Skip to content

build(deps): bump the ci-python-tools group across 1 directory with 5 updates - #12

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/dot-github/requirements/ci-python-tools-7ff590deda
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/dot-github/requirements/ci-python-tools-7ff590deda

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 25, 2026 •

Copy link
Copy Markdown

Bumps the ci-python-tools group with 5 updates in the /.github/requirements directory:

Package From To
jsonschema 4.25.1 4.26.0
filelock 3.32.5 4.0.0
platformdirs 4.11.7 4.11.10
python-discovery 1.6.0 1.6.1
virtualenv 21.7.8 21.7.15

Updates jsonschema from 4.25.1 to 4.26.0

Release notes

Sourced from jsonschema's releases.

v4.26.0

What's Changed

New Contributors

Full Changelog: python-jsonschema/jsonschema@v4.25.1...v4.26.0

Changelog

Sourced from jsonschema's changelog.

v4.26.0

  • Decrease import time by delaying importing of urllib.request (#1416).
Commits
  • a727743 Add a changelog entry for 4.26.
  • 6d28c13 Update the lockfile.
  • 739499e Update pre-commit hooks.
  • cb2d779 Merge pull request #1443 from python-jsonschema/pre-commit-ci-update-config
  • e6bbbb7 [pre-commit.ci] pre-commit autoupdate
  • d56037a Merge pull request #1442 from python-jsonschema/dependabot/github_actions/ast...
  • e54ce13 Bump astral-sh/setup-uv from 7.1.4 to 7.1.6
  • 1f7c9fb Partially update docs requirements.
  • 241aec9 Merge pull request #1441 from python-jsonschema/pre-commit-ci-update-config
  • 2818efb Apache-2.0 -> nongpl
  • Additional commits viewable in compare view

Updates filelock from 3.32.5 to 4.0.0

Release notes

Sourced from filelock's releases.

4.0.0

What's Changed

Full Changelog: tox-dev/filelock@3.32.7...4.0.0

3.32.7

What's Changed

New Contributors

Full Changelog: tox-dev/filelock@3.32.6...3.32.7

3.32.6

What's Changed

New Contributors

Full Changelog: tox-dev/filelock@3.32.5...3.32.6

Changelog

Sourced from filelock's changelog.

########### Changelog ###########

.. towncrier-draft-entries:: Unreleased

.. towncrier release notes start


4.0.3 (2026-09-23)


  • Importing filelock on CPython 3.10 or 3.11 no longer makes new threads fail with RuntimeError: Cannot install a trace function while another trace function is being installed under coverage or a debugger. filelock skips its fork-safety audit hook there, so forking from inside a thread's own lock-state transition no longer raises immediately on those versions. :pr:747

4.0.2 (2026-09-23)


  • Concurrent acquire() and release() on a thread_local=False lock no longer leak the OS lock, close a descriptor twice, drop a lease token, or leave a false deadlock after a cross-thread release (:issue:744). :pr:745
  • :class:~filelock.AsyncReadWriteLock and :class:~filelock.AsyncSoftReadWriteLock now give each asyncio task its own hold, so tasks sharing one instance no longer enter the write lock together. :pr:746
  • Correct the async cache example to create its data directory and clarify automatic creation of lock-file parent directories. :pr:740
  • Exclude sphinx-llm 1.1.0 from documentation dependencies because its Markdown builder emits unknown-node warnings. :pr:742

4.0.1 (2026-09-19)


  • poll_interval is now validated at construction, on the setter, and on acquire(): a negative, non-finite, or non-numeric value raises :class:ValueError/:class:TypeError immediately instead of failing inside time.sleep. :pr:739

4.0.0 (2026-09-17)


  • The :class:~filelock.SoftReadWriteLock on-disk protocol is a generation log under <path>.rw, and a process running an earlier release does not see it: an old and a new participant on one lock path do not exclude each other. Stop every participant, upgrade them all, then restart them; the new code ignores leftover .state, .write and .readers/ files, and you can delete them. The filesystem must provide no-replace hard links, as it must for :class:~filelock.StrictSoftFileLock, so a runtime without os.link raises :class:~filelock.SoftFileLockProtocolError on acquire. Constructing a singleton again with a different on_compromise, or with poll_interval at or above stale_threshold, now raises :class:ValueError. :pr:735
  • :class:~filelock.SoftReadWriteLock exposes :attr:~filelock.SoftReadWriteLock.generation as a fencing token for the protected resource and reports a lost hold through on_compromise and :attr:~filelock.SoftReadWriteLock.compromise. :pr:735
  • :class:~filelock.SoftReadWriteLock no longer deadlocks when a holder dies on another host mid-transition, and

... (truncated)

Commits
  • 7e57436 Release 4.0.0
  • f974328 🐛 fix(soft-rw): replace the state mutex with a generation log (#738)
  • 20929f7 Release 3.32.7
  • 35f07c4 [pre-commit.ci] pre-commit autoupdate (#736)
  • e860d39 📝 docs: say acquire() falls back to the lock's blocking attribute (#733)
  • c530efe Fix final symlink test on musl (#737)
  • 4efd93e Release 3.32.6
  • 7b7b7a8 Fix SoftReadWriteLock state lock timeout (#726)
  • f2f7b86 fix: respect ACL write access when the owner write bit is absent (#728)
  • e947a69 test(soft-rw): reuse existing test module (#730)
  • Additional commits viewable in compare view

Updates platformdirs from 4.11.7 to 4.11.10

Release notes

Sourced from platformdirs's releases.

4.11.10

What's Changed

Full Changelog: tox-dev/platformdirs@4.11.9...4.11.10

4.11.9

What's Changed

New Contributors

Full Changelog: tox-dev/platformdirs@4.11.8...4.11.9

4.11.8

What's Changed

New Contributors

Full Changelog: tox-dev/platformdirs@4.11.7...4.11.8

Changelog

Sourced from platformdirs's changelog.

########### Changelog ###########

.. towncrier-draft-entries:: Unreleased

.. towncrier release notes start


4.11.14 (2026-09-25)


  • With ensure_exists, create a media directory such as user_documents_dir only when the user set it through an XDG_*_DIR variable or user-dirs.dirs, and return a dangling symlink there instead of raising FileExistsError. 4.11.13 also created the platform defaults, which filled headless home directories with folders such as ~/Templates and made a literal ~ directory when HOME was unset. :pr:561
  • Ignore $XDG_RUNTIME_DIR in user_runtime_dir when use_site_for_root redirects root. :pr:562
  • Return /storage/emulated/0/Download from the Android :func:~platformdirs.user_downloads_dir fallback. :pr:563
  • Ignore WIN_PD_OVERRIDE_* values that lack a drive or a root. :pr:564
  • Find the Android app folder for package names that start with files. :pr:565
  • Reject an appname, appauthor or version that leaves the base directory when set after construction. :pr:566
  • Apply a changed use_site_for_root on the next read. :pr:567
  • Stop raising UnicodeDecodeError on user-dirs.dirs bytes the locale encoding cannot decode. :pr:568
  • Drop a trailing # comment from unquoted user-dirs.dirs values. :pr:569
  • Treat empty Windows folder variables, such as PUBLIC or LOCALAPPDATA, as unset. :pr:571
  • Accept roaming in :func:~platformdirs.user_log_dir and :func:~platformdirs.user_log_path. :pr:572
  • Detect Homebrew Python on macOS by its opt/python*/Frameworks layout. :pr:573
  • Keep colons in the Unix site_cache_path under multipath. :pr:574
  • Return long Windows folder paths in place of 8.3 short names. :pr:575
  • Create the Unix runtime-<uid> temporary fallback with mode 0700 and reject one another user owns. :pr:576
  • Raise RuntimeError in place of creating a literal ~ directory when ensure_exists finds no home. :pr:578
  • Fix the Windows user_preference_dir path in the platform docs. :pr:577
  • Document that the macOS user_state_dir and site_state_dir ignore the XDG_DATA_* variables. :pr:579

4.11.13 (2026-09-25)


  • With ensure_exists, the media directories such as user_documents_dir are created on Unix, and on macOS when an XDG variable sets them - by :user:ekanshul. :pr:560

4.11.12 (2026-09-22)


  • Ignore relative paths in the XDG user directory environment variables, so XDG_DOCUMENTS_DIR=Documents no longer makes :func:~platformdirs.user_documents_dir and the other media directories return a path relative to the working directory. They now fall back to the platform default like the XDG Base Directory variables, and like the same keys read from user-dirs.dirs - by :user:darrenhuai. :pr:554

... (truncated)

Commits
  • 35391fc Release 4.11.10
  • 7d5c85d fix: only create the site dirs a call hands back (#550)
  • 5118d32 👷 ci(release): docstrfmt the changelog before committing it (#551)
  • 4ebd03d Release 4.11.9
  • 0ae539b fix: raise RuntimeError when the Android app folder is missing (#547)
  • de87396 fix: resolve PUBLIC before looking up the user home (#546)
  • 2ba683b fix: accept multipath in the site cache functions (#544)
  • bdb0a67 fix: read user-dirs.dirs as shell assignments, not INI (#545)
  • 5921065 [pre-commit.ci] pre-commit autoupdate (#549)
  • c5ef1ed Release 4.11.8
  • Additional commits viewable in compare view

Updates python-discovery from 1.6.0 to 1.6.1

Release notes

Sourced from python-discovery's releases.

v1.6.1

What's Changed

Full Changelog: tox-dev/python-discovery@1.6.0...1.6.1

Changelog

Sourced from python-discovery's changelog.

Bug fixes - 1.6.1

  • Skip empty PATH entries during interpreter discovery - by :user:gaborbernat. (:issue:129)

Improved documentation - 1.6.1

  • Document :attr:~python_discovery.PythonInfo.system_exe across the tutorial, the how-to guide and the explanation of how resolution reaches a base interpreter. The class diagram in the how-to guide had :attr:~python_discovery.PythonInfo.system_executable typed str rather than str | None - by :user:gaborbernat. (:issue:128)

v1.6.0 (2026-08-28)


Commits

Updates virtualenv from 21.7.8 to 21.7.15

Release notes

Sourced from virtualenv's releases.

21.7.15

What's Changed

Full Changelog: pypa/virtualenv@21.7.14...21.7.15

21.7.14

What's Changed

Full Changelog: pypa/virtualenv@21.7.13...21.7.14

21.7.13

What's Changed

Full Changelog: pypa/virtualenv@21.7.12...21.7.13

21.7.12

What's Changed

Full Changelog: pypa/virtualenv@21.7.11...21.7.12

21.7.11

What's Changed

... (truncated)

Changelog

Sourced from virtualenv's changelog.

Bugfixes - 21.7.15

  • Restore an empty PATH on deactivate in the bash and fish activators, and stop bash leaving the prompt in PS1 when it was unset before activation. (:issue:3259)
  • Fix activate.csh failing to restore PATH and other saved variables on deactivate when PATH was already empty. (:issue:3260)

v21.7.14 (2026-09-18)


Bugfixes - 21.7.14

  • Fix activate.csh failing with Event not found when the virtual environment path contains !. (:issue:3256)

v21.7.13 (2026-09-18)


Bugfixes - 21.7.13

  • Fix activate and activate.fish running commands embedded in the virtual environment path or in the interpreter's Tcl/Tk library paths. (:issue:3252)

v21.7.12 (2026-09-18)


Bugfixes - 21.7.12

  • Fix activate.bat running arbitrary commands from a crafted --prompt, VIRTUALENV_PROMPT, or config file value. (:issue:3250)
  • Verify a downloaded seed wheel's sha256 against PyPI before seeding it into a virtual environment, skipped when a custom pip index is configured. (:issue:3251)

v21.7.11 (2026-09-17)


Bugfixes - 21.7.11

  • Running activate.bat again before deactivate no longer makes deactivate leave the environment's PKG_CONFIG_PATH, TCL_LIBRARY and TK_LIBRARY behind, or lose values the user had set before the first activation - by :user:darrenhuai. (:issue:3245)

... (truncated)

Commits
  • 502d383 release 21.7.15
  • fc2f35f 🐛 fix(activation): make csh deactivate work without test (#3260)
  • ee55cc2 🐛 fix(activation): restore empty saved values on deactivate (#3259)
  • 9baea3c release 21.7.14
  • ab3dcff 🐛 fix(activation): escape ! for csh history expansion (#3256)
  • 0c295ff release 21.7.13
  • 4d5a105 🐛 fix(activation): stop path command injection in bash and fish (#3252)
  • 0525dce 👷 ci: scope the nushell apt key to its own repo (#3253)
  • aa8323a 🔧 chore: drop misc as a changelog fragment type (#3255)
  • a435477 👷 ci: correct a stale checkout pin comment (#3254)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

… updates

Bumps the ci-python-tools group with 5 updates in the /.github/requirements directory:

| Package | From | To |
| --- | --- | --- |
| [jsonschema](https://github.com/python-jsonschema/jsonschema) | `4.25.1` | `4.26.0` |
| [filelock](https://github.com/tox-dev/py-filelock) | `3.32.5` | `4.0.0` |
| [platformdirs](https://github.com/tox-dev/platformdirs) | `4.11.7` | `4.11.10` |
| [python-discovery](https://github.com/tox-dev/python-discovery) | `1.6.0` | `1.6.1` |
| [virtualenv](https://github.com/pypa/virtualenv) | `21.7.8` | `21.7.15` |



Updates `jsonschema` from 4.25.1 to 4.26.0
- [Release notes](https://github.com/python-jsonschema/jsonschema/releases)
- [Changelog](https://github.com/python-jsonschema/jsonschema/blob/main/CHANGELOG.rst)
- [Commits](python-jsonschema/jsonschema@v4.25.1...v4.26.0)

Updates `filelock` from 3.32.5 to 4.0.0
- [Release notes](https://github.com/tox-dev/py-filelock/releases)
- [Changelog](https://github.com/tox-dev/filelock/blob/main/docs/changelog.rst)
- [Commits](tox-dev/filelock@3.32.5...4.0.0)

Updates `platformdirs` from 4.11.7 to 4.11.10
- [Release notes](https://github.com/tox-dev/platformdirs/releases)
- [Changelog](https://github.com/tox-dev/platformdirs/blob/main/docs/changelog.rst)
- [Commits](tox-dev/platformdirs@4.11.7...4.11.10)

Updates `python-discovery` from 1.6.0 to 1.6.1
- [Release notes](https://github.com/tox-dev/python-discovery/releases)
- [Changelog](https://github.com/tox-dev/python-discovery/blob/main/docs/changelog.rst)
- [Commits](tox-dev/python-discovery@1.6.0...1.6.1)

Updates `virtualenv` from 21.7.8 to 21.7.15
- [Release notes](https://github.com/pypa/virtualenv/releases)
- [Changelog](https://github.com/pypa/virtualenv/blob/main/docs/changelog.rst)
- [Commits](pypa/virtualenv@21.7.8...21.7.15)

---
updated-dependencies:
- dependency-name: jsonschema
  dependency-version: 4.26.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: ci-python-tools
- dependency-name: filelock
  dependency-version: 4.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: ci-python-tools
- dependency-name: platformdirs
  dependency-version: 4.11.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: ci-python-tools
- dependency-name: python-discovery
  dependency-version: 1.6.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: ci-python-tools
- dependency-name: virtualenv
  dependency-version: 21.7.15
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: ci-python-tools
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Sep 25, 2026
@dependabot
dependabot Bot requested a review from joey-huckabee as a code owner September 25, 2026 23:24
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Sep 25, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants