dependabot[bot] opened a new pull request, #73335: URL: https://github.com/apache/airflow/pull/73335
Bumps the uv-dependency-updates group in /dev/breeze with 2 updates: [prek](https://github.com/j178/prek) and [semver](https://github.com/python-semver/python-semver). Updates `prek` from 0.5.2 to 0.5.3 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/j178/prek/releases">prek's releases</a>.</em></p> <blockquote> <h2>0.5.3</h2> <h2>Release Notes</h2> <p>Released on 2026-09-13.</p> <h3>Enhancements</h3> <ul> <li>Add PEP 740 attestations for PyPI releases (<a href="https://redirect.github.com/j178/prek/pull/2705">#2705</a>)</li> <li>Add a <code>check-jsonc</code> builtin hook (<a href="https://redirect.github.com/j178/prek/pull/2682">#2682</a>)</li> <li>Allow disabling automatic uv installation (<a href="https://redirect.github.com/j178/prek/pull/2702">#2702</a>)</li> </ul> <h3>Bug fixes</h3> <ul> <li>Fix Julia additional dependency specifiers (<a href="https://redirect.github.com/j178/prek/pull/2703">#2703</a>)</li> <li>Update <code>granit-parser</code> to fix YAML flow indentation (<a href="https://redirect.github.com/j178/prek/pull/2707">#2707</a>)</li> </ul> <h3>Contributors</h3> <ul> <li><a href="https://github.com/clbarnes"><code>@clbarnes</code></a></li> <li><a href="https://github.com/j178"><code>@j178</code></a></li> <li><a href="https://github.com/tisonkun"><code>@tisonkun</code></a></li> </ul> <h2>Install prek 0.5.3</h2> <h3>Install prebuilt binaries via shell script</h3> <pre lang="sh"><code>curl --proto '=https' --tlsv1.2 -LsSf https://github.com/j178/prek/releases/download/v0.5.3/prek-installer.sh | sh </code></pre> <h3>Install prebuilt binaries via powershell script</h3> <pre lang="sh"><code>powershell -ExecutionPolicy Bypass -c "irm https://github.com/j178/prek/releases/download/v0.5.3/prek-installer.ps1 | iex" </code></pre> <h3>Install prebuilt binaries via Homebrew</h3> <pre lang="sh"><code>brew install prek </code></pre> <h2>Download prek 0.5.3</h2> <table> <thead> <tr> <th>File</th> <th>Platform</th> <th>Checksum</th> </tr> </thead> <tbody> <tr> <td><a href="https://github.com/j178/prek/releases/download/v0.5.3/prek-aarch64-apple-darwin.tar.gz">prek-aarch64-apple-darwin.tar.gz</a></td> <td>Apple Silicon macOS</td> <td><a href="https://github.com/j178/prek/releases/download/v0.5.3/prek-aarch64-apple-darwin.tar.gz.sha256">checksum</a></td> </tr> <tr> <td><a href="https://github.com/j178/prek/releases/download/v0.5.3/prek-x86_64-apple-darwin.tar.gz">prek-x86_64-apple-darwin.tar.gz</a></td> <td>Intel macOS</td> <td><a href="https://github.com/j178/prek/releases/download/v0.5.3/prek-x86_64-apple-darwin.tar.gz.sha256">checksum</a></td> </tr> <tr> <td><a href="https://github.com/j178/prek/releases/download/v0.5.3/prek-aarch64-pc-windows-msvc.zip">prek-aarch64-pc-windows-msvc.zip</a></td> <td>ARM64 Windows</td> <td><a href="https://github.com/j178/prek/releases/download/v0.5.3/prek-aarch64-pc-windows-msvc.zip.sha256">checksum</a></td> </tr> <tr> <td><a href="https://github.com/j178/prek/releases/download/v0.5.3/prek-x86_64-pc-windows-msvc.zip">prek-x86_64-pc-windows-msvc.zip</a></td> <td>x64 Windows</td> <td><a href="https://github.com/j178/prek/releases/download/v0.5.3/prek-x86_64-pc-windows-msvc.zip.sha256">checksum</a></td> </tr> </tbody> </table> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/j178/prek/blob/master/CHANGELOG.md">prek's changelog</a>.</em></p> <blockquote> <h2>0.5.3</h2> <p>Released on 2026-09-13.</p> <h3>Enhancements</h3> <ul> <li>Add PEP 740 attestations for PyPI releases (<a href="https://redirect.github.com/j178/prek/pull/2705">#2705</a>)</li> <li>Add a <code>check-jsonc</code> builtin hook (<a href="https://redirect.github.com/j178/prek/pull/2682">#2682</a>)</li> <li>Allow disabling automatic uv installation (<a href="https://redirect.github.com/j178/prek/pull/2702">#2702</a>)</li> </ul> <h3>Bug fixes</h3> <ul> <li>Fix Julia additional dependency specifiers (<a href="https://redirect.github.com/j178/prek/pull/2703">#2703</a>)</li> <li>Update <code>granit-parser</code> to fix YAML flow indentation (<a href="https://redirect.github.com/j178/prek/pull/2707">#2707</a>)</li> </ul> <h3>Contributors</h3> <ul> <li><a href="https://github.com/clbarnes"><code>@clbarnes</code></a></li> <li><a href="https://github.com/j178"><code>@j178</code></a></li> <li><a href="https://github.com/tisonkun"><code>@tisonkun</code></a></li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/j178/prek/commit/b7eb6027125de7e3b67dd94039a4f69abf3a5fb0"><code>b7eb602</code></a> Bump version to 0.5.3 (<a href="https://redirect.github.com/j178/prek/issues/2708">#2708</a>)</li> <li><a href="https://github.com/j178/prek/commit/4644f81e1c86eeb8e22a1ba4aaa6dec99b4266c5"><code>4644f81</code></a> Update granit-parser to fix YAML flow indentation (<a href="https://redirect.github.com/j178/prek/issues/2707">#2707</a>)</li> <li><a href="https://github.com/j178/prek/commit/87f2ea44c258dc6606ca5556a7b3ff0d9a0a601e"><code>87f2ea4</code></a> Use self-repository syntax in CI workflows</li> <li><a href="https://github.com/j178/prek/commit/f39abae3cafd9ff245843b790fdd9b7c2e933b5c"><code>f39abae</code></a> Add PEP 740 attestations for PyPI releases (<a href="https://redirect.github.com/j178/prek/issues/2705">#2705</a>)</li> <li><a href="https://github.com/j178/prek/commit/f4924dccacd86afab22ae45e634d7f9ca12dd59e"><code>f4924dc</code></a> Allow disabling automatic uv installation (<a href="https://redirect.github.com/j178/prek/issues/2702">#2702</a>)</li> <li><a href="https://github.com/j178/prek/commit/156c0cec12847513ba764d1d87543ab6d0785c64"><code>156c0ce</code></a> Fix Julia additional dependency specifiers (<a href="https://redirect.github.com/j178/prek/issues/2703">#2703</a>)</li> <li><a href="https://github.com/j178/prek/commit/c3ede77b83e7d578e31d076863b755b296256a21"><code>c3ede77</code></a> Add a <code>check-jsonc</code> builtin hook (<a href="https://redirect.github.com/j178/prek/issues/2682">#2682</a>)</li> <li><a href="https://github.com/j178/prek/commit/c0b9749c3ee43f42efd0116624a7922feded3fc2"><code>c0b9749</code></a> Verify checksums for PyPI/mirror wheel installs (<a href="https://redirect.github.com/j178/prek/issues/2688">#2688</a>)</li> <li><a href="https://github.com/j178/prek/commit/fbe5c66737e679f31018dd438d16774c19c6774d"><code>fbe5c66</code></a> Update prek hooks (<a href="https://redirect.github.com/j178/prek/issues/2690">#2690</a>)</li> <li><a href="https://github.com/j178/prek/commit/4687a2c57f8ae58cf0e66b65baf49ea72ccb62ba"><code>4687a2c</code></a> Fix <code>check-hooks-apply</code> for builtin Windows filename checks</li> <li>Additional commits viewable in <a href="https://github.com/j178/prek/compare/v0.5.2...v0.5.3">compare view</a></li> </ul> </details> <br /> Updates `semver` from 3.0.4 to 3.1.0 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/python-semver/python-semver/releases">semver's releases</a>.</em></p> <blockquote> <h2>3.1.0</h2> <h2>What's Changed</h2> <ul> <li>Fix <a href="https://redirect.github.com/python-semver/python-semver/issues/463">#463</a>: Remove duplicate code Version.bump_build by <a href="https://github.com/tomschr"><code>@tomschr</code></a> in <a href="https://redirect.github.com/python-semver/python-semver/pull/464">python-semver/python-semver#464</a></li> <li>Fix <a href="https://redirect.github.com/python-semver/python-semver/issues/460">#460</a> Improve bump_prerelease to alway get a newer version by <a href="https://github.com/Learloj"><code>@Learloj</code></a> in <a href="https://redirect.github.com/python-semver/python-semver/pull/462">python-semver/python-semver#462</a></li> <li>441 update pydantic section of docs by <a href="https://github.com/jbkroner"><code>@jbkroner</code></a> in <a href="https://redirect.github.com/python-semver/python-semver/pull/442">python-semver/python-semver#442</a></li> <li>Fix <a href="https://redirect.github.com/python-semver/python-semver/issues/448">#448</a>: Remove Python 3.7-3.9 (EOL) by <a href="https://github.com/tomschr"><code>@tomschr</code></a> in <a href="https://redirect.github.com/python-semver/python-semver/pull/470">python-semver/python-semver#470</a></li> <li>fix: replace semver.parse() with semver.Version.parse() in docstrings by <a href="https://github.com/koteshyelamati"><code>@koteshyelamati</code></a> in <a href="https://redirect.github.com/python-semver/python-semver/pull/471">python-semver/python-semver#471</a></li> <li>fix: next_version should bump version for build-only versions by <a href="https://github.com/binggao1230"><code>@binggao1230</code></a> in <a href="https://redirect.github.com/python-semver/python-semver/pull/469">python-semver/python-semver#469</a></li> <li>fix(next_version): reset prerelease when token changes (<a href="https://redirect.github.com/python-semver/python-semver/issues/339">#339</a>) by <a href="https://github.com/Mukller"><code>@Mukller</code></a> in <a href="https://redirect.github.com/python-semver/python-semver/pull/472">python-semver/python-semver#472</a></li> <li>Bump cryptography from 49.0.0 to 50.0.0 by <a href="https://github.com/dependabot"><code>@dependabot</code></a>[bot] in <a href="https://redirect.github.com/python-semver/python-semver/pull/473">python-semver/python-semver#473</a></li> <li>Declare support for Python 3.15 by <a href="https://github.com/edgarrmondragon"><code>@edgarrmondragon</code></a> in <a href="https://redirect.github.com/python-semver/python-semver/pull/475">python-semver/python-semver#475</a></li> <li>Add optional native parser backend (minimal adapter) by <a href="https://github.com/lowmiaq-gmail"><code>@lowmiaq-gmail</code></a> in <a href="https://redirect.github.com/python-semver/python-semver/pull/476">python-semver/python-semver#476</a></li> <li>Reject non-ASCII digits and trailing newlines in version parsing by <a href="https://github.com/Str0k"><code>@Str0k</code></a> in <a href="https://redirect.github.com/python-semver/python-semver/pull/478">python-semver/python-semver#478</a></li> <li>Fix bump_build() silently returning an unchanged version for digitless build metadata by <a href="https://github.com/Str0k"><code>@Str0k</code></a> in <a href="https://redirect.github.com/python-semver/python-semver/pull/480">python-semver/python-semver#480</a></li> <li>Handle malformed collection operands in Version comparisons by <a href="https://github.com/Str0k"><code>@Str0k</code></a> in <a href="https://redirect.github.com/python-semver/python-semver/pull/479">python-semver/python-semver#479</a></li> <li>Change version to 3.1.0 by <a href="https://github.com/tomschr"><code>@tomschr</code></a> in <a href="https://redirect.github.com/python-semver/python-semver/pull/481">python-semver/python-semver#481</a></li> </ul> <h2>New Contributors</h2> <ul> <li><a href="https://github.com/Learloj"><code>@Learloj</code></a> made their first contribution in <a href="https://redirect.github.com/python-semver/python-semver/pull/462">python-semver/python-semver#462</a></li> <li><a href="https://github.com/jbkroner"><code>@jbkroner</code></a> made their first contribution in <a href="https://redirect.github.com/python-semver/python-semver/pull/442">python-semver/python-semver#442</a></li> <li><a href="https://github.com/koteshyelamati"><code>@koteshyelamati</code></a> made their first contribution in <a href="https://redirect.github.com/python-semver/python-semver/pull/471">python-semver/python-semver#471</a></li> <li><a href="https://github.com/binggao1230"><code>@binggao1230</code></a> made their first contribution in <a href="https://redirect.github.com/python-semver/python-semver/pull/469">python-semver/python-semver#469</a></li> <li><a href="https://github.com/Mukller"><code>@Mukller</code></a> made their first contribution in <a href="https://redirect.github.com/python-semver/python-semver/pull/472">python-semver/python-semver#472</a></li> <li><a href="https://github.com/dependabot"><code>@dependabot</code></a>[bot] made their first contribution in <a href="https://redirect.github.com/python-semver/python-semver/pull/473">python-semver/python-semver#473</a></li> <li><a href="https://github.com/edgarrmondragon"><code>@edgarrmondragon</code></a> made their first contribution in <a href="https://redirect.github.com/python-semver/python-semver/pull/475">python-semver/python-semver#475</a></li> <li><a href="https://github.com/lowmiaq-gmail"><code>@lowmiaq-gmail</code></a> made their first contribution in <a href="https://redirect.github.com/python-semver/python-semver/pull/476">python-semver/python-semver#476</a></li> <li><a href="https://github.com/Str0k"><code>@Str0k</code></a> made their first contribution in <a href="https://redirect.github.com/python-semver/python-semver/pull/478">python-semver/python-semver#478</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/python-semver/python-semver/compare/3.0.4...3.1.0">https://github.com/python-semver/python-semver/compare/3.0.4...3.1.0</a> <strong>Documentation</strong>: <a href="https://python-semver.readthedocs.io/en/latest/">https://python-semver.readthedocs.io/en/latest/</a></p> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/python-semver/python-semver/blob/master/CHANGELOG.rst">semver's changelog</a>.</em></p> <blockquote> <h1>Version 3.1.0</h1> <p>:Released: 2026-09-12 :Maintainer: Tom Schraitle</p> <h2>Bug Fixes</h2> <ul> <li> <p>:pr:<code>478</code>: <code>Version.parse()</code> and <code>Version.is_valid()</code> now reject non-ASCII digits and trailing newlines, in accordance with the SemVer grammar. Optional minor and patch parsing applies the same character restrictions.</p> </li> <li> <p>:pr:<code>479</code>: Comparing a :class:<code>~semver.Version</code> with a <code>dict</code>, <code>tuple</code>, or <code>list</code> that cannot construct a valid version (for example, an empty collection, wrong number of parts, non-numeric parts, or unknown keys) no longer raises internal errors from <code>Version.__init__</code>. The comparison operators now return :py:const:<code>NotImplemented</code> for such operands, following the general rule for invalid comparison operand types: equality evaluates to <code>False</code> and ordering raises Python's standard :py:exc:<code>TypeError</code> (for example, <code>'>' not supported between instances of 'Version' and 'dict'</code>).</p> </li> <li> <p>:pr:<code>480</code>: (:meth:<code>~semver.version.Version.bump_build</code>) will now add <code>.0</code> to an existing build when the last segment of the current build metadata, split by dots (<code>.</code>), is not numeric. This is to ensure the bumped version contains a raised build instead of silently returning an unchanged version. For example, <code>1.2.3+alpha</code> is bumped to <code>1.2.3+alpha.0</code>. This mirrors the corresponding fix for the prerelease part (:gh:<code>460</code>). Related to :gh:<code>466</code>.</p> </li> <li> <p>:gh:<code>460</code>: :meth:<code>~semver.version.Version.bump_prerelease</code> will now add <code>.0</code> to an existing prerelease when the last segment of the current prerelease, split by dots (<code>.</code>), is not numeric. This is to ensure the new prerelease is considered higher than the previous one.</p> <p>:meth:<code>~semver.version.Version.bump_prerelease</code> now also support an argument <code>bump_when_empty</code> which will bump the patch version if there is no existing prerelease, to ensure the resulting version is considered a higher version than the previous one.</p> </li> </ul> <h2>Features</h2> <ul> <li>:pr:<code>476</code>: Added optional <code>[native]</code> extra to accelerate parsing on CPython via the <code>fast-semver-rs-backend</code> package. The pure-Python parser remains the default; the native backend is opt-in and only available on CPython.</li> </ul> <h2>Internal Changes</h2> <p>: Update GitHub Actions for astral-sh/setup-uv (version 0.10.1), github/codeql-action (version 4)</p> <h2>Trivial Changes</h2> <ul> <li>:gh:<code>463</code>: Remove double code in :meth:<code>Version.bump_build</code></li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/python-semver/python-semver/commit/642d1bc8949d38cca7922df478d0f2c06513f99d"><code>642d1bc</code></a> Change version to 3.1.0 (<a href="https://redirect.github.com/python-semver/python-semver/issues/481">#481</a>)</li> <li><a href="https://github.com/python-semver/python-semver/commit/2a2cf632f9b6c6b5731db85284db129e0d07837d"><code>2a2cf63</code></a> Suppress deprecation warnings in test suite</li> <li><a href="https://github.com/python-semver/python-semver/commit/a62477b6113791ed046e71936754e285892fd1ed"><code>a62477b</code></a> Improve comparisons and fix test coverage.</li> <li><a href="https://github.com/python-semver/python-semver/commit/0aa17a3447958cfe13634b0c3917e7aa4eee3334"><code>0aa17a3</code></a> Handle malformed collection operands in Version comparisons (<a href="https://redirect.github.com/python-semver/python-semver/issues/479">#479</a>)</li> <li><a href="https://github.com/python-semver/python-semver/commit/1b7350c1a7cacea983ab10b345990fee78761d44"><code>1b7350c</code></a> Improve test coverage to 100% (Rust backend)</li> <li><a href="https://github.com/python-semver/python-semver/commit/ea2524a51767cefab58a9b3bb6bcf38e5cdc7d54"><code>ea2524a</code></a> Fix bump_build() silently returning an unchanged version for digitless build ...</li> <li><a href="https://github.com/python-semver/python-semver/commit/1e8757912f633684e1a65d9d7c7e2270c3c79928"><code>1e87579</code></a> Reject non-ASCII digits and trailing newlines in version parsing (<a href="https://redirect.github.com/python-semver/python-semver/issues/478">#478</a>)</li> <li><a href="https://github.com/python-semver/python-semver/commit/0f18aa0b1e0cabba65ee1b506e637faabcdf5d05"><code>0f18aa0</code></a> Add optional native parser backend (minimal adapter) (<a href="https://redirect.github.com/python-semver/python-semver/issues/476">#476</a>)</li> <li><a href="https://github.com/python-semver/python-semver/commit/873a6750f22e82f72fb7c8c4a1ebe958beaa2f1a"><code>873a675</code></a> Declare support for Python 3.15 (<a href="https://redirect.github.com/python-semver/python-semver/issues/475">#475</a>)</li> <li><a href="https://github.com/python-semver/python-semver/commit/99d2032c8f7ef4895df25053ddcdcb85d5460326"><code>99d2032</code></a> Bump cryptography from 49.0.0 to 50.0.0 (<a href="https://redirect.github.com/python-semver/python-semver/issues/473">#473</a>)</li> <li>Additional commits viewable in <a href="https://github.com/python-semver/python-semver/compare/3.0.4...3.1.0">compare view</a></li> </ul> </details> <br /> Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore <dependency name> major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself) - `@dependabot ignore <dependency name> minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself) - `@dependabot ignore <dependency name>` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself) - `@dependabot unignore <dependency name>` will remove all of the ignore conditions of the specified dependency - `@dependabot unignore <dependency name> <ignore condition>` will remove the ignore condition of the specified dependency and ignore conditions </details> -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
