Repository navigation
chore(deps): lower bounds for all dependencies, ruff 0.16, latest uv/Task/checkout - #248
Merged
Merged
Conversation
Most dependencies had no version specifier, so Renovate's pep621 manager skipped them (skipReason "unspecified-version") and could only update them through the global uv.lock refresh. Each dependency now has a ">=" lower bound set to the version currently locked in uv.lock, so Renovate can track it individually. Existing bounds are raised to the locked version (django, requests, wagtail); upper bounds and the ruff pin are unchanged. No resolved version changes: uv.lock only gets its requires-dist metadata updated (115 packages before and after). For Renovate to actually bump these bounds, renovate.json needs rangeStrategy "bump" for pep621 (see #197): with the default "replace" strategy a ">=" range already satisfied by the new version produces no update.
ruff 0.16 enables more rules by default (113 findings on the codebase).
- Autofix (no behaviour change): drop Python 2 leftovers
(`# -*- coding: utf-8 -*-`, `from __future__ import unicode_literals`)
in migrations, str.format -> f-strings, log.warn -> log.warning,
datetime.timezone.utc -> datetime.UTC, import order.
- Timezone-aware datetimes (the project has USE_TZ = True):
- Meetup.future_events uses django.utils.timezone.now() instead of a
naive datetime.now().
- meetups.schema uses datetime.fromtimestamp(..., tz=UTC) instead of
datetime.utcfromtimestamp(), deprecated since Python 3.12. The
resulting Europe/Dublin datetime is unchanged.
- The Meetup.updated default is datetime(1970, 1, 1, tzinfo=UTC), the
same value Delorean produced; makemigrations detects no change.
- The next_n_months tests use aware datetimes.
- The Redis log line uses logging arguments instead of % formatting.
- RUF012 (mutable class attributes) is ignored: it only flags the
Django/Wagtail class-attribute idioms (Meta, migration operations,
content_panels).
ruff check, ruff format --check, makemigrations --check and the test
suite (with RuntimeWarning turned into errors) all pass.
- uv 0.12.1 -> 0.12.19 in the Dockerfile and mise.toml, matching the version locked in uv.lock and used by CI (setup-uv installs latest). - Task 3.50.0 -> 3.53.1 in mise.toml. - Dockerfile syntax 1.21.0 -> 1.27.0. - actions/checkout v4 -> v7.0.1. The v5-v7 breaking changes (Node 24 runtime, credentials in a separate file, no fork checkout on pull_request_target/workflow_run) do not affect this workflow. The dev image builds and ships uv 0.12.19, Python 3.13.15, ruff 0.16.9.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Brings every dependency and tool up to its latest version, and makes the dependencies trackable by Renovate (#197).
1. Lower bounds in
pyproject.toml(31aaac2)Renovate's
pep621manager skips any dependency without a version specifier (skipReason: unspecified-version). That was 30 of the 35 dependencies. Each one now has a>=lower bound set to the currently locked version. No resolved version changes.rangeStrategy: "bump", which #197 adds. With the defaultreplacestrategy, a>=Xrange that already allows the new version produces no update. I checked this with a local Renovate dry-run. Merge #197 and #248 together.2. ruff 0.15.16 → 0.16.9 (
0136a1e)ruff 0.16 enables more rules by default: 113 findings.
coding: utf-8,from __future__), convertsstr.formatto f-strings,log.warntolog.warning,timezone.utctoUTC.USE_TZ = True):Meetup.future_eventsusestimezone.now()instead of a naivedatetime.now().meetups.schemareplacesutcfromtimestamp()(deprecated since 3.12) withfromtimestamp(..., tz=UTC). The result is identical.Meetup.updateddefault keeps the same value, andmakemigrations --checkreports no change.Meta, migrationoperations,content_panels).3. Tooling (
a239e13)mise.toml)uv.lockand CI)mise.toml)actions/checkoutThe
actions/checkoutbreaking changes (Node 24, credentials in a separate file, no fork checkout onpull_request_target) don't affect this workflow.Left as is on purpose: Python 3.13 and PostgreSQL 17 (production constraints), and
redis:6.2in docker-compose (depends on the production Redis version; Renovate will open a separate PR for it).Checks
ruff check/ruff format --check: ✅makemigrations --check: no changeRuntimeWarningturned into errors)docker build --target dev: ✅, the image ships uv 0.12.19, Python 3.13.15, ruff 0.16.9, Django 6.0.8, Wagtail 7.3.4🤖 Generated with Claude Code