Skip to content

build(deps-dev): bump the development-minor-patch group across 1 directory with 2 updates - #59

Merged
haasonsaas merged 2 commits into
mainfrom
dependabot/pip/development-minor-patch-1d90ea42fc
Sep 2, 2026
Merged

haasonsaas merged 2 commits into
mainfrom
dependabot/pip/development-minor-patch-1d90ea42fc

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 26, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the development-minor-patch group with 2 updates in the / directory: pre-commit and mkdocs-material.

Updates pre-commit from 4.6.0 to 4.6.2

Release notes

Sourced from pre-commit's releases.

pre-commit v4.6.2

Fixes

pre-commit v4.6.1

Fixes

Changelog

Sourced from pre-commit's changelog.

4.6.2 - 2026-08-10

Fixes

4.6.1 - 2026-07-21

Fixes

Commits
  • 9767b6c v4.6.2
  • 42ee3ff Merge pull request #3743 from pre-commit/npm-build-scripts-11-x
  • 3056619 fix language: node for hooks with build scripts and npm 11.x
  • 242ce8a v4.6.1
  • 766e550 Merge pull request #3727 from pre-commit/dedupe
  • 1558d06 Merge pull request #3726 from pre-commit/exists-faster
  • 8a1c47a avoid duplicate files in --all-files during conflict
  • 2e01c99 faster check of rev existing locally as a commit
  • 3613bf2 Merge pull request #3701 from pre-commit/autoupdate-repos
  • 1d811d9 Return an error for invalid --repo
  • Additional commits viewable in compare view

Updates mkdocs-material from 9.7.6 to 9.7.7

Release notes

Sourced from mkdocs-material's releases.

mkdocs-material-9.7.7

[!WARNING]

Material for MkDocs is approaching end of life

Material for MkDocs is scheduled to reach end of life on November 5, 2026. Until then, maintenance is limited to critical bug fixes and security updates. After this date, the project will remain available on PyPI and GitHub, but no further maintenance is planned except in exceptional circumstances.

For users looking for a long-term, actively developed successor, we're building Zensical – a next-generation static site generator designed for technical documentation. If you're planning a new documentation project or evaluating your long-term options, we invite you to take a look.

Organizations requiring support beyond this date are welcome to get in touch to discuss available options.

Read the full announcement on our blog

Changes

  • Fixed a DOM-based XSS vulnerability in search suggestions

Thanks to @​p- for responsibly reporting this issue.

Changelog

Sourced from mkdocs-material's changelog.

mkdocs-material-9.7.7 (2026-07-17)

  • Fixed DOM-based XSS vulnerability in search suggestions

mkdocs-material-9.7.6 (2026-03-19)

  • Automatically disable MkDocs 2.0 warning for forks of MkDocs

mkdocs-material-9.7.5 (2026-03-10)

  • Limited version range of mkdocs to <2
  • Updated MkDocs 2.0 incompatibility warning (clarify relation with MkDocs)

mkdocs-material-9.7.4 (2026-03-03)

  • Hardened social cards plugin by switching to sandboxed environment
  • Updated MkDocs 2.0 incompatibility warning

mkdocs-material-9.7.3 (2026-02-24)

  • Fixed #8567: Print MkDocs 2.0 incompatibility warning to stderr

mkdocs-material-9.7.2 (2026-02-18)

  • Opened up version ranges of optional dependencies for forward-compatibility
  • Added warning to 'mkdocs build' about impending MkDocs 2.0 incompatibility

mkdocs-material-9.7.1 (2025-12-18)

  • Updated requests to 2.30+ to mitigate CVE in urllib
  • Fixed privacy plugin not picking up protocol-relative URLs
  • Fixed #8542: false positives and negatives captured in privacy plugin

mkdocs-material-9.7.0 (2025-11-11)

⚠️ Material for MkDocs is now in maintenance mode

This is the last release of Material for MkDocs that will receive new features. Going forward, the Material for MkDocs team focuses on Zensical, a next-gen static site generator built from first principles. We will provide critical bug fixes and security updates for Material for MkDocs for 12 months at least.

Read the full announcement on our blog: https://squidfunk.github.io/mkdocs-material/blog/2025/11/05/zensical/

This release includes all features that were previously exclusive to the Insiders edition. These features are now freely available to everyone.

Note on deprecated plugins: The projects and typeset plugins are included in this release, but must be considered deprecated. Both plugins proved

... (truncated)

Commits

@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Jul 26, 2026
@socket-security

socket-security Bot commented Jul 26, 2026 •

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedmkdocs-material@​9.7.6 ⏵ 9.7.790100100100100
Updatedpre-commit@​4.6.0 ⏵ 4.6.293 +1100100100100

View full report

haasonsaas added a commit that referenced this pull request Sep 2, 2026
Two independent defects keep every Dependabot pull request in this
repository red. Both are fixed here.

1. The lock-sync gate can never pass for Dependabot.

.github/workflows/ci.yml requires requirements.lock to change whenever
requirements.txt changes, and requirements-dev.lock whenever
requirements-dev.txt changes. Dependabot's pip ecosystem edits only the
.txt manifests. It cannot regenerate these locks: dependabot-core treats
a file as a pip-compile output only when the name ends in .txt
(python/lib/dependabot/python/pip_compile_file_matcher.rb, which checks
`name.end_with?(".txt")` and looks for a sibling .in manifest). Files
named requirements.lock and requirements-dev.lock are never fetched as
lockfiles at all. #59 and #63 both fail on this.

.github/workflows/dependabot-lockfiles.yml now recompiles both locks on
Dependabot branches using the exact uv command recorded in their headers,
runs `uv pip install`, `black --check .`, `ruff check .` and `pytest -q`
against the recompiled result, and pushes the refreshed locks back to the
pull request branch. No --upgrade is passed, so uv reads the existing
output file as preferences and only the pins the manifest change forces
will move. The job is gated on
`github.event.pull_request.user.login == 'dependabot[bot]'` and on the
head branch living in this repository, and it is the only place that
holds `contents: write`.

The ci.yml lock-sync step now skips Dependabot pull requests, because the
new workflow satisfies that invariant for them by construction and runs a
strictly larger check. It is unchanged for every human pull request.

2. `ruff check .` silently redefines itself on a ruff upgrade.

There was no ruff configuration in the repository, so `ruff check .` ran
whatever ruff's built-in default selection happened to be. That default
changed in ruff 0.16. On the current tree:

  ruff 0.15.21: All checks passed!
  ruff 0.16.4:  Found 124 errors.
                (48 UP006, 36 BLE001, 17 I001, 10 UP045, 7 UP035, ...)

So #63, which bumps ruff 0.15.21 -> 0.16.4, would still fail after the
lockfile problem is fixed. ruff.toml now pins
`select = ["E4", "E7", "E9", "F"]`, which is the rule set this repository
has actually been enforcing. This makes the existing contract explicit
instead of letting a tool upgrade rewrite it. Adopting the additional
rules stays available as a deliberate, separate change.

Verified locally:
- `actionlint .github/workflows/dependabot-lockfiles.yml
  .github/workflows/ci.yml` is clean.
- Recompiling both locks on the current main is a no-op apart from the uv
  version string in the header comment; every pin is preserved.
- Simulating #63 on top of main (its requirements.txt and
  requirements-dev.txt applied, then both locks recompiled) moves exactly
  six pins in each lock -- gunicorn, mypy, python-dotenv, ruff, twilio,
  typer -- and nothing else. In a Python 3.11 venv from the recompiled
  requirements-dev.lock: `black --check .` passes (24 files),
  `pytest -q` passes (30 passed), and `ruff check .` passes with the new
  ruff.toml under both 0.15.21 and 0.16.4.


Claude-Session: https://claude.ai/code/session_01XpuXXVrWCZk3Tq5NRXejNP

Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
@haasonsaas

Copy link
Copy Markdown
Contributor

@dependabot rebase

Context: #64 just merged. .github/workflows/dependabot-lockfiles.yml now recompiles requirements.lock and requirements-dev.lock on Dependabot branches and pushes them back, and ruff.toml pins the lint rule selection so a ruff upgrade cannot silently change the gate. Both were blocking this PR.

…ctory with 2 updates

Bumps the development-minor-patch group with 2 updates in the / directory: [pre-commit](https://github.com/pre-commit/pre-commit) and [mkdocs-material](https://github.com/squidfunk/mkdocs-material).


Updates `pre-commit` from 4.6.0 to 4.6.2
- [Release notes](https://github.com/pre-commit/pre-commit/releases)
- [Changelog](https://github.com/pre-commit/pre-commit/blob/main/CHANGELOG.md)
- [Commits](pre-commit/pre-commit@v4.6.0...v4.6.2)

Updates `mkdocs-material` from 9.7.6 to 9.7.7
- [Release notes](https://github.com/squidfunk/mkdocs-material/releases)
- [Changelog](https://github.com/squidfunk/mkdocs-material/blob/master/CHANGELOG)
- [Commits](squidfunk/mkdocs-material@9.7.6...9.7.7)

---
updated-dependencies:
- dependency-name: mkdocs-material
  dependency-version: 9.7.7
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: development-minor-patch
- dependency-name: pre-commit
  dependency-version: 4.6.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: development-minor-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/pip/development-minor-patch-1d90ea42fc branch from 58fb885 to 5c70cc8 Compare September 2, 2026 01:44
@haasonsaas

Copy link
Copy Markdown
Contributor

Merging with smoke still queued. That job is .github/workflows/bazel-rbe.yml, which targets the self-hosted evalops-orbit-agent-rbe + bazel-rbe lane. That lane has not produced a completed run since 2026-08-11: every run since is queued or cancelled, including the run on main from 2026-09-02T00:59:58Z. It is not a required status check and it is not gating anything today.

What did run and pass on this PR's head commit:

  • Refresh compiled lock files — recompiled requirements.lock and requirements-dev.lock, installed from the recompiled dev lock, then black --check ., ruff check . and pytest -q, all green.
  • test (3.11) and test (3.12) — green.

The stuck Bazel lane is a runner-capacity item for the repository owner, tracked separately.

@haasonsaas
haasonsaas merged commit 85fab7d into main Sep 2, 2026
5 of 6 checks passed
@haasonsaas
haasonsaas deleted the dependabot/pip/development-minor-patch-1d90ea42fc branch September 2, 2026 02:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant