Skip to content

Bump the monthly-batch group with 6 updates - #62

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/monthly-batch-7e475e0f50
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/monthly-batch-7e475e0f50

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown
Contributor

Updates the requirements on copier, pydantic, python-hcl2, ruff, zensical and uv-build to permit the latest version.
Updates copier from 9.17.2 to 9.18.2

Release notes

Sourced from copier's releases.

v9.18.2 (2026-09-07)

Fix

  • allow overwriting destination symlinks when preserve_symlinks: false
  • cache: resolve submodules from the current checkout's .gitmodules (#2767)

Security

  • prevent trust bypass via ambiguous URL characters

    To prevent URL confusion attacks, trusted prefix matching is now restricted to repository URL paths containing only RFC 3986 §2.3 "unreserved" characters (letters, digits, -, ., _, ~) and /. URL paths containing other characters now require an exact, verbatim match.

v9.18.1 (2026-09-01)

Fix

  • disambiguate Windows paths from SCP URLs in trust check

v9.18.0 (2026-09-01)

Feat

  • exclude: add support for multiple exclude patterns in a single entry (#2804)

Fix

  • preserve the original error when cleanup fails (#2824)

Security

  • prevent trust bypass via encoded URL traversal for alias and SCP-style URLs
Changelog

Sourced from copier's changelog.

v9.18.2 (2026-09-07)

Fix

  • allow overwriting destination symlinks when preserve_symlinks: false
  • cache: resolve submodules from the current checkout's .gitmodules (#2767)

Security

  • prevent trust bypass via ambiguous URL characters

    To prevent URL confusion attacks, trusted prefix matching is now restricted to repository URL paths containing only RFC 3986 §2.3 "unreserved" characters (letters, digits, -, ., _, ~) and /. URL paths containing other characters now require an exact, verbatim match.

v9.18.1 (2026-09-01)

Fix

  • disambiguate Windows paths from SCP URLs in trust check

v9.18.0 (2026-09-01)

Feat

  • exclude: add support for multiple exclude patterns in a single entry (#2804)

Fix

  • preserve the original error when cleanup fails (#2824)

Security

  • prevent trust bypass via encoded URL traversal for alias and SCP-style URLs
Commits
  • 217e4f8 bump: version 9.18.1 → 9.18.2
  • 50b1927 fix: prevent trust bypass via ambiguous URL characters
  • bfa05c1 fix: allow overwriting destination symlinks when preserve_symlinks: false
  • 68c8aa2 fix(cache): resolve submodules from the current checkout's .gitmodules (#2767)
  • 03c95e2 bump: version 9.18.0 → 9.18.1
  • 2a3e140 fix: disambiguate Windows paths from SCP URLs in trust check
  • b65cd70 bump: version 9.17.2 → 9.18.0
  • dcae663 fix: prevent trust bypass via encoded URL traversal for alias and SCP-style URLs
  • bb956bb build(deps): update dependency ruff to v0.16.5
  • 27d3629 build(deps): lock file maintenance
  • Additional commits viewable in compare view

Updates pydantic from 2.13.4 to 2.13.5

Release notes

Sourced from pydantic's releases.

v2.13.5 (2026-08-28)

What's Changed

Fixes

  • Allow reuse of validators when plugins are set by @​Viicos in #13535
  • Fix missing GC traversal on some pydantic-core struct fields by @​Viicos in #13624
  • Fix missing GC traversal in pydantic-core for GeneralFieldsSerializer by @​Viicos in #13629
  • Count validated model fields once in smart unions by @​tamird in #13731
Changelog

Sourced from pydantic's changelog.

v2.13.5 (2026-08-28)

GitHub release

What's Changed

Fixes

  • Allow reuse of validators when plugins are set by @​Viicos in #13535
  • Fix missing GC traversal on some pydantic-core struct fields by @​Viicos in #13624
  • Fix missing GC traversal in pydantic-core for GeneralFieldsSerializer by @​Viicos in #13629
  • Count validated model fields once in smart unions by @​tamird in #13731
Commits
  • 001dea0 Bump pypa/gh-action-pypi-publish action to v1.14.2
  • 558379f Bump twine to v7.0.0
  • 2cfd5d3 Do not check for docs build
  • a735bee Fix more Clippy lints
  • 7eed4a1 Fix Clippy 0.1.95 warnings
  • b353bbb Prepare release v2.13.5
  • 63d2ccc Count validated model fields once in smart unions
  • a53ec2e Speed up PyPy CI tests
  • d65e0f9 Workaround circular import error in Mypy
  • 47a6dbf Fix missing GC traversal in pydantic-core for GeneralFieldsSerializer
  • Additional commits viewable in compare view

Updates python-hcl2 from 8.1.3 to 8.1.4

Release notes

Sourced from python-hcl2's releases.

v8.1.4

What's Changed

Fixed

  • Parse blocks whose type or unquoted label is an HCL keyword, such as the in block in Snowflake's snowflake_schemas data source. HCL reserves no keywords, so all are now accepted as block labels. Diagnosed independently in #355. (#357)
  • Parse keyword-named object keys reliably, fixing a regression of #148. A key such as in parsed only where the lexer fell back to NAME, so its separator and position decided whether the file parsed. (#357)

Full Changelog: amplify-education/python-hcl2@v8.1.3...v8.1.4

Changelog

Sourced from python-hcl2's changelog.

[8.1.4] - 2026-09-08

Fixed

  • Parse blocks whose type or unquoted label is an HCL keyword, such as the in block in Snowflake's snowflake_schemas data source. HCL reserves no keywords, so all are now accepted as block labels. Diagnosed independently in #355. (#357)
  • Parse keyword-named object keys reliably, fixing a regression of #148. A key such as in parsed only where the lexer fell back to NAME, so its separator and position decided whether the file parsed. (#357)
Commits

Updates ruff from 0.16.4 to 0.16.8

Release notes

Sourced from ruff's releases.

0.16.8

Release Notes

Released on 2026-09-16.

Bug fixes

  • Visit functional TypedDict keyword arguments correctly (#28584)
  • [flake8-simplify] Detect nested async with under sync parent (SIM117) (#27821)
  • [flake8-simplify] Preserve operand order in SIM109 fix (#27824)
  • [pyupgrade] Preserve required parentheses in multiline UP040 fixes (#28164)
  • [pyupgrade] Skip TypeVarTuple and ParamSpec conversions with bounds or constraints (UP040, UP046, UP047) (#28505)

Rule changes

  • Add support for __lazy_modules__ (#28459)
  • Recognize PEP-728 TypedDict class keywords (#28533)
  • Recognize quoted types in typing.TypeForm (#28507)
  • Support conditional assignment to __lazy_modules__ (#28491)
  • [flake8-type-checking] Prefer lazy imports over TYPE_CHECKING on Python 3.15 and later (TC001, TC002, TC003) (#28541)
  • [pyupgrade] Make the fix for UP040 always unsafe (#28526)
  • [pyupgrade] Stop recommending deprecated ByteString aliases (UP035) (#28498)
  • [ruff, flake8-use-pathlib] Recognize the parent_mode argument (RUF064, PTH103) (#28528)
  • [ruff] Detect \Z in pytest.raises() match patterns (RUF043) (#28598)

CLI

  • Use rule name and code in formatter incompatibility warnings (#28571)

Configuration

  • [flake8-tidy-imports] Add extend-banned-api (#28644)

Contributors

Install ruff 0.16.8

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/ruff/releases/download/0.16.8/ruff-installer.sh | sh
</tr></table> 

... (truncated)

Changelog

Sourced from ruff's changelog.

0.16.8

Released on 2026-09-16.

Bug fixes

  • Visit functional TypedDict keyword arguments correctly (#28584)
  • [flake8-simplify] Detect nested async with under sync parent (SIM117) (#27821)
  • [flake8-simplify] Preserve operand order in SIM109 fix (#27824)
  • [pyupgrade] Preserve required parentheses in multiline UP040 fixes (#28164)
  • [pyupgrade] Skip TypeVarTuple and ParamSpec conversions with bounds or constraints (UP040, UP046, UP047) (#28505)

Rule changes

  • Add support for __lazy_modules__ (#28459)
  • Recognize PEP-728 TypedDict class keywords (#28533)
  • Recognize quoted types in typing.TypeForm (#28507)
  • Support conditional assignment to __lazy_modules__ (#28491)
  • [flake8-type-checking] Prefer lazy imports over TYPE_CHECKING on Python 3.15 and later (TC001, TC002, TC003) (#28541)
  • [pyupgrade] Make the fix for UP040 always unsafe (#28526)
  • [pyupgrade] Stop recommending deprecated ByteString aliases (UP035) (#28498)
  • [ruff, flake8-use-pathlib] Recognize the parent_mode argument (RUF064, PTH103) (#28528)
  • [ruff] Detect \Z in pytest.raises() match patterns (RUF043) (#28598)

CLI

  • Use rule name and code in formatter incompatibility warnings (#28571)

Configuration

  • [flake8-tidy-imports] Add extend-banned-api (#28644)

Contributors

0.16.7

Released on 2026-09-10.

Preview features

  • [ruff] Add rule for default values on method receivers (RUF077) (#26700)

... (truncated)

Commits
  • 62914c4 Bump version to 0.16.8 (#28648)
  • c47e0cd [ty] Bound aliased intersection expansion during inference (#28546)
  • ff4747b renovate: update uv hashes correctly with setup-uv (#28621)
  • 94efeaa [ty] Compact reachable binding and declaration histories (#28349)
  • 50020fb [ty] Avoid storing constraint nodes twice (#28375)
  • 446bb68 [ty] Compare bound-method receivers before signatures (#28384)
  • 304ab86 [flake8-type-checking] Prefer lazy imports over TYPE_CHECKING on 3.15+ (`...
  • d940b24 [ty] Watch script dependencies in CLI watch mode (#28125)
  • fe9f065 [flake8-tidy-imports] Add extend-banned-api (#28644)
  • 31131db [ty] Support type[A & B] (#27124)
  • Additional commits viewable in compare view

Updates zensical from 0.0.57 to 0.0.64

Release notes

Sourced from zensical's releases.

0.0.64

Summary

Many of you have been waiting for this one: Zensical now includes native blog support. As a direct port of the Material for MkDocs blog plugin, it preserves the familiar configuration, metadata, URLs, archives, categories, authors, pagination, and more. We're happy to finally put it into your hands, with more flexible blogging functionality planned for the future.

Changelog

Features

  • 5825381 zensical, compat, ui – add blog plugin replacement

Bug fixes

  • a85875e ui – update ui to v0.0.32

0.0.63

Summary

This version ensures pages containing snippets rebuild when source files change during local preview and excludes hidden files and directories from the generated site. It also fixes preview-site root redirects and returns proper 404 responses while preserving custom error pages.

Additionally, the user interface is updated to v0.0.31, fixing empty submenus for sections containing only an index page and improving task list checkbox sizing and alignment in the modern theme. It also updates dependencies and adds 60 new icons across Lucide, Octicons, and Simple Icons.

Changelog

Bug fixes

  • a771962 ui – update ui to v0.0.31
  • dfe8f94 zensical – rebuild pages containing snippets on source changes (#950)
  • d6cd5d5 zensical, zensical-serve – append trailing slash to preview site root (#944)
  • 2070bf1 zensical, compat – don't add dotfiles to final site (#945)

0.0.62

Summary

This version adds support for the mkdocs-callouts plugin, which renders Obsidian-style callouts as admonitions. It also improves compatibility with existing MkDocs projects by accepting more plugin settings and fixes builds when the project configuration file is included in watch.

Additionally, the user interface is updated to v0.0.30, ensuring that anchor links reveal targets inside collapsed details, content tabs, and annotations – including deeply nested combinations – before scrolling to them.

Changelog

Features

  • d8fbb05 compat – support mkdocs-callouts plugin by enabling pymdownx.quotes extension with callouts support (#938)

... (truncated)

Commits
  • 7cac628 chore: release v0.0.64
  • 5825381 feature: add blog plugin replacement
  • a85875e fix: update ui to v0.0.32
  • 1d03851 chore: release v0.0.63
  • a771962 fix: update ui to v0.0.31
  • 51b3d3d chore: update pull request guide
  • 39cc42b chore: upgrade dependencies
  • dfe8f94 fix: rebuild pages containing snippets on source changes (#950)
  • d6cd5d5 fix: append trailing slash to preview site root (#944)
  • 2070bf1 fix: don't add dotfiles to final site (#945)
  • Additional commits viewable in compare view

Updates uv-build to 0.12.18

Release notes

Sourced from uv-build's releases.

0.12.18

Release Notes

Released on 2026-09-22.

This release addresses GHSA-2cv4-cqwr-gwf7, which is a path traversal weakness during wheel installation on Windows. No other platforms are affected by this advisory.

Enhancements

  • Add --output-format json to uv pip install and uv pip sync, including for --dry-run and --check (#21893)
  • Add --check to uv pip install and uv pip sync to report planned changes without modifying the environment (#21844)
  • Identify failures from get_requires_for_build_* hooks correctly in build errors (#21881)

Preview features

  • Validate build requirements for uv build --no-build-isolation with --preview-features build-dependency-check; use --skip-dependency-check to opt out (#21880)

Performance

  • Speed up uv_build editable wheel creation by omitting compression from temporary wheels (#21918)

Bug fixes

  • Select package versions with wheels compatible with each Python resolution fork, correctly interpreting generic and stable-ABI wheel tags (#21835, #21836)
  • Restore project, script, and lock files when uv add, uv remove, or uv version fails or is interrupted (#21860, #21856)
  • Use configured dependency-metadata when checking whether installed requirements are satisfied (#21843)
  • Reject archive entries that normalize to absolute Windows paths (#21923)
  • Recognize distribution filenames and archive extensions when URL fragments contain ? (#21920)
  • Generate correctly lowercased platform tags for BSD and Haiku releases (#21853)
  • Avoid rebuilding a Windows relative path into an absolute form (#21923)

Install uv 0.12.18

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.18/uv-installer.sh | sh

Install prebuilt binaries via powershell script

powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.18/uv-installer.ps1 | iex"

Download uv 0.12.18

File Platform Checksum
uv-aarch64-apple-darwin.tar.gz Apple Silicon macOS checksum

... (truncated)

Changelog

Sourced from uv-build's changelog.

0.12.18

Released on 2026-09-22.

This release addresses GHSA-2cv4-cqwr-gwf7, which is a path traversal weakness during wheel installation on Windows. No other platforms are affected by this advisory.

Enhancements

  • Add --output-format json to uv pip install and uv pip sync, including for --dry-run and --check (#21893)
  • Add --check to uv pip install and uv pip sync to report planned changes without modifying the environment (#21844)
  • Identify failures from get_requires_for_build_* hooks correctly in build errors (#21881)

Preview features

  • Validate build requirements for uv build --no-build-isolation with --preview-features build-dependency-check; use --skip-dependency-check to opt out (#21880)

Performance

  • Speed up uv_build editable wheel creation by omitting compression from temporary wheels (#21918)

Bug fixes

  • Select package versions with wheels compatible with each Python resolution fork, correctly interpreting generic and stable-ABI wheel tags (#21835, #21836)
  • Restore project, script, and lock files when uv add, uv remove, or uv version fails or is interrupted (#21860, #21856)
  • Use configured dependency-metadata when checking whether installed requirements are satisfied (#21843)
  • Reject archive entries that normalize to absolute Windows paths (#21923)
  • Recognize distribution filenames and archive extensions when URL fragments contain ? (#21920)
  • Generate correctly lowercased platform tags for BSD and Haiku releases (#21853)
  • Avoid rebuilding a Windows relative path into an absolute form (#21923)

0.12.17

Released on 2026-09-18.

Enhancements

  • Reject unsupported Git archive paths in lockfiles with a clear error instead of panicking during frozen exports (#21780)

Preview features

  • Set minimum glibc and musl versions that universal resolutions must support with minimum-libc-version (#21651)
  • Reject pylock.toml files whose wheel filenames do not match their declared package names or versions (#20746)
  • Keep uv workspace metadata read-only unless --sync is provided (#21821)
  • Apply uv check lock modes when retrieving workspace metadata (#21821)

Performance

  • Speed up builds with many exclusion patterns by avoiding quadratic deduplication (#21650)
  • Reduce resolver allocations when deduplicating package and distribution requests (#21810)

... (truncated)

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Updates the requirements on [copier](https://github.com/copier-org/copier), [pydantic](https://github.com/pydantic/pydantic), [python-hcl2](https://github.com/amplify-education/python-hcl2), [ruff](https://github.com/astral-sh/ruff), [zensical](https://github.com/zensical/zensical) and [uv-build](https://github.com/astral-sh/uv) to permit the latest version.

Updates `copier` from 9.17.2 to 9.18.2
- [Release notes](https://github.com/copier-org/copier/releases)
- [Changelog](https://github.com/copier-org/copier/blob/master/CHANGELOG.md)
- [Commits](copier-org/copier@v9.17.2...v9.18.2)

Updates `pydantic` from 2.13.4 to 2.13.5
- [Release notes](https://github.com/pydantic/pydantic/releases)
- [Changelog](https://github.com/pydantic/pydantic/blob/v2.13.5/HISTORY.md)
- [Commits](pydantic/pydantic@v2.13.4...v2.13.5)

Updates `python-hcl2` from 8.1.3 to 8.1.4
- [Release notes](https://github.com/amplify-education/python-hcl2/releases)
- [Changelog](https://github.com/amplify-education/python-hcl2/blob/main/CHANGELOG.md)
- [Commits](amplify-education/python-hcl2@v8.1.3...v8.1.4)

Updates `ruff` from 0.16.4 to 0.16.8
- [Release notes](https://github.com/astral-sh/ruff/releases)
- [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md)
- [Commits](astral-sh/ruff@0.16.4...0.16.8)

Updates `zensical` from 0.0.57 to 0.0.64
- [Release notes](https://github.com/zensical/zensical/releases)
- [Commits](zensical/zensical@v0.0.57...v0.0.64)

Updates `uv-build` to 0.12.18
- [Release notes](https://github.com/astral-sh/uv/releases)
- [Changelog](https://github.com/astral-sh/uv/blob/main/CHANGELOG.md)
- [Commits](astral-sh/uv@0.12.6...0.12.18)

---
updated-dependencies:
- dependency-name: copier
  dependency-version: 9.18.2
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: monthly-batch
- dependency-name: pydantic
  dependency-version: 2.13.5
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: monthly-batch
- dependency-name: python-hcl2
  dependency-version: 8.1.4
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: monthly-batch
- dependency-name: ruff
  dependency-version: 0.16.8
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: monthly-batch
- dependency-name: zensical
  dependency-version: 0.0.64
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: monthly-batch
- dependency-name: uv-build
  dependency-version: 0.12.18
  dependency-type: direct:development
  dependency-group: monthly-batch
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels Oct 1, 2026
@vercel

vercel Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
python-template Ready Ready Preview Oct 1, 2026 5:01pm UTC

This branch was successfully deployed

1 active deployment
Preview — d8b67c4d Deployed Oct 1, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants