Skip to content

chore(deps-dev): bump ruff from 0.11.5 to 0.15.8#806

Closed
dependabot[bot] wants to merge 1 commit intomasterfrom
dependabot/pip/ruff-0.15.8
Closed

chore(deps-dev): bump ruff from 0.11.5 to 0.15.8#806
dependabot[bot] wants to merge 1 commit intomasterfrom
dependabot/pip/ruff-0.15.8

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot bot commented on behalf of github Mar 27, 2026

Bumps ruff from 0.11.5 to 0.15.8.

Release notes

Sourced from ruff's releases.

0.15.8

Release Notes

Released on 2026-03-26.

Preview features

  • [ruff] New rule unnecessary-if (RUF050) (#24114)
  • [ruff] New rule useless-finally (RUF072) (#24165)
  • [ruff] New rule f-string-percent-format (RUF073): warn when using % operator on an f-string (#24162)
  • [pyflakes] Recognize frozendict as a builtin for Python 3.15+ (#24100)

Bug fixes

  • [flake8-async] Use fully-qualified anyio.lowlevel import in autofix (ASYNC115) (#24166)
  • [flake8-bandit] Check tuple arguments for partial paths in S607 (#24080)
  • [pyflakes] Skip undefined-name (F821) for conditionally deleted variables (#24088)
  • E501/W505/formatter: Exclude nested pragma comments from line width calculation (#24071)
  • Fix %foo? parsing in IPython assignment expressions (#24152)
  • analyze graph: resolve string imports that reference attributes, not just modules (#24058)

Rule changes

  • [eradicate] ignore ty: ignore comments in ERA001 (#24192)
  • [flake8-bandit] Treat sys.executable as trusted input in S603 (#24106)
  • [flake8-self] Recognize Self annotation and self assignment in SLF001 (#24144)
  • [pyflakes] F507: Fix false negative for non-tuple RHS in %-formatting (#24142)
  • [refurb] Parenthesize generator arguments in FURB142 fixer (#24200)

Performance

  • Speed up diagnostic rendering (#24146)

Server

  • Warn when Markdown files are skipped due to preview being disabled (#24150)

Documentation

  • Clarify extend-ignore and extend-select settings documentation (#24064)
  • Mention AI policy in PR template (#24198)

Other changes

  • Use trusted publishing for NPM packages (#24171)

Contributors

... (truncated)

Changelog

Sourced from ruff's changelog.

0.15.8

Released on 2026-03-26.

Preview features

  • [ruff] New rule unnecessary-if (RUF050) (#24114)
  • [ruff] New rule useless-finally (RUF072) (#24165)
  • [ruff] New rule f-string-percent-format (RUF073): warn when using % operator on an f-string (#24162)
  • [pyflakes] Recognize frozendict as a builtin for Python 3.15+ (#24100)

Bug fixes

  • [flake8-async] Use fully-qualified anyio.lowlevel import in autofix (ASYNC115) (#24166)
  • [flake8-bandit] Check tuple arguments for partial paths in S607 (#24080)
  • [pyflakes] Skip undefined-name (F821) for conditionally deleted variables (#24088)
  • E501/W505/formatter: Exclude nested pragma comments from line width calculation (#24071)
  • Fix %foo? parsing in IPython assignment expressions (#24152)
  • analyze graph: resolve string imports that reference attributes, not just modules (#24058)

Rule changes

  • [eradicate] ignore ty: ignore comments in ERA001 (#24192)
  • [flake8-bandit] Treat sys.executable as trusted input in S603 (#24106)
  • [flake8-self] Recognize Self annotation and self assignment in SLF001 (#24144)
  • [pyflakes] F507: Fix false negative for non-tuple RHS in %-formatting (#24142)
  • [refurb] Parenthesize generator arguments in FURB142 fixer (#24200)

Performance

  • Speed up diagnostic rendering (#24146)

Server

  • Warn when Markdown files are skipped due to preview being disabled (#24150)

Documentation

  • Clarify extend-ignore and extend-select settings documentation (#24064)
  • Mention AI policy in PR template (#24198)

Other changes

  • Use trusted publishing for NPM packages (#24171)

Contributors

... (truncated)

Commits
  • c2a8815 Release 0.15.8 (#24217)
  • d444d52 [ty] Infer lambda expressions with Callable type context (#22633)
  • 9622285 [ty] Autocomplete arguments if in arguments node (#24167)
  • d812662 Use the release environment in publish-docs (#24214)
  • eda2355 [ty] Show Final source in final assignment diagnostic (#24194)
  • 929eb52 [ty] Enforce Final attribute assignment rules for annotated and augmented wri...
  • 34998be [ty] Fix typo in comment (#24211)
  • 560aca0 [ty] Minor simplifications to some benchmark code (#24209)
  • 683bae5 [ty] Track non-terminal-call constraints in global scope (#23245)
  • 4704c2a [ty] Remove unnecessary intermediate collection in `StaticClassLiteral::field...
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [ruff](https://github.com/astral-sh/ruff) from 0.11.5 to 0.15.8.
- [Release notes](https://github.com/astral-sh/ruff/releases)
- [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md)
- [Commits](astral-sh/ruff@0.11.5...0.15.8)

---
updated-dependencies:
- dependency-name: ruff
  dependency-version: 0.15.8
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added dependencies One or more dependencies are being bumped python Pull requests that update Python code labels Mar 27, 2026
@dependabot dependabot bot requested a review from a team as a code owner March 27, 2026 08:54
@dependabot dependabot bot added dependencies One or more dependencies are being bumped python Pull requests that update Python code labels Mar 27, 2026
kishore7snehil added a commit that referenced this pull request Mar 30, 2026
…rop Python 3.8; replace Snyk with SCA scan (#808)

## Changes

### Python 3.8 Support Dropped

Python 3.8 reached end-of-life in October 2024. Several security-patched
dependency versions (`aiohttp`, `cryptography`, `urllib3`) require
Python >=3.9, making it impossible to keep 3.8 support while applying
security fixes. The previous minimum (`>=3.8`) allowed installation on
Python versions that can only resolve to **vulnerable** dependency
versions.

- Changed `python` from `^3.8` to `>=3.9.2,<4.0` (3.9.0 and 3.9.1 are
excluded by `cryptography` due to known bugs in those patch releases)
- Removed `Programming Language :: Python :: 3.8` classifier from
`pyproject.toml`
- Updated `README.md`, `v5_MIGRATION_GUIDE.md`, and
`github_discussion_v5_announcement.md` to reflect Python >=3.9

### Dependency Updates

#### Python Dependencies - From Dependabot PRs
- Bump `ruff` from `0.11.5` to `0.15.8`
([#806](#806))
- Bump `responses` upper bound from `<0.26.0` to `<0.28.0`
([#786](#786))

#### Python Dependencies - From Security Review
- Update `aiohttp` from `>=3.10.11` to `>=3.11.18` - fixes multiple
CVEs; previous minimum resolved to versions with known vulnerabilities
on Python 3.8
- Update `cryptography` from `>=43.0.1` to `>=44.0.0` - fixes known
vulnerabilities in older versions
- Update `urllib3` from `>=2.2.3` to `>=2.3.0` - fixes known
vulnerabilities; requires Python >=3.9

#### GitHub Actions
- Bump `codecov/codecov-action` from `5.5.1` to `6.0.0` (SHA pin
updated) ([#805](#805))

#### CI Workflow Changes
- Added `sca_scan.yml` - new SCA scan using `auth0/devsecops-tooling`
reusable workflow with `requirements.txt`
- Removed `snyk.yml` - replaced by the new `sca_scan.yml` reusable
workflow
- Removed `docs.yml` - documentation build workflow removed
- Added `.claude/` to `.gitignore`
@dependabot @github
Copy link
Copy Markdown
Contributor Author

dependabot bot commented on behalf of github Mar 30, 2026

Looks like ruff is up-to-date now, so this is no longer needed.

@dependabot dependabot bot closed this Mar 30, 2026
@dependabot dependabot bot deleted the dependabot/pip/ruff-0.15.8 branch March 30, 2026 10:45
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies One or more dependencies are being bumped python Pull requests that update Python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants