build(deps-dev): bump types-toml from 0.10.8.20260408 to 0.10.8.20260518 - #25
Conversation
Bumps [types-toml](https://github.com/python/typeshed) from 0.10.8.20260408 to 0.10.8.20260518. - [Commits](https://github.com/python/typeshed/commits) --- updated-dependencies: - dependency-name: types-toml dependency-version: 0.10.8.20260518 dependency-type: direct:development update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
nishantmodak
left a comment
There was a problem hiding this comment.
Reviewed the full types-toml lockfile update and the actual installed stub diff at 18f68f8c865b869929f8d2e2ba1fc535f734bda2. No actionable blocker found. The semantic change moves TypeAlias from typing_extensions to typing; both versions require Python>=3.10, matching this repository. Public signatures are unchanged, and repository runtime configuration uses tomli rather than toml.
Validation: exact base/head package hashes verified. Native mypy1.20.1 checks pass for Python3.10,3.11 and3.12 targets on both versions: valid text/path/list/text-stream/custom-mapping/encoder calls are accepted, while all three invalid input contracts are rejected. All13CIchecks report success.
Limits: these are type-check targets on local Python3.12/macOS, not three interpreter runs. No additional runtime harness or full application suite was needed for this stub-only change. The full dev lock has an unchanged cryptography/cffi resolution conflict; changed packages were installed in isolation, and CI uses pyproject extras.
Bumps types-toml from 0.10.8.20260408 to 0.10.8.20260518.
Commits
You can trigger a rebase of this PR by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)