Skip to content

chore(deps): Bump the "all-dependencies" group with 2 updates across multiple ecosystems - #144

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/all_dependencies-dc03a7be39
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/all_dependencies-dc03a7be39

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the all-dependencies group with 3 updates: ty, ruff and sphinx-autodoc-typehints.

Updates ty from 0.0.83 to 0.0.84

Release notes

Sourced from ty's releases.

0.0.84

Release Notes

Released on 2026-09-24.

This release addresses GHSA-vxvm-j4xq-q7m4, a use-after-free vulnerability during incremental type checking that can result in arbitrary code execution when analyzing a specially crafted Python project. Users who run ty on untrusted code should upgrade to 0.0.84 or newer.

Bug fixes

  • Fix stale diagnostics from the LSP server after toggling showSyntaxErrors (#28759)

LSP server

  • Complete string keys from dictionary initializers (#28820)
  • Support LSP requests against closed documents (#28595)
  • Select projects for external files using import search paths (#28594)
  • Use workspace editor settings for external files (#28639)

Performance

  • Avoid repeated subtyping checks for materialized recursive protocols (#28774)
  • Skip reading notebooks when discovering scripts (#28781)

Core type checking

  • Avoid incorrect simplification of TypeIs materializations (#28817)
  • Fix disjointness of generic class types (#28787)
  • Fix staticmethod shadowing through generic receivers and unions (#28766)
  • Infer callable signatures from bounded type variables (#28599)
  • Infer constant membership in inline list and set literals (e.g. "foo" in ["foo"] is now inferred as Literal[True]) (#28676)
  • Infer through optional generic containers in the legacy solver (#28791)
  • Preserve call narrowing during cyclic inference (#28708)
  • Preserve intersections of type guard return types (#28796)
  • Use subtyping for constraint-set implication (#28657)

Configuration

  • Disable invalid-legacy-positional-parameter by default (#28834)

Other changes

  • Only consider reachable definitions when determining whether a condition should be exempted from redundant-condition(-strict) due to the condition being defined relative to sys.version_info, sys.platform, os.name or typing.TYPE_CHECKING (#28788)

Contributors

... (truncated)

Changelog

Sourced from ty's changelog.

0.0.84

Released on 2026-09-24.

This release addresses GHSA-vxvm-j4xq-q7m4, a use-after-free vulnerability during incremental type checking that can result in arbitrary code execution when analyzing a specially crafted Python project. Users who run ty on untrusted code should upgrade to 0.0.84 or newer.

Bug fixes

  • Fix stale diagnostics from the LSP server after toggling showSyntaxErrors (#28759)

LSP server

  • Complete string keys from dictionary initializers (#28820)
  • Support LSP requests against closed documents (#28595)
  • Select projects for external files using import search paths (#28594)
  • Use workspace editor settings for external files (#28639)

Performance

  • Avoid repeated subtyping checks for materialized recursive protocols (#28774)
  • Skip reading notebooks when discovering scripts (#28781)

Core type checking

  • Avoid incorrect simplification of TypeIs materializations (#28817)
  • Fix disjointness of generic class types (#28787)
  • Fix staticmethod shadowing through generic receivers and unions (#28766)
  • Infer callable signatures from bounded type variables (#28599)
  • Infer constant membership in inline list and set literals (e.g. "foo" in ["foo"] is now inferred as Literal[True]) (#28676)
  • Infer through optional generic containers in the legacy solver (#28791)
  • Preserve call narrowing during cyclic inference (#28708)
  • Preserve intersections of type guard return types (#28796)
  • Use subtyping for constraint-set implication (#28657)

Configuration

  • Disable invalid-legacy-positional-parameter by default (#28834)

Other changes

  • Only consider reachable definitions when determining whether a condition should be exempted from redundant-condition(-strict) due to the condition being defined relative to sys.version_info, sys.platform, os.name or typing.TYPE_CHECKING (#28788)

Contributors

... (truncated)

Commits

Updates ruff from 0.16.8 to 0.16.9

Release notes

Sourced from ruff's releases.

0.16.9

Release Notes

Released on 2026-09-24.

Preview features

  • [ruff] Avoid false positives for overloaded division (RUF069) (#28309)

Bug fixes

  • [flake8-bugbear] Avoid false positives for calls with keyword arguments (B009, B010, B043) (#28776)
  • [flake8-tidy-imports] Allow lazy imports to be used in deferred annotations (TID255) (#28767)

Rule changes

  • Update LibCST-based fixes for Python 3.15 (#28616)
  • [flake8-pyi] Mention stubs in the diagnostic message (PYI002) (#28542)

Documentation

  • Fix horizontal overflow on the rules documentation page (#28699)
  • Update rules table with category information (#28651)
  • [flake8-annotations] Clarify that ANN401 checks return types in addition to arguments (#28334)
  • [flake8-bugbear] Document type-checker interaction (B010) (#28509)
  • [flake8-comprehensions] Document map/generator exception behavior (C417) (#27794)
  • [ruff] Mention related isort settings (RUF022) (#28719)

Contributors

Install ruff 0.16.9

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/ruff/releases/download/0.16.9/ruff-installer.sh | sh

... (truncated)

Changelog

Sourced from ruff's changelog.

0.16.9

Released on 2026-09-24.

Preview features

  • [ruff] Avoid false positives for overloaded division (RUF069) (#28309)

Bug fixes

  • [flake8-bugbear] Avoid false positives for calls with keyword arguments (B009, B010, B043) (#28776)
  • [flake8-tidy-imports] Allow lazy imports to be used in deferred annotations (TID255) (#28767)

Rule changes

  • Update LibCST-based fixes for Python 3.15 (#28616)
  • [flake8-pyi] Mention stubs in the diagnostic message (PYI002) (#28542)

Documentation

  • Fix horizontal overflow on the rules documentation page (#28699)
  • Update rules table with category information (#28651)
  • [flake8-annotations] Clarify that ANN401 checks return types in addition to arguments (#28334)
  • [flake8-bugbear] Document type-checker interaction (B010) (#28509)
  • [flake8-comprehensions] Document map/generator exception behavior (C417) (#27794)
  • [ruff] Mention related isort settings (RUF022) (#28719)

Contributors

Commits
  • 0be08a2 Bump version to 0.16.9 (#28882)
  • b4920b7 Rename ruff_cli to ruff_command_line (#28881)
  • 47c751b Update dependency astral-sh/uv to v0.12.18 (#28880)
  • 8c244e5 [flake8-comprehensions] Document map/generator exception behavior (C417...
  • 5edf5a1 Use target form in rooster.version_files (#28876)
  • 915bb2b [ty] Prefer existing @ paths over response files in Ruff and ty (#28877)
  • 4710e1a ci(github): update version number in placeholder of issue template (#28871)
  • eedfc62 [ty] Propagate outer type context through cast calls (#28855)
  • ceaa6a0 [ty] Contain rendered code within Markdown fences (#28869)
  • dba0f30 authorize ruff-pre-commit dispatch via OIDC (#28867)
  • Additional commits viewable in compare view

Updates sphinx-autodoc-typehints from 3.13.7 to 3.13.8

Release notes

Sourced from sphinx-autodoc-typehints's releases.

3.13.8

What's Changed

Full Changelog: tox-dev/sphinx-autodoc-typehints@3.13.7...3.13.8

Commits
  • 0a96a6c 🐛 fix(resolver): resolve guarded class imports (#775)
  • d794732 build(deps): bump astral-sh/setup-uv from 10.1.0 to 10.2.0 in the github-acti...
  • 6dc6c4e [pre-commit.ci] pre-commit autoupdate (#773)
  • 9627932 build(deps): bump astral-sh/setup-uv from 10.0.1 to 10.1.0 in the github-acti...
  • bd00366 [pre-commit.ci] pre-commit autoupdate (#771)
  • See full diff in compare view

Bumps the all-dependencies group with 3 updates: anthropics/claude-code-action, github/codeql-action and trufflesecurity/trufflehog.

Updates anthropics/claude-code-action from 1.0.233 to 1.0.238

Release notes

Sourced from anthropics/claude-code-action's releases.

v1.0.238

What's Changed

New Contributors

Full Changelog: anthropics/claude-code-action@v1.0.237...v1.0.238

v1.0.237

Full Changelog: anthropics/claude-code-action@v1.0.236...v1.0.237

v1.0.236

Full Changelog: anthropics/claude-code-action@v1.0.235...v1.0.236

v1.0.235

Full Changelog: anthropics/claude-code-action@v1.0.234...v1.0.235

v1.0.234

Full Changelog: anthropics/claude-code-action@v1.0.233...v1.0.234

Commits
  • 12dd8d7 chore: bump Claude Code to 2.1.286 and Agent SDK to 0.3.286
  • a8cb0db ci: security hardening for GitHub Actions workflows that call Claude (#1867)
  • fd1c128 chore: bump Claude Code to 2.1.285 and Agent SDK to 0.3.285
  • 8ce9314 chore: bump Claude Code to 2.1.284 and Agent SDK to 0.3.284
  • 756cc22 chore: bump Claude Code to 2.1.283 and Agent SDK to 0.3.283
  • 9171db3 chore: bump Claude Code to 2.1.282 and Agent SDK to 0.3.282
  • See full diff in compare view

Updates github/codeql-action from 4.38.1 to 4.38.2

Release notes

Sourced from github/codeql-action's releases.

v4.38.2

  • Update default CodeQL bundle version to 2.27.1. #4160
Changelog

Sourced from github/codeql-action's changelog.

4.38.2 - 24 Sept 2026

  • Update default CodeQL bundle version to 2.27.1. #4160
Commits
  • 2892aa5 Merge pull request #4168 from github/update-v4.38.2-a6ef2c96f
  • 8ad03a3 Trigger workflows
  • 98af865 Update changelog for v4.38.2
  • a6ef2c9 Merge pull request #4156 from github/mario-campos/fix-validate-cmd
  • 1ef28a1 Merge pull request #4166 from github/dependabot/github_actions/dot-github/wor...
  • 26cb08b Merge pull request #4163 from github/mbg/fix-getCommitOid-stubs
  • f035ce3 Merge pull request #4165 from github/dependabot/npm_and_yarn/npm-minor-8eaed9...
  • 5e4e255 Rebuild
  • b13f5f4 Bump ruby/setup-ruby
  • c87fe57 Rebuild
  • Additional commits viewable in compare view

Updates trufflesecurity/trufflehog from 3.97.8 to 3.97.9

Release notes

Sourced from trufflesecurity/trufflehog's releases.

v3.97.9

What's Changed

Full Changelog: trufflesecurity/trufflehog@v3.97.8...v3.97.9

Commits
  • 4dd8831 Spruce up Makefile a little (#5347)
  • 449d8a3 Int 595 auth errors (#5259)
  • bad9901 Add version and comment_number lines to SharePoint source metadata (#5348)
  • 4b8eb0e make 401s for Basic auth verified false. (#5290)
  • bbf9447 Update module github.com/gabriel-vasile/mimetype to v1.4.15 (#5283)
  • 16b566b Update module github.com/aymanbagabas/go-osc52 to v1.2.2 (#5252)
  • a25ff85 ci: scope Smoke timeouts to trufflehog runs, not the build (#5317)
  • ca9d3b3 [SCAN-162] Add Err() to JobProgress and JobProgressRef (#5346)
  • See full diff in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

View with [code]smith Autofix with [code]smith
Need help on this PR? Tag @codesmith-bot with what you need. Autofix is disabled.

Bumps the all-dependencies group with 3 updates: [ty](https://github.com/astral-sh/ty), [ruff](https://github.com/astral-sh/ruff) and [sphinx-autodoc-typehints](https://github.com/tox-dev/sphinx-autodoc-typehints).


Updates `ty` from 0.0.83 to 0.0.84
- [Release notes](https://github.com/astral-sh/ty/releases)
- [Changelog](https://github.com/astral-sh/ty/blob/main/CHANGELOG.md)
- [Commits](astral-sh/ty@0.0.83...0.0.84)

Updates `ruff` from 0.16.8 to 0.16.9
- [Release notes](https://github.com/astral-sh/ruff/releases)
- [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md)
- [Commits](astral-sh/ruff@0.16.8...0.16.9)

Updates `sphinx-autodoc-typehints` from 3.13.7 to 3.13.8
- [Release notes](https://github.com/tox-dev/sphinx-autodoc-typehints/releases)
- [Commits](tox-dev/sphinx-autodoc-typehints@3.13.7...3.13.8)
chore(deps): bump the all-dependencies group with 3 updates

Bumps the all-dependencies group with 3 updates: [anthropics/claude-code-action](https://github.com/anthropics/claude-code-action), [github/codeql-action](https://github.com/github/codeql-action) and [trufflesecurity/trufflehog](https://github.com/trufflesecurity/trufflehog).


Updates `anthropics/claude-code-action` from 1.0.233 to 1.0.238
- [Release notes](https://github.com/anthropics/claude-code-action/releases)
- [Commits](anthropics/claude-code-action@v1.0.233...v1.0.238)

Updates `github/codeql-action` from 4.38.1 to 4.38.2
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](github/codeql-action@v4.38.1...v4.38.2)

Updates `trufflesecurity/trufflehog` from 3.97.8 to 3.97.9
- [Release notes](https://github.com/trufflesecurity/trufflehog/releases)
- [Commits](trufflesecurity/trufflehog@v3.97.8...v3.97.9)

---
updated-dependencies:
- dependency-name: ty
  dependency-version: 0.0.84
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: all-dependencies
- dependency-name: ruff
  dependency-version: 0.16.9
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: all-dependencies
- dependency-name: sphinx-autodoc-typehints
  dependency-version: 3.13.8
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: all-dependencies
- dependency-name: anthropics/claude-code-action
  dependency-version: 1.0.238
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all-dependencies
- dependency-name: github/codeql-action
  dependency-version: 4.38.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all-dependencies
- dependency-name: trufflesecurity/trufflehog
  dependency-version: 3.97.9
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Oct 5, 2026
@dependabot @github

dependabot Bot commented on behalf of github Oct 5, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: python. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

OpenSSF Scorecard

PackageVersionScoreDetails
actions/trufflesecurity/trufflehog 3.97.9 🟢 7.9
Details
CheckScoreReason
Security-Policy🟢 10security policy file detected
Code-Review🟢 10all changesets reviewed
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Maintained🟢 1030 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Binary-Artifacts🟢 9binaries present in source code
License🟢 10license file detected
Fuzzing🟢 10project is fuzzed
Pinned-Dependencies🟢 7dependency not pinned by hash detected -- score normalized to 7
Signed-Releases🟢 85 out of the last 5 releases have a total of 5 signed artifacts.
Branch-Protection🟢 5branch protection is not maximal on development and all release branches
Packaging🟢 10packaging workflow detected
SAST🟢 10SAST tool is run on all commits
pip/ruff 0.16.9 UnknownUnknown
pip/sphinx-autodoc-typehints 3.13.8 UnknownUnknown
pip/ty 0.0.84 UnknownUnknown

Scanned Files

  • .github/workflows/secret-scan.yml
  • uv.lock

@coderabbitai

coderabbitai Bot commented Oct 5, 2026

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: defaults
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 68c0a453-0608-4f9f-9633-2886185ae044

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

🌳 difftree — changes in this PR

📱 Plain text version (mobile / email)
PR: origin/main...85466e5 · committed
template-press
├──   .github (4 files, +5 −5)
│   └──   workflows (4 files, +5 −5)
│       ├── ● claude-code-review.yml +1 −1
│       ├── ● claude.yml +1 −1
│       ├── ● codeql.yml +2 −2
│       └── ● secret-scan.yml +1 −1
└── ● uv.lock +45 −45

2 dirs touched · 5 files modified · +50 −50
🌳 2 dirs touched · 5 files modified · +50 −50

${\color{#6e7781}\texttt{PR:~origin/main...85466e}\texttt{5~·~committed}}$
$\texttt{template-press}$
$\texttt{├──~}\texttt{~}\texttt{~.github}\texttt{~(4~files,~}{\color{#2da44e}\texttt{+5}}\texttt{~}{\color{#cf222e}\texttt{−5}}\texttt{)}$
$\texttt{│~~~└──~}\texttt{~}\texttt{~workflows}\texttt{~(4~files,~}{\color{#2da44e}\texttt{+5}}\texttt{~}{\color{#cf222e}\texttt{−5}}\texttt{)}$
$\texttt{│~~~}{\color{transparent}\texttt{│}}\texttt{~~~├──~}{\color{#2da44e}\texttt{●}}\texttt{~claude-code-review.yml}\texttt{~}{\color{#2da44e}\texttt{+1}}\texttt{~}{\color{#cf222e}\texttt{−1}}$
$\texttt{│~~~}{\color{transparent}\texttt{│}}\texttt{~~~├──~}{\color{#2da44e}\texttt{●}}\texttt{~claude.yml}\texttt{~}{\color{#2da44e}\texttt{+1}}\texttt{~}{\color{#cf222e}\texttt{−1}}$
$\texttt{│~~~}{\color{transparent}\texttt{│}}\texttt{~~~├──~}{\color{#2da44e}\texttt{●}}\texttt{~codeql.yml}\texttt{~}{\color{#2da44e}\texttt{+2}}\texttt{~}{\color{#cf222e}\texttt{−2}}$
$\texttt{│~~~}{\color{transparent}\texttt{│}}\texttt{~~~└──~}{\color{#2da44e}\texttt{●}}\texttt{~secret-scan.yml}\texttt{~}{\color{#2da44e}\texttt{+1}}\texttt{~}{\color{#cf222e}\texttt{−1}}$
$\texttt{└──~}{\color{#2da44e}\texttt{●}}\texttt{~uv.lock}\texttt{~}{\color{#2da44e}\texttt{+45}}\texttt{~}{\color{#cf222e}\texttt{−45}}$

$\texttt{2~dirs~touched~·~5~files~}{\color{#bf8700}\texttt{modified}}\texttt{~·~}{\color{#2da44e}\texttt{+50}}\texttt{~}{\color{#cf222e}\texttt{−50}}$

🌳 Get your own diff tree at smorinlabs/difftree-action

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants