Skip to content

Bump the python-dependencies group across 1 directory with 2 updates - #2147

Merged
edmorley merged 3 commits into
mainfrom
dependabot/pip/python-dependencies-88dada5d40
Oct 1, 2026
Merged

edmorley merged 3 commits into
mainfrom
dependabot/pip/python-dependencies-88dada5d40

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the python-dependencies group with 2 updates in the / directory: poetry and uv.

Updates poetry from 2.4.2 to 2.5.1

Release notes

Sourced from poetry's releases.

2.5.1

Fixed

  • Fix an issue where uninstalling a package with installer.builtin-uninstall set failed with a TypeError (#11077).

2.5.0

Added

  • Add an installer.builtin-uninstall setting to uninstall packages with a built-in uninstaller instead of invoking pip uninstall (#10931).
  • Add official support for Python 3.15 (#11046).

Changed

  • Do not send credentials configured for an https repository via http (#11073).
  • Fail with an error when the current Python version is not compatible with the project and virtualenvs.create is false (#10941).
  • Validate version constraints that are entered interactively in poetry init (#10909).
  • Include the path of the pyproject.toml file in the message about already present packages in poetry add (#10908).
  • Improve performance of processing package links and repository pages (#10895, #10896, #10903, #10949, #10951, #10953).
  • Improve performance of dependency resolution (#10907, #10954).
  • Improve performance of choosing and installing wheels (#10905, #10958).
  • Improve performance by avoiding redundant keyring lookups for repositories without credentials (#10959).
  • Improve performance by reducing the number of subprocesses to discover virtual environment data (#11042).
  • Improve performance of poetry search for single-token queries (#10906).
  • Improve startup time by deferring the import of requests (#11004).
  • Improve performance of schema validation by caching compiled JSON schema validators (#11033).

Fixed

  • Fix an issue where credentials of the wrong repository were used under certain circumstances when multiple repositories were configured on the same host (#11072).
  • Fix an issue where credentials of a repository on another host were used for git dependencies if the path of the URL was the same (#11074).
  • Fix an issue where dependency resolution failed for conflicting requirements of different packages even though the requirements had mutually exclusive markers (#10944).
  • Fix an issue where dependency resolution failed when the same package was required with different extras in several optional dependencies or dependency groups (#10943).
  • Fix an issue where dependency resolution failed with a KeyError (#11008).
  • Fix an issue where the dependencies of an extra were missing in the lock file after adding the extra to a locked dependency, e.g. a git dependency, in the pyproject.toml file (#10987).
  • Fix an issue where a path or git dependency was not reinstalled when its develop setting changed (#11022).
  • Fix an issue where scripts of type file were not installed when installing the project (#10736).
  • Fix an issue where GUI scripts were not installed when installing the project (#10973).
  • Fix an issue where a relative path was written to direct_url.json for path dependencies (#10917).
  • Fix an issue where poetry show <package> showed a version that was not relevant for the current environment if there were multiple versions of the package in the lock file (#11003).
  • Fix an issue where poetry show --outdated did not find newer versions of packages from sources with explicit priority (#10982).
  • Fix an issue where poetry env activate ignored the environment that was determined by the application, e.g. when using --directory (#10916).
  • Fix an issue where poetry init proposed an invalid package name if the directory name was not a valid package name (#10975).

Docs

  • Document the --license option of poetry init and poetry new (#11064).
  • Clarify which dependencies are locked when running poetry update with dependency groups (#11024).
  • Clarify the portability of path dependencies (#11020).
  • Clarify the usage of poetry run with console scripts (#10984).

... (truncated)

Changelog

Sourced from poetry's changelog.

[2.5.1] - 2026-09-20

Fixed

  • Fix an issue where uninstalling a package with installer.builtin-uninstall set failed with a TypeError (#11077).

[2.5.0] - 2026-09-19

Added

  • Add an installer.builtin-uninstall setting to uninstall packages with a built-in uninstaller instead of invoking pip uninstall (#10931).
  • Add official support for Python 3.15 (#11046).

Changed

  • Do not send credentials configured for an https repository via http (#11073).
  • Fail with an error when the current Python version is not compatible with the project and virtualenvs.create is false (#10941).
  • Validate version constraints that are entered interactively in poetry init (#10909).
  • Include the path of the pyproject.toml file in the message about already present packages in poetry add (#10908).
  • Improve performance of processing package links and repository pages (#10895, #10896, #10903, #10949, #10951, #10953).
  • Improve performance of dependency resolution (#10907, #10954).
  • Improve performance of choosing and installing wheels (#10905, #10958).
  • Improve performance by avoiding redundant keyring lookups for repositories without credentials (#10959).
  • Improve performance by reducing the number of subprocesses to discover virtual environment data (#11042).
  • Improve performance of poetry search for single-token queries (#10906).
  • Improve startup time by deferring the import of requests (#11004).
  • Improve performance of schema validation by caching compiled JSON schema validators (#11033).

Fixed

  • Fix an issue where credentials of the wrong repository were used under certain circumstances when multiple repositories were configured on the same host (#11072).
  • Fix an issue where credentials of a repository on another host were used for git dependencies if the path of the URL was the same (#11074).
  • Fix an issue where dependency resolution failed for conflicting requirements of different packages even though the requirements had mutually exclusive markers (#10944).
  • Fix an issue where dependency resolution failed when the same package was required with different extras in several optional dependencies or dependency groups (#10943).
  • Fix an issue where dependency resolution failed with a KeyError (#11008).
  • Fix an issue where the dependencies of an extra were missing in the lock file after adding the extra to a locked dependency, e.g. a git dependency, in the pyproject.toml file (#10987).
  • Fix an issue where a path or git dependency was not reinstalled when its develop setting changed (#11022).
  • Fix an issue where scripts of type file were not installed when installing the project (#10736).
  • Fix an issue where GUI scripts were not installed when installing the project (#10973).
  • Fix an issue where a relative path was written to direct_url.json for path dependencies (#10917).
  • Fix an issue where poetry show <package> showed a version that was not relevant for the current environment if there were multiple versions of the package in the lock file (#11003).
  • Fix an issue where poetry show --outdated did not find newer versions of packages from sources with explicit priority (#10982).

... (truncated)

Commits
  • 94b6e35 release: bump version to 2.5.1
  • f8408ca fix TypeError when using installer.builtin-uninstall (#11077)
  • 165fb4b release: bump version to 2.5.0
  • c93fd63 update poetry-core (#10921)
  • 32356ae chore: update dependencies (#11075)
  • d266d45 test: accept compatible extension wheel tags (#11014)
  • c8790a3 add Python 3.15 to tests matrix (#11046)
  • a416efd authenticator: match host when looking up git credentials (#11074)
  • e078ebf authenticator: do not send credentials configured for https with http (#11073)
  • 8711c83 authenticator: sort candidates by common path segments instead of prefixes (#...
  • Additional commits viewable in compare view

Updates uv from 0.12.9 to 0.12.21

Release notes

Sourced from uv's releases.

0.12.21

Release Notes

Released on 2026-09-29.

Python

  • Update CPython to use OpenSSL 3.5.9 (#22076)

Enhancements

  • Omit empty [manifest] tables from lockfiles that contain only manifest subtables (#22070)

Preview features

  • Omit redundant runtime constraints from uv.lock, including those involving pre-releases, with the resolution-inputs preview feature (#22004, #22068)

Bug fixes

  • Prevent uv python pin --rm from removing a global .python-versions file without --global (#21992)
  • Fix installed-package checks incorrectly reporting post-releases as incompatible with exclusive lower bounds on pre-releases (#22049)

Install uv 0.12.21

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/uv/releases/download/0.12.21/uv-installer.sh | sh

Install prebuilt binaries via powershell script

powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/uv/releases/download/0.12.21/uv-installer.ps1 | iex"

Download uv 0.12.21

File Platform Checksum
uv-aarch64-apple-darwin.tar.gz Apple Silicon macOS checksum
uv-x86_64-apple-darwin.tar.gz Intel macOS checksum
uv-aarch64-pc-windows-msvc.zip ARM64 Windows checksum
uv-i686-pc-windows-msvc.zip x86 Windows checksum
uv-x86_64-pc-windows-msvc.zip x64 Windows checksum
uv-aarch64-unknown-linux-gnu.tar.gz ARM64 Linux checksum
uv-i686-unknown-linux-gnu.tar.gz x86 Linux checksum
uv-powerpc64le-unknown-linux-gnu.tar.gz PPC64LE Linux checksum
uv-riscv64gc-unknown-linux-gnu.tar.gz RISCV Linux checksum
uv-s390x-unknown-linux-gnu.tar.gz S390x Linux checksum

... (truncated)

Changelog

Sourced from uv's changelog.

0.12.21

Released on 2026-09-29.

Python

  • Update CPython to use OpenSSL 3.5.9 (#22076)

Enhancements

  • Omit empty [manifest] tables from lockfiles that contain only manifest subtables (#22070)

Preview features

  • Omit redundant runtime constraints from uv.lock, including those involving pre-releases, with the resolution-inputs preview feature (#22004, #22068)

Bug fixes

  • Prevent uv python pin --rm from removing a global .python-versions file without --global (#21992)
  • Fix installed-package checks incorrectly reporting post-releases as incompatible with exclusive lower bounds on pre-releases (#22049)

0.12.20

Released on 2026-09-28.

Enhancements

  • Reuse lockfiles when dependency declarations are semantically equivalent (#21951)
  • Preserve second-line encoding declarations when installing wheel scripts with CRLF shebangs (#21990)

Preview features

  • Write normalized requirement declarations with the lockfile-normalization preview feature (#21951)
  • Honor synthetic default groups when installing or syncing from pylock.toml (#22003)
  • Resolve local paths in exported pylock.toml files relative to the output file (#22042)
  • Install each package only once when repeated tool-install-locks requirements resolve to the same package (#22000)
  • Reuse lock-without-metadata lockfiles for conflicting groups with distinct base and extra requirement specifiers (#22055)
  • Use consistent root-package paths in uv workspace metadata and uv tree --format json output (#22050)

Configuration

  • Continue searching XDG_CONFIG_DIRS after empty entries (#21987)

Performance

  • Restore the previous HTTP cache-write scheduling while investigating severe cache-revalidation stalls on ext4 filesystems (#22051)

Bug fixes

  • Apply hash constraints to every repeated requirement under --require-hashes and --verify-hashes (#21996)

... (truncated)

Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Dependabot pull requests that update Python dependencies labels Oct 1, 2026
@dependabot
dependabot Bot requested a review from edmorley as a code owner October 1, 2026 13:14
@edmorley

edmorley commented Oct 1, 2026

Copy link
Copy Markdown
Member

@dependabot recreate

@dependabot dependabot Bot changed the title Bump the python-dependencies group with 2 updates Bump the python-dependencies group across 1 directory with 2 updates Oct 1, 2026
@dependabot
dependabot Bot force-pushed the dependabot/pip/python-dependencies-88dada5d40 branch from 0d9f51e to 915dbf6 Compare October 1, 2026 13:37
@edmorley

edmorley commented Oct 1, 2026

Copy link
Copy Markdown
Member

@dependabot rebase

Bumps the python-dependencies group with 2 updates in the / directory: [poetry](https://github.com/python-poetry/poetry) and [uv](https://github.com/astral-sh/uv).


Updates `poetry` from 2.4.2 to 2.5.1
- [Release notes](https://github.com/python-poetry/poetry/releases)
- [Changelog](https://github.com/python-poetry/poetry/blob/main/CHANGELOG.md)
- [Commits](python-poetry/poetry@2.4.2...2.5.1)

Updates `uv` from 0.12.9 to 0.12.21
- [Release notes](https://github.com/astral-sh/uv/releases)
- [Changelog](https://github.com/astral-sh/uv/blob/main/CHANGELOG.md)
- [Commits](astral-sh/uv@0.12.9...0.12.21)

---
updated-dependencies:
- dependency-name: poetry
  dependency-version: 2.5.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-dependencies
- dependency-name: uv
  dependency-version: 0.12.21
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/pip/python-dependencies-88dada5d40 branch from 915dbf6 to a7a215f Compare October 1, 2026 20:40
@edmorley
edmorley requested a review from a team as a code owner October 1, 2026 20:47
@edmorley
edmorley merged commit 81876b1 into main Oct 1, 2026
9 of 10 checks passed
@edmorley
edmorley deleted the dependabot/pip/python-dependencies-88dada5d40 branch October 1, 2026 21:01
edmorley added a commit that referenced this pull request Oct 2, 2026
Poetry 2.5.0 fixed the upstream bug where Poetry didn't error on a
Python version mismatch when `virtualenvs.create` is `false`:
python-poetry/poetry#10226
python-poetry/poetry#10941

Now that the buildpack uses Poetry 2.5.1 (as of #2147), the disabled
test can be re-enabled, and the outdated comment in `lib/poetry.sh`
removed.

GUS-W-24154059.
@heroku-linguist heroku-linguist Bot mentioned this pull request Oct 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Dependabot pull requests that update Python dependencies

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant