Skip to content

deps: bump ruff from 0.16.0 to 0.16.1 - #35

Merged
helebest merged 1 commit into
mainfrom
dependabot/uv/ruff-0.16.1
Aug 3, 2026
Merged

deps: bump ruff from 0.16.0 to 0.16.1#35
helebest merged 1 commit into
mainfrom
dependabot/uv/ruff-0.16.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 3, 2026

Copy link
Copy Markdown
Contributor

Bumps ruff from 0.16.0 to 0.16.1.

Release notes

Sourced from ruff's releases.

0.16.1

Release Notes

Released on 2026-07-30.

Preview features

  • Add an option to opt out of human-readable names (#27160)
  • [flake8-pytest-style] Make fixes safe by default and unsafe only when comments are present (PT018) (#27201)
  • [pyupgrade] Skip fix when a defaulted TypeVar precedes a non-defaulted one (UP040, UP046, UP047) (#27133)
  • [ruff] Fix false positive with unpacked arguments (RUF065) (#26959)

Bug fixes

  • Bump gen-lsp-types to gracefully handle unknown enumeration values in LSP messages (#27230)
  • [flake8-bugbear] Mark range as immutable (B008) (#27247)
  • [flake8-comprehensions] NFKC-normalize keyword names in C408 fix (#26813)
  • [flake8-return] Fix false positive when variable is read in finally clause (RET504) (#25441)
  • [pydocstyle] Skip section detection inside RST directive bodies (D214, D405, D413) (#23635)
  • [refurb] Parenthesize yield arguments in the FURB192 fix (#27192)

Rule changes

  • [flake8-pytest-style] Mark PT022 fixes as unsafe (#26440)
  • [refurb] Mark fixes that remove unknown separators as unsafe (FURB105) (#27200)

Server

  • Fix indexing of excluded nested Ruff workspaces (#27303)
  • Lint TOML files in the LSP (#26862)

Documentation

  • Cover pycon Markdown formatting (#27153)
  • [flake8-bandit] Document TYPE_CHECKING exception (S101) (#27004)
  • [flake8-import-conventions] Document that extend-aliases can override default aliases (#27191)
  • [pylint] Add missing fix safety gotchas for non-augmented-assignment (PLR6104) (#27250)

Other changes

  • Reduce syntax error noise by swallowing dedents like indents (#27170)
  • Vendor latest annotate-snippets (#27033)

Contributors

... (truncated)

Changelog

Sourced from ruff's changelog.

0.16.1

Released on 2026-07-30.

Preview features

  • Add an option to opt out of human-readable names (#27160)
  • [flake8-pytest-style] Make fixes safe by default and unsafe only when comments are present (PT018) (#27201)
  • [pyupgrade] Skip fix when a defaulted TypeVar precedes a non-defaulted one (UP040, UP046, UP047) (#27133)
  • [ruff] Fix false positive with unpacked arguments (RUF065) (#26959)

Bug fixes

  • Bump gen-lsp-types to gracefully handle unknown enumeration values in LSP messages (#27230)
  • [flake8-bugbear] Mark range as immutable (B008) (#27247)
  • [flake8-comprehensions] NFKC-normalize keyword names in C408 fix (#26813)
  • [flake8-return] Fix false positive when variable is read in finally clause (RET504) (#25441)
  • [pydocstyle] Skip section detection inside RST directive bodies (D214, D405, D413) (#23635)
  • [refurb] Parenthesize yield arguments in the FURB192 fix (#27192)

Rule changes

  • [flake8-pytest-style] Mark PT022 fixes as unsafe (#26440)
  • [refurb] Mark fixes that remove unknown separators as unsafe (FURB105) (#27200)

Server

  • Fix indexing of excluded nested Ruff workspaces (#27303)
  • Lint TOML files in the LSP (#26862)

Documentation

  • Cover pycon Markdown formatting (#27153)
  • [flake8-bandit] Document TYPE_CHECKING exception (S101) (#27004)
  • [flake8-import-conventions] Document that extend-aliases can override default aliases (#27191)
  • [pylint] Add missing fix safety gotchas for non-augmented-assignment (PLR6104) (#27250)

Other changes

  • Reduce syntax error noise by swallowing dedents like indents (#27170)
  • Vendor latest annotate-snippets (#27033)

Contributors

... (truncated)

Commits
  • 80790b3 Bump 0.16.1 (#27330)
  • 63830f3 [ty] Borrow from constraint set storage less often (#27328)
  • f40dca9 [ty] Preserve forwarded expanded-variadic diagnostic sources (#27266)
  • 0d80497 Lint TOML files in the LSP (#26862)
  • d91586b Update prek dependencies (#27293)
  • 7da4b8b [ty] Respect bounds and constraints in generic materializations (#27228)
  • b20daf7 [ty] refactor: add helper function to send partial results (#27249)
  • 4d4c8fa [ty] Emit diagnostic when specializing a non-generic class (#26883)
  • 7c3e2db [ty] Fix enum class container assignability (#27318)
  • d5ef97f [flake8-return] Fix false positive when variable is read in finally claus...
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [ruff](https://github.com/astral-sh/ruff) from 0.16.0 to 0.16.1.
- [Release notes](https://github.com/astral-sh/ruff/releases)
- [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md)
- [Commits](astral-sh/ruff@0.16.0...0.16.1)

---
updated-dependencies:
- dependency-name: ruff
  dependency-version: 0.16.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Aug 3, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: deps. Please create it before Dependabot can add it to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

helebest commented Aug 3, 2026

Copy link
Copy Markdown
Contributor

Automated review: ruff 0.16.0 → 0.16.1

Step 1 — Code review

  • Consistency: PR description (Dependabot-generated) matches the actual diff — pyproject.toml's dev-dependency pin and the corresponding uv.lock entry (metadata, sdist/wheel hashes) are both bumped to 0.16.1. No unrelated changes.
  • Correctness: Pure version-constraint bump (ruff>=0.16.0ruff>=0.16.1), no logic changes. Lockfile is internally consistent.
  • Conventions: Follows repo convention for dev-tooling dependency bumps; no CHANGELOG.md/package version bump required since ruff is a workspace dev dependency, not a released package.
  • Security: ruff is a lint-only dev dependency (not shipped in any plugin's runtime deps), so it carries no runtime/production exposure. Reviewed upstream release notes for 0.16.1 (2026-07-30): bug fixes, a few rule-safety adjustments (PT018, PT022, FURB105), and preview-feature additions. No CVEs or security advisories associated with this release.
  • Effectiveness: Achieves its stated purpose — updates the pinned ruff version and lockfile.
  • Test coverage: N/A — a dependency version bump with no source changes doesn't require new tests. Existing suite is the correct regression signal here.

Step 2 — Regression verification (ran locally against the PR branch, mirroring CI's uv sync --all-packages --all-extras):

  • uv run ruff check . → All checks passed (no new lint findings surfaced by 0.16.1's rule-safety changes).
  • uv run mypy packages/*/src → Success, no issues in 14 source files.
  • uv run pytest -v --ignore=tests/packaging → 107 passed.
  • uv run pytest tests/packaging -v → 27 passed.

No regressions found.

Step 3 — CI monitoring
All required checks completed successfully: test (3.12), test (3.13), analyze, CodeQL. mergeable_state is clean.

Step 4 — Decision
All gates passed — proceeding with squash merge.


Generated by Claude Code

@helebest
helebest merged commit 577f92c into main Aug 3, 2026
4 checks passed
@helebest
helebest deleted the dependabot/uv/ruff-0.16.1 branch August 3, 2026 23:18

helebest commented Aug 3, 2026

Copy link
Copy Markdown
Contributor

Automated Review: ruff 0.16.0 → 0.16.1

Consistency: PR description matches the diff — pyproject.toml and uv.lock bump the ruff dev dependency floor from >=0.16.0 to >=0.16.1, no other changes.

Correctness: Patch release only. Upstream changelog for 0.16.1 lists preview-feature tweaks, bug fixes (pytest-style, bugbear, comprehensions, pydocstyle, refurb rules), and LSP/server fixes — no rule removals or default-behavior changes that would require code changes here.

Conventions: Follows repo convention of pinning dev tooling via >= floor in the workspace root pyproject.toml; uv.lock regenerated consistently.

Security: No CVE/security advisory associated with this release; it's a routine bug-fix release from astral-sh/ruff. Dependabot compatibility score present.

Effectiveness: Achieves its stated purpose — keeps the dev-only lint tool current.

Test coverage: N/A — dev-tool version bump, no functional code changed, so no new tests required.

Regression verification

Ran locally against this PR's branch (uv sync --all-packages --all-extras, matching CI):

  • uv run ruff check .All checks passed (no new lint findings surfaced by 0.16.1 against this codebase)
  • uv run mypy packages/*/srcSuccess, no issues found in 14 source files
  • uv run pytest -v --ignore=tests/packaging107 passed
  • uv run pytest tests/packaging -v27 passed
  • uv build --all-packages → all 3 packages built successfully

CI status

All required checks green: test (3.12), test (3.13), analyze, CodeQL.

Decision

No issues found. Proceeding with squash merge.


Generated by Claude Code

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant