chore(deps): update ci-configs - #431
Merged
Merged
Conversation
|
|
Overall Grade |
Security Reliability Complexity Hygiene |
Code Review Summary
| Analyzer | Status | Updated (UTC) | Details |
|---|---|---|---|
| Secrets | Oct 5, 2026 3:01a.m. | Review ↗ | |
| Python | Oct 5, 2026 3:01a.m. | Review ↗ |
Important
AI Review is run only on demand for your team. We're only showing results of static analysis review right now. To trigger AI Review, comment @deepsourcebot review on this thread.
There was a problem hiding this comment.
Copilot review overview
🔵 Needs a closer look
Updated remote revisions and hook compatibility could not be verified offline.
Review effort: Balanced
Findings: None
What changed in this PR
Updates pre-commit tooling pins used by the SDK’s development and CI checks.
Changes:
- Upgrades Ruff, Pylint, isort, Flake8, and mypy.
- Updates the Renovate configuration validator.
- Leaves hook settings and execution stages unchanged.
| File | Description |
|---|---|
.pre-commit-config.yaml |
Updates six tooling revisions. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
cowan-macady
approved these changes
Oct 5, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
7.3.0→7.4.19.0.1→9.0.2v4.0.8→v4.1.2v0.16.8→v0.16.10v2.3.1→v2.4.044.105.0→44.133.0Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
Note: The
pre-commitmanager in Renovate is not supported by thepre-commitmaintainers or community. Please do not report any problems there, instead create a Discussion in the Renovate repository if you have any questions.Release Notes
PyCQA/flake8 (PyCQA/flake8)
v7.4.1Compare Source
v7.4.0Compare Source
PyCQA/isort (PyCQA/isort)
v9.0.2Compare Source
🪲 Fixes
Other changes
processby @DanielNoord in #2677Full Changelog: PyCQA/isort@9.0.1...9.0.2
PyCQA/pylint (PyCQA/pylint)
v4.1.2Compare Source
What's new in Pylint 4.1.2?
Release date: 2026-10-03
False Positives Fixed
Fixed a false positive
unbalanced-tuple-unpackingwhen unpacking a tupleconcatenation whose elements have several possible values.
Fixed by upgrading astroid to 4.3.3.
Closes #2621
Other Bug Fixes
Fixed a crash when calling
__bases__on a class.Fixed by upgrading astroid to 4.3.3.
Closes #11491
Fix a crash (
astroid-error) when the class of a called attribute cannotbe fully inferred, for example when the attribute is used as a
withstatement target or inside a comprehension.
Closes #11492
Fix a crash when a name bound by a
typestatement (a TypeVar) is used in awithstatement.Closes #11510
Fixed a crash (
TypeError) in the variables checker when checking a classwhose metaclass name binding has no line number, for example a class defined
with
metaclass=__annotations__.Closes #11511
Fix a crash in the
using-final-decorator-in-unsupported-versioncheckwhen
import finalis used.Closes #11521
Fix a crash when a plugin passes
confidence=Nonetoadd_message, aspylint-pytestdoes, for a message that is disabled.confidence=Noneisaccepted again and means
UNDEFINED, like in pylint 4.0. Passing itexplicitly to
add_message,add_ignored_messageorMessagenow emits aDeprecationWarning: it will raise an error in pylint 5.0.Closes #11530
v4.1.1Compare Source
What's new in Pylint 4.1.1?
Release date: 2026-09-29
Other Changes
Pylint 4.1.0 could not be uploaded to PyPI, because it required an unreleased
version of
dillon Python 3.15, and PyPI refuses such a dependency. 4.1.1 isthe first 4.1 release available on PyPI, see the 4.1.0 changes below.
Refs #11495
v4.1.0Compare Source
What's new in Pylint 4.1.0?
Release date: 2026-09-29
Startup is about 25% faster thanks to lazy imports. The import checker caches
its isort configuration, which makes pylint about 17% faster on ansible.
Finding the files to lint with
--recursive=yno longer walks ignoreddirectories such as
.venvornode_modules, which took seconds on largetrees. The duplicate-code checker and
symilaralso received optimizationsthat result in considerable performance improvements and memory use reduction
on larger codebases. For example, pandas analysis went from 20 min to 55 s and
pylint does not get OOM-killed when analyzing cpython anymore.
Python 3.15 support progresses: the unpacking in comprehensions added by
PEP 798 no longer raises false positives, and the standard library
deprecations of Python 3.15 are followed.
For CI, there is a new built-in
junitoutput format(
--output-format=junit), theNO_COLORandFORCE_COLORenvironmentvariables are respected, and the files to lint can now be set with the
filesoption in the configuration file.New checks:
looping-through-iterator,impossible-comparison,chained-comparison-all-equalandusing-comprehension-unpacking-in-unsupported-version.Running with
--jobsno longer duplicates the messages of extensions orignores extensions enabled in the configuration.
Plugin authors: the
confidenceparameter can no longer beNone, exceptin
is_message_enabled, and theMSG_STATE_*constants are deprecated infavor of the
MessageDisableReasonenum.The required
astroidversion is now 4.3.2. See the astroid changelog for additional fixes, features, and performance improvements applicable to pylint.Breaking Changes
The
confidenceparameter is no longer nullable on any APIs except foris_message_enabled(whereconfidence=Nonemeans "don't filter byconfidence"). The default became
interfaces.UNDEFINED(an immutable value);the behavior is unchanged unless you were passing an explicit
None. Thisavoids a runtime check in multiple function to set the default value conditionally.
The
constants.MSG_STATE_*integer were replaced by aMessageDisableReasonenum.The old names remain as deprecated aliases pointing at the enum members.
MessageDisableReasonis anIntEnumso existing code comparing the return of_get_message_state_scopeto the literal0/1/2keeps working.Refs #11018
New Features
Add support for
ignore-pattern-in-long-linesto allow ignoring specific parts of a line when checking line length.Refs #3352
Support for the
NO_COLORandFORCE_COLORenvironment variables has been added.When running pylint, the reporter that writes to stdout is switched between
textand
colorizedaccording to the requested mode.The order is:
NO_COLOR>FORCE_COLOR>--output-format=....Closes #3995
The dict-init-mutate message now includes a suggested dictionary literal showing how to combine the initialization and subsequent mutations into a single statement.
Closes #7819
Add a built-in
junitoutput format (--output-format=junit) that produces JUnit-compatible XML output for CI/CD integration with Jenkins, Azure DevOps, GitLab CI, and GitHub Actions.Closes #9143
Trailing pragmas understood by other common tooling (
# type: ignore,# pyright: ignore,# noqa,# pragma: no coverand# pragma: no branch) are no longer counted toward the line length, so a lineis not flagged as
line-too-longsolely because of such a pragma. This mirrorsthe existing behaviour for Pylint's own
# pylint:pragmas.Closes #10172
pyreverse: add
--no-signaturesto show method names without parameter lists or return type annotations in class diagrams.Closes #10772
Add support for
--known-first-partysimilar to--known-third-party.Refs #10803
New Checks
Added a new checker
looping-through-iterator(W4801) to detect when an iterator from an outer scope is consumed in a nested loop, which can lead to the iterator being unexpectedly exhausted.Refs #2996
Add new checks
impossible-comparisonandchained-comparison-all-equal.impossible-comparisonflags boolean conditions whose chain of numericcomparisons is logically contradictory and can never be true (for example
a > b and b > a).chained-comparison-all-equalflags boolean conditionswhose operands form a cycle of weak inequalities (
<=or>=) and can besimplified to a chain of equalities (for example
a >= b and b >= aisequivalent to
a == b).Closes #5814
Add
using-comprehension-unpacking-in-unsupported-version(W2607), emitted whenthe code uses the unpacking in comprehensions added by PEP 798 while
py-versionstill includes a Python version that cannot compile it.Refs #10982
False Positives Fixed
Fix a false positive for
unnecessary-negation(C0117) when negating acomparison between dict views (
dict.keys()/dict.items()), which likeset/frozensetsupport only a partial (subset/superset) ordering, sonot a.items() <= b.items()is not equivalent toa.items() > b.items().Closes #3668
Fix false positives for
attribute-defined-outside-initwhere__init__(etc.) uses a helper method to create attributes.
Closes #5214
Fix a false positive for
consider-using-generatoranduse-a-generatorwith an asynchronous list comprehension. Turning it into a generator expression
would create an asynchronous generator, which those functions cannot consume.
Closes #7271
Fixed a false positive
assigning-non-slotwhen assigning to an inheriteddescriptor through an instance returned by a method annotated with the
subclass. This regressed in pylint 3.0.0.
Fixed by upgrading astroid to 4.1.0.
Closes #8053
Fixed a false positive
no-memberwhen aclassmethodannotated withtyping.Selfis overridden in a subclass and its result is used directly,as in
Subclass.build().only_on_subclass(). The return type is now narrowedto the subclass rather than the base class. This regressed in pylint 3.0.0.
Fixed by upgrading astroid to 4.1.0.
Closes #9159
Avoid emitting
deprecated-classfor imports inside a recognizedsys.version_infoguard.Closes #9533
Fix a false positive for
inconsistent-return-statementswhen an instancemethod annotated with
NoReturn(orNever) is called via the classrather than an instance (e.g.
MyClass.raise_method(obj)). The unboundmethod form is now recognised as never returning, matching the existing
behaviour for the bound-method form.
Closes #9692
Fix
used-before-assignmentfalse positive for names bound in only some arms of anif/elif/elsechain.Closes #9879
Fix a false positive for
useless-parent-delegationwhen a method overrides amethod of a C-level parent whose signature cannot be inspected, such as
Exception.__init__. BecauseException.__init__accepts*args, anoverride taking only
selfnarrows the accepted arguments and is not useless.Overrides of
object.__init__are still reported.Closes #9994
Fixed a false positive
no-name-in-modulewhen a module is imported withan alias that shadows its base module and a function named
formatiscalled on the alias.
Fixed by upgrading astroid to 4.3.1.
Closes #10193
Fixed a false positive
unsubscriptable-objecton instances of a generic class defining__class_getitem__.Closes #10360
Fixed a false positive
unexpected-keyword-argumentwhen passingdtypeto
numpy.concatenate().Fixed by upgrading astroid to 4.3.1.
Closes #10548
Fix a false positive for
unexpected-keyword-argfor dataclassesusing generic type aliases (PEP 695).
Closes #10703
Fix false positive
unreachablewhen calling a function with@overloadwhere one signature returnsNoReturn.Closes #10785
Fix a false positive for
too-many-function-argsfor dataclassesusing generic type aliases (PEP 695).
Closes #10788
Fix a false positive
relative-beyond-top-levelerror when linting specific files in namespace packages in parallel mode by augmentingsys.pathbefore loading plugins and expanding files consistently for parallel workers.Closes #10794
Fix
# pylint: enableinside atryblock leaking into theexcepthandler. For example in the following code,
no-memberis no longerincorrectly re-enabled in the
exceptblock:Requires astroid 4.2.
Refs #10933
Fix false positives for the Python 3.15 syntax added by PEP 798, unpacking in
comprehensions:
star-needs-assignment-target(E0114) was emitted for the unpacked elementof a comprehension, e.g.
[*sub for sub in lists].consider-using-dict-comprehension(R1717) was emitted fordict([*pairs for pairs in nested]), which flattens its argument and istherefore not equivalent to a key/value dict comprehension.
Refs #10982
Fix
access-member-before-definitionfalse positive for bare type annotations(
self.x: Type) that don't assign a value.Refs #11015
Fix a false positive for
assignment-from-no-returnwhen the called function'sbody ends in an unconditional
raise, such aspathlib.Path.readlink()onplatforms without symlink support.
Closes #11114
Fix a false positive for
protected-accesswhen a protected member isaccessed through
self.__class__, which is now treated liketype(self).Closes #11160
Treat
typing.NoReturnandtyping.Neverthe same asNoReturn/Neverwhen deciding that a call never returns.Closes #11271
Fix a false positive for
unreachableon the statement following aninstantiation of
_sitebuiltins.Quitter(the class of theexitandquitbuiltins). Only calling the instance terminates, not creating it.Closes #11310
Fixed a false positive
unbalanced-tuple-unpackingwhen unpacking theargsof an exception.
Fixed by upgrading astroid to 4.3.2.
Closes #11312
Fixed a false positive for
unnecessary-semicolonwhen an f-string ending in;is continued onto the next line with a backslash on Python 3.12+.Closes #11444
False Negatives Fixed
missing-param-docandmissing-type-docno longer false-negative onNumPy-style parameters whose type line includes a default value, e.g.
number : int, default 0. Any text after the colon on the type line isnow accepted as the type, matching the NumPy style guide.
Closes #6211
The
docparamsextension now emitsmultiple-constructor-docwhenconstructor parameters are documented in both the class docstring and the
constructor docstring, even when the constructor method is skipped by
no-docstring-rgx.Closes #6692
chained-comparisonis now emitted for additional simplifiable patterns(e.g.
a > 1 and a > 10) and its message now includes the suggestedsimplification.
Refs #7611
Fix a false negative for
abstract-methodwhere a concrete subclassinheriting from an abstract class (without redeclaring
abc.ABCorABCMeta) was treated as abstract and silently exempted from the check.A class is now only considered abstract when it opts in explicitly, via
direct
abc.ABCinheritance,metaclass=ABCMeta, an@abstractmethoddefined on the class, or being aProtocol.Closes #7950
no-value-for-parameteris now emitted when a call unpacks a dictionary literalwith
**and that dictionary does not provide a required argument.Closes #8785
attribute-defined-outside-initnow reports attributes assigned withsetattr(self, "name", value)outside defining methods.It no longer reports attributes assigned normally when a defining method of the
class or of a parent initializes them with
setattr.Closes #9798
superfluous-parens(C0325) no longer false-negatives on a singleparenthesised literal after the
inkeyword, e.g.x in ("foo"). Theparentheses around a single string or number literal are now reported as
superfluous, while a tuple (
x in ("foo",)) or a larger expression(
x in ("foo" + bar)) is still left untouched.Closes #9878
comparison-with-itselfnow detects repeated attribute chains such asobject.attribute == object.attribute.Closes #10713
not-an-iterableandnot-a-mappingare now also emitted for the valueunpacked by PEP 798 comprehension unpacking, e.g.
[*number for number in numbers]or{**number for number in numbers}.Refs #10982
Fix a false negative in
unnecessary-negation(C0117):not (a is not b)andnot (a not in b)are now flagged (they simplify toa is banda in b), consistent with the existing handling ofis/in.Closes #11140
Emit
arguments-differwhen an overridden special method takes a differentnumber of parameters. Only renamed parameters and removed variadics stay
exempt, and the constructor family (
__new__,__init__,__init_subclass__and__post_init__) is still fully ignored.Closes #11295
access-member-before-definitionis now also emitted when__init__calls amethod that reads an instance attribute which
__init__only assigns after the call.Closes #11338
Fix a false negative for
unspecified-encodingandbad-open-modewhen themode of an
opencall is a parameter of the enclosing function that has adefault value. The default is now used to check the call, as a literal mode
would be. Calls with such a mode stopped being reported in pylint 4.0.8.
Refs #11415
Other Bug Fixes
# pylint: disablecomments at the beginning of anelseblock (or onthe line just above the
elsekeyword) now suppress messages in that blockinstead of being ignored.
Fixed by upgrading astroid to 4.3.1.
Closes #872
dangerous-default-valuenow detects mutable default values intyping.NamedTuplefield definitions.Closes #3716
Repeated
--output-formatoptions now write reports to every requested file instead of only the last one.Closes #8147
Fixed a crash when defining a functional
namedtuplewith a field namethat changes under NFKC normalization, like
"µ"(MICRO SIGN).Fixed by upgrading astroid to 4.3.1.
Closes #8746
Fix a crash in
pyreversewhen a requested class cannot be inferred.Closes #9797
Fix enabling checks from extensions which are disabled by default if multiple jobs are used.
Closes #10037
Fixed an
AstroidBuildingErrorcrash when inheriting from a genericdataclass that rebinds
__init__in__init_subclass__.Fixed by upgrading astroid to 4.3.1.
Closes #10519
wrong-import-positionnow exemptstry,if,with, andmatchblocks from marking the import boundary. Fixedasync defnot being detected as an import boundary. Pragma on non-import lines now suppresses following imports until the next non-import.Closes #10589
Fix duplicate messages for extension checks if multiple jobs are used.
Refs #10642
Fix an issue where discovery can miss a similarly named directory if a shorter named directory is processed first.
Closes #10969
Follow the standard library deprecations of Python 3.15.
Refs #10982
Fixed inflated message occurrence counts in the final
Messagesreport whenrunning pylint in parallel mode with
--jobsgreater than 1.Closes #10996
Fix a crash in
consider-using-dict-itemswhen theforloop or comprehension target is an attribute or a subscript (e.g.for self.key in d) rather than a simple variable name.Closes #11173
nan-comparisonnow also recognizesmath.nan,numpy.nan,Decimal("nan")and any name or attribute that pylint can infer to a NaN constant, such as a module
level constant defined as
math.nan. Onlynumpy.NaN-- removed in numpy 2.0 --and
float("nan")were detected before. Infinities are still not reported, ascomparing against them is meaningful.
Refs #11219
Fix a crash in the comparison checker when a NaN comparison operand is a call to a name that cannot be inferred, such as
1 == b('nan').Closes #11224
Fix a crash in
invalid-class-objectandassigning-non-slotwhen__class__is assigned outside a simple assignment (e.g.for obj.__class__ in classes:).Closes #11267
Avoid a fatal
astroid-errorininvalid-name,stop-iteration-return,assigning-non-slotandredefined-slots-in-subclassfor classes with duplicate or inconsistentbases, which leave the class without an MRO to walk.
Refs #11272
collections.abc.Callableandcollections.abc.Bufferno longer count towardstoo-many-ancestors. Every other abstract base class incollections.abcwas already ignored, so a class deriving fromCallablewas charged for an ancestor while an otherwise identical class deriving fromIterablewas not.Refs #11358
Fix
import-private-namedepending on the order of the checked files: typeannotations are now collected for each module instead of only for the first
module checked that contains an import. This removes a false positive on imports
used only as annotations and a false negative on private imports used at runtime.
Closes #11466
Other Changes
Clarify how to choose the Python interpreter and
py-versionwhen linting aproject that supports multiple Python versions.
Closes #5038
You can now set the
filesoption in configuration files and on the command line.Passing files without the
--filesflag is still supported. This allows to setfilestofiles = my_source_directoryand invokingpylintwith onlythe
pylintcommand similar to how other CLI tools allow to do so.The help message can always be invoked with
pylint -horpylint --help.Closes #5701
Removed messages (such as
print-statementorapply-builtin) now havetheir own page in the documentation, with a link to the change that removed
them. They are also listed in the messages overview alongside renamed messages.
Closes #6670
Documentation for options defined by
Run, such as--errors-onlyand--init-hook, is now generated alongside checker configuration options.Closes #6938
Document that the
wrong-import-order(C0411) classification of imports asthird-party vs first-party depends on the current working directory and
recommend
known-first-partyas the deterministic workaround.Closes #8801
Clarify related
no-else-*messages so they say that only the firstelifafter the reported branch should change. Expand the
no-else-returndocumentation to explain later branches and when retaining an
elifchaincan better communicate an exhaustive decision.
Closes #9274
assignment-from-no-returnnow names the callable that does not return anything and,for functions listed in the new
known-side-effects-only-functionsoption, hints atthe equivalent function to use instead (e.g.
reversed(...)forreverse()).Closes #10383
Internal Changes
Add
assertDoesNotAddMessagestoCheckerTestCaseto assert thatspecific messages are not emitted, while allowing other messages to be
present. This complements
assertNoMessageswhich asserts that nomessages at all are emitted.
Refs #9598
The primer now pairs residual messages — first by
(symbol, path, obj)and then byexact source location — and reports altered messages as a single changed entry with
a compact diff, rather than as a separate removal + addition. The location-based pass
also catches symbol renames at the same code position (e.g.
used-before-assignment→
possibly-used-before-assignment). When several messages are eligible, the oneclosest to the original line wins, so pairs never cross. New messages are classified
into fixed false positives (
useless-suppression),astroid-errorfatal errors,and the rest.
astroid-errormessages are excluded from pairing (their text embedsa unique crash-report path) so persistent crashes keep raising the prominent warning.
Truncated comments are now cut at a line break and keep their code fences and
<details>blocks closed.Refs #10914
The primer's project cache key is now derived from the commits pinned in
packages_to_prime.jsoninstead of the remote branch tips.mainand PR primerruns now share the same project cache and lint files in the same on-disk order,
removing spurious diffs from primer comments (message positions and astroid inference
results depend on the order in which modules are linted).
Closes #11192
Performance Improvements
Lazily import
isort,dill,multiprocessing/concurrent.futures,and
tomlkitso they are only loaded when actually needed.This reduces startup time by ~25% (e.g.
--version: 91 => 67 ms,--help: 176 => 133 ms, single-file lint: 272 => 226 ms).Closes #2866
Sped up the
duplicate-codechecker. When run inside pylint thechecker now reuses the already-parsed AST instead of re-parsing every
file like it has to do when launched via
symilar, and it uses arolling hash window with caching across file pairs. Additionally, a
quadratic blow-up in the hash-matching phase is avoided by switching
algorithm at a threshold, which previously caused the checker to hang
on files with many repeated lines.
Speedup scales with codebase size from 1.5x on small projects
(~10k lines), to 20x on large ones (500k+ lines). Memory usage also
drops 12-27%. Codebases that previously hung or were OOM-killed could
now complete.
Refs #10881
Skip isort classification in the import checker when no import-ordering message is enabled,
and cache the isort configuration so it is built once instead of once per import statement.
Skipping the isort processing become a negligible improvement once the caching is applied.
pylint became
17% faster on ansible (=4500 imports) even with isort enabled.Refs #10886, #2866, #10637
Finding the files to lint with
--recursive=yis faster. Directories matchingignore,ignore-patternsorignore-paths(such as.venv,.gitor
node_modules) are no longer walked, and neither are the packages alreadyfound. In a checkout of pylint with its virtual environment, this step is about
three times faster when
.git,.toxand.venvare ignored, and abouttwenty times faster when a large ignored tree is present.
Directories and files are now also visited in sorted order, so the order in
which files are linted no longer depends on the file system. The order of
messages can change once for projects whose file system listed directories in
another order.
Closes #11005
v4.0.10Compare Source
What's new in Pylint 4.0.10?
Release date: 2026-09-29
False Positives Fixed
Fix false positives for :ref:
unnecessary-lambdawhen a variable referenced inthe called expression is assigned, reassigned, or deleted later in the same scope.
Closes #8192
Fix a false positive for
unused-argumentin dataclass__new__methodswhen the arguments are consumed by a generated
__init__method.Closes #9843
Fix a false positive for
missing-kwoawhen keyword-only arguments are passedthrough a
**kwargsdictionary that is not a literal at the call site, forexample one filled with
options["key"] = valueafter its creation.Closes #10029
ungrouped-importsno longer reports imports inside mutually exclusiveOS guard branches (
if os.name == "nt":/if sys.platform == "win32":),matching the existing behavior for
sys.version_infoguards.Closes #10460
Other Bug Fixes
A
TypeErrorcrash could occur when checking aforloop thatiterates over a subscript with non-numeric constant bounds or a zero
step, e.g.
for a, b in {"k": [][0: ""]}.values():.Closes #11472
Fix a crash (
AttributeError: 'ClassDef' object has no attribute 'expr') in theimport-private-nameextension when an annotated assignment's value is anattribute access on a call rooted at a non-
Namenode, e.g.x: str = ''().a.Closes #11479
v4.0.9Compare Source
What's new in Pylint 4.0.9?
Release date: 2026-09-23
Security Fixes
to the cache directory (predictable
PYLINT_HOMEon a multi-user host) can nolonger write a crafted pickle that will runs arbitrary code when pylint access its
stat cache. The result cache is now stored as JSON instead of pickle,
preventing code-execution. The workaround is upgrading or not pointing
PYLINT_HOMEto an untrusted, shared, or group-writable directory. The default value,
~/.cache/pylint,is writable only by the user running pylint. (CVE with the same information pending)
False Positives Fixed
Fixed a false positive for
no-self-useon a method that only usesselfbefore a locally defined class (or other nested method), becausethe checker's could-be-a-function tracking state was not restored after
visiting the nested method.
Closes #3705
Fix a false positive for :ref:
not-callablewhen calling functions constructed withtypes.FunctionTypeortypes.LambdaType.Closes #7500
Fix a false positive for
unnecessary-direct-lambda-callwhen a directly calledlambda in a class body wraps a comprehension containing an assignment expression.
PEP 572 makes that a
SyntaxErrorwithout the lambda's scope, so following themessage produced code that would not compile.
Closes #9294
Fix a false positive for :ref:
unnecessary-ellipsiswhen an ellipsis is thesole body statement of a method defined on a
Protocol.Closes #9319
Fix a false positive for :ref:
bad-exception-causewhen the bases of the classbeing raised from cannot be inferred, such as an exception deriving from a
C extension class. :ref:
raising-non-exceptionand:ref:
catching-non-exceptionalready guard the sameinherit_from_std_exhelper with
has_known_bases.Refs #11399
False Negatives Fixed
method-hiddenis no longer silenced when the hidden method shares its name witha builtin function or with a function defined at module level. Only members of the
ancestor classes themselves can excuse the method now.
Refs #11361
Other Bug Fixes
Fix a block-scoped
# pylint: disable=directive placed inside anifbody leaking into sibling
elif/elseblocks for messages such asstop-iteration-return, which default to a line-based (rather thannode-based) message scope.
Closes #3136
Fix a false positive for
declare-non-slotwhen a class variable isannotated with
ClassVarwithout an initial value.Closes #9950
Fix a crash in the
no-memberchecker when attribute lookup raises anInferenceError.Closes #11356
Fix a crash in the
unnecessary-default-type-argscheck when aGeneratoror
AsyncGeneratorsubscript holds an empty tuple, such asGenerator[()].Closes #11357
Fix a crash in
method-hiddenwhen a method shadows a name thatbuiltinsbinds to a node without a statement, such as
helporlicense. Every classinherits from
object, which lives in thebuiltinsmodule, so no base classwas needed to trigger it.
Closes #11361
Closes #8079
astral-sh/ruff-pre-commit (astral-sh/ruff-pre-commit)
v0.16.10Compare Source
See: https://github.com/astral-sh/ruff/releases/tag/0.16.10
v0.16.9Compare Source
See: https://github.com/astral-sh/ruff/releases/tag/0.16.9
pre-commit/mirrors-mypy (pre-commit/mirrors-mypy)
v2.4.0Compare Source
renovatebot/pre-commit-hooks (renovatebot/pre-commit-hooks)
v44.133.0Compare Source
v44.132.6Compare Source
See https://github.com/renovatebot/renovate/releases/tag/44.132.6 for more changes
v44.132.5Compare Source
See https://github.com/renovatebot/renovate/releases/tag/44.132.5 for more changes
v44.132.4Compare Source
See https://github.com/renovatebot/renovate/releases/tag/44.132.4 for more changes
v44.132.3Compare Source
See https://github.com/renovatebot/renovate/releases/tag/44.132.3 for more changes
v44.132.2Compare Source
See https://github.com/renovatebot/renovate/releases/tag/44.132.2 for more changes
v44.131.0Compare Source
See https://github.com/renovatebot/renovate/releases/tag/44.131.0 for more changes
v44.130.0Compare Source
See https://github.com/renovatebot/renovate/releases/tag/44.130.0 for more changes
v44.129.0Compare Source
See https://github.com/renovatebot/renovate/releases/tag/44.129.0 for more changes
v44.128.3Compare Source
See https://github.com/renovatebot/renovate/releases/tag/44.128.3 for more changes
v44.128.1Compare Source
See https://github.com/renovatebot/renovate/releases/tag/44.128.1 for more changes
v44.128.0Compare Source
See https://github.com/renovatebot/renovate/releases/tag/44.128.0 for more changes
v44.127.1Compare Source
See https://github.com/renovatebot/renovate/releases/tag/44.127.1 for more changes
v44.127.0Compare Source
See https://github.com/renovatebot/renovate/releases/tag/44.127.0 for more changes
v44.126.0Compare Source
See https://github.com/renovatebot/renovate/releases/tag/44.126.0 for more changes
v44.125.2Compare Source
See https://github.com/renovatebot/renovate/releases/tag/44.125.2 for more changes
v44.125.1Compare Source
See https://github.com/renovatebot/renovate/releases/tag/44.125.1 for more changes
v44.124.2Compare Source
See https://github.com/renovatebot/renovate/releases/tag/44.124.2 for more changes
v44.123.1Compare Source
See https://github.com/renovatebot/renovate/releases/tag/44.123.1 for more changes
v44.123.0Compare Source
See https://github.com/renovatebot/renovate/releases/tag/44.123.0 for more changes
v44.121.4Compare Source
See https://github.com/renovatebot/renovate/releases/tag/44.121.4 for more changes
v44.121.3Compare Source
See https://github.com/renovatebot/renovate/releases/tag/44.121.3 for more changes
v44.121.1Compare Source
See https://github.com/renovatebot/renovate/releases/tag/44.121.1 for more changes
v44.121.0Compare Source
See https://github.com/renovatebot/renovate/releases/tag/44.121.0 for more changes
v44.120.0Compare Source
See https://github.com/renovatebot/renovate/releases/tag/44.120.0 for more changes
v44.119.1Compare Source
See https://github.com/renovatebot/renovate/releases/tag/44.119.1 for more changes
v44.119.0Compare Source
See https://github.com/renovatebot/renovate/releases/tag/44.119.0 for more changes
v44.118.1Compare Source
See https://github.com/renovatebot/renovate/releases/tag/44.118.1 for more changes
v44.118.0Compare Source
See https://github.com/renovatebot/renovate/releases/tag/44.118.0 for more changes
v44.117.2Compare Source
See https://github.com/renovatebot/renovate/releases/tag/44.117.2 for more changes
v44.117.1Compare Source
See https://github.com/renovatebot/renovate/releases/tag/44.117.1 for more changes
v44.117.0Compare Source
See https://github.com/renovatebot/renovate/releases/tag/44.117.0 for more changes
v44.116.1Compare Source
See https://github.com/renovatebot/renovate/releases/tag/44.116.1 for more changes
v44.116.0Compare Source
See https://github.com/renovatebot/renovate/releases/tag/44.116.0 for more changes
v44.115.13Compare Source
See https://github.com/renovatebot/renovate/releases/tag/44.115.13 for more changes
v44.115.12Compare Source
See https://github.com/renovatebot/renovate/releases/tag/44.115.12 for more changes
v44.115.11Compare Source
See https://github.com/renovatebot/renovate/releases/tag/44.115.11 for more changes
v44.115.10Compare Source
See https://github.com/renovatebot/renovate/releases/tag/44.115.10 for more changes
v44.115.9Compare Source
See https://github.com/renovatebot/renovate/releases/tag/44.115.9 for more changes
v44.115.8Compare Source
See https://github.com/renovatebot/renovate/releases/tag/44.115.8 for more changes
v44.115.7Compare Source
See https://github.com/renovatebot/renovate/releases/tag/44.115.7 for more changes
v44.115.6Compare Source
See https://github.com/renovatebot/renovate/releases/tag/44.115.6 for more changes
v44.115.5Compare Source
See https://github.com/renovatebot/renovate/releases/tag/44.115.5 for more changes
[
v44.115.4](https://redirecConfiguration
📅 Schedule: (UTC)
* 0-3 * * 1)🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.