chore: refresh all Python dependencies - #47
Conversation
Bumps [ruff](https://github.com/astral-sh/ruff) from 0.16.1 to 0.16.2. - [Release notes](https://github.com/astral-sh/ruff/releases) - [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md) - [Commits](astral-sh/ruff@0.16.1...0.16.2) --- updated-dependencies: - dependency-name: ruff dependency-version: 0.16.2 dependency-type: direct:development update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
kriptoburak
left a comment
There was a problem hiding this comment.
Verified the full lock refresh locally across all supported Python and Pydantic test combinations. Lint, types, coverage, vulnerability audit, and reproducibility all pass.
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
|
Warning Review the following alerts detected in dependencies. According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.
|
||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Refreshes every eligible dependency under the repository's 7-day stability window.
Direct updates include Ruff 0.16.2 and Coverage 7.15.4. The lock refresh also updates annotated-types, ast-serialize, certifi, httpx-aiohttp, librt, packaging, time-machine, typing-inspection, and yarl. This supersedes #48.
The generated pip fallback lock now keeps exact pins without redundant annotations. The coverage verifier is data-driven and smaller while preserving both thresholds and invalid-report checks.
Validation: