deps(deps): bump the python-minor-and-patch group across 1 directory with 12 updates - #807
Closed
dependabot[bot] wants to merge 1 commit into
Closed
deps(deps): bump the python-minor-and-patch group across 1 directory with 12 updates#807dependabot[bot] wants to merge 1 commit into
dependabot[bot] wants to merge 1 commit into
Conversation
…with 12 updates Bumps the python-minor-and-patch group with 12 updates in the / directory: | Package | From | To | | --- | --- | --- | | [simplejson](https://github.com/simplejson/simplejson) | `4.1.1` | `4.1.2` | | [django-flexible-reports](https://github.com/mpasternak/django-flexible-reports) | `0.4.2` | `0.5.0` | | [django-tables2](https://github.com/jieter/django-tables2) | `3.0.0` | `3.0.1` | | [nh3](https://github.com/messense/nh3) | `0.3.6` | `0.3.7` | | [cryptography](https://github.com/pyca/cryptography) | `50.0.0` | `50.0.1` | | [crispy-bootstrap5](https://github.com/django-crispy-forms/crispy-bootstrap5) | `2026.3` | `2026.9` | | [xhtml2pdf](https://github.com/xhtml2pdf/xhtml2pdf) | `0.2.17` | `0.2.18` | | [gunicorn](https://github.com/benoitc/gunicorn) | `26.0.0` | `26.2.0` | | [django-oauth-toolkit](https://github.com/django-oauth/django-oauth-toolkit) | `3.4.0` | `3.4.1` | | [pytest-rerunfailures](https://github.com/pytest-dev/pytest-rerunfailures) | `16.5` | `16.6.1` | | [ruff](https://github.com/astral-sh/ruff) | `0.16.3` | `0.16.6` | | [djlint](https://github.com/djlint/djLint) | `1.44.2` | `1.45.0` | Updates `simplejson` from 4.1.1 to 4.1.2 - [Release notes](https://github.com/simplejson/simplejson/releases) - [Changelog](https://github.com/simplejson/simplejson/blob/main/CHANGES.txt) - [Commits](simplejson/simplejson@v4.1.1...v4.1.2) Updates `django-flexible-reports` from 0.4.2 to 0.5.0 - [Release notes](https://github.com/mpasternak/django-flexible-reports/releases) - [Changelog](https://github.com/mpasternak/django-flexible-reports/blob/master/HISTORY.md) - [Commits](mpasternak/django-flexible-reports@v0.4.2...v0.5.0) Updates `django-tables2` from 3.0.0 to 3.0.1 - [Changelog](https://github.com/jieter/django-tables2/blob/master/CHANGELOG.md) - [Commits](jieter/django-tables2@v3.0.0...v3.0.1) Updates `nh3` from 0.3.6 to 0.3.7 - [Release notes](https://github.com/messense/nh3/releases) - [Commits](messense/nh3@v0.3.6...v0.3.7) Updates `cryptography` from 50.0.0 to 50.0.1 - [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst) - [Commits](pyca/cryptography@50.0.0...50.0.1) Updates `crispy-bootstrap5` from 2026.3 to 2026.9 - [Release notes](https://github.com/django-crispy-forms/crispy-bootstrap5/releases) - [Changelog](https://github.com/django-crispy-forms/crispy-bootstrap5/blob/main/CHANGELOG.md) - [Commits](django-crispy-forms/crispy-bootstrap5@2026.3...2026.9) Updates `xhtml2pdf` from 0.2.17 to 0.2.18 - [Release notes](https://github.com/xhtml2pdf/xhtml2pdf/releases) - [Commits](xhtml2pdf/xhtml2pdf@v0.2.17...v0.2.18) Updates `gunicorn` from 26.0.0 to 26.2.0 - [Release notes](https://github.com/benoitc/gunicorn/releases) - [Commits](benoitc/gunicorn@26.0.0...26.2.0) Updates `django-oauth-toolkit` from 3.4.0 to 3.4.1 - [Release notes](https://github.com/django-oauth/django-oauth-toolkit/releases) - [Changelog](https://github.com/django-oauth/django-oauth-toolkit/blob/master/CHANGELOG.md) - [Commits](django-oauth/django-oauth-toolkit@3.4.0...3.4.1) Updates `pytest-rerunfailures` from 16.5 to 16.6.1 - [Changelog](https://github.com/pytest-dev/pytest-rerunfailures/blob/master/CHANGES.rst) - [Commits](pytest-dev/pytest-rerunfailures@16.5...16.6.1) Updates `ruff` from 0.16.3 to 0.16.6 - [Release notes](https://github.com/astral-sh/ruff/releases) - [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md) - [Commits](astral-sh/ruff@0.16.3...0.16.6) Updates `djlint` from 1.44.2 to 1.45.0 - [Release notes](https://github.com/djlint/djLint/releases) - [Changelog](https://github.com/djlint/djLint/blob/master/CHANGELOG.md) - [Commits](djlint/djLint@v1.44.2...v1.45.0) --- updated-dependencies: - dependency-name: simplejson dependency-version: 4.1.2 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: python-minor-and-patch - dependency-name: django-flexible-reports dependency-version: 0.5.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: python-minor-and-patch - dependency-name: django-tables2 dependency-version: 3.0.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: python-minor-and-patch - dependency-name: nh3 dependency-version: 0.3.7 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: python-minor-and-patch - dependency-name: cryptography dependency-version: 50.0.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: python-minor-and-patch - dependency-name: crispy-bootstrap5 dependency-version: '2026.9' dependency-type: direct:production update-type: version-update:semver-minor dependency-group: python-minor-and-patch - dependency-name: xhtml2pdf dependency-version: 0.2.18 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: python-minor-and-patch - dependency-name: gunicorn dependency-version: 26.2.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: python-minor-and-patch - dependency-name: django-oauth-toolkit dependency-version: 3.4.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: python-minor-and-patch - dependency-name: pytest-rerunfailures dependency-version: 16.6.1 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: python-minor-and-patch - dependency-name: ruff dependency-version: 0.16.6 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: python-minor-and-patch - dependency-name: djlint dependency-version: 1.45.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: python-minor-and-patch ... Signed-off-by: dependabot[bot] <support@github.com>
mpasternak
added a commit
that referenced
this pull request
Sep 10, 2026
… — zamyka 4 CVE i odblokowuje pip-audit (#809) * ci(deps): zbiorczy bump akcji GitHub (PR-y #806, #805, #788) Trzy PR-y dependabota z ekosystemu github-actions, scalone recznie zamiast mergowania po kolei. Wszystkie to podmiana SHA przy zachowanym pinowaniu do commita + komentarz z tagiem (polityka repo: akcje pinowane po SHA, nie po ruchomym tagu). * anthropics/claude-code-action 1.0.193 -> 1.0.216 (#806) .github/workflows/claude.yml * actions/deploy-pages 5.0.0 -> 5.0.1 (#805) .github/workflows/docs.yml * docker/setup-buildx-action 4.2.0 -> 4.3.0 (#788) build-docker-images.yml (2x), promote.yml, release-candidate.yml, tests.yml Weryfikacja: po podmianie w drzewie nie zostal ani jeden ze starych SHA (grep po .github/ pusty). Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_011aZqYiv56cwAudG2CPS3k5 * build(deps): postcss-selector-parser 7.1.1 -> 7.1.5 (PR #798) Zaleznosc przechodnia (przez postcss-modules-*), wiec `yarn upgrade postcss-selector-parser` jej nie rusza — podniesiony wpis w yarn.lock wprost, wersja/resolved/integrity wziete z PR-a dependabota. Weryfikacja: `yarn install --frozen-lockfile` przechodzi (lock rozwiazuje sie bez zmian, integrity zgadza sie z tarballem z rejestru), a node_modules/postcss-selector-parser/package.json raportuje 7.1.5. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_011aZqYiv56cwAudG2CPS3k5 * deps: grupa python-minor-and-patch + pypdf/webob/uvicorn + sync pinu ruffa Cztery PR-y dependabota z ekosystemu uv, scalone recznie w jedna zmiane. Powod: kazdy z nich rusza uv.lock, wiec mergowanie po kolei wymusza rebase i osobny przebieg CI dla kazdego kolejnego. Grupa python-minor-and-patch (#807), 12 pakietow: simplejson 4.1.1 -> 4.1.2 django-flexible-reports 0.4.2 -> 0.5.0 django-tables2 3.0.0 -> 3.0.1 nh3 0.3.6 -> 0.3.7 cryptography 50.0.0 -> 50.0.1 (tylko lock) crispy-bootstrap5 2026.3 -> 2026.9 xhtml2pdf 0.2.17 -> 0.2.18 gunicorn 26.0.0 -> 26.2.0 django-oauth-toolkit 3.4.0 -> 3.4.1 pytest-rerunfailures 16.5 -> 16.6.1 ruff 0.16.3 -> 0.16.6 djlint 1.44.2 -> 1.45.0 (tylko lock) Pozostale trzy PR-y: uvicorn[standard] 0.52.3 -> 0.52.4 (#790) pypdf 6.15.0 -> 6.16.1 (#799) webob 1.8.10 -> 1.8.11 (#794) BEZPIECZENSTWO — pypdf i webob zamykaja 4 fixable CVE, ktore od kilku dni wywalaja gate `pip-audit` (job "pip-audit scan"), blokujac takze niezwiazane PR-y (m.in. #804): pypdf 6.15.0 CVE-2026-84309 / -84310 / -84311 fix: 6.16.1 webob 1.8.10 CVE-2026-54770 fix: 1.8.11 Weryfikacja lokalna, dokladnie ta komenda co w CI (uv export --no-dev | pip-audit --disable-pip --no-deps): przed zmiana "Found 4 known vulnerabilities in 2 packages", po zmianie "No known vulnerabilities found". RUFF — bump 0.16.3 -> 0.16.6 wymaga rownoleglej zmiany rev w .pre-commit-config.yaml. To sa dwa fizycznie rozne binaria (pre-commit buduje wlasne srodowisko z wheela spod `rev:`), a dependabot tego sprzezenia nie widzi, bo sledzi tylko ekosystem uv. Pilnuje tego bramka bin/check-ruff-pin-sync.py — sam PR #807 by ja wywalil. Po synchronizacji skrypt zwraca 0. Ruff 0.16.6 nie wnosi nowych naruszen: na tym drzewie 0.16.3 i 0.16.6 daja identyczny wynik — 122 errors z tym samym rozkladem regul oraz 124 pliki do reformatu. Caly ten dlug jest pre-existing na dev i zgodnie z konwencja repo (lint changed-files-only) zostaje nietkniety. COOLDOWN — `uv lock --upgrade-package` celuje w najnowsze wydanie, co po cichu omija 3-dniowy cooldown z .github/dependabot.yml (ochrona przed atakami typu LiteLLM). Dwa pakiety przestrzelilo i zostaly przypiete do wersji, ktore odlezaly swoje: djlint 1.46.1 wydany dzis (2026-09-08) -> przypiety 1.45.0 (2026-09-03) pypdf 6.18.0 wydany wczoraj -> przypiety 6.16.1 (2026-08-14) WERSJA uv UZYTA DO PRZELICZENIA LOCKA — celowo `uv@0.11.29`, czyli pin z CI (setup-uv w jobach `lockfile` / `lint` / `pip-audit`), a NIE lokalne uv 0.11.14 ani 0.11.15 z hooka uv-pre-commit. Powod: przy przeliczaniu locka starsze uv rozpisuje marker `platform_python_implementation != 'PyPy'` na cala rozwiazana grafe zaleznosci — 13 wystapien rosnie do ~700, a diff uv.lock puchnie z ~500 do ~1900 linii czystego szumu. Wersje pakietow wychodza identyczne (sprawdzone: 367 pakietow, zero roznic w parach nazwa/wersja), wiec to wylacznie metadane, ale zasmiecaja review pliku, ktory trzeba czytac uwaznie. Zweryfikowane empirycznie: to samo `--upgrade-package simplejson` na czystym dev daje 700 markerow pod 0.11.14 i 0.11.15, a 13 pod 0.11.29. UWAGA: komentarz przy hooku uv-pre-commit w .pre-commit-config.yaml ("Trzymaj z grubsza w parze z wersja uv w uzyciu (obecnie 0.11.14)") jest wiec juz nieaktualny i doradza dokladnie to, co produkuje churn. Lock na dev pochodzi z nowszego uv. Aktualizacja tego komentarza i pinu hooka to osobna zmiana, poza zakresem tego PR-a. Reszta lockfile bez zmian — uzyty celowany `--upgrade-package` dla 15 pakietow, nie zbiorczy `uv lock --upgrade`. Diff uv.lock to 15 zmian wersji + ich sdist/wheels, 11 linii `requires-dist` (lustro zmian w pyproject.toml) i jedna usunieta zaleznosc `packaging`, ktora gunicorn 26.2.0 porzucil u siebie. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_011aZqYiv56cwAudG2CPS3k5 * docs(deps): udokumentuj `[tool.uv] environments` + zrownaj dolna granice z requires-python Linia `environments` w [tool.uv] jest load-bearing, a stala bez slowa wyjasnienia. Wjechala commitem 0f3f049 o wiadomosci "Prepare fix, maybe" (2025-10-14) — razem z `urllib3>=2.2.3` i `vcrpy>=6.0.2`, i to byl wlasnie ten fix, tylko nigdzie nieopisany. Odtworzenie powodu zajelo osobne sledztwo, wiec zapisuje je przy samej linii. POWOD HISTORYCZNY. uv robi universal resolution: jeden lock ma byc poprawny dla kazdej platformy i kazdego interpretera, takze takiego, ktorego nigdy nie uruchomimy. vcrpy 6.0.2 deklarowalo: urllib3; platform_python_implementation != "PyPy" and python_version >= "3.10" urllib3<2; platform_python_implementation == "PyPy" czyli galaz PyPy zadala urllib3<2, nie do pogodzenia z urllib3>=2.2.3. Wykluczenie PyPy kasuje te galaz i odblokowuje rezolucje. STAN OBECNY — zweryfikowany, nie zgadniety. Przeskanowany caly graf z uv.lock (364 pakiety z rejestru, 3 pominiete jako editable/git, zero bledow pobrania metadanych). Warunki `== "PyPy"` wystepuja w czterech miejscach: celery 5.6.3 brotlipy>=0.7.0 extra == "brotli" fonttools 4.62.1 munkres extra == "all" fonttools 4.62.1 munkres extra == "interpolatable" jaraco-functools 4.4.0 mypy<1.19 extra == "type" Wszystkie cztery siedza za extrasami, ktorych nie wlaczamy — brotlipy, munkres ani mypy nie wystepuja w uv.lock, a z fonttools bierzemy wylacznie extra `woff`. vcrpy 8.3.0 nie ma juz swojego warunku. Zdjecie wykluczenia daje dzis DOKLADNIE te same wersje: 367 pakietow, zero roznic w parach nazwa/wersja. Zostaje mimo to — kosztuje 13 linii resolution-markers w naglowku locka i chroni przed powtorka klasy problemu, ktora juz raz zablokowala rezolucje. Bez niego cryptography, pynacl i uvicorn[standard] odzyskuja markery PyPy na krawedziach do cffi/uvloop, wiec lock i tak nie robi sie prostszy. DOLNA GRANICA. `python_version >= '3.10'` -> `>= '3.11'`. Byla martwa (przeciecie z requires-python = ">=3.11,<3.15" i tak dawalo 3.11), ale mylnie sugerowala wsparcie dla 3.10. uv.lock po tej zmianie jest BIT W BIT identyczny (`uv lock` nie ruszyl pliku, `uv lock --check` przechodzi) — to zmiana czysto opisowa. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_011aZqYiv56cwAudG2CPS3k5 --------- Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Contributor
Author
|
Looks like these dependencies are updatable in another way, so this is no longer needed. |
dependabot
Bot
deleted the
dependabot/uv/python-minor-and-patch-c35ffc63b3
branch
September 10, 2026 11:33
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the python-minor-and-patch group with 12 updates in the / directory:
4.1.14.1.20.4.20.5.03.0.03.0.10.3.60.3.750.0.050.0.12026.32026.90.2.170.2.1826.0.026.2.03.4.03.4.116.516.6.10.16.30.16.61.44.21.45.0Updates
simplejsonfrom 4.1.1 to 4.1.2Release notes
Sourced from simplejson's releases.
Changelog
Sourced from simplejson's changelog.
... (truncated)
Commits
d1fe71aAdd missing changelog entries (#384)aa1f2c4Update CHANGES for v4.1.2 (#383)b84ad54Report the comma position for illegal trailing comma errors (#382)b0fe1efHandle non-finite Decimals like floats in the encoder (fixes #149) (#381)fa8feeaReport the offending char, not the backslash, for invalid \X escapes (#380)bded822Fix control character error position when content precedes the control char (...Updates
django-flexible-reportsfrom 0.4.2 to 0.5.0Release notes
Sourced from django-flexible-reports's releases.
Changelog
Sourced from django-flexible-reports's changelog.
Commits
a9ee294release: 0.5.0e3b2183Merge pull request #14 from mpasternak/feat/set-order-bydbf4c2btest: pin header-click ordering against the set_order_by override31ec542feat: Report.set_order_by() overrides a report's stored orderingUpdates
django-tables2from 3.0.0 to 3.0.1Changelog
Sourced from django-tables2's changelog.
Commits
6b830faBump version to 3.0.1c28fd51Add support for django 6.1, drop python 3.10 support (#1047)47c5cd2Bump actions/setup-python from 6 to 7 (#1046)2d53383Bump actions/cache from 5.0.5 to 6.1.0 (#1042)b2dc2cbBump actions/checkout from 6 to 7 (#1039)e52d5bcBump actions/cache from 5.0.4 to 5.0.5 (#1034)Updates
nh3from 0.3.6 to 0.3.7Release notes
Sourced from nh3's releases.
Commits
74f36b8Bump pyo3 from 0.29.0 to 0.29.2 (#140)5cb1a16Update ammonia and bump version to 0.3.75bc937aBump ammonia from 4.1.3 to 4.1.4 (#139)5816c84Bump actions/setup-python from 6 to 7 in the github-actions group (#138)7718812Bump ammonia from 4.1.2 to 4.1.3 (#137)567c411Validate tag_attribute_values conflict with attributes (#135)c23021cDon’t depend on deprecated pyo3/generate-import-lib feature (#136)0343d0bBump actions/checkout from 6 to 7 in the github-actions group (#132)0573fe4Expose ammonia's id_prefix option via id_prefix kwarg (#134)Updates
cryptographyfrom 50.0.0 to 50.0.1Changelog
Sourced from cryptography's changelog.
Commits
ffde75abump for 50.0.1 + changelog (#15520)Updates
crispy-bootstrap5from 2026.3 to 2026.9Release notes
Sourced from crispy-bootstrap5's releases.
Changelog
Sourced from crispy-bootstrap5's changelog.
Commits
2eb9d8fRelease 2026.9. (#225)1d1ae49Bumped pre-commit versions.6a8ab7aLint test files.fdf04a4Update workflow action versions.0a2a74cConfirmed support for Django 6.1 (#223)Updates
xhtml2pdffrom 0.2.17 to 0.2.18Release notes
Sourced from xhtml2pdf's releases.
... (truncated)
Commits
19071d0Keep the logo the header used to lose without a wordb8f7c99Answer ruff and mypy, and uncover what an untyped node was hiding4159417Merge branch 'fix/remaining-findings' into development4d338e3Write down the behaviours that cost an afternoon each7feb418Remove the tags that were never implemented, and read two attributes1cade61Make the arguments of pisaDocument mean what they say7d36d26Let a document be encrypted, and say why it cannot also be signedf79ab77Make the form controls carry what the markup gives them8f5be05Fit a chart to the canvas it was given, and the canvas to the frame1759953Fade a background image instead of flattening its transparencyUpdates
gunicornfrom 26.0.0 to 26.2.0Release notes
Sourced from gunicorn's releases.
... (truncated)
Commits
36f2a3cgunicorn 26.2.0cbba350test: cover the h2c edge paths that had none9885411Merge pull request #3703 from cormier/fix-inconsistency-in-control-socket-docs86f0919Merge pull request #3704 from methane/doc-wsgi-h1c5853551Merge pull request #3712 from Rotzbua/patch-17bce87eMerge pull request #3700 from benoitc/fix/sponsor-logo-path972dfb0Merge pull request #3690 from melbinjp/docs/contributing-settings-path7b3f16bMerge pull request #3711 from benoitc/docs/http2-changelog5bf237chttp2: require gunicorn_h1c 0.6.9 and drop the upgrade body workaround7cf0338test: skip the fast-parser cases when gunicorn_h1c is absentUpdates
django-oauth-toolkitfrom 3.4.0 to 3.4.1Release notes
Sourced from django-oauth-toolkit's releases.
... (truncated)
Changelog
Sourced from django-oauth-toolkit's changelog.
... (truncated)
Commits
db6c4f5chore: 3.4.1 release (#1820)9c70975fix: enforce device grant confirmation ownership (#1819)28bf64cperf: revoke refresh token families as a set on reuse detection (#1810)f797b8afix(validators): stop honoring revoked refresh tokens in the grace window (#1...11024a0chore(deps): bump cryptography in the uv group across 1 directory (#1807)1e19d4dLog why a redirect URI failed to match (#1814)4f18e0efeat(templates): serve default styles from a bundled stylesheet (#1815)ae05be9feat(models): make model field labels translatable (#1812)2b1a322fix(models): associate Application validation errors with their fields (#1811)0915396fix(dcr): honour hashed token storage for registration access tokens (#1799)Updates
pytest-rerunfailuresfrom 16.5 to 16.6.1Changelog
Sourced from pytest-rerunfailures's changelog.
... (truncated)
Commits
dad07a7Preparing release 16.6.1968fb6cPrevent negative reruns from skipping initial execution (#360)367df90Keep higher-scoped fixtures alive across re-runs of failed subtests (#357)69ac0a7Authenticate xdist StatusDB connections (#358)20decd3Restore higher-scoped teardown when a teardown error rules out a re-run (#356)84af73dFix subtest rerun reporting with xdist (#352)d784cddTest with pytest-xdist on CI (#354)9f85e06Restore higher-scoped teardown when a flaky condition is falsy (#351)eab650fTest rerun-except for setup errors (#349)0b0843aFix only_rerun marker precedence test (#348)Updates
rufffrom 0.16.3 to 0.16.6Release notes
Sourced from ruff's releases.
... (truncated)
Changelog
Sourced from ruff's changelog.
... (truncated)
Commits
22f65a2Bump 0.16.6 (#28280)7cc9f1e[ty] DocumentCallableTypeKindvariants (#28277)056ce07Add UV_LOCKED to all workflows (#28261)6d6e35d[flake8-pytest-style] Avoid duplicatePT017diagnostics (#27918)80b4891[ty] Temporarily disable tuple types in property tests (#28275)3f7a54d[flake8-tidy-imports] Prevent fix loop betweenTID254andTID255(#28262)35656cf[ty] Preserve deprecations on decorated callables (#28256)d2626c8[ty] Reject missing attributes ontype[]aliases (#28267)ee6a6d1[ty] Support ParamSpecs inConstraintSet(#28028)7f6a170[ty] Move bound APIs to constraint owners (#28094)Updates
djlintfrom 1.44.2 to 1.45.0Release notes
Sourced from djlint's releases.