Skip to content

Bump coverage from 7.15.4 to 7.16.0 - #151

Merged
docktermj merged 1 commit into
mainfrom
dependabot/pip/coverage-7.16.0
Sep 21, 2026
Merged

docktermj merged 1 commit into
mainfrom
dependabot/pip/coverage-7.16.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 21, 2026 •

Copy link
Copy Markdown
Contributor

Bumps coverage from 7.15.4 to 7.16.0.

Release notes

Sourced from coverage's releases.

7.16.0

Version 7.16.0 — 2026-08-28

  • When combining files, now path separator slashes will automatically be converted to the local file system style. This makes it less necessary to define [paths] configuration to combine data across operating systems. Fixes issue 2266.
  • The Coverage.switch_context() method now returns the previous context.
  • Fix: previously, a [paths] pattern would be replaced everywhere in a file path when it was only meant to be replaced once, in the leading portion of the path. This is now fixed, in pull 2268.
  • Fixes to validation of options and configuration settings:
    • Negative precision settings now always cause useful error messages (pull 2261).
    • An invalid regex in the --contexts option (or the [report] contexts setting) reported a confusing “Couldn’t use data file …: user-defined function raised exception” error. Now it raises a proper configuration error naming the bad regex, like other regex settings do (pull 2262).
    • Non-string values in TOML configuration settings now produce a helpful error message instead of a traceback. This affects list settings whose elements aren’t strings (like omit, exclude_lines, or a [paths] entry), file settings like data_file, and any wrong-typed value in the [paths] section (pull 2263).
    • coverage run refuses run-affecting command-line options like --branch alongside --concurrency=multiprocessing, since they can’t reach the subprocesses. The check only recognized multiprocessing as the entire option value, so --concurrency=multiprocessing,thread slipped through and failed later with “Can’t combine statement coverage data with branch data”. Each named concurrency library is now properly considered (pull 2270).
  • Fix: coverage annotate -d DIR raised an AssertionError if any measured file had an extension other than .py, such as a .pyw file on Windows. The original extension is now restored on the annotated copy (pull 2265).

➡️  PyPI page: coverage 7.16.0. :arrow_right:  To install: python3 -m pip install coverage==7.16.0

Changelog

Sourced from coverage's changelog.

Version 7.16.0 — 2026-08-28

  • When combining files, now path separator slashes will automatically be converted to the local file system style. This makes it less necessary to define [paths] configuration to combine data across operating systems. Fixes issue 2266_.

  • The :meth:.Coverage.switch_context method now returns the previous context.

  • Fix: previously, a [paths] pattern would be replaced everywhere in a file path when it was only meant to be replaced once, in the leading portion of the path. This is now fixed, in pull 2268_.

  • Fixes to validation of options and configuration settings:

    • Negative precision settings now always cause useful error messages (pull 2261_).

    • An invalid regex in the --contexts option (or the [report] contexts setting) reported a confusing "Couldn't use data file ...: user-defined function raised exception" error. Now it raises a proper configuration error naming the bad regex, like other regex settings do (pull 2262_).

    • Non-string values in TOML configuration settings now produce a helpful error message instead of a traceback. This affects list settings whose elements aren't strings (like omit, exclude_lines, or a [paths] entry), file settings like data_file, and any wrong-typed value in the [paths] section (pull 2263_).

    • coverage run refuses run-affecting command-line options like --branch alongside --concurrency=multiprocessing, since they can't reach the subprocesses. The check only recognized multiprocessing as the entire option value, so --concurrency=multiprocessing,thread slipped through and failed later with "Can't combine statement coverage data with branch data". Each named concurrency library is now properly considered (pull 2270_).

  • Fix: coverage annotate -d DIR raised an AssertionError if any measured file had an extension other than .py, such as a .pyw file on Windows. The original extension is now restored on the annotated copy (pull 2265_).

.. _pull 2261: coveragepy/coveragepy#2261 .. _pull 2262: coveragepy/coveragepy#2262 .. _pull 2263: coveragepy/coveragepy#2263 .. _pull 2265: coveragepy/coveragepy#2265 .. _issue 2266: coveragepy/coveragepy#2266 .. _pull 2268: coveragepy/coveragepy#2268

... (truncated)

Commits
  • 3e9fc16 docs: prep for 7.16.0
  • 38be8d1 build: control check-manifest explicitly
  • 8eb1266 docs(build): no longer commit sample_html
  • 1a8b3fa docs: remove sample_html
  • aeaa79b docs: linklint is now sphinx-linklint
  • d5eaf3f test: a branchless way to re-add extensions
  • 57e52fd docs: adjust CHANGES for #2270
  • b9d304d fix: check for multiprocessing in a --concurrency list (#2270)
  • a6ef928 chore: make upgrade
  • 070461f chore: bump the action-dependencies group with 4 updates (#2271)
  • Additional commits viewable in compare view

@dependabot
dependabot Bot requested a review from a team as a code owner September 21, 2026 15:32
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Sep 21, 2026
@github-actions

Copy link
Copy Markdown

🤖 Claude Code Review

PR Code Review

Scope: This PR bumps the coverage package pin from 7.15.4 to 7.16.0 for Python > 3.11, in two locations in pyproject.toml (the development and test extras).

Code Quality

  • ✅ Style conventions — Diff is a version string change only; consistent with surrounding TOML formatting.
  • ✅ No commented-out code — N/A, none present.
  • ✅ Meaningful variable names — N/A, no code identifiers changed.
  • ✅ DRY principle — ⚠️ Minor pre-existing issue (not introduced by this PR): the coverage version pins are duplicated across development (pyproject.toml:37-38) and test (pyproject.toml:86-87) dependency groups, requiring changes in two places to stay in sync. This PR correctly updated both, but this is a maintenance risk for future bumps.
  • ✅ Defects/bugs/security — No logic changes, no bugs introduced. This is a routine dependency version bump (likely from Dependabot, consistent with recent commit history showing similar bumps).
  • ✅ CLAUDE.md review — .claude/CLAUDE.md content is general-purpose (describes project structure, dev commands, code style, supported Python versions) and contains nothing specific to a local developer's environment (no hardcoded paths, usernames, or machine-specific config).

Testing

  • ✅ N/A — No new functions, endpoints, or logic; a version bump doesn't require new tests. Existing CI test matrix (Python 3.10–3.13) will validate compatibility with coverage==7.16.0.

Documentation

  • ✅ README — Not applicable, no user-facing change.
  • ✅ API docs — Not applicable.
  • ✅ Inline comments — Not applicable.
  • ❌ CHANGELOG.md — Not updated. If this repo maintains a CHANGELOG.md convention for dependency bumps, it appears to have been skipped here (I don't have visibility into whether one exists/is required in this repo, since only pyproject.toml is in the diff — worth confirming this is intentional for routine bot-driven bumps).
  • ✅ Markdown/CommonMark — No markdown files touched.

Security

  • ✅ No hardcoded credentials.
  • ✅ No input validation concerns — pure dependency version bump.
  • ✅ No error handling concerns.
  • ✅ No sensitive data in logs.
  • ✅ No .lic files or AQAAAD-prefixed strings present in this diff.

Summary

This is a low-risk, routine dependency version bump with correct, consistent updates across both locations in pyproject.toml. No defects found. The only note is a pre-existing DRY concern (duplicated version pin) and an unverified CHANGELOG.md convention — neither blocks approval.

Verdict: ✅ Approve

Automated code review analyzing defects and coding standards

Bumps [coverage](https://github.com/coveragepy/coveragepy) from 7.15.4 to 7.16.0.
- [Release notes](https://github.com/coveragepy/coveragepy/releases)
- [Changelog](https://github.com/coveragepy/coveragepy/blob/main/CHANGES.rst)
- [Commits](coveragepy/coveragepy@7.15.4...7.16.0)

---
updated-dependencies:
- dependency-name: coverage
  dependency-version: 7.16.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/pip/coverage-7.16.0 branch from 7186080 to 5564d23 Compare September 21, 2026 15:36
@github-actions

Copy link
Copy Markdown

🤖 Claude Code Review

No .lic files present, and this is a routine Dependabot version bump confined to pyproject.toml. Here's the review:

Code Quality

  • ✅ Standard style conventions — well-formed TOML, matches existing pinning pattern used throughout the file.
  • ✅ No commented-out code.
  • ✅ Meaningful variable names — N/A (dependency version bump only).
  • ✅ DRY principle followed — the version is updated consistently in both locations (pyproject.toml:38 in the development extra and pyproject.toml:87 in the test extra); no drift between the two pins.
  • ✅ Defects — no logic changes, no code touched. Version bump is a patch release (coverage 7.15.4 → 7.16.0) with no apparent breaking API surface for this project's usage.
  • ✅ .claude/CLAUDE.md — unrelated to this change; still general-purpose and contains nothing environment-specific.

Testing

  • ✅ N/A — dependency version bump, no new functions/endpoints introduced.
  • ⚠️ Not verified in this review: whether CI actually passes with coverage==7.16.0 on Python 3.12/3.13 (no network access available to check the coverage.py changelog for breaking changes). Recommend confirming the CI run is green before merging.

Documentation

  • ✅ N/A — no README/API/inline-comment changes needed for a dependency bump.
  • ❌ CHANGELOG.md not updated. If this repo tracks dependency bumps in CHANGELOG.md (worth confirming against past Dependabot-merge conventions — check if prior bumps like e1c398b/b53a9b2 updated it), this one should follow suit for consistency; otherwise this is a non-issue.

Security

  • ✅ No hardcoded credentials.
  • ✅ No input validation concerns — build tooling dependency only.
  • ✅ No error handling concerns.
  • ✅ No sensitive data in logs.
  • ✅ No .lic files or AQAAAD-prefixed strings found in the repo.

Summary: Trivial, low-risk Dependabot dependency bump. No blocking issues found. Only open item is confirming whether this repo's convention requires a CHANGELOG.md entry for dependency bumps — check recent merged Dependabot PRs to confirm.

Automated code review analyzing defects and coding standards

@docktermj
docktermj merged commit 4698866 into main Sep 21, 2026
12 checks passed
@docktermj
docktermj deleted the dependabot/pip/coverage-7.16.0 branch September 21, 2026 15:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python Pull requests that update python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants