Skip to content

chore(deps): lower bounds for all dependencies, ruff 0.16, latest uv/Task/checkout - #248

Merged
matrixise merged 3 commits into
masterfrom
feat/pyproject-lower-bounds
Sep 25, 2026
Merged

matrixise merged 3 commits into
masterfrom
feat/pyproject-lower-bounds

Conversation

@matrixise

@matrixise matrixise commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

Brings every dependency and tool up to its latest version, and makes the dependencies trackable by Renovate (#197).

1. Lower bounds in pyproject.toml (31aaac2)

Renovate's pep621 manager skips any dependency without a version specifier (skipReason: unspecified-version). That was 30 of the 35 dependencies. Each one now has a >= lower bound set to the currently locked version. No resolved version changes.

⚠️ This only works with rangeStrategy: "bump", which #197 adds. With the default replace strategy, a >=X range that already allows the new version produces no update. I checked this with a local Renovate dry-run. Merge #197 and #248 together.

2. ruff 0.15.16 → 0.16.9 (0136a1e)

ruff 0.16 enables more rules by default: 113 findings.

  • Autofix, no behaviour change: removes Python 2 leftovers in migrations (coding: utf-8, from __future__), converts str.format to f-strings, log.warn to log.warning, timezone.utc to UTC.
  • Timezone-aware datetimes (USE_TZ = True):
    • Meetup.future_events uses timezone.now() instead of a naive datetime.now().
    • meetups.schema replaces utcfromtimestamp() (deprecated since 3.12) with fromtimestamp(..., tz=UTC). The result is identical.
    • The Meetup.updated default keeps the same value, and makemigrations --check reports no change.
  • RUF012 ignored: it only flags Django/Wagtail class-attribute idioms (Meta, migration operations, content_panels).

3. Tooling (a239e13)

Before After
uv (Dockerfile, mise.toml) 0.12.1 0.12.19 (same as uv.lock and CI)
Task (mise.toml) 3.50.0 3.53.1
Dockerfile syntax 1.21.0 1.27.0
actions/checkout v4 v7.0.1

The actions/checkout breaking changes (Node 24, credentials in a separate file, no fork checkout on pull_request_target) don't affect this workflow.

Left as is on purpose: Python 3.13 and PostgreSQL 17 (production constraints), and redis:6.2 in docker-compose (depends on the production Redis version; Renovate will open a separate PR for it).

Checks

  • ruff check / ruff format --check: ✅
  • makemigrations --check: no change
  • Test suite: ✅ (7/7, with RuntimeWarning turned into errors)
  • docker build --target dev: ✅, the image ships uv 0.12.19, Python 3.13.15, ruff 0.16.9, Django 6.0.8, Wagtail 7.3.4

🤖 Generated with Claude Code

Most dependencies had no version specifier, so Renovate's pep621 manager
skipped them (skipReason "unspecified-version") and could only update
them through the global uv.lock refresh.

Each dependency now has a ">=" lower bound set to the version currently
locked in uv.lock, so Renovate can track it individually. Existing
bounds are raised to the locked version (django, requests, wagtail);
upper bounds and the ruff pin are unchanged.

No resolved version changes: uv.lock only gets its requires-dist
metadata updated (115 packages before and after).

For Renovate to actually bump these bounds, renovate.json needs
rangeStrategy "bump" for pep621 (see #197): with the default "replace"
strategy a ">=" range already satisfied by the new version produces no
update.
ruff 0.16 enables more rules by default (113 findings on the codebase).

- Autofix (no behaviour change): drop Python 2 leftovers
  (`# -*- coding: utf-8 -*-`, `from __future__ import unicode_literals`)
  in migrations, str.format -> f-strings, log.warn -> log.warning,
  datetime.timezone.utc -> datetime.UTC, import order.
- Timezone-aware datetimes (the project has USE_TZ = True):
  - Meetup.future_events uses django.utils.timezone.now() instead of a
    naive datetime.now().
  - meetups.schema uses datetime.fromtimestamp(..., tz=UTC) instead of
    datetime.utcfromtimestamp(), deprecated since Python 3.12. The
    resulting Europe/Dublin datetime is unchanged.
  - The Meetup.updated default is datetime(1970, 1, 1, tzinfo=UTC), the
    same value Delorean produced; makemigrations detects no change.
  - The next_n_months tests use aware datetimes.
- The Redis log line uses logging arguments instead of % formatting.
- RUF012 (mutable class attributes) is ignored: it only flags the
  Django/Wagtail class-attribute idioms (Meta, migration operations,
  content_panels).

ruff check, ruff format --check, makemigrations --check and the test
suite (with RuntimeWarning turned into errors) all pass.
- uv 0.12.1 -> 0.12.19 in the Dockerfile and mise.toml, matching the
  version locked in uv.lock and used by CI (setup-uv installs latest).
- Task 3.50.0 -> 3.53.1 in mise.toml.
- Dockerfile syntax 1.21.0 -> 1.27.0.
- actions/checkout v4 -> v7.0.1. The v5-v7 breaking changes (Node 24
  runtime, credentials in a separate file, no fork checkout on
  pull_request_target/workflow_run) do not affect this workflow.

The dev image builds and ships uv 0.12.19, Python 3.13.15, ruff 0.16.9.
@matrixise matrixise changed the title chore(deps): add lower bounds to every dependency in pyproject.toml chore(deps): lower bounds for all dependencies, ruff 0.16, latest uv/Task/checkout Sep 25, 2026
@matrixise
matrixise merged commit ad2a6e9 into master Sep 25, 2026
2 checks passed
@matrixise
matrixise deleted the feat/pyproject-lower-bounds branch September 25, 2026 06:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant