chore(deps): bump click from 8.4.1 to 8.4.2#22
Conversation
Bumps [click](https://github.com/pallets/click) from 8.4.1 to 8.4.2. - [Release notes](https://github.com/pallets/click/releases) - [Changelog](https://github.com/pallets/click/blob/main/CHANGES.md) - [Commits](pallets/click@8.4.1...8.4.2) --- updated-dependencies: - dependency-name: click dependency-version: 8.4.2 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]>
LabelsThe following labels could not be found: Please fix the above issues or remove invalid values from |
## Why The 5 open Dependabot uv PRs (#21 click, #22 click*, #23 ruff, #24 pyright, #25 hypothesis + coverage) each failed CI with: ``` The lockfile at `uv.lock` needs to be updated, but `--locked` was provided. ``` Root cause: this repo routes installs through **Takumi Guard** (`pypi.flatt.tech`). Dependabot resolves against public PyPI and rewrites the lock's URLs to `files.pythonhosted.org`, so `uv sync --locked` (running behind the Takumi index) sees the lock as inconsistent and fails. It is **not** a code problem — `main` is green. ## What One relock via `uv lock --upgrade-package {click,coverage,hypothesis,pyright,ruff}` against the `pypi.flatt.tech` index, honoring the pinned `exclude-newer = 2026-07-22`. Only `uv.lock` changes; the index URLs stay on `pypi.flatt.tech` (0 pythonhosted leaks). Resolved: click 8.4.2 · coverage 7.15.2 · hypothesis 6.157.0 · pyright 1.1.411 · ruff 0.15.22. Supersedes #21, #22, #23, #24, #25. 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-authored-by: Claude Opus 4.8 <[email protected]>
|
Superseded by #26, which relocks these bumps against the Takumi Guard index (pypi.flatt.tech) in one consolidated uv.lock. Individual Dependabot PRs fail because they rewrite the lock URLs to files.pythonhosted.org. |
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
Bumps click from 8.4.1 to 8.4.2.
Release notes
Sourced from click's releases.
Changelog
Sourced from click's changelog.
Commits
b2e30a1Release version 8.4.27a16b20Fixpackage_nameresolution when module differs from distribution name (#3582)bec5928Fixpackage_nameresolution when top-level module differs from distribution...916883aFix tests to not rely on-Wdefaultoption (#3591)09195f6Fix double-bracketing of choices in synopsis (#3578)1557e26Check for warning exception with idiomatic context managerd9ff133Static typing improvements inclick.shell_completion(#3460)762c97eFix double-bracketing of choices in synopsis8929d39Convert changes to markdown. (#3559)237be50Move changes headings down a level.Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)