Skip to content

build(deps-dev): bump the uv-major group with 2 updates - #2

Merged
v-byte-cpu merged 1 commit into
mainfrom
dependabot/uv/uv-major-7938b6bc48
Sep 26, 2026
Merged

v-byte-cpu merged 1 commit into
mainfrom
dependabot/uv/uv-major-7938b6bc48

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 26, 2026

Copy link
Copy Markdown
Contributor

Bumps the uv-major group with 2 updates: complexipy and mypy.

Updates complexipy from 4.2.0 to 8.0.1

Release notes

Sourced from complexipy's releases.

8.0.1

Patch release: complexipy now ships and documents itself under its own complexipy.com domain, and the sdist includes the LICENSE file it was previously missing.

Fixed

  • The sdist now includes the LICENSE file, which was previously missing from the published source distribution.

Changed

  • Docs, package metadata, and embedded links (rule doc URLs in --suggest-refactors output, SARIF report URIs) now point to the complexipy.com custom domain instead of the GitHub Pages default. (#252)

PRs

Full Changelog: rohaquinlop/complexipy@8.0.0...8.0.1

8.0.0

Major release: complexipy is now a native Rust implementation end to end. The Python CLI is retired in favor of a Rust binary exposed through a thin console-script shim, so the whole pipeline runs without a Python interpreter. The Python API is unchanged and gains diff comparison (compute_diff, has_regressions, DiffEntry, DiffStatus) backed by the same Rust engine as the CLI. Check the migration guide before upgrading.

Changed

  • The Python CLI is retired: complexipy is now a native Rust implementation exposed through a thin console-script shim, so the whole pipeline runs without a Python interpreter. The Python API is unchanged and now includes the diff comparison (compute_diff, has_regressions, DiffEntry, DiffStatus) backed by the same Rust engine as the CLI. The extension module keeps being distributed via maturin wheels. (#224, #243)

Removed

  • Git-URL analysis (complexipy <repository-url>) - local paths only.
  • Legacy cache migration - the previous .complexipy_cache/<hash>.json layout is no longer migrated; existing legacy files are ignored and the delta history starts fresh.
  • Legacy snapshot files - snapshots created with older versions are no longer detected; recreate them with --snapshot-create.
  • -mx short flag for --max-complexity-allowed - carried over from the Python CLI but never ported to the clap-based parser; use --max-complexity-allowed instead.

Fixed

  • The C007 collapsible-if rule no longer suggests merging a nested if when a same-level statement with side effects precedes it - the merge would change program behavior. Comments in multiline headers and trailing comments are handled instead of being misplaceable by the replacement. (#228, #236)
  • The C007 preceding-statement guard no longer fails when blank or comment-only lines sit between the outer and inner if: the indent step detection now skips such lines, so the merge is still rejected instead of producing a replacement that drops code. (#245)
  • The C002 loop-guards suggestion keeps statements that sit between the chained ifs: they now appear in the replacement between the corresponding guards instead of being dropped. Guard conditions are now parenthesized (if not (<cond>):), so inverting conditions with and or or no longer silently changes what the guard skips.
  • The C005 extract-predicate suggestion keeps the statement keyword: while conditions stay while loops, and elif conditions get help text only instead of a broken standalone if replacement. The predicate body indent now follows the file's indent step.
  • C002 and C007 refuse machine suggestions when the shifted body holds a multi-line string literal: dedenting would change the string's value. The plans carry help text instead.
  • C002 loop guards strip a redundant top-level not from the guard condition (if not a: becomes guard if a:), and C005 predicate names get an underscore suffix when the source already defines the generated name.
  • C005 extract-predicate now emits a module-level helper whose parameters are the condition's free variables (attribute bases included, builtins excluded), so the helper is unit-testable. The snippet shows the enclosing context at the statement's real indentation. Conditions that bind a name (:=) or contain a lambda/comprehension get help text only.

PRs

... (truncated)

Changelog

Sourced from complexipy's changelog.

[8.0.1] - 2026-09-06

Changed

  • Docs, package metadata, and embedded links (rule doc URLs in --suggest-refactors output, SARIF report URIs) now point to the complexipy.com custom domain instead of the GitHub Pages default. (#252)

Fixed

  • The sdist now includes the LICENSE file, which was previously missing from the published source distribution.

See the release notes for the full details.

[8.0.0] - 2026-09-03

!!! note "Migration"

See the [migration guide](https://rohaquinlop.github.io/complexipy/migration/)
for the breaking changes below.

Changed

  • The Python CLI is retired: complexipy is now a native Rust implementation exposed through a thin console-script shim, so the whole pipeline runs without a Python interpreter. The Python API is unchanged and now includes the diff comparison (compute_diff, has_regressions, DiffEntry, DiffStatus) backed by the same Rust engine as the CLI. The extension module keeps being distributed via maturin wheels. (#224, #243)

Removed

  • Git-URL analysis (complexipy <repository-url>) - local paths only.
  • Legacy cache migration - the previous .complexipy_cache/<hash>.json layout is no longer migrated; existing legacy files are ignored and the delta history starts fresh.
  • Legacy snapshot files - snapshots created with older versions are no longer detected; recreate them with --snapshot-create.
  • -mx short flag for --max-complexity-allowed - carried over from the Python CLI but never ported to the clap-based parser; use --max-complexity-allowed instead.

Fixed

  • The C007 collapsible-if rule no longer suggests merging a nested if when a same-level statement with side effects precedes it - the merge

... (truncated)

Commits
  • 030e207 chore(release): bump version to 8.0.1
  • a1d37ba Merge pull request #252 from rohaquinlop/docs-url-migration
  • ae0b8e5 chore(core): rustfmt doc_url string formatting
  • 6f0d81f chore(core): update embedded rule and sarif doc urls to complexipy.com
  • c335460 chore: point docs links at the complexipy.com domain
  • 807aeaa docs(release-notes): verify rendered body and clean up scratch file
  • 0fac8bf docs(create-pr): verify rendered body and clean up scratch file
  • a36d0ce docs(release-notes): verify sdist contents and version consistency before tag...
  • bf3faed fix(build): include LICENSE file in the sdist
  • 70e2058 docs(benchmarks): drop pre-release label for 8.0.0
  • Additional commits viewable in compare view

Updates mypy from 1.20.2 to 2.3.1

Changelog

Sourced from mypy's changelog.

Mypy 2.3.1

  • Fix mypyc crash on double yielding Iterators (Daniël van Noord, PR 21826)
  • Fix mypyc default_factory for inherited dataclass (Daniël van Noord, PR 21785)
  • Clear mypyc coroutine env on coroutine completion (Piotr Sawicki, PR 21734)
  • Fix crash when unpacking return value from overload (Shantanu, PR 21830)

Acknowledgements

Thanks to all mypy contributors who contributed to this release:

  • Agriya Khetarpal
  • Ethan Sarp
  • Ivan Levkivskyi
  • Jingchen Ye
  • Jukka Lehtosalo
  • Piotr Sawicki
  • Shantanu
  • Tom Bannink
  • Viktor Szépe
  • ygale

I'd also like to thank my employer, Dropbox, for supporting mypy development.

Mypy 2.2

We've just uploaded mypy 2.2.0 to the Python Package Index (PyPI). Mypy is a static type checker for Python. This release includes new features, performance improvements and bug fixes. You can install it as follows:

python3 -m pip install -U mypy

You can read the full documentation for this release on Read the Docs.

Support for Closed TypedDicts (PEP 728)

Mypy now supports closed TypedDicts as specified in PEP 728. A closed TypedDict cannot have extra keys beyond those explicitly defined. This allows the type checker to determine that certain operations are safe when they otherwise wouldn't be due to the potential presence of unknown keys.

You can use the closed keyword argument with TypedDict:

HasName = TypedDict("HasName", {"name": str})
HasOnlyName = TypedDict("HasOnlyName", {"name": str}, closed=True)
Movie = TypedDict("Movie", {"name": str, "year": int})
movie: Movie = {"name": "Nimona", "year": 2023}
has_name: HasName = movie  # OK: HasName is open (default)
has_only_name: HasOnlyName = movie  # Error: HasOnlyName is closed and Movie has extra "year" key
</tr></table>

... (truncated)

Commits
  • d642c44 Bump version to 2.3.1
  • a392429 [mypyc] Fix crash on double yielding Iterators (#21826)
  • 4843e77 [mypyc] Fix default_factory for inherited dataclass (#21785)
  • 14f5df9 [mypyc] Clear coroutine env on coroutine completion (#21734)
  • 6dfa06d Fix crash when unpacking return value from overload (#21830)
  • a385746 Bump version to 2.3.1+dev
  • 8aabf84 Drop +dev from version
  • 4d8ad2a Update changelog for 2.3 release (#21728)
  • 2c21546 [mypyc] Update documentation of race conditions under free threading (#21726)
  • a9f62a3 [mypyc] Make attribute access memory safe on free-threaded builds (#21705)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the uv-major group with 2 updates: [complexipy](https://github.com/rohaquinlop/complexipy) and [mypy](https://github.com/python/mypy).


Updates `complexipy` from 4.2.0 to 8.0.1
- [Release notes](https://github.com/rohaquinlop/complexipy/releases)
- [Changelog](https://github.com/rohaquinlop/complexipy/blob/main/CHANGELOG.md)
- [Commits](rohaquinlop/complexipy@4.2.0...8.0.1)

Updates `mypy` from 1.20.2 to 2.3.1
- [Changelog](https://github.com/python/mypy/blob/master/CHANGELOG.md)
- [Commits](python/mypy@v1.20.2...v2.3.1)

---
updated-dependencies:
- dependency-name: complexipy
  dependency-version: 8.0.1
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: uv-major
- dependency-name: mypy
  dependency-version: 2.3.1
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: uv-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels Sep 26, 2026
@v-byte-cpu
v-byte-cpu merged commit 12a06d9 into main Sep 26, 2026
2 checks passed
@dependabot
dependabot Bot deleted the dependabot/uv/uv-major-7938b6bc48 branch September 26, 2026 18:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant