Skip to content

Bump the "dependencies" group with 2 updates across multiple ecosystems - #99

Merged
kattni merged 2 commits into
mainfrom
dependabot/dependencies-c18ee736a4
Oct 5, 2026
Merged

kattni merged 2 commits into
mainfrom
dependabot/dependencies-c18ee736a4

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 4, 2026

Copy link
Copy Markdown
Contributor

Bumps the dependencies group with 3 updates: towncrier, tox-uv and setuptools-scm.

Updates towncrier from 25.8.0 to 26.9.0

Release notes

Sourced from towncrier's releases.

Towncrier 26.9.0

Features

  • towncrier build now support setting the date via the SOURCE_DATE_EPOCH specification. This adds support for Reproducible Builds. ([#746](https://github.com/twisted/towncrier/issues/746) <https://github.com/twisted/towncrier/issues/746>_)
  • Wrapped line length can now be configured by setting wrap to an integer value greater than 0, using 79 by default if set to true. ([#464](https://github.com/twisted/towncrier/issues/464) <https://github.com/twisted/towncrier/issues/464>_)
  • The towncrier create command line tool now has the --sub-issue option that is used when creating multiple fragments for the same issue number. ([#714](https://github.com/twisted/towncrier/issues/714) <https://github.com/twisted/towncrier/issues/714>_)

Bugfixes

  • towncrier create now rejects fragment names whose issue identifier contains .. ([#733](https://github.com/twisted/towncrier/issues/733) <https://github.com/twisted/towncrier/issues/733>_)

Misc

  • [#719](https://github.com/twisted/towncrier/issues/719) <https://github.com/twisted/towncrier/issues/719>, [#729](https://github.com/twisted/towncrier/issues/729) <https://github.com/twisted/towncrier/issues/729>, [#736](https://github.com/twisted/towncrier/issues/736) <https://github.com/twisted/towncrier/issues/736>, [#741](https://github.com/twisted/towncrier/issues/741) <https://github.com/twisted/towncrier/issues/741>, [#747](https://github.com/twisted/towncrier/issues/747) <https://github.com/twisted/towncrier/issues/747>_

Towncrier 26.9.0rc1

Features

  • towncrier build now support setting the date via the SOURCE_DATE_EPOCH specification. This adds support for Reproducible Builds. ([#746](https://github.com/twisted/towncrier/issues/746) <https://github.com/twisted/towncrier/issues/746>_)
  • Wrapped line length can now be configured by setting wrap to an integer value greater than 0, using 79 by default if set to true. ([#464](https://github.com/twisted/towncrier/issues/464) <https://github.com/twisted/towncrier/issues/464>_)
  • The towncrier create command line tool now has the --sub-issue option that is used when creating multiple fragments for the same issue number. ([#714](https://github.com/twisted/towncrier/issues/714) <https://github.com/twisted/towncrier/issues/714>_)

Bugfixes

  • towncrier create now rejects fragment names whose issue identifier contains .. ([#733](https://github.com/twisted/towncrier/issues/733) <https://github.com/twisted/towncrier/issues/733>_)

Misc

  • [#719](https://github.com/twisted/towncrier/issues/719) <https://github.com/twisted/towncrier/issues/719>, [#729](https://github.com/twisted/towncrier/issues/729) <https://github.com/twisted/towncrier/issues/729>, [#736](https://github.com/twisted/towncrier/issues/736) <https://github.com/twisted/towncrier/issues/736>, [#741](https://github.com/twisted/towncrier/issues/741) <https://github.com/twisted/towncrier/issues/741>, [#747](https://github.com/twisted/towncrier/issues/747) <https://github.com/twisted/towncrier/issues/747>_
Changelog

Sourced from towncrier's changelog.

towncrier 26.9.0 (2026-09-04)

No significant changes since the previous release candidate.

Features

  • towncrier build now support setting the date via the SOURCE_DATE_EPOCH specification. This adds support for Reproducible Builds. ([#746](https://github.com/twisted/towncrier/issues/746) <https://github.com/twisted/towncrier/issues/746>_)
  • Wrapped line length can now be configured by setting wrap to an integer value greater than 0, using 79 by default if set to true. ([#464](https://github.com/twisted/towncrier/issues/464) <https://github.com/twisted/towncrier/issues/464>_)
  • The towncrier create command line tool now has the --sub-issue option that is used when creating multiple fragments for the same issue number. ([#714](https://github.com/twisted/towncrier/issues/714) <https://github.com/twisted/towncrier/issues/714>_)

Bugfixes

  • towncrier create now rejects fragment names whose issue identifier contains .. ([#733](https://github.com/twisted/towncrier/issues/733) <https://github.com/twisted/towncrier/issues/733>_)

Misc

  • [#719](https://github.com/twisted/towncrier/issues/719) <https://github.com/twisted/towncrier/issues/719>, [#729](https://github.com/twisted/towncrier/issues/729) <https://github.com/twisted/towncrier/issues/729>, [#736](https://github.com/twisted/towncrier/issues/736) <https://github.com/twisted/towncrier/issues/736>, [#741](https://github.com/twisted/towncrier/issues/741) <https://github.com/twisted/towncrier/issues/741>, [#747](https://github.com/twisted/towncrier/issues/747) <https://github.com/twisted/towncrier/issues/747>_
Commits
  • 12e95a9 Prepare final release.
  • 7f5ef06 Initial commit.
  • 1598380 #746 Reproducible build source date epoch (#749)
  • b2df9f8 Merge branch 'trunk' into 746-reproducible-build-source-date-epoch
  • dc07055 Update release for single line.
  • 1e46459 docs: Clarify the defaults for build timestamp values.
  • 803dbc5 Specify the precedence order for computing the build date.
  • 434bf70 Show an example of 'SOURCE_DATE_EPOCH' in the Tutorial.
  • 48f8b3d Document the 'SOURCE_DATE_EPOCH' behaviour for towncrier build.
  • 9f899f5 Document the user-facing change in a Towncrier news fragment.
  • Additional commits viewable in compare view

Updates tox-uv from 1.35.2 to 1.36.0

Release notes

Sourced from tox-uv's releases.

1.36.0

What's Changed

Full Changelog: tox-dev/tox-uv@1.35.2...1.36.0

Commits
  • 6268ef9 👷 ci: add Python 3.15 to the test matrix (#358)
  • 12edb70 [pre-commit.ci] pre-commit autoupdate (#357)
  • a6d24f8 Replace prettier with mdformat and yamlfmt (#356)
  • 8bab275 build(deps): bump astral-sh/setup-uv from 8.3.1 to 8.3.2 (#355)
  • 75c7409 build(deps): bump astral-sh/setup-uv from 8.3.0 to 8.3.1 (#354)
  • a4ef4f2 [pre-commit.ci] pre-commit autoupdate (#353)
  • 16203a1 build(deps): bump astral-sh/setup-uv from 8.2.0 to 8.3.0 (#352)
  • af040e7 [pre-commit.ci] pre-commit autoupdate (#351)
  • 1a09434 💰 Surface GitHub Sponsors + thanks.dev
  • 9781bb7 [pre-commit.ci] pre-commit autoupdate (#350)
  • Additional commits viewable in compare view

Updates setuptools-scm from 10.2.1 to 10.3.4

Release notes

Sourced from setuptools-scm's releases.

setuptools-scm v10.3.4

Fixed

  • Ship the tracked files of projects whose pyproject.toml sits in a subdirectory of the checkout. root defaults to the project directory, so version inference correctly finds no SCM there and answers from SETUPTOOLS_SCM_PRETEND_VERSION or fallback_version -- but that says nothing about which files git tracks, and the sdist and wheel came out with none of them. This was the 10.3.0 regression fixed in 10.3.3, surviving in the subdirectory layout.

    File discovery now follows the checkout the project sits in, independently of the root that scopes versioning, and records scm_file_list.json in the egg-info as a root-level project already did. (#1543)

  • Require vcs-versioning>=2.5.0. The subdirectory file-discovery fix (#1543) imports discover_file_workdir, which no earlier release has, while the declared floor still named 2.4.0 -- an install against a published vcs-versioning raised ImportError during the build. (#1546)

setuptools-scm v10.3.3

Fixed

  • Keep file discovery working when the version is pretended. SETUPTOOLS_SCM_PRETEND_VERSION and its scoped _FOR_<DIST> form made version inference return before discovering a workdir, and the egg_info mixin read the absent workdir as "searched, found no checkout" -- the signal it acts on by suppressing the setuptools.file_finders chain. Every SCM-tracked file that setuptools' own package discovery does not find was then dropped from the sdist and the wheel, silently, since the build succeeded and the version was correct.

    A pretended version still skips discovery, because most builds only want a version and probing for a checkout nobody asks about costs subprocesses for nothing. What no longer happens is passing that off as an answer: "nobody looked yet" is now distinct from "looked and found nothing", and the workdir is discovered on demand the first time a consumer needs a file list.

    scm_file_list.json is now written to the egg-info for pretended builds as well. It describes which files the checkout tracks, which a pretended version says nothing about. scm_version.json stays absent there, because a pretended version must not be recorded as what the SCM said. (#1540)

setuptools-scm v10.3.2

Fixed

  • Stop the command mixins from reordering a project's own build_py, egg_info or bdist_wheel MRO. ScmVersionFileMixin and friends inherited from the corresponding setuptools command, so wrapping a project class built on a disjoint hierarchy -- distutils.command.build_py, or the standalone wheel package's bdist_wheel -- placed setuptools' command ahead of the project's class. setuptools.build_py.run() does not delegate any further, so the project's

... (truncated)

Commits
  • b27f597 Merge pull request #1545 from pypa/release/main
  • aa18322 Prepare release: setuptools-scm v10.3.4, vcs-versioning v2.5.0
  • e40176e Merge pull request #1551 from RonnyPfannschmidt/fix/version-missing-accepts-tool
  • 873d4b3 fix(vcs-versioning): accept tool= in _version_missing again
  • 5173a1e Merge pull request #1546 from RonnyPfannschmidt/fix/dependency-floor-runs-the...
  • cbcd429 fix(deps): require vcs-versioning>=2.5.0.dev0
  • 5f95612 ci(dependency-floor): run the testsuite, not just the imports
  • e377730 Merge pull request #1544 from RonnyPfannschmidt/fix/file-discovery-follows-th...
  • 98fa24d fix(file-discovery): follow the checkout, not the versioning root
  • 41edffe Merge pull request #1538 from pypa/release/main
  • Additional commits viewable in compare view

Bumps the dependencies group with 3 updates: https://github.com/astral-sh/ruff-pre-commit, https://github.com/rvben/rumdl-pre-commit and https://github.com/zizmorcore/zizmor-pre-commit.

Updates https://github.com/astral-sh/ruff-pre-commit from v0.16.5 to 0.16.9

Release notes

Sourced from https://github.com/astral-sh/ruff-pre-commit's releases.

v0.16.9

See: https://github.com/astral-sh/ruff/releases/tag/0.16.9

v0.16.8

See: https://github.com/astral-sh/ruff/releases/tag/0.16.8

v0.16.7

See: https://github.com/astral-sh/ruff/releases/tag/0.16.7

v0.16.6

See: https://github.com/astral-sh/ruff/releases/tag/0.16.6

Commits

Updates https://github.com/rvben/rumdl-pre-commit from v0.2.62 to 0.2.77

Release notes

Sourced from https://github.com/rvben/rumdl-pre-commit's releases.

v0.2.77

See: https://github.com/rvben/rumdl/releases/tag/v0.2.77

v0.2.76

See: https://github.com/rvben/rumdl/releases/tag/v0.2.76

v0.2.75

See: https://github.com/rvben/rumdl/releases/tag/v0.2.75

v0.2.74

See: https://github.com/rvben/rumdl/releases/tag/v0.2.74

v0.2.73

See: https://github.com/rvben/rumdl/releases/tag/v0.2.73

v0.2.72

See: https://github.com/rvben/rumdl/releases/tag/v0.2.72

v0.2.71

See: https://github.com/rvben/rumdl/releases/tag/v0.2.71

v0.2.70

See: https://github.com/rvben/rumdl/releases/tag/v0.2.70

v0.2.69

See: https://github.com/rvben/rumdl/releases/tag/v0.2.69

v0.2.68

See: https://github.com/rvben/rumdl/releases/tag/v0.2.68

v0.2.67

See: https://github.com/rvben/rumdl/releases/tag/v0.2.67

v0.2.66

See: https://github.com/rvben/rumdl/releases/tag/v0.2.66

v0.2.65

See: https://github.com/rvben/rumdl/releases/tag/v0.2.65

v0.2.64

See: https://github.com/rvben/rumdl/releases/tag/v0.2.64

v0.2.63

See: https://github.com/rvben/rumdl/releases/tag/v0.2.63

Commits

Updates https://github.com/zizmorcore/zizmor-pre-commit from v1.29.0 to 1.30.1

Release notes

Sourced from https://github.com/zizmorcore/zizmor-pre-commit's releases.

v1.30.1

Sponsorship is appreciated!

Bug Fixes 🐛🔗

  • Fixed a bug where zizmor would crash on pre-commit inputs that reference a GitHub URL with an explicit .git suffix (#2363)

  • Fixed a bug where self-repository auto-fixes were incorrectly marked as "safe" instead of "unsafe" (#2373)

v1.30.0

Sponsorship is appreciated!

New Features 🌈🔗

Bug Fixes 🐛🔗

... (truncated)

Commits
  • fa41207 Mirror: 1.30.1
  • 7361a0b fix: include pre-commit files in hook (#59)
  • 34c5ce3 Bump zizmorcore/zizmor-action from 0.6.2 to 0.6.3 in the github-actions group...
  • cef8b83 Mirror: 1.30.0
  • 2e74fc1 Bump astral-sh/setup-uv from 9.0.0 to 10.0.1 in the github-actions group (#61)
  • 7bb2343 Bump zizmorcore/zizmor-action in the github-actions group (#58)
  • 950796f chore: replace pre-commit checks with zizmor-action (#57)
  • a5dde09 chore: freeze pin commit hooks, bump usage of own hook (#56)
  • a21d6cd Bump astral-sh/setup-uv from 8.3.2 to 9.0.0 in the github-actions group (#55)
  • See full diff in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the dependencies group with 3 updates: [towncrier](https://github.com/twisted/towncrier), [tox-uv](https://github.com/tox-dev/tox-uv) and [setuptools-scm](https://github.com/pypa/setuptools-scm).


Updates `towncrier` from 25.8.0 to 26.9.0
- [Release notes](https://github.com/twisted/towncrier/releases)
- [Changelog](https://github.com/twisted/towncrier/blob/trunk/NEWS.rst)
- [Commits](twisted/towncrier@25.8.0...26.9.0)

Updates `tox-uv` from 1.35.2 to 1.36.0
- [Release notes](https://github.com/tox-dev/tox-uv/releases)
- [Commits](tox-dev/tox-uv@1.35.2...1.36.0)

Updates `setuptools-scm` from 10.2.1 to 10.3.4
- [Release notes](https://github.com/pypa/setuptools-scm/releases)
- [Changelog](https://github.com/pypa/setuptools-scm/blob/main/RELEASE_SYSTEM.md)
- [Commits](pypa/setuptools-scm@setuptools-scm-v10.2.1...setuptools-scm-v10.3.4)
Bump the dependencies group with 3 updates

Bumps the dependencies group with 3 updates: [https://github.com/astral-sh/ruff-pre-commit](https://github.com/astral-sh/ruff-pre-commit), [https://github.com/rvben/rumdl-pre-commit](https://github.com/rvben/rumdl-pre-commit) and [https://github.com/zizmorcore/zizmor-pre-commit](https://github.com/zizmorcore/zizmor-pre-commit).


Updates `https://github.com/astral-sh/ruff-pre-commit` from v0.16.5 to 0.16.9
- [Release notes](https://github.com/astral-sh/ruff-pre-commit/releases)
- [Commits](astral-sh/ruff-pre-commit@v0.16.5...v0.16.9)

Updates `https://github.com/rvben/rumdl-pre-commit` from v0.2.62 to 0.2.77
- [Release notes](https://github.com/rvben/rumdl-pre-commit/releases)
- [Commits](rvben/rumdl-pre-commit@v0.2.62...v0.2.77)

Updates `https://github.com/zizmorcore/zizmor-pre-commit` from v1.29.0 to 1.30.1
- [Release notes](https://github.com/zizmorcore/zizmor-pre-commit/releases)
- [Commits](zizmorcore/zizmor-pre-commit@v1.29.0...v1.30.1)

---
updated-dependencies:
- dependency-name: towncrier
  dependency-version: 26.9.0
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: dependencies
- dependency-name: tox-uv
  dependency-version: 1.36.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dependencies
- dependency-name: setuptools-scm
  dependency-version: 10.3.4
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: dependencies
- dependency-name: https://github.com/astral-sh/ruff-pre-commit
  dependency-version: 0.16.9
  dependency-type: direct:production
  dependency-group: dependencies
- dependency-name: https://github.com/rvben/rumdl-pre-commit
  dependency-version: 0.2.77
  dependency-type: direct:production
  dependency-group: dependencies
- dependency-name: https://github.com/zizmorcore/zizmor-pre-commit
  dependency-version: 1.30.1
  dependency-type: direct:production
  dependency-group: dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Oct 4, 2026
@kattni
kattni merged commit c77cef0 into main Oct 5, 2026
23 checks passed
@kattni
kattni deleted the dependabot/dependencies-c18ee736a4 branch October 5, 2026 04:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant