Skip to content

Bump the uv-dependencies group with 20 updates - #88

Merged
semenko merged 1 commit into
mainfrom
dependabot/uv/uv-dependencies-e9510c5e5d
Oct 1, 2026
Merged

semenko merged 1 commit into
mainfrom
dependabot/uv/uv-dependencies-e9510c5e5d

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown
Contributor

Bumps the uv-dependencies group with 20 updates:

Package From To
tqdm 4.70.0 4.70.1
pysam 0.24.0 0.24.1
ruff 0.16.5 0.16.9
anyio 4.14.2 4.15.1
ast-serialize 0.8.0 0.11.2
coverage 7.16.0 7.16.2
filelock 3.32.4 3.32.7
identify 2.6.19 2.6.20
idna 3.19 3.20
nodeenv 1.10.0 1.11.0
platformdirs 4.11.5 4.12.1
pure-eval 0.2.3 0.2.4
python-discovery 1.6.0 1.6.1
soupsieve 2.9.2 2.10
starlette 1.6.0 1.7.0
urllib3 2.7.0 2.8.0
uvicorn 0.52.4 0.54.0
virtualenv 21.7.7 21.13.0
watchfiles 1.2.0 1.3.0
wcwidth 0.8.3 0.9.1

Updates tqdm from 4.70.0 to 4.70.1

Release notes

Sourced from tqdm's releases.

tqdm v4.70.1 stable

  • contrib.concurrent: fix no-len iterables (#1830 <- #1828)
  • tests: major overhaul (#1819)
  • update AI policy in PR template
  • misc lint & tidy
  • CI: bump workflow actions & pre-commit hooks
Commits

Updates pysam from 0.24.0 to 0.24.1

Release notes

Sourced from pysam's releases.

v0.24.1

This minor pysam release wraps htslib/samtools/bcftools version 1.24.

It has been tested with Python versions 3.9 through 3.15 (RC2) and wheels are available via PyPI for all of those Python versions. Wheels are built for macOS and Linux (manylinux_2_28 and musllinux_1_2) on both ARM and x86-64. The final pysam release that supported Python 3.8 was v0.24.0.

Starting from v0.24.0 pysam wraps htslib 1.22 or later, which contains significant CRAM-related operational changes that are inherited by pysam: the default output CRAM version is now 3.1 rather than 3.0; CRAM reference data is no longer fetched from EBI's server by default.

Bugs fixed:

  • Fixed type hints for VariantFile to re-allow file descriptors and file-like objects as “filenames” to be opened. (PR #1406, reported by @​dpoznik)

  • Fixed AlignedSegment.get_aligned_pairs() type hints so that omitted arguments also produce precise return types. (PR #1371, reported by @​gshiba)

  • Optimized AlignedSegment.query_sequence and AlignedSegment.query_alignment_sequence, resulting in an approximately 3× speed improvement. (PR #1411)

  • Fixed tabix_compress() error handling, which now raises an exception when filename_in cannot be opened rather than treating it as an empty file.

  • Reinstated S3 support in pre-built Linux wheels when used on Debian and Ubuntu, which was broken in v0.24.0 due to pysam's CA Certificate location workaround no longer being applied to S3 URLs. (PR #1420)

  • Pre-built PyPI Linux wheels now load networking libraries dynamically at runtime when needed, rather than having copies of networking and security libraries bundled within the wheel. (PR #1420; #1097, #1276, reported by @​MikeWazoWski123 and @​shaze)

  • Cython and C source files, which have been inadvertently present in binary wheels since v0.21.0, are now properly omitted again.

New functionality:

  • New reverse_complement() and reverse_complement_inplace() functions. (PR #1411)

  • VariantRecordSample now supports Number=P (VCF v4.4 or greater) and Number=LA, LR, LG, and M (VCF v4.5). (#1419, reported by @​cjw85)

  • Pre-built PyPI wheels are no longer built with C debugging symbols, which are largely unnecessary in a Python context. Due to this and the removal of most Linux bundled libraries and the inadvertently added source code, pre-built wheels are now much smaller, especially on Linux.

  • Pysam's test suite has been overhauled to be natively pytest-based. It now uses tmp_path fixtures rather than its own ad hoc temporary file management and mostly no longer makes network requests.

Documentation improvements:

  • Added new FastxRecord documentation. (PR #1245, thanks to @​nh13)
Changelog

Sourced from pysam's changelog.

Release 0.24.1

.. rubric:: 7 September 2026

This minor pysam release wraps htslib/samtools/bcftools version 1.24.

It has been tested with Python versions 3.9 through 3.15 (RC2) and wheels are available via PyPI_ for all of those Python versions. Wheels are built for macOS and Linux (manylinux_2_28 and musllinux_1_2) on both ARM and x86-64. The final pysam release that supported Python 3.8 was v0.24.0.

Starting from v0.24.0 pysam wraps htslib 1.22 or later, which contains significant CRAM-related operational changes that are inherited by pysam: the default output CRAM version is now 3.1 rather than 3.0; CRAM reference data is no longer fetched from EBI's server by default.

Bugs fixed:

  • Fixed type hints for :class:.VariantFile to re-allow file descriptors and file-like objects as "filenames" to be opened. (PR #1406, reported by David Poznik)

  • Fixed :meth:.AlignedSegment.get_aligned_pairs type hints so that omitted arguments also produce precise return types. (PR #1371, reported by Gosuke Shibahara)

  • Optimized :attr:.AlignedSegment.query_sequence and :attr:.AlignedSegment.query_alignment_sequence, resulting in an approximately 3× speed improvement. (PR #1411)

  • Fixed :func:.tabix_compress error handling, which now raises an exception when filename_in cannot be opened rather than treating it as an empty file.

  • Reinstated S3 support in pre-built Linux wheels when used on Debian and Ubuntu, which was broken in v0.24.0 due to pysam's CA Certificate location workaround no longer being applied to S3 URLs. (PR #1420)

  • Pre-built PyPI Linux wheels now load networking libraries dynamically at runtime when needed, rather than having copies of networking and security libraries bundled within the wheel. (PR #1420; #1097, #1276, reported by @​MikeWazoWski123 and Scott Hazelhurst)

  • Cython and C source files, which have been inadvertently present in binary wheels since v0.21.0, are now properly omitted again.

New functionality:

  • New :func:.reverse_complement and :func:.reverse_complement_inplace

... (truncated)

Commits
  • ba2e6c1 Bump version number to 0.24.1 and add release notes
  • c68dc22 Implement Number=P/LA/LR/LG/M count calculation
  • 2076cbf Update to yesterday's cibuildwheel release that includes CPython 3.15 RC2
  • ff301f9 Fix documentation: this is a JSON-style dict with no actual json involved
  • cebcb9e Omit all C debugging symbols from pre-built wheels
  • 3adc0c7 Prevent libcurl/libcrypto/et al being bundled in Linux wheels
  • dbcca7b Update to FreeBSD 15.1 and omit py312-mypy
  • 0250378 Rewrite network file tests to use local test files via a local web server
  • e283649 Spelling corrections [minor]
  • 79a0984 Omit py314-mypy on NetBSD and update to NetBSD 11
  • Additional commits viewable in compare view

Updates ruff from 0.16.5 to 0.16.9

Release notes

Sourced from ruff's releases.

0.16.9

Release Notes

Released on 2026-09-24.

Preview features

  • [ruff] Avoid false positives for overloaded division (RUF069) (#28309)

Bug fixes

  • [flake8-bugbear] Avoid false positives for calls with keyword arguments (B009, B010, B043) (#28776)
  • [flake8-tidy-imports] Allow lazy imports to be used in deferred annotations (TID255) (#28767)

Rule changes

  • Update LibCST-based fixes for Python 3.15 (#28616)
  • [flake8-pyi] Mention stubs in the diagnostic message (PYI002) (#28542)

Documentation

  • Fix horizontal overflow on the rules documentation page (#28699)
  • Update rules table with category information (#28651)
  • [flake8-annotations] Clarify that ANN401 checks return types in addition to arguments (#28334)
  • [flake8-bugbear] Document type-checker interaction (B010) (#28509)
  • [flake8-comprehensions] Document map/generator exception behavior (C417) (#27794)
  • [ruff] Mention related isort settings (RUF022) (#28719)

Contributors

Install ruff 0.16.9

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/ruff/releases/download/0.16.9/ruff-installer.sh | sh

... (truncated)

Changelog

Sourced from ruff's changelog.

0.16.9

Released on 2026-09-24.

Preview features

  • [ruff] Avoid false positives for overloaded division (RUF069) (#28309)

Bug fixes

  • [flake8-bugbear] Avoid false positives for calls with keyword arguments (B009, B010, B043) (#28776)
  • [flake8-tidy-imports] Allow lazy imports to be used in deferred annotations (TID255) (#28767)

Rule changes

  • Update LibCST-based fixes for Python 3.15 (#28616)
  • [flake8-pyi] Mention stubs in the diagnostic message (PYI002) (#28542)

Documentation

  • Fix horizontal overflow on the rules documentation page (#28699)
  • Update rules table with category information (#28651)
  • [flake8-annotations] Clarify that ANN401 checks return types in addition to arguments (#28334)
  • [flake8-bugbear] Document type-checker interaction (B010) (#28509)
  • [flake8-comprehensions] Document map/generator exception behavior (C417) (#27794)
  • [ruff] Mention related isort settings (RUF022) (#28719)

Contributors

0.16.8

Released on 2026-09-16.

Bug fixes

  • Visit functional TypedDict keyword arguments correctly (#28584)
  • [flake8-simplify] Detect nested async with under sync parent (SIM117) (#27821)
  • [flake8-simplify] Preserve operand order in SIM109 fix (#27824)

... (truncated)

Commits
  • 0be08a2 Bump version to 0.16.9 (#28882)
  • b4920b7 Rename ruff_cli to ruff_command_line (#28881)
  • 47c751b Update dependency astral-sh/uv to v0.12.18 (#28880)
  • 8c244e5 [flake8-comprehensions] Document map/generator exception behavior (C417...
  • 5edf5a1 Use target form in rooster.version_files (#28876)
  • 915bb2b [ty] Prefer existing @ paths over response files in Ruff and ty (#28877)
  • 4710e1a ci(github): update version number in placeholder of issue template (#28871)
  • eedfc62 [ty] Propagate outer type context through cast calls (#28855)
  • ceaa6a0 [ty] Contain rendered code within Markdown fences (#28869)
  • dba0f30 authorize ruff-pre-commit dispatch via OIDC (#28867)
  • Additional commits viewable in compare view

Updates anyio from 4.14.2 to 4.15.1

Release notes

Sourced from anyio's releases.

4.15.1

  • Implemented a compatibility fix for supporting direct access of anyio.* submodules from the main package even when those submodules were not directly imported first (#1311 <agronholm/anyio#1311)

4.15.0

  • Added support for the newer keyword-only arguments on anyio.Path methods to match the standard library pathlib.Path:

    • follow_symlinks on exists() (Python 3.12+)
    • follow_symlinks on is_dir() (Python 3.13+)
    • follow_symlinks on is_file() (Python 3.13+)
    • follow_symlinks on owner() (Python 3.13+)
    • follow_symlinks on group() (Python 3.13+)
    • newline on read_text() (Python 3.13+)

    (#1286, #1293; PR by @​jaideeppyne)

  • Added amap, gather, and as_completed utility functions to simplify common patterns (#1173; PR by @​Graeme22)

  • Added --anyio-mode command-line option as an alternative to the anyio_mode ini setting, and fix the pytest plugin's auto mode detection to recognize the mode when set via either mechanism(e.g: pytest_asyncio). (#1242; PR by @​EmmanuelNiyonshuti)

  • Added the anyio.Future synchronization primitive which behaves similar to asyncio.Future, allowing tasks to wait for a value (or exception) from another task (#1146; PR by @​Vizonex)

  • Added guidance for managing multiple memory object stream producers and consumers with cloned streams (#330; PR by @​nightcityblade)

  • Added StapledObjectStream.send_nowait() that delegates to the underlying ObjectSendStream, if it implements it (#1241; PR by @​davidbrochart)

  • Added the move_on_at() and fail_at() functions to complement move_on_after() and fail_after()

  • Changed the default name for a task spawned with TaskGroup.create_task(func()) to match the default task name for the analogous task spawned with TaskGroup.start_soon(func) or TaskGroup.start(func) in more situations. Previously, the default name of a TaskGroup.create_task task never included the module name. (The default name for a task spawned with TaskGroup.start_soon or TaskGroup.start typically includes the module name.) (#1234; PR by @​gschaffner)

  • Changed the anyio and anyio.abc modules to lazily (much like 810) import the necessary submodules. This is done by parsing the AST of the module and building a lookup table from the if TYPE_CHECKING: block. A fallback mode has been provided for installations where the source code is unavailable (e.g. PyInstaller). (#1169)

  • Fixed free-threading compatibility issues arising from the fact that on Python 3.14 free-threading builds, newly created threads inherit the current context by default, causing AnyIO to behave erroneously in relation to start_blocking_portal() and anyio.to_thread.run_sync() (#1224; PR by @​EmmanuelNiyonshuti)

  • Fixed SpooledTemporaryFile.readinto() and readinto1() reading twice before rollover, so the destination buffer was overwritten by the second read and the file position advanced twice, silently losing data (#1215; PR by @​c-tonneslan)

  • Added a reason parameter to fail_after (and the new fail_at) allowing for added exception context when raising TimeoutError (#1227; PR by @​Graeme22)

  • Fixed the default TaskHandle.name missing part of the task name for tasks started with TaskGroup.start on Trio (#1231; PR by @​gschaffner)

  • Fixed anyio.run leaking, or at least, delaying collection of loop and root_task due to the root task being cached in a RunVar. (#1203; PR by @​tapetersen)

  • Fixed anyio.Path.with_stem() silently producing a wrong path (e.g. Path(".txt")) instead of raising ValueError when given an empty stem on a path with a non-empty suffix, unlike pathlib.PurePath.with_stem (#1200; PR by @​Sanjays2402)

  • Fixed UNIXSocketStream.aclose() raising asyncio.InvalidStateError when a concurrent receive or send operation had just been cancelled on the asyncio backend (#1267; PR by @​alloutflo)

  • Fixed the pytest plugin importing the deprecated _pytest.python.CallSpec2 alias, which triggers PytestRemovedIn10Warning on pytest>=9.2 and crashes pytest at startup when filterwarnings = error is configured (#1271; PR by @​matthewfeickert)

  • Fixed an asyncio worker thread race that could raise RuntimeError when the event loop closed between checking its state and scheduling the worker result (#1265; PR by @​hansu650)

  • Fixed CapacityLimiter on the asyncio backend over-granting tokens when total_tokens was raised while the limiter was over-subscribed (#1223; PR by @​zelinewang)

... (truncated)

Commits
  • ffcd154 Bumped up the version
  • 0ecf5ed Added a workaround for third party code accessing unimported submodules (#1309)
  • 9283662 Bumped up the version
  • d137692 Improved the instructions for AI agents
  • 033fc52 Shield TemporaryDirectory cleanup from cancellation (#1304)
  • 942e9a6 [pre-commit.ci] pre-commit autoupdate (#1305)
  • b825c3b Fixed pyproject.toml changes not triggering the test suite
  • 9727dc5 Fixed start inconsistencies between trio and asyncio (#1198)
  • b05fe6d Fixed wrong type in move_on_after (#1297)
  • 44d0c93 Fixed asyncio task group coroutine cleanup (#1275)
  • Additional commits viewable in compare view

Updates ast-serialize from 0.8.0 to 0.11.2

Commits

Updates coverage from 7.16.0 to 7.16.2

Release notes

Sourced from coverage's releases.

7.16.2

Version 7.16.2 — 2026-09-27

  • Fix: on Python 3.14 and later, a for loop completing immediately before a function return could mistakenly report an uncovered branch. This is now fixed, closing issue 2168.
  • Fix: on Python 3.14 and later, the else clause of a try whose body is a with statement could incorrectly be reported as covered when the with raised. This is now fixed, closing issue 2289.
  • Fix: with dynamic_context = test_function, test methods written as @staticmethod or @classmethod were not given a context of their own. Now they are, on Python 3.11 and later. Closes issue 1923.

➡️  PyPI page: coverage 7.16.2. :arrow_right:  To install: python3 -m pip install coverage==7.16.2

7.16.1

Version 7.16.1 — 2026-09-13

  • Fix: when the body of an irrefutable case (like case _:) is entirely excluded, the case line is now excluded too, just as an excluded else: body removes the else: line. Previously the case line was left behind and reported as missing. Closes issue 1563 with pull 2269.
  • Fix: using CoverageData.update() twice on an in-memory database would fail, as described in issue 2279. This is now fixed.

➡️  PyPI page: coverage 7.16.1. :arrow_right:  To install: python3 -m pip install coverage==7.16.1

Changelog

Sourced from coverage's changelog.

Version 7.16.2 — 2026-09-27

  • Fix: on Python 3.14 and later, a for loop completing immediately before a function return could mistakenly report an uncovered branch. This is now fixed, closing issue 2168_.

  • Fix: on Python 3.14 and later, the else clause of a try whose body is a with statement could incorrectly be reported as covered when the with raised. This is now fixed, closing issue 2289_.

  • Fix: with dynamic_context = test_function, test methods written as @staticmethod or @classmethod were not given a context of their own. Now they are, on Python 3.11 and later. Closes issue 1923_.

.. _issue 1923: coveragepy/coveragepy#1923 .. _issue 2168: coveragepy/coveragepy#2168 .. _issue 2289: coveragepy/coveragepy#2289

.. _changes_7-16-1:

Version 7.16.1 — 2026-09-13

  • Fix: when the body of an irrefutable case (like case _:) is entirely excluded, the case line is now excluded too, just as an excluded else: body removes the else: line. Previously the case line was left behind and reported as missing. Closes issue 1563_ with pull 2269_.

  • Fix: using :meth:.CoverageData.update twice on an in-memory database would fail, as described in issue 2279_. This is now fixed.

.. _issue 1563: coveragepy/coveragepy#1563 .. _pull 2269: coveragepy/coveragepy#2269 .. _issue 2279: coveragepy/coveragepy#2279

.. _changes_7-16-0:

Commits

Updates filelock from 3.32.4 to 3.32.7

Release notes

Sourced from filelock's releases.

3.32.7

What's Changed

New Contributors

Full Changelog: tox-dev/filelock@3.32.6...3.32.7

3.32.6

What's Changed

New Contributors

Full Changelog: tox-dev/filelock@3.32.5...3.32.6

3.32.5

What's Changed

New Contributors

Full Changelog: tox-dev/filelock@3.32.4...3.32.5

Changelog

Sourced from filelock's changelog.

########### Changelog ###########

.. towncrier-draft-entries:: Unreleased

.. towncrier release notes start


4.0.8 (2026-10-01)


  • ReadWriteLock.release() and SoftReadWriteLock.release() from a thread that does not hold the write lock now raise RuntimeError instead of dropping the holder's lock and letting a second writer in. :pr:761

4.0.7 (2026-09-29)


  • File locks now raise ValueError at construction when mode denies the owner read or write, such as mode=0o444, instead of failing on a later acquire and staying broken until someone deletes the lock file. :pr:760

4.0.6 (2026-09-28)


  • Reject negative blocking timeouts other than -1 before reentrant ReadWriteLock and SoftReadWriteLock acquisition. Preserve unlimited waits and nonblocking acquisition. :pr:756

4.0.5 (2026-09-28)


  • Fix MarkerSoftFileLock acquisition and prevent contenders from evicting live protocol-2 owners after two seconds. Reclaim recognized records after owner death; preserve unknown contracts. :pr:749
  • Honor instance timeout and blocking settings in sync and async ReadWriteLock acquisition, including waits between tasks on one instance. Preserve explicit per-call overrides. :pr:750
  • Skip access-denial checks when the process can read mode-0o000 files. Keep mode-bit checks enabled for privileged processes on filesystems that support POSIX permissions. :pr:753
  • Skip vanished StrictSoftFileLock claims after a read-permission retry expires. Recheck the directory before raising a protocol error so concurrent removal does not turn a stale claim listing into an acquisition failure. :pr:754
  • Reject negative timeouts other than -1 in blocking AsyncReadWriteLock and AsyncSoftReadWriteLock acquisitions. Keep -1 as an unlimited wait and ignore timeouts when blocking=False. :pr:755

4.0.4 (2026-09-26)


  • Hostnames that still differ after their first 253 escaped characters now publish distinct owners, so a soft lock no longer takes another such host's live holder for its own and reclaims its marker. :pr:748

... (truncated)

Commits
  • 20929f7 Release 3.32.7
  • 35f07c4 [pre-commit.ci] pre-commit autoupdate (#736)
  • e860d39 📝 docs: say acquire() falls back to the lock's blocking attribute (#733)
  • c530efe Fix final symlink test on musl (#737)
  • 4efd93e Release 3.32.6
  • 7b7b7a8 Fix SoftReadWriteLock state lock timeout (#726)
  • f2f7b86 fix: respect ACL write access when the owner write bit is absent (#728)
  • e947a69 test(soft-rw): reuse existing test module (#730)
  • da3ae2b fix: preserve exception notes when copying and pickling (#729)
  • ae9cb5b 🐛 fix(soft-rw): reject non-finite timing options (#724)
  • Additional commits viewable in compare view

Updates identify from 2.6.19 to 2.6.20

Commits
  • aa34031 v2.6.20
  • 116099f Merge pull request #609 from Malix-Labs/feat/add-nushell
  • 971546c Merge pull request #610 from pre-commit/lock-file-tags
  • da45cb1 Add support for 'nu' extension and Nushell interpreters
  • a35b99b Merge pull request #608 from steovd/profile-sh
  • bd5cdb7 Merge pull request #601 from ngie-eign/issue-258
  • 66faf04 Merge pull request #597 from edgarrmondragon/patch-1
  • c75a0a2 Merge pull request #593 from NinjaMandalorian/main
  • ea6c9f9 Add support for 'luau' file extension
  • d28c571 Merge pull request #585 from Kvan7/patch-1
  • Additional commits viewable in compare view

Updates idna from 3.19 to 3.20

Release notes

Sourced from idna's releases.

v3.20

  • Update to Unicode 18.0.0.
  • Better enforcement of the domain length limit in the incremental codec.
  • Add support for Python 3.15.
Changelog

Sourced from idna's changelog.

3.20 (2026-09-17)

  • Update to Unicode 18.0.0.
  • Better enforcement of the domain length limit in the incremental codec.
  • Add support for Python 3.15.
Commits
  • d55e65e Release 3.20
  • 0c0824a Pre-release 3.20rc0
  • bd7c316 Note Python 3.15 support in the 3.20 changelog
  • b6cce85 Merge pull request #276 from kjd/unicode-18
  • 9a4bc59 Update to Unicode 18.0.0
  • dfab5a0 Merge branch 'python-3.15'
  • 417c354 Read the latest Unicode version from the DerivedAge.txt header instead of the...
  • cd17392 Merge pull request #274 from kjd/fix-decode-length-check
  • c5796d7 Skip the decode round-trip check for domains past encode's length limit
  • d6ee690 Update to Python 3.15 release candidate in CI and add trove classifier
  • Additional commits viewable in compare view

Updates nodeenv from 1.10.0 to 1.11.0

Release notes

Sourced from nodeenv's releases.

1.11.0

What's Changed

New Features 🎉

Fixed bugs 🐛

Improvements 🛠

Documentation 📄

Other Changes

  • chore(release): bump nodeenv version to 1.11.0 by

Bumps the uv-dependencies group with 20 updates:

| Package | From | To |
| --- | --- | --- |
| [tqdm](https://github.com/tqdm/tqdm) | `4.70.0` | `4.70.1` |
| [pysam](https://github.com/pysam-developers/pysam) | `0.24.0` | `0.24.1` |
| [ruff](https://github.com/astral-sh/ruff) | `0.16.5` | `0.16.9` |
| [anyio](https://github.com/agronholm/anyio) | `4.14.2` | `4.15.1` |
| [ast-serialize](https://github.com/mypyc/ast_serialize) | `0.8.0` | `0.11.2` |
| [coverage](https://github.com/coveragepy/coveragepy) | `7.16.0` | `7.16.2` |
| [filelock](https://github.com/tox-dev/py-filelock) | `3.32.4` | `3.32.7` |
| [identify](https://github.com/pre-commit/identify) | `2.6.19` | `2.6.20` |
| [idna](https://github.com/kjd/idna) | `3.19` | `3.20` |
| [nodeenv](https://github.com/ekalinin/nodeenv) | `1.10.0` | `1.11.0` |
| [platformdirs](https://github.com/tox-dev/platformdirs) | `4.11.5` | `4.12.1` |
| [pure-eval](https://github.com/alexmojaki/pure_eval) | `0.2.3` | `0.2.4` |
| [python-discovery](https://github.com/tox-dev/python-discovery) | `1.6.0` | `1.6.1` |
| [soupsieve](https://github.com/facelessuser/soupsieve) | `2.9.2` | `2.10` |
| [starlette](https://github.com/Kludex/starlette) | `1.6.0` | `1.7.0` |
| [urllib3](https://github.com/urllib3/urllib3) | `2.7.0` | `2.8.0` |
| [uvicorn](https://github.com/Kludex/uvicorn) | `0.52.4` | `0.54.0` |
| [virtualenv](https://github.com/pypa/virtualenv) | `21.7.7` | `21.13.0` |
| [watchfiles](https://github.com/samuelcolvin/watchfiles) | `1.2.0` | `1.3.0` |
| [wcwidth](https://github.com/jquast/wcwidth) | `0.8.3` | `0.9.1` |


Updates `tqdm` from 4.70.0 to 4.70.1
- [Release notes](https://github.com/tqdm/tqdm/releases)
- [Commits](tqdm/tqdm@v4.70.0...v4.70.1)

Updates `pysam` from 0.24.0 to 0.24.1
- [Release notes](https://github.com/pysam-developers/pysam/releases)
- [Changelog](https://github.com/pysam-developers/pysam/blob/master/NEWS)
- [Commits](pysam-developers/pysam@v0.24.0...v0.24.1)

Updates `ruff` from 0.16.5 to 0.16.9
- [Release notes](https://github.com/astral-sh/ruff/releases)
- [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md)
- [Commits](astral-sh/ruff@0.16.5...0.16.9)

Updates `anyio` from 4.14.2 to 4.15.1
- [Release notes](https://github.com/agronholm/anyio/releases)
- [Commits](agronholm/anyio@4.14.2...4.15.1)

Updates `ast-serialize` from 0.8.0 to 0.11.2
- [Commits](mypyc/ast_serialize@v0.8.0...v0.11.2)

Updates `coverage` from 7.16.0 to 7.16.2
- [Release notes](https://github.com/coveragepy/coveragepy/releases)
- [Changelog](https://github.com/coveragepy/coveragepy/blob/main/CHANGES.rst)
- [Commits](coveragepy/coveragepy@7.16.0...7.16.2)

Updates `filelock` from 3.32.4 to 3.32.7
- [Release notes](https://github.com/tox-dev/py-filelock/releases)
- [Changelog](https://github.com/tox-dev/filelock/blob/main/docs/changelog.rst)
- [Commits](tox-dev/filelock@3.32.4...3.32.7)

Updates `identify` from 2.6.19 to 2.6.20
- [Commits](pre-commit/identify@v2.6.19...v2.6.20)

Updates `idna` from 3.19 to 3.20
- [Release notes](https://github.com/kjd/idna/releases)
- [Changelog](https://github.com/kjd/idna/blob/master/HISTORY.md)
- [Commits](kjd/idna@v3.19...v3.20)

Updates `nodeenv` from 1.10.0 to 1.11.0
- [Release notes](https://github.com/ekalinin/nodeenv/releases)
- [Changelog](https://github.com/ekalinin/nodeenv/blob/master/CHANGES)
- [Commits](ekalinin/nodeenv@1.10.0...1.11.0)

Updates `platformdirs` from 4.11.5 to 4.12.1
- [Release notes](https://github.com/tox-dev/platformdirs/releases)
- [Changelog](https://github.com/tox-dev/platformdirs/blob/main/docs/changelog.rst)
- [Commits](tox-dev/platformdirs@4.11.5...4.12.1)

Updates `pure-eval` from 0.2.3 to 0.2.4
- [Commits](alexmojaki/pure_eval@v0.2.3...v0.2.4)

Updates `python-discovery` from 1.6.0 to 1.6.1
- [Release notes](https://github.com/tox-dev/python-discovery/releases)
- [Changelog](https://github.com/tox-dev/python-discovery/blob/main/docs/changelog.rst)
- [Commits](tox-dev/python-discovery@1.6.0...1.6.1)

Updates `soupsieve` from 2.9.2 to 2.10
- [Release notes](https://github.com/facelessuser/soupsieve/releases)
- [Commits](facelessuser/soupsieve@2.9.2...2.10)

Updates `starlette` from 1.6.0 to 1.7.0
- [Release notes](https://github.com/Kludex/starlette/releases)
- [Changelog](https://github.com/Kludex/starlette/blob/main/docs/release-notes.md)
- [Commits](Kludex/starlette@1.6.0...1.7.0)

Updates `urllib3` from 2.7.0 to 2.8.0
- [Release notes](https://github.com/urllib3/urllib3/releases)
- [Changelog](https://github.com/urllib3/urllib3/blob/main/CHANGES.rst)
- [Commits](urllib3/urllib3@2.7.0...2.8.0)

Updates `uvicorn` from 0.52.4 to 0.54.0
- [Release notes](https://github.com/Kludex/uvicorn/releases)
- [Changelog](https://github.com/Kludex/uvicorn/blob/main/docs/release-notes.md)
- [Commits](Kludex/uvicorn@0.52.4...0.54.0)

Updates `virtualenv` from 21.7.7 to 21.13.0
- [Release notes](https://github.com/pypa/virtualenv/releases)
- [Changelog](https://github.com/pypa/virtualenv/blob/main/docs/changelog.rst)
- [Commits](pypa/virtualenv@21.7.7...21.13.0)

Updates `watchfiles` from 1.2.0 to 1.3.0
- [Release notes](https://github.com/samuelcolvin/watchfiles/releases)
- [Commits](samuelcolvin/watchfiles@v1.2.0...v1.3.0)

Updates `wcwidth` from 0.8.3 to 0.9.1
- [Release notes](https://github.com/jquast/wcwidth/releases)
- [Changelog](https://github.com/jquast/wcwidth/blob/master/docs/history.rst)
- [Commits](jquast/wcwidth@0.8.3...0.9.1)

---
updated-dependencies:
- dependency-name: tqdm
  dependency-version: 4.70.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: uv-dependencies
- dependency-name: pysam
  dependency-version: 0.24.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: uv-dependencies
- dependency-name: ruff
  dependency-version: 0.16.9
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: uv-dependencies
- dependency-name: anyio
  dependency-version: 4.15.1
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: uv-dependencies
- dependency-name: ast-serialize
  dependency-version: 0.11.2
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: uv-dependencies
- dependency-name: coverage
  dependency-version: 7.16.2
  dependency-type: indirect
  update-type: version-update:semver-patch
  dependency-group: uv-dependencies
- dependency-name: filelock
  dependency-version: 3.32.7
  dependency-type: indirect
  update-type: version-update:semver-patch
  dependency-group: uv-dependencies
- dependency-name: identify
  dependency-version: 2.6.20
  dependency-type: indirect
  update-type: version-update:semver-patch
  dependency-group: uv-dependencies
- dependency-name: idna
  dependency-version: '3.20'
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: uv-dependencies
- dependency-name: nodeenv
  dependency-version: 1.11.0
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: uv-dependencies
- dependency-name: platformdirs
  dependency-version: 4.12.1
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: uv-dependencies
- dependency-name: pure-eval
  dependency-version: 0.2.4
  dependency-type: indirect
  update-type: version-update:semver-patch
  dependency-group: uv-dependencies
- dependency-name: python-discovery
  dependency-version: 1.6.1
  dependency-type: indirect
  update-type: version-update:semver-patch
  dependency-group: uv-dependencies
- dependency-name: soupsieve
  dependency-version: '2.10'
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: uv-dependencies
- dependency-name: starlette
  dependency-version: 1.7.0
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: uv-dependencies
- dependency-name: urllib3
  dependency-version: 2.8.0
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: uv-dependencies
- dependency-name: uvicorn
  dependency-version: 0.54.0
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: uv-dependencies
- dependency-name: virtualenv
  dependency-version: 21.13.0
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: uv-dependencies
- dependency-name: watchfiles
  dependency-version: 1.3.0
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: uv-dependencies
- dependency-name: wcwidth
  dependency-version: 0.9.1
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: uv-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels Oct 1, 2026
@semenko
semenko merged commit 2b1a268 into main Oct 1, 2026
7 of 8 checks passed
@semenko
semenko deleted the dependabot/uv/uv-dependencies-e9510c5e5d branch October 1, 2026 13:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant