Skip to content

chore(python-deps): update poetry dependencies in all dependant actions (minor) - #1229

Merged
nfelt14 merged 1 commit into
mainfrom
renovate/python-deps/poetry-dependencies
Oct 2, 2026
Merged

nfelt14 merged 1 commit into
mainfrom
renovate/python-deps/poetry-dependencies

Conversation

@renovate

@renovate renovate Bot commented Sep 28, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
poetry (changelog) ==2.4.1 → ==2.5.1 age confidence
poetry-core 2.4.0 → 2.5.0 age confidence
poetry-core ==2.4.0 → ==2.5.0 age confidence

Release Notes

python-poetry/poetry (poetry)

v2.5.1

Compare Source

Fixed
  • Fix an issue where uninstalling a package with installer.builtin-uninstall set failed with a TypeError (#​11077).

v2.5.0

Compare Source

Added
  • Add an installer.builtin-uninstall setting to uninstall packages with a built-in uninstaller instead of invoking pip uninstall (#​10931).
  • Add official support for Python 3.15 (#​11046).
Changed
  • Do not send credentials configured for an https repository via http (#​11073).
  • Fail with an error when the current Python version is not compatible with the project and virtualenvs.create is false (#​10941).
  • Validate version constraints that are entered interactively in poetry init (#​10909).
  • Include the path of the pyproject.toml file in the message about already present packages in poetry add (#​10908).
  • Improve performance of processing package links and repository pages (#​10895,
    #​10896,
    #​10903,
    #​10949,
    #​10951,
    #​10953).
  • Improve performance of dependency resolution (#​10907,
    #​10954).
  • Improve performance of choosing and installing wheels (#​10905,
    #​10958).
  • Improve performance by avoiding redundant keyring lookups for repositories without credentials (#​10959).
  • Improve performance by reducing the number of subprocesses to discover virtual environment data (#​11042).
  • Improve performance of poetry search for single-token queries (#​10906).
  • Improve startup time by deferring the import of requests (#​11004).
  • Improve performance of schema validation by caching compiled JSON schema validators (#​11033).
Fixed
  • Fix an issue where credentials of the wrong repository were used under certain circumstances when multiple repositories were configured on the same host (#​11072).
  • Fix an issue where credentials of a repository on another host were used for git dependencies if the path of the URL was the same (#​11074).
  • Fix an issue where dependency resolution failed for conflicting requirements of different packages even though the requirements had mutually exclusive markers (#​10944).
  • Fix an issue where dependency resolution failed when the same package was required with different extras in several optional dependencies or dependency groups (#​10943).
  • Fix an issue where dependency resolution failed with a KeyError (#​11008).
  • Fix an issue where the dependencies of an extra were missing in the lock file after adding the extra to a locked dependency, e.g. a git dependency, in the pyproject.toml file (#​10987).
  • Fix an issue where a path or git dependency was not reinstalled when its develop setting changed (#​11022).
  • Fix an issue where scripts of type file were not installed when installing the project (#​10736).
  • Fix an issue where GUI scripts were not installed when installing the project (#​10973).
  • Fix an issue where a relative path was written to direct_url.json for path dependencies (#​10917).
  • Fix an issue where poetry show <package> showed a version that was not relevant for the current environment if there were multiple versions of the package in the lock file (#​11003).
  • Fix an issue where poetry show --outdated did not find newer versions of packages from sources with explicit priority (#​10982).
  • Fix an issue where poetry env activate ignored the environment that was determined by the application, e.g. when using --directory (#​10916).
  • Fix an issue where poetry init proposed an invalid package name if the directory name was not a valid package name (#​10975).
Docs
  • Document the --license option of poetry init and poetry new (#​11064).
  • Clarify which dependencies are locked when running poetry update with dependency groups (#​11024).
  • Clarify the portability of path dependencies (#​11020).
  • Clarify the usage of poetry run with console scripts (#​10984).
  • Clarify what --no-cache disables (#​10915).
  • Document how to use package sources for poetry self update (#​10923).
  • Fix the stale minimum Python version (#​11050).
  • Update outdated links (#​10913,
    #​10938,
    #​11000,
    #​11043).
poetry-core (2.5.0)
  • Add Python 3.15 to the automatically generated classifiers (#​961).
  • Fix an issue where a <V version constraint wrongly allowed pre-releases of V in some cases (#​939).
  • Fix an issue where version ranges with coincident bounds were not recognized as empty (#​939).
  • Fix an issue where the string representation of a version union did not describe the same constraint after being parsed again (#​939).
  • Fix an issue where the intersection of a version range with a local version resulted in a wrong constraint (#​949).
  • Fix an issue where the union of a version range and a public version did not include all local versions of the public version (#​950).
  • Fix an issue where the union of a public version and one of its local versions did not result in the public version (#​966).
  • Fix an issue where the difference between a public version and one of its local versions still allowed the local version, which could result in an infinite loop during dependency resolution (#​953).
  • Fix an issue where a version range that excluded some local versions of a public version was wrongly considered to allow all versions of the public version (#​959).
  • Fix an issue where a != <value> constraint was wrongly considered to allow all values of a <value> not in constraint (#​955).
  • Fix an issue where merging platform_release markers with incompatible constraint types failed (#​956).
  • Fix an issue where the string representation of a version range whose upper bound only consists of zeros raised an IndexError (#​964).
  • Fix an issue where formatting a Python constraint that only allows unknown Python versions raised an IndexError (#​971).
  • Fix an issue where marker values containing spaces could not be parsed (#​972).
  • Fix an issue where the upper bound of a ~= constraint was wrong for versions with more than three release segments (#​973).
  • Fix an issue where the filename of a link created from a Windows path was wrong and reject filenames containing path separators (#​974).

v2.4.3

Compare Source

Fixed
  • Fix an issue where Poetry could not extract sdists on Python 3.10.0-3.10.12 and 3.11.0-3.11.4 (#​11037).

v2.4.2

Compare Source

Fixed
  • Fix an issue where Poetry installs an artifact that is not listed in the lockfile when the package source does not provide a hash for this artifact (#​11030).
  • Fix a path traversal vulnerability when downloading files from a compromised URL and/or package source (#​11029).
  • Fix a path traversal vulnerability in sdist extraction on Python 3.10.0-3.10.12 and 3.11.0-3.11.4 that could allow malicious tarball files to write files outside the target directory (#​11027).
python-poetry/poetry-core (poetry-core)

v2.5.0

Compare Source

Added
  • Add Marker.apply() to partially evaluate a marker for a given environment (#​945).
  • Add Python 3.15 to the automatically generated classifiers (#​961).
Changed
  • Reject links with filenames containing path separators (#​974).
  • Update list of supported licenses (#​946,
    #​958,
    #​968).
  • Improve performance of creating links and determining file extensions (#​940,
    #​941).
  • Improve performance of version comparisons (#​951,
    #​952).
  • Improve performance of schema validation by caching compiled JSON schema validators (#​965).
Fixed
  • Fix an issue where a <V version constraint wrongly allowed pre-releases of V in some cases (#​939).
  • Fix an issue where version ranges with coincident bounds were not recognized as empty (#​939).
  • Fix an issue where the string representation of a version union did not describe the same constraint after being parsed again (#​939).
  • Fix an issue where the intersection of a version range with a local version resulted in a wrong constraint (#​949).
  • Fix an issue where the union of a version range and a public version did not include all local versions of the public version (#​950).
  • Fix an issue where the union of a public version and one of its local versions did not result in the public version (#​966).
  • Fix an issue where the difference between a public version and one of its local versions still allowed the local version, which could result in an infinite loop during dependency resolution (#​953).
  • Fix an issue where a version range that excluded some local versions of a public version was wrongly considered to allow all versions of the public version (#​959).
  • Fix an issue where a != <value> constraint was wrongly considered to allow all values of a <value> not in constraint (#​955).
  • Fix an issue where merging platform_release markers with incompatible constraint types failed (#​956).
  • Fix an issue where the string representation of a version range whose upper bound only consists of zeros raised an IndexError (#​964).
  • Fix an issue where formatting a Python constraint that only allows unknown Python versions raised an IndexError (#​971).
  • Fix an issue where marker values containing spaces could not be parsed (#​972).
  • Fix an issue where the upper bound of a ~= constraint was wrong for versions with more than three release segments (#​973).
  • Fix an issue where the filename of a link created from a Windows path was wrong (#​974).
Vendoring

v2.4.1

Compare Source

Fixed
  • Fix an issue where certain marker operations (mostly used with extra markers) resulted in wrong markers (#​943).

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@codecov

codecov Bot commented Sep 28, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 100.00%. Comparing base (17c6d52) to head (bd7c812).

Additional details and impacted files
@@            Coverage Diff            @@
##              main     #1229   +/-   ##
=========================================
  Coverage   100.00%   100.00%           
=========================================
  Files            4         4           
  Lines          233       233           
  Branches        32        32           
=========================================
  Hits           233       233           

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@renovate
renovate Bot force-pushed the renovate/python-deps/poetry-dependencies branch 2 times, most recently from 9facbc0 to ce3a278 Compare September 29, 2026 04:02
nfelt14
nfelt14 previously approved these changes Sep 29, 2026
@nfelt14
nfelt14 enabled auto-merge (squash) September 29, 2026 17:48
@renovate
renovate Bot force-pushed the renovate/python-deps/poetry-dependencies branch 3 times, most recently from fd7b8c5 to ab23b22 Compare September 30, 2026 07:58
@renovate
renovate Bot force-pushed the renovate/python-deps/poetry-dependencies branch from ab23b22 to 732e1ed Compare October 1, 2026 13:36
nfelt14
nfelt14 previously approved these changes Oct 1, 2026
@renovate
renovate Bot force-pushed the renovate/python-deps/poetry-dependencies branch from 732e1ed to 654bae9 Compare October 1, 2026 18:59
nfelt14
nfelt14 previously approved these changes Oct 1, 2026
@renovate
renovate Bot force-pushed the renovate/python-deps/poetry-dependencies branch 4 times, most recently from 912fa04 to f002abd Compare October 1, 2026 20:10
@renovate
renovate Bot force-pushed the renovate/python-deps/poetry-dependencies branch 2 times, most recently from 7f64655 to 3f7706a Compare October 2, 2026 02:36
@renovate
renovate Bot force-pushed the renovate/python-deps/poetry-dependencies branch from 3f7706a to bd7c812 Compare October 2, 2026 18:20
@nfelt14
nfelt14 merged commit 7491b1b into main Oct 2, 2026
40 checks passed
@nfelt14
nfelt14 deleted the renovate/python-deps/poetry-dependencies branch October 2, 2026 18:24
@github-actions

github-actions Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

Test Results (windows)

path passed subtotal
tests\test_bump_version_in_files.py 5 5
tests\test_create_unique_testpypi_version.py 7 7
tests\test_find_unreleased_changelog_items.py 6 6
tests\test_update_development_dependencies.py 13 13
TOTAL 31 31

Link to workflow run

@github-actions

github-actions Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

Test Results (macos)

path passed subtotal
tests/test_bump_version_in_files.py 5 5
tests/test_create_unique_testpypi_version.py 7 7
tests/test_find_unreleased_changelog_items.py 6 6
tests/test_update_development_dependencies.py 13 13
TOTAL 31 31

Link to workflow run

@github-actions

github-actions Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

Test Results (ubuntu)

path passed subtotal
tests/test_bump_version_in_files.py 5 5
tests/test_create_unique_testpypi_version.py 7 7
tests/test_find_unreleased_changelog_items.py 6 6
tests/test_update_development_dependencies.py 13 13
TOTAL 31 31

Link to workflow run

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant