Skip to content

chore(deps): update ci-configs - #431

Merged
cowan-macady merged 1 commit into
masterfrom
renovate/ci-configs
Oct 5, 2026
Merged

cowan-macady merged 1 commit into
masterfrom
renovate/ci-configs

Conversation

@renovate

@renovate renovate Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Type Update Change OpenSSF
PyCQA/flake8 repository minor 7.3.0 → 7.4.1 OpenSSF Scorecard
PyCQA/isort repository patch 9.0.1 → 9.0.2 OpenSSF Scorecard
PyCQA/pylint repository minor v4.0.8 → v4.1.2 OpenSSF Scorecard
astral-sh/ruff-pre-commit repository patch v0.16.8 → v0.16.10 OpenSSF Scorecard
pre-commit/mirrors-mypy repository minor v2.3.1 → v2.4.0 OpenSSF Scorecard
renovatebot/pre-commit-hooks repository minor 44.105.0 → 44.133.0 OpenSSF Scorecard

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.

Note: The pre-commit manager in Renovate is not supported by the pre-commit maintainers or community. Please do not report any problems there, instead create a Discussion in the Renovate repository if you have any questions.


Release Notes

PyCQA/flake8 (PyCQA/flake8)

v7.4.1

Compare Source

v7.4.0

Compare Source

PyCQA/isort (PyCQA/isort)

v9.0.2

Compare Source

🪲 Fixes

Other changes

Full Changelog: PyCQA/isort@9.0.1...9.0.2

PyCQA/pylint (PyCQA/pylint)

v4.1.2

Compare Source

What's new in Pylint 4.1.2?

Release date: 2026-10-03

False Positives Fixed

  • Fixed a false positive unbalanced-tuple-unpacking when unpacking a tuple
    concatenation whose elements have several possible values.

    Fixed by upgrading astroid to 4.3.3.

    Closes #​2621

Other Bug Fixes

  • Fixed a crash when calling __bases__ on a class.

    Fixed by upgrading astroid to 4.3.3.

    Closes #​11491

  • Fix a crash (astroid-error) when the class of a called attribute cannot
    be fully inferred, for example when the attribute is used as a with
    statement target or inside a comprehension.

    Closes #​11492

  • Fix a crash when a name bound by a type statement (a TypeVar) is used in a with statement.

    Closes #​11510

  • Fixed a crash (TypeError) in the variables checker when checking a class
    whose metaclass name binding has no line number, for example a class defined
    with metaclass=__annotations__.

    Closes #​11511

  • Fix a crash in the using-final-decorator-in-unsupported-version check
    when import final is used.

    Closes #​11521

  • Fix a crash when a plugin passes confidence=None to add_message, as
    pylint-pytest does, for a message that is disabled. confidence=None is
    accepted again and means UNDEFINED, like in pylint 4.0. Passing it
    explicitly to add_message, add_ignored_message or Message now emits a
    DeprecationWarning: it will raise an error in pylint 5.0.

    Closes #​11530

v4.1.1

Compare Source

What's new in Pylint 4.1.1?

Release date: 2026-09-29

Other Changes

  • Pylint 4.1.0 could not be uploaded to PyPI, because it required an unreleased
    version of dill on Python 3.15, and PyPI refuses such a dependency. 4.1.1 is
    the first 4.1 release available on PyPI, see the 4.1.0 changes below.

    Refs #​11495

v4.1.0

Compare Source

What's new in Pylint 4.1.0?

Release date: 2026-09-29

Startup is about 25% faster thanks to lazy imports. The import checker caches
its isort configuration, which makes pylint about 17% faster on ansible.
Finding the files to lint with --recursive=y no longer walks ignored
directories such as .venv or node_modules, which took seconds on large
trees. The duplicate-code checker and symilar also received optimizations
that result in considerable performance improvements and memory use reduction
on larger codebases. For example, pandas analysis went from 20 min to 55 s and
pylint does not get OOM-killed when analyzing cpython anymore.

Python 3.15 support progresses: the unpacking in comprehensions added by
PEP 798 no longer raises false positives, and the standard library
deprecations of Python 3.15 are followed.

For CI, there is a new built-in junit output format
(--output-format=junit), the NO_COLOR and FORCE_COLOR environment
variables are respected, and the files to lint can now be set with the
files option in the configuration file.

New checks: looping-through-iterator, impossible-comparison,
chained-comparison-all-equal and
using-comprehension-unpacking-in-unsupported-version.

