You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebase will rebase this PR
@dependabot recreate will recreate this PR, overwriting any edits that have been made to it
@dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
@dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
@dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
@dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
Consistency: PR description (Dependabot-generated) matches the actual diff — pyproject.toml's dev-dependency pin and the corresponding uv.lock entry (metadata, sdist/wheel hashes) are both bumped to 0.16.1. No unrelated changes.
Correctness: Pure version-constraint bump (ruff>=0.16.0 → ruff>=0.16.1), no logic changes. Lockfile is internally consistent.
Conventions: Follows repo convention for dev-tooling dependency bumps; no CHANGELOG.md/package version bump required since ruff is a workspace dev dependency, not a released package.
Security: ruff is a lint-only dev dependency (not shipped in any plugin's runtime deps), so it carries no runtime/production exposure. Reviewed upstream release notes for 0.16.1 (2026-07-30): bug fixes, a few rule-safety adjustments (PT018, PT022, FURB105), and preview-feature additions. No CVEs or security advisories associated with this release.
Effectiveness: Achieves its stated purpose — updates the pinned ruff version and lockfile.
Test coverage: N/A — a dependency version bump with no source changes doesn't require new tests. Existing suite is the correct regression signal here.
Step 2 — Regression verification (ran locally against the PR branch, mirroring CI's uv sync --all-packages --all-extras):
uv run ruff check . → All checks passed (no new lint findings surfaced by 0.16.1's rule-safety changes).
uv run mypy packages/*/src → Success, no issues in 14 source files.
uv run pytest -v --ignore=tests/packaging → 107 passed.
uv run pytest tests/packaging -v → 27 passed.
No regressions found.
Step 3 — CI monitoring
All required checks completed successfully: test (3.12), test (3.13), analyze, CodeQL. mergeable_state is clean.
Step 4 — Decision
All gates passed — proceeding with squash merge.
Consistency: PR description matches the diff — pyproject.toml and uv.lock bump the ruff dev dependency floor from >=0.16.0 to >=0.16.1, no other changes.
Correctness: Patch release only. Upstream changelog for 0.16.1 lists preview-feature tweaks, bug fixes (pytest-style, bugbear, comprehensions, pydocstyle, refurb rules), and LSP/server fixes — no rule removals or default-behavior changes that would require code changes here.
Conventions: Follows repo convention of pinning dev tooling via >= floor in the workspace root pyproject.toml; uv.lock regenerated consistently.
Security: No CVE/security advisory associated with this release; it's a routine bug-fix release from astral-sh/ruff. Dependabot compatibility score present.
Effectiveness: Achieves its stated purpose — keeps the dev-only lint tool current.
Test coverage: N/A — dev-tool version bump, no functional code changed, so no new tests required.
Regression verification
Ran locally against this PR's branch (uv sync --all-packages --all-extras, matching CI):
uv run ruff check . → All checks passed (no new lint findings surfaced by 0.16.1 against this codebase)
uv run mypy packages/*/src → Success, no issues found in 14 source files
uv run pytest -v --ignore=tests/packaging → 107 passed
uv run pytest tests/packaging -v → 27 passed
uv build --all-packages → all 3 packages built successfully
CI status
All required checks green: test (3.12), test (3.13), analyze, CodeQL.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps ruff from 0.16.0 to 0.16.1.
Release notes
Sourced from ruff's releases.
... (truncated)
Changelog
Sourced from ruff's changelog.
... (truncated)
Commits
80790b3Bump 0.16.1 (#27330)63830f3[ty] Borrow from constraint set storage less often (#27328)f40dca9[ty] Preserve forwarded expanded-variadic diagnostic sources (#27266)0d80497Lint TOML files in the LSP (#26862)d91586bUpdate prek dependencies (#27293)7da4b8b[ty] Respect bounds and constraints in generic materializations (#27228)b20daf7[ty] refactor: add helper function to send partial results (#27249)4d4c8fa[ty] Emit diagnostic when specializing a non-generic class (#26883)7c3e2db[ty] Fix enum class container assignability (#27318)d5ef97f[flake8-return] Fix false positive when variable is read infinallyclaus...Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)