deps: update tomli requirement from >=2.0.1 to >=2.4.1 - #54
dependabot[bot] wants to merge 1 commit into
Conversation
Updates the requirements on [tomli](https://github.com/hukkin/tomli) to permit the latest version. - [Changelog](https://github.com/hukkin/tomli/blob/master/CHANGELOG.md) - [Commits](hukkin/tomli@2.0.1...2.4.1) --- updated-dependencies: - dependency-name: tomli dependency-version: 2.4.1 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
|
Holding this one rather than merging with the action bumps — as written it introduces the exact drift The PR changes only while It would also have no practical effect: If the floor should move, both files need to move together. Worth considering whether |
…r bumps (#55) requirements.txt has said "Keep in sync with pyproject.toml [project.dependencies]" since it was written, and nothing enforced it. Dependabot then proposed raising tomli>=2.0.1 to >=2.4.1 in requirements.txt alone (#54), which would have left the two manifests disagreeing on the first line it touched -- silently, since installs resolve from pyproject.toml, so the requirements floor has no effect on what a user actually gets. A manual-sync comment is not a control. TestRequirementsMatchPyproject compares the two dependency sets with whitespace and quote noise normalised away, so the environment marker on tomli does not produce a false difference. Verified it bites by simulating #54: it names tomli>=2.4.1 as present only in requirements.txt. A second case asserts the parse is non-empty, so an empty read cannot make the comparison vacuous. The second half is the reason that PR existed at all. Dependabot's pip default versioning-strategy is "increase", which raises a `>=` floor on every upstream release whether or not anything needs it -- proposing churn with no security driver, and dropping support for environments the code runs on perfectly well. increase-if-necessary moves a floor only when the existing constraint genuinely excludes the new version. Security updates still raise floors when they have to.
|
Closing in favour of #55, which fixes the cause rather than the symptom. Two things land there:
No objection to |
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
Updates the requirements on tomli to permit the latest version.
Changelog
Sourced from tomli's changelog.
... (truncated)
Commits
c5f4469Bump version: 2.4.0 → 2.4.12bcd262Add change log for 2.4.1 and 2.3.1e1fdb94Limit number of parts of a key (#286)c20c491pre-commit autoupdate920e20bUpdate performance benchmark and results064e492Merge pull request #280 from hukkin/version-2.4.0a678e6fBump version: 2.3.0 → 2.4.0b8a1358Tests: remove now needless "TOML compliance"->"burntsushi" format conversion4979375Update GitHub actionsf890dd1Update pre-commit hooksDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)