Skip to content

Bump the python-dependencies group across 1 directory with 3 updates - #2139

Merged
edmorley merged 2 commits into
mainfrom
dependabot/pip/python-dependencies-ad517071b5
Sep 3, 2026
Merged

edmorley merged 2 commits into
mainfrom
dependabot/pip/python-dependencies-ad517071b5

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 3, 2026

Copy link
Copy Markdown
Contributor

Bumps the python-dependencies group with 3 updates in the / directory: poetry, uv and pipenv.

Updates poetry from 2.4.1 to 2.4.2

Release notes

Sourced from poetry's releases.

2.4.2

Fixed

  • Fix an issue where Poetry installs an artifact that is not listed in the lockfile when the package source does not provide a hash for this artifact (#11030).
  • Fix a path traversal vulnerability when downloading files from a compromised URL and/or package source (#11029).
  • Fix a path traversal vulnerability in sdist extraction on Python 3.10.0-3.10.12 and 3.11.0-3.11.4 that could allow malicious tarball files to write files outside the target directory (#11027).
Changelog

Sourced from poetry's changelog.

[2.4.2] - 2026-08-29

Fixed

  • Fix an issue where Poetry installs an artifact that is not listed in the lockfile when the package source does not provide a hash for this artifact (#11030).
  • Fix a path traversal vulnerability when downloading files from a compromised URL and/or package source (#11029).
  • Fix a path traversal vulnerability in sdist extraction on Python 3.10.0-3.10.12 and 3.11.0-3.11.4 that could allow malicious tarball files to write files outside the target directory (#11027).
Commits
  • 15ce1fc release: bump version to 2.4.2
  • 3dd0f2d perf: avoid unnecessary downloads when the index does not provide hashes
  • c2f9af2 Fail closed when a locked hash cannot be checked
  • 3a194dd fix: reject invalid link filenames when downloading files (#11029)
  • 22173fd fix: refuse to write files outside the target directory during sdist extracti...
  • See full diff in compare view

Updates uv from 0.12.5 to 0.12.9

Release notes

Sourced from uv's releases.

0.12.9

Release Notes

Released on 2026-09-01.

Python

Enhancements

  • Add --no-locked and --no-frozen to disable lock modes enabled by UV_LOCKED and UV_FROZEN for a single invocation (#21408)
  • Report the exact command-line lock-mode flag in warnings and errors (#21402)

Performance

  • Speed up cold wheel installs by extracting each streaming ZIP archive in a single blocking task and reusing buffers across files (#21372)

Bug fixes

  • Update async_http_range_reader to 0.11.1 to address a potential memory-safety issue when reading metadata ranges from untrusted wheels (#21401)
  • Remove sensitive headers when redirects cross authentication realms, including same-host redirects that change URL schemes (#21382)
  • Redact secrets in signed URLs from retry diagnostics, including nested request errors (#21381)
  • Give --locked, --frozen, --check, and --check-exists precedence over conflicting UV_LOCKED and UV_FROZEN values (#21396)
  • Prevent concurrent uv processes from redundantly extracting the same local or source-built wheel (#21400)

Install uv 0.12.9

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.9/uv-installer.sh | sh

Install prebuilt binaries via powershell script

powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.9/uv-installer.ps1 | iex"

Download uv 0.12.9

File Platform Checksum
uv-aarch64-apple-darwin.tar.gz Apple Silicon macOS checksum
uv-x86_64-apple-darwin.tar.gz Intel macOS checksum
uv-aarch64-pc-windows-msvc.zip ARM64 Windows checksum
uv-i686-pc-windows-msvc.zip x86 Windows checksum
uv-x86_64-pc-windows-msvc.zip x64 Windows checksum
uv-aarch64-unknown-linux-gnu.tar.gz ARM64 Linux checksum

... (truncated)

Changelog

Sourced from uv's changelog.

0.12.9

Released on 2026-09-01.

Python

Enhancements

  • Add --no-locked and --no-frozen to disable lock modes enabled by UV_LOCKED and UV_FROZEN for a single invocation (#21408)
  • Report the exact command-line lock-mode flag in warnings and errors (#21402)

Performance

  • Speed up cold wheel installs by extracting each streaming ZIP archive in a single blocking task and reusing buffers across files (#21372)

Bug fixes

  • Update async_http_range_reader to 0.11.1 to address a potential memory-safety issue when reading metadata ranges from untrusted wheels (#21401)
  • Remove sensitive headers when redirects cross authentication realms, including same-host redirects that change URL schemes (#21382)
  • Redact secrets in signed URLs from retry diagnostics, including nested request errors (#21381)
  • Give --locked, --frozen, --check, and --check-exists precedence over conflicting UV_LOCKED and UV_FROZEN values (#21396)
  • Prevent concurrent uv processes from redundantly extracting the same local or source-built wheel (#21400)

0.12.8

Released on 2026-08-31.

Enhancements

  • Warn about invalid tool directories and continue upgrading valid tools with uv tool upgrade --all (#21368)

Preview features

  • Deduplicate identical files within and across cached wheels with the content-addressed-cache preview feature (#21327)
  • Reduce allocations while extracting content-addressed wheels by reusing the hashing buffer across files (#21340)
  • Speed up content-addressed cache cleanup on macOS by reading hard-link counts in bulk (#21344)

Performance

  • Prevent concurrent uv processes from downloading and extracting the same remote wheel more than once (#21379)
  • Speed up dependency graph construction from large lockfiles by indexing packages during traversal (#21373)
  • Extend indexed lockfile traversal to exports, dependency trees, audits, and freshness checks (#21377)
  • Speed up warm resolutions by reducing repeated marker interner work (#21300)

Bug fixes

  • Do not trust hashes from direct URLs discovered only in wheel metadata when installing with --require-hashes (#21348)
  • Use a compatible Azure Storage API version for anonymous and authenticated requests, allowing credential retries when public access is disabled (#21366)

... (truncated)

Commits

Updates pipenv from 2026.7.1 to 2026.8.0

Release notes

Sourced from pipenv's releases.

Release v2026.8.0

🤖 AI-Generated Changelog

Added

  • Parallel index manifest prefetching (PIPENV_PREFETCH_INDEX_MANIFESTS): New experimental feature that fetches package index manifests concurrently during lock operations, significantly reducing resolution time for large dependency sets
  • PEP 691 JSON Simple API support: Native parsing of PEP 691 JSON responses from package indexes alongside existing PEP 503 HTML parsing
  • Disk-based manifest cache (ParsedManifestCache): JSON-on-disk cache with TTL and atomic writes to avoid redundant index fetches across lock operations
  • Pluggable resolver backend scaffolding: Foundation for swappable resolver backends, enabling future customization of dependency resolution strategies
  • Per-source verify_ssl fan-out for prefetcher: Each index source now independently respects its SSL verification and certificate settings during parallel prefetch
  • peek_etag stale-cache short-circuit: Resolver can now skip full manifest fetches when ETags indicate cached data is still fresh
  • prefetch_index_manifests setting: New boolean configuration option to enable/disable the parallel prefetch feature
  • Reject Pipfile entries with unrecognized keys, providing clearer errors on misconfiguration

Changed

  • Pipfile subsystem extracted from Project: Internal refactor completing Initiative D; project.build_script and related attributes now live on project.pipfile
  • Lockfile subsystem extracted from Project: Lockfile state management is now a dedicated subsystem
  • unpack_url / get_http_url moved to pipenv/utils/unpack.py; legacy requirementslib.py removed
  • Resolver backend selection is now stamped onto resolver requests for improved traceability
  • Prior Pipfile.lock pins are fed as pip constraints on warm relock to speed up re-locking (reverted and re-landed with fixes)
  • Resolver subprocess skipped entirely for empty Pipfile categories, reducing unnecessary process overhead
  • Vendor pip updated to 26.2.1

Fixed

  • Corrupt lockfile recovery: Fixed return path when recovering from a corrupt lockfile
  • Editable VCS extras now resolve correctly with pip 26.2
  • netrc login handling: Quote-only netrc credentials are now treated as empty on Python 3.10+, preventing auth failures
  • Manifest cache retry on Windows: os.replace is retried on ERROR_ACCESS_DENIED with a wall-clock budget, fixing cache write failures on Windows
  • Missing Pipfile hashes are now handled gracefully instead of raising an error
  • Plette Pipfile attribute delegation fixed after subsystem refactor
  • resolver_backend is now correctly plumbed through the venv_resolve_deps call chain
  • Prerelease versions are now allowed as a fallback at final lower bounds
  • Stale project.build_script call sites migrated to project.pipfile.build_script
  • Test for Pipfile version warning updated after subsystem extraction
  • test_lockfile_location_is_pipfile_plus_lock made OS-portable
  • Fixed latest hash and virtualenv guidance in documentation/output
  • Fixed first-party CodeQL reliability errors
  • Deferred pip-internal imports (InstallCommand, unpack, Downloader, network imports) to improve startup performance

Security

  • CodeQL reliability improvements to reduce false negatives in static analysis

🔗 Full Changelog: pypa/pipenv@v2026.7.1...v2026.8.0

Changelog

Sourced from pipenv's changelog.

2026.8.0 (2026-08-20)

pipenv 2026.8.0 (2026-08-20)

Features & Improvements

  • Pipenv now includes scaffolding for pluggable resolver backends. The --resolver NAME CLI flag, PIPENV_RESOLVER environment variable, and [pipenv] resolver Pipfile setting are now recognized, but only pip (the default) is shipped in this release. Selecting an unknown backend will produce a clear error message. Future releases will add additional backends. #T_F.5 <https://github.com/pypa/pipenv/issues/T_F.5>_
  • Add a pure-Python PEP 691 / PEP 503 simple-API client + parsed-manifest cache + parallel fetcher under pipenv/resolver/. Initiative G phase 1 ships the standalone surface; no integration yet. Phase 2 (cache-prime bridge) and Phase 3 (full backend) will wire it in. pipenv lock --clear and pipenv install --clear now invalidate this parsed-manifest cache in addition to pip's HTTP cache. #initiative-g-phase1-pep691-client <https://github.com/pypa/pipenv/issues/initiative-g-phase1-pep691-client>_
  • Add [pipenv] prefetch_index_manifests opt-in setting (also PIPENV_PREFETCH_INDEX_MANIFESTS=1) that pre-fetches simple-API index pages for top-level Pipfile packages in parallel before the resolver runs. Most beneficial on cold caches or slow networks; off-by-default because warm-cache dev machines see neutral-to- slightly-slower behaviour. Initiative G phase 2. #initiative-g-phase2-prefetch-bridge <https://github.com/pypa/pipenv/issues/initiative-g-phase2-prefetch-bridge>_

Bug Fixes

  • Fixed corrupt Pipfile and lockfile errors so they retain the affected path and backup location while reporting the file-specific error message.
  • Allow dependency locking to fall back to a prerelease of a final lower bound, such as resolving odin~=2.11 to 2.11rc3 before the 2.11 final release is available. [#6701](https://github.com/pypa/pipenv/issues/6701) <https://github.com/pypa/pipenv/issues/6701>_
  • Python-version mismatch warnings now recommend pipenv remove instead of the deprecated pipenv --rm flag. [#6704](https://github.com/pypa/pipenv/issues/6704) <https://github.com/pypa/pipenv/issues/6704>_
  • Hash-lookup sessions now use pip's combined certificate trust configuration, so custom CA bundles do not discard the public roots trusted by pip. [#6711](https://github.com/pypa/pipenv/issues/6711) <https://github.com/pypa/pipenv/issues/6711>_
  • PyPI hash collection now handles requests and pip network exceptions and falls back to the resolver's other hash sources. [#6712](https://github.com/pypa/pipenv/issues/6712) <https://github.com/pypa/pipenv/issues/6712>_

Vendored Libraries

  • Updated the bundled pip to 26.2.
  • Updated the bundled pip to 26.2.1.
Commits
  • 2a37cdb Release v2026.8.0
  • 2b855a4 Bumped version to 2026.8.0.
  • 200082a Merge pull request #6668 from pypa/maintenance/code-cleanup-phase5-perf-2026-06
  • 5cdd812 Address final Phase V review feedback
  • d1248c2 Document best-effort cache cleanup
  • f798b2e Address additional resolver code quality feedback
  • c610fb9 Adapt truststore test to lazy imports
  • 0fa2c19 Address manifest cache test review feedback
  • 6c1f520 fix(tests): validate prefetch source hostnames structurally
  • 1067385 fix(resolver-auth): treat quote-only netrc login as empty on Python 3.10
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the python-dependencies group with 3 updates in the / directory: [poetry](https://github.com/python-poetry/poetry), [uv](https://github.com/astral-sh/uv) and [pipenv](https://github.com/pypa/pipenv).


Updates `poetry` from 2.4.1 to 2.4.2
- [Release notes](https://github.com/python-poetry/poetry/releases)
- [Changelog](https://github.com/python-poetry/poetry/blob/main/CHANGELOG.md)
- [Commits](python-poetry/poetry@2.4.1...2.4.2)

Updates `uv` from 0.12.5 to 0.12.9
- [Release notes](https://github.com/astral-sh/uv/releases)
- [Changelog](https://github.com/astral-sh/uv/blob/main/CHANGELOG.md)
- [Commits](astral-sh/uv@0.12.5...0.12.9)

Updates `pipenv` from 2026.7.1 to 2026.8.0
- [Release notes](https://github.com/pypa/pipenv/releases)
- [Changelog](https://github.com/pypa/pipenv/blob/main/CHANGELOG.md)
- [Commits](pypa/pipenv@v2026.7.1...v2026.8.0)

---
updated-dependencies:
- dependency-name: poetry
  dependency-version: 2.4.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python-dependencies
- dependency-name: uv
  dependency-version: 0.12.9
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python-dependencies
- dependency-name: pipenv
  dependency-version: 2026.8.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Dependabot pull requests that update Python dependencies labels Sep 3, 2026
@dependabot
dependabot Bot requested a review from edmorley as a code owner September 3, 2026 08:46
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Dependabot pull requests that update Python dependencies labels Sep 3, 2026
@edmorley
edmorley merged commit 9487921 into main Sep 3, 2026
14 of 15 checks passed
@edmorley
edmorley deleted the dependabot/pip/python-dependencies-ad517071b5 branch September 3, 2026 12:38
@heroku-linguist heroku-linguist Bot mentioned this pull request Sep 3, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Dependabot pull requests that update Python dependencies

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant