Skip to content

[UV] Bump the uv group with 10 updates - #718

Merged
tagdots-owner merged 1 commit into
mainfrom
dependabot/uv/uv-62b0d596a4
Oct 5, 2026
Merged

tagdots-owner merged 1 commit into
mainfrom
dependabot/uv/uv-62b0d596a4

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 4, 2026

Copy link
Copy Markdown
Contributor

Bumps the uv group with 10 updates:

Package From To
commitizen 4.18.1 4.19.0
coverage 7.16.1 7.16.2
charset-normalizer 3.5.1 3.5.2
cryptography 50.0.1 50.0.2
identify 2.6.19 2.6.20
nodeenv 1.10.0 1.11.0
platformdirs 4.11.12 4.12.0
pyjwt 2.14.0 2.15.0
virtualenv 21.8.1 21.13.0
wcwidth 0.8.5 0.9.1

Updates commitizen from 4.18.1 to 4.19.0

Release notes

Sourced from commitizen's releases.

v4.19.0 (2026-09-22)

Feat

  • add extensible commit filters
Changelog

Sourced from commitizen's changelog.

v4.19.0 (2026-09-22)

Feat

  • add extensible commit filters
Commits
  • 3f5ccc8 bump: version 4.18.1 → 4.19.0
  • 07c9745 feat: add extensible commit filters
  • f0c7c6b ci(deps): bump soupsieve from 2.8.4 to 2.9 (#2091)
  • 100bfe3 ci: remove redundant incremental changelog setting
  • 4967717 ci(deps): bump dawidd6/action-homebrew-bump-formula from 8 to 10 (#2087)
  • 543250f docs(cli/screenshots): update CLI screenshots
  • See full diff in compare view

Updates coverage from 7.16.1 to 7.16.2

Release notes

Sourced from coverage's releases.

7.16.2

Version 7.16.2 — 2026-09-27

  • Fix: on Python 3.14 and later, a for loop completing immediately before a function return could mistakenly report an uncovered branch. This is now fixed, closing issue 2168.
  • Fix: on Python 3.14 and later, the else clause of a try whose body is a with statement could incorrectly be reported as covered when the with raised. This is now fixed, closing issue 2289.
  • Fix: with dynamic_context = test_function, test methods written as @staticmethod or @classmethod were not given a context of their own. Now they are, on Python 3.11 and later. Closes issue 1923.

➡️  PyPI page: coverage 7.16.2. :arrow_right:  To install: python3 -m pip install coverage==7.16.2

Changelog

Sourced from coverage's changelog.

Version 7.16.2 — 2026-09-27

  • Fix: on Python 3.14 and later, a for loop completing immediately before a function return could mistakenly report an uncovered branch. This is now fixed, closing issue 2168_.

  • Fix: on Python 3.14 and later, the else clause of a try whose body is a with statement could incorrectly be reported as covered when the with raised. This is now fixed, closing issue 2289_.

  • Fix: with dynamic_context = test_function, test methods written as @staticmethod or @classmethod were not given a context of their own. Now they are, on Python 3.11 and later. Closes issue 1923_.

.. _issue 1923: coveragepy/coveragepy#1923 .. _issue 2168: coveragepy/coveragepy#2168 .. _issue 2289: coveragepy/coveragepy#2289

.. _changes_7-16-1:

Commits

Updates charset-normalizer from 3.5.1 to 3.5.2

Release notes

Sourced from charset-normalizer's releases.

Version 3.5.2

3.5.2 (2026-09-29)

Changed

  • Raised the Cython upper bound to <3.4 for native builds. The bound remains <3.3 for abi3 builds to preserve compatibility with the Python 3.7 Limited API.

Fixed

  • Valid UTF-8 Chinese JSON incorrectly detected as PTCP154 due to excessive noise penalties for uncommon CJK characters. (#796)
  • Supported encodings without aliases failing name resolution or being ignored in charset declarations. (#800)
Changelog

Sourced from charset-normalizer's changelog.

3.5.2 (2026-09-29)

Changed

  • Raised the Cython upper bound to <3.4 for native builds. The bound remains <3.3 for abi3 builds to preserve compatibility with the Python 3.7 Limited API.

Fixed

  • Valid UTF-8 Chinese JSON incorrectly detected as PTCP154 due to excessive noise penalties for uncommon CJK characters. (#796)
  • Supported encodings without aliases failing name resolution or being ignored in charset declarations. (#800)
Commits
  • 935c29a Release 3.5.2 (#805)
  • 9d3238a test: disable traefik in downstream niquests
  • b4c0368 docs: write changelog entry for 3.5.2
  • 717da31 chore: bump version to 3.5.2
  • 264895d chore: update pypa/cibuildwheel and pypa/gh-action-pypi-publish
  • 41e28b6 chore: raise Cython upper bound to 3.3
  • b130b7d Fix valid UTF-8 Chinese JSON misdetected as PTCP154 (#796)
  • f6afd31 Make the IANA_NO_ALIASES encodings resolvable by name (#800)
  • See full diff in compare view

Updates cryptography from 50.0.1 to 50.0.2

Changelog

Sourced from cryptography's changelog.

50.0.2 - 2026-09-30


* Updated Windows, macOS, and Linux wheels to be compiled with OpenSSL 4.0.3.
* Added ``abi3.abi3t`` wheels for free-threaded CPython 3.15 and later.
* Updated to PyO3 0.29.2, which fixes building ``cryptography`` on Cygwin and
  MSYS2.

.. _v50-0-1:

Commits

Updates identify from 2.6.19 to 2.6.20

Commits
  • aa34031 v2.6.20
  • 116099f Merge pull request #609 from Malix-Labs/feat/add-nushell
  • 971546c Merge pull request #610 from pre-commit/lock-file-tags
  • da45cb1 Add support for 'nu' extension and Nushell interpreters
  • a35b99b Merge pull request #608 from steovd/profile-sh
  • bd5cdb7 Merge pull request #601 from ngie-eign/issue-258
  • 66faf04 Merge pull request #597 from edgarrmondragon/patch-1
  • c75a0a2 Merge pull request #593 from NinjaMandalorian/main
  • ea6c9f9 Add support for 'luau' file extension
  • d28c571 Merge pull request #585 from Kvan7/patch-1
  • Additional commits viewable in compare view

Updates nodeenv from 1.10.0 to 1.11.0

Release notes

Sourced from nodeenv's releases.

1.11.0

What's Changed

New Features 🎉

Fixed bugs 🐛

Improvements 🛠

Documentation 📄

Other Changes

New Contributors

Full Changelog: ekalinin/nodeenv@1.10.0...1.11.0

Changelog

Sourced from nodeenv's changelog.

Version 1.11.0

  • Fixed zsh source bin/activate aborting on the direct-call guard [#398](https://github.com/ekalinin/nodeenv/issues/398) <https://github.com/ekalinin/nodeenv/issues/398>_
  • Added check for how activate is called [#384](https://github.com/ekalinin/nodeenv/issues/384) <https://github.com/ekalinin/nodeenv/pull/384>_
  • Addressed the tarfile.extractall deprecation on Python >= 3.12 by setting filter='data', which also prevents writing files via ".." or absolute paths [#380](https://github.com/ekalinin/nodeenv/issues/380) <https://github.com/ekalinin/nodeenv/pull/380>_
  • Added support for Solaris/illumos [#360](https://github.com/ekalinin/nodeenv/issues/360) <https://github.com/ekalinin/nodeenv/issues/360>_
  • Added predeactivate hooks for Windows
  • Added error handling and tests for the node installation [#336](https://github.com/ekalinin/nodeenv/issues/336) <https://github.com/ekalinin/nodeenv/issues/336>_
  • Removed the leftover debug print that leaked a dict to stdout on every version detection [#390](https://github.com/ekalinin/nodeenv/issues/390) <https://github.com/ekalinin/nodeenv/issues/390>_
  • Added --with-certifi to download packages with the certifi certificate bundle [#388](https://github.com/ekalinin/nodeenv/issues/388) <https://github.com/ekalinin/nodeenv/pull/388>_
  • --node accepts npm-style semver ranges [#393](https://github.com/ekalinin/nodeenv/issues/393) <https://github.com/ekalinin/nodeenv/pull/393>_
  • Added --prefer-system to use system-wide node.js when available and install one otherwise [#153](https://github.com/ekalinin/nodeenv/issues/153) <https://github.com/ekalinin/nodeenv/issues/153>_
  • Added --isolate-npm to keep npm cache, userconfig and init-module inside the environment [#154](https://github.com/ekalinin/nodeenv/issues/154) <https://github.com/ekalinin/nodeenv/issues/154>_
  • Added tests that run the activation scripts in sh, dash, bash, zsh and fish.
  • -p no longer reinstalls node when the requested version is already in the virtualenv [#159](https://github.com/ekalinin/nodeenv/issues/159) <https://github.com/ekalinin/nodeenv/issues/159>_
  • Repeated -p runs no longer duplicate the predeactivate hook [#159](https://github.com/ekalinin/nodeenv/issues/159) <https://github.com/ekalinin/nodeenv/issues/159>_
  • -p accepts an optional virtualenv directory and prefers the activated VIRTUAL_ENV over the virtualenv nodeenv itself is installed in [#156](https://github.com/ekalinin/nodeenv/issues/156) <https://github.com/ekalinin/nodeenv/issues/156>_
  • -r/--requirements may now be given more than once, and the new --local-requirements installs the packages of a file locally, into "node_modules" of the current directory, which is what freeze -l writes. Under npm < 1.0.0, which has no -g, a local file is still installed the old way [#206](https://github.com/ekalinin/nodeenv/issues/206) <https://github.com/ekalinin/nodeenv/issues/206>_
  • The "src" directory is now removed after installation by default, which halves the size of an environment. Added --no-clean-src to keep it: with --source that is what lets a repeated --force build reuse the downloaded source tree [#205](https://github.com/ekalinin/nodeenv/issues/205) <https://github.com/ekalinin/nodeenv/issues/205>_
  • Documented that --mirror takes a file:// URL, so a local directory can serve as the download source [#193](https://github.com/ekalinin/nodeenv/issues/193) <https://github.com/ekalinin/nodeenv/issues/193>_
  • The posix activate is now written on Windows too, into "Scripts", so git-bash and the other posix shells there can activate an environment [#226](https://github.com/ekalinin/nodeenv/issues/226) <https://github.com/ekalinin/nodeenv/issues/226>_
  • A download that reaches nothing at all, which a broken http_proxy or https_proxy usually causes, now reports the url and the proxy settings instead of a traceback

... (truncated)

Commits
  • e745358 Merge pull request #418 from ekalinin/chore/release-1.11.0
  • fd19956 chore(release): bump nodeenv version to 1.11.0
  • 1767015 Merge pull request #415 from ekalinin/fix/nodejs-exe-link
  • 55df3ce Merge pull request #417 from r3wretrhy/fix/zsh-activate-source-guard
  • bb15c5c fix: allow zsh to source bin/activate
  • 152cd3d fix(nodeenv): link nodejs.exe without mklink
  • d163302 Merge pull request #414 from ekalinin/fix/freeze-requirements
  • ef5ec35 fix(nodeenv): read npm's parseable listing in freeze
  • b1f0c54 Merge pull request #413 from ekalinin/fix/musl-vendor-detection
  • aadf307 fix(nodeenv): detect musl regardless of the host triplet vendor
  • Additional commits viewable in compare view

Updates platformdirs from 4.11.12 to 4.12.0

Release notes

Sourced from platformdirs's releases.

4.12.0

What's Changed

Full Changelog: tox-dev/platformdirs@4.11.15...4.12.0

4.11.15

What's Changed

Full Changelog: tox-dev/platformdirs@4.11.14...4.11.15

4.11.14

What's Changed

... (truncated)

Changelog

Sourced from platformdirs's changelog.

########### Changelog ###########

.. towncrier-draft-entries:: Unreleased

.. towncrier release notes start


4.12.3 (2026-10-03)


  • Place files from place_config_file and place_data_file in the first site directory for root on Unix with use_site_for_root=True and multipath=True, where find_config_file and find_data_file look for them. :pr:607

4.12.2 (2026-09-29)


  • Keep os.pathsep in site_applications_path under multipath=True on platforms with one applications directory. :pr:604

4.12.1 (2026-09-28)


  • Avoid PytestAssertRewriteWarning when importing platformdirs before invoking pytest. :pr:601

4.12.0 (2026-09-26)


  • Add place_*_file methods that return a file path under a user directory and create its missing parents with mode 0o700. :pr:585
  • Add find_<kind>_file and find_<kind>_files to look up an existing file across the user and site directories of each kind that has an iter_<kind>_paths method. :pr:586
  • Add :func:platformdirs.testing.isolated_dirs and the platformdirs_isolated pytest fixture to resolve every directory under one test root. :pr:590
  • Emit :class:~platformdirs.RuntimeDirWarning when the Unix :func:~platformdirs.user_runtime_dir falls back from XDG_RUNTIME_DIR. :pr:599
  • Read user_templates_dir, user_publicshare_dir and user_bin_dir on Windows from their known folders. :pr:587
  • Create missing user app directories and their parents with mode 0700 under ensure_exists on POSIX platforms. :pr:588
  • Raise RuntimeError for a Unix or macOS directory under the home when no home resolves, and read the password database for an empty HOME. :pr:589
  • Skip an XDG_RUNTIME_DIR or /run/user/<uid> that is not a private directory of the user, and reject a symlink or file as the runtime-<uid> fallback. :pr:599
  • Use the app container layout on iOS, such as ~/Library/Application Support for data. :pr:600

... (truncated)

Commits
  • ea7be87 Release 4.12.0
  • de46f51 🐛 fix(unix): validate XDG_RUNTIME_DIR and warn on fallback (#599)
  • ca2b313 🐛 fix(dirs): raise when no home directory resolves (#589)
  • c34e758 🐛 fix(dirs): create user directories with mode 0700 (#588)
  • f88693c ✨ feat(api): add find_*_file methods for user and site lookup (#586)
  • ba1cc1e 🐛 fix(windows): resolve templates, public and bin dirs by known folder (#587)
  • 9f2ee08 ✨ feat(testing): redirect every directory under a test root (#590)
  • dfaeabf ✨ feat(api): add place_*_file methods that create parents as 0700 (#585)
  • 46843f1 🐛 fix(ios): use the iOS app container instead of Linux XDG paths (#600)
  • 6a439b3 📝 docs(macos): fix the Homebrew site dir note (#591)
  • Additional commits viewable in compare view

Updates pyjwt from 2.14.0 to 2.15.0

Release notes

Sourced from pyjwt's releases.

2.15.0

See the 2.15.0 changelog for complete release details.

Changelog

Sourced from pyjwt's changelog.

v2.15.0 <https://github.com/jpadilla/pyjwt/compare/2.14.0...2.15.0>__

Security


- Wrap recursion errors from deeply nested JWT payloads in ``DecodeError``
  instead of exposing a raw ``RecursionError``.

Added


- Support Python 3.15 by @kytta in `[#1202](https://github.com/jpadilla/pyjwt/issues/1202) &lt;https://github.com/jpadilla/pyjwt/pull/1202&gt;`__

Changed

  • JWKSetCache now stores the parsed PyJWKSet rather than the raw JWKS payload, so a cache hit no longer re-parses every key. JWKSetCache.put() accepts either form and raises PyJWKSetError for anything else. As a result, PyJWKClient.get_jwk_set() returns the same PyJWKSet instance for as long as it stays cached, rather than a freshly built one per call in [#1208](https://github.com/jpadilla/pyjwt/issues/1208) &lt;https://github.com/jpadilla/pyjwt/pull/1208&gt;__
  • PyJWKClient.fetch_data() now raises PyJWKClientError(&quot;The JWKS endpoint did not return a JSON object&quot;) when the endpoint response is not a JSON object, instead of returning it for get_jwk_set() to reject. Callers reaching the JWKS through get_jwk_set() see the same error as before in [#1208](https://github.com/jpadilla/pyjwt/issues/1208) &lt;https://github.com/jpadilla/pyjwt/pull/1208&gt;__

Fixed


- Return cached ``PyJWKSet`` values from ``PyJWKClient.get_jwk_set()`` instead
  of raising ``PyJWKClientError(&quot;The JWKS endpoint did not return a JSON
  object&quot;)``. ``JWKSetCache.put()`` documents ``PyJWKSet`` as the cached value,
  so callers pre-populating the cache to avoid a network round-trip could not
  read it back in `[#914](https://github.com/jpadilla/pyjwt/issues/914) &lt;https://github.com/jpadilla/pyjwt/issues/914&gt;`__ and
  `[#1208](https://github.com/jpadilla/pyjwt/issues/1208) &lt;https://github.com/jpadilla/pyjwt/pull/1208&gt;`__
- ``PyJWKClient.get_jwk_set()`` now caches the key set it returns, so a
  ``fetch_data()`` override that filters or transforms the JWKS is no longer
  undone by the next cache hit in
  `[#1208](https://github.com/jpadilla/pyjwt/issues/1208) &lt;https://github.com/jpadilla/pyjwt/pull/1208&gt;`__
- Raise the documented ``PyJWTError`` subclass instead of leaking a
  ``TypeError`` when the ``exp``, ``nbf``, or ``iat`` claim decodes to a
  non-numeric, non-string value such as a list, dict, or ``null``.
- Reject OKP JWK private keys when their public ``x`` component does not
  match the private ``d`` component.
- Treat malformed JWK Set members as unusable keys rather than letting
  ``AttributeError`` or ``TypeError`` escape ``PyJWKSet``. A member that is not
&lt;/tr&gt;&lt;/table&gt; 
</code></pre>
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>

<ul>
<li><a href="https://github.com/jpadilla/pyjwt/commit/1d41a6478e1562e68ff667fcd703356acf085f68&quot;&gt;&lt;code&gt;1d41a64&lt;/code&gt;&lt;/a> chore: prepare 2.15.0 release</li>
<li><a href="https://github.com/jpadilla/pyjwt/commit/9bc06658f875b9b40091539140bbbdc4639161c3&quot;&gt;&lt;code&gt;9bc0665&lt;/code&gt;&lt;/a> fix: make recursive payload tests deterministic</li>
<li><a href="https://github.com/jpadilla/pyjwt/commit/5fde08a6cf906aa7698de2d6391d88b73006b17b&quot;&gt;&lt;code&gt;5fde08a&lt;/code&gt;&lt;/a> fix: normalize recursive JWT payload errors</li>
<li><a href="https://github.com/jpadilla/pyjwt/commit/171062d2d734315272a901100aa4b109f2fc3c19&quot;&gt;&lt;code&gt;171062d&lt;/code&gt;&lt;/a> utils: mention bytes in force_bytes type error (<a href="https://redirect.github.com/jpadilla/pyjwt/issues/1173&quot;&gt;#1173&lt;/a&gt;)&lt;/li>
<li><a href="https://github.com/jpadilla/pyjwt/commit/c9d4d5375bf464ef363506fed9eb6e7f33217ab6&quot;&gt;&lt;code&gt;c9d4d53&lt;/code&gt;&lt;/a> docs/conf: drop duplicate 'and' from read() docstring (<a href="https://redirect.github.com/jpadilla/pyjwt/issues/1174&quot;&gt;#1174&lt;/a&gt;)&lt;/li>
<li><a href="https://github.com/jpadilla/pyjwt/commit/2763752196113e1473b0ed7905aa6034aedfbe53&quot;&gt;&lt;code&gt;2763752&lt;/code&gt;&lt;/a> Add support for Python 3.15 (<a href="https://redirect.github.com/jpadilla/pyjwt/issues/1202&quot;&gt;#1202&lt;/a&gt;)&lt;/li>
<li><a href="https://github.com/jpadilla/pyjwt/commit/4adcd02722f5011c60079d3978dfc167b9a8eaa5&quot;&gt;&lt;code&gt;4adcd02&lt;/code&gt;&lt;/a> Catch http.client.HTTPException in PyJWKClient.fetch_data (<a href="https://redirect.github.com/jpadilla/pyjwt/issues/1201&quot;&gt;#1201&lt;/a&gt;)&lt;/li>
<li><a href="https://github.com/jpadilla/pyjwt/commit/9e501d993b4d3e7dba14bdb1722b1d993ac75097&quot;&gt;&lt;code&gt;9e501d9&lt;/code&gt;&lt;/a> fix: correct docstring typo in _validate_jti (<a href="https://redirect.github.com/jpadilla/pyjwt/issues/1179&quot;&gt;#1179&lt;/a&gt;)&lt;/li>
<li><a href="https://github.com/jpadilla/pyjwt/commit/4047c44d51950ffda15f40054508d3f17c43b1e2&quot;&gt;&lt;code&gt;4047c44&lt;/code&gt;&lt;/a> docs: clarify JWK certificate member handling (<a href="https://redirect.github.com/jpadilla/pyjwt/issues/1212&quot;&gt;#1212&lt;/a&gt;)&lt;/li>
<li><a href="https://github.com/jpadilla/pyjwt/commit/f4e2b59f543cc82d46d9d69922bba59e804216b9&quot;&gt;&lt;code&gt;f4e2b59&lt;/code&gt;&lt;/a> [pre-commit.ci] pre-commit autoupdate (<a href="https://redirect.github.com/jpadilla/pyjwt/issues/1210&quot;&gt;#1210&lt;/a&gt;)&lt;/li>
<li>Additional commits viewable in <a href="https://github.com/jpadilla/pyjwt/compare/2.14.0...2.15.0&quot;&gt;compare view</a></li>
</ul>
</details>

<br />

Updates virtualenv from 21.8.1 to 21.13.0

Release notes

Sourced from virtualenv's releases.

21.13.0

What's Changed

New Contributors

Full Changelog: https://github.com/pypa/virtualenv/compare/21.12.1...21.13.0

21.12.1

What's Changed

Full Changelog: https://github.com/pypa/virtualenv/compare/21.12.0...21.12.1

21.12.0

What's Changed

Full Changelog: https://github.com/pypa/virtualenv/compare/21.11.1...21.12.0

21.11.1

What's Changed

... (truncated)

Changelog

Sourced from virtualenv's changelog.

Features - 21.13.0

  • Add Changelog and Funding links to the PyPI project metadata, and replace the 2020-202x placeholder in LICENSE with 2020-present so the copyright field of the wheel SBOM reads as a real range - by :user:gaborbernat. (:issue:3334)

Bugfixes - 21.13.0

  • Escape the curly single quotes U+2018-U+201B in the PowerShell activator's quote so a virtual environment prompt, name or Tcl/Tk library path containing them can no longer close the string literal and run commands - by :user:gaborbernat. (:issue:3325)
  • Stop the bash activator from re-expanding the prompt inside PS1, so a virtual environment name or --prompt value containing $(...), backticks or backslashes no longer runs as a command each time bash draws the prompt - by :user:gaborbernat. (:issue:3326)

Improved Documentation - 21.13.0

  • Correct the documented changelog fragment types and example to match the enforced towncrier categories. (:issue:3323)
  • List the Unlicense and the SPDX BSD variants in the runtime dependency licensing policy, matching the filelock releases virtualenv installs on Python 3.9, and describe the dependency review check that enforces the policy. (:issue:3329)
  • Show how to check a release with gh release verify and gh release verify-asset, and how to rebuild the zipapp byte for byte with the build tool versions its SBOMs list. Drop the claims that the zipapp build does not pin the distributions it bundles and that wheels differ between build machines - by :user:gaborbernat. (:issue:3330)

v21.12.1 (2026-09-24)


Bugfixes - 21.12.1

  • Limit the :PEP:832 .venv redirect to folders holding a pyproject.toml and no .venv yet, so virtualenv foo in a scratch folder, and tools such as tox or nox building environments through virtualenv, no longer claim a folder's default environment - by :user:gaborbernat.

    • --venv-redirect writes the redirect in any folder and replaces an earlier virtualenv redirect.
    • A flag on the command line overrides the environment variable and the config file in either direction. (:issue:3316)

v21.12.0 (2026-09-24)


Features - 21.12.0

... (truncated)

Commits
  • 14859e6 release 21.13.0
  • c83f49e 👷 ci(deps): review dependency licenses and advisories on pull requests (#3329)
  • 9cbed16 👷 ci(upgrade): bump the GraalPy test version weekly (#3332)
  • 7e36e66 📝 docs(release): refresh release verification docs (#3330)
  • 07dcf29 🔧 build(meta): add Changelog and Funding project URLs (#3334)
  • dbf474d 🔧 build(docs): pin Mermaid and bump it weekly (#3333)
  • a70c1da 🐛 fix(activation): stop bash re-expanding the prompt in PS1 (#3326)
  • ffb86b7 👷 ci(check): gate required checks behind one job (#3328)
  • 1ef46f1 👷 ci(codeql): scan the tasks scripts (#3327)
  • 876c5ba 🐛 fix(activation): escape PowerShell curly single quotes (#3325)
  • Additional commits viewable in compare view

Updates wcwidth from 0.8.5 to 0.9.1

Release notes

Sourced from wcwidth's releases.

0.9.1

What's Changed

Full Changelog: https://github.com/jquast/wcwidth/compare/0.9.0...0.9.1

0.9.0: Python build extension

What's Changed

Full Changelog: https://github.com/jquast/wcwidth/compare/0.8.5...0.9.0

Changelog

Sourced from wcwidth's changelog.

0.9.1 2026-09-23

  • Bugfix width()_ in Python and libwcwidth mis-measured CSI sequences over 64 bytes, a 0.9.0 release regression! PR [#271](https://github.com/jquast/wcwidth/issues/271)_.
  • Performance improvement of ~15% for many Python API functions when using default arguments like ambiguous_width and term_program. PR [#273](https://github.com/jquast/wcwidth/issues/273)_

0.9.0 2026-09-23

  • New Optional CPython extension using libwcwidth_, improving performance 10-58x PR [#248](https://github.com/jquast/wcwidth/issues/248)_.
  • Drop Support for Python 3.8, PR [#248](https://github.com/jquast/wcwidth/issues/248)_.
Commits

Bumps the uv group with 10 updates:

| Package | From | To |
| --- | --- | --- |
| [commitizen](https://github.com/commitizen-tools/commitizen) | `4.18.1` | `4.19.0` |
| [coverage](https://github.com/coveragepy/coveragepy) | `7.16.1` | `7.16.2` |
| [charset-normalizer](https://github.com/jawah/charset_normalizer) | `3.5.1` | `3.5.2` |
| [cryptography](https://github.com/pyca/cryptography) | `50.0.1` | `50.0.2` |
| [identify](https://github.com/pre-commit/identify) | `2.6.19` | `2.6.20` |
| [nodeenv](https://github.com/ekalinin/nodeenv) | `1.10.0` | `1.11.0` |
| [platformdirs](https://github.com/tox-dev/platformdirs) | `4.11.12` | `4.12.0` |
| [pyjwt](https://github.com/jpadilla/pyjwt) | `2.14.0` | `2.15.0` |
| [virtualenv](https://github.com/pypa/virtualenv) | `21.8.1` | `21.13.0` |
| [wcwidth](https://github.com/jquast/wcwidth) | `0.8.5` | `0.9.1` |


Updates `commitizen` from 4.18.1 to 4.19.0
- [Release notes](https://github.com/commitizen-tools/commitizen/releases)
- [Changelog](https://github.com/commitizen-tools/commitizen/blob/master/CHANGELOG.md)
- [Commits](commitizen-tools/commitizen@v4.18.1...v4.19.0)

Updates `coverage` from 7.16.1 to 7.16.2
- [Release notes](https://github.com/coveragepy/coveragepy/releases)
- [Changelog](https://github.com/coveragepy/coveragepy/blob/main/CHANGES.rst)
- [Commits](coveragepy/coveragepy@7.16.1...7.16.2)

Updates `charset-normalizer` from 3.5.1 to 3.5.2
- [Release notes](https://github.com/jawah/charset_normalizer/releases)
- [Changelog](https://github.com/jawah/charset_normalizer/blob/master/CHANGELOG.md)
- [Commits](jawah/charset_normalizer@3.5.1...3.5.2)

Updates `cryptography` from 50.0.1 to 50.0.2
- [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst)
- [Commits](pyca/cryptography@50.0.1...50.0.2)

Updates `identify` from 2.6.19 to 2.6.20
- [Commits](pre-commit/identify@v2.6.19...v2.6.20)

Updates `nodeenv` from 1.10.0 to 1.11.0
- [Release notes](https://github.com/ekalinin/nodeenv/releases)
- [Changelog](https://github.com/ekalinin/nodeenv/blob/master/CHANGES)
- [Commits](ekalinin/nodeenv@1.10.0...1.11.0)

Updates `platformdirs` from 4.11.12 to 4.12.0
- [Release notes](https://github.com/tox-dev/platformdirs/releases)
- [Changelog](https://github.com/tox-dev/platformdirs/blob/main/docs/changelog.rst)
- [Commits](tox-dev/platformdirs@4.11.12...4.12.0)

Updates `pyjwt` from 2.14.0 to 2.15.0
- [Release notes](https://github.com/jpadilla/pyjwt/releases)
- [Changelog](https://github.com/jpadilla/pyjwt/blob/master/CHANGELOG.rst)
- [Commits](jpadilla/pyjwt@2.14.0...2.15.0)

Updates `virtualenv` from 21.8.1 to 21.13.0
- [Release notes](https://github.com/pypa/virtualenv/releases)
- [Changelog](https://github.com/pypa/virtualenv/blob/main/docs/changelog.rst)
- [Commits](pypa/virtualenv@21.8.1...21.13.0)

Updates `wcwidth` from 0.8.5 to 0.9.1
- [Release notes](https://github.com/jquast/wcwidth/releases)
- [Changelog](https://github.com/jquast/wcwidth/blob/master/docs/history.rst)
- [Commits](jquast/wcwidth@0.8.5...0.9.1)

---
updated-dependencies:
- dependency-name: commitizen
  dependency-version: 4.19.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: uv
- dependency-name: coverage
  dependency-version: 7.16.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: uv
- dependency-name: charset-normalizer
  dependency-version: 3.5.2
  dependency-type: indirect
  update-type: version-update:semver-patch
  dependency-group: uv
- dependency-name: cryptography
  dependency-version: 50.0.2
  dependency-type: indirect
  update-type: version-update:semver-patch
  dependency-group: uv
- dependency-name: identify
  dependency-version: 2.6.20
  dependency-type: indirect
  update-type: version-update:semver-patch
  dependency-group: uv
- dependency-name: nodeenv
  dependency-version: 1.11.0
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: uv
- dependency-name: platformdirs
  dependency-version: 4.12.0
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: uv
- dependency-name: pyjwt
  dependency-version: 2.15.0
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: uv
- dependency-name: virtualenv
  dependency-version: 21.13.0
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: uv
- dependency-name: wcwidth
  dependency-version: 0.9.1
  dependency-type: indirect
  update-type: version-update:semver-minor
  dependency-group: uv
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot requested a review from a team as a code owner October 4, 2026 00:21
@dependabot
dependabot Bot requested a review from tagdots-owner October 4, 2026 00:21
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels Oct 4, 2026
@tagdots-owner
tagdots-owner merged commit ba122ae into main Oct 5, 2026
9 checks passed
@tagdots-owner
tagdots-owner deleted the dependabot/uv/uv-62b0d596a4 branch October 5, 2026 07:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code

Development

Successfully merging this pull request may close these issues.

1 participant