Take the Python toolchain to its current patches - #26
Merged
Merged
Conversation
Three packages, all inside the range `pyproject.toml` already states, so the lock file is the only intent that moves: pydantic 2.13.4 -> 2.13.5, mypy 2.3.0 -> 2.3.1 and ruff 0.16.2 -> 0.16.8. `pydantic-core` follows pydantic, as it always does. Ruff and mypy are the two packages a bump can break without breaking a test, because they are the checks themselves -- a new release finds things the old one did not. Neither does here: `ruff check`, `ruff format --check` and `mypy src` are clean on the new versions with no source change and no ignore added. `docs/legal/third-party-notices.md` states the version that is locked, so the three rows move with the lock. That coupling is what `test_third_party_notice_contract.py` gates, and it is why a dependency bump can never be a lock-file-only commit here.
basecubedev
force-pushed
the
deps/python-group
branch
from
September 20, 2026 14:09
3a4f789 to
92553f2
Compare
basecubedev
added a commit
that referenced
this pull request
Sep 20, 2026
Take the Python toolchain to its current patches
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Three packages, all inside the range
pyproject.tomlalready states, so the lock file is the only intent that moves: pydantic 2.13.4 -> 2.13.5, mypy 2.3.0 -> 2.3.1 and ruff 0.16.2 -> 0.16.8.pydantic-corefollows pydantic, as it always does.Ruff and mypy are the two packages a bump can break without breaking a test, because they are the checks themselves -- a new release finds things the old one did not. Neither does here:
ruff check,ruff format --checkandmypy srcare clean on the new versions with no source change and no ignore added.docs/legal/third-party-notices.mdstates the version that is locked, so the three rows move with the lock. That coupling is whattest_third_party_notice_contract.pygates, and it is why a dependency bump can never be a lock-file-only commit here.