Skip to content

[pull] master from aio-libs:master - #761

Merged
pull[bot] merged 5 commits into
tj-python:masterfrom
aio-libs:master
Sep 14, 2026
Merged

pull[bot] merged 5 commits into
tj-python:masterfrom
aio-libs:master

Conversation

@pull

@pull pull Bot commented Sep 14, 2026

Copy link
Copy Markdown

See Commits and Changes for more details.


Created by pull[bot] (v2.0.0-alpha.4)

Can you help keep this open source service alive? 💖 Please sponsor : )

Bumps [github/codeql-action](https://github.com/github/codeql-action)
from 4.37.9 to 4.38.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/github/codeql-action/releases">github/codeql-action's
releases</a>.</em></p>
<blockquote>
<h2>v4.38.0</h2>
<ul>
<li>On GitHub-hosted runners, the CodeQL Action now deletes unused
CodeQL bundles from the toolcache before downloading a different bundle,
which frees up disk space for the analysis. We expect to roll this
change out to everyone in September. <a
href="https://redirect.github.com/github/codeql-action/pull/4124">#4124</a></li>
<li>The CodeQL Action now supports CodeQL releases that are compatible
with Linux Arm64 and downloads the native <code>linux-arm64</code>
CodeQL bundle when available. <a
href="https://redirect.github.com/github/codeql-action/pull/4072">#4072</a></li>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.0">2.27.0</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4129">#4129</a></li>
</ul>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/github/codeql-action/blob/main/CHANGELOG.md">github/codeql-action's
changelog</a>.</em></p>
<blockquote>
<h2>4.38.0 - 09 Sept 2026</h2>
<ul>
<li>On GitHub-hosted runners, the CodeQL Action now deletes unused
CodeQL bundles from the toolcache before downloading a different bundle,
which frees up disk space for the analysis. We expect to roll this
change out to everyone in September. <a
href="https://redirect.github.com/github/codeql-action/pull/4124">#4124</a></li>
<li>The CodeQL Action now supports CodeQL releases that are compatible
with Linux Arm64 and downloads the native <code>linux-arm64</code>
CodeQL bundle when available. <a
href="https://redirect.github.com/github/codeql-action/pull/4072">#4072</a></li>
<li>Update default CodeQL bundle version to <a
href="https://github.com/github/codeql-action/releases/tag/codeql-bundle-v2.27.0">2.27.0</a>.
<a
href="https://redirect.github.com/github/codeql-action/pull/4129">#4129</a></li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/github/codeql-action/commit/b96794f015dfd88f77b49b1c93e0fa7110f94c63"><code>b96794f</code></a>
Merge pull request <a
href="https://redirect.github.com/github/codeql-action/issues/4131">#4131</a>
from github/update-v4.38.0-7e08580a9</li>
<li><a
href="https://github.com/github/codeql-action/commit/02d5093871674ea20274117103ce3038c73c77ef"><code>02d5093</code></a>
Update changelog for v4.38.0</li>
<li><a
href="https://github.com/github/codeql-action/commit/7e08580a93dc4e4b9dda167e364577035cf504c6"><code>7e08580</code></a>
Merge pull request <a
href="https://redirect.github.com/github/codeql-action/issues/4130">#4130</a>
from github/henrymercer/workflow-runner-sizing</li>
<li><a
href="https://github.com/github/codeql-action/commit/bfcc52b4f5d98468a5993daa0bf0e4fb3f3ed698"><code>bfcc52b</code></a>
Run slow macOS checks on larger runners</li>
<li><a
href="https://github.com/github/codeql-action/commit/8c251e757c0260283fc50214a06ac768b61d3af4"><code>8c251e7</code></a>
Merge pull request <a
href="https://redirect.github.com/github/codeql-action/issues/4129">#4129</a>
from github/update-bundle/codeql-bundle-v2.27.0</li>
<li><a
href="https://github.com/github/codeql-action/commit/0b7ca400df35985869d4b9146a067865d4115da1"><code>0b7ca40</code></a>
Add changelog note</li>
<li><a
href="https://github.com/github/codeql-action/commit/40484b339517c6bcf00f81eebc95ca041ddca505"><code>40484b3</code></a>
Update default bundle to codeql-bundle-v2.27.0</li>
<li><a
href="https://github.com/github/codeql-action/commit/977e6ceaea7361825998245d787fa3b4d6b9e5df"><code>977e6ce</code></a>
Merge pull request <a
href="https://redirect.github.com/github/codeql-action/issues/4124">#4124</a>
from github/henrymercer/toolcache-bundle-cleanup</li>
<li><a
href="https://github.com/github/codeql-action/commit/40a6b3824794ae1156e1a5320d32e364bf1dcebc"><code>40a6b38</code></a>
Address toolcache cleanup review feedback</li>
<li><a
href="https://github.com/github/codeql-action/commit/deece8f852f048bc3f52fd42c9cc7a99b1ebb252"><code>deece8f</code></a>
Apply suggestion from <a
href="https://github.com/henrymercer"><code>@​henrymercer</code></a></li>
<li>Additional commits viewable in <a
href="https://github.com/github/codeql-action/compare/v4.37.9...v4.38.0">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=github/codeql-action&package-manager=github_actions&previous-version=4.37.9&new-version=4.38.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [multidict](https://github.com/aio-libs/multidict) from 6.7.1 to
6.8.0.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/aio-libs/multidict/releases">multidict's
releases</a>.</em></p>
<blockquote>
<h2>6.8.0</h2>
<h2>Bug fixes</h2>
<ul>
<li>
<p>A segmentation fault that could be triggered when getting an item is
now fixed
-- by :user:<code>Vizonex</code>.</p>
<p><em>Related issues and pull requests on GitHub:</em>
<a
href="https://redirect.github.com/aio-libs/multidict/issues/1310">#1310</a>.</p>
</li>
<li>
<p>Fixed reference leak in iterators, views and <code>istr</code>
-- by :user:<code>Vizonex</code>.</p>
<p><em>Related issues and pull requests on GitHub:</em>
<a
href="https://redirect.github.com/aio-libs/multidict/issues/1311">#1311</a>.</p>
</li>
<li>
<p>Fixed the pure-Python :class:<code>~multidict.MultiDict</code>
constructor and
:py:meth:<code>~multidict.MultiDict.extend</code>,
:py:meth:<code>~multidict.MultiDict.update</code>, and
:py:meth:<code>~multidict.MultiDict.merge</code> methods over-allocating
their
internal hash table when called with both a positional argument and
keyword arguments, because keyword arguments were counted twice in the
size estimate -- by :user:<code>aiolibsbot</code>.</p>
<p><em>Related issues and pull requests on GitHub:</em>
<a
href="https://redirect.github.com/aio-libs/multidict/issues/1338">#1338</a>.</p>
</li>
<li>
<p>Fixed <code>__repr__</code> of
:class:<code>~multidict.MultiDict</code>,
:class:<code>~multidict.CIMultiDict</code>, their proxies, and the
keys/items views
producing invalid output when keys contained quote characters --
keys are now formatted with :func:<code>repr</code> so the result is a
valid Python
string literal -- by :user:<code>aiolibsbot</code>.</p>
<p><em>Related issues and pull requests on GitHub:</em>
<a
href="https://redirect.github.com/aio-libs/multidict/issues/1342">#1342</a>.</p>
</li>
<li>
<p>Fixed a segfault when calling
:py:meth:<code>~multidict.MultiDict.add</code> with only one of its two
required arguments supplied by keyword, e.g.
<code>d.add(key=&quot;k&quot;)</code>. Extra keyword arguments passed to
the lookup and removal methods are also now rejected with
:exc:<code>TypeError</code> instead of being silently ignored.</p>
<p>-- by :user:<code>devdanzin</code></p>
<p><em>Related issues and pull requests on GitHub:</em>
<a
href="https://redirect.github.com/aio-libs/multidict/issues/1376">#1376</a>.</p>
</li>
<li>
<p>Fixed a segfault when constructing a multidict iterator type
directly, e.g. <code>type(iter(md.keys())).__new__(...)</code>. Such an
iterator had a NULL internal pointer that <code>next()</code>
dereferenced. The iterator types now forbid direct instantiation, the
same way the view types were fixed in <a
href="https://redirect.github.com/aio-libs/multidict/issues/1163">#1163</a>.</p>
<p>-- by :user:<code>devdanzin</code></p>
<p><em>Related issues and pull requests on GitHub:</em>
<a
href="https://redirect.github.com/aio-libs/multidict/issues/1377">#1377</a>.</p>
</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/aio-libs/multidict/blob/master/CHANGES.rst">multidict's
changelog</a>.</em></p>
<blockquote>
<h1>6.8.0</h1>
<p><em>(2026-09-09)</em></p>
<h2>Bug fixes</h2>
<ul>
<li>
<p>A segmentation fault that could be triggered when getting an item is
now fixed
-- by :user:<code>Vizonex</code>.</p>
<p><em>Related issues and pull requests on GitHub:</em>
:issue:<code>1310</code>.</p>
</li>
<li>
<p>Fixed reference leak in iterators, views and <code>istr</code>
-- by :user:<code>Vizonex</code>.</p>
<p><em>Related issues and pull requests on GitHub:</em>
:issue:<code>1311</code>.</p>
</li>
<li>
<p>Fixed the pure-Python :class:<code>~multidict.MultiDict</code>
constructor and
:py:meth:<code>~multidict.MultiDict.extend</code>,
:py:meth:<code>~multidict.MultiDict.update</code>, and
:py:meth:<code>~multidict.MultiDict.merge</code> methods over-allocating
their
internal hash table when called with both a positional argument and
keyword arguments, because keyword arguments were counted twice in the
size estimate -- by :user:<code>aiolibsbot</code>.</p>
<p><em>Related issues and pull requests on GitHub:</em>
:issue:<code>1338</code>.</p>
</li>
<li>
<p>Fixed <code>__repr__</code> of
:class:<code>~multidict.MultiDict</code>,
:class:<code>~multidict.CIMultiDict</code>, their proxies, and the
keys/items views
producing invalid output when keys contained quote characters --
keys are now formatted with :func:<code>repr</code> so the result is a
valid Python
string literal -- by :user:<code>aiolibsbot</code>.</p>
<p><em>Related issues and pull requests on GitHub:</em>
:issue:<code>1342</code>.</p>
</li>
<li>
<p>Fixed a segfault when calling
:py:meth:<code>~multidict.MultiDict.add</code> with only one of its two
required arguments supplied by keyword, e.g.
<code>d.add(key=&quot;k&quot;)</code>. Extra keyword arguments passed to
the lookup and removal methods are also now rejected with
:exc:<code>TypeError</code> instead of being silently ignored.</p>
<p>-- by :user:<code>devdanzin</code></p>
<p><em>Related issues and pull requests on GitHub:</em>
:issue:<code>1376</code>.</p>
</li>
<li>
<p>Fixed a segfault when constructing a multidict iterator type
directly, e.g. <code>type(iter(md.keys())).__new__(...)</code>. Such an
iterator had a NULL internal pointer that <code>next()</code>
dereferenced. The iterator types now forbid direct instantiation, the
same way the view types were fixed in :issue:<code>1163</code>.</p>
</li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/aio-libs/multidict/commit/a8d89e44b6fbc68ef409b2f84ae68a8af84edfc9"><code>a8d89e4</code></a>
Use plain build frontend for iOS wheels in cibuildwheel (<a
href="https://redirect.github.com/aio-libs/multidict/issues/1429">#1429</a>)</li>
<li><a
href="https://github.com/aio-libs/multidict/commit/afa2e979edc96dedeb1087661e4cfa564aadf6bc"><code>afa2e97</code></a>
Release 6.8.0 (<a
href="https://redirect.github.com/aio-libs/multidict/issues/1428">#1428</a>)</li>
<li><a
href="https://github.com/aio-libs/multidict/commit/265d3e5c241a9eea19676dc6dbf6d40a7c6775a1"><code>265d3e5</code></a>
Mark temporarily-removed entries via the hash's high bit, not -1 (<a
href="https://redirect.github.com/aio-libs/multidict/issues/1426">#1426</a>)</li>
<li><a
href="https://github.com/aio-libs/multidict/commit/64a7046960cbc279ce7e8ad385f1af6898906629"><code>64a7046</code></a>
Bump pypa/cibuildwheel from 4.2.0 to 4.2.1 (<a
href="https://redirect.github.com/aio-libs/multidict/issues/1427">#1427</a>)</li>
<li><a
href="https://github.com/aio-libs/multidict/commit/5ef9f06402d898fad75293e8292ab13c7d393289"><code>5ef9f06</code></a>
Remove useless <code>pp*</code> skip selector in
<code>cibuildwheel</code> configs</li>
<li><a
href="https://github.com/aio-libs/multidict/commit/884e0db3b821ad4ec535e4240355f9ab181cd8f9"><code>884e0db</code></a>
Document design principle for pure-Python istr (<a
href="https://redirect.github.com/aio-libs/multidict/issues/1425">#1425</a>)</li>
<li><a
href="https://github.com/aio-libs/multidict/commit/ec2ec222f874754f193af3fd5d315ad4bc31f6ad"><code>ec2ec22</code></a>
Fix changelog entries to use past tense (<a
href="https://redirect.github.com/aio-libs/multidict/issues/1424">#1424</a>)</li>
<li><a
href="https://github.com/aio-libs/multidict/commit/f3cebdc4a3d8d51b1f8424d7980c7bb71add7f4c"><code>f3cebdc</code></a>
Drop dead code, _md_del_at and _md_del_at_for_update never fails (<a
href="https://redirect.github.com/aio-libs/multidict/issues/1423">#1423</a>)</li>
<li><a
href="https://github.com/aio-libs/multidict/commit/cd511da7da99e79d34188ad44ea9d864ccf00088"><code>cd511da</code></a>
Fix missing decref for None on error in setdefault (<a
href="https://redirect.github.com/aio-libs/multidict/issues/1421">#1421</a>)</li>
<li><a
href="https://github.com/aio-libs/multidict/commit/d74a504cb2694a1708389904f0aa023d5b1b3116"><code>d74a504</code></a>
Add reversed() support to MultiDict views (C-ext + pure-Python) (<a
href="https://redirect.github.com/aio-libs/multidict/issues/1340">#1340</a>)</li>
<li>Additional commits viewable in <a
href="https://github.com/aio-libs/multidict/compare/v6.7.1...v6.8.0">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=multidict&package-manager=pip&previous-version=6.7.1&new-version=6.8.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [virtualenv](https://github.com/pypa/virtualenv) from 21.7.8 to
21.7.9.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/pypa/virtualenv/releases">virtualenv's
releases</a>.</em></p>
<blockquote>
<h2>21.7.9</h2>
<!-- raw HTML omitted -->
<h2>What's Changed</h2>
<ul>
<li>fix(test): EncodingWarning: 'encoding' argument not specified by <a
href="https://github.com/even-even"><code>@​even-even</code></a> in <a
href="https://redirect.github.com/pypa/virtualenv/pull/3228">pypa/virtualenv#3228</a></li>
<li>🐛 fix(config): ignore a config file that fails to parse instead of
crashing by <a
href="https://github.com/darrenhuai"><code>@​darrenhuai</code></a> in <a
href="https://redirect.github.com/pypa/virtualenv/pull/3230">pypa/virtualenv#3230</a></li>
<li>🐛 fix(util): replace a stale symlink instead of writing through it
by <a href="https://github.com/darrenhuai"><code>@​darrenhuai</code></a>
in <a
href="https://redirect.github.com/pypa/virtualenv/pull/3229">pypa/virtualenv#3229</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/pypa/virtualenv/compare/21.7.8...21.7.9">https://github.com/pypa/virtualenv/compare/21.7.8...21.7.9</a></p>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/pypa/virtualenv/blob/main/docs/changelog.rst">virtualenv's
changelog</a>.</em></p>
<blockquote>
<h1>Bugfixes - 21.7.9</h1>
<ul>
<li>Replace dangling symlinks, including interpreter aliases, when
recreating an environment. This prevents
<code>FileExistsError</code> with <code>--symlinks</code> and writes
outside the environment with <code>--copies</code> - by
:user:<code>darrenhuai</code>.
(:issue:<code>3229</code>)</li>
<li>Ignore malformed or unreadable <code>virtualenv.ini</code> files and
report the error in the log and <code>--help</code>. Accept a UTF-8
byte order mark, as written by PowerShell 5 and older Notepad versions -
by :user:<code>darrenhuai</code>. (:issue:<code>3230</code>)</li>
</ul>
<hr />
<p>v21.7.8 (2026-09-01)</p>
<hr />
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/pypa/virtualenv/commit/abd3829378b6c14369962b43907f92049bb962e8"><code>abd3829</code></a>
release 21.7.9</li>
<li><a
href="https://github.com/pypa/virtualenv/commit/66fadcbfeac2977a12d4d671b81a32f0a3458cb4"><code>66fadcb</code></a>
🐛 fix(util): replace a stale symlink instead of writing through it (<a
href="https://redirect.github.com/pypa/virtualenv/issues/3229">#3229</a>)</li>
<li><a
href="https://github.com/pypa/virtualenv/commit/4b31a6316a872a5c0713c88ace1ceb1782d6b5b4"><code>4b31a63</code></a>
🐛 fix(config): ignore a config file that fails to parse instead of
crashing (...</li>
<li><a
href="https://github.com/pypa/virtualenv/commit/f9010b32c2116388a89080f4d07879772e28c820"><code>f9010b3</code></a>
[pre-commit.ci] pre-commit autoupdate (<a
href="https://redirect.github.com/pypa/virtualenv/issues/3231">#3231</a>)</li>
<li><a
href="https://github.com/pypa/virtualenv/commit/2ef85af47fcae15625ca7ad6f77452d5c78fadb2"><code>2ef85af</code></a>
fix(test): EncodingWarning: 'encoding' argument not specified (<a
href="https://redirect.github.com/pypa/virtualenv/issues/3228">#3228</a>)</li>
<li>See full diff in <a
href="https://github.com/pypa/virtualenv/compare/21.7.8...21.7.9">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=virtualenv&package-manager=pip&previous-version=21.7.8&new-version=21.7.9)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [filelock](https://github.com/tox-dev/py-filelock) from 3.32.5 to
3.32.6.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/tox-dev/py-filelock/releases">filelock's
releases</a>.</em></p>
<blockquote>
<h2>3.32.6</h2>
<!-- raw HTML omitted -->
<h2>What's Changed</h2>
<ul>
<li>🐛 fix(lease): reject a duration no marker can carry by <a
href="https://github.com/lprnmns"><code>@​lprnmns</code></a> in <a
href="https://redirect.github.com/tox-dev/filelock/pull/723">tox-dev/filelock#723</a></li>
<li>🐛 fix(soft-rw): reject non-finite timing options by <a
href="https://github.com/lprnmns"><code>@​lprnmns</code></a> in <a
href="https://redirect.github.com/tox-dev/filelock/pull/724">tox-dev/filelock#724</a></li>
<li>fix: preserve exception notes when copying and pickling by <a
href="https://github.com/jackwalkerlabs"><code>@​jackwalkerlabs</code></a>
in <a
href="https://redirect.github.com/tox-dev/filelock/pull/729">tox-dev/filelock#729</a></li>
<li>test(soft-rw): reuse existing test module by <a
href="https://github.com/gaborbernat"><code>@​gaborbernat</code></a> in
<a
href="https://redirect.github.com/tox-dev/filelock/pull/730">tox-dev/filelock#730</a></li>
<li>fix: respect ACL write access when the owner write bit is absent by
<a
href="https://github.com/jackwalkerlabs"><code>@​jackwalkerlabs</code></a>
in <a
href="https://redirect.github.com/tox-dev/filelock/pull/728">tox-dev/filelock#728</a></li>
<li>Fix SoftReadWriteLock state lock timeout by <a
href="https://github.com/Sohel2309"><code>@​Sohel2309</code></a> in <a
href="https://redirect.github.com/tox-dev/filelock/pull/726">tox-dev/filelock#726</a></li>
</ul>
<h2>New Contributors</h2>
<ul>
<li><a
href="https://github.com/jackwalkerlabs"><code>@​jackwalkerlabs</code></a>
made their first contribution in <a
href="https://redirect.github.com/tox-dev/filelock/pull/729">tox-dev/filelock#729</a></li>
<li><a href="https://github.com/Sohel2309"><code>@​Sohel2309</code></a>
made their first contribution in <a
href="https://redirect.github.com/tox-dev/filelock/pull/726">tox-dev/filelock#726</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/tox-dev/filelock/compare/3.32.5...3.32.6">https://github.com/tox-dev/filelock/compare/3.32.5...3.32.6</a></p>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/tox-dev/filelock/blob/main/docs/changelog.rst">filelock's
changelog</a>.</em></p>
<blockquote>
<p>###########
Changelog
###########</p>
<p>.. towncrier-draft-entries:: Unreleased</p>
<p>.. towncrier release notes start</p>
<hr />
<p>3.32.6 (2026-09-08)</p>
<hr />
<ul>
<li><code>SoftFileLease</code> and <code>AsyncSoftFileLease</code> now
reject a boolean or non-finite <code>lease_duration</code>, which used
to
publish an owner record their own <code>owner</code> property reads back
as malformed. :pr:<code>723</code></li>
<li>Reject non-finite heartbeat, stale, and polling intervals in
<code>SoftReadWriteLock</code> and <code>AsyncSoftReadWriteLock</code>,
including cached singleton construction and overflow in the default
stale threshold. :pr:<code>724</code></li>
<li>Honor acquisition timeouts and <code>blocking=False</code> during
<code>SoftReadWriteLock</code> state-mutex contention, including
failed writer cleanup. Cross-host recovery of an abandoned
<code>.state</code> marker remains unsupported.
:pr:<code>726</code></li>
<li>Allow acquiring existing lock files that grant write access through
group permissions or an ACL even when their
owner-write mode bit is unset. :pr:<code>728</code></li>
<li>Preserve exception notes and custom attributes when copying or
pickling <code>Timeout</code> and
<code>SoftFileLockProtocolError</code>. :pr:<code>729</code></li>
</ul>
<hr />
<p>3.32.5 (2026-08-31)</p>
<hr />
<ul>
<li><code>SoftFileLease.token</code> and
<code>AsyncSoftFileLease.token</code> now read <code>None</code> after a
failed acquisition, so a contender
turned away by a live holder no longer reports a token for a claim it
never published. :pr:<code>721</code></li>
<li>Document that <code>mode</code> has no setter: unlike
<code>poll_interval</code>, <code>timeout</code>, <code>blocking</code>
and <code>lifetime</code>, it is fixed at construction and
<code>lock.mode = ...</code> raises <code>AttributeError</code>.
:pr:<code>716</code></li>
</ul>
<hr />
<p>3.32.4 (2026-08-23)</p>
<hr />
<ul>
<li><code>StrictSoftFileLock</code> always retries a claim read whose
first attempt reports the claim as pending, so a first read
that itself outlasts the retry grace no longer fails closed on a claim
it could have read. :pr:<code>705</code></li>
<li><code>WindowsFileLock</code> waits out a transient
<code>STATUS_ACCESS_DENIED</code> from <code>NtCreateFile</code> for up
to half a second
before raising <code>PermissionError</code>, since a peer unlinking the
lock file as it releases can answer that for a moment; a
real denial still fails fast. :pr:<code>705</code></li>
<li>Every lock class now escapes the hostname it publishes, so a host
whose <code>socket.gethostname()</code> carries a space, a
newline or a byte outside UTF-8 no longer writes a marker it reads back
as malformed. Such a host used to lose a held
<code>SoftReadWriteLock</code> read slot to a peer and could not take a
write slot or a <code>StrictSoftFileLock</code> at all.
:pr:<code>709</code></li>
</ul>
<hr />
<p>3.32.3 (2026-08-13)</p>
<hr />
<ul>
<li>The fork-safety audit hook no longer prints <code>Exception ignored
in audit hook</code> with a <code>TypeError</code> when an audit
event fires during interpreter shutdown, after CPython has already
cleared the module globals. :pr:<code>701</code></li>
</ul>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/tox-dev/filelock/commit/4efd93e0482e8095a0b6949fb337206e7f67495d"><code>4efd93e</code></a>
Release 3.32.6</li>
<li><a
href="https://github.com/tox-dev/filelock/commit/7b7b7a8b9b10acf826cca246441297468039b0c1"><code>7b7b7a8</code></a>
Fix SoftReadWriteLock state lock timeout (<a
href="https://redirect.github.com/tox-dev/py-filelock/issues/726">#726</a>)</li>
<li><a
href="https://github.com/tox-dev/filelock/commit/f2f7b8696426c518b6828ea10e755c0ba2a4ffe2"><code>f2f7b86</code></a>
fix: respect ACL write access when the owner write bit is absent (<a
href="https://redirect.github.com/tox-dev/py-filelock/issues/728">#728</a>)</li>
<li><a
href="https://github.com/tox-dev/filelock/commit/e947a694fb0da6676c4861c8bfef3650e5656153"><code>e947a69</code></a>
test(soft-rw): reuse existing test module (<a
href="https://redirect.github.com/tox-dev/py-filelock/issues/730">#730</a>)</li>
<li><a
href="https://github.com/tox-dev/filelock/commit/da3ae2bca0035fb9e5269257e6f393360866cf88"><code>da3ae2b</code></a>
fix: preserve exception notes when copying and pickling (<a
href="https://redirect.github.com/tox-dev/py-filelock/issues/729">#729</a>)</li>
<li><a
href="https://github.com/tox-dev/filelock/commit/ae9cb5b2d66d6a79edd76b292fa7320c11468812"><code>ae9cb5b</code></a>
🐛 fix(soft-rw): reject non-finite timing options (<a
href="https://redirect.github.com/tox-dev/py-filelock/issues/724">#724</a>)</li>
<li><a
href="https://github.com/tox-dev/filelock/commit/d00f9bbd709fbe92a99a38cb1e32b6690813e5a8"><code>d00f9bb</code></a>
[pre-commit.ci] pre-commit autoupdate (<a
href="https://redirect.github.com/tox-dev/py-filelock/issues/727">#727</a>)</li>
<li><a
href="https://github.com/tox-dev/filelock/commit/82f66d7b0aaa83755f8d71d0b0da88408b58ec4a"><code>82f66d7</code></a>
🐛 fix(lease): reject a duration no marker can carry (<a
href="https://redirect.github.com/tox-dev/py-filelock/issues/723">#723</a>)</li>
<li><a
href="https://github.com/tox-dev/filelock/commit/1d9e9e7e43a1089c57d7c6f20d6a2268235a4745"><code>1d9e9e7</code></a>
[pre-commit.ci] pre-commit autoupdate (<a
href="https://redirect.github.com/tox-dev/py-filelock/issues/722">#722</a>)</li>
<li>See full diff in <a
href="https://github.com/tox-dev/py-filelock/compare/3.32.5...3.32.6">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=filelock&package-manager=pip&previous-version=3.32.5&new-version=3.32.6)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [build](https://github.com/pypa/build) from 1.6.0 to 1.6.1.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/pypa/build/releases">build's
releases</a>.</em></p>
<blockquote>
<h2>1.6.1</h2>
<!-- raw HTML omitted -->
<h2>What's Changed</h2>
<ul>
<li>chore[v1]: prepare for v1.6.1 by <a
href="https://github.com/henryiii"><code>@​henryiii</code></a> in <a
href="https://redirect.github.com/pypa/build/pull/1181">pypa/build#1181</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/pypa/build/compare/1.6.0...1.6.1">https://github.com/pypa/build/compare/1.6.0...1.6.1</a></p>
</blockquote>
</details>
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/pypa/build/blob/main/CHANGELOG.rst">build's
changelog</a>.</em></p>
<blockquote>
<p>####################
1.6.1 (2026-09-10)
####################</p>
<hr />
<p>Bugfixes</p>
<hr />
<ul>
<li>Avoid trying to detect symlinks on Windows, regression in 1.6.0 - by
:user:<code>henryiii</code> (:issue:<code>1175</code>)
(:issue:<code>1175</code>)</li>
</ul>
<hr />
<p>Documentation</p>
<hr />
<ul>
<li>Fix doubled backslashes in the Windows pip config path
(<code>%APPDATA%\pip\pip.ini</code>) in the docs - by
:user:<code>aroh3006</code>
(:issue:<code>1149</code>)</li>
</ul>
<hr />
<p>Miscellaneous</p>
<hr />
<ul>
<li>:issue:<code>1168</code>, :issue:<code>1170</code>,
:issue:<code>1178</code></li>
</ul>
<p>####################
1.6.0 (2026-08-27)
####################</p>
<hr />
<p>Features</p>
<hr />
<ul>
<li>Add <code>--report=PATH</code> to write a machine-readable JSON
report of built artifacts; <code>--metadata</code> now also accepts
<code>.whl</code> files - by :user:<code>gaborbernat</code>
(:issue:<code>198</code>)</li>
<li>The <code>srcdir</code> argument now accepts <code>.tar.gz</code>
source distributions, extracting and building from them - by
:user:<code>gaborbernat</code> (:issue:<code>311</code>)</li>
<li>The &quot;Unmet dependencies&quot; error from
<code>--no-isolation</code> builds now shows the wanted version, found
version, and
interpreter - by :user:<code>gaborbernat</code>
(:issue:<code>504</code>)</li>
<li>Add <code>--sdist-extract-dir</code> to extract the intermediate
sdist into a persistent directory, enabling compiler cache
reuse across rebuilds - by :user:<code>gaborbernat</code>
(:issue:<code>614</code>)</li>
<li>Add <code>--env-dir</code> to place the isolated build environment
at a fixed path, enabling compiler cache reuse across builds
<ul>
<li>by :user:<code>gaborbernat</code> (:issue:<code>655</code>)</li>
</ul>
</li>
<li>Print a summary of resolved dependency versions
(<code>name==version</code>) after installing them in isolated builds -
by
:user:<code>gaborbernat</code> (:issue:<code>959</code>)</li>
<li>On build failure, print a tip pointing to <code>--env-dir</code> and
<code>--sdist-extract-dir</code> for debugging and link to the
&quot;Debug a failed build&quot; how-to - reported by
:user:<code>dimpase</code>, implemented by
:user:<code>gaborbernat</code> (:issue:<code>966</code>)</li>
</ul>
<hr />
<p>Bugfixes</p>
<hr />
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/pypa/build/commit/89cccef40df9011f03bec18cf52c53d1096ed6ee"><code>89cccef</code></a>
chore: prepare for 1.6.1</li>
<li><a
href="https://github.com/pypa/build/commit/a6f707a75fc8548d7707645e97c7903197387849"><code>a6f707a</code></a>
ci: support releases from v* branches (<a
href="https://redirect.github.com/pypa/build/issues/1178">#1178</a>)</li>
<li><a
href="https://github.com/pypa/build/commit/77851610de5d3894fa8a88e06e0232901cf93758"><code>7785161</code></a>
docs: fix doubled backslashes in Windows pip config path (<a
href="https://redirect.github.com/pypa/build/issues/1149">#1149</a>)</li>
<li><a
href="https://github.com/pypa/build/commit/244b250c3219070eebb29764f7709262d48afd41"><code>244b250</code></a>
fix: always use copies for the isolated venv on Windows (<a
href="https://redirect.github.com/pypa/build/issues/1176">#1176</a>)</li>
<li><a
href="https://github.com/pypa/build/commit/c93ca6f6d252e4d8df7fda4a61f8f9ed8a55a411"><code>c93ca6f</code></a>
build(deps): bump re-actors/alls-green from 1.2.2 to 1.3.0 in the
github-acti...</li>
<li><a
href="https://github.com/pypa/build/commit/e02ffd32241aec2e306d90869417c1e900c0adb4"><code>e02ffd3</code></a>
pre-commit: bump repositories (<a
href="https://redirect.github.com/pypa/build/issues/1173">#1173</a>)</li>
<li><a
href="https://github.com/pypa/build/commit/aad39a800e3d81bf907018ebe2fab135717da59b"><code>aad39a8</code></a>
docs: fix changelog page heading levels and sidebar (<a
href="https://redirect.github.com/pypa/build/issues/1171">#1171</a>)</li>
<li><a
href="https://github.com/pypa/build/commit/5c3fd46b5c38c7caea5dd95ce365971104a734aa"><code>5c3fd46</code></a>
docs: use PyPI ref directly (<a
href="https://redirect.github.com/pypa/build/issues/1172">#1172</a>)</li>
<li><a
href="https://github.com/pypa/build/commit/1c5bd6c21cbd33c1816978d45219d48fb4c2b269"><code>1c5bd6c</code></a>
🐛 fix(release): format generated changelog (<a
href="https://redirect.github.com/pypa/build/issues/1170">#1170</a>)</li>
<li><a
href="https://github.com/pypa/build/commit/7f0cc7ed19969558c7daeaa3652ce2ffc81599c1"><code>7f0cc7e</code></a>
🔧 build(type): replace mypy with pyrefly (<a
href="https://redirect.github.com/pypa/build/issues/1168">#1168</a>)</li>
<li>See full diff in <a
href="https://github.com/pypa/build/compare/1.6.0...1.6.1">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=build&package-manager=pip&previous-version=1.6.0&new-version=1.6.1)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)


</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
@pull pull Bot locked and limited conversation to collaborators Sep 14, 2026
@pull pull Bot added the ⤵️ pull label Sep 14, 2026
@pull
pull Bot merged commit 5186393 into tj-python:master Sep 14, 2026
2 checks passed
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants