Skip to content

chore(deps-dev): bump the python-dependencies group across 1 directory with 3 updates - #774

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/python-dependencies-4bbdbbe29c
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/python-dependencies-4bbdbbe29c

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the python-dependencies group with 3 updates in the / directory: uv, boto3 and hypothesis.

Updates uv from 0.12.19 to 0.12.20

Release notes

Sourced from uv's releases.

0.12.20

Release Notes

Released on 2026-09-28.

Enhancements

  • Reuse lockfiles when dependency declarations are semantically equivalent (#21951)
  • Preserve second-line encoding declarations when installing wheel scripts with CRLF shebangs (#21990)

Preview features

  • Write normalized requirement declarations with the lockfile-normalization preview feature (#21951)
  • Honor synthetic default groups when installing or syncing from pylock.toml (#22003)
  • Resolve local paths in exported pylock.toml files relative to the output file (#22042)
  • Install each package only once when repeated tool-install-locks requirements resolve to the same package (#22000)
  • Reuse lock-without-metadata lockfiles for conflicting groups with distinct base and extra requirement specifiers (#22055)
  • Use consistent root-package paths in uv workspace metadata and uv tree --format json output (#22050)

Configuration

  • Continue searching XDG_CONFIG_DIRS after empty entries (#21987)

Performance

  • Restore the previous HTTP cache-write scheduling while investigating severe cache-revalidation stalls on ext4 filesystems (#22051)

Bug fixes

  • Apply hash constraints to every repeated requirement under --require-hashes and --verify-hashes (#21996)
  • Allow metadata builds for first-party workspace projects under --no-build (#21988)
  • Honor project exclusion flags with --all-packages, including --no-install-project and --no-emit-project (#21994)
  • Restore pyproject.toml if uv upgrade fails or is interrupted (#21983)
  • Generate working Nushell activation scripts for relocatable virtual environments (#21979)
  • Prevent commands from running and changing state after displaying --show-settings (#21989)
  • Treat UTF-16 requirements files containing only a byte-order mark as empty (#21991)
  • Ignore unrecognized managed-Python implementation directories during uv python list and uv python upgrade instead of panicking (#22033)
  • Avoid panics and incorrect rewriting when managed Python sysconfig paths merely start with /install (#22036)
  • Report whitespace-only non-ASCII requirements as invalid instead of panicking (#22035)
  • Avoid a resolver panic when trace logging an always-false constraint (#22034)

Install uv 0.12.20

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.20/uv-installer.sh | sh

Install prebuilt binaries via powershell script

... (truncated)

Changelog

Sourced from uv's changelog.

0.12.20

Released on 2026-09-28.

Enhancements

  • Reuse lockfiles when dependency declarations are semantically equivalent (#21951)
  • Preserve second-line encoding declarations when installing wheel scripts with CRLF shebangs (#21990)

Preview features

  • Write normalized requirement declarations with the lockfile-normalization preview feature (#21951)
  • Honor synthetic default groups when installing or syncing from pylock.toml (#22003)
  • Resolve local paths in exported pylock.toml files relative to the output file (#22042)
  • Install each package only once when repeated tool-install-locks requirements resolve to the same package (#22000)
  • Reuse lock-without-metadata lockfiles for conflicting groups with distinct base and extra requirement specifiers (#22055)
  • Use consistent root-package paths in uv workspace metadata and uv tree --format json output (#22050)

Configuration

  • Continue searching XDG_CONFIG_DIRS after empty entries (#21987)

Performance

  • Restore the previous HTTP cache-write scheduling while investigating severe cache-revalidation stalls on ext4 filesystems (#22051)

Bug fixes

  • Apply hash constraints to every repeated requirement under --require-hashes and --verify-hashes (#21996)
  • Allow metadata builds for first-party workspace projects under --no-build (#21988)
  • Honor project exclusion flags with --all-packages, including --no-install-project and --no-emit-project (#21994)
  • Restore pyproject.toml if uv upgrade fails or is interrupted (#21983)
  • Generate working Nushell activation scripts for relocatable virtual environments (#21979)
  • Prevent commands from running and changing state after displaying --show-settings (#21989)
  • Treat UTF-16 requirements files containing only a byte-order mark as empty (#21991)
  • Ignore unrecognized managed-Python implementation directories during uv python list and uv python upgrade instead of panicking (#22033)
  • Avoid panics and incorrect rewriting when managed Python sysconfig paths merely start with /install (#22036)
  • Report whitespace-only non-ASCII requirements as invalid instead of panicking (#22035)
  • Avoid a resolver panic when trace logging an always-false constraint (#22034)
Commits

Updates boto3 from 1.43.103 to 1.43.104

Commits
  • ca37987 Merge branch 'release-1.43.104'
  • c468e3d Bumping version to 1.43.104
  • f2d1bac Add changelog entries from botocore
  • 378d670 Merge branch 'release-1.43.103' into develop
  • See full diff in compare view

Updates hypothesis from 6.168.1 to 6.168.3

Commits
  • 44b82b2 Bump hypothesis version to 6.168.3 and update changelog
  • aeaafb5 Merge pull request #4888 from gpacix/fix-quadratic-statistics
  • f3f4a29 wording, remove hardcoded test
  • 7fabb94 Add RELEASE.rst and AUTHORS.rst changes
  • 0ab4e38 Summarize statistics events in linear time
  • 32ebeb2 Bump hypothesis version to 6.168.2 and update changelog
  • ff7e800 Merge pull request #4886 from pschanely/atomic-constants-cache
  • e57fd12 Isolate the constants cache test from existing cache files
  • c8981a0 Write the local constants cache atomically
  • 9c55f97 Merge pull request #4877 from HypothesisWorks/create-pull-request/patch
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

…y with 3 updates

Bumps the python-dependencies group with 3 updates in the / directory: [uv](https://github.com/astral-sh/uv), [boto3](https://github.com/boto/boto3) and [hypothesis](https://github.com/HypothesisWorks/hypothesis).


Updates `uv` from 0.12.19 to 0.12.20
- [Release notes](https://github.com/astral-sh/uv/releases)
- [Changelog](https://github.com/astral-sh/uv/blob/main/CHANGELOG.md)
- [Commits](astral-sh/uv@0.12.19...0.12.20)

Updates `boto3` from 1.43.103 to 1.43.104
- [Release notes](https://github.com/boto/boto3/releases)
- [Commits](boto/boto3@1.43.103...1.43.104)

Updates `hypothesis` from 6.168.1 to 6.168.3
- [Release notes](https://github.com/HypothesisWorks/hypothesis/releases)
- [Commits](HypothesisWorks/hypothesis@v6.168.1...v6.168.3)

---
updated-dependencies:
- dependency-name: uv
  dependency-version: 0.12.20
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: python-dependencies
- dependency-name: boto3
  dependency-version: 1.43.104
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: python-dependencies
- dependency-name: hypothesis
  dependency-version: 6.168.3
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: python-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Oct 5, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner October 5, 2026 23:56
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Oct 5, 2026
@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

OpenSSF Scorecard

PackageVersionScoreDetails
pip/boto3 1.43.104 🟢 7.4
Details
CheckScoreReason
Packaging⚠️ -1packaging workflow not detected
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Code-Review⚠️ 0Found 1/28 approved changesets -- score normalized to 0
Security-Policy🟢 10security policy file detected
Maintained🟢 1030 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Token-Permissions🟢 9detected GitHub workflow tokens with excessive permissions
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Pinned-Dependencies🟢 10all dependencies are pinned
Binary-Artifacts🟢 10no binaries found in the repo
Fuzzing⚠️ 0project is not fuzzed
License🟢 10license file detected
Signed-Releases⚠️ -1no releases found
Branch-Protection🟢 6branch protection is not maximal on development and all release branches
SAST🟢 10SAST tool is run on all commits
pip/hypothesis 6.168.3 UnknownUnknown
pip/uv 0.12.20 UnknownUnknown

Scanned Files

  • uv.lock

@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

OPA/conftest tenant-isolation gate

Result: passed

Gate Result
conftest verify --policy policy/opa passed

@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

Mutation test critical Lambda boundaries

Result: passed

Suite Passed Failed Errors Skipped Total Duration Result
Mutation tests 17 0 0 0 17 1.31s passed

Coverage: 39.67% (1215/3063 lines)

Lowest-covered Lambda files

File Coverage Missed lines

@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

Offline IaC contract tests

Result: passed

Suite Passed Failed Errors Skipped Total Duration Result
Offline IaC contracts 129 0 0 0 129 5.29s passed

Coverage: 95.18% (1481/1556 lines)

Lowest-covered Lambda files

File Coverage Missed lines

@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

Automation gate tests

Result: passed

Suite Passed Failed Errors Skipped Total Duration Result
Automation gate tests 51 0 0 0 51 25.32s passed

Coverage: 88.30% (906/1026 lines)

Lowest-covered Lambda files

File Coverage Missed lines

@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

Lambda unit tests

Result: passed

Suite Passed Failed Errors Skipped Total Duration Result
Lambda unit tests 255 0 0 0 255 50.96s passed

Coverage: 92.76% (4641/5003 lines)

Lowest-covered Lambda files

File Coverage Missed lines
modules/integrations/splunk_aws_billing/lambda/handler_per_resource_process.py 73.13% 18
modules/platform/forge_runners/forge_trust_validator/lambda/trust_common.py 77.57% 48
modules/integrations/splunk_stuck_workflow_job_dispatcher/lambda/worker.py 78.83% 58
modules/integrations/splunk_aws_billing/lambda/handler_per_service.py 79.41% 14
modules/platform/forge_runners/forge_trust_validator/lambda/trust_validator.py 79.80% 20
modules/platform/forge_runners/forge_trust_validator/lambda/trust_preparer.py 80.00% 10
modules/integrations/github_webhook_relay_destination_receivers/webex_webhook_relay/lambda/handler.py 80.00% 24
modules/integrations/splunk_cloud_data_manager/log_group_reconciler/lambda/log_group_reconciler.py 82.52% 18

@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

OpenTofu module tests (latest-stable)

Result: passed

OpenTofu version: 1.13.1

Metric Count
Passed modules 72
Failed modules 0
Total modules 72
Module Result
modules/helpers/ami_policy passed
modules/helpers/ami_sharing passed
modules/helpers/aws_config_recording passed
modules/helpers/cloud_custodian passed
modules/helpers/cloud_formation passed
modules/helpers/dedicated_mac_hosts passed
modules/helpers/ecr passed
modules/helpers/forge_subscription passed
modules/helpers/microvm passed
modules/helpers/opt_in_regions passed
modules/helpers/service_linked_roles passed
modules/helpers/storage passed
modules/infra/eks passed
modules/integrations/github_webhook_relay_destination passed
modules/integrations/github_webhook_relay_destination_receivers passed
modules/integrations/github_webhook_relay_destination_receivers/webex_webhook_relay passed
modules/integrations/splunk_aws_billing passed
modules/integrations/splunk_cloud_conf_shared passed
modules/integrations/splunk_cloud_data_manager passed
modules/integrations/splunk_cloud_data_manager/data_input passed
modules/integrations/splunk_cloud_data_manager/log_group_reconciler passed
modules/integrations/splunk_cloud_data_manager/sec_meta_ec2_tags passed
modules/integrations/splunk_cloud_data_manager_common passed
modules/integrations/splunk_dependency_monitor passed
modules/integrations/splunk_o11y_aws_integration passed
modules/integrations/splunk_o11y_aws_integration_common passed
modules/integrations/splunk_o11y_conf_shared passed
modules/integrations/splunk_o11y_conf_shared/dashboards/arc_runner_operations passed
modules/integrations/splunk_o11y_conf_shared/dashboards/aws_regional_health passed
modules/integrations/splunk_o11y_conf_shared/dashboards/aws_service_limits passed
modules/integrations/splunk_o11y_conf_shared/dashboards/billing passed
modules/integrations/splunk_o11y_conf_shared/dashboards/dependency_probes passed
modules/integrations/splunk_o11y_conf_shared/dashboards/dynamodb passed
modules/integrations/splunk_o11y_conf_shared/dashboards/ebs passed
modules/integrations/splunk_o11y_conf_shared/dashboards/forge_impact passed
modules/integrations/splunk_o11y_conf_shared/dashboards/k8s_control_plane passed
modules/integrations/splunk_o11y_conf_shared/dashboards/lambda passed
modules/integrations/splunk_o11y_conf_shared/dashboards/lambda_control_plane passed
modules/integrations/splunk_o11y_conf_shared/dashboards/metric_ingest passed
modules/integrations/splunk_o11y_conf_shared/dashboards/opencost passed
modules/integrations/splunk_o11y_conf_shared/dashboards/runner_ec2 passed
modules/integrations/splunk_o11y_conf_shared/dashboards/runner_k8s passed
modules/integrations/splunk_o11y_conf_shared/dashboards/runner_usage passed
modules/integrations/splunk_o11y_conf_shared/dashboards/s3 passed
modules/integrations/splunk_o11y_conf_shared/dashboards/s3_control_plane passed
modules/integrations/splunk_o11y_conf_shared/dashboards/sqs passed
modules/integrations/splunk_o11y_conf_shared/dashboards/sqs_control_plane passed
modules/integrations/splunk_o11y_conf_shared/detectors/aws_regional_health passed
modules/integrations/splunk_o11y_conf_shared/detectors/dependency_probes passed
modules/integrations/splunk_o11y_conf_shared/detectors/ec2_runner_health passed
modules/integrations/splunk_o11y_conf_shared/detectors/k8s passed
modules/integrations/splunk_opencost_eks passed
modules/integrations/splunk_otel_eks passed
modules/integrations/splunk_secrets passed
modules/integrations/splunk_stuck_workflow_job_dispatcher passed
modules/integrations/teleport passed
modules/integrations/teleport/tenant passed
modules/platform/arc passed
modules/platform/arc/scale_set passed
modules/platform/arc/scale_set_controller passed
modules/platform/arc_deployment passed
modules/platform/ec2_deployment passed
modules/platform/ec2_deployment/ec2_update_runner_ssm_ami passed
modules/platform/ec2_deployment/ec2_update_runner_tags passed
modules/platform/forge_runners passed
modules/platform/forge_runners/forge_trust_validator passed
modules/platform/forge_runners/github_actions_job_logs passed
modules/platform/forge_runners/github_app_runner_group passed
modules/platform/forge_runners/github_global_lock passed
modules/platform/forge_runners/github_webhook_relay passed
modules/platform/forge_runners/github_webhook_relay/source passed
modules/platform/forge_runners/redrive_deadletter passed

@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

OpenTofu module tests (minimum-supported)

Result: passed

OpenTofu version: 1.11.0

Metric Count
Passed modules 72
Failed modules 0
Total modules 72
Module Result
modules/helpers/ami_policy passed
modules/helpers/ami_sharing passed
modules/helpers/aws_config_recording passed
modules/helpers/cloud_custodian passed
modules/helpers/cloud_formation passed
modules/helpers/dedicated_mac_hosts passed
modules/helpers/ecr passed
modules/helpers/forge_subscription passed
modules/helpers/microvm passed
modules/helpers/opt_in_regions passed
modules/helpers/service_linked_roles passed
modules/helpers/storage passed
modules/infra/eks passed
modules/integrations/github_webhook_relay_destination passed
modules/integrations/github_webhook_relay_destination_receivers passed
modules/integrations/github_webhook_relay_destination_receivers/webex_webhook_relay passed
modules/integrations/splunk_aws_billing passed
modules/integrations/splunk_cloud_conf_shared passed
modules/integrations/splunk_cloud_data_manager passed
modules/integrations/splunk_cloud_data_manager/data_input passed
modules/integrations/splunk_cloud_data_manager/log_group_reconciler passed
modules/integrations/splunk_cloud_data_manager/sec_meta_ec2_tags passed
modules/integrations/splunk_cloud_data_manager_common passed
modules/integrations/splunk_dependency_monitor passed
modules/integrations/splunk_o11y_aws_integration passed
modules/integrations/splunk_o11y_aws_integration_common passed
modules/integrations/splunk_o11y_conf_shared passed
modules/integrations/splunk_o11y_conf_shared/dashboards/arc_runner_operations passed
modules/integrations/splunk_o11y_conf_shared/dashboards/aws_regional_health passed
modules/integrations/splunk_o11y_conf_shared/dashboards/aws_service_limits passed
modules/integrations/splunk_o11y_conf_shared/dashboards/billing passed
modules/integrations/splunk_o11y_conf_shared/dashboards/dependency_probes passed
modules/integrations/splunk_o11y_conf_shared/dashboards/dynamodb passed
modules/integrations/splunk_o11y_conf_shared/dashboards/ebs passed
modules/integrations/splunk_o11y_conf_shared/dashboards/forge_impact passed
modules/integrations/splunk_o11y_conf_shared/dashboards/k8s_control_plane passed
modules/integrations/splunk_o11y_conf_shared/dashboards/lambda passed
modules/integrations/splunk_o11y_conf_shared/dashboards/lambda_control_plane passed
modules/integrations/splunk_o11y_conf_shared/dashboards/metric_ingest passed
modules/integrations/splunk_o11y_conf_shared/dashboards/opencost passed
modules/integrations/splunk_o11y_conf_shared/dashboards/runner_ec2 passed
modules/integrations/splunk_o11y_conf_shared/dashboards/runner_k8s passed
modules/integrations/splunk_o11y_conf_shared/dashboards/runner_usage passed
modules/integrations/splunk_o11y_conf_shared/dashboards/s3 passed
modules/integrations/splunk_o11y_conf_shared/dashboards/s3_control_plane passed
modules/integrations/splunk_o11y_conf_shared/dashboards/sqs passed
modules/integrations/splunk_o11y_conf_shared/dashboards/sqs_control_plane passed
modules/integrations/splunk_o11y_conf_shared/detectors/aws_regional_health passed
modules/integrations/splunk_o11y_conf_shared/detectors/dependency_probes passed
modules/integrations/splunk_o11y_conf_shared/detectors/ec2_runner_health passed
modules/integrations/splunk_o11y_conf_shared/detectors/k8s passed
modules/integrations/splunk_opencost_eks passed
modules/integrations/splunk_otel_eks passed
modules/integrations/splunk_secrets passed
modules/integrations/splunk_stuck_workflow_job_dispatcher passed
modules/integrations/teleport passed
modules/integrations/teleport/tenant passed
modules/platform/arc passed
modules/platform/arc/scale_set passed
modules/platform/arc/scale_set_controller passed
modules/platform/arc_deployment passed
modules/platform/ec2_deployment passed
modules/platform/ec2_deployment/ec2_update_runner_ssm_ami passed
modules/platform/ec2_deployment/ec2_update_runner_tags passed
modules/platform/forge_runners passed
modules/platform/forge_runners/forge_trust_validator passed
modules/platform/forge_runners/github_actions_job_logs passed
modules/platform/forge_runners/github_app_runner_group passed
modules/platform/forge_runners/github_global_lock passed
modules/platform/forge_runners/github_webhook_relay passed
modules/platform/forge_runners/github_webhook_relay/source passed
modules/platform/forge_runners/redrive_deadletter passed

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants