Skip to content

⬆️ deps: bump Python dev dependencies - #104

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/python-dev-dependencies
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/python-dev-dependencies

Conversation

@renovate

@renovate renovate Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
ruff (source, changelog) >=0.16.9 → >=0.17.0 age confidence
ty (changelog) >=0.0.84 → >=0.0.86 age confidence

Release Notes

astral-sh/ruff (ruff)

v0.17.0

Compare Source

Released on 2026-10-09.

The executables in our macOS and Windows release archives and ruff wheels are now code-signed.
macOS executables are signed with an Apple Developer ID certificate and notarized by Apple. Windows
executables have timestamped Authenticode signatures from Azure Artifact Signing. This enables
verification of the release publisher and binary integrity, supports publisher-based allowlisting,
and should reduce security warnings and antivirus false positives.

Breaking changes
  • Update the default and latest Python versions for 3.15 (#​28792)

    Ruff now defaults to Python 3.11 instead of 3.10 when no Python version is configured through
    target-version or
    requires-python. When
    checking for syntax errors without a configured Python version, Ruff now defaults to Python 3.15
    instead of 3.14.

  • Update the default rule set (#​28786)

    Several of the flake8-datetimez rules
    (DTZ001,
    DTZ005,
    DTZ006,
    DTZ007,
    DTZ011,
    DTZ012, and
    DTZ901) are no longer enabled by default,
    while undefined-local-with-nested-import-star-usage
    (F406), which corresponds to a syntax error, is now enabled by default.

  • Update Rust crate quick-junit to 0.8.0 (#​27295)

    JUnit output now uses a skipped attribute instead of disabled on <testsuite> elements and
    includes a skipped attribute on the root <testsuites> element.

  • [flake8-import-conventions] Add datetime as dt as a conventional alias (ICN001) (#​28790)

  • Support Unicode dummy variable names (#​28722)

    The default lint.dummy-variable-rgx
    now recognizes underscore-prefixed Unicode names, such as _次, as dummy variables.

  • Update to Unicode 17 (#​21229, #​28784)

    Ruff now uses Unicode 17 data for identifier normalization and named character escapes ("\N{...}").

  • Always show unsafe and display-only fixes in the CLI (#​27810)

    The default full output format now shows unsafe fixes and suggestions requiring manual review,
    regardless of the unsafe-fixes setting.
    Actually applying unsafe fixes still requires explicit opt-in.

  • Remove the Python dependency from conda-forge builds (conda-forge/ruff-feedstock#361)

    The conda-forge build no longer depends on Python, now supports linux-riscv64, win-arm64, and
    linux-ppc64le platforms, and now includes shell completions. However, no longer depending on
    Python means that python -m ruff and import ruff will no longer work. Use ruff directly from
    PATH instead. PyPI installations and those from the standalone installer are unaffected.

  • Remove support for ruff-lsp (#​28750)

    Support for ruff-lsp, the legacy Python language server deprecated in Ruff
    v0.9.5
    , has been removed. The Ruff VS Code
    extension now always uses the native language server; ruff.nativeServer is deprecated and
    ignored. See the migration guide.

Stabilization

The following rules have been stabilized and are no longer in preview:

The following behaviors have been stabilized:

  • The formatter, unsorted-imports (I001),
    line-too-long (E501), and
    doc-line-too-long (W505) now
    consistently ignore trailing pragma comments when computing line length. This resolved several
    bugs involving interactions between these rules
    (#​27313) but may also cause existing imports to be
    reformatted and was thus classified as a breaking change.
Preview features
  • [flake8-bugbear] Report the method name and a more precise range (B005) (#​27050)
  • [refurb] Mark fix unsafe and move to suspicious (FURB152) (#​28405)
  • [ruff] Allow docstrings in strict mode (RUF067) (#​28679)
Bug fixes
  • [flake8-builtins] Expand checks in class scopes (A001) (#​29076)
  • [flake8-self] Allow private access on object.__new__(cls) instances (SLF001) (#​29001)
  • [flake8-tidy-imports] Skip lazy-import-mismatch in stubs (TID254) (#​29095)
  • [flake8-type-checking] Add the notion of runtime-ambiguous references (#​26508)
  • [flake8-type-checking] Never flag annotations in function scopes (#​29183)
  • [pyflakes] Mark the fix as unsafe when it creates a docstring (F541) (#​28258)
  • [pylint] Preserve trailing comments in useless-return fix (PLR1711) (#​29180)
  • [ruff] Avoid false positive when pytest.raises is used in a with statement (RUF061) (#​28186)
Rule changes
  • [pyupgrade] Suggest typing.TypeForm on Python 3.15 (UP035) (#​29084)
Contributors

v0.16.10

Compare Source

Release Notes

Released on 2026-10-01.

Preview features
  • Add a migration guide for categories (#​28087)
  • [pyupgrade] Add rule for context manager iterator annotations (UP052) (#​29000)
Performance
  • Reduce memory used by diagnostics (#​28951)
Server
  • Avoid running uv format in untrusted workspaces (#​28873)
Documentation
  • Fix links to moved changelog sections and renamed mdtests (#​28941)
  • Add Python 3.15 as a supported version (#​28907)
  • Add ty as a type checker example (#​28906)
Other changes
  • Update Rust toolchain to 1.99 and MSRV to 1.97 (#​29047)
Contributors

Install ruff 0.16.10

Install prebuilt binaries via shell script
curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/ruff/releases/download/0.16.10/ruff-installer.sh | sh
Install prebuilt binaries via powershell script
powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/ruff/releases/download/0.16.10/ruff-installer.ps1 | iex"

Download ruff 0.16.10

File Platform Checksum
ruff-aarch64-apple-darwin.tar.gz Apple Silicon macOS checksum
ruff-x86_64-apple-darwin.tar.gz Intel macOS checksum
ruff-aarch64-pc-windows-msvc.zip ARM64 Windows checksum
ruff-i686-pc-windows-msvc.zip x86 Windows checksum
ruff-x86_64-pc-windows-msvc.zip x64 Windows checksum
ruff-aarch64-unknown-linux-gnu.tar.gz ARM64 Linux checksum
ruff-i686-unknown-linux-gnu.tar.gz x86 Linux checksum
ruff-powerpc64-unknown-linux-gnu.tar.gz PPC64 Linux checksum
ruff-powerpc64le-unknown-linux-gnu.tar.gz PPC64LE Linux checksum
ruff-riscv64gc-unknown-linux-gnu.tar.gz RISCV Linux checksum
ruff-s390x-unknown-linux-gnu.tar.gz S390x Linux checksum
ruff-x86_64-unknown-linux-gnu.tar.gz x64 Linux checksum
ruff-armv7-unknown-linux-gnueabihf.tar.gz ARMv7 Linux checksum
ruff-aarch64-unknown-linux-musl.tar.gz ARM64 MUSL Linux checksum
ruff-i686-unknown-linux-musl.tar.gz x86 MUSL Linux checksum
ruff-x86_64-unknown-linux-musl.tar.gz x64 MUSL Linux checksum
ruff-arm-unknown-linux-musleabihf.tar.gz ARMv6 MUSL Linux (Hardfloat) checksum
ruff-armv7-unknown-linux-musleabihf.tar.gz ARMv7 MUSL Linux checksum

Verifying GitHub Artifact Attestations

The artifacts in this release have attestations generated with GitHub Artifact Attestations. These can be verified by using the GitHub CLI:

gh attestation verify <file-path of downloaded artifact> --repo astral-sh/ruff

You can also download the attestation from GitHub and verify against that directly:

gh attestation verify <file-path of downloaded artifact> --bundle <file-path of downloaded attestation>
astral-sh/ty (ty)

v0.0.86

Compare Source

Released on 2026-10-09.

The executables in our macOS and Windows release archives and ty wheels are now code-signed.
macOS executables are signed with an Apple Developer ID certificate and notarized by Apple. Windows
executables have timestamped Authenticode signatures from Azure Artifact Signing. This enables
verification of the release publisher and binary integrity, supports publisher-based allowlisting,
and should reduce security warnings and antivirus false positives.

Bug fixes
  • Infer empty collection branches from nonempty literals (#​29131)
  • Invalidate dependency metadata when environments change (#​29126)
  • Preserve final attribute restrictions on composite types (#​29135)
  • Preserve recursive structure in Annotated values (#​29058)
  • Specialize inherited dataclass field converters (#​29192)
LSP server
  • Show documentation for annotation operators on hover (#​29185)
Core type checking
  • Check attribute and property override types (#​28556)
  • Narrow tuple unions through truthiness and type checks (#​29125)
  • Preserve literal types when consuming dictionary literals (#​29145)
  • Preserve non-boolean comparison results for intersections (#​28045)
  • Preserve receiver specializations when calling unions of bound methods (#​29015)
  • Represent uninhabited truthiness explicitly (#​28843)
  • Solve validity type context through constraint sets (#​28909)
Performance
  • Avoid recursion guards for non-generic nominal targets (#​29202)
  • Check exact exclusions before intersection positives (#​29195)
Memory usage improvements
  • Share constraints in retained sequent maps (#​28966)
Other changes
Contributors

v0.0.85

Compare Source

Released on 2026-10-06.

Preview features
  • Refresh uv project metadata when uv files change (#​28529)
Bug fixes
  • Avoid recursive lambda class decorator panics (#​28984)
  • Compare observable notebook state for equality (#​28874)
  • Detect recursive alias cycles through intersections (#​28916)
  • Fix anchoring of include and exclude patterns after the project's root changed (#​28995)
  • Fix stack overflow when inferring dynamic class metaclasses (#​28917)
  • Normalize recursive dataclass transform metadata (#​28920)
  • Normalize recursive TypedDicts during cycle recovery (#​28918)
  • Preserve cycle markers in ParamSpec specialization (#​29024)
CLI
  • Prefer existing @​ paths over response files in Ruff and ty (#​28877)
LSP server
  • Add namespace package support to import completions. (#​28202)
  • Avoid stale I/O diagnostics when closing deleted files (#​28988)
  • Contain rendered code within Markdown fences (#​28869)
  • Refresh Python settings when virtual environments change (#​28650)
Diagnostic improvements
  • Add opt-in truthiness-test-of-none-union rule (#​28889)
  • Avoid disjoint-cast diagnostics in situations where the value could have been inferred as being compatible with the casted type if it had only been inferred with the right type context (#​28851)
  • Bound nested callable signature display (#​29049)
  • Explain outdated uv versions in metadata errors (#​28959)
  • Improve display of string literal types that include unicode characters or double quotes (#​29089)
  • Improve uv metadata diagnostics (#​28990)
  • Preserve constrained type-variable failure diagnostics (#​28768)
  • Preserve generic inference errors during diagnostic recovery (#​28811)
  • Report deprecated overloads in decorator applications (#​28999)
Core type checking
  • Bound methods without a receiver are not callable (#​28981)
  • Fix member lookup on union-bounded type variables (#​29018)
  • Fix type variable inference for final class objects (#​29097)
  • Freshen ParamSpec identities consistently (#​28826)
  • Honor generic property setters in protocol compatibility (#​28562)
  • Infer nominal generic specializations from bounded type variables (#​28812)
  • Inherit annotations for unannotated subclass defaults (#​28575)
  • Keep unresolved TypeIs targets provisional (#​29066)
  • Limit wildcard exports using literal __all__ (#​28972)
  • Narrow later match cases after always-true guards (#​28960)
  • Pass generic context to call inference solver (#​29065)
  • Preserve captured variables in ParamSpec comparisons (#​28827)
  • Preserve intersection receivers in implicit dunder calls (#​28833)
  • Preserve literal unpacking during call analysis (#​28821)
  • Preserve recursive type context during constructor inference (#​28903)
  • Preserve tuple shapes when slicing NewTypes (#​29091)
  • Preserve tuple subclass identity during type expansion (#​29090)
  • Promote bounded type variables to declared constraints (#​28814)
  • Propagate outer type context through cast calls (#​28855)
  • Recognize bare TypeVarTuples in materialization checks (#​28815)
  • Retain individual overload argument expansion outcomes (#​28825)
  • Specialize instance members once (#​29043)
  • Specialize Self bounds through generic type aliases (#​28890)
  • Support slots_default in dataclass_transform (#​28885)
  • Sync vendored typeshed stubs (#​29032). Typeshed diff
  • Sync vendored typeshed stubs (#​29042). Typeshed diff
  • Validate call arguments once after inference (#​28824)
  • Validate union operands involving None (#​28931)
Performance
  • Avoid expanding recursive protocol materializations (#​29026)
  • Avoid repeated work in nested match patterns (#​28926)
  • Cache the flattened module list (#​28932)
  • Index nonlocal bindings when sweeping snapshots (#​28935)
  • Skip descendant searches for leaf modules (#​28845)
  • Skip independent constraint-pair derivation (#​28950)
  • Skip storing default definition states (#​28934)
Memory usage improvements
  • Avoid caching empty sequent maps (#​28949)
  • Avoid retaining docstring literal types (#​28944)
  • Compact bound-method receivers (#​28969)
  • Move ParamSpec signature metadata to extras (#​28970)
  • Release closed module ASTs synchronously during auto-import discovery (#​28714)
  • Skip caching trivially assignable types (#​28936)
Contributors

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • Between 12:00 AM and 03:59 AM, only on Monday (* 0-3 * * 1)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the dependencies label Oct 5, 2026
@renovate
renovate Bot enabled auto-merge (squash) October 5, 2026 01:28
@renovate
renovate Bot force-pushed the renovate/python-dev-dependencies branch from 410bb79 to 39b6f08 Compare October 8, 2026 03:00
@renovate renovate Bot changed the title ⬆️ deps: bump dependency ruff to >=0.16.10 ⬆️ deps: bump Python dev dependencies Oct 8, 2026
@renovate
renovate Bot force-pushed the renovate/python-dev-dependencies branch from 39b6f08 to 1a002b6 Compare October 11, 2026 00:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants