](https://github.com/lxml/lxml/blob/master/CHANGES.txt)
- [Commits](lxml/lxml@lxml-6.1.2...lxml-6.1.3)

Updates `pytz` from 2026.3.post1 to 2026.4
- [Release notes](https://github.com/stub42/pytz/releases)
- [Commits](stub42/pytz@release_2026.3.post1...release_2026.4)

Updates `regex` from 2026.7.19 to 2026.9.10
- [Changelog](https://github.com/mrabarnett/mrab-regex/blob/hg/changelog.txt)
- [Commits](mrabarnett/mrab-regex@2026.7.19...2026.9.10)

Updates `tzdata` from 2026.3 to 2026.4
- [Release notes](https://github.com/python/tzdata/releases)
- [Changelog](https://github.com/python/tzdata/blob/master/NEWS.md)
- [Commits](python/tzdata@2026.3...2026.4)

Updates `urllib3` from 2.7.0 to 2.8.0
- [Release notes](https://github.com/urllib3/urllib3/releases)
- [Changelog](https://github.com/urllib3/urllib3/blob/main/CHANGES.rst)
- [Commits](urllib3/urllib3@2.7.0...2.8.0)

---
updated-dependencies:
- dependency-name: basedpyright
  dependency-version: 1.40.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: all-version-updates
- dependency-name: ruff
  dependency-version: 0.16.9
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: all-version-updates
- dependency-name: hatchling
  dependency-version: 1.32.4
  dependency-type: direct:development
  dependency-group: all-version-updates
- dependency-name: dateparser
  dependency-version: 1.4.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all-version-updates
- dependency-name: lxml
  dependency-version: 6.1.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all-version-updates
- dependency-name: pytz
  dependency-version: '2026.4'
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-version-updates
- dependency-name: regex
  dependency-version: 2026.9.10
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-version-updates
- dependency-name: tzdata
  dependency-version: '2026.4'
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-version-updates
- dependency-name: urllib3
  dependency-version: 2.8.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-version-updates
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Oct 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants