Skip to content

Bump the patches group across 1 directory with 6 updates - #1892

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/patches-86052a1119
Closed

Bump the patches group across 1 directory with 6 updates#1892
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/patches-86052a1119

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 12, 2026

Copy link
Copy Markdown
Contributor

Bumps the patches group with 6 updates in the / directory:

Package From To
django-guardian 3.3.2 3.3.3
django-polymorphic 4.11.6 4.11.7
markdown 3.10.2 3.10.3
css-inline 0.21.0 0.21.1
coverage 7.15.2 7.15.4
prek 0.4.10 0.4.12

Updates django-guardian from 3.3.2 to 3.3.3

Release notes

Sourced from django-guardian's releases.

3.3.3

What's Changed

New Contributors

Full Changelog: django-guardian/django-guardian@3.3.2...3.3.3

Commits
  • bd5a274 Merge pull request #1006 from django-guardian/version-update-3-3-3
  • a73329e Bump version to 3.3.3
  • a39dd2c Merge pull request #1005 from django-guardian/1004-lits-of-maintainers-in-pyp...
  • 6802c32 Merge pull request #1003 from django-guardian/dependabot/github_actions/githu...
  • 209ad03 The maintainers have been updated
  • 66ce5bb Bump astral-sh/setup-uv from 8.2.0 to 8.3.2 in the github-actions group
  • 2bc6a89 Merge pull request #1002 from django-guardian/dependabot/github_actions/githu...
  • 2eddd31 Bump actions/setup-python in the github-actions group
  • 63b015c Fix generic object_pk bigint cast regression in shortcuts (#990)
  • 4de11eb Merge pull request #1001 from django-guardian/dependabot/github_actions/githu...
  • Additional commits viewable in compare view

Updates django-polymorphic from 4.11.6 to 4.11.7

Release notes

Sourced from django-polymorphic's releases.

v4.11.7

What's Changed

New Contributors

Full Changelog: django-commons/django-polymorphic@v4.11.6...v4.11.7

Commits
  • f78240b add a regression test for #905
  • c1fd7c6 fix: add kwargs to save method to keep compatability with other tools overrid...
  • 2b1b76a fix secondary test database 6.1 behavior
  • 113d405 exclude django 6.1 postgres <15 tests
  • 7051576 fix django 6.1 descriptor get_queryset compat
  • 14b9bad support django 6.1
  • See full diff in compare view

Updates markdown from 3.10.2 to 3.10.3

Release notes

Sourced from markdown's releases.

Release 3.10.3

Fixed

  • Fix SetextHeaderProcessor regex to prevent mixed = and - chars in setext-style headers (#1606).
  • Add AI Policy to Contributing Guide.
  • Officially document all included extensions as being in maintenance mode.
  • Link the Extension API documentation to the API Reference (#1612).
Changelog

Sourced from markdown's changelog.

[3.10.3] - 2026-07-30

Fixed

  • Fix SetextHeaderProcessor regex to prevent mixed = and - chars in setext-style headers (#1606).
  • Add AI Policy to Contributing Guide.
  • Officially document all included extensions as being in maintenance mode.
  • Link the Extension API documentation to the API Reference (#1612).
Commits
  • bb50627 Bump version to 3.10.3
  • 8453df0 Update Extension API documentation
  • 93ac448 Document that all extensions are in maintenance mode
  • d38fd4a Create AI Policy
  • ddead47 Prevent mixed =/- chars in Setext-style headings
  • See full diff in compare view

Updates css-inline from 0.21.0 to 0.21.1

Release notes

Sourced from css-inline's releases.

[C] Release 0.21.1

Fixed

  • With keep_at_rules enabled, at-rules without a block (e.g. @import) lost their prelude and terminator, fusing with the following rule (@import@media ...) and producing a stylesheet browsers reject entirely.

[Java] Release 0.21.1

Fixed

  • With keep_at_rules enabled, at-rules without a block (e.g. @import) lost their prelude and terminator, fusing with the following rule (@import@media ...) and producing a stylesheet browsers reject entirely.

[JavaScript] Release 0.21.1

Fixed

  • With keep_at_rules enabled, at-rules without a block (e.g. @import) lost their prelude and terminator, fusing with the following rule (@import@media ...) and producing a stylesheet browsers reject entirely.

[PHP] Release 0.21.1

Fixed

  • With keep_at_rules enabled, at-rules without a block (e.g. @import) lost their prelude and terminator, fusing with the following rule (@import@media ...) and producing a stylesheet browsers reject entirely.

[Python] Release 0.21.1

Fixed

  • With keep_at_rules enabled, at-rules without a block (e.g. @import) lost their prelude and terminator, fusing with the following rule (@import@media ...) and producing a stylesheet browsers reject entirely.

[Ruby] Release 0.21.1

Fixed

  • With keep_at_rules enabled, at-rules without a block (e.g. @import) lost their prelude and terminator, fusing with the following rule (@import@media ...) and producing a stylesheet browsers reject entirely.

[Rust] Release 0.21.1

Fixed

  • With keep_at_rules enabled, at-rules without a block (e.g. @import) lost their prelude and terminator, fusing with the following rule (@import@media ...) and producing a stylesheet browsers reject entirely.
Changelog

Sourced from css-inline's changelog.

[0.21.1] - 2026-08-08

Fixed

  • With keep_at_rules enabled, at-rules without a block (e.g. @import) lost their prelude and terminator, fusing with the following rule (@import@media ...) and producing a stylesheet browsers reject entirely.
Commits
  • 0f37b40 chore(c): Release 0.21.1
  • 948fe99 chore(python): Release 0.21.1
  • e76640a build(deps): bump js-yaml from 3.15.0 to 3.15.1 in /bindings/javascript
  • 1f85320 build(deps): bump brace-expansion in /bindings/javascript
  • 38f60a9 build(deps): bump soupsieve in /bindings/python/requirements
  • 61fe95f build(deps): bump shell-quote in /bindings/javascript
  • eb9a9da build(deps): bump tar from 7.5.16 to 7.5.22 in /bindings/javascript
  • 28e4106 build(deps): bump quinn-proto in /bindings/ruby/ext/css_inline
  • 9aa94d9 build(deps): bump quinn-proto from 0.11.14 to 0.11.16 in /bindings/ruby
  • dd3269e build(deps): bump brace-expansion in /bindings/javascript
  • Additional commits viewable in compare view

Updates coverage from 7.15.2 to 7.15.4

Release notes

Sourced from coverage's releases.

7.15.4

Version 7.15.4 — 2026-08-06

  • Fix: in the HTML report, a source file name containing a double quote (legal on POSIX) wasn’t escaped where it’s dropped into the href of the index and prev/next links, so it could close the attribute early and inject markup. Page URLs are now escaped. Thanks, Rajath Mohare.
  • Fix: the LCOV report wrote file names and other fields into its line-oriented records without neutralizing control characters. A measured file whose name contained a newline (legal on POSIX) could forge extra records, inflating the coverage seen by tools that read the report. Control characters in a field are now replaced. Thanks, Rajath Mohare.
  • Wheels are now provided for Python 3.15.

➡️  PyPI page: coverage 7.15.4. :arrow_right:  To install: python3 -m pip install coverage==7.15.4

7.15.3

Version 7.15.3 — 2026-08-02

  • Fix: the sysmon core is incompatible with dynamic contexts. Previously, the combination would be prevented when read from the coverage.py configuration. But using the context API as pytest-cov does, contexts would be silently dropped. Now a warning is issued, thanks to Jisang Han. Closes issue 2200.
  • A performance improvement in the low-level line number bookkeeping when combining data files, thanks to Kevin Turcios.
  • Performance improvement in HTML reporting by reducing the number of times files have to be parsed, thanks to Kevin Turcios.

➡️  PyPI page: coverage 7.15.3. :arrow_right:  To install: python3 -m pip install coverage==7.15.3

Changelog

Sourced from coverage's changelog.

Version 7.15.4 — 2026-08-06

  • Fix: in the HTML report, a source file name containing a double quote (legal on POSIX) wasn't escaped where it's dropped into the href of the index and prev/next links, so it could close the attribute early and inject markup. Page URLs are now escaped. Thanks, Rajath Mohare <pull 2227_>_.

  • Fix: the LCOV report wrote file names and other fields into its line-oriented records without neutralizing control characters. A measured file whose name contained a newline (legal on POSIX) could forge extra records, inflating the coverage seen by tools that read the report. Control characters in a field are now replaced. Thanks, Rajath Mohare <pull 2226_>_.

  • Wheels are now provided for Python 3.15.

.. _pull 2226: coveragepy/coveragepy#2226 .. _pull 2227: coveragepy/coveragepy#2227

.. _changes_7-15-3:

Version 7.15.3 — 2026-08-02

  • Fix: the sysmon core is incompatible with dynamic contexts. Previously, the combination would be prevented when read from the coverage.py configuration. But using the context API as pytest-cov does, contexts would be silently dropped. Now a warning is issued, thanks to Jisang Han <pull 2234_>. Closes issue 2200.

  • A performance improvement in the low-level line number bookkeeping when combining data files, thanks to Kevin Turcios <pull 2239_>_.

  • Performance improvement in HTML reporting by reducing the number of times files have to be parsed, thanks to Kevin Turcios <pull 2240_>_.

.. _issue 2200: coveragepy/coveragepy#2200 .. _pull 2234: coveragepy/coveragepy#2234 .. _pull 2239: coveragepy/coveragepy#2239 .. _pull 2240: coveragepy/coveragepy#2240

.. _changes_7-15-2:

Commits
  • 4c0e7ff docs: sample HTML for 7.15.4
  • db4cc32 docs: prep for 7.15.4
  • c33085c style: start gradual move to ruff 0.16
  • 53a0fd5 fix: neutralize control characters in lcov report fields (#2226)
  • b64d53d build: make 3.15 wheels
  • 53792ab build: show the python version for kits
  • f6b03c7 chore: make upgrade_one package=cibuildwheel
  • d9b660a chore: make upgrade
  • b128a31 docs: oops, move this entry to the correct place
  • a7a2c15 fix: escape filename urls in html report href attributes (#2227)
  • Additional commits viewable in compare view

Updates prek from 0.4.10 to 0.4.12

Release notes

Sourced from prek's releases.

0.4.12

Release Notes

Released on 2026-08-03.

Enhancements

  • Add --require-group for hook group intersections (#2472)
  • Align fast-path and builtin pre-commit hooks (#2433)
  • Do not shuffle file list for verbose output (#2431)
  • Improve top-level command descriptions (#2429)
  • Install uv from Astral CDN and drop source racing (#2455)
  • Make prek install --force bypass external hooks paths (#2437)
  • Show builtin hook flags in verbose list output (#2427)
  • Verify uv release archive checksums (#2456)

Performance

  • Precompute file tags in parallel (#2440)
  • Skip diffs after known hook modifications (#2447)
  • Skip worktree diffs for read-only languages (#2432)
  • Track builtin hook file changes directly (#2404)

Bug fixes

  • Use full object IDs in diff snapshots (#2448)

Documentation

  • Add a multi-repository configuration example (#2434)
  • Rewrite benchmark documentation (#2469)

Contributors

Install prek 0.4.12

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://github.com/j178/prek/releases/download/v0.4.12/prek-installer.sh | sh

Install prebuilt binaries via powershell script

powershell -ExecutionPolicy Bypass -c "irm https://github.com/j178/prek/releases/download/v0.4.12/prek-installer.ps1 | iex"
</tr></table> 

... (truncated)

Changelog

Sourced from prek's changelog.

0.4.12

Released on 2026-08-03.

Enhancements

  • Add --require-group for hook group intersections (#2472)
  • Align fast-path and builtin pre-commit hooks (#2433)
  • Do not shuffle file list for verbose output (#2431)
  • Improve top-level command descriptions (#2429)
  • Install uv from Astral CDN and drop source racing (#2455)
  • Make prek install --force bypass external hooks paths (#2437)
  • Show builtin hook flags in verbose list output (#2427)
  • Verify uv release archive checksums (#2456)

Performance

  • Precompute file tags in parallel (#2440)
  • Skip diffs after known hook modifications (#2447)
  • Skip worktree diffs for read-only languages (#2432)
  • Track builtin hook file changes directly (#2404)

Bug fixes

  • Use full object IDs in diff snapshots (#2448)

Documentation

  • Add a multi-repository configuration example (#2434)
  • Rewrite benchmark documentation (#2469)

Contributors

0.4.11

Released on 2026-07-25.

Highlights

  • This release adds two new builtin hooks, deny-pattern and require-pattern, as native alternatives for pygrep use cases. deny-pattern fails when a configured pattern is found, while require-pattern ensures every selected file contains a match. By matching natively without spawning a Python subprocess, they run over 4x faster than pygrep in benchmarks. Note that they use Rust regex syntax, which does

... (truncated)

Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels Aug 12, 2026
@dependabot
dependabot Bot force-pushed the dependabot/uv/patches-86052a1119 branch from e63a40f to f8e7f8b Compare August 12, 2026 16:01
Bumps the patches group with 6 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [django-guardian](https://github.com/django-guardian/django-guardian) | `3.3.2` | `3.3.3` |
| [django-polymorphic](https://github.com/django-commons/django-polymorphic) | `4.11.6` | `4.11.7` |
| [markdown](https://github.com/Python-Markdown/markdown) | `3.10.2` | `3.10.3` |
| [css-inline](https://github.com/Stranger6667/css-inline) | `0.21.0` | `0.21.1` |
| [coverage](https://github.com/coveragepy/coveragepy) | `7.15.2` | `7.15.4` |
| [prek](https://github.com/j178/prek) | `0.4.10` | `0.4.12` |



Updates `django-guardian` from 3.3.2 to 3.3.3
- [Release notes](https://github.com/django-guardian/django-guardian/releases)
- [Commits](django-guardian/django-guardian@3.3.2...3.3.3)

Updates `django-polymorphic` from 4.11.6 to 4.11.7
- [Release notes](https://github.com/django-commons/django-polymorphic/releases)
- [Commits](django-commons/django-polymorphic@v4.11.6...v4.11.7)

Updates `markdown` from 3.10.2 to 3.10.3
- [Release notes](https://github.com/Python-Markdown/markdown/releases)
- [Changelog](https://github.com/Python-Markdown/markdown/blob/master/docs/changelog.md)
- [Commits](Python-Markdown/markdown@3.10.2...3.10.3)

Updates `css-inline` from 0.21.0 to 0.21.1
- [Release notes](https://github.com/Stranger6667/css-inline/releases)
- [Changelog](https://github.com/Stranger6667/css-inline/blob/master/CHANGELOG.md)
- [Commits](Stranger6667/css-inline@c-v0.21.0...c-v0.21.1)

Updates `coverage` from 7.15.2 to 7.15.4
- [Release notes](https://github.com/coveragepy/coveragepy/releases)
- [Changelog](https://github.com/coveragepy/coveragepy/blob/main/CHANGES.rst)
- [Commits](coveragepy/coveragepy@7.15.2...7.15.4)

Updates `prek` from 0.4.10 to 0.4.12
- [Release notes](https://github.com/j178/prek/releases)
- [Changelog](https://github.com/j178/prek/blob/master/CHANGELOG.md)
- [Commits](j178/prek@v0.4.10...v0.4.12)

---
updated-dependencies:
- dependency-name: coverage
  dependency-version: 7.15.4
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: patches
- dependency-name: css-inline
  dependency-version: 0.21.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: patches
- dependency-name: django-guardian
  dependency-version: 3.3.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: patches
- dependency-name: django-polymorphic
  dependency-version: 4.11.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: patches
- dependency-name: markdown
  dependency-version: 3.10.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: patches
- dependency-name: prek
  dependency-version: 0.4.12
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: patches
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/uv/patches-86052a1119 branch from f8e7f8b to b194f7a Compare August 12, 2026 16:10
@dependabot @github

dependabot Bot commented on behalf of github Aug 13, 2026

Copy link
Copy Markdown
Contributor Author

Looks like these dependencies are updatable in another way, so this is no longer needed.

@dependabot dependabot Bot closed this Aug 13, 2026
@dependabot
dependabot Bot deleted the dependabot/uv/patches-86052a1119 branch August 13, 2026 10:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants