Skip to content

deps: bump the python-dependencies group with 6 updates - #66

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/python-dependencies-f0a7270d7d
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/python-dependencies-f0a7270d7d

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 28, 2026

Copy link
Copy Markdown
Contributor

Bumps the python-dependencies group with 6 updates:

Package From To
ml4t-specs 0.1.4 0.1.5
ta-lib 0.7.1 0.8.1
shap 0.49.1 0.52.0
hypothesis 6.168.0 6.168.1
ruff 0.16.8 0.16.9
ty 0.0.82 0.0.84

Updates ml4t-specs from 0.1.4 to 0.1.5

Release notes

Sourced from ml4t-specs's releases.

v0.1.5

What's Changed

Full Changelog: ml4t/specs@v0.1.4...v0.1.5

Commits
  • 07db811 ci: qualify commit-bound Specs releases (#18)
  • eaf0e61 fix: publish canonical package metadata (#17)
  • be310ff ci: bump astral-sh/setup-uv in the github-actions group (#16)
  • ce98f93 docs: establish public agent orientation (#15)
  • bd4ae39 deps: update mkdocstrings requirement from <1,>=0.24 to >=0.24,<2 in the pyth...
  • b357bb2 ci: bump astral-sh/setup-uv in the github-actions group (#11)
  • See full diff in compare view

Updates ta-lib from 0.7.1 to 0.8.1

Release notes

Sourced from ta-lib's releases.

v0.8.1

  • [CHANGE]: talib.stream is now the real streaming API of TA-Lib C 0.8.1: stream.SMA(close) returns a handle, not a value. handle.value is the value at the last history bar, handle.update(bar) costs O(1) and returns that bar's value, handle.peek(bar) evaluates a forming bar without committing it, and handle.copy() forks it. stream.SMA.open_and_fill() returns the handle and the Function API's series in one pass. A multi-output function answers with the same tuple the Function API returns. The old last-value functions -- talib.stream.SMA, talib.stream_SMA, and their _ta_lib.pyi stubs -- are gone; talib/stream.pyi types the handles instead.

    Migrating is stream.X(...) -> stream.X(...).value, and the compiler cannot find the sites for you: if stream.CDLDOJI(o, h, l, c): used to test the pattern and now tests a handle, which is always true.

  • [NEW]: talib.InsufficientHistory, raised when a stream is opened with too little history. It is the library's one recoverable error, so it is catchable on its own rather than as a bare Exception.

  • [FIX]: help(talib.SUPERTREND) and the abstract stub named the outputs real and integer; they are supertrend and trend, the names abstract.Function('SUPERTREND').output_names already reported.

  • [FIX]: An empty array given to a function whose lookback is zero, such as talib.ACOS or talib.MA(x, timeperiod=1), made TA-Lib read and write one element outside the buffers, which could crash the interpreter later or corrupt memory silently. An empty input now returns empty outputs without calling TA-Lib, whatever the function and its parameters. The bug dates from 0.4.27.

v0.8.0

  • [NEW]: Support TA-Lib C 0.8.1, which is now the minimum required version.

  • [NEW]: The 40 functions TA-Lib C added since 0.7.1: AC, ADR, AO, CMF, CMOU, COPPOCK, CUMSUM, CVI, DONCHIAN, DPO, EFI, ER, ERI, FOSC, FRACTAL, HA, HMA, KC, KDJ, MARKETFI, MASSI, NVI, PERCENTILE, PERCENTRANK, PVI, PVO, PVT, QSTICK, RMA, RVI, RVOL, SMI, SUPERTREND, TSI, VHF, VORTEX, VWAP, VWMA, WAD, ZLEMA.

  • [NEW]: New moving averages: MA_Type.HMA, MA_Type.DISABLED, MA_Type.DEFAULT, MA_Type.ZLEMA and MA_Type.RMA.

  • [NEW]: set_unstable_period() and get_unstable_period() accept 'RMA', 'HA' and 'RVI'.

  • [FIX]: abstract raised KeyError on function and output flags added after this wrapper was written; unknown flag bits are now ignored.

  • [FIX]: A moving-average parameter not spelled exactly matype -- KDJ's slowk_matype -- defaulted to SMA rather than to the function's own documented default.

  • [FIX]: An integer output is documented as the candlestick -100/0/100 convention only for candlestick functions; SUPERTREND's is a trend direction.

  • [CHANGE]: APO and PPO now default matype to EMA, and BBANDS defaults timeperiod to 20, following TA-Lib C 0.8.1.

  • [FIX]: set_unstable_period() targeted the wrong function for every id after IMI (e.g. 'RSI' set PLUS_DM); ids now come from the C header. 'ADXR', 'MFI' and 'STOCHRSI' are no-ops that emit a DeprecationWarning.

  • [CHANGE]: Remove the unnecessary build runtime dependency and wheel build dependency.

  • [NEW]: Upgrade to Cython 3.3.0

Changelog

Sourced from ta-lib's changelog.

0.8.1

  • [CHANGE]: talib.stream is now the real streaming API of TA-Lib C 0.8.1: stream.SMA(close) returns a handle, not a value. handle.value is the value at the last history bar, handle.update(bar) costs O(1) and returns that bar's value, handle.peek(bar) evaluates a forming bar without committing it, and handle.copy() forks it. stream.SMA.open_and_fill() returns the handle and the Function API's series in one pass. A multi-output function answers with the same tuple the Function API returns. The old last-value functions -- talib.stream.SMA, talib.stream_SMA, and their _ta_lib.pyi stubs -- are gone; talib/stream.pyi types the handles instead.

    Migrating is stream.X(...) -> stream.X(...).value, and the compiler cannot find the sites for you: if stream.CDLDOJI(o, h, l, c): used to test the pattern and now tests a handle, which is always true.

  • [NEW]: talib.InsufficientHistory, raised when a stream is opened with too little history. It is the library's one recoverable error, so it is catchable on its own rather than as a bare Exception.

  • [FIX]: help(talib.SUPERTREND) and the abstract stub named the outputs real and integer; they are supertrend and trend, the names abstract.Function('SUPERTREND').output_names already reported.

  • [FIX]: An empty array given to a function whose lookback is zero, such as talib.ACOS or talib.MA(x, timeperiod=1), made TA-Lib read and write one element outside the buffers, which could crash the interpreter later or corrupt memory silently. An empty input now returns empty outputs without calling TA-Lib, whatever the function and its parameters. The bug dates from 0.4.27.

0.8.0

  • [NEW]: Support TA-Lib C 0.8.1, which is now the minimum required version.

  • [NEW]: The 40 functions TA-Lib C added since 0.7.1: AC, ADR, AO, CMF, CMOU, COPPOCK, CUMSUM, CVI, DONCHIAN, DPO, EFI, ER, ERI, FOSC, FRACTAL, HA, HMA, KC, KDJ, MARKETFI, MASSI, NVI, PERCENTILE, PERCENTRANK, PVI, PVO, PVT, QSTICK, RMA, RVI, RVOL, SMI, SUPERTREND, TSI, VHF, VORTEX, VWAP, VWMA, WAD, ZLEMA.

  • [NEW]: New moving averages: MA_Type.HMA, MA_Type.DISABLED, MA_Type.DEFAULT, MA_Type.ZLEMA and MA_Type.RMA.

  • [NEW]: set_unstable_period() and get_unstable_period() accept 'RMA', 'HA' and 'RVI'.

... (truncated)

Commits
  • 8f5cadc docs: updates
  • e5aab28 ci: add the dev-* release lane, pinned to the wheels' TA-Lib C
  • f4ad30e test: accept a TA-Lib C newer than we require
  • 9c7f7bd update README from TA-Lib C 0.7.1 to 0.8.1
  • 7a10655 version bump
  • f972213 fix(func): no input, no output
  • bdb8c5e fix(func): SUPERTREND's outputs are supertrend and trend
  • 7a5544c changelog: the streaming entries belong to the next release
  • 25dd74b fix(abstract): stop relying on Cython resolving __NAME from class scope
  • a93703b perf(stream): multi-output handles answer with a plain tuple
  • Additional commits viewable in compare view

Updates shap from 0.49.1 to 0.52.0

Release notes

Sourced from shap's releases.

v0.52.0

What's Changed

Highlights

  • Native bindings rewritten with nanobind, and the build system migrated from setup.py to scikit-build-core + CMake. The Cython _kernel_lib.pyx and the existing _cext / _cext_gpu modules are now built as nanobind extensions, and MANIFEST.in / setup.py have been removed in favor of a pyproject.toml-driven build. (#4366, by @​CloseChoice and @​daidahao and @​claude)
  • Minimum dependency versions raised to follow SPEC 0. (#4310, by @​CloseChoice)

Enhancements

Bug Fixes

  • Improve GPU TreeExplainer parity: preserve XGBoost default/missing child routing so NaN values follow the same branch as the source model, preserve vector-valued XGBoost base_score values (fixing multiclass additivity offsets), and tighten categorical handling so sklearn models with enable_categorical=True raise the existing unsupported-categorical error even when the booster does not expose feature_types. (#4997, by @​RAMitchell)
  • TreeExplainer no longer crashes with pandas nullable dtypes. (#4298, by @​tudstudent)
  • Fix NameError when with_binary=False and with_cuda=True by initializing compile_args. (#4322, by @​mohityadav8)
  • Text plot colors render correctly by converting NumPy types to float. (#4332, by @​Saloni-0465)
  • Assign the result of np.flipud so it is no longer a no-op in AdditiveForceArrayVisualizer. (#4343, by @​Mahaveerjain-18)
  • Use isinstance() instead of is for type checks. (#4373, by @​divyam-jha123)
  • Record 'sample' in Explanation.op_history instead of '__getitem__'. (#4376, by @​tarun-227)
  • Move the unreachable large-dataset warning into the interventional branch. (#4392, by @​Mahaveerjain-18)
  • Fix "structure of inputs doesn't match the expected structure". (#4410, by @​shaivimalik)
  • Fix the return value from is_color_map() in plots/_beeswarm.py. (#4421, by @​maniktyagi04)
  • Suppress the UserWarning when LGBMRegressor was fitted with feature names. (#4422, by @​shaivimalik)

... (truncated)

Commits
  • 8461059 FIX: Improve GPU TreeExplainer parity (#4997)
  • 8549e6b fix: use isinstance() instead of type() is tuple checks (#4508)
  • 3be7001 remove webpack dependency for sickness scores (#5018)
  • 6e9f9b8 build(deps): bump qs and express in /javascript (#5015)
  • 9be5435 build(deps): bump idna from 3.11 to 3.15 in /docs (#5007)
  • 52dd763 pin torch to <=2.11.0 in pyproject.toml (#5017)
  • d8f2e76 build(deps-dev): bump webpack-dev-server in /javascript (#5009)
  • ac6e677 build(deps-dev): bump @​babel/plugin-transform-modules-systemjs (#4991)
  • 679b2ee FIX: warn when covariance matrix is singular in LinearExplainer (#4471)
  • ce4abd7 build(deps): bump mistune from 3.2.0 to 3.2.1 (#4990)
  • Additional commits viewable in compare view

Updates hypothesis from 6.168.0 to 6.168.1

Commits
  • 6cee8ce Bump hypothesis version to 6.168.1 and update changelog
  • d97fdf3 Merge pull request #4879 from Liam-DeVoe/more-wheels
  • 37da03c publish wheels for s390x and i686+musl
  • See full diff in compare view

Updates ruff from 0.16.8 to 0.16.9

Release notes

Sourced from ruff's releases.

0.16.9

Release Notes

Released on 2026-09-24.

Preview features

  • [ruff] Avoid false positives for overloaded division (RUF069) (#28309)

Bug fixes

  • [flake8-bugbear] Avoid false positives for calls with keyword arguments (B009, B010, B043) (#28776)
  • [flake8-tidy-imports] Allow lazy imports to be used in deferred annotations (TID255) (#28767)

Rule changes

  • Update LibCST-based fixes for Python 3.15 (#28616)
  • [flake8-pyi] Mention stubs in the diagnostic message (PYI002) (#28542)

Documentation

  • Fix horizontal overflow on the rules documentation page (#28699)
  • Update rules table with category information (#28651)
  • [flake8-annotations] Clarify that ANN401 checks return types in addition to arguments (#28334)
  • [flake8-bugbear] Document type-checker interaction (B010) (#28509)
  • [flake8-comprehensions] Document map/generator exception behavior (C417) (#27794)
  • [ruff] Mention related isort settings (RUF022) (#28719)

Contributors

Install ruff 0.16.9

Install prebuilt binaries via shell script

curl --proto '=https' --tlsv1.2 -LsSf https://releases.astral.sh/github/ruff/releases/download/0.16.9/ruff-installer.sh | sh

... (truncated)

Changelog

Sourced from ruff's changelog.

0.16.9

Released on 2026-09-24.

Preview features

  • [ruff] Avoid false positives for overloaded division (RUF069) (#28309)

Bug fixes

  • [flake8-bugbear] Avoid false positives for calls with keyword arguments (B009, B010, B043) (#28776)
  • [flake8-tidy-imports] Allow lazy imports to be used in deferred annotations (TID255) (#28767)

Rule changes

  • Update LibCST-based fixes for Python 3.15 (#28616)
  • [flake8-pyi] Mention stubs in the diagnostic message (PYI002) (#28542)

Documentation

  • Fix horizontal overflow on the rules documentation page (#28699)
  • Update rules table with category information (#28651)
  • [flake8-annotations] Clarify that ANN401 checks return types in addition to arguments (#28334)
  • [flake8-bugbear] Document type-checker interaction (B010) (#28509)
  • [flake8-comprehensions] Document map/generator exception behavior (C417) (#27794)
  • [ruff] Mention related isort settings (RUF022) (#28719)

Contributors

Commits
  • 0be08a2 Bump version to 0.16.9 (#28882)
  • b4920b7 Rename ruff_cli to ruff_command_line (#28881)
  • 47c751b Update dependency astral-sh/uv to v0.12.18 (#28880)
  • 8c244e5 [flake8-comprehensions] Document map/generator exception behavior (C417...
  • 5edf5a1 Use target form in rooster.version_files (#28876)
  • 915bb2b [ty] Prefer existing @ paths over response files in Ruff and ty (#28877)
  • 4710e1a ci(github): update version number in placeholder of issue template (#28871)
  • eedfc62 [ty] Propagate outer type context through cast calls (#28855)
  • ceaa6a0 [ty] Contain rendered code within Markdown fences (#28869)
  • dba0f30 authorize ruff-pre-commit dispatch via OIDC (#28867)
  • Additional commits viewable in compare view

Updates ty from 0.0.82 to 0.0.84

Release notes

Sourced from ty's releases.

0.0.84

Release Notes

Released on 2026-09-24.

This release addresses GHSA-vxvm-j4xq-q7m4, a use-after-free vulnerability during incremental type checking that can result in arbitrary code execution when analyzing a specially crafted Python project. Users who run ty on untrusted code should upgrade to 0.0.84 or newer.

Bug fixes

  • Fix stale diagnostics from the LSP server after toggling showSyntaxErrors (#28759)

LSP server

  • Complete string keys from dictionary initializers (#28820)
  • Support LSP requests against closed documents (#28595)
  • Select projects for external files using import search paths (#28594)
  • Use workspace editor settings for external files (#28639)

Performance

  • Avoid repeated subtyping checks for materialized recursive protocols (#28774)
  • Skip reading notebooks when discovering scripts (#28781)

Core type checking

  • Avoid incorrect simplification of TypeIs materializations (#28817)
  • Fix disjointness of generic class types (#28787)
  • Fix staticmethod shadowing through generic receivers and unions (#28766)
  • Infer callable signatures from bounded type variables (#28599)
  • Infer constant membership in inline list and set literals (e.g. "foo" in ["foo"] is now inferred as Literal[True]) (#28676)
  • Infer through optional generic containers in the legacy solver (#28791)
  • Preserve call narrowing during cyclic inference (#28708)
  • Preserve intersections of type guard return types (#28796)
  • Use subtyping for constraint-set implication (#28657)

Configuration

  • Disable invalid-legacy-positional-parameter by default (#28834)

Other changes

  • Only consider reachable definitions when determining whether a condition should be exempted from redundant-condition(-strict) due to the condition being defined relative to sys.version_info, sys.platform, os.name or typing.TYPE_CHECKING (#28788)

Contributors

... (truncated)

Changelog

Sourced from ty's changelog.

0.0.84

Released on 2026-09-24.

This release addresses GHSA-vxvm-j4xq-q7m4, a use-after-free vulnerability during incremental type checking that can result in arbitrary code execution when analyzing a specially crafted Python project. Users who run ty on untrusted code should upgrade to 0.0.84 or newer.

Bug fixes

  • Fix stale diagnostics from the LSP server after toggling showSyntaxErrors (#28759)

LSP server

  • Complete string keys from dictionary initializers (#28820)
  • Support LSP requests against closed documents (#28595)
  • Select projects for external files using import search paths (#28594)
  • Use workspace editor settings for external files (#28639)

Performance

  • Avoid repeated subtyping checks for materialized recursive protocols (#28774)
  • Skip reading notebooks when discovering scripts (#28781)

Core type checking

  • Avoid incorrect simplification of TypeIs materializations (#28817)
  • Fix disjointness of generic class types (#28787)
  • Fix staticmethod shadowing through generic receivers and unions (#28766)
  • Infer callable signatures from bounded type variables (#28599)
  • Infer constant membership in inline list and set literals (e.g. "foo" in ["foo"] is now inferred as Literal[True]) (#28676)
  • Infer through optional generic containers in the legacy solver (#28791)
  • Preserve call narrowing during cyclic inference (#28708)
  • Preserve intersections of type guard return types (#28796)
  • Use subtyping for constraint-set implication (#28657)

Configuration

  • Disable invalid-legacy-positional-parameter by default (#28834)

Other changes

  • Only consider reachable definitions when determining whether a condition should be exempted from redundant-condition(-strict) due to the condition being defined relative to sys.version_info, sys.platform, os.name or typing.TYPE_CHECKING (#28788)

Contributors

... (truncated)

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the python-dependencies group with 6 updates:

| Package | From | To |
| --- | --- | --- |
| [ml4t-specs](https://github.com/ml4t/specs) | `0.1.4` | `0.1.5` |
| [ta-lib](https://github.com/ta-lib/ta-lib-python) | `0.7.1` | `0.8.1` |
| [shap](https://github.com/shap/shap) | `0.49.1` | `0.52.0` |
| [hypothesis](https://github.com/HypothesisWorks/hypothesis) | `6.168.0` | `6.168.1` |
| [ruff](https://github.com/astral-sh/ruff) | `0.16.8` | `0.16.9` |
| [ty](https://github.com/astral-sh/ty) | `0.0.82` | `0.0.84` |


Updates `ml4t-specs` from 0.1.4 to 0.1.5
- [Release notes](https://github.com/ml4t/specs/releases)
- [Commits](ml4t/specs@v0.1.4...v0.1.5)

Updates `ta-lib` from 0.7.1 to 0.8.1
- [Release notes](https://github.com/ta-lib/ta-lib-python/releases)
- [Changelog](https://github.com/TA-Lib/ta-lib-python/blob/master/CHANGELOG)
- [Commits](TA-Lib/ta-lib-python@v0.7.1...v0.8.1)

Updates `shap` from 0.49.1 to 0.52.0
- [Release notes](https://github.com/shap/shap/releases)
- [Changelog](https://github.com/shap/shap/blob/main/docs/release_notes.rst)
- [Commits](shap/shap@v0.49.1...v0.52.0)

Updates `hypothesis` from 6.168.0 to 6.168.1
- [Release notes](https://github.com/HypothesisWorks/hypothesis/releases)
- [Commits](HypothesisWorks/hypothesis@v6.168.0...v6.168.1)

Updates `ruff` from 0.16.8 to 0.16.9
- [Release notes](https://github.com/astral-sh/ruff/releases)
- [Changelog](https://github.com/astral-sh/ruff/blob/main/CHANGELOG.md)
- [Commits](astral-sh/ruff@0.16.8...0.16.9)

Updates `ty` from 0.0.82 to 0.0.84
- [Release notes](https://github.com/astral-sh/ty/releases)
- [Changelog](https://github.com/astral-sh/ty/blob/main/CHANGELOG.md)
- [Commits](astral-sh/ty@0.0.82...0.0.84)

---
updated-dependencies:
- dependency-name: ml4t-specs
  dependency-version: 0.1.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: python-dependencies
- dependency-name: ta-lib
  dependency-version: 0.8.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-dependencies
- dependency-name: shap
  dependency-version: 0.52.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: python-dependencies
- dependency-name: hypothesis
  dependency-version: 6.168.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: python-dependencies
- dependency-name: ruff
  dependency-version: 0.16.9
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: python-dependencies
- dependency-name: ty
  dependency-version: 0.0.84
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: python-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Dependency updates python Python dependencies labels Sep 28, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Dependency updates python Python dependencies

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants