Skip to content

deps: update tomli requirement from >=2.0.1 to >=2.4.1 - #54

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/tomli-gte-2.4.1
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/pip/tomli-gte-2.4.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 13, 2026

Copy link
Copy Markdown
Contributor

Updates the requirements on tomli to permit the latest version.

Changelog

Sourced from tomli's changelog.

2.4.1

  • Fixed
    • Limit number of parts of a TOML key to address quadratic time complexity

2.4.0

  • Added
    • TOML v1.1.0 compatibility
    • Binary wheels for Windows arm64

2.3.0

  • Added
    • Binary wheels for Python 3.14 (also free-threaded)
  • Performance
    • Reduced import time

2.2.1

  • Fixed
    • Don't attempt to compile binary wheels for Python 3.8, 3.9 and 3.10 where cibuildwheel depends on a conflicting Tomli version

2.2.0

  • Added
    • mypyc generated binary wheels for common platforms

2.1.0

  • Deprecated
    • Instantiating TOMLDecodeError with free-form arguments. msg, doc and pos arguments should be given.
  • Added
    • msg, doc, pos, lineno and colno attributes to TOMLDecodeError

2.0.2

  • Removed
    • Python 3.7 support
  • Improved
    • Make loads raise TypeError not AttributeError on bad input types that do not have the replace attribute. Improve error message when bytes is received.
  • Type annotations
    • Type annotate load input as typing.IO[bytes] (previously typing.BinaryIO).

2.0.1

  • Improved
    • Make bundling easier by using relative imports internally and adding license and copyright notice to source files.

... (truncated)

Commits
  • c5f4469 Bump version: 2.4.0 → 2.4.1
  • 2bcd262 Add change log for 2.4.1 and 2.3.1
  • e1fdb94 Limit number of parts of a key (#286)
  • c20c491 pre-commit autoupdate
  • 920e20b Update performance benchmark and results
  • 064e492 Merge pull request #280 from hukkin/version-2.4.0
  • a678e6f Bump version: 2.3.0 → 2.4.0
  • b8a1358 Tests: remove now needless "TOML compliance"->"burntsushi" format conversion
  • 4979375 Update GitHub actions
  • f890dd1 Update pre-commit hooks
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Updates the requirements on [tomli](https://github.com/hukkin/tomli) to permit the latest version.
- [Changelog](https://github.com/hukkin/tomli/blob/master/CHANGELOG.md)
- [Commits](hukkin/tomli@2.0.1...2.4.1)

---
updated-dependencies:
- dependency-name: tomli
  dependency-version: 2.4.1
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Sep 13, 2026
@SackOfHacks

Copy link
Copy Markdown
Owner

Holding this one rather than merging with the action bumps — as written it introduces the exact drift requirements.txt warns about.

The PR changes only requirements.txt:

-tomli>=2.0.1; python_version < "3.11"
+tomli>=2.4.1; python_version < "3.11"

while pyproject.toml:49 stays at tomli>=2.0.1. The file’s own header says “Keep in sync with pyproject.toml [project.dependencies]”, so merging this breaks that invariant on the first line it touches.

It would also have no practical effect: pip install pcapper resolves from pyproject.toml, so the installed floor stays 2.0.1 regardless. And there is no Dependabot alert on tomli — this is a "newest version" bump, not a security fix.

If the floor should move, both files need to move together. Worth considering whether requirements.txt should instead be generated from pyproject.toml, or reduced to -e ., so the two cannot drift again — the manual-sync comment is doing work that tooling could do.

SackOfHacks added a commit that referenced this pull request Sep 13, 2026
…r bumps (#55)

requirements.txt has said "Keep in sync with pyproject.toml
[project.dependencies]" since it was written, and nothing enforced it.
Dependabot then proposed raising tomli>=2.0.1 to >=2.4.1 in
requirements.txt alone (#54), which would have left the two manifests
disagreeing on the first line it touched -- silently, since installs
resolve from pyproject.toml, so the requirements floor has no effect on
what a user actually gets. A manual-sync comment is not a control.

TestRequirementsMatchPyproject compares the two dependency sets with
whitespace and quote noise normalised away, so the environment marker
on tomli does not produce a false difference. Verified it bites by
simulating #54: it names tomli>=2.4.1 as present only in
requirements.txt. A second case asserts the parse is non-empty, so an
empty read cannot make the comparison vacuous.

The second half is the reason that PR existed at all. Dependabot's pip
default versioning-strategy is "increase", which raises a `>=` floor on
every upstream release whether or not anything needs it -- proposing
churn with no security driver, and dropping support for environments
the code runs on perfectly well. increase-if-necessary moves a floor
only when the existing constraint genuinely excludes the new version.
Security updates still raise floors when they have to.
@SackOfHacks

Copy link
Copy Markdown
Owner

Closing in favour of #55, which fixes the cause rather than the symptom.

Two things land there:

  1. TestRequirementsMatchPyproject — the sync this PR would have broken is now an assertion instead of a comment. Verified against this exact change: it reports tomli>=2.4.1 as present only in requirements.txt.
  2. versioning-strategy: increase-if-necessary — Dependabot's pip default (increase) raises a >= floor on every upstream release regardless of need, which is why this PR existed with no security advisory behind it. Floors now move only when the current constraint genuinely excludes the new version; security updates still raise them when they have to.

No objection to tomli 2.4.1 itself — but it would need to move in pyproject.toml too, and there is nothing asking for it.

@dependabot @github

dependabot Bot commented on behalf of github Sep 13, 2026

Copy link
Copy Markdown
Contributor Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@SackOfHacks
SackOfHacks deleted the dependabot/pip/tomli-gte-2.4.1 branch September 13, 2026 17:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant