Skip to content

Bump the python-version-updates group with 4 updates - #628

Merged
RussTedrake merged 1 commit into
masterfrom
dependabot/pip/python-version-updates-25dc8f4a75
Oct 3, 2026
Merged

RussTedrake merged 1 commit into
masterfrom
dependabot/pip/python-version-updates-25dc8f4a75

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the python-version-updates group with 4 updates: soupsieve, poetry, filelock and virtualenv.

Updates soupsieve from 2.9.2 to 2.10

Release notes

Sourced from soupsieve's releases.

2.10

  • NEW: Support Python 3.15.
  • NEW: Add new ignore option to API methods that allows the specification of specific pseudo-classes to be ignored.
  • NEW: Tighten restrictions such that namespaces and custom objects must always be a Mapping, previously lists of tuples were also allowed.
  • NEW: Use a singleton for null selectors internally via called Null of type SelectorNull.
  • NEW: For performance, Soup Sieve will no longer try and coerce bad attribute values to useable strings.
  • NEW: Add NOCACHE flag that can be used to disable caching optimizations selectors and possibly other future caching optimizations. Provided for disabling and also disabling if issues are found with the new caching approach.
  • FIX: Improve performance of ~ for various cases by employing caching.
  • FIX: Improve performance of nth-* family of selectors in certain scenarios by employing caching.
  • FIX: Ensure custom is properly passed down from API functions to compilation.
Commits
  • fc195cd Add official support for Python 3.15 (#305)
  • 04af8c7 Update changelog
  • edf9a5e Include tools in sdist
  • 71c662b Fix example and update doc configuration
  • 0928124 Rework patterns
  • 56c9655 Update documentation
  • ffb88cc Employ caching to speed up various cases of general sibling combinator (#304)
  • 537d072 Use caching to increase performance of nth-* family of selectors (#301)
  • 8df4abf Don't coerce bad attributes to strings
  • 7975507 Improve performance for tag and namespace checking
  • Additional commits viewable in compare view

Updates poetry from 2.4.3 to 2.5.1

Release notes

Sourced from poetry's releases.

2.5.1

Fixed

  • Fix an issue where uninstalling a package with installer.builtin-uninstall set failed with a TypeError (#11077).

2.5.0

Added

  • Add an installer.builtin-uninstall setting to uninstall packages with a built-in uninstaller instead of invoking pip uninstall (#10931).
  • Add official support for Python 3.15 (#11046).

Changed

  • Do not send credentials configured for an https repository via http (#11073).
  • Fail with an error when the current Python version is not compatible with the project and virtualenvs.create is false (#10941).
  • Validate version constraints that are entered interactively in poetry init (#10909).
  • Include the path of the pyproject.toml file in the message about already present packages in poetry add (#10908).
  • Improve performance of processing package links and repository pages (#10895, #10896, #10903, #10949, #10951, #10953).
  • Improve performance of dependency resolution (#10907, #10954).
  • Improve performance of choosing and installing wheels (#10905, #10958).
  • Improve performance by avoiding redundant keyring lookups for repositories without credentials (#10959).
  • Improve performance by reducing the number of subprocesses to discover virtual environment data (#11042).
  • Improve performance of poetry search for single-token queries (#10906).
  • Improve startup time by deferring the import of requests (#11004).
  • Improve performance of schema validation by caching compiled JSON schema validators (#11033).

Fixed

  • Fix an issue where credentials of the wrong repository were used under certain circumstances when multiple repositories were configured on the same host (#11072).
  • Fix an issue where credentials of a repository on another host were used for git dependencies if the path of the URL was the same (#11074).
  • Fix an issue where dependency resolution failed for conflicting requirements of different packages even though the requirements had mutually exclusive markers (#10944).
  • Fix an issue where dependency resolution failed when the same package was required with different extras in several optional dependencies or dependency groups (#10943).
  • Fix an issue where dependency resolution failed with a KeyError (#11008).
  • Fix an issue where the dependencies of an extra were missing in the lock file after adding the extra to a locked dependency, e.g. a git dependency, in the pyproject.toml file (#10987).
  • Fix an issue where a path or git dependency was not reinstalled when its develop setting changed (#11022).
  • Fix an issue where scripts of type file were not installed when installing the project (#10736).
  • Fix an issue where GUI scripts were not installed when installing the project (#10973).
  • Fix an issue where a relative path was written to direct_url.json for path dependencies (#10917).
  • Fix an issue where poetry show <package> showed a version that was not relevant for the current environment if there were multiple versions of the package in the lock file (#11003).
  • Fix an issue where poetry show --outdated did not find newer versions of packages from sources with explicit priority (#10982).
  • Fix an issue where poetry env activate ignored the environment that was determined by the application, e.g. when using --directory (#10916).
  • Fix an issue where poetry init proposed an invalid package name if the directory name was not a valid package name (#10975).

Docs

  • Document the --license option of poetry init and poetry new (#11064).
  • Clarify which dependencies are locked when running poetry update with dependency groups (#11024).
  • Clarify the portability of path dependencies (#11020).
  • Clarify the usage of poetry run with console scripts (#10984).

... (truncated)

Changelog

Sourced from poetry's changelog.

[2.5.1] - 2026-09-20

Fixed

  • Fix an issue where uninstalling a package with installer.builtin-uninstall set failed with a TypeError (#11077).

[2.5.0] - 2026-09-19

Added

  • Add an installer.builtin-uninstall setting to uninstall packages with a built-in uninstaller instead of invoking pip uninstall (#10931).
  • Add official support for Python 3.15 (#11046).

Changed

  • Do not send credentials configured for an https repository via http (#11073).
  • Fail with an error when the current Python version is not compatible with the project and virtualenvs.create is false (#10941).
  • Validate version constraints that are entered interactively in poetry init (#10909).
  • Include the path of the pyproject.toml file in the message about already present packages in poetry add (#10908).
  • Improve performance of processing package links and repository pages (#10895, #10896, #10903, #10949, #10951, #10953).
  • Improve performance of dependency resolution (#10907, #10954).
  • Improve performance of choosing and installing wheels (#10905, #10958).
  • Improve performance by avoiding redundant keyring lookups for repositories without credentials (#10959).
  • Improve performance by reducing the number of subprocesses to discover virtual environment data (#11042).
  • Improve performance of poetry search for single-token queries (#10906).
  • Improve startup time by deferring the import of requests (#11004).
  • Improve performance of schema validation by caching compiled JSON schema validators (#11033).

Fixed

  • Fix an issue where credentials of the wrong repository were used under certain circumstances when multiple repositories were configured on the same host (#11072).
  • Fix an issue where credentials of a repository on another host were used for git dependencies if the path of the URL was the same (#11074).
  • Fix an issue where dependency resolution failed for conflicting requirements of different packages even though the requirements had mutually exclusive markers (#10944).
  • Fix an issue where dependency resolution failed when the same package was required with different extras in several optional dependencies or dependency groups (#10943).
  • Fix an issue where dependency resolution failed with a KeyError (#11008).
  • Fix an issue where the dependencies of an extra were missing in the lock file after adding the extra to a locked dependency, e.g. a git dependency, in the pyproject.toml file (#10987).
  • Fix an issue where a path or git dependency was not reinstalled when its develop setting changed (#11022).
  • Fix an issue where scripts of type file were not installed when installing the project (#10736).
  • Fix an issue where GUI scripts were not installed when installing the project (#10973).
  • Fix an issue where a relative path was written to direct_url.json for path dependencies (#10917).
  • Fix an issue where poetry show <package> showed a version that was not relevant for the current environment if there were multiple versions of the package in the lock file (#11003).
  • Fix an issue where poetry show --outdated did not find newer versions of packages from sources with explicit priority (#10982).

... (truncated)

Commits
  • 94b6e35 release: bump version to 2.5.1
  • f8408ca fix TypeError when using installer.builtin-uninstall (#11077)
  • 165fb4b release: bump version to 2.5.0
  • c93fd63 update poetry-core (#10921)
  • 32356ae chore: update dependencies (#11075)
  • d266d45 test: accept compatible extension wheel tags (#11014)
  • c8790a3 add Python 3.15 to tests matrix (#11046)
  • a416efd authenticator: match host when looking up git credentials (#11074)
  • e078ebf authenticator: do not send credentials configured for https with http (#11073)
  • 8711c83 authenticator: sort candidates by common path segments instead of prefixes (#...
  • Additional commits viewable in compare view

Updates filelock from 3.32.7 to 4.0.3

Release notes

Sourced from filelock's releases.

4.0.3

What's Changed

Full Changelog: tox-dev/filelock@4.0.2...4.0.3

4.0.2

What's Changed

New Contributors

Full Changelog: tox-dev/filelock@4.0.1...4.0.2

4.0.1

What's Changed

New Contributors

Full Changelog: tox-dev/filelock@4.0.0...4.0.1

4.0.0

What's Changed

Full Changelog: tox-dev/filelock@3.32.7...4.0.0

Changelog

Sourced from filelock's changelog.

########### Changelog ###########

.. towncrier-draft-entries:: Unreleased

.. towncrier release notes start


4.0.5 (2026-09-28)


  • Fix MarkerSoftFileLock acquisition and prevent contenders from evicting live protocol-2 owners after two seconds. Reclaim recognized records after owner death; preserve unknown contracts. :pr:749
  • Honor instance timeout and blocking settings in sync and async ReadWriteLock acquisition, including waits between tasks on one instance. Preserve explicit per-call overrides. :pr:750
  • Skip access-denial checks when the process can read mode-0o000 files. Keep mode-bit checks enabled for privileged processes on filesystems that support POSIX permissions. :pr:753
  • Skip vanished StrictSoftFileLock claims after a read-permission retry expires. Recheck the directory before raising a protocol error so concurrent removal does not turn a stale claim listing into an acquisition failure. :pr:754
  • Reject negative timeouts other than -1 in blocking AsyncReadWriteLock and AsyncSoftReadWriteLock acquisitions. Keep -1 as an unlimited wait and ignore timeouts when blocking=False. :pr:755

4.0.4 (2026-09-26)


  • Hostnames that still differ after their first 253 escaped characters now publish distinct owners, so a soft lock no longer takes another such host's live holder for its own and reclaims its marker. :pr:748

4.0.3 (2026-09-23)


  • Importing filelock on CPython 3.10 or 3.11 no longer makes new threads fail with RuntimeError: Cannot install a trace function while another trace function is being installed under coverage or a debugger. filelock skips its fork-safety audit hook there, so forking from inside a thread's own lock-state transition no longer raises immediately on those versions. :pr:747

4.0.2 (2026-09-23)


  • Concurrent acquire() and release() on a thread_local=False lock no longer leak the OS lock, close a descriptor twice, drop a lease token, or leave a false deadlock after a cross-thread release (:issue:744). :pr:745
  • :class:~filelock.AsyncReadWriteLock and :class:~filelock.AsyncSoftReadWriteLock now give each asyncio task its own hold, so tasks sharing one instance no longer enter the write lock together. :pr:746
  • Correct the async cache example to create its data directory and clarify automatic creation of lock-file parent directories. :pr:740
  • Exclude sphinx-llm 1.1.0 from documentation dependencies because its Markdown builder emits unknown-node warnings. :pr:742

... (truncated)

Commits
  • 5283806 Release 4.0.3
  • fd10e07 🐛 fix(api): skip the fork audit hook on CPython <3.12 (#747)
  • 2d4530f Release 4.0.2
  • 6c46312 🐛 fix(async-rw): give each task its own hold (#746)
  • fe0e99d 🐛 fix(api): serialize concurrent transitions on shared locks (#745)
  • b26beda build(deps): bump astral-sh/setup-uv from 10.0.1 to 10.1.0 in the github-acti...
  • 10572ec fix: ignore broken sphinx-llm release (#742)
  • 6c10af3 [pre-commit.ci] pre-commit autoupdate (#741)
  • 9380408 docs: create the data directory in the async cache example (#740)
  • b5016c4 Release 4.0.1
  • Additional commits viewable in compare view

Updates virtualenv from 21.7.14 to 21.13.0

Release notes

Sourced from virtualenv's releases.

21.13.0

What's Changed

New Contributors

Full Changelog: pypa/virtualenv@21.12.1...21.13.0

21.12.1

What's Changed

Full Changelog: pypa/virtualenv@21.12.0...21.12.1

21.12.0

What's Changed

Full Changelog: pypa/virtualenv@21.11.1...21.12.0

21.11.1

What's Changed

... (truncated)

Changelog

Sourced from virtualenv's changelog.

Features - 21.13.0

  • Add Changelog and Funding links to the PyPI project metadata, and replace the 2020-202x placeholder in LICENSE with 2020-present so the copyright field of the wheel SBOM reads as a real range - by :user:gaborbernat. (:issue:3334)

Bugfixes - 21.13.0

  • Escape the curly single quotes U+2018-U+201B in the PowerShell activator's quote so a virtual environment prompt, name or Tcl/Tk library path containing them can no longer close the string literal and run commands - by :user:gaborbernat. (:issue:3325)
  • Stop the bash activator from re-expanding the prompt inside PS1, so a virtual environment name or --prompt value containing $(...), backticks or backslashes no longer runs as a command each time bash draws the prompt - by :user:gaborbernat. (:issue:3326)

Improved Documentation - 21.13.0

  • Correct the documented changelog fragment types and example to match the enforced towncrier categories. (:issue:3323)
  • List the Unlicense and the SPDX BSD variants in the runtime dependency licensing policy, matching the filelock releases virtualenv installs on Python 3.9, and describe the dependency review check that enforces the policy. (:issue:3329)
  • Show how to check a release with gh release verify and gh release verify-asset, and how to rebuild the zipapp byte for byte with the build tool versions its SBOMs list. Drop the claims that the zipapp build does not pin the distributions it bundles and that wheels differ between build machines - by :user:gaborbernat. (:issue:3330)

v21.12.1 (2026-09-24)


Bugfixes - 21.12.1

  • Limit the :PEP:832 .venv redirect to folders holding a pyproject.toml and no .venv yet, so virtualenv foo in a scratch folder, and tools such as tox or nox building environments through virtualenv, no longer claim a folder's default environment - by :user:gaborbernat.

    • --venv-redirect writes the redirect in any folder and replaces an earlier virtualenv redirect.
    • A flag on the command line overrides the environment variable and the config file in either direction. (:issue:3316)

v21.12.0 (2026-09-24)


Features - 21.12.0

... (truncated)

Commits
  • 14859e6 release 21.13.0
  • c83f49e 👷 ci(deps): review dependency licenses and advisories on pull requests (#3329)
  • 9cbed16 👷 ci(upgrade): bump the GraalPy test version weekly (#3332)
  • 7e36e66 📝 docs(release): refresh release verification docs (#3330)
  • 07dcf29 🔧 build(meta): add Changelog and Funding project URLs (#3334)
  • dbf474d 🔧 build(docs): pin Mermaid and bump it weekly (#3333)
  • a70c1da 🐛 fix(activation): stop bash re-expanding the prompt in PS1 (#3326)
  • ffb86b7 👷 ci(check): gate required checks behind one job (#3328)
  • 1ef46f1 👷 ci(codeql): scan the tasks scripts (#3327)
  • 876c5ba 🐛 fix(activation): escape PowerShell curly single quotes (#3325)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

This change is Reviewable

Bumps the python-version-updates group with 4 updates: [soupsieve](https://github.com/facelessuser/soupsieve), [poetry](https://github.com/python-poetry/poetry), [filelock](https://github.com/tox-dev/py-filelock) and [virtualenv](https://github.com/pypa/virtualenv).


Updates `soupsieve` from 2.9.2 to 2.10
- [Release notes](https://github.com/facelessuser/soupsieve/releases)
- [Commits](facelessuser/soupsieve@2.9.2...2.10)

Updates `poetry` from 2.4.3 to 2.5.1
- [Release notes](https://github.com/python-poetry/poetry/releases)
- [Changelog](https://github.com/python-poetry/poetry/blob/main/CHANGELOG.md)
- [Commits](python-poetry/poetry@2.4.3...2.5.1)

Updates `filelock` from 3.32.7 to 4.0.3
- [Release notes](https://github.com/tox-dev/py-filelock/releases)
- [Changelog](https://github.com/tox-dev/filelock/blob/main/docs/changelog.rst)
- [Commits](tox-dev/filelock@3.32.7...4.0.3)

Updates `virtualenv` from 21.7.14 to 21.13.0
- [Release notes](https://github.com/pypa/virtualenv/releases)
- [Changelog](https://github.com/pypa/virtualenv/blob/main/docs/changelog.rst)
- [Commits](pypa/virtualenv@21.7.14...21.13.0)

---
updated-dependencies:
- dependency-name: soupsieve
  dependency-version: '2.10'
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-version-updates
- dependency-name: poetry
  dependency-version: 2.5.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: python-version-updates
- dependency-name: filelock
  dependency-version: 4.0.3
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: python-version-updates
- dependency-name: virtualenv
  dependency-version: 21.13.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: python-version-updates
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Sep 28, 2026
@RussTedrake
RussTedrake merged commit 02386dd into master Oct 3, 2026
4 checks passed
@dependabot
dependabot Bot deleted the dependabot/pip/python-version-updates-25dc8f4a75 branch October 3, 2026 16:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant