Skip to content

chore(deps): bump the python-minor-patch group across 1 directory with 2 updates - #34

Merged
QuintinBotes merged 1 commit into
mainfrom
dependabot/uv/python-minor-patch-6fb3e49434
Jul 9, 2026
Merged

QuintinBotes merged 1 commit into
mainfrom
dependabot/uv/python-minor-patch-6fb3e49434

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 9, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the python-minor-patch group with 2 updates in the / directory: tree-sitter and signxml.

Updates tree-sitter from 0.25.2 to 0.26.0

Release notes

Sourced from tree-sitter's releases.

v0.26.0

Breaking changes are marked with !.

Additions:

  • Point.edit()
  • Point.__repr__()
  • QueryCursor.set_containing_byte_range()
  • QueryCursor.set_containing_point_range()
  • Range.edit()
  • tree_sitter.__version__

Removals:

  • Language.version: use Language.abi_version !
  • Language.query(source): use Query(language, source) !
  • Parser.timeout_micros: use the progress_callback in parse() !
  • QueryCursor.timeout_micros: use the progress_callback in matches() or captures() !

Changes:

  • Point is a tuple subclass rather than a namedtuple object
Commits
  • a9e753e ci(pypi): skip riscv64 tests properly
  • eeababc chore: release 0.26.0
  • dac834e fix(node): fix reference leak
  • bdddb61 build: bump tree-sitter-rust from 0.24.1 to 0.24.2
  • baa5fd8 ci: bump the actions group across 1 directory with 2 updates
  • c680e3b build: bump tree_sitter/core from cd5b087 to 7f53486
  • 2d3fb3a ci: bump actions/upload-pages-artifact from 4 to 5 in the actions group
  • bae0829 build: bump tree-sitter-rust from 0.24.0 to 0.24.1
  • d99f796 build: bump tree_sitter/core from 6f2e8a6 to cd5b087
  • a9282df build: bump tree_sitter/core from cd4b6e2 to 6f2e8a6
  • Additional commits viewable in compare view

Updates signxml from 5.0.1 to 5.1.0

Release notes

Sourced from signxml's releases.

v5.1.0

  • Implement point-in-time verification
  • xades: fix CertDigest handling
  • Confirm certs passed to validate are X.509 formatted
  • Clarify location parameter syntax
Changelog

Sourced from signxml's changelog.

Changes for v5.1.0 (2026-07-04)

  • Implement point-in-time verification

    • Breaking change: SignXML now raises an error if a trusted cert passed in the x509_cert keyword argument has expired, restoring the behavior that was in place before v4.0.0. See the documentation if you need to verify signatures using expired certificates.
  • xades: fix CertDigest handling

  • Confirm certs passed to validate are X.509 formatted

  • Clarify location parameter syntax

Commits
  • 6d57a0d v5.1.0
  • 2bd58f1 ruff format
  • f964532 Implement point-in-time verification
  • d732ce2 xades: fix CertDigest handling
  • 52dccc4 Confirm certs passed to validate are X.509 formatted. Clarify location syntax.
  • 4c4de69 Upgrade GHA to latest supported runners and actions
  • See full diff in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

…h 2 updates

Bumps the python-minor-patch group with 2 updates in the / directory: [tree-sitter](https://github.com/tree-sitter/py-tree-sitter) and [signxml](https://github.com/XML-Security/signxml).


Updates `tree-sitter` from 0.25.2 to 0.26.0
- [Release notes](https://github.com/tree-sitter/py-tree-sitter/releases)
- [Commits](tree-sitter/py-tree-sitter@v0.25.2...v0.26.0)

Updates `signxml` from 5.0.1 to 5.1.0
- [Release notes](https://github.com/XML-Security/signxml/releases)
- [Changelog](https://github.com/XML-Security/signxml/blob/main/Changes.rst)
- [Commits](XML-Security/signxml@v5.0.1...v5.1.0)

---
updated-dependencies:
- dependency-name: tree-sitter
  dependency-version: 0.26.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-minor-patch
- dependency-name: signxml
  dependency-version: 5.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-minor-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Jul 9, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: python. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@QuintinBotes

Copy link
Copy Markdown
Owner

@dependabot rebase

@QuintinBotes
QuintinBotes merged commit 918d11c into main Jul 9, 2026
19 checks passed
@QuintinBotes
QuintinBotes deleted the dependabot/uv/python-minor-patch-6fb3e49434 branch July 9, 2026 11:28
@dependabot @github

dependabot Bot commented on behalf of github Jul 9, 2026

Copy link
Copy Markdown
Contributor Author

Oh no! Something went wrong on our end. Please try again later.

If the problem persists, please contact GitHub support for assistance 🙇

QuintinBotes pushed a commit that referenced this pull request Oct 5, 2026
…h 2 updates (#34)

Bumps the python-minor-patch group with 2 updates in the / directory: [tree-sitter](https://github.com/tree-sitter/py-tree-sitter) and [signxml](https://github.com/XML-Security/signxml).


Updates `tree-sitter` from 0.25.2 to 0.26.0
- [Release notes](https://github.com/tree-sitter/py-tree-sitter/releases)
- [Commits](tree-sitter/py-tree-sitter@v0.25.2...v0.26.0)

Updates `signxml` from 5.0.1 to 5.1.0
- [Release notes](https://github.com/XML-Security/signxml/releases)
- [Changelog](https://github.com/XML-Security/signxml/blob/main/Changes.rst)
- [Commits](XML-Security/signxml@v5.0.1...v5.1.0)

---
updated-dependencies:
- dependency-name: tree-sitter
  dependency-version: 0.26.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-minor-patch
- dependency-name: signxml
  dependency-version: 5.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-minor-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant