dependabot[bot] opened a new pull request, #73487: URL: https://github.com/apache/airflow/pull/73487
Bumps the 3-3-uv-dependency-updates group with 8 updates in the /dev/breeze directory: | Package | From | To | | --- | --- | --- | | [filelock](https://github.com/tox-dev/py-filelock) | `3.32.5` | `3.32.7` | | [flit](https://github.com/pypa/flit) | `4.0.2` | `4.1.0` | | [flit-core](https://github.com/pypa/flit) | `4.0.2` | `4.1.0` | | [hatch](https://github.com/pypa/hatch) | `1.18.0` | `1.18.1` | | [prek](https://github.com/j178/prek) | `0.5.2` | `0.5.3` | | [tqdm](https://github.com/tqdm/tqdm) | `4.70.0` | `4.70.1` | | [boto3](https://github.com/boto/boto3) | `1.43.89` | `1.43.96` | | [semver](https://github.com/python-semver/python-semver) | `3.0.4` | `3.1.0` | Updates `filelock` from 3.32.5 to 3.32.7 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/tox-dev/py-filelock/releases">filelock's releases</a>.</em></p> <blockquote> <h2>3.32.7</h2> <!-- raw HTML omitted --> <h2>What's Changed</h2> <ul> <li>Fix final symlink test on musl by <a href="https://github.com/lprnmns"><code>@lprnmns</code></a> in <a href="https://redirect.github.com/tox-dev/filelock/pull/737">tox-dev/filelock#737</a></li> <li>📝 docs: say acquire() falls back to the lock's blocking attribute by <a href="https://github.com/hxperl"><code>@hxperl</code></a> in <a href="https://redirect.github.com/tox-dev/filelock/pull/733">tox-dev/filelock#733</a></li> </ul> <h2>New Contributors</h2> <ul> <li><a href="https://github.com/hxperl"><code>@hxperl</code></a> made their first contribution in <a href="https://redirect.github.com/tox-dev/filelock/pull/733">tox-dev/filelock#733</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/tox-dev/filelock/compare/3.32.6...3.32.7">https://github.com/tox-dev/filelock/compare/3.32.6...3.32.7</a></p> <h2>3.32.6</h2> <!-- raw HTML omitted --> <h2>What's Changed</h2> <ul> <li>🐛 fix(lease): reject a duration no marker can carry by <a href="https://github.com/lprnmns"><code>@lprnmns</code></a> in <a href="https://redirect.github.com/tox-dev/filelock/pull/723">tox-dev/filelock#723</a></li> <li>🐛 fix(soft-rw): reject non-finite timing options by <a href="https://github.com/lprnmns"><code>@lprnmns</code></a> in <a href="https://redirect.github.com/tox-dev/filelock/pull/724">tox-dev/filelock#724</a></li> <li>fix: preserve exception notes when copying and pickling by <a href="https://github.com/jackwalkerlabs"><code>@jackwalkerlabs</code></a> in <a href="https://redirect.github.com/tox-dev/filelock/pull/729">tox-dev/filelock#729</a></li> <li>test(soft-rw): reuse existing test module by <a href="https://github.com/gaborbernat"><code>@gaborbernat</code></a> in <a href="https://redirect.github.com/tox-dev/filelock/pull/730">tox-dev/filelock#730</a></li> <li>fix: respect ACL write access when the owner write bit is absent by <a href="https://github.com/jackwalkerlabs"><code>@jackwalkerlabs</code></a> in <a href="https://redirect.github.com/tox-dev/filelock/pull/728">tox-dev/filelock#728</a></li> <li>Fix SoftReadWriteLock state lock timeout by <a href="https://github.com/Sohel2309"><code>@Sohel2309</code></a> in <a href="https://redirect.github.com/tox-dev/filelock/pull/726">tox-dev/filelock#726</a></li> </ul> <h2>New Contributors</h2> <ul> <li><a href="https://github.com/jackwalkerlabs"><code>@jackwalkerlabs</code></a> made their first contribution in <a href="https://redirect.github.com/tox-dev/filelock/pull/729">tox-dev/filelock#729</a></li> <li><a href="https://github.com/Sohel2309"><code>@Sohel2309</code></a> made their first contribution in <a href="https://redirect.github.com/tox-dev/filelock/pull/726">tox-dev/filelock#726</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/tox-dev/filelock/compare/3.32.5...3.32.6">https://github.com/tox-dev/filelock/compare/3.32.5...3.32.6</a></p> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/tox-dev/filelock/blob/main/docs/changelog.rst">filelock's changelog</a>.</em></p> <blockquote> <p>########### Changelog ###########</p> <p>.. towncrier-draft-entries:: Unreleased</p> <p>.. towncrier release notes start</p> <hr /> <p>4.0.1 (2026-09-19)</p> <hr /> <ul> <li><code>poll_interval</code> is now validated at construction, on the setter, and on <code>acquire()</code>: a negative, non-finite, or non-numeric value raises :class:<code>ValueError</code>/:class:<code>TypeError</code> immediately instead of failing inside <code>time.sleep</code>. :pr:<code>739</code></li> </ul> <hr /> <p>4.0.0 (2026-09-17)</p> <hr /> <ul> <li>The :class:<code>~filelock.SoftReadWriteLock</code> on-disk protocol is a generation log under <code><path>.rw</code>, and a process running an earlier release does not see it: an old and a new participant on one lock path do not exclude each other. Stop every participant, upgrade them all, then restart them; the new code ignores leftover <code>.state</code>, <code>.write</code> and <code>.readers/</code> files, and you can delete them. The filesystem must provide no-replace hard links, as it must for :class:<code>~filelock.StrictSoftFileLock</code>, so a runtime without <code>os.link</code> raises :class:<code>~filelock.SoftFileLockProtocolError</code> on acquire. Constructing a singleton again with a different <code>on_compromise</code>, or with <code>poll_interval</code> at or above <code>stale_threshold</code>, now raises :class:<code>ValueError</code>. :pr:<code>735</code></li> <li>:class:<code>~filelock.SoftReadWriteLock</code> exposes :attr:<code>~filelock.SoftReadWriteLock.generation</code> as a fencing token for the protected resource and reports a lost hold through <code>on_compromise</code> and :attr:<code>~filelock.SoftReadWriteLock.compromise</code>. :pr:<code>735</code></li> <li>:class:<code>~filelock.SoftReadWriteLock</code> no longer deadlocks when a holder dies on another host mid-transition, and <code>release()</code> no longer waits on a mutex a dead host left behind (:pr:<code>725</code>, :pr:<code>735</code>). The state mutex is gone. Each transition is one atomic snapshot commit, and liveness is a heartbeat nonce read on the observer's own clock rather than an <code>mtime</code> read against another host's. :pr:<code>735</code></li> </ul> <hr /> <p>3.32.7 (2026-09-16)</p> <hr /> <ul> <li>Validate final-symlink refusal by error number so the test works across libc implementations. :pr:<code>737</code></li> <li>Document that :meth:<code>~filelock.BaseFileLock.acquire</code> reads <code>blocking=None</code> as the lock's <code>blocking</code> attribute and raises :class:<code>~filelock.Timeout</code> after one attempt when <code>blocking=False</code>. :pr:<code>733</code></li> </ul> <hr /> <p>3.32.6 (2026-09-08)</p> <hr /> <ul> <li><code>SoftFileLease</code> and <code>AsyncSoftFileLease</code> now reject a boolean or non-finite <code>lease_duration</code>, which used to publish an owner record their own <code>owner</code> property reads back as malformed. :pr:<code>723</code></li> <li>Reject non-finite heartbeat, stale, and polling intervals in <code>SoftReadWriteLock</code> and <code>AsyncSoftReadWriteLock</code>, including cached singleton construction and overflow in the default stale threshold. :pr:<code>724</code></li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/tox-dev/filelock/commit/20929f7d1439d5fa1df158fcac87b60815f5d422"><code>20929f7</code></a> Release 3.32.7</li> <li><a href="https://github.com/tox-dev/filelock/commit/35f07c48009c41faecfa7182939e5b7e1c78ae71"><code>35f07c4</code></a> [pre-commit.ci] pre-commit autoupdate (<a href="https://redirect.github.com/tox-dev/py-filelock/issues/736">#736</a>)</li> <li><a href="https://github.com/tox-dev/filelock/commit/e860d3905d369b4753de5759d1cd70d0ca639d1f"><code>e860d39</code></a> 📝 docs: say acquire() falls back to the lock's blocking attribute (<a href="https://redirect.github.com/tox-dev/py-filelock/issues/733">#733</a>)</li> <li><a href="https://github.com/tox-dev/filelock/commit/c530efec2ee5012eeaa742c196c3623d478888ba"><code>c530efe</code></a> Fix final symlink test on musl (<a href="https://redirect.github.com/tox-dev/py-filelock/issues/737">#737</a>)</li> <li><a href="https://github.com/tox-dev/filelock/commit/4efd93e0482e8095a0b6949fb337206e7f67495d"><code>4efd93e</code></a> Release 3.32.6</li> <li><a href="https://github.com/tox-dev/filelock/commit/7b7b7a8b9b10acf826cca246441297468039b0c1"><code>7b7b7a8</code></a> Fix SoftReadWriteLock state lock timeout (<a href="https://redirect.github.com/tox-dev/py-filelock/issues/726">#726</a>)</li> <li><a href="https://github.com/tox-dev/filelock/commit/f2f7b8696426c518b6828ea10e755c0ba2a4ffe2"><code>f2f7b86</code></a> fix: respect ACL write access when the owner write bit is absent (<a href="https://redirect.github.com/tox-dev/py-filelock/issues/728">#728</a>)</li> <li><a href="https://github.com/tox-dev/filelock/commit/e947a694fb0da6676c4861c8bfef3650e5656153"><code>e947a69</code></a> test(soft-rw): reuse existing test module (<a href="https://redirect.github.com/tox-dev/py-filelock/issues/730">#730</a>)</li> <li><a href="https://github.com/tox-dev/filelock/commit/da3ae2bca0035fb9e5269257e6f393360866cf88"><code>da3ae2b</code></a> fix: preserve exception notes when copying and pickling (<a href="https://redirect.github.com/tox-dev/py-filelock/issues/729">#729</a>)</li> <li><a href="https://github.com/tox-dev/filelock/commit/ae9cb5b2d66d6a79edd76b292fa7320c11468812"><code>ae9cb5b</code></a> 🐛 fix(soft-rw): reject non-finite timing options (<a href="https://redirect.github.com/tox-dev/py-filelock/issues/724">#724</a>)</li> <li>Additional commits viewable in <a href="https://github.com/tox-dev/py-filelock/compare/3.32.5...3.32.7">compare view</a></li> </ul> </details> <br /> Updates `flit` from 4.0.2 to 4.1.0 <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/pypa/flit/blob/main/doc/history.rst">flit's changelog</a>.</em></p> <blockquote> <h1>Release history</h1> <h2>Version 4.1</h2> <ul> <li>License expressions with named exceptions, the WITH syntax, are accepted (:ghpull:<code>809</code>).</li> <li><code>flit init</code> allows dotted module names, for a component of a namespace package (:ghissue:<code>822</code>).</li> <li>Fix line endings in <code>.cmd</code> script wrappers on Windows (:ghpull:<code>824</code>).</li> </ul> <h2>Version 4.0.3</h2> <ul> <li>Fix built wheels being created with overly restrictive <code>0600</code> permissions instead of the normal, world-readable <code>0644</code> (:ghpull:<code>806</code>).</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/pypa/flit/commit/75b1c909d587c1ff5e0fd5f3df1046f74ee249d4"><code>75b1c90</code></a> Merge pull request <a href="https://redirect.github.com/pypa/flit/issues/826">#826</a> from pypa/prepare-4.1</li> <li><a href="https://github.com/pypa/flit/commit/b5ad0d7ac228781a300221706bfddbd88e217912"><code>b5ad0d7</code></a> Add release note about PR <a href="https://redirect.github.com/pypa/flit/issues/824">#824</a></li> <li><a href="https://github.com/pypa/flit/commit/9fb48c1ccff116f9c0a752cbcdcd16104cd2780b"><code>9fb48c1</code></a> Bump version: 4.0.2 → 4.1.0</li> <li><a href="https://github.com/pypa/flit/commit/a4ea331683399850045c6a4c4c2f1228c0969b2b"><code>a4ea331</code></a> Prepare release notes for 4.1</li> <li><a href="https://github.com/pypa/flit/commit/337c49942fd0b10834c7b62461e574f21d9a7f43"><code>337c499</code></a> Merge pull request <a href="https://redirect.github.com/pypa/flit/issues/824">#824</a> from r3wretrhy/fix-win-cmd-crlf</li> <li><a href="https://github.com/pypa/flit/commit/04cfa08ec5c6446c8852473766c35270a2d4b809"><code>04cfa08</code></a> Merge pull request <a href="https://redirect.github.com/pypa/flit/issues/825">#825</a> from hxperl/docs-dynamic-fields</li> <li><a href="https://github.com/pypa/flit/commit/33be60767051acb5940881a2eb55958334866ba9"><code>33be607</code></a> doc: list all four fields accepted in project.dynamic</li> <li><a href="https://github.com/pypa/flit/commit/d538cb4841ce7412ef9c69cbd966a537ed899168"><code>d538cb4</code></a> install: keep explicit CRLF in Windows .cmd wrappers</li> <li><a href="https://github.com/pypa/flit/commit/3c926045ecbdf084a6af0d596be675345633bbcf"><code>3c92604</code></a> Merge pull request <a href="https://redirect.github.com/pypa/flit/issues/809">#809</a> from yangfan-yf-yf/fix/spdx-with-exceptions</li> <li><a href="https://github.com/pypa/flit/commit/33a7a39fc10ce50be2b47219ba21ceecd2b64210"><code>33a7a39</code></a> Clarify SPDX WITH version requirement and error message</li> <li>Additional commits viewable in <a href="https://github.com/pypa/flit/compare/4.0.2...4.1.0">compare view</a></li> </ul> </details> <br /> Updates `flit-core` from 4.0.2 to 4.1.0 <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/pypa/flit/blob/main/doc/history.rst">flit-core's changelog</a>.</em></p> <blockquote> <h1>Release history</h1> <h2>Version 4.1</h2> <ul> <li>License expressions with named exceptions, the WITH syntax, are accepted (:ghpull:<code>809</code>).</li> <li><code>flit init</code> allows dotted module names, for a component of a namespace package (:ghissue:<code>822</code>).</li> <li>Fix line endings in <code>.cmd</code> script wrappers on Windows (:ghpull:<code>824</code>).</li> </ul> <h2>Version 4.0.3</h2> <ul> <li>Fix built wheels being created with overly restrictive <code>0600</code> permissions instead of the normal, world-readable <code>0644</code> (:ghpull:<code>806</code>).</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/pypa/flit/commit/75b1c909d587c1ff5e0fd5f3df1046f74ee249d4"><code>75b1c90</code></a> Merge pull request <a href="https://redirect.github.com/pypa/flit/issues/826">#826</a> from pypa/prepare-4.1</li> <li><a href="https://github.com/pypa/flit/commit/b5ad0d7ac228781a300221706bfddbd88e217912"><code>b5ad0d7</code></a> Add release note about PR <a href="https://redirect.github.com/pypa/flit/issues/824">#824</a></li> <li><a href="https://github.com/pypa/flit/commit/9fb48c1ccff116f9c0a752cbcdcd16104cd2780b"><code>9fb48c1</code></a> Bump version: 4.0.2 → 4.1.0</li> <li><a href="https://github.com/pypa/flit/commit/a4ea331683399850045c6a4c4c2f1228c0969b2b"><code>a4ea331</code></a> Prepare release notes for 4.1</li> <li><a href="https://github.com/pypa/flit/commit/337c49942fd0b10834c7b62461e574f21d9a7f43"><code>337c499</code></a> Merge pull request <a href="https://redirect.github.com/pypa/flit/issues/824">#824</a> from r3wretrhy/fix-win-cmd-crlf</li> <li><a href="https://github.com/pypa/flit/commit/04cfa08ec5c6446c8852473766c35270a2d4b809"><code>04cfa08</code></a> Merge pull request <a href="https://redirect.github.com/pypa/flit/issues/825">#825</a> from hxperl/docs-dynamic-fields</li> <li><a href="https://github.com/pypa/flit/commit/33be60767051acb5940881a2eb55958334866ba9"><code>33be607</code></a> doc: list all four fields accepted in project.dynamic</li> <li><a href="https://github.com/pypa/flit/commit/d538cb4841ce7412ef9c69cbd966a537ed899168"><code>d538cb4</code></a> install: keep explicit CRLF in Windows .cmd wrappers</li> <li><a href="https://github.com/pypa/flit/commit/3c926045ecbdf084a6af0d596be675345633bbcf"><code>3c92604</code></a> Merge pull request <a href="https://redirect.github.com/pypa/flit/issues/809">#809</a> from yangfan-yf-yf/fix/spdx-with-exceptions</li> <li><a href="https://github.com/pypa/flit/commit/33a7a39fc10ce50be2b47219ba21ceecd2b64210"><code>33a7a39</code></a> Clarify SPDX WITH version requirement and error message</li> <li>Additional commits viewable in <a href="https://github.com/pypa/flit/compare/4.0.2...4.1.0">compare view</a></li> </ul> </details> <br /> Updates `hatch` from 1.18.0 to 1.18.1 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/pypa/hatch/releases">hatch's releases</a>.</em></p> <blockquote> <h2>Hatch v1.18.1</h2> <p><em><strong>Added:</strong></em></p> <ul> <li>Apply context formatting to the <code>lock-filename</code> environment option so fields such as <code>{env_name}</code> and <code>{matrix:...}</code> are resolved when computing the lock file path.</li> </ul> <p><em><strong>Fixed:</strong></em></p> <ul> <li> <p>Consolidate extras and feature resolution into a single code path, fixing regressions where environment and project extras could be dropped or resolved inconsistently, and always validate undefined features.</p> </li> <li> <p>Normalize hyphens in the plugin name when building environment option environment variable names in <code>get_env_var()</code>, so options for hyphenated plugins resolve to the correct variable.</p> </li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/pypa/hatch/commit/4b17561f822b1b416403a61855374892ecbe11de"><code>4b17561</code></a> release Hatch v1.18.1 (<a href="https://redirect.github.com/pypa/hatch/issues/2426">#2426</a>)</li> <li><a href="https://github.com/pypa/hatch/commit/b6aaa1a3cac6be652ac90c8c79612bddcca733ea"><code>b6aaa1a</code></a> release Hatchling v1.32.1 (<a href="https://redirect.github.com/pypa/hatch/issues/2425">#2425</a>)</li> <li><a href="https://github.com/pypa/hatch/commit/47f333a98228c326786d3919f346bd7b74d9cf8f"><code>47f333a</code></a> Prepare for hatch and hatchling releases (<a href="https://redirect.github.com/pypa/hatch/issues/2424">#2424</a>)</li> <li><a href="https://github.com/pypa/hatch/commit/d5f7bfe813dd4d81520def23b43f5d46aad1899c"><code>d5f7bfe</code></a> Fix version metadata to preserve leading zeros in CalVer (<a href="https://redirect.github.com/pypa/hatch/issues/2398">#2398</a>)</li> <li><a href="https://github.com/pypa/hatch/commit/cbfc465e019ff51460f80ebbc35370e476aed6b9"><code>cbfc465</code></a> Context formatting support for <code>lock-filename</code> (<a href="https://redirect.github.com/pypa/hatch/issues/2412">#2412</a>)</li> <li><a href="https://github.com/pypa/hatch/commit/929362c909899556ae4efd1f61a3b078677ad235"><code>929362c</code></a> Mark a few more tests that require Internet access (<a href="https://redirect.github.com/pypa/hatch/issues/2400">#2400</a>)</li> <li><a href="https://github.com/pypa/hatch/commit/c9d4e8a82a81835e1ed8b29e6885631d7f5aecb3"><code>c9d4e8a</code></a> Fix env var formatting in <code>get_env_var()</code> function (<a href="https://redirect.github.com/pypa/hatch/issues/2397">#2397</a>)</li> <li><a href="https://github.com/pypa/hatch/commit/84023e0b77ddec3aa3015cd9b57f78f00da2cb18"><code>84023e0</code></a> Some type fixes (<a href="https://redirect.github.com/pypa/hatch/issues/1138">#1138</a>)</li> <li><a href="https://github.com/pypa/hatch/commit/ed8e30bebf98f2fe4d70c18a32a50a8160c391cb"><code>ed8e30b</code></a> Refactor extras so that the logic is in one place (<a href="https://redirect.github.com/pypa/hatch/issues/2382">#2382</a>)</li> <li>See full diff in <a href="https://github.com/pypa/hatch/compare/hatch-v1.18.0...hatch-v1.18.1">compare view</a></li> </ul> </details> <br /> Updates `prek` from 0.5.2 to 0.5.3 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/j178/prek/releases">prek's releases</a>.</em></p> <blockquote> <h2>0.5.3</h2> <h2>Release Notes</h2> <p>Released on 2026-09-13.</p> <h3>Enhancements</h3> <ul> <li>Add PEP 740 attestations for PyPI releases (<a href="https://redirect.github.com/j178/prek/pull/2705">#2705</a>)</li> <li>Add a <code>check-jsonc</code> builtin hook (<a href="https://redirect.github.com/j178/prek/pull/2682">#2682</a>)</li> <li>Allow disabling automatic uv installation (<a href="https://redirect.github.com/j178/prek/pull/2702">#2702</a>)</li> </ul> <h3>Bug fixes</h3> <ul> <li>Fix Julia additional dependency specifiers (<a href="https://redirect.github.com/j178/prek/pull/2703">#2703</a>)</li> <li>Update <code>granit-parser</code> to fix YAML flow indentation (<a href="https://redirect.github.com/j178/prek/pull/2707">#2707</a>)</li> </ul> <h3>Contributors</h3> <ul> <li><a href="https://github.com/clbarnes"><code>@clbarnes</code></a></li> <li><a href="https://github.com/j178"><code>@j178</code></a></li> <li><a href="https://github.com/tisonkun"><code>@tisonkun</code></a></li> </ul> <h2>Install prek 0.5.3</h2> <h3>Install prebuilt binaries via shell script</h3> <pre lang="sh"><code>curl --proto '=https' --tlsv1.2 -LsSf https://github.com/j178/prek/releases/download/v0.5.3/prek-installer.sh | sh </code></pre> <h3>Install prebuilt binaries via powershell script</h3> <pre lang="sh"><code>powershell -ExecutionPolicy Bypass -c "irm https://github.com/j178/prek/releases/download/v0.5.3/prek-installer.ps1 | iex" </code></pre> <h3>Install prebuilt binaries via Homebrew</h3> <pre lang="sh"><code>brew install prek </code></pre> <h2>Download prek 0.5.3</h2> <table> <thead> <tr> <th>File</th> <th>Platform</th> <th>Checksum</th> </tr> </thead> <tbody> <tr> <td><a href="https://github.com/j178/prek/releases/download/v0.5.3/prek-aarch64-apple-darwin.tar.gz">prek-aarch64-apple-darwin.tar.gz</a></td> <td>Apple Silicon macOS</td> <td><a href="https://github.com/j178/prek/releases/download/v0.5.3/prek-aarch64-apple-darwin.tar.gz.sha256">checksum</a></td> </tr> <tr> <td><a href="https://github.com/j178/prek/releases/download/v0.5.3/prek-x86_64-apple-darwin.tar.gz">prek-x86_64-apple-darwin.tar.gz</a></td> <td>Intel macOS</td> <td><a href="https://github.com/j178/prek/releases/download/v0.5.3/prek-x86_64-apple-darwin.tar.gz.sha256">checksum</a></td> </tr> <tr> <td><a href="https://github.com/j178/prek/releases/download/v0.5.3/prek-aarch64-pc-windows-msvc.zip">prek-aarch64-pc-windows-msvc.zip</a></td> <td>ARM64 Windows</td> <td><a href="https://github.com/j178/prek/releases/download/v0.5.3/prek-aarch64-pc-windows-msvc.zip.sha256">checksum</a></td> </tr> <tr> <td><a href="https://github.com/j178/prek/releases/download/v0.5.3/prek-x86_64-pc-windows-msvc.zip">prek-x86_64-pc-windows-msvc.zip</a></td> <td>x64 Windows</td> <td><a href="https://github.com/j178/prek/releases/download/v0.5.3/prek-x86_64-pc-windows-msvc.zip.sha256">checksum</a></td> </tr> </tbody> </table> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/j178/prek/blob/master/CHANGELOG.md">prek's changelog</a>.</em></p> <blockquote> <h2>0.5.3</h2> <p>Released on 2026-09-13.</p> <h3>Enhancements</h3> <ul> <li>Add PEP 740 attestations for PyPI releases (<a href="https://redirect.github.com/j178/prek/pull/2705">#2705</a>)</li> <li>Add a <code>check-jsonc</code> builtin hook (<a href="https://redirect.github.com/j178/prek/pull/2682">#2682</a>)</li> <li>Allow disabling automatic uv installation (<a href="https://redirect.github.com/j178/prek/pull/2702">#2702</a>)</li> </ul> <h3>Bug fixes</h3> <ul> <li>Fix Julia additional dependency specifiers (<a href="https://redirect.github.com/j178/prek/pull/2703">#2703</a>)</li> <li>Update <code>granit-parser</code> to fix YAML flow indentation (<a href="https://redirect.github.com/j178/prek/pull/2707">#2707</a>)</li> </ul> <h3>Contributors</h3> <ul> <li><a href="https://github.com/clbarnes"><code>@clbarnes</code></a></li> <li><a href="https://github.com/j178"><code>@j178</code></a></li> <li><a href="https://github.com/tisonkun"><code>@tisonkun</code></a></li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/j178/prek/commit/b7eb6027125de7e3b67dd94039a4f69abf3a5fb0"><code>b7eb602</code></a> Bump version to 0.5.3 (<a href="https://redirect.github.com/j178/prek/issues/2708">#2708</a>)</li> <li><a href="https://github.com/j178/prek/commit/4644f81e1c86eeb8e22a1ba4aaa6dec99b4266c5"><code>4644f81</code></a> Update granit-parser to fix YAML flow indentation (<a href="https://redirect.github.com/j178/prek/issues/2707">#2707</a>)</li> <li><a href="https://github.com/j178/prek/commit/87f2ea44c258dc6606ca5556a7b3ff0d9a0a601e"><code>87f2ea4</code></a> Use self-repository syntax in CI workflows</li> <li><a href="https://github.com/j178/prek/commit/f39abae3cafd9ff245843b790fdd9b7c2e933b5c"><code>f39abae</code></a> Add PEP 740 attestations for PyPI releases (<a href="https://redirect.github.com/j178/prek/issues/2705">#2705</a>)</li> <li><a href="https://github.com/j178/prek/commit/f4924dccacd86afab22ae45e634d7f9ca12dd59e"><code>f4924dc</code></a> Allow disabling automatic uv installation (<a href="https://redirect.github.com/j178/prek/issues/2702">#2702</a>)</li> <li><a href="https://github.com/j178/prek/commit/156c0cec12847513ba764d1d87543ab6d0785c64"><code>156c0ce</code></a> Fix Julia additional dependency specifiers (<a href="https://redirect.github.com/j178/prek/issues/2703">#2703</a>)</li> <li><a href="https://github.com/j178/prek/commit/c3ede77b83e7d578e31d076863b755b296256a21"><code>c3ede77</code></a> Add a <code>check-jsonc</code> builtin hook (<a href="https://redirect.github.com/j178/prek/issues/2682">#2682</a>)</li> <li><a href="https://github.com/j178/prek/commit/c0b9749c3ee43f42efd0116624a7922feded3fc2"><code>c0b9749</code></a> Verify checksums for PyPI/mirror wheel installs (<a href="https://redirect.github.com/j178/prek/issues/2688">#2688</a>)</li> <li><a href="https://github.com/j178/prek/commit/fbe5c66737e679f31018dd438d16774c19c6774d"><code>fbe5c66</code></a> Update prek hooks (<a href="https://redirect.github.com/j178/prek/issues/2690">#2690</a>)</li> <li><a href="https://github.com/j178/prek/commit/4687a2c57f8ae58cf0e66b65baf49ea72ccb62ba"><code>4687a2c</code></a> Fix <code>check-hooks-apply</code> for builtin Windows filename checks</li> <li>Additional commits viewable in <a href="https://github.com/j178/prek/compare/v0.5.2...v0.5.3">compare view</a></li> </ul> </details> <br /> Updates `tqdm` from 4.70.0 to 4.70.1 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/tqdm/tqdm/releases">tqdm's releases</a>.</em></p> <blockquote> <h2>tqdm v4.70.1 stable</h2> <ul> <li><code>contrib.concurrent</code>: fix no-len iterables (<a href="https://redirect.github.com/tqdm/tqdm/issues/1830">#1830</a> <- <a href="https://redirect.github.com/tqdm/tqdm/issues/1828">#1828</a>)</li> <li>tests: major overhaul (<a href="https://redirect.github.com/tqdm/tqdm/issues/1819">#1819</a>)</li> <li>update AI policy in PR template</li> <li>misc lint & tidy</li> <li>CI: bump workflow actions & pre-commit hooks</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/tqdm/tqdm/commit/9cf5a12b1f955468a17f0ba3c59092b23e4258ac"><code>9cf5a12</code></a> Merge pull request <a href="https://redirect.github.com/tqdm/tqdm/issues/1830">#1830</a> from eaubin/master</li> <li><a href="https://github.com/tqdm/tqdm/commit/24b9e1e08a097f1c30f2d235b63f9eb25ba47974"><code>24b9e1e</code></a> misc tidy</li> <li><a href="https://github.com/tqdm/tqdm/commit/2a9e4e82ddba07c5dd6d126e23a4745b76ea49c8"><code>2a9e4e8</code></a> contrib.concurrent: fix no-len iterables</li> <li><a href="https://github.com/tqdm/tqdm/commit/8d6ff8de5a9066de77d0a9df3e80a022a3dcf146"><code>8d6ff8d</code></a> Merge pull request <a href="https://redirect.github.com/tqdm/tqdm/issues/1819">#1819</a> from tqdm/devel</li> <li><a href="https://github.com/tqdm/tqdm/commit/bed379609c2c8300671c784c8f85a185c8cf6fb3"><code>bed3796</code></a> tests: major overhaul</li> <li><a href="https://github.com/tqdm/tqdm/commit/4d3d3194d5467e0701bc0f4b836a735273ef0868"><code>4d3d319</code></a> AI policy</li> <li><a href="https://github.com/tqdm/tqdm/commit/5dcb022b55553b60ed2131b64aa5bf1e65470df1"><code>5dcb022</code></a> minor syntax update</li> <li><a href="https://github.com/tqdm/tqdm/commit/309effe4244bf45427c5add7f1bcf33f98a7b421"><code>309effe</code></a> tests: pre-commit coverage</li> <li><a href="https://github.com/tqdm/tqdm/commit/604193aa03b5f5c0ad5f3d441951f0fbb515f1e4"><code>604193a</code></a> tests: slight tidy</li> <li><a href="https://github.com/tqdm/tqdm/commit/17f1cac07c89943eb0e6082875b3821205308d4f"><code>17f1cac</code></a> CI: bump workflow actions</li> <li>See full diff in <a href="https://github.com/tqdm/tqdm/compare/v4.70.0...v4.70.1">compare view</a></li> </ul> </details> <br /> Updates `boto3` from 1.43.89 to 1.43.96 <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/boto/boto3/commit/2be9967c9214ffb4421dc9710c7f7fead47dcd33"><code>2be9967</code></a> Merge branch 'release-1.43.96'</li> <li><a href="https://github.com/boto/boto3/commit/6e1774a1ffe1d84bfd70f36c0bdff3e6dd079aaa"><code>6e1774a</code></a> Bumping version to 1.43.96</li> <li><a href="https://github.com/boto/boto3/commit/ef6f957bc22f980c1a68275e79c54aab05b59f02"><code>ef6f957</code></a> Add changelog entries from botocore</li> <li><a href="https://github.com/boto/boto3/commit/238d6ecf828482808e1a2135dba4dcb92284ed4f"><code>238d6ec</code></a> Update PyPI package summary to add Boto3 (<a href="https://redirect.github.com/boto/boto3/issues/4846">#4846</a>)</li> <li><a href="https://github.com/boto/boto3/commit/2d18ca8b7ba0a13858ac958962bac4946afe33b0"><code>2d18ca8</code></a> Add root workspace folder to gitignore (<a href="https://redirect.github.com/boto/boto3/issues/4847">#4847</a>)</li> <li><a href="https://github.com/boto/boto3/commit/3061d2212799aca9c6d350df852e55402dc4dfb3"><code>3061d22</code></a> Merge branch 'release-1.43.95'</li> <li><a href="https://github.com/boto/boto3/commit/5dc82d93514d7315ae593b4a5a1f9b65e95cd999"><code>5dc82d9</code></a> Merge branch 'release-1.43.95' into develop</li> <li><a href="https://github.com/boto/boto3/commit/70cfb814905b20c3760bf55851aece177098a5ae"><code>70cfb81</code></a> Bumping version to 1.43.95</li> <li><a href="https://github.com/boto/boto3/commit/95ba0d9676a0d7674b8042e8f546334ae1f11135"><code>95ba0d9</code></a> Add changelog entries from botocore</li> <li><a href="https://github.com/boto/boto3/commit/ec50e6e012a25a3be7893b933696c58df5b69a04"><code>ec50e6e</code></a> Merge branch 'release-1.43.94'</li> <li>Additional commits viewable in <a href="https://github.com/boto/boto3/compare/1.43.89...1.43.96">compare view</a></li> </ul> </details> <br /> Updates `semver` from 3.0.4 to 3.1.0 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/python-semver/python-semver/releases">semver's releases</a>.</em></p> <blockquote> <h2>3.1.0</h2> <h2>What's Changed</h2> <ul> <li>Fix <a href="https://redirect.github.com/python-semver/python-semver/issues/463">#463</a>: Remove duplicate code Version.bump_build by <a href="https://github.com/tomschr"><code>@tomschr</code></a> in <a href="https://redirect.github.com/python-semver/python-semver/pull/464">python-semver/python-semver#464</a></li> <li>Fix <a href="https://redirect.github.com/python-semver/python-semver/issues/460">#460</a> Improve bump_prerelease to alway get a newer version by <a href="https://github.com/Learloj"><code>@Learloj</code></a> in <a href="https://redirect.github.com/python-semver/python-semver/pull/462">python-semver/python-semver#462</a></li> <li>441 update pydantic section of docs by <a href="https://github.com/jbkroner"><code>@jbkroner</code></a> in <a href="https://redirect.github.com/python-semver/python-semver/pull/442">python-semver/python-semver#442</a></li> <li>Fix <a href="https://redirect.github.com/python-semver/python-semver/issues/448">#448</a>: Remove Python 3.7-3.9 (EOL) by <a href="https://github.com/tomschr"><code>@tomschr</code></a> in <a href="https://redirect.github.com/python-semver/python-semver/pull/470">python-semver/python-semver#470</a></li> <li>fix: replace semver.parse() with semver.Version.parse() in docstrings by <a href="https://github.com/koteshyelamati"><code>@koteshyelamati</code></a> in <a href="https://redirect.github.com/python-semver/python-semver/pull/471">python-semver/python-semver#471</a></li> <li>fix: next_version should bump version for build-only versions by <a href="https://github.com/binggao1230"><code>@binggao1230</code></a> in <a href="https://redirect.github.com/python-semver/python-semver/pull/469">python-semver/python-semver#469</a></li> <li>fix(next_version): reset prerelease when token changes (<a href="https://redirect.github.com/python-semver/python-semver/issues/339">#339</a>) by <a href="https://github.com/Mukller"><code>@Mukller</code></a> in <a href="https://redirect.github.com/python-semver/python-semver/pull/472">python-semver/python-semver#472</a></li> <li>Bump cryptography from 49.0.0 to 50.0.0 by <a href="https://github.com/dependabot"><code>@dependabot</code></a>[bot] in <a href="https://redirect.github.com/python-semver/python-semver/pull/473">python-semver/python-semver#473</a></li> <li>Declare support for Python 3.15 by <a href="https://github.com/edgarrmondragon"><code>@edgarrmondragon</code></a> in <a href="https://redirect.github.com/python-semver/python-semver/pull/475">python-semver/python-semver#475</a></li> <li>Add optional native parser backend (minimal adapter) by <a href="https://github.com/lowmiaq-gmail"><code>@lowmiaq-gmail</code></a> in <a href="https://redirect.github.com/python-semver/python-semver/pull/476">python-semver/python-semver#476</a></li> <li>Reject non-ASCII digits and trailing newlines in version parsing by <a href="https://github.com/Str0k"><code>@Str0k</code></a> in <a href="https://redirect.github.com/python-semver/python-semver/pull/478">python-semver/python-semver#478</a></li> <li>Fix bump_build() silently returning an unchanged version for digitless build metadata by <a href="https://github.com/Str0k"><code>@Str0k</code></a> in <a href="https://redirect.github.com/python-semver/python-semver/pull/480">python-semver/python-semver#480</a></li> <li>Handle malformed collection operands in Version comparisons by <a href="https://github.com/Str0k"><code>@Str0k</code></a> in <a href="https://redirect.github.com/python-semver/python-semver/pull/479">python-semver/python-semver#479</a></li> <li>Change version to 3.1.0 by <a href="https://github.com/tomschr"><code>@tomschr</code></a> in <a href="https://redirect.github.com/python-semver/python-semver/pull/481">python-semver/python-semver#481</a></li> </ul> <h2>New Contributors</h2> <ul> <li><a href="https://github.com/Learloj"><code>@Learloj</code></a> made their first contribution in <a href="https://redirect.github.com/python-semver/python-semver/pull/462">python-semver/python-semver#462</a></li> <li><a href="https://github.com/jbkroner"><code>@jbkroner</code></a> made their first contribution in <a href="https://redirect.github.com/python-semver/python-semver/pull/442">python-semver/python-semver#442</a></li> <li><a href="https://github.com/koteshyelamati"><code>@koteshyelamati</code></a> made their first contribution in <a href="https://redirect.github.com/python-semver/python-semver/pull/471">python-semver/python-semver#471</a></li> <li><a href="https://github.com/binggao1230"><code>@binggao1230</code></a> made their first contribution in <a href="https://redirect.github.com/python-semver/python-semver/pull/469">python-semver/python-semver#469</a></li> <li><a href="https://github.com/Mukller"><code>@Mukller</code></a> made their first contribution in <a href="https://redirect.github.com/python-semver/python-semver/pull/472">python-semver/python-semver#472</a></li> <li><a href="https://github.com/dependabot"><code>@dependabot</code></a>[bot] made their first contribution in <a href="https://redirect.github.com/python-semver/python-semver/pull/473">python-semver/python-semver#473</a></li> <li><a href="https://github.com/edgarrmondragon"><code>@edgarrmondragon</code></a> made their first contribution in <a href="https://redirect.github.com/python-semver/python-semver/pull/475">python-semver/python-semver#475</a></li> <li><a href="https://github.com/lowmiaq-gmail"><code>@lowmiaq-gmail</code></a> made their first contribution in <a href="https://redirect.github.com/python-semver/python-semver/pull/476">python-semver/python-semver#476</a></li> <li><a href="https://github.com/Str0k"><code>@Str0k</code></a> made their first contribution in <a href="https://redirect.github.com/python-semver/python-semver/pull/478">python-semver/python-semver#478</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/python-semver/python-semver/compare/3.0.4...3.1.0">https://github.com/python-semver/python-semver/compare/3.0.4...3.1.0</a> <strong>Documentation</strong>: <a href="https://python-semver.readthedocs.io/en/latest/">https://python-semver.readthedocs.io/en/latest/</a></p> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/python-semver/python-semver/blob/master/CHANGELOG.rst">semver's changelog</a>.</em></p> <blockquote> <h1>Version 3.1.0</h1> <p>:Released: 2026-09-12 :Maintainer: Tom Schraitle</p> <h2>Bug Fixes</h2> <ul> <li> <p>:pr:<code>478</code>: <code>Version.parse()</code> and <code>Version.is_valid()</code> now reject non-ASCII digits and trailing newlines, in accordance with the SemVer grammar. Optional minor and patch parsing applies the same character restrictions.</p> </li> <li> <p>:pr:<code>479</code>: Comparing a :class:<code>~semver.Version</code> with a <code>dict</code>, <code>tuple</code>, or <code>list</code> that cannot construct a valid version (for example, an empty collection, wrong number of parts, non-numeric parts, or unknown keys) no longer raises internal errors from <code>Version.__init__</code>. The comparison operators now return :py:const:<code>NotImplemented</code> for such operands, following the general rule for invalid comparison operand types: equality evaluates to <code>False</code> and ordering raises Python's standard :py:exc:<code>TypeError</code> (for example, <code>'>' not supported between instances of 'Version' and 'dict'</code>).</p> </li> <li> <p>:pr:<code>480</code>: (:meth:<code>~semver.version.Version.bump_build</code>) will now add <code>.0</code> to an existing build when the last segment of the current build metadata, split by dots (<code>.</code>), is not numeric. This is to ensure the bumped version contains a raised build instead of silently returning an unchanged version. For example, <code>1.2.3+alpha</code> is bumped to <code>1.2.3+alpha.0</code>. This mirrors the corresponding fix for the prerelease part (:gh:<code>460</code>). Related to :gh:<code>466</code>.</p> </li> <li> <p>:gh:<code>460</code>: :meth:<code>~semver.version.Version.bump_prerelease</code> will now add <code>.0</code> to an existing prerelease when the last segment of the current prerelease, split by dots (<code>.</code>), is not numeric. This is to ensure the new prerelease is considered higher than the previous one.</p> <p>:meth:<code>~semver.version.Version.bump_prerelease</code> now also support an argument <code>bump_when_empty</code> which will bump the patch version if there is no existing prerelease, to ensure the resulting version is considered a higher version than the previous one.</p> </li> </ul> <h2>Features</h2> <ul> <li>:pr:<code>476</code>: Added optional <code>[native]</code> extra to accelerate parsing on CPython via the <code>fast-semver-rs-backend</code> package. The pure-Python parser remains the default; the native backend is opt-in and only available on CPython.</li> </ul> <h2>Internal Changes</h2> <p>: Update GitHub Actions for astral-sh/setup-uv (version 0.10.1), github/codeql-action (version 4)</p> <h2>Trivial Changes</h2> <ul> <li>:gh:<code>463</code>: Remove double code in :meth:<code>Version.bump_build</code></li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/python-semver/python-semver/commit/642d1bc8949d38cca7922df478d0f2c06513f99d"><code>642d1bc</code></a> Change version to 3.1.0 (<a href="https://redirect.github.com/python-semver/python-semver/issues/481">#481</a>)</li> <li><a href="https://github.com/python-semver/python-semver/commit/2a2cf632f9b6c6b5731db85284db129e0d07837d"><code>2a2cf63</code></a> Suppress deprecation warnings in test suite</li> <li><a href="https://github.com/python-semver/python-semver/commit/a62477b6113791ed046e71936754e285892fd1ed"><code>a62477b</code></a> Improve comparisons and fix test coverage.</li> <li><a href="https://github.com/python-semver/python-semver/commit/0aa17a3447958cfe13634b0c3917e7aa4eee3334"><code>0aa17a3</code></a> Handle malformed collection operands in Version comparisons (<a href="https://redirect.github.com/python-semver/python-semver/issues/479">#479</a>)</li> <li><a href="https://github.com/python-semver/python-semver/commit/1b7350c1a7cacea983ab10b345990fee78761d44"><code>1b7350c</code></a> Improve test coverage to 100% (Rust backend)</li> <li><a href="https://github.com/python-semver/python-semver/commit/ea2524a51767cefab58a9b3bb6bcf38e5cdc7d54"><code>ea2524a</code></a> Fix bump_build() silently returning an unchanged version for digitless build ...</li> <li><a href="https://github.com/python-semver/python-semver/commit/1e8757912f633684e1a65d9d7c7e2270c3c79928"><code>1e87579</code></a> Reject non-ASCII digits and trailing newlines in version parsing (<a href="https://redirect.github.com/python-semver/python-semver/issues/478">#478</a>)</li> <li><a href="https://github.com/python-semver/python-semver/commit/0f18aa0b1e0cabba65ee1b506e637faabcdf5d05"><code>0f18aa0</code></a> Add optional native parser backend (minimal adapter) (<a href="https://redirect.github.com/python-semver/python-semver/issues/476">#476</a>)</li> <li><a href="https://github.com/python-semver/python-semver/commit/873a6750f22e82f72fb7c8c4a1ebe958beaa2f1a"><code>873a675</code></a> Declare support for Python 3.15 (<a href="https://redirect.github.com/python-semver/python-semver/issues/475">#475</a>)</li> <li><a href="https://github.com/python-semver/python-semver/commit/99d2032c8f7ef4895df25053ddcdcb85d5460326"><code>99d2032</code></a> Bump cryptography from 49.0.0 to 50.0.0 (<a href="https://redirect.github.com/python-semver/python-semver/issues/473">#473</a>)</li> <li>Additional commits viewable in <a href="https://github.com/python-semver/python-semver/compare/3.0.4...3.1.0">compare view</a></li> </ul> </details> <br /> Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore <dependency name> major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself) - `@dependabot ignore <dependency name> minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself) - `@dependabot ignore <dependency name>` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself) - `@dependabot unignore <dependency name>` will remove all of the ignore conditions of the specified dependency - `@dependabot unignore <dependency name> <ignore condition>` will remove the ignore condition of the specified dependency and ignore conditions </details> -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
