Skip to content

build(deps): bump the patch-updates group across 1 directory with 4 updates - #85

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/patch-updates-0cfbb72125
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/patch-updates-0cfbb72125

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


Bumps the patch-updates group with 4 updates in the / directory: ruff, hypothesis, build and agentseam.

Updates ruff from 0.16.6 to 0.16.9

Release notes

Sourced from ruff's releases.

0.16.9

Release Notes

Released on 2026-09-24.

Preview features

  • [ruff] Avoid false positives for overloaded division (RUF069) (#28309)

Bug fixes

  • [flake8-bugbear] Avoid false positives for calls with keyword arguments (B009, B010, B043) (#28776)
  • [flake8-tidy-imports] Allow lazy imports to be used in deferred annotations (TID255) (#28767)

Rule changes

  • Update LibCST-based fixes for Python 3.15 (#28616)
  • [flake8-pyi] Mention stubs in the diagnostic message (PYI002) (#28542)

Documentation

  • Fix horizontal overflow on the rules documentation page (#28699)
  • Update rules table with category information (#28651)
  • [flake8-annotations] Clarify that ANN401 checks return types in addition to arguments (#28334)
  • [flake8-bugbear] Document type-checker interaction (B010) (#28509)
  • [flake8-comprehensions] Document map/generator exception behavior (C417) (#27794)
  • [ruff] Mention related isort settings (RUF022) (#28719)

Contributors

Install ruff 0.16.9

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/ruff/releases/download/0.16.9/ruff-installer.sh | sh

... (truncated)

Changelog

Sourced from ruff's changelog.

0.16.9

Released on 2026-09-24.

Preview features

  • [ruff] Avoid false positives for overloaded division (RUF069) (#28309)

Bug fixes

  • [flake8-bugbear] Avoid false positives for calls with keyword arguments (B009, B010, B043) (#28776)
  • [flake8-tidy-imports] Allow lazy imports to be used in deferred annotations (TID255) (#28767)

Rule changes

  • Update LibCST-based fixes for Python 3.15 (#28616)
  • [flake8-pyi] Mention stubs in the diagnostic message (PYI002) (#28542)

Documentation

  • Fix horizontal overflow on the rules documentation page (#28699)
  • Update rules table with category information (#28651)
  • [flake8-annotations] Clarify that ANN401 checks return types in addition to arguments (#28334)
  • [flake8-bugbear] Document type-checker interaction (B010) (#28509)
  • [flake8-comprehensions] Document map/generator exception behavior (C417) (#27794)
  • [ruff] Mention related isort settings (RUF022) (#28719)

Contributors

0.16.8

Released on 2026-09-16.

Bug fixes

  • Visit functional TypedDict keyword arguments correctly (#28584)
  • [flake8-simplify] Detect nested async with under sync parent (SIM117) (#27821)
  • [flake8-simplify] Preserve operand order in SIM109 fix (#27824)

... (truncated)

Commits
  • 0be08a2 Bump version to 0.16.9 (#28882)
  • b4920b7 Rename ruff_cli to ruff_command_line (#28881)
  • 47c751b Update dependency astral-sh/uv to v0.12.18 (#28880)
  • 8c244e5 [flake8-comprehensions] Document map/generator exception behavior (C417...
  • 5edf5a1 Use target form in rooster.version_files (#28876)
  • 915bb2b [ty] Prefer existing @ paths over response files in Ruff and ty (#28877)
  • 4710e1a ci(github): update version number in placeholder of issue template (#28871)
  • eedfc62 [ty] Propagate outer type context through cast calls (#28855)
  • ceaa6a0 [ty] Contain rendered code within Markdown fences (#28869)
  • dba0f30 authorize ruff-pre-commit dispatch via OIDC (#28867)
  • Additional commits viewable in compare view

Updates hypothesis from 6.168.0 to 6.168.3

Commits
  • 44b82b2 Bump hypothesis version to 6.168.3 and update changelog
  • aeaafb5 Merge pull request #4888 from gpacix/fix-quadratic-statistics
  • f3f4a29 wording, remove hardcoded test
  • 7fabb94 Add RELEASE.rst and AUTHORS.rst changes
  • 0ab4e38 Summarize statistics events in linear time
  • 32ebeb2 Bump hypothesis version to 6.168.2 and update changelog
  • ff7e800 Merge pull request #4886 from pschanely/atomic-constants-cache
  • e57fd12 Isolate the constants cache test from existing cache files
  • c8981a0 Write the local constants cache atomically
  • 9c55f97 Merge pull request #4877 from HypothesisWorks/create-pull-request/patch
  • Additional commits viewable in compare view

Updates build from 1.6.0 to 1.6.1

Release notes

Sourced from build's releases.

1.6.1

What's Changed

Full Changelog: pypa/build@1.6.0...1.6.1

Changelog

Sourced from build's changelog.

#################### 1.6.1 (2026-09-10) ####################


Bugfixes


  • Avoid trying to detect symlinks on Windows, regression in 1.6.0 - by :user:henryiii (:issue:1175) (:issue:1175)

Documentation


  • Fix doubled backslashes in the Windows pip config path (%APPDATA%\pip\pip.ini) in the docs - by :user:aroh3006 (:issue:1149)

Miscellaneous


  • :issue:1168, :issue:1170, :issue:1178

#################### 1.6.0 (2026-08-27) ####################


Features


  • Add --report=PATH to write a machine-readable JSON report of built artifacts; --metadata now also accepts .whl files - by :user:gaborbernat (:issue:198)
  • The srcdir argument now accepts .tar.gz source distributions, extracting and building from them - by :user:gaborbernat (:issue:311)
  • The "Unmet dependencies" error from --no-isolation builds now shows the wanted version, found version, and interpreter - by :user:gaborbernat (:issue:504)
  • Add --sdist-extract-dir to extract the intermediate sdist into a persistent directory, enabling compiler cache reuse across rebuilds - by :user:gaborbernat (:issue:614)
  • Add --env-dir to place the isolated build environment at a fixed path, enabling compiler cache reuse across builds
    • by :user:gaborbernat (:issue:655)
  • Print a summary of resolved dependency versions (name==version) after installing them in isolated builds - by :user:gaborbernat (:issue:959)
  • On build failure, print a tip pointing to --env-dir and --sdist-extract-dir for debugging and link to the "Debug a failed build" how-to - reported by :user:dimpase, implemented by :user:gaborbernat (:issue:966)

Bugfixes


... (truncated)

Commits
  • 89cccef chore: prepare for 1.6.1
  • a6f707a ci: support releases from v* branches (#1178)
  • 7785161 docs: fix doubled backslashes in Windows pip config path (#1149)
  • 244b250 fix: always use copies for the isolated venv on Windows (#1176)
  • c93ca6f build(deps): bump re-actors/alls-green from 1.2.2 to 1.3.0 in the github-acti...
  • e02ffd3 pre-commit: bump repositories (#1173)
  • aad39a8 docs: fix changelog page heading levels and sidebar (#1171)
  • 5c3fd46 docs: use PyPI ref directly (#1172)
  • 1c5bd6c 🐛 fix(release): format generated changelog (#1170)
  • 7f0cc7e 🔧 build(type): replace mypy with pyrefly (#1168)
  • See full diff in compare view

Updates agentseam from 0.3.0 to 0.3.5

Release notes

Sourced from agentseam's releases.

v0.3.5

What's Changed

Full Changelog: open-coder-ai/agentseam@v0.3.4...v0.3.5

v0.3.4

What's Changed

Full Changelog: open-coder-ai/agentseam@v0.3.3...v0.3.4

v0.3.3

What's Changed

Full Changelog: open-coder-ai/agentseam@v0.3.2...v0.3.3

Changelog

Sourced from agentseam's changelog.

[0.3.5] - 2026-09-29

Fixed

  • install vscode_copilot now writes bash and powershell beside command and windows. Live on Windows (VS Code Copilot Chat agent mode, "Copilot CLI runtime"), Copilot ran the plain command in PowerShell and ignored windows; the command errored and Copilot denied every tool call ("hook errored"). Every entry now carries powershell (the same wrapped form as windows) and bash; re-installing upgrades an older entry in place. Other vendors are unchanged.
  • A Write (file creation) carries its content to the policy. Its text arrives as tool_input.file_text, which only the memory tool's branch read, so a content guard saw None.
  • Copilot's camelCase agentStop payload is a stop. It names no event (sessionId, transcriptPath, stopReason); it was read as a preToolUse and, unclaimed, passed unseen.

Added

  • Evidence for vscode_copilot from a second live Windows run (2026-09-28): the snake_case tool payloads and tools seen, a witnessed permissionDecision deny, both agentStop and Stop firing at every turn end, and a Stop block answered with both dialects' keys (which one Copilot reads is not isolated). A hook that errored blocked every tool once; fail_mode stays open, recorded as a note, not a claim.

[0.3.4] - 2026-09-27

Fixed

  • A handler's own output can no longer turn a deny into an allow. Anything a handler printed -- or a child process it ran -- landed on stdout ahead of the JSON verdict; Claude Code and Gemini CLI then fail to parse the hook's answer and treat it as a non-blocking error, so the tool ran (witnessed live). While the handler runs, sys.stdout and fd 1 now point at stderr, in dispatch and in the bundled runtime alike, and only the verdict reaches the real stdout. Text buffered on a stream the handler held (sys.__stdout__, a reference cached at import) is flushed to stderr before fd 1 is restored, and with fd 2 closed the diversion goes to devnull rather than back to stdout.
  • Copilot CLI's native camelCase hooks are read. preToolUse sends toolName and toolArgs (an object, or JSON text in earlier builds) and no event name; parse() read only tool_input, so the command, path and content were None and every guard allowed the call. toolArgs, sessionId and toolResult are now read, the payload is detected, and a camelCase preToolUse is answered with the documented top-level permissionDecision/permissionDecisionReason (a transform blocks there, since the CLI has no input rewrite). A call carrying toolName but no toolArgs is claimed and judged too.
  • Claude Code's PowerShell tool is a shell tool. It is on by default on Windows and carries the command in tool_input.command; tools.shell is now Bash, PowerShell (vendor docs, not yet live).
  • Codex runs project hooks only once trusted. needs_trust is now true for codex_cli with a sourced trust_hint, and agentseam install/doctor say "not live until trusted" for every agent that gates on trust. apply_patch is recorded as Codex's write tool; its patch arrives as event.command.
  • Devin no longer claims PermissionRequest by name. Claude Code sends it too; a Devin one carries prompt_id and is claimed by the marker path like every other Devin event.
  • install() edits a user's file more carefully. A tool-name --matcher is written only at tool events (a Bash matcher on Claude Code's SessionStart or Stop stopped those hooks firing), uninstall prunes the event lists its own removal emptied, an existing event value that is not a list is refused rather than overwritten, and the file keeps its own key order instead of being re-sorted.
  • The probe blames the right thing. A driver whose agent CLI is missing (shell exit 127/9009) raises "driver binary not found" instead of scoring "the hook never fired -- config path or format is wrong", and the reference driver refuses agents other than claude_code, whose protocol is the only one it models.
  • A PowerShell hook keeps its exit code. pwsh -Command turns any failing native exit into 1, so a

... (truncated)

Commits
  • c5d2a00 Merge pull request #165 from open-coder-ai/release/0.3.5
  • 018c5cf release: 0.3.5
  • cd9504e Merge pull request #164 from open-coder-ai/fix/copilot-windows-evidence
  • cdf134e fix(vscode_copilot): write powershell and bash keys; record 2026-09-28 Window...
  • d3e083e Merge pull request #161 from open-coder-ai/fix/review-2026-09-27
  • 4d65652 docs(changelog): record the review fixes under 0.3.4
  • 6578e11 fix(vscode_copilot): judge a Copilot CLI call that carries no toolArgs
  • 25d01fa fix(dispatch): flush held stdout streams while fd 1 is diverted
  • 590cb63 fix(windows): refuse when a PowerShell hook's interpreter never ran
  • a263705 fix(windows): keep a PowerShell hook's exit code
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

…pdates

Bumps the patch-updates group with 4 updates in the / directory: [ruff](https://github.com/astral-sh/ruff), [hypothesis](https://github.com/HypothesisWorks/hypothesis), [build](https://github.com/pypa/build) and [agentseam](https://github.com/open-coder-ai/agentseam).


Updates `ruff` from 0.16.6 to 0.16.9
- [Release notes](https://github.com/astral-sh/ruff/releases)
- [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md)
- [Commits](astral-sh/ruff@0.16.6...0.16.9)

Updates `hypothesis` from 6.168.0 to 6.168.3
- [Release notes](https://github.com/HypothesisWorks/hypothesis/releases)
- [Commits](HypothesisWorks/hypothesis@v6.168.0...v6.168.3)

Updates `build` from 1.6.0 to 1.6.1
- [Release notes](https://github.com/pypa/build/releases)
- [Changelog](https://github.com/pypa/build/blob/main/CHANGELOG.rst)
- [Commits](pypa/build@1.6.0...1.6.1)

Updates `agentseam` from 0.3.0 to 0.3.5
- [Release notes](https://github.com/open-coder-ai/agentseam/releases)
- [Changelog](https://github.com/open-coder-ai/agentseam/blob/main/CHANGELOG.md)
- [Commits](open-coder-ai/agentseam@v0.3.0...v0.3.5)

---
updated-dependencies:
- dependency-name: ruff
  dependency-version: 0.16.9
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: patch-updates
- dependency-name: hypothesis
  dependency-version: 6.168.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: patch-updates
- dependency-name: build
  dependency-version: 1.6.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: patch-updates
- dependency-name: agentseam
  dependency-version: 0.3.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: patch-updates
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Oct 6, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: dependencies. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot @github

dependabot Bot commented on behalf of github Oct 6, 2026

Copy link
Copy Markdown
Contributor Author

Looks like these dependencies are no longer being updated by Dependabot, so this is no longer needed.

@dependabot dependabot Bot closed this Oct 6, 2026
@dependabot
dependabot Bot deleted the dependabot/pip/patch-updates-0cfbb72125 branch October 6, 2026 10:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants