Conversation
Bumps [https://github.com/gitleaks/gitleaks](https://github.com/gitleaks/gitleaks) from v8.30.0 to 8.30.1. - [Release notes](https://github.com/gitleaks/gitleaks/releases) - [Commits](gitleaks/gitleaks@v8.30.0...v8.30.1) --- updated-dependencies: - dependency-name: https://github.com/gitleaks/gitleaks dependency-version: 8.30.1 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [https://github.com/PyCQA/bandit](https://github.com/PyCQA/bandit) from 1.9.3 to 1.9.4. - [Release notes](https://github.com/PyCQA/bandit/releases) - [Commits](PyCQA/bandit@1.9.3...1.9.4) --- updated-dependencies: - dependency-name: https://github.com/PyCQA/bandit dependency-version: 1.9.4 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [https://github.com/psf/black](https://github.com/psf/black) from 26.1.0 to 26.3.1. - [Release notes](https://github.com/psf/black/releases) - [Changelog](https://github.com/psf/black/blob/main/CHANGES.md) - [Commits](psf/black@26.1.0...26.3.1) --- updated-dependencies: - dependency-name: https://github.com/psf/black dependency-version: 26.3.1 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
…-/github.com/psf/black-26.3.1 ⬆️ Bump https://github.com/psf/black from 26.1.0 to 26.3.1
…-/github.com/PyCQA/bandit-1.9.4 ⬆️ Bump https://github.com/PyCQA/bandit from 1.9.3 to 1.9.4
…-/github.com/gitleaks/gitleaks-8.30.1 ⬆️ Bump https://github.com/gitleaks/gitleaks from v8.30.0 to 8.30.1
Bumps [https://github.com/psf/black](https://github.com/psf/black) from 26.3.1 to 26.5.1. - [Release notes](https://github.com/psf/black/releases) - [Changelog](https://github.com/psf/black/blob/main/CHANGES.md) - [Commits](psf/black@26.3.1...26.5.1) --- updated-dependencies: - dependency-name: https://github.com/psf/black dependency-version: 26.5.1 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
…-/github.com/psf/black-26.5.1 ⬆️ Bump https://github.com/psf/black from 26.3.1 to 26.5.1
Bumps [actions/checkout](https://github.com/actions/checkout) from 6 to 7. - [Release notes](https://github.com/actions/checkout/releases) - [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md) - [Commits](actions/checkout@v6...v7) --- updated-dependencies: - dependency-name: actions/checkout dependency-version: '7' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [https://github.com/igorshubovych/markdownlint-cli](https://github.com/igorshubovych/markdownlint-cli) from v0.48.0 to 0.49.0. - [Release notes](https://github.com/igorshubovych/markdownlint-cli/releases) - [Commits](igorshubovych/markdownlint-cli@v0.48.0...v0.49.0) --- updated-dependencies: - dependency-name: https://github.com/igorshubovych/markdownlint-cli dependency-version: 0.49.0 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
…ctions/checkout-7 ⬆️ Bump actions/checkout from 6 to 7
…-/github.com/igorshubovych/markdownlint-cli-0.49.0 ⬆️ Bump https://github.com/igorshubovych/markdownlint-cli from v0.48.0 to 0.49.0
Updates the requirements on [setuptools](https://github.com/pypa/setuptools) to permit the latest version. - [Release notes](https://github.com/pypa/setuptools/releases) - [Changelog](https://github.com/pypa/setuptools/blob/main/NEWS.rst) - [Commits](pypa/setuptools@v82.0.1...v83.0.0) --- updated-dependencies: - dependency-name: setuptools dependency-version: 83.0.0 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
…te-82.0.1-and-lt-84.0.0 ⬆️ Update setuptools requirement from <83.0.0,>=82.0.1 to >=82.0.1,<84.0.0
Bumps [https://github.com/igorshubovych/markdownlint-cli](https://github.com/igorshubovych/markdownlint-cli) from v0.49.0 to 0.49.1. - [Release notes](https://github.com/igorshubovych/markdownlint-cli/releases) - [Commits](igorshubovych/markdownlint-cli@v0.49.0...v0.49.1) --- updated-dependencies: - dependency-name: https://github.com/igorshubovych/markdownlint-cli dependency-version: 0.49.1 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
…-/github.com/igorshubovych/markdownlint-cli-0.49.1 ⬆️ Bump https://github.com/igorshubovych/markdownlint-cli from v0.49.0 to 0.49.1
Bumps [actions/setup-python](https://github.com/actions/setup-python) from 6 to 7. - [Release notes](https://github.com/actions/setup-python/releases) - [Commits](actions/setup-python@v6...v7) --- updated-dependencies: - dependency-name: actions/setup-python dependency-version: '7' dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
…ctions/setup-python-7 ⬆️ Bump actions/setup-python from 6 to 7
There was a problem hiding this comment.
Pull request overview
This pull request updates dependency constraints and developer/CI tooling to keep the template current, improve reliability, and add automated pre-commit checks in CI.
Changes:
- Broadened the upper bound for
setuptoolsin build requirements (<84.0.0). - Updated several pre-commit hook versions (gitleaks, markdownlint, black, bandit) and removed commented-out local pytest hooks.
- Upgraded GitHub Actions
checkout/setup-pythonversions in workflows and added a newpre-commitworkflow for PRs.
Reviewed changes
Copilot reviewed 10 out of 10 changed files in this pull request and generated 2 comments.
Show a summary per file
| File | Description |
|---|---|
| requirements/requirements.build.txt | Expands allowable setuptools build version range. |
| pyproject.toml | Expands setuptools build-system constraint upper bound. |
| .vscode/settings.json | Removes deprecated VS Code Python language server setting. |
| .vscode/extensions.json | Removes an extension recommendation entry. |
| .pre-commit-config.yaml | Bumps hook versions and cleans up commented-out test hooks. |
| .github/workflows/publish-docs.yml | Upgrades GitHub Actions checkout/setup-python versions. |
| .github/workflows/pre-commit.yml | Adds CI workflow to run pre-commit on pull requests. |
| .github/workflows/3.update-changelog.yml | Upgrades GitHub Actions checkout version. |
| .github/workflows/2.build-publish.yml | Upgrades GitHub Actions checkout/setup-python versions. |
| .github/workflows/1.bump-version.yml | Upgrades GitHub Actions checkout version. |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
Comment on lines
+27
to
+31
| - name: Cache pip | ||
| uses: actions/cache@v6 | ||
| with: | ||
| path: ~/.cache/pip | ||
| key: pip-${{ runner.os }}-${{ hashFiles('requirements.txt') }} |
Comment on lines
+32
to
+36
| - name: Install pre-commit and dependencies | ||
| run: | | ||
| python -m pip install -U pip | ||
| python -m pip install -r ./requirements.txt | ||
| python -m pip install -U pre-commit pyright pytest |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This pull request updates several dependencies and CI workflows to ensure compatibility, improve reliability, and add new automation. The main changes include upgrading GitHub Actions versions in workflow files, updating pre-commit hook versions, adding a new pre-commit workflow, and making minor dependency and configuration adjustments.
CI/CD Workflow Upgrades:
actions/checkoutandactions/setup-pythonto version 7 in all GitHub Actions workflow files for improved reliability and access to new features. (.github/workflows/1.bump-version.yml,.github/workflows/2.build-publish.yml,.github/workflows/3.update-changelog.yml,.github/workflows/publish-docs.yml) [1] [2] [3] [4] [5]Pre-commit and Linting Improvements:
.github/workflows/pre-commit.ymlworkflow to automatically run pre-commit checks on pull requests targetingmainordev, ensuring code quality before merging.gitleaksto v8.30.1markdownlint-clito v0.49.1blackto 26.5.1banditto 1.9.4.pre-commit-config.yamlfor clarity.Dependency and Configuration Updates:
setuptoolsinpyproject.tomlandrequirements/requirements.build.txtto<84.0.0for improved compatibility with future releases. [1] [2]python.languageServersetting from.vscode/settings.jsonto avoid warnings with recent VS Code versions.gruntfuggly.todo-treeextension from.vscode/extensions.json, likely as a cleanup step.