Skip to content

build(jupyter): bump the uv-deps group in /apps/cogstack-jupyter-hub with 5 updates - #165

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/apps/cogstack-jupyter-hub/uv-deps-03a70c3a0d
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/apps/cogstack-jupyter-hub/uv-deps-03a70c3a0d

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 7, 2026

Copy link
Copy Markdown
Contributor

Bumps the uv-deps group in /apps/cogstack-jupyter-hub with 5 updates:

Package From To
virtualenv 21.13.0 21.14.5
isort 9.0.1 9.0.2
simplejson 4.1.2 4.2.0
jsonpickle 4.1.2 4.1.3
ruff 0.16.9 0.16.10

Updates virtualenv from 21.13.0 to 21.14.5

Release notes

Sourced from virtualenv's releases.

21.14.5

What's Changed

Full Changelog: pypa/virtualenv@21.14.4...21.14.5

21.14.4

What's Changed

Full Changelog: pypa/virtualenv@21.14.3...21.14.4

21.14.3

What's Changed

Full Changelog: pypa/virtualenv@21.14.2...21.14.3

21.14.2

What's Changed

Full Changelog: pypa/virtualenv@21.14.1...21.14.2

21.14.1

What's Changed

... (truncated)

Changelog

Sourced from virtualenv's changelog.

Bugfixes - 21.14.5

  • Fall back to the bundled seed wheel and remove the embed update log when the log in the app data folder holds JSON of the wrong shape, instead of failing to create the environment - by :user:pasmud. (:issue:3376)

v21.14.4 (2026-10-02)


Bugfixes - 21.14.4

  • Fix activate running commands from a virtual environment name or --prompt that holds $(...), backticks or ${...} when zsh has PROMPT_SUBST set, and show a % in the name as typed under zsh (GHSA-5vjq-rrrf-7h2q <https://github.com/pypa/virtualenv/security/advisories/GHSA-5vjq-rrrf-7h2q>_); reported by :user:kemrec. (:issue:3373)

v21.14.3 (2026-10-01)


Bugfixes - 21.14.3

  • Honor ~= and every clause of a seed wheel's Requires-Python when picking a wheel for the target Python, and skip a wheel whose Requires-Python is not a valid specifier instead of failing - by :user:pasmud. (:issue:3369)

v21.14.2 (2026-10-01)


Bugfixes - 21.14.2

  • Fix pyvenv.cfg getting an absolute path in python-version, include-system-site-packages and the other keys that hold no path when the working directory has an entry named like the value, such as 3.14 for virtualenv 3.14 or true with --system-site-packages - by :user:darrenhuai. (:issue:3366)
  • Fix activation scripts running code from a virtual environment path whose parent directory carries a placeholder name such as __VIRTUAL_NAME__ (GHSA-8rjx-v5ww-45pp <https://github.com/pypa/virtualenv/security/advisories/GHSA-8rjx-v5ww-45pp>), and activate.fish running commands from a path or --prompt that holds a backslash before a single quote (GHSA-c947-3pg5-gm8q <https://github.com/pypa/virtualenv/security/advisories/GHSA-c947-3pg5-gm8q>); both reported by :user:Kwstubbs of GitHub Security Lab. (:issue:3367)

v21.14.1 (2026-09-29)


... (truncated)

Commits

Updates isort from 9.0.1 to 9.0.2

Release notes

Sourced from isort's releases.

9.0.2

🪲 Fixes

Other changes

Full Changelog: PyCQA/isort@9.0.1...9.0.2

Commits
  • 9f90561 Core developers revision
  • 4371472 Fix a "security" issue
  • e74b4ba Do some formatting and setting updates
  • 539abb1 Bump the uv group with 15 updates
  • 0482160 Fully type check tests and modernize code
  • bbda474 Bump pypa/cibuildwheel from 4.2.0 to 4.2.1 in the github-actions group
  • 1fd0701 Agent Host changes for agents/dependabot-monthly-updates-uv
  • 6911091 Always split on parsed.line_separator
  • 3808b70 Keep CRLF regression cases beside existing check-mode tests
  • 3202ce8 Preserve CRLF blank lines during float-to-top preprocessing
  • Additional commits viewable in compare view

Updates simplejson from 4.1.2 to 4.2.0

Release notes

Sourced from simplejson's releases.

v4.2.0

What's Changed

New Contributors

Full Changelog: simplejson/simplejson@v4.1.2...v4.2.0

Changelog

Sourced from simplejson's changelog.

Version 4.2.0 released 2026-10-02

  • Start building wheels for Python 3.15 and drop Python 3.8 support via upgrade to cibuildwheel v4.2.0 simplejson/simplejson#385
  • Build and test riscv64 Linux wheels on native RISE runners simplejson/simplejson#389
  • The C scanner now reports the same error message as the pure Python decoder for an invalid first key in an object simplejson/simplejson#388
  • int_as_string_bitcount now supports thresholds of 64 bits and above (including 128-bit integers) in both the C and pure Python encoders; the C encoder previously rejected them simplejson/simplejson#387
  • Circular references introduced through for_json() or _asdict() now raise ValueError("Circular reference detected") instead of recursing without bound simplejson/simplejson#390
  • CI now tests Python 3.15 (including free-threaded 3.15t), PyPy 3.12, CPython 3.14.8 debug builds, and uses current GitHub Actions and cibuildwheel v4.2.1 simplejson/simplejson#386

Version 4.1.2 released 2026-08-26

Version 4.1.1 released 2026-04-24

  • The build_wheels_py27 CI job now also builds Python 2.7 wheels for Windows AMD64 and Windows x86, joining the existing Py2.7 manylinux1 / manylinux2010 x86_64 wheels. This unblocks offline / --no-index installs on Py2.7-on-Windows (the original reporter's case), which previously had no matching binary wheel on PyPI, fell through to the sdist, and failed on the PEP 517 isolated-build step complaining that setuptools>=42 was not in the wheelhouse. simplejson/simplejson#377

Version 4.1.0 released 2026-04-22

  • The C extension now accelerates encoding when indent= is set.

... (truncated)

Commits
  • 0ace7d1 Prep for v4.2.0 - Update CHANGES and build matrix (#386)
  • c3edf28 ci: build and test riscv64 wheels (#389)
  • 41f8017 Check circular references introduced by custom JSON methods (#390)
  • 48e7c3b Support large integer stringification thresholds in both encoders (#387)
  • 50cadb6 Use the first-key error message in the C scanner (#388)
  • fbc057f Start building CPython 3.15 wheels (#385)
  • See full diff in compare view

Updates jsonpickle from 4.1.2 to 4.1.3

Changelog

Sourced from jsonpickle's changelog.

v4.1.3

* Add deprecation warnings for the pending removal of the ``backend``, ``max_iter``, and
  ``v1_decode`` arguments, as well as the new behavior of 5.0.0 in not registering the
  yaml backend by default. (+637)
Commits

Updates ruff from 0.16.9 to 0.16.10

Release notes

Sourced from ruff's releases.

0.16.10

Release Notes

Released on 2026-10-01.

Preview features

  • Add a migration guide for categories (#28087)
  • [pyupgrade] Add rule for context manager iterator annotations (UP052) (#29000)

Performance

  • Reduce memory used by diagnostics (#28951)

Server

  • Avoid running uv format in untrusted workspaces (#28873)

Documentation

  • Fix links to moved changelog sections and renamed mdtests (#28941)
  • Add Python 3.15 as a supported version (#28907)
  • Add ty as a type checker example (#28906)

Other changes

  • Update Rust toolchain to 1.99 and MSRV to 1.97 (#29047)

Contributors

Install ruff 0.16.10

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/ruff/releases/download/0.16.10/ruff-installer.sh | sh

Install prebuilt binaries via powershell script

powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/ruff/releases/download/0.16.10/ruff-installer.ps1 | iex"

Download ruff 0.16.10

... (truncated)

Changelog

Sourced from ruff's changelog.

0.16.10

Released on 2026-10-01.

Preview features

  • Add a migration guide for categories (#28087)
  • [pyupgrade] Add rule for context manager iterator annotations (UP052) (#29000)

Performance

  • Reduce memory used by diagnostics (#28951)

Server

  • Avoid running uv format in untrusted workspaces (#28873)

Documentation

  • Fix links to moved changelog sections and renamed mdtests (#28941)
  • Add Python 3.15 as a supported version (#28907)
  • Add ty as a type checker example (#28906)

Other changes

  • Update Rust toolchain to 1.99 and MSRV to 1.97 (#29047)

Contributors

Commits
  • 3265ed1 Bump version to 0.16.10 (#29055)
  • e786964 Authorize shared PR security-review workflow to publish findings (#29052)
  • a81291e [ty] Defer uv workspace discovery until after project configuration (#28525)
  • b6a74d2 [ty] Refresh uv project metadata when uv files change (#28529)
  • 41d30df Update Rust toolchain to 1.99 and MSRV to 1.97 (#29047)
  • 317e0a3 [ty] Bound nested callable signature display (#29049)
  • 8546752 [ty] Fix member lookup on union-bounded type variables (#29018)
  • 56180bc [ty] Specialize instance members once (#29043)
  • aa9a1ff [ty] Avoid stale I/O diagnostics when closing deleted files (#28988)
  • 2d25346 [ty] Improve unresolved-import documentation (#29039)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the uv-deps group in /apps/cogstack-jupyter-hub with 5 updates:

| Package | From | To |
| --- | --- | --- |
| [virtualenv](https://github.com/pypa/virtualenv) | `21.13.0` | `21.14.5` |
| [isort](https://github.com/PyCQA/isort) | `9.0.1` | `9.0.2` |
| [simplejson](https://github.com/simplejson/simplejson) | `4.1.2` | `4.2.0` |
| [jsonpickle](https://github.com/jsonpickle/jsonpickle) | `4.1.2` | `4.1.3` |
| [ruff](https://github.com/astral-sh/ruff) | `0.16.9` | `0.16.10` |


Updates `virtualenv` from 21.13.0 to 21.14.5
- [Release notes](https://github.com/pypa/virtualenv/releases)
- [Changelog](https://github.com/pypa/virtualenv/blob/main/docs/changelog.rst)
- [Commits](pypa/virtualenv@21.13.0...21.14.5)

Updates `isort` from 9.0.1 to 9.0.2
- [Release notes](https://github.com/PyCQA/isort/releases)
- [Changelog](https://github.com/PyCQA/isort/blob/main/CHANGELOG.md)
- [Commits](PyCQA/isort@9.0.1...9.0.2)

Updates `simplejson` from 4.1.2 to 4.2.0
- [Release notes](https://github.com/simplejson/simplejson/releases)
- [Changelog](https://github.com/simplejson/simplejson/blob/main/CHANGES.txt)
- [Commits](simplejson/simplejson@v4.1.2...v4.2.0)

Updates `jsonpickle` from 4.1.2 to 4.1.3
- [Release notes](https://github.com/jsonpickle/jsonpickle/releases)
- [Changelog](https://github.com/jsonpickle/jsonpickle/blob/v4.1.3/CHANGES.rst)
- [Commits](jsonpickle/jsonpickle@v4.1.2...v4.1.3)

Updates `ruff` from 0.16.9 to 0.16.10
- [Release notes](https://github.com/astral-sh/ruff/releases)
- [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md)
- [Commits](astral-sh/ruff@0.16.9...0.16.10)

---
updated-dependencies:
- dependency-name: virtualenv
  dependency-version: 21.14.5
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: uv-deps
- dependency-name: isort
  dependency-version: 9.0.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: uv-deps
- dependency-name: simplejson
  dependency-version: 4.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: uv-deps
- dependency-name: jsonpickle
  dependency-version: 4.1.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: uv-deps
- dependency-name: ruff
  dependency-version: 0.16.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: uv-deps
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels Oct 7, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants