Skip to content

chore(deps)(deps): bump the python-dependencies group with 5 updates - #554

Merged
tschm merged 8 commits into
mainfrom
dependabot/uv/python-dependencies-312833862e
Jun 17, 2026
Merged

chore(deps)(deps): bump the python-dependencies group with 5 updates#554
tschm merged 8 commits into
mainfrom
dependabot/uv/python-dependencies-312833862e

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 16, 2026

Copy link
Copy Markdown
Contributor

Bumps the python-dependencies group with 5 updates:

Package From To
cvx-linalg 0.6.2 0.7.0
jquantstats 0.9.3 0.9.6
pytest 9.0.3 9.1.0
hypothesis 6.155.2 6.155.3
ty 0.0.46 0.0.49

Updates cvx-linalg from 0.6.2 to 0.7.0

Release notes

Sourced from cvx-linalg's releases.

v0.7.0

[0.7.0] - 2026-06-11

💼 Other

  • Bump version 0.6.2 → 0.7.0

🚜 Refactor

  • Address code-quality, packaging, and API consistency issues (#50)

⚙️ Miscellaneous Tasks

  • Update CHANGELOG.md for v0.6.2 [skip ci]

PyPI Package

cvx-linalg

Conda Recipe

A conda-forge recipe was generated with grayskull and uploaded as the conda-recipe workflow artifact.

Changelog

Sourced from cvx-linalg's changelog.

[0.7.0] - 2026-06-11

💼 Other

  • Bump version 0.6.2 → 0.7.0

🚜 Refactor

  • Address code-quality, packaging, and API consistency issues (#50)

⚙️ Miscellaneous Tasks

  • Update CHANGELOG.md for v0.6.2 [skip ci]
Commits
  • a2be383 Chore: bump version 0.6.2 → 0.7.0
  • 75ab48d refactor: address code-quality, packaging, and API consistency issues (#50)
  • db50246 chore(deps-dev)(deps-dev): bump the python-dependencies group with 3 updates ...
  • 881715b chore(deps)(deps): bump actions/checkout in the github-actions group (#48)
  • a8e91b7 chore: update CHANGELOG.md for v0.6.2 [skip ci]
  • See full diff in compare view

Updates jquantstats from 0.9.3 to 0.9.6

Release notes

Sourced from jquantstats's releases.

v0.9.6

[0.9.6] - 2026-06-13

💼 Other

  • Bump version 0.9.5 → 0.9.6

⚙️ Miscellaneous Tasks

  • Update CHANGELOG.md for v0.9.5 [skip ci]

PyPI Package

jquantstats

Conda Recipe

A conda-forge recipe was generated with grayskull and uploaded as the conda-recipe workflow artifact.

v0.9.5

[0.9.5] - 2026-06-12

🐛 Bug Fixes

  • Warn when benchmark alignment drops rows, loosen kaleido pin
  • Raise timeout for kaleido tests to absorb Chrome cold-start

💼 Other

  • Bump version 0.9.4 → 0.9.5

⚙️ Miscellaneous Tasks

  • Update CHANGELOG.md for v0.9.4 [skip ci]

PyPI Package

jquantstats

Conda Recipe

A conda-forge recipe was generated with grayskull and uploaded as the conda-recipe workflow artifact.

v0.9.4

[0.9.4] - 2026-06-12

🚀 Features

  • Typed stat decorators, snapshot tests, docs FAQ/diagrams, protocol dedup

... (truncated)

Changelog

Sourced from jquantstats's changelog.

[0.9.6] - 2026-06-13

💼 Other

  • Bump version 0.9.5 → 0.9.6

⚙️ Miscellaneous Tasks

  • Update CHANGELOG.md for v0.9.5 [skip ci]

[0.9.5] - 2026-06-12

🐛 Bug Fixes

  • Warn when benchmark alignment drops rows, loosen kaleido pin
  • Raise timeout for kaleido tests to absorb Chrome cold-start

💼 Other

  • Bump version 0.9.4 → 0.9.5

⚙️ Miscellaneous Tasks

  • Update CHANGELOG.md for v0.9.4 [skip ci]

[0.9.4] - 2026-06-12

🚀 Features

  • Typed stat decorators, snapshot tests, docs FAQ/diagrams, protocol dedup

🐛 Bug Fixes

  • CAGR sign flip in reports, accept integer rf, harden API endpoint (#791)
  • Harden public API, messaged exceptions, numerical edge-case docs, 100% coverage gate
  • Move coverage gate to custom-env.mk so rhiza validation passes

💼 Other

  • Bump version 0.9.3 → 0.9.4

🧪 Testing

  • Increase coverage to 100%

⚙️ Miscellaneous Tasks

  • Update CHANGELOG.md for v0.9.3 [skip ci]
  • Bump rhiza to v0.18.8 (#788)
Commits
  • 5fcc3cf Chore: bump version 0.9.5 → 0.9.6
  • 3f6a8e2 Round 3 quality: input validation, mutation-gated baseline, PR benchmarks, ar...
  • b838307 chore: update CHANGELOG.md for v0.9.5 [skip ci]
  • 79c6621 Chore: bump version 0.9.4 → 0.9.5
  • ea12eb6 fix: raise timeout for kaleido tests to absorb Chrome cold-start
  • 2512727 fix: warn when benchmark alignment drops rows, loosen kaleido pin
  • 724ce8c chore: update CHANGELOG.md for v0.9.4 [skip ci]
  • e393af8 Chore: bump version 0.9.3 → 0.9.4
  • a3170de Round 2 quality: API observability & auth, branch coverage + mutation pass, d...
  • 04c551d feat: typed stat decorators, snapshot tests, docs FAQ/diagrams, protocol dedup
  • Additional commits viewable in compare view

Updates pytest from 9.0.3 to 9.1.0

Release notes

Sourced from pytest's releases.

9.1.0

pytest 9.1.0 (2026-06-13)

Removals and backward incompatible breaking changes

  • #14533: When using --doctest-modules, autouse fixtures with module, package or session scope that are defined inline in Python test modules (not plugins or conftests) will now possibly execute twice.

    If this is undesirable, move the fixture definition to a conftest.py file if possible.

    Technical explanation for those interested: When using --doctest-modules, pytest possibly collects Python modules twice, once as pytest.Module and once as a DoctestModule (depending on the configuration). Due to improvements in pytest's fixture implementation, if e.g. the DoctestModule collects a fixture, it is now visible to it only, and not to the Module. This means that both need to register the fixtures independently.

Deprecations (removal in next major release)

  • #10819: Added a deprecation warning for class-scoped fixtures defined as instance methods (without @classmethod). Such fixtures set attributes on a different instance than the test methods use, leading to unexpected behavior. Use @classmethod decorator instead -- by yastcher.

    See 10819 and 14011.

  • #12882: Calling request.getfixturevalue() <pytest.FixtureRequest.getfixturevalue> during teardown to request a fixture that was not already requested is now deprecated and will become an error in pytest 10.

    See dynamic-fixture-request-during-teardown for details.

  • #13409: Using non-~collections.abc.Collection iterables (such as generators, iterators, or custom iterable objects) for the argvalues parameter in @pytest.mark.parametrize <pytest.mark.parametrize ref> and metafunc.parametrize <pytest.Metafunc.parametrize> is now deprecated.

    These iterables get exhausted after the first iteration, leading to tests getting unexpectedly skipped in cases such as running pytest.main() multiple times, using class-level parametrize decorators, or collecting tests multiple times.

    See parametrize-iterators for details and suggestions.

  • #13946: The private config.inicfg attribute is now deprecated. Use config.getini() <pytest.Config.getini> to access configuration values instead.

    See config-inicfg for more details.

  • #14004: Passing baseid to ~pytest.FixtureDef or nodeid strings to fixture registration APIs is now deprecated. These are internal pytest APIs that are used by some plugins.

    Use the node parameter instead for fixture scoping. This enables more robust node-based matching instead of string prefix matching. If you've used nodeid=None, pass node=session instead.

    This will be removed in pytest 10.

  • #14335: The method of configuring hooks using markers, deprecated since pytest 7.2, is now scheduled to be removed in pytest 10. See hook-markers for more details.

  • #14434: The --pastebin option is now deprecated.

... (truncated)

Commits
  • b2522cf Prepare release version 9.1.0
  • 368d2fc [refactor] Tighten SetComparisonFunction to Iterator[str] (#14587)
  • ff77cd8 [refactor] Make base assertion comparisons return an iterator instead of a li...
  • 0d8491a build(deps): Bump actions/stale from 10.2.0 to 10.3.0
  • 4a809d9 Merge pull request #14568 from pytest-dev/register-fixture
  • 5dfa385 Fix recursion traceback test to cover all styles (#14582)
  • f52ff0c Add pytest.register_fixture
  • a8ac094 Merge pull request #14567 from pytest-dev/more-visibility-deprecate
  • e5620cd [pre-commit.ci] pre-commit autoupdate (#14577)
  • 2ce9c6d Merge pull request #14540 from minbang930/fix-14533-doctest-module-fixtures
  • Additional commits viewable in compare view

Updates hypothesis from 6.155.2 to 6.155.3

Commits
  • 8497a82 Bump hypothesis version to 6.155.3 and update changelog
  • 1ac02e3 Merge pull request #4767 from pschanely/suppress-observations
  • 814a0ef Merge branch 'master' into suppress-observations
  • ef41ab2 Fix two crosshair-backend test failures + a spurious empty observation
  • 1084b33 claude: fix link preview dark styling in furo auto theme mode
  • caa15d0 Bump hypothesis version to 6.155.2 and update changelog
  • 41f16b2 format
  • e4ce59e rewrite comments and improve test
  • b3d84f5 fixed flake
  • 47b6f0f Update pinned dependencies
  • Additional commits viewable in compare view

Updates ty from 0.0.46 to 0.0.49

Release notes

Sourced from ty's releases.

0.0.49

Release Notes

Released on 2026-06-11.

Bug fixes

  • Fix site-package error when multiple versions of Python are installed in system path (#25769)

Diagnostics

  • Point at attribute's binding site in `invalid-await diagnostic (#24628)
  • Report redefined legacy TypeVars (#25854)

Performance

  • Add dedicated TDDs for narrowing constraints (#25834)
  • Avoid caching same-file raw signatures (#25761)
  • Cache reachability evaluations during inference (#25696)
  • Compact retained definition maps (#25737)
  • Omit redundant definition inference owner keys (#25837)

Core type checking

  • Preserve nominal type of enum.property instances (#25849)
  • Restrict length narrowing to types that encode their length (#25840)
  • Use peer context for collection literals (#25848)

Contributors

Install ty 0.0.49

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/ty/releases/download/0.0.49/ty-installer.sh | sh

Install prebuilt binaries via powershell script

powershell -ExecutionPolicy Bypass -c "irm https://releases.astral.sh/github/ty/releases/download/0.0.49/ty-installer.ps1 | iex"

Download ty 0.0.49

... (truncated)

Changelog

Sourced from ty's changelog.

0.0.49

Released on 2026-06-11.

Bug fixes

  • Fix site-package error when multiple versions of Python are installed in system path (#25769)

Diagnostics

  • Point at attribute's binding site in `invalid-await diagnostic (#24628)
  • Report redefined legacy TypeVars (#25854)

Performance

  • Add dedicated TDDs for narrowing constraints (#25834)
  • Avoid caching same-file raw signatures (#25761)
  • Cache reachability evaluations during inference (#25696)
  • Compact retained definition maps (#25737)
  • Omit redundant definition inference owner keys (#25837)

Core type checking

  • Preserve nominal type of enum.property instances (#25849)
  • Restrict length narrowing to types that encode their length (#25840)
  • Use peer context for collection literals (#25848)

Contributors

0.0.48

Released on 2026-06-10.

Performance

  • Avoid redundant constraint saturation work (#25786)

Core type checking

  • Add support for TypedDict extra_items (#25591)
  • Improve closed=True TypedDict precision (#25651)
  • Require subtyping for transitive constraint pivots (#25778)
  • Sync vendored typeshed stubs (#25828). Typeshed diff

Contributors

... (truncated)

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the python-dependencies group with 5 updates:

| Package | From | To |
| --- | --- | --- |
| [cvx-linalg](https://github.com/Jebel-Quant/linalg) | `0.6.2` | `0.7.0` |
| [jquantstats](https://github.com/jebel-quant/jquantstats) | `0.9.3` | `0.9.6` |
| [pytest](https://github.com/pytest-dev/pytest) | `9.0.3` | `9.1.0` |
| [hypothesis](https://github.com/HypothesisWorks/hypothesis) | `6.155.2` | `6.155.3` |
| [ty](https://github.com/astral-sh/ty) | `0.0.46` | `0.0.49` |


Updates `cvx-linalg` from 0.6.2 to 0.7.0
- [Release notes](https://github.com/Jebel-Quant/linalg/releases)
- [Changelog](https://github.com/Jebel-Quant/linalg/blob/main/CHANGELOG.md)
- [Commits](Jebel-Quant/linalg@v0.6.2...v0.7.0)

Updates `jquantstats` from 0.9.3 to 0.9.6
- [Release notes](https://github.com/jebel-quant/jquantstats/releases)
- [Changelog](https://github.com/Jebel-Quant/jquantstats/blob/main/CHANGELOG.md)
- [Commits](Jebel-Quant/jquantstats@v0.9.3...v0.9.6)

Updates `pytest` from 9.0.3 to 9.1.0
- [Release notes](https://github.com/pytest-dev/pytest/releases)
- [Changelog](https://github.com/pytest-dev/pytest/blob/main/CHANGELOG.rst)
- [Commits](pytest-dev/pytest@9.0.3...9.1.0)

Updates `hypothesis` from 6.155.2 to 6.155.3
- [Release notes](https://github.com/HypothesisWorks/hypothesis/releases)
- [Commits](HypothesisWorks/hypothesis@v6.155.2...v6.155.3)

Updates `ty` from 0.0.46 to 0.0.49
- [Release notes](https://github.com/astral-sh/ty/releases)
- [Changelog](https://github.com/astral-sh/ty/blob/main/CHANGELOG.md)
- [Commits](astral-sh/ty@0.0.46...0.0.49)

---
updated-dependencies:
- dependency-name: cvx-linalg
  dependency-version: 0.7.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-dependencies
- dependency-name: jquantstats
  dependency-version: 0.9.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python-dependencies
- dependency-name: pytest
  dependency-version: 9.1.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: python-dependencies
- dependency-name: hypothesis
  dependency-version: 6.155.3
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: python-dependencies
- dependency-name: ty
  dependency-version: 0.0.49
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: python-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Jun 16, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: dependencies, python. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

cvx-linalg >= 0.7 renamed the private `_DEFAULT_COND_THRESHOLD` constant
to the public `DEFAULT_COND_THRESHOLD`. The production code in
`_factor_model.py` already uses a try/except to handle both versions.
Apply the same pattern to the two test files that directly imported the
private name, fixing the ImportError on macOS with Python 3.11.
Copilot AI requested a review from tschm June 17, 2026 09:52
Copilot finished work on behalf of tschm June 17, 2026 09:52
tschm and others added 3 commits June 17, 2026 14:08
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
cvx-linalg 0.7 now ships type information, surfacing three typecheck
failures under ty + mypy --strict:

- _factor_model.py: import the threshold from the public top-level name
  (cvx.linalg.DEFAULT_COND_THRESHOLD); keep a suppressed fallback to the
  old private cvx.linalg.solve._DEFAULT_COND_THRESHOLD for <0.7.
- exceptions.py: cvx exception base classes are now typed; drop the
  unused type: ignore[misc] comments.
- _stream.py: ewm_covariance now returns dict[Hashable, np.ndarray];
  cast the integer t-index keys for max().

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
ruff wraps the <0.7 fallback import across lines; mypy attaches the
attr-defined/no-redef errors to the `from` line while ty reports the
unresolved-import on the name line. Split the directives accordingly so
both checkers are satisfied and ruff format stays stable.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@tschm
tschm merged commit 332a520 into main Jun 17, 2026
62 checks passed
@tschm
tschm deleted the dependabot/uv/python-dependencies-312833862e branch June 17, 2026 10:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants