-
Notifications
You must be signed in to change notification settings - Fork 250
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
chore(deps): bump black from 24.8.0 to 24.10.0 #1194
Conversation
Codecov ReportAll modified and coverable lines are covered by tests ✅
Additional details and impacted files@@ Coverage Diff @@
## main #1194 +/- ##
=======================================
Coverage 90.93% 90.93%
=======================================
Files 222 222
Lines 7505 7505
=======================================
Hits 6825 6825
Misses 680 680 ☔ View full report in Codecov by Sentry. |
@@ -1,3 +1,3 @@ | |||
mypy==1.11.2 | |||
flake8==6.0.0 | |||
black==24.8.0 # Until we drop Python 3.6 support, we have to stay with this version | |||
black==24.10.0 # Until we drop Python 3.6 support, we have to stay with this version |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
@WilliamBergamin @seratch Dependabot would like to bump us to [email protected]
from 24.8.0
. The Release Notes mention dropping Python 3.8 support and the comment above mentions that we still support Python 3.6. So, it sounds like the latest version of black may not run reliably on Python 3.6.
What's your advice on this PR?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
@mwbrooks Thanks for checking this. Upgrading black to a newer version does not bring any benefits and I personally think still we should keep 3.6 support for a while (say, one or two more years). It's indeed EOLed a long time ago! but for Python and Java, providing much longer supports for EOLed versions would be expected in many cases.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thanks @seratch! Is there a range syntax that we can use to prevent @dependabot from trying to upgrade it? For example black<=24.8.0
?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Run all the unit tests / build (3.6) (pull_request)
The test execution does not fail (because it does not use black) but let's keep the current black version this time
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thanks @seratch! Is there a range syntax that we can use to prevent https://github.com/dependabot from trying to upgrade it? For example black<=24.8.0?
Hmm, honestly i am not sure about the way to prevent this. Even if you use a version range, the bot still tries to upgrade to newer range 😅
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Ah, alright. Well, the comment left on the dependency was enough for me to question accepting the upgrade. Hopefully it'll be enough for other reviewers to know that we don't want to upgrade it yet.
4d5119f
to
dbee0f6
Compare
Bumps [black](https://github.com/psf/black) from 24.8.0 to 24.10.0. - [Release notes](https://github.com/psf/black/releases) - [Changelog](https://github.com/psf/black/blob/main/CHANGES.md) - [Commits](psf/black@24.8.0...24.10.0) --- updated-dependencies: - dependency-name: black dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <[email protected]>
dbee0f6
to
4e237c1
Compare
@dependabot don't upgrade this dependency from now on |
@dependabot ignore this dependency |
OK, I won't notify you about black again, unless you re-open this PR. |
Bumps black from 24.8.0 to 24.10.0.
Release notes
Sourced from black's releases.
Changelog
Sourced from black's changelog.
Commits
1b2427a
Prepare release 24.10.0 (#4471)a22b1eb
Add mypyc 3.13 wheel build (#4449)b7d0e72
Bump AndreMiras/coveralls-python-action from 65c1672f0b8a201702d86c81b79187df...f1a2f92
Include --unstable in cache key (#4466)8d9d18c
Fix skipping Jupyter cells with unknown %% magic (#4462)bbfdba3
Fix docs CI: use venv for uv to fix 'failed to create directory' (#4460)8fb2add
Use builtin generics (#4458)2a45cec
Fix crashes with comments in parentheses (#4453)b4d6d86
Drop Python 3.8 support (#4452)ac018c1
Require newer aiohttp for blackd (#4451)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebase
will rebase this PR@dependabot recreate
will recreate this PR, overwriting any edits that have been made to it@dependabot merge
will merge this PR after your CI passes on it@dependabot squash and merge
will squash and merge this PR after your CI passes on it@dependabot cancel merge
will cancel a previously requested merge and block automerging@dependabot reopen
will reopen this PR if it is closed@dependabot close
will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditions
will show all of the ignore conditions of the specified dependency@dependabot ignore this major version
will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor version
will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependency
will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)