chore(deps): combine Dependabot updates (#1250)

### Significant changes / EOS impact

The dependency bumps are mostly patch/tooling updates, but a few are worth explicit review:

- **`pydantic-settings` 2.14.2 → 2.15.0 — highest runtime impact.** EOS directly subclasses `pydantic_settings.BaseSettings` for `SettingsEOS` / `ConfigEOS`, with `case_sensitive` left at its default. In 2.15.0, `case_sensitive` now also applies to init kwargs and config-file sources, so top-level setting keys are now matched case-insensitively by default where those sources previously did not behave that way. This can change how differently-cased config keys are accepted/resolved. The release also adds warnings for unresolved forward references and changes strict non-JSON env-value failures to `ValidationError`. **Recommended:** exercise JSON config loading, init/update paths, env overrides, and config round-trips.

- **`tzfpy` 1.3.2 → 1.3.3 — runtime correctness change.** EOS uses `tzfpy.get_tz()` in `to_timezone()` and exposes the result through `GeneralSettings.timezone`. Queries exactly on timezone polygon borders now resolve instead of returning an empty result, and the `America/Argentina/Ushuaia` boundary is corrected. This can intentionally change timezone output for users on/near affected boundaries.

- **`cachebox` 6.2.2 → 6.2.5 — runtime cache correctness/safety.** EOS uses `cachebox.LRUCache` and `cachebox.cached` for the energy-management cache. The update fixes iterator lifetime safety, LRU iterator invalidation when reads promote entries, and a potential `setdefault_with` locking issue. EOS does not appear to rely on those edge cases directly, so this is expected to be low-risk and mostly corrective; existing cache tests are the relevant regression coverage.

- **`GitPython` 3.1.58 → 3.1.59 — dev/tooling security hardening.** This release blocks file-reading Git options, separate git-directory use during clone, and hardens config parsing. It appears to be a dev/docs dependency rather than EOS runtime code, but CI/tooling that intentionally passes unusual Git options could be affected.

- **`pre-commit` 4.6.1 → 4.6.2 — dev-only bug fix.** Fixes a regression in Node-language hooks using npm 11.x build scripts.

- **`mypy` 2.3.1, `commitizen` 4.17.1, and `types-PyYaml` stub update** are tooling/type-checking changes with no expected EOS runtime behavior change.

Overall, the main compatibility focus should be **configuration handling (`pydantic-settings`)**, followed by **timezone edge cases (`tzfpy`)**. The remaining updates are primarily correctness, security, or developer-tooling fixes.
This commit is contained in:
Normann
2026-08-22 00:11:08 +02:00
committed by GitHub
parent 9b3f37e172
commit 6849b731b0
3 changed files with 209 additions and 201 deletions
+2 -2
View File
@@ -31,7 +31,7 @@ repos:
# --- Static type checking ---
- repo: https://github.com/pre-commit/mirrors-mypy
rev: v2.3.0
rev: v2.3.1
hooks:
- id: mypy
additional_dependencies:
@@ -39,7 +39,7 @@ repos:
- pandas-stubs==3.0.5.260730
- tokenize-rt==6.2.0
- types-docutils==0.22.3.20260712
- types-PyYaml==6.0.12.20260724
- types-PyYaml==6.0.12.20260815
pass_filenames: false
# --- Markdown linter ---