Running with --jobs no longer duplicates the messages of extensions or
ignores extensions enabled in the configuration.

Plugin authors: the confidence parameter can no longer be None, except
in is_message_enabled, and the MSG_STATE_* constants are deprecated in
favor of the MessageDisableReason enum.

The required astroid version is now 4.3.2. See the astroid changelog for additional fixes, features, and performance improvements applicable to pylint.

Breaking Changes

  • The confidence parameter is no longer nullable on any APIs except for
    is_message_enabled (where confidence=None means "don't filter by
    confidence"). The default became interfaces.UNDEFINED (an immutable value);
    the behavior is unchanged unless you were passing an explicit None. This
    avoids a runtime check in multiple function to set the default value conditionally.

    The constants.MSG_STATE_* integer were replaced by a MessageDisableReason enum.
    The old names remain as deprecated aliases pointing at the enum members.
    MessageDisableReason is an IntEnum so existing code comparing the return of
    _get_message_state_scope to the literal 0 / 1 / 2 keeps working.

    Refs #​11018

New Features

  • Add support for ignore-pattern-in-long-lines to allow ignoring specific parts of a line when checking line length.

    Refs #​3352

  • Support for the NO_COLOR and FORCE_COLOR environment variables has been added.
    When running pylint, the reporter that writes to stdout is switched between text
    and colorized according to the requested mode.
    The order is: NO_COLOR > FORCE_COLOR > --output-format=....

    Closes #​3995

  • The dict-init-mutate message now includes a suggested dictionary literal showing how to combine the initialization and subsequent mutations into a single statement.

    Closes #​7819

  • Add a built-in junit output format (--output-format=junit) that produces JUnit-compatible XML output for CI/CD integration with Jenkins, Azure DevOps, GitLab CI, and GitHub Actions.

    Closes #​9143

  • Trailing pragmas understood by other common tooling (# type: ignore,
    # pyright: ignore, # noqa, # pragma: no cover and
    # pragma: no branch) are no longer counted toward the line length, so a line
    is not flagged as line-too-long solely because of such a pragma. This mirrors
    the existing behaviour for Pylint's own # pylint: pragmas.

    Closes #​10172

  • pyreverse: add --no-signatures to show method names without parameter lists or return type annotations in class diagrams.

    Closes #​10772

  • Add support for --known-first-party similar to --known-third-party.

    Refs #​10803

New Checks

  • Added a new checker looping-through-iterator (W4801) to detect when an iterator from an outer scope is consumed in a nested loop, which can lead to the iterator being unexpectedly exhausted.

    Refs #​2996

  • Add new checks impossible-comparison and chained-comparison-all-equal.
    impossible-comparison flags boolean conditions whose chain of numeric
    comparisons is logically contradictory and can never be true (for example
    a > b and b > a). chained-comparison-all-equal flags boolean conditions
    whose operands form a cycle of weak inequalities (<= or >=) and can be
    simplified to a chain of equalities (for example a >= b and b >= a is
    equivalent to a == b).

    Closes #​5814

  • Add using-comprehension-unpacking-in-unsupported-version (W2607), emitted when
    the code uses the unpacking in comprehensions added by PEP 798 while
    py-version still includes a Python version that cannot compile it.

    Refs #​10982

False Positives Fixed

  • Fix a false positive for unnecessary-negation (C0117) when negating a
    comparison between dict views (dict.keys()/dict.items()), which like
    set/frozenset support only a partial (subset/superset) ordering, so
    not a.items() <= b.items() is not equivalent to a.items() > b.items().

    Closes #​3668

  • Fix false positives for attribute-defined-outside-init where __init__
    (etc.) uses a helper method to create attributes.

    Closes #​5214

  • Fix a false positive for consider-using-generator and use-a-generator
    with an asynchronous list comprehension. Turning it into a generator expression
    would create an asynchronous generator, which those functions cannot consume.

    Closes #​7271

  • Fixed a false positive assigning-non-slot when assigning to an inherited
    descriptor through an instance returned by a method annotated with the
    subclass. This regressed in pylint 3.0.0.

    Fixed by upgrading astroid to 4.1.0.

    Closes #​8053

  • Fixed a false positive no-member when a classmethod annotated with
    typing.Self is overridden in a subclass and its result is used directly,
    as in Subclass.build().only_on_subclass(). The return type is now narrowed
    to the subclass rather than the base class. This regressed in pylint 3.0.0.

    Fixed by upgrading astroid to 4.1.0.

    Closes #​9159

  • Avoid emitting deprecated-class for imports inside a recognized
    sys.version_info guard.

    Closes #​9533

  • Fix a false positive for inconsistent-return-statements when an instance
    method annotated with NoReturn (or Never) is called via the class
    rather than an instance (e.g. MyClass.raise_method(obj)). The unbound
    method form is now recognised as never returning, matching the existing
    behaviour for the bound-method form.

    Closes #​9692

  • Fix used-before-assignment false positive for names bound in only some arms of an if/elif/else chain.

    Closes #​9879

  • Fix a false positive for useless-parent-delegation when a method overrides a
    method of a C-level parent whose signature cannot be inspected, such as
    Exception.__init__. Because Exception.__init__ accepts *args, an
    override taking only self narrows the accepted arguments and is not useless.
    Overrides of object.__init__ are still reported.

    Closes #​9994

  • Fixed a false positive no-name-in-module when a module is imported with
    an alias that shadows its base module and a function named format is
    called on the alias.

    Fixed by upgrading astroid to 4.3.1.

    Closes #​10193

  • Fixed a false positive unsubscriptable-object on instances of a generic class defining __class_getitem__.

    Closes #​10360

  • Fixed a false positive unexpected-keyword-argument when passing dtype
    to numpy.concatenate().

    Fixed by upgrading astroid to 4.3.1.

    Closes #​10548

  • Fix a false positive for unexpected-keyword-arg for dataclasses
    using generic type aliases (PEP 695).

    Closes #​10703

  • Fix false positive unreachable when calling a function with @overload where one signature returns NoReturn.

    Closes #​10785

  • Fix a false positive for too-many-function-args for dataclasses
    using generic type aliases (PEP 695).

    Closes #​10788

  • Fix a false positive relative-beyond-top-level error when linting specific files in namespace packages in parallel mode by augmenting sys.path before loading plugins and expanding files consistently for parallel workers.

    Closes #​10794

  • Fix # pylint: enable inside a try block leaking into the except
    handler. For example in the following code, no-member is no longer
    incorrectly re-enabled in the except block:

    class Basket:
        # pylint: disable=no-member
        def pick(self):
            try:
                # pylint: enable=no-member
                print(self.apple)  # no-member emitted here
            except KeyError:
                print(self.banana)  # no-member NOT emitted here (correct)

    Requires astroid 4.2.

    Refs #​10933

  • Fix false positives for the Python 3.15 syntax added by PEP 798, unpacking in
    comprehensions:

    • star-needs-assignment-target (E0114) was emitted for the unpacked element
      of a comprehension, e.g. [*sub for sub in lists].
    • consider-using-dict-comprehension (R1717) was emitted for
      dict([*pairs for pairs in nested]), which flattens its argument and is
      therefore not equivalent to a key/value dict comprehension.

    Refs #​10982

  • Fix access-member-before-definition false positive for bare type annotations
    (self.x: Type) that don't assign a value.

    Refs #​11015

  • Fix a false positive for assignment-from-no-return when the called function's
    body ends in an unconditional raise, such as pathlib.Path.readlink() on
    platforms without symlink support.

    Closes #​11114

  • Fix a false positive for protected-access when a protected member is
    accessed through self.__class__, which is now treated like type(self).

    Closes #​11160

  • Treat typing.NoReturn and typing.Never the same as NoReturn / Never when deciding that a call never returns.

    Closes #​11271

  • Fix a false positive for unreachable on the statement following an
    instantiation of _sitebuiltins.Quitter (the class of the exit and
    quit builtins). Only calling the instance terminates, not creating it.

    Closes #​11310

  • Fixed a false positive unbalanced-tuple-unpacking when unpacking the args
    of an exception.

    Fixed by upgrading astroid to 4.3.2.

    Closes #​11312

  • Fixed a false positive for unnecessary-semicolon when an f-string ending in ; is continued onto the next line with a backslash on Python 3.12+.

    Closes #​11444

False Negatives Fixed

  • missing-param-doc and missing-type-doc no longer false-negative on
    NumPy-style parameters whose type line includes a default value, e.g.
    number : int, default 0. Any text after the colon on the type line is
    now accepted as the type, matching the NumPy style guide.

    Closes #​6211

  • The docparams extension now emits multiple-constructor-doc when
    constructor parameters are documented in both the class docstring and the
    constructor docstring, even when the constructor method is skipped by
    no-docstring-rgx.

    Closes #​6692

  • chained-comparison is now emitted for additional simplifiable patterns
    (e.g. a > 1 and a > 10) and its message now includes the suggested
    simplification.

    Refs #​7611

  • Fix a false negative for abstract-method where a concrete subclass
    inheriting from an abstract class (without redeclaring abc.ABC or
    ABCMeta) was treated as abstract and silently exempted from the check.
    A class is now only considered abstract when it opts in explicitly, via
    direct abc.ABC inheritance, metaclass=ABCMeta, an
    @abstractmethod defined on the class, or being a Protocol.

    Closes #​7950

  • no-value-for-parameter is now emitted when a call unpacks a dictionary literal
    with ** and that dictionary does not provide a required argument.

    Closes #​8785

  • attribute-defined-outside-init now reports attributes assigned with
    setattr(self, "name", value) outside defining methods.
    It no longer reports attributes assigned normally when a defining method of the
    class or of a parent initializes them with setattr.

    Closes #​9798

  • superfluous-parens (C0325) no longer false-negatives on a single
    parenthesised literal after the in keyword, e.g. x in ("foo"). The
    parentheses around a single string or number literal are now reported as
    superfluous, while a tuple (x in ("foo",)) or a larger expression
    (x in ("foo" + bar)) is still left untouched.

    Closes #​9878

  • comparison-with-itself now detects repeated attribute chains such as
    object.attribute == object.attribute.

    Closes #​10713

  • not-an-iterable and not-a-mapping are now also emitted for the value
    unpacked by PEP 798 comprehension unpacking, e.g. [*number for number in numbers] or {**number for number in numbers}.

    Refs #​10982

  • Fix a false negative in unnecessary-negation (C0117): not (a is not b) and not (a not in b) are now flagged (they simplify to a is b and a in b), consistent with the existing handling of is / in.

    Closes #​11140

  • Emit arguments-differ when an overridden special method takes a different
    number of parameters. Only renamed parameters and removed variadics stay
    exempt, and the constructor family (__new__, __init__,
    __init_subclass__ and __post_init__) is still fully ignored.

    Closes #​11295

  • access-member-before-definition is now also emitted when __init__ calls a
    method that reads an instance attribute which __init__ only assigns after the call.

    Closes #​11338

  • Fix a false negative for unspecified-encoding and bad-open-mode when the
    mode of an open call is a parameter of the enclosing function that has a
    default value. The default is now used to check the call, as a literal mode
    would be. Calls with such a mode stopped being reported in pylint 4.0.8.

    Refs #​11415

Other Bug Fixes

  • # pylint: disable comments at the beginning of an else block (or on
    the line just above the else keyword) now suppress messages in that block
    instead of being ignored.

    Fixed by upgrading astroid to 4.3.1.

    Closes #​872

  • dangerous-default-value now detects mutable default values in typing.NamedTuple field definitions.

    Closes #​3716

  • Repeated --output-format options now write reports to every requested file instead of only the last one.

    Closes #​8147

  • Fixed a crash when defining a functional namedtuple with a field name
    that changes under NFKC normalization, like "µ" (MICRO SIGN).

    Fixed by upgrading astroid to 4.3.1.

    Closes #​8746

  • Fix a crash in pyreverse when a requested class cannot be inferred.

    Closes #​9797

  • Fix enabling checks from extensions which are disabled by default if multiple jobs are used.

    Closes #​10037

  • Fixed an AstroidBuildingError crash when inheriting from a generic
    dataclass that rebinds __init__ in __init_subclass__.

    Fixed by upgrading astroid to 4.3.1.

    Closes #​10519

  • wrong-import-position now exempts try, if, with, and match blocks from marking the import boundary. Fixed async def not being detected as an import boundary. Pragma on non-import lines now suppresses following imports until the next non-import.

    Closes #​10589

  • Fix duplicate messages for extension checks if multiple jobs are used.

    Refs #​10642

  • Fix an issue where discovery can miss a similarly named directory if a shorter named directory is processed first.

    Closes #​10969

  • Follow the standard library deprecations of Python 3.15.

    Refs #​10982

  • Fixed inflated message occurrence counts in the final Messages report when
    running pylint in parallel mode with --jobs greater than 1.

    Closes #​10996

  • Fix a crash in consider-using-dict-items when the for loop or comprehension target is an attribute or a subscript (e.g. for self.key in d) rather than a simple variable name.

    Closes #​11173

  • nan-comparison now also recognizes math.nan, numpy.nan, Decimal("nan")
    and any name or attribute that pylint can infer to a NaN constant, such as a module
    level constant defined as math.nan. Only numpy.NaN -- removed in numpy 2.0 --
    and float("nan") were detected before. Infinities are still not reported, as
    comparing against them is meaningful.

    Refs #​11219

  • Fix a crash in the comparison checker when a NaN comparison operand is a call to a name that cannot be inferred, such as 1 == b('nan').

    Closes #​11224

  • Fix a crash in invalid-class-object and assigning-non-slot when __class__ is assigned outside a simple assignment (e.g. for obj.__class__ in classes:).

    Closes #​11267

  • Avoid a fatal astroid-error in invalid-name,
    stop-iteration-return, assigning-non-slot and
    redefined-slots-in-subclass for classes with duplicate or inconsistent
    bases, which leave the class without an MRO to walk.

    Refs #​11272

  • collections.abc.Callable and collections.abc.Buffer no longer count towards too-many-ancestors. Every other abstract base class in collections.abc was already ignored, so a class deriving from Callable was charged for an ancestor while an otherwise identical class deriving from Iterable was not.

    Refs #​11358

  • Fix import-private-name depending on the order of the checked files: type
    annotations are now collected for each module instead of only for the first
    module checked that contains an import. This removes a false positive on imports
    used only as annotations and a false negative on private imports used at runtime.

    Closes #​11466

Other Changes

  • Clarify how to choose the Python interpreter and py-version when linting a
    project that supports multiple Python versions.

    Closes #​5038

  • You can now set the files option in configuration files and on the command line.
    Passing files without the --files flag is still supported. This allows to set
    files to files = my_source_directory and invoking pylint with only
    the pylint command similar to how other CLI tools allow to do so.
    The help message can always be invoked with pylint -h or pylint --help.

    Closes #​5701

  • Removed messages (such as print-statement or apply-builtin) now have
    their own page in the documentation, with a link to the change that removed
    them. They are also listed in the messages overview alongside renamed messages.

    Closes #​6670

  • Documentation for options defined by Run, such as --errors-only and
    --init-hook, is now generated alongside checker configuration options.

    Closes #​6938

  • Document that the wrong-import-order (C0411) classification of imports as
    third-party vs first-party depends on the current working directory and
    recommend known-first-party as the deterministic workaround.

    Closes #​8801

  • Clarify related no-else-* messages so they say that only the first elif
    after the reported branch should change. Expand the no-else-return
    documentation to explain later branches and when retaining an elif chain
    can better communicate an exhaustive decision.

    Closes #​9274

  • assignment-from-no-return now names the callable that does not return anything and,
    for functions listed in the new known-side-effects-only-functions option, hints at
    the equivalent function to use instead (e.g. reversed(...) for reverse()).

    Closes #​10383

Internal Changes

  • Add assertDoesNotAddMessages to CheckerTestCase to assert that
    specific messages are not emitted, while allowing other messages to be
    present. This complements assertNoMessages which asserts that no
    messages at all are emitted.

    Refs #​9598

  • The primer now pairs residual messages — first by (symbol, path, obj) and then by
    exact source location — and reports altered messages as a single changed entry with
    a compact diff, rather than as a separate removal + addition. The location-based pass
    also catches symbol renames at the same code position (e.g. used-before-assignment
    → possibly-used-before-assignment). When several messages are eligible, the one
    closest to the original line wins, so pairs never cross. New messages are classified
    into fixed false positives (useless-suppression), astroid-error fatal errors,
    and the rest. astroid-error messages are excluded from pairing (their text embeds
    a unique crash-report path) so persistent crashes keep raising the prominent warning.
    Truncated comments are now cut at a line break and keep their code fences and
    <details> blocks closed.

    Refs #​10914

  • The primer's project cache key is now derived from the commits pinned in
    packages_to_prime.json instead of the remote branch tips. main and PR primer
    runs now share the same project cache and lint files in the same on-disk order,
    removing spurious diffs from primer comments (message positions and astroid inference
    results depend on the order in which modules are linted).

    Closes #​11192

Performance Improvements

  • Lazily import isort, dill, multiprocessing/concurrent.futures,
    and tomlkit so they are only loaded when actually needed.
    This reduces startup time by ~25% (e.g. --version: 91 => 67 ms,
    --help: 176 => 133 ms, single-file lint: 272 => 226 ms).

    Closes #​2866

  • Sped up the duplicate-code checker. When run inside pylint the
    checker now reuses the already-parsed AST instead of re-parsing every
    file like it has to do when launched via symilar, and it uses a
    rolling hash window with caching across file pairs. Additionally, a
    quadratic blow-up in the hash-matching phase is avoided by switching
    algorithm at a threshold, which previously caused the checker to hang
    on files with many repeated lines.

    Speedup scales with codebase size from 1.5x on small projects
    (~10k lines), to 20x on large ones (500k+ lines). Memory usage also
    drops 12-27%. Codebases that previously hung or were OOM-killed could
    now complete.

    Refs #​10881

  • Skip isort classification in the import checker when no import-ordering message is enabled,
    and cache the isort configuration so it is built once instead of once per import statement.
    Skipping the isort processing become a negligible improvement once the caching is applied.
    pylint became 17% faster on ansible (=4500 imports) even with isort enabled.

    Refs #​10886, #​2866, #​10637

  • Finding the files to lint with --recursive=y is faster. Directories matching
    ignore, ignore-patterns or ignore-paths (such as .venv, .git
    or node_modules) are no longer walked, and neither are the packages already
    found. In a checkout of pylint with its virtual environment, this step is about
    three times faster when .git, .tox and .venv are ignored, and about
    twenty times faster when a large ignored tree is present.

    Directories and files are now also visited in sorted order, so the order in
    which files are linted no longer depends on the file system. The order of
    messages can change once for projects whose file system listed directories in
    another order.

    Closes #​11005

v4.0.10

Compare Source

What's new in Pylint 4.0.10?

Release date: 2026-09-29

False Positives Fixed

  • Fix false positives for :ref:unnecessary-lambda when a variable referenced in
    the called expression is assigned, reassigned, or deleted later in the same scope.

    Closes #​8192

  • Fix a false positive for unused-argument in dataclass __new__ methods
    when the arguments are consumed by a generated __init__ method.

    Closes #​9843

  • Fix a false positive for missing-kwoa when keyword-only arguments are passed
    through a **kwargs dictionary that is not a literal at the call site, for
    example one filled with options["key"] = value after its creation.

    Closes #​10029

  • ungrouped-imports no longer reports imports inside mutually exclusive
    OS guard branches (if os.name == "nt": / if sys.platform == "win32":),
    matching the existing behavior for sys.version_info guards.

    Closes #​10460

Other Bug Fixes

  • A TypeError crash could occur when checking a for loop that
    iterates over a subscript with non-numeric constant bounds or a zero
    step, e.g. for a, b in {"k": [][0: ""]}.values():.

    Closes #​11472

  • Fix a crash (AttributeError: 'ClassDef' object has no attribute 'expr') in the
    import-private-name extension when an annotated assignment's value is an
    attribute access on a call rooted at a non-Name node, e.g. x: str = ''().a.

    Closes #​11479

v4.0.9

Compare Source

What's new in Pylint 4.0.9?

Release date: 2026-09-23

Security Fixes

  • Someone without access to the configuration or linted code, but with access
    to the cache directory (predictable PYLINT_HOME on a multi-user host) can no
    longer write a crafted pickle that will runs arbitrary code when pylint access its
    stat cache. The result cache is now stored as JSON instead of pickle,
    preventing code-execution. The workaround is upgrading or not pointing PYLINT_HOME
    to an untrusted, shared, or group-writable directory. The default value, ~/.cache/pylint,
    is writable only by the user running pylint. (CVE with the same information pending)

False Positives Fixed

  • Fixed a false positive for no-self-use on a method that only uses
    self before a locally defined class (or other nested method), because
    the checker's could-be-a-function tracking state was not restored after
    visiting the nested method.

    Closes #​3705

  • Fix a false positive for :ref:not-callable when calling functions constructed with
    types.FunctionType or types.LambdaType.

    Closes #​7500

  • Fix a false positive for unnecessary-direct-lambda-call when a directly called
    lambda in a class body wraps a comprehension containing an assignment expression.
    PEP 572 makes that a SyntaxError without the lambda's scope, so following the
    message produced code that would not compile.

    Closes #​9294

  • Fix a false positive for :ref:unnecessary-ellipsis when an ellipsis is the
    sole body statement of a method defined on a Protocol.

    Closes #​9319

  • Fix a false positive for :ref:bad-exception-cause when the bases of the class
    being raised from cannot be inferred, such as an exception deriving from a
    C extension class. :ref:raising-non-exception and
    :ref:catching-non-exception already guard the same inherit_from_std_ex
    helper with has_known_bases.

    Refs #​11399

False Negatives Fixed

  • method-hidden is no longer silenced when the hidden method shares its name with
    a builtin function or with a function defined at module level. Only members of the
    ancestor classes themselves can excuse the method now.

    Refs #​11361

Other Bug Fixes

  • Fix a block-scoped # pylint: disable= directive placed inside an if
    body leaking into sibling elif/else blocks for messages such as
    stop-iteration-return, which default to a line-based (rather than
    node-based) message scope.

    Closes #​3136

  • Fix a false positive for declare-non-slot when a class variable is
    annotated with ClassVar without an initial value.

    Closes #​9950

  • Fix a crash in the no-member checker when attribute lookup raises an
    InferenceError.

    Closes #​11356

  • Fix a crash in the unnecessary-default-type-args check when a Generator
    or AsyncGenerator subscript holds an empty tuple, such as Generator[()].

    Closes #​11357

  • Fix a crash in method-hidden when a method shadows a name that builtins
    binds to a node without a statement, such as help or license. Every class
    inherits from object, which lives in the builtins module, so no base class
    was needed to trigger it.

    Closes #​11361
    Closes #​8079

astral-sh/ruff-pre-commit (astral-sh/ruff-pre-commit)

v0.16.10

Compare Source

See: https://github.com/astral-sh/ruff/releases/tag/0.16.10

v0.16.9

Compare Source

See: https://github.com/astral-sh/ruff/releases/tag/0.16.9

pre-commit/mirrors-mypy (pre-commit/mirrors-mypy)

v2.4.0

Compare Source

renovatebot/pre-commit-hooks (renovatebot/pre-commit-hooks)

v44.133.0

Compare Source

v44.132.6

Compare Source

See https://github.com/renovatebot/renovate/releases/tag/44.132.6 for more changes

v44.132.5

Compare Source

See https://github.com/renovatebot/renovate/releases/tag/44.132.5 for more changes

v44.132.4

Compare Source

See https://github.com/renovatebot/renovate/releases/tag/44.132.4 for more changes

v44.132.3

Compare Source

See https://github.com/renovatebot/renovate/releases/tag/44.132.3 for more changes

v44.132.2

Compare Source

See https://github.com/renovatebot/renovate/releases/tag/44.132.2 for more changes

v44.131.0

Compare Source

See https://github.com/renovatebot/renovate/releases/tag/44.131.0 for more changes

v44.130.0

Compare Source

See https://github.com/renovatebot/renovate/releases/tag/44.130.0 for more changes

v44.129.0

Compare Source

See https://github.com/renovatebot/renovate/releases/tag/44.129.0 for more changes

v44.128.3

Compare Source

See https://github.com/renovatebot/renovate/releases/tag/44.128.3 for more changes

v44.128.1

Compare Source

See https://github.com/renovatebot/renovate/releases/tag/44.128.1 for more changes

v44.128.0

Compare Source

See https://github.com/renovatebot/renovate/releases/tag/44.128.0 for more changes

v44.127.1

Compare Source

See https://github.com/renovatebot/renovate/releases/tag/44.127.1 for more changes

v44.127.0

Compare Source

See https://github.com/renovatebot/renovate/releases/tag/44.127.0 for more changes

v44.126.0

Compare Source

See https://github.com/renovatebot/renovate/releases/tag/44.126.0 for more changes

v44.125.2

Compare Source

See https://github.com/renovatebot/renovate/releases/tag/44.125.2 for more changes

v44.125.1

Compare Source

See https://github.com/renovatebot/renovate/releases/tag/44.125.1 for more changes

v44.124.2

Compare Source

See https://github.com/renovatebot/renovate/releases/tag/44.124.2 for more changes

v44.123.1

Compare Source

See https://github.com/renovatebot/renovate/releases/tag/44.123.1 for more changes

v44.123.0

Compare Source

See https://github.com/renovatebot/renovate/releases/tag/44.123.0 for more changes

v44.121.4

Compare Source

See https://github.com/renovatebot/renovate/releases/tag/44.121.4 for more changes

v44.121.3

Compare Source

See https://github.com/renovatebot/renovate/releases/tag/44.121.3 for more changes

v44.121.1

Compare Source

See https://github.com/renovatebot/renovate/releases/tag/44.121.1 for more changes

v44.121.0

Compare Source

See https://github.com/renovatebot/renovate/releases/tag/44.121.0 for more changes

v44.120.0

Compare Source

See https://github.com/renovatebot/renovate/releases/tag/44.120.0 for more changes

v44.119.1

Compare Source

See https://github.com/renovatebot/renovate/releases/tag/44.119.1 for more changes

v44.119.0

Compare Source

See https://github.com/renovatebot/renovate/releases/tag/44.119.0 for more changes

v44.118.1

Compare Source

See https://github.com/renovatebot/renovate/releases/tag/44.118.1 for more changes

v44.118.0

Compare Source

See https://github.com/renovatebot/renovate/releases/tag/44.118.0 for more changes

v44.117.2

Compare Source

See https://github.com/renovatebot/renovate/releases/tag/44.117.2 for more changes

v44.117.1

Compare Source

See https://github.com/renovatebot/renovate/releases/tag/44.117.1 for more changes

v44.117.0

Compare Source

See https://github.com/renovatebot/renovate/releases/tag/44.117.0 for more changes

v44.116.1

Compare Source

See https://github.com/renovatebot/renovate/releases/tag/44.116.1 for more changes

v44.116.0

Compare Source

See https://github.com/renovatebot/renovate/releases/tag/44.116.0 for more changes

v44.115.13

Compare Source

See https://github.com/renovatebot/renovate/releases/tag/44.115.13 for more changes

v44.115.12

Compare Source

See https://github.com/renovatebot/renovate/releases/tag/44.115.12 for more changes

v44.115.11

Compare Source

See https://github.com/renovatebot/renovate/releases/tag/44.115.11 for more changes

v44.115.10

Compare Source

See https://github.com/renovatebot/renovate/releases/tag/44.115.10 for more changes

v44.115.9

Compare Source

See https://github.com/renovatebot/renovate/releases/tag/44.115.9 for more changes

v44.115.8

Compare Source

See https://github.com/renovatebot/renovate/releases/tag/44.115.8 for more changes

v44.115.7

Compare Source

See https://github.com/renovatebot/renovate/releases/tag/44.115.7 for more changes

v44.115.6

Compare Source

See https://github.com/renovatebot/renovate/releases/tag/44.115.6 for more changes

v44.115.5

Compare Source

See https://github.com/renovatebot/renovate/releases/tag/44.115.5 for more changes

[v44.115.4](https://redirec

❗ Important

✂ PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • Between 12:00 AM and 03:59 AM, only on Monday (* 0-3 * * 1)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

Copilot AI balanced review requested due to automatic review settings October 5, 2026 03:01
@renovate
renovate Bot requested a review from a team as a code owner October 5, 2026 03:01
@renovate
renovate Bot requested a review from a team as a code owner October 5, 2026 03:01
@deepsource-io

deepsource-io Bot commented Oct 5, 2026

Copy link
Copy Markdown

DeepSource Code Review

We reviewed changes in 67ae90f...abab512 on this pull request. Below is the summary for the review, and you can see the individual issues we found as inline review comments.

See full review on DeepSource ↗

PR Report Card

Overall Grade   Security  

Reliability  

Complexity  

Hygiene  

Code Review Summary

Analyzer Status Updated (UTC) Details
Secrets Oct 5, 2026 3:01a.m. Review ↗
Python Oct 5, 2026 3:01a.m. Review ↗

Important

AI Review is run only on demand for your team. We're only showing results of static analysis review right now. To trigger AI Review, comment @deepsourcebot review on this thread.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Updated remote revisions and hook compatibility could not be verified offline.

Review effort: Balanced
Findings: None

What changed in this PR

Updates pre-commit tooling pins used by the SDK’s development and CI checks.

Changes:

  • Upgrades Ruff, Pylint, isort, Flake8, and mypy.
  • Updates the Renovate configuration validator.
  • Leaves hook settings and execution stages unchanged.
File Description
.pre-commit-config.yaml Updates six tooling revisions.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@cowan-macady
cowan-macady merged commit 872e0fb into master Oct 5, 2026
13 checks passed
@cowan-macady
cowan-macady deleted the renovate/ci-configs branch October 5, 2026 06:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants