Skip to content

chore(deps): bump the production-dependencies group with 4 updates - #109

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/production-dependencies-9797f4b017
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/production-dependencies-9797f4b017

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 28, 2026

Copy link
Copy Markdown
Contributor

Bumps the production-dependencies group with 4 updates: platformdirs, python-gitlab, python-slugify and virtualenv.

Updates platformdirs from 4.11.10 to 4.11.13

Release notes

Sourced from platformdirs's releases.

4.11.13

What's Changed

Full Changelog: tox-dev/platformdirs@4.11.12...4.11.13

4.11.12

What's Changed

New Contributors

Full Changelog: tox-dev/platformdirs@4.11.11...4.11.12

4.11.11

What's Changed

New Contributors

Full Changelog: tox-dev/platformdirs@4.11.10...4.11.11

Changelog

Sourced from platformdirs's changelog.

########### Changelog ###########

.. towncrier-draft-entries:: Unreleased

.. towncrier release notes start


4.12.1 (2026-09-28)


  • Avoid PytestAssertRewriteWarning when importing platformdirs before invoking pytest. :pr:601

4.12.0 (2026-09-26)


  • Add place_*_file methods that return a file path under a user directory and create its missing parents with mode 0o700. :pr:585
  • Add find_<kind>_file and find_<kind>_files to look up an existing file across the user and site directories of each kind that has an iter_<kind>_paths method. :pr:586
  • Add :func:platformdirs.testing.isolated_dirs and the platformdirs_isolated pytest fixture to resolve every directory under one test root. :pr:590
  • Emit :class:~platformdirs.RuntimeDirWarning when the Unix :func:~platformdirs.user_runtime_dir falls back from XDG_RUNTIME_DIR. :pr:599
  • Read user_templates_dir, user_publicshare_dir and user_bin_dir on Windows from their known folders. :pr:587
  • Create missing user app directories and their parents with mode 0700 under ensure_exists on POSIX platforms. :pr:588
  • Raise RuntimeError for a Unix or macOS directory under the home when no home resolves, and read the password database for an empty HOME. :pr:589
  • Skip an XDG_RUNTIME_DIR or /run/user/<uid> that is not a private directory of the user, and reject a symlink or file as the runtime-<uid> fallback. :pr:599
  • Use the app container layout on iOS, such as ~/Library/Application Support for data. :pr:600
  • Document that a Homebrew Python puts the Homebrew prefix first in the macOS shared directories, with or without multipath. :pr:591
  • Document that the macOS media directories honor the XDG_*_DIR variables. :pr:592
  • Document the WIN_PD_OVERRIDE_COMMON_PROGRAMS variable. :pr:593
  • Document /usr/local/share/applications as the Linux site_applications_dir default. :pr:594
  • Correct the BSD user_runtime_dir defaults and describe the temporary directory fallback. :pr:595
  • Describe how platformdirs detects Android, finds the app folder and places the shared folders. :pr:596
  • Document that Microsoft Store Python redirects only new files and folders under AppData. :pr:597
  • Show how to load a font on Windows after copying it into user_fonts_dir. :pr:598

4.11.15 (2026-09-26)


  • Fix the pyjnius lookup of the Android app folder and media directories, which always failed. :pr:580

... (truncated)

Commits
  • 9ce6068 Release 4.11.13
  • 4440e9f 🐛 fix(dirs): create media dirs when ensure_exists is set (#560)
  • 6d28702 build(deps): bump astral-sh/setup-uv from 10.0.1 to 10.1.0 in the all group (...
  • 0975949 Release 4.11.12
  • f0f5667 fix: ignore relative XDG user directory environment variables (#554)
  • 1f944d0 fix: ignore broken sphinx-llm release (#556)
  • 3e2e590 [pre-commit.ci] pre-commit autoupdate (#555)
  • 897097b docs: preserve nested directories in the migration recipe (#553)
  • 321e35a Release 4.11.11
  • 902c268 fix: reject app arguments that leave the base directory (#552)
  • See full diff in compare view

Updates python-gitlab from 6.5.0 to 8.5.0

Release notes

Sourced from python-gitlab's releases.

v8.5.0 (2026-07-28)

This release is published under the LGPL-3.0-or-later License.

Bug Fixes

  • Typo (72134f5)

  • api: Allow ProjectMergeRequestDiscussionNote.resolved to be updated (b411e5a)

  • client: Retry fetching server version after an unknown result (046fbac)

Continuous Integration

  • Run the pre-commit rst checks in the CI (a9c5d17)

Documentation

  • Correct error with backticks (e57559e)

  • discussions: Add example of resolving a single project merge request discussion note (2ef6452)

Features

  • api: Add ListMixin to remaining *DiscussionNoteManagers (0e2347c)

  • client: Additionally handle retries for request timeouts (4e32439)

  • hooks: Support custom webhook template on project hooks (39dc990)

  • users: Allow updating only a user's email, username or name (0d2afb8)

Testing

  • api: Ensure ProjectMergeRequestDiscussionNote.resolved can be updated successfully (57fd60c)

Detailed Changes: v8.4.0...v8.5.0

v8.4.0 (2026-05-28)

This release is published under the LGPL-3.0-or-later License.

Features

  • const: Add new Security Manager role (3738bb2)

Testing

... (truncated)

Changelog

Sourced from python-gitlab's changelog.

v8.5.0 (2026-07-28)

Bug Fixes

  • Typo (72134f5)

  • api: Allow ProjectMergeRequestDiscussionNote.resolved to be updated (b411e5a)

  • client: Retry fetching server version after an unknown result (046fbac)

Continuous Integration

  • Run the pre-commit rst checks in the CI (a9c5d17)

Documentation

  • Correct error with backticks (e57559e)

  • discussions: Add example of resolving a single project merge request discussion note (2ef6452)

Features

  • api: Add ListMixin to remaining *DiscussionNoteManagers (0e2347c)

  • client: Additionally handle retries for request timeouts (4e32439)

  • hooks: Support custom webhook template on project hooks (39dc990)

  • users: Allow updating only a user's email, username or name (0d2afb8)

Testing

  • api: Ensure ProjectMergeRequestDiscussionNote.resolved can be updated successfully (57fd60c)

v8.4.0 (2026-05-28)

Features

... (truncated)

Commits
  • f899b5e chore: release v8.5.0
  • 0e2347c feat(api): add ListMixin to remaining *DiscussionNoteManagers
  • ede7fd7 chore(deps): update actions/setup-python action to v7
  • 2ef6452 docs(discussions): Add example of resolving a single project merge request di...
  • b411e5a fix(api): Allow ProjectMergeRequestDiscussionNote.resolved to be updated
  • 57fd60c test(api): Ensure ProjectMergeRequestDiscussionNote.resolved can be updated s...
  • 39dc990 feat(hooks): support custom webhook template on project hooks
  • 00e3802 chore(deps): update all non-major dependencies
  • 0d2afb8 feat(users): allow updating only a user's email, username or name
  • 8734e41 chore(deps): update all non-major dependencies
  • Additional commits viewable in compare view

Updates python-slugify from 9.0.0 to 9.1.1

Release notes

Sourced from python-slugify's releases.

9.1.1

Bug fix in the modern algorithm. Legacy output is unchanged and remains the permanent default.

  • Modern mode only: avoid emitting a trailing separator when a hard cut truncates through repeated post-replacement delimiters, keeping the delimiter run with the next word that fits. Legacy output and public smart_truncate are unchanged (曾楚笑, #200).

Full Changelog: un33k/python-slugify@v9.1.0...v9.1.1

🚀 Generated with Dojo ⛩️

9.1.0

Modern-algorithm improvements and fixes. Legacy output is unchanged and remains the permanent default.

  • Modern mode only: decode uppercase &#X..; hexadecimal references as HTML allows, in addition to lowercase &#x..; (Rupayon Haldar, #195).
  • Modern mode only: preserve post-replacement output when the whole slug already fits max_length, so intentional repeated/trailing delimiters are not collapsed at the length limit. Public smart_truncate is unchanged (emme1t, #193).
  • Fix add_uppercase_char to apply insertions atomically, leaving the input list unchanged if iteration fails. Built-in transliteration tables are unaffected (Cristian Ramirez, #194).
  • Modern mode only: validate argument types up front, raising TypeError for a bool/non-int max_length or a non-str separator. Legacy behavior is unchanged (Jon Bailey, #196).

Internal: the legacy pipeline is now frozen in slugify/_legacy.py with the public slugify() dispatching by algorithm; tests reorganized under tests/.

Full Changelog: un33k/python-slugify@v9.0.0...v9.1.0

🚀 Generated with Dojo ⛩️

Changelog

Sourced from python-slugify's changelog.

9.1.1

  • Modern mode only: avoid emitting a trailing separator when a hard cut truncates through repeated post-replacement delimiters, keeping the delimiter run with the next word that fits. Legacy output and public smart_truncate are unchanged (曾楚笑, #200).

9.1.0

  • Modern mode only: decode uppercase &#X..; hexadecimal references as HTML allows, in addition to lowercase &#x..;. Legacy output is unchanged (Rupayon Haldar, #195).
  • Modern mode only: preserve post-replacement output when the whole slug already fits max_length, so intentional repeated/trailing delimiters are not collapsed at the length limit. Public smart_truncate is unchanged (emme1t, #193).
  • Fix add_uppercase_char to apply insertions atomically, leaving the input list unchanged if iteration fails. Built-in transliteration tables are unaffected (Cristian Ramirez, #194).
  • Modern mode only: validate argument types up front, raising TypeError for a bool/non-int max_length (bool is an int subclass) or a non-str separator. Legacy behavior is unchanged and still treats max_length=True as its historical single-character truncation (Jon Bailey, #196).
Commits
  • 6aa0b0f Release 9.1.1: fix modern hard-cut trailing delimiter
  • 8f9a550 Avoid trailing post-replacement delimiters in modern hard cuts (#200)
  • c442cd4 Lead Quickstart examples with algorithm='modern'
  • 6e6fc4b Reframe README intro around 9+ modern algorithm, drop PyPI prose
  • b9171f7 Use version-agnostic 9.x wording in README
  • e9f287d Fix CI and DEV workflows to use the current test directory (#199)
  • 54c356b Finalize 9.1.0 changelog for release
  • 3f9e9b7 Freeze legacy into _legacy.py, reorganize tests, ship 9.1.0 (#198)
  • 2f23599 Fix add_uppercase_char to leave input unchanged on error (#194)
  • 548b14f Preserve fitting post-replacement output during modern truncation (#193)
  • Additional commits viewable in compare view

Updates virtualenv from 21.7.14 to 21.12.1

Release notes

Sourced from virtualenv's releases.

21.12.1

What's Changed

Full Changelog: pypa/virtualenv@21.12.0...21.12.1

21.12.0

What's Changed

Full Changelog: pypa/virtualenv@21.11.1...21.12.0

21.11.1

What's Changed

New Contributors

Full Changelog: pypa/virtualenv@21.11.0...21.11.1

21.11.0

What's Changed

... (truncated)

Changelog

Sourced from virtualenv's changelog.

Bugfixes - 21.12.1

  • Limit the :PEP:832 .venv redirect to folders holding a pyproject.toml and no .venv yet, so virtualenv foo in a scratch folder, and tools such as tox or nox building environments through virtualenv, no longer claim a folder's default environment - by :user:gaborbernat.

    • --venv-redirect writes the redirect in any folder and replaces an earlier virtualenv redirect.
    • A flag on the command line overrides the environment variable and the config file in either direction. (:issue:3316)

v21.12.0 (2026-09-24)


Features - 21.12.0

  • Write the PEP 838 <https://peps.python.org/pep-0838/>_ python-version key into pyvenv.cfg, holding the target interpreter's feature release. The new :doc:reference/files page covers it alongside every other file a created environment holds - by :user:konstin. (:issue:3193)

  • Point a .venv redirect file in the parent folder at the created environment, per PEP 832 <https://peps.python.org/pep-0832/>_, so editors and type checkers can find it - by :user:gaborbernat.

    • virtualenv leaves a .venv folder alone, and a redirect pointing at an environment it did not create.
    • Pass --no-venv-redirect to opt out.
    • The feature is provisional while PEP 832 is a draft: a minor or patch release may change it in backward incompatible ways to follow the PEP. (:issue:3204)

v21.11.1 (2026-09-23)


Bugfixes - 21.11.1

  • Include the pre-commit configuration and the zipapp lock file in the source distribution, so downstream packagers can run the test suite from it. (:issue:3314)

v21.11.0 (2026-09-23)


Features - 21.11.0

  • Attach the CycloneDX SBOM and an SPDX 2.3 rendering of it (virtualenv.cdx.json, virtualenv.spdx.json) to each GitHub release, and attest the SPDX document against the sdist and wheel. (:issue:3299)
  • Describe the zipapp in its own CycloneDX SBOM, which lists virtualenv, the embedded pip and setuptools wheels, and each bundled dependency with the Python versions that load it, down to a SHA-256 per file. The SBOM sits at the root

... (truncated)

Commits
  • befec5e release 21.12.1
  • 572d159 🐛 fix(create): limit .venv redirect to projects (#3316)
  • f19165b release 21.12.0
  • 554bc8f ✨ feat(create): point a .venv redirect per PEP 832 (#3204)
  • 4c13875 release 21.11.1
  • ae073fb 🐛 fix(build): ship test inputs in the sdist and check it (#3315)
  • fc912de 📝 docs(security): close threat items resolved by 21.11.0 (#3313)
  • 49077e7 release 21.11.0
  • 5d9dc58 🐛 fix(sbom): keep the build machine out of the SBOMs (#3311)
  • bcb0fa6 📝 docs(security): sync threat model with merged fixes (#3312)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the production-dependencies group with 4 updates: [platformdirs](https://github.com/tox-dev/platformdirs), [python-gitlab](https://github.com/python-gitlab/python-gitlab), [python-slugify](https://github.com/un33k/python-slugify) and [virtualenv](https://github.com/pypa/virtualenv).


Updates `platformdirs` from 4.11.10 to 4.11.13
- [Release notes](https://github.com/tox-dev/platformdirs/releases)
- [Changelog](https://github.com/tox-dev/platformdirs/blob/main/docs/changelog.rst)
- [Commits](tox-dev/platformdirs@4.11.10...4.11.13)

Updates `python-gitlab` from 6.5.0 to 8.5.0
- [Release notes](https://github.com/python-gitlab/python-gitlab/releases)
- [Changelog](https://github.com/python-gitlab/python-gitlab/blob/main/CHANGELOG.md)
- [Commits](python-gitlab/python-gitlab@v6.5.0...v8.5.0)

Updates `python-slugify` from 9.0.0 to 9.1.1
- [Release notes](https://github.com/un33k/python-slugify/releases)
- [Changelog](https://github.com/un33k/python-slugify/blob/master/CHANGELOG.md)
- [Commits](un33k/python-slugify@v9.0.0...v9.1.1)

Updates `virtualenv` from 21.7.14 to 21.12.1
- [Release notes](https://github.com/pypa/virtualenv/releases)
- [Changelog](https://github.com/pypa/virtualenv/blob/main/docs/changelog.rst)
- [Commits](pypa/virtualenv@21.7.14...21.12.1)

---
updated-dependencies:
- dependency-name: platformdirs
  dependency-version: 4.11.13
  dependency-type: indirect
  update-type: version-update:semver-patch
  dependency-group: production-dependencies
- dependency-name: python-gitlab
  dependency-version: 8.5.0
  dependency-type: indirect
  update-type: version-update:semver-major
  dependency-group: production-dependencies
- dependency-name: python-slugify
  dependency-version: 9.1.1
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
- dependency-name: virtualenv
  dependency-version: 21.12.1
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: production-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Sep 28, 2026

Copy link
Copy Markdown
Contributor Author

Assignees

The following users could not be added as assignees: jonzeolla. Either the username does not exist or it does not have the correct permissions to be added as an assignee.

Labels

The following labels could not be found: dependencies, python. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@ai-coding-guardrails ai-coding-guardrails Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nice work! 😎

I didn't find anything of concern

List of skipped files due to configuration

Risk: 🟢 Low

Reviewed with 🤟 by Zenable

@ai-coding-guardrails ai-coding-guardrails Bot added the zenable/risk:low Zenable assessed this PR as LOW risk. label Sep 28, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

zenable/risk:low Zenable assessed this PR as LOW risk.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant