Skip to content

Bump setuptools from 81.0.0 to 83.0.0 in /lib - #50

Open
dependabot[bot] wants to merge 4 commits into
masterfrom
dependabot/uv/lib/setuptools-83.0.0
Open

Bump setuptools from 81.0.0 to 83.0.0 in /lib#50
dependabot[bot] wants to merge 4 commits into
masterfrom
dependabot/uv/lib/setuptools-83.0.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 8, 2026

Copy link
Copy Markdown
Contributor

Bumps setuptools from 81.0.0 to 83.0.0.

Changelog

Sourced from setuptools's changelog.

v83.0.0

Features

  • Require Python 3.10 or later.

Bugfixes

  • MANIFEST.in matching (via FileList) is now insensitive to Unicode normalization form. A pattern authored in one form (e.g. NFC, as typically saved by editors) now matches a file whose name is stored on disk in another (e.g. NFD, as produced by macOS APFS/HFS+). Previously an exclude, global-exclude, recursive-exclude, or prune rule could silently fail to drop a non-ASCII-named file from the source distribution, publishing it despite the exclusion -- see GHSA-h35f-9h28-mq5c.

Deprecations and Removals

  • pypa/distutils#334

v82.0.1

Bugfixes

  • Fix the loading of launcher manifest.xml file. (#5047)
  • Replaced deprecated json.__version__ with fixture in tests. (#5186)

Improved Documentation

  • Add advice about how to improve predictability when installing sdists. (#5168)

Misc

v82.0.0

... (truncated)

Commits
  • 6519f72 Bump version: 82.0.1 → 83.0.0
  • d1151b1 Merge pull request #5250 from pypa/feature/distutils-d7633fbed
  • a2df31e Capture removal of dry_run parameter in changelog.
  • 00144dc Moved newsfragment to the release where it occurred.
  • a4a5a2b Add news fragment.
  • 77470c2 Merge https://github.com/pypa/distutils into feature/distutils-d7633fbed
  • 3c43897 Merge pull request #5247 from pypa/copilot/fix-pypy-version-issue
  • bb6ea66 Bump PyPy from 3.10 to 3.11 in CI workflow
  • a2bc3ac Fix broken intersphinx reference to build's installation docs
  • 2d6a739 Use stacked parametrize decorators instead of itertools.product
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

clovis and others added 4 commits September 8, 2026 09:56
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Lockfile-only refresh of the packages named in open Dependabot alerts:
pillow 12.2.0->12.3.0, urllib3->2.7.0, lxml->6.1.3, idna->3.19 in lib;
transformers 5.5.4->5.16.1 in labeler; postcss, nanoid and immutable in
browser-app. Clears 27 of 53 alerts, 21 of the 25 highs. No pyproject.toml
or package.json changes, so no pinned API moved.

Still open: torch (the cu124 index caps CUDA installs at 2.6.0),
transformers in lib (spacy-transformers caps it below 5.x), and
vite/esbuild (needs vite 5 -> 8).

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
A runtime install that only serves existing model.duckdb files never
reaches the labeler: DB.py shells out to it from save_topics, i.e. during
training. Installing it anyway costs ~5GB — a second torch copy alongside
the one in topologic_env.

Guard the call site with shutil.which() while adding the flag. The
existing check=False only suppresses a non-zero exit, so a missing
binary raised FileNotFoundError and killed the run rather than falling
back to top-word descriptions the way the message promised. Unreachable
until now, since the labeler was always installed.

--skip-labeler declines to install or update it; an existing labeler is
left in place and keeps working.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Bumps [setuptools](https://github.com/pypa/setuptools) from 81.0.0 to 83.0.0.
- [Release notes](https://github.com/pypa/setuptools/releases)
- [Changelog](https://github.com/pypa/setuptools/blob/main/NEWS.rst)
- [Commits](pypa/setuptools@v81.0.0...v83.0.0)

---
updated-dependencies:
- dependency-name: setuptools
  dependency-version: 83.0.0
  dependency-type: direct:development
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels Sep 8, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant