Skip to content

chore(deps): bump the dependencies group with 4 updates - #633

Merged
jmeridth merged 1 commit into
mainfrom
dependabot/uv/dependencies-9fa708913f
Oct 9, 2026
Merged

jmeridth merged 1 commit into
mainfrom
dependabot/uv/dependencies-9fa708913f

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 8, 2026

Copy link
Copy Markdown
Contributor

Bumps the dependencies group with 4 updates: python-dotenv, isort, mypy and pylint.

Updates python-dotenv from 1.2.3 to 1.2.4

Release notes

Sourced from python-dotenv's releases.

v1.2.4

Fixed

  • dotenv get no longer exits with code 1 for empty string values (KEY=) by [@​ShamikOfficial] in #700
  • An unquoted empty value followed by an inline comment (e.g. KEY= # comment) is now parsed as an empty string instead of the comment text by [@​Noethix55555] in #663
  • dotenv run --no-override now expands variable references with the same precedence as load_dotenv(override=False), so a value like ${BASE}/suffix uses the existing BASE from the environment instead of the one from the .env file by [@​ROTl24] in #698
Changelog

Sourced from python-dotenv's changelog.

[1.2.4] - 2026-10-01

Fixed

  • dotenv get no longer exits with code 1 for empty string values (KEY=) by [@​ShamikOfficial] in #700
  • An unquoted empty value followed by an inline comment (e.g. KEY= # comment) is now parsed as an empty string instead of the comment text by [@​Noethix55555] in #663
  • dotenv run --no-override now expands variable references with the same precedence as load_dotenv(override=False), so a value like ${BASE}/suffix uses the existing BASE from the environment instead of the one from the .env file by [@​ROTl24] in #698
Commits
  • a565c2c Bump version: 1.2.3 → 1.2.4
  • 4a7abd0 docs: add 1.2.4 release notes (#663, #698, #700)
  • f215c02 fix: dotenv get exits 0 for empty string values (#700)
  • 58f2d7c test: make test_run_with_command_flags portable and meaningful (#709)
  • e0310e5 fix: honor --no-override when expanding variables in dotenv run (#698)
  • a00cb2e docs: add CHANGELOG entry for #663 (fix #600)
  • f5485a6 fix: parse empty unquoted value with inline comment as empty string
  • See full diff in compare view

Updates isort from 9.0.1 to 9.0.2

Release notes

Sourced from isort's releases.

9.0.2

🪲 Fixes

Other changes

Full Changelog: PyCQA/isort@9.0.1...9.0.2

Commits
  • 9f90561 Core developers revision
  • 4371472 Fix a "security" issue
  • e74b4ba Do some formatting and setting updates
  • 539abb1 Bump the uv group with 15 updates
  • 0482160 Fully type check tests and modernize code
  • bbda474 Bump pypa/cibuildwheel from 4.2.0 to 4.2.1 in the github-actions group
  • 1fd0701 Agent Host changes for agents/dependabot-monthly-updates-uv
  • 6911091 Always split on parsed.line_separator
  • 3808b70 Keep CRLF regression cases beside existing check-mode tests
  • 3202ce8 Preserve CRLF blank lines during float-to-top preprocessing
  • Additional commits viewable in compare view

Updates mypy from 2.3.1 to 2.4.0

Changelog

Sourced from mypy's changelog.

Mypy Release Notes

Next Release

Mypy 2.4

We've just uploaded mypy 2.4.0 to the Python Package Index (PyPI). Mypy is a static type checker for Python. This release includes new features, performance improvements and bug fixes. You can install it as follows:

python3 -m pip install -U mypy

You can read the full documentation for this release on Read the Docs.

Python 3.15 Support

Mypy 2.4 supports running on Python 3.15 and type checking most Python 3.15 features. This includes the new builtin sentinel type for sentinel values (PEP 661), which mypy now supports (see below for details). Lazy imports (PEP 810) and unpacking in comprehensions (PEP 798) are also supported. Closed TypedDicts (PEP 728) have been supported since mypy 2.2, but the extra_items TypedDict argument, also introduced in PEP 728, is still unsupported. Support for extra_items will be added in a future mypy release.

Native Parser Enabled by Default

Mypy now uses the new native parser by default. It's based on the Ruff parser, and it's significantly faster than the legacy parser, which uses the stdlib ast module. The native parser also has other benefits:

  • You can target newer Python versions and use recent Python syntax even when running mypy on an older Python version. For example, you can use --python-version 3.15 when running mypy on Python 3.14.
  • Stub files can use syntax that is newer than the target Python version. For example, stubs can use the PEP 695 generic class syntax (class Box[T]: ...) when running on or targeting Python 3.10.
  • Parallel type checking requires the native parser.

The legacy parser is still available through --no-native-parser, or native_parser = False in the config file (native_parser = false under [tool.mypy] in pyproject.toml). We are planning to remove the legacy parser in early 2027. If you run into a problem with the native parser, please report it on the issue tracker.

Unlike the legacy parser, the native parser doesn't support type comments for variables defined by for and with statements. These type comments are silently ignored, and the types of the variables are

... (truncated)

Commits

Updates pylint from 4.0.9 to 4.1.1

Release notes

Sourced from pylint's releases.

v4.1.1

What's new in Pylint 4.1.1?

Release date: 2026-09-29

Other Changes

  • Pylint 4.1.0 could not be uploaded to PyPI, because it required an unreleased version of dill on Python 3.15, and PyPI refuses such a dependency. 4.1.1 is the first 4.1 release available on PyPI, see the 4.1.0 changes below.

    Refs #11495

v4.1.0

What's new in Pylint 4.1.0?

Release date: 2026-09-29

Startup is about 25% faster thanks to lazy imports. The import checker caches its isort configuration, which makes pylint about 17% faster on ansible. Finding the files to lint with --recursive=y no longer walks ignored directories such as .venv or node_modules, which took seconds on large trees. The duplicate-code checker and symilar also received optimizations that result in considerable performance improvements and memory use reduction on larger codebases. For example, pandas analysis went from 20 min to 55 s and pylint does not get OOM-killed when analyzing cpython anymore.

Python 3.15 support progresses: the unpacking in comprehensions added by PEP 798 no longer raises false positives, and the standard library deprecations of Python 3.15 are followed.

For CI, there is a new built-in junit output format (--output-format=junit), the NO_COLOR and FORCE_COLOR environment variables are respected, and the files to lint can now be set with the files option in the configuration file.

New checks: looping-through-iterator, impossible-comparison, chained-comparison-all-equal and using-comprehension-unpacking-in-unsupported-version.

Running with --jobs no longer duplicates the messages of extensions or ignores extensions enabled in the configuration.

Plugin authors: the confidence parameter can no longer be None, except in is_message_enabled, and the MSG_STATE_* constants are deprecated in favor of the MessageDisableReason enum.

The required astroid version is now 4.3.2. See the astroid changelog for additional fixes, features, and performance improvements applicable to pylint.

... (truncated)

Commits
  • 8c6daca Bump pylint to 4.1.1, update changelog (#11499)
  • bdb17b3 [Backport maintenance/4.1.x] Only pin the unreleased dill for the tests (#11498)
  • 92bb7ba Bump pylint to 4.1.0, update changelog
  • 9144956 Fix a crash in import-private-name on attribute access rooted at a non-Name n...
  • 68366cb Fix false positive for unnecessary-lambda when variable is reassigned or de...
  • c741677 [pre-commit.ci] pre-commit autoupdate (#11488)
  • a9ebdf6 Add regression test for unsubscriptable-object FP on class_getitem (#11487)
  • b877d3b Do not flag ungrouped imports inside OS platform guards (#11217)
  • 87351be Update OSS-Fuzz docs for Python 3.14 (#11485)
  • 4f263c1 Fix access checks through called methods (#11456)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the dependencies group with 4 updates: [python-dotenv](https://github.com/theskumar/python-dotenv), [isort](https://github.com/PyCQA/isort), [mypy](https://github.com/python/mypy) and [pylint](https://github.com/pylint-dev/pylint).


Updates `python-dotenv` from 1.2.3 to 1.2.4
- [Release notes](https://github.com/theskumar/python-dotenv/releases)
- [Changelog](https://github.com/theskumar/python-dotenv/blob/main/CHANGELOG.md)
- [Commits](theskumar/python-dotenv@v1.2.3...v1.2.4)

Updates `isort` from 9.0.1 to 9.0.2
- [Release notes](https://github.com/PyCQA/isort/releases)
- [Changelog](https://github.com/PyCQA/isort/blob/main/CHANGELOG.md)
- [Commits](PyCQA/isort@9.0.1...9.0.2)

Updates `mypy` from 2.3.1 to 2.4.0
- [Changelog](https://github.com/python/mypy/blob/master/CHANGELOG.md)
- [Commits](python/mypy@v2.3.1...v2.4.0)

Updates `pylint` from 4.0.9 to 4.1.1
- [Release notes](https://github.com/pylint-dev/pylint/releases)
- [Commits](pylint-dev/pylint@v4.0.9...v4.1.1)

---
updated-dependencies:
- dependency-name: python-dotenv
  dependency-version: 1.2.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: isort
  dependency-version: 9.0.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: mypy
  dependency-version: 2.4.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dependencies
- dependency-name: pylint
  dependency-version: 4.1.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot requested review from jmeridth and zkoppert as code owners October 8, 2026 21:35
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update Python code labels Oct 8, 2026
@jmeridth
jmeridth merged commit ee42159 into main Oct 9, 2026
37 checks passed
@jmeridth
jmeridth deleted the dependabot/uv/dependencies-9fa708913f branch October 9, 2026 02:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file maintenance python Pull requests that update Python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant