Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
GitPythonis not imported anywhere in this repo (grep -rn "import git"finds nothing) — it is a transitive dependency ofpython-semantic-release. Hard-pinning a transitive dep to an exact patch version has two downsides worth weighing:python-semantic-release 10.6.xtightens itsGitPythonrange past3.1.59,pip install -r requirements-release.txtin thereleaseenv (hatch.toml:40) fails outright rather than resolving. The release-bump job then breaks for a reason unrelated to this repo.==pin means a fixed patch release will not be picked up until someone edits this line by hand.Every other requirement in this repo uses a minor-series wildcard (
python-semantic-release == 10.6.*, and all ofrequirements-testing.txt). Suggest matching that convention:If an exact pin is deliberate — i.e. a specific GitPython release broke the bump — please add a short comment naming the breakage (as
requirements-testing.txt:8-9does forblack), so a future reader knows when the pin can be relaxed. The commit message ("chore: pin GitPython for release bump") does not record the reason.