chore(deps-dev): bump coverage from 7.15.2 to 7.15.4 - #257
Conversation
Bumps [coverage](https://github.com/coveragepy/coveragepy) from 7.15.2 to 7.15.4. - [Release notes](https://github.com/coveragepy/coveragepy/releases) - [Changelog](https://github.com/coveragepy/coveragepy/blob/main/CHANGES.rst) - [Commits](coveragepy/coveragepy@7.15.2...7.15.4) --- updated-dependencies: - dependency-name: coverage dependency-version: 7.15.4 dependency-type: direct:development update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
There was a problem hiding this comment.
LGTM — trivial dev-dependency patch bump.
What was reviewed: the single-line version bump of coverage (7.15.2 → 7.15.4) in requirements-dev.txt, a pinned dev/test-only dependency used via pytest-cov. Confirmed no other lines in the lockfile changed and no transitive pins were affected.
Extended reasoning...
Overview
This PR is an automated Dependabot bump of coverage from 7.15.2 to 7.15.4 in requirements-dev.txt, a pip-compile-generated lockfile. The only change is the pinned version string on one line; the comment (# via pytest-cov) is unchanged.
Security risks
None applicable to this repo. The upstream fixes in 7.15.3/7.15.4 (HTML report href escaping, LCOV control-character neutralization) address issues in coverage's own report-writing code, not in pyUSPTO. coverage is a dev/test-only dependency and is never shipped or run in production paths of this library.
Level of scrutiny
Minimal scrutiny is warranted: this is a mechanical, single-line dev-dependency version bump with no code changes in the repository itself, generated by pip-compile/Dependabot.
Other factors
No prior reviews exist on this PR. The diff is fully contained in the lockfile and matches the expected pip-compile output.
Bumps coverage from 7.15.2 to 7.15.4.
Release notes
Sourced from coverage's releases.
Changelog
Sourced from coverage's changelog.
Commits
4c0e7ffdocs: sample HTML for 7.15.4db4cc32docs: prep for 7.15.4c33085cstyle: start gradual move to ruff 0.1653a0fd5fix: neutralize control characters in lcov report fields (#2226)b64d53dbuild: make 3.15 wheels53792abbuild: show the python version for kitsf6b03c7chore: make upgrade_one package=cibuildwheeld9b660achore: make upgradeb128a31docs: oops, move this entry to the correct placea7a2c15fix: escape filename urls in html report href attributes (#2227)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)