Skip to content

build(deps-dev): bump build from 1.6.0 to 1.6.1 - #242

Merged
github-actions[bot] merged 1 commit into
mainfrom
dependabot/pip/build-1.6.1
Oct 7, 2026
Merged

github-actions[bot] merged 1 commit into
mainfrom
dependabot/pip/build-1.6.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Bumps build from 1.6.0 to 1.6.1.

Release notes

Sourced from build's releases.

1.6.1

What's Changed

Full Changelog: pypa/build@1.6.0...1.6.1

Changelog

Sourced from build's changelog.

#################### 1.6.1 (2026-09-10) ####################


Bugfixes


  • Avoid trying to detect symlinks on Windows, regression in 1.6.0 - by :user:henryiii (:issue:1175) (:issue:1175)

Documentation


  • Fix doubled backslashes in the Windows pip config path (%APPDATA%\pip\pip.ini) in the docs - by :user:aroh3006 (:issue:1149)

Miscellaneous


  • :issue:1168, :issue:1170, :issue:1178

#################### 1.6.0 (2026-08-27) ####################


Features


  • Add --report=PATH to write a machine-readable JSON report of built artifacts; --metadata now also accepts .whl files - by :user:gaborbernat (:issue:198)
  • The srcdir argument now accepts .tar.gz source distributions, extracting and building from them - by :user:gaborbernat (:issue:311)
  • The "Unmet dependencies" error from --no-isolation builds now shows the wanted version, found version, and interpreter - by :user:gaborbernat (:issue:504)
  • Add --sdist-extract-dir to extract the intermediate sdist into a persistent directory, enabling compiler cache reuse across rebuilds - by :user:gaborbernat (:issue:614)
  • Add --env-dir to place the isolated build environment at a fixed path, enabling compiler cache reuse across builds
    • by :user:gaborbernat (:issue:655)
  • Print a summary of resolved dependency versions (name==version) after installing them in isolated builds - by :user:gaborbernat (:issue:959)
  • On build failure, print a tip pointing to --env-dir and --sdist-extract-dir for debugging and link to the "Debug a failed build" how-to - reported by :user:dimpase, implemented by :user:gaborbernat (:issue:966)

Bugfixes


... (truncated)

Commits
  • 89cccef chore: prepare for 1.6.1
  • a6f707a ci: support releases from v* branches (#1178)
  • 7785161 docs: fix doubled backslashes in Windows pip config path (#1149)
  • 244b250 fix: always use copies for the isolated venv on Windows (#1176)
  • c93ca6f build(deps): bump re-actors/alls-green from 1.2.2 to 1.3.0 in the github-acti...
  • e02ffd3 pre-commit: bump repositories (#1173)
  • aad39a8 docs: fix changelog page heading levels and sidebar (#1171)
  • 5c3fd46 docs: use PyPI ref directly (#1172)
  • 1c5bd6c 🐛 fix(release): format generated changelog (#1170)
  • 7f0cc7e 🔧 build(type): replace mypy with pyrefly (#1168)
  • See full diff in compare view

@dependabot
dependabot Bot requested a review from a team as a code owner October 1, 2026 17:47
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Oct 1, 2026

@senzingdevops senzingdevops left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Automated: approving this pull request because it includes a patch update

@github-actions
github-actions Bot enabled auto-merge (squash) October 1, 2026 17:47
@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown

🤖 Claude Code Review

PR Review: bump build from 1.6.0 to 1.6.1

This PR changes one line in pyproject.toml. It raises the pinned dev dependency build from 1.6.0 to 1.6.1, a patch bump. I didn't check the upstream release notes, since there is no network access.

Code Quality

  • ✅ Style: The change is a single pinned version in the existing development group and matches the other == pins.
  • ✅ Commented-out code: None.
  • ✅ Variable names: Not applicable.
  • ✅ DRY: Not applicable.
  • ✅ Defects: None expected from a patch bump of a build-time tool. build is only a development dependency, so it doesn't affect the snippets' runtime behavior.
  • ✅ .claude/CLAUDE.md: Not modified. The existing file has no local-environment-specific content, apart from the example paths, which are generic placeholders.

Testing

  • ✅ Unit and integration tests: None needed for a dependency pin.
  • ✅ Edge cases and coverage: Not applicable. CI should confirm the package still builds with 1.6.1.

Documentation

  • ✅ README and API docs: No update needed.
  • ✅ Inline comments: Not applicable.
  • ✅ CHANGELOG.md: Dependabot-style dev dependency bumps typically don't need an entry. Add one only if this repo's convention records them.
  • ✅ Markdown: No Markdown files changed.

Security

  • ✅ Credentials: None hardcoded.
  • ✅ Input validation, error handling and logging: Not applicable.
  • ✅ License files: No .lic files or AQAAAD strings in the diff. git status shows untracked build-resources/, pr_diff.txt, prompt-header.md, prompt-temp.md and review.txt. These aren't part of the PR diff, but make sure none of them gets committed.

Summary

✅ Approve. This is a low-risk patch bump of a dev-only dependency. The pin style is consistent with the surrounding entries. Merge once CI is green.

Automated code review analyzing defects and coding standards

@dependabot
dependabot Bot force-pushed the dependabot/pip/build-1.6.1 branch from 6377898 to b8264cf Compare October 7, 2026 17:55
@github-actions

github-actions Bot commented Oct 7, 2026

Copy link
Copy Markdown

🤖 Claude Code Review

PR Code Review: bump build 1.6.0 → 1.6.1

This PR changes one line in pyproject.toml. It bumps the dev dependency build from 1.6.0 to 1.6.1, which is a patch release.

Code Quality

  • ✅ Style conventions: The pin format == matches the other entries.
  • ✅ No commented-out code
  • ✅ Variable names: Not applicable.
  • ✅ DRY: Not applicable.
  • ✅ Defects: I found none. The package is in the development group only, so it doesn't affect runtime or the snippets. I couldn't check the 1.6.1 release notes because the network is disabled. A patch bump of a build-frontend tool is low risk.
  • ✅ .claude/CLAUDE.md: This PR doesn't change it. The file has no local-environment-specific content. Its paths are placeholders such as /path/to/data and <project_path>.

Testing

  • ✅ Not applicable. There is no new code. CI should confirm that dependency installation and the lint and build steps still pass.

Documentation

  • ✅ README and API docs: No update needed.
  • ❌ CHANGELOG.md: This PR doesn't update it. Dependabot-style dev-dependency bumps usually don't need an entry, so this is minor. Check the project's convention.
  • ✅ Markdown: No Markdown files changed.

Security

  • ✅ No hardcoded credentials.
  • ✅ No input validation or error handling is affected.
  • ✅ No sensitive data in logs.
  • ✅ License files: The diff has no .lic files and no strings starting with AQAAAD.

The untracked files in the working tree (build-resources/, pr_diff.txt, prompt-header.md, prompt-temp.md, review.txt) aren't part of the PR diff. They look like review-run artifacts, so make sure they aren't committed.

Verdict

Approve. It's a safe, minimal dev-dependency patch bump. The only open item is the optional CHANGELOG check.

Automated code review analyzing defects and coding standards

@senzingdevops senzingdevops left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Automated: approving this pull request because it includes a patch update

Bumps [build](https://github.com/pypa/build) from 1.6.0 to 1.6.1.
- [Release notes](https://github.com/pypa/build/releases)
- [Changelog](https://github.com/pypa/build/blob/main/CHANGELOG.rst)
- [Commits](pypa/build@1.6.0...1.6.1)

---
updated-dependencies:
- dependency-name: build
  dependency-version: 1.6.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/pip/build-1.6.1 branch from b8264cf to 3441cb3 Compare October 7, 2026 18:19

@senzingdevops senzingdevops left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Automated: approving this pull request because it includes a patch update

@github-actions

github-actions Bot commented Oct 7, 2026

Copy link
Copy Markdown

🤖 Claude Code Review

PR Review: bump build 1.6.0 → 1.6.1

The change is one line in pyproject.toml. It raises the pinned dev dependency build from 1.6.0 to 1.6.1, a patch release.

Code Quality

  • ✅ Style: The pin format matches the neighbouring entries (== exact pins, alphabetical order).
  • ✅ No commented-out code.
  • ✅ Variable names: Not applicable.
  • ✅ DRY: Not applicable.
  • ✅ Defects: None found. This is a patch bump of a build-only tool in the development group, so it doesn't affect the snippets at runtime. I didn't check the 1.6.1 release notes, because there's no network access.
  • ✅ .claude/CLAUDE.md: Not modified. Its content is general and has no local-environment specifics.

Testing

  • ✅ Unit tests, integration tests, edge cases and coverage: None are needed for a dev-dependency version bump. CI should confirm that the environment resolves and installs.

Documentation

Security

  • ✅ No hardcoded credentials, license files (.lic) or AQAAAD strings.
  • ✅ Input validation, error handling and logging: Not applicable.
  • ✅ Supply chain: The version is pinned exactly, and build is a well-known PyPA package.

Summary

✅ Approve. This is a low-risk, mechanical dependency bump with no issues found. The only follow-up is to confirm CI passes.

Automated code review analyzing defects and coding standards

@github-actions
github-actions Bot merged commit 7e0ba8e into main Oct 7, 2026
58 checks passed
@github-actions
github-actions Bot deleted the dependabot/pip/build-1.6.1 branch October 7, 2026 18:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants