Bump black from 22.10.0 to 26.3.1 in /python/requirements - #65078
Bump black from 22.10.0 to 26.3.1 in /python/requirements#65078dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [black](https://github.com/psf/black) from 22.10.0 to 26.3.1. - [Release notes](https://github.com/psf/black/releases) - [Changelog](https://github.com/psf/black/blob/main/CHANGES.md) - [Commits](psf/black@22.10.0...26.3.1) --- updated-dependencies: - dependency-name: black dependency-version: 26.3.1 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes using default effort and found 1 potential issue.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, have a team admin enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit 2f9faeb. Configure here.
| mypy-extensions==1.0.0 | ||
| types-PyYAML==6.0.12.2 | ||
| black==22.10.0 | ||
| black==26.3.1 |
There was a problem hiding this comment.
Incomplete Black security version bump
Medium Severity
This Dependabot bump updates black to 26.3.1 only in lint-requirements.txt, but CI formats via pre-commit which still pins 22.10.0, and requirements_compiled.txt / requirements_compiled_py3.14.txt still constrain black==22.10.0. The CVE-2026-32274 fix therefore does not reach the Black version actually used in lint, while constrained installs of lint-requirements.txt hit a pip resolution conflict. install_linters also installs 26.3.1 unconstrained, creating local-vs-CI version skew across multiple Black stable-style releases.
Reviewed by Cursor Bugbot for commit 2f9faeb. Configure here.


Bumps black from 22.10.0 to 26.3.1.
Release notes
Sourced from black's releases.
... (truncated)
Changelog
Sourced from black's changelog.
... (truncated)
Commits
c6755bbPrepare release 26.3.1 (#5046)69973fdHarden blackd browser-facing request handling (#5039)4937fe6Fix some shenanigans with the cache file and IPython (#5038)2e641d1docs: remove outdated Black Playground references (#5044)c014b22Remove unused internal code (#5041)0dae20bAdd new changelog (#5036)c5c1cbdMinor release patches (#5035)7e5a828docs: clarify relationship between Black style and PEP 8 (#5025)69705dedocs: add clearer pyproject configuration guidance (#5026)35ea679Prepare release 26.3.0 (#5032)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.