Skip to content

Python dependency: Update setuptools requirement from ==82.* to ==83.* in /web/regression#10145

Closed
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/pip/web/regression/setuptools-eq-83.star
Closed

Python dependency: Update setuptools requirement from ==82.* to ==83.* in /web/regression#10145
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/pip/web/regression/setuptools-eq-83.star

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 6, 2026

Copy link
Copy Markdown
Contributor

Updates the requirements on setuptools to permit the latest version.

Changelog

Sourced from setuptools's changelog.

v83.0.0

Features

  • Require Python 3.10 or later.

Bugfixes

  • MANIFEST.in matching (via FileList) is now insensitive to Unicode normalization form. A pattern authored in one form (e.g. NFC, as typically saved by editors) now matches a file whose name is stored on disk in another (e.g. NFD, as produced by macOS APFS/HFS+). Previously an exclude, global-exclude, recursive-exclude, or prune rule could silently fail to drop a non-ASCII-named file from the source distribution, publishing it despite the exclusion -- see GHSA-h35f-9h28-mq5c.

Deprecations and Removals

  • pypa/distutils#334

v82.0.1

Bugfixes

  • Fix the loading of launcher manifest.xml file. (#5047)
  • Replaced deprecated json.__version__ with fixture in tests. (#5186)

Improved Documentation

  • Add advice about how to improve predictability when installing sdists. (#5168)

Misc

v82.0.0

... (truncated)

Commits
  • 6519f72 Bump version: 82.0.1 → 83.0.0
  • d1151b1 Merge pull request #5250 from pypa/feature/distutils-d7633fbed
  • a2df31e Capture removal of dry_run parameter in changelog.
  • 00144dc Moved newsfragment to the release where it occurred.
  • a4a5a2b Add news fragment.
  • 77470c2 Merge https://github.com/pypa/distutils into feature/distutils-d7633fbed
  • 3c43897 Merge pull request #5247 from pypa/copilot/fix-pypy-version-issue
  • bb6ea66 Bump PyPy from 3.10 to 3.11 in CI workflow
  • a2bc3ac Fix broken intersphinx reference to build's installation docs
  • 2d6a739 Use stacked parametrize decorators instead of itertools.product
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Updates the requirements on [setuptools](https://github.com/pypa/setuptools) to permit the latest version.
- [Release notes](https://github.com/pypa/setuptools/releases)
- [Changelog](https://github.com/pypa/setuptools/blob/main/NEWS.rst)
- [Commits](pypa/setuptools@v82.0.0...v83.0.0)

---
updated-dependencies:
- dependency-name: setuptools
  dependency-version: 83.0.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the Dependencies Pull requests that update a dependency file label Jul 6, 2026
asheshv added a commit that referenced this pull request Jul 24, 2026
…, shell-quote, svgo) (#10199)

Supersedes 7 open Dependabot PRs by applying the safe ones and
properly fixing the one with a broken lockfile, in one CI cycle:

- setuptools ==82.* -> ==83.* (#10144, #10145 - duplicate PRs, same
  patch). Only touches the `python_version > '3.9'` line; the
  `<82; python_version <= '3.9'` gate for Python 3.9 is untouched,
  so this doesn't affect Python 3.9 support.
- fast-uri 3.1.2 -> 3.1.4 in both /web and /runtime (#10183, #10195)
  - fixes two real CVEs (GHSA-v2hh-gcrm-f6hx, GHSA-4c8g-83qw-93j6).
- tar 7.5.16 -> 7.5.21 (#10182) - patch series, decompression-bomb
  and unbounded-recursion hardening only.
- shell-quote 1.8.4 -> 1.10.0 (#10185) - additive opt-in option +
  parser fixes, no breaking changes.
- svgo 3.3.3 -> 4.0.2 (#10184) - Dependabot's own PR left yarn.lock
  internally inconsistent (dropped the workspace-level `svgo` entry
  while merging version-range blocks), so `yarn install --immutable`
  failed in CI with "the lockfile would have been modified by this
  install". Regenerated properly via `yarn up`/`yarn dedupe` here.
  The direct `svgo`/`svgo-loader` deps are not actually wired into
  any webpack rule (verified via grep) - the real SVG pipeline is
  `@svgr/webpack` -> `@svgr/plugin-svgo` -> svgo 3.3.3, which this
  bump does not touch - so the major version jump has no build
  impact. `yarn.lock` now correctly keeps that separate 3.3.3
  resolution alongside the deduped 4.0.2 one.

Not included (structurally blocked, tracked separately):
- paramiko 3.5.1 -> 5.0.0 (#9927): paramiko 5 removes DSSKey
  entirely; sshtunnel 0.4.0 (dormant since 2021) still references
  paramiko.DSSKey, so `import sshtunnel` would crash immediately.
- pywinpty 2.0.* -> 3.0.* (#10082, #10084): the existing pin cites
  andfoy/pywinpty#545, confirmed still
  open ("process read and write not working as expected in 3.x").

Verified: `yarn install --immutable` clean in both /web and
/runtime, `yarn run linter` clean, full `yarn run bundle:dev`
compiles successfully.
@dependabot @github

dependabot Bot commented on behalf of github Jul 24, 2026

Copy link
Copy Markdown
Contributor Author

Looks like setuptools is no longer updatable, so this is no longer needed.

@dependabot dependabot Bot closed this Jul 24, 2026
@dependabot
dependabot Bot deleted the dependabot/pip/web/regression/setuptools-eq-83.star branch July 24, 2026 20:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants