Update setuptools-scm requirement from >=3.5.0 to >=10.1.2 - #90
dependabot[bot] wants to merge 1 commit into
Conversation
Updates the requirements on [setuptools-scm](https://github.com/pypa/setuptools-scm) to permit the latest version. - [Release notes](https://github.com/pypa/setuptools-scm/releases) - [Changelog](https://github.com/pypa/setuptools-scm/blob/main/RELEASE_SYSTEM.md) - [Commits](pypa/setuptools-scm@setuptools-scm-v10.0.0...setuptools-scm-v10.1.2) --- updated-dependencies: - dependency-name: setuptools-scm dependency-version: 10.1.2 dependency-type: direct:development ... Signed-off-by: dependabot[bot] <support@github.com>
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes and found 1 potential issue.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit 2031819. Configure here.
| @@ -1,5 +1,5 @@ | |||
| [build-system] | |||
| requires = ["setuptools>=42", "wheel", "setuptools_scm[toml]>=3.5.0", "pybind11>=2.10.0"] | |||
| requires = ["setuptools>=42", "wheel", "setuptools_scm[toml]>=10.1.2", "pybind11>=2.10.0"] | |||
There was a problem hiding this comment.
Build requires Python 3.10+
Medium Severity
Raising setuptools_scm[toml] to >=10.1.2 forces a build dependency that only supports Python 3.10+, while setup.py still declares python_requires=">=3.7". Source builds or editable installs on Python 3.7–3.9 can fail when pip resolves build requirements, even though older setuptools-scm versions satisfied the previous >=3.5.0 floor.
Reviewed by Cursor Bugbot for commit 2031819. Configure here.
|
Superseded by #92. |


Updates the requirements on setuptools-scm to permit the latest version.
Release notes
Sourced from setuptools-scm's releases.
Commits
fa1c6e2Merge pull request #1427 from pypa/release/main0e8b865Prepare release: setuptools-scm v10.1.2, vcs-versioning v2.1.0b447622Merge pull request #1432 from RonnyPfannschmidt/fix/1431-fallback-discovery-p...d79683cfix: don't let unprocessed .git_archival.txt shadow PKG-INFO (#1431)651e9bfMerge pull request #1430 from RonnyPfannschmidt/fix/1422-suppress-tag-strict-...2dba8affix: use surrogateescape for subprocess encoding on Windows2480097Merge pull request #1428 from RonnyPfannschmidt/fix/compat-shim-parse-version42c97f9fix: suppress conflicting tag.strict warnings (#1422)2c17c0efix: add backward-compat shim for parse_version (#1423)a841b68Merge pull request #1426 from RonnyPfannschmidt/warning-fixesDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)Note
Low Risk
Single build-backend version constraint change with no runtime or security-sensitive code paths touched.
Overview
Raises the build-system pin for
setuptools_scm[toml]from>=3.5.0to>=10.1.2inpyproject.toml, so installs during package builds can use current setuptools-scm releases.No application or runtime dependency changes; only the tooling that derives versions from VCS at build time is affected.
Reviewed by Cursor Bugbot for commit 2031819. Bugbot is set up for automated code reviews on this repo. Configure here.