Skip to content

build(deps): bump the ci-python-tools group across 1 directory with 6 updates - #6

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/dot-github/requirements/ci-python-tools-26f2aa4613
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/dot-github/requirements/ci-python-tools-26f2aa4613

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 9, 2026

Copy link
Copy Markdown

Bumps the ci-python-tools group with 6 updates in the /.github/requirements directory:

Package From To
filelock 3.32.5 4.0.9
identify 2.6.19 2.6.20
nodeenv 1.10.0 1.11.0
platformdirs 4.11.7 4.12.2
python-discovery 1.6.0 1.6.1
virtualenv 21.7.8 21.14.3

Updates filelock from 3.32.5 to 4.0.9

Release notes

Sourced from filelock's releases.

4.0.9

What's Changed

New Contributors

Full Changelog: tox-dev/filelock@4.0.8...4.0.9

4.0.8

What's Changed

Full Changelog: tox-dev/filelock@4.0.7...4.0.8

4.0.7

What's Changed

Full Changelog: tox-dev/filelock@4.0.6...4.0.7

4.0.6

What's Changed

Full Changelog: tox-dev/filelock@4.0.5...4.0.6

4.0.5

What's Changed

New Contributors

... (truncated)

Changelog

Sourced from filelock's changelog.

########### Changelog ###########

.. towncrier-draft-entries:: Unreleased

.. towncrier release notes start


4.0.12 (2026-10-05)


  • Fix read-lock acquisition on SQLite versions older than 3.33.0 by using sqlite_master for the schema probe. :pr:769

4.0.11 (2026-10-05)


  • ReadWriteLock and AsyncReadWriteLock use a validated private hard link when /dev/fd has no entry for the database descriptor, supporting NetBSD's static descriptor directory beyond descriptor 63. The temporary location must share a filesystem with the database. The symlink refusal test accepts NetBSD's error wording.

4.0.10 (2026-10-03)


  • Reusing a singleton AsyncFileLock with another loop, executor or run_in_executor, or a singleton SoftFileLease with another lease_duration, heartbeat_interval or on_compromise, now raises ValueError instead of returning the lock with its original options. :pr:765

4.0.9 (2026-10-01)


  • ReadWriteLock and AsyncReadWriteLock close the descriptor that checks the database path once SQLite has connected, so on PyPy a dropped lock leaves no descriptor open until garbage collection runs. :pr:763
  • ReadWriteLock and AsyncReadWriteLock refuse a symlink at the database path instead of following it, so a user who can create names in a shared lock directory cannot point the lock at another file (GHSA-j8f7-rjxc-mr56).

4.0.8 (2026-10-01)


  • ReadWriteLock.release() and SoftReadWriteLock.release() from a thread that does not hold the write lock now raise RuntimeError instead of dropping the holder's lock and letting a second writer in. :pr:761

4.0.7 (2026-09-29)


... (truncated)

Commits
  • 7b00bb8 Release 4.0.9
  • 4944624 🐛 fix(read-write): close db fd after connect (#763)
  • 162060e 📝 docs(util): correct write and break guarantees (#762)
  • 4d45e83 Merge commit from fork
  • 9376e9b Release 4.0.8
  • 34f4657 🐛 fix(read-write): refuse cross-thread write release (#761)
  • 9ed62ac Release 4.0.7
  • 2f2c4a7 🐛 fix(mode): require owner read and write (#760)
  • d4ffe9c build(deps): bump astral-sh/setup-uv from 10.1.0 to 10.2.0 in the github-acti...
  • 61ce360 Release 4.0.6
  • Additional commits viewable in compare view

Updates identify from 2.6.19 to 2.6.20

Commits
  • aa34031 v2.6.20
  • 116099f Merge pull request #609 from Malix-Labs/feat/add-nushell
  • 971546c Merge pull request #610 from pre-commit/lock-file-tags
  • da45cb1 Add support for 'nu' extension and Nushell interpreters
  • a35b99b Merge pull request #608 from steovd/profile-sh
  • bd5cdb7 Merge pull request #601 from ngie-eign/issue-258
  • 66faf04 Merge pull request #597 from edgarrmondragon/patch-1
  • c75a0a2 Merge pull request #593 from NinjaMandalorian/main
  • ea6c9f9 Add support for 'luau' file extension
  • d28c571 Merge pull request #585 from Kvan7/patch-1
  • Additional commits viewable in compare view

Updates nodeenv from 1.10.0 to 1.11.0

Release notes

Sourced from nodeenv's releases.

1.11.0

What's Changed

New Features 🎉

Fixed bugs 🐛

Improvements 🛠

Documentation 📄

Other Changes

New Contributors

Full Changelog: ekalinin/nodeenv@1.10.0...1.11.0

Changelog

Sourced from nodeenv's changelog.

Version 1.11.0

  • Fixed zsh source bin/activate aborting on the direct-call guard [#398](https://github.com/ekalinin/nodeenv/issues/398) <https://github.com/ekalinin/nodeenv/issues/398>_
  • Added check for how activate is called [#384](https://github.com/ekalinin/nodeenv/issues/384) <https://github.com/ekalinin/nodeenv/pull/384>_
  • Addressed the tarfile.extractall deprecation on Python >= 3.12 by setting filter='data', which also prevents writing files via ".." or absolute paths [#380](https://github.com/ekalinin/nodeenv/issues/380) <https://github.com/ekalinin/nodeenv/pull/380>_
  • Added support for Solaris/illumos [#360](https://github.com/ekalinin/nodeenv/issues/360) <https://github.com/ekalinin/nodeenv/issues/360>_
  • Added predeactivate hooks for Windows
  • Added error handling and tests for the node installation [#336](https://github.com/ekalinin/nodeenv/issues/336) <https://github.com/ekalinin/nodeenv/issues/336>_
  • Removed the leftover debug print that leaked a dict to stdout on every version detection [#390](https://github.com/ekalinin/nodeenv/issues/390) <https://github.com/ekalinin/nodeenv/issues/390>_
  • Added --with-certifi to download packages with the certifi certificate bundle [#388](https://github.com/ekalinin/nodeenv/issues/388) <https://github.com/ekalinin/nodeenv/pull/388>_
  • --node accepts npm-style semver ranges [#393](https://github.com/ekalinin/nodeenv/issues/393) <https://github.com/ekalinin/nodeenv/pull/393>_
  • Added --prefer-system to use system-wide node.js when available and install one otherwise [#153](https://github.com/ekalinin/nodeenv/issues/153) <https://github.com/ekalinin/nodeenv/issues/153>_
  • Added --isolate-npm to keep npm cache, userconfig and init-module inside the environment [#154](https://github.com/ekalinin/nodeenv/issues/154) <https://github.com/ekalinin/nodeenv/issues/154>_
  • Added tests that run the activation scripts in sh, dash, bash, zsh and fish.
  • -p no longer reinstalls node when the requested version is already in the virtualenv [#159](https://github.com/ekalinin/nodeenv/issues/159) <https://github.com/ekalinin/nodeenv/issues/159>_
  • Repeated -p runs no longer duplicate the predeactivate hook [#159](https://github.com/ekalinin/nodeenv/issues/159) <https://github.com/ekalinin/nodeenv/issues/159>_
  • -p accepts an optional virtualenv directory and prefers the activated VIRTUAL_ENV over the virtualenv nodeenv itself is installed in [#156](https://github.com/ekalinin/nodeenv/issues/156) <https://github.com/ekalinin/nodeenv/issues/156>_
  • -r/--requirements may now be given more than once, and the new --local-requirements installs the packages of a file locally, into "node_modules" of the current directory, which is what freeze -l writes. Under npm < 1.0.0, which has no -g, a local file is still installed the old way [#206](https://github.com/ekalinin/nodeenv/issues/206) <https://github.com/ekalinin/nodeenv/issues/206>_
  • The "src" directory is now removed after installation by default, which halves the size of an environment. Added --no-clean-src to keep it: with --source that is what lets a repeated --force build reuse the downloaded source tree [#205](https://github.com/ekalinin/nodeenv/issues/205) <https://github.com/ekalinin/nodeenv/issues/205>_
  • Documented that --mirror takes a file:// URL, so a local directory can serve as the download source [#193](https://github.com/ekalinin/nodeenv/issues/193) <https://github.com/ekalinin/nodeenv/issues/193>_
  • The posix activate is now written on Windows too, into "Scripts", so git-bash and the other posix shells there can activate an environment [#226](https://github.com/ekalinin/nodeenv/issues/226) <https://github.com/ekalinin/nodeenv/issues/226>_
  • A download that reaches nothing at all, which a broken http_proxy or https_proxy usually causes, now reports the url and the proxy settings instead of a traceback

... (truncated)

Commits
  • e745358 Merge pull request #418 from ekalinin/chore/release-1.11.0
  • fd19956 chore(release): bump nodeenv version to 1.11.0
  • 1767015 Merge pull request #415 from ekalinin/fix/nodejs-exe-link
  • 55df3ce Merge pull request #417 from r3wretrhy/fix/zsh-activate-source-guard
  • bb15c5c fix: allow zsh to source bin/activate
  • 152cd3d fix(nodeenv): link nodejs.exe without mklink
  • d163302 Merge pull request #414 from ekalinin/fix/freeze-requirements
  • ef5ec35 fix(nodeenv): read npm's parseable listing in freeze
  • b1f0c54 Merge pull request #413 from ekalinin/fix/musl-vendor-detection
  • aadf307 fix(nodeenv): detect musl regardless of the host triplet vendor
  • Additional commits viewable in compare view

Updates platformdirs from 4.11.7 to 4.12.2

Release notes

Sourced from platformdirs's releases.

4.12.2

What's Changed

New Contributors

Full Changelog: tox-dev/platformdirs@4.12.1...4.12.2

4.12.1

What's Changed

Full Changelog: tox-dev/platformdirs@4.12.0...4.12.1

4.12.0

What's Changed

Full Changelog: tox-dev/platformdirs@4.11.15...4.12.0

4.11.15

What's Changed

... (truncated)

Changelog

Sourced from platformdirs's changelog.

########### Changelog ###########

.. towncrier-draft-entries:: Unreleased

.. towncrier release notes start


4.12.4 (2026-10-07)


  • Keep site directories readable by other users when root calls :meth:~platformdirs.api.PlatformDirsABC.place_config_file or another place_*_file method with :attr:~platformdirs.api.PlatformDirsABC.use_site_for_root - by :user:darrenhuai. :pr:610
  • Make :func:~platformdirs.user_runtime_dir warn and fall back from an unreachable XDG_RUNTIME_DIR under :attr:~platformdirs.api.PlatformDirsABC.ensure_exists instead of raising. :pr:611

4.12.3 (2026-10-03)


  • Place files from place_config_file and place_data_file in the first site directory for root on Unix with use_site_for_root=True and multipath=True, where find_config_file and find_data_file look for them. :pr:607

4.12.2 (2026-09-29)


  • Keep os.pathsep in site_applications_path under multipath=True on platforms with one applications directory. :pr:604

4.12.1 (2026-09-28)


  • Avoid PytestAssertRewriteWarning when importing platformdirs before invoking pytest. :pr:601

4.12.0 (2026-09-26)


  • Add place_*_file methods that return a file path under a user directory and create its missing parents with mode 0o700. :pr:585
  • Add find_<kind>_file and find_<kind>_files to look up an existing file across the user and site directories of each kind that has an iter_<kind>_paths method. :pr:586
  • Add :func:platformdirs.testing.isolated_dirs and the platformdirs_isolated pytest fixture to resolve every directory under one test root. :pr:590
  • Emit :class:~platformdirs.RuntimeDirWarning when the Unix :func:~platformdirs.user_runtime_dir falls back from

... (truncated)

Commits
  • af2fc7f Release 4.12.2
  • bdafa67 ♻️ refactor(api): share use_site iteration (#606)
  • d5ff75c 🐛 fix(api): keep os.pathsep in site_applications_path (#604)
  • d545744 build(deps): bump astral-sh/setup-uv from 10.1.0 to 10.2.0 in the all group (...
  • 9fd89a7 [pre-commit.ci] pre-commit autoupdate (#603)
  • 0a50795 Release 4.12.1
  • 72e93ff fix(pytest): allow import before pytest startup (#602)
  • ea7be87 Release 4.12.0
  • de46f51 🐛 fix(unix): validate XDG_RUNTIME_DIR and warn on fallback (#599)
  • ca2b313 🐛 fix(dirs): raise when no home directory resolves (#589)
  • Additional commits viewable in compare view

Updates python-discovery from 1.6.0 to 1.6.1

Release notes

Sourced from python-discovery's releases.

v1.6.1

What's Changed

Full Changelog: tox-dev/python-discovery@1.6.0...1.6.1

Changelog

Sourced from python-discovery's changelog.

Bug fixes - 1.6.1

  • Skip empty PATH entries during interpreter discovery - by :user:gaborbernat. (:issue:129)

Improved documentation - 1.6.1

  • Document :attr:~python_discovery.PythonInfo.system_exe across the tutorial, the how-to guide and the explanation of how resolution reaches a base interpreter. The class diagram in the how-to guide had :attr:~python_discovery.PythonInfo.system_executable typed str rather than str | None - by :user:gaborbernat. (:issue:128)

v1.6.0 (2026-08-28)


Commits

Updates virtualenv from 21.7.8 to 21.14.3

Release notes

Sourced from virtualenv's releases.

21.14.3

What's Changed

Full Changelog: pypa/virtualenv@21.14.2...21.14.3

21.14.2

What's Changed

Full Changelog: pypa/virtualenv@21.14.1...21.14.2

21.14.1

What's Changed

Full Changelog: pypa/virtualenv@21.14.0...21.14.1

21.14.0

What's Changed

... (truncated)

Changelog

Sourced from virtualenv's changelog.

Bugfixes - 21.14.3

  • Honor ~= and every clause of a seed wheel's Requires-Python when picking a wheel for the target Python, and skip a wheel whose Requires-Python is not a valid specifier instead of failing - by :user:pasmud. (:issue:3369)

v21.14.2 (2026-10-01)


Bugfixes - 21.14.2

  • Fix pyvenv.cfg getting an absolute path in python-version, include-system-site-packages and the other keys that hold no path when the working directory has an entry named like the value, such as 3.14 for virtualenv 3.14 or true with --system-site-packages - by :user:darrenhuai. (:issue:3366)
  • Fix activation scripts running code from a virtual environment path whose parent directory carries a placeholder name such as __VIRTUAL_NAME__ (GHSA-8rjx-v5ww-45pp <https://github.com/pypa/virtualenv/security/advisories/GHSA-8rjx-v5ww-45pp>), and activate.fish running commands from a path or --prompt that holds a backslash before a single quote (GHSA-c947-3pg5-gm8q <https://github.com/pypa/virtualenv/security/advisories/GHSA-c947-3pg5-gm8q>); both reported by :user:Kwstubbs of GitHub Security Lab. (:issue:3367)

v21.14.1 (2026-09-29)


No significant changes.


v21.14.0 (2026-09-29)


Features - 21.14.0

  • Record the SPDX license id in the wheel and zipapp SBOMs for bundled packages that declare their license by name or classifier, such as distlib and python-discovery, so license scanners can match them. (:issue:3339)
  • Add the Tidelift and thanks.dev funding links to the PyPI project URLs, next to GitHub Sponsors - by :user:gaborbernat. (:issue:3340)

Bugfixes - 21.14.0

  • Build the release sdist, wheel and zipapp with the build backend and SBOM tools that tasks/release-requirements.txt pins by version and SHA-256, so a rebuild of the tag uses the same versions. (:issue:3337)
  • Use PEP 440 version ordering when selecting seed wheels, so pinned pre-releases, post-releases and local versions resolve to the requested wheel. (:issue:3361)

... (truncated)

Commits
  • fe14686 release 21.14.3
  • 85db059 Upgrade embedded pip/setuptools/wheel and CI test tools (#3368)
  • 40d94e3 Apply the whole Requires-Python specifier set in Wheel.support_py (#3369)
  • 03643d5 📝 docs(changelog): link the 21.14.0 wheel-order fix to #3361 (#3371)
  • 3bd51f5 ✨ feat(security): add a private vulnerability report form (#3370)
  • a6bdda0 release 21.14.2
  • 9916be9 🐛 fix(create): keep non-path pyvenv.cfg values as written (#3366)
  • 415224a 📝 docs(changelog): note the activation security fixes (#3367)
  • 602b266 Merge commit from fork
  • 3bddeaf Merge commit from fork
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

… updates

Bumps the ci-python-tools group with 6 updates in the /.github/requirements directory:

| Package | From | To |
| --- | --- | --- |
| [filelock](https://github.com/tox-dev/py-filelock) | `3.32.5` | `4.0.9` |
| [identify](https://github.com/pre-commit/identify) | `2.6.19` | `2.6.20` |
| [nodeenv](https://github.com/ekalinin/nodeenv) | `1.10.0` | `1.11.0` |
| [platformdirs](https://github.com/tox-dev/platformdirs) | `4.11.7` | `4.12.2` |
| [python-discovery](https://github.com/tox-dev/python-discovery) | `1.6.0` | `1.6.1` |
| [virtualenv](https://github.com/pypa/virtualenv) | `21.7.8` | `21.14.3` |



Updates `filelock` from 3.32.5 to 4.0.9
- [Release notes](https://github.com/tox-dev/py-filelock/releases)
- [Changelog](https://github.com/tox-dev/filelock/blob/main/docs/changelog.rst)
- [Commits](tox-dev/filelock@3.32.5...4.0.9)

Updates `identify` from 2.6.19 to 2.6.20
- [Commits](pre-commit/identify@v2.6.19...v2.6.20)

Updates `nodeenv` from 1.10.0 to 1.11.0
- [Release notes](https://github.com/ekalinin/nodeenv/releases)
- [Changelog](https://github.com/ekalinin/nodeenv/blob/master/CHANGES)
- [Commits](ekalinin/nodeenv@1.10.0...1.11.0)

Updates `platformdirs` from 4.11.7 to 4.12.2
- [Release notes](https://github.com/tox-dev/platformdirs/releases)
- [Changelog](https://github.com/tox-dev/platformdirs/blob/main/docs/changelog.rst)
- [Commits](tox-dev/platformdirs@4.11.7...4.12.2)

Updates `python-discovery` from 1.6.0 to 1.6.1
- [Release notes](https://github.com/tox-dev/python-discovery/releases)
- [Changelog](https://github.com/tox-dev/python-discovery/blob/main/docs/changelog.rst)
- [Commits](tox-dev/python-discovery@1.6.0...1.6.1)

Updates `virtualenv` from 21.7.8 to 21.14.3
- [Release notes](https://github.com/pypa/virtualenv/releases)
- [Changelog](https://github.com/pypa/virtualenv/blob/main/docs/changelog.rst)
- [Commits](pypa/virtualenv@21.7.8...21.14.3)

---
updated-dependencies:
- dependency-name: filelock
  dependency-version: 4.0.9
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: ci-python-tools
- dependency-name: identify
  dependency-version: 2.6.20
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: ci-python-tools
- dependency-name: nodeenv
  dependency-version: 1.11.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: ci-python-tools
- dependency-name: platformdirs
  dependency-version: 4.12.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: ci-python-tools
- dependency-name: python-discovery
  dependency-version: 1.6.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: ci-python-tools
- dependency-name: virtualenv
  dependency-version: 21.14.3
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: ci-python-tools
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Oct 9, 2026
@dependabot
dependabot Bot requested a review from joey-huckabee as a code owner October 9, 2026 02:25
@dependabot dependabot Bot added python Pull requests that update python code dependencies Pull requests that update a dependency file labels Oct 9, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants