Repository navigation
Update dependency pylint to v4.0.9 - #269
Conversation
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #269 +/- ##
=======================================
Coverage 85.30% 85.30%
=======================================
Files 8 8
Lines 776 776
=======================================
Hits 662 662
Misses 114 114 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
7a652cc to
ab07cc6
Compare
|



This PR contains the following updates:
==4.0.8→==4.0.9Release Notes
pylint-dev/pylint (pylint)
v4.0.9Compare Source
What's new in Pylint 4.0.9?
Release date: 2026-09-23
Security Fixes
to the cache directory (predictable
PYLINT_HOMEon a multi-user host) can nolonger write a crafted pickle that will runs arbitrary code when pylint access its
stat cache. The result cache is now stored as JSON instead of pickle,
preventing code-execution. The workaround is upgrading or not pointing
PYLINT_HOMEto an untrusted, shared, or group-writable directory. The default value,
~/.cache/pylint,is writable only by the user running pylint. (CVE with the same information pending)
False Positives Fixed
Fixed a false positive for
no-self-useon a method that only usesselfbefore a locally defined class (or other nested method), becausethe checker's could-be-a-function tracking state was not restored after
visiting the nested method.
Closes #3705
Fix a false positive for :ref:
not-callablewhen calling functions constructed withtypes.FunctionTypeortypes.LambdaType.Closes #7500
Fix a false positive for
unnecessary-direct-lambda-callwhen a directly calledlambda in a class body wraps a comprehension containing an assignment expression.
PEP 572 makes that a
SyntaxErrorwithout the lambda's scope, so following themessage produced code that would not compile.
Closes #9294
Fix a false positive for :ref:
unnecessary-ellipsiswhen an ellipsis is thesole body statement of a method defined on a
Protocol.Closes #9319
Fix a false positive for :ref:
bad-exception-causewhen the bases of the classbeing raised from cannot be inferred, such as an exception deriving from a
C extension class. :ref:
raising-non-exceptionand:ref:
catching-non-exceptionalready guard the sameinherit_from_std_exhelper with
has_known_bases.Refs #11399
False Negatives Fixed
method-hiddenis no longer silenced when the hidden method shares its name witha builtin function or with a function defined at module level. Only members of the
ancestor classes themselves can excuse the method now.
Refs #11361
Other Bug Fixes
Fix a block-scoped
# pylint: disable=directive placed inside anifbody leaking into sibling
elif/elseblocks for messages such asstop-iteration-return, which default to a line-based (rather thannode-based) message scope.
Closes #3136
Fix a false positive for
declare-non-slotwhen a class variable isannotated with
ClassVarwithout an initial value.Closes #9950
Fix a crash in the
no-memberchecker when attribute lookup raises anInferenceError.Closes #11356
Fix a crash in the
unnecessary-default-type-argscheck when aGeneratoror
AsyncGeneratorsubscript holds an empty tuple, such asGenerator[()].Closes #11357
Fix a crash in
method-hiddenwhen a method shadows a name thatbuiltinsbinds to a node without a statement, such as
helporlicense. Every classinherits from
object, which lives in thebuiltinsmodule, so no base classwas needed to trigger it.
Closes #11361
Closes #8079
Configuration
📅 Schedule: (UTC)
* 0-3 * * 1)🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